Security Data Class Registry
docs/security-data-class-registry.json.This generated snapshot is derived from the security data class ledger at docs/security-data-class-registry.json, which is itself generated from server/src/modules/security-governance/dataClassRegistry.ts. Each class records its sensitivity tier, authorized purposes, permitted readers, retention rule, and deletion rule.
Data class count: 25. Registry schema version: 1.
Sensitivity tiers
| Sensitivity | Class count |
|---|---|
confidential_personal | 7 |
confidential_tenant | 5 |
restricted_secret | 5 |
restricted_security | 8 |
Data classes
| Class | Description | Sensitivity | Subjects | Purpose | Readers | Retention | Deletion |
|---|---|---|---|---|---|---|---|
account_contact_email | Account contact email | confidential_personal | account | Deliver authentication, recovery, security, and required account notices. | account_owner, support_operator, platform_security_service | permanent_records | soft_delete |
account_contact_phone | Account contact phone | confidential_personal | account | Deliver opted-in authentication and account-security challenges. | account_owner, credential_verifier, support_operator | permanent_records | soft_delete |
account_identity | Platform account identity | confidential_personal | account | Identify the account, enforce lifecycle state, and present the account-owned profile. | account_owner, authorized_tenant_member, support_operator | permanent_records | soft_delete |
admin_case_annotations | Administrative case annotations | restricted_security | account, administrator, organization, workspace, game, player | Coordinate a named security, privacy, fraud, or safety investigation. | incident_responder, security_auditor, privacy_operator | permanent_records | soft_delete |
api_and_capability_credentials | API key and capability credential material | restricted_secret | account, service | Authenticate a named machine actor and authorize explicit scopes and resources. | credential_verifier, platform_security_service | permanent_records | soft_delete |
audit_and_incident_evidence | Immutable audit and incident evidence | restricted_security | account, administrator, organization, workspace, game, service | Investigate security events, prove control actions, and satisfy accountable audit obligations. | incident_responder, security_auditor, privacy_operator | permanent_evidence | retain_immutable_evidence |
billing_and_payment_metadata | Billing and payment metadata | confidential_personal | account, organization, provider | Price, charge, reconcile, refund, dispute, and support purchased services. | billing_service, account_owner, support_operator | permanent_records | soft_delete |
client_telemetry_and_error_samples | Client telemetry and scrubbed error samples | confidential_personal | account, workspace, game, player | Diagnose release regressions, crashes, and abuse of client-facing surfaces. | platform_security_service, support_operator, incident_responder | permanent_records | soft_delete |
creator_asset_content | Creator assets and authored content | confidential_tenant | account, organization, workspace, game | Store, transform, collaborate on, publish, and deliver creator-authorized content. | authorized_tenant_member, game_runtime_service, support_operator | permanent_records | soft_delete |
device_binding_and_attestation | Verified device binding and attestation metadata | restricted_security | account, service, provider | Bind sessions and high-risk requests to a verified device key and current attestation policy. | credential_verifier, risk_engine, platform_security_service | permanent_records | soft_delete |
game_configuration_and_state | Game configuration and durable state | confidential_tenant | organization, workspace, game, player | Configure, publish, operate, and persist the state of a tenant-owned game. | authorized_tenant_member, game_runtime_service | permanent_records | soft_delete |
machine_and_service_account_identity | Machine and service account identity | restricted_security | organization, workspace, game, service | Attribute automated actions to a named, scoped, revocable non-human principal. | authorized_tenant_member, platform_security_service | permanent_records | soft_delete |
mfa_passkey_and_recovery_metadata | MFA, passkey, and recovery metadata | restricted_security | account | Authenticate the account, calculate assurance, detect cloned authenticators, and recover access. | credential_verifier, account_owner, support_operator | permanent_records | soft_delete |
network_and_client_risk_signals | Network and client-derived risk signals | restricted_security | account, service | Detect anomalous access, enforce rate limits, investigate compromise, and trigger proportionate step-up. | risk_engine, platform_security_service, account_owner | permanent_records | soft_delete |
organization_identity_and_membership | Organization identity and membership | confidential_tenant | account, organization | Operate tenant ownership, collaboration, policy, and billing boundaries. | authorized_tenant_member, support_operator | permanent_records | soft_delete |
player_identity_and_gameplay_data | Player identity and gameplay data | confidential_personal | game, player, account | Admit players, operate gameplay, persist requested progress, and enforce game safety controls. | game_runtime_service, account_owner, authorized_tenant_member | permanent_records | soft_delete |
provider_credentials_and_secrets | Provider credentials and integration secrets | restricted_secret | organization, workspace, game, service, provider | Authenticate the platform to a configured external provider for an explicitly authorized integration. | provider_integration_service, platform_security_service | permanent_records | soft_delete |
provider_payload_samples | Transient provider verification payloads | restricted_secret | account, organization, service, provider | Verify a single callback, identity assertion, or device attestation and derive bounded claims. | credential_verifier, provider_integration_service | transient_verification | release_transient_memory |
