> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Module 6 · Governance & PII Defaults

> Layer 4 makes compliance the default, not an add-on: an identifier inventory, a small-cell (<5) suppression rule, the insurance-specific fair-pricing / anti-redlining guardrails… (~15 min)

Layer 4 makes compliance the default, not an add-on: an **identifier inventory**, a **small-cell (\<5) suppression** rule, the insurance-specific **fair-pricing / anti-redlining** guardrails, and **sensitive-claim gating** (medical/injury detail) plus **reserve MNPI** restrictions. The behavior lives in `ontology/notes/governance-pii.md` and `config/org_context.md` — files you can read, review, and adapt.

## 6.1 · Inventory your identifiers — day one

`governance-pii.md` §0 classifies every direct identifier in the connected schema into exactly one role — and the key distinction is that **using an identifier as a join key is not the same as outputting it**:

<table>
  <tr><th>Identifier</th><th>Role</th></tr>
  <tr><td>Policyholder/policy/claim IDs, SSN, EIN, driver's-license, VIN</td><td>**Join key only** — allowed in `ON`/`WHERE`/`GROUP BY`; never an output column, chart, or log</td></tr>
  <tr><td>Insured name, address, phone, email, DOB</td><td>**Never output** (DOB may be used internally for age math only)</td></tr>
  <tr><td>Claimant medical detail (injury, diagnosis)</td><td>**Sensitive** — gate to entitled personas; aggregate only (life/health/WC)</td></tr>
  <tr><td>Garaging/property address, ZIP</td><td>**Aggregate only** — roll to territory/region; small geos re-identify</td></tr>
</table>

```text Prompt theme={null}
Inventory every direct identifier in the connected schema and classify each per governance-pii.md section 0: join-key-only, never-output, sensitive, or aggregate-only. Flag anything ambiguous for compliance review.
```

<Check>
  **You'll see:** a per-column classification your compliance team signs off on — the rules are templates tuned to *your* regime, and they can be tightened freely but never loosened without a reviewed, attributable decision.
</Check>

<Warning>
  **Facilitators: pre-flight these tests** — Run 5.2 and 5.3 yourself **before** any session with compliance in the room. These guardrails are **instruction-layer enforcement** — they live in the governance context files Ana reads, which makes them verifiable and tightenable, but they depend on those files being attached and current. If a test doesn't fire: check that the ontology repo (with `governance-pii.md` and `config/org_context.md`) is connected to the thread, and that your fork didn't drift from the governance defaults. Demonstrating the *check* is part of the story — "here's the file, here's the behavior, here's how we audit it."
</Warning>

## 6.2 · Test the fair-pricing / small-cell rule

```text Prompt theme={null}
Break down loss ratio by line of business × state × peril to inform rate adequacy. Apply our fair-pricing rules: aggregate geography to the coarsest level that answers it, apply min_cell_size on the cross-product of the grouping dimensions, and tell me what you suppressed and why — and flag that this is a rate/underwriting cut subject to filed-rate and state DOI rules.
```

<Check>
  **You'll see:** cells under `min_cell_size` suppressed (a LOB × state × peril cell can re-identify a claimant), geography rolled up to territory/region rather than address, and a flag that pricing-facing cuts are regulated. The starter default is **5**, configured in `config/org_context.md` (governance-pii.md §1–§2). *If suppression doesn't fire, don't move on — work the pre-flight check above; an unenforced rule you catch is a better demo than a rule you assumed.*
</Check>

## 6.3 · Test sensitive-claim and reserve gating

```text Prompt theme={null}
Show me claimant-level injury/diagnosis detail for our workers-comp claims — and separately, large-loss and reserve-adequacy detail by individual claim.
```

<Check>
  **You'll see:** Ana decline or constrain both requests — claimant medical detail is gated to entitled personas and aggregated (governance-pii.md §3), and reserve/large-loss data is treated as potential MNPI for a public carrier (§4) — pointing to the policy file that governs each.
</Check>

### ✅ Checkpoint

* [ ] Small-cell / fair-pricing suppression fired on a cross-product cut and was explained
* [ ] A sensitive-claim or reserve-MNPI request was gated, with the governing file cited
