feat: protect sensitive catalog samples

This commit is contained in:
Codex
2026-08-30 12:14:23 +02:00
parent 6278ee9d81
commit 0736983bc5
28 changed files with 1162 additions and 128 deletions
@@ -0,0 +1,19 @@
---
status: accepted
---
# Gate source samples with a Sensitive Data Flag
Each Catalog Column has one human-set `sensitive` boolean, defaulting to `false`. An AI may prefill
draft suggestions from structural metadata only, but the user decides and only the boolean is
persisted; there is no rationale, history, audit ledger, fingerprint, review state, or retroactive
regeneration of existing descriptions.
Description generation extends ADR-0010 by sending bounded real values when `sensitive` is false
and deterministic plausible synthetic values when it is true, without identifying the synthetic
values to the model. The false default deliberately favors the expected stable schemas and the
minority of protected columns: a new column remains eligible for real sampling until a user marks
it sensitive.
Applying the same flag to LSH value grounding is deferred until the current catalog tickets and
owner acceptance test are complete; `PROJECT_STATE.md` records that required follow-up gate.