Skip to content

Canonical intake schema

What it is

The canonical intake schema is the single definition of what a claim looks like on the way into Adjust360. There is one schema per LOB, generated from the input maps of the tools that read it, never authored by hand. Projections for a carrier's structured payload and for an IDP vendor differ only in wrapping, never in content. Schema, projections, field guide, roles and profiles are reference_data records in the snapshot, covered by the drift check and the packager; a tenant overlay is an overlay record and cannot remove a decisive field .

The schema is an interface, not intellectual property. It is what a carrier receives. The corpus, registry, evaluator, templates, seeds and kit are never shared.

The envelope

Every fact, including core facts, is carried in one envelope: {value, status, source_ref, speaker}. Status is one of the four canonical literals; a carrier may send only stated and not_stated, an omitted field is not_returned, and there is no unknown. "Required" means presence with status, not presence with a value: a carrier that has checked and found nothing sends not_stated, and the receipt scores that as answered .

The party graph

Parties are one graph with a shared role enum and a stated identity_status (identified or unknown). A party carries name, organization and insurer_name with a roles[] array; the roles were expanded to include contractor, tenant, landlord, utility, municipality and product_seller. Vehicles reference parties by owner_party_id and driver_party_id and carry for_hire. An invented party enum was reverted to engine values by ruling; the enum is the engine's, not the carrier's.

Damages and policy terms

Money arrives as damages[] with a head and a kind. The head vocabulary (DAMAGES-HEAD-VOCAB-v1) and the kind vocabulary (DAMAGES-KIND-VOCAB-v1: estimate, paid, incurred, reserve, coverage_terms) are accepted records . The deductible is not a damages head; it is a policy term in core.policy.coverages[] alongside in_force and limit, and coverage_responds lives at core.policy.coverages[].responds. Waiver signals live under core.policy so there is one path for every LOB. The coverage vocabulary is AUTO collision, comprehensive, medpay, um_uim and rental; PROPERTY dwelling, contents and ALE.

Selector grammar

A rule reaches into an array with array[key=value].field; an ambiguous match is an error, never a first-match pick. The seeded resolver anchor record carries no fallback. header.stage is required with no default, and the header is one block: {claim_id, lob, stage, format_version, profile} .

Profiles and tiers

An analysis profile (subro, liability, coverage, authority, full) names the fields a run needs. Each field's tier (decisive, supporting, optional) is generated from read_by, the set of records that read it, never assigned by hand. The receipt is scored against the declared profile: it lists what is stated, what was checked and not present, what was not supplied by tier with needed_by, and what falls outside the profile, and it says a field is "listed on the receipt as outside scope", never "silently discarded" .

Projections

Two projections remain: carrier_structured, the JSON a carrier authors and delivers, and idp.reducto. A third, warehouse.flat, was dropped because the carrier delivers JSON in carrier_structured and there was nothing for a flat projection to serve. One normalizer serves the projections through adapters. Once the generator lands, generate_intake_schema.py --diff replaces the manifest diff as item 4 of the standing header .

Jurisdiction and anchors as records

The harness derives jurisdiction_context through a jurisdiction_role_map record (JURIS-ROLE-MAP-v1), and deadlines anchor on an anchor_field record (RESOLVER-ANCHOR-FIELD-v1): date_of_loss is the only core anchor, and WC's date_of_injury sits in the WC extension. The resolver, the AUTO liability analyzer and the GL liability analyzer each have an input map record (JURIS-RESOLVER-INPUT-MAP-v1, LIABILITY-AUTO-INPUT-MAP-v1, LIABILITY-GL-INPUT-MAP-v1), one per LOB. Liability facts sit inside the LOB extension: negligence_per_party is an array with party_ref, and physical and rebuttal facts are {fact_id, status, party_ref} against closed vocabularies. A computed default of 100 minus the other party's percentage was found and logged; nothing is computed on the intake side .

Derived signals

A signal the engine computes from carrier facts is a derivation record, never a carrier field. Roster flags such as owner_differs_from_driver are derived, notice_of_claim_days is derived by the resolver, and fault_pattern is a derived signal on the PD-1 track. The carrier states facts; derivations cite the facts they read.

The field guide

The field guide is the carrier-facing description of every path, held as records. It went through three reviews before seeding as v4 with 88 paths .

Review 1 (84 rows) was not accepted. decisive_for and read_by must be generated from spec records: eleven rows cited theories that do not exist. Descriptions describe the carrier's fact, not engine behaviour. assignment_stated had been described as a subrogation assignment; it is the employer's trip assignment. frolic_or_detour was deleted as a conclusion. Duplicates between subro summary facts and liability detail were annotated for consolidation, with the fault percentage consolidated at once. A completeness check was required because gates read coverage_responds, the waiver fields, party roles, identity status and owner_differs_from_driver, none of which were among the 84.

Review 2 on the delivery package stopped the work: a live database connection string had been printed in a delivery document. The remedy was rotation, purge of the repository and its history, environment variables only, and a pre-commit check. In the same review a defense record change was reverted (bars_when had been set to "route_deviation_described is not null" and the defense renamed; the ruled form is that a described deviation makes the defense indeterminate with a routine condition and fires only on deviation_personal_purpose_stated true), curb weight was added to the AUTO spec, and the completeness script was required to actually run because the baseline showed zero.

Review 3 on v3 (88 paths) accepted the guide for seeding as v4 with corrections: descriptions trimmed of engine behaviour, decisive_for record ids fixed, closed enums for admission, licence, trip purpose, employment relationship, disposition and coverage status (no unknown, underinsured added), array element shapes with party_ref, and eleven tool_observed rows given input map records. Conclusion-shaped fields are gone from the guide; a carrier states what happened, and the engine draws the conclusion under a cited record.

The carrier-facing data requirements document

The data requirements document for a profile is generated from records, not written: field paths, descriptions, tiers with a Needed-for column, the coverage vocabulary, sample payloads embedded as sections, a schema hash and front matter with a confidentiality line. A forbidden-term scan keeps corpus terms out of it, because theory names, defense names and record ids are corpus content and the carrier sees only the interface. Sample payloads carry a neutral claim id and "Format v1.0" .

The box test surfaced one blocking defect in the first AUTO sample: seven facts the Morales inputs table lists as not supplied were sent as not_stated. Sent that way, the waiver gate clears, the independent-contractor defense excludes and fleet negligence excludes instead of staying open, so the engine render cannot match the target brief. Fields not supplied are omitted, and a converter that emits not_stated from a not_returned seed field is a converter defect. The receipt for the shipped sample read 29 stated, 7 checked and not present, 23 not supplied, matching the inputs table.

Open items

The screener's comparative gate source path after a row retirement is still owed. Seeds A31 to A33 must carry signed no-fault expectations once the jurisdiction payload is loaded. Addendum A to the carrier (not_stated means reviewed and absent; unknown is left out) ships only after engine verification returns. Consolidation of subro summary facts against liability detail waits for the liability contract step.