# Sensitive Input Redaction Checklist

Remove or replace confidential, personal, regulated, proprietary, and security-sensitive information before approved external AI processing.

## Usage note

Redaction reduces exposure but does not authorize a prohibited workflow. If the task depends on restricted facts or combinations that could identify someone, stop and use an approved environment or process.

## How to use this template

1. Confirm that the AI task and vendor are approved for the intended remaining data class.
2. Reduce the source to the minimum passages, fields, media, and relationships needed.
3. Remove direct identifiers, secrets, protected content, metadata, and re-identifying combinations.
4. Replace necessary relationships with safe synthetic tokens and inspect the exported result.
5. Have an authorized reviewer approve the sanitized input and record its controlled disposal.

## Blank template

### Task and authorization

- **Task ID and permitted output:** [Enter]
- **Approved service and use-case card:** [Enter]
- **Original source owner:** [Name/team]
- **Original data classification:** [Enter]
- **Permitted remaining classification:** [Enter]
- **Minimum context required:** [Describe]
- **Redaction owner and reviewer:** [Names]
- **Working-copy location:** [Controlled reference]

### Removal inventory

- [ ] Names, contact details, usernames, account and government identifiers.
- [ ] Health, financial, employment, education, legal, and other regulated details.
- [ ] Credentials, access tokens, private keys, security findings, and internal endpoints.
- [ ] Customer, employee, partner, and confidential business information.
- [ ] Exact locations, dates, rare roles, or event combinations that enable re-identification.
- [ ] Copyrighted or licensed material not approved for this processing.
- [ ] Comments, track changes, hidden rows, formulas, metadata, filenames, and attachments.
- [ ] Images, audio, screenshots, or logs containing overlooked identifiers.

### Transformation record

Duplicate for each class or field.

- **Source field or passage:** [Describe, do not repeat the value]
- **Sensitivity category:** [Enter]
- **Action:** [Remove / Generalize / Synthetic replace / Keep with authorization]
- **Replacement token or range:** [Enter]
- **Relationship that must remain:** [Explain]
- **Re-identification concern:** [Describe]
- **Reviewer decision:** [Accept / Revise / Stop]

### Final review and disposal

- **Pattern searches performed:** [List]
- **Visual and metadata inspection:** [Result]
- **Task still answerable:** [Yes / No and why]
- **Residual sensitive context:** [List or None]
- **Authorized reviewer approval:** [Name/date]
- **Sanitized input version:** [Enter]
- **Mapping-key location:** [Restricted reference or None]
- **Working-copy deletion or retention:** [Owner/date/policy]
