Disciplines · Audits

Eve end-to-end data inventory and flow map

Record digest:

3sections15 minread

On this page

Task 14.1 inventory dated 2026-09-15. It covers 12 source-verified planes × 9 modalities = 108 explicit cells, with 45 flows and 63 fail-closed non-flows.

“FLOW” means payload or a stated minimized projection crosses the plane. It does not mean every downstream privacy control is complete. Each JSON flow cell carries the full required fields and all six destination dispositions.

Plane text structured-record document-pdf image-screenshot audio video code three-d-scene telemetry-evidence
session-http FLOW FLOW FLOW
operator-http FLOW FLOW FLOW
prompt-assembly FLOW FLOW FLOW FLOW FLOW
member-domain-tools FLOW FLOW
client-tool-bridge FLOW FLOW FLOW
retrieval FLOW FLOW FLOW
operator-tools FLOW FLOW FLOW
memory-and-session FLOW FLOW
workbench-intent FLOW FLOW FLOW FLOW FLOW FLOW FLOW FLOW FLOW
model-provider FLOW FLOW FLOW FLOW FLOW FLOW FLOW
voice FLOW FLOW
audit-and-evidence FLOW FLOW FLOW

Open requirements exposed by the inventory#

Cell Field Owner task Exact condition
audit-and-evidence/structured-record deletion 14.4 Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained.
audit-and-evidence/structured-record providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer.
audit-and-evidence/structured-record retention 14.5 Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5.
audit-and-evidence/telemetry-evidence deletion 14.4 Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained.
audit-and-evidence/telemetry-evidence providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer.
audit-and-evidence/telemetry-evidence retention 14.5 Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5.
audit-and-evidence/text deletion 14.4 Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained.
audit-and-evidence/text providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer.
audit-and-evidence/text retention 14.5 Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5.
client-tool-bridge/image-screenshot providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer.
client-tool-bridge/structured-record providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer.
client-tool-bridge/text providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer.
member-domain-tools/structured-record deletion 14.4 Covered V1 subject stores join deletion fanout; total domain and artifact propagation is Task 14.4.
member-domain-tools/structured-record providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for member-domain-tools must be admitted before transfer.
member-domain-tools/structured-record retention 14.5 Retention belongs to each domain store and is not yet joined into one enforceable policy.
member-domain-tools/text deletion 14.4 Covered V1 subject stores join deletion fanout; total domain and artifact propagation is Task 14.4.
member-domain-tools/text providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for member-domain-tools must be admitted before transfer.
member-domain-tools/text retention 14.5 Retention belongs to each domain store and is not yet joined into one enforceable policy.
memory-and-session/structured-record providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for memory-and-session must be admitted before transfer.
memory-and-session/structured-record retention 14.5 Expiry/salience metadata exists for operator memory; a total operator-visible retention policy remains Task 14.5.
memory-and-session/text providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for memory-and-session must be admitted before transfer.
memory-and-session/text retention 14.5 Expiry/salience metadata exists for operator memory; a total operator-visible retention policy remains Task 14.5.
model-provider/audio deletion 14.4 No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.
model-provider/audio destination:storage 14.2 Establish provider-side storage and buffering for every model leg carrying audio.
model-provider/audio modelLeg:speech-to-text 14.2 The speech-to-text leg has no independently verified provider storage, retention, training, residency, or subprocessor record.
model-provider/audio providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
model-provider/audio retention 14.5 Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.
model-provider/code deletion 14.4 No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.
model-provider/code destination:storage 14.2 Establish provider-side storage and buffering for every model leg carrying code.
model-provider/code providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
model-provider/code retention 14.5 Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.
model-provider/document-pdf deletion 14.4 No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.
model-provider/document-pdf destination:storage 14.2 Establish provider-side storage and buffering for every model leg carrying document-pdf.
model-provider/document-pdf providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
model-provider/document-pdf retention 14.5 Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.
model-provider/image-screenshot deletion 14.4 No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.
model-provider/image-screenshot destination:storage 14.2 Establish provider-side storage and buffering for every model leg carrying image-screenshot.
model-provider/image-screenshot providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
model-provider/image-screenshot retention 14.5 Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.
model-provider/structured-record deletion 14.4 No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.
model-provider/structured-record destination:storage 14.2 Establish provider-side storage and buffering for every model leg carrying structured-record.
model-provider/structured-record providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
model-provider/structured-record retention 14.5 Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.
model-provider/telemetry-evidence deletion 14.4 No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.
model-provider/telemetry-evidence destination:storage 14.2 Establish provider-side storage and buffering for every model leg carrying telemetry-evidence.
model-provider/telemetry-evidence providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
model-provider/telemetry-evidence retention 14.5 Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.
model-provider/text deletion 14.4 No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.
model-provider/text destination:storage 14.2 Establish provider-side storage and buffering for every model leg carrying text.
model-provider/text modelLeg:computer-use-planning 14.2 The computer-use-planning leg has no independently verified provider storage, retention, training, residency, or subprocessor record.
model-provider/text modelLeg:embedding 14.2 The embedding leg has no independently verified provider storage, retention, training, residency, or subprocessor record.
model-provider/text modelLeg:escalation 14.2 The escalation leg has no independently verified provider storage, retention, training, residency, or subprocessor record.
model-provider/text modelLeg:judge 14.2 The judge leg has no independently verified provider storage, retention, training, residency, or subprocessor record.
