The whole system
Video stays inside the shop. Only visit records cross the boundary — and every connection across it is made from the inside, outward.
Inside the shop PC
Three processes on one machine, each in the language its job is best done in, sharing one state root.
Recognition: one decision per visit
Frames become tracks; tracks accumulate evidence; a track is identified once. A "not sure" outcome is what stops one person becoming three, and a stranger becoming a regular.
Delivery: durable before published
Nothing is removed from the shop's disk until the broker has confirmed it, and the server drops what it has already seen. That pair is what makes an outage a delay and not a hole.
Local gallery, master database
Two stores with two jobs. The shop PC's gallery recognises people in that shop, offline if need be. The platform's database knows the business: customers across shops, history, reports, tenancy.
seq, never by the camera's clock: lossless under bursts and backlogs; cursors are opaque.Clients and the API
Three kinds of people and one kind of machine, all through one API. Sessions are opaque tokens in a table, so "log that device out, now" actually works.
Onboarding: each tier creates the next
No credential ships inside an installer, and nobody creates their own account from nothing.
Where every secret lives
Biometric data is treated as biometric data. Each credential has one home and one protection, and none of them is ever returned by an API.
The stack, and the numbers behind it
Each layer, the choice, and the one reason that decided it.