Platform acknowledges ADR-0040 and approves a scoped, audited Revenue balance-reconciliation operation
Platform position
Platform acknowledges ADR-0040 and approves the architecture. Delivery remains the operator surface and operator-authorization owner. Revenue remains the sole writer of CreditAccount.balanceCredits and the owner of the reconciliation transaction. Platform owns the workload authority and stewards the shared contract.
The operation is acceptable because it repairs only Revenue's stored projection from current authoritative Revenue facts. It does not alter ledger entries, reservation state, recognition, lesson history, or a correction-apply record. Preview remains read-only, reconciliation remains an explicit operator action, and Delivery must discard the authorizing preview and obtain a fresh ready preview before enabling confirmation.
This acknowledgment clears Platform's approval gate. It does not authorize a write from a stale memo snapshot or permit Delivery to bypass stored_ledger_balance_drift. Revenue must re-derive and guard every financial fact inside the transaction that performs the projection repair.
Workload scope
Platform approves the exact additive scope revenue.lesson-outcome-corrections.balance-reconcile for the existing Delivery production to Revenue workload policy. The scope is distinct from preview and apply. It grants no general credit-account write authority and must not be interpreted through prefix or wildcard matching.
The existing ADR-0039 bounds continue to apply: sub: system:delivery, aud: revenue, the canonical tenant and Organization reach, a five-minute maximum lifetime, exact scope enforcement, and a unique jti. Revenue must additionally verify that the token Organization reach contains the preview-bound account's Organization and that the authenticated operation, correction identity, lesson, reservation when present, Person, and credit account all resolve to the same preview-bound facts.
Audit and failure behavior
Platform's issuer audit remains the service-auth source for workload policy, subject, audience, tenant, Organization reach, scopes, jti, issuance result, and denial reason. Revenue's mutation audit must durably record the Delivery correction id, operator actor, account id, expected and observed stored balance, transactionally derived ledger balance, qualifying ledger entry count, open-reservation total, account version, result, request or correlation id, and workload-token jti. Bearer tokens and opaque preview tokens must not be logged.
reconciled and noop are the only successful outcomes. Changed preview facts, ambiguous resolution, an additional blocker, failed Organization binding, missing exact scope, or failed audit persistence must return a non-mutating error. The account update and Revenue audit marker must commit atomically.
Contract publication
Platform approves an additive amendment to the lesson-outcome-correction API and service-auth scope vocabulary with these boundaries. Delivery and Revenue still need to settle the exact endpoint, request, response, blocker, replay, and preview-token binding shape as ADR-0040 co-owners. After they record that agreement and ADR-0040 reaches Accepted, Platform will publish the accepted contract text and scope through the canonical coordination contracts.
Contract publication is a rollout gate, not a second Platform architecture decision. Revenue may continue using its existing guarded incident-repair procedure meanwhile. The in-product operation must not be enabled until Revenue implements the accepted shape, Delivery refreshes after repair, and the controlled production validation required by ADR-0040 succeeds.
Incident boundary
The June 19 lesson identified in Delivery's request remains unchanged. Platform's acknowledgment approves the reusable recovery path only. It does not apply the July 10 cancellation or direct Revenue to write a balance value of 2 from the memo. Revenue must preflight the current ledger and reservation state, repair the projection if the transaction guards still pass, and return a fresh preview before Delivery can ask the operator to confirm that correction.
References
- ADR-0040:
adrs/ADR-0040-delivery-ui-revenue-balance-reconciliation.md - Delivery request:
2026-08-02-delivery-corrigan-credit-balance-drift-prevention - ADR-0038:
adrs/ADR-0038-guarded-lesson-outcome-corrections.md - ADR-0039:
adrs/ADR-0039-platform-issued-workload-identity.md - Correction API proposal:
contracts/credit-reservation-lock/lesson-outcome-correction-api-proposal.md - Service-auth contract:
contracts/service-auth/README.md