Obsidian Tek arrowhead mark

DataHub Compliance Posture (DHCP)

Posture Brief · http://localhost:8080 · 9 datasets

Supporting evidence package

A compact view of catalog-visible governance evidence. Exact asset sets, mapping interpretations, limitations, and provenance remain in the bound Supporting Evidence Package and JSON companion.

9 datasets 6 evidence profiles 8 observations run 0406b48c-b438-4b2f-bb2d-d495c1870333

Claim boundary. Observation coverage describes catalog-visible metadata only. Profile mappings explain possible relevance and limitations; DHCP does not determine conformity with any objective.

Selected catalog scope
aic.ai_inference_inputsaic.ai_training_featuresaic.ai_validation_setaic.claims_billingaic.clinical_featuresaic.compliance_reportingaic.consent_preferencesaic.encounter_eventsaic.patient_records

Exact dataset names from this bound catalog snapshot; colliding names include platform and environment.

Catalog observations

backup_requirement_coverage

Documented backup-requirement decision

77.8%
7 observed2 not observed

The dataset has a controlled io.obsidiantek.dhcp.backupRequirement value: REQUIRED, NOT_REQUIRED, or CONDITIONAL.

documentation_coverage

Substantive dataset description

100.0%
9 observed0 not observed

The trimmed dataset description is at least 20 characters long.

domain_assignment

Domain assignment

88.9%
8 observed1 not observed

The dataset has a non-empty DataHub domain assignment.

lineage_presence

Registered lineage

88.9%
8 observed1 not observed

The dataset has at least one registered upstream or downstream lineage edge.

ownership_coverage

Assigned owner

88.9%
8 observed1 not observed

The dataset has at least one assigned DataHub owner.

personal_information_retention_coverage

Retention intent for identified personal information

57.1%
4 observed3 not observed

Among datasets with a schema field carrying a recognized PII, PHI, personal, personal-data, or personal-information label, the dataset has a non-empty io.acryl.privacy.retentionTime structured property.

pii_tag_coverage

Field sensitivity label

77.8%
7 observed2 not observed

At least one schema field has a tag or glossary term whose normalized name includes one of these exact tokens: PHI, HIPAA, PCI, financial, PII, GDPR, personal, sensitive, or confidential; explicitly non-sensitive labels do not count.

retention_property_coverage

Documented retention intent

66.7%
6 observed3 not observed

The dataset has a non-empty io.acryl.privacy.retentionTime structured property.

Named evidence gaps

Datasets requiring review
Catalog observationNot observed on
Documented backup-requirement decision
aic.ai_inference_inputsaic.consent_preferences
Domain assignment
aic.compliance_reporting
Registered lineage
aic.consent_preferences
Assigned owner
aic.compliance_reporting
Retention intent for identified personal information
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events
Field sensitivity label
aic.claims_billingaic.compliance_reporting
Documented retention intent
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events

These are catalog-visible absences, not control failures. The bound Supporting Evidence Package contains every exact observed and not-observed asset set.

LangChain agent analysis

claude-sonnet-4-6 DataHub Agent Context Kit read-only context 1 context lookup narrative claim checks: accepted
Documentation catalog observation coverage is the strongest signal in this digest, with all 9 datasets carrying substantive descriptions, and ownership, domain assignment, and lineage each observed on 8 of 9 datasets. The weakest observations are retention_property_coverage, present on 6 of 9 datasets, and personal_information_retention_coverage, present on only 4 of the 7 datasets identified as carrying personal-information labels. The catalog lookup confirms that aic.compliance_reporting is the single dataset missing ownership, domain assignment, and a PII tag simultaneously, and that aic.ai_training_features, aic.clinical_features, and aic.encounter_events are the datasets whose retention intent has not been recorded in DataHub. The most consequential review implications cluster around retention and classification. For GDPR Article 5(1)(e), SOC 2 P4.2, and DSP-16, the 3 datasets without a retention property and the 3 personal-information-labeled datasets without a retention record represent the highest-priority catalog gaps; however, the absence of a structured property does not prove that no retention policy exists outside DataHub, and accountable privacy counsel must confirm whether any period is legally appropriate and whether deletion is enforced.

Evidence profile interpretations

CSA AI Controls Matrix (AICM)

AICM v1.1.0 · profile aicm v1.1.0 · authoritative source

DSP-03 — Data Inventory

Dataset evidence snapshot

Raw catalog observations · not a control determination

Domain assignment
8 / 9
88.9% of datasets observed
Not observed on
aic.compliance_reporting
Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.

