Groundskeeper
Architecture decisions

ADR 0010: Two structured identifier detector classes

  • Status: Accepted
  • Date: 2026-10-03

Context

Australian identifiers have materially different evidence quality. Some have an authoritatively published structure and possibly a checksum. Others are confirmed to exist, but their grammar is unpublished, broad, issuer-specific, or varies by jurisdiction. Treating both groups as generic regex detectors would either miss useful labelled data or create false certainty from ordinary alphanumeric tokens.

The sourced inventory in data/australian-additional-identifiers.json records source status separately from runtime evidence.

Decision

Support two explicit detector classes:

  1. validated_structured — the candidate grammar is supported by an authoritative source. It may use published prefixes, alphabets, lengths, and checksums. Context gates remain required where the published syntax collides with ordinary values.
  2. context_bound_structured — a finding is emitted only when a candidate is bound to an approved exact issuer/document label or structured field and, where relevant, jurisdiction. A broad alphanumeric regex alone is not evidence and must not emit a finding.

These detector classes do not redefine finding validation state:

  • authoritative syntax alone supports candidate;
  • syntax plus required label/field/jurisdiction context supports probable;
  • only a published checksum/reference validation or approved authoritative registry/service lookup supports validated;
  • validated establishes structural/reference validity, not ownership, current entitlement, or issuance unless the evidence explicitly comes from that service.

Confidence is calibrated separately by detector class and category. A score from a validated-structured detector expresses local structural plausibility. A score from a context-bound detector expresses the joint strength of label/field, jurisdiction, and candidate evidence. Scores are not interchangeable and cannot be promoted merely because a pattern matched.

Consequences

  • Detector manifests and findings can declare the structured detector class.
  • Context-bound conformance cases must prove that the same value does not produce a finding without the required label/field and jurisdiction.
  • Inventory include means an authoritative grammar can drive implementation; it does not guarantee a checksum or permit context gates to be removed.
  • Inventory context_only maps to context_bound_structured; exclude does not generate a detector.
  • Inventory taxonomy IDs are research/catalogue identifiers. Public runtime categories must be mapped into Groundskeeper's hierarchical taxonomy before a detector ships.

On this page