| Invocation state | one managed cognition call | until the call ends | web/worker seeds validated JSON; ADK output_key and event state_delta add handoffs | coordinator and selected specialists | discarded after validation | no; typed transport only |
| Managed ADK session | hashed workspace/user/job/operation/specialist | restart-resumable cognitive operation | Agent Engine event lifecycle only | managed runner for that operation | provider/deployment session lifecycle; job erasure remains Firestore/storage scoped | no; never workflow authority |
| Firestore job | workspace + brand + job | workflow plus explicit retention policy | authenticated web internal routes and deterministic state machine | dashboard, worker, chat, evidence collector | terminal jobs receive a 90-day deletion deadline; holds block erasure | yes for stage, status, Temi’s immutable planning snapshot and digest, the complete Temi editorial plan and digest/lineage, selected item lifecycle, artifacts, budget, and failure |
| Approval decisions | workspace + job + action | durable audit record | authenticated decision engine after explicit operator input | publish stage, UI, evidence collector | retained with the job/audit record | yes for human authority |
| Receipts and verification | workspace + job + action/idempotency key | durable and replay-relevant | deterministic executor writes receipt; independent verifier writes verification | worker, UI, monitoring, evidence collector | retained through judging and deployment audit policy | yes for effects and observed outcome |
| Usage and reservations | workspace + job + operation | durable, immutable after finalization | budget service and provider usage normalizer | dispatcher, monitoring, evidence verifier | deployment accounting policy | yes for authorized/observed cost |
| Chat history | workspace + authenticated user + interface + conversation | bounded conversational continuity | dashboard or allow-listed Telegram path | the same scoped operator/interface/conversation | maximum 300 messages; pruning stores metadata-only turn/time and linked-ID boundaries | no; cannot grant approval or reconstruct job state |
| Memory Bank | exact workspace + brand | cross-session eligible knowledge | learn path writes only typed, evidence-linked decisions and verified outcomes | bounded analysis/strategy/drafting retrieval with fact IDs and Firestore provenance | provider/deployment policy, maximum five facts per retrieval/write | no; advisory context never grants authority |
| Secrets | deployment or workspace integration | until rotation/revocation | deployment operator or authenticated connection flow | server-side minimum-permission adapters | secret-manager/rotation policy | yes for credentials; never copied to state, telemetry, chat, or evidence bundles |
| Private evidence | one authorized demo/evaluation run | submission and judging evidence period | read-only collector and operator capture procedure | submission team and judges as authorized | private parent workspace; frozen at submission deadline | yes for claims, paired with authenticated provider exports |