Separate merchant exports from the analyst-wide mart
Removing merchant_id from an export request returns every merchant's sales because the support route passes filters directly to an analyst-wide query.
- Focused work estimate
- 3h + prerequisites
- Priority in the scenario
- High
- Engineering practice
- Data access control · Tenant boundaries · Column minimization
Estimated field mix
- Security50%
- Data engineering30%
- Privacy engineering20%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional marketplace reports daily sales to merchants. Refund joins inflate revenue, merchants close books in different time zones, and backfills compete with nightly loads. All source orders and merchants are synthetic.
Setup prerequisites
- SQL joins and aggregates
- Batch pipelines
- Metric definitions
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- LAKE-101 · Write the daily net-sales contract with worked rows
- LAKE-102 · Profile source keys before trusting the order feed
- LAKE-103 · Remove the order-line and refund join fan-out
- LAKE-104 · Assign sales to the merchant's reporting day
- LAKE-106 · Pick up late refunds in an incremental load
- LAKE-108 · Block publication when revenue fails source reconciliation
Acceptance criteria
- Derive merchant scope from authorized context at the export boundary.
- Expose only approved aggregate columns.
- Reject unbounded date ranges and cross-merchant access.
Implementation constraints
- An analyst credential cannot substitute for merchant authorization.
Verification to include
- Export permitted dates for one merchant with correct totals.
- Omit or replace merchant scope and request raw customer columns; assert denial.
Deliverables
- Scoped export boundary and authorization regression cases
Rollout and recovery
Route one synthetic merchant through reduced credentials first; revoke export permission on scope failures.
Value of the work
For the engineer: Practice metric contracts, historical dimensions, incremental processing, and reproducible warehouse releases.
For the team: Inspect whether an engineer can reconcile business totals and explain metric changes in a reviewable data product.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.