---
title: "Security Data Class Registry"
description: "Sources: `docs/security-data-class-registry.json`."
engineVersion: v1.0.234
date: 2026-09-28
license: "(c) Gessa, proprietary. Cite with attribution to https://gessa.ai/docs/. Terms: https://gessa.ai/terms/."
canonical: https://gessa.ai/docs/spec/generated/data-classes/
---
<!-- GENERATED FILE: do not edit by hand. -->
<!-- Regenerate with `npm run gen-docs`. -->

Sources: `docs/security-data-class-registry.json`.

# Security Data Class Registry

This generated snapshot is derived from the security data class ledger at `docs/security-data-class-registry.json`, which is itself generated from `server/src/modules/security-governance/dataClassRegistry.ts`. Each class records its sensitivity tier, authorized purposes, permitted readers, retention rule, and deletion rule.

Data class count: `25`.
Registry schema version: `1`.

## Sensitivity tiers

| Sensitivity | Class count |
| --- | --- |
| `confidential_personal` | 7 |
| `confidential_tenant` | 5 |
| `restricted_secret` | 5 |
| `restricted_security` | 8 |

## Data classes

| Class | Description | Sensitivity | Subjects | Purpose | Readers | Retention | Deletion |
| --- | --- | --- | --- | --- | --- | --- | --- |
| `account_contact_email` | Account contact email | `confidential_personal` | `account` | Deliver authentication, recovery, security, and required account notices. | `account_owner`, `support_operator`, `platform_security_service` | `permanent_records` | `soft_delete` |
| `account_contact_phone` | Account contact phone | `confidential_personal` | `account` | Deliver opted-in authentication and account-security challenges. | `account_owner`, `credential_verifier`, `support_operator` | `permanent_records` | `soft_delete` |
| `account_identity` | Platform account identity | `confidential_personal` | `account` | Identify the account, enforce lifecycle state, and present the account-owned profile. | `account_owner`, `authorized_tenant_member`, `support_operator` | `permanent_records` | `soft_delete` |
| `admin_case_annotations` | Administrative case annotations | `restricted_security` | `account`, `administrator`, `organization`, `workspace`, `game`, `player` | Coordinate a named security, privacy, fraud, or safety investigation. | `incident_responder`, `security_auditor`, `privacy_operator` | `permanent_records` | `soft_delete` |
| `api_and_capability_credentials` | API key and capability credential material | `restricted_secret` | `account`, `service` | Authenticate a named machine actor and authorize explicit scopes and resources. | `credential_verifier`, `platform_security_service` | `permanent_records` | `soft_delete` |
| `audit_and_incident_evidence` | Immutable audit and incident evidence | `restricted_security` | `account`, `administrator`, `organization`, `workspace`, `game`, `service` | Investigate security events, prove control actions, and satisfy accountable audit obligations. | `incident_responder`, `security_auditor`, `privacy_operator` | `permanent_evidence` | `retain_immutable_evidence` |
| `billing_and_payment_metadata` | Billing and payment metadata | `confidential_personal` | `account`, `organization`, `provider` | Price, charge, reconcile, refund, dispute, and support purchased services. | `billing_service`, `account_owner`, `support_operator` | `permanent_records` | `soft_delete` |
| `client_telemetry_and_error_samples` | Client telemetry and scrubbed error samples | `confidential_personal` | `account`, `workspace`, `game`, `player` | Diagnose release regressions, crashes, and abuse of client-facing surfaces. | `platform_security_service`, `support_operator`, `incident_responder` | `permanent_records` | `soft_delete` |
| `creator_asset_content` | Creator assets and authored content | `confidential_tenant` | `account`, `organization`, `workspace`, `game` | Store, transform, collaborate on, publish, and deliver creator-authorized content. | `authorized_tenant_member`, `game_runtime_service`, `support_operator` | `permanent_records` | `soft_delete` |
| `device_binding_and_attestation` | Verified device binding and attestation metadata | `restricted_security` | `account`, `service`, `provider` | Bind sessions and high-risk requests to a verified device key and current attestation policy. | `credential_verifier`, `risk_engine`, `platform_security_service` | `permanent_records` | `soft_delete` |
| `game_configuration_and_state` | Game configuration and durable state | `confidential_tenant` | `organization`, `workspace`, `game`, `player` | Configure, publish, operate, and persist the state of a tenant-owned game. | `authorized_tenant_member`, `game_runtime_service` | `permanent_records` | `soft_delete` |
