ADR-A33: Surface revision ledger and optimistic concurrency

Status: Accepted Date: 2026-09-19 Supersedes: none Related: Phase 2, ADR-A13, ADR-A27, ADR-A32, Surface workflow architecture

Context

Surface revision state changes are user and worker initiated. Two actors can read the same revision and attempt incompatible updates, such as an approval after a supersession. Storing workflow state inside RDF would conflate operational coordination with semantic source-of-truth graphs. Storing mutable graph documents in the operational database would duplicate semantic content and make revision hashes less meaningful.

Decision

Maintain Surface workflow state in a PostgreSQL operational ledger. Store graph references and lifecycle evidence, not RDF content. Give each revision an increasing optimistic-concurrency version. A replacement must name the version that was read. The database updates state only when the stored version matches, and otherwise reports a stale-revision conflict.

Consequences