Sentinel Signal

Sentinel Policy — Source Rights Matrix

Source: docs/sentinel-policy-m0-source-rights-matrix.md

Document Content

Sentinel Policy — Source Rights Matrix

Living document (spec §4/§26: sources are re-reviewed as terms/licenses change, not versioned per deploy). Renders the sources table's rights fields (added by migration 0008_m0_rights) plus reasoning that doesn't fit in a DB column. Source of truth for the data is the sources table itself (GET /v1/sources, admin-token-gated); this document is the human-readable rendering plus citations, per spec §37's "choose one authoritative machine-readable representation and derive human-readable output where practical."

Per M0's core principle: public accessibility is never treated as commercial redistribution authorization. Every source below defaults to DISCOVERED (fail-closed) unless a human has explicitly reviewed and approved it — no source in this table is currently COMMERCIAL_APPROVED.

| source_id | authority_rank | commercial state | terms/reference URL | notes | |---|---|---|---|---| | cms-medicare-ncd | AUTH_A (CMS is the canonical issuing authority for its own NCDs) | DISCOVERED | https://api.coverage.cms.gov/ | Real production source, cms_coverage_ncd adapter. Uses only the CMS Coverage API's open endpoints (/v1/reports/national-coverage-ncd/, /v1/reports/whats-new/national/, /v1/data/ncd/) — the AMA/ADA/AHA license-token-gated endpoints are deliberately not implemented (M2 decision, unchanged by M0). No structured CPT/CDT/UB-04 content has ever been fetched through this source (confirmed live, see the M0 report's audit section). | | cms-medicare-ncd-eval | AUTH_A | DISCOVERED | https://api.coverage.cms.gov/ | M7's isolated golden-evaluation copy of the same source, same adapter, same open-endpoints-only scope. Never contributes to any commercial-facing surface; exists solely for the offline eval harness. | | s3-verify-test | — (not applicable) | INTERNAL_ONLY | — | Harmless M1 storage-proof artifact (confirms S3 object storage works), not a real content source. INTERNAL_ONLY explicitly removes it from any future commercial-review consideration rather than leaving it DISCOVERED alongside real sources. |

Robots.txt vs. terms/license (spec §16)

Neither real source's ingestion path has been checked against a robots.txt — CMS's Coverage API is consumed as a documented REST API, not crawled, so robots.txt (which governs crawler access to web pages) is not the relevant access-control surface here; the API's own published terms are. robots_url is left null for both sources rather than populated with an irrelevant robots.txt reference.

What "approving" a source actually requires

Flipping terms_review_state to COMMERCIAL_APPROVED is a distinct, explicit action from anything in M0's engineering scope — the M0 report documents that this was deliberately not done as part of this work (confirmed with the product owner 2026-08-20). Approving a source is the real "we have decided this content class may be commercially distributed" decision and should happen only after the counsel review in spec §34, informed by this matrix and the code-system rights matrix (sentinel-policy-m0-code-system-rights-matrix.md).