ADR-0083: The TD Dossier — a Versioned, Cross-Scope, Regulatory-Structured Deliverable¶
- Status: accepted (Nicolas 2026-07-19 — all seven recommendations of
docs/ai/td-dossier-options.mdconfirmed as D-1..D-7; that paper is this ADR's decision basis and evidence record). - Date: 2026-07-19
- Deciders: Nicolas Burri, design by Claude.
- Builds on: ADR-0074 (PDF render path — the only render surface), ADR-0075 (claims record /
version continuity), ADR-0021/0049 (version-precise pins, coverage-style completeness),
ADR-0060 §5 (audit pack), the suspect pattern (ADR-0077 stage 2 / ADR-0081 family),
docs/planning/deliverable-structures.md(D-A),docs/planning/traceability-model.md§5 (the baseline property this realizes). - Refined by: ADR-0104 (the on-the-fly render for ISSUED dossiers is superseded — an issued dossier is a persisted artifact of record, its stored bytes and stable hash are its identity, plain delete is forbidden, and re-issue clones to a new draft)
Context¶
Auditors and notified bodies receive a curated, version-pinned, regulatory-structured PDF set — not a live database (options paper §4: Matrix, Greenlight, IMDRF practice). The scope audit pack ("everything in this scope, now") is nearly free but does not answer "the technical file for device X". The dossier is that answer: chosen versions, arranged under a regulatory skeleton, frozen as an issued baseline. The motivating cross-scope case is live in the data: PULSEMED documents cite governing MeridianQMS procedures.
Decisions (D-1..D-7, all as recommended)¶
- D-1 — Build the dossier (3a); ship the scope audit pack first (~0.5 slice, ADR-0060 §5 packaging over ADR-0074 PDFs + manifest). The dossier realizes the traceability model's baseline/snapshot property.
- D-2 — Pins are DOCUMENT VERSIONS, modeled as an extensible content-reference:
SectionPin { kind: DOCUMENT; documentId, versionId }with the seam for futureITEM/ITEM_GLOBkinds. Note recorded at acceptance: the requirement-item substrate now EXISTS (ADR-0077/-0078/-0079), so the seam is cheap to open later — but the deliverable NBs receive is document-level, and item-level trace is already served by the traceability views. Full-ALM (option iii) stays out. - D-3 — Skeletons at ship: MDR Annex II, IEC 62304 software file, custom. Fixed catalog
templates authored from the
norms/texts (paraphrased per ADR-0061 D-5); 62304 Class B/C mandatory-slot toggles are template attributes, not code. IMDRF nIVD deferred until a submission customer appears. The Annex II §4 GSPR slot can later feed from Stage Cregulatory-refitems without remodeling. - D-4 — Export shape: BOTH — one merged PDF (cover + ToC + sections, the reviewer's copy)
AND a zip of per-document PDFs with a hash MANIFEST always (the evidence-grade, verifiable
bundle). Single render path: ADR-0074's markdown→FO→FOP over N pinned versions; same footer
band, same
EXPORTEDaudit, same honest degradations. - D-5 — The suspect flag ships with 3a: a DRAFT dossier section whose pinned version has been superseded shows a live read-time verdict (pinned version-id vs the document's current effective version-id — one query, no stored state). The audited re-pin action and re-issue as a new dossier version (ADR-0075 continuity) are slice 3b. An ISSUED dossier is immutable; advancing is always a new dossier version.
- D-6 — Folder convention packs (D-B) remain authoring organization; the dossier is the issued deliverable. The folder tree must never pretend to be a dossier.
- D-7 — This ADR is that required record; the dossier entity (name, skeleton, sections with clause refs, filled-by hints, per-section notes, pinned content, DRAFT→ISSUED lifecycle) is a new first-class object; cross-scope pinning is RLS-governed (you pin only what you can see, ADR-0021 rule); completeness ("every mandatory slot has ≥1 released pin") is the coverage-rule-style live evaluator pointed at skeleton slots.
Non-goals¶
Item/glob pins (seam only, D-2); any second render surface (ADR-0074 is the path); folder-pack conflation (D-6); IMDRF skeleton (deferred); item-level trace inside the dossier (lives in the traceability workspace).
