Architecture Decision Records
Architecture Decision Records (ADRs) capture significant architectural decisions made during the development of Trust Relay. Each ADR documents the context that motivated a decision, the decision itself, and its consequences -- both positive and negative.
ADRs are immutable once accepted. If a decision is superseded, the original ADR is marked as such and a new ADR is created.
ADR Registry
| ADR | Title | Status | Date |
|---|---|---|---|
| ADR-0001 | PydanticAI + AG-UI + CopilotKit as AI Layer | Accepted | 2026-02-20 |
| ADR-0002 | Temporal for Workflow Orchestration | Accepted | 2026-02-20 |
| ADR-0003 | AGUIAdapter on FastAPI (not standalone AGUIApp) | Accepted | 2026-02-20 |
| ADR-0004 | CopilotKit v1 API with v2 Migration Plan | Superseded by ADR-0013 | 2026-02-20 |
| ADR-0005 | STATE_SNAPSHOT over STATE_DELTA for Tier 1 | Accepted | 2026-02-20 |
| ADR-0006 | PEPPOL Verify as Synchronous REST API | Accepted | 2026-02-20 |
| ADR-0007 | Belgian Data Layer, Country Routing & PEPPOL UI | Implemented | 2026-02-23 |
| ADR-0008 | Raw SQL via SQLAlchemy text() for Database Access | Partially Superseded 2026-04-18 — ORM Repository pattern adopted for new code; existing text() usage retained as acceptable technical debt | 2026-02-24 |
| ADR-0009 | Minimal Error Handling with Silent Recovery for PoC | Accepted (PoC), Migration In Progress | 2026-02-24 |
| ADR-0010 | React useState/useEffect for Frontend State Management | Accepted (PoC) | 2026-02-24 |
| ADR-0011 | Authentication Deliberately Deferred for PoC | Superseded 2026-04-18 — Keycloak OIDC implemented | 2026-02-24 |
| ADR-0012 | Hybrid Scraping Tool Selection per Data Source | Accepted | 2026-02-24 |
| ADR-0013 | CopilotKit v2 Migration | Accepted | 2026-02-28 |
| ADR-0014 | Native Bi-Temporal Graph (Drop Graphiti) | Accepted | 2026-03-02 |
| ADR-0015 | Session-Based Investigation Diagnostics | Accepted | 2026-03-08 |
| ADR-0016 | Shared Regulatory Corpus Without Tenant RLS | Accepted | 2026-03-17 |
| ADR-0017 | Trust Capsule Cryptographic Architecture | Accepted | 2026-03-19 |
| ADR-0018 | Dynamic Document Requirements — Pre-Investigation Resolution | Accepted | 2026-04-02 |
| ADR-0019 | Multi-Agent OSINT Pipeline with Country Routing | Accepted | 2026-02-20 (date decision was originally made) |
| ADR-0020 | EBA Risk Matrix with Weighted-Max Aggregation | Accepted | 2026-03-31 (date decision was originally made) |
| ADR-0021 | Evidence Bundle System for EU AI Act Chain-of-Thought Capture | Accepted | 2026-03-06 (date decision was originally made) |
| ADR-0022 | Neo4j Knowledge Graph with Sequential ETL Pipeline | Accepted | 2026-02-25 (date decision was originally made) |
| ADR-0023 | PostgreSQL Row-Level Security for Multi-Tenant Isolation | Accepted | 2026-03-08 (date decision was originally made) |
| ADR-0024 | Entity Matching with Blocking Keys and Trust-Weighted Survivorship | Accepted | 2026-03-31 (date decision was originally made) |
| ADR-0025 | Network Intelligence Hub with ReactFlow Three-Perspective Visualization | Accepted | 2026-03-30 (date decision was originally made) |
| ADR-0026 | Prompt Centralization with DB-First Registry and Filesystem Fallback | Accepted | 2026-03-17 (date decision was originally made) |
| ADR-0027 | GoAML Export with Three-Layer Pipeline and Country Profiles | Accepted | 2026-03-21 (date decision was originally made) |
| ADR-0028 | White-Label Branding with Logo Palette Extraction and WCAG AA Enforcement | Accepted | 2026-03-08 (date decision was originally made) |
| ADR-0029 | Cost-Optimized Model Tiers for Agent Fleet | Accepted | 2026-03-31 (date decision was originally made) |
| ADR-0030 | Social Intelligence via BrightData MCP Expansion | Accepted | 2026-04-05 |
| ADR-0031 | Regulatory Segment Profiles with Declarative YAML Compiler | Accepted | 2026-04-06 |
| ADR-0032 | Circuit Breakers for OSINT Pipeline Resilience | Accepted | 2026-04-06 |
| ADR-0033 | Document Gap Analysis Engine | Accepted | 2026-04-06 |
| ADR-0034 | Multi-Country Registry Architecture | Accepted | 2026-04-06 |
| ADR-0035 | Atlas Reference Documentation within Trust Relay Docusaurus | Accepted | 2026-04-06 |
| ADR-0036 | PII Classification with Hybrid Annotations and Generated Manifest | Accepted | 2026-04-07 |
| ADR-0037 | Shared Python Packages for Atlas Integration | Accepted | 2026-04-11 |
| ADR-0038 | Shell Company Detection via Establishment Address Comparison | Accepted | 2026-04-14 |
| ADR-0039 | Resilience Rollout Completion + KBC Acquiring Gap Signals | Accepted | 2026-04-14 |
| ADR-0040 | Observability Metrics + Breaker State Persistence | Accepted | 2026-04-14 |
| ADR-0041 | Pure-Mailbox Detection for Shell Companies Without Operational Footprint | Accepted | 2026-04-17 |
