{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "4ff1df46-8579-4752-8e91-ea387b17a173",
      "key": "AAUDIT",
      "title": "Make privileged support actions inspectable",
      "field": "Security",
      "summary": "Constrain support elevation and preserve trustworthy audit records.",
      "context": "A fictional support console can reveal protected account settings and run repairs. The team needs bounded elevation, clear reasons and durable records of what happened.",
      "stack": [
        "TypeScript",
        "PostgreSQL",
        "REST"
      ],
      "prerequisites": [
        "Create synthetic support actors and organizations.",
        "Implement a local authorization boundary and append-only audit store."
      ],
      "developerValue": "Practice privileged workflows, denial paths and audit integrity.",
      "companyValue": "Review accountable support operations without unnecessary access to customer data.",
      "delivery": "Ten scoped tickets across three phases. Build a synthetic local service or select a ticket after recreating its prerequisites; estimates exclude setup.",
      "phases": [
        {
          "id": "access",
          "title": "Constrain elevated access",
          "goal": "Define permission, purpose and expiry."
        },
        {
          "id": "actions",
          "title": "Guard privileged mutations",
          "goal": "Bind changes to reviewed scope and durable records."
        },
        {
          "id": "review",
          "title": "Review and recover",
          "goal": "Inspect events and respond to missing audit coverage."
        }
      ],
      "tickets": [
        {
          "id": "5cfc3967-3cd4-468b-b6f1-bb3136c128f3",
          "key": "AAUDIT-101",
          "title": "List support actions with required permission and disclosure level",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "access",
          "dependsOn": [],
          "scenario": "Support agents share an admin role because nobody has separated read diagnostics from account-changing actions.",
          "acceptanceCriteria": [
            "Classify each action by permission and exposed fields.",
            "Default unknown actions to denied.",
            "Keep read-only diagnostics separate from mutation authority."
          ],
          "implementationNotes": [
            "Use six concrete fictional support actions."
          ],
          "verification": [
            "Map an allowed diagnostic read to its minimal permission.",
            "Attempt an unlisted action and deny it before data access."
          ],
          "deliverables": [
            "Support permission matrix"
          ],
          "rollout": "Review the matrix before enabling new actions; retain unknown operations as disabled.",
          "skills": [
            "Authorization design",
            "Least privilege"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 100
            }
          ],
          "patterns": []
        },
        {
          "id": "27460c62-35a2-47b5-8473-80aca55610ea",
          "key": "AAUDIT-102",
          "title": "Require a bounded purpose record before support elevation",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "access",
          "dependsOn": [
            "AAUDIT-101"
          ],
          "scenario": "An agent opens account settings using permanent elevated access with no connection to a support case.",
          "acceptanceCriteria": [
            "Record target organization, permitted actions, reason and expiry.",
            "Require an authorized actor to request elevation.",
            "Reject empty purpose or an excessive lifetime."
          ],
          "implementationNotes": [
            "Use synthetic case references without copying case conversations."
          ],
          "verification": [
            "Create a scoped time-limited elevation.",
            "Request a different organization's action outside the grant and deny it."
          ],
          "deliverables": [
            "Elevation request contract"
          ],
          "rollout": "Canary grants for synthetic actors; revoke active test grants if policy checks fail.",
          "skills": [
            "Privileged access",
            "Scoping"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Backend",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "852a8172-3b5f-4daa-a24e-dfd85939bdcc",
          "key": "AAUDIT-103",
          "title": "Remove sensitive account fields from ordinary support search",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 75,
          "phaseId": "access",
          "dependsOn": [
            "AAUDIT-101",
            "AAUDIT-102"
          ],
          "scenario": "Searching by account ID returns confidential settings before the agent opens an elevated support session.",
          "acceptanceCriteria": [
            "Ordinary search returns an explicit minimal projection.",
            "Protected details require the exact active grant.",
            "Denied search responses do not reveal account existence across scope."
          ],
          "implementationNotes": [
            "Define response schemas at the service boundary."
          ],
          "verification": [
            "Find an account using permitted safe fields.",
            "Search outside scope and inspect response and logs for protected fields."
