Problem
Emergency authority can become an unrestricted drain if the target, amount, pause state, and audit requirements are not constrained.
Objective
Deliver a production-quality improvement to emergency controls and recovery entrypoints that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
- Define eligible assets, roles, pause preconditions, maximums, destination checks, and event metadata; preserve stream and supply invariants.
Acceptance criteria
- Unauthorized or unpaused recovery fails; approved recovery is bounded and auditable; all accounting remains conserved.
Required validation
- Role, pause, limit, destination, invariant, and event tests.
- Existing tests and CI remain passing.
- Add regression coverage for the original failure mode.
- Do not weaken, delete, or skip unrelated tests to obtain a green build.
PR quality bar
- Keep the PR focused and explain design tradeoffs, compatibility impact, and test evidence.
- Avoid typo-only, documentation-only, cosmetic-only, or unrelated refactor submissions.
Out of scope
- Broad rewrites not required by the acceptance criteria.
- Changes to unrelated services, contracts, or user flows.
Problem
Emergency authority can become an unrestricted drain if the target, amount, pause state, and audit requirements are not constrained.
Objective
Deliver a production-quality improvement to emergency controls and recovery entrypoints that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
Acceptance criteria
Required validation
PR quality bar
Out of scope