chore(privacy): scrub real-org references from plugin internals (phase 2)

Same bulk replacement applied to plugin-internal KB, examples, fixtures,
tests, and docs. Real organization names, persona names, internal system
identifiers, and domain-specific terms replaced with fictional generic
public-sector entity (DDT) and generic terminology.

Scope:
- okr/ — examples, governance, framework, integrations, sources
- ms-ai-architect/ — KB references (engineering, governance, security,
  infrastructure, advisor), tests/fixtures, agents, docs
- linkedin-thought-leadership/ — voice samples, network-builder,
  examples (genericized identifying headlines to "[your organization]")
- llm-security/ — research notes, scan report

Manual genericization beyond bulk replace:
- okr SKILL.md "Primary user / Domain" — generic Norwegian public sector
- linkedin-voice SKILL.md headline placeholder
- network-builder.md headline placeholder
- high-engagement-posts.md voice sample employer line + hashtag

Phase 3 (factual-attribution review) remains: a few KB files attribute
publicly known transport-sector docs/datasets (e.g. håndbok V440, NVDB)
to the fictional DDT after bulk replace. Needs manual semantic review
to either remove or restore correct citation without re-introducing
affiliation references.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Kjell Tore Guttormsen 2026-05-03 04:28:15 +02:00
commit 9ea5a2e6c6
76 changed files with 191 additions and 191 deletions

View file

@ -455,7 +455,7 @@ Hvis Copilot-svar brukes til **vedtak i offentlig sektor**, må:
- Kan data forlate Norge? (compliance-vurdering)
- Hvilke Microsoft-underleverandører har tilgang?
**Anbefaling for SVV:**
**Anbefaling for DDT:**
- **Synced connectors** kun for ikke-sensitive data (public policies, FAQs)
- **Federated connectors** for sensitive data (saksdokumenter, brukerdata)
- **On-prem connector agent** for høyeste data sovereignty

View file

@ -522,7 +522,7 @@ Start-SPOAccessReview -SiteUrl "https://contoso.sharepoint.com/sites/Finance"
- Tilgangskontroll: RBAC via Microsoft Entra ID
- Logging og sporbarhet: Microsoft Purview Audit (1 år retention minimum)
### Statens vegvesen-spesifikke hensyn
### Direktoratet for digital tjenesteutvikling-spesifikke hensyn
**Dataklassifisering:**
- **Åpne data** — Kan brukes i Copilot uten restriksjoner
@ -594,7 +594,7 @@ Descriptor:
### Når anbefale hvilken security pattern?
**Scenario 1: Offentlig sektor (Statens vegvesen) trenger M365 Copilot med intern vegdata**
**Scenario 1: Offentlig sektor (Direktoratet for digital tjenesteutvikling) trenger M365 Copilot med intern vegdata**
**Anbefaling:**
1. **Zero Trust foundation (E5 + SharePoint Advanced Management):**