27 lines
1.5 KiB
Markdown
27 lines
1.5 KiB
Markdown
---
|
|
status: accepted
|
|
---
|
|
|
|
# Gate source samples with a Sensitive Data Flag
|
|
|
|
Each Catalog Column has one human-set `sensitive` boolean, defaulting to `false`. An AI may prefill
|
|
draft suggestions from structural metadata only, but the user decides and only the boolean is
|
|
persisted; there is no rationale, history, audit ledger, fingerprint, review state, or retroactive
|
|
regeneration of existing descriptions.
|
|
|
|
The user starts a suggestion from an explicit selection at database, table, or column level. A
|
|
database request accepts exactly one selected database; a table or column request contains only the
|
|
selected tables' columns or the selected columns, respectively. The backend divides that structural
|
|
metadata into deterministic model requests of at most ten columns, also bounded by helper message
|
|
size, and returns one combined draft for human review. No flag changes until the user saves the
|
|
reviewed draft.
|
|
|
|
Description generation extends ADR-0010 by sending bounded real values when `sensitive` is false
|
|
and deterministic plausible synthetic values when it is true, without identifying the synthetic
|
|
values to the model. The false default deliberately favors the expected stable schemas and the
|
|
minority of protected columns: a new column remains eligible for real sampling until a user marks
|
|
it sensitive.
|
|
|
|
Applying the same flag to LSH value grounding is deferred until the current catalog tickets and
|
|
owner acceptance test are complete; `PROJECT_STATE.md` records that required follow-up gate.
|