| Takeaway | Detail |
|---|---|
| 28% should trigger evaluation, not adoption. | Measure both sustained offline exposure and genuine causal concurrency; Sabaoon-style local writes and background replication should not displace server authority by default. |
| Causality must precede the 6-hour review target. | Lamport happens-before can identify stale writes, while concurrent lesson edits still need an explicit semantic decision about prerequisite integrity. |
| 6 hours should bound ambiguous merge escalation. | Use the review target for changes that may alter lesson order or prerequisites while local writes continue and background replication proceeds. |
| A 6-hour window cannot guarantee a valid prerequisite path. | A CRDT may produce a single deterministic state, but expert review must determine whether concurrent lesson edits preserve a valid learning path. |
At 28%, local-first sync should trigger an evidence review, not automatic adoption. Require both sustained offline exposure and genuine causal concurrency before choosing the architecture. Server authority remains the default. Sabaoon’s architecture makes every lesson action a local SQLite/WebAssembly write, then uses a service worker to replicate deltas after connectivity returns. The learner need not wait for a network round trip. That is a resilience gain, not evidence that a device can choose the instructionally correct lesson.
Apply Lamport’s causal axioms before conflict resolution: preserve happens-before, refuse to invent precedence for concurrent edits, and do not mistake logical time for curricular judgment. A CRDT can force offline edits into a single deterministic state. It cannot, by itself, show whether that state preserves a prerequisite path. Causality can identify stale writes; concurrent changes still require authority to choose the instructionally valid result.
Keep that authority on the server and make its intervention bounded. Use 6 hours as the escalation target for ambiguous merges while local writes continue and background replication catches up. For adaptive-tutorial systems, authority-first does not mean server-only: the device owns immediate interaction, the network assists replication, and expert review protects the lesson graph. The goal is not automatic merging. It is offline usability without presenting convergence as instructional truth.

Write Authority First
Write authority—not conflict resolution—is the first architectural choice. A CRDT specifies how accepted replicas converge; it does not determine who may accept a write or whether the converged lesson is semantically valid. That distinction kills the myth that conflict-free replication automatically makes local-first sync safer or better for instructional design.
I define local-first sync as a durable client replica that accepts edits without server acknowledgement and merges them later through a CRDT. The server may relay encrypted updates and retain backups, but it is not the sole acceptance authority. An edit committed on the client is already locally durable even while disconnected; synchronization determines when peers learn it.
I define server-authoritative sync as a model in which the server decides whether a write is durable and accepted. Disconnected clients may draft or queue, but reconnecting edits can be rejected, transformed, or merged before becoming canonical. The server can still use a CRDT: if it adjudicates or transforms an update before declaring the result canonical, CRDT convergence has not moved acceptance authority to the client.
I use RGA, or Replicated Growable Array, as the concrete sequence-CRDT example. Suppose devices A and B each make one offline insert adjacent to the same prior element. Each insert carries an actor identifier and causal position. Delivery in the order A→B must produce the same deterministic two-element order as delivery in the order B→A. That property settles sequence convergence; it does not determine which insertion is pedagogically appropriate.
| Measure | Count exactly | Do not substitute |
|---|---|---|
| O: offline-write exposure | Accepted writes committed without server acknowledgement divided by all accepted writes | General connectivity or uptime statistics |
| C: causal concurrency | Accepted writes whose vector-clock context excludes at least one concurrently accepted peer write divided by all accepted writes | Wall-clock overlap or timestamp ordering |
| R: semantic repair rate | Reviewed merged lesson or authorization objects failing first-pass semantic or policy validation divided by all reviewed merged objects | Replica equality or transport-success rates |
The denominators are where instrumentation usually misleads. A queued draft rejected on reconnect is neither an accepted offline write for O nor an accepted concurrent write for C. For C, wall-clock overlap neither establishes concurrency nor rules it out when device clocks differ. For R, an incorrect prerequisite edge, contradictory hint, or inaccessible media description counts as a failure even if every replica converges. Review merged lesson and authorization objects, not merely update envelopes.
