Automation Flow Builder — Grilling Session Decisions (2026-07-22)
Outcome of a structured decision-grilling session (PM: Dimas Fauzi Hidayat) walking the open questions of the discovery product plan (§12) plus the decision branches they imply. Each decision below is committed — the future ANCHOR PRD and the P2 feasibility spike brief should inherit these directly. Decisions marked ⚡ deliberately trade safety for speed (consistent posture, chosen with eyes open).
Decision register
| # | Decision area | Committed answer |
|---|---|---|
| D1 | Kill-switch | P0+P1 are committed unconditionally; P2 is conditional on the feasibility spike. "Replacement" is a direction, not a launch promise. If the spike fails, P1 stands alone as an automation-first builder. |
| D2 | Spike pass bar | Time-boxed ~2 weeks, three explicit exit criteria: (a) migration mapping covers ≥90% of published Path/Intent/Response constructs with the remainder enumerated as a known-gap list (folds in the risk-#7 parity audit: content-type rendering, idle-rule side effects, IntentAPIEntity field-saving); (b) shadow-run parity on ≥5 real production flows with a defined equivalence rule (message content + branch taken + side effects); (c) one demonstrated rollback (flag-off returns a migrated org to the legacy engine, zero data loss). Fail any → P2 re-scopes or dies per D1. |
| D3 | Interim IA (plan §12 Q5) | P1 ships as a separate "Automation" nav item; bot-flow IA untouched; zero replacement messaging until the spike passes. Unification appears in the UI only at P2 (Conversation node group inside the same canvas). |
| D4 ⚡ | P2 wave 1 (plan §12 Q2) | Opt-in existing design partners migrate first — chosen over new-tenant greenfield because it exercises the actual risk machinery (translate + shadow-run + cutover) earliest, and drops the day-one full-authoring-parity requirement (partners are selected whose flows fit the proven node set). |
| D5 | P2 wave 2 — new tenants | New-org default flips to the new engine after 2–4 weeks of stable wave-1 traffic, gated on parity proof only (not forced-migration readiness). The spike's known-gap list is the entry bar: a new tenant needing an unsupported node type sees the legacy builder. Forced migration of the remaining installed base is last, on its own timeline. |
| D6 | Rollback SLA (plan §12 Q7) | 4-week per-org warm window post-cutover with one-click flag-off. Legacy tree is frozen read-only post-cutover so rollback is always consistent (editable legacy would turn rollback into a merge problem). Global legacy decommission ≥1 quarter after the last forced-wave org. |
| D7 ⚡ | v1 authoring persona (plan §12 Q3) | Org admins AND supervisors both author in v1 — activation over caution; supervisors are the ops persona (coherent with Live Monitoring). |
| D8 | Authoring guardrails (consequence of D7) | No approval pipeline in v1. Two cheap controls from P0: (a) audit fields created_by / last_edited_by / activated_by on Workflow, surfaced in the workflow list and Runs tab; (b) org-level setting "who can author automations", defaulting to admin+supervisor, tightenable to admin-only. |
| D9 | Pricing gate (plan §12 Q1) | Pricing/finance review gates launch/GTM, not the PRD. The PRD commits the structural model (plan-gated builder, quota metering in WorkflowRun, run packs, notify-never-silent-stop, bot-conversation runs never quota-gated) with numeric quotas marked TBD-finance. The production bot-message volume pull starts now — one pull feeding both quota sizing (§8.1) and run-history retention sizing (§12 Q6). |
| D10 | Scheduled-trigger timezone (plan §12 Q4) | timezone column per workflow from P0, silently defaulting to org timezone; no picker UI in v1 (override UI ships on demand). Avoids a later migration; Indonesian tenants span WIB/WITA/WIT. |
| D11 ⚡ | Critical path to write-prd | Nothing gates PRD drafting — it starts now. P2 is authored as a gated phase carrying the D2 spike-exit criteria in the PRD itself, so a negative spike deletes a section rather than forcing a rewrite. Spike, design change-request brief to Wulan, and the volume pull all run in parallel; concept-test findings fold in before sign-off, not before drafting. |
What this closes / supersedes
- Plan §12 open questions 1, 2, 3, 4, 5, 7 are closed (D9, D4+D5, D7, D10, D3, D6).
- §12 Q6 (run-history retention) is half-closed: the sizing input is the D9 volume pull; the retention-tier decision itself lands in the PRD.
- The §12 next-steps list is re-sequenced by D11: spike, design brief, and volume pull
are parallel tracks;
write-prdis unblocked immediately (PRD build not yet started — deliberately deferred by the PM on 2026-07-22).
Standing consequences for the spike brief
- Sample selection for D2(b) should draw from the candidate design-partner orgs' flows (D4), so parity evidence and wave-1 eligibility are the same artifact.
- The known-gap list is a triple-duty output: P2 scope input (D1/D2), new-tenant entry bar (D5), and authoring-parity checklist.