# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## RTELEMETRY — Measure a workflow without collecting its private content

A fictional document workspace wants to measure upload completion and failure. Its prototype sends filenames, document titles and raw errors to general analytics. Replace that path with a minimal event contract using synthetic traffic.

**Field:** Privacy engineering. **Suggested stack:** TypeScript, JSON Schema, HTTP collector double, SQL.

**Engineer value:** Practice minimization, safe failure handling and correct aggregates.

**Company value:** Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

**Delivery agreement:** Ten tickets using synthetic data. No claim of anonymization, privacy certification or measured customer behavior is made.

### Setup prerequisites

- Create synthetic upload workflows and a local collector that captures received payloads.

- Define measurement questions and a separate restricted diagnostic store fixture.

### Specify minimal measurement

Define useful questions and an allowlisted event schema.

#### RTELEMETRY-101 — Translate upload questions into bounded telemetry events

**Task · Medium priority · Foundational**

noCV practice brief v5 · RTELEMETRY-101 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Specify minimal measurement. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 60 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 80% · Data engineering 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Product wants to understand upload failures, but the event captures the entire form submission.

Acceptance criteria

- Define attempted, accepted, completed and failed events with bounded reason categories.

- Map every field to a stated measurement question.

- Exclude filenames, document text, form values and unrestricted URLs.

Implementation constraints

- Counts describe workflow outcomes, not ability, attention or authorship.

Verification

- Answer the stated questions from a synthetic sequence.

- Remove a field without a measurement purpose and verify the report remains possible.

Deliverables

- Question map and minimal event contract

Rollout and recovery: Review the contract before changing collection; unknown fields remain disallowed.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### RTELEMETRY-102 — Reject unknown telemetry fields at the sending boundary

**Bug · High priority · Intermediate**

noCV practice brief v5 · RTELEMETRY-102 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Specify minimal measurement. Depends on: RTELEMETRY-101.

Difficulty: Intermediate. Estimated focused work: 120 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 60% · Security 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Spreading an error object into an event accidentally includes headers and document metadata.

Acceptance criteria

- Build payloads through a runtime schema with unknown-field rejection.

- Expose a typed interface that does not accept arbitrary payload spreading.

- Report rejection without echoing the rejected payload.

Implementation constraints

- The runtime boundary must handle loosely typed callers as well as normal TypeScript code.

Verification

- Send a valid completion and inspect the collector payload.

- Add token-like headers, nested objects and unknown properties; no event may reach the collector.

Deliverables

- Telemetry boundary and rejection tests

Rollout and recovery: Route events through the boundary before retiring the old sender.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### RTELEMETRY-103 — Use a short-lived workflow correlation ID with a defined scope

**Task · Medium priority · Intermediate**

noCV practice brief v5 · RTELEMETRY-103 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Specify minimal measurement. Depends on: RTELEMETRY-101, RTELEMETRY-102.

Difficulty: Intermediate. Estimated focused work: 120 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 100%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Analytics uses the account email as a permanent join key for all uploads.

Acceptance criteria

- Use a random operation ID limited to one workflow and its bounded retry window.

- Exclude account, document and contact identifiers from the ID.

- Document linkability within the operation rather than calling the event anonymous.

Implementation constraints

- Keep subject mapping outside the generic sink; collect correlation only when required for the stated question.

Verification

- Retry one operation and verify intended correlation, then start another with a new ID.

- Inspect IDs and payloads for subject or document fields.

Deliverables

- Correlation lifecycle and identifier tests

Rollout and recovery: Version the schema and stop emitting direct identifiers before comparing reports.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Enforce collection limits

Reject accidental content, separate diagnostics and bound retention.

#### RTELEMETRY-104 — Map upload errors to safe categories before analytics dispatch

**Bug · High priority · Advanced**

noCV practice brief v5 · RTELEMETRY-104 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Enforce collection limits. Depends on: RTELEMETRY-102.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 70% · Site reliability 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

An unfamiliar storage exception contains a signed URL. The fallback serializes it into analytics.

