Model the business rules
Identify records, relationships and permitted transitions. Separate an editable draft from an approved transaction when the business needs an audit trail. Put important validation on the server even if the frontend also checks it. Use database constraints for invariants that must hold across concurrent requests. Document assumptions about deletion, archiving and record ownership.
Authentication and authorization
Authentication identifies a session; authorization decides what that session may do. Enforce permissions at the request and data layers. Plan account recovery, session expiry and access revocation. Cookie-based sessions need appropriate security flags and CSRF protection for state-changing requests. Avoid trusting organization or role fields supplied by the browser without checking them.
Performance and resilience
Measure expected queries with realistic data sizes, inspect slow paths and avoid loading entire tables for compact screens. Introduce queues where a user should not wait for a slow external service. Set request deadlines and resource limits. A modular application can be easier to operate than many services; choose boundaries based on real ownership and workload constraints.
Deployment and operation
Use separate environments, controlled migrations and a documented rollback process. Test restoring data instead of assuming backups work. Logs should support debugging while avoiding secrets and unnecessary personal data. Handover includes hosting ownership, alert routing, dependency updates and support responsibilities. Bring expected traffic, data shape and critical failure scenarios to the backend planning session.