# Architecture Decision Records

Each record captures a decision that would be expensive to reverse, the reason
it was made, and what it cost. They exist so a maintainer in 2031 can tell the
difference between a deliberate choice and an accident — and so an argument that
was already settled is not re-litigated every six months.

Decisions D1–D12 were raised in `docs/ARCHITECTURE.md` §19 and approved
2026-08-01.

| # | Decision | Status |
|---|---|---|
| [0001](0001-custom-module-kernel.md) | Own the module kernel rather than take a package | Accepted |
| [0002](0002-license-degrades-never-locks.md) | A lapsed licence degrades administration, never patient care | Accepted |
| [0003](0003-repositories-and-query-objects.md) | Repositories for writes, query objects for complex reads | Accepted |
| [0004](0004-identifiers-money-and-time.md) | ULIDs, integer minor units, UTC | Accepted |
| [0005](0005-tamper-evident-audit-trail.md) | Hash-chained, append-only audit trail | Accepted |
| [0006](0006-mysql-floor-and-test-database.md) | MySQL 8 floor; tests run on MySQL | Accepted |
| [0007](0007-branding-decoupled-from-namespaces.md) | Product name is configuration, not a namespace | Accepted |
| [0008](0008-privilege-escalation-guard.md) | Escalation rules live in the service layer, not in policies | Accepted |
| [0009](0009-patient-identity-and-duplicates.md) | Duplicate patients are prevented at registration, in two tiers | Accepted |
| [0010](0010-clinical-records-are-append-only.md) | Clinical records are retracted, never deleted | Accepted |
| [0011](0011-scheduling-time-and-concurrency.md) | Local rotas, UTC bookings, three defences against double-booking | Accepted |
| [0012](0012-cross-module-directories.md) | Modules read each other through directories, not relations | Accepted |
| [0013](0013-clinical-notes-are-versioned.md) | Signed clinical notes are versioned, never rewritten | Accepted |
| [0014](0014-allergy-checking-is-name-matching.md) | Allergy checking is name matching, and says so | Accepted |
| [0015](0015-screen-slots-for-module-panels.md) | Modules extend each other's screens through named slots | Accepted |
| [0016](0016-money-and-financial-corrections.md) | Integer money, stored totals, and corrections that never edit | Accepted |
| [0017](0017-laboratory-results-and-the-charging-port.md) | Reference ranges belong to populations; results are released, not saved | Accepted |

Remaining approved decisions with no separate record, because the reasoning is
already stated in full in `docs/ARCHITECTURE.md`: D2 (English + Arabic with RTL
from day one), D5 (plain PHP in v1, no source encoder), D6 (Fortify for auth
primitives), D8 (opt-in telemetry, aggregate counts only), D9 (two repositories),
D11 (multi-tax-capable schema, single-tax UI).
