Rule Cascade
Get started

What Rule Cascade is

One rule contract, compiled once and evaluated by the same pure function in the browser, the backend and any other language.

One rule, written once: before, three teams code the same rule three different ways; after, the UI, the API, a batch job and an AI agent all read one contract and give the same answer

The problem it solves

A business rule such as "a retail transfer may not exceed 25,000 unless a risk officer accepts the risk" usually exists three times: in the form, in the API and in a batch job, each written by a different team in a different language. The copies drift. Rule Cascade keeps one copy, as data, and gives every place that must enforce it an engine that reads that data and returns the same answer.

How it works

Compile once, evaluate anywhere: an author writes YAML, a compiler checks it and seals one bundle, and six engines read that bundle and give the same answer

  1. Write. A ruleset is a YAML or JSON document: where it sits in the organisation (scope), what it inherits (extends), the rules, the messages users see, and golden tests.
  2. Check. The compiler validates the document against the JSON Schema, resolves inheritance, checks every data path against your OpenAPI schema and runs the golden tests. It refuses anything that is wrong. This happens in CI.
  3. Seal. The result is a bundle: one immutable JSON file with a SHA-256 checksum. It holds a server manifest and a client manifest that contains only what a browser may see.
  4. Evaluate. An engine is a pure function, (manifest, request) → decision, findings, effects, commands. It reads no clock, no network and no file. The browser evaluates the client manifest for immediate feedback; the server evaluates the server manifest for the decision.

A client evaluation is advice. The server decides, always.

The vocabulary

TermMeaning
RulesetThe source document, YAML or JSON. Identified by metadata.id and metadata.version
RuleOne validation, state, compute or action rule, with a target (entity, page, screen, section, component, field, or data type) and the operations it applies to
FindingWhat a failed validation rule produces: a stable code, a severity (info, warning, error), the field pointers, a message, whether it is blocking
EffectA field state (visible, enabled, required, readOnly) or a computed value
CommandWhat an action rule asks the host to do after a successful save, with an idempotencyKey
BundleThe compiled ruleset: server and client manifest, version and checksum
Channelserver (every rule) or client (rules with enforcement: client or both, no action rules)
ResolutionThe user's answer to a finding: acknowledge a warning, or accept-risk on an error with a justification

The engines

EngineUse it inPage
TypeScriptBrowsers, Node.js, React (hook), React NativeTypeScript
JavaSpring Boot and any JVM, Java 17+Java
GoGo services; also the command and the WebAssembly moduleGo
PythonServices and jobs; the reference implementationPython
Command rule-cascadeCI, and any language that can start a processCommand and WebAssembly
WebAssembly rule-cascade.wasmAny WASI preview 1 hostCommand and WebAssembly
Rule serverAnything that speaks HTTPRule server

What it guarantees

  • No implicit conversion. 1 is not "1"; null is not false. A wrong type is an evaluation error and the rule blocks.
  • Decimal arithmetic. 0.1 + 0.2 is 0.3 in every engine.
  • Fails closed. A rule that cannot be evaluated produces a blocking RULE-EVALUATION-ERROR finding. It is never skipped.
  • Nothing ships unchecked. Unknown paths, operators and parameters, duplicate ids, illegal overrides, missing messages and failing golden tests stop the build.
  • Server-only rules stay on the server. The client manifest carries no enforcement: server rule and no action rule.

The complete list, with the error code that enforces each item, is in the authoring guidelines; the exact semantics are in the specification.

Next

Run the quickstart: five minutes from an empty directory to an evaluated request.

Source: site/content/docs/get-started/what-it-is.mdx

On this page