# Control / Coordination / Centralization

> Every principle in this category is listed as a record.

Page: Ontology · Principles
Canonical: https://banes-lab.com/ontology#architecture-category-control-coordination-centralization

Listed in [Ontology · Principles](https://banes-lab.com/api/pages/ontology/principles.md), after [Contracts / Interfaces / Compatibility](https://banes-lab.com/ontology/principles/architecture-category-contracts-interfaces-compatibility.md) and before [Correctness / Determinism / Verification](https://banes-lab.com/ontology/principles/architecture-category-correctness-determinism-verification.md).

Every principle in this category is listed as a record. Each record carries its kind, its severity, the scopes it applies at and the layer it lives in, then the edge relations that join it to other records, the records that point back at it, the contracts that answer to it and the tensions it takes part in. The descriptors say how it is violated, detected, measured, repaired and enforced. Where the record carries one, an exemplar shows the shape before and after the principle is applied.

Relations diagram

The relations inside this category.

```mermaid
flowchart LR
n_control_plane["Control Plane"]
n_orchestration["Orchestration"]
n_centralized_configuration["Centralized Configuration"]
n_centralized_authentication["Centralized Authentication"]
n_centralized_logging["Centralized Logging"]
n_decentralization["Decentralization"]
n_leader_election["Leader Election"]
n_consensus["Consensus"]
n_choreography["Choreography"]
n_control_plane --> n_orchestration
n_orchestration --> n_control_plane
n_leader_election --> n_consensus
n_leader_election --> n_control_plane
n_choreography --> n_decentralization
```

### Control Plane

- Kind: [artifact](https://banes-lab.com/records/kind/artifact.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: platform, infrastructure, distributed system
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
Descriptive data about the desired state of a distributed runtime, held in one place and applied to every node through a management interface.

Requires
[Management API](https://banes-lab.com/records/lexicon/management-api.md), [Policy](https://banes-lab.com/records/lexicon/policy.md)

Reinforces
[Governance](https://banes-lab.com/records/architecture/governance.md), [Orchestration](https://banes-lab.com/records/architecture/orchestration.md)

Enables
[Centralized Control of Distributed Runtime](https://banes-lab.com/records/lexicon/centralized-control-of-distributed-runtime.md)

In tension with
[Availability](https://banes-lab.com/records/lexicon/availability.md)

Conflicts with
[Fully Decentralized Control](https://banes-lab.com/records/lexicon/fully-decentralized-control.md)

Referenced by
[Orchestration](https://banes-lab.com/records/architecture/orchestration.md), [Leader Election](https://banes-lab.com/records/architecture/leader-election.md)

Contracts
[Control Plane](https://banes-lab.com/records/algorithms/control-plane.md)

Tensions
[Control Plane / Availability](https://banes-lab.com/records/tension/availability-control-plane.md)

Violated by
unmanaged distributed configuration/control

Detected by
manual node/service control

Measured by
control coverage, control-plane availability

Refactored by
Add Control Plane, Externalize Policy

Enforced by
platform architecture

Before

```typescript
for (const node of fooNodes) {
node.configure({ retries: 3, timeoutMs: 500 });
}
```

After

```typescript
controlPlane.apply("foo-service", {
retries: 3,
timeoutMs: 500,
rollout: "progressive",
});
```

How it is checked

Checked by
platform architecture

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Management API](https://banes-lab.com/records/lexicon/management-api.md), [Policy](https://banes-lab.com/records/lexicon/policy.md), [Governance](https://banes-lab.com/records/architecture/governance.md), [Orchestration](https://banes-lab.com/records/architecture/orchestration.md), [Centralized Control of Distributed Runtime](https://banes-lab.com/records/lexicon/centralized-control-of-distributed-runtime.md)

Shape it refuses
[Fully Decentralized Control](https://banes-lab.com/records/lexicon/fully-decentralized-control.md)

### Orchestration

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: workflow, deployment, services
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A mechanism that runs a multi-step workflow from one coordinator, which calls each step in order and tracks its outcome.

