Typed User Actions
Each interaction defines what may be shown, what must be provided and what typed output the Process receives.
Systems, Decisions, Agents and provider calls remain in the Process. When execution reaches a User Action, the Journey exposes that interaction to the authorised participant and the Process waits durably for its result.
This keeps business routing and operational state out of front-end code. The participant sees one coherent journey while Ormuz keeps the orchestration contract explicit.
Each interaction defines what may be shown, what must be provided and what typed output the Process receives.
A Journey can present a secure provider-owned browser interaction while the Process owns the surrounding wait and continuation.
Closing a browser does not erase operational state; the Process remains the source of truth for what is waiting and what comes next.
A Process may collect company data, verify contact details, ask for a choice, request clarification and later present terms. The Journey can group these interactions into stages so participants understand where they are without changing Process semantics.
Progress is derived from the running Process, not maintained as a separate client-side workflow.
Present the information and checks that require participant input.
Ask only for the missing or ambiguous information when the operation needs it.
Present the final participant action when policy and provider work are complete.
A journey-link grants temporary access scoped to the intended participant and Process instance. It is a capability for the Journey, not a general platform session.
The Journey application can be hosted by Ormuz, redirected to, or embedded where supported. Hosting is a delivery mechanism; the product concept remains the User journey connected to the Process.
The link authorises the interactions exposed to that participant in that Process context. It does not grant arbitrary API, Console or business-object access.
Values collected through User Actions are validated against the interaction contract before the Process resumes. Data classification travels with those outputs so later nodes do not silently lose protection context.
Protected values remain masked in generic observability; targeted reveal remains a separate controlled operation.