Keep manual account restrictions separate from plan allowances
A support restriction disappears when an account upgrades because both settings currently share one mutable limit.
- Focused work estimate
- 2h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- Domain modeling · Authorization
Estimated field mix
- Backend70%
- Security30%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional document service grants storage and collaboration rights from subscriptions. Support cannot explain why delayed events restore old limits.
Setup prerequisites
- Create a local subscription API with synthetic accounts.
- Understand transactions and UTC intervals.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
Acceptance criteria
- Store restriction and plan allowance with separate provenance.
- Return the effective minimum with both reasons.
- Removing a restriction restores the current plan allowance.
Implementation constraints
- Restrict mutation to an authorized support role.
Verification to include
- Upgrade a restricted account and retain its lower limit.
- Attempt a restriction change as a normal member and deny it.
Deliverables
- Restriction command and permission tests
Rollout and recovery
Enable for synthetic accounts; disable mutation while retaining restriction history.
Value of the work
For the engineer: Practice temporal rules, concurrency and explainable API decisions.
For the team: Review whether entitlement changes preserve customer access and produce supportable decisions.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.