[Privacy] Add governed Reporting DSAR coverage #9

Closed
opened 2026-08-21 03:02:17 +02:00 by zemion · 1 comment
Owner

Part of GovOPlaN/govoplan#47. Add a tenant-scoped privacy.dsar.reporting provider for subject-owned Reporting state and minimized operator attribution. Cover exact saved-view, execution, provider-execution, export, schedule, publication, drill-context, grant, and definition references; canonical account/identity/membership ownership and attribution; explicit separation of source-owned report content from Reporting-derived copies; fail-closed alias correlation; safe erasure/minimization planning; Core workflow tests; and static user/admin documentation.

Part of GovOPlaN/govoplan#47. Add a tenant-scoped `privacy.dsar.reporting` provider for subject-owned Reporting state and minimized operator attribution. Cover exact saved-view, execution, provider-execution, export, schedule, publication, drill-context, grant, and definition references; canonical account/identity/membership ownership and attribution; explicit separation of source-owned report content from Reporting-derived copies; fail-closed alias correlation; safe erasure/minimization planning; Core workflow tests; and static user/admin documentation.
Author
Owner

Implemented and pushed as eb6742a. Reporting now publishes privacy.dsar.reporting with exact artifact selectors, canonical ownership/attribution matching, tenant isolation and corroboration, minimized access output, protected shared/institutional state, and idempotent deletion, revocation, or minimization for eligible derived state. Verification: 20 tests, Ruff, manifest registry (68/68), and diff checks passed.

Implemented and pushed as `eb6742a`. Reporting now publishes `privacy.dsar.reporting` with exact artifact selectors, canonical ownership/attribution matching, tenant isolation and corroboration, minimized access output, protected shared/institutional state, and idempotent deletion, revocation, or minimization for eligible derived state. Verification: 20 tests, Ruff, manifest registry (68/68), and diff checks passed.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-reporting#9