Architecture

Why a platform outage won't take down your live stores

Reqursor's own control and AI layers can go down without your stores going down with them, because a live store doesn't depend on them to keep serving traffic.

Architecture introduced the three-layer split at a glance. This page answers the question that follows naturally: if Reqursor's own systems have a problem, what happens to the stores already live on the platform?

The short answer: they keep running

A live store is a running, independent piece of infrastructure. Once it's deployed, it doesn't call back to Reqursor's brain to keep serving visitors, taking orders, or doing anything else it was built to do. It depends on the servers it's actually hosted on, not on Reqursor's AI, its record-keeping, or its dashboard being reachable at that exact moment.

What actually happens if each piece is unavailable

If this has a problemWhat happens to your live stores
The AI / conversational assistantAI features pause: no new drafts, no diagnoses, no chat. Every store already live keeps running, and scheduled monitoring, drift checks, and rollback all keep working.
Where declarations are recordedNew deployments and changes pause. Stores already running are completely unaffected.
The registry that stores verified software versionsNew deployments pause unless the needed version is already available locally. Running stores are unaffected.
Domain routingRunning stores keep serving as normal once their routing is established; only brand-new domain setup is affected.
Secure credential storageDeployments that need a credential pause. Stores already running keep using what they already have.

The one genuine exception

The servers a store's pieces actually run on are the one thing truly critical to that specific store staying up, the same as with any hosting arrangement. That's a different kind of event than "Reqursor is having a problem," and it's exactly what per-store isolation keeps contained to one store at a time, not your whole fleet.

Why this separation is deliberate

This isn't luck: it follows directly from the deterministic engine's two-halves design. The AI proposes, and a separate engine executes and keeps stores running. Because a live store's day-to-day operation was never wired to depend on the AI or the platform's own coordination layer, an outage in those systems degrades what you can change. It never touches what's already running.

Why this matters for your agency

  • Your clients' stores keep taking orders during a Reqursor incident. Checkout doesn't pause because Reqursor's own dashboard had a bad day.
  • Monitoring doesn't stop watching. Scheduled drift checks and health monitoring keep running even if AI features are degraded.
  • One kind of failure stays one kind of failure. A platform issue is an inconvenience to your workflow, not an outage on your storefronts.

Where to go next