Skip to main content
Layer 4 makes compliance the default, not an add-on: PII roles (a join key is not an output column), small-cell suppression, MNPI / information barriers on position-level surfaces, and suitability / GIPS framing. The behavior lives in ontology/notes/governance-mnpi-pii.md and config/org_context.md — files you can read, review, and adapt. The domain is regulated (SEC / FINRA in the US, MiFID II in the EU), so the starter ships conservative.

6.1 · Inventory your identifiers — day one

governance-mnpi-pii.md §0 classifies every direct identifier in the connected schema into exactly one role — and the key distinction is that using an identifier as a join key is not the same as outputting it:
IdentifierRole
Client / account / household IDs, SSN / tax_idJoin key only — allowed in ON/WHERE/GROUP BY; never an output column, chart label, or log
Client name, address, email, phone, DOBNever output — not needed for analytics; exclude from SELECT
Account numberNever output — aggregate to advisor / segment / household instead
advisor_idInternal key — OK in internal book reporting; not a client identifier
Prompt
You’ll see: a per-column classification your compliance team signs off on — the rules are templates tuned to your regime, and they can be tightened freely but never loosened without a reviewed, attributable decision.
Facilitators: pre-flight these tests — Run 6.2 and 6.3 yourself before any session with compliance in the room. These guardrails are instruction-layer enforcement — they live in the governance context files Ana reads, plus persona/RBAC (ana.md), which makes them verifiable and tightenable, but they depend on those files being attached and current. If a test doesn’t fire: check that the ontology repo (with governance-mnpi-pii.md and config/org_context.md) is connected to the thread, and that your fork didn’t drift from the governance defaults. Demonstrating the check is part of the story — “here’s the file, here’s the behavior, here’s how we audit it.”

6.2 · Test the small-cell rule

Prompt
You’ll see: cells whose client/household count is under min_cell_size suppressed with an explanation — and never an emitted client identifier. The starter default is 5 (books and segments are smaller than payer populations), configured in config/org_context.md. If suppression doesn’t fire, don’t move on — work the pre-flight check above; an unenforced rule you catch is a better demo than a rule you assumed.

6.3 · Test MNPI / information-barrier gating

Prompt
You’ll see: Ana decline or constrain the request per §2 — holdings/orders/pipeline can be MNPI, default personas see aggregates not position-level detail for restricted lists, and cross-desk queries that would reveal another desk’s positions are gated. The ontology must not become a side channel around the information barrier; she points to the policy file that governs it.

✅ Checkpoint

  • Small-cell suppression fired and was explained
  • An MNPI / restricted-list request was gated, with the governing file cited