A REPEATABLE APPROACH
Assessment workflow
Work through these decisions before reaching for implementation details.
Read requirements
Restate requested outcomes. Mark must-have behavior and acceptance criteria.
Identify actors
List who interacts with the system: customer, administrator, operator, external provider.
Identify use cases
Write actor + action + outcome. Cover reads and mutations, not only creation.
Identify entities
Name persistent identities and value objects; describe relationships.
Extract business rules
Turn prose into invariants: bounds, ownership, valid states, currency, duplicate behavior.
Identify constraints
Record time, language, database, offline requirements, scale, and forbidden dependencies.
Design data model
Choose primary/foreign keys, nullability, uniqueness, indexes, retention, and amounts.
Design API / interfaces
Define input, output, status codes, authorization, and errors for each use case.
Design architecture
Use routes, controllers, models, and focused services only when warranted.
Identify security requirements
Check validation, identity, permissions, encoding, secrets, audit needs, and least privilege.
Identify failure cases
List missing records, invalid state, insufficient funds, duplicates, database failures, and unknown outcomes.
Implement smallest correct version
Complete one vertical path with validation, persistence, response, and tests before extras.
Test happy paths
Prove each acceptance criterion with realistic data and expected persisted results.
Test edge cases
Check zero, negative, maximum, missing, malformed, unauthorized, duplicate, and concurrent inputs.
Review security
Recheck every mutation and read boundary; inspect raw SQL, mass assignment, errors, and logs.
Review maintainability
Check naming, responsibilities, duplication, configuration, and whether the next reader can follow the flow.
Explain trade-offs
State assumptions, choices, limitations, alternatives, and what you would change with more time.