noCV
ABOUND-102 · Frame the boundary

Draw the document trust boundary with authoritative state owners

Practice briefTaskIntermediate

The first sketch lets the API parse uploaded documents and write arbitrary worker status into the upload row.

Focused work estimate
2h 30m + prerequisites
Priority in the scenario
Medium
Engineering practice
System boundaries · Threat modeling

Estimated field mix

  • System design60%
  • Security40%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional procurement portal extracts metadata from uploaded documents. Product wants a responsive upload flow; security wants parser failures isolated from customer-facing processes.

Setup prerequisites

  • Create synthetic upload metadata and a fake processing provider.
  • Treat diagrams as proposals; implement only local contract probes.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Identify storage, API, coordinator and isolated parser boundaries.
  • Assign one owner to each lifecycle transition.
  • Mark untrusted bytes and privileged credentials on data flows.

Implementation constraints

  • Parsing belongs behind an explicit isolated provider; no candidate code runs in product processes.

Verification to include

  • Trace a valid upload through every boundary.
  • Trace a malformed document and show that parser failure cannot mutate API memory.

Deliverables

  • Trust-boundary diagram and state-ownership table

Rollout and recovery

Review the boundary before implementation; reject paths that collapse isolation.

Value of the work

For the engineer: Practice boundary decisions backed by executable consistency and failure checks.

For the team: Review architecture tradeoffs with explicit assumptions before infrastructure commitment.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.