Reliability — FMEA risk ranking
A typed FMEA worksheet whose risk priority numbers are computed. Typed FlowScript for reliability engineering. Keywords: FMEA, failure mode, RPN, reliability.
Make it your own.
fmea checkout {
title: "Stripe checkout flow"
system: "Payments service"
team: "Platform"
revision: "rev 3"
}
failure_mode webhook_lost {
component: "Stripe webhook receiver"
mode: "Webhook silently dropped under load"
cause: "Receiver returns 5xx, Stripe retries exceeded"
effect: "Subscription stays active in app despite cancellation"
severity: 9
occurrence: 3
detection: 7
}
failure_mode dup_charge {
component: "Checkout API"
mode: "Customer charged twice"
cause: "Client retry on flaky network without idempotency key"
effect: "Manual refund + support load + chargeback risk"
severity: 8
occurrence: 4
detection: 4
}
failure_mode plan_drift {
component: "Entitlements sync"
mode: "Plan tier in DB drifts from Stripe"
cause: "Webhook + manual edit race"
effect: "User gets wrong quotas / features"
severity: 6
occurrence: 5
detection: 6
}
failure_mode card_expired {
component: "Renewal job"
mode: "Card expires mid-period"
cause: "Customer didn't update payment method"
effect: "Service interruption at renewal"
severity: 5
occurrence: 7
detection: 2
}
mitigation webhook_retry {
mode: webhook_lost
action: "Persist webhook payload before ACK; retry from queue on 5xx"
owner: "Ada (platform)"
target_severity: 9
target_occurrence: 1
target_detection: 3
}
mitigation idem_key {
mode: dup_charge
action: "Require client-supplied Idempotency-Key on /checkout"
owner: "Ben (api)"
target_severity: 8
target_occurrence: 1
target_detection: 4
}
mitigation reconcile {
mode: plan_drift
action: "Nightly reconcile job: Stripe → plans table"
owner: "Cleo (billing)"
target_severity: 6
target_occurrence: 2
target_detection: 3
}
view rpn: fmea_table