Exclude workloads requiring linearizable global reads. For workloads that tolerate eventually consistent reads, choose local-first CRDT sync only when offline exposure and causal concurrency are high and semantic repair is low; otherwise choose server-authoritative sync. The concrete next action is to record server-acknowledgment status, vector-clock context, and first-pass review results in the authoring audit record, then select the authority model from those measurements—not from whether the underlying CRDT converges.

Lamport’s 3 Axioms, CAP’s 2-of-3 Rule, and the
A CRDT does not win by calling itself conflict-free. It is eligible only after the workload permits eventually consistent reads and the offline-write, causal-concurrency, and semantic-repair evidence clears the canonical O/C/R gate. These formal results explain why that gate concerns instructional integrity, not merely technical convergence.
I anchor C in Leslie Lamport’s happened-before relation: irreflexivity rejects self-precedence, transitivity preserves chained causes, and antisymmetry forbids cycles. Together, these axioms let instrumentation distinguish genuinely stale concurrent branches from edits that merely happened later. That distinction must come from causal metadata; a larger wall-clock timestamp does not prove that one edit happened-before another.
I anchor the availability boundary in Seth Gilbert and Nancy Lynch’s CAP result: consistency, availability, and partition tolerance cannot all be guaranteed during a partition. CAP consistency means atomic consistency, not eventual CRDT convergence. A CRDT can preserve offline writes and reconcile replicas after healing, but it cannot also promise a linearizable global read. A workload requiring that read is therefore excluded before architecture selection.
I anchor merge correctness in Shapiro, Preguiça, Baquero, and Zawirski’s CRDT report. Its join-based model uses commutativity, associativity, idempotence, and a least-upper-bound merge. Delivery order, batching, and duplication therefore stop changing replica state. None of those properties proves that the joined lesson preserves prerequisite order, feedback logic, or instructional intent, so convergence alone cannot determine the winner.
I use Freeman and colleagues’ PNAS meta-analysis as indirect prioritization evidence, not CRDT proof. Its learning outcomes indicate that a syntactically perfect merge can still carry instructional costs worth expert review. I therefore count semantically necessary repairs in R; they are not cosmetic cleanup. This makes the repair gate consequential: it tests whether converged state remains fit for adaptive instruction.
Operationally, I attach causal metadata to accepted writes, exclude linearizable-read workloads, and send converged lessons with suspicious semantic changes to expert review before selecting an architecture. Local-first CRDT sync wins only when the O and C gates and the R ceiling all pass; otherwise server-authoritative sync wins. “Conflict-free” by itself never makes local-first safer or better.
| Decision test | External evidence | Actionable audit | Architectural consequence |
|---|---|---|---|
| Causal concurrency | According to Leslie Lamport, happened-before has 3 axioms. | Use causal metadata rather than timestamps; classify branches as concurrent only when neither precedes the other. | Failure of the C gate rules out local-first CRDT selection. |
| Partition behavior | According to Gilbert and Lynch, a partition permits at most 2 guarantees among 3 CAP properties. | First ask whether the workload requires a linearizable global read. | If it does, server-authoritative sync wins immediately. |
| Merge correctness | According to Shapiro and colleagues, the join model uses 4 semilattice conditions. | Review deterministic joins for prerequisite and feedback correctness; record every semantically necessary repair. | Convergence alone cannot select CRDT; the R ceiling decides. |
| Instructional stakes | According to Freeman and colleagues, active learning improved examination outcomes, while traditional-lecture students faced greater failure risk. | Treat semantic repair as an instructional-risk signal rather than cleanup after a technical success. | R remains decisive; local-first is eligible only if the complete O/C/R gate passes. |

Local Sync vs Server Sync: The O/C/R Winner Matrix
The matrix has one unambiguous result: after excluding tutorials that require linearizable global reads, local-first CRDT sync wins only in the established high-O, high-C, low-R branch. O denotes the share of accepted writes made offline, C the share that is causally concurrent, and R the share of reviewed merges needing repair. A CRDT label cannot decide this matrix; authority over the durable lesson-source state can.
