Suppress small-group reports under the exercise disclosure rule
Filtering a report to a tiny group reveals one person’s workflow even when source events omit email.
- Focused work estimate
- 4h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- Disclosure control · Aggregation boundaries
Estimated field mix
- Privacy engineering70%
- Data engineering30%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional document workspace wants to measure upload completion and failure. Its prototype sends filenames, document titles and raw errors to general analytics. Replace that path with a minimal event contract using synthetic traffic.
Setup prerequisites
- Create synthetic upload workflows and a local collector that captures received payloads.
- Define measurement questions and a separate restricted diagnostic store fixture.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- RTELEMETRY-101 · Translate upload questions into bounded telemetry events
- RTELEMETRY-102 · Reject unknown telemetry fields at the sending boundary
- RTELEMETRY-103 · Use a short-lived workflow correlation ID with a defined scope
- RTELEMETRY-104 · Map upload errors to safe categories before analytics dispatch
- RTELEMETRY-105 · Keep restricted upload diagnostics out of the analytics transport
- RTELEMETRY-106 · Drop telemetry safely when validation or the collector fails
- RTELEMETRY-107 · Expire raw workflow events while preserving only approved aggregates
Acceptance criteria
- Apply an exercise threshold of 10 distinct synthetic subjects through a separately restricted aggregation fixture.
- Prevent supported filter combinations and complementary totals from releasing a suppressed value.
- Document that thresholding addresses a specific disclosure path and does not prove anonymity or differential privacy.
Implementation constraints
- Do not add permanent subject IDs to the general event sink to support this exercise; define the separate aggregation boundary and tested query family.
Verification to include
- Query small, large and overlapping groups and inspect API plus report downloads.
- Attempt deduction from a total and complementary group; verify the declared release rule suppresses the relevant results.
Deliverables
- Report-release rule, disclosure fixtures and limitations
Rollout and recovery
Keep fine-grained reports disabled until the rule and tested limits are reviewed.
Value of the work
For the engineer: Practice minimization, safe failure handling and correct aggregates.
For the team: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.