feat(records): add governed DSAR coverage
This commit is contained in:
@@ -54,6 +54,25 @@ Restricted object grants remain a separate governed slice. A target-tested
|
||||
archive adapter and any destructive effect remain deliberately unimplemented;
|
||||
approved destruction is only a pending lifecycle state.
|
||||
|
||||
## Data-subject requests
|
||||
|
||||
Records publishes `privacy.dsar.records`. A record-subject search must include
|
||||
an exact record, revision, item, volume, chronology, hold, disposition,
|
||||
transfer-package, or authoritative source-module reference. A canonical
|
||||
account, identity, or membership match identifies staff accountability
|
||||
activity only; creating, filing, reviewing, or transferring an eAkte does not
|
||||
make that staff member the subject of its contents.
|
||||
|
||||
The provider exports bounded record identity, revision, filing, chronology,
|
||||
hold, disposition, and transfer lifecycle metadata. It excludes source
|
||||
content, record snapshots and search text, opaque institutional contexts and
|
||||
payloads, digests, replay keys, launch URLs, approval identifiers, archive
|
||||
manifests and receipts, and unrelated records. Exact source content remains in
|
||||
the source owner's DSAR provider. Record revisions and lifecycle evidence are
|
||||
immutable retention evidence; the current record fact receives a
|
||||
non-executable manual-review action. Actual correction, closure, appraisal,
|
||||
hold, disposition, or transfer must use the governed eAkte lifecycle.
|
||||
|
||||
## First Implementation Slice
|
||||
|
||||
Complete restricted access and one target-tested archive provider without
|
||||
|
||||
Reference in New Issue
Block a user