All storiesIntegration

What does “saved” mean in an embedded document editor?

Distinguish session updates, durable application versions, and exported files to build a save contract users can trust.

What does “saved” mean in an embedded document editor?: Save event, Stored candidate, Content check, Version publish.
Integration / Office SDK

“Saved” may mean that edits reached the editing service, while the latest downloadable file is still being prepared. Your application should name the persistence milestone it can actually verify. The user needs to know whether their work is durable and whether Download will return that same state.

The persistence milestones users encounter

Document the states supported by the actual integration: accepted locally, synchronized with the editing service, persisted by that service, and available as a business file version are possible examples. Do not invent states that the provider cannot observe. Identify which system is authoritative during an active session and after it closes. If export runs asynchronously, distinguish a durable editing state from the latest downloadable file. This vocabulary should appear consistently in application messages, monitoring, support procedures, and agreements about recovery after an interruption.

Use separate state fields when the architecture exposes separate milestones. For example, editing_state_confirmed can describe the last acknowledged editor state, while published_file_version identifies a retrievable business file. These are example application concepts; the provider may expose different or fewer signals. Never manufacture a precise status from a timer after the user stops typing.

Visible messageEvidence it requires
Changes synchronizedThe documented editing service acknowledgement
Preparing downloadA tracked export or publication operation is pending
Version readyThe version record references validated retrievable bytes

Failure messages also need this distinction. If export fails after the editor has persisted changes, saying that all work was lost is inaccurate. Say which result is unavailable and provide the supported recovery action. If the integration cannot prove persistence, avoid reassuring language that exceeds the available signal. Ask the provider which state survives a process restart, and reproduce that recovery in acceptance before deciding what the interface should promise.

Session state, durable editing state, and a downloadable business version are separate layers.
Figure 1. Only show a milestone that the integration can observe and verify.

A save event is not necessarily a named version

A service may produce frequent save notifications without every notification deserving a user visible version. Conversely, a deliberate submission may need a retained version even if little content changed. Define the policy for automatic checkpoints, named versions, approvals, and retention. Store enough metadata to link a durable object to its business document, source editing state, creation time, and integrity digest. Avoid using the arrival time of a notification as the only ordering signal when deliveries may be delayed or repeated across network retries.

Publish retrievable bytes before advancing the record

In a common storage pattern, download or generate the candidate file into a temporary object, validate it, and then update the business version record in a transaction or equivalent guarded operation. If metadata changes before the object is ready, readers may encounter a version that cannot be retrieved. If the object arrives but metadata fails, track it as an uncommitted candidate for reconciliation. The implementation details vary by storage system, but the invariant is simple: a published version must reference a readable, validated object.

When Download follows the last edit immediately

Suppose a finance team finishes a report and immediately downloads it for distribution. A save notification has arrived, but the new export is still processing. The application should either wait for the requested version, explain that preparation is underway, or offer a clearly labeled older version. It should not display Saved beside an unlabeled stale download. During acceptance, interrupt the export worker, restart it, and confirm that the final business record points to one complete version with a traceable relationship to the editing state.

A download request may arrive between save acknowledgement and file publication.
Figure 2. Offer preparation status or an explicitly labeled older version while the requested file is pending.

Recovery conditions to agree before launch

  • State which milestone the visible saved indicator represents.
  • Define how users identify the version returned by download and approval actions.
  • Verify temporary object cleanup after failed metadata commits.
  • Reconcile unprocessed save events after a worker restart.
  • Confirm that concurrent publication cannot move the current version backward.

Further reading

Back to all stories

Keep reading.

All stories