Skip to content
Vibedata

Build something that is not there yet

Tag PII columns, apply masking, and prove the masked view to a lower-privilege role

  • When an erasure request arrives and nobody can list which tables hold personal data.
  • When a lower-privilege role can currently see raw PII in a table nobody has classified.

Classify PII columns across an agreed set of schemas, tag them in column metadata, apply masking or column-level security on the target platform, and prove that a lower-privilege role sees masked values. Covers the classification and the masked-view proof, not a wider data-retention or erasure workflow.

Area
Governance and cost
Runs on
  • Microsoft Fabric Lakehouse
  • Microsoft Fabric Warehouse
Built with
  • dbt
Readiness
PlannedAt least one capability or object type this Recipe needs is not supported yet.

Sample This Recipe has not been materialized in the Cookbook repository yet. Its trigger, description, prompt, agent guidance and acceptance conditions, and the explanation below, are prototype drafts. Its name, job, area and readiness come from the reconciled Cookbook seed snapshot. Readiness is a separate question from this one: it says whether the capability exists, not whether the writing has been reviewed.

Review planned Recipe

At least one capability or object type this Recipe needs is not supported yet.

Read the VibeData Recipe `pii-classification-and-masking` at https://getvibedata.ai/cookbook/pii-classification-and-masking At least one capability or object type this Recipe needs is not supported yet. Treat it as a reference, not as work to execute.

Recipe id pii-classification-and-masking · Not yet materialized in the Cookbook repository, so the pointer addresses this page.

Verified by

What has to be observably true before this Recipe is finished.

  • the lower-privilege role's query returns masked values, not raw PII
  • every classified column is tagged in column metadata
  • the masking mechanism used matches what the target platform supports
  • an unclassified column added later is flagged rather than passed through
Recipe promptThe task specification the agent reads. Reference only — it is not what you copy.
Deliver: Tag PII columns, apply masking, and prove the masked view to a lower-privilege role.

Classify PII columns across an agreed set of schemas, tag them in column metadata, apply masking or column-level security on the target platform, and prove that a lower-privilege role sees masked values. Covers the classification and the masked-view proof, not a wider data-retention or erasure workflow.

Execute inside the current Intent. Its Domain, repository, platform, environment and attached sources are the context for this work — read them rather than asking for them.

The work is done when:
- the lower-privilege role's query returns masked values, not raw PII
- every classified column is tagged in column metadata
- the masking mechanism used matches what the target platform supports
- an unclassified column added later is flagged rather than passed through

Report the evidence for each condition above with the result. A condition you cannot meet is something to say, not something to work around.
Agent guidanceHow the agent approaches the work, and what it will not do.

Profile the inputs the grain, joins and measures actually depend on before proposing a model. Put the design up for review — grain first — then build in an isolated copy with tests and documentation landing beside the model rather than after it.

Composes

  • permission and billing reads
  • dbt in the project
  • isolated-copy execution and gate verification

Asks first

Semantic decisions the Intent cannot supply. Never context Studio already holds.

  • which Fabric target this work lands on, when the Domain carries both a Lakehouse and a Warehouse

Guardrails

  • Build in an isolated copy. Production is read, never written.
  • At least one capability this Recipe needs is not supported yet. Say so and stop rather than substituting a different approach.

What you need

  • Microsoft Fabric Lakehouse, or Microsoft Fabric Warehouse.
  • Read access to the billing or permission surface the work reads from.
  • dbt in the project, or the intent to add it.

How it goes

  1. State the outcome in one sentence, in the language the request arrived in.
  2. Let it profile the inputs the grain, the joins and the measures actually depend on.
  3. Review the design. Disagreeing about grain here costs a sentence; after the model exists it costs a rewrite.
  4. Let it build in an isolated copy, with the tests and the documentation landing beside the model rather than after it.
  5. Read the acceptance conditions against the run.

What you end up with

The deliverable, in your own repository, as governance and cost work a reviewer who knows the project reads as native to it. Alongside it, the evidence for every one of the acceptance conditions above — which is the part that is still there in three weeks when somebody asks.