feat(workflow-engine): add governed DSAR coverage

This commit is contained in:
2026-08-21 03:33:06 +02:00
parent 9174e07118
commit ceb61b5867
4 changed files with 1516 additions and 0 deletions
+17
View File
@@ -1,5 +1,22 @@
# GovOPlaN Workflow Engine
## Data-subject requests
Workflow Engine publishes `privacy.dsar.workflow_engine` for exact definition,
revision, instance, step, event, trigger, delivery, and wait references and for
structured instance authorization, work assignments, automation authority, and
minimized operator attribution. It never exports graphs/BPMN, inputs, context,
outputs, handoffs, events/configuration, authorization snapshots, errors,
replay keys, external references, hashes, or credentials. Owning service, case,
form, and other source modules locate and correct facts inside arbitrary
runtime payloads.
Subject-linked automation can be disabled and revoked, while exact terminal
delivery detail can be minimized idempotently without changing its replay key.
Definitions, instances, live work, assignments, transition and decision
events, waits, and institutional attribution require authorized review or
retention.
<!-- govoplan-repository-type:start -->
**Repository type:** module (platform).
<!-- govoplan-repository-type:end -->