Issue: revoking downloads in a fictional team library Problem: hiding the button can leave email links, direct URLs and generation jobs intact. Objective: evaluate new download requests after committed revocation against current effective permission. Preserve login and unrelated work. Scope: the team library and the new mediated download route. Recalling already saved copies is excluded. Choice: verify session, team, file access, effective download permission, file availability and a successful authorization lookup on every new request. Stream through the application without exposing direct storage URLs. Concurrency: establish a consistent order between committed revocation and the transfer-authorization decision using consistent permission state. Deny new decisions after commitment when no effective permission remains. Transfers authorized earlier may finish. Retries and range resumption require a new decision. Lookup failure never grants access. Jobs and notifications: recheck before execution, result registration and notification delivery. A revoked member receives neither an available result nor a download notification. Generation completion and access authorization are separate states. Migration: stop issuing direct links; inventory their validity conditions, remaining lifetime and cache routes. Do not claim full cutover until the old delivery routes stop serving files. UI: distinguish login required, access unavailable and authorization lookup failed. Do not disclose protected filenames or storage addresses in unauthorized responses. Revocation does not mean deleting the file. Ownership: planning defines timing, exceptions and copy; engineering maps delivery paths, consistency and caches; QA reproduces old-link and concurrent requests; operations checks notices and audit records. Before release: test direct-route bypass, other-team files, multiple roles, queued jobs, revocation before completion, resumption and lookup outage. Obtain owner decisions on retention, transfer capacity and in-flight behavior. Completion evidence: design table, decision rationale, API and screen results, legacy-route shutdown checks and handoff record. This is a worked fictional design. Timing and rollout checks: before migration, a direct URL issued09:59 expires10:29 at30 minutes or10:04 atfive minutes and remains valid at10:01. After migration, repeat the relative timing to test denial on the application URL and separately verify no body from retained old direct URLs. Do not mark transitional state as complete.