Lessons / Rule 3
🎯 Correctness Before Optimisation
Produce the right result even when things go wrong.
A fast wrong answer is still wrong.
A calculator that gives answers quickly but sometimes adds wrong is worse than a slow, correct one. Get it right first, then make it fast.
💡 Key ideas
- Correct first, fast second
- The system must stay correct when things break
- Never assume the client sends something only once
🛠️ How to apply it
- Ask "what if this runs twice?"
- Ask "what if the network fails halfway?"
Reading level: 🐣 Simple
The happy path is the easiest path — and the least important.
The system must produce the correct business result even when a request is submitted twice, the browser is refreshed, the network drops after the server got the request, or a worker crashes mid-job.
💡 Key ideas
- Design for duplicates, retries, simultaneous requests and temporary failures
- Never assume "the client will only send this once"
- The server — not the UI — protects data integrity
🛠️ How to apply it
- Enumerate the ways this operation could be triggered twice or partially
- Decide how the server recognises and handles each case
⚠️ Common pitfalls
- Relying on a disabled button to prevent duplicate submission
Reading level: 🚀 Standard
Correctness is a property of the system under adversity.
A correct system yields the same authoritative business outcome regardless of ordering, duplication, partial completion or timing of the operations that produce it. This is what makes it safe to retry, safe to scale and safe to reason about.
💡 Key ideas
- Separate "accepted" from "completed" in your mental model
- Correctness must hold under concurrency, not just in a single-threaded test
- Optimisation that weakens correctness is a downgrade, not an upgrade
🛠️ How to apply it
- Model the operation as transitions and define the legal outcomes
- Write failure tests (Rule 28) that assert state is never corrupted
⚠️ Common pitfalls
- Optimising a path that is rarely hot while leaving a correctness bug in a hot path
- Assuming the database will reject bad writes when no constraint exists
Reading level: 🧠 Deep
Community
Ask a question, share your own analogy, or help someone else get it.