Skip to content

docs: explain how PII anonymization works and how to control it - #161

Merged
anttiviljami merged 1 commit into
mainfrom
claude/admiring-wozniak-06r886
Sep 29, 2026
Merged

anttiviljami merged 1 commit into
mainfrom
claude/admiring-wozniak-06r886

Conversation

@anttiviljami

Copy link
Copy Markdown
Member

Summary

Anonymize mode can give a false sense of security: it is best effort, and custom attributes usually aren't masked unless they're classified. This adds one page that explains how it actually works, and links to it from the places that mention anonymization.

  • New page docs/auth/anonymization.md (/docs/auth/anonymization, under Auth & Security). It covers:
    • Best-effort caveat up front.
    • When anonymization applies: a token with anonymize: true (forced, one-way) vs ?anonymize=true (the caller opts in).
    • Which APIs enforce it: the Entity API (schema-aware, sets the x-epilot-anonymized header, blocks exports) and the Audit Log API (heuristics only). APIs that read entities with the caller's token inherit it. Other APIs don't anonymize.
    • How values are masked (a pseudonym table) and the order in which attributes are classified.
    • What is not anonymized: custom attributes, free text, unusual formats, other APIs, configuration data, quasi-identifiers, search by value.
    • Control via schema: data_classification: pii | public, the Entity Builder Anonymize checkbox (German: Anonymisieren), Entity API examples, and a schema review checklist.
    • Don't edit data through anonymized connections, because pseudonyms get written back.
  • Access tokens: documents read-only and anonymized tokens, with an API example.
  • CLI: documents epilot auth login --anonymize and the Data: anonymized status line.
  • Entity attributes: adds data_classification to the common properties, plus a short section.
  • Agent toolkit: best-effort note, links to the new page, and a caution to prefer read-only connections.

The facts come from @epilot/anonymization, the entity-api (anonymization/*), svc-audit-log-api, epilot-mcp and epilot360-entity-builder-v2.

Companion UI changes, which all link to this page:

  • epilot360-login!215: CLI + MCP approval pages
  • epilot-mcp!5: anonymize on the approval request details
  • epilot360-tokens!24: anonymize option in the token drawer
  • epilot360-root-config!2566: en/de copy
  • epilot-dev/sdk-js: CLI --anonymize copy

Test plan

  • docusaurus build succeeds with no broken links or anchors

🤖 Generated with Claude Code

https://claude.ai/code/session_01W6dmanYSntb6SZZmQ3QfJK


Generated by Claude Code

- New page docs/auth/anonymization: when anonymization applies (token
  flag vs ?anonymize=true), which APIs enforce it, how values are masked,
  the classification order, what is NOT anonymized (best effort), and how
  to control it with data_classification in the Entity Builder
  ("Anonymize" checkbox) or the Entity API.
- Access tokens: document read-only and anonymized tokens.
- CLI: document `epilot auth login --anonymize`.
- Entity attributes: document `data_classification`.
- Agent toolkit: link the new page, warn against writing through
  anonymized connections.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6dmanYSntb6SZZmQ3QfJK
@anttiviljami
anttiviljami merged commit e62f972 into main Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants