# Transactions / State / Concurrency

> Every principle in this category is listed as a record.

Page: Ontology · Principles
Canonical: https://banes-lab.com/ontology#architecture-category-transactions-state-concurrency

Listed in [Ontology · Principles](https://banes-lab.com/api/pages/ontology/principles.md), after [Taxonomy / Classification / Naming](https://banes-lab.com/ontology/principles/architecture-category-taxonomy-classification-naming.md).

Every principle in this category is listed as a record. Each record carries its kind, its severity, the scopes it applies at and the layer it lives in, then the edge relations that join it to other records, the records that point back at it, the contracts that answer to it and the tensions it takes part in. The descriptors say how it is violated, detected, measured, repaired and enforced. Where the record carries one, an exemplar shows the shape before and after the principle is applied.

Relations diagram

The relations inside this category.

```mermaid
flowchart LR
n_idempotency["Idempotency"]
n_atomicity["Atomicity"]
n_acid["ACID"]
n_transaction_boundary["Transaction Boundary"]
n_unit_of_work_pattern["Unit of Work Pattern"]
n_consistency["Consistency"]
n_isolation["Isolation"]
n_concurrency_control["Concurrency Control"]
n_optimistic_locking["Optimistic Locking"]
n_pessimistic_locking["Pessimistic Locking"]
n_state_isolation["State Isolation"]
n_controlled_side_effects["Controlled Side Effects"]
n_petri_nets["Petri Nets"]
n_atomicity --> n_transaction_boundary
n_atomicity --> n_consistency
n_acid --> n_atomicity
n_acid --> n_consistency
n_acid --> n_isolation
n_transaction_boundary --> n_atomicity
n_transaction_boundary --> n_unit_of_work_pattern
n_unit_of_work_pattern --> n_transaction_boundary
n_unit_of_work_pattern --> n_atomicity
n_unit_of_work_pattern --> n_consistency
n_isolation --> n_concurrency_control
n_concurrency_control --> n_isolation
n_optimistic_locking --> n_concurrency_control
n_pessimistic_locking --> n_isolation
```

### Idempotency

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: API, command, message handler
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A design rule that repeating an operation with the same input has the same effect as running it once.

Requires
[Idempotency Key or Deterministic Operation](https://banes-lab.com/records/lexicon/idempotency-key-or-deterministic-operation.md)

Reinforces
[Retry Safety](https://banes-lab.com/records/lexicon/retry-safety.md), [Event-Driven Architecture](https://banes-lab.com/records/architecture/event-driven-architecture.md)

Enables
[Safe Retries](https://banes-lab.com/records/lexicon/safe-retries.md)

In tension with
[State Tracking](https://banes-lab.com/records/lexicon/state-tracking.md)

Conflicts with
[Non-Repeatable Side Effects](https://banes-lab.com/records/lexicon/non-repeatable-side-effects.md)

Referenced by
[Event-Driven Architecture](https://banes-lab.com/records/architecture/event-driven-architecture.md), [Eventual Consistency](https://banes-lab.com/records/architecture/eventual-consistency.md), [Saga Pattern](https://banes-lab.com/records/architecture/saga-pattern.md), [Retry Pattern](https://banes-lab.com/records/architecture/retry-pattern.md), [Canonicalization](https://banes-lab.com/records/architecture/canonicalization.md)

Tensions
[Idempotency / State Tracking](https://banes-lab.com/records/tension/idempotency-state-tracking.md)

Violated by
duplicate charges/orders/messages on retry

Detected by
side-effectful handlers without deduplication

Measured by
duplicate-effect defect rate

Refactored by
Add Idempotency Key, Add Dedup Store

Enforced by
retry tests, API policy

Before

```typescript
app.post("/foo", async request => fooStore.create(await request.json()));
```

After

```typescript
app.post("/foo", async request => {
const key = requireHeader(request, "Idempotency-Key");
const body = await request.json();
return idempotency.execute(key, () => fooStore.create(body));
});
```

How it is checked

Checked by
retry tests, API policy

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Idempotency Key or Deterministic Operation](https://banes-lab.com/records/lexicon/idempotency-key-or-deterministic-operation.md), [Retry Safety](https://banes-lab.com/records/lexicon/retry-safety.md), [Event-Driven Architecture](https://banes-lab.com/records/architecture/event-driven-architecture.md), [Safe Retries](https://banes-lab.com/records/lexicon/safe-retries.md)

Shape it refuses
[Non-Repeatable Side Effects](https://banes-lab.com/records/lexicon/non-repeatable-side-effects.md)

### Atomicity

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: transaction, operation, workflow
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A design rule that the steps of a state change either all take effect or none do.

Requires
[Transaction Boundary](https://banes-lab.com/records/architecture/transaction-boundary.md)

Reinforces
[Consistency](https://banes-lab.com/records/architecture/consistency.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md)

Enables
[All-or-Nothing State Change](https://banes-lab.com/records/lexicon/all-or-nothing-state-change.md)

In tension with
[Distributed Scalability](https://banes-lab.com/records/lexicon/distributed-scalability.md)

Conflicts with
[Partial Commit](https://banes-lab.com/records/lexicon/partial-commit.md)

Referenced by
[ACID](https://banes-lab.com/records/architecture/acid.md), [Transaction Boundary](https://banes-lab.com/records/architecture/transaction-boundary.md), [Unit of Work Pattern](https://banes-lab.com/records/architecture/unit-of-work-pattern.md)

Contracts
[Atomic Boundary](https://banes-lab.com/records/algorithms/atomic-boundary.md)

Tensions
[Atomicity / Distributed Scalability](https://banes-lab.com/records/tension/atomicity-distributed-scalability.md)

Violated by
partial updates after failure

Detected by
multi-step writes without transaction/compensation

Measured by
partial failure rate

Refactored by
Add Transaction, Add Saga/Compensation

Enforced by
transaction tests

Before

```typescript
await fooStore.remove(from, foo.id);
await fooStore.add(to, foo.id);
```

After

```typescript
await database.transaction(async tx => {
await tx.foos.remove(from, foo.id);
await tx.foos.add(to, foo.id);
});
```

How it is checked

Checked by
transaction tests

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Transaction Boundary](https://banes-lab.com/records/architecture/transaction-boundary.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md), [All-or-Nothing State Change](https://banes-lab.com/records/lexicon/all-or-nothing-state-change.md)

Shape it refuses
[Partial Commit](https://banes-lab.com/records/lexicon/partial-commit.md)

### ACID

- Kind: [model](https://banes-lab.com/records/kind/model.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: database, transaction
- Aliases: Atomicity, Consistency, Isolation, Durability
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A conceptual representation of the four guarantees of a database transaction: atomicity, consistency, isolation and durability.