| Decision variable | Local-first CRDT | Server-authoritative sync | Winner |
|---|---|---|---|
| Durable source write | Replica accepts immediately | Server accepts, merges, or sequences | Local-first only if O passes |
| Disconnected edit | Durable on the device | Drafted, queued, or rejected | Local-first if O is high |
| Concurrent edits | Deterministic replica merge | Central merge or ordering | Local-first if C is high |
| Lesson and policy validity | Client validator plus expert review | Central schema, role, and release gate | Server if R is high |
| Global read | May be stale until merge | Can be made linearizable | Server when linearizable reads are required |
| Overall | High O + high C + low R | Every other branch | Local-first only in the three-pass branch; server-authoritative otherwise |
I mark local-first as the explicit winner only for high O, high C, and low R because it removes the disconnected-write dependency and central-ordering bottleneck without routinely pushing expert repair onto learners. According to ResourceFinderHQ’s July 3, 2026 conflict inventory, simultaneous modifications, independent offline edits, delayed or out-of-order delivery, and automated updates can all produce concurrency. That also explains why C must be measured separately from O: an edit can occur offline yet remain causally ordered after previously accepted state.
I mark server-authoritative sync as the winner whenever O or C is low, or R is high. A central schema, role check, and release gate can stop an illegal prerequisite graph or contradictory instructional hint before learner-facing publication. Eventual convergence does not help if the converged lesson remains instructionally invalid and its repair burden falls on learners.
A server-relayed CRDT exposes the matrix’s sharpest edge case. According to Sabaoon’s June 2, 2026 architecture, actions are first written to local SQLite/WebAssembly, after which a background service worker replicates deltas. I classify that design as local-first only if the offline client durably accepts the source edit and can merge it independently. If the server may reject, reorder, or rewrite accepted state, the system remains server-authoritative under this guide; the transport mechanism does not transfer authority.
I keep the framework instructional rather than ideological. Server-authoritative publication can coexist with local-only drafts, but caching does not determine classification. To audit an implementation, trace one source edit from entry through durable acceptance to learner-facing publication: if a server veto can still alter that accepted state, choose server-authoritative sync; otherwise, apply the O/C/R gate specified earlier.

Counter-Evidence
The O/C/R gate is an evidentiary claim, not a law of nature. I begin by asking whether a merge sample can distinguish acceptable repair from unacceptable repair. Applying Wilson’s interval method yields a useful warning: identical observed proportions do not imply identical confidence.
| Review history | Observed review evidence | Wilson lower bound | Governance reading |
|---|---|---|---|
| Pilot review | Reported pilot outcomes | Not numerically specified | Too little evidence for a strong reliability claim |
| Scaled review | Reported scaled-review outcomes | Not numerically specified | Potentially stronger lower bound, but still not proof of semantic correctness |
An identical point estimate can still accompany a materially different lower-bound claim when the review sample changes. That distinction matters because a narrow interval around an estimated merge-success rate does not establish that the resulting lessons are instructionally valid. Sampling variation, review procedures, and unreviewed failures can all remain hidden behind the same headline proportion.
I therefore label the guide’s three cutoffs as governance defaults, not universal scientific constants. Before a deployment ratifies them, its record should document rejected learner work, time spent repairing merges, and the cognitive cost imposed when a broken lesson reaches learners. A cutoff becomes defensible through local evidence about those harms; decimal precision alone supplies no such evidence.
I also refuse to treat offline-writing share O and causal-concurrency share C as independent votes, or hide their relationship inside one pooled average. A single outage can generate both offline writes and stale causal contexts, so scoring the same event on both dimensions would double-count correlated evidence. A multi-device-author subgroup may also have higher C or repair rate R than the population as a whole. I would report O by outage length and R by lesson type, preserving subgroup counts and uncertainty rather than letting an aggregate conceal a vulnerable cohort.
Almeida and colleagues’ critical review of CRDTs helps separate convergence from application semantics. Suppose one offline author deletes prerequisite P while another adds quiz Q that references P. The replicas can converge perfectly on the same lesson graph, yet the graph is unusable until the missing context is reconstructed. If human review classifies that remediation as repair, it belongs in R; calling it a convergence failure confuses data agreement with instructional validity. Thus, “conflict-free” does not make local-first synchronization automatically safer or better for collaborative instructional design.
Long partitions expose another failure mode. An average session ending does not establish causal stability across every delayed replica. Causal history and tombstones cannot be compacted merely because ordinary sessions have ended: some operation-based CRDTs can lose deduplication context when a delayed replica returns after unsafe compaction. Compaction must wait for causal stability, or the local-first availability benefit may be purchased with weakened merge correctness.
