beginner 3 min answer Multiple choice

A team has three weeks to launch and has agreed that exactly one corner will be cut. Four candidates are on the table. Which shortcut is the safe one to take?

technical-debtidentifiersdata-modelreversibilitydelivery
Pick one
Show the full answer Hide the answer

The principle

The cost of undoing a shortcut is set by how many parties have already read its shape, not by how much code it touched. An unpaginated admin screen is read by your own staff through one query in one module. Changing it later is 1 to 2 engineer-days: add a limit and an offset, ship it, nobody else is affected.

The other three all write their shape into something you do not control any more. That is what makes them expensive, and the expense arrives long after the launch.

What each of the other three actually costs

Sequential integer order ids in a public API. Customers build scripts on the id format within weeks, so changing it needs a versioned endpoint, a translation table kept forever, and a customer migration measured in quarters. Sequential ids also disclose volume: any customer can infer your order rate by placing two orders an hour apart, and can probe for other tenants' ids.

Floats in the ledger. 0.1 plus 0.2 is not 0.3 in binary floating point as standardised in IEEE 754 in 1985, so totals drift by fractions of a cent and reconciliation against the payment provider fails at a rate that grows with volume. The fix is not a code change: it is a backfill of historical rows whose true values you no longer have, because the error is already baked into what was stored.

Tenant rows with no tenant column. Every query in the system now needs to reconstruct ownership from something else, one bug leaks another customer's data, and a residency requirement later cannot be answered at all because you cannot say which rows belong to which jurisdiction. That is a rewrite of the data access layer plus a disclosure risk while it lasts.

The decision rule

Choose the shortcut whose blast radius on reversal is one module, and only if no stored data or external contract encodes the choice. Screens, internal reports, background job schedules, admin tooling and anything behind a feature flag qualify. Identifiers, stored money, tenancy keys, partition keys, public contracts and audit records do not, because the choice is copied into data and into other people's code the moment it ships.

When this is the wrong answer

If that admin screen is the tool used during incidents, an unpaginated list that times out on 50000 rows costs you exactly when minutes matter, and the shortcut becomes a reliability decision rather than a maintainability one. Check what the screen is for before agreeing it is cheap. The same test applies in reverse: a public id format is nearly free to change in the first month of a private beta with four design-partner customers, because nobody has built on it yet.

Why the other options fail

They are all genuine decisions teams make under deadline, and each is cheap on the day and expensive for years. The reason they cluster is that all three write into a place with no undo: an external contract, a stored value whose original is lost, or a schema whose omission cannot be inferred later. The admin screen writes into none of those.