Collective Runtime
Recovery Semantics

Recovery semantics

Failure is an operating condition. The runtime can represent peer loss, communication loss, capability failure, stale state, expired leases and unsafe outcomes as explicit recovery signals.

Recovery follows a bounded loop:

  1. Detect and authenticate the failure signal.
  2. Stop or fence work whose authority is no longer valid.
  3. Preserve the causal predecessor and evidence.
  4. Re-evaluate eligible peers, roles and policy.
  5. Reassign or replan within the configured recovery budget.
  6. Resume only after readiness and authority checks pass.

Missing, conflicting or stale evidence remains unresolved. The safe default is pause or fail closed, not silent continuation.