The launch goes live. Two agents are on the phone to two clients about unit 0803. Both press hold within the same few seconds.
What happens next is not a matter of etiquette. It is decided entirely by whether the system treats a hold as a check followed by a write, or as a single operation that either succeeds or fails.
Check then write is the bug
Read the unit, see that it is available, write the hold. Between the read and the write there is a gap, and in that gap another agent did exactly the same thing. Both reads said available. Both writes succeeded. Two clients have been told they have the unit.
This is not a rare race condition on a launch day. On a launch day it is the normal case.
Atomic means the gap does not exist
The operation has to be one thing: take this unit if and only if nobody holds it. One agent gets a success. The other gets an immediate, unambiguous rejection, while they are still on the phone, before a client has been told anything.
Holds need an expiry
The second failure is quieter. An agent holds a unit for a client who goes cold, and the unit sits frozen for a fortnight because releasing it was nobody’s job. A hold with a timer returns the unit to stock on its own, and the stock grid stays truthful without anyone auditing it.
What the developer sees
A brokerage that double books units loses more than the client. It loses the allocation. Inventory control is a commercial relationship, not a feature.
