noCV
RDELETE-109 · Reconcile exceptions and completion

Retry a removal operation after losing a provider acknowledgement

Practice briefChoreAdvanced

A provider removes a copy but the cleanup process crashes before recording the result. Retrying currently converts the missing object into a fatal error.

Focused work estimate
3h 30m + prerequisites
Priority in the scenario
Medium
Engineering practice
Distributed recovery · Idempotency

Estimated field mix

  • Distributed systems50%
  • Privacy engineering30%
  • Site reliability20%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional collaboration product lets a member request removal of their personal profile. Search, notifications and cached displays retain copies after the primary row disappears. The exercise uses a documented product deletion policy and synthetic identities.

Setup prerequisites

  • Create local profile, search-index and notification fixtures with controlled provider failures.
  • Define synthetic members, organizations and a current-session authorization fixture.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Reconcile uncertain acknowledgement states using the provider’s declared lookup/removal contract.
  • Make repeated cleanup converge without recreating data or duplicating completion notifications.
  • Retain a distinct unresolved state when the provider cannot confirm the outcome.

Implementation constraints

  • Use deterministic crash points around dispatch, provider completion and local persistence.

Verification to include

  • Crash after external removal and before local update, then retry and verify truthful convergence.
  • Inject repeated provider timeout and verify bounded retries plus visible unresolved status.

Deliverables

  • Acknowledgement-loss regression and retry procedure

Rollout and recovery

Retry only through the recorded operation identity; unresolved high-impact states require authorized review in the exercise.

Value of the work

For the engineer: Practice distributed cleanup, identity scope, idempotency and accurate user-facing lifecycle states.

For the team: Produce a reviewable deletion workflow and copy inventory for adaptation to an approved company policy.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.