          ],
          "deliverables": [
            "Minimal support search projection"
          ],
          "rollout": "Deploy projection before elevation rollout; disable broad debug search endpoints.",
          "skills": [
            "Privacy",
            "Response schemas"
          ],
          "fieldMix": [
            {
              "field": "Privacy engineering",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "38ac938d-1c35-4e75-a675-4b31510289c9",
          "key": "AAUDIT-104",
          "title": "Reauthorize elevation immediately before a support repair commits",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "actions",
          "dependsOn": [
            "AAUDIT-102",
            "AAUDIT-103"
          ],
          "scenario": "An agent starts a repair, loses access, then the pending request commits using the authorization decision from several minutes earlier.",
          "acceptanceCriteria": [
            "Reload actor and grant authority in the mutation transaction.",
            "Check target scope, permitted operation and expiry.",
            "Revoked or expired grants leave domain state unchanged."
          ],
          "implementationNotes": [
            "Use controlled barriers to model revocation between read and commit."
          ],
          "verification": [
            "Commit a repair under an active matching grant.",
            "Revoke at the barrier and verify rollback with no repair effect."
          ],
          "deliverables": [
            "Commit-boundary authorization guard"
          ],
          "rollout": "Canary the guard on synthetic repairs; disable repair writes if authorization freshness fails.",
          "skills": [
            "Authorization races",
            "Transactions"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Database engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "569e31a3-4195-474d-8906-f89f78602f4b",
          "key": "AAUDIT-105",
          "title": "Commit privileged repair state and its audit fact together",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "ADVANCED",
          "estimateMinutes": 210,
          "phaseId": "actions",
          "dependsOn": [
            "AAUDIT-104"
          ],
          "scenario": "A repair succeeds while the audit insert fails, leaving an unrecorded privileged change.",
          "acceptanceCriteria": [
            "Persist repair and audit fact in one transaction.",
            "Audit captures actor, grant, action and safe target identity.",
            "Audit failure rolls back the repair."
          ],
          "implementationNotes": [
            "Keep payload contents and secrets out of the audit record."
          ],
          "verification": [
            "Commit a synthetic repair and inspect one matching audit fact.",
            "Force audit persistence failure and verify unchanged domain state."
          ],
          "deliverables": [
            "Atomic repair audit and failure test"
          ],
          "rollout": "Deploy transactional writes before exposing repairs; stop mutation if audit storage is unavailable.",
          "skills": [
            "Audit integrity",
            "Transactions"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 50
            }
          ],
          "patterns": []
        },
        {
          "id": "76e3860b-0a82-43df-95c2-577565cb796d",
          "key": "AAUDIT-106",
          "title": "Make support repair commands replay-safe without repeating side effects",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "actions",
          "dependsOn": [
            "AAUDIT-105"
          ],
          "scenario": "The console retries a repair after a timeout, generating a second account reset and confusing the support trail.",
          "acceptanceCriteria": [
            "Bind idempotency to actor, grant, target and operation input.",
            "Return the original result for identical retries.",
            "Reject changed parameters under the same key."
          ],
          "implementationNotes": [
            "Audit the logical operation once and retain safe retry observations separately."
          ],
          "verification": [
            "Lose a post-commit response and retry to one repair.",
            "Reuse the command key for another target and deny it."
          ],
          "deliverables": [
            "Idempotent support repair command"
          ],
          "rollout": "Canary with disposable accounts; pause conflicting command keys for investigation.",
          "skills": [
            "Idempotency",
            "Privileged workflows"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Backend",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "b05ef40f-26f0-4a71-bd62-b15bcd17ac9a",
          "key": "AAUDIT-107",
          "title": "Expire support grants without relying on a cleanup job",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "actions",
          "dependsOn": [
            "AAUDIT-104",
            "AAUDIT-106"
          ],
          "scenario": "A delayed cleanup worker leaves expired support sessions usable throughout an outage.",
          "acceptanceCriteria": [
            "Every privileged authorization checks the stored expiry.",
            "Cleanup only archives derived state and cannot extend authority.",
            "Use one documented exact-expiry boundary."
