Fitness (GYM)

Fitness (GYM) - Audit Trail & Compensating Strategies

Attendance ledger immutability, membership timeline replay, and compensating strategies for cancellations, strike errors, retroactive freezes, and payment failures in the Fitness (GYM) domain.

Audit Trail & Compensating Strategies

In membership-driven fitness businesses, contract records, attendance ledgers, and credit balances serve both as operational truth and as evidence in billing disputes, consumer protection inquiries, and safety investigations. Every freeze window, strike, credit forfeiture, and access denial must be backed by a tamper-evident, append-only audit trail.

When club-initiated cancellations, erroneous strikes, medical emergencies, or payment failures deviate from the planned path, the system relies on structured compensating strategies rather than mutating or deleting historical facts.


1. Operational Audit Trail & Record Immutability

Every mutation within the Fitness bounded context is captured as an immutable event. The audit subsystem supports consumer protection regulations, card network dispute processes, and duty-of-care obligations toward members physically present in the facility.

Audit Attributes

AttributeBusiness Purpose
Actor IdentityThe unique identifier of the member, front desk agent, trainer, club manager, or automated policy engine performing the action.
Timestamp (UTC & Local)The precise timestamp recorded at the originating terminal, access point, or scheduler.
Branch & Access PointThe physical facility and device context where the action occurred.
Agreement LineageThe parent MembershipAgreementId, ScheduledClassSessionId, or PtCreditPackageId providing full business context.
Origin ChannelClarifies whether the entry originated from the member app, front desk terminal, turnstile hardware, billing callback, or automated policy evaluation.
Before / After SnapshotComplete serialization of the affected aggregate state before and after the transition.
Policy Version ReferenceThe version of the strike policy, freeze quota, or cancellation terms applied, ensuring historical decisions remain interpretable after policy changes.

Core Audit Invariants

  • Append-Only Attendance Ledger: Check-in, check-out, and denial events can never be updated in-place or deleted; occupancy manifests and evacuation lists are legally dependent on this guarantee.
  • Permanent Contract Lineage: Every freeze period, plan change, and cancellation remains permanently visible in the agreement timeline, even after the member rejoins under a new agreement.
  • Credit Ledger Integrity: PT credit balances are derived exclusively from append-only ledger entries; any discrepancy between a derived balance and a member statement is resolvable by replaying the ledger.

2. Membership Timeline Replay & As-Of Reconstruction

Membership standing changes continuously: activations, freezes, suspensions, renewals, and cancellations. A system that only shows the current state cannot answer the disputes that actually occur — “Was my membership frozen when I was charged?” or “Was I entitled to book that class last month?”

The domain implements an event-sourced membership replay mechanism:

$$\text{MembershipState}(t) = \text{Fold}(\text{Activation}, \text{Events}[0 \dots t])$$

flowchart LR
    E0["Jan 1: Agreement Activated<br/>Annual Premium Plan"] --> E1["Mar 10: Freeze Started<br/>Medical, 21 Days"]
    E1 --> E2["Mar 31: Freeze Ended<br/>Expiry Extended +21 Days"]
    E2 --> E3["Jun 15: Payment Suspended<br/>Card Expired"]
    E3 --> E4["Jun 18: Reactivated<br/>Balance Cured"]
    E4 --> E5["Sep 1: Plan Changed<br/>Premium → Standard"]

    E0 -.->|Query as of Mar 20| ViewA["View: Frozen, Access Blocked"]
    E0 -.->|Query as of Jun 16| ViewB["View: Payment Suspended"]
    E0 -.->|Query Current| ViewC["View: Active, Standard Tier"]

Dispute and Compliance Utility

  • Billing Disputes: When a member contests a recurring charge, the club replays the agreement to the charge date, proving whether the membership was active, frozen, or suspended at that exact moment.
  • Access Disputes: When a member claims wrongful denial, the access event and the replayed agreement state at presentation time jointly settle the question.
  • Consumer Protection Audits: Freeze quota consumption, notice period honoring, and cancellation effective dates are reconstructible for regulators without relying on mutable current-state fields.

3. Compensating Strategies for Operational Exceptions

Real-world club operations frequently deviate from planned paths. Rather than breaking system integrity, the domain employs four canonical compensating strategies:

Strategy 1: Club-Initiated Class Session Cancellation

Scenario: The cycling instructor calls in sick two hours before a fully booked 18:00 session, and no substitute is available.

sequenceDiagram
    autonumber
    actor Manager as Club Manager
    participant Session as Scheduled Class Session
    participant Booking as Class Bookings
    participant Notify as Notification Service
    participant Billing as Accounting / Billing