| `machine_and_service_account_identity` | Machine and service account identity | `restricted_security` | `organization`, `workspace`, `game`, `service` | Attribute automated actions to a named, scoped, revocable non-human principal. | `authorized_tenant_member`, `platform_security_service` | `permanent_records` | `soft_delete` |
| `mfa_passkey_and_recovery_metadata` | MFA, passkey, and recovery metadata | `restricted_security` | `account` | Authenticate the account, calculate assurance, detect cloned authenticators, and recover access. | `credential_verifier`, `account_owner`, `support_operator` | `permanent_records` | `soft_delete` |
| `network_and_client_risk_signals` | Network and client-derived risk signals | `restricted_security` | `account`, `service` | Detect anomalous access, enforce rate limits, investigate compromise, and trigger proportionate step-up. | `risk_engine`, `platform_security_service`, `account_owner` | `permanent_records` | `soft_delete` |
| `organization_identity_and_membership` | Organization identity and membership | `confidential_tenant` | `account`, `organization` | Operate tenant ownership, collaboration, policy, and billing boundaries. | `authorized_tenant_member`, `support_operator` | `permanent_records` | `soft_delete` |
| `player_identity_and_gameplay_data` | Player identity and gameplay data | `confidential_personal` | `game`, `player`, `account` | Admit players, operate gameplay, persist requested progress, and enforce game safety controls. | `game_runtime_service`, `account_owner`, `authorized_tenant_member` | `permanent_records` | `soft_delete` |
| `provider_credentials_and_secrets` | Provider credentials and integration secrets | `restricted_secret` | `organization`, `workspace`, `game`, `service`, `provider` | Authenticate the platform to a configured external provider for an explicitly authorized integration. | `provider_integration_service`, `platform_security_service` | `permanent_records` | `soft_delete` |
| `provider_payload_samples` | Transient provider verification payloads | `restricted_secret` | `account`, `organization`, `service`, `provider` | Verify a single callback, identity assertion, or device attestation and derive bounded claims. | `credential_verifier`, `provider_integration_service` | `transient_verification` | `release_transient_memory` |
| `runtime_session_and_replication_data` | Runtime session and replication data | `confidential_tenant` | `game`, `player`, `service` | Operate live rooms, synchronize admitted players, recover connections, and diagnose runtime incidents. | `game_runtime_service`, `authorized_tenant_member`, `incident_responder` | `permanent_records` | `soft_delete` |
| `security_decisions_and_events` | Security decisions and normalized events | `restricted_security` | `account`, `administrator`, `organization`, `workspace`, `game`, `player`, `service` | Explain authorization outcomes, detect attacks, alert responders, and verify policy behavior. | `platform_security_service`, `incident_responder`, `security_auditor` | `permanent_records` | `soft_delete` |
| `server_operational_errors` | Server operational errors | `restricted_security` | `account`, `organization`, `workspace`, `game`, `service` | Detect, diagnose, and remediate platform failures and security-relevant anomalies. | `platform_security_service`, `incident_responder`, `support_operator` | `permanent_records` | `soft_delete` |
| `session_and_refresh_credentials` | Session and refresh credential material | `restricted_secret` | `account`, `service` | Maintain authenticated continuity, rotate refresh credentials, and revoke compromised credential families. | `credential_verifier`, `platform_security_service` | `permanent_records` | `soft_delete` |
| `support_case_data` | Customer support case data | `confidential_personal` | `account`, `organization`, `workspace`, `game` | Resolve a customer-requested product, account, billing, or security issue. | `support_operator`, `account_owner`, `privacy_operator` | `permanent_records` | `soft_delete` |
| `user_authentication_secrets` | User authentication secret verifiers | `restricted_secret` | `account` | Verify a user's proof of knowledge during authentication or controlled recovery. | `credential_verifier`, `platform_security_service` | `permanent_records` | `soft_delete` |
| `workspace_identity_and_membership` | Workspace identity and membership | `confidential_tenant` | `account`, `organization`, `workspace` | Organize tenant resources and authorize scoped collaboration below an organization. | `authorized_tenant_member`, `support_operator` | `permanent_records` | `soft_delete` |

