Problem
The contents of the "Regulation" section in the artifact creation form are not completely aligned with the risk assessment process that experiment owners have to follow (and are familiar with) in order to ensure compliance with WMF's data collection guidelines. In particular, one of the fields requires users to provide a link to the Security and Legal review, when not all data collection projects require it. On the other hand, the "Compliance requirements" field was particularly cryptic in meaning, with users generally missing further clarification of system expectations.
Suggested solution
Fields in the "Regulation" section should be aligned with the steps of the risk assessment process, following @VirginiaPoundstone's suggestions.
| Components | Flow overview | Validation |
| We'll provide users with a 'Risk level' select component that allows users to specify the risks associated with their artifact, and conditionally enable a 'Security and legal review' input to collect the link to the L3SC review in case their artifact has medium or high risk. | The 'Risk level' select is prefilled with the option 'Risk assessment pending', and provides 3 other options: 'Tier 1: High risk', 'Tier 2: Medium risk' and 'Tier 3: Low risk'. The 'Security and legal review' field below is required, and will remain disabled unless users select the options 'Tier 1: High risk' or 'Tier 2: Medium risk' from the 'Risk level' field. If users select either 'Risk assessment pending' or 'Tier 3:Low risk', then the 'Security and legal review' field will remain inactive. | The 'Security and legal review' field will be validated on submit in case users attempt saving a configuration that they have assessed of High or Medium risk without providing a link to the L3SC review. |
Open questions
- The message "Data will be automatically discarded after 90 days of storage." seems to indicate that the system (Metrics platform) will be in charge of discarding said data. Is that the case? Does the message need to be updated to ensure accuracy?
Acceptance criteria
- The Regulation section provides users with a new 'Risk level' select component that allows users to indicate the risk level associated with their artifact
- The Regulation section provides a 'Security and legal review' input component that is disabled by default and becomes active if users select the options "Tier 1: High risk" or "Tier 2: Medium risk"
- Inline validation is triggered under the 'Security and legal review' field if users try to submit high or medium risk artifact without providing the corresponding Security and Legal review link
- Read view has been modified according to the section to show the Regulation details configured for the artifact


