All writingWhat I do now
Field note 03 / Voice access
A dry run that kept a new rule from locking out paying subscribers
A flag to end voice access on a lapsed App Store period looked safe. A dry run against production data showed it was not, and traced the problem to an old repair job.
- 01
Symptom
A new flag would end voice access when an App Store subscription period had lapsed. Before it was turned on, a dry run listed every account it would deny, and some of them were paying subscribers.
- 02
Diagnosis
- Most of the flagged accounts had been written by the first version of an identity-mapping repair.
- That repair took the first stored purchase row, ignored renewals, and never re-ran for users it had already repaired.
- Upgrades were forwarded only to the paywall provider, so the stored product and period never changed.
- 03
Fix
- The repair job and the webhook now take product, period, and grace state from Apple's signature-verified current transaction, when the canonical account token resolves to exactly that user.
- Live voice re-verifies with Apple before it denies anyone.
- The enforcement flag stayed off until the stored data checked out.
Prove the data before you enforce the rule
- Ship enforcement behind a flag that defaults to off.
- Dry-run the decision against production data and read the would-be denials by hand.
- Trace every surprising denial back to the writer that produced its data.
- Fix the writer, backfill from the signed source, then run the dry run again.
- Re-verify with the source of truth at the moment of denial.