System design
Part 4 of 6 · Push NotificationsCritical & Time-Sensitive Alerts — Interruption Levels, Channels & Abuse Controls
Critical and time-sensitive paths bypass Focus/DND in limited, entitlement-gated ways. Interviews look for product judgment: which events deserve interrupt, how Android channels and iOS interruption levels differ, and how you stop abuse that would get the app removed or all notifications disabled.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Who may break Focus
Prefer
Server-side classifier + allowlist + quotas
Safety/health with entitlement and explicit permission may be critical. Delivery windows the user opted into may be time-sensitive. Everything else is active or passive. Anomaly spikes auto-downgrade.
- Client-sent urgency is untrusted.
- Kill switch + staged rollout for new urgent templates.
- Audit who/what elevated — App Store / Play review stories.
Alternative
Client sets critical, or a new channel per campaign
A buggy client or attacker elevates. Channel proliferation confuses users into disabling all notifications. Focus-bypass fatigue trains stricter Focus. Store rejection follows.
- Marketing never uses critical — ethics plus store policy.
- OTP is usually high / time-sensitive, not a critical entitlement.
- Full-screen intent is heavily restricted; justify with real-world urgency.
Policy gate before APNs/FCM
Downgrade is a success path. Interviews fail people who only draw 'send critical'.
- 1
Classify the template
Safety vs security vs transactional vs marketing. Product policy, not sender mood. - 2
Quota per user and type
Token bucket. Spike in critical sends → auto-downgrade. - 3
Entitlement + user grant
Critical only if the app is entitled and the user opted in. Else time-sensitive or active. - 4
Send with the mapped level
APNs interruption-level or Android high-importance channel_id. - 5
If already in-app
Prefer the live surface; suppress OS interrupt to avoid duplicate panic.
Overview
Critical and time-sensitive paths bypass Focus/DND in limited, entitlement-gated ways. Seniors are graded on judgment and abuse controls, not on finding the enum name.
You should be able to:
- Walk classify → quota → entitlement → send or downgrade.
- Contrast iOS interruption levels with Android channels without treating them as the same API.
- Name the kill switch you would page on.
Platform models
| Platform | Mechanism | Catch |
|---|---|---|
| iOS interruption levels | passive, active, time-sensitive, critical | Critical needs entitlement + user grant |
| iOS Time Sensitive | Breaks Focus with limits | Not "alarm through silent switch" |
| Android channels | Per-channel importance | User can demote; you cannot silently re-elevate forever |
| Full-screen intent | Alarm-ish UX | Heavily restricted; safety, not marketing |
Urgency tiers
| Tier | Examples | Level |
|---|---|---|
| Marketing / social | promos, likes | normal/active; never critical; collapse aggressively |
| Transactional | shipped, receipt | active; optional time-sensitive if the user opted into delivery windows |
| Security | new login | time-sensitive or high channel; still not "critical" unless policy says so |
| Safety / health / alarm | med window, personal safety | critical only with entitlement, explicit permission, and abuse review |
Architecture (single-column policy)
Decisions
- 1
1 Domain event
- next2 Classify urgency
- 2
2 Classify urgency
- next3 Quota per user/type
- 3
3 Quota per user/type
- next4 Allow urgent?
- ?
4 Allow urgent?
- no5 Downgrade to active/normal
- yes5 Entitlement + send
- 5
5 Downgrade to active/normal
- 6
5 Entitlement + send
- next6 APNs interruption-level or FCM channel
- 7
6 APNs interruption-level or FCM channel
NSE cannot invent critical. Depth: NSE. Channel ids on Android: FCM fan-out.
Diagrams - step by step
Three small diagrams for critical and time-sensitive alerts. Step numbers in the labels give the animation order. The lesson map under Diagram 1 plays those steps.
Diagram 1 - Happy path: policy gate before an urgent send
Decisions
- 1
Step 1 Domain event arrives
- nextStep 2 Classify urgency from the template allowlist
- 2
Step 2 Classify urgency from the template allowlist
- nextStep 3 Check per-user and per-template quota
- 3
Step 3 Check per-user and per-template quota
- nextStep 4 Which level is allowed?
- quota exceeded or anomaly spikeFailure path - kill switch auto-downgrades
- ?
Step 4 Which level is allowed?
- critical, entitled and user grantedStep 5a APNs critical or Android high-importance channel
- time-sensitive allowedStep 5b Time-sensitive level
- neitherStep 5c Downgrade to active or normal
- 5
Step 5a APNs critical or Android high-importance channel
- nextStep 6 Audit log of the elevation
- 6
Step 5b Time-sensitive level
- nextStep 6 Audit log of the elevation
- 7
Step 5c Downgrade to active or normal
- 8
Step 6 Audit log of the elevation
- 9
Failure path - kill switch auto-downgrades
Urgency is decided on the server from an allowlist, then capped by quotas. Critical needs the Apple entitlement plus user permission; everything else falls back to time-sensitive or normal. Every elevation is logged.
Lesson map
Critical & Time-Sensitive Alerts — Interruption Levels, Channels & Abuse
Diagram 1 walks 8 steps from Step 1 Domain event arrives through Step 6 Audit log of the elevation.
