Every row has an owner and a flag. The degraded mode is chosen in advance, not during an incident
Core writes (post, apply, message, connect) never depend on search, recommendations or notifications
The requirement's three examples map directly: recommendations down gives a chronological feed; notifications down, actions still succeed; search down, profile, feed and apply stay up
Mechanisms
Timeouts and circuit breakers per dependency, in the Rest.li client
Hodor sheds bot and prefetch traffic first
Kafka holds a notification backlog for up to 7 days
The red cells
Search switched off is visible to members, and accepted
Apply fails closed, because a lost application is worse than a retry