All writing

Field note 03 / Voice access

A dry run that kept a new rule from locking out paying subscribers

A flag to end voice access on a lapsed App Store period looked safe. A dry run against production data showed it was not, and traced the problem to an old repair job.

  1. 01

    Symptom

    A new flag would end voice access when an App Store subscription period had lapsed. Before it was turned on, a dry run listed every account it would deny, and some of them were paying subscribers.

  2. 02

    Diagnosis

    • Most of the flagged accounts had been written by the first version of an identity-mapping repair.
    • That repair took the first stored purchase row, ignored renewals, and never re-ran for users it had already repaired.
    • Upgrades were forwarded only to the paywall provider, so the stored product and period never changed.
  3. 03

    Fix

    • The repair job and the webhook now take product, period, and grace state from Apple's signature-verified current transaction, when the canonical account token resolves to exactly that user.
    • Live voice re-verifies with Apple before it denies anyone.
    • The enforcement flag stayed off until the stored data checked out.
What I do now

Prove the data before you enforce the rule

  1. Ship enforcement behind a flag that defaults to off.
  2. Dry-run the decision against production data and read the would-be denials by hand.
  3. Trace every surprising denial back to the writer that produced its data.
  4. Fix the writer, backfill from the signed source, then run the dry run again.
  5. Re-verify with the source of truth at the moment of denial.