model-provider/text modelLeg:text-to-speech 14.2 The text-to-speech leg has no independently verified provider storage, retention, training, residency, or subprocessor record.
model-provider/text modelLeg:turn 14.2 The turn leg has no independently verified provider storage, retention, training, residency, or subprocessor record.
model-provider/text modelLeg:vision 14.2 The vision leg has no independently verified provider storage, retention, training, residency, or subprocessor record.
model-provider/text providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
model-provider/text retention 14.5 Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.
model-provider/text upstreamSource:apps/oshun/bff/src/assistant/model-registry.ts 15.1 Refresh the model-leg contract's nested binding for apps/oshun/bff/src/assistant/model-registry.ts before using it as current source proof.
operator-http/structured-record deletion 14.4 Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work.
operator-http/structured-record retention 14.5 The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions.
operator-http/telemetry-evidence deletion 14.4 Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work.
operator-http/telemetry-evidence retention 14.5 The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions.
operator-http/text deletion 14.4 Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work.
operator-http/text retention 14.5 The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions.
operator-tools/structured-record deletion 14.4 Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4.
operator-tools/structured-record providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer.
operator-tools/structured-record retention 14.5 Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable.
operator-tools/telemetry-evidence deletion 14.4 Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4.
operator-tools/telemetry-evidence providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer.
operator-tools/telemetry-evidence retention 14.5 Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable.
operator-tools/text deletion 14.4 Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4.
operator-tools/text providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer.
operator-tools/text retention 14.5 Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable.
prompt-assembly/code providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.
prompt-assembly/document-pdf providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.
prompt-assembly/structured-record providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.
prompt-assembly/telemetry-evidence providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.
prompt-assembly/text providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.
retrieval/document-pdf providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer.
retrieval/structured-record providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer.
retrieval/text providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer.
session-http/structured-record retention 14.5 No duration is enforced at this plane; Task 14.5 owns the policy.
session-http/telemetry-evidence retention 14.5 No duration is enforced at this plane; Task 14.5 owns the policy.
session-http/text retention 14.5 No duration is enforced at this plane; Task 14.5 owns the policy.
voice/audio deletion 14.4 No durable local raw-audio store is admitted; provider-side lifecycle remains unproved.
voice/audio destination:storage 14.2 Establish provider-side storage and buffering for the voice audio route.
voice/audio providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
voice/audio retention 14.5 Local buffers are request-scoped, but provider retention is unmeasured and owned by Task 14.2.
voice/text deletion 14.4 No durable local raw-audio store is admitted; provider-side lifecycle remains unproved.
voice/text destination:storage 14.2 Establish provider-side storage and buffering for the voice text route.
voice/text providerTransfer 14.2 Routing enforcement is recorded, but provider practice and subprocessors require independent review.
voice/text retention 14.5 Local buffers are request-scoped, but provider retention is unmeasured and owned by Task 14.2.
workbench-intent/audio deletion 14.4 Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.
workbench-intent/audio destination:artifact 14.4 Register the owning audio artifact store, owner, identity mapping, and deletion propagation path.
workbench-intent/audio providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/audio retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.
workbench-intent/code deletion 14.4 Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.
workbench-intent/code destination:artifact 14.4 Register the owning code artifact store, owner, identity mapping, and deletion propagation path.
workbench-intent/code providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/code retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.
workbench-intent/document-pdf deletion 14.4 Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.
workbench-intent/document-pdf destination:artifact 14.4 Register the owning document-pdf artifact store, owner, identity mapping, and deletion propagation path.
workbench-intent/document-pdf providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/document-pdf retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.
workbench-intent/image-screenshot deletion 14.4 Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.
workbench-intent/image-screenshot destination:artifact 14.4 Register the owning image-screenshot artifact store, owner, identity mapping, and deletion propagation path.
workbench-intent/image-screenshot providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/image-screenshot retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.
workbench-intent/structured-record providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/structured-record retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.
workbench-intent/telemetry-evidence providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/telemetry-evidence retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.
workbench-intent/text providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/text retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.
workbench-intent/three-d-scene deletion 14.4 Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.
workbench-intent/three-d-scene destination:artifact 14.4 Register the owning three-d-scene artifact store, owner, identity mapping, and deletion propagation path.
workbench-intent/three-d-scene providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/three-d-scene retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.
workbench-intent/video deletion 14.4 Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.
workbench-intent/video destination:artifact 14.4 Register the owning video artifact store, owner, identity mapping, and deletion propagation path.
workbench-intent/video providerTransfer 14.2 Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.
workbench-intent/video retention 14.5 Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.

