When you start working on modern payment infrastructure, moving money seems deceptively simple.

A user initiates a payout. Your system calls a banking API. The bank responds with success or failure. You update your database accordingly.

At least, that's how it looks on architecture diagrams.

In reality, payout systems operate in a world of partial failures, delayed confirmations, network timeouts, and legacy banking infrastructure that doesn't always behave the way software engineers expect.

Over the years, one architectural principle has consistently proven itself to be the difference between a resilient payout platform and an expensive operational incident: