Great framing — "what correct means" is exactly the hard part. The mechanisms I'd want to see named: (1) idempotency keys on every transfer, so retries never double-move money; (2) an immutable double-entry ledger — never update balances in place, balances are a derived projection over the entry log; (3) debit/credit pairs inside a single DB transaction with proper isolation; (4) settlement retries keyed off the transfer record's state machine, not blind re-submission. Get those four right and most "ghost money" bugs disappear.