Interpretation: A governed data inventory should make in-scope datasets discoverable, organized, and understandable.

Evidence: Domain assignments and substantive dataset descriptions provide catalog-visible inventory context for auditor review.

DataHub surfaces: Domains, Dataset descriptions

Domain assignment Substantive dataset description

DSP-04 — Data Classification

Dataset evidence snapshot

Raw catalog observations · not a control determination

Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting

Interpretation: Cataloged fields should carry explicit classification labels so reviewers can identify recorded sensitivity decisions.

Evidence: A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that selected data-classification decisions have been recorded for that dataset.

DataHub surfaces: Schema field tags, Glossary terms

Field sensitivity label

DSP-05 — Data Flow Documentation

Dataset evidence snapshot

Raw catalog observations · not a control determination

Registered lineage
8 / 9
88.9% of datasets observed
Not observed on
aic.consent_preferences

Interpretation: Data movement should be documented so reviewers can trace material upstream and downstream relationships.

Evidence: Registered DataHub lineage edges provide catalog-visible data-flow evidence.

DataHub surfaces: Lineage

Registered lineage

DSP-06 — Data Ownership and Stewardship

Dataset evidence snapshot

Raw catalog observations · not a control determination

Assigned owner
8 / 9
88.9% of datasets observed
Not observed on
aic.compliance_reporting

Interpretation: Governed data assets should have a catalog-visible accountable party.

Evidence: Assigned DataHub owners provide direct metadata evidence that a dataset has a named accountable party.

DataHub surfaces: Ownership

Assigned owner

DSP-16 — Data Retention and Deletion

Dataset evidence snapshot

Raw catalog observations · not a control determination

Documented retention intent
6 / 9
66.7% of datasets observed
Not observed on
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events

Interpretation: Retention intentions should be recorded in a structured form so lifecycle work can be identified and handed off.

Evidence: A non-empty DataHub retention-time structured property provides evidence of documented retention intent.

DataHub surfaces: Structured properties, Forms

Documented retention intent

DSP-17 — Sensitive Data Protection

Dataset evidence snapshot

Raw catalog observations · not a control determination

Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting

Interpretation: Sensitive-data review depends on catalog-visible identification of fields that may require protection.

Evidence: An explicit sensitivity tag or glossary term on at least one field shows that field-level sensitivity labeling is present for that dataset.

DataHub surfaces: Schema field tags, Glossary terms

Field sensitivity label

DSP-20 — Data Provenance and Transparency

Dataset evidence snapshot

Raw catalog observations · not a control determination

Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.
Registered lineage
8 / 9
88.9% of datasets observed
Not observed on
aic.consent_preferences

Interpretation: Reviewers should be able to understand a dataset's stated purpose and trace its catalog-visible origin or downstream use.

Evidence: Substantive descriptions and registered lineage provide complementary documentation and provenance evidence.

DataHub surfaces: Dataset descriptions, Lineage

Substantive dataset description Registered lineage

GDPR

Regulation (EU) 2016/679 · profile gdpr v1.0.0 · authoritative source

Article 30 — Records of processing activities

Dataset evidence snapshot

Raw catalog observations · not a control determination

Assigned owner
8 / 9
88.9% of datasets observed
Not observed on
aic.compliance_reporting
Domain assignment
8 / 9
88.9% of datasets observed
Not observed on
aic.compliance_reporting
Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.
Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting
Registered lineage
8 / 9
88.9% of datasets observed
Not observed on
aic.consent_preferences
Documented retention intent
6 / 9
66.7% of datasets observed
Not observed on
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events

Interpretation: A processing-activity review needs an accountable inventory with purpose, personal-data context, data flows, and retention intent.

Evidence: Owners, domains, descriptions, sensitivity labels, lineage, and retention properties provide reusable catalog evidence for assembling or testing parts of a record of processing activities.

DataHub surfaces: Ownership, Domains, Dataset descriptions, Schema field tags, Glossary terms, Lineage, Structured properties

Assigned owner Domain assignment Substantive dataset description Field sensitivity label Registered lineage Documented retention intent

Article 5(1)(e) — Storage limitation

Dataset evidence snapshot

Raw catalog observations · not a control determination

Documented retention intent
6 / 9
66.7% of datasets observed
Not observed on
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events

Interpretation: Personal-data review should be able to identify the intended retention period associated with cataloged datasets.

Evidence: A non-empty retention-time structured property provides reviewable evidence of documented retention intent.

