bcquality/community/knowledge/security/classify-every-field-with-dataclassification.md
Jesper Schulz-Wedde 23184480d0 Triage seed knowledge and document admission test for preview
Remove seven knowledge files whose content is generic software-engineering
guidance that a capable LLM already applies without BCQuality present
(HTTPS-only, secret-leakage-in-errors, no-credentials-in-URLs, silent
security-error swallowing, short transaction scope, HTTP timeouts,
StrSubstNo-vs-concatenation). These fail the remedial-knowledge premise
and dilute the signal of the preview corpus.

Strip the "Seed article — domain stewards should expand" banner from ten
files that are ready to showcase (AA0232/AA0233 rules, FindSet read-only
semantics, SetLoadFields ordering and usage, CalcFields-in-loops,
SecretText end-to-end, DataClassification). The banner remains on files
that still need domain-steward refinement.

Add a "What belongs here" section to the README stating the admission
test: a file exists only if a modern LLM would get something wrong or
miss something without it. Gives contributors a concrete yes/no filter
before they open a PR.
2026-04-23 15:47:01 +02:00

1.5 KiB

bc-version domain keywords technologies countries application-area
26..28
security
dataclassification
gdpr
privacy
euii
compliance
al
w1
all

Classify every field with DataClassification

Description

Every field on every AL table and table extension must carry an explicit DataClassification property. The value drives GDPR tooling, data-subject requests, retention policies, and audit reporting — all of which rely on the field metadata to know what data to include, anonymize, or delete. A field with no DataClassification defaults to ToBeClassified, which is a compliance gap, not a neutral state.

Best Practice

Choose the narrowest value that accurately describes the field's content: EndUserIdentifiableInformation for data that directly identifies a person, EndUserPseudonymousIdentifiers for indirect identifiers, CustomerContent for business operational data, SystemMetadata for system-generated housekeeping, AccountData for tenant/billing, OrganizationIdentifiableInformation for organization-level identifiers. When uncertain between two values, pick the stronger protection.

See sample: classify-every-field-with-dataclassification.good.al.

Anti Pattern

Leaving DataClassification = ToBeClassified on a field, or omitting the property entirely (which resolves to the same default). Code in this state fails compliance audits and breaks the subject-access-request and retention tooling that depends on the property being set correctly.

See sample: classify-every-field-with-dataclassification.bad.al.