Gessa Docs
Generated Reference

Reference

Security Data Class Registry

Sources: docs/security-data-class-registry.json.
engine v1.0.234Copy for LLM

This generated snapshot is derived from the security data class ledger at docs/security-data-class-registry.json, which is itself generated from server/src/modules/security-governance/dataClassRegistry.ts. Each class records its sensitivity tier, authorized purposes, permitted readers, retention rule, and deletion rule.

Data class count: 25. Registry schema version: 1.

Sensitivity tiers

SensitivityClass count
confidential_personal7
confidential_tenant5
restricted_secret5
restricted_security8

Data classes

ClassDescriptionSensitivitySubjectsPurposeReadersRetentionDeletion
account_contact_emailAccount contact emailconfidential_personalaccountDeliver authentication, recovery, security, and required account notices.account_owner, support_operator, platform_security_servicepermanent_recordssoft_delete
account_contact_phoneAccount contact phoneconfidential_personalaccountDeliver opted-in authentication and account-security challenges.account_owner, credential_verifier, support_operatorpermanent_recordssoft_delete
account_identityPlatform account identityconfidential_personalaccountIdentify the account, enforce lifecycle state, and present the account-owned profile.account_owner, authorized_tenant_member, support_operatorpermanent_recordssoft_delete
admin_case_annotationsAdministrative case annotationsrestricted_securityaccount, administrator, organization, workspace, game, playerCoordinate a named security, privacy, fraud, or safety investigation.incident_responder, security_auditor, privacy_operatorpermanent_recordssoft_delete
api_and_capability_credentialsAPI key and capability credential materialrestricted_secretaccount, serviceAuthenticate a named machine actor and authorize explicit scopes and resources.credential_verifier, platform_security_servicepermanent_recordssoft_delete
audit_and_incident_evidenceImmutable audit and incident evidencerestricted_securityaccount, administrator, organization, workspace, game, serviceInvestigate security events, prove control actions, and satisfy accountable audit obligations.incident_responder, security_auditor, privacy_operatorpermanent_evidenceretain_immutable_evidence
billing_and_payment_metadataBilling and payment metadataconfidential_personalaccount, organization, providerPrice, charge, reconcile, refund, dispute, and support purchased services.billing_service, account_owner, support_operatorpermanent_recordssoft_delete
client_telemetry_and_error_samplesClient telemetry and scrubbed error samplesconfidential_personalaccount, workspace, game, playerDiagnose release regressions, crashes, and abuse of client-facing surfaces.platform_security_service, support_operator, incident_responderpermanent_recordssoft_delete
creator_asset_contentCreator assets and authored contentconfidential_tenantaccount, organization, workspace, gameStore, transform, collaborate on, publish, and deliver creator-authorized content.authorized_tenant_member, game_runtime_service, support_operatorpermanent_recordssoft_delete
device_binding_and_attestationVerified device binding and attestation metadatarestricted_securityaccount, service, providerBind sessions and high-risk requests to a verified device key and current attestation policy.credential_verifier, risk_engine, platform_security_servicepermanent_recordssoft_delete
game_configuration_and_stateGame configuration and durable stateconfidential_tenantorganization, workspace, game, playerConfigure, publish, operate, and persist the state of a tenant-owned game.authorized_tenant_member, game_runtime_servicepermanent_recordssoft_delete
machine_and_service_account_identityMachine and service account identityrestricted_securityorganization, workspace, game, serviceAttribute automated actions to a named, scoped, revocable non-human principal.authorized_tenant_member, platform_security_servicepermanent_recordssoft_delete
mfa_passkey_and_recovery_metadataMFA, passkey, and recovery metadatarestricted_securityaccountAuthenticate the account, calculate assurance, detect cloned authenticators, and recover access.credential_verifier, account_owner, support_operatorpermanent_recordssoft_delete
network_and_client_risk_signalsNetwork and client-derived risk signalsrestricted_securityaccount, serviceDetect anomalous access, enforce rate limits, investigate compromise, and trigger proportionate step-up.risk_engine, platform_security_service, account_ownerpermanent_recordssoft_delete
organization_identity_and_membershipOrganization identity and membershipconfidential_tenantaccount, organizationOperate tenant ownership, collaboration, policy, and billing boundaries.authorized_tenant_member, support_operatorpermanent_recordssoft_delete
player_identity_and_gameplay_dataPlayer identity and gameplay dataconfidential_personalgame, player, accountAdmit players, operate gameplay, persist requested progress, and enforce game safety controls.game_runtime_service, account_owner, authorized_tenant_memberpermanent_recordssoft_delete
provider_credentials_and_secretsProvider credentials and integration secretsrestricted_secretorganization, workspace, game, service, providerAuthenticate the platform to a configured external provider for an explicitly authorized integration.provider_integration_service, platform_security_servicepermanent_recordssoft_delete
provider_payload_samplesTransient provider verification payloadsrestricted_secretaccount, organization, service, providerVerify a single callback, identity assertion, or device attestation and derive bounded claims.credential_verifier, provider_integration_servicetransient_verificationrelease_transient_memory
runtime_session_and_replication_dataRuntime session and replication dataconfidential_tenantgame, player, serviceOperate live rooms, synchronize admitted players, recover connections, and diagnose runtime incidents.game_runtime_service, authorized_tenant_member, incident_responderpermanent_recordssoft_delete
security_decisions_and_eventsSecurity decisions and normalized eventsrestricted_securityaccount, administrator, organization, workspace, game, player, serviceExplain authorization outcomes, detect attacks, alert responders, and verify policy behavior.platform_security_service, incident_responder, security_auditorpermanent_recordssoft_delete
server_operational_errorsServer operational errorsrestricted_securityaccount, organization, workspace, game, serviceDetect, diagnose, and remediate platform failures and security-relevant anomalies.platform_security_service, incident_responder, support_operatorpermanent_recordssoft_delete
session_and_refresh_credentialsSession and refresh credential materialrestricted_secretaccount, serviceMaintain authenticated continuity, rotate refresh credentials, and revoke compromised credential families.credential_verifier, platform_security_servicepermanent_recordssoft_delete
support_case_dataCustomer support case dataconfidential_personalaccount, organization, workspace, gameResolve a customer-requested product, account, billing, or security issue.support_operator, account_owner, privacy_operatorpermanent_recordssoft_delete
user_authentication_secretsUser authentication secret verifiersrestricted_secretaccountVerify a user's proof of knowledge during authentication or controlled recovery.credential_verifier, platform_security_servicepermanent_recordssoft_delete
workspace_identity_and_membershipWorkspace identity and membershipconfidential_tenantaccount, organization, workspaceOrganize tenant resources and authorize scoped collaboration below an organization.authorized_tenant_member, support_operatorpermanent_recordssoft_delete

