Groundskeeper
Architecture decisions

ADR 0007: Sensitive-data observability

  • Status: Accepted
  • Date: 2026-10-03

Context

Guardrail inputs and findings commonly contain the exact secrets and personal information the service exists to protect. Conventional request logging or error reporting can become a secondary breach.

Decision

Logs, traces, metrics, and default audit events contain metadata, counts, category, versions, timings, and keyed privacy-safe fingerprints only. They do not contain raw provider bodies, normalized content, matched substrings, credentials, PII, or reversible redaction tokens. Debug capture is not part of v1.

Consequences

  • Incident diagnosis relies on reproducible synthetic cases and safe identifiers.
  • Any future payload capture needs a separate privacy threat model, explicit authorisation, encryption, access controls, and retention/deletion policy.
  • Error types and third-party telemetry integrations must be reviewed for value leakage.

On this page