Switch customer reads to immutable IDs with a compatibility fallback plan
The new writer is deployed, but detail routes still resolve mutable codes and can display the wrong record after a rename.
- Focused work estimate
- 2h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- API migration · Identity modeling
Estimated field mix
- Database engineering50%
- API design30%
- Backend20%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional support platform stores a mutable external account code as its primary relationship key. Renames and imports now break references in several tables.
Setup prerequisites
- Create a disposable database with synthetic customers and dependent records.
- Apply real migration files; never use production db push.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- AMIGRATE-101 · Inventory every reference to the mutable customer code
- AMIGRATE-102 · Add immutable customer IDs through an additive migration
- AMIGRATE-103 · Add nullable customer-ID references to dependent tables
- AMIGRATE-104 · Backfill customer IDs with resumable keyset batches
- AMIGRATE-105 · Bridge legacy customer writes to the new identity transactionally
- AMIGRATE-106 · Protect customer-code renames during the backfill window
- AMIGRATE-107 · Verify relationship completeness before making customer IDs mandatory
- AMIGRATE-108 · Validate and enforce the new customer relationship constraints
Acceptance criteria
- Use immutable IDs for internal relationships and new detail routes.
- Keep documented legacy lookup behavior at the API boundary.
- Record fallback use without leaking customer payloads.
Implementation constraints
- Fallback must remain tenant-scoped and reject ambiguous codes.
Verification to include
- Rename a customer and keep its ID-based detail route stable.
- Request an ambiguous legacy code and reject rather than selecting a row.
Deliverables
- ID-based read path and compatibility cases
Rollout and recovery
Canary new routes; restore bridge reads if client compatibility fails.
Value of the work
For the engineer: Practice migration ordering, compatibility and referential integrity.
For the team: Review a reversible schema transition with measurable completeness checks.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.