Groundskeeper

Groundskeeper research index

This index preserves the discussions that informed Groundskeeper's foundational architecture. Repository ADRs and contracts are the implementation source of truth; research threads retain rationale, alternatives, citations, and caveats.

ResearchTopic
Source Puck discussionThe originating product and research discussion. It coordinates the specialist investigations, consolidates their outcomes, and identifies the architecture artefacts and unresolved decisions required here.
Architecture researchGo/Gin and net/http service boundaries, canonical evaluation flow, Portkey isolation, composition, immutable policy snapshots, package layout, and initial delivery shape.
Australian PII and address schemasAustralian identifiers, published versus controlled validation, contextual evidence, address structure, G-NAF/PAF constraints, and PostGIS-backed reference matching.
Policy bundlesDeclarative policy authoring, constrained CEL predicates, explicit imports and typed overrides, OCI distribution, signing, compilation, activation, canary, and rollback.
Plugin executionA common detector contract across built-ins, supervised local and remote gRPC, and future WASM; isolation, capabilities, resource controls, compatibility, and artefact trust.
Benchmarking and conformancePolicy-native evaluation, external benchmark roles, PII/safety/jailbreak metrics, Australian slices, paired statistical comparison, corpus governance, and release gates.
Indigenous Data GovernanceIndigenous Data Sovereignty and governance authorities, prohibited proxy inference, provenance and consent controls, licensing distinctions, evaluation constraints, and evidence gaps.
Podman PostgreSQL commandsPractical Podman commands and operating notes for the foundational correlation/provenance store and later control-plane or address-reference phases. PostgreSQL remains outside the synchronous evaluation path.
Additional Australian identifiersEvidence-backed inventory of 59 health, welfare, immigration, education, screening, professional, transport, financial, and other identifiers; authoritative formats, context-only candidates, exclusions, sources, and licensing notes.
Detector capability roadmapConsolidated detector capability matrix across generic PII, Australian identifiers, secrets, prompt security, content safety, data handling, action controls, and banking signals; build/integrate/policy-evaluator classification, ranked next detectors after HPI-I/VSN (IHI first), and defer/reject decisions. Recorded in the roadmap and matrix.
Guardrail catalogue structureDomain-first package organization, path-independent identities, package-level release and governance boundaries, canonical build artefacts, OCI distribution, and signed flattened runtime snapshots.
First structured-detector micro-sliceEvaluation and full specification of the first validated_structured (HPI-I) and context_bound_structured (VSN) detectors: pinned sources, grammar/checksum/label rules, evidence states, taxonomy, synthetic fixtures, benchmark method, and provisional gates. Recorded in the micro-slice spec.
Australian banking AI guardrailsAction-aware banking policy controls, deterministic and probabilistic enforcement boundaries, typed authority and provenance data, human review, sequence-level safeguards, regulatory evidence, and a ranked 20-capability AU.BANK.* inventory.
Detector maturity gatesG1–G3 observe, redact and block gates for detectors, starting with HPI-I and labelled VSN; bound-based statistics, corpus minimums, leakage and Unicode robustness, determinism and performance budgets, human review, evidence bundles, and OD-004/OD-019 mapping.
HPI-I and VSN controlsPrivacy, legal, records, and security controls for HPI-I and Victorian Student Numbers. Covers the Healthcare Identifiers Act, ETR Act Part 5.3A, APPs and IPPs, PROV, breach regimes, and ISM. Includes synthetic-fixture collision analysis, a control matrix, a pre-production checklist, and OD-023 to OD-031. See the specification.

Research reflects the state of investigation at the linked thread. External facts, licences, legal requirements, and vendor contracts must be revalidated before use.