Requires
[Atomicity](https://banes-lab.com/records/architecture/atomicity.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md), [Isolation](https://banes-lab.com/records/architecture/isolation.md), [Durability](https://banes-lab.com/records/lexicon/durability.md)

Reinforces
[Correctness](https://banes-lab.com/records/architecture/correctness.md)

Enables
[Strong Transactional Guarantees](https://banes-lab.com/records/lexicon/strong-transactional-guarantees.md)

In tension with
[Distributed Availability](https://banes-lab.com/records/lexicon/distributed-availability.md), [BASE/Eventual Consistency](https://banes-lab.com/records/lexicon/base-eventual-consistency.md)

Conflicts with
none

Tensions
[ACID / Distributed Availability](https://banes-lab.com/records/tension/acid-distributed-availability.md), [ACID / BASE/Eventual Consistency](https://banes-lab.com/records/tension/acid-base-eventual-consistency.md)

Distinct from
[BASE/Eventual Consistency](https://banes-lab.com/records/lexicon/base-eventual-consistency.md): ACID keeps each transaction atomic, consistent, isolated and durable, while BASE favors availability and lets replicas converge later.

Violated by
inconsistent transactional boundaries

Detected by
non-transactional multi-write invariants

Measured by
transactional invariant defects

Refactored by
Define Transaction Boundary, Add Constraints

Enforced by
DB transactions, isolation tests

Before

```typescript
await fooDb.write(foo);
await barDb.write(bar);
```

After

```typescript
await database.transaction({ isolation: "serializable" }, async tx => {
await tx.foos.save(foo);
await tx.bars.save(bar);
assertInvariant(foo, bar);
});
```

How it is checked

Checked by
DB transactions, isolation tests

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Atomicity](https://banes-lab.com/records/architecture/atomicity.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md), [Isolation](https://banes-lab.com/records/architecture/isolation.md), [Durability](https://banes-lab.com/records/lexicon/durability.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md), [Strong Transactional Guarantees](https://banes-lab.com/records/lexicon/strong-transactional-guarantees.md)

Shape it refuses
Not answered

### Transaction Boundary

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: unit of work, aggregate, service
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A rule or precondition that a transaction covers exactly the writes of one unit of work inside one service.

Requires
[Consistency Rules](https://banes-lab.com/records/lexicon/consistency-rules.md)

Reinforces
[Atomicity](https://banes-lab.com/records/architecture/atomicity.md), [Unit of Work Pattern](https://banes-lab.com/records/architecture/unit-of-work-pattern.md)

Enables
[Safe State Mutation](https://banes-lab.com/records/lexicon/safe-state-mutation.md)

In tension with
[Large Transaction Scope](https://banes-lab.com/records/lexicon/large-transaction-scope.md)

Conflicts with
[Hidden Distributed Transaction](https://banes-lab.com/records/lexicon/hidden-distributed-transaction.md)

Referenced by
[Atomicity](https://banes-lab.com/records/architecture/atomicity.md), [Unit of Work Pattern](https://banes-lab.com/records/architecture/unit-of-work-pattern.md)

Contracts
[Transaction Boundary](https://banes-lab.com/records/algorithms/transaction-boundary.md)

Tensions
[Transaction Boundary / Large Transaction Scope](https://banes-lab.com/records/tension/large-transaction-scope-transaction-boundary.md)

Distinct from
[Consistency Rules](https://banes-lab.com/records/lexicon/consistency-rules.md): A transaction boundary fixes which writes one transaction covers, while consistency rules are the invariants it must keep inside that scope.

Violated by
spanning transactions across service boundaries

Detected by
transaction scope leakage

Measured by
transaction size/duration

Refactored by
Shrink Boundary, Add Saga

Enforced by
transaction policy

Before

```typescript
await beginTransaction();
await controller.parse(request);
await service.validate(foo);
await repository.save(foo);
await commitTransaction();
```

After

```typescript
async function createFoo(input: CreateFoo) {
const foo = validateFoo(input);
return database.transaction(tx => new FooRepository(tx).save(foo));
}
```

How it is checked

Checked by
transaction policy

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Consistency Rules](https://banes-lab.com/records/lexicon/consistency-rules.md), [Atomicity](https://banes-lab.com/records/architecture/atomicity.md), [Unit of Work Pattern](https://banes-lab.com/records/architecture/unit-of-work-pattern.md), [Safe State Mutation](https://banes-lab.com/records/lexicon/safe-state-mutation.md)

Shape it refuses
[Hidden Distributed Transaction](https://banes-lab.com/records/lexicon/hidden-distributed-transaction.md)

### Unit of Work Pattern

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: application service, persistence
- Aliases: Unit of Work
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A design pattern that collects the changes of one use case and commits them together in a single transaction.

