Part 6 · 2 chapters · ~20 min

Rollout and Migration

Launching a country as mostly not engineering (licence, providers, team, counsel) plus a country package, a flag with rings inside the market and a checklist that grows per launch; migrating a fork onto the core by strangler with a client half that protects sessions, journeys and receipts; and deprecating a market through staged wind-down states.

13

Launching a country

mostly not engineering, which is the point
  1. Before engineering: the licence on the regulator's clock, the providers with contracts and sandboxes, the country team (a lead, compliance, support, a native reviewer), the legal entity and counsel's disclosures. Engineering runs in parallel against sandboxes and cannot ship before these exist.
  2. The country package (part 5) as a PR: config validated against the schema, catalogues translated and validated, adapters chosen or built and passing the contract suite, rules authored with compliance and a case table, CODEOWNERS, a tenant and region (part 1). The platform team reviews the boundary; the country team the content. No core change if the points were general.
  3. The flag and the rings inside the market: off, employees in the country on real rails with small amounts, a waitlist cohort, 10% of signups, everyone; dashboards cut by tenant (KYC completion by step, transfer success by rail, error signatures, vitals by device tier for that market).
  4. What launches find: a sandbox unlike production (the first real identity check times out), an undocumented rail state (pending for two days), a string overflowing on the market's common devices, a rounding rule the regulator's worked example contradicts, a tier limit wrong by a hundred because of an exponent. Rings find them at 1%; each becomes a checklist line and often a contract-suite case.
  5. The client specifics: tenant resolution and the first-run choice for the new code; lazy catalogues for the new locales; a device lab with that market's phones and budgets per tier (the Architecture course part 6); synthetics from that market's networks on its browsers and WebViews (part 7 of the same); local support contacts from config.
  6. The checklist as an artefact: a document that grows with every launch, owned by the platform team, run by the country team, signed off per section. The platform's metric: time from licence granted to 100% of the market, trending down. The first launch wrote it; the fifth follows it in a quarter, mostly waiting for the regulator.
LAUNCHING A COUNTRY
a config change, a set of adapters, a licence, and a rollout through rings in one market
swipe the figure sideways, or tap expand for full screen
1/6
before engineering
Before engineering: the licence (months; the regulator's timeline, not the roadmap's); the providers (a KYC provider with coverage in the country, payment rails, an SMS gateway: contracts and sandboxes); the country team (a lead, compliance, support, a native-speaking reviewer); the legal entity and the disclosures counsel writes. The engineering starts in parallel against sandboxes but cannot ship before these exist.
14

Migrating a country onto the core, and deprecating one

the fork that must come home
  1. The inventory: everything the fork does that the core does not, each mapped to an extension point (existing or needed), a config value, a rule, or a decision to drop it. Three years of one country's decisions; the hardest meeting of the migration.
  2. The strangler: the core's shell takes the country's traffic flow by flow behind flags (login and home, then KYC, then transfers rail by rail, then the long tail), each a ring rollout in the market with the fork as the rollback, both sharing the ledger (the CBA module's event log) so a user sees one balance throughout.
  3. The client's migration, where users are harmed if careless: sessions exchanged transparently; half-done journeys resume on the core (the state machine's persistence is the bridge); pending transactions keep references the user's receipt can still resolve; caches cleared by tenant; fork clients told to update (the Architecture course part 7's forced reload).
  4. Data: entities cut over one at a time, dual-written during the window, reconciled (the CBA module part 10) before the fork's copy retires; audit timestamps preserved. Complete at zero fork traffic for a release cycle; the fork archived, not deleted, for the inspection that will come.
the market that must close
  1. The wind-down: a date from the regulator or the business; communication in the local language across channels (part 3); signups off (a flag), then withdraw-only (a rule set change), then read-only with exports prominent (the Trust course part 6), then closed with a final statement and a support path that outlives the app; balances returned through a regulator-approved process with a receipt per user; data retained per the law.
  2. The client's states: a banner with the date and stage; withdraw-only with its reason in words (the Trust course part 7); read-only where every action is replaced by an explanation; a closed page, not an error page, with the statement and the contact; the tenant removed from the first-run choice but resolvable for returning users until retention ends. Then config and adapters deleted on schedule and the package archived with its last config version.
the exercise
Pick the country you would launch next and the one you would close if a licence were lost. Write both checklists; the lines you cannot fill in are the extension points, states and processes the platform lacks.
MIGRATING A COUNTRY ONTO THE CORE, AND DEPRECATING ONE
the fork that must come home, and the market that must close, each with its client half
swipe the figure sideways, or tap expand for full screen
1/6
the fork's inventory
The fork's inventory: everything the fork does that the core does not (a feature, a flow variant, a provider), mapped to an extension point (exists, or must be added: part 5), a config value, a rule, or a decision to drop it. The inventory is the migration's scope and the first thing to argue about: the fork accumulated three years of one country's decisions, and not all of them survive.