# Architecture decisions

## Boundary rule

Routes translate HTTP requests and responses only. Services own application use cases. Models describe persistence. Schemas define explicit contracts. This separation keeps future modules independently testable and limits coupling as the system grows.

## Persistence rule

PostgreSQL is the system of record. SQLAlchemy models are changed only with an accompanying Alembic migration. The declarative-base naming convention creates stable constraint names for safe migrations.

## Identity rule

JWT creation and validation live in `app.core.security`. Authentication dependencies and authorization policies belong to the future identity bounded context, not in endpoint handlers.

## Tenant and audit readiness

Church, campus, and ministry scoping must be explicit in every future domain model and query. Add immutable audit fields and actor attribution consistently through a shared persistence mixin when the first regulated domain is introduced.