Requires
[Coordinator](https://banes-lab.com/records/lexicon/coordinator.md)

Reinforces
[Control Plane](https://banes-lab.com/records/architecture/control-plane.md), [Saga](https://banes-lab.com/records/lexicon/saga.md)

Enables
[Ordered Multi-Step Execution](https://banes-lab.com/records/lexicon/ordered-multi-step-execution.md)

In tension with
[Centralized Coordinator Coupling](https://banes-lab.com/records/lexicon/centralized-coordinator-coupling.md)

Conflicts with
[Pure Choreography](https://banes-lab.com/records/lexicon/pure-choreography.md)

Referenced by
[Control Plane](https://banes-lab.com/records/architecture/control-plane.md)

Contracts
[Workflow Creation Kernel](https://banes-lab.com/records/algorithms/workflow-creation-kernel.md)

Tensions
[Orchestration / Centralized Coordinator Coupling](https://banes-lab.com/records/tension/centralized-coordinator-coupling-orchestration.md)

Distinct from
[Coordinator](https://banes-lab.com/records/lexicon/coordinator.md): Orchestration is the mechanism of driving a workflow from one place, while the coordinator is the component that plays that role.

Violated by
implicit fragile workflow spread across services

Detected by
unclear workflow ownership

Measured by
workflow observability/completion

Refactored by
Add Orchestrator, Define Workflow

Enforced by
workflow tests

Before

```typescript
await fooService.create(foo);
await barService.create(bar);
await bazService.create(baz);
```

After

```typescript
await orchestrator.run("CreateFooFlow", {
steps: [
step("foo", () => fooService.create(foo)),
step("bar", () => barService.create(bar)),
step("baz", () => bazService.create(baz)),
],
});
```

How it is checked

Checked by
workflow tests

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Coordinator](https://banes-lab.com/records/lexicon/coordinator.md), [Control Plane](https://banes-lab.com/records/architecture/control-plane.md), [Saga](https://banes-lab.com/records/lexicon/saga.md), [Ordered Multi-Step Execution](https://banes-lab.com/records/lexicon/ordered-multi-step-execution.md)

Shape it refuses
[Pure Choreography](https://banes-lab.com/records/lexicon/pure-choreography.md)

### Centralized Configuration

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: service, platform, runtime
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design pattern that keeps every service's configuration in one versioned store the services read from.

Requires
[Config Store](https://banes-lab.com/records/lexicon/config-store.md), [Access Control](https://banes-lab.com/records/architecture/access-control.md)

Reinforces
[Governance](https://banes-lab.com/records/architecture/governance.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md)

Enables
[Unified Config Management](https://banes-lab.com/records/lexicon/unified-config-management.md)

In tension with
[Central Dependency Risk](https://banes-lab.com/records/lexicon/central-dependency-risk.md)

Conflicts with
[Scattered Configuration](https://banes-lab.com/records/lexicon/scattered-configuration.md)

Tensions
[Centralized Configuration / Central Dependency Risk](https://banes-lab.com/records/tension/central-dependency-risk-centralized-configuration.md)

Violated by
duplicated divergent configs

Detected by
config drift

Measured by
config drift count

Refactored by
Move to Central Config, Add Schema

Enforced by
config policy

Before

```typescript
const fooConfig = loadLocalFooConfig();
const barConfig = loadLocalBarConfig();
const bazConfig = loadLocalBazConfig();
```

After

```typescript
const config = await configService.readVersioned("platform/v3");
fooApp.apply(config.foo);
barApp.apply(config.bar);
bazApp.apply(config.baz);
```

How it is checked

Checked by
config policy

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Config Store](https://banes-lab.com/records/lexicon/config-store.md), [Access Control](https://banes-lab.com/records/architecture/access-control.md), [Governance](https://banes-lab.com/records/architecture/governance.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md), [Unified Config Management](https://banes-lab.com/records/lexicon/unified-config-management.md)

Shape it refuses
[Scattered Configuration](https://banes-lab.com/records/lexicon/scattered-configuration.md)

### Centralized Authentication

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: identity, system
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design pattern that verifies identity once, at a shared identity provider, and passes the result to each service.

