This can be addressed in CouchDB, by creating a validating function that validates all the incoming updates.
Besides that, I'm addressing this via the architecture (there's an aside in the article where I cover this briefly), which will be a subject of a future article:
Central records shouldn't be directly changed by a user. That's now how central record systems should work.
Instead, we should view any document as a request to get or change the central records, to be processed by a clerk. The clerk then changes the state of the document according to the permissions and results.