[Privacy] Add governed Datasources DSAR coverage #8

Closed
opened 2026-08-21 03:14:28 +02:00 by zemion · 1 comment
Owner

Part of GovOPlaN/govoplan#47. Add tenant-scoped privacy.dsar.datasources coverage for catalogue, staging, payload, immutable materialization, publication, and governance-reference state. Never export connector/provider references, locators, credentials, arbitrary rows, schemas, validation samples, metadata, provenance bodies, or hashes. Distinguish removable unpromoted staging state from immutable/referenced data and institutional operator attribution; document why source-owned subject facts require governed source correction rather than unsafe payload scanning; add Core workflow and retry coverage.

Part of GovOPlaN/govoplan#47. Add tenant-scoped `privacy.dsar.datasources` coverage for catalogue, staging, payload, immutable materialization, publication, and governance-reference state. Never export connector/provider references, locators, credentials, arbitrary rows, schemas, validation samples, metadata, provenance bodies, or hashes. Distinguish removable unpromoted staging state from immutable/referenced data and institutional operator attribution; document why source-owned subject facts require governed source correction rather than unsafe payload scanning; add Core workflow and retry coverage.
Author
Owner

Implemented and pushed as f03497b. Datasources now publishes privacy.dsar.datasources with tenant-scoped exact lifecycle selectors, canonical operator attribution, credential/payload minimization, immutable-state review boundaries, and idempotent deletion limited to explicitly selected unpromoted stages and orphan payloads. Verification: 39 tests (2 expected PostgreSQL skips), Ruff, manifest registry (68/68), targeted safety regression, and diff checks passed.

Implemented and pushed as `f03497b`. Datasources now publishes `privacy.dsar.datasources` with tenant-scoped exact lifecycle selectors, canonical operator attribution, credential/payload minimization, immutable-state review boundaries, and idempotent deletion limited to explicitly selected unpromoted stages and orphan payloads. Verification: 39 tests (2 expected PostgreSQL skips), Ruff, manifest registry (68/68), targeted safety regression, and diff checks passed.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-datasources#8