Status: Accepted; complete cross-projection privacy qualification pending. Current policy contracts are in src/KeyLoad.Abstractions/Contracts.cs, enforcement in src/KeyLoad.Core/MutationAuthorization.cs and src/KeyLoad.Core/DatabaseEngine.cs, and shared policy primitives in src/KeyLoad.Security/Features/Authorization/Execution/AuthorizationPolicy.cs; product source sections 14, 26, 29–30, and 44.
Sensitive data can flow through documents, events, message payloads/headers, graph attributes, text/vector/search projections, query aliases, diagnostics, backups, and replay. Classified fields carry versioned policy/lineage. Human-readable outputs omit protected fields by default. A computation requiring raw fields needs an explicit data-use grant; redacted replacement is not silently substituted when it would change business semantics. Derived projections inherit source classification and policy epoch, and every read/replay/export boundary rechecks current restrictions.
Omission and lineage reduce accidental disclosure through search, logs, aliases, and replay. Reclassification/revocation may invalidate projections and cursors and may require rebuild. Historical raw bytes are not erased by response omission; retention, physical purge, backups, and crypto-erasure need separate verified lifecycle decisions. Hashes can themselves be sensitive.
Authorization REQ-AUTH-001..003 plus REQ-AUTH-004..009 and matching AC-AUTH-004..009, particularly field read/use/write, policy-epoch enforcement, protected processing inputs, and sensitive-data lineage/diagnostics. Search REQ-SR-002/005, DocumentStorage REQ-DSTORE-003, Messaging REQ-MSG-002/003, GraphTraversal REQ-GRAPH-002, and EventStreams REQ-EVENT-003/006 also apply. ADR-014 defines authority; ADR-029 expands event/message classification.
- Freeze classification vocabulary, schema lineage, required-input behavior, omission rules, derived-provider metadata, and safe diagnostic format.
- Add canary tests across document, event/header, queue/DLQ, SQL alias/sort, graph edge, search/vector, export, trace, and replay; assert both allowed raw use and denied omission/failure.
- Target owners:
src/KeyLoad.Security/Features/Authorization/, each canonical source slice, and the existingsrc/KeyLoad.Query/Features/Search/projection slice; no generic endpoint may bypass source ownership or create a separate search technical root. - Reclassification increments policy/schema epochs and invalidates stale derived generations before exposing output. Rollback cannot restore permissive reads without restoring authorized policy state; purge operations must report replica/archive boundaries.
- GitHub CI runs TUnit and real RF3 SDK/MCP privacy cases. Root joins Security, Search, Messaging, and backup owners; retain sanitized evidence only.
Dependencies: ADR-004, ADR-006, ADR-009, ADR-010, ADR-013, ADR-014, ADR-018, ADR-019, ADR-022, ADR-029, and ADR-030. Stop on missing lineage or unsafe replay; do not infer erasure from omission.
flowchart LR
Source[Classified canonical field] --> Lineage[Versioned source lineage]
Lineage --> Policy[Current policy and use grant]
Policy -->|human read| Omit[Safe omission or masked projection]
Policy -->|required processing| Raw[Explicit authorized raw use]
Raw --> Derived[Versioned derived output with inherited lineage]
Derived --> Recheck[Recheck policy before every disclosure]