Expand description
ApprovalEscalator — resolves approval gates whose SLA deadline expired.
An approval gate configured with
ApprovalConfig::with_deadline
stores its deadline on the step itself, so the timer survives an API or
worker restart: nothing is held in memory, and a brand-new process picks the
gate up on its next tick.
ApprovalEscalator::tick claims every gate whose deadline has passed and
applies the configured EscalationPolicy. The claim clears the timer in
the same transaction, so a deadline fires at most once even with several
API instances running an escalator. A process that dies between the claim and
the escalation leaves the gate open with no timer — the same trade-off the
lease reaper accepts.
Every firing publishes an Event::ApprovalEscalated, which the
AuditLogSubscriber persists with the
reason, so the escalation history of a gate is always reconstructable.
Structs§
- Approval
Escalator - Resolves approval gates whose deadline expired.
- Escalation
Record - Outcome of escalating one gate, returned by
ApprovalEscalator::tick.
Enums§
- Escalation
Action - What an escalation did to a gate.
Constants§
- APPROVAL_
TIMEOUT_ ERROR - Error recorded on a step and run auto-rejected after an SLA breach.
- DEFAULT_
ESCALATION_ BATCH_ SIZE - How many gates a single
ApprovalEscalator::tickresolves. - SYSTEM_
TIMEOUT_ ACTOR - Actor recorded on a gate resolved by the escalator rather than a human.