Class details

account_contact_email

FieldValue
Display nameAccount contact email
Sensitivityconfidential_personal
Subjectsaccount
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
account_contactDeliver authentication, recovery, security, and required account notices.An authenticated account needs one verified recovery and security-notification channel.

Permitted readers:

ReaderProjectionExport allowedConditions
account_ownerself_serviceyesOnly the authenticated subject receives the normalized address.
support_operatorredactednoStep-up and a support case expose only a masked address.
platform_security_serviceservice_internalnoDelivery and compromise-response services receive the address for a named event.

account_contact_phone

FieldValue
Display nameAccount contact phone
Sensitivityconfidential_personal
Subjectsaccount
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
phone_factorDeliver opted-in authentication and account-security challenges.The number is collected only when the account chooses a phone-backed factor.

Permitted readers:

ReaderProjectionExport allowedConditions
account_ownerself_serviceyesOnly the authenticated subject receives a masked or self-service projection.
credential_verifierservice_internalnoThe factor service reads the normalized destination for a live challenge.
support_operatorredactednoStep-up and an active support case expose only the final digits.

account_identity

FieldValue
Display namePlatform account identity
Sensitivityconfidential_personal
Subjectsaccount
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
account_operationIdentify the account, enforce lifecycle state, and present the account-owned profile.A stable platform subject is required to bind credentials, grants, billing, and resources.

