Ground generation prompts with bounded real source samples #10

Closed
opened 2026-08-28 13:34:23 +00:00 by mptyl · 0 comments
Owner

Parent

#4

What to build

Improve selected and database-wide description generation with bounded real source context while making the disclosure visible and preventing sampled values from becoming persistent operational data.

Acceptance criteria

  • A model request may include no more than five real rows and no more than five representative distinct non-null example values for relevant columns.
  • Sampling uses the binding's existing read-only data-access capability when available and never mutates the source database.
  • Unavailable optional samples do not fabricate values; generation can continue from catalog metadata with a safe diagnostic.
  • Schema names, comments, descriptions, and values are bounded and treated as untrusted prompt content separated from instructions.
  • Sample rows and values are never stored in runs, events, catalog metadata, API responses, or application logs.
  • The UI and operator documentation disclose that real source values may be sent to the selected provider before generation is used.
  • Tests prove the five-row and five-example limits, metadata-only fallback, read-only behavior, prompt boundary, and absence of sampled values from persistence and logs.
  • The future Sensitive Data Policy remains explicitly documented as required follow-up work; this ticket does not invent a partial classifier.

Blocked by

  • #8 — Generate selected tables and columns in structured batches
## Parent https://git.tylconsulting.it/mptyl/ThothII/issues/4 ## What to build Improve selected and database-wide description generation with bounded real source context while making the disclosure visible and preventing sampled values from becoming persistent operational data. ## Acceptance criteria - [ ] A model request may include no more than five real rows and no more than five representative distinct non-null example values for relevant columns. - [ ] Sampling uses the binding's existing read-only data-access capability when available and never mutates the source database. - [ ] Unavailable optional samples do not fabricate values; generation can continue from catalog metadata with a safe diagnostic. - [ ] Schema names, comments, descriptions, and values are bounded and treated as untrusted prompt content separated from instructions. - [ ] Sample rows and values are never stored in runs, events, catalog metadata, API responses, or application logs. - [ ] The UI and operator documentation disclose that real source values may be sent to the selected provider before generation is used. - [ ] Tests prove the five-row and five-example limits, metadata-only fallback, read-only behavior, prompt boundary, and absence of sampled values from persistence and logs. - [ ] The future Sensitive Data Policy remains explicitly documented as required follow-up work; this ticket does not invent a partial classifier. ## Blocked by - #8 — Generate selected tables and columns in structured batches
mptyl added the enhancementready-for-agent labels 2026-08-28 13:34:23 +00:00
mptyl added a new dependency 2026-08-28 13:35:03 +00:00
mptyl closed this issue 2026-08-28 16:09:42 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: mptyl/ThothII#10