TFD Bounded Context Map

Business ownership, public contracts, in-process events, projections, and isolated boundaries

TFD Bounded Context Map Business ownership, public contracts, in-process events, projections, and isolated boundaries Identity / Staff Access · RBAC · VIP Notes HTTP API · Architecture component · Implemented Identity / Staff Access RBAC · VIP Notes HTTP API Implemented Realtime Transport · Attendance + recorder projections after persistence · Architecture component · Not a domain context Realtime Transport Attendance + recorder projections after persistence Not a domain context Sales · Facts · historical staging · Architecture component · Implemented Sales Facts · historical staging Implemented VIP / CRM · VIP profile · internal notes · onboarding · Architecture component · Partial in Identity VIP / CRM VIP profile · internal notes · onboarding Partial in Identity Delivery · Programs · sessions · attendance · analysis · Architecture component · Implemented Delivery Programs · sessions · attendance · analysis Implemented Engagement · Snapshots · status · follow-ups · Architecture component · Implemented Engagement Snapshots · status · follow-ups Implemented Notifications · Role-aware preferences · staff inbox · realtime facts · Architecture component · Implemented Notifications Role-aware preferences · staff inbox · realtime facts Implemented Marketing · Tags · campaigns · marketing operations · Architecture component · Initial capability Marketing Tags · campaigns · marketing operations Initial capability Integrations · Source adapters · inboxes · links · media · Architecture component · Implemented Integrations Source adapters · inboxes · links · media Implemented Clinical · Explicit grants · VIP care workspace · Architecture component · Workspace implemented Clinical Explicit grants · VIP care workspace Workspace implemented Audit evidence · P0 facts · no content · Architecture component · Platform Audit evidence P0 facts · no content Platform consultation facts VIP + VIT references participation recorded snapshot failure facts staff actor + RBAC normalized provider operations allowlisted source records meeting/video facts · sender blacklist query session projections recorder projections analysis facts + actor id recording failure facts per-staff inbox changes required signals only source copies bounded facts Legend Security Message bus Backend External Database

