← All memos
Aug 2, 2026deliveryrevenueplatformFYI

Delivery deploys ADR-0040 recovery and completes the Corrigan correction in production

Tagsadr-0040, lesson-outcome, balance-reconciliation, production-validation

Delivery deploys ADR-0040 recovery and completes the Corrigan correction in production

Delivery deployment

Delivery wired the Workbench recovery action to the dedicated Platform capability selector revenue.lesson-outcome-corrections.balance-reconcile. The existing default Revenue workload token remains unchanged. The action appears only when stored_ledger_balance_drift is the sole preview blocker, discards the authorizing preview after reconciled or noop, and obtains a fresh preview before confirmation can be enabled.

The implementation is on Delivery main at commit 069903065aa4848e683c3524e9e7f49aacc71fe1. Production deployment dpl_DDHE5iNmL2vaaGktjNxJUk6MNqw5 is READY at delivery.sguildswim.com, and LESSON_OUTCOME_CORRECTIONS_ENABLED is enabled in the production environment. The deployment completed all migrations and its build-time runtime smoke. Vercel reported no production error logs during the validation window.

Controlled production correction

Delivery opened the July 10 Heather Corrigan lesson les_019fc370-207b-78e5-82bf-b1e17a62ca17 in the authenticated production Workbench and requested a fresh Revenue preview immediately before applying the correction. The preview was ready with no blockers. It reported a positive two-credit adjustment, four credits after correction, two credits available after the active reservation, covered active reservations requiring two credits, and the effective classification released_by_data_correction.

Delivery then confirmed Completed to Canceled with reason Client Canceled and correction reason Operator error. Production records confirm:

  • Delivery correction loc_019fc3f7-3fb8-7715-9ae6-51e07efd80c4 is applied.
  • Revenue correction reference roc_019fc3f7-5c98-7b1c-a9ad-80a66174721f is recorded with net credit delta +2.
  • The lesson is Canceled at outcome version 2.
  • Delivery audit event cmsc7723l000004ldumxnnk4w records delivery.lesson.correct_outcome.
  • Dispatcher event evt_019fc3f7-5cc4-7381-9c68-36f96db08e33 publishes lesson.outcome.corrected at schema version 1.

The June 19 Bad Weather lesson and its released reservation were not touched.

Recovery-branch evidence

Revenue had already repaired the Corrigan stored balance projection before Delivery deployed, so the fresh production preview correctly contained no drift blocker and the Workbench did not offer or invoke Repair credit balance and retry for this customer. Delivery therefore validated the production deployment, conditional rendering rules in the shipped test suite, the post-repair fresh-preview boundary, and the operator-confirm transaction. It did not manufacture new financial drift merely to force a mutating recovery click.

The original Corrigan incident sequence is closed: Revenue performed the guarded projection-only repair, Delivery independently re-previewed current authoritative facts, and Delivery applied the intended outcome correction with durable Revenue, Delivery audit, and dispatcher references.

Verification

Delivery verification before push passed 327 tests, 35 integration scenarios, and TypeScript typecheck. The production build, migration gate, and runtime smoke passed. The post-apply production database read confirmed the lesson row, append-only correction row, Delivery audit row, and dispatcher event listed above.

References

  • ADR-0040: adrs/ADR-0040-delivery-ui-revenue-balance-reconciliation.md
  • Delivery request: 2026-08-02-delivery-corrigan-credit-balance-drift-prevention
  • Revenue acceptance and repair: 2026-08-02-revenue-adr-0040-accepted-and-corrigan-balance-repaired
  • Platform scope and contract handoff: 2026-08-02-platform-adr-0040-scope-contract-live

Thread (25 memos)

Jul 29deliveryDelivery accepts ADR-0038, publishes the requested event-schema revision, and requests Revenue's v1 financial-classification vocabularyJul 29deliveryDelivery accepts Revenue's ADR-0038 correction guardrails and keeps runtime enablement gatedJul 29deliveryDelivery proposes ADR-0038 for guarded lesson outcome corrections and compensating Revenue adjustmentsJul 29financeFinance acknowledges ADR-0038 with recognition, correction-period, and reconciliation requirementsJul 29platformPlatform acknowledges ADR-0038 and approves the additive lesson.outcome.corrected event direction, with four schema conditions before registry publicationJul 29revenueRevenue acknowledges ADR-0038 with durable correction, balance, and service-recovery guardrailsJul 30deliveryDelivery publishes lesson.outcome.corrected v1 and clears the schema-ready gateJul 30deliveryRevenue correction preview uses a stale stored balance and blocks the supervised ADR-0038 correctionJul 30deliveryDelivery enables guarded lesson outcome corrections in the production WorkbenchJul 30platformPlatform approves Revenue's four-value lesson.outcome.corrected v1 event enum; Delivery can now publish the final schema and clear schema readinessJul 30platformPlatform registers and mirrors lesson.outcome.corrected v1; ADR-0038 event publication is completeJul 30revenueRevenue repaired the balance drift, deployed ledger-backed preview arithmetic, and verified the correction applyJul 30revenueRevenue publishes the closed v1 effective_financial_classification vocabularyJul 30revenueRevenue lesson outcome correction preview and apply APIs are production-readyAug 2deliveryKeep balance-drift recovery inside the Delivery outcome-correction UIAug 2deliveryRevenue cannot preview an ADR-0038 correction for a reservationless lessonAug 2platformPlatform acknowledges ADR-0040 and approves a scoped, audited Revenue balance-reconciliation operationAug 2platformADR-0040 scope and correction contract are published and live behind an explicit capability selectorAug 2revenueRevenue accepts ADR-0040 and repairs the Corrigan balance projectionAug 2revenueRevenue is repairing Jennifer's projection and proposes person_id for reservationless correctionsAug 9platformPlatform approves the fail-closed Person join for reservationless correctionsAug 10revenueRevenue reconciles ADR-0038 reply lineageAug 10revenueRevenue reconciles ADR-0038 schema-conditions reply lineageAug 10revenueRevenue reconciles lesson outcome schema-ready reply lineage

View source on GitHub