## Class details

### account_contact_email

| Field | Value |
| --- | --- |
| Display name | Account contact email |
| Sensitivity | `confidential_personal` |
| Subjects | `account` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `account_contact` | Deliver authentication, recovery, security, and required account notices. | An authenticated account needs one verified recovery and security-notification channel. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `account_owner` | `self_service` | yes | Only the authenticated subject receives the normalized address. |
| `support_operator` | `redacted` | no | Step-up and a support case expose only a masked address. |
| `platform_security_service` | `service_internal` | no | Delivery and compromise-response services receive the address for a named event. |
### account_contact_phone

| Field | Value |
| --- | --- |
| Display name | Account contact phone |
| Sensitivity | `confidential_personal` |
| Subjects | `account` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `phone_factor` | Deliver opted-in authentication and account-security challenges. | The number is collected only when the account chooses a phone-backed factor. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `account_owner` | `self_service` | yes | Only the authenticated subject receives a masked or self-service projection. |
| `credential_verifier` | `service_internal` | no | The factor service reads the normalized destination for a live challenge. |
| `support_operator` | `redacted` | no | Step-up and an active support case expose only the final digits. |
### account_identity

| Field | Value |
| --- | --- |
| Display name | Platform account identity |
| Sensitivity | `confidential_personal` |
| Subjects | `account` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `account_operation` | Identify the account, enforce lifecycle state, and present the account-owned profile. | A stable platform subject is required to bind credentials, grants, billing, and resources. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `account_owner` | `self_service` | yes | The authenticated account receives its own profile projection. |
| `authorized_tenant_member` | `tenant_scoped` | no | Members receive only collaboration-safe identity fields in a shared tenant. |
| `support_operator` | `redacted` | no | Case-bound access exposes the minimum account locator and state. |
### admin_case_annotations

| Field | Value |
| --- | --- |
| Display name | Administrative case annotations |
| Sensitivity | `restricted_security` |
| Subjects | `account`, `administrator`, `organization`, `workspace`, `game`, `player` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `case_coordination` | Coordinate a named security, privacy, fraud, or safety investigation. | Responders need bounded context and decisions that are not representable as automated event fields. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `incident_responder` | `incident_scoped` | no | An assigned case and current elevated authorization are required. |
| `security_auditor` | `redacted` | no | Audit review receives immutable author and decision history with subject data minimized. |
| `privacy_operator` | `incident_scoped` | no | Privacy cases expose only annotations necessary for the data-subject request. |
### api_and_capability_credentials

| Field | Value |
| --- | --- |
| Display name | API key and capability credential material |
| Sensitivity | `restricted_secret` |
| Subjects | `account`, `service` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `machine_authentication` | Authenticate a named machine actor and authorize explicit scopes and resources. | Non-browser automation requires a revocable credential with least-privilege scope. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `credential_verifier` | `service_internal` | no | Only the verifier reads hashes or encrypted token material during issuance and verification. |
| `platform_security_service` | `metadata_only` | no | Security services receive identifiers, scopes, and status but never plaintext secret material. |
### audit_and_incident_evidence

| Field | Value |
| --- | --- |
| Display name | Immutable audit and incident evidence |
| Sensitivity | `restricted_security` |
| Subjects | `account`, `administrator`, `organization`, `workspace`, `game`, `service` |
| Retention mode | `permanent_evidence` |
| Retention policy | data_policy / `PERMANENT_SECURITY_EVIDENCE` |
| Retention detail | justification: Containment and forensic evidence is immutable because later compromise review must survive mutable control state. |
| Deletion mode | `retain_immutable_evidence` |
| Deletion trigger | Deletion is prohibited except through an explicit legal and security policy migration. |
| Deletion execution owner | security_operations |
| Deletion verification | Append-only triggers, chain verification, and archive manifests continuously prove integrity. |
| Data-subject request | not_applicable_security_evidence |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `incident_evidence` | Investigate security events, prove control actions, and satisfy accountable audit obligations. | Critical containment and operator actions require durable tamper-evident evidence. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `incident_responder` | `incident_scoped` | no | A named incident, elevated session, and audited query are required. |
| `security_auditor` | `redacted` | yes | Approved audits receive bounded immutable evidence projections. |
| `privacy_operator` | `redacted` | yes | Privacy review receives only subject-relevant evidence permitted by law. |
### billing_and_payment_metadata

