Architecture decisions
ADR 0007: Sensitive-data observability
- Status: Accepted
- Date: 2026-10-03
Context
Guardrail inputs and findings commonly contain the exact secrets and personal information the service exists to protect. Conventional request logging or error reporting can become a secondary breach.
Decision
Logs, traces, metrics, and default audit events contain metadata, counts, category, versions, timings, and keyed privacy-safe fingerprints only. They do not contain raw provider bodies, normalized content, matched substrings, credentials, PII, or reversible redaction tokens. Debug capture is not part of v1.
Consequences
- Incident diagnosis relies on reproducible synthetic cases and safe identifiers.
- Any future payload capture needs a separate privacy threat model, explicit authorisation, encryption, access controls, and retention/deletion policy.
- Error types and third-party telemetry integrations must be reviewed for value leakage.