## Why

Timetabler is authoritative for Staff, Locations, activities, and final allocations, but Resource Booking cannot mirror that state reliably from the current best-effort Redis/Kafka side effects. A durable, transactionally coupled outbound change stream is required before real-time two-way booking and shared conflict enforcement can be introduced safely.

## What Changes

- Add a Timetabler integration outbox whose rows commit in the same database transaction as Staff, Location, activity, and allocation mutations.
- Publish one bounded canonical transaction envelope/Kafka record per finalized Timetabler change set, with one globally commit-ordered source-scope sequence/hash and member identities, aggregate versions, final replacement state, absolute calendar/occurrence facts, affected old/new resources/weeks, and tombstones, without embedding Resource Booking schema transformations in Timetabler.
- Refactor final allocation writers toward one atomic schedule change-set service, including normal/bulk engine responses, final drag/drop, manual constraint-break scheduling, booking schedules, unschedule/delete, swaps, current-resource replacement, variants/JTA, imports, and management commands.
- Make Scheduling Engine response application idempotent and atomic, move external effects after commit, and use manual Kafka offset store/commit only after the database and outbox commit.
- Add durable whole-transaction publishing/retry/dead-letter/replay, an authenticated fixed-watermark composite snapshot, explicit default-off activation gates, liveness, lag monitoring, reconciliation, and operator controls.
- Keep Resource Booking mirrors read-only and protected from conflicting Resource Booking writes until Phase 2 conflict enforcement is enabled.
- Establish a hard delivery gate: Phase 2 implementation cannot begin until Phase 1 implementation and the full Phase 1 integration, regression, and performance suites have passed for both services and the evidence is approved.

## Capabilities

### New Capabilities

- `timetabler-resource-mirror-events`: Authoritative, versioned Staff, Location, activity, allocation-replacement, and tombstone events from Timetabler.
- `atomic-schedule-change-application`: Atomic and idempotent application of every final scheduling change, especially Scheduling Engine responses and direct-writer paths.
- `outbox-delivery-reconciliation-operations`: Durable delivery, replay, observability, reconciliation, staged rollout, rollback, and the Phase 1 completion gate.

### Modified Capabilities

None. This repository has no existing OpenSpec capability baseline.

## Impact

- **Timetabler models/migrations:** `api/models/`, `api/models/__init__.py`, and `api/migrations/` gain integration outbox and applied-response receipt records.
- **Scheduling application:** `kafka_consumer/tt_response.py`, legacy `kafka_consumer/schedule_response.py`, `api/views/admin/simulate_schedule_response.py`, `api/views/admin/schedule_request.py`, `api/views/admin/unschedule.py`, `api/views/admin/resources_update_current.py`, `api/views/admin/resources_update_requirement.py`, `api/views/admin/booking_schedule.py`, `api/views/admin/booking_swap.py`, `api/views/admin/activity_delete.py`, `api/views/admin/variant_create.py`, `api/views/admin/jta_create.py`, and `api/views/admin/jta_split.py` are planned consumers of a shared change-set service or must be formally decommissioned if obsolete.
- **Cascading allocation deletion:** `api/views/admin/activity_template_delete.py`, `module_delete.py`, and `academic_term_delete.py` can cascade-delete scheduled activities; `week_pattern_delete.py` can change scheduled occurrence semantics through `SET_NULL`. These paths require pre-delete snapshots, atomic tombstones/resource maps, or a validated block on affected scheduled activities.
- **Direct/import writers:** `api/views/admin/import_table.py` (including `import_tt_staff`, `import_tt_location`, `import_tt_activity`, and `import_tt_booking`) and scheduling management commands require the same atomic/outbox rules.
- **Resource lifecycle:** Staff and Location create/update/delete endpoints under `api/views/admin/` require lifecycle outbox writes.
- **Delivery/config:** New integration services/worker commands, `backend/settings.py`, `.env-sample`, deployment worker configuration, metrics, alerts, and runbooks.
- **Cross-service contract:** A Resource Booking-owned adapter consumes the canonical v2 change-set object on Kafka, validates Timetabler absolute occurrence facts, performs Resource Booking transformation/identity mapping, and reconciles mirrors from the authenticated composite snapshot. Publication remains disabled until RB accepts the shared fixtures and coordinated activation is approved.
- **Compatibility statement:** Atomic application is compatible with the current engine protocol because the engine returns a complete result and does not read Timetabler SQL while BE applies it, provided the exception, Kafka offset, external-side-effect, idempotency, locking, and timing safeguards in this change are implemented and tested. This is not a claim of zero implementation risk.