Permitted readers:

ReaderProjectionExport allowedConditions
account_ownerself_serviceyesThe authenticated account receives its own profile projection.
authorized_tenant_membertenant_scopednoMembers receive only collaboration-safe identity fields in a shared tenant.
support_operatorredactednoCase-bound access exposes the minimum account locator and state.

admin_case_annotations

FieldValue
Display nameAdministrative case annotations
Sensitivityrestricted_security
Subjectsaccount, administrator, organization, workspace, game, player
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
case_coordinationCoordinate a named security, privacy, fraud, or safety investigation.Responders need bounded context and decisions that are not representable as automated event fields.

Permitted readers:

ReaderProjectionExport allowedConditions
incident_responderincident_scopednoAn assigned case and current elevated authorization are required.
security_auditorredactednoAudit review receives immutable author and decision history with subject data minimized.
privacy_operatorincident_scopednoPrivacy cases expose only annotations necessary for the data-subject request.

api_and_capability_credentials

FieldValue
Display nameAPI key and capability credential material
Sensitivityrestricted_secret
Subjectsaccount, service
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
machine_authenticationAuthenticate a named machine actor and authorize explicit scopes and resources.Non-browser automation requires a revocable credential with least-privilege scope.

Permitted readers:

ReaderProjectionExport allowedConditions
credential_verifierservice_internalnoOnly the verifier reads hashes or encrypted token material during issuance and verification.
platform_security_servicemetadata_onlynoSecurity services receive identifiers, scopes, and status but never plaintext secret material.

audit_and_incident_evidence

FieldValue
Display nameImmutable audit and incident evidence
Sensitivityrestricted_security
Subjectsaccount, administrator, organization, workspace, game, service
Retention modepermanent_evidence
Retention policydata_policy / PERMANENT_SECURITY_EVIDENCE
Retention detailjustification: Containment and forensic evidence is immutable because later compromise review must survive mutable control state.
Deletion moderetain_immutable_evidence
Deletion triggerDeletion is prohibited except through an explicit legal and security policy migration.
Deletion execution ownersecurity_operations
Deletion verificationAppend-only triggers, chain verification, and archive manifests continuously prove integrity.
Data-subject requestnot_applicable_security_evidence
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
incident_evidenceInvestigate security events, prove control actions, and satisfy accountable audit obligations.Critical containment and operator actions require durable tamper-evident evidence.

Permitted readers:

ReaderProjectionExport allowedConditions
incident_responderincident_scopednoA named incident, elevated session, and audited query are required.
security_auditorredactedyesApproved audits receive bounded immutable evidence projections.
privacy_operatorredactedyesPrivacy review receives only subject-relevant evidence permitted by law.

billing_and_payment_metadata

FieldValue
Display nameBilling and payment metadata
Sensitivityconfidential_personal
Subjectsaccount, organization, provider
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
billing_operationPrice, charge, reconcile, refund, dispute, and support purchased services.Commercial service delivery requires an auditable account-to-provider billing relation.

Permitted readers:

ReaderProjectionExport allowedConditions
billing_serviceservice_internalnoBilling services read provider references and state for a named transaction.
account_ownerself_serviceyesThe payer receives a PCI-minimized invoice and subscription projection.
support_operatorredactednoCase-bound billing support sees masked payment metadata and transaction state.

client_telemetry_and_error_samples

FieldValue
Display nameClient telemetry and scrubbed error samples
Sensitivityconfidential_personal
Subjectsaccount, workspace, game, player
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
client_reliabilityDiagnose release regressions, crashes, and abuse of client-facing surfaces.Bounded failure context is necessary to restore customer workflows and identify attack patterns.

