ADR 0003: Publish licensed official SEC filings into the OAuth data namespace¶
Status: Accepted within the production repair task; implementation prepared, actual ordinary-user and production release verification pending.
Connector credentials belong to the machine institution. Filing repositories correctly restrict documents, fragments and facts to their data institution. Consequently, successful operator ingestion alone does not populate the ordinary OAuth users' shared data namespace. Removing tenant filters or granting machine credentials in that namespace would violate the existing boundary.
The existing trusted SEC filing connector publishes a separate, idempotent document into the configured OAuth data institution after its normal ingestion. Following the owner's explicit default-off instruction, captured source grants and factual lookup purposes are checked only when the administrative license switch is explicitly enabled. Source terms remain captured without relabeling. It always checks the official HTTPS SEC archive URL, its issuer CIK, source identity and the original content checksum. Unverified source content fails the connector record; unknown grants and redistribution terms do not block publication with the default disabled switch.
The publication reuses the ingestion, parsing and deterministic extraction services and existing PostgreSQL/object storage. Source bytes, checksum, publication, retrieval and known times and captured terms remain unchanged. The data institution enters idempotency and object keys, so the machine and OAuth records remain distinct. Tenant filters continue to apply to every read. There is no new public parameter, user-selected target, machine credential or ordinary-user connector permission.
The original operator caller and institution own the ingestion, parsing and extraction audits. An internal keyword records that actor separately from the data owner, only for the explicit worker publication operations; the input summary records the target data institution. Tasks and connector runs retain their original owner. Ordinary users own their own public query/evidence/audit resources and cannot read the operator's protected records.
Publication is limited to the configured official sec_edgar_filings source.
Other sources and private uploads keep their existing data ownership. Financial
annual/quarterly reports with failed extraction cannot become successful
publication tasks; other legitimate forms without company facts retain their
parsed evidence and explicit quality issue. No model, dependency or
source-policy mode is added or enabled. Rollback preserves the two scoped data
copies and their audits; deleting them is not part of application rollback.
Captured terms participate in ingestion idempotency. Migration
0066_filing_capture_versions removes the obsolete byte-only uniqueness
constraint while retaining the unique idempotency key and adding a scoped
capture search index. It preserves existing records and keys. Re-delivery with
equivalent captured terms is idempotent; a changed captured grant creates
separate metadata for the same verified bytes without relabeling old records.
Downgrade refuses duplicate byte identities rather than deleting their history;
use the paired database/object-store backup to restore the earlier application.
Broad fragment search selects the latest capture of each source document visible to the requesting institution at the requested time. Both recorded and source times restrict that choice. An explicit document ID still reads its original capture and license, including old grants that do not authorize the current user. Failed new captures cannot silently fall back to older evidence. The public ten-fragment limit remains explicit and returns partial on overflow.