Handling Cross-Cutting Concerns

1. Implementing Request Correlation

ElementDetail
Trace contextW3C traceparent in every hop
Request IDPer HTTP request UUID
Workflow IDFor long sagas

2. Managing Service Identity

MechanismDetail
SPIFFE / SPIREWorkload identity (SVID)
K8s ServiceAccountPer service
mTLS certBound to identity (mesh)

3. Implementing Tenant Isolation

ModelDetail
SiloPer-tenant infra (strongest)
PoolShared infra; tenantId in code (cheapest)
BridgeHybrid (e.g. silo DB, pool app)
EnforcementRow-level security; OPA checks

4. Handling Internationalization

ElementDetail
LocaleFrom Accept-Language
CatalogsICU MessageFormat
Server vs clientServer for emails / PDFs
PluralizationCLDR rules

5. Implementing Audit Logging

FieldDetail
whouserId / serviceAccount
whataction + resource
whenUTC timestamp
whereIP, region
changebefore/after diff
storeAppend-only / WORM

6. Managing Data Privacy

PracticeDetail
Data classificationPublic / internal / confidential / PII
MinimizationCollect only what's needed
DSARExport / delete on request
EncryptionAt rest + in transit

7. Implementing Compliance Controls

StandardDetail
SOC 2 / ISO 27001Security controls
GDPR / CCPAPrivacy
PCI-DSSCards
HIPAAHealth
EvidenceAutomate via Drata, Vanta

8. Handling Time Zones

RuleDetail
Store UTCAlways
Display localConvert at boundary
IANA TZAmerica/New_York not EST
DSTUse library; don't compute offsets

9. Implementing Accessibility

ElementDetail
WCAG 2.2AA target
APILocalized error messages
Email/PDFTagged PDF, alt text

10. Managing Environmental Configuration

AspectDetail
Env-specific filesdev / stage / prod
PromotionSame artifact, different config
Drift detectionGitOps reconcile

11. Implementing Feature Flags

PracticeDetail
Per-tenant / per-userTargeting rules
Default safeOff-by-default for risky flags
CleanupSchedule flag removal
OpenFeatureVendor-neutral SDK

12. Managing Cross-Service Transactions

PatternDetail
SagaLocal TX + compensations
OutboxAtomic write + publish
Idempotency keysSafe retries
Avoid 2PCAcross services