Files
ThothII/docs/adr/0011-gate-source-samples-with-a-sensitive-data-flag.md
T

27 lines
1.5 KiB
Markdown

---
status: accepted
---
# Gate source samples with a Sensitive Data Flag
Each Catalog Column has one human-set `sensitive` boolean, defaulting to `false`. An AI may prefill
draft suggestions from structural metadata only, but the user decides and only the boolean is
persisted; there is no rationale, history, audit ledger, fingerprint, review state, or retroactive
regeneration of existing descriptions.
The user starts a suggestion from an explicit selection at database, table, or column level. A
database request accepts exactly one selected database; a table or column request contains only the
selected tables' columns or the selected columns, respectively. The backend divides that structural
metadata into deterministic model requests of at most ten columns, also bounded by helper message
size, and returns one combined draft for human review. No flag changes until the user saves the
reviewed draft.
Description generation extends ADR-0010 by sending bounded real values when `sensitive` is false
and deterministic plausible synthetic values when it is true, without identifying the synthetic
values to the model. The false default deliberately favors the expected stable schemas and the
minority of protected columns: a new column remains eligible for real sampling until a user marks
it sensitive.
Applying the same flag to LSH value grounding is deferred until the current catalog tickets and
owner acceptance test are complete; `PROJECT_STATE.md` records that required follow-up gate.