bcquality/microsoft/knowledge/privacy
Jeremy Vyska 02e7ab15b0
Some checks are pending
Validate knowledge index / validate-index (push) Waiting to run
Validate AL review fixtures / validate-review-fixtures (push) Waiting to run
Validate skill index and report schemas / validate-contract (push) Waiting to run
Validate frontmatter and structure / validate (push) Waiting to run
Add retention policy knowledge to the privacy domain (#177)
* Add retention policy knowledge to the privacy domain

Two articles covering retention policies for extension-owned tables,
the gap that lets high-volume log tables grow unbounded:

- register-owned-log-tables-for-retention-policies: an extension's own
  log tables must be added to the allowed-tables list from install AND
  upgrade code, guarded by IsAllowedTable plus an upgrade tag, with a
  mandatory minimum retention where audit needs one.
- ship-a-default-retention-policy-setup: registration only makes a table
  selectable; nothing is deleted until a Retention Policy Setup record
  exists, so ship one (disabled by default) as the platform's own
  Retention Policy Installer does.

Each ships good/bad AL samples. Claims verified against the BC admin
docs and the Retention Policy module in microsoft/BCApps.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011gvTjm746MtJEVWeRTbG46

* Address review feedback on retention policy knowledge

- Scope both articles to bc-version [17..] (retention policies shipped in v17).
- Allowed-tables sample: add OnRefreshAllowedTables subscriber with a
  ForceUpdate path; the upgrade tag now gates one-time setup only.
- Default-policy sample: use Retention Policy Setup.FindOrCreateRetentionPeriod
  instead of a hand-rolled lookup-then-insert that can collide on code.
- Anti-pattern now keys on append-only tables rather than table names.
- al-privacy-review: add retention-policy tokens and deterministic routing
  for both articles, with a bounded per-table text search for delete and
  registration paths.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Address second review round on retention policy knowledge

- Scope both articles to bc-version [22..]: FindOrCreateRetentionPeriod
  first appears in the 21.1 System Application and OnRefreshAllowedTables
  in 22.
- Reframe the default-setup article as optional guidance; registration
  without a setup is valid. The anti-pattern and review routing now cover
  only false claims that registration alone cleans up data.
- Make all four samples self-contained: declare Contoso Activity Log in
  each, add the Retention Policy Setup permission, and guard the default
  setup on IsAllowedTable.
- Let evaluation overrides list additionalArticles and register both
  retention pairs as extra privacy cases (38 cases, existing IDs unchanged).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Revert evaluation harness change for multiple articles per domain

The harness intentionally evaluates one paired article per domain. Keep it
as designed; how the retention pairs join privacy evaluation is left to the
maintainers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register retention policy pairs in the privacy evaluation override

Use main's articles override so both retention article pairs get positive
and clean cases alongside no-pii-in-telemetry-message-string.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Jeremy Vyska <jeremy@sparebrained.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-10-05 15:02:04 +02:00
..
avoid-strsubstno-prebuild-before-error.bad.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
avoid-strsubstno-prebuild-before-error.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
avoid-strsubstno-prebuild-before-error.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
data-classification-is-table-field-property.md Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
data-classification-required-on-pii-fields.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
data-classification-required-on-pii-fields.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
data-classification-required-on-pii-fields.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
error-vs-message-telemetry-logging.md Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
errorinfo-telemetry-classification-and-errortype.bad.al Add lifecycle error and privacy knowledge (#99) 2026-07-14 12:52:56 +02:00
errorinfo-telemetry-classification-and-errortype.good.al Add lifecycle error and privacy knowledge (#99) 2026-07-14 12:52:56 +02:00
errorinfo-telemetry-classification-and-errortype.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
featuretelemetry-customdimensions-no-pii.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
featuretelemetry-customdimensions-no-pii.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
featuretelemetry-customdimensions-no-pii.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
featuretelemetry-logerror-implicit-errortext.bad.al Add lifecycle error and privacy knowledge (#99) 2026-07-14 12:52:56 +02:00
featuretelemetry-logerror-implicit-errortext.good.al Add lifecycle error and privacy knowledge (#99) 2026-07-14 12:52:56 +02:00
featuretelemetry-logerror-implicit-errortext.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
flowfield-flowfilter-classification-systemmetadata.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
flowfield-flowfilter-classification-systemmetadata.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
getlasterrortext-customer-content-in-errors.bad.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
getlasterrortext-customer-content-in-errors.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
getlasterrortext-customer-content-in-errors.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
in-memory-data-not-a-privacy-concern.md Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
migration-destination-classification.md Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
no-pii-in-telemetry-message-string.bad.al Complete AL review knowledge readiness (#108) 2026-07-15 10:55:25 +02:00
no-pii-in-telemetry-message-string.good.al Complete AL review knowledge readiness (#108) 2026-07-15 10:55:25 +02:00
no-pii-in-telemetry-message-string.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
page-display-is-not-a-privacy-concern.md Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
privacy-notice-consent-for-external-data-transfer.bad.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
privacy-notice-consent-for-external-data-transfer.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
privacy-notice-consent-for-external-data-transfer.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
register-integration-in-privacy-notice-registrations.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
register-integration-in-privacy-notice-registrations.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
register-owned-log-tables-for-retention-policies.bad.al Add retention policy knowledge to the privacy domain (#177) 2026-10-05 15:02:04 +02:00
register-owned-log-tables-for-retention-policies.good.al Add retention policy knowledge to the privacy domain (#177) 2026-10-05 15:02:04 +02:00
register-owned-log-tables-for-retention-policies.md Add retention policy knowledge to the privacy domain (#177) 2026-10-05 15:02:04 +02:00
resolve-tobeclassified-before-release.md Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
session-logmessage-requires-dataclassification.bad.al Complete AL review knowledge readiness (#108) 2026-07-15 10:55:25 +02:00
session-logmessage-requires-dataclassification.good.al Complete AL review knowledge readiness (#108) 2026-07-15 10:55:25 +02:00
session-logmessage-requires-dataclassification.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
ship-a-default-retention-policy-setup.bad.al Add retention policy knowledge to the privacy domain (#177) 2026-10-05 15:02:04 +02:00
ship-a-default-retention-policy-setup.good.al Add retention policy knowledge to the privacy domain (#177) 2026-10-05 15:02:04 +02:00
ship-a-default-retention-policy-setup.md Add retention policy knowledge to the privacy domain (#177) 2026-10-05 15:02:04 +02:00
table-level-data-classification-cascades.good.al Scope DataClassification inheritance to fields declared in the table 2026-08-17 15:14:53 +02:00
table-level-data-classification-cascades.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00