Enrolled record sets. Separation health — computed from each catalog's own scans at enrollment — predicts its accuracy regime before any match is run.
Drop each stone's polish scans (.dpt / .csv / .txt, any wavenumber grid, or one .zip). Stone IDs come from filenames: <stone>-<scan>.dpt. At least 2 scans per stone; 5 recommended.
Open batch is the default: any stone may be foreign, and one global assignment resolves the batch — two stones can never claim the same record.
One click reruns our validation on YOUR stones: each stone's last enrollment scan is held out as a returning query, and a chosen fraction of stones are removed from the records entirely — their queries are foreign by construction. No uploads needed.
Validated on production data (18 disjoint 100-stone catalogs, multi-scan records and queries, thresholds self-calibrated per catalog):
| mode | metric | measured |
|---|---|---|
| sealed batch | identity mapping | 100.0000% (1,800/1,800) |
| open batch (α=0.01) | foreign/stranger detection | 100% (630/630) |
| open batch | wrong name to a genuine stone | 0.00–0.07% |
| open batch | genuine auto-confirmed | 93–94% (rest → review) |
| per-stone | Top-1 / Top-3 | 99.1–99.6% / 99.94% |
NO_MATCH is a review flag, not a foreign verdict. For a genuine member the true record appears in its top-3 ≈ 99.9% of the time — review the candidates.
Separation health (shown at enrollment) predicts the regime: CLEAN → headline rates; TIGHT (e.g. a stone population far from the encoder's training corpus) → the security promises hold but more stones route to review. First fix: more scans per stone.
Known limits: an absent sibling (same rough) of a catalog stone is the hardest impostor (~90% rejection stand-alone); keep sibling sets enrolled together. Scans should follow the enrollment protocol; multi-year instrument drift is outside the validated envelope — re-enroll periodically.
To verify on your data: enroll with scans held out, present them later as a batch with known truth (including FOREIGN stones), and compare the scorecard — the full protocol is in VERIFICATION.md.