Keep the lesson for the next incident
Write the lifecycle contract
Document which application record and page state represent pending verification, how resend changes the lifecycle, what an expired link does, and where successful verification redirects. State which data is never rendered or logged and which delivery stages remain external.
Keep redacted fixtures
Save synthetic registration traces for first send, resend, expiry, old link, wrong link, and successful verification. Assert messages, safe redirects, and account state without storing tokens or addresses. Attach the fixtures to the work record so the next change can reuse them.
Define recurrence signals
Reopen review when pending accounts lose their recovery action, an old link reaches the wrong state, or a new route leaks sensitive data. Record browser and delivery-observation limits and assign owners for application lifecycle versus mailbox evidence.
What to carry forward
Close learning with the verification lifecycle, redacted fixtures, secret-handling rule, and external evidence boundary. Recurrence triggers should name observable application failures rather than pretending mailbox timing is fully controlled by the product for application review.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow