Governance
Every field, classified.
Two labels on every column of every contract: how much depends on it, and who may see it. Together they decide what a change costs and what may cross.
Criticality: what breaks if it changes.
Critical
Keys and the measures products are built on: dates, trip and stop identifiers, actual times, boardings. A change breaks every downstream join. New contract version, conformance tests fail until adapters update, notice period.
Important
Measures and attributes that shape results but not joins: capacities, fare amounts, direction, derived durations. Minor version; consumers are notified; nothing stops.
Informational
Display names, variant letters, vendor labels. Logged, never blocking. Vendor labels such as a KPI flag are never shared as-is, since thresholds differ by agency.
Sensitivity: who may see it.
Public
Already published: GTFS, GBFS. Served on open APIs.
Internal
Operational measures with no person behind them. Shared under agreement, bound to a purpose.
Restricted
Anything that can point to a rider: card serials, fare classes that reveal a concession. Never crosses raw. Aggregated above a minimum group size, pseudonymised, or used only inside a clean room.
Impact analysis follows from the labels. Each regional product lists the critical fields it depends on; each field lists the products that depend on it. A proposed change is scored by the products it touches before anyone writes code. The field tables apply this to the four sample datasets.
This is where schema drift is handled: in governance and contract versions, not by a system that tries to survive every surprise.