Skip to content
Ritesh FirodiyaGet in touch

Work / Chitragupt / Wiki / Decisions

2026-07-17-identity-creation-is-upload-only

Decisioncanonicalverified 2026-07-17

DECISION.2026-07-17.IDENTITY-CREATION-IS-UPLOAD-ONLY

Identity creation is upload-only

Decision

Non-self identities (banks, employers, brokers, mf_amcs, loans, insurers, health conditions, assets, retirement instruments, business entities, identity documents) are minted only by the parser via ensureAcceptedIdentity during document ingestion. The Self identity is the sole hand-editable identity. Settings › People & accounts is a read-only + delete-only surface for non-self identities — no "+ Add …" or per-row "Edit" affordance ships.

Why

The upload-only and no-manual-entry invariants say the parser is the only writer of facts. Identities are the anchor every fact hangs off — a user-entered identity that no document backs would let phantom rows appear in every downstream rollup that groups by identity (Tax review, Portfolio NAV, §80D reconciliation, Inbox folder L2). That gives a second unaudited entry surface and breaks the guarantee that "every number on screen traces back to an uploaded document."

The prior stub in apps/website/src/components/settings/identities/IdentityBucketSection.tsx rendered "+ Add" and row "Edit" as disabled placeholders. That advertised a feature that must never ship. This ADR names the invariant so we stop building toward it.

Self stays editable because it holds the login owner's own PAN/DOB/name/residential_status — no document originates those; the user supplies them in Profile.

Impact

  • apps/functions/src/profile/upsert-identity.ts: upsertIdentity remains the writer only for the Self identity + parser-invoked flows (via ensureAcceptedIdentity). deleteIdentity now guards against deleting an identity with linked documents (.count() precondition — otherwise every doc's identity_id FK dangles).
  • apps/website/src/components/settings/identities/IdentityBucketSection.tsx: the disabled + Add header button and disabled row Edit button are removed. Only Delete remains per row. SelfIdentityCard.tsx is unchanged.
  • .context/designs/web/settings/identities.html: the 11 header + Add … buttons and 7 row Edit / Restore buttons are removed; Self card Edit preserved.
  • user-identity-entry: gains an addendum stating identity creation is upload-only and Self is the sole writable identity.
  • Not in scope for this ADR: archive/restore of stale identities (parser stops seeing an identifier for N months), "move to bucket" for mis-typed Other identities, or per-identity document-count on cards. Those are follow-on work.

Status

Active

Sources

Every project of mine is written down like this.

Read the résumé