ontology/notes/governance-mnpi-pii.md and config/org_context.md — files you can read, review, and adapt. The domain is regulated (SEC / FINRA in the US, MiFID II in the EU), so the starter ships conservative.
6.1 · Inventory your identifiers — day one
governance-mnpi-pii.md §0 classifies every direct identifier in the connected schema into exactly one role — and the key distinction is that using an identifier as a join key is not the same as outputting it:
| Identifier | Role |
|---|---|
| Client / account / household IDs, SSN / tax_id | Join key only — allowed in ON/WHERE/GROUP BY; never an output column, chart label, or log |
| Client name, address, email, phone, DOB | Never output — not needed for analytics; exclude from SELECT |
| Account number | Never output — aggregate to advisor / segment / household instead |
| advisor_id | Internal key — OK in internal book reporting; not a client identifier |
Prompt
You’ll see: a per-column classification your compliance team signs off on — the rules are templates tuned to your regime, and they can be tightened freely but never loosened without a reviewed, attributable decision.
6.2 · Test the small-cell rule
Prompt
You’ll see: cells whose client/household count is under
min_cell_size suppressed with an explanation — and never an emitted client identifier. The starter default is 5 (books and segments are smaller than payer populations), configured in config/org_context.md. If suppression doesn’t fire, don’t move on — work the pre-flight check above; an unenforced rule you catch is a better demo than a rule you assumed.6.3 · Test MNPI / information-barrier gating
Prompt
You’ll see: Ana decline or constrain the request per §2 — holdings/orders/pipeline can be MNPI, default personas see aggregates not position-level detail for restricted lists, and cross-desk queries that would reveal another desk’s positions are gated. The ontology must not become a side channel around the information barrier; she points to the policy file that governs it.
✅ Checkpoint
- Small-cell suppression fired and was explained
- An MNPI / restricted-list request was gated, with the governing file cited