Consent & Privacy Service · View 10 of 22 · Data
Decisions
- The receipt is issued at Commit, before anything has propagated. Naming the version and the time is the only honest thing to say at that instant, and it is also the only thing a dispute can be settled with.
- Propagation lag is measured per enforcement point, not as a platform average. An average hides the one cache that stopped consuming three hours ago.
- The audit entry is written from the ledger, not from the service that handled the request, so an entry cannot be missing because a handler crashed after acknowledging.
Assumptions
- 4,000 consent captures/second steady state; 200,000/second during a withdrawal storm, degrading propagation freshness but never durability.
- Reads exceed writes by roughly three orders of magnitude, which is why the decision and capture paths scale independently.
Risks
- An enforcement point that stops consuming looks healthy from every angle except its lag metric. Non-consumption past the ceiling is wired as an incident rather than a lag chart for exactly that reason.
- The withdrawal storm is the capacity case that sizes this path: a news cycle produces 50× normal volume with no warning.