Skip to content

Redaction: hook-time gate, reconciliation-time, or both #375

Description

@antejavor

Part of #374

Question

Where does redaction happen, and what does it guarantee?

Action nodes store tool_input and tool results verbatim, and reconciliation later sends that content to an LLM. A secret read or typed during a session currently ends up both in Memgraph and at the LLM provider.

Options to grill

  • Hook-time hard gate. Redact in the adapter / connector before anything is written. Nothing sensitive ever persists. The cost is latency on every hook call (30s timeout budget), and a missed pattern is permanent.
  • Reconciliation-time. Store raw, then redact before chunking and the LLM call. It's cheaper and rules can be re-run, but the secret still sits in the Collection Tier.
  • Both. A cheap deterministic gate at hook time (known secret shapes, .env-like paths), plus a reporting signal (count of redactions per session, visible in status).

Sub-questions

  • What's the unit: the whole field, a span, or dropping the Action entirely?
  • Where do rules live? It must be the config file; see the file-only rule in AGENTS.md.
  • What does a redacted Action look like in the graph, so provenance still says "something was here"?
  • Does the Event Protocol carry a "redacted" marker, so every connector applies it the same way, rather than per connector?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions