Skip to content

Person identities and current accepted-prospect evidence

Status: accepted Date: 2026-09-14 Issues: #768, #769

Decision

The person list uses the existing CVR PERSON participant identifier. It does not combine website mentions into a new person identity. A deleted current projection can retain a nameless deep link when retained participant-kind facts still establish the registry identity. Unknown participant kinds and company participants do not enter the list. This follows ADR-0006 and ADR-0008.

Search is a case-insensitive literal substring of the current registry name, or an exact person identifier. Company references and relationship types filter the same current role. Sets use OR; different keys use AND. Results sort by person identifier and have 100 rows per page. A transactional data version binds the request and cursor. Source changes and the UTC date expire old cursors. The list does not promise a retained historical snapshot.

Profiles preserve dated registry assertions and separate website claims. Missing starts cannot prove current membership. Multiple website claims stay separate, including conflicting names, titles, or roles within one company. A registry name is not replaced by an observed name. Historical registry names and residential data remain excluded. The existing person-keyed participant_facts_as_of operation remains the narrow participant-kind history read; it was never a company-keyed person search operation.

Contact deletion retains only its contact and mention identifiers. This allows an explicit withdrawn state without retaining the value or a reason. Suppression is also checked at read time, before physical deletion completes. A reversed identity link exposes only its withdrawn reference in the person profile. Free-text evidence and URLs can contain contact values. After a company has a contact withdrawal, these unstructured person evidence fields are unavailable, including profile text and URLs on accepted cards and profile URLs in the queue. The rule is shared across these reads; permitted typed contact values and source timestamps remain separate. No suppression reason or operational record is public. This does not approve the deferred credit or entitlement product in #602.

Accepted-prospect evidence is current evidence in the saved seed/filter context. It is not a snapshot of the acceptance date. The consumer stores CVR, seed/filter context, optional ranking-version expectations, and an optional seller-selected person reference. It does not copy platform evidence. The direct CVR lookup happens after the global Hybrid ranking, and shares the queue's calculation. A rank is an ordinal, not a percentage or probability.

Collection owns this existing Hybrid calculation under ADR-0018 and the Hybrid contract delivered in #587. The accepted-card reason states its similarity basis and returns the registry, financial, profile, and embedding evidence used to inspect it. It does not add a sales recommendation model. General analysis, outreach decisions, and seller workflow remain outside collection. This is the same narrow exception to the charter's general analysis boundary as the existing Hybrid read, now recorded explicitly.

A seller-selected person reference must have a permitted attributed contact on an unreversed website mention for this exact company. A registry role alone never supplies a linked person. Without a selection, the linked-person field is unavailable. Changed ranking versions, missing evidence, withdrawn references, and a CVR outside the saved context have explicit states.

Alternatives

A combined registry/website person cluster would violate the existing identity boundary. A historical card snapshot would need retained ranking inputs and an acceptance-time write, which the current system does not have. Copying those inputs into a tenant store would create a second evidence store. Current reads keep ownership and withdrawal enforcement at the collection boundary.