Browse documentation
Coming from Elixir or Erlang
Start with state owners and messages, then make durability and authority explicit.
The actor model gives you a familiar starting point: state belongs to an actor, messages cross its boundary, and handlers define how that state changes. Septa combines this shape with a Rust profile, typed contracts, durable progress and scoped authority.
Start by separating an actor’s identity from the process currently executing it. An actor can remain the same durable state owner when a later process opens its history.
Translate the familiar concepts
| Familiar idea | Septa connection | What to check |
|---|---|---|
| A process that owns state | A durable actor | State representation, message contract and persistence rules |
| Cast | A message without a typed reply | Admission and delivery behaviour |
| Call | A request with a typed reply | Caller authority, reply ownership and failure behaviour |
| Supervision | Explicit lifecycle and recovery policies | The particular policy supported by your runtime version |
| Process inspection | Source-connected state and execution inspection | Who may inspect, and what retained evidence covers |
This is a bridge between mental models, not BEAM compatibility. Distribution, selective receive, reentrancy, shutdown and supervision have their own contracts. An actor abstraction does not automatically supply all of them.
Durability changes the unit of reasoning
In the first actor tutorial, each command starts a new process. The count remains available because the state directory holds the node’s persisted history. The actor is more than the process that happens to execute a handler.
A workflow is a related shape for work that progresses toward completion: record a request, wait for approval, then continue. Actors suit services that keep receiving messages; workflows suit a piece of work with a place to resume.
A message also has an authority context
A typed operation tells you what a message means. Scoped grants and admission checks determine whether this caller may request it. A typed capability handle does not itself confer that authority. A reply belongs to its interaction; receiving a reply does not grant general permission to initiate new operations on the caller.
That distinction matters when agents implement different parts of a domain. You can review both the communication contract and the authority assigned to each part.
Begin with one local domain
Model two responsibilities, such as Checkout and Inventory, inside one runtime. Give each a state owner, a small operation contract and a bounded reason to communicate. Deployment separation is a later operational decision.
After the counter, read durable execution and effects and authority. They explain the two places where familiar actor vocabulary needs more precise meaning.
Build software you can reason about.