One click, five things saved
Clicking Save changes (or Create territory) writes the entire
sheet, all five tabs, in one API call. The write is transactional at
the API level: if any part fails validation, the whole save is rolled
back and the territory is left in its previous state.
What "saving replaces the full list" means
Two collections are treated as complete replacements rather than
merges:
cadence.
So if a coworker adds three ZIPs to a territory while you have the
sheet open, and then you save, your save wins and their three ZIPs are
gone. This is intentional; the alternative (merging live) would produce
surprising behavior when two operators disagree. If you're editing a
territory that someone else might be touching, refresh the page first.
Validation on save
The API validates every field independently and reports back in the
success toast:
Territory updated · 12 ZIPs · 1 duplicate dropped · 2 invalid skipped
are silently dropped.
the entire save and shows an error toast.
the polygon error is surfaced.
Audit log
Every create, edit, and delete writes an entry to
`service_territory_audit_log` with the diff, the user who made the
change, and a timestamp. This is admin-only and viewed from the database
side; there's no UI for it yet.
Tenant isolation
Every read and write is filtered by your organization ID on the server.
A driver ID or service ID from another org submitted in a payload is
silently dropped rather than attached. This is enforced at the API
level, not by database RLS; the safety comes from the route handlers.