Requires
[Identity Provider](https://banes-lab.com/records/lexicon/identity-provider.md)

Reinforces
[Security](https://banes-lab.com/records/lexicon/security.md), [Governance](https://banes-lab.com/records/architecture/governance.md)

Enables
[Unified Identity](https://banes-lab.com/records/lexicon/unified-identity.md)

In tension with
[Identity Provider Availability](https://banes-lab.com/records/lexicon/identity-provider-availability.md)

Conflicts with
[Scattered Auth Implementations](https://banes-lab.com/records/lexicon/scattered-auth-implementations.md)

Tensions
[Centralized Authentication / Identity Provider Availability](https://banes-lab.com/records/tension/centralized-authentication-identity-provider-availability.md)

Violated by
custom auth per service without federation

Detected by
duplicated credential stores

Measured by
auth centralization coverage

Refactored by
Introduce IdP, Federate Auth

Enforced by
[security policy](https://banes-lab.com/records/algorithms/security-policy.md)

Before

```typescript
fooService.verifyToken(token);
barService.verifyToken(token);
bazService.verifyToken(token);
```

After

```typescript
const identity = await identityProvider.authenticate(token);
await fooService.handle({ identity });
await barService.handle({ identity });
await bazService.handle({ identity });
```

How it is checked

Checked by
security policy

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Identity Provider](https://banes-lab.com/records/lexicon/identity-provider.md), [Security](https://banes-lab.com/records/lexicon/security.md), [Governance](https://banes-lab.com/records/architecture/governance.md), [Unified Identity](https://banes-lab.com/records/lexicon/unified-identity.md)

Shape it refuses
[Scattered Auth Implementations](https://banes-lab.com/records/lexicon/scattered-auth-implementations.md)

### Centralized Logging

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: services, platform
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design pattern that ships structured logs from every instance to one aggregated store.

Requires
[Log Aggregation](https://banes-lab.com/records/lexicon/log-aggregation.md)

Reinforces
[Observability](https://banes-lab.com/records/architecture/observability.md), [Auditability](https://banes-lab.com/records/architecture/auditability.md)

Enables
[Cross-Service Analysis](https://banes-lab.com/records/lexicon/cross-service-analysis.md)

In tension with
[Cost/Personal Data Exposure](https://banes-lab.com/records/lexicon/cost-personal-data-exposure.md)

Conflicts with
[Local-Only Logs](https://banes-lab.com/records/lexicon/local-only-logs.md)

Tensions
[Centralized Logging / Cost/Personal Data Exposure](https://banes-lab.com/records/tension/centralized-logging-cost-personal-data-exposure.md)

Violated by
logs only available per instance

Detected by
missing log shipping

Measured by
log ingestion coverage

Refactored by
Add Log Forwarder, Standardize Fields

Enforced by
observability policy

Before

```typescript
fooService.writeLocalLog(event);
barService.writeLocalLog(event);
bazService.writeLocalLog(event);
```

After

```typescript
const sink = new CentralLogSink();
fooService.useLogger(structuredLogger(sink));
barService.useLogger(structuredLogger(sink));
bazService.useLogger(structuredLogger(sink));
```

How it is checked

Checked by
observability policy

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Log Aggregation](https://banes-lab.com/records/lexicon/log-aggregation.md), [Observability](https://banes-lab.com/records/architecture/observability.md), [Auditability](https://banes-lab.com/records/architecture/auditability.md), [Cross-Service Analysis](https://banes-lab.com/records/lexicon/cross-service-analysis.md)

Shape it refuses
[Local-Only Logs](https://banes-lab.com/records/lexicon/local-only-logs.md)

### Decentralization

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: system, team, service
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that decisions and runtime control sit with the teams and services that own them, joined by contracts.