| Field | Value |
| --- | --- |
| Display name | Billing and payment metadata |
| Sensitivity | `confidential_personal` |
| Subjects | `account`, `organization`, `provider` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `billing_operation` | Price, charge, reconcile, refund, dispute, and support purchased services. | Commercial service delivery requires an auditable account-to-provider billing relation. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `billing_service` | `service_internal` | no | Billing services read provider references and state for a named transaction. |
| `account_owner` | `self_service` | yes | The payer receives a PCI-minimized invoice and subscription projection. |
| `support_operator` | `redacted` | no | Case-bound billing support sees masked payment metadata and transaction state. |
### client_telemetry_and_error_samples

| Field | Value |
| --- | --- |
| Display name | Client telemetry and scrubbed error samples |
| Sensitivity | `confidential_personal` |
| Subjects | `account`, `workspace`, `game`, `player` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `client_reliability` | Diagnose release regressions, crashes, and abuse of client-facing surfaces. | Bounded failure context is necessary to restore customer workflows and identify attack patterns. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `platform_security_service` | `service_internal` | no | Automated triage reads scrubbed fields and aggregate fingerprints. |
| `support_operator` | `redacted` | no | A customer case may expose a scrubbed sample tied to that case. |
| `incident_responder` | `incident_scoped` | no | Security incidents may inspect bounded samples under elevated authorization. |
### creator_asset_content

| Field | Value |
| --- | --- |
| Display name | Creator assets and authored content |
| Sensitivity | `confidential_tenant` |
| Subjects | `account`, `organization`, `workspace`, `game` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `content_operation` | Store, transform, collaborate on, publish, and deliver creator-authorized content. | The product cannot provide creation and publishing without retaining the customer's authored resources. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `authorized_tenant_member` | `tenant_scoped` | yes | Canonical grants and resource ancestry constrain reads to the owning tenant. |
| `game_runtime_service` | `service_internal` | no | Only published or explicitly preview-authorized content is delivered to a game runtime. |
| `support_operator` | `redacted` | no | Support receives metadata unless a case-specific customer grant authorizes content inspection. |
### device_binding_and_attestation

| Field | Value |
| --- | --- |
| Display name | Verified device binding and attestation metadata |
| Sensitivity | `restricted_security` |
| Subjects | `account`, `service`, `provider` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `device_assurance` | Bind sessions and high-risk requests to a verified device key and current attestation policy. | Device-bound proof reduces replay and distinguishes possession from a caller-supplied client label. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `credential_verifier` | `service_internal` | no | Proof verification reads public keys, counters, and current trust state. |
| `risk_engine` | `metadata_only` | no | Risk evaluation receives normalized trust tier and freshness, not raw evidence. |
| `platform_security_service` | `metadata_only` | no | Security operations receives key identifiers, trust history, and revocation state. |
### game_configuration_and_state

| Field | Value |
| --- | --- |
| Display name | Game configuration and durable state |
| Sensitivity | `confidential_tenant` |
| Subjects | `organization`, `workspace`, `game`, `player` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `game_operation` | Configure, publish, operate, and persist the state of a tenant-owned game. | Durable game behavior and customer-requested persistence require server-side state. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `authorized_tenant_member` | `tenant_scoped` | yes | Game grants and ancestry constrain creator reads and exports. |
| `game_runtime_service` | `service_internal` | no | A runtime lease reads only its admitted game and version coordinates. |
### machine_and_service_account_identity

| Field | Value |
| --- | --- |
| Display name | Machine and service account identity |
| Sensitivity | `restricted_security` |
| Subjects | `organization`, `workspace`, `game`, `service` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `machine_principal` | Attribute automated actions to a named, scoped, revocable non-human principal. | Automation must not borrow human identity or ambient process authority. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `authorized_tenant_member` | `tenant_scoped` | yes | Administrators with credential-management grants receive non-secret service-account metadata. |
| `platform_security_service` | `metadata_only` | no | Security services receive identity, owner scope, grants, and status. |
### mfa_passkey_and_recovery_metadata

| Field | Value |
| --- | --- |
| Display name | MFA, passkey, and recovery metadata |
| Sensitivity | `restricted_security` |
| Subjects | `account` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `factor_assurance` | Authenticate the account, calculate assurance, detect cloned authenticators, and recover access. | Strong authentication requires public verification state and controlled recovery metadata. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `credential_verifier` | `service_internal` | no | The factor verifier reads public verification and lifecycle state for a live challenge. |
| `account_owner` | `metadata_only` | yes | The authenticated account receives factor labels, dates, and status but no verification secrets. |
| `support_operator` | `redacted` | no | A recovery case exposes factor type and status only after elevated authorization. |
### network_and_client_risk_signals

| Field | Value |
| --- | --- |
| Display name | Network and client-derived risk signals |
| Sensitivity | `restricted_security` |
| Subjects | `account`, `service` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `abuse_and_risk` | Detect anomalous access, enforce rate limits, investigate compromise, and trigger proportionate step-up. | Network-level abuse and session theft cannot be mitigated using account identity alone. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `risk_engine` | `service_internal` | no | The risk engine receives bounded signals for active admission and revalidation. |
| `platform_security_service` | `metadata_only` | no | Security operations receives salted hashes, normalized categories, and anomaly history. |
| `account_owner` | `redacted` | no | Session security views expose coarse device and location labels, never raw defensive hashes. |
### organization_identity_and_membership

| Field | Value |
| --- | --- |
| Display name | Organization identity and membership |
| Sensitivity | `confidential_tenant` |
| Subjects | `account`, `organization` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `organization_operation` | Operate tenant ownership, collaboration, policy, and billing boundaries. | Organizations require a stable ownership and membership scope above workspaces. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `authorized_tenant_member` | `tenant_scoped` | yes | Members receive only organization fields allowed by their effective grants. |
| `support_operator` | `redacted` | no | Case-bound support sees organization locator and status, not member security profiles. |
### player_identity_and_gameplay_data

| Field | Value |
| --- | --- |
| Display name | Player identity and gameplay data |
| Sensitivity | `confidential_personal` |
| Subjects | `game`, `player`, `account` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `player_service` | Admit players, operate gameplay, persist requested progress, and enforce game safety controls. | A multiplayer game needs a game-scoped player subject and authoritative progress state. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `game_runtime_service` | `service_internal` | no | An admitted runtime reads only player data for its game and active purpose. |
| `account_owner` | `self_service` | yes | A linked account receives its own exportable player projection. |
| `authorized_tenant_member` | `tenant_scoped` | yes | Creators receive game-scoped operational projections, never platform-account security data. |
### provider_credentials_and_secrets

| Field | Value |
| --- | --- |
| Display name | Provider credentials and integration secrets |
| Sensitivity | `restricted_secret` |
| Subjects | `organization`, `workspace`, `game`, `service`, `provider` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `provider_access` | Authenticate the platform to a configured external provider for an explicitly authorized integration. | Provider operations require revocable credentials without exposing them to feature code or users. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `provider_integration_service` | `service_internal` | no | Only the named provider adapter receives decrypted material for a bounded outbound operation. |
| `platform_security_service` | `metadata_only` | no | Security services receive credential identifiers, owner scope, age, and status only. |
### provider_payload_samples

| Field | Value |
| --- | --- |
| Display name | Transient provider verification payloads |
| Sensitivity | `restricted_secret` |
| Subjects | `account`, `organization`, `service`, `provider` |
| Retention mode | `transient_verification` |
| Retention policy | security_governance / `raw-provider-evidence-transient-only` |
| Retention detail | maxProcessingSeconds: 300<br>persistedRepresentation: Only a digest, verifier, policy ID, verification time, and bounded normalized claims may persist. |
| Deletion mode | `release_transient_memory` |
| Deletion trigger | Verification completion or process termination releases raw payload memory; this payload is never a durable record. |
| Deletion execution owner | security_operations |
| Deletion verification | The governance gate forbids durable raw-payload readers and persistence contracts. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `provider_verification` | Verify a single callback, identity assertion, or device attestation and derive bounded claims. | Cryptographic verification requires the original signed representation for the duration of one transaction. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `credential_verifier` | `service_internal` | no | Only the verifier handling the current transaction may read the raw payload. |
| `provider_integration_service` | `service_internal` | no | Only the named callback adapter may parse its provider payload during verification. |
### runtime_session_and_replication_data

| Field | Value |
| --- | --- |
| Display name | Runtime session and replication data |
| Sensitivity | `confidential_tenant` |
| Subjects | `game`, `player`, `service` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `runtime_delivery` | Operate live rooms, synchronize admitted players, recover connections, and diagnose runtime incidents. | Authoritative multiplayer operation requires short-lived shared state and sequencing data. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `game_runtime_service` | `service_internal` | no | Runtime workers read only active leases and game-scoped state assigned to them. |
| `authorized_tenant_member` | `tenant_scoped` | yes | Creators receive bounded operational and debugging projections for their game. |
| `incident_responder` | `incident_scoped` | no | A runtime incident permits bounded replay inspection under elevated authorization. |
### security_decisions_and_events

