[Privacy] Add governed Dataflow DSAR coverage #21

Closed
opened 2026-08-21 03:20:43 +02:00 by zemion · 1 comment
Owner

Part of GovOPlaN/govoplan#47. Add tenant-scoped privacy.dsar.dataflow coverage for pipeline definitions/revisions, reconciliation decisions, runs, deployments, triggers, and deliveries. Keep graphs, SQL, request/event payloads, corrections, authorization snapshots, provenance, errors, source details, hashes, and credentials out of access results. Allow exact terminal-run/delivery minimization and revocation of subject-linked automation authority while preserving institutional evidence and published Datasource ownership. Add fail-closed correlation, retries, active/inactive workflow coverage, and static user/admin documentation.

Part of GovOPlaN/govoplan#47. Add tenant-scoped `privacy.dsar.dataflow` coverage for pipeline definitions/revisions, reconciliation decisions, runs, deployments, triggers, and deliveries. Keep graphs, SQL, request/event payloads, corrections, authorization snapshots, provenance, errors, source details, hashes, and credentials out of access results. Allow exact terminal-run/delivery minimization and revocation of subject-linked automation authority while preserving institutional evidence and published Datasource ownership. Add fail-closed correlation, retries, active/inactive workflow coverage, and static user/admin documentation.
Author
Owner

Implemented and pushed as 6767905. Dataflow now publishes privacy.dsar.dataflow with tenant-scoped exact selectors, minimized operator/automation attribution, fail-closed correlation, terminal run/delivery minimization that preserves replay identity, subject-linked automation revocation, idempotent retries, and static user/admin documentation. Verification: 91 tests, Ruff, focused DSAR/manifest regression, manifest registry (68/68), and diff checks passed.

Implemented and pushed as `6767905`. Dataflow now publishes `privacy.dsar.dataflow` with tenant-scoped exact selectors, minimized operator/automation attribution, fail-closed correlation, terminal run/delivery minimization that preserves replay identity, subject-linked automation revocation, idempotent retries, and static user/admin documentation. Verification: 91 tests, Ruff, focused DSAR/manifest regression, manifest registry (68/68), and diff checks passed.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-dataflow#21