Synchronous communication

  • • The Sales overview All About You contract exposes conversion_showed, the attendance denominator matched to confirmed became_vip contributions. Incomplete spreadsheet months and unknown Airtable outcomes no longer block other eligible records; excluded groups produce partial quality and an explicit basis warning. Source ownership, monthly provider precedence and undated-adjustment boundaries remain unchanged.
  • • Consultations follows the existing Integrations-to-Sales aggregate adapter boundary. Sales owns consultations campaign Silver, SalesConsultationMetricsGold and the overview read composition with individual Airtable facts. Published spreadsheet coverage takes monthly priority before date or attribution filters; unsupported dimensions and absent counts remain explicit. The manual import catalog, retry and publication preserve the consultations dataset independently from Registration and All About You.
  • • Business modules consume another context only through its explicit public contract
  • • All About You crosses the existing Integrations-to-Sales adapter boundary as approved aggregate cells, with worksheet-year correction and original date evidence. Sales owns separate aggregate/individual Silver and canonical SalesAllAboutYouGold. Spreadsheet coverage has monthly priority over Airtable before date/dimension filters. Undated adjustments require a complete month; unavailable attribution or conflicting VIP counts remain explicit. The overview exposes card-specific quality, nullable metrics and source freshness; private lineage never crosses to the browser.
  • • Composition roots may wire modules; internals remain private
  • • The public SubscriptionRenewalsService.listRenewingBetween read supplies the complete UTC upcoming-month Slack digest and matched-VIP subscription-ending facts using the same effective dates, package details and selection as the UI. The financials-authorized renewal queue projects one representative subscription per VIP before filtering and pagination, excluding canceled representatives, VIP Free and internal emails. VIP-scoped reads preserve complete subscription history and expose current VIP profile status independently of subscription selection; start dates and late-start state reuse VIP/CRM ownership and existing confirmation permissions
  • • VIP/CRM VipNotesService consumes ClinicalNotesService through clinical/public.ts; both contexts recheck their own grants
  • • The merged notes feed queries only readable kinds, orders by createdAt/id DESC, and binds its opaque cursor to VIP plus readable scope
  • • VipNotesController fixes scope to /vip-profiles/:vipId/notes, resolves the active StaffUser, and exposes no feed filters beyond pagination
  • • Marketing reads and replaces ActiveCampaign tags through the Integrations public contract
  • • Delivery may retain a provider URL as review evidence, but analysis resolves stable technical video ids through Integrations; private S3 keys never cross
  • • Spreadsheet imports hand reviewed Program Run VIP matches and explicit exclusions from Integrations to Delivery; Delivery remains the owner of Program Run membership
  • • Registration metrics cross from Integrations to Sales as allowlisted normalized records. Workbook title metadata identifies programs and editions from zoom-fbf-N-monthYY; worksheet names are authoritative over internal tags. Annual counts and explicit affiliate totals stay in their original monthly grain, with reviewed worksheet associations on campaign dimensions. Publication atomically writes Silver and Gold. Dashboard reads stored totals only, exposing shared edition scope and reporting-period dates separately from confirmed program campaigns. The legacy FBF Campaigns mapping remains optional; Zoom time-series quantities are not imported as registrations.
  • • Practice Better clients, tags and session notes remain Integrations-owned staging; explicit clinical read access protects the Imports workspace and an explicit second stage copies uniquely matched source records through the Clinical public service
  • • Integrations resolves unique existing VIPs and active staff authorization through Identity public services, then calls ClinicalSourceImportService; no raw Clinical models cross back
  • • Identity resolves active staff and existing VIPs for ClinicalWorkspaceService; Clinical owns summary and body-map revisions, explicit grants and content-free access audit. The UI reads exact-VIP video catalogs through the existing Integrations HTTP contract
  • • Clinical exposes an explicitly authorized, VIP-scoped YouTube catalog from current copied note revisions. The frontend opens an official privacy-enhanced YouTube iframe only on staff selection; only a validated video id and origin referrer cross to YouTube, never VIP identifiers or note content. Existing recording permissions remain separate
  • • Historical Sales reads use the Integrations public adapter for allowlisted Airtable pages; Sales owns leased checkpoints, immutable source versions and row validation. Missing records are retained for review; metric publication stays blocked
  • • Sales owns immutable metric-review revisions and sanitized decision pages for manual acquisition imports. Staff confirmation pins review id/hash; publication rechecks the active baseline and atomically supersedes changed facts with the selected FBF, All About You or Consultations projection. Missing metrics remain active for review; Airtable metric publication and legacy cutover remain blocked
  • • Sales owns organization-scoped import history and revision-checked cancel/retry routes. GET historical-imports/sources and the manual start page expose Registration, All About You and Consultations spreadsheet datasets. Existing Airtable historical reads retain review/resume/cancel and blocked publication; new-capture/restart controls are absent. Individual Airtable All About You and Consultations keep the configured Sales Overview cron; All About You conversion also writes canonical Gold
  • • Sales Overview shares inclusive UTC date bounds across cards. Membership keeps immutable snapshot and interval comparison rules. FBF1-FBF4 remain repeatable programs: reviewed worksheet names associate them with monthly editions without an extra mapping tab. The card labels registration, ad and affiliate figures as shared edition totals; monthly overlap selects whole reporting periods and no program delta is inferred. Confirmed single-program campaigns retain actual dates and same-program comparisons. A bounded organization-scoped Gold snapshot supplies saved reads. Unsupported attribution remains unavailable; context ownership and publication review are unchanged.
  • • Acquisition precision errors expose only approved metric labels, worksheet/cell references and decimal value/unit/scale evidence. Integrations converts percentage ratios without binary division artifacts; Sales retains immutable old captures and requires an explicit new capture for corrected values
  • • The complete existing Stripe import calls Sales MembershipHistoryService. Identity MembershipEvidenceService supplies sanitized VIP coverage and active pauses; Engagement supplies the last completed UTC week. Sales atomically versions daily MembershipCapture, per-VIP Silver and aggregate Gold, serving authorized /sales/overview/memberships with exact 30-day comparisons only when evidence is complete. No new worker, direct cross-context table reads or manual publication flow.
  • • Delivery exposes GET /vip-session-history to the VIP drawer under attendance.view. The paginated read combines current live and on-demand attendance with sessions within ProgramRunVip membership intervals; session dates and timezones remain Delivery-owned. Identity activity history is not the attendance source of truth.
  • • Delivery owns occurrence-scoped joined_by_mistake reviews through the attendance.manage candidate endpoint. A reviewed accidental join has no VIP or attendance link and does not block attendance finalization or Session Analysis assignment. Unlink restores needs_review; meeting reprocessing preserves human reviews. Existing manual attendance, analyses, and attendance supported by another candidate remain protected.
  • • Studio access: Identity authorizes video deletion and recovery through session_recordings.delete, inherited by administrators and separately grantable to non-admin staff; session_recordings.manage alone does not grant deletion. Delivery allows session_analysis.edit_own to soft-delete only an owned draft with no final render, checking ownership and draft state again in the write. The Integrations project catalog exposes the creating StaffUser id for accurate action visibility.
  • • Attendance opens the Integrations-owned recording blacklist through authenticated HTTP. attendance.view or recorder_operations.view lists all organization-scoped excluded names; attendance.manage or recorder_operations.manage adds or removes entries. Removal allows future recording without rewriting attendance. Video-source reads expose has_audio metadata so Studio can disable source audio controls for video-only media.
  • • Identity owns read-only staff impersonation (ADR 0070). Every HTTP request verifies the original Cognito JWT and current administrator authority, resolves an active target, and applies only target permissions and ownership. GET/HEAD are allowed; writes are rejected before controllers. Audit records the viewed StaffUser and verified original administrator; no credentials enter evidence.

