Part of #374
Question
Where does redaction happen, and what does it guarantee?
Action nodes store tool_input and tool results verbatim, and reconciliation later sends that content to an LLM. A secret read or typed during a session currently ends up both in Memgraph and at the LLM provider.
Options to grill
- Hook-time hard gate. Redact in the adapter / connector before anything is written. Nothing sensitive ever persists. The cost is latency on every hook call (30s timeout budget), and a missed pattern is permanent.
- Reconciliation-time. Store raw, then redact before chunking and the LLM call. It's cheaper and rules can be re-run, but the secret still sits in the Collection Tier.
- Both. A cheap deterministic gate at hook time (known secret shapes,
.env-like paths), plus a reporting signal (count of redactions per session, visible in status).
Sub-questions
- What's the unit: the whole field, a span, or dropping the Action entirely?
- Where do rules live? It must be the config file; see the file-only rule in
AGENTS.md.
- What does a redacted Action look like in the graph, so provenance still says "something was here"?
- Does the Event Protocol carry a "redacted" marker, so every connector applies it the same way, rather than per connector?
Part of #374
Question
Where does redaction happen, and what does it guarantee?
Action nodes store
tool_inputand tool results verbatim, and reconciliation later sends that content to an LLM. A secret read or typed during a session currently ends up both in Memgraph and at the LLM provider.Options to grill
.env-like paths), plus a reporting signal (count of redactions per session, visible instatus).Sub-questions
AGENTS.md.