    Manager->>Session: Cancel Session (Reason: InstructorUnavailable)
    Session->>Booking: Compensate All Confirmed Bookings (Transition to 'ClubCancelled')
    Session->>Booking: Release All Waitlist Entries (Session Void)
    Session->>Notify: Emit 'ClassSessionCancelledByClub' (Urgent Broadcast)
    Session->>Billing: Emit Fee Reversal Facts for Paid-Per-Class Attendees
    Session->>Manager: Suggest Priority Rebooking into Equivalent Sessions
  • No Penalties: Club-cancelled bookings never accrue strikes; the cancellation origin is recorded as ClubInitiated, explicitly distinguishing it from member behavior.
  • Automatic Release: All confirmed seats and waitlist entries are voided in one aggregate transaction, preserving capacity accounting integrity.
  • Goodwill Restoration: Affected members receive priority rebooking windows for equivalent sessions, and per-class fees are reversed through Billing.

Strategy 2: Erroneous No-Show Strike Reversal

Scenario: A member attended the 07:00 yoga class, but the studio’s secondary gate scanner was offline; the roster reconciliation recorded a no-show and applied a strike.

DimensionStandard No-Show FlowCompensating Strike Reversal Flow
Booking StateTransitions to NoShow; strike appended.NoShow record preserved; reversal record appended with evidence.
Strike LedgerStrike counts toward the rolling threshold.Strike marked Reversed; excluded from threshold evaluation immediately.
Booking PrivilegesSuspended if threshold crossed.Suspension lifted retroactively if the reversed strike caused it.
EvidenceRoster reconciliation timestamp.Attendance proof: main gate check-in event, instructor confirmation, or access camera reference.
  • The original no-show record is never deleted; a StrikeReversalRecord is appended, referencing the evidence and the approving staff member.
  • If the erroneous strike contributed to a booking privilege suspension, the suspension end date is recalculated and the member is notified of the correction.

Strategy 3: Retroactive Medical Freeze Correction

Scenario: A member is hospitalized and cannot request a freeze. Two weeks later, a family member presents medical documentation requesting coverage of the hospitalization period.

flowchart TD
    Request["Documented Retroactive Freeze Request"] --> Verify{"Documentation Verified by Club Manager?"}
    Verify -->|No| Reject["Request Rejected with Reason; Member Notified"]
    Verify -->|Yes| Append["Append Corrective Freeze Period<br/>Marked 'RetroactiveCorrection' with Evidence Reference"]
    Append --> Recalc["Recalculate Expiry Extension from Corrective Freeze Days"]
    Recalc --> Quota{"Annual Freeze Quota Sufficient?"}
    Quota -->|Yes| Settle["Apply Expiry Extension & Access Credit"]
    Quota -->|No| Policy["Manager Override Path: Quota Exception Recorded with Justification"]
    Policy --> Settle
    Settle --> Billing["Emit Billing Adjustment Fact for Overlapping Charged Days"]
  • No Backdating: The corrective freeze is appended with its own recording date; the original timeline remains untouched, preserving the audit guarantee that no freeze was backdated silently.
  • Billing Compensation: Days already charged that fall inside the corrective freeze window produce a compensating adjustment fact to Billing — credit note or period extension — never an edit to the settled invoice.
  • Quota Governance: Quota overflow requires an explicit, logged manager override, keeping the Freeze Suspension & Extension Law intact by default.

Strategy 4: Failed Recurring Payment & Dunning Recovery

Scenario: A member’s card expires. The renewal charge fails, and the member — traveling — does not notice the dunning messages for ten days.

flowchart TD
    Fail["Recurring Payment Failed"] --> Suspend["Agreement → PaymentSuspended<br/>Access Denied with 'PaymentSuspended'"]
    Suspend --> Dunning["Billing Executes Retry & Dunning Schedule<br/>(Day 1 / 3 / 7 Reminders)"]
    Dunning --> Cured{"Balance Cured Within Grace Window?"}
    Cured -->|Yes| Reactivate["Agreement → Active<br/>Access Restored Immediately"]
    Cured -->|No| Terminate["Agreement → Terminated<br/>Formal Notice & Final Settlement"]
    Reactivate --> Notify1["Member Notified: Standing Restored, No Interruption Recorded"]
    Terminate --> Notify2["Member Notified: Rejoin Path via New Agreement"]
  • Continuity Protection: During suspension, the expiry date continues to elapse — suspension is not a freeze — but the billing anchor is preserved so a cured member resumes without re-onboarding.
  • Graceful Rejoin: A terminated member rejoining later opens a new agreement; the terminated agreement remains sealed, preserving the complete payment and access history for dispute resolution.
  • Access Fairness: Every denial during suspension carries the PaymentSuspended reason, directing the member to settle rather than creating front desk confrontation.

Our Premium Sponsors

Obelaw is proudly open-source. Continued development, bug fixes, and community support are made possible by the generosity of our sponsors.

Sponsor Obelaw