Requires
[Transaction Boundary](https://banes-lab.com/records/architecture/transaction-boundary.md)

Reinforces
[Atomicity](https://banes-lab.com/records/architecture/atomicity.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md)

Enables
[Coordinated Persistence](https://banes-lab.com/records/lexicon/coordinated-persistence.md)

In tension with
[Repository Complexity](https://banes-lab.com/records/lexicon/repository-complexity.md)

Conflicts with
[Scattered Save Calls](https://banes-lab.com/records/lexicon/scattered-save-calls.md)

Referenced by
[Transaction Boundary](https://banes-lab.com/records/architecture/transaction-boundary.md)

Tensions
[Unit of Work Pattern / Repository Complexity](https://banes-lab.com/records/tension/repository-complexity-unit-of-work-pattern.md)

Violated by
unmanaged partial persistence

Detected by
multiple independent saves in one use case

Measured by
save coordination defects

Refactored by
Introduce Unit of Work

Enforced by
persistence conventions

Before

```typescript
await fooRepository.save(foo);
await barRepository.save(bar);
await eventRepository.save(event);
```

After

```typescript
const uow = unitOfWork.begin();
uow.foos.save(foo);
uow.bars.save(bar);
uow.events.append(event);
await uow.commit();
```

How it is checked

Checked by
persistence conventions

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Transaction Boundary](https://banes-lab.com/records/architecture/transaction-boundary.md), [Atomicity](https://banes-lab.com/records/architecture/atomicity.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md), [Coordinated Persistence](https://banes-lab.com/records/lexicon/coordinated-persistence.md)

Shape it refuses
[Scattered Save Calls](https://banes-lab.com/records/lexicon/scattered-save-calls.md)

### Consistency

- Kind: [quality-attribute](https://banes-lab.com/records/kind/quality-attribute.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: data, transaction, distributed system
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
The degree to which stored data satisfies its invariants after every change.

Requires
[Invariant](https://banes-lab.com/records/architecture/invariant.md), [Validation](https://banes-lab.com/records/architecture/validation.md)

Reinforces
[Correctness](https://banes-lab.com/records/architecture/correctness.md)

Enables
[Reliable State](https://banes-lab.com/records/lexicon/reliable-state.md)

In tension with
[Availability](https://banes-lab.com/records/lexicon/availability.md), [Latency](https://banes-lab.com/records/architecture/latency.md)

Conflicts with
[Inconsistent Replicas/Models](https://banes-lab.com/records/lexicon/inconsistent-replicas-models.md)

Referenced by
[Total-Order Broadcast](https://banes-lab.com/records/architecture/total-order-broadcast.md), [Invariant](https://banes-lab.com/records/architecture/invariant.md), [Centralized Configuration](https://banes-lab.com/records/architecture/centralized-configuration.md), [Decentralization](https://banes-lab.com/records/architecture/decentralization.md), [Consensus](https://banes-lab.com/records/architecture/consensus.md), [Do Not Repeat Yourself (DRY)](https://banes-lab.com/records/architecture/duplicate-code.md), [Code Review](https://banes-lab.com/records/architecture/code-review.md), [Reference Architecture](https://banes-lab.com/records/architecture/reference-architecture.md), [Standardization](https://banes-lab.com/records/architecture/standardization.md), [Scalability](https://banes-lab.com/records/architecture/scalability.md), [Caching](https://banes-lab.com/records/architecture/caching.md), [Failover](https://banes-lab.com/records/architecture/failover.md), [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md), [Normalization](https://banes-lab.com/records/architecture/normalization.md), [Governance](https://banes-lab.com/records/architecture/governance.md), [Microservices](https://banes-lab.com/records/architecture/microservices.md), [Space-Based Architecture](https://banes-lab.com/records/architecture/space-based-architecture.md), [Atomicity](https://banes-lab.com/records/architecture/atomicity.md), [ACID](https://banes-lab.com/records/architecture/acid.md), [Unit of Work Pattern](https://banes-lab.com/records/architecture/unit-of-work-pattern.md)

Tensions
[Consistency / Availability](https://banes-lab.com/records/tension/availability-consistency.md), [Consistency / Latency](https://banes-lab.com/records/tension/consistency-latency.md)

Distinct from
[Correctness](https://banes-lab.com/records/architecture/correctness.md): Consistency is stored data satisfying its invariants, while correctness is code behavior matching its specification.

Distinct from
[Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md): Consistency is data keeping its invariants, while fault tolerance is operation continuing through component failure.

Distinct from
[Interoperability](https://banes-lab.com/records/architecture/interoperability.md): Consistency is data inside one system keeping its invariants, while interoperability is separate systems exchanging data.

Distinct from
[Always-Fresh Reads](https://banes-lab.com/records/lexicon/always-fresh-reads.md): Consistency is invariants holding after every change, while always-fresh reads is every read seeing the latest write.

Distinct from
[Availability](https://banes-lab.com/records/lexicon/availability.md): Consistency is data keeping its invariants, while availability is the system answering at all.

Distinct from
[Durability](https://banes-lab.com/records/lexicon/durability.md): Consistency is invariants holding after a change, while durability is a committed change surviving a crash.

Distinct from
[Maintainability](https://banes-lab.com/records/lexicon/maintainability.md): Consistency is a property of stored data, while maintainability is a property of the code that changes it.

Distinct from
[Scalability](https://banes-lab.com/records/architecture/scalability.md): Consistency is invariants holding, while scalability is performance holding as load grows.

Distinct from
[Operational Complexity](https://banes-lab.com/records/lexicon/operational-complexity.md): Consistency is invariants holding, while operational complexity is the effort of running the system in production.

Distinct from
[Quality](https://banes-lab.com/records/lexicon/quality.md): Consistency is one property of stored data, while quality is how far a system meets all its expectations.

Distinct from
[Security](https://banes-lab.com/records/lexicon/security.md): Consistency is data keeping its invariants, while security is protection from misuse and attack.

Distinct from
[Simplicity](https://banes-lab.com/records/lexicon/simplicity.md): Consistency is invariants holding, while simplicity is the absence of unneeded structure.

