Status: Proposed
Date: 2026-09-23
Related: Architecture Review §5.5, G-07, ADR-A65, ontology-architecture.md
Drafted by: Agent, autonomous session (P0.1.6). Pending human ratification — see phase-0-status.md.
The platform needs two independent time axes and currently models neither explicitly at the runtime layer. Valid time answers “what was true in the world at date X” (Foundation already provides fnd:TemporalScope, unused by the platform). Transaction time answers “what did the system believe at date X, before a later correction arrived.”
lattice:transactionTime (the commit instant, monotone per dataset). Where the asserted facts are themselves temporally scoped, subject nodes also carry fnd:TemporalScope (validFrom/validTo).fnd:supersededBy), with fnd:Evidence naming the correction cause. The prior version remains queryable.C-12) accepts asOfValidTime and asOfTransactionTime parameters independently. Omitting both means “current beliefs about now.”decisionTime (valid time) as a stimulus field. The engine pins transaction time at commit. Replay supplies both, so determinism survives backdated claims.Bi-temporal queries over named graphs require either a per-graph temporal index or a temporal-filter pattern on every query. Materialise current projections for the hot path (subject to the NFR/SLO catalogue, P0.1.15); answer as-of queries from authoritative layers via a separate analytic path with relaxed SLOs. This is a deliberate two-path design, stated here rather than discovered later.
now() inside guards, effects, or canonicalisation — time is an input) is the enforcement mechanism for rule 4; ArchUnit bans clock access in named packages.lattice:transactionTime are the same field — one write path sets it once, not twice.docs/architecture/nfr.md (P0.1.15) before the query component’s L7 benchmarks are meaningful.