Permitted readers:

ReaderProjectionExport allowedConditions
platform_security_serviceservice_internalnoAutomated triage reads scrubbed fields and aggregate fingerprints.
support_operatorredactednoA customer case may expose a scrubbed sample tied to that case.
incident_responderincident_scopednoSecurity incidents may inspect bounded samples under elevated authorization.

creator_asset_content

FieldValue
Display nameCreator assets and authored content
Sensitivityconfidential_tenant
Subjectsaccount, organization, workspace, game
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
content_operationStore, transform, collaborate on, publish, and deliver creator-authorized content.The product cannot provide creation and publishing without retaining the customer's authored resources.

Permitted readers:

ReaderProjectionExport allowedConditions
authorized_tenant_membertenant_scopedyesCanonical grants and resource ancestry constrain reads to the owning tenant.
game_runtime_serviceservice_internalnoOnly published or explicitly preview-authorized content is delivered to a game runtime.
support_operatorredactednoSupport receives metadata unless a case-specific customer grant authorizes content inspection.

device_binding_and_attestation

FieldValue
Display nameVerified device binding and attestation metadata
Sensitivityrestricted_security
Subjectsaccount, service, provider
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
device_assuranceBind sessions and high-risk requests to a verified device key and current attestation policy.Device-bound proof reduces replay and distinguishes possession from a caller-supplied client label.

Permitted readers:

ReaderProjectionExport allowedConditions
credential_verifierservice_internalnoProof verification reads public keys, counters, and current trust state.
risk_enginemetadata_onlynoRisk evaluation receives normalized trust tier and freshness, not raw evidence.
platform_security_servicemetadata_onlynoSecurity operations receives key identifiers, trust history, and revocation state.

game_configuration_and_state

FieldValue
Display nameGame configuration and durable state
Sensitivityconfidential_tenant
Subjectsorganization, workspace, game, player
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
game_operationConfigure, publish, operate, and persist the state of a tenant-owned game.Durable game behavior and customer-requested persistence require server-side state.

Permitted readers:

ReaderProjectionExport allowedConditions
authorized_tenant_membertenant_scopedyesGame grants and ancestry constrain creator reads and exports.
game_runtime_serviceservice_internalnoA runtime lease reads only its admitted game and version coordinates.

machine_and_service_account_identity

FieldValue
Display nameMachine and service account identity
Sensitivityrestricted_security
Subjectsorganization, workspace, game, service
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
machine_principalAttribute automated actions to a named, scoped, revocable non-human principal.Automation must not borrow human identity or ambient process authority.

Permitted readers:

ReaderProjectionExport allowedConditions
authorized_tenant_membertenant_scopedyesAdministrators with credential-management grants receive non-secret service-account metadata.
platform_security_servicemetadata_onlynoSecurity services receive identity, owner scope, grants, and status.

mfa_passkey_and_recovery_metadata

FieldValue
Display nameMFA, passkey, and recovery metadata
Sensitivityrestricted_security
Subjectsaccount
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
factor_assuranceAuthenticate the account, calculate assurance, detect cloned authenticators, and recover access.Strong authentication requires public verification state and controlled recovery metadata.

Permitted readers:

ReaderProjectionExport allowedConditions
credential_verifierservice_internalnoThe factor verifier reads public verification and lifecycle state for a live challenge.
account_ownermetadata_onlyyesThe authenticated account receives factor labels, dates, and status but no verification secrets.
support_operatorredactednoA recovery case exposes factor type and status only after elevated authorization.

network_and_client_risk_signals

FieldValue
Display nameNetwork and client-derived risk signals
Sensitivityrestricted_security
Subjectsaccount, service
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
abuse_and_riskDetect anomalous access, enforce rate limits, investigate compromise, and trigger proportionate step-up.Network-level abuse and session theft cannot be mitigated using account identity alone.

