feat: protect sensitive catalog samples

This commit is contained in:
Codex
2026-08-30 12:14:23 +02:00
parent 6278ee9d81
commit 0736983bc5
28 changed files with 1162 additions and 128 deletions
+10 -6
View File
@@ -305,12 +305,16 @@ Configuration changes take effect after restart and do not use Pi settings or wo
`llm_policy`.
Before enabling Description Generation, approve the selected model provider for bounded source-data
disclosure. A request may send up to five real source rows and up to five representative distinct,
non-null example values for relevant columns. Samples are transient and are not stored in generation
runs, run logs, application logs, API responses, or catalog metadata; prompt and sample snapshots are
not retained. Automated Sensitive Data Policy filtering and anonymization are not currently provided.
A future Sensitive Data Policy is required to classify protected fields and exclude or anonymize
their values before model calls.
disclosure. Every catalog column has a **Sensitive** flag that defaults to `false`. Administrators can
request an AI proposal based only on structural metadata, then must review and save the resulting
checkboxes themselves. The proposal never reads column contents and is not persisted automatically.
For unprotected columns, a request may send up to five real source rows and five representative
distinct, non-null example values. Protected columns are omitted from source reads and replaced in the
prompt by deterministic plausible values derived only from column metadata. Samples are transient and
are not stored in generation runs, run logs, application logs, API responses, or catalog metadata;
prompt and sample snapshots are not retained. A flag change applies to later generations and does not
regenerate existing descriptions.
Description Generation is an interactive Database Management operation, not a user-facing CLI.
The installation runs at most one sequential generation at a time. The run drawer exposes safe