# Membership access windows: policy and boundary worksheet Proposed companion guide: https://www.overskill.com/learn/plan-membership-access-windows All Field Notes members and events are fictional. Allow/Deny are expected policy answers, not observed authorization results. No invitation is sent and no money is charged, cancelled or refunded by this exercise. ## 1. Write your policy Course or community: Named timezone used to define the offer: Saved start/end instants and displayed timezone: Is the start included? Is the end excluded? Resource releases and cohort scope: What an invitation grants: Pause behavior / whether the end moves: Cancellation of renewal versus end of existing access: Which approved event authorizes revocation / effective time: Refund request, refund result and access-change relationship: Rejoin end date / access to earlier cohorts: Transfer behavior / overlap or gap policy: Alumni or administrator exceptions: Person who approves changes / evidence retained: ## 2. Use the sample windows Every sample time is UTC. Start is included; end is excluded. | Cohort | Included start | Excluded end | Second lesson release | | --- | --- | --- | --- | | A | 2026-11-02 15:00:00Z | 2026-11-16 15:00:00Z | 2026-11-09 15:00:00Z | | B | 2026-11-16 15:00:00Z | 2026-11-30 15:00:00Z | 2026-11-23 15:00:00Z | The pack and discussion release at the cohort start. Protected resources require a signed-in person with a matching approved cohort record, start <= now < end, no active pause, no effective revocation and an arrived resource release time. The public overview is available to everyone. A signed-in member may open their own account before, during or after cohort access; it grants no other member's data. Discussion reading and posting use the same window. Invitations alone grant no course access. Pauses do not extend the end. Renewal cancellation does not shorten the existing window. A refund request or result is kept separate from an explicitly authorized access revocation. Rejoining requires a new record and does not restore earlier cohorts. No lifetime/alumni or admin exception is assumed. These are proposed sample terms, not Overskill subscription rules or verified native feature behavior. ## 3. Record the member events | Member | Approved access | Change / effective time | | --- | --- | --- | | M-00 | None; invited only | No automatic activation | | M-01 | Full A; B from 2026-11-20 15:00:00Z to B's end | Rejoin begins a new record; old A stays closed | | M-02 | Full A | Pause [2026-11-06 15:00:00Z, 2026-11-08 15:00:00Z); original end unchanged | | M-03 | Full A | Renewal cancellation at 2026-11-10 18:00:00Z; existing end unchanged | | M-04 | A until revocation | Refund requested Nov 11; separately approved revocation effective 2026-11-12 12:00:00Z | | M-05 | A until 2026-11-09 15:00:00Z; full B | Transfer ends A; B starts 2026-11-16 15:00:00Z; deliberate gap | Your member ID (sample data only): Approved cohort / start / end: Pause window(s): Cancellation request and effect: Revocation effective at / authorizer: Replacement cohort record / gap: History or evidence location: ## 4. Test exact instants Each row starts from the defined records above. All members are signed in except where stated. A pair of times has a pair of expected answers in the same order. | Case | Member / resource | Time in 2026, UTC | Expected | Observed / evidence | | --- | --- | --- | --- | --- | | A01 | M-00 / A pack | Nov 3 15:00 | Deny; invitation is insufficient | Not tested | | A02 | M-00 / own account | Nov 3 15:00 | Allow | Not tested | | A03 | M-01 / A pack | Nov 2 14:59:59 / 15:00:00 | Deny / Allow | Not tested | | A04 | M-01 / A second lesson | Nov 9 14:59:59 / 15:00:00 | Deny / Allow | Not tested | | A05 | M-02 / A pack | Nov 6 14:59:59 / 15:00:00 | Allow / Deny | Not tested | | A06 | M-02 / A pack | Nov 8 14:59:59 / 15:00:00 | Deny / Allow | Not tested | | A07 | M-03 / A pack | Nov 10 18:00:00 | Allow; cancellation does not shorten window | Not tested | | A08 | M-04 / A pack | Nov 11 18:00:00 | Allow; refund request alone changes no access | Not tested | | A09 | M-04 / A pack | Nov 12 11:59:59 / 12:00:00 | Allow / Deny | Not tested | | A10 | M-05 / A second lesson | Nov 9 15:00:00 | Deny; transfer beats lesson release | Not tested | | A11 | M-05 / B pack | Nov 16 14:59:59 / 15:00:00 | Deny / Allow | Not tested | | A12 | M-01 / A pack | Nov 16 14:59:59 / 15:00:00 | Allow / Deny | Not tested | | A13 | M-01 / B pack | Nov 20 14:59:59 / 15:00:00 | Deny / Allow | Not tested | | A14 | M-01 / A pack | Nov 20 15:00:00 | Deny; rejoin does not restore A | Not tested | | A15 | M-01 / B second lesson | Nov 20 15:00:00 | Deny; release is Nov 23 | Not tested | | A16 | M-01 / B second lesson | Nov 23 14:59:59 / 15:00:00 | Deny / Allow | Not tested | | A17 | M-01 / B pack | Nov 30 14:59:59 / 15:00:00 | Allow / Deny | Not tested | | A18 | M-01 / own account | Nov 30 15:00:00 | Allow after course access ends | Not tested | | A19 | Signed out / public overview | Nov 3 15:00 | Allow | Not tested | | A20 | Signed out / A pack or own account | Nov 3 15:00 | Deny for each | Not tested | | A21 | M-02 / A discussion read and post | Nov 6 15:00:00 | Deny for both during pause | Not tested | ## 5. Resolve ambiguous changes - Independent reset: pause an A record until exactly its closing instant. At Nov 16 15:00, access remains denied because the membership window ended. - Keep a stable source event ID. If the same ID returns different instructions, stop for review instead of silently changing the record. - Repeat M-04's revocation with the same effective time. Its record stays ended; no new access or changed date is created. - Repeat M-03's renewal cancellation. A's end stays Nov 16 at 15:00. - A late event keeps its approved effective time. Do not substitute processing time. Define a correction process if that effective time was wrong. - Reject a record with end <= start, a missing timezone, or a window outside its cohort. Reject overlapping approved windows in two cohorts, even if one is paused. - Record M-05's transfer as one approved change to the old and new records. A second tab must not leave both active. The sample's gap is deliberate and shown. Your change / original values / replacement values: Effective instant / authorizer / reason: Expected resources at that instant: Actual result / evidence / remaining repair: ## 6. Verify implementation separately Test allowed and denied rows against the app's protected pages, records, files and posting actions, in existing and fresh sessions. Keep passwords and session tokens out of this worksheet. Use only accounts and sample data you are authorized to test. A hidden button or badge does not prove that a direct request is refused. Already downloaded files cannot be recalled by denying future access. App version / observed at / reviewer: Failed or untested check / owner / next action: Use https://www.overskill.com/learn/verify-private-record-access for the separate access-test method and https://www.overskill.com/learn/ai-app-launch-checklist for release checks. Leave all unperformed results Not tested.