{"admissionConditions":[{"id":"named-blockers-resolved","requirement":"Both immediate publication blockers are resolved and tested.","status":"required-not-satisfied"},{"id":"controller-lawful-basis-retention-and-rights","requirement":"The real controller, processors, purposes, lawful basis, retention, privacy information and rights handling are recorded for the operational pipeline.","status":"required-not-satisfied"},{"id":"formal-dpia-decision","requirement":"A formal DPIA decision covers the actual sources, fields, combinations, screening and publication interface.","status":"required-not-satisfied"},{"id":"asset-rights-expiry-and-locator-review","requirement":"Every exact source asset has separate link and derived-use decisions, a mutation-detection digest, human-reviewed locators and a review-expiry date.","status":"required-not-satisfied"},{"id":"small-territorial-field-set-reviewed","requirement":"One deliberately small territorial source and field allowlist passes legal, privacy, security and editorial review.","status":"required-not-satisfied"},{"id":"end-to-end-correction-and-rollback-exercised","requirement":"Exact-ID bridges, source change, correction, urgent suppression, tombstones, cache handling and full rollback are exercised end to end.","status":"required-not-satisfied"},{"id":"comparison-review-guidance-calibrated","requirement":"Human comparison reviewers have written guidance, calibration examples, appeal handling and periodic error review.","status":"required-not-satisfied"},{"id":"public-meaning-and-limits-explained","requirement":"The public interface keeps source voice, TaxSorted analysis, uncertainty, money dimensions, source permanence and non-equivalence visible.","status":"required-not-satisfied"},{"id":"monitored-emergency-stop","requirement":"A monitored off-switch can stop organisation records without removing the sector framework or official source doors.","status":"required-not-satisfied"}],"collectionGuide":[{"boundary":"Organisation-only identity with exact public identifiers; no people or contacts.","collection":"organisations","question":"Which registered organisation or official institution is in view?"},{"boundary":"Bidirectional organisation membership and declared ASCII canonicalisation; no name, address, domain, person, award-ID or probabilistic join.","collection":"identifierMappings","question":"Which exact official identifier establishes the join?"},{"boundary":"Reviewed document metadata plus bounded public review declarations and notes; every field is screened, locators are pointers, and source bodies, excerpts, images and attachments stay external.","collection":"documents","question":"Which reviewed public source door supports the record?"},{"boundary":"Organisation capacity or TaxSorted editorial voice; never a natural-person profile.","collection":"voices","question":"Which institution is attributed as speaking?"},{"boundary":"Human-reviewed paraphrase and modality, not quotation or truth verdict.","collection":"claims","question":"What does the source report the attributed institution said?"},{"boundary":"Aggregate programme scope only; no beneficiary rows.","collection":"programmes","question":"What organised work was planned or delivered?"},{"boundary":"Money stage stays explicit; anonymous or aggregate funding needs disclosure review.","collection":"fundingEvents","question":"What organisation-level award, commitment, payment or aggregate flow was reported?"},{"boundary":"Integer GBP minor units, complete basis and aggregate pay only; every fact has a disclosure review, staff costs and remuneration are always people-derived, every TaxSorted-derived number uses structured exact arithmetic with a fresh result review, and named pay is never stored.","collection":"financialFacts","question":"What aggregate financial fact was filed or exactly derived?"},{"boundary":"Category totals only; no asset identity, address or location.","collection":"assetAggregates","question":"What aggregate asset value was reported?"},{"boundary":"Organisation-to-organisation exact official links; no person-control graph.","collection":"controlRelations","question":"Which organisation controls or is formally linked to which organisation?"},{"boundary":"Source-backed observation with disclosure review, separate from outcome or proof.","collection":"observations","question":"What organisation-level action or event was recorded?"},{"boundary":"Aggregate scope and attribution strength; no individual outcome rows.","collection":"outcomes","question":"What aggregate result was reported or measured?"},{"boundary":"Organisation evaluator and reviewed finding; TaxSorted analysis is never labelled independent.","collection":"evaluations","question":"Who evaluated the work, by what method and with what independence?"},{"boundary":"Human-approved rule and visible context; every numeric result has a fresh disclosure review; no trust, faith, honesty or impact score.","collection":"comparisons","question":"How do two exact candidate records relate?"},{"boundary":"Absence stays visible. Suppression uses fixed safe wording and no source-document pointer, so the omitted value and its context are not repeated.","collection":"coverageGaps","question":"What is unknown, unavailable, conflicting, unsafe or deliberately excluded?"