feat: add governed Scheduling DSAR coverage
This commit is contained in:
@@ -61,6 +61,18 @@ Participant availability is sensitive operational data. Scheduling must record:
|
||||
Availability responses should be removable or redacted after the poll decision
|
||||
unless a configured process requires longer evidence retention.
|
||||
|
||||
Scheduling publishes `privacy.dsar.scheduling` for Core's governed
|
||||
data-subject-request workflow. It projects tenant-scoped participant, request,
|
||||
candidate-slot, and notification-envelope metadata while omitting Poll and
|
||||
invitation identifiers, public-link and proof material, Calendar identifiers,
|
||||
free/busy detail, notification content and errors, password hashes, opaque
|
||||
metadata, and unrelated participants. Poll owns the actual availability choices
|
||||
and response-retirement evidence; Calendar owns event and hold state. Terminal,
|
||||
responded, or notified records are retained or manually reviewed. Only a truly
|
||||
unengaged participant can be anonymized automatically, after tenant, identity,
|
||||
request status, invitation, response, enrollment, and notification state are
|
||||
revalidated under lock.
|
||||
|
||||
## Candidate Capabilities
|
||||
|
||||
- `scheduling.polls`
|
||||
|
||||
Reference in New Issue
Block a user