Permitted readers:

ReaderProjectionExport allowedConditions
risk_engineservice_internalnoThe risk engine receives bounded signals for active admission and revalidation.
platform_security_servicemetadata_onlynoSecurity operations receives salted hashes, normalized categories, and anomaly history.
account_ownerredactednoSession security views expose coarse device and location labels, never raw defensive hashes.

organization_identity_and_membership

FieldValue
Display nameOrganization identity and membership
Sensitivityconfidential_tenant
Subjectsaccount, organization
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
organization_operationOperate tenant ownership, collaboration, policy, and billing boundaries.Organizations require a stable ownership and membership scope above workspaces.

Permitted readers:

ReaderProjectionExport allowedConditions
authorized_tenant_membertenant_scopedyesMembers receive only organization fields allowed by their effective grants.
support_operatorredactednoCase-bound support sees organization locator and status, not member security profiles.

player_identity_and_gameplay_data

FieldValue
Display namePlayer identity and gameplay data
Sensitivityconfidential_personal
Subjectsgame, player, account
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
player_serviceAdmit players, operate gameplay, persist requested progress, and enforce game safety controls.A multiplayer game needs a game-scoped player subject and authoritative progress state.

Permitted readers:

ReaderProjectionExport allowedConditions
game_runtime_serviceservice_internalnoAn admitted runtime reads only player data for its game and active purpose.
account_ownerself_serviceyesA linked account receives its own exportable player projection.
authorized_tenant_membertenant_scopedyesCreators receive game-scoped operational projections, never platform-account security data.

provider_credentials_and_secrets

FieldValue
Display nameProvider credentials and integration secrets
Sensitivityrestricted_secret
Subjectsorganization, workspace, game, service, provider
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
provider_accessAuthenticate the platform to a configured external provider for an explicitly authorized integration.Provider operations require revocable credentials without exposing them to feature code or users.

Permitted readers:

ReaderProjectionExport allowedConditions
provider_integration_serviceservice_internalnoOnly the named provider adapter receives decrypted material for a bounded outbound operation.
platform_security_servicemetadata_onlynoSecurity services receive credential identifiers, owner scope, age, and status only.

provider_payload_samples

FieldValue
Display nameTransient provider verification payloads
Sensitivityrestricted_secret
Subjectsaccount, organization, service, provider
Retention modetransient_verification
Retention policysecurity_governance / raw-provider-evidence-transient-only
Retention detailmaxProcessingSeconds: 300<br>persistedRepresentation: Only a digest, verifier, policy ID, verification time, and bounded normalized claims may persist.
Deletion moderelease_transient_memory
Deletion triggerVerification completion or process termination releases raw payload memory; this payload is never a durable record.
Deletion execution ownersecurity_operations
Deletion verificationThe governance gate forbids durable raw-payload readers and persistence contracts.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
provider_verificationVerify a single callback, identity assertion, or device attestation and derive bounded claims.Cryptographic verification requires the original signed representation for the duration of one transaction.

Permitted readers:

ReaderProjectionExport allowedConditions
credential_verifierservice_internalnoOnly the verifier handling the current transaction may read the raw payload.
provider_integration_serviceservice_internalnoOnly the named callback adapter may parse its provider payload during verification.

runtime_session_and_replication_data

FieldValue
Display nameRuntime session and replication data
Sensitivityconfidential_tenant
Subjectsgame, player, service
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
runtime_deliveryOperate live rooms, synchronize admitted players, recover connections, and diagnose runtime incidents.Authoritative multiplayer operation requires short-lived shared state and sequencing data.

Permitted readers:

ReaderProjectionExport allowedConditions
game_runtime_serviceservice_internalnoRuntime workers read only active leases and game-scoped state assigned to them.
authorized_tenant_membertenant_scopedyesCreators receive bounded operational and debugging projections for their game.
incident_responderincident_scopednoA runtime incident permits bounded replay inspection under elevated authorization.

security_decisions_and_events

FieldValue
Display nameSecurity decisions and normalized events
Sensitivityrestricted_security
Subjectsaccount, administrator, organization, workspace, game, player, service
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
security_observabilityExplain authorization outcomes, detect attacks, alert responders, and verify policy behavior.A gated platform requires accountable evidence of deny, anomaly, and sampled allow decisions.

