[Privacy] Add governed Organizations DSAR coverage #8

Closed
opened 2026-08-21 01:22:19 +02:00 by zemion · 1 comment
Owner

Parent umbrella: GovOPlaN/govoplan#47

Outcome

Organizations participates in the provider-neutral data-subject request workflow for the tenant-scoped operator attribution it actually owns, while documenting that IDM—not Organizations—owns identity-held function assignments.

Acceptance criteria

  • Publish privacy.dsar.organizations through the module manifest.
  • Corroborate account selectors and fail closed on conflicts.
  • Return capped, deterministic, exact-tenant model-instantiation and upgrade attribution only.
  • Exclude global templates, unrelated institutional units/functions, opaque definitions, previews, decisions, provenance, idempotency keys, and request digests.
  • Retain organization-change attribution with explicit governance reasons; publish no automatic erasure action.
  • Static administrator documentation explains the narrow coverage and the IDM boundary.
  • Tests cover tenant isolation, selector conflicts, minimization, dispositions, foreign actions, and active/inactive Core coverage.
  • Module, manifest, and focused checks pass.
Parent umbrella: GovOPlaN/govoplan#47 ## Outcome Organizations participates in the provider-neutral data-subject request workflow for the tenant-scoped operator attribution it actually owns, while documenting that IDM—not Organizations—owns identity-held function assignments. ## Acceptance criteria - [x] Publish `privacy.dsar.organizations` through the module manifest. - [x] Corroborate account selectors and fail closed on conflicts. - [x] Return capped, deterministic, exact-tenant model-instantiation and upgrade attribution only. - [x] Exclude global templates, unrelated institutional units/functions, opaque definitions, previews, decisions, provenance, idempotency keys, and request digests. - [x] Retain organization-change attribution with explicit governance reasons; publish no automatic erasure action. - [x] Static administrator documentation explains the narrow coverage and the IDM boundary. - [x] Tests cover tenant isolation, selector conflicts, minimization, dispositions, foreign actions, and active/inactive Core coverage. - [x] Module, manifest, and focused checks pass.
Author
Owner

Organizations module coverage is implemented and pushed in aa4ed0b. The module suite is green (30 tests), the 68-manifest shape/architecture/governance check passes, and the complete focused workspace gate passes, including all 59 WebUI module permutations and 7 browser conformance checks. Closing as complete.

Organizations module coverage is implemented and pushed in `aa4ed0b`. The module suite is green (30 tests), the 68-manifest shape/architecture/governance check passes, and the complete focused workspace gate passes, including all 59 WebUI module permutations and 7 browser conformance checks. Closing as complete.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-organizations#8