Finally, I count unauthorized offline visibility as an R policy failure, not an availability benefit to discount elsewhere. If learner work requires immediate deletion or access revocation, server authority applies under the same rule even when offline exposure and causal concurrency are both high. After workloads requiring linearizable global reads are excluded, these limits narrow CRDT eligibility rather than reverse the canonical rule: uncertain evidence, semantic damage, unsafe compaction, or revocation exposure sends the decision to server-authoritative sync.

Worked Tutorial Trace
Server-authoritative sync wins this tutorial trace because a pedagogically invalid merge vetoes local-first even when replicas converge. I use Automerge to make the convergence test concrete, while treating every workload value below as a specified trace input—not as measured performance or a field-deployment result.
According to O’Keefe, McSherry, and Perarnau’s paper, “A Highly-Available Move-to-List CRDT,” the Automerge design uses actor identifiers. The worked trace’s operational values are specified solely to exercise the decision logic, not as measured performance or a field-deployment result: 12 edits were committed without server acknowledgement, 8 of those were based on a causal context missing a peer edit, and 20 merged lesson objects were submitted for expert review. Actor identifiers are only one part of the state; they do not include causal metadata or the rest of the lesson state.
| Gate | Specified numerator | Calculation | Required gate | Decision effect |
|---|---|---|---|---|
| O: unacknowledged accepted edits | 12 commits without server acknowledgement | Unacknowledged share of all accepted writes | Sustained offline-exposure gate | Measure before selecting authority |
| C: causally concurrent accepted edits | 8 edits missing a peer edit in their causal context | Causal-concurrency share of all accepted writes | Causal-concurrency gate | Measure before selecting authority |
| R: reviewed merges requiring repair | 1 expert-required correction | Repair share of all reviewed objects | No pedagogically invalid merge | Fail; vetoes local-first |
The review records 1 expert-required correction among the 20 merged objects. Its automatically merged hint tells a learner who has already answered correctly to retry. The CRDT can converge on that contradiction because deterministic state equality does not test whether an instruction matches the learner’s state. The lesson remains unfit for publication until the hint is repaired. This is where the belief that conflict-free replication makes local-first authoring safer fails: convergence guarantees a shared state, not a valid lesson graph.
The trace makes the asymmetry explicit: offline exposure and concurrency cannot rescue a pedagogically invalid merge. The rule is conjunctive, so a favorable result on one measure cannot cancel a failure on another. The semantic-repair failure therefore vetoes local-first, and I choose server-authoritative sync. Editors may retain Automerge-backed offline drafts, but a server validator must approve the canonical lesson graph before learners receive it.
I require the raw CRDT state to produce the same content hash under both delivery schedules. Matching hashes establish schedule-independent state convergence for this specified trace; they do not establish pedagogical correctness. The concrete next action is to block release, repair the contradictory hint, and recompute R from the expert-reviewed object set. Until that failed gate is cleared, local-first remains disqualified even though the editor drafts remain useful offline.

Decision Tree: Five Rules for the O/C/R Gate
An underpowered evidence sample is the first veto: the O/C/R gate allocates write authority, so insufficient evidence cannot justify local writes. Apply the rules in order. If the workload requires linearizable global reads, stop at server-authoritative sync; the local branch exists only for tutorial workflows that can tolerate eventually consistent reads.
| Rule | Gate condition | Decision and consequence |
|---|---|---|
| Rule 1 — Sample gate | Use a prespecified rolling window with a representative accepted-write sample and independently reviewed merge objects. | If the required evidence is missing, mark the decision inconclusive and retain server-authoritative sync. |
| Rule 2 — Offline gate | If O is below the required offline-exposure gate. | Choose server-authoritative sync. Local drafts are allowed, but offline-first write authority is not justified. |
| Rule 3 — Concurrency gate | If O clears the offline gate but C is below the causal-concurrency gate. | Choose server-authoritative sync because genuine causal concurrency is too uncommon to justify local merge complexity. |
| Rule 4 — Repair gate | If O and C clear their gates but R shows a material semantic-repair burden. | Choose server-authoritative sync and require server-side lesson validation or human approval before learner-facing publication. |
| Rule 5 — Local gate | If linearizable global reads are unnecessary, O and C clear their gates, and R remains low. | Choose local-first CRDT sync for lesson-source edits while the server only relays updates and serves validated snapshots. Revert to server authority if any metric later crosses its gate. |
Read the gate as an ordered conjunction, not a score. High concurrency cannot rescue insufficient offline writing, and a low repair rate cannot rescue an undersampled decision. Once the sample gate passes, failure at the offline, concurrency, or repair gate ends the current evaluation with server authority; the local option is reached only when every prerequisite remains jointly true.
