Worker-level approval service sharing the DO's D1 database. Decisions
resume the run through the injected topology (grants come from the store
via the DO-side provider, never from this request); if the resumed run
suspends again at a later gate, the next approval is queued right here, so
multi-gate workflows keep flowing through the queue.
One audit sink instance backs both the service's own trail and the
bridge's re-queue-failure signal: a re-queue that fails after a durable
resume is reported through it rather than silently absorbed.
Worker-level approval service sharing the DO's D1 database. Decisions resume the run through the injected topology (grants come from the store via the DO-side provider, never from this request); if the resumed run suspends again at a later gate, the next approval is queued right here, so multi-gate workflows keep flowing through the queue.
One audit sink instance backs both the service's own trail and the bridge's re-queue-failure signal: a re-queue that fails after a durable resume is reported through it rather than silently absorbed.