Engineering
How we build Bladbase
Bladbase exists because decisions get made in chat and lost by Thursday. These are ours: the real architecture decision records from the repository, in the shape the product stores them — a type, a status, the context that forced the choice, and what it cost.
ADR-0014: Handwriting is read by a multimodal model the workspace chooses, behind one interface
acceptedThe scan plan (2026-09-20) asked for a photographed handwritten page to become a Markdown page, keeping the formatting a person wrote on paper — # headings, - lists, [ ] tasks, bold, tables ruled by hand — with the ph…
ADR-0013: A group decides which pages, a role decides what you may do; a restriction covers the branch; the repository is the source
acceptedPhase 16 asked three questions that each had a cheap answer and a right one.
ADR-0012: A decision records what it assumed, a runbook records its runs, and both append rather than rewrite
acceptedTwo kinds of page were losing their most useful information because they had nowhere to put it.
ADR-0011: The CLI signs in through the browser and mints at exchange
acceptedConnecting an agent to a workspace was a settings page, a paste into a config file whose shape differs per agent, and a token that reaches the wrong workspace without anyone noticing — the endpoint is one URL for ever…
ADR-0010: A request for changes is a comment, not a status
acceptedAn approver reading an ADR had two answers: accept, or reject with a note. Neither says "yes, but change the rollback section." That answer went into an ordinary comment, which an agent would never see unless a person…
ADR-0009: A page opens to read; editing is a state a person enters
acceptedAn editor who opened a page got the editor at once. The server load signed a collab ticket for anyone with page.edit, the client joined the WebSocket room on mount, and the Tiptap bundle loaded — whether the person ha…
ADR-0008: The tree marks, the work list filters
acceptedA workspace accumulates finished work. Every completed plan, accepted ADR and approved brief stays where it was, and after a few months the page tree is mostly things nobody needs to open. The tree drew no status at a…
ADR-0007: Comment anchors are sections and tasks, not editor ranges
acceptedThe comment record has carried an anchor field since Phase 4, documented as a "ProseMirror/Yjs-relative range anchor; null = page-level thread". Nothing ever wrote it. The web use case and the MCP add_comment tool bot…
ADR-0006: Rate-limit counters live in RTDB
acceptedThe MCP service limits each token to 120 requests a minute, and /developers says so. Until now the counter was a Map in the process, so on Cloud Run the real limit was 120 × the number of instances serving that token…
ADR-0005: Service members
AcceptedAn MCP token today binds to a human. apiTokenSchema carries a userId, and every request resolves getMember(db, token.workspaceId, token.userId) (apps/mcp/src/index.ts), so an unattended system acts with a real person'…
ADR-0004: Storage portability and what "self-hosting" promises
acceptedBladbase is Firebase-native by design (Strategy §8): Firestore for metadata, Cloud Storage for document content, RTDB for presence, Firebase Auth for identity, Cloud Tasks for async work, Typesense for search. That ch…
ADR-0003: MCP writes to live-edited pages are rejected
PLAN Phase 6 required an explicit choice: reject, or apply API writes as Yjs updates through the collab service. A live room's in-memory Y.Doc is the authority while editors are connected; writing beneath it silently…
ADR-0002: UI framework and styling strategy
The product needs a dense, quiet, keyboard-first UI (Outline/Docmost class) with heavy customization of editor chrome, page tree, and command palette. Most polished component libraries are React-only; the SvelteKit ch…
ADR-0001: Yjs collaboration service on Cloud Run
AcceptedStrategy §13 calls for authenticated Yjs rooms over WebSockets. Cloud Run supports WebSockets but has properties that could disqualify it: instances are ephemeral, requests have a max timeout (configurable to 60 min),…
Everything above is a page of the same kind your workspace holds — an agent can read them over MCP, and a person can approve a change to one. Try the beta to keep your own.
References
- Architecture decision records — the convention these follow
- Documenting architecture decisions — Michael Nygard, who proposed the format