Commitment and replay
Understand off-chain commitment, durable execution history and recovery.
What an execution commitment means
The execution engine orders commands and applies their outcomes off-chain. A committed reply is released only when the outcome reaches the required applied and replicated durability boundary. Replies preserve that order: a later committed response cannot overtake an earlier outcome that is still awaiting commitment.
Off-chain commitment and Canton settlement are separate completion states. An accepted request, an applied outcome, a durably committed outcome and a settled ledger effect are not interchangeable measurements. Use the order lifecycle to distinguish these stages in your application.
Execution commitment
Execution commitment
Drag to pan, or use arrow keys when the diagram is focused. Use plus and minus to zoom, and zero to fit. On a touch screen, pinch to zoom.
Command application, journal recording and replication work together to establish a committed outcome. Responses remain ordered while they wait for that boundary.
Durable execution. A reply marked committed requires the relevant outcome to be applied and durably replicated.
Asynchronous settlement. Canton confirmation follows separately; it is not a prerequisite for the off-chain execution reply.
Verified recovery. Snapshots and replay reconstruct state from the same execution history.
Recovery preserves committed history
Recovery validates snapshots against the execution journal before using them. When a snapshot cannot be verified, validated journal replay reconstructs the state. Read projections can be rebuilt from committed evidence without redefining the original execution outcome.
For clients, reconnection alone does not make a saved value current. Validate identity, sequence and replay information before applying updates. If continuity is missing, retain the last-known value with a stale state until supported recovery restores it.
Read acknowledgements by layer
Each acknowledgement answers a specific question. A transport acknowledgement concerns message delivery or storage. A query-model commit concerns a derived view. An execution commitment confirms the defined off-chain durability boundary. Canton confirmation establishes the relevant ledger fact.
Display the state appropriate to the operation: submitted, accepted, filled, rejected or unresolved for order activity, and the documented settlement status for ledger progression. See account streams and settlement.