Skip to content

RG-22: Classification and scanner contract #803

Description

@hedhoud

Context

OpenRAG should support content-risk and personal-data checks without coupling governance to one scanner vendor or model.

Problem

Scanner outcomes, limits, failures, retries, and their effect on source lifecycle do not yet have a stable contract.

Expected behavior

  • The contract defines pass, redact, quarantine, review, and failure outcomes.
  • Input limits, timeouts, retry behavior, and findings are explicit.
  • Outcomes integrate with source-version lifecycle decisions.
  • A no-op option keeps scanning optional for existing deployments.

Delivery dependency: RG-06. This track is conditional on pilot requirements.

Metadata

Metadata

Assignees

No one assigned

    Labels

    featAdd a new feature

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions