08.1
Protect at the source
Redaction after upload expands the number of systems that briefly hold sensitive data. Source-level privacy keeps protected pixels and inputs outside the artifact from the beginning.
That boundary is easier to explain, audit, and trust.
08.2
Make privacy visible
Operators need an unambiguous indication of what is being captured and what is excluded. Hidden policy is not enough when people are sharing real working environments.
The safest controls are easy to check without interrupting the task.
08.3
Window-level control
A professional session may move between a task application and private communication. Window-aware capture can preserve the useful workflow while omitting unrelated surfaces.
Rules should follow the window even as it moves or changes size.
08.4
Audit the absence
A privacy system should record that protection was active without recording the protected content itself.
That evidence lets reviewers confirm the policy while preserving the boundary it created.
