You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add an optional review flag to filter strategies. The strategy is applied as usual, and every span it produces is marked as needing human review.
Motivation
Detection and classification are probabilistic. Some decisions should go to a person even when a strategy applies: a name whose age cannot be determined, an address whose role is unclear, a detection below a confidence threshold. Review tools such as Arbiter currently decide what to queue on their own, from confidence alone, so the policy (the versioned record of intent) cannot say "redact this, but have someone check it."
Summary
Add an optional
reviewflag to filter strategies. The strategy is applied as usual, and every span it produces is marked as needing human review.Motivation
Detection and classification are probabilistic. Some decisions should go to a person even when a strategy applies: a name whose age cannot be determined, an address whose role is unclear, a detection below a confidence threshold. Review tools such as Arbiter currently decide what to queue on their own, from confidence alone, so the policy (the versioned record of intent) cannot say "redact this, but have someone check it."
Split from #48, which covers reasons only.
What does this change touch?
reviewon strategies)Proposed change (sketch)
reviewonbaseFilterStrategyanddateFilterStrategy, defaultfalse, and on document rules (RFC: Document rules applied to every span in a document #54) if those land.reviewRequiredon each span produced by a strategy withreview: true.reviewnever changes the replacement text.PhiSQL. A trailing
REVIEWclause, matched contextually so it is not reserved:Expected versioning impact
PhiSQL spec minor (new clause; no reserved keyword). Schema additive, edited in place.
Backward compatibility
Additive. Spans gain a field consumers must tolerate. A runtime embedding the schema from before this change rejects a policy using
review.Alternatives considered
Open questions
OPTIONSclause a better home than a newREVIEWclause?Acceptance Criteria
schema/<version>/schema.jsonis edited in place to addreviewto base and date strategies.reviewand thereviewRequiredspan field, and that it never changes output.REVIEWclause onREDACTandDEIDENTIFYwithout reserving a keyword, and the compilers emitreview: true.