E2 · Publication Volume 24

Data Contracts and Interoperability

schema versions, compatibility, validation and exports

Learning objectives

  • Explain why schema versions, compatibility, validation and exports require explicit semantic modelling.
  • Design identities, relations and constraints that preserve data contracts and interoperability across exchange.
  • Separate hard release gates from diagnostic metrics and interpretation choices.
  • Produce a versioned contract, compatibility matrix and independently verifiable conformance report from synthetic evidence.

The lesson is complete only when the learner can defend both the model and the release decision. A neat schema without evidence, tests or declared limitations is an unverified design. The assessed artefact must make assumptions visible and distinguish source assertions from derived conclusions.

Decision context

Define required fields, semantic identifiers, types, units, value states, relationships, constraints, error behaviour, version policy and service expectations. Classify changes by consumer impact. Compatibility is directional: a new producer with an old consumer may behave differently from an old producer with a new consumer.

Start with a decision record: name the intended use, the evidence required, the consequence of error, the accepted uncertainty and the role authorised to accept residual risk. Then ask whether the proposed model can answer the decision question without relying on filename conventions, row order, undocumented defaults or someone’s memory. This prevents technology selection from concealing a missing semantic requirement.

The same record may be fit for one use and unfit for another. A rapid exploratory view can tolerate conditions that a released exchange package cannot. Fitness is therefore stated against a use, contract version and quality gate rather than attached permanently to the data.

Core concept

A data contract is a versioned agreement about meaning, structure, quality and operational behaviour between producers and consumers. Interoperability is demonstrated when independent implementations exchange conforming data and preserve intended meaning, not when two systems merely open the same file.

The working scope is schema versions, compatibility, validation and exports. For each item in that scope, distinguish the thing itself, the label used by a source, the claim made about it and the record that carries the claim. Identity is not a display name; a value is not its unit; an observation is not a model; current is not the same as valid. These distinctions create explicit places for correction, uncertainty and competing interpretations.

A good semantic design can be explained as a set of sentences before it is encoded. Each sentence identifies a subject, a property or relationship, an object or result, and the context under which the claim holds. Physical tables and files are then projections of those sentences, not their source of meaning.

Semantic model

Keep a contract identifier and immutable versions. Each version contains logical schema, vocabulary dependencies, validation rules, examples, change log and compatibility declaration. Conformance reports identify contract version, validator version, test cases, failures and evaluated artefact fingerprint.

Test every proposed record against seven questions: What has identity? What type is it? Which property or relationship is asserted? Which spatial and temporal context applies? Which state or qualifier modifies the assertion? Which evidence supports it? Which version and activity produced the stored representation? Missing answers become explicit contract gaps.

Normalisation is used to separate independent facts, not to maximise the number of tables. A compact nested object can be semantically sound if the same identities, constraints and provenance remain explicit. Conversely, a highly normalised database can still be ambiguous when relationships and units exist only in documentation or application code.

Constraints and invariants

| Invariant | Executable or review test | | --- | --- | | Versions are explicit | Every payload or distribution identifies its contract version. | | Compatibility is tested directionally | Test supported producer–consumer version pairs. | | Semantic changes are classified | A familiar field name cannot hide changed meaning or unit. | | Validation failures are actionable | Report path, rule, observed value and expected condition. |

An invariant is a condition that must remain true across storage, export, correction and reprocessing. Implement it as close to the authoritative boundary as practical and repeat the check at exchange boundaries. Record rule identifier, version, severity, evaluated scope, observed value and outcome so a failure can be reproduced.

Hard gates protect identity, semantic validity, required provenance and authorised use. Diagnostic checks reveal unusual values or patterns but require interpretation. Never convert a diagnostic threshold into deletion or correction without a reviewed rule and preserved source evidence.

Quantitative reasoning

Use a compatibility matrix K_{ij} for producer version i and consumer version j, with states such as supported, supported with declared loss and unsupported. Conformance rate C = n_p / n_t summarises passed tests but must retain hard-gate failures and test coverage.

Every reported ratio states its numerator, denominator, exclusions and evaluation time. Stratify results by source, entity type, contract version or processing run where aggregation could hide a local failure. Counts accompany percentages so a seemingly large change based on a tiny denominator remains visible.

Precision is part of meaning. Do not add decimal places merely because a storage type permits them, and do not round identity, interval or coordinate fields without a declared tolerance and test. Quantitative summaries support a release decision; they do not replace semantic review.

Evidence and uncertainty

Interoperability evidence includes shared fixtures, boundary cases, invalid cases, round trips and independent consumer results. Example payloads are executable tests, not decorative documentation. Test semantic invariants after parsing, because schema validity alone may accept a wrong unit or relationship.

