Skip to content

ADR 0002: Archive governed public packages for evidence bundles

Status: Implemented in prepared source; production release pending.

The existing evidence bundle implementation hashes a requested package ID without reading a result. Audit summaries intentionally truncate content and cannot reconstruct a complete, verified financial result. A real bundle needs the original governed public projection and a caller-bound locator.

Reuse the existing object-storage interface and PostgreSQL. Add an immutable locator record with source audit, caller, institution, tool, length and checksum. The shared core boundary writes the public package after all governance and commit callbacks, before completing the success audit. Readers require the latest source audit to be successful and owned by that caller and institution. An object left by a failed audit is inaccessible. Storage failure fails the business call and leaves a sanitized failure audit; it cannot become a success with an unverified bundle.

The public locator is data_package:<audit_id>, derived from the existing result field, with no new public tool or DataPackage schema field. Export reuses the original public facts, evidence and license scopes, and verifies the original canonical JSON rather than hashing the locator. It never reopens controlled material or recovers shortened audit content. Old unarchived calls remain unavailable and must be repeated after the formal release.

No dependency, build tool, model service or storage-provider migration is added. The additive migration must be rehearsed with the existing backup/restore procedure. Application rollback preserves archived objects and locator rows. Backup and future retention must include both; abandoned objects require a separate, reversible cleanup inventory. Supplier raw records and these public result objects retain distinct checksum meanings.