Skip to content

Documentation model

VerifiedOwner Documentation integratorLast verified onix-docs@a2-publication

Two decisions shape everything on this site: one authority per fact, and declared omission rather than silent omission.

The first is an architecture rule described on the authority model page. The second is a documentation rule, and it is what this page is about.

Declared omission

Plenty of material about ONIX exists and is not published here. Operational runbooks, alerting configuration, monitor inventories, incident history, and security and administration internals are all deliberately withheld.

Withholding them is uncontroversial. Withholding them quietly is not: a reader cannot distinguish "this system has no security model" from "the security model is not published", and the first reading is both wrong and damaging.

So the content is withheld and the fact of withholding is published. The register below is complete. Every item names what was withheld and why.

The quarantine register

Fourteen pages from the previous documentation set are quarantined. None of them is published, none is reachable from this site, and none is a build input — they live outside the directory the site is built from, which is a structural guarantee rather than a procedural one.

Legacy page Title Reason withheld
onix.site.developer.agent-worktree-protocol Agent and worktree protocol Internal engineering process; not part of the public product documentation.
onix.site.identity-venues.identity-incidents Identity incidents Incident history is internal operational evidence.
onix.site.operations.critical-alerting Critical alerting Operational alerting exposes private topology and internal response procedures.
onix.site.operations.deployment-recovery Deployment and recovery Deployment and recovery runbooks expose private topology.
onix.site.operations.index Operations Operations section is internal.
onix.site.operations.monitors Monitor registry and dispatch Monitor inventory is internal operational evidence.
onix.site.operations.notifications Notifications and routing Notification wiring is internal operational evidence.
onix.site.security-admin.admin-guide Admin guide Administrative guidance withheld pending implementation and disclosure review.
onix.site.security-admin.index Security and admin Security section withheld pending disclosure review.
onix.site.security-admin.roles-permissions Roles and permissions Authorization model withheld pending implementation and disclosure review.
onix.site.security-admin.security-overview Security overview Security boundary withheld pending disclosure review.
onix.site.security-admin.sessions-login-2fa Sessions, login and two-factor authentication Session and authentication detail withheld pending disclosure review.
onix.site.security-admin.socket-authentication Realtime authentication Realtime authentication detail withheld pending disclosure review.
onix.site.security-admin.tokens-api-keys API keys and agent tokens Token and API-key handling withheld pending disclosure review.

The security and administration group shares one condition for release: the implementation must be current and a disclosure review must be completed. Neither had happened at the pinned commits. Publishing an authorization model that does not match the running system would be worse than publishing nothing.

The public half of the operational health model is published, at health and status contract, because a contract about what a health surface means carries no operational risk while a monitor inventory does.

Retirement, and why retired pages still have URLs

Three pages describe things that were removed on purpose: a TypeScript venue-adapter prototype, a TypeScript compile and isolation gate, and a TypeScript strategy runtime.

They are not quietly deleted. A reader who remembers them needs to be told they are gone and what replaced them, so their old URLs redirect to the page that explains the retirement. Deleting a URL destroys that explanation; redirecting it preserves it.

The full closure

Every page of the previous 61-page set resolves to exactly one outcome. There is no sixth category and no silent drop — the generator that produces the route contract fails if a page is unaccounted for.

Outcome Count What it means
Published 34 Rewritten against current evidence and live at a route.
Merged 9 Folded into another published page; the old URL redirects there.
Retired 3 Removed on purpose; the old URL redirects to the explanation.
Split 1 The classification required two separately owned destinations; both are published, and the old URL redirects to an index linking them.
Quarantined 14 Withheld, with the reason above.
Total 61

The current site publishes 58 pages, more than the rewritten ones, because several new cross-cutting pages were added — the status model, the authority model, the capability register, the generated API navigation and this page among them.

Accounted for is not closed

All 61 rows are accounted for. 45 are fully closed. Two are published and still carry an unmet prerequisite, and the contract names them rather than rounding up:

  • Native clients. The classification required unambiguous repository references for both native clients. The iOS client has none: two candidate commits exist and neither is canonical. The pages are published with that blocker stated and an unverified status.
  • Live market projection. The classification asked for observed stream evidence before any present-tense claim about the projection lifecycle. This documentation pass read Git objects and started no process, so that evidence does not exist and no present-tense claim is made.

The classification also asked, on most rows, for a named repository owner's sign-off before publication. There were no separate repository owners in this pass. What was produced instead — evidence packets bound to Git blob ids, plus an independent verification and disclosure challenge against the same objects — is recorded once in the route contract with obtained: false. It is review, and it is not the same thing as sign-off. No page here claims an owner approved it.

What "published" does not mean

A published page is not a guarantee. It is a claim about a specific commit, on a specific date, at a specific confidence level, with its evidence named. The status model explains how to read that grading, and the capability register collects every claim with its status in one table — including the ones marked unverified.

Screenshots and third-party material

This site contains no product screenshots. Screenshots of a live trading system risk exposing account state, instrument holdings and private topology, and they go stale invisibly. Where a visual would help, a diagram is used instead, and the diagram never carries information absent from the prose.

No upstream NautilusTrader documentation and no licensed charting-library documentation or imagery is reproduced here. Those are linked. See upstream reference discipline.

Evidence and source pins for this page

Verified. Current behaviour, confirmed in source at the pinned commit.

Verified on against the following immutable sources:

  • onix-docs:manifest/page-route-contract.json
  • onix-docs:manifest/a1-61-page-disposition-matrix.json

Status tokens are defined on the documentation and status model page. Every pin on this site is listed under versions and source pins.