Workflow: recover from conflicts and partial workflows
On 412, reread the aggregate, reconcile, and retry with its strong ETag. On state conflict, follow allowedActions. On expired confirmation, request a fresh preview. On idempotency conflict, use the original payload or a new key only for new intent. On 429/503, honor Retry-After; after timeouts replay identical idempotent writes.
Expected state: no lost update, duplicate record, broadened scope, or unconfirmed destructive effect occurs.