1.0.0-rc.1 · Release Candidate1 min read
AutoCore Consent Receipts, Withdrawal, and Readiness
Consent categories, revision handling, anonymous/authenticated boundaries, receipt review, and privacy limitations.
Before publishing a privacy draft, verify category values, locale, necessary/optional behavior, revision reference, and resulting public configuration. Do not promise that every receipt is editable, exportable, or erasable from Admin.
| Area | Source-verified boundary |
|---|---|
| Anonymous/authenticated | The relationship is source-dependent and must not be inferred from a label. |
| Withdrawal/expiry | Document only behaviors proven by the current controller and service. |
| Identifiers | Use <POLICY_REVISION_ID>; never publish consent receipts. |
| Readiness | Technical configuration signal only; not automatic GDPR, KVKK, CCPA, or ePrivacy compliance. |
High-risk operation
Use the required permission, reason, confirmation, and post-action verification. UI visibility is not the authorization boundary.
Verification
Verify the route, permission, response state, audit outcome, and public effect before closing the task. Record unknown or configuration-dependent behavior as a limitation.