feat(destinations): marts, with R3 masking applied at the boundary

Disadvantaged and other-pupils partition the whole and the all-pupils
figure is published, so publishing both halves recovers the suppressed
one. The mask is applied in the mart rather than the API so no consumer
added later can reach an unmasked combination.

The R1 test is a warn, not an error: DfE publishes the recoverable
combination and the mart's job is to carry it faithfully. Refusing to
close the gap is the API's job and the frontend's.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BvdDKvFFSZuMVDH5fEyTob
This commit is contained in:
TudorandClaude Opus 5 committed 2026-08-28 16:08:20 +01:00
1 parent c564566432
commit 5e5b61987a
7 files changed
+267

No files matched your search

@@ -0,0 +1,15 @@
-- pupils must be null wherever status is not 'published', and never null where
-- it is. This is what stops a later coalesce, or a wide-format refactor,
-- turning a withheld figure into a zero — which would read on the page as
-- "no pupils went here" rather than "we are not told".
select
urn,
year,
pupil_group,
destination_measure,
status,
pupils
from {{ ref('fact_ks4_destinations') }}
where (status <> 'published' and pupils is not null)
or (status = 'published' and pupils is null)
@@ -0,0 +1,20 @@
-- R3 GUARD. Fails if a category is suppressed for disadvantaged pupils but
-- still published for the other-pupils group.
--
-- The two groups partition the cohort and the all-pupils figure is published,
-- so publishing both halves recovers the withheld one. fact_ks4_destinations
-- masks the other group to prevent it; this asserts the masking actually held.
select
d.urn,
d.year,
d.destination_measure
from {{ ref('fact_ks4_destinations') }} d
inner join {{ ref('fact_ks4_destinations') }} o
on o.urn = d.urn
and o.year = d.year
and o.destination_measure = d.destination_measure
and o.pupil_group = 'other'
where d.pupil_group = 'disadvantaged'
and d.status = 'suppressed'
and o.status = 'published'
@@ -0,0 +1,24 @@
{{ config(severity='warn') }}
-- R1 TRIPWIRE. Flags a school/year/pupil group that has exactly one suppressed
-- category while its cohort total is published — the combination that lets the
-- withheld figure be recovered by subtracting the published categories.
--
-- This is a WARN, not an error, and the distinction matters. The mart is not
-- wrong: DfE publishes exactly this, and the mart's job is to carry the source
-- faithfully. What must refuse to close the gap is everything downstream — the
-- API serialiser and lib/destinations.ts, which have their own tests. This
-- query exists so the condition stays visible and counted, and so anyone
-- adding a consumer later has to look at it rather than discover it.
--
-- Expect a non-trivial count: measured at 22% of mainstream secondaries.
select
urn,
year,
pupil_group,
count(*) filter (where status = 'suppressed') as suppressed_categories
from {{ ref('fact_ks4_destinations') }}
where destination_measure not like 'agg\_%' escape '\'
group by urn, year, pupil_group
having count(*) filter (where status = 'suppressed') = 1