Requires
[Autonomy](https://banes-lab.com/records/architecture/autonomy.md), [Contracts](https://banes-lab.com/records/lexicon/contracts.md)

Reinforces
[Microservices](https://banes-lab.com/records/architecture/microservices.md), [Resilience](https://banes-lab.com/records/architecture/resilience.md)

Enables
[Independent Ownership](https://banes-lab.com/records/lexicon/independent-ownership.md)

In tension with
[Governance](https://banes-lab.com/records/architecture/governance.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md)

Conflicts with
[Centralized Control](https://banes-lab.com/records/lexicon/centralized-control.md)

Referenced by
[Choreography](https://banes-lab.com/records/architecture/choreography.md), [Autonomy](https://banes-lab.com/records/architecture/autonomy.md), [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)

Tensions
[Decentralization / Governance](https://banes-lab.com/records/tension/decentralization-governance.md), [Decentralization / Consistency](https://banes-lab.com/records/tension/consistency-decentralization.md)

Violated by
central bottleneck for independent decisions/runtime

Detected by
centralized team/service dependency

Measured by
decision/deployment dependency count

Refactored by
Delegate Ownership, Split Service/Control

Enforced by
ownership model

Before

```typescript
const coordinator = new GlobalFooCoordinator();
await coordinator.approveEveryFoo(foo);
```

After

```typescript
await fooNode.validate(foo);
await fooNode.commit(foo);
await fooNode.publish({ type: "FooCommitted", fooId: foo.id });
```

How it is checked

Checked by
ownership model

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Autonomy](https://banes-lab.com/records/architecture/autonomy.md), [Contracts](https://banes-lab.com/records/lexicon/contracts.md), [Microservices](https://banes-lab.com/records/architecture/microservices.md), [Resilience](https://banes-lab.com/records/architecture/resilience.md), [Independent Ownership](https://banes-lab.com/records/lexicon/independent-ownership.md)

Shape it refuses
[Centralized Control](https://banes-lab.com/records/lexicon/centralized-control.md)

### Leader Election

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: distributed systems
- Scope: distributed system, coordination, availability
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A mechanism that lets a group of nodes agree on one coordinator and replace it when it fails.

Requires
[Consensus](https://banes-lab.com/records/architecture/consensus.md)

Reinforces
[Control Plane](https://banes-lab.com/records/architecture/control-plane.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md)

Enables
[Single-Writer Coordination](https://banes-lab.com/records/lexicon/single-writer-coordination.md), [Automatic Failover of Leadership](https://banes-lab.com/records/lexicon/automatic-failover-of-leadership.md)

In tension with
[Availability](https://banes-lab.com/records/lexicon/availability.md)

Conflicts with
[Split-Brain Coordination](https://banes-lab.com/records/lexicon/split-brain-coordination.md)

Tensions
[Leader Election / Availability](https://banes-lab.com/records/tension/availability-leader-election.md)

Violated by
multiple nodes assuming the coordinator role at once

Detected by
concurrent leader actions / split-brain

Measured by
split-brain incident rate

Refactored by
Introduce Leader Election

Enforced by
distributed-systems review

Before

```typescript
if (process.env.IS_LEADER === "true") runFooScheduler();
```

After

```typescript
const lease = await fooCoordinator.acquireLeadership("foo-scheduler", { ttlMs: 10_000 });
lease.onAcquired(() => runFooScheduler());
lease.onLost(() => stopFooScheduler());
```

How it is checked

Checked by
distributed-systems review

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Consensus](https://banes-lab.com/records/architecture/consensus.md), [Control Plane](https://banes-lab.com/records/architecture/control-plane.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Single-Writer Coordination](https://banes-lab.com/records/lexicon/single-writer-coordination.md), [Automatic Failover of Leadership](https://banes-lab.com/records/lexicon/automatic-failover-of-leadership.md)

Shape it refuses
[Split-Brain Coordination](https://banes-lab.com/records/lexicon/split-brain-coordination.md)

### Consensus

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: distributed systems
- Scope: distributed system, agreement, consistency
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A mechanism that lets a quorum of nodes commit one value, so every correct node ends up with the same value.