Consequences¶
- Effort: 3a + the suspect flag ≈ 3–4 slices; 3b ≈ 1 slice. Sequencing: after the risk-table work and the expert/colleague conversations by default — pulled earlier only if a demo needs an issued dossier.
- Activates the traceability model's Stage D baseline thread; the change-impact/orphan surfaces remain separate Stage D work.
- The dossier entity, sections and pins are control/content-plane modeling decisions for the implementing wave to place per ADR-0027's boundary (pins reference cross-scope content — the read path must degrade per the inert-reference pattern, never leak).
Realization note (3a, 2026-08-04/05)¶
- Gate: a dedicated
MANAGE_DOSSIERSpermission (this ADR left the gate open). Confirmed by Nicolas 2026-08-05 ("I'd also keep the dedicated permission"). One write authority for every dossier act (create/edit/section/pin/issue/delete) per the ADR-0097 one-permission posture; deliberately NOT reusedCONFIGURE_REVIEW_POLICY— issuing a submission baseline and rewriting review policies are separately grantable. Reads gated by VIEW + RLS. Narrow backfill overCONFIGURE_REVIEW_POLICYholders + bootstrap + seed parity. - Nav (open for Nicolas): "Dossiers" shipped as a 7th top-level nav word (both languages), a first-class deliverable per D-6. It pushes the toolbar collapse ceiling past 1280 (EN 1280 / DE 1440 now collapse into the overflow menu — inherent: 7 words cannot fit 1280 at any label length), re-measured per the 2026-07-29 collapse-when-can't-fit policy. Reversible levers if rejected: a documents-area door, or dropping another top-level word.
- 3a scope realized; deferred to 3b/later: re-pin + re-issue-as-new-version (schema admits it, no 3a path writes a 2nd version), ITEM/ITEM_GLOB pin kinds (CHECK seam only), pin reorder as a dedicated act, the IMDRF nIVD skeleton, per-dossier 62304 safety-class selector.
Clarification 2026-08-05 — a DRAFT dossier DOES export the merged PDF, watermarked¶
3a implemented "only an ISSUED dossier exports" for both bundles. Nicolas's first hands-on
(register feedback-2026-08-05-dossier.md #2) asked for the draft PDF: a curator has to read the
assembly as a reviewer will, and being unable to until they issue inverts the point of a draft.
Amended as follows — the refusal is split by bundle, not lifted:
- The merged PDF exports a DRAFT. It is regenerated on the fly, carries no hash, states on
its cover that it is an uncontrolled review copy and not the record, is named
…_draft_….pdf, and is stampedDRAFTdiagonally across every page. ItsEXPORTEDaudit event carriesdossierState: DRAFTbeside the artifactformat. - The zip stays ISSUED-only. It is the evidence-grade bundle: per-version PDFs with a SHA-256 manifest. A verifiable claim over contents that can still change is a false claim, and no watermark fixes that — the original D-4 reasoning applies to this bundle unchanged.
- The draft copy renders the work-in-progress honestly, deliberately unsoftened: unfilled mandatory slots keep their section cards, superseded and unreachable pins keep their notices, and the cover keeps its incompleteness counts. The same renderers as the issued copy.
- The invariant that replaces the refusal: watermark present ⟺ NOT the record. An issued
dossier's PDF is unwatermarked — today still rendered on the fly, and under ADR-0104 it becomes the
bytes stored at issue; either way the ABSENCE of the mark is what identifies the artifact of record.
The watermark mechanism is a parameterized, non-dossier-specific facility of the ADR-0074 renderer
(
PdfRenderer), so any future not-the-record rendering marks itself the same way.
The original reasoning ("a controlled-looking technical file whose contents can still change") was right about the RISK and wrong about the remedy: the risk is a draft copy circulating as if it were the deliverable, and a copy that says DRAFT on every page cannot. Refusing the render also had a cost the ADR did not weigh — it pushed a curator toward issuing a dossier merely to read it, which manufactures exactly the junk issued baselines that ADR-0104 §3 then forbids deleting.