Problem
Private action input currently reaches four preview paths: approval requests, optional audit input previews, sandbox envelopes, and normalized error metadata.
The shared redactor hides named sensitive fields and common encoded forms, but it cannot classify arbitrary data under neutral field names.
Deepgram transcription.bytes proved the gap: an unknown extra field reached a persisted approval preview before adapter validation rejected it.
Acceptance
- Let a catalog action declare a private input preview projection or an explicit no-input preview.
- Carry that action policy into approval, audit, sandbox, and error normalization before any preview is stored or returned.
- For Deepgram bytes, show only validated allowlisted content type and byte count if useful; omit unknown input fields and raw bytes.
- Prove all four paths omit nested, encoded, malformed, cyclic, and unknown private values under neutral field names.
- Keep useful previews for nonprivate actions and preserve current public connector contracts unless a versioned change is required.
This is a follow-up to #316. The current named contentBase64 field remains redacted; neutral-key detection is defense in depth, not a complete privacy boundary.
Problem
Private action input currently reaches four preview paths: approval requests, optional audit input previews, sandbox envelopes, and normalized error metadata.
The shared redactor hides named sensitive fields and common encoded forms, but it cannot classify arbitrary data under neutral field names.
Deepgram
transcription.bytesproved the gap: an unknownextrafield reached a persisted approval preview before adapter validation rejected it.Acceptance
This is a follow-up to #316. The current named
contentBase64field remains redacted; neutral-key detection is defense in depth, not a complete privacy boundary.