Consent & Privacy Service · View 22 of 22 · Assurance
How to read it
- The last two rows are green because the design chooses them: a region denying its own subjects' consent-based purposes, and a control plane outage that stops new purposes without stopping decisions.
- Everything above is a defect with a named owner. "Eventual consistency" is not a cost column entry — unlawful processing is.
- Each bound is a number stated elsewhere in the set: the staleness ceiling, the 15-minute propagation ceiling, the per-target window, the sampling confidence.
The two that worry most
- A silent target closing as complete. The platform cannot distinguish a target that finished from one that stopped answering, except by treating silence as failure — which is the rule, and it will be argued with every time a vendor integration is flaky.
- An identity resolution miss produces an erasure that looks complete to everyone including the subject. It is detected only by re-resolution later, which means the system knowingly ships a class of silent partial failure.
Assumptions
- Every occurrence of a late ALLOW is a reportable defect rather than a tolerance; the target is zero, not a percentage.
- Verification sampling is budgeted, so detection is probabilistic and its confidence is stated rather than implied.