Permitted readers:

ReaderProjectionExport allowedConditions
platform_security_serviceservice_internalnoDetection and response services read bounded normalized events.
incident_responderincident_scopednoA named incident and elevated session permit event investigation.
security_auditorredactedyesAudits receive policy, outcome, and scoped actor/resource projections.

server_operational_errors

FieldValue
Display nameServer operational errors
Sensitivityrestricted_security
Subjectsaccount, organization, workspace, game, service
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
service_reliabilityDetect, diagnose, and remediate platform failures and security-relevant anomalies.Operators require bounded server context to restore service and investigate exploitation attempts.

Permitted readers:

ReaderProjectionExport allowedConditions
platform_security_serviceservice_internalnoAutomated detection consumes normalized severity, fingerprint, and route context.
incident_responderincident_scopednoAssigned incidents permit bounded diagnostic inspection.
support_operatorredactednoCustomer support receives public error codes and correlation IDs, not internal stacks.

session_and_refresh_credentials

FieldValue
Display nameSession and refresh credential material
Sensitivityrestricted_secret
Subjectsaccount, service
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
session_continuityMaintain authenticated continuity, rotate refresh credentials, and revoke compromised credential families.Usable customer sessions require short-lived authentication continuity without repeated primary login.

Permitted readers:

ReaderProjectionExport allowedConditions
credential_verifierservice_internalnoOnly session and refresh verification paths read credential hashes or protected material.
platform_security_servicemetadata_onlynoSecurity services receive credential IDs, family, assurance, expiry, and revocation status only.

support_case_data

FieldValue
Display nameCustomer support case data
Sensitivityconfidential_personal
Subjectsaccount, organization, workspace, game
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
customer_supportResolve a customer-requested product, account, billing, or security issue.Support requires limited issue context and an accountable communication record.

Permitted readers:

ReaderProjectionExport allowedConditions
support_operatorincident_scopednoAssignment, current case purpose, and support permission are required.
account_ownerself_serviceyesThe authenticated requester receives their case history and exportable submissions.
privacy_operatorredactedyesPrivacy requests receive subject-scoped support records.

user_authentication_secrets

FieldValue
Display nameUser authentication secret verifiers
Sensitivityrestricted_secret
Subjectsaccount
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
primary_authenticationVerify a user's proof of knowledge during authentication or controlled recovery.Accounts without an enrolled phishing-resistant factor require a protected primary authentication method.

Permitted readers:

ReaderProjectionExport allowedConditions
credential_verifierservice_internalnoOnly constant-behavior verification code receives the stored verifier.
platform_security_servicemetadata_onlynoSecurity services receive algorithm, age, and compromise status without verifier bytes.

workspace_identity_and_membership

FieldValue
Display nameWorkspace identity and membership
Sensitivityconfidential_tenant
Subjectsaccount, organization, workspace
Retention modepermanent_records
Retention policydata_policy / PERMANENT_RECORD_POLICY
Retention detailjustification: Durable records remain in their source store indefinitely, including after access revocation or logical deletion.
Deletion modesoft_delete
Deletion triggerAn authorized lifecycle transition ends active access without removing the durable record.
Deletion execution ownerresource_lifecycle
Deletion verificationDatabase destruction guards preserve rows; active API projections exclude logically deleted records and revoked credentials fail verification.
Data-subject requestsoft_delete_only
Legal holddoes_not_apply

Authorized purposes:

PurposeStatementNecessity
workspace_operationOrganize tenant resources and authorize scoped collaboration below an organization.Workspaces are the canonical collaboration and resource-ownership boundary for creator operations.

Permitted readers:

ReaderProjectionExport allowedConditions
authorized_tenant_membertenant_scopedyesEffective workspace or ancestor grants constrain every projection.
support_operatorredactednoCase-bound support receives workspace locator and status only.
Was this helpful?Report an issueContact support

On this page