skip to content

How can a year of audit-selection decisions stay reviewable without the log retaining the filers' identities?

level: seniorimportance: nice to knowfreq 33%

answer

  1. two stores, two clocks
  2. token on the row, mapping elsewhere
  3. most review questions need no identity
  4. raw figures are quasi-identifiers too
  5. erase the mapping, not the chain

basics

~20 s

Split the record: decision rows carry a per-subject token and get the long retention, while the token-to-identity mapping lives in a separate store with tighter access and its own clock. Most review questions never need identity at all.

solid answer

~40 s

Two stores, two clocks. The decision row — identifier, timestamp, input snapshot with direct identifiers replaced by a token, versions, score, threshold, action — carries the retention a review needs, typically set by how long a selection can be challenged. The mapping from token to filer identity sits elsewhere, under tighter access and usually a shorter window, and every re-identification is itself a logged, per-case action. Most oversight questions — was the cut applied consistently, did selections concentrate in one filing type — are answered from score, band and outcome without touching identity. Be honest that this is pseudonymisation, not anonymisation: the retained figures are quasi-identifiers, so the row stays personal data while the mapping exists.

go deeper

for a junior

Know that identity need not live on the decision row: a token stands in for the person, and the link back is kept in a different store with tighter access.

for a middle

Explain what each store is for and how long each is kept, and why most review questions are answered from score, band and outcome without any identity at all.

for a senior

Handle the awkward parts: quasi-identifiers in the retained figures, re-identification as an authorised and logged per-case action, and erasure served by dropping the mapping.

for a principal

Set the window from the challenge period the organisation is actually exposed to, and name who may authorise a re-identification and on what basis.

## Split the record A decision log for audit selection has to serve two very different readers. An oversight review wants a year of decisions in aggregate. A challenge wants one decision, attributed to one person. Building one record that serves both means retaining identity on every row for years, which is the outcome you are trying to avoid. The split is straightforward once stated: | part | contents | retention | who reads it | |---|---|---|---| | decision record | id, timestamp, tokenised subject, input snapshot, versions, score, threshold, action | the long window — as long as a selection can be challenged | reviewers, analysts, the append-only verifier | | identity mapping | token to filer identity | the shorter window, and revocable per subject | a narrow role, per case, with the lookup itself logged | The decision rows stay append-only and chained; the mapping is an ordinary, tightly-controlled store that can be written to and deleted from. That asymmetry is deliberate and it is what makes the rest work. ## Most review questions need no identity It is worth checking how much of the review load actually requires a name. "Was the cut applied consistently across the near-threshold band?" needs score, threshold and action. "Did selections concentrate in one filing type or one income band?" needs banded features. "Which model version made these decisions?" needs the version stamp. None of them needs to know who the filer was. Identity is needed for exactly one workflow — someone challenges their own selection — and that is a single-record lookup, authorised per case, through the mapping. Designing for the bulk case first is what lets the identity store stay small and tightly held. ## Pseudonymisation is not anonymisation The common mistake is to call the tokenised record anonymous and relax its controls. It is not anonymous, for two reasons. 1. **The mapping exists.** A pseudonym is a reversible reference by construction. While the mapping is retained, the row is attributable to a person by anyone who can reach both. 2. **The retained figures identify.** Income, sector, region and filing type are quasi-identifiers. A sufficiently unusual combination singles out one filer even with no token at all — and a tax return is full of unusual combinations. So the decision record keeps its access controls and its retention limit. Where an extract leaves for an external review, coarsen the quasi-identifiers — band the income, widen the region — and state the criterion you are releasing under, such as a minimum group size of *k* under k-anonymity, rather than asserting that the extract "has no names in it". ## Choosing the window The retention meant here is how long a **decision record** is kept, which is not the same question as how long a model artifact stays rebuildable; the two are routinely confused because both are called retention. Retention is set from the obligation, not from "storage is cheap". The decision record's window is the longest period in which a selection can be challenged or reviewed, plus a margin. Then it expires, and expiry is enforced by the store rather than by a job someone can disable. Keep that clock separate from the one that governs how long a model artifact stays rebuildable. They answer different questions and are usually different lengths; tying them together over-retains one or truncates the other, and the conversation about each becomes impossible to have on its own terms. ## Erasure against an append-only log The two requirements look contradictory: the decision rows must not be deleted or edited, and a person may be entitled to have their data removed. They are reconciled by deleting the **mapping entry**, not the rows. - The rows survive, with their hashes intact and the chain verifiable. - Nothing in them attributes a decision to a named person any more; the token dangles. - The aggregate record of what the system decided that year remains complete, which is what the oversight review needs. This is the main structural argument for the split, more than access control is. An append-only log that contains identity has no answer to an erasure request except to break itself. One that references identity indirectly has a clean one. The residual issue is the quasi-identifiers in the retained figures, which is why the coarsening rule above applies to anything that leaves the controlled store.

  • Does replacing the filer's name with a token make the decision log non-personal?
    No, not while the mapping exists. Pseudonymisation reduces exposure; it does not anonymise. The retained figures — income, sector, region, filing type — are quasi-identifiers that can single someone out on their own, so the record stays personal data and keeps its access controls and its retention limit.
  • How does an append-only decision log honour an erasure request without breaking its own chain?
    By deleting the token-to-identity mapping entry rather than the rows. The decision rows survive with their hashes intact and the chain still verifies, and nothing in them attributes a decision to a named person any more. The chain is computed over the rows, so removing an entry from a different store leaves it undisturbed.
  • Why are the decision record's retention window and the model artifact's not the same number?
    They answer different obligations. The record's window is set by how long a selection can still be challenged or reviewed. The artifact's is set by how long you may need to rebuild or re-examine a scorer. Tying them together over-retains whichever is shorter and truncates whichever is longer, and hides both decisions behind one setting.

saying these in an interview costs you the question

  • Calls a tokenised record anonymous while the mapping still exists
  • Keeps decision records indefinitely because storage is cheap
  • Retains the filer's name on the row for reviewer convenience
  • Assumes removing the name makes the retained figures non-identifying
  • Uses one retention window for decision records and model artifacts