Groundskeeper research index
This index preserves the discussions that informed Groundskeeper's foundational architecture. Repository ADRs and contracts are the implementation source of truth; research threads retain rationale, alternatives, citations, and caveats.
| Research | Topic |
|---|---|
| Source Puck discussion | The originating product and research discussion. It coordinates the specialist investigations, consolidates their outcomes, and identifies the architecture artefacts and unresolved decisions required here. |
| Architecture research | Go/Gin and net/http service boundaries, canonical evaluation flow, Portkey isolation, composition, immutable policy snapshots, package layout, and initial delivery shape. |
| Australian PII and address schemas | Australian identifiers, published versus controlled validation, contextual evidence, address structure, G-NAF/PAF constraints, and PostGIS-backed reference matching. |
| Policy bundles | Declarative policy authoring, constrained CEL predicates, explicit imports and typed overrides, OCI distribution, signing, compilation, activation, canary, and rollback. |
| Plugin execution | A common detector contract across built-ins, supervised local and remote gRPC, and future WASM; isolation, capabilities, resource controls, compatibility, and artefact trust. |
| Benchmarking and conformance | Policy-native evaluation, external benchmark roles, PII/safety/jailbreak metrics, Australian slices, paired statistical comparison, corpus governance, and release gates. |
| Indigenous Data Governance | Indigenous Data Sovereignty and governance authorities, prohibited proxy inference, provenance and consent controls, licensing distinctions, evaluation constraints, and evidence gaps. |
| Podman PostgreSQL commands | Practical Podman commands and operating notes for the foundational correlation/provenance store and later control-plane or address-reference phases. PostgreSQL remains outside the synchronous evaluation path. |
| Additional Australian identifiers | Evidence-backed inventory of 59 health, welfare, immigration, education, screening, professional, transport, financial, and other identifiers; authoritative formats, context-only candidates, exclusions, sources, and licensing notes. |
| Detector capability roadmap | Consolidated detector capability matrix across generic PII, Australian identifiers, secrets, prompt security, content safety, data handling, action controls, and banking signals; build/integrate/policy-evaluator classification, ranked next detectors after HPI-I/VSN (IHI first), and defer/reject decisions. Recorded in the roadmap and matrix. |
| Guardrail catalogue structure | Domain-first package organization, path-independent identities, package-level release and governance boundaries, canonical build artefacts, OCI distribution, and signed flattened runtime snapshots. |
| First structured-detector micro-slice | Evaluation and full specification of the first validated_structured (HPI-I) and context_bound_structured (VSN) detectors: pinned sources, grammar/checksum/label rules, evidence states, taxonomy, synthetic fixtures, benchmark method, and provisional gates. Recorded in the micro-slice spec. |
| Australian banking AI guardrails | Action-aware banking policy controls, deterministic and probabilistic enforcement boundaries, typed authority and provenance data, human review, sequence-level safeguards, regulatory evidence, and a ranked 20-capability AU.BANK.* inventory. |
| Detector maturity gates | G1–G3 observe, redact and block gates for detectors, starting with HPI-I and labelled VSN; bound-based statistics, corpus minimums, leakage and Unicode robustness, determinism and performance budgets, human review, evidence bundles, and OD-004/OD-019 mapping. |
| HPI-I and VSN controls | Privacy, legal, records, and security controls for HPI-I and Victorian Student Numbers. Covers the Healthcare Identifiers Act, ETR Act Part 5.3A, APPs and IPPs, PROV, breach regimes, and ISM. Includes synthetic-fixture collision analysis, a control matrix, a pre-production checklist, and OD-023 to OD-031. See the specification. |
Research reflects the state of investigation at the linked thread. External facts, licences, legal requirements, and vendor contracts must be revalidated before use.