Which problem do you have
Three different problems look alike from the pager. One client fails under load or at a provider's limit and its retries make things worse: that is a bounded fix to one client. Several services are called from many files, each with its own keys and error handling, and nothing can be tested without the network: that is a consolidation. Nothing is currently broken, but credentials, quotas and provider notices have no owner: that is a monthly watch. Mixing them up leads to buying a refactor when a retry policy would do, or the reverse.
- One client, one provider, a clear failing sequence: the retry job.
- Four or fewer services scattered through the code: the consolidation project.
- Up to three integrations and no incident yet: the monthly check.
What you keep
Your repository, accounts, credentials and production remain yours. Work arrives as pull requests from a branch or fork you control, reviewed separately from the work that produced it, and your team merges. Credentials we are given are staging or sandbox ones that you create; renewing and rotating stay with you. A monthly service tells you what is coming due, with steps, but does not hold production secrets and does not merge.
- No production access is needed for any of the three.
- The agreed tests must run without production credentials.
- A written agreement names who accepts each change.
How each is accepted
The retry job is accepted when scripted failure sequences pass in your own test suite. The consolidation is accepted when characterisation tests pass unchanged before and after, an automated rule fails a deliberate direct call, and the suite runs with the network blocked. The monthly service is accepted each month by a summary you can compare with your provider dashboards. All prices are untested: a fixed £295 for the retry job, from £3,500 for the consolidation after a quote, and a fixed £195 a month for the monthly check.
- Payment for fixed and project work follows sign-off.
- The monthly service has terms agreed in writing before it starts.
- None of the three promises that a provider will not fail.
Start with the register
Before you ask for anything, list each service your product calls, who owns the account, what kind of credential it uses, any review date the provider shows and the limit that matters. That one page tells you which of the three problems you have, and it is the first deliverable of the monthly service and of the consolidation. Send the list, not the credentials.
- A blank date is a finding; write it down.
- Name a person for each row.
- Add the page where each provider posts notices.
Sources and limits
- AWS Builders' Library: timeouts, retries and backoff with jitter Checked 2026-10-11.
- Retries at several layers multiply load, and timeouts, caps, jitter and retry limits are the standard controls.
- Google: OAuth 2.0 overview, refresh token expiration Checked 2026-10-11.
- A credential can stop working for documented reasons that no code change in your product causes.