Architecture. Step 1 Domain event arrives Ready. Step 2 Classify urgency from the template allowlist Ready. Step 3 Check per-user and per-template quota Ready. Step 4 Which level is allowed? Ready. Step 5a APNs critical or Android high-importance channel Ready. Step 5b Time-sensitive level Ready. Step 5c Downgrade to active or normal Ready. Step 6 Audit log of the elevation Ready. Failure path - kill switch auto-downgrades Ready
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB A["Step 1 Domain event arrives Ready"] B["Step 2 Classify urgency from the template allowlist Ready"] C["Step 3 Check per-user and per-template quota Ready"] D["Step 4 Which level is allowed? Ready"] E["Step 5a APNs critical or Android high-importance channel Ready"] F["Step 5b Time-sensitive level Ready"] G["Step 5c Downgrade to active or normal Ready"] H["Step 6 Audit log of the elevation Ready"] X["Failure path - kill switch auto-downgrades Ready"] A -->|continues| B B -->|continues| C C -->|continues| D D -->|critical, entitled and user granted| E D -->|time-sensitive allowed| F D -->|neither| G E -->|continues| H F -->|continues| H C -->|quota exceeded or anomaly spike| X
Diagram 2 - Failure path: marketing breaks Focus
Sequence
- 1
Marketing job → Policy gate
Step 1 flash sale template asks for time-sensitive
- 2
Policy gate → iOS and Android
Step 2 no allowlist, so it passes through
- 3
iOS and Android → User
Step 3 breaks Focus at 2 am
- 4
User → iOS and Android
Step 4 user turns off all notifications for the app
- 5
Marketing job
Step 5 the channel is lost for real alerts, and store review risk
- 6
Marketing job
Fix - server allowlist per template, quotas, anomaly kill switch
Misused urgency costs more than one ignored message: users disable everything and app reviewers notice. Abuse controls belong in the server before the send.
Diagram 3 - Decision: urgency tier by event type
Decisions
- ?
Step 1 Event type?
- marketing or socialActive or normal, collapse aggressively
- transactionalActive, time-sensitive only if the user opted in
- security like a new loginTime-sensitive or high channel
- safety, health, alarmStep 2 Entitlement and user permission?
- 2
Active or normal, collapse aggressively
- Wrong pick - marketing as criticalStore policy violation
- 3
Active, time-sensitive only if the user opted in
- 4
Time-sensitive or high channel
- Wrong pick - OTP as criticalOTP does not qualify for the critical entitlement
- ?
Step 2 Entitlement and user permission?
- yesCritical with abuse review
- noTime-sensitive or high channel
- 6
Critical with abuse review
- 7
Store policy violation
- 8
OTP does not qualify for the critical entitlement
This is the urgency tier table as a flowchart. Only safety-type events can be critical, and only with entitlement and permission. Security and OTP messages use time-sensitive or a high-importance channel.
Abuse controls (must-have)
- Per-user and per-template rate limits (token bucket).
- Server-side allowlist of templates permitted for time-sensitive/critical.
- Kill switch + staged rollout for new urgent templates.
- Anomaly detection: spike in critical sends → auto-downgrade.
- Audit log of who/what elevated urgency (store review stories).
Elevate rate and disable rate belong on the dashboard as SLIs — SLIs / SLOs — do not recap error-budget math here.
Urgent retries must not double-alert: collapse + idempotency keys.
Sandbox: urgency classifier (Python)
Entitlement-backed allowlist. Marketing cannot promote itself.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Same idea (TypeScript): Android channel map
Do not auto-create a spam channel per campaign. Users disable the whole app.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Failure modes
- Critical entitlement misuse — store rejection / user revoke; brand damage.
- Channel proliferation — users confused; they disable all notifications.
- Client-only urgency — attacker or buggy client elevates; must enforce server-side.
- Focus bypass fatigue — time-sensitive spam trains users to turn Focus stricter.
- Silent dual-path — in-app WS already alerted; OS critical also fires → duplicate panic.
Pitfalls
User has Focus on. Template is security_new_login. Are they entitled for critical? What level do you send? If they already confirmed the login in-app on the web, do you still interrupt the phone?
Interview Q&A
Can marketing use critical?
Answer
No. Entitlement, ethics, and store policy forbid it. Collapse aggressively and use passive/active.
Time-sensitive vs critical on iOS?
Answer
Time-sensitive breaks Focus in a limited way. Critical can bypass Silent with permission. Critical is for safety-class product, not "we really want this open."
Who creates Android channels?
Answer
App code at runtime. Importance is user-adjustable afterward. You cannot silently re-promote forever.
How do you prevent abuse?
Answer
Template allowlist, per-user/per-template quotas, anomaly kill switch, audit of who elevated. Client urgency is untrusted.
OTP as critical?
Answer
Usually a high / time-sensitive channel — not a critical entitlement. Rate-limit and collapse.
What SLIs sit on this path?
Answer
Elevate rate, disable rate, quota-downgrade rate. How to turn those into good/valid ratios: SLIs.
In-app already open?
Answer
Prefer the in-app surface; suppress the OS interrupt while the session is live. Depth: WebSockets & MQTT.
Idempotency for urgent retries?
Answer
Same. Urgent retries must not double-alert. Collapse + idempotency key. Depth: idempotency keys and reliability.
Can NSE raise interruption level to critical?
Answer
It can set fields on mutable content, but it cannot satisfy the entitlement + user permission contract. Policy stays on the server.
Full-screen intent on Android?
Answer
Heavily restricted. Justify with real-world urgency (safety). Not a marketing trick. Users and Play review will punish misuse.