Skip to content

Data Classification and Handling Architecture

Why this chapter matters

Every keeping begins with knowing what kind of thing is kept. Five of this family's standards require a record to carry its class; this chapter defines the classes once, so that a field required across the family is defined once, and so that the weight of a record's keeping is a recorded judgement rather than a habit. The classes of this standard grade exposure, not truth: a record's evidence class under the Evidence Classification standard answers a different question, and neither substitutes for the other.

Return to the Book of Infrastructure to see the classes serve the whole substrate.

Defines the classification of records by the consequence of their exposure, and the handling postures each class binds.

The classes

  • D0 Open. Records published or approved for publication. Exposure of a published record costs nothing by design, because the record was made to be seen; an approved record keeps its timing until publication. Open is necessary for publication and not sufficient; publication remains its own decision under its own authority.
  • D1 Hall. The working records of the hall: drafts, analyses, indexes, and the ordinary correspondence of the work. Exposure embarrasses without harming. Access is participant-wide and purpose-bound.
  • D2 Guarded. Records whose exposure could harm operations, third parties, or the protective mission: boundary designs in force, unpublished findings, configurations. Access requires a recorded grant, bounded in purpose and time.
  • D3 Sealed. Records whose exposure could harm a person or a protected interest: identity evidence, safeguarding records, testimony held for governance. Access is by named grant only, every movement leaves evidence, and a Sealed record's existence may itself be Sealed.
  • D4 Held. The innermost keeping: material held in trust that is never published, never summarized outward, and never moved without the Architect's own grant. Secret material takes this class by default; its custody remains governed by the Secrets and Key Custody Architecture.

Normative clauses

  • INFRA12-R001: Every record required by this family to carry a class SHALL draw it from the five classes of this standard, exactly one class per record; where more than one class fits, the record takes the highest applicable class.
  • INFRA12-R002: A classification SHALL record the classifier, the basis, the time, and the condition that would trigger review.
  • INFRA12-R003: An unclassified record SHALL be handled as Sealed, and unclassified secret material as Held, until an accountable owner classifies it; the default SHALL record its holder and the condition that ends it, and a first classification below the default SHALL carry the basis and review that INFRA12-R006 requires for lowering.
  • INFRA12-R004: A class SHALL NOT create authority: no class grants access, access to one record grants nothing for another, and declassification is not publication.
  • INFRA12-R005: A derived view, summary, index, or compilation SHALL take the highest class among its sources except where a reclassification under INFRA12-R006 records the reduction, its basis, and its authority, and aggregation review SHALL test whether the combination warrants a higher class than any source alone; a class is raised by evidence and never lowered silently.
  • INFRA12-R006: Reclassification SHALL record the reason, authority, evidence, affected copies and derivations, and propagation; lowering a Sealed record's class requires independent review, and lowering a Held record's class requires the Architect.
  • INFRA12-R007: The class fields of the Trust Zone (INFRA-2), Model Routing (INFRA-3), Memory and Knowledge Storage (INFRA-4), Continuity (INFRA-7), and Network and Gateway (INFRA-10) architectures SHALL draw from this standard, and Held material SHALL NOT enter a model context. Each consumer maps its own postures to the classes as it next revises: what may enter an untrusted model context, what crosses which boundary, and what restoration verification each class demands.
  • INFRA12-R008: This Draft SHALL NOT label, enforce, disclose, or operate a live classification; the classes bind records and designs, not live systems.

This Draft excludes live labelling systems and real records.

Classification method

Classification shall begin with one question: what follows if this record is exposed? The answer selects the class, the class binds the posture, and the posture travels with the record into storage, flows, backups, and model contexts. A classification names its classifier, its basis, and the condition that would reopen it, because a class assigned once and never questioned decays into a label, and a label carries no judgement.

Failure cases

A record put to work above its class, a summary quietly below its sources, an aggregation whose whole reveals what its parts each concealed, a default class worn as a permanent one, and a declassification treated as a publication decision are material failures. Recovery preserves the uncertainty about what was exposed and pauses dependent use until the exposure's reach is established.

Operating model and evidence

Classification review begins with the record's content and consequence, not its container or its convenience. It tests whether the assigned class matches the harm its exposure could do, whether the classification record carries its classifier, basis, and review condition, and whether every derivation and copy carries a class no lower than its sources. The mosaic question is asked explicitly: does the compilation reveal more than its parts?

Consumers of the classes are reviewed for conformance: routing records against what their class permits near a model, storage records against their access class, backups against the verification depth their class demands, and flows against the crossings their class allows. A class field that draws from any other value set is a defect in the consuming record.

Interpretation cases

  • Conforming: A record carries its class, classifier, basis, and review condition, and its derivations carry the highest source class.
  • Prohibited: A class is treated as a grant, with access following the label instead of an authorization record.
  • Boundary: An unclassified record is handled as Sealed while work that does not require it proceeds.
  • Failure: An aggregation reveals more than its parts; its class is raised and dependent disclosures pause.
  • Loophole: A summary is classified below its sources to ease its movement.
  • Misuse: Classification conceals accountability, sealing a record to hide a decision from its rightful reviewers.
  • Care-control: Protective classification limits exposure while preserving a person's access to records about themselves, and their voice, review, and correction.

Design evidence

Classification review should map records to classes, classifiers, bases, and review conditions, walk derivation chains against the highest-source rule and the mosaic question, and sample the consuming standards' class fields for conformance. A record whose class cannot be established is handled as Sealed, and the handling is itself recorded.


Where this document sits

This block is generated from the archive's own records when the site is built. It records position only and creates no authority.