| Bi-directional sync on a contested field | Two writers, no arbiter. The last write wins and both teams lose confidence in the record. | One owner, one-directional flow, and a read-only copy labelled as such at the destination. |
|---|
| Billing logic re-implemented in the product | Proration and price calculation drift apart from the billing system on every pricing change. | Read entitlements and prices from the billing record. Let one system own the arithmetic. |
|---|
| Processing the webhook synchronously | Slow downstream work causes a timeout, which causes a retry, which causes duplicate work. | Store the event durably, acknowledge with a 2xx immediately, process from a queue. |
|---|
| Polling instead of subscribing | Wasteful at low frequency and still latent at high frequency, while the platform already publishes the event. | Consume webhooks. Reserve polling for reconciliation sweeps, not for state propagation. |
|---|
| Plan names as the integration contract | Every new plan or packaging variant requires code changes in every consumer. | Map against catalog concepts — entitlements, product families, item price attributes — not string identifiers. |
|---|
| No environment separation | Testing against the live site, or a test site whose catalog has diverged from production. | A test site kept structurally aligned with production, refreshed on a schedule and used for every change. |
|---|
| Reconciliation by exception report only | Only detects the failures you predicted. The expensive ones are the categories nobody anticipated. | Compare totals and counts as well as exceptions, so an unexplained variance surfaces even without a known rule. |
|---|
| One integration owner with no documentation | The architecture leaves when the person does, and the next change is made by someone reverse-engineering it. | A written ownership matrix, documented interfaces and a runbook, maintained as part of delivery. |
|---|