runtime_session_and_replication_data | Runtime session and replication data | confidential_tenant | game, player, service | Operate live rooms, synchronize admitted players, recover connections, and diagnose runtime incidents. | game_runtime_service, authorized_tenant_member, incident_responder | permanent_records | soft_delete |
security_decisions_and_events | Security decisions and normalized events | restricted_security | account, administrator, organization, workspace, game, player, service | Explain authorization outcomes, detect attacks, alert responders, and verify policy behavior. | platform_security_service, incident_responder, security_auditor | permanent_records | soft_delete |
server_operational_errors | Server operational errors | restricted_security | account, organization, workspace, game, service | Detect, diagnose, and remediate platform failures and security-relevant anomalies. | platform_security_service, incident_responder, support_operator | permanent_records | soft_delete |
session_and_refresh_credentials | Session and refresh credential material | restricted_secret | account, service | Maintain authenticated continuity, rotate refresh credentials, and revoke compromised credential families. | credential_verifier, platform_security_service | permanent_records | soft_delete |
support_case_data | Customer support case data | confidential_personal | account, organization, workspace, game | Resolve a customer-requested product, account, billing, or security issue. | support_operator, account_owner, privacy_operator | permanent_records | soft_delete |
user_authentication_secrets | User authentication secret verifiers | restricted_secret | account | Verify a user's proof of knowledge during authentication or controlled recovery. | credential_verifier, platform_security_service | permanent_records | soft_delete |
workspace_identity_and_membership | Workspace identity and membership | confidential_tenant | account, organization, workspace | Organize tenant resources and authorize scoped collaboration below an organization. | authorized_tenant_member, support_operator | permanent_records | soft_delete |
Class details
account_contact_email
| Field | Value |
|---|---|
| Display name | Account contact email |
| Sensitivity | confidential_personal |
| Subjects | account |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
account_contact | Deliver authentication, recovery, security, and required account notices. | An authenticated account needs one verified recovery and security-notification channel. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
account_owner | self_service | yes | Only the authenticated subject receives the normalized address. |
support_operator | redacted | no | Step-up and a support case expose only a masked address. |
platform_security_service | service_internal | no | Delivery and compromise-response services receive the address for a named event. |
account_contact_phone
| Field | Value |
|---|---|
| Display name | Account contact phone |
| Sensitivity | confidential_personal |
| Subjects | account |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
phone_factor | Deliver opted-in authentication and account-security challenges. | The number is collected only when the account chooses a phone-backed factor. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
account_owner | self_service | yes | Only the authenticated subject receives a masked or self-service projection. |
credential_verifier | service_internal | no | The factor service reads the normalized destination for a live challenge. |
support_operator | redacted | no | Step-up and an active support case expose only the final digits. |
account_identity
| Field | Value |
|---|---|
| Display name | Platform account identity |
| Sensitivity | confidential_personal |
| Subjects | account |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
account_operation | Identify the account, enforce lifecycle state, and present the account-owned profile. | A stable platform subject is required to bind credentials, grants, billing, and resources. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
account_owner | self_service | yes | The authenticated account receives its own profile projection. |
authorized_tenant_member | tenant_scoped | no | Members receive only collaboration-safe identity fields in a shared tenant. |
support_operator | redacted | no | Case-bound access exposes the minimum account locator and state. |
admin_case_annotations
| Field | Value |
|---|---|
| Display name | Administrative case annotations |
| Sensitivity | restricted_security |
| Subjects | account, administrator, organization, workspace, game, player |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
case_coordination | Coordinate a named security, privacy, fraud, or safety investigation. | Responders need bounded context and decisions that are not representable as automated event fields. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
incident_responder | incident_scoped | no | An assigned case and current elevated authorization are required. |
security_auditor | redacted | no | Audit review receives immutable author and decision history with subject data minimized. |
privacy_operator | incident_scoped | no | Privacy cases expose only annotations necessary for the data-subject request. |
api_and_capability_credentials
| Field | Value |
|---|---|
| Display name | API key and capability credential material |
| Sensitivity | restricted_secret |
| Subjects | account, service |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
machine_authentication | Authenticate a named machine actor and authorize explicit scopes and resources. | Non-browser automation requires a revocable credential with least-privilege scope. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
credential_verifier | service_internal | no | Only the verifier reads hashes or encrypted token material during issuance and verification. |
platform_security_service | metadata_only | no | Security services receive identifiers, scopes, and status but never plaintext secret material. |
audit_and_incident_evidence
| Field | Value |
