Household returns and service-generated waste can use one software platform only if their physical flows and responsibilities are kept distinct.
Shared software is not shared custody
Common identifiers, event logs and reporting views can reduce software cost. They do not merge the legal classification, packaging rule or authorized operator for two different streams.
Separation must appear in the data model
Each record needs a stream type, container type, custodian, authorized next party and exception route. A user should not be able to transfer one stream through the workflow designed for the other.
Audit the join points
Identity, site and route tables may be shared. Material events, treatment evidence and permissions should remain segregated so that a combined dashboard cannot create a false combined chain of custody.
Expansion decision
When adding a new item, test both whether the common event model can be reused and whether the existing responsibility boundary remains intact. Reusable scanning and reporting do not justify a common container or carrier. If the event model fits but custody does not, use a separate module and permissions. If the accepted route, responsible operator or evidence cannot be defined, postpone the service rather than force the item into an existing stream.
Minimum stream-aware record
Require stream ID, legal or internal classification reference, container ID, event ID, item or aggregate ID, event type, timestamp, location, custodian, authorised next role, quantity and unit, evidence link, exception code and retention class. The stream ID must be immutable after the first custody event. Corrections should reverse and replace a record with an audit trail rather than overwrite the original. Shared master data may describe a site or role, but it must not silently supply the missing authority for a transfer event.
Permission design follows purpose
Route planners may need locations and service windows but not household identity or treatment certificates. Field operators need assigned containers and exception actions but not manufacturer analytics. Treatment partners need the accepted stream, quantity and transfer evidence. Analysts may use pseudonymous event data after the operational need is met. Define view, create, correct, approve and export permissions separately; a shared login or administrator role defeats stream separation even when the database tables are distinct.
Three negative tests before release
Attempt to route Stream A through Stream B's container, transfer it to a party authorised only for Stream B and include it in Stream B's dashboard total. Each attempt should be blocked and logged. Then test a correction, rejected hand-off and lost container without deleting the original event. Stop release if a user can change stream ID, if an exception has no owner or if a combined report cannot be reconciled to the two separate ledgers.
Primary sources and limits
GS1 EPCIS 2.0.1 distinguishes event data from contextual master data and supports interoperable visibility events: https://ref.gs1.org/standards/epcis/2.0.1/. GDPR Article 5 provides purpose limitation, data minimisation and accountability principles for personal data in its scope: https://eur-lex.europa.eu/eli/reg/2016/679/oj. These sources inform data architecture; they do not merge legal custody, determine Korean waste classification or authorise a transfer.