| Field | Value |
| --- | --- |
| Display name | Security decisions and normalized events |
| Sensitivity | `restricted_security` |
| Subjects | `account`, `administrator`, `organization`, `workspace`, `game`, `player`, `service` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `security_observability` | Explain authorization outcomes, detect attacks, alert responders, and verify policy behavior. | A gated platform requires accountable evidence of deny, anomaly, and sampled allow decisions. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `platform_security_service` | `service_internal` | no | Detection and response services read bounded normalized events. |
| `incident_responder` | `incident_scoped` | no | A named incident and elevated session permit event investigation. |
| `security_auditor` | `redacted` | yes | Audits receive policy, outcome, and scoped actor/resource projections. |
### server_operational_errors

| Field | Value |
| --- | --- |
| Display name | Server operational errors |
| Sensitivity | `restricted_security` |
| Subjects | `account`, `organization`, `workspace`, `game`, `service` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `service_reliability` | Detect, diagnose, and remediate platform failures and security-relevant anomalies. | Operators require bounded server context to restore service and investigate exploitation attempts. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `platform_security_service` | `service_internal` | no | Automated detection consumes normalized severity, fingerprint, and route context. |
| `incident_responder` | `incident_scoped` | no | Assigned incidents permit bounded diagnostic inspection. |
| `support_operator` | `redacted` | no | Customer support receives public error codes and correlation IDs, not internal stacks. |
### session_and_refresh_credentials

| Field | Value |
| --- | --- |
| Display name | Session and refresh credential material |
| Sensitivity | `restricted_secret` |
| Subjects | `account`, `service` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `session_continuity` | Maintain authenticated continuity, rotate refresh credentials, and revoke compromised credential families. | Usable customer sessions require short-lived authentication continuity without repeated primary login. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `credential_verifier` | `service_internal` | no | Only session and refresh verification paths read credential hashes or protected material. |
| `platform_security_service` | `metadata_only` | no | Security services receive credential IDs, family, assurance, expiry, and revocation status only. |
### support_case_data

| Field | Value |
| --- | --- |
| Display name | Customer support case data |
| Sensitivity | `confidential_personal` |
| Subjects | `account`, `organization`, `workspace`, `game` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `customer_support` | Resolve a customer-requested product, account, billing, or security issue. | Support requires limited issue context and an accountable communication record. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `support_operator` | `incident_scoped` | no | Assignment, current case purpose, and support permission are required. |
| `account_owner` | `self_service` | yes | The authenticated requester receives their case history and exportable submissions. |
| `privacy_operator` | `redacted` | yes | Privacy requests receive subject-scoped support records. |
### user_authentication_secrets

| Field | Value |
| --- | --- |
| Display name | User authentication secret verifiers |
| Sensitivity | `restricted_secret` |
| Subjects | `account` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `primary_authentication` | Verify a user's proof of knowledge during authentication or controlled recovery. | Accounts without an enrolled phishing-resistant factor require a protected primary authentication method. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `credential_verifier` | `service_internal` | no | Only constant-behavior verification code receives the stored verifier. |
| `platform_security_service` | `metadata_only` | no | Security services receive algorithm, age, and compromise status without verifier bytes. |
### workspace_identity_and_membership

| Field | Value |
| --- | --- |
| Display name | Workspace identity and membership |
| Sensitivity | `confidential_tenant` |
| Subjects | `account`, `organization`, `workspace` |
| Retention mode | `permanent_records` |
| Retention policy | data_policy / `PERMANENT_RECORD_POLICY` |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | `soft_delete` |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |

Authorized purposes:

| Purpose | Statement | Necessity |
| --- | --- | --- |
| `workspace_operation` | Organize tenant resources and authorize scoped collaboration below an organization. | Workspaces are the canonical collaboration and resource-ownership boundary for creator operations. |

Permitted readers:

| Reader | Projection | Export allowed | Conditions |
| --- | --- | --- | --- |
| `authorized_tenant_member` | `tenant_scoped` | yes | Effective workspace or ancestor grants constrain every projection. |
| `support_operator` | `redacted` | no | Case-bound support receives workspace locator and status only. |
