[Feature] Add policy-aware datasource and field visibility #5

Open
opened 2026-07-28 12:48:19 +02:00 by zemion · 0 comments
Owner

Parent: #1

Extend current tenant and scope isolation with governed source,
materialization, row, and field visibility.

Acceptance criteria:

  • source/materialization ACL and policy references without connector credential exposure
  • field classification and redaction/projection before rows leave the provider
  • optional row-filter policy with deterministic diagnostics
  • consuming module receives only an opaque permitted view and its fingerprint
  • audit records denied and redacted reads without logging protected values
  • reduced local behavior remains available when Access/Policy is absent
  • tests cover tenant, role, field, row, frozen-state, and service-principal access
Parent: https://git.add-ideas.de/GovOPlaN/govoplan-datasources/issues/1 Extend current tenant and scope isolation with governed source, materialization, row, and field visibility. Acceptance criteria: - source/materialization ACL and policy references without connector credential exposure - field classification and redaction/projection before rows leave the provider - optional row-filter policy with deterministic diagnostics - consuming module receives only an opaque permitted view and its fingerprint - audit records denied and redacted reads without logging protected values - reduced local behavior remains available when Access/Policy is absent - tests cover tenant, role, field, row, frozen-state, and service-principal access
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-datasources#5
No description provided.