Context
OpenRAG should support content-risk and personal-data checks without coupling governance to one scanner vendor or model.
Problem
Scanner outcomes, limits, failures, retries, and their effect on source lifecycle do not yet have a stable contract.
Expected behavior
- The contract defines pass, redact, quarantine, review, and failure outcomes.
- Input limits, timeouts, retry behavior, and findings are explicit.
- Outcomes integrate with source-version lifecycle decisions.
- A no-op option keeps scanning optional for existing deployments.
Delivery dependency: RG-06. This track is conditional on pilot requirements.
Context
OpenRAG should support content-risk and personal-data checks without coupling governance to one scanner vendor or model.
Problem
Scanner outcomes, limits, failures, retries, and their effect on source lifecycle do not yet have a stable contract.
Expected behavior
Delivery dependency: RG-06. This track is conditional on pilot requirements.