{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "ee51ce9a-8287-468e-8bfd-59f9b19b7462",
      "key": "ATENANT",
      "title": "Enforce organization boundaries in a relational case schema",
      "field": "Database engineering",
      "summary": "Make cross-organization relationships impossible through database and repository constraints.",
      "context": "A fictional case-management application filters most requests correctly, but imports and background commands can connect a case to another organization's project or assignee.",
      "stack": [
        "PostgreSQL",
        "Prisma",
        "TypeScript"
      ],
      "prerequisites": [
        "Create two synthetic organizations with overlapping display names.",
        "Use repository-level authorization and migration-backed constraints."
      ],
      "developerValue": "Practice tenant-aware keys, foreign keys and direct-write denial tests.",
      "companyValue": "Review defense in depth for data isolation across ordinary and privileged writers.",
      "delivery": "Ten scoped tickets across three phases. Build a synthetic local service or select a ticket after recreating its prerequisites; estimates exclude setup.",
      "phases": [
        {
          "id": "relations",
          "title": "Inventory tenant relationships",
          "goal": "Find and constrain cross-organization references."
        },
        {
          "id": "writers",
          "title": "Protect every write path",
          "goal": "Carry scope through imports, jobs and transactions."
        },
        {
          "id": "verify",
          "title": "Prove boundary coverage",
          "goal": "Reconcile legacy rows and verify database denials."
        }
      ],
      "tickets": [
        {
          "id": "2eb7166a-de0a-4a96-a7e8-60898ce969a6",
          "key": "ATENANT-101",
          "title": "Map tenant ownership for case-management entities",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "relations",
          "dependsOn": [],
          "scenario": "The schema lists organization IDs on cases but not on comments or attachment relationships, leaving ownership implicit.",
          "acceptanceCriteria": [
            "Identify the owning organization for every selected entity.",
            "List relationships that must stay within one organization.",
            "Separate truly global reference data from tenant data."
          ],
          "implementationNotes": [
            "Use a bounded case/project/comment schema."
          ],
          "verification": [
            "Trace ownership from a case attachment to its organization.",
            "Identify an intentionally ambiguous relationship and mark it unresolved."
          ],
          "deliverables": [
            "Tenant ownership map"
          ],
          "rollout": "Review the map before migrations; keep ambiguous relationships out of new writes.",
          "skills": [
            "Relational modeling",
            "Tenant boundaries"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "49caf826-b680-4cea-812d-a9e20c0f8ec1",
          "key": "ATENANT-102",
          "title": "Add composite uniqueness for tenant-owned relationship targets",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "relations",
          "dependsOn": [
            "ATENANT-101"
          ],
          "scenario": "Globally unique row IDs do not by themselves let a foreign key enforce that case and project belong to the same organization.",
          "acceptanceCriteria": [
            "Add the composite target keys needed for tenant-bound references.",
            "Preserve existing globally unique identities.",
            "Document index duplication and selected constraint names."
          ],
          "implementationNotes": [
            "Inspect actual migration SQL and query patterns."
          ],
          "verification": [
            "Create identical display names in different organizations.",
            "Attempt a duplicate target identity within the same composite key and verify rejection."
          ],
          "deliverables": [
            "Composite-key migration"
          ],
          "rollout": "Apply additive keys first; remove only demonstrably redundant indexes after usage review.",
          "skills": [
            "Composite keys",
            "Migrations"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 80
            },
            {
              "field": "Security",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "89ac5d93-3131-4808-953c-bc5df79310d8",
          "key": "ATENANT-103",
          "title": "Reject null organization scope in protected repository methods",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 75,
          "phaseId": "relations",
          "dependsOn": [
            "ATENANT-101",
            "ATENANT-102"
          ],
          "scenario": "An optional organization argument defaults to an unscoped query when an internal caller forgets to pass it.",
          "acceptanceCriteria": [
            "Require nonempty scope in protected method signatures and validation.",
            "Remove unscoped fallback branches.",
            "Keep global reference methods explicitly separate."
          ],
          "implementationNotes": [
            "Test direct service calls rather than relying solely on controllers."
          ],
          "verification": [
            "Read a project using valid tenant scope.",
            "Omit scope at the runtime boundary and verify no database query executes."
          ],
          "deliverables": [
            "Required-scope repository contract"
          ],
          "rollout": "Deploy boundary validation before new callers; deny ambiguous internal requests.",
          "skills": [
            "Repository design",
            "Fail-closed handling"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Backend",
              "percentage": 30
            },
            {
              "field": "Database engineering",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "463bb75d-903c-44f3-a4e0-fab4a935875e",
          "key": "ATENANT-104",
          "title": "Enforce same-organization case-to-project references with a foreign key",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 210,
          "phaseId": "writers",
          "dependsOn": [
            "ATENANT-102",
            "ATENANT-103"
          ],
          "scenario": "An import can connect a case in one organization to a globally valid project in another organization.",
          "acceptanceCriteria": [
            "Create a composite foreign key including organization identity.",
            "Reject mismatched direct SQL and application writes.",
            "Retain valid same-organization associations."
          ],
          "implementationNotes": [
            "Backfill and inspect existing mismatches before validating the constraint."
          ],
          "verification": [
            "Insert a valid synthetic case/project relationship.",
            "Insert a cross-organization relationship directly and observe database rejection."
          ],
          "deliverables": [
            "Tenant-bound foreign-key migration"
          ],
          "rollout": "Validate after a clean discrepancy report; quarantine invalid legacy relationships without guessing ownership.",
          "skills": [
            "Foreign keys",
            "Tenant isolation"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "13d0ebf7-4a2e-4856-b01b-fec0425adde4",
          "key": "ATENANT-105",
          "title": "Keep case-comment inserts scoped during concurrent parent changes",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "writers",
          "dependsOn": [
            "ATENANT-104"
          ],
          "scenario": "A comment command checks the case once, then writes after an administrator changes related project state.",
          "acceptanceCriteria": [
            "Authorize and insert against current parent ownership in one boundary.",
            "Prevent parent reassignment that would violate child scope.",
            "Return a conflict rather than attach a comment ambiguously."
          ],
          "implementationNotes": [
            "Prefer immutable tenant ownership for existing entities."
          ],
          "verification": [
            "Insert a comment under stable ownership.",
            "Race a prohibited parent-scope change and verify no cross-tenant comment results."
          ],
          "deliverables": [
            "Comment transaction and ownership race test"
          ],
          "rollout": "Enable the guarded command; disable tenant reassignment paths that lack a migration protocol.",
          "skills": [
            "Transactions",
            "Ownership invariants"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 60
            },
            {
              "field": "Backend",
              "percentage": 20
            },
            {
              "field": "Security",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "f3cd284f-346b-40af-bbb1-422e7ca76bb7",
          "key": "ATENANT-106",
          "title": "Make bulk case imports validate every tenant relationship before commit",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 180,
          "phaseId": "writers",
          "dependsOn": [
            "ATENANT-103",
            "ATENANT-104",
            "ATENANT-105"
          ],
          "scenario": "A bulk import checks the organization of the first row but trusts project IDs in subsequent rows.",
          "acceptanceCriteria": [
            "Validate each relationship under the requested organization.",
            "Report row coordinates with nondisclosing reason codes.",
            "Follow an explicit all-or-nothing import contract."
          ],
          "implementationNotes": [
            "Use a synthetic file containing one cross-tenant project reference."
          ],
          "verification": [
            "Import a valid multi-row file.",
            "Place an invalid reference late in the file and verify zero case rows commit."
          ],
          "deliverables": [
            "Scoped bulk importer and late-row regression"
          ],
          "rollout": "Canary small synthetic imports; retain rejected files under bounded restricted storage.",
          "skills": [
            "Bulk validation",
            "Transactions"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 30
            },
            {
              "field": "Backend",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "67a0153c-3017-4319-b45b-ae2db9c09289",
          "key": "ATENANT-107",
          "title": "Carry tenant identity through background case-processing commands",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "writers",
          "dependsOn": [
            "ATENANT-103",
            "ATENANT-104",
            "ATENANT-106"
          ],
          "scenario": "The queue payload stores only a case ID, and the worker resolves its organization from mutable caller-supplied metadata.",
          "acceptanceCriteria": [
            "Bind durable command identity to case and authoritative tenant.",
            "Reload scoped state before each guarded mutation.",
            "Reject conflicting tenant metadata without executing the provider."
          ],
          "implementationNotes": [
            "Queue messages contain opaque IDs, not case contents or secrets."
          ],
          "verification": [
            "Process a valid tenant-bound synthetic command.",
            "Replay its case ID with another organization and verify no provider call or mutation."
          ],
          "deliverables": [
            "Scoped job command and replay-denial probe"
          ],
          "rollout": "Deploy worker guards before new dispatch; quarantine old commands lacking required authority.",
          "skills": [
            "Background authorization",
            "Idempotency"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 40
            },
            {
              "field": "Backend",
              "percentage": 30
            },
            {
              "field": "Distributed systems",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "464dc3ef-cc2c-48cd-ae75-3b733bf045e6",
          "key": "ATENANT-108",
          "title": "Find legacy cross-tenant references without exposing case contents",
          "type": "CHORE",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 180,
          "phaseId": "verify",
          "dependsOn": [
            "ATENANT-104",
            "ATENANT-107"
          ],
          "scenario": "The new constraint cannot validate until operators understand existing mismatches, but incident exports should not include case bodies.",
          "acceptanceCriteria": [
            "Report safe entity IDs and mismatch category only.",
            "Bound scans by table and cursor.",
            "Do not automatically choose which tenant should own an invalid relationship."
          ],
          "implementationNotes": [
            "Make the reconciliation command read-only."
          ],
          "verification": [
            "Scan a valid synthetic dataset with no mismatches.",
            "Insert a deliberate legacy mismatch in a fixture and identify its exact relationship."
          ],
          "deliverables": [
            "Tenant-integrity report"
          ],
          "rollout": "Run before constraint validation; repair only reviewed mappings through audited commands.",
          "skills": [
            "Data reconciliation",
            "Privacy"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 50
            },
            {
              "field": "Privacy engineering",
              "percentage": 30
            },
            {
              "field": "Security",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "ca9d9bb1-7d68-4a69-ba80-2c032cffb2c8",
          "key": "ATENANT-109",
          "title": "Verify tenant constraints through a least-privilege database writer",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "verify",
          "dependsOn": [
            "ATENANT-104",
            "ATENANT-105",
            "ATENANT-107",
            "ATENANT-108"
          ],
          "scenario": "Application tests pass, but direct SQL imports use a role that can bypass expected safeguards.",
          "acceptanceCriteria": [
            "Inventory grants for the application and import roles.",
            "Verify ordinary writers cannot disable constraints or change schema.",
            "Run same-tenant and cross-tenant write checks under the actual limited role."
          ],
          "implementationNotes": [
            "Use disposable local roles; do not alter production permissions."
          ],
          "verification": [
            "Write a valid relationship through the limited import role.",
            "Attempt cross-tenant insertion and constraint disabling and verify both are denied."
          ],
          "deliverables": [
            "Role/grant verification and direct-write tests"
          ],
          "rollout": "Apply the limited role in the local import path; stop imports if required checks are bypassable.",
          "skills": [
            "Database permissions",
            "Defense in depth"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 50
            }
          ],
          "patterns": []
        },
        {
          "id": "38e5bb46-c86d-4d82-8448-75e8c4aa5606",
          "key": "ATENANT-110",
          "title": "Document the tenant-data repair protocol and its non-goals",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "verify",
          "dependsOn": [
            "ATENANT-108",
            "ATENANT-109"
          ],
          "scenario": "Support wants to move an incorrectly linked case by editing organization IDs directly, risking a cascade of broken ownership.",
          "acceptanceCriteria": [
            "Require a reviewed explicit mapping and affected-relationship inventory.",
            "Preserve audit references and report unresolved children.",
            "Separate repairing a bad link from transferring entity ownership."
          ],
          "implementationNotes": [
            "Use one fabricated mismatch as the worked example."
          ],
          "verification": [
            "Repair a reviewed synthetic project link with all constraints enabled.",
            "Attempt an incomplete ownership transfer and stop before mutation."
          ],
          "deliverables": [
            "Tenant repair runbook"
          ],
          "rollout": "Review repairs in a disposable database first; retain invalid rows quarantined when ownership is uncertain.",
          "skills": [
            "Repair planning",
            "Data integrity"
          ],
          "fieldMix": [
            {
              "field": "Database engineering",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