Event communication

  • • MVP events are past-tense facts dispatched in process
  • • Owning modules persist durable state before events or realtime publication
  • • AddPipe media uses dedicated Redis request/result streams as infrastructure; Integrations emits on_demand.video.available only after private storage is durable
  • • Live Zoom and on-demand AddPipe use one normalized participant blacklist; a VIT decision blocks the same name in both media paths
  • • The availability fact preserves the provider's original availableAt so Delivery chooses the first strictly later scheduled occurrence
  • • Identity, Delivery, Sales, Integrations, Engagement, and scheduled jobs emit typed past-tense facts without importing or waiting for Notifications
  • • Staff-triggered Session Analysis assignment facts carry the acting StaffUser id; batch request creation emits one past-tense fact per assigned VIT with that batch's created-request count, and Notifications refreshes one consolidated inbox item
  • • Non-blocking Notifications listeners resolve direct StaffUser, assigned VIT, salesperson, and VIP-linked recipients independently
  • • New VIT forms and spreadsheet provisioning copy the approved creation permission preset into StaffUser.permissions; role vit remains grant-free at runtime, and delegation checks still prevent grants beyond the creator access
  • • Notification preferences: active StaffUsers read and update only their own /me subscriptions without administrative grants; admin read/list requires staff_users:read and admin updates require staff_users:update
  • • Notifications applies active-recipient eligibility, mandatory rules, persisted per-staff overrides, then catalog defaults; staff-access changes are always enabled
  • • Assignment, due-date, attendance attention/incident, subscription-ending, consultation-processing, and VIP-break facts use stable per-target dedupe keys. Weekly renewal digests use the public effective-renewal queue, project once per staff/UTC Monday week, require financials:read and effective subscription, and link to the matched 90-day queue
  • • In-process notification source facts are best effort across process termination; guaranteed recovery requires a future transactional outbox
  • • Notifications emits notification.projection.committed only after its inbox write; an asynchronous bridge publishes notification.projection.changed locally and through Redis to authorized staff rooms
  • • Internal and Clinical note lifecycle facts carry identifiers and revision only; Clinical timeline rows and counts require the explicit read grant
  • • A linked Zoom meeting requests recorder bots after any participant joins when an authorized StaffUser host is present; per-user OAuth enables owner-first OBF with co-host fallback
  • • Delivery owns monitored Meeting IDs and their optional expected session time on ProgramRun; Bot Management selects only configured run time slots and propagates IDs to matching occurrences
  • • The recorder dashboard combines durable attendance presence, signed Zoom breakout-room membership events, and short-lived recorder camera snapshots only after each owning state change persists

Current alignment risks

  • • VIP/CRM and VIT operations still live partially inside the Identity source module
  • • Dashed relationships are planned or policy-level boundaries, not guaranteed runtime calls

Sensitive boundaries

  • • Clinical content stays isolated and exposes only required operational summaries
  • • Realtime transports authorized projections and never becomes a source of truth
  • • Attendance consumes authorized recorder status and capacity projections; durable attendance remains owned by Delivery
  • • Integrations owns provider media metadata and the shared Zoom/AddPipe participant blacklist; Delivery owns candidates, pending review, atomic occurrence-scoped linking, relocation, and explicit analysis
  • • Registration workbook credentials and raw cells stay outside frontend and Sales contracts; only masked identity and aggregate reconciliation are exposed; the manual preview resolves two exact affiliate-tab aliases to one stable historical identity and returns HTTP 400 for missing or ambiguous required tabs
  • • Clinical owns the experimental movement lab browser workspace: explicit tab-sharing consent creates a temporary local clip, preview and movement detection stay in memory, and no Clinical or Delivery record is written. Integrations retains legacy staff-scoped YouTube import routes, unused by the lab UI.

Audit P0 and P1 coverage

  • • Identity, Clinical, Sales, Delivery and Integrations retain their state; Audit receives bounded facts through the synchronous public contract
  • • Staff/RBAC, Clinical and attendance/evidence changes commit with Audit. Private media and sensitive VIP concessions await durable evidence before disclosure
  • • Integrations owns MediaDeletionJob: committed intent blocks playback, leased bounded retries remove private objects, completion and Audit commit together; terminal failure has an authorized repair path
  • • Audit HTTP queries use explicit independent read, restricted-metadata and export grants, server organization scope and validated unsigned pagination; every page reapplies authorization and query limits. No Audit secret is required. Retention is held without automatic purge or receipt expiry
  • • P1 adds manual VIP changes, VIT assignment decisions, Program Run creation, manual attendance and named soft archives; existing video decisions retain one P0 fact and owner histories remain independent
  • • Staff Audit UI uses the canonical query contract; no Identity StaffAuditLog. Breaks, follow-ups, analysis and run changes retain owner transactions and publish timeline facts after commit.

Transcript reuse — ADR 0069

  • • Shared Transcript Processing runs inside the monolith. Source authorities and assessment owners register public ports; original/candidate content stays in owner schemas.
  • • Sales owns commercial sources/assessments; Clinical owns private transcripts and VIP review; Delivery owns PrivateConsultation schedules and VIT quality assessments.
  • • Owner-held candidates remain sensitive. Reviewed releases gate shared indexing and external processing; explicit actor, purpose and source grants gate retrieval.
  • • Owners invoke the lifecycle contract inside source corrections. After-commit release/index/revocation/supersession facts contain identifiers only. See tfd-transcript-reuse for detailed boundaries.