Designing Data-Intensive Applications
Case 8

Requirements and Constraints

Multistep workflows span services, minutes to days, and must survive partial failure.

Checkout, trip lifecycle, and loan origination are the same shape: forward steps with explicit failure branches, not a prayer that every service stays up.

Shopify at scale

Checkout coordinates inventory holds, Stripe charges, and fulfillment webhooks. A card decline must release the hold before the customer sees an error.

Define invariants first

What must never happen? Double charge, ship without payment, lose inventory on crash. Invariants pick orchestration vs choreography.

Key Takeaways
  • No single database transaction spans payment, inventory, shipping, and email.
  • Each step must be idempotent — retries cannot double-charge or double-ship.
  • Compensating actions roll back prior steps when a later step fails.
  • Human review gates (KYC, underwriting) can park a flow for days.
  • Visibility: ops must see which step failed and with what payload.
  • Correlation ID ties every HTTP call and queue message to one saga instance.
requirementssagaidempotencycompensationworkflow