Collection owns the CVR-anchored data hub and its read boundary¶
Status: accepted
Date: 2026-08-14
Deciders: Chris (solo founder)
Supersedes as repository authority: the collection-scope decisions that
only existed in data-collection-prephase/CVR/docs/adr/ and the platform root
docs/adr/
Context¶
The repository has implementation ADRs for ingestion, personal-data minimization, financial reports, orchestration, and quality. Its central store and service-boundary decisions still live outside the repository. This split has caused drift. The project charter describes a collection-owned detail interface and a relational graph, but the local ADR set does not define them.
The external records remain useful design history. They are not a safe source of current authority because they describe an earlier population size, daily full refreshes, raw JSONB in Postgres, and a broad lazy-detail model. The current implementation uses an incremental CVR refresh, GCS raw snapshots, and an eager five-year financial-document window.
Decision¶
- This repository is the authority for collection architecture. A
collection decision is not active until it is in
docs/adr/here. External prephase and platform ADRs are design input only. - Collection owns data availability. It owns upstream access, mapping, storage, provenance, freshness, schema migrations, and consumer read contracts. It is the only writer to the hub. Analysis and product code do not call upstream sources and do not read base tables.
- Supabase PostgreSQL is the query store. It holds current projections, queryable source history, relationship history, and read models. GCS holds immutable raw source artifacts and large documents. Raw artifacts are the audit and rebuild source; they are not the product read interface.
- CVR is the anchor. Companies, production units, participants, financial publications, web signals, and later sources join through canonical entity identities rooted in CVR.
- The store is derived and rebuildable. Each source declares its source of truth, freshness limit, provenance fields, and rebuild path. A completed ingestion run and a valid data-quality verdict are separate facts.
- Ingester and enrichment failures stay isolated. Source ingesters and composite enrichment pipelines have separate schedules, ledgers, budgets, and failure surfaces. They exchange stored data, not adapter calls.
The company-detail contract is in ADR-0012. The graph foundation is in ADR-0013. Web enrichment is in ADR-0014.
Options considered¶
| Option | Benefit | Cost | Decision |
|---|---|---|---|
| Keep external ADRs as authority | No document work | Decisions continue to drift from code and are hard to review in one repository | Rejected |
| Copy every old ADR unchanged | Preserves the old sequence | Imports obsolete assumptions and creates number conflicts | Rejected |
| Record the current foundation locally and keep external records as history | One current decision spine; old evidence stays available | Requires explicit local replacement records | Chosen |
Consequences¶
PROJECT_CHARTER.md,CONTEXT.md, architecture pages, and read-contract documents must link to local ADRs for collection decisions.- A source document in GCS is not a substitute for queryable history in PostgreSQL.
- Consumers receive collection-owned contracts. They do not assemble a company dossier from private tables.
- A later platform-wide ADR can constrain this repository, but the local ADR must state how that constraint applies here.
Open questions¶
- None for the ownership boundary. Transport and schema details belong to the decision that owns each contract.