
# ADR 006 — Server-authoritative cell occupation

## Decision

Cell ownership is changed only by the backend.

The Mini App sends Telegram `initData` plus the chosen public content and waits for
a successful API response. It never treats a local optimistic mutation as ownership.

## Failure behavior

- network/auth failure: no local ownership change;
- occupied cell: API returns `409`, then the Mini App refreshes server state;
- success: Mini App reloads the mandala from the API.

## Consequence

The browser cannot create a divergent ownership state. The server and SQLite remain
the source of truth.