},{"boundary":"Fixed explanation and reviewed non-personal identifiers; removed content is never repeated, and effective time cannot postdate the named candidate's assembly.","collection":"tombstones","question":"Which record was removed, when and by which safe reason?"},{"boundary":"Candidate history only; a digest detects declared-byte mutation but is not publication approval.","collection":"releases","question":"Which immutable candidate chain was assembled?"}],"collectionOrder":["organisations","identifierMappings","documents","voices","claims","programmes","fundingEvents","financialFacts","assetAggregates","controlRelations","observations","outcomes","evaluations","comparisons","coverageGaps","tombstones","releases"],"comparableMoney":{"calculationRule":"Differences use right amount minus left amount and must remain a safe integer. Ratios preserve right and left minor-unit amounts as an exact numerator and non-zero denominator; no floating-point quotient is stored. A derived financial fact follows its inputs and reviews, then receives a fresh disclosure review. A numeric comparison's fresh disclosure review follows both records and the human comparison review. People-derived status propagates to either result.","exactBasisFields":["currency","accountingBasis","grossOrNet","vatBasis","priceBasis","priceBaseDate","consolidationScope"],"exactContextFields":["organisationId","period","scopeKey","scopeDefinition","metricKey","metricDefinition"],"mismatchRule":"If organisation, scope, definition, metric or a money-basis field differs, do not calculate a delta or ratio; record not-comparable in the candidate and name the differing dimensions. A period difference permits arithmetic only for an explicit change-over-time relation.","stageRule":"Measurement stage must be displayed. A forecast, commitment, payment and outturn are different stages even when arithmetic comparison is possible.","storage":"signed integer minor units; GBP only in version 1"},"comparisonContract":{"changeOverTime":"change-over-time requires the same organisation, scope and metric across different periods.","contextAnchor":"comparisonContext repeats the left record's exact context; the right record retains its own context.","dimensions":"sameOrganisation, samePeriod, sameScope and sameMetric are declared by the producer, recomputed from the referenced records and must match. For inconsistent-with between two money records, money basis, measurement stage and amount date must also match.","exactContextRelations":["consistent-with","inconsistent-with","supports","qualifies"],"notComparable":"not-comparable may preserve differing contexts or money bases and cannot carry numericComparison."},"cursor":{"encoding":"base64url of canonical UTF-8 JSON","invalidCursor":"Fail with a typed error and a safe next action to restart at the first page of the requested release.","payloadFieldsInOrder":["version","releaseId","collection","lastId"],"stability":"A cursor is valid only for its immutable release. A different release requires a new cursor; records are never inserted into an old release.","version":"taxsorted.cursor/1"},"hardBoundaries":["organisation-level records only","no natural-person records or identifiers","no contact details or addresses","no named pay","no personal belief data and no belief inference","no fuzzy, probabilistic or name-only joins","every identifier mapping is listed by its referenced organisation and every listed mapping points back; uppercase-alphanumeric canonicalisation accepts only ASCII letters, digits, spaces and hyphens","multiple official identifiers need a human-reviewed source bridge that explicitly publishes both identifiers; a privacy flag alone is not a bridge","documents store reviewed metadata plus bounded public source-review declarations and notes; source bodies, excerpts, images and attachments remain external and are not stored","every public document and source-review field is human-reviewed to exclude people, contacts, addresses, named pay, personal belief detail or belief inference about a person, and source excerpts; locators are pointers only and free-text arrays are bounded","source locators are human-reviewed editorial assertions, not mechanically verified anchors or a source archive","a value needing statistical suppression is omitted from value-bearing collections and represented by a coverage gap with fixed safe wording and no source-document pointer","every financial fact has a disclosure review and states whether it is genuinely organisation-only or people-derived; staff costs and remuneration are always people-derived","every derived financial fact and numeric comparison has a fresh disclosure review; people-derived status propagates from inputs","taxsorted-derived is reserved for structured exact-arithmetic financial facts and labelled TaxSorted source-comparison evaluations; other action and money records remain externally attributed","asset values remain aggregates; no item-level asset or location records","control relations connect organisations only","public record IDs and retained tombstone target IDs must be opaque or non-personal and human-reviewed"],"id":"uk-charity-accountability","inconsistencyRule":{"relation":"inconsistent-with","requirements":["human-approved review","exact published organisation identifier","same organisation","same period","same scope key and scope definition","same metric key and metric definition","for two money records: same money basis, measurement stage and amount date"],"warning":"A numerical difference, changed measurement stage or missing record is not by itself evidence of inconsistency."