Privacy, retention and audit essentials
Configure information handling with clear purposes, visibility and human accountability.
Outcome
Information collection, role visibility, retention and supported audit coverage are documented and tested before real worker data enters the pilot.
Find it in TASC
Before you begin
- Documented purposes for each pilot data type
- Approved retention requirements
- Named roles allowed to see individual information
- Worker-facing notices and question route
Interface landmarks
Production V1 path and labels.
Decisions that matter
Visibility by purpose
Grant access because a role must act on the information—not because the data is available.
Retention
Use the approved legal, contractual and operating requirement; document exceptions separately.
Audit claims
Describe supported create, edit, status and assignment coverage by module. Avoid claiming every action is logged without evidence.
Progress is saved on this device only.
Step 1
Map information by workflow
Document what each workflow collects, why it is needed and whether it is anonymous, confidential or identified.
Step 2
Set role visibility
Grant access based on operational need and test the experience for every role.
Step 3
Approve retention
Set retention based on documented legal, contractual and operational requirements.
Step 4
Review Passport sharing
Separate employer roster identity from the Passport information a worker is asked to share.
Step 5
Verify the audit trail
Confirm which supported create, edit, status and assignment events are recorded and exportable.
Step 6
Publish understandable notices
Explain information use before rollout and provide a clear route for questions, corrections and rights requests.
Prove it worked
- Every pilot field has a purpose
- Role tests prove both allowed and denied access
- Retention is approved and recorded
- The Audit Log and CSV export are accessible only to authorized administrators
Common problems and safe recovery
A supervisor can see more worker detail than expected.
Review individual-status visibility, role permissions and module-level access before continuing the pilot.
The audit export lacks an expected event.
Record the gap and confirm module coverage before relying on it for an assurance claim.
What happens next
Run the pilot’s role-by-role access test and retain the approved configuration record with the launch decision.