Documented backup-requirement decision
The dataset has a controlled io.obsidiantek.dhcp.backupRequirement value: REQUIRED, NOT_REQUIRED, or CONDITIONAL.
Posture Brief · http://localhost:8080 · 9 datasets
A compact view of catalog-visible governance evidence. Exact asset sets, mapping interpretations, limitations, and provenance remain in the bound Supporting Evidence Package and JSON companion.
Claim boundary. Observation coverage describes catalog-visible metadata only. Profile mappings explain possible relevance and limitations; DHCP does not determine conformity with any objective.
aic.ai_inference_inputsaic.ai_training_featuresaic.ai_validation_setaic.claims_billingaic.clinical_featuresaic.compliance_reportingaic.consent_preferencesaic.encounter_eventsaic.patient_records
Exact dataset names from this bound catalog snapshot; colliding names include platform and environment.
The dataset has a controlled io.obsidiantek.dhcp.backupRequirement value: REQUIRED, NOT_REQUIRED, or CONDITIONAL.
The trimmed dataset description is at least 20 characters long.
The dataset has a non-empty DataHub domain assignment.
The dataset has at least one registered upstream or downstream lineage edge.
The dataset has at least one assigned DataHub owner.
Among datasets with a schema field carrying a recognized PII, PHI, personal, personal-data, or personal-information label, the dataset has a non-empty io.acryl.privacy.retentionTime structured property.
At least one schema field has a tag or glossary term whose normalized name includes one of these exact tokens: PHI, HIPAA, PCI, financial, PII, GDPR, personal, sensitive, or confidential; explicitly non-sensitive labels do not count.
The dataset has a non-empty io.acryl.privacy.retentionTime structured property.
| Catalog observation | Not observed on |
|---|---|
| Documented backup-requirement decision | aic.ai_inference_inputsaic.consent_preferences
|
| Domain assignment | aic.compliance_reporting
|
| Registered lineage | aic.consent_preferences
|
| Assigned owner | aic.compliance_reporting
|
| Retention intent for identified personal information | aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
|
| Field sensitivity label | aic.claims_billingaic.compliance_reporting
|
| Documented retention intent | aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
|
These are catalog-visible absences, not control failures. The bound Supporting Evidence Package contains every exact observed and not-observed asset set.
Raw catalog observations · not a control determination
aic.compliance_reporting
Interpretation: A governed data inventory should make in-scope datasets discoverable, organized, and understandable.
Evidence: Domain assignments and substantive dataset descriptions provide catalog-visible inventory context for auditor review.
DataHub surfaces: Domains, Dataset descriptions
Raw catalog observations · not a control determination
aic.claims_billingaic.compliance_reporting
Interpretation: Cataloged fields should carry explicit classification labels so reviewers can identify recorded sensitivity decisions.
Evidence: A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that selected data-classification decisions have been recorded for that dataset.
DataHub surfaces: Schema field tags, Glossary terms
Raw catalog observations · not a control determination
aic.consent_preferences
Interpretation: Data movement should be documented so reviewers can trace material upstream and downstream relationships.
Evidence: Registered DataHub lineage edges provide catalog-visible data-flow evidence.
DataHub surfaces: Lineage
Raw catalog observations · not a control determination
aic.compliance_reporting
Interpretation: Governed data assets should have a catalog-visible accountable party.
Evidence: Assigned DataHub owners provide direct metadata evidence that a dataset has a named accountable party.
DataHub surfaces: Ownership
Raw catalog observations · not a control determination
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
Interpretation: Retention intentions should be recorded in a structured form so lifecycle work can be identified and handed off.
Evidence: A non-empty DataHub retention-time structured property provides evidence of documented retention intent.
DataHub surfaces: Structured properties, Forms
Raw catalog observations · not a control determination
aic.claims_billingaic.compliance_reporting
Interpretation: Sensitive-data review depends on catalog-visible identification of fields that may require protection.
Evidence: An explicit sensitivity tag or glossary term on at least one field shows that field-level sensitivity labeling is present for that dataset.
DataHub surfaces: Schema field tags, Glossary terms
Raw catalog observations · not a control determination
aic.consent_preferences
Interpretation: Reviewers should be able to understand a dataset's stated purpose and trace its catalog-visible origin or downstream use.
Evidence: Substantive descriptions and registered lineage provide complementary documentation and provenance evidence.
DataHub surfaces: Dataset descriptions, Lineage
Raw catalog observations · not a control determination
aic.compliance_reporting
aic.compliance_reporting
aic.claims_billingaic.compliance_reporting
aic.consent_preferences
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
Interpretation: A processing-activity review needs an accountable inventory with purpose, personal-data context, data flows, and retention intent.
Evidence: Owners, domains, descriptions, sensitivity labels, lineage, and retention properties provide reusable catalog evidence for assembling or testing parts of a record of processing activities.
DataHub surfaces: Ownership, Domains, Dataset descriptions, Schema field tags, Glossary terms, Lineage, Structured properties
Raw catalog observations · not a control determination
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
Interpretation: Personal-data review should be able to identify the intended retention period associated with cataloged datasets.
Evidence: A non-empty retention-time structured property provides reviewable evidence of documented retention intent.