Build an evidence packet containing preserved source reference, acquisition or assertion context, applicable method, validation results, reviewer decision and links to derivatives. Classify uncertainty as observational, semantic, structural, parametric or policy-related where that distinction changes treatment. “Unknown” is a valid state when the evidence cannot justify a stronger claim.

Contradictory evidence remains available. The model may select one current assertion, but the reason, competing assertion and effective time are retained. This makes later reinterpretation possible without pretending the earlier evidence never existed.

Interfaces and storage

An export endpoint or job accepts a requested contract and format profile, then returns either a conforming package or a structured refusal. It must not silently downgrade. Include manifest, schema, vocabulary versions, validation report and content fingerprint with each released export.

Design an interface from the logical contract outward. Specify identifiers, types, cardinalities, units, value states, coordinate and time references, version negotiation, validation behaviour and structured errors before choosing a serialisation. The physical representation then declares its mapping to those logical elements.

Storage optimisation may partition, compress, index or cache data, but it must not change identity or silently remove context. A derived representation points to immutable inputs and a processing manifest. A cache carries freshness and contract-version information and is never treated as the only evidence copy.

Governance and access

A change process identifies affected producers and consumers, classifies compatibility, provides migration and records deprecation. Breaking versions may coexist during transition, but each remains explicit. Contract stewardship is assigned to roles and cannot depend on an unnamed person’s memory.

Governance is expressed through named roles, review states and versioned decisions, not through references to a particular organisation. Define who may propose, validate, approve, supersede and withdraw each governed resource. The audit trail records the role and event while avoiding unnecessary personal data.

Apply least-necessary access to source evidence and derivatives. Access controls must not erase identifiers, lineage or quality metadata needed to understand an authorised release. When policy is unresolved, quarantine the output with a precise reason and escalation route.

Integration checkpoint

Contract versions connect tested producers and consumers
Contract versions connect tested producers and consumers

The diagram summarises the control flow for this lesson. Read it from source evidence through semantic structure and validation to a decision-ready artefact. Each arrow should correspond to a declared relationship or transformation; each boundary should have a contract; each released node should have an identity, version and provenance pointer.

Integrate the lesson by adding a versioned contract, compatibility matrix and independently verifiable conformance report to the evolving synthetic data package. Verify that earlier artefacts still resolve and that the new model does not overwrite observations, identifiers, values or versions introduced in previous lessons. Record every changed assumption.

Synthetic worked example

A synthetic contract adds an optional confidence field, then changes a concentration unit in a later proposal. The learner classifies the first change as compatible for consumers that ignore unknown fields, but treats the unit change as breaking. Fixtures test four producer–consumer version pairs and the export refuses an unsupported pair.

Work the example in four passes:

  1. Preserve the received records and write the intended decision without correcting anything.
  2. Identify entities, claims, context, uncertainties and policy constraints; mark every unresolved item.
  3. Apply the versioned rules, create derivatives and record the exact transformation plus validation evidence.
  4. Issue an accept, reject or quarantine decision and show how an independent reviewer can reproduce it.

Because the example is entirely synthetic, its values demonstrate method only. The important result is the chain from received evidence to justified decision. If a required fact is absent, the worked solution records the gap rather than manufacturing a plausible value.

Practice task

Write two versions of a synthetic sample-result contract. Build valid, boundary and invalid fixtures; classify every change; populate a directional compatibility matrix; run validation and round trips; then produce a conformance report that a consumer can independently verify.

Use the following acceptance criteria:

  • All required identifiers and references resolve to declared types.
  • Every transformation preserves the received evidence and records its derivation.
  • Invalid, unknown and inapplicable states remain distinct and machine-testable.
  • The output identifies the contract, vocabulary and processing versions used.
  • A second reader can reproduce the validation result without private knowledge.

Submit the source snapshot, authored contract or model, validation output, derivative, manifest and a short decision record. A screenshot alone is insufficient because it cannot demonstrate the exact input, version or rule execution.

Common failure modes

  • A payload omits its contract version.
  • Compatibility is claimed from one successful happy-path file.
  • A changed unit keeps the same field name and version.
  • An exporter silently removes unsupported properties.

These failures share a pattern: convenient representation is mistaken for verified meaning. Diagnose the earliest boundary at which an assumption became implicit. Correct by restoring source evidence, making the assumption a versioned field or rule, rerunning dependent transformations and superseding—not overwriting—the affected release.

Do not repair a failure by adding an undocumented default. A blocked result with a specific missing dependency is safer and more reusable than a complete-looking result whose meaning cannot be reconstructed.

Review questions

  1. Why is compatibility directional?
  2. Which semantic changes are breaking?
  3. What makes an example payload an executable specification?
  4. How should an unsupported export request fail?

For each answer, identify the governing invariant, the evidence needed to evaluate it and the appropriate release behaviour when the invariant fails. A strong answer distinguishes scientific uncertainty from missing semantics and distinguishes a recoverable warning from a hard contract violation.

Sources and further reading