Reference
Write policies
Mutation, identity, and safety fields with policy examples.
A write policy is the rulebook on a destination or ontology write: what changes are allowed, how identity works, what happens on conflict, and what can never be deleted silently. Reads are free; writes answer to a policy.
Mutations
| Mutation | Effect | Requires |
|---|---|---|
| Append | Add rows, never touch existing | Nothing — the safe default |
| Upsert | Insert new, update known | Identity keys |
| Update | Change matched rows only | Identity keys |
| Replace | Swap whole target for a snapshot | Snapshot state + omission-delete, approved together |
| Delete | Remove matched rows | Identity keys + physical-deletion permission |
{
"mutation": "append",
"identity": { "keys": ["forecast_id", "run_id"] },
"duplicates": "reject",
"conflicts": "reject",
"invalidRows": "reject"
}A second example — reviewed nightly dimension upsert:
{
"mutation": "upsert",
"identity": { "keys": ["account_id"] },
"duplicates": "last_write_wins",
"conflicts": "overwrite",
"omission": "preserve",
"invalidRows": "quarantine",
"atomicity": "run"
}Identity, duplicates, conflicts, omission
| Field | Options | Rule of thumb |
|---|---|---|
| Identity keys | Field list, unique, non-empty; nulls rejected | Business keys, never generated ones |
| Duplicates | Reject / preserve / last-write-wins | Reject where money moves |
| Conflicts | Reject / overwrite | Updates must explicitly allow overwrite |
| Omission | Preserve / delete missing rows | Delete only with snapshot + replace, one decision |
A full read is never implicit permission to delete missing rows.
Safety fields
| Field | Options | Meaning |
|---|---|---|
| Schema evolution | Reject / create-only / additive / rebuild | Additive is the usual truce |
| Retention | Minimum days + physical-delete flag | Deletion paths need the flag set deliberately |
| Invalid rows | Reject batch / quarantine rows | Quarantine at volume, reject where critical |
| Atomicity | Row / object / file / run | How much commits together — never half-apply |
| Empty snapshot | Always rejected | An empty read never wipes a target |
| Concurrency | Reject / destination-managed | Who serializes simultaneous writes |
Destructive combinations
Any of these raises the approval bar: replace, update, delete, or upsert mutations; omission-delete; relationship cascade; rebuild-level schema evolution; physical deletion; compaction. Append-only with none of these is comparatively safe.
Image: write policy summary on a destination node with the destructive flags highlighted for approval.
Next
- Nodes that carry policies: Workflow nodes.
- First external write: Deliver results somewhere.