Define the day after integration.
Plan who responds, how incidents are investigated and what recovery looks like before your integration becomes an operating responsibility.
Assign an owner on both sides.
Before a pilot, name technical and business owners, an incident contact path, escalation authority, operating hours, allowed actions and a change-notification process. The public contact link opens the existing partnership channel; it is not a guaranteed incident hotline. This guide establishes no 24/7 support promise or response-time SLA.
| Situation | Required response |
|---|---|
| Unknown payment result | Preserve the attempt reference; block blind re-charge; obtain authoritative lookup. |
| Provider unavailable | Separate unsent work from submitted work; apply approved recovery limits. |
| Settlement difference | Compare statement and per-asset totals; assign and record the exception. |
| Suspected credential or data exposure | Use the restricted incident process; authorized owner coordinates containment and evidence. |
| Non-financial sync failure | Preserve source identity and checkpoint; replay only the approved scope. |
Measure commitments in the target environment.
No measured throughput, latency percentile, availability target, backup recovery objective or maximum data-loss objective is published by this edition. Agree on proposed SLO/SLA, RTO/RPO, transaction volumes, backlog thresholds, limits and evidence before relying on them. Queue implementation and local tests do not establish capacity or disaster recovery.
- Exercise restoration and replay using isolated fixtures; retain measured recovery results.
- Demonstrate alert ownership, deployed instrumentation and one incident walkthrough.
- Record planned maintenance, release rollback and backward-compatibility responsibilities.
Share a redacted incident packet.
Provide the environment and release, occurrence time with timezone, permitted operation, HTTP/core code, request identity, synthetic reproduction and impact classification. Share financial/customer evidence only through the agreed restricted channel. Never place credentials, raw provider responses, customer KYC or account data in public tickets.