Step 1Start from the story
The user story and the business goal, as product wrote them.
PRODUCTAs a user, I see partner offers and redeem one with my points.
ATALAIAGood. Now, what should never happen with this story?
Leaves the roomStory: redeem a partner offer
Step 2Ask the non-functional questions
Data, identity, limits, logging, failure and abuse.
ATALAIAHow many redeems a minute is normal for one user?
PRODUCTTwo, maybe three. Ten would be a bot.
DEV LEADWe log the voucher code today. Should we?
ATALAIALog that it happened, never the code. A code is money.
Leaves the room6 questions, 6 answers
Step 3Write them as criteria
Testable acceptance criteria, not guidelines.
DEV LEADCriterion: at most 5 redeems a minute per user, then a 429.
QATestable. And an abuse case: a bot redeeming from 50 accounts.
DEVELOPERAn audit event for every redeem, without the voucher code.
Leaves the room6 criteria in the ticket
Step 4Make it a baseline
The common ones become the default for every new service.
ATALAIARate limits, audit events and secret rules go into the service baseline.
DEV LEADSo the next service starts with them, and nobody argues them again.
Leaves the roomBaseline: 12 rules for every service
- ATALAIA
- PRODUCT
- DEV LEAD
- QA
- DEVELOPER