DataHub surfaces: Structured properties, Forms
Raw catalog observations · not a control determination
aic.compliance_reporting
aic.compliance_reporting
aic.claims_billingaic.compliance_reporting
aic.consent_preferences
Interpretation: Risk analysis begins with identifying all locations where electronic protected health information is created, received, maintained, or transmitted.
Evidence: Catalog ownership, domain, documentation, field sensitivity labeling, and lineage observations can support scoping and data collection for ePHI risk analysis.
DataHub surfaces: Ownership, Domains, Dataset descriptions, Schema field tags, Glossary terms, Lineage
Raw catalog observations · not a control determination
aic.claims_billingaic.compliance_reporting
Interpretation: Reviewers need to identify categories of protected health information and their stated purpose before assessing minimum-necessary policies and access.
Evidence: Field sensitivity labels and substantive dataset descriptions provide catalog evidence that can help scope minimum-necessary review.
DataHub surfaces: Schema field tags, Glossary terms, Dataset descriptions
Raw catalog observations · not a control determination
aic.compliance_reporting
aic.compliance_reporting
Interpretation: Cataloged datasets should carry accountable ownership and sufficient context to support review of the information-asset inventory.
Evidence: Dataset ownership, domain assignment, and substantive descriptions provide catalog-visible evidence for reviewing inventory records, accountability, and context.
DataHub surfaces: Ownership, Domains, Dataset descriptions
Raw catalog observations · not a control determination
aic.claims_billingaic.compliance_reporting
Interpretation: Cataloged datasets should expose reviewed field-level sensitivity classifications that support information-classification governance.
Evidence: A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that selected classification decisions have been recorded for that dataset.
DataHub surfaces: Schema field tags, Glossary terms
Raw catalog observations · not a control determination
aic.claims_billingaic.compliance_reporting
Interpretation: Fields with confirmed sensitivity classifications should carry explicit catalog labels so reviewers can see where information labelling has been implemented.
Evidence: A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that field-level labelling is present for that dataset.
DataHub surfaces: Schema field tags, Glossary terms
Raw catalog observations · not a control determination
aic.consent_preferences
aic.claims_billingaic.compliance_reporting
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
Interpretation: In-scope AI data resources should carry catalog documentation, provenance relationships, explicit field sensitivity classification, and documented retention intent.
Evidence: Substantive descriptions can carry intended-use context, registered lineage provides provenance inputs, reviewed field labels expose selected information categories, and retention properties record retention intent.
DataHub surfaces: Dataset descriptions, Lineage, Schema field tags, Glossary terms, Structured properties
Raw catalog observations · not a control determination
aic.consent_preferences
Interpretation: Cataloged AI data resources should expose traceable upstream or downstream relationships for provenance review.
Evidence: Registered DataHub lineage edges provide machine-readable provenance evidence for cataloged datasets.
DataHub surfaces: Lineage
Raw catalog observations · not a control determination
aic.consent_preferences
aic.claims_billingaic.compliance_reporting
Interpretation: Cataloged descriptions, lineage, and field-level sensitivity labels support review of asset records, documented data flows, and information classification.
Evidence: Substantive descriptions, registered lineage, and field-level sensitivity tags or glossary terms provide catalog-visible evidence of asset records, data-flow documentation, and information classification.
DataHub surfaces: Dataset descriptions, Lineage, Schema field tags, Glossary terms
Raw catalog observations · not a control determination
aic.ai_inference_inputsaic.consent_preferences
Interpretation: In-scope datasets should carry a governed decision recording whether backup is required.
Evidence: A controlled dataset Structured Property provides catalog-visible evidence that an accountable backup-requirement decision has been recorded.
DataHub surfaces: Structured properties, Forms, Ownership, Dataset documentation
Raw catalog observations · not a control determination
aic.claims_billingaic.compliance_reporting
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
Interpretation: Confidential-information review should be able to identify cataloged sensitive datasets, their stated purpose or context, and their documented retention intent.
Evidence: Field-level sensitivity labels, substantive dataset descriptions, and retention Structured Properties provide complementary catalog evidence for identifying confidential-information retention decisions that need review.
DataHub surfaces: Dataset descriptions, Schema field tags, Glossary terms, Structured properties, Forms
Raw catalog observations · not a control determination
aic.claims_billingaic.compliance_reporting
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
Interpretation: Cataloged sensitivity labels and documented retention intent provide inputs for identifying confidential datasets that may require disposition review when their retention period ends.
Evidence: Field-level sensitivity labels and retention Structured Properties provide complementary catalog evidence for assembling an exact confidential-information population whose disposition requirements need accountable review.
DataHub surfaces: Schema field tags, Glossary terms, Structured properties, Forms
Raw catalog observations · not a control determination
aic.consent_preferences
Interpretation: Cataloged lineage helps document declared upstream input relationships for in-scope datasets.
Evidence: Registered upstream and downstream lineage edges provide reviewable catalog records of declared system-input relationships, with raw dataset counts and exact observed and not-observed populations.
DataHub surfaces: Lineage
Raw catalog observations · not a control determination
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
Interpretation: Cataloged datasets identified as containing personal information should carry documented retention intent.
Evidence: Reviewed PII, PHI, personal-data, or personal-information field labels define the catalog-identified population; a retention Structured Property on the same dataset records stated retention intent.
DataHub surfaces: Schema field tags, Glossary terms, Structured properties, Forms