DataHub surfaces: Structured properties, Forms

Documented retention intent

HIPAA

45 CFR Parts 160 and 164 · profile hipaa v1.0.1 · authoritative source

45 CFR 164.308(a)(1)(ii)(A) — Security risk-analysis scope · official guidance

Dataset evidence snapshot

Raw catalog observations · not a control determination

Assigned owner
8 / 9
88.9% of datasets observed
Not observed on
aic.compliance_reporting
Domain assignment
8 / 9
88.9% of datasets observed
Not observed on
aic.compliance_reporting
Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.
Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting
Registered lineage
8 / 9
88.9% of datasets observed
Not observed on
aic.consent_preferences

Interpretation: Risk analysis begins with identifying all locations where electronic protected health information is created, received, maintained, or transmitted.

Evidence: Catalog ownership, domain, documentation, field sensitivity labeling, and lineage observations can support scoping and data collection for ePHI risk analysis.

DataHub surfaces: Ownership, Domains, Dataset descriptions, Schema field tags, Glossary terms, Lineage

Assigned owner Domain assignment Substantive dataset description Field sensitivity label Registered lineage

45 CFR 164.502(b) / 164.514(d) — Minimum-necessary review support · official guidance

Dataset evidence snapshot

Raw catalog observations · not a control determination

Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting
Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.

Interpretation: Reviewers need to identify categories of protected health information and their stated purpose before assessing minimum-necessary policies and access.

Evidence: Field sensitivity labels and substantive dataset descriptions provide catalog evidence that can help scope minimum-necessary review.

DataHub surfaces: Schema field tags, Glossary terms, Dataset descriptions

Field sensitivity label Substantive dataset description

ISO/IEC 27001

ISO/IEC 27001:2022 Annex A · profile iso27001 v1.1.0 · authoritative source

A.5.9 — Inventory of information and associated assets

Dataset evidence snapshot

Raw catalog observations · not a control determination

Assigned owner
8 / 9
88.9% of datasets observed
Not observed on
aic.compliance_reporting
Domain assignment
8 / 9
88.9% of datasets observed
Not observed on
aic.compliance_reporting
Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.

Interpretation: Cataloged datasets should carry accountable ownership and sufficient context to support review of the information-asset inventory.

Evidence: Dataset ownership, domain assignment, and substantive descriptions provide catalog-visible evidence for reviewing inventory records, accountability, and context.

DataHub surfaces: Ownership, Domains, Dataset descriptions

Assigned owner Domain assignment Substantive dataset description

A.5.12 — Information-classification records

Dataset evidence snapshot

Raw catalog observations · not a control determination

Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting

Interpretation: Cataloged datasets should expose reviewed field-level sensitivity classifications that support information-classification governance.

Evidence: A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that selected classification decisions have been recorded for that dataset.

DataHub surfaces: Schema field tags, Glossary terms

Field sensitivity label

A.5.13 — Labelling of information

Dataset evidence snapshot

Raw catalog observations · not a control determination

Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting

Interpretation: Fields with confirmed sensitivity classifications should carry explicit catalog labels so reviewers can see where information labelling has been implemented.

Evidence: A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that field-level labelling is present for that dataset.

DataHub surfaces: Schema field tags, Glossary terms

Field sensitivity label

ISO/IEC 42001

ISO/IEC 42001:2023 Annex A · profile iso42001 v1.1.1 · authoritative source

A.4.3 — Documentation of data resources

Dataset evidence snapshot

Raw catalog observations · not a control determination

Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.
Registered lineage
8 / 9
88.9% of datasets observed
Not observed on
aic.consent_preferences
Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting
Documented retention intent
6 / 9
66.7% of datasets observed
Not observed on
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events

Interpretation: In-scope AI data resources should carry catalog documentation, provenance relationships, explicit field sensitivity classification, and documented retention intent.

Evidence: Substantive descriptions can carry intended-use context, registered lineage provides provenance inputs, reviewed field labels expose selected information categories, and retention properties record retention intent.

DataHub surfaces: Dataset descriptions, Lineage, Schema field tags, Glossary terms, Structured properties

Substantive dataset description Registered lineage Field sensitivity label Documented retention intent

A.7.5 — Data provenance

Dataset evidence snapshot

Raw catalog observations · not a control determination

Registered lineage
8 / 9
88.9% of datasets observed
Not observed on
aic.consent_preferences

Interpretation: Cataloged AI data resources should expose traceable upstream or downstream relationships for provenance review.

Evidence: Registered DataHub lineage edges provide machine-readable provenance evidence for cataloged datasets.