          ],
          "implementationNotes": [
            "Use an injected UTC clock at the service boundary."
          ],
          "verification": [
            "Authorize a matching action immediately before expiry.",
            "Advance to expiry while cleanup is paused and deny the action."
          ],
          "deliverables": [
            "Expiry enforcement and paused-cleanup test"
          ],
          "rollout": "Enable boundary checks before cleanup changes; revoke grants if clock assumptions are violated.",
          "skills": [
            "Temporal authorization",
            "Fail-closed design"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 100
            }
          ],
          "patterns": []
        },
        {
          "id": "e0b77682-3f97-449e-8e52-e9f01b00bdaf",
          "key": "AAUDIT-108",
          "title": "Provide a scoped audit timeline with stable cursor pagination",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 180,
          "phaseId": "review",
          "dependsOn": [
            "AAUDIT-105",
            "AAUDIT-107"
          ],
          "scenario": "Security reviewers need to inspect a repair sequence, but an unbounded audit endpoint times out and exposes unrelated organizations.",
          "acceptanceCriteria": [
            "Filter by authorized organization and bounded time window.",
            "Order by committed sequence with a stable cursor.",
            "Return safe action metadata without repair payloads."
          ],
          "implementationNotes": [
            "Reject cursors bound to another scope."
          ],
          "verification": [
            "Page a synthetic incident timeline while new events arrive.",
            "Tamper with scope in a cursor and return a nondisclosing denial."
          ],
          "deliverables": [
            "Audit timeline endpoint and scope tests"
          ],
          "rollout": "Expose read-only timelines to a review role; revoke the route if projection checks fail.",
          "skills": [
            "Pagination",
            "Audit review"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 40
            },
            {
              "field": "API design",
              "percentage": 30
            },
            {
              "field": "Database engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "2704a99f-3201-4fc9-ad56-c077ee4d7a70",
          "key": "AAUDIT-109",
          "title": "Detect missing privileged audit coverage using domain references",
          "type": "CHORE",
          "priority": "MEDIUM",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "review",
          "dependsOn": [
            "AAUDIT-105",
            "AAUDIT-108"
          ],
          "scenario": "A legacy repair path may still bypass the transactional audit method; reviewers need a precise way to find uncovered changes.",
          "acceptanceCriteria": [
            "Compare privileged operation references with audit identities.",
            "Report missing and contradictory links separately.",
            "Do not invent audit facts for historical gaps."
          ],
          "implementationNotes": [
            "Use bounded synthetic data and a read-only reconciliation command."
          ],
          "verification": [
            "Reconcile a complete operation history with no gaps.",
            "Remove one audit reference in a fixture and report explicit incomplete coverage."
          ],
          "deliverables": [
            "Audit coverage reconciler"
          ],
          "rollout": "Run read-only before enabling legacy repair paths; disable uncovered writes until corrected.",
          "skills": [
            "Integrity verification",
            "Uncertainty"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Quality engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "a1ce5baf-db80-43d4-85ba-2c03c12c8d4d",
          "key": "AAUDIT-110",
          "title": "Rehearse termination of an active support elevation incident",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 120,
          "phaseId": "review",
          "dependsOn": [
            "AAUDIT-107",
            "AAUDIT-108",
            "AAUDIT-109"
          ],
          "scenario": "A fictional support account is suspected of misuse while one elevated request is still running.",
          "acceptanceCriteria": [
            "Runbook revokes grants and checks in-flight commit protection.",
            "Preserve immutable audit facts and record coverage limits.",
            "Verify ordinary support access remains scoped after containment."
          ],
          "implementationNotes": [
            "Use only synthetic actors and repairs."
          ],
          "verification": [
            "Contain an active grant and verify later actions are denied.",
            "Pause a repair before commit, revoke authority, and confirm no mutation completes."
          ],
          "deliverables": [
            "Support containment runbook and drill trace"
          ],
          "rollout": "Rehearse locally before release; keep repairs disabled if containment cannot be verified.",
          "skills": [
            "Incident response",
            "Operational verification"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Site reliability",
              "percentage": 40
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