Requires
[Quorum](https://banes-lab.com/records/lexicon/quorum.md)

Reinforces
[Consistency](https://banes-lab.com/records/architecture/consistency.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md)

Enables
[Agreed Single Value Across Nodes](https://banes-lab.com/records/lexicon/agreed-single-value-across-nodes.md)

In tension with
[Latency](https://banes-lab.com/records/architecture/latency.md), [Availability](https://banes-lab.com/records/lexicon/availability.md)

Conflicts with
[Independent Node Decisions](https://banes-lab.com/records/lexicon/independent-node-decisions.md)

Referenced by
[Total-Order Broadcast](https://banes-lab.com/records/architecture/total-order-broadcast.md), [Leader Election](https://banes-lab.com/records/architecture/leader-election.md)

Tensions
[Consensus / Latency](https://banes-lab.com/records/tension/consensus-latency.md), [Consensus / Availability](https://banes-lab.com/records/tension/availability-consensus.md)

Distinct from
[Leader Election](https://banes-lab.com/records/architecture/leader-election.md): Consensus commits one value across a quorum, while leader election uses it to agree on one coordinator and replace it when it fails.

Distinct from
[Total-Order Broadcast](https://banes-lab.com/records/architecture/total-order-broadcast.md): Consensus agrees on one value, while total-order broadcast agrees on the order of every message.

Violated by
nodes committing values without quorum agreement

Detected by
divergent committed state across replicas

Measured by
agreement-violation rate

Refactored by
Adopt a Consensus Protocol

Enforced by
distributed-systems review

Before

```typescript
fooNodeA.setValue(value);
```

After

```typescript
const committed = await fooCluster.propose(value, { quorum: majority(fooNodes) });
if (!committed.accepted) throw new NoQuorumError();
```

How it is checked

Checked by
distributed-systems review

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Quorum](https://banes-lab.com/records/lexicon/quorum.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Agreed Single Value Across Nodes](https://banes-lab.com/records/lexicon/agreed-single-value-across-nodes.md)

Shape it refuses
[Independent Node Decisions](https://banes-lab.com/records/lexicon/independent-node-decisions.md)

### Choreography

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Control / Coordination / Centralization](https://banes-lab.com/ontology/principles/architecture-category-control-coordination-centralization.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: distributed system, coordination, event
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A mechanism that coordinates a cross-service flow through events, with each service reacting to the previous one's event.

Requires
[Event-Driven Architecture](https://banes-lab.com/records/architecture/event-driven-architecture.md)

Reinforces
[Decentralization](https://banes-lab.com/records/architecture/decentralization.md), [Autonomy](https://banes-lab.com/records/architecture/autonomy.md)

Enables
[Central-Orchestrator-Free Coordination](https://banes-lab.com/records/lexicon/central-orchestrator-free-coordination.md)

In tension with
[Traceability](https://banes-lab.com/records/architecture/traceability.md)

Conflicts with
[Central Orchestrator Bottleneck](https://banes-lab.com/records/lexicon/central-orchestrator-bottleneck.md)

Tensions
[Choreography / Traceability](https://banes-lab.com/records/tension/choreography-traceability.md)

Violated by
one orchestrator commanding every step of a cross-service flow

Detected by
a central coordinator coupled to all participants

Measured by
orchestrator fan-out coupling

Refactored by
Coordinate via Choreographed Events

Enforced by
[architecture review](https://banes-lab.com/records/architecture/architecture-review.md)

Before

```typescript
await orchestrator.run("CreateFoo", [
() => createFoo(foo),
() => reserveBar(foo),
() => notifyBaz(foo),
]);
```

After

```typescript
fooEvents.on("FooCreated", event => barService.reserve(event.fooId));
barEvents.on("BarReserved", event => bazService.notify(event.fooId));
```

