Schema contracts
Each dataset declares its schema and the assertions it must satisfy. A producer cannot publish a breaking change; a consumer can see which contract version a figure was computed under.
When the warehouse, the BI tool, and the notebook each compute a metric their own way, nobody owns the join and every quarterly number starts a thread. On Genedata there is one committed record, and contracts, lineage, trust scoring, and audit all wrap that record — so any figure on any surface resolves back to where it came from.
Each dataset declares its schema and the assertions it must satisfy. A producer cannot publish a breaking change; a consumer can see which contract version a figure was computed under.
Every field traces through every transform to its sources. Click a number on a dashboard and GeneCatalog shows the tables, the steps, and the run that produced it.
Each dataset carries a score from its contract pass rate, freshness against its SLA, lineage completeness, and ownership. It is visible wherever the data is used, including inside an agent answer.
The record at the core is written once by the engine. Contracts say what it must look like, lineage says where it came from, the trust score says how far to rely on it, and the audit log says who touched it. Every surface — SQL, dashboard, agent — reads through the same rings.
The score travels with the dataset into SQL results, dashboards, and agent answers. A drop is a signal before anyone disputes a figure: a failed contract, a missed freshness window, or a lineage gap lowers it the same day. The gauge here is an illustrative example, not a live reading.
Integrity is not a separate product bolted onto the warehouse. The contract is checked by the engine, the lineage is emitted by the engine, the score is computed from both, and the audit log records all of it — because it is one system.
What analysts and data owners ask before they stop keeping a spreadsheet of which number is right.
The contract check on the pipeline edge catches it. An additive change — a new nullable column — propagates and is recorded in lineage. A breaking change stops the run at that step and opens a review listing every downstream dataset, dashboard, and agent that would be affected. Nothing is published until someone decides.
From four inputs the platform already measures: the share of recent runs that passed their contracts, freshness against the dataset's declared SLA, whether lineage is complete back to a source, and whether the dataset has a named owner. The weights are visible in the catalog, and the score on this page is illustrative.
Yes. Lineage is column-level, so a metric on a dashboard resolves to the transform that computed it, the tables it read, the contract version they satisfied, and the run ID. From the run you can open the committed records that fed it, subject to your row-level access.
It does. Cortex AI answers against governed tables, and each figure in an answer links to the dataset and trust score it came from. A low-trust source is flagged in the answer rather than silently blended in.
The reliability proof shows how anomalies are caught on the pipeline and routine failures heal without a page.