Surface sheet · level 2

Moderation queues and the record

Three queues with three different order rules, a closed list of reason codes, and a record that only ever appends — so that a correction is a new row rather than a tidier version of the old one.

Three queues, each with its own order rule

The three
  • 01New submissions — oldest first. Nothing in this queue is live, so waiting costs a holder time and costs a reader nothing.
  • 02Revisions against a published listing — oldest first, but the published copy stays up throughout, which is what makes oldest-first defensible here.
  • 03Reports against a published listing — ahead of both, because the copy complained about is in front of readers while the report sits.
Why not one inbox

One inbox has one order, and these three need different ones. Collapsing them puts a report about live copy behind a fortnight of drafts; splitting them makes each queue’s order a decision somebody can defend, and a decision somebody can defend is one a holder can be told.

The reason list is closed

Reason codes

CodeWhat it saysWhat the holder can do
category-wrongthe filing fails the category’s inclusion testrefile against the sibling named on the sheet
entry-duplicateanother entry already resolves this listed thingask for the two to be merged
name-off-registerthe registered name does not match the register the portal draws oncorrect the name or supply the register reference
body-off-subjectthe body describes something other than what the category coversrewrite the body or refile
contact-unreachablethe contact route did not answer when it was triedsupply a route that answers
slug-reservedthe requested slug is a word a surface answers onchoose another slug

A moderator picks a code and may attach a note. The note is never the reason: a free-text reason cannot be counted, cannot be compared between moderators, and gives a holder nothing specific to fix. Codes make a queue countable, and a countable queue is the only kind whose rules can be argued about honestly.

A report carries a listing identifier and one code. It never carries anything about who raised it beyond the account identifier, and it is never shown to the holder with that identifier attached.

A record that only ever appends

  1. 1A state movesA moderator accepts, withdraws or removes, against a code.the queue
  2. 2One row is writtenListing, state before, state after, account, stamp, and the code.append only
  3. 3The holder is toldFrom that row and nothing else: the code, the sentence it maps to, the field, and what may be done next.no fresh wording
  4. 4A mistake is correctedBy a new row naming the row it corrects. The record shows both, never only the tidied version.never an edit

Nothing in the holder’s message is composed per holder, because a message written fresh each time is a message that can disagree with the record it describes.

Append-only has a cost, and it is accepted. The record grows and it is never compacted, so it is in the backup set and it is one of the three things a restore drill reconciles row for row.