Data protection

Classification describes how a value must be protected across Ormuz surfaces. It follows the data through bindings and transformations; it must not be replaced by a convention specific to each extension.

Data classification

The cross-cutting contract uses one ordered axis:

normal → sensitive → secret, from the least restrictive to the most restrictive protection level.

ClassUseExamples
normalBusiness data visible in normal observability surfaces to authorized operators.Amounts, statuses, operational identities, business references.
sensitivePersistable data whose raw value requires an explicit reveal action.Suspension reason, some opaque provider responses, or strongly restricted compliance data.
secretData whose raw value must not be persisted in generic state, audit, or logging surfaces.API key, password, OTP, bearer token, token SDK temporaire.

Ormuz classification is not a mechanical translation of external regulatory categories. Financial data required for operations does not become sensitive solely because it is financial.

Propagation

Derived data without a more precise declaration inherits the most restrictive classification of its sources. Omitting security.class therefore does not mean “force normal”.

When the extension natively knows a field's sensitivity, declare it at the relevant path rather than classifying the entire object. Classification that is too broad makes observability unusable; classification that is too weak creates a leak.

Secrets

  • do not return a secret as an ordinary output merely to make it visible to the process;
  • never place a secret in a warning, error, trace, or configuration description;
  • a temporary token remains secret even when its lifetime is short;
  • a URL that carries an access capability must be protected like the credential it represents.

Disclosure to Agents

Internal classification and Agent disclosure policy are orthogonal. A field normal may still be restricted for an Agent, and a Tool low may read data that requires a specific disclosure policy.

Classification ≠ disclosure

Never infer agent_access from security.class alone or from a Tool risk_level: these dimensions answer different questions.

Extension responsibility

Ormuz protects its persistence and observability surfaces. An extension to which a process author has deliberately passed data remains responsible for how it uses that data with the external service.

The right contract must make this egress understandable through the design of the node or Tool; classification does not replace explicit business intent.