Continuity controls
Make each load recoverable without the developer's private query history.
ETL becomes dependent when source filters, file conventions, null handling, lookup snapshots, merge exceptions, restart commands, rejected-row fixes, reconciliation spreadsheets, and recovery order live in one person's shell or memory. The client record should let another qualified practitioner trace, run, repair, reconcile, and retire the load.
- Client-held load registry
- Purpose, owners, sources, targets, records and keys, schemas, mappings, rules, extraction modes, schedules, load modes, state, quality checks, quarantine, lineage, service limits, access, dependencies, releases, incidents, backfills, corrections, acceptance, changes, and retirement state remain findable and versioned.
- Reproducible run chain
- Approved code, dependencies, configurations, credential references, source and target contracts, extraction boundary, input manifests, raw and staged references, rule versions, tests, run and attempt identities, target changes, exceptions, lineage, and reconciliation can reproduce or explain a selected load without undocumented edits.
- Least-privilege data path
- Individual source read, landing, staging, transformation, quarantine, target write, publication, telemetry, replay, correction, administration, deployment, and incident access is approved for the role, reviewable, and removed through an owned transition path.
- Demonstrated handoff
- A receiving developer can obtain approved access, identify one source boundary, trace a target value, deploy a reviewed rule, diagnose a failed stage, handle a rejected row, restart after partial work, run a bounded backfill, reconcile source and target, and retire a superseded load before responsibility changes.