Open decisions register
These choices are intentionally unresolved. Defaults elsewhere are implementation starting points, not permission to invent product, risk, legal, or governance policy. Each item needs an owner and a recorded decision before the named gate.
| ID | Decision needed | Owner | Required before |
|---|---|---|---|
| OD-001 | Whether OpenGuardrails wire compatibility is a future requirement | Product + architecture | freezing public v1 API |
| OD-002 | Exact provider/protocol adapters in the first supported release | Product | Phase 1 scope lock |
| OD-003 | Whether any streaming enforcement is in the first production milestone | Product + security | production scope lock |
| OD-004 | Risk tiers and numerical precision, recall, benign-pass, latency, and availability SLOs | Risk + product + SRE | enforcement release gates |
| OD-005 | Portkey outage posture per route/stage; especially fail-open versus fail-closed | Risk + service owners | enforcement rollout |
| OD-006 | Required/advisory checks and timeout/error behavior by policy stage | Risk + policy owners | enforcement rollout |
| OD-007 | Whether third-party native subprocess detectors are permitted | Security | external plugin pilot |
| OD-008 | External model-judge and cross-border processing policy | Privacy + legal + governance | sending any corpus externally |
| OD-009 | Audit metadata and sensitive-payload retention periods | Privacy + security | production telemetry |
| OD-010 | Redaction/tokenisation semantics by category; whether reversible tokenisation is allowed | Privacy + product | transformation release |
| OD-011 | Formal approval of YAML plus constrained CEL as the public authoring contract | Architecture + policy owners | public policy SDK |
| OD-012 | OCI registry, signing identity, trust-root administration, and key rotation | Security + platform | artefact distribution |
| OD-013 | Exact tenant-overridable fields and publish/approve/activate role separation | Security + product | multi-tenant control plane |
| OD-014 | Indigenous governance body composition, compensation, authority, quorum, and operating process | Executive sponsor + Indigenous governance body | collecting or using relevant material |
| OD-015 | Community-controlled evaluation access, release criteria, and withdrawal/deletion SLAs | Indigenous governance body | relevant corpus creation |
| OD-016 | Whether to obtain controlled ATO validation algorithms, DVS access, or commercial PAF | Product + legal + privacy | claiming corresponding validation |
| OD-017 | G-NAF EULA interpretation, attribution, mail-generation restriction, and deployment model | Legal + data owner | address reference deployment |
| OD-018 | Sourcing and approval of ACN and other algorithms not established by current research | Data + legal | implementing those validators |
| OD-019 | Confidence calibration thresholds per entity and context | Risk + data science | enforcing PII policies |
| OD-020 | Whether measured retrieval quality justifies pgvector | Architecture + data science | adding vector infrastructure |
| OD-021 | Whether remote detector execution ships in v1 or only the interface | Product + security | Phase 1 scope lock |
| OD-022 | Workflow states above the wire-level allow/block result | Product | control-plane design |
| OD-023 | Whether inspection, redaction, and any allow-through of HPI-Is is an authorised use/disclosure under Healthcare Identifiers Act s 26 for each deployment role | Health-law counsel + privacy | any health deployment or trial |
| OD-024 | Whether the operator and sub-processors need VCAA authorisation under ETR Act s 5.3A.9 for VSNs, which permitted purpose applies, and which Secretary's Guidelines conditions bind Groundskeeper | Legal + privacy + customer (Department/VCAA/school) | any Victorian education deployment or trial |
| OD-025 | Approved processing/storage jurisdictions and APP 8 / IPP 9 basis, including interstate hosting and telemetry sub-processors | Privacy + legal + security | production trial |
| OD-026 | Whether any per-value fingerprint of HPI-I/VSN is allowed (10⁹-value spaces are enumerable), and if so key management, rotation, and retention | Privacy + security | production telemetry |
| OD-027 | Records status of Groundskeeper decision artefacts for public-office customers, record-keeper, and retention and disposal authority class | Records manager + legal | Victorian public sector production |
| OD-028 | Breach-notification allocation and SLAs across NDB, OAIC (HI Act), OVIC, VCAA/Department, ransomware reporting, and contracts | Privacy + legal + security | production trial |
| OD-029 | Acceptance of residual risk that structurally valid synthetic HPI-I/VSN fixtures may equal issued identifiers; approval of fixture registry and generation rules | Privacy + engineering lead | adding any structurally valid HPI-I or VSN fixture |
| OD-030 | Production-trial authorisation: PIA outcome, scope, duration, stop criteria, and any HREC/research approval | Privacy + product + customer | production trial |
| OD-031 | Whether Groundskeeper decisions are APP 1.7 automated decisions and whether the Children's Online Privacy Code affects deployers; documentation to supply | Privacy + product | 10 December 2026 for APP entity customers |
Detector maturity gates proposes the evidence structure, provisional values and approval points for OD-004 and OD-019. It does not decide them.
Suggested working defaults pending decision
These are reversible and deliberately conservative:
- buffered evaluation only;
- observe mode before enforcement;
- built-in checks only;
- metadata-and-hash audit only;
- synthetic/nonfunctional evaluation data only;
- no external judges for sensitive or community-controlled data;
- no reversible tokenisation;
- no vector database;
- no raw prompt/response retention.
The suggested defaults do not settle OD-004 through OD-010 or grant authority to process data that otherwise requires legal or community approval.
OD-023 to OD-031 come from the HPI-I and VSN controls research. Pending those decisions, treat both identifiers as restricted: redact before any onward disclosure, perform no registry lookups, emit no per-value fingerprints, and add no further structurally valid fixtures. The micro-slice already ships three Luhn-valid HPI-I values (two synthetic plus the HL7 AU published example) and three VSN-shaped values, chosen by hand before this research and not yet in a fixture registry (GK-HV-19). OD-029 must accept or replace them before G1 evidence uses them.