File Upload & Scanning Pipeline  ·  View 12 of 21  ·  Data

Data Model

Twelve entities — and the thirteenth, which every first draft adds and this design refuses.

Editable source SVG draw.io All views
tenant tenant_id PK residency_region storage_quota_bytes reuse_isolation_level destination_scope scope_id PK tenant_id FK -> tenant size_ceiling_bytes allowed_types[] required_engines[] optimistic_allowed bool policy_version policy_version_id PK scope_id FK -> scope effective_from composition_rule principal principal_id PK type user | workload tenant_id FK -> tenant upload_session session_id PK scope_id FK -> scope principal_id FK -> principal idempotency_key declared_length declared_type expires_at (+7 d) chunk session_id FK -> upload_session block_index PK byte_length checksum stored_at object object_id PK scope_id FK -> scope content_id FK -> content policy_version_id FK lifecycle_state current_verdict_id FK filename (metadata only) content content_id PK (= hash) byte_length determined_type claimed_type first_seen_at verdict verdict_id PK content_id FK -> content engine_version_id FK outcome clean|infected|indeterminate detection_id bound_hit decided_at revoked_at null engine_version engine_version_id PK engine_name engine_build signature_set_version signature_published_at transition transition_id PK object_id FK -> object from_state to_state actor_principal_id FK cause at (immutable) release_override override_id PK object_id FK -> object approver_principal_id FK reason (required) approved_at 1 : N 1 : N 1 : N 1 : N 1 : 1 1 : N 1 : N 1 : N 1 : N 1 : N Data Model — Twelve Entities, and the Absent One The absent entity is the one every first draft adds: a boolean is_clean on object. Cleanliness is a verdict with an engine, a signature version, a time and a revocation field — not a property of the object. v 1.0 · entities 12

The entity that is not here

  • There is no is_clean boolean on object. Cleanliness is a verdict row with an engine, a build, a signature-set version, a decision time and a revocation field.
  • A boolean cannot answer "which signature version declared this clean, and when", which is the question an auditor and an incident both ask
  • A boolean also cannot be revoked without destroying the evidence that the earlier judgement was made — so the model keeps verdicts and lets state point at the current one

Decisions

  • content is separate from object: one content identity, many objects across many tenants, which is what makes verdict reuse expressible and its isolation level enforceable
  • verdict is keyed by content and engine_version, so a re-scan under a new signature set is a new row rather than an overwrite
  • transition is append-only with actor and cause, and release_override carries a required reason — a release with no recorded reason is not a release this model can represent

Stated assumptions

  • Dedup index partitioned by the tenant's declared reuse isolation level
  • Policy version recorded per object, so the governing rules are recoverable years later
  • Filename retained as display metadata only