# 0002 — A lapsed licence degrades administration, never patient care

**Status:** Accepted · 2026-08-01

## Context

The commercial instinct in licensed on-premise software is to make expiry hurt:
lock the application until the customer pays. This is clinical software. The
people at the keyboard when a licence lapses are a receptionist with a waiting
room and a doctor mid-consultation. The data behind the lock is the clinic's own
patient records.

## Decision

A degradation ladder:

| Condition | Behaviour |
|---|---|
| Token valid | Normal |
| Server unreachable, token unexpired | Normal, silent |
| Server unreachable beyond grace (default 14 days) | Persistent admin banner; full clinical function |
| Licence expired | Administrative surfaces read-only (settings, user creation, exports). **Appointments, encounters, prescriptions and invoicing keep working**, with a banner |
| Licence revoked | As expired, plus a prominent notice and the vendor's commercial process |

`config/licensing.php` carries an `always_available` list of route prefixes that
never degrade. Commercial pressure comes from update access, support access and
administrative degradation — never from withholding a clinic's patient data.

## Consequences

**Good.** No support call ever begins with a clinic unable to see a patient's
allergies. The failure mode of our own billing problem is not a safety incident,
and it is not a headline.

**Bad.** A determined non-payer can keep running the clinical core indefinitely.
Accepted: they cannot get updates, security fixes or support, and that is where
the ongoing value is. Recovering revenue from a hostile customer was never going
to come from a lockout screen.

**Also.** The client tolerates an unreachable licence server by design — a
circuit breaker after three failures, and every call site treats failure as
normal. An outage on our infrastructure must never slow down a clinic.
