A dedupe key carries the intent, not just the identity
Submit the teardown form, then the contact form, same address, inside the window. Watch whether the contact email arrives.
Get every Fix AI Slop Code episode
The code it wrote, the code it should have written and a check, for every episode
Watch the episode
The same idea in a short video. It plays here, and nothing loads until you press play
What is going on
Deduplication keyed on the email alone means the second thing a person does is treated as a repeat of the first. The screen still says "sent," because the handler returns success on the dedupe path. Nobody is lying; the key is just too short.
Where it bit
Newsletter and contact on the same worker shared one dedupe key. A person who grabbed the teardown and then wrote a real message ten minutes later got "sent" and the message vanished. That is the warmest lead in the funnel, dropped silently.
The practice
Key on {action}:{identity}:{window}. Return a distinct status for the dedupe path and show it. Log the collision so you can count how often it happens.
Get this check as a script you can run tonight

The coding agent never holds production credentials
An agent with a production database URL will sooner or later run a migration or a cleanup against it, so production secrets never enter its env
Keys go in headers, never in URLs
A URL is written to server logs, CDN logs, browser history and error trackers, so an API key in a query string is a key in five places
Backups the app cannot reach, and one restore you have actually done
A backup on the same account the app or an agent can delete from is not a backup, and a restore you have never run is a number you do not have
If this check came back with more than you expected, that is worth a conversation