Violated by
invariant-breaking writes

Detected by
data anomalies, failed invariant checks

Measured by
consistency violation count

Refactored by
Add Constraints, Add Transaction, Add Reconciliation

Enforced by
database constraints, invariant tests

Before

```typescript
foo.total = foo.items.reduce((sum, item) => sum + item.value, 0);
foo.itemCount = externalCount;
```

After

```typescript
function rebuildFoo(items: readonly FooItem[]): Foo {
return { items, total: sum(items), itemCount: items.length };
}
const foo = rebuildFoo(items);
```

How it is checked

Checked by
database constraints, invariant tests

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Invariant](https://banes-lab.com/records/architecture/invariant.md), [Validation](https://banes-lab.com/records/architecture/validation.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md), [Reliable State](https://banes-lab.com/records/lexicon/reliable-state.md)

Shape it refuses
[Inconsistent Replicas/Models](https://banes-lab.com/records/lexicon/inconsistent-replicas-models.md)

### Isolation

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: database, transaction, concurrency
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A rule or precondition that concurrent transactions do not see each other's uncommitted changes, to the degree the isolation level declares.

Requires
[Concurrency Control](https://banes-lab.com/records/architecture/concurrency-control.md)

Reinforces
[Correctness](https://banes-lab.com/records/architecture/correctness.md)

Enables
[Safe Concurrent Operations](https://banes-lab.com/records/lexicon/safe-concurrent-operations.md)

In tension with
[Throughput](https://banes-lab.com/records/architecture/throughput.md)

Conflicts with
[Dirty Reads/Writes](https://banes-lab.com/records/lexicon/dirty-reads-writes.md)

Referenced by
[Partitioning](https://banes-lab.com/records/architecture/partitioning.md), [ACID](https://banes-lab.com/records/architecture/acid.md), [Concurrency Control](https://banes-lab.com/records/architecture/concurrency-control.md), [Pessimistic Locking](https://banes-lab.com/records/architecture/pessimistic-locking.md)

Tensions
[Isolation / Throughput](https://banes-lab.com/records/tension/isolation-throughput.md)

Violated by
race-condition state corruption

Detected by
concurrency tests, isolation anomalies

Measured by
anomaly rate, lock contention

Refactored by
Add Locking, Set Isolation Level

Enforced by
DB isolation, concurrency tests

Before

```typescript
const foo = await fooStore.find(id);
foo.count += 1;
await fooStore.save(foo);
```

After

```typescript
await database.transaction({ isolation: "serializable" }, async tx => {
const foo = await tx.foos.lock(id);
await tx.foos.save({ ...foo, count: foo.count + 1 });
});
```

How it is checked

Checked by
DB isolation, concurrency tests

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Concurrency Control](https://banes-lab.com/records/architecture/concurrency-control.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md), [Safe Concurrent Operations](https://banes-lab.com/records/lexicon/safe-concurrent-operations.md)

Shape it refuses
[Dirty Reads/Writes](https://banes-lab.com/records/lexicon/dirty-reads-writes.md)

### Concurrency Control

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: transaction, memory, distributed system
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A mechanism that coordinates concurrent access to shared state, through locks, versions or compare-and-swap.

Requires
[Shared State Identification](https://banes-lab.com/records/lexicon/shared-state-identification.md)

Reinforces
[Isolation](https://banes-lab.com/records/architecture/isolation.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md)

Enables
[Safe Parallel Mutation](https://banes-lab.com/records/lexicon/safe-parallel-mutation.md)

In tension with
[Performance](https://banes-lab.com/records/lexicon/performance.md)

Conflicts with
[Race Conditions](https://banes-lab.com/records/lexicon/race-conditions.md), [Lost Update](https://banes-lab.com/records/architecture/lost-update.md)

Referenced by
[Concurrency](https://banes-lab.com/records/architecture/concurrency.md), [Isolation](https://banes-lab.com/records/architecture/isolation.md), [Optimistic Locking](https://banes-lab.com/records/architecture/optimistic-locking.md)

Tensions
[Concurrency Control / Performance](https://banes-lab.com/records/tension/concurrency-control-performance.md)

Violated by
unsynchronized shared mutation

Detected by
race detectors, flaky concurrent tests

Measured by
race count, contention

Refactored by
Add Locking, Use Immutable State, Add CAS

Enforced by
thread-safety analysis, [tests](https://banes-lab.com/records/lexicon/tests.md)

Before

```typescript
const foo = await fooStore.find(id);
await fooStore.save({ ...foo, count: foo.count + 1 });
```

After

```typescript
await fooStore.update(id, current => ({
...current,
count: current.count + 1,
}), { expectedVersion: foo.version });
```

How it is checked

Checked by
thread-safety analysis, tests

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Shared State Identification](https://banes-lab.com/records/lexicon/shared-state-identification.md), [Isolation](https://banes-lab.com/records/architecture/isolation.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md), [Safe Parallel Mutation](https://banes-lab.com/records/lexicon/safe-parallel-mutation.md)

Shape it refuses
[Race Conditions](https://banes-lab.com/records/lexicon/race-conditions.md), [Lost Update](https://banes-lab.com/records/architecture/lost-update.md)

### Optimistic Locking

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: persistence, transaction
- Aliases: Own-Span Compare-and-Swap
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A design pattern that checks a record's version when it is written and rejects the write if another writer changed it first, comparing only the writer's own span where a surface is fenced per writer.