|---|---|
| Display name | Immutable audit and incident evidence |
| Sensitivity | restricted_security |
| Subjects | account, administrator, organization, workspace, game, service |
| Retention mode | permanent_evidence |
| Retention policy | data_policy / PERMANENT_SECURITY_EVIDENCE |
| Retention detail | justification: Containment and forensic evidence is immutable because later compromise review must survive mutable control state. |
| Deletion mode | retain_immutable_evidence |
| Deletion trigger | Deletion is prohibited except through an explicit legal and security policy migration. |
| Deletion execution owner | security_operations |
| Deletion verification | Append-only triggers, chain verification, and archive manifests continuously prove integrity. |
| Data-subject request | not_applicable_security_evidence |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
incident_evidence | Investigate security events, prove control actions, and satisfy accountable audit obligations. | Critical containment and operator actions require durable tamper-evident evidence. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
incident_responder | incident_scoped | no | A named incident, elevated session, and audited query are required. |
security_auditor | redacted | yes | Approved audits receive bounded immutable evidence projections. |
privacy_operator | redacted | yes | Privacy review receives only subject-relevant evidence permitted by law. |
billing_and_payment_metadata
| Field | Value |
|---|---|
| Display name | Billing and payment metadata |
| Sensitivity | confidential_personal |
| Subjects | account, organization, provider |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
billing_operation | Price, charge, reconcile, refund, dispute, and support purchased services. | Commercial service delivery requires an auditable account-to-provider billing relation. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
billing_service | service_internal | no | Billing services read provider references and state for a named transaction. |
account_owner | self_service | yes | The payer receives a PCI-minimized invoice and subscription projection. |
support_operator | redacted | no | Case-bound billing support sees masked payment metadata and transaction state. |
client_telemetry_and_error_samples
| Field | Value |
|---|---|
| Display name | Client telemetry and scrubbed error samples |
| Sensitivity | confidential_personal |
| Subjects | account, workspace, game, player |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
client_reliability | Diagnose release regressions, crashes, and abuse of client-facing surfaces. | Bounded failure context is necessary to restore customer workflows and identify attack patterns. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
platform_security_service | service_internal | no | Automated triage reads scrubbed fields and aggregate fingerprints. |
support_operator | redacted | no | A customer case may expose a scrubbed sample tied to that case. |
incident_responder | incident_scoped | no | Security incidents may inspect bounded samples under elevated authorization. |
creator_asset_content
| Field | Value |
|---|---|
| Display name | Creator assets and authored content |
| Sensitivity | confidential_tenant |
| Subjects | account, organization, workspace, game |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
content_operation | Store, transform, collaborate on, publish, and deliver creator-authorized content. | The product cannot provide creation and publishing without retaining the customer's authored resources. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
authorized_tenant_member | tenant_scoped | yes | Canonical grants and resource ancestry constrain reads to the owning tenant. |
game_runtime_service | service_internal | no | Only published or explicitly preview-authorized content is delivered to a game runtime. |
support_operator | redacted | no | Support receives metadata unless a case-specific customer grant authorizes content inspection. |
device_binding_and_attestation
| Field | Value |
|---|---|
| Display name | Verified device binding and attestation metadata |
| Sensitivity | restricted_security |
| Subjects | account, service, provider |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
device_assurance | Bind sessions and high-risk requests to a verified device key and current attestation policy. | Device-bound proof reduces replay and distinguishes possession from a caller-supplied client label. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
credential_verifier | service_internal | no | Proof verification reads public keys, counters, and current trust state. |
risk_engine | metadata_only | no | Risk evaluation receives normalized trust tier and freshness, not raw evidence. |
platform_security_service | metadata_only | no | Security operations receives key identifiers, trust history, and revocation state. |
game_configuration_and_state
| Field | Value |
|---|---|
| Display name | Game configuration and durable state |
| Sensitivity | confidential_tenant |
| Subjects | organization, workspace, game, player |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
game_operation | Configure, publish, operate, and persist the state of a tenant-owned game. | Durable game behavior and customer-requested persistence require server-side state. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
authorized_tenant_member | tenant_scoped | yes | Game grants and ancestry constrain creator reads and exports. |
game_runtime_service | service_internal | no | A runtime lease reads only its admitted game and version coordinates. |
machine_and_service_account_identity
| Field | Value |
|---|---|
| Display name | Machine and service account identity |
| Sensitivity | restricted_security |
| Subjects | organization, workspace, game, service |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
machine_principal | Attribute automated actions to a named, scoped, revocable non-human principal. | Automation must not borrow human identity or ambient process authority. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