The repair gate supplies the essential myth correction. CRDT convergence can establish that replicas reach the same state, but it does not establish that the merged state is instructionally valid. Conflict-free data structures therefore do not make local-first sync automatically safer or better for collaborative instructional design; the observed repair burden still governs authority.
At the next gate review, record the window bounds, sample status, O/C/R values, global-read requirement, and resulting authority together. Reapply the tree from Rule 1. If a metric later crosses its boundary, or linearizable global reads become necessary, revert to server authority. If the sample requirement is no longer met, label the decision inconclusive and retain server authority rather than extrapolating from the earlier local decision.
What to do next
| Step | Action | Why it matters | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Classify the lesson workload and exclude any flow requiring linearizable global reads before evaluating local-first sync. | Convergent replicas cannot satisfy workloads that require an authoritative global read. | |||||||||
| 2 | Measure sustained offline exposure and genuine causal concurrency across Sabaoon learners; treat Takeaway Detail 28% as an evidence-review trigger, not an adoption threshold. | Offline usability alone does not establish causal concurrency or justify a CRDT. | |||||||||
| 3 | Apply the canonical O/C/R gate: choose local-first CRDT only when O, C, and R meet all defined thresholds; otherwise choose server-authoritative sync. | The architecture decision must follow the stated evidence gate, with server authority as the default. | |||||||||
| 4 | For a qualifying Sabaoon workload, retain local SQLite/WebAssembly lesson writes and service-worker delta replicatio
Frequently Asked QuestionsDoes a 28% result justify automatically adopting local-first CRDT sync? No; 28% should trigger an evidence review rather than automatic adoption, with both sustained offline exposure and genuine causal concurrency required and server authority remaining the default. How can causal concurrency be distinguished from edits that merely happened later? Use causal metadata and classify branches as concurrent only when neither precedes the other, because a larger wall-clock timestamp does not prove that one edit happened-before the other. How should a queued draft rejected on reconnect be counted in the O and C metrics? It is neither an accepted offline write for O nor an accepted concurrent write for C. What should happen when concurrent edits may alter lesson order or prerequisites? After causal analysis, use 6 hours as the escalation target for ambiguous merges while local writes continue and background replication catches up, but do not treat that window as a guarantee of a valid prerequisite path. Does a CRDT that converges to one deterministic state prove the merged lesson is instructionally valid? No; expert review must determine whether concurrent edits preserve a valid learning path, and server authority remains the default. What counts as a semantic-repair failure under R, and when can local-first CRDT sync be selected? An incorrect prerequisite edge, contradictory hint, or inaccessible media description counts as a failure in R even if replicas converge, while local-first CRDT sync is selected only when the O and C gates and the R ceiling pass after workloads requiring linearizable global reads are excluded. Quick answers
Also worth reading: Which Free Machine Learning Courses Are Worth Your Time: Which Free Machine Learning Courses · Nano Banana 2 versus Pro Which AI Model Should You Choose: Nano Banana 2 versus Pro · Mealy vs Moore Machines Comparing State-Based Output Strategies in Finite Automata: Mealy vs Moore Machines Comparing Research Methodology & Editorial StandardsWe begin by defining the specific objectives the reader needs to accomplish. Primary product documentation and authoritative secondary sources are assembled into a verified research corpus; drafting occurs only after this foundation is in place. Every quantitative claim is subjected to dual-source verification. Any figure that cannot be independently corroborated is either qualified or omitted. Published · Last reviewed · Owned by the Aitutorialmaker editorial desk (About, Contact, Privacy). Related readingLatestRelated answers |