Leaderboard & Counting Service · View 09 of 21 · Structure
Decisions
- Counting, reading, configuration and operations are four separate surfaces with four different authorisation models. A single API with a mode flag would make "who may retract" a code review question.
- The client path can only write counters a tenant has declared client-writable, and only as the authenticated member. A trusted backend path exists precisely so that is not a limitation.
- Display names are resolved outbound, at read time, from the member directory — so the platform never becomes a second source of identity.
Contracts
- Batch of up to 500 events per call with per-event acceptance, so one bad event does not fail the batch.
- Conditional reads, so a polling client transfers nothing while the projection version has not advanced.
- Rank-change events are emitted asynchronously; standings and the log export leave as batch.
Deliberately omitted
- Workload identity on every service-to-service call, which would add an edge to every node here.
- A public read API for third parties — named and deferred.