authorized_tenant_member | tenant_scoped | yes | Administrators with credential-management grants receive non-secret service-account metadata. |
platform_security_service | metadata_only | no | Security services receive identity, owner scope, grants, and status. |
mfa_passkey_and_recovery_metadata
| Field | Value |
|---|---|
| Display name | MFA, passkey, and recovery metadata |
| Sensitivity | restricted_security |
| Subjects | account |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
factor_assurance | Authenticate the account, calculate assurance, detect cloned authenticators, and recover access. | Strong authentication requires public verification state and controlled recovery metadata. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
credential_verifier | service_internal | no | The factor verifier reads public verification and lifecycle state for a live challenge. |
account_owner | metadata_only | yes | The authenticated account receives factor labels, dates, and status but no verification secrets. |
support_operator | redacted | no | A recovery case exposes factor type and status only after elevated authorization. |
network_and_client_risk_signals
| Field | Value |
|---|---|
| Display name | Network and client-derived risk signals |
| Sensitivity | restricted_security |
| Subjects | account, service |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
abuse_and_risk | Detect anomalous access, enforce rate limits, investigate compromise, and trigger proportionate step-up. | Network-level abuse and session theft cannot be mitigated using account identity alone. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
risk_engine | service_internal | no | The risk engine receives bounded signals for active admission and revalidation. |
platform_security_service | metadata_only | no | Security operations receives salted hashes, normalized categories, and anomaly history. |
account_owner | redacted | no | Session security views expose coarse device and location labels, never raw defensive hashes. |
organization_identity_and_membership
| Field | Value |
|---|---|
| Display name | Organization identity and membership |
| Sensitivity | confidential_tenant |
| Subjects | account, organization |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
organization_operation | Operate tenant ownership, collaboration, policy, and billing boundaries. | Organizations require a stable ownership and membership scope above workspaces. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
authorized_tenant_member | tenant_scoped | yes | Members receive only organization fields allowed by their effective grants. |
support_operator | redacted | no | Case-bound support sees organization locator and status, not member security profiles. |
player_identity_and_gameplay_data
| Field | Value |
|---|---|
| Display name | Player identity and gameplay data |
| Sensitivity | confidential_personal |
| Subjects | game, player, account |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
player_service | Admit players, operate gameplay, persist requested progress, and enforce game safety controls. | A multiplayer game needs a game-scoped player subject and authoritative progress state. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
game_runtime_service | service_internal | no | An admitted runtime reads only player data for its game and active purpose. |
account_owner | self_service | yes | A linked account receives its own exportable player projection. |
authorized_tenant_member | tenant_scoped | yes | Creators receive game-scoped operational projections, never platform-account security data. |
provider_credentials_and_secrets
| Field | Value |
|---|---|
| Display name | Provider credentials and integration secrets |
| Sensitivity | restricted_secret |
| Subjects | organization, workspace, game, service, provider |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
provider_access | Authenticate the platform to a configured external provider for an explicitly authorized integration. | Provider operations require revocable credentials without exposing them to feature code or users. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
provider_integration_service | service_internal | no | Only the named provider adapter receives decrypted material for a bounded outbound operation. |
platform_security_service | metadata_only | no | Security services receive credential identifiers, owner scope, age, and status only. |
provider_payload_samples
| Field | Value |
|---|---|
| Display name | Transient provider verification payloads |
| Sensitivity | restricted_secret |
| Subjects | account, organization, service, provider |
| Retention mode | transient_verification |
| Retention policy | security_governance / raw-provider-evidence-transient-only |
| Retention detail | maxProcessingSeconds: 300<br>persistedRepresentation: Only a digest, verifier, policy ID, verification time, and bounded normalized claims may persist. |
| Deletion mode | release_transient_memory |
| Deletion trigger | Verification completion or process termination releases raw payload memory; this payload is never a durable record. |
| Deletion execution owner | security_operations |
| Deletion verification | The governance gate forbids durable raw-payload readers and persistence contracts. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
provider_verification | Verify a single callback, identity assertion, or device attestation and derive bounded claims. | Cryptographic verification requires the original signed representation for the duration of one transaction. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
credential_verifier | service_internal | no | Only the verifier handling the current transaction may read the raw payload. |
provider_integration_service | service_internal | no | Only the named callback adapter may parse its provider payload during verification. |
runtime_session_and_replication_data
| Field | Value |
|---|---|
| Display name | Runtime session and replication data |
| Sensitivity | confidential_tenant |
| Subjects | game, player, service |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
