Seraya Psikologi — Documentation

Booking and payment MVP · Implementation baseline · 96 ADR

47. Keep Guest Client Records Separate by Default

Status

Accepted for the MVP working model; exact merge/link semantics, verification checklist, and historical access behavior remain open.

Context

The same email/phone can be shared by family members or reused for different people. Automatic dedupe could connect one guest to another person's Booking/package. A guest should not gain broad history merely because a contact value matches.

Decision

Create/keep guest Client records separate by default. An authorized admin may perform a ClientMergeAction/identity link after manual verification. The operation records source/target records, evidence category, actor/time, resulting canonical identity, and affected references. Existing ClientAccess remains scoped and is not automatically broadened by a merge/link; a new verified access flow is required for each Booking/package.

No clinical records are merged because clinical records are out of MVP scope.

Consequences

Positive:

Costs and constraints:

Open follow-up

Define link vs irreversible merge semantics, admin permissions, post-merge access, correction/undo behavior, and reporting identity rules.