Data flow
The community surface is a thin read-side over snapshots produced by the Trace Commons server. The pipeline:
- Contributor's local Ironclaw redacts a trace and queues it.
- Ironclaw uploads the redacted envelope to the hosted ingest API.
- Server applies the novelty / perplexity / tail-fraction gate.
- Accepted submissions enter the corpus and the credit ledger.
- A snapshot worker computes leaderboard rows + corpus aggregates on a schedule, applying the deployment's configured release guards.
- This site renders against the latest snapshot.
Consent scopes
The contributor's standing policy carries a consent_scope that
determines which uses the envelope contents permit:
debugging_evaluation(default): debugging, evaluation, aggregate analytics.benchmark_only: evaluation, benchmark generation, aggregate analytics.ranking_training: + ranker training.model_training: + training-data inclusion.public_attribution: separate, profile-management consent that links the contributor's pseudonym to a public handle. Does NOT grant any trace-content uses on its own.
Aggregation guards
The snapshot worker honours these operator-tunable guards:
TRACE_COMMONS_ANALYTICS_MIN_CELL_COUNT— a leaderboard row is suppressed if the contributor's window count is below this threshold. Publication is refused outright unless this is at least 2.TRACE_COMMONS_COMMUNITY_TENANT_IDS— the tenants aggregated into the community surface. Under the stricter publication basis, publication is refused unless at least two tenants are in the cohort, so a "community" figure is never one tenant's corpus under another name. This deployment publishes under cell suppression, which waives that check; see below.TRACE_COMMONS_COMMUNITY_ANALYTICS_PUBLICATION_BASIS— what published aggregates rest on: an approved noise mechanism, or cell suppression alone. Each published snapshot records which basis produced it.TRACE_COMMONS_ANALYTICS_BROAD_RELEASE_NOISE— when enabled, applies keyed bounded jitter to aggregate counts. See the note below.TRACE_COMMONS_ANALYTICS_BROAD_RELEASE_PRIVACY_ACCOUNTING— budget tracking across snapshots.
What the noise setting does not guarantee
An earlier version of this page described the broad-release noise setting as Laplace noise. That was inaccurate and we have corrected it.
What the implementation actually does is derive a bounded signed offset from a keyed hash and add it to the count. It is deterministic for a given input, the derivation includes the exact count being perturbed, and the epsilon figure tracked by the accounting setting is not calibrated against a sensitivity analysis. It is a reasonable obfuscation measure. It is not a differentially private mechanism and it carries no formal privacy guarantee, so it should not be relied on as one.
What protects the corpus analytics on this deployment
The server records what each published set of aggregates rests on, and this deployment publishes them under cell suppression alone. No noise is applied to them. We would rather say that plainly than imply a guarantee we are not providing.
What that does protect:
- Any novelty bucket or gate outcome holding fewer records than the minimum-cell threshold is dropped before publication. A dropped cell is indistinguishable from an empty one, so its absence does not reveal how few records it held.
- Only contributors who chose public attribution are ever named. The aggregates carry no handles.
What it does not protect:
- The totals are exact. Total submissions, accepted, rejected and the acceptance rate are published as computed. They are not cells, so cell suppression does not cover them.
- While the contributor base is small, an exact total is close to a statement about the handful of people who produced it. This is a real limitation of publishing at pilot scale, not a theoretical one.
- There is no formal privacy guarantee attached to these figures, and no epsilon is charged, because no calibrated mechanism is in force.
A calibrated mechanism is intended as the contributor base grows, at which point the published aggregates will record that basis instead. The minimum-cell threshold applies either way and is never waived.
Source-of-truth links
- Envelope contract: trace-commons.md
- Storage contract: trace-commons-storage.md
- Leaderboard design: community-analytics-leaderboard-design.md
- Frontend design: community-frontend-design.md