Requires
[Version Field](https://banes-lab.com/records/lexicon/version-field.md)

Reinforces
[Concurrency Control](https://banes-lab.com/records/architecture/concurrency-control.md)

Enables
[Conflict Detection](https://banes-lab.com/records/lexicon/conflict-detection.md)

In tension with
[Retry Complexity](https://banes-lab.com/records/lexicon/retry-complexity.md)

Conflicts with
[Blind Overwrite](https://banes-lab.com/records/lexicon/blind-overwrite.md)

Referenced by
[Write Barrier](https://banes-lab.com/records/architecture/write-barrier.md)

Tensions
[Optimistic Locking / Retry Complexity](https://banes-lab.com/records/tension/optimistic-locking-retry-complexity.md)

Violated by
[lost update](https://banes-lab.com/records/architecture/lost-update.md)

Detected by
updates without version check

Measured by
conflict/retry rate

Refactored by
Add Version Column, Add Compare-And-Swap

Enforced by
repository rules, integration tests

Before

```typescript
await fooTable.update({ id: foo.id, name: foo.name });
```

After

```typescript
const updated = await fooTable.update({
id: foo.id,
expectedVersion: foo.version,
next: { ...foo, version: foo.version + 1 },
});
if (!updated) throw new ConflictError(foo.id);
```

How it is checked

Checked by
repository rules, integration tests

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Version Field](https://banes-lab.com/records/lexicon/version-field.md), [Concurrency Control](https://banes-lab.com/records/architecture/concurrency-control.md), [Conflict Detection](https://banes-lab.com/records/lexicon/conflict-detection.md)

Shape it refuses
[Blind Overwrite](https://banes-lab.com/records/lexicon/blind-overwrite.md)

### Pessimistic Locking

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: persistence, critical section
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A design pattern that locks a record before reading it for update, so other writers wait until the transaction ends.

Requires
[Lock Ownership](https://banes-lab.com/records/lexicon/lock-ownership.md)

Reinforces
[Isolation](https://banes-lab.com/records/architecture/isolation.md)

Enables
[Strong Conflict Prevention](https://banes-lab.com/records/lexicon/strong-conflict-prevention.md)

In tension with
[Deadlock Freedom](https://banes-lab.com/records/lexicon/deadlock-freedom.md), [Latency](https://banes-lab.com/records/architecture/latency.md), [Lock-Free Throughput](https://banes-lab.com/records/lexicon/lock-free-throughput.md)

Conflicts with
none

Tensions
[Pessimistic Locking / Deadlock Freedom](https://banes-lab.com/records/tension/deadlock-freedom-pessimistic-locking.md), [Pessimistic Locking / Latency](https://banes-lab.com/records/tension/latency-pessimistic-locking.md), [Pessimistic Locking / Lock-Free Throughput](https://banes-lab.com/records/tension/lock-free-throughput-pessimistic-locking.md)

Violated by
missing lock around critical mutation

Detected by
concurrent update conflicts

Measured by
lock wait/deadlock rate

Refactored by
Add Lock, Narrow Lock Scope

Enforced by
transactional tests

Before

```typescript
const foo = await fooTable.find(id);
await fooTable.save(change(foo));
```

After

```typescript
await database.transaction(async tx => {
const foo = await tx.foos.findForUpdate(id);
await tx.foos.save(change(foo));
});
```

How it is checked

Checked by
transactional tests

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Lock Ownership](https://banes-lab.com/records/lexicon/lock-ownership.md), [Isolation](https://banes-lab.com/records/architecture/isolation.md), [Strong Conflict Prevention](https://banes-lab.com/records/lexicon/strong-conflict-prevention.md)

Shape it refuses
Not answered

### State Isolation

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: function, component, service
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A design rule that each piece of mutable state belongs to one unit of concurrent execution, so no two units that run at the same time can write it.

Requires
[Encapsulation](https://banes-lab.com/records/architecture/encapsulation.md), [Ownership](https://banes-lab.com/records/lexicon/ownership.md)

Reinforces
[Predictability](https://banes-lab.com/records/architecture/predictability.md), [Concurrency Correctness](https://banes-lab.com/records/lexicon/concurrency-correctness.md)

Enables
[Testability](https://banes-lab.com/records/architecture/testability.md)

In tension with
[Data Sharing](https://banes-lab.com/records/lexicon/data-sharing.md)

Conflicts with
[Shared Mutable State](https://banes-lab.com/records/architecture/shared-mutable-state.md)

Contracts
[Resource Core](https://banes-lab.com/records/algorithms/resource-core.md)

Tensions
[State Isolation / Data Sharing](https://banes-lab.com/records/tension/data-sharing-state-isolation.md)

Violated by
[global mutable state](https://banes-lab.com/records/lexicon/global-mutable-state.md)

Detected by
static mutable fields, shared caches without ownership

Measured by
global state count

Refactored by
Encapsulate State, Pass Explicit State, Use Immutable Data

Enforced by
lint rules, architecture tests

Before

```typescript
const globalFooState: Foo[] = [];
function addFoo(foo: Foo) { globalFooState.push(foo); }
```

After

```typescript
class FooSession {
#state: Foo[] = [];
add(foo: Foo) { this.#state = [...this.#state, foo]; }
snapshot() { return [...this.#state]; }
}
```

How it is checked

Checked by
lint rules, architecture tests

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Encapsulation](https://banes-lab.com/records/architecture/encapsulation.md), [Ownership](https://banes-lab.com/records/lexicon/ownership.md), [Predictability](https://banes-lab.com/records/architecture/predictability.md), [Concurrency Correctness](https://banes-lab.com/records/lexicon/concurrency-correctness.md), [Testability](https://banes-lab.com/records/architecture/testability.md)

Shape it refuses
[Shared Mutable State](https://banes-lab.com/records/architecture/shared-mutable-state.md)

### Controlled Side Effects

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: function, module, boundary
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A design rule that mutation, I/O and persistence happen at declared boundaries, around a core of pure functions.

Requires
[Effect Boundaries](https://banes-lab.com/records/lexicon/effect-boundaries.md)

Reinforces
[Predictability](https://banes-lab.com/records/architecture/predictability.md), [Testability](https://banes-lab.com/records/architecture/testability.md)

Enables
[Pure Core / Imperative Shell](https://banes-lab.com/records/lexicon/pure-core-imperative-shell.md)

In tension with
[Performance Optimization](https://banes-lab.com/records/lexicon/performance-optimization.md)

Conflicts with
[Hidden Side Effect](https://banes-lab.com/records/architecture/hidden-side-effect.md), [Action at a Distance](https://banes-lab.com/records/architecture/action-at-a-distance.md)

Contracts
[Execution Core](https://banes-lab.com/records/algorithms/execution-core.md)

Tensions
[Controlled Side Effects / Performance Optimization](https://banes-lab.com/records/tension/controlled-side-effects-performance-optimization.md)

Violated by
mutation/network/persistence hidden in pure-looking code

Detected by
side effects in domain/pure functions

Measured by
side-effect boundary violations

Refactored by
Move Side Effect to Boundary, Return Command/Event

Enforced by
effect linting, layer rules

Before

```typescript
function calculateFoo(foo: Foo) {
foo.count += 1;
fooLog.record(foo);
fooDb.save(foo);
return foo.count;
}
```

After

```typescript
function nextFoo(foo: Foo): Foo { return { ...foo, count: foo.count + 1 }; }
async function applyFoo(foo: Foo, store: FooStore, log: Log) {
const next = nextFoo(foo);
log.write(next);
await store.save(next);
return next;
}
```

How it is checked

Checked by
effect linting, layer rules

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Effect Boundaries](https://banes-lab.com/records/lexicon/effect-boundaries.md), [Predictability](https://banes-lab.com/records/architecture/predictability.md), [Testability](https://banes-lab.com/records/architecture/testability.md), [Pure Core / Imperative Shell](https://banes-lab.com/records/lexicon/pure-core-imperative-shell.md)

Shape it refuses
[Hidden Side Effect](https://banes-lab.com/records/architecture/hidden-side-effect.md), [Action at a Distance](https://banes-lab.com/records/architecture/action-at-a-distance.md), [Hidden Side Effect](https://banes-lab.com/records/architecture/hidden-side-effect.md)

### Petri Nets

- Kind: [model](https://banes-lab.com/records/kind/model.md)
- Category: [Transactions / State / Concurrency](https://banes-lab.com/ontology/principles/architecture-category-transactions-state-concurrency.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: concurrency, workflow, verification
- Layer: [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)

Details

Definition
A conceptual representation of concurrent flow as places holding tokens and transitions that consume and produce them, which can be analyzed for deadlock.

Requires
[Places and Transitions](https://banes-lab.com/records/lexicon/places-and-transitions.md)

Reinforces
[Concurrency Correctness](https://banes-lab.com/records/lexicon/concurrency-correctness.md), [Deadlock Freedom](https://banes-lab.com/records/lexicon/deadlock-freedom.md)

Enables
[Concurrent-Flow Modeling](https://banes-lab.com/records/lexicon/concurrent-flow-modeling.md), [Reachability and Deadlock Analysis](https://banes-lab.com/records/lexicon/reachability-and-deadlock-analysis.md)

In tension with
[Modeling Overhead](https://banes-lab.com/records/lexicon/modeling-overhead.md)

Conflicts with
[Ad-Hoc Lock Ordering](https://banes-lab.com/records/lexicon/ad-hoc-lock-ordering.md)

Contracts
[Petri Nets](https://banes-lab.com/records/algorithms/petri-nets.md)

Tensions
[Petri Nets / Modeling Overhead](https://banes-lab.com/records/tension/modeling-overhead-petri-nets.md)

Violated by
concurrent resource flows coordinated by hand-reasoned lock ordering

Detected by
deadlocks or lost tokens found only at runtime

Measured by
unreachable or deadlock-prone markings

Refactored by
Model concurrent flow as a Petri net and analyze reachability

Enforced by
concurrency model review

Before

```typescript
acquire(a); acquire(b); work(); release(b); release(a);
```

After

```typescript
const net = petriNet({
places: { idle: 1, aHeld: 0, bHeld: 0 },
transitions: [
{ name: "takeA", consume: { idle: 1 }, produce: { aHeld: 1 } },
{ name: "takeB", consume: { aHeld: 1 }, produce: { bHeld: 1 } },
],
});
assertNoDeadlock(reachableMarkings(net));
```

How it is checked

Checked by
concurrency model review

Population
Every multi-step write, shared mutable state and retried side effect

Freshness
A verdict stands until the write path, the isolation level or the concurrency model changes

Refusal
The transaction or concurrency test fails a write path that loses an update, commits partially or repeats an effect

Observation
Outcomes of concurrent and retried runs, plus the transaction boundaries read from source

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The transaction boundary and the isolation level, which every write path conforms to

Depends on
[Places and Transitions](https://banes-lab.com/records/lexicon/places-and-transitions.md), [Concurrency Correctness](https://banes-lab.com/records/lexicon/concurrency-correctness.md), [Deadlock Freedom](https://banes-lab.com/records/lexicon/deadlock-freedom.md), [Concurrent-Flow Modeling](https://banes-lab.com/records/lexicon/concurrent-flow-modeling.md), [Reachability and Deadlock Analysis](https://banes-lab.com/records/lexicon/reachability-and-deadlock-analysis.md)

Shape it refuses
[Ad-Hoc Lock Ordering](https://banes-lab.com/records/lexicon/ad-hoc-lock-ordering.md)

