Responsibilities in the ecosystem
A reliable extension depends on an explicit separation of responsibilities between Ormuz, the extension publisher, and the merchant who installs it. No partnership level should blur these boundaries.
Ormuz responsibilities
- provide stable, verifiable public contracts for partner contributions;
- isolate merchants and propagate trusted execution context without delegating it to the model or plugin;
- enforce permissions, authority limits, and platform-object resolution rules;
- preserve canonical contracts for objects, events, nodes, and tools;
- make effects, errors, and warnings observable according to the platform's public guarantees.
Partner responsibilities
- declare only capabilities that the extension actually supports;
- adapt external contracts to Ormuz types without weakening business invariants;
- never bypass permissions, authority, or merchant isolation;
- design nodes and tools whose effects, prerequisites, and errors are understandable;
- preserve idempotency, provenance, and correlation when the operation contract requires them;
- document from established sources rather than inventing false precision.
Merchant responsibilities
- install and configure the extensions whose capabilities it wants to use;
- provide the credentials or parameters it owns;
- grant the explicit permissions required by a node's opaque access;
- compose processes and Agent activities within the limits of declared contracts;
- choose its systems of record and operational partners within the framework supported by Ormuz.
What a partnership does not change
A more advanced commercial relationship may provide additional support, visibility, or collaboration processes. It cannot turn an extension into a platform super-user.
Effective rights remain determined by runtime contracts: explicitly supplied parameters, declared permissions, existing mappings, merchant consent, authority rules, data classification, and Tool risk level.