Test telemetry collection with planted private-content markers
The contract looks safe, but errors, retries and report downloads may bypass the sending boundary.
- Focused work estimate
- 4h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- Privacy testing · Defense in depth
Estimated field mix
- Privacy engineering50%
- Quality engineering50%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional document workspace wants to measure upload completion and failure. Its prototype sends filenames, document titles and raw errors to general analytics. Replace that path with a minimal event contract using synthetic traffic.
Setup prerequisites
- Create synthetic upload workflows and a local collector that captures received payloads.
- Define measurement questions and a separate restricted diagnostic store fixture.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- RTELEMETRY-101 · Translate upload questions into bounded telemetry events
- RTELEMETRY-102 · Reject unknown telemetry fields at the sending boundary
- RTELEMETRY-104 · Map upload errors to safe categories before analytics dispatch
- RTELEMETRY-103 · Use a short-lived workflow correlation ID with a defined scope
- RTELEMETRY-105 · Keep restricted upload diagnostics out of the analytics transport
- RTELEMETRY-106 · Drop telemetry safely when validation or the collector fails
- RTELEMETRY-107 · Expire raw workflow events while preserving only approved aggregates
- RTELEMETRY-108 · Suppress small-group reports under the exercise disclosure rule
- RTELEMETRY-109 · Reconcile upload outcome counts without hiding dropped telemetry
Acceptance criteria
- Plant unique synthetic markers in filenames, titles, headers, errors and form values.
- Exercise success, retry, validation failure, collector outage and report download paths.
- Verify markers never reach generic telemetry or logs while required aggregate questions remain answerable.
Implementation constraints
- Passing supports only inspected conditions and boundaries, not a blanket no-leak guarantee.
Verification to include
- Search collector captures, fallback logs and downloaded reports for every marker.
- Add a deliberate bypass to the test sender and confirm the regression detects it; verify the guarded implementation passes.
Deliverables
- Disclosure regression matrix and boundary review
Rollout and recovery
Run the matrix when schemas or sending paths change; block the exercise release on a prohibited disclosure.
Value of the work
For the engineer: Practice minimization, safe failure handling and correct aggregates.
For the team: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.