Consent & Privacy Service  ·  View 13 of 22  ·  Runtime

Critical Flow — A Withdrawal Reaches the Read Path

Fourteen messages, and the one self-call that decides whether the architecture is honest.

Editable source SVG draw.io All views
Subject Capture API Consent ledger Withdrawal stream Product service Decision API Audit store 1. POST /withdraw 2. purpose registered? 3. append entry 4. committed, v=1841 5. receipt: v=1841, 12:04:07Z 6. WithdrawalRecorded 7. invalidate subject 8. drop cached ALLOW 9. evaluate(S, ads.personalised) 10. projection v >= 1841? 11. DENY, basis=consent, v=1841 12. serve unpersonalised 13. sampled outcome 14. propagation lag Critical Flow — A Withdrawal Reaches the Read Path Message 10 is the whole design: the cache may be stale, so the decision carries the version it was computed from and the caller can tell. v 1.0 · owner Security & Identity Architecture

Decisions

  • Message 10 — "projection v ≥ 1841?" — is the design. The decision carries the version it was computed from, so a caller can tell whether it has an answer old enough to matter.
  • The receipt (message 5) is returned after the ledger commits and before the stream fans out. Durability is what was promised; propagation is what is published as a ceiling.
  • The product service drops its cached ALLOW on invalidation rather than waiting for a TTL, which is what makes the p95 propagation figure achievable at all.

Assumptions

  • Capture durably committed and acknowledged at p99 ≤ 200 ms; withdrawal visible at p95 ≤ 5 s.
  • Decision outcomes are audited at a sampled rate rather than exhaustively, at 120,000 decisions/second.

Risks

  • An invalidation that is lost leaves a stale ALLOW that nothing corrects until the cache's own staleness ceiling expires. The ceiling, not the event, is the actual guarantee.
  • Sampled decision audit means a specific disputed read may not be individually evidenced. The ledger proves what was permitted; the sample proves what the platform answered in general.