How the Smart Ledger stays consistent at scale
A look inside the double-entry engine behind fee collection — and how it stays correct under load.
Smart Ledger sits inside Campus ERP, but the engine isn't campus-specific — it's a generic double-entry ledger that any of our products can post to, and it's built to stay correct under heavy fee volume. Here's how it stays consistent.
The core invariant
Every posting is a pair of entries — debit and credit — that net to zero. The transaction record is the source of truth; balances are projections. This is older than computers, and it's older for a reason: it makes a whole class of bugs impossible to write down.
Idempotency
External payment gateways occasionally send the same callback twice. We require every transaction posting to carry an idempotency key. The ledger writer is upserts-only.
Reconciliation
Nightly, every account is reconciled against the gateway's settlement file. Mismatches open a flagged ticket — they almost never appear, and when they do, it's a real problem.