feat: protect sensitive catalog samples
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
---
|
||||
status: accepted
|
||||
---
|
||||
|
||||
# Gate source samples with a Sensitive Data Flag
|
||||
|
||||
Each Catalog Column has one human-set `sensitive` boolean, defaulting to `false`. An AI may prefill
|
||||
draft suggestions from structural metadata only, but the user decides and only the boolean is
|
||||
persisted; there is no rationale, history, audit ledger, fingerprint, review state, or retroactive
|
||||
regeneration of existing descriptions.
|
||||
|
||||
Description generation extends ADR-0010 by sending bounded real values when `sensitive` is false
|
||||
and deterministic plausible synthetic values when it is true, without identifying the synthetic
|
||||
values to the model. The false default deliberately favors the expected stable schemas and the
|
||||
minority of protected columns: a new column remains eligible for real sampling until a user marks
|
||||
it sensitive.
|
||||
|
||||
Applying the same flag to LSH value grounding is deferred until the current catalog tickets and
|
||||
owner acceptance test are complete; `PROJECT_STATE.md` records that required follow-up gate.
|
||||
Reference in New Issue
Block a user