How Contains Social Security Number Checks Work
Definition
Asserts that every value in the selected field contains a social security number.
Overview
The Contains Social Security Number rule scans the text of a single field and requires that each value contains a social security number. The match is a containment test, not an equality test: the value passes as soon as a social security number appears anywhere inside it, so surrounding text does not cause a failure. The pattern accepts the usual grouped-digits shape, with or without separators, found anywhere inside the value.
Typical use cases:
- Confirm that a tax identifier column really holds an identifier.
- Detect badge numbers or placeholders that would break a payroll or compliance filing.
- Audit a legacy column while identifiers are migrated into a dedicated field.
Field Scope
Single: The rule evaluates exactly one field per check.
Accepted Types
| Type | Supported |
|---|---|
String |
|
Array |
On an array field every element is tested and the row fails as soon as one element does not contain the pattern. That evaluation runs as a field-level check, so it reports a Shape Anomaly for the field instead of per-row Record Anomalies, whatever the coverage is set to.
General Properties
| Name | Supported |
|---|---|
Filter Allows the targeting of specific data based on conditions |
|
Coverage Customization Allows adjusting the percentage of records that must meet the rule's conditions |
The filter allows you to define a subset of data upon which the rule will operate.
It requires a valid Spark SQL expression that determines the criteria rows in the DataFrame should meet. This means the expression specifies which rows the DataFrame should include based on those criteria. Since it's applied directly to the Spark DataFrame, traditional SQL constructs like WHERE clauses are not supported.
Examples
Direct Conditions
Simply specify the condition you want to be met.
Combining Conditions
Combine multiple conditions using logical operators like AND and OR.
Correct usage" collapsible="true
Incorrect usage" collapsible="true
Utilizing Functions
Leverage Spark SQL functions to refine and enhance your conditions.
Correct usage" collapsible="true
Incorrect usage" collapsible="true
Using scan-time variables
To refer to the current dataframe being analyzed, use the reserved dynamic variable {{_qualytics_self}}.
Correct usage" collapsible="true
Incorrect usage" collapsible="true
While subqueries can be useful, their application within filters in our context has limitations. For example, directly referencing other containers or the broader target container in such subqueries is not supported. Attempting to do so will result in an error.
Important Note on {{_qualytics_self}}
The {{_qualytics_self}} keyword refers to the dataframe that's currently under examination. In the context of a full scan, this variable represents the entire target container. However, during incremental scans, it only reflects a subset of the target container, capturing just the incremental data. It's crucial to recognize that in such scenarios, using {{_qualytics_self}} may not encompass all entries from the target container.
Anomaly Types
| Type | Supported |
|---|---|
| Record Flag inconsistencies at the row level |
|
| Shape Flag inconsistencies in the overall patterns and distributions of a field |
Evaluation Flow
Every Contains Social Security Number check follows the same four-step evaluation flow:
- Apply the filter clause. If the check has a
filterset, only rows matching the filter expression continue to the next step. Rows outside the filter are ignored and cannot contribute to the violation count. - Read the field value as text. The platform reads the row's value for the selected field.
- Look for a social security number. The value passes when the pattern is found anywhere inside it, and fails when it is not.
- Apply coverage. At 100% coverage, any failing row causes the check to fail. Below 100% coverage, the check fails only when the passing fraction drops below the threshold (see Coverage and Tolerance).
NULL Handling
The check passes NULL values: a row with NULL in the evaluated field is not counted as a violation. Contains Social Security Number only asserts that present values contain a social security number and does not enforce mandatory presence on the field.
If the field must also be populated, pair it with a Not Null check on the same field. An empty string is a present value with no match, so it is reported as a violation.
Array Fields
On an array field, every element is tested and the row fails as soon as one element does not contain the pattern. A NULL array passes, and so does an empty array, since there is nothing to evaluate. NULL elements inside an array are skipped rather than failing the row.
The Filter Clause
The filter clause is a SQL WHERE expression applied before the evaluation. Filtered-out rows are ignored entirely (they cannot trigger a violation and are not counted in the totals).
When a filter is set, both the Record Anomaly and the Shape Anomaly messages end with [filter: <expression>] so the evaluated scope is visible in the alert.
Coverage and Tolerance
Coverage is a fractional value between 0 and 1 that defines the minimum fraction of evaluated rows that must pass:
1.0(100%, default): every row in the filtered set must pass. Any failing row causes the check to fail. This is the strictest setting.< 1.0: the check tolerates a fraction of rows failing. The check fails only when the fraction of passing rows drops below the threshold.
Lower coverage values are useful when a small, known fraction of failures is expected. Use coverage carefully: a 0.5% tolerance can mask a real regression that happens to fall just under the threshold.
See Also
-
Anomaly Reporting
The anomaly messages the check produces, what the numbers mean, Source Records highlighting, and Custom Anomaly Description.
-
Examples
Three production scenarios with sample data, anomaly messages, and the SQL equivalent of what the check evaluates.
-
Best Practices
Guidelines for scoping the check, pairing rules, and keeping the signal clean.
-
Permissions
The team permission each action needs: view, create, edit, archive, restore, and delete.