## Links to

- [principle](https://banes-lab.com/records/kind/principle.md)
- [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- [Atomic Boundary](https://banes-lab.com/records/layer/atomic-boundary.md)
- [Idempotency Key or Deterministic Operation](https://banes-lab.com/records/lexicon/idempotency-key-or-deterministic-operation.md)
- [Retry Safety](https://banes-lab.com/records/lexicon/retry-safety.md)
- [Event-Driven Architecture](https://banes-lab.com/records/architecture/event-driven-architecture.md)
- [Safe Retries](https://banes-lab.com/records/lexicon/safe-retries.md)
- [State Tracking](https://banes-lab.com/records/lexicon/state-tracking.md)
- [Non-Repeatable Side Effects](https://banes-lab.com/records/lexicon/non-repeatable-side-effects.md)
- [Eventual Consistency](https://banes-lab.com/records/architecture/eventual-consistency.md)
- [Saga Pattern](https://banes-lab.com/records/architecture/saga-pattern.md)
- [Retry Pattern](https://banes-lab.com/records/architecture/retry-pattern.md)
- [Canonicalization](https://banes-lab.com/records/architecture/canonicalization.md)
- [Idempotency / State Tracking](https://banes-lab.com/records/tension/idempotency-state-tracking.md)
- [Transaction Boundary](https://banes-lab.com/records/architecture/transaction-boundary.md)
- [Consistency](https://banes-lab.com/records/architecture/consistency.md)
- [Correctness](https://banes-lab.com/records/architecture/correctness.md)
- [All-or-Nothing State Change](https://banes-lab.com/records/lexicon/all-or-nothing-state-change.md)
- [Distributed Scalability](https://banes-lab.com/records/lexicon/distributed-scalability.md)
- [Partial Commit](https://banes-lab.com/records/lexicon/partial-commit.md)
- [ACID](https://banes-lab.com/records/architecture/acid.md)
- [Unit of Work Pattern](https://banes-lab.com/records/architecture/unit-of-work-pattern.md)
- [Atomic Boundary](https://banes-lab.com/records/algorithms/atomic-boundary.md)
- [Atomicity / Distributed Scalability](https://banes-lab.com/records/tension/atomicity-distributed-scalability.md)
- [model](https://banes-lab.com/records/kind/model.md)
- [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- [Atomicity](https://banes-lab.com/records/architecture/atomicity.md)
- [Isolation](https://banes-lab.com/records/architecture/isolation.md)
- [Durability](https://banes-lab.com/records/lexicon/durability.md)
- [Strong Transactional Guarantees](https://banes-lab.com/records/lexicon/strong-transactional-guarantees.md)
- [Distributed Availability](https://banes-lab.com/records/lexicon/distributed-availability.md)
- [BASE/Eventual Consistency](https://banes-lab.com/records/lexicon/base-eventual-consistency.md)
- [ACID / Distributed Availability](https://banes-lab.com/records/tension/acid-distributed-availability.md)
- [ACID / BASE/Eventual Consistency](https://banes-lab.com/records/tension/acid-base-eventual-consistency.md)
- [constraint](https://banes-lab.com/records/kind/constraint.md)
- [Consistency Rules](https://banes-lab.com/records/lexicon/consistency-rules.md)
- [Safe State Mutation](https://banes-lab.com/records/lexicon/safe-state-mutation.md)
- [Large Transaction Scope](https://banes-lab.com/records/lexicon/large-transaction-scope.md)
- [Hidden Distributed Transaction](https://banes-lab.com/records/lexicon/hidden-distributed-transaction.md)
- [Transaction Boundary](https://banes-lab.com/records/algorithms/transaction-boundary.md)
- [Transaction Boundary / Large Transaction Scope](https://banes-lab.com/records/tension/large-transaction-scope-transaction-boundary.md)
- [pattern](https://banes-lab.com/records/kind/pattern.md)
- [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- [Coordinated Persistence](https://banes-lab.com/records/lexicon/coordinated-persistence.md)
- [Repository Complexity](https://banes-lab.com/records/lexicon/repository-complexity.md)
- [Scattered Save Calls](https://banes-lab.com/records/lexicon/scattered-save-calls.md)
- [Unit of Work Pattern / Repository Complexity](https://banes-lab.com/records/tension/repository-complexity-unit-of-work-pattern.md)
- [quality-attribute](https://banes-lab.com/records/kind/quality-attribute.md)
- [Invariant](https://banes-lab.com/records/architecture/invariant.md)
- [Validation](https://banes-lab.com/records/architecture/validation.md)
- [Reliable State](https://banes-lab.com/records/lexicon/reliable-state.md)
- [Availability](https://banes-lab.com/records/lexicon/availability.md)
- [Latency](https://banes-lab.com/records/architecture/latency.md)
- [Inconsistent Replicas/Models](https://banes-lab.com/records/lexicon/inconsistent-replicas-models.md)
- [Total-Order Broadcast](https://banes-lab.com/records/architecture/total-order-broadcast.md)
- [Centralized Configuration](https://banes-lab.com/records/architecture/centralized-configuration.md)
- [Decentralization](https://banes-lab.com/records/architecture/decentralization.md)
- [Consensus](https://banes-lab.com/records/architecture/consensus.md)
- [Do Not Repeat Yourself](https://banes-lab.com/records/architecture/duplicate-code.md)
- [Code Review](https://banes-lab.com/records/architecture/code-review.md)
- [Reference Architecture](https://banes-lab.com/records/architecture/reference-architecture.md)
- [Standardization](https://banes-lab.com/records/architecture/standardization.md)
- [Scalability](https://banes-lab.com/records/architecture/scalability.md)
- [Caching](https://banes-lab.com/records/architecture/caching.md)
- [Failover](https://banes-lab.com/records/architecture/failover.md)
- [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)
- [Normalization](https://banes-lab.com/records/architecture/normalization.md)
- [Governance](https://banes-lab.com/records/architecture/governance.md)
- [Microservices](https://banes-lab.com/records/architecture/microservices.md)
