Your model keeps working when the platform moves on
Every definition file states the format it was written for, and the platform reads older files as they were meant, indefinitely. When the format does change, you get your whole repository back rewritten, with a report of what changed, so upgrading is a review rather than a project. A model with an error is refused with every problem listed at once — file and location included — and your previous model keeps serving the application, so a bad commit means nothing changed rather than something broke. Removed features get at least twelve months of warnings first.
Technical: definition format v1 with a versioned upgrade chain applied before binding; apiVersion per script against a frozen ScriptApi facade; strict validation with all ModelIssues reported and swap-on-success reloads; GET /admin/{tenant}/modelUpgrade returns the rewritten repository plus report; gateways declare stable/beta; published JSON Schema per version.