},"orientation":{"readingPath":["organisations and exact identifiers establish which registered organisation or official institution is in view","documents establish the public source door, link decision and separately reviewed derived uses","voices and claims attribute a human-approved faithful paraphrase and point readers to the publisher's words as available at review time; source permanence fields say whether a version or lawful archive is known","programmes, funding, finance, assets and control preserve what admitted sources report about the organisation-level machinery","observations, outcomes and evaluations keep reported activity, result and judgement separate without treating any one as independent proof","comparisons expose aligned evidence and coverage gaps preserve what is not known"],"safeNextActions":["read the JSON Schema before producing a candidate dataset","treat every validated dataset as a candidate-not-admitted shape","use exact published identifiers and create a coverage gap when an exact join is unavailable","send sensitive corrections through the future confidential intake, never a public issue"],"startHere":["publicationBlockers","admissionConditions","hardBoundaries","collectionOrder"]},"publicationAdmission":{"currentSchema":"candidate-shape-only","datasetStatus":"candidate-not-admitted","digestMeaning":"Dataset and source-review digests detect mutation of declared bytes only; they prove neither legality, reviewer identity nor external workflow completion.","externalEnvelopeRequired":true,"requirement":"A later versioned publication envelope must resolve every admission condition and real confidential-intake, source-review, emergency-stop and human-approval check ID against an operational audit store. Fields supplied inside this dataset cannot prove those checks happened."},"publicationBlockerScope":"These are the two immediate missing systems, not the complete publication test. Every admissionConditions item must also be evidenced and approved.","publicationBlockers":[{"id":"confidential-correction-safety-intake","requirement":"A confidential correction and safety intake with identity-safe triage, urgent suppression and an auditable resolution path must exist and be tested.","status":"blocking"},{"id":"asset-level-rights-admission-digest","requirement":"Every source asset needs a separate link decision and locator-specific derived-use decision. Locator equality is checked, but meaning and resolvability are human assertions. Its digest detects mutation of the declared review record; it does not prove legality or reviewer identity.","status":"blocking"}],"purpose":"Keep attributed normalisations of what sources report organisations said, funded and did traceable without building a people or belief graph or presenting reports as independent proof.","releaseIntegrity":{"digestAlgorithm":"sha256","digestPreimage":"canonical-utf8-dataset-with-current-release-datasetDigest-omitted-v1","predecessorRule":"Every previousReleaseId must resolve, be assembled no later than its child and form one acyclic chain in which every candidate is reachable from meta.currentReleaseId. A tombstone cannot take effect after the candidate named by its releaseId was assembled; that is the first candidate carrying it. The tombstone remains in every later candidate, whose tombstone count must equal the cumulative retained ledger.","verification":"The current candidate digest is recomputed and must match during validation. It detects mutation of declared bytes and is not proof of source rights, review identity or publication approval."},"schemaId":"taxsorted.uk.charity-accountability/1","stableSort":{"reason":"Record IDs are restricted to 1–100 lowercase ASCII letters, digits and hyphens, making bytewise ascending order stable across runtimes and locales and bounding identifier metadata.","rule":"collection-order-then-ascii-id-ascending","ties":"forbidden because IDs are unique within and across record collections"},"status":"schema-only-not-admitted","validationLayers":{"jsonSchema":"Validates strict record shapes, required fields, literals, formats and local constraints.","requirement":"A candidate producer should pass the runtime Zod schema. Neither JSON Schema nor Zod validation is publication admission.","runtimeZod":"Also validates the declared all-public document/source-review field scope, bounded review text, reviewed source-use permission and locator equality, source subjects, voice roles and modalities, bidirectional identifier membership, identifier alphabets, ownership and bridge connectivity, programme ownership, reserved TaxSorted-derived assertions, every financial fact's disclosure decision, forced people-derived treatment for staff costs and remuneration, publishable and propagated disclosure reviews, final privacy-after-disclosure ordering, safe suppression gaps, structured integer arithmetic and derivation cycles, comparison alignment, review-time ordering, release counts, sorting and safe tombstones."}}