Customer-level execution control.
One customer remains one customer. Bruiser admits one authorised execution for that customer, and holds the rest.
Permission to attempt. Not a hold.
An execution lease is permission to attempt allocation. It is not an inventory hold. Inventory stays in the merchant’s system. The execution belongs to the customer; a browser or an agent only holds it on their behalf.
Customer identity remains constant when execution moves between browser and agent.
- Acquire — the customer takes the authorised execution for a scarce operation.
- Renew — the same execution stays admitted while the attempt continues.
- Release — the attempt ends and the execution returns.
- Expire — a lease that is not renewed ceases to be admitted.
- Revoke — policy or an operator withdraws the execution.
- Handoff — the same customer continues from another principal. Identity does not change.
Additional agents wait.
Further agents from the same customer wait, rather than creating additional origin executions. They do not multiply the customer at the scarce-inventory origin.
Customer A’s agents do not block Customer B. Queue and admission are scoped to the customer. One customer’s amplification is not another customer’s place in line.
Limits before the origin.
Bruiser applies execution pressure in front of the scarce operation. It does not decide how many scarce units the customer may obtain.
- In-flight limits — how many authorised executions may be active.
- Route-level rate limits — pressure on a path, independent of any one execution.
- Execution-level rate limits — pressure on an admitted execution.
- Deadlines — an attempt that outlives its window is no longer admitted.
- Cancellation — an in-flight attempt can be stopped.
- Backpressure — surplus attempts wait or are refused, rather than forwarded.
Control settings, including dry run and progressive enforcement, are described on Control.