Skip to main content

AnonPolicy

Struct AnonPolicy 

Source
pub struct AnonPolicy {
Show 14 fields pub mode: String, pub categories: BTreeMap<String, String>, pub default_action: String, pub custom_terms: Vec<String>, pub term_sets: BTreeMap<String, Vec<String>>, pub co_occurrence: Vec<CoOccurrence>, pub scope: String, pub placeholder: String, pub min_confidence: f32, pub detectors: Vec<String>, pub vault: bool, pub vault_ttl_days: Option<f64>, pub because: Option<String>, pub known: Vec<KnownIdentity>,
}
Expand description

The declarative anonymization policy (proposal §8.1). Serialized as the JSON value of an anon:<ns> meta row from P1 on; in P0 it is supplied explicitly to the text APIs.

deny_unknown_fields is the fail-closed half of D3: a policy field this build does not understand could be the field that strengthens the policy, so refusing it loudly beats silently ignoring it.

Fields§

§mode: String§categories: BTreeMap<String, String>

category → action (“pseudonym” | “mask” | “redact” | “allow”).

§default_action: String

Action for categories a detector emits but the map omits — the chain fails closed on categories it didn’t anticipate, not open.

§custom_terms: Vec<String>

User dictionary; matches become category custom.

§term_sets: BTreeMap<String, Vec<String>>

Named dictionaries: category -> terms. Each set’s matches carry that category, so the policy can act on them separately and — the reason they exist — so a CoOccurrence rule can NAME one side of the relationship. The single custom_terms bucket cannot express “a person near a condition” because both halves land in custom.

§co_occurrence: Vec<CoOccurrence>

Context-sensitive escalation: re-categorize a detection when another category appears close to it.

This is the rule healthcare actually needs and no per-category action can express. A name alone may be acceptable in a prompt; a name together with a condition, medication or procedure in the same span is health data under most privacy regimes. The distinction is not a property of either detection — it is a property of the pair.

§scope: String

Pseudonym stability scope. P0 supports context only (per-call numbering); session/memory arrive with the store boundary.

§placeholder: String

Placeholder template; must contain {CATEGORY} and {ID}.

§min_confidence: f32§detectors: Vec<String>

Which chain links this policy demands (proposal §5.4): “tier0” runs in-tree; “ner”/“llm” require a host-installed DetectorBackend of that kind and FAIL CLOSED without one (D6).

§vault: bool

Persist the pseudonym mapping to the file’s sealed vault (proposal §7). Requires scope session/memory and an encrypted memory.

§vault_ttl_days: Option<f64>

Storage limitation for vault rows (REQ-ANON-6), in days.

§because: Option<String>§known: Vec<KnownIdentity>

Caller-supplied identities to detect verbatim in free text (issue #32’s escape hatch): a host that hasn’t interned the identity as a grain subject first — an email’s From header, a CRM row, a project codename — still gets it detected and pseudonymized, without writing it to the store just to make it detectable. Distinct from the automatic propagation scan_text/anonymize_text already pull from the store’s own interned subjects for the call’s namespace (same table the grain-egress path builds).

Implementations§

Source§

impl AnonPolicy

Source

pub fn from_json(json: &str) -> Result<AnonPolicy>

Parse and validate a policy from JSON. Parse or validation failure is a hard VAL error (D3): a policy this build cannot read must not silently mean “no policy”.

Source

pub fn validate(&self) -> Result<()>

Trait Implementations§

Source§

impl Clone for AnonPolicy

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for AnonPolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for AnonPolicy

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for AnonPolicy

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for AnonPolicy

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more