Robotic systems operate in a world that changes underneath them. Networks disappear, devices report partial state, operators intervene, and a valid plan can stop being valid. Recovery cannot be an afterthought attached to a happy-path executor.

A durable runtime represents cancellation, restart, and safe failure as normal states. Each transition should preserve enough context to make the next decision deliberate rather than accidental.

Accountability after interruption

When an action stops, the system should still explain who proposed it, who executed it, which resources were involved, and what result was observed. That record supports both recovery and learning.

Reliable action is not action that never stops. It is action that knows how to stop, how to resume, and how to leave evidence behind.