Acceptance criteria

- Map known failures to bounded categories and unknown failures to a generic category.

- Never send raw messages, stacks, headers or signed URLs through generic telemetry.

- Route justified detailed diagnostics through a separate restricted interface.

Implementation constraints

- Do not rely on a regular expression to find every possible secret in an arbitrary object.

Verification

- Classify known storage, validation and timeout errors.

- Inject an unfamiliar nested error with a token-like URL and verify only the generic category is emitted.

Deliverables

- Safe classifier and nested-error fixtures

Rollout and recovery: Deploy the safe fallback before expanding error coverage.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### RTELEMETRY-105 — Keep restricted upload diagnostics out of the analytics transport

**Story · Medium priority · Advanced**

noCV practice brief v5 · RTELEMETRY-105 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Enforce collection limits. Depends on: RTELEMETRY-103, RTELEMETRY-104.

Difficulty: Advanced. Estimated focused work: 210 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 60% · Security 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Support needs a detailed failure record, but the proposed implementation reuses analytics permissions and transport.

Acceptance criteria

- Create a separate diagnostic store with tenant-scoped access.

- Collect only justified fields with a bounded retention period.

- Use safe references for an authorized diagnostic lookup rather than exposing details in counters.

Implementation constraints

- Use synthetic errors; omit credentials and private upload bytes even from this exercise diagnostic store.

Verification

- Read a diagnostic as an authorized scoped operator.

- Attempt cross-tenant access and inspect analytics requests to verify no diagnostic details pass through them.

Deliverables

- Restricted diagnostics and transport-separation tests

Rollout and recovery: Enable diagnostics independently; analytics must work when diagnostics are disabled.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### RTELEMETRY-106 — Drop telemetry safely when validation or the collector fails

**Bug · High priority · Advanced**

noCV practice brief v5 · RTELEMETRY-106 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Enforce collection limits. Depends on: RTELEMETRY-102, RTELEMETRY-104.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 60% · Site reliability 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The validation failure handler prints the original event, leaking the content the guard rejected.

Acceptance criteria

- Never log the rejected event payload.

- Keep optional analytics failure independent of upload completion with bounded buffers and retries.

- Count dropped events through safe categories so gaps remain visible.

Implementation constraints

- A collector outage must not block the workflow or grow an unlimited in-memory queue.

Verification

- Fail validation and inspect captured logs and requests for the rejected marker.

- Disconnect the collector under sustained synthetic events and verify bounded buffering and successful uploads.

Deliverables

- Safe fallback and outage regressions

Rollout and recovery: Ship the fallback before stricter validation; drop optional events rather than exposing raw content.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### RTELEMETRY-107 — Expire raw workflow events while preserving only approved aggregates

**Chore · Medium priority · Advanced**

noCV practice brief v5 · RTELEMETRY-107 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Enforce collection limits. Depends on: RTELEMETRY-103, RTELEMETRY-105, RTELEMETRY-106.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 60% · Data engineering 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Correlation-bearing raw events remain forever although reporting needs only daily counts.

Acceptance criteria

- Version fictional raw-event and aggregate retention rules.

- Remove expired raw events from the declared sink and replay buffers.

- Report unresolved copies and avoid assuming aggregates cannot identify people.

Implementation constraints

- Use injected time and local adapters; retention values are exercise inputs, not real-world policy advice.

Verification

- Advance beyond raw expiry and verify sink and replay cleanup while permitted counts remain.

- Fail one cleanup adapter and verify its unresolved location appears in the report.

Deliverables

- Telemetry retention job and copy-reconciliation cases

Rollout and recovery: Preview eligibility before removal and version aggregate definitions when collection changes.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Verify useful reporting

Reconcile aggregates and test disclosure under failures.

