Skip to content
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Data classification

dataPolicy:
classification: confidential
inputs:
- name: customer_data
classification: personal
outputs:
- name: report
classification: internal
restrictions:
externalTransfer: deny
  • Classes from least to most restrictive: public, internal, confidential/personal, restricted/sensitive, secret.
  • Executions whose inputs rank above dataPolicy.classification are rejected.
  • Declassifying an output is recorded in the artifact.created event.
  • The classes are an organizational vocabulary. Mapping them to legal definitions is up to the organization.

Normative text: Data classification.