How it is checked

Checked by
architecture review

Population
Every node, service and workflow step that shares configuration, identity, logs, leadership or agreement

Freshness
A verdict stands until membership, topology or the coordinating policy changes

Refusal
The workflow test or the platform policy rejects a participant that bypasses the coordinator or the agreed value

Observation
The control plane's recorded state compared with each participant's reported state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The control plane's recorded state, which each participant's reported state is compared against

Depends on
[Event-Driven Architecture](https://banes-lab.com/records/architecture/event-driven-architecture.md), [Decentralization](https://banes-lab.com/records/architecture/decentralization.md), [Autonomy](https://banes-lab.com/records/architecture/autonomy.md), [Central-Orchestrator-Free Coordination](https://banes-lab.com/records/lexicon/central-orchestrator-free-coordination.md)

Shape it refuses
[Central Orchestrator Bottleneck](https://banes-lab.com/records/lexicon/central-orchestrator-bottleneck.md)

## Links to

- [artifact](https://banes-lab.com/records/kind/artifact.md)
- [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- [Execution Core](https://banes-lab.com/records/layer/execution-core.md)
- [Management API](https://banes-lab.com/records/lexicon/management-api.md)
- [Policy](https://banes-lab.com/records/lexicon/policy.md)
- [Governance](https://banes-lab.com/records/architecture/governance.md)
- [Orchestration](https://banes-lab.com/records/architecture/orchestration.md)
- [Centralized Control of Distributed Runtime](https://banes-lab.com/records/lexicon/centralized-control-of-distributed-runtime.md)
- [Availability](https://banes-lab.com/records/lexicon/availability.md)
- [Fully Decentralized Control](https://banes-lab.com/records/lexicon/fully-decentralized-control.md)
- [Leader Election](https://banes-lab.com/records/architecture/leader-election.md)
- [Control Plane](https://banes-lab.com/records/algorithms/control-plane.md)
- [Control Plane / Availability](https://banes-lab.com/records/tension/availability-control-plane.md)
- [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- [Coordinator](https://banes-lab.com/records/lexicon/coordinator.md)
- [Control Plane](https://banes-lab.com/records/architecture/control-plane.md)
- [Saga](https://banes-lab.com/records/lexicon/saga.md)
- [Ordered Multi-Step Execution](https://banes-lab.com/records/lexicon/ordered-multi-step-execution.md)
- [Centralized Coordinator Coupling](https://banes-lab.com/records/lexicon/centralized-coordinator-coupling.md)
- [Pure Choreography](https://banes-lab.com/records/lexicon/pure-choreography.md)
- [Workflow Creation Kernel](https://banes-lab.com/records/algorithms/workflow-creation-kernel.md)
- [Orchestration / Centralized Coordinator Coupling](https://banes-lab.com/records/tension/centralized-coordinator-coupling-orchestration.md)
- [pattern](https://banes-lab.com/records/kind/pattern.md)
- [Config Store](https://banes-lab.com/records/lexicon/config-store.md)
- [Access Control](https://banes-lab.com/records/architecture/access-control.md)
- [Consistency](https://banes-lab.com/records/architecture/consistency.md)
- [Unified Config Management](https://banes-lab.com/records/lexicon/unified-config-management.md)
- [Central Dependency Risk](https://banes-lab.com/records/lexicon/central-dependency-risk.md)
- [Scattered Configuration](https://banes-lab.com/records/lexicon/scattered-configuration.md)
- [Centralized Configuration / Central Dependency Risk](https://banes-lab.com/records/tension/central-dependency-risk-centralized-configuration.md)
- [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- [Identity Provider](https://banes-lab.com/records/lexicon/identity-provider.md)
- [Security](https://banes-lab.com/records/lexicon/security.md)
- [Unified Identity](https://banes-lab.com/records/lexicon/unified-identity.md)