- [Space-Based Architecture](https://banes-lab.com/records/architecture/space-based-architecture.md)
- [Consistency / Availability](https://banes-lab.com/records/tension/availability-consistency.md)
- [Consistency / Latency](https://banes-lab.com/records/tension/consistency-latency.md)
- [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md)
- [Interoperability](https://banes-lab.com/records/architecture/interoperability.md)
- [Always-Fresh Reads](https://banes-lab.com/records/lexicon/always-fresh-reads.md)
- [Maintainability](https://banes-lab.com/records/lexicon/maintainability.md)
- [Operational Complexity](https://banes-lab.com/records/lexicon/operational-complexity.md)
- [Quality](https://banes-lab.com/records/lexicon/quality.md)
- [Security](https://banes-lab.com/records/lexicon/security.md)
- [Simplicity](https://banes-lab.com/records/lexicon/simplicity.md)
- [Concurrency Control](https://banes-lab.com/records/architecture/concurrency-control.md)
- [Safe Concurrent Operations](https://banes-lab.com/records/lexicon/safe-concurrent-operations.md)
- [Throughput](https://banes-lab.com/records/architecture/throughput.md)
- [Dirty Reads/Writes](https://banes-lab.com/records/lexicon/dirty-reads-writes.md)
- [Partitioning](https://banes-lab.com/records/architecture/partitioning.md)
- [Pessimistic Locking](https://banes-lab.com/records/architecture/pessimistic-locking.md)
- [Isolation / Throughput](https://banes-lab.com/records/tension/isolation-throughput.md)
- [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- [Shared State Identification](https://banes-lab.com/records/lexicon/shared-state-identification.md)
- [Safe Parallel Mutation](https://banes-lab.com/records/lexicon/safe-parallel-mutation.md)
- [Performance](https://banes-lab.com/records/lexicon/performance.md)
- [Race Conditions](https://banes-lab.com/records/lexicon/race-conditions.md)
- [Lost Update](https://banes-lab.com/records/architecture/lost-update.md)
- [Concurrency](https://banes-lab.com/records/architecture/concurrency.md)
- [Optimistic Locking](https://banes-lab.com/records/architecture/optimistic-locking.md)
- [Concurrency Control / Performance](https://banes-lab.com/records/tension/concurrency-control-performance.md)
- [Tests](https://banes-lab.com/records/lexicon/tests.md)
- [Version Field](https://banes-lab.com/records/lexicon/version-field.md)
- [Conflict Detection](https://banes-lab.com/records/lexicon/conflict-detection.md)
- [Retry Complexity](https://banes-lab.com/records/lexicon/retry-complexity.md)
- [Blind Overwrite](https://banes-lab.com/records/lexicon/blind-overwrite.md)
- [Write Barrier](https://banes-lab.com/records/architecture/write-barrier.md)
- [Optimistic Locking / Retry Complexity](https://banes-lab.com/records/tension/optimistic-locking-retry-complexity.md)
- [Lock Ownership](https://banes-lab.com/records/lexicon/lock-ownership.md)
- [Strong Conflict Prevention](https://banes-lab.com/records/lexicon/strong-conflict-prevention.md)
- [Deadlock Freedom](https://banes-lab.com/records/lexicon/deadlock-freedom.md)
- [Lock-Free Throughput](https://banes-lab.com/records/lexicon/lock-free-throughput.md)
- [Pessimistic Locking / Deadlock Freedom](https://banes-lab.com/records/tension/deadlock-freedom-pessimistic-locking.md)
- [Pessimistic Locking / Latency](https://banes-lab.com/records/tension/latency-pessimistic-locking.md)
- [Pessimistic Locking / Lock-Free Throughput](https://banes-lab.com/records/tension/lock-free-throughput-pessimistic-locking.md)
- [Encapsulation](https://banes-lab.com/records/architecture/encapsulation.md)
- [Ownership](https://banes-lab.com/records/lexicon/ownership.md)
- [Predictability](https://banes-lab.com/records/architecture/predictability.md)
- [Concurrency Correctness](https://banes-lab.com/records/lexicon/concurrency-correctness.md)
- [Testability](https://banes-lab.com/records/architecture/testability.md)
- [Data Sharing](https://banes-lab.com/records/lexicon/data-sharing.md)
- [Shared Mutable State](https://banes-lab.com/records/architecture/shared-mutable-state.md)
- [Resource Core](https://banes-lab.com/records/algorithms/resource-core.md)
- [State Isolation / Data Sharing](https://banes-lab.com/records/tension/data-sharing-state-isolation.md)
- [Global Mutable State](https://banes-lab.com/records/lexicon/global-mutable-state.md)
- [Effect Boundaries](https://banes-lab.com/records/lexicon/effect-boundaries.md)
- [Pure Core / Imperative Shell](https://banes-lab.com/records/lexicon/pure-core-imperative-shell.md)
- [Performance Optimization](https://banes-lab.com/records/lexicon/performance-optimization.md)
- [Hidden Side Effect](https://banes-lab.com/records/architecture/hidden-side-effect.md)
- [Action at a Distance](https://banes-lab.com/records/architecture/action-at-a-distance.md)
- [Execution Core](https://banes-lab.com/records/algorithms/execution-core.md)
- [Controlled Side Effects / Performance Optimization](https://banes-lab.com/records/tension/controlled-side-effects-performance-optimization.md)
- [Places and Transitions](https://banes-lab.com/records/lexicon/places-and-transitions.md)
- [Concurrent-Flow Modeling](https://banes-lab.com/records/lexicon/concurrent-flow-modeling.md)
- [Reachability and Deadlock Analysis](https://banes-lab.com/records/lexicon/reachability-and-deadlock-analysis.md)
- [Modeling Overhead](https://banes-lab.com/records/lexicon/modeling-overhead.md)
- [Ad-Hoc Lock Ordering](https://banes-lab.com/records/lexicon/ad-hoc-lock-ordering.md)
- [Petri Nets](https://banes-lab.com/records/algorithms/petri-nets.md)
- [Petri Nets / Modeling Overhead](https://banes-lab.com/records/tension/modeling-overhead-petri-nets.md)

## Linked from

- [The layer topology](https://banes-lab.com/ontology/schema/the-layer-topology.md)
- [The membership](https://banes-lab.com/ontology/schema/the-membership.md)