DataHub surfaces: Lineage

Registered lineage

SOC 2

2017 Trust Services Criteria · profile soc2 v1.5.0 · authoritative source

CC2.1 — Quality information supporting internal control

Dataset evidence snapshot

Raw catalog observations · not a control determination

Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.
Registered lineage
8 / 9
88.9% of datasets observed
Not observed on
aic.consent_preferences
Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting

Interpretation: Cataloged descriptions, lineage, and field-level sensitivity labels support review of asset records, documented data flows, and information classification.

Evidence: Substantive descriptions, registered lineage, and field-level sensitivity tags or glossary terms provide catalog-visible evidence of asset records, data-flow documentation, and information classification.

DataHub surfaces: Dataset descriptions, Lineage, Schema field tags, Glossary terms

Substantive dataset description Registered lineage Field sensitivity label

A1.2 — Backup-requirement decisions

Dataset evidence snapshot

Raw catalog observations · not a control determination

Documented backup-requirement decision
7 / 9
77.8% of datasets observed
Not observed on
aic.ai_inference_inputsaic.consent_preferences

Interpretation: In-scope datasets should carry a governed decision recording whether backup is required.

Evidence: A controlled dataset Structured Property provides catalog-visible evidence that an accountable backup-requirement decision has been recorded.

DataHub surfaces: Structured properties, Forms, Ownership, Dataset documentation

Documented backup-requirement decision

C1.1 — Confidential-information retention review

Dataset evidence snapshot

Raw catalog observations · not a control determination

Substantive dataset description
9 / 9
100.0% of datasets observed
Dataset breakdown: observed across all 9 selected datasets.
Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting
Documented retention intent
6 / 9
66.7% of datasets observed
Not observed on
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events

Interpretation: Confidential-information review should be able to identify cataloged sensitive datasets, their stated purpose or context, and their documented retention intent.

Evidence: Field-level sensitivity labels, substantive dataset descriptions, and retention Structured Properties provide complementary catalog evidence for identifying confidential-information retention decisions that need review.

DataHub surfaces: Dataset descriptions, Schema field tags, Glossary terms, Structured properties, Forms

Substantive dataset description Field sensitivity label Documented retention intent

C1.2 — Confidential-information disposition identification

Dataset evidence snapshot

Raw catalog observations · not a control determination

Field sensitivity label
7 / 9
77.8% of datasets observed
Not observed on
aic.claims_billingaic.compliance_reporting
Documented retention intent
6 / 9
66.7% of datasets observed
Not observed on
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events

Interpretation: Cataloged sensitivity labels and documented retention intent provide inputs for identifying confidential datasets that may require disposition review when their retention period ends.

Evidence: Field-level sensitivity labels and retention Structured Properties provide complementary catalog evidence for assembling an exact confidential-information population whose disposition requirements need accountable review.

DataHub surfaces: Schema field tags, Glossary terms, Structured properties, Forms

Field sensitivity label Documented retention intent

PI1.2 — System-input relationship records

Dataset evidence snapshot

Raw catalog observations · not a control determination

Registered lineage
8 / 9
88.9% of datasets observed
Not observed on
aic.consent_preferences

Interpretation: Cataloged lineage helps document declared upstream input relationships for in-scope datasets.

Evidence: Registered upstream and downstream lineage edges provide reviewable catalog records of declared system-input relationships, with raw dataset counts and exact observed and not-observed populations.

DataHub surfaces: Lineage

Registered lineage

P4.2 — Personal-information retention review

Dataset evidence snapshot

Raw catalog observations · not a control determination

Retention intent for identified personal information
4 / 7
57.1% of datasets observed
Not observed on
aic.ai_training_featuresaic.clinical_featuresaic.encounter_events

Interpretation: Cataloged datasets identified as containing personal information should carry documented retention intent.

Evidence: Reviewed PII, PHI, personal-data, or personal-information field labels define the catalog-identified population; a retention Structured Property on the same dataset records stated retention intent.

DataHub surfaces: Schema field tags, Glossary terms, Structured properties, Forms

Retention intent for identified personal information

Provenance

DHCP 0.1.0 · schema 2.0.0
catalog 37cd51fd1dd2cce5d653aec6775ac92f6d7d05deaf3215118fc4691da3eff47b
profile manifest 91cfaa84aa052371bca2b2efb2c35d2b0e908bf36fd61c34e50efd9c4ad0ddcf
report pair d11579e72fd154923bcef96684dc92d8c4446e99bbc94dfe330e15d7db8d96a1