> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Module 6 · Governance Defaults

> Layer 4 makes compliance the default, not an add-on: PII roles (a join key is not an output column), small-cell suppression, MNPI / information barriers on position-level surfac… (~15 min)

Layer 4 makes compliance the default, not an add-on: **PII roles** (a join key is not an output column), **small-cell suppression**, **MNPI / information barriers** on position-level surfaces, and **suitability / GIPS** framing. The behavior lives in `ontology/notes/governance-mnpi-pii.md` and `config/org_context.md` — files you can read, review, and adapt. The domain is regulated (SEC / FINRA in the US, MiFID II in the EU), so the starter ships conservative.

## 6.1 · Inventory your identifiers — day one

`governance-mnpi-pii.md` §0 classifies every direct identifier in the connected schema into exactly one role — and the key distinction is that **using an identifier as a join key is not the same as outputting it**:

<table>
  <tr><th>Identifier</th><th>Role</th></tr>
  <tr><td>Client / account / household IDs, SSN / tax\_id</td><td>**Join key only** — allowed in `ON`/`WHERE`/`GROUP BY`; never an output column, chart label, or log</td></tr>
  <tr><td>Client name, address, email, phone, DOB</td><td>**Never output** — not needed for analytics; exclude from SELECT</td></tr>
  <tr><td>Account number</td><td>**Never output** — aggregate to advisor / segment / household instead</td></tr>
  <tr><td>advisor\_id</td><td>Internal key — OK in internal book reporting; not a client identifier</td></tr>
</table>

```text Prompt theme={null}
Inventory every direct identifier in the connected schema and classify each per governance-mnpi-pii.md section 0: join-key-only, never-output, or internal. Flag anything ambiguous for compliance review.
```

<Check>
  **You'll see:** a per-column classification your compliance team signs off on — the rules are templates tuned to *your* regime, and they can be tightened freely but never loosened without a reviewed, attributable decision.
</Check>

<Warning>
  **Facilitators: pre-flight these tests** — Run 6.2 and 6.3 yourself **before** any session with compliance in the room. These guardrails are **instruction-layer enforcement** — they live in the governance context files Ana reads, plus persona/RBAC (`ana.md`), which makes them verifiable and tightenable, but they depend on those files being attached and current. If a test doesn't fire: check that the ontology repo (with `governance-mnpi-pii.md` and `config/org_context.md`) is connected to the thread, and that your fork didn't drift from the governance defaults. Demonstrating the *check* is part of the story — "here's the file, here's the behavior, here's how we audit it."
</Warning>

## 6.2 · Test the small-cell rule

```text Prompt theme={null}
Break down AUM and client count by advisor × segment for a review. Apply our suppression rules and tell me what you suppressed and why.
```

<Check>
  **You'll see:** cells whose client/household count is under `min_cell_size` suppressed with an explanation — and never an emitted client identifier. The starter default is **5** (books and segments are smaller than payer populations), configured in `config/org_context.md`. *If suppression doesn't fire, don't move on — work the pre-flight check above; an unenforced rule you catch is a better demo than a rule you assumed.*
</Check>

## 6.3 · Test MNPI / information-barrier gating

```text Prompt theme={null}
Show me position-level holdings detail for [a restricted / watch-listed name], across desks.
```

<Check>
  **You'll see:** Ana decline or constrain the request per §2 — holdings/orders/pipeline can be MNPI, default personas see aggregates not position-level detail for restricted lists, and cross-desk queries that would reveal another desk's positions are gated. The ontology must not become a side channel around the information barrier; she points to the policy file that governs it.
</Check>

### ✅ Checkpoint

* [ ] Small-cell suppression fired and was explained
* [ ] An MNPI / restricted-list request was gated, with the governing file cited
