[Privacy] Add governed Workflow Engine DSAR coverage #2

Closed
opened 2026-08-21 03:27:36 +02:00 by zemion · 1 comment
Owner

Part of GovOPlaN/govoplan#47. Add tenant-scoped privacy.dsar.workflow_engine coverage for definitions/revisions, instances, steps, immutable events, triggers/deliveries, and wait states. Correlate structured instance authorization, work assignments, automation authority, actor attribution, and exact artifact references without scanning arbitrary graph/runtime payloads. Exclude graphs/BPMN, input/context/output, handoffs, event/config payloads, authorization snapshots, errors, source keys, hashes, and secrets. Revoke subject-linked automation and minimize exact terminal deliveries while preserving operational/decision evidence; add retries, active/inactive workflow coverage, and static user/admin documentation.

Part of GovOPlaN/govoplan#47. Add tenant-scoped `privacy.dsar.workflow_engine` coverage for definitions/revisions, instances, steps, immutable events, triggers/deliveries, and wait states. Correlate structured instance authorization, work assignments, automation authority, actor attribution, and exact artifact references without scanning arbitrary graph/runtime payloads. Exclude graphs/BPMN, input/context/output, handoffs, event/config payloads, authorization snapshots, errors, source keys, hashes, and secrets. Revoke subject-linked automation and minimize exact terminal deliveries while preserving operational/decision evidence; add retries, active/inactive workflow coverage, and static user/admin documentation.
Author
Owner

Implemented and pushed as ceb61b5. Workflow Engine now publishes privacy.dsar.workflow_engine with exact artifact/package selectors, structured instance authorization and work-assignment matching, minimized attribution, bounded fail-closed correlation, subject-linked automation revocation, terminal delivery minimization that preserves replay identity, retries, and static user/admin documentation. Verification: 78 tests, Ruff, targeted DSAR matrix, manifest registry (68/68), and diff checks passed.

Implemented and pushed as `ceb61b5`. Workflow Engine now publishes `privacy.dsar.workflow_engine` with exact artifact/package selectors, structured instance authorization and work-assignment matching, minimized attribution, bounded fail-closed correlation, subject-linked automation revocation, terminal delivery minimization that preserves replay identity, retries, and static user/admin documentation. Verification: 78 tests, Ruff, targeted DSAR matrix, manifest registry (68/68), and diff checks passed.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-workflow-engine#2