File Upload & Scanning Pipeline · View 12 of 21 · Data
The entity that is not here
- There is no is_clean boolean on object. Cleanliness is a verdict row with an engine, a build, a signature-set version, a decision time and a revocation field.
- A boolean cannot answer "which signature version declared this clean, and when", which is the question an auditor and an incident both ask
- A boolean also cannot be revoked without destroying the evidence that the earlier judgement was made — so the model keeps verdicts and lets state point at the current one
Decisions
- content is separate from object: one content identity, many objects across many tenants, which is what makes verdict reuse expressible and its isolation level enforceable
- verdict is keyed by content and engine_version, so a re-scan under a new signature set is a new row rather than an overwrite
- transition is append-only with actor and cause, and release_override carries a required reason — a release with no recorded reason is not a release this model can represent
Stated assumptions
- Dedup index partitioned by the tenant's declared reuse isolation level
- Policy version recorded per object, so the governing rules are recoverable years later
- Filename retained as display metadata only