Protection covers what a report implies, not just what it says.
Separate identity and protection records, with review of identification risk before any use.
How it works
Source identity and protection context are held in dedicated stores, separate from reporting. A source officer reviews the proposed use against the permitted bounded scope, and identification risk is assessed before any projection or release. Ordinary views omit protected identity and risk context entirely.
Boundaries
Protection applies to implicit identification as well as literal text. A changed proposed use requires fresh review; expired authority or hidden origins block the action rather than degrading quietly.
Source protection
Element
Collection
Versioning
Reviewed per use
Human decision
Source officer decision
Status
Implemented