Data Hydration Source Packs
TattooAPI hydrates real-world tattoo data through source packs first, then review, then canonical runtime promotion. The current rule is:- source data is evidence
- reviewed candidates are promotion inputs
- TattooAPI canonical tables are runtime truth
- raw exports do not rename ontology nouns
Current Inputs
Current Counts
The current checked-in hydration reports show:71,080first-party rows extracted63,209promotable directory rows28,894expected canonical studio profiles from directory sync3,996expected canonical artist profiles from directory sync5promoted creative canary candidates3managed-studio media connections scaffolded0media-source tokens stored in reports or git27HI/NV law-compliance canary rows in the current refresh candidate26CA/TX/NY/FL/WA law-compliance canary rows staged from official sources
Promotion Rules
Directory hydration is non-destructive:- non-empty incoming fields can improve canonical records
- blank incoming values must not erase existing canonical values
- every promoted record needs an
externalSourceReference - every promoted record needs a
canonicalPromotionLink
- tokens live only in local env aliases
- registry files store the alias name, not the token value
- published media records can promote only when studio and artist identities resolve
- drafts, unresolved artists, and missing rights/consent posture stay staging-only
- external acquisition nodes produce official-source records and run manifests
- ontology guidance can validate lane, noun, required field, and review-queue posture
- staging uploads write source-pack files only
- diff reports show new, changed, missing, and unchanged citation units
- missing rows are review warnings, not deletion instructions
- public legal advice and canonical runtime promotion remain disabled until operator approval gates exist
Operator Verification
Internal operators use repo-native inventory, preview, and verifier gates before any promotion. Public docs describe the contract and boundaries; internal command names, staging paths, provider identifiers, and token aliases stay out of the public surface.What Not To Do Yet
- Do not broad-scrape the market into canonical runtime tables.
- Do not promote media records when artist identity is unresolved.
- Do not expose media-source tokens through API responses, docs, reports, or runtime records.
- Do not activate public writes or public SEO pages from staged evidence.
- Do not treat law sync diffs as automatic legal updates.
- Do not let external scraping apps write directly to TattooAPI runtime.
project-context/ontology/governed-hydration-sprint.md.