Goal
Make runtime validation explicit wherever untrusted or externally sourced data enters the system.
When to Use
- Compile-time typing exists but runtime safety is still needed.
- The system ingests external or cross-boundary data.
- Config, payload, or schema validation strategy is unclear.
Instructions
- Identify the trust boundaries where data enters.
- Decide what must be validated and normalized.
- Choose where validation lives and what happens on failure.
- Align validation with error handling and observability.
Constraints
- Do not trust types alone.
- Do not let invalid external data leak into domain logic.
- Keep validation close to boundary entrypoints.
Output Format
- validation boundary map
- payload/config validation plan
- failure behavior
- implementation notes
Examples
- "Plan runtime validation for this TS API."
- "Where should webhook and env validation happen?"