One rental has several state owners
A reliable shared power bank workflow does not compress every system into one success flag. Device, rental, payment and return evidence progress independently and must be reconciled.
Evidence lanes
| Lane | Source of truth | Examples of evidence |
|---|---|---|
| Station presence | Device connectivity service | last accepted observation, profile version, freshness |
| Rental record | Rental service | rental reference, station reference, timestamps, state history |
| Device outcome | Device integration service | prepared, released, timeout or exception category |
| Payment | Approved payment provider integration | authorization, capture, decline, refund and provider reference |
| Return | Station and rental reconciliation | slot observation, return acceptance, exception review |
| Support | Operator workflow | reason, owner, decision, timestamp and audit note |
Important transitions
Prepared is not released
An eligible slot and a prepared rental do not prove that a power bank was physically released. Device outcome evidence must be accepted separately.
Paid is not dispensed
Payment acceptance does not prove hardware release. If payment and device outcomes diverge, the rental enters a review or compensation path defined by the approved market workflow.
Returned is not reconciled
A station observation may start return handling, but the rental closes only after return and billing evidence agree.
Unknown is not zero
Missing telemetry, unavailable provider data or inaccessible support records must be represented as UNKNOWN, not as zero activity or success.
Integration review questions
- Which service owns each transition?
- What is the retry and idempotency key?
- How long may evidence be stale?
- Which transitions require human review?
- What compensation path applies when payment and device results diverge?
- Which fields may be exported without exposing personal or operational secrets?