- [Identity Provider Availability](https://banes-lab.com/records/lexicon/identity-provider-availability.md)
- [Scattered Auth Implementations](https://banes-lab.com/records/lexicon/scattered-auth-implementations.md)
- [Centralized Authentication / Identity Provider Availability](https://banes-lab.com/records/tension/centralized-authentication-identity-provider-availability.md)
- [Security Policy](https://banes-lab.com/records/algorithms/security-policy.md)
- [Log Aggregation](https://banes-lab.com/records/lexicon/log-aggregation.md)
- [Observability](https://banes-lab.com/records/architecture/observability.md)
- [Auditability](https://banes-lab.com/records/architecture/auditability.md)
- [Cross-Service Analysis](https://banes-lab.com/records/lexicon/cross-service-analysis.md)
- [Cost/Personal Data Exposure](https://banes-lab.com/records/lexicon/cost-personal-data-exposure.md)
- [Local-Only Logs](https://banes-lab.com/records/lexicon/local-only-logs.md)
- [Centralized Logging / Cost/Personal Data Exposure](https://banes-lab.com/records/tension/centralized-logging-cost-personal-data-exposure.md)
- [principle](https://banes-lab.com/records/kind/principle.md)
- [Autonomy](https://banes-lab.com/records/architecture/autonomy.md)
- [Contracts](https://banes-lab.com/records/lexicon/contracts.md)
- [Microservices](https://banes-lab.com/records/architecture/microservices.md)
- [Resilience](https://banes-lab.com/records/architecture/resilience.md)
- [Independent Ownership](https://banes-lab.com/records/lexicon/independent-ownership.md)
- [Centralized Control](https://banes-lab.com/records/lexicon/centralized-control.md)
- [Choreography](https://banes-lab.com/records/architecture/choreography.md)
- [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)
- [Decentralization / Governance](https://banes-lab.com/records/tension/decentralization-governance.md)
- [Decentralization / Consistency](https://banes-lab.com/records/tension/consistency-decentralization.md)
- [Consensus](https://banes-lab.com/records/architecture/consensus.md)
- [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md)
- [Single-Writer Coordination](https://banes-lab.com/records/lexicon/single-writer-coordination.md)
- [Automatic Failover of Leadership](https://banes-lab.com/records/lexicon/automatic-failover-of-leadership.md)
- [Split-Brain Coordination](https://banes-lab.com/records/lexicon/split-brain-coordination.md)
- [Leader Election / Availability](https://banes-lab.com/records/tension/availability-leader-election.md)
- [Quorum](https://banes-lab.com/records/lexicon/quorum.md)
- [Agreed Single Value Across Nodes](https://banes-lab.com/records/lexicon/agreed-single-value-across-nodes.md)
- [Latency](https://banes-lab.com/records/architecture/latency.md)
- [Independent Node Decisions](https://banes-lab.com/records/lexicon/independent-node-decisions.md)
- [Total-Order Broadcast](https://banes-lab.com/records/architecture/total-order-broadcast.md)
- [Consensus / Latency](https://banes-lab.com/records/tension/consensus-latency.md)
- [Consensus / Availability](https://banes-lab.com/records/tension/availability-consensus.md)
- [Event-Driven Architecture](https://banes-lab.com/records/architecture/event-driven-architecture.md)
- [Decentralization](https://banes-lab.com/records/architecture/decentralization.md)
- [Central-Orchestrator-Free Coordination](https://banes-lab.com/records/lexicon/central-orchestrator-free-coordination.md)
- [Traceability](https://banes-lab.com/records/architecture/traceability.md)
- [Central Orchestrator Bottleneck](https://banes-lab.com/records/lexicon/central-orchestrator-bottleneck.md)
- [Choreography / Traceability](https://banes-lab.com/records/tension/choreography-traceability.md)
- [Architecture Review](https://banes-lab.com/records/architecture/architecture-review.md)

## Linked from

- [The layer topology](https://banes-lab.com/ontology/schema/the-layer-topology.md)
- [The membership](https://banes-lab.com/ontology/schema/the-membership.md)
