Specs.
The data-model layer — entity relationships, row-level isolation policies, and strict contracts. The structural decisions made before the first migration runs, defined precisely enough to build from.
10 specs
- Data Model5 invariants
RBAC permission model
Server-owned roles, tenant-scoped assignments, and default-deny checks — with a consistency model that's explicit about caching windows, replica lag, and the failure modes where the guarantees weaken. Principles, decisions, and known limits, kept separate.
- PostgreSQL
- RBAC
- Authorization
- Security Contract6 invariants
Session and token lifecycle contract
How tokens are issued, verified, stored, refreshed, and revoked: verified access tokens, rotating single-use refresh tokens with reuse detection, hashed server-side storage, platform-specific client storage, and revocation with a bounded staleness window.
- JWT
- OAuth
- Authentication
- Data Model6 invariants
Offline-first sync and conflict model
Records that live on the device and reconcile with a server: collision-resistant IDs, client/server versioning with base_version conflict detection, field-level merge with custom resolvers, server-enforced scope, idempotent failure handling, and paginated delta-sync for scale.
- SQLite
- Sync
- Mobile
- Job Contract7 invariants
Async write and job contract
The rules for work moved off the request path: 202 means accepted not applied, jobs carry IDs and re-load state, commit-then-ack backed by idempotency, explicit ordering and coordination, bounded payloads, declared timeouts, and queues you can actually see.
- Queues
- Laravel
- Async
- Data Model6 invariants
Append-only audit log model
A tamper-evident record of who did what, when, and to what — append-only against the application, hash-chained so alterations are detectable, and anchored externally to catch even a full-chain rewrite.
- PostgreSQL
- Audit
- Compliance
- Data Model8 invariants
Regulated quantity-limit model
The data model and enforcement contract for a statutory rolling-window purchase limit: a fail-closed control, a boot-time-validated window, and an immutable compliance-decision log that proves every check ran.
- PostgreSQL
- Compliance
- Regulated systems
- API Contract8 invariants
Idempotent webhook ingestion contract
The strict contract for receiving at-least-once webhooks: verify the signature, dedupe on the provider's event ID via an atomic insert, apply the effect in the same transaction, and always answer 2xx once accepted.
- Webhooks
- Idempotency
- Stripe
- Data Model6 invariants
Serialised inventory and stock model
Two representations of the same goods — an aggregate count and individually-tracked units — kept consistent by a single state machine and a database-checkable invariant, so a drift between the ledger and the shelf is caught the same day by reconciliation, not discovered at stocktake.
- PostgreSQL
- Inventory
- State machines
- Data Model7 invariants
Money and ledger data model
Money as integer minor units, a double-entry ledger whose lines always sum to zero, and the constraints that make “the books don’t balance” a write error instead of a month-end discovery.
- PostgreSQL
- Double-entry
- Financial systems
- Isolation Policy8 invariants
Row-level tenant isolation policy
The single-database isolation model: a mandatory tenant key, a default-deny global scope, an explicit bypass registry, and a database-enforced backstop. Where the request scope dies and what carries the tenant across it.
- PostgreSQL
- Laravel
- Row-Level Security