#### RTELEMETRY-108 — Suppress small-group reports under the exercise disclosure rule

**Story · Medium priority · Expert**

noCV practice brief v5 · RTELEMETRY-108 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Verify useful reporting. Depends on: RTELEMETRY-101, RTELEMETRY-103, RTELEMETRY-107.

Difficulty: Expert. Estimated focused work: 270 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 70% · Data engineering 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Filtering a report to a tiny group reveals one person’s workflow even when source events omit email.

Acceptance criteria

- Apply an exercise threshold of 10 distinct synthetic subjects through a separately restricted aggregation fixture.

- Prevent supported filter combinations and complementary totals from releasing a suppressed value.

- Document that thresholding addresses a specific disclosure path and does not prove anonymity or differential privacy.

Implementation constraints

- Do not add permanent subject IDs to the general event sink to support this exercise; define the separate aggregation boundary and tested query family.

Verification

- Query small, large and overlapping groups and inspect API plus report downloads.

- Attempt deduction from a total and complementary group; verify the declared release rule suppresses the relevant results.

Deliverables

- Report-release rule, disclosure fixtures and limitations

Rollout and recovery: Keep fine-grained reports disabled until the rule and tested limits are reviewed.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### RTELEMETRY-109 — Reconcile upload outcome counts without hiding dropped telemetry

**Task · Medium priority · Intermediate**

noCV practice brief v5 · RTELEMETRY-109 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Verify useful reporting. Depends on: RTELEMETRY-101, RTELEMETRY-106, RTELEMETRY-107.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Site reliability 50% · Data engineering 30% · Privacy engineering 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The success percentage rises during a collector outage because failed uploads lose terminal events.

Acceptance criteria

- Define denominators and windows from the event contract.

- Expose incomplete operations and dropped events instead of treating missing completion as success.

- Mark comparisons incomplete when collection gaps prevent a supported result.

Implementation constraints

- Keep uncertainty visible; never invent missing user behavior with model guesses.

Verification

- Replay success, failure, duplicate and missing-terminal sequences and reconcile counts.

- Simulate asymmetric loss and verify the report is incomplete rather than improved.

Deliverables

- Outcome aggregation and collection-gap regressions

Rollout and recovery: Compare the new calculation with the old one on synthetic traces before changing the report.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### RTELEMETRY-110 — Test telemetry collection with planted private-content markers

**Task · Medium priority · Expert**

noCV practice brief v5 · RTELEMETRY-110 · Measure a workflow without collecting its private content

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Verify useful reporting. Depends on: RTELEMETRY-102, RTELEMETRY-104, RTELEMETRY-105, RTELEMETRY-106, RTELEMETRY-107, RTELEMETRY-108, RTELEMETRY-109.

Difficulty: Expert. Estimated focused work: 270 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 50% · Quality engineering 50%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The contract looks safe, but errors, retries and report downloads may bypass the sending boundary.

Acceptance criteria

- Plant unique synthetic markers in filenames, titles, headers, errors and form values.

- Exercise success, retry, validation failure, collector outage and report download paths.

- Verify markers never reach generic telemetry or logs while required aggregate questions remain answerable.

Implementation constraints

- Passing supports only inspected conditions and boundaries, not a blanket no-leak guarantee.

Verification

- Search collector captures, fallback logs and downloaded reports for every marker.

- Add a deliberate bypass to the test sender and confirm the regression detects it; verify the guarded implementation passes.

Deliverables

- Disclosure regression matrix and boundary review

Rollout and recovery: Run the matrix when schemas or sending paths change; block the exercise release on a prohibited disclosure.

Project prerequisites: Create synthetic upload workflows and a local collector that captures received payloads. Define measurement questions and a separate restricted diagnostic store fixture.

Engineer value: Practice minimization, safe failure handling and correct aggregates.

Company value: Produce useful operational measurements with a reviewable collection boundary and disclosure regression suite.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
