CRM minimal change event
Fingerprint + revision + assessment reference. No name, diagnosis, feature, score, explanation, or raw profile.
Business flow · Option B
A minimal trusted CRM signal converges on the latest revision, clinics receive fair worker time, and the reservation transaction protects existing commitments. Raw profile data never crosses this boundary.
Fingerprint + revision + assessment reference. No name, diagnosis, feature, score, explanation, or raw profile.
Verify producer, signature, issuer, audience, hash, schema, replay window, and clinic scope. Merge duplicates and mark older jobs stale.
HELD before PROPOSED across clinics, with global and per-clinic concurrency, keyset pages, DB leases, and bounded work.
Resolve the opaque reference at processing time over fixed-host HTTPS. Strict response size, schema, identity, timeout, and concurrency limits.
Lock current revision and reservation version. Apply only an eligible latest decision; allocation replacement and outbox write share one transaction.
Persist outcome class, minimal audit, and low-cardinality metrics. Never label metrics with tenant, clinic, patient, appointment, or event IDs.
Supersede the current proposal with the latest valid candidate. No active allocation is released.
Keep a valid hold; otherwise acquire the replacement before releasing the old allocation. If replacement is unavailable, fall back to `PROPOSED` without duplicate allocation.
The customer commitment remains unchanged. A profile event cannot cancel, move, replace, or silently reinterpret it.
Retry with jitter and elapsed-time caps. Expired leases are reclaimed; exhausted jobs require scoped preview and redrive. Newer revisions make older work stale.
Quarantine an encrypted bounded envelope, stop unsafe ingress, preserve evidence, and investigate with security/privacy and CRM owners. Do not turn it into a normal retry.