Integrity and scope#

Record digest: 6820699cfc49fbe2a1fc01069c20b19d570399b81e6bd77c792d2218ac057b75.

  • Every Task 4.1 plane and every admitted modality intersect in exactly one explicit flow or not-applicable cell.
  • Every flow records source, purpose, actor/tenant binding, classification, prompt and provider transfer, all six destination kinds, retention, deletion, and owner.
  • Every flow cell participates in at least one typed edge, and every admitted model leg maps to concrete transfer cells, provider targets, and source-bound implementation references.
  • Unknown or partial lifecycle facts remain open requirements with a named owner task; they never default to absent, safe, or complete.
  • A stale nested source digest in an upstream authority is exposed as an owned discrepancy while the current runtime file is bound directly.
  • Cross-plane edges may narrow authority and classification but may not widen either.
  • A new plane, modality, provider leg, destination kind, or source binding invalidates this inventory until regenerated and reviewed.

Limitations#

  • This is a source-bound inventory and flow map, not proof that every listed retention, deletion, minimization, or provider control is deployed.
  • Task 14.2 owns provider and subprocessor practice; Task 14.3 owns end-to-end minimization; Task 14.4 owns complete rights propagation; Task 14.5 owns retention and audited access; Task 14.7 owns creative-media licence and consent.
  • Artifact modalities on the workbench plane describe manifests and references, not an assertion that raw binary payloads are stored in PostgreSQL.
  • The unregistered artifact-custody endpoint is an explicit inventory gap, not a claim that its store, owner, retention, or deletion behavior is known.
  • Media generation, video understanding, and 3D provider legs remain unadmitted; their cells stay explicit not-applicable entries rather than disappearing.
  • Task 13.6 recovery results are local measured evidence for eleven families and do not prove production backup, provider deletion, or legal compliance.
  • The Task 15.1 model-leg record has a stale nested model-registry source digest; Task 14.1 binds the current file and exposes the discrepancy rather than silently treating the older digest as fresh.