runtime_delivery | Operate live rooms, synchronize admitted players, recover connections, and diagnose runtime incidents. | Authoritative multiplayer operation requires short-lived shared state and sequencing data. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
game_runtime_service | service_internal | no | Runtime workers read only active leases and game-scoped state assigned to them. |
authorized_tenant_member | tenant_scoped | yes | Creators receive bounded operational and debugging projections for their game. |
incident_responder | incident_scoped | no | A runtime incident permits bounded replay inspection under elevated authorization. |
security_decisions_and_events
| Field | Value |
|---|---|
| Display name | Security decisions and normalized events |
| Sensitivity | restricted_security |
| Subjects | account, administrator, organization, workspace, game, player, service |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
security_observability | Explain authorization outcomes, detect attacks, alert responders, and verify policy behavior. | A gated platform requires accountable evidence of deny, anomaly, and sampled allow decisions. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
platform_security_service | service_internal | no | Detection and response services read bounded normalized events. |
incident_responder | incident_scoped | no | A named incident and elevated session permit event investigation. |
security_auditor | redacted | yes | Audits receive policy, outcome, and scoped actor/resource projections. |
server_operational_errors
| Field | Value |
|---|---|
| Display name | Server operational errors |
| Sensitivity | restricted_security |
| Subjects | account, organization, workspace, game, service |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
service_reliability | Detect, diagnose, and remediate platform failures and security-relevant anomalies. | Operators require bounded server context to restore service and investigate exploitation attempts. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
platform_security_service | service_internal | no | Automated detection consumes normalized severity, fingerprint, and route context. |
incident_responder | incident_scoped | no | Assigned incidents permit bounded diagnostic inspection. |
support_operator | redacted | no | Customer support receives public error codes and correlation IDs, not internal stacks. |
session_and_refresh_credentials
| Field | Value |
|---|---|
| Display name | Session and refresh credential material |
| Sensitivity | restricted_secret |
| Subjects | account, service |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
session_continuity | Maintain authenticated continuity, rotate refresh credentials, and revoke compromised credential families. | Usable customer sessions require short-lived authentication continuity without repeated primary login. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
credential_verifier | service_internal | no | Only session and refresh verification paths read credential hashes or protected material. |
platform_security_service | metadata_only | no | Security services receive credential IDs, family, assurance, expiry, and revocation status only. |
support_case_data
| Field | Value |
|---|---|
| Display name | Customer support case data |
| Sensitivity | confidential_personal |
| Subjects | account, organization, workspace, game |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
customer_support | Resolve a customer-requested product, account, billing, or security issue. | Support requires limited issue context and an accountable communication record. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
support_operator | incident_scoped | no | Assignment, current case purpose, and support permission are required. |
account_owner | self_service | yes | The authenticated requester receives their case history and exportable submissions. |
privacy_operator | redacted | yes | Privacy requests receive subject-scoped support records. |
user_authentication_secrets
| Field | Value |
|---|---|
| Display name | User authentication secret verifiers |
| Sensitivity | restricted_secret |
| Subjects | account |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
primary_authentication | Verify a user's proof of knowledge during authentication or controlled recovery. | Accounts without an enrolled phishing-resistant factor require a protected primary authentication method. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
credential_verifier | service_internal | no | Only constant-behavior verification code receives the stored verifier. |
platform_security_service | metadata_only | no | Security services receive algorithm, age, and compromise status without verifier bytes. |
workspace_identity_and_membership
| Field | Value |
|---|---|
| Display name | Workspace identity and membership |
| Sensitivity | confidential_tenant |
| Subjects | account, organization, workspace |
| Retention mode | permanent_records |
| Retention policy | data_policy / PERMANENT_RECORD_POLICY |
| Retention detail | justification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion. |
| Deletion mode | soft_delete |
| Deletion trigger | An authorized lifecycle transition ends active access without removing the durable record. |
| Deletion execution owner | resource_lifecycle |
| Deletion verification | Database destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification. |
| Data-subject request | soft_delete_only |
| Legal hold | does_not_apply |
Authorized purposes:
| Purpose | Statement | Necessity |
|---|---|---|
workspace_operation | Organize tenant resources and authorize scoped collaboration below an organization. | Workspaces are the canonical collaboration and resource-ownership boundary for creator operations. |
Permitted readers:
| Reader | Projection | Export allowed | Conditions |
|---|---|---|---|
authorized_tenant_member | tenant_scoped | yes | Effective workspace or ancestor grants constrain every projection. |
support_operator | redacted | no | Case-bound support receives workspace locator and status only. |