Builder Console, tenant runtime, admin/developer/operations surfaces and public APIs.
React · TypeScript · ASP.NET Core · OpenAPI · MCPCurrent technical architecture · three database planes
BuildWithHQ combines a record-graph tenant runtime, exact-version application supply chain, secured multimodal AI, approval-fenced agents, isolated custom services and replayable operational evidence. This page is generated from the current repository contracts—not an aspirational database sketch.
Architecture thesis
The browser never talks directly to SQL Server, provider secrets, payment rails, DNS or tenant containers. Authenticated gateways resolve identity, typed services call reviewed procedures, and workers own durable or external side effects.
Everything operational becomes a secured record graph; everything long-running becomes fenced work; everything AI sees is authorized before prompt construction; and every material action can be correlated to evidence.
Builder Console, tenant runtime, admin/developer/operations surfaces and public APIs.
React · TypeScript · ASP.NET Core · OpenAPI · MCPPages, Puck components, Monaco JSON, modules, fields, User Types, DataRoles, locations, workflows and versioned templates.
shared page + tenant fork · revision locks · exact snapshotsFirst-class and custom business objects share relations, activity, files, dynamic fields, as-of history and secured graph traversal.
RecordId · ModuleId · RecordRelations · security envelopeConversations and forms remain source records; Universal Inbox routes attention and GoClaw prepares proposed work.
InboxItems.ActivityVersion · suggestion batch · approvalLease-fenced workers execute deterministic workflows, messages, webhooks, installs, AI jobs, backups and exports.
claim · lease token/version · renew · complete · recoverSigned installable services run behind authenticated gateways in OCI or Firecracker boundaries with declared egress and secret references.
immutable artifact · endpoint policy · invocation ledgerCorrelation, audit, record changes, AI citations, flight recorder, metrics, traces and warehouse checkpoints reconstruct behavior without copying secrets.
Customer Log DB · OTLP · dashboards · status feedNewest repository updates
These slices are marked complete in the machine-readable task state. “Complete” means the repository acceptance evidence passed; it does not by itself claim the public production launch is signed off. Launch checklist and production launch remain partial in this snapshot.
Signed, exact-version appliance releases deploy a customer's own SaaS databases and isolated services locally; the central Template Library remains catalog-operated, not copied into the appliance runtime.
Lease-fenced provisioning, marketplace, template, AI, GoClaw, workflow, communications, webhook and operations workers now share recovery, telemetry, dashboards, alerts and runbooks.
Capability-routed multimodal embedding uses Qwen/Qwen3-VL-Embedding-8B with exact 256D, 1024D and 1998D SQL lanes, post-truncation normalization and physical-fleet revalidation gates.
Published, reviewable knowledge is connected to records, secured RAG, questions, Inbox support context and a sanitized post-resolution learning loop that cannot self-publish.
Any permitted record graph can anchor a secured workplace with participants, activity, pulse evaluation, snapshots and playback—without cloning the underlying business records.
User Types now control shared-page menus and the tenant runtime can switch between visual Puck editing and advanced Monaco JSON, with ownership, revision and publication fences.
The Field Service reference package and end-to-end proofs cover custom records, workflows, communications, secured AI/RAG, GoClaw approval, exact-version marketplace install, Snowflake and appliance deployment.
IIS junction swaps and Cloudflare custom-hostname/origin controls join schema compatibility, lease-safe workers, restore rehearsal, monitoring and security release gates.
Trust boundary
Client identifiers are query targets, never authorization proof. The effective SaaS app, AppAccount, user, role, DataRole, location and capability are reconstructed from the authenticated server context at every boundary.
Domain, session or service credentials resolve a server-owned tenant context. Payloads cannot select another database or elevate actor scope.
Controllers and routes use typed application services mapped to reviewed stored procedures. Ad-hoc DML is outside the production contract.
DataRole, row/record policy and location membership are evaluated for reads, actions, global search, history and recursive graph traversal.
CanAiReadRecords and source policy apply in addition to normal read access—before retrieval results, images or chunks enter a model context.
Inbox ActivityVersion follows a proposal through approval and deterministic execution. New activity invalidates work prepared against old context.
Browsers receive neither provider credentials nor raw secure fields. Server-owned resolvers unwrap secrets only at the service that needs them.
Templates, Harness Packs, services and appliance releases are signed/versioned inputs with snapshot isolation and install evidence.
Operation, parent and correlation identifiers connect requests, procedure calls, workers, AI citations and external effects across planes.
SQL Server topology per SaaS
Every SaaS you publish gets these three databases of its own. Each is summarized by its responsibility, security boundary and current contract footprint—enough technical detail to understand the system without listing every implementation object.
Tenant runtime
The authoritative tenant business runtime: records, fields, relations, pages, DataRoles, locations, workflows, communications, Universal Inbox, GoClaw action control, Knowledge Core and ActiveWorkplace.
BoundaryOne tenant/app security envelope; every request is resolved from verified server identity and uses reviewed stored procedures.
Tenant AI retrieval
The tenant semantic retrieval plane: source registry, document structure, chunks, visual evidence, 256/1024/1998D embeddings, rebuild jobs, secured candidate search and tenant AI state.
BoundarySearch material is not authorization proof. Tenant, DataRole, location and CanAiReadRecords are reapplied before any model context is assembled.
Tenant evidence
Append-oriented operational evidence: audit, record change, AI query citations, page activity, worker and appliance flight-recorder events, tamper-evident ledgers and Snowflake sync state.
BoundaryEvidence stays tenant-scoped, privacy-minimized and correlation-linked; business services do not turn the log plane into a second source of mutable truth.
AI + governed agents
The SaaS Vector DB makes authorized evidence searchable. It never grants GoClaw permission to mutate a business record. Planning, approval and execution stay separate and auditable.
Text, document structure and visual evidence share the existing source/chunk model. Qwen3-VL maps them into the production SQL vector lanes.
Inbound activity becomes attention first. GoClaw planning is read-only; customer-facing work becomes deterministic only after current authority is proven.
Deployment + extension
The same contract model supports BuildWithHQ-operated environments and customer/MSP-hosted appliances. Appliance operation is local: a customer runs their own SaaS databases and services, while catalog acquisition remains a signed central interaction.