| ADR-0042 | Czech Regulatory + Professional Registry Coverage | Accepted | 2026-04-17 |
| ADR-0043 | Cross-Country Registry Parity — Decoders, Director Shapes, and the KBO Packed-Layout Bug | Accepted | 2026-04-17 |
| ADR-0044 | (Withdrawn during review — number reserved, never reused) | Withdrawn | — |
| ADR-0045 | Sanctions False-Positive Suppression — Evidence-Based, Tenant-Scoped, Always Visible | Accepted (implemented 2026-04-22) | 2026-04-18 |
| ADR-0046 | NBB CBSO CSV endpoint degradation and honest data-gap surfacing | Accepted | 2026-04-22 |
| ADR-0047 | Async Docling extraction (Option B) | Accepted | 2026-04-23 |
| ADR-0048 | Financial Analysis Agent | Accepted | 2026-04-22 |
| ADR-0049 | Cross-reference registration-number identity-mismatch detection | Accepted | 2026-04-22 |
| ADR-0050 | Enforce RLS by running the app as a non-superuser role | Accepted | 2026-06-12 |
| ADR-0051 | Tenant-scoped session selection for RLS-enforced access | Accepted | 2026-06-13 |
| ADR-0052 | Dashboard Age filter defaults to "Any", not "Today" | Accepted | 2026-06-15 |
| ADR-0053 | UBO ownership computation engine (multi-path summation) | Accepted | 2026-06-15 |
| ADR-0054 | UBO via control — ControlEdge dimension (binary reachability) | Accepted | 2026-06-15 |
| ADR-0055 | UBO Senior Managing Official (SMO) fallback | Accepted | 2026-06-15 |
| ADR-0056 | 1-to-many person/UBO verification model | Accepted | 2026-06-15 |
| ADR-0057 | Min-2-independent-source verification gate (gate, not score) | Accepted | 2026-06-15 |
| ADR-0058 | Central register is cross-check only (require ≥1 non-central source) | Accepted | 2026-06-15 |
| ADR-0059 | Block approval on open UBO discrepancy + discrepancy SAR lifecycle | Accepted | 2026-06-15 |
| ADR-0060 | NaturalPerson AMLR fields — plural nationality, PEP classification/RCA, place_of_birth | Accepted | 2026-06-16 |
| ADR-0061 | Role-based LegalArrangement model + separate UBO determination path | Accepted | 2026-06-16 |
| ADR-0062 | Typed SubjectEntity + PurposeProfile models | Accepted | 2026-06-16 |
| ADR-0063 | Typed persisted ScreeningResult (ongoing-monitoring evidence trail) | Accepted | 2026-06-16 |
| ADR-0064 | DB-enforced audit_events immutability (retention-first) | Accepted | 2026-06-16 |
| ADR-0065 | Dissolved-entity onboarding block-by-default (audited override) | Accepted | 2026-06-16 |
| ADR-0066 | Live risk-paced UBO re-screening + general-population monitoring | Accepted | 2026-06-16 |
| ADR-0067 | Fail-Closed Compliance Outputs & the "Not Assessed" Contract | Accepted | 2026-06-26 |
| ADR-0068 | Country-Capability Registry & Honest "Not Assessed for X" | Accepted | 2026-06-26 |
| ADR-0069 | Regulator-Ready Case-Pack Export & Retention | Accepted | 2026-06-26 |
| ADR-0070 | Maker-checker / four-eyes control for high-risk decisions | Accepted | 2026-06-26 |
| ADR-0071 | SAR/STR lifecycle + tipping-off controls | Accepted | 2026-06-26 |
| ADR-0072 | EU AI Act conformity record (system-level, data-driven, honest) | Accepted | 2026-06-26 |
| ADR-0073 | Round-2 entity-resolution & signal hardening (name-collision guard, vertical/licence consistency, financials-ingestion gap, payment-account-outside-licence) | Accepted | 2026-06-27 |
| ADR-0074 | Role-based access control (RBAC) enforcement, phased (log-first) | Accepted | 2026-06-27 |
| ADR-0075 | Document-content adverse analysis (uploaded documents can RAISE risk) | Accepted | 2026-06-28 |
| ADR-0076 | SSO federation (per-tenant IdP brokering on Keycloak) | Proposed (design only — NOT implemented) | 2026-06-28 |
| ADR-0077 | Multi-provider adverse-media retrieval with native-language recall | Accepted | 2026-06-28 |
| ADR-0078 | Alias / brand / group expansion of the screened entity set | Accepted | 2026-06-28 |
| ADR-0079 | Estonian company financials via RIK e-Äriregister open data | Accepted | 2026-06-28 |
| ADR-0080 | Signal.FINANCIAL_STATEMENTS jurisdiction-gated capability | Accepted | 2026-06-28 |
| ADR-0081 | Super-admin tenant impersonation over SSE via validated query parameter | Accepted | 2026-06-30 |
| ADR-0082 | Post-validation calibration & integrity hardening (OB Holding adversarial run) | Accepted | 2026-06-30 |
The Docusaurus sidebar auto-includes every generated ADR page; this table is the hand-maintained landing index. Titles/status/date mirror the canonical
docs/adr/register (regenerated 2026-07-02). ADR-0044 was withdrawn during review — the number is reserved and never reused.
ADR Template
New ADRs follow this structure:
# ADR-NNNN: Title
**Date**: YYYY-MM-DD
**Status**: Proposed | Accepted | Implemented | Superseded by ADR-XXXX
**Deciders**: Names
## Context
Why this decision is needed.
## Decision
What was decided.
## Consequences
### Positive
### Negative
### Neutral
## Alternatives Considered