← Files VeraARCHIVED FILE
privacy/workstreams/archive-organization.json
11.5 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "archive-organization",
"display_name": "Vera · Riordino archivio",
"role": "workflow",
"governed_paths": [
"README.md",
".codex-plugin/plugin.json",
".mcp.json",
"skills",
"scripts",
"references",
"mcp",
"assets/review-workbench-adapter.json",
"assets/archive-organization-review-widget.html",
"requirements.txt",
"requirements-core.txt"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "client-folder-document-evidence",
"purpose": "Understand each selected client document and propose an evidence-backed studio archive category, practice, date, name, anomaly status, or probable-duplicate relationship",
"content": "One registered client and engagement identity and the complete bounded inventory population, not a sample: opaque inventory and item references; purpose-relevant projected client-relative paths, filenames, extensions, MIME types where available, sizes, timestamps, evidence-opening availability, exclusions, and opaque exact-duplicate groups and canonical relationships. Raw local hashes, absolute source paths, Google Drive root, file and parent IDs, versions, capabilities and checksums remain in the sealed local receipt. Selected readable content or transiently downloaded or exported Drive evidence enters context only after local resolution and identity revalidation. Proposed category, document type, date, subject, reference, practice, confidence, reasons, anomaly observations, and probable-duplicate item references remain model judgments",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "archive-review-and-execution-evidence",
"purpose": "Prepare a dry-run filing plan, collect professional decisions, and execute only a separately approved mechanically safe path plan",
"content": "Versioned studio policy; storage mode; projected current and proposed client-relative paths; opaque exact-duplicate relationships; semantic reasons, confidence, anomalies, collisions and blocked reasons; review payload; reviewer alias, actions, notes and edited paths; approved-plan summary; and execution limitations. Deterministic raw source identities, hashes, byte counts, Drive IDs, versions, capabilities and checksums remain in the local executable plan and journals. In Codex and Cowork local-folder mode, when local MCP is callable, the full review is exposed once and later phases use a random hash-bound reference that expires after four hours instead of resending the payload; a bound stored review can persist decisions without repeating the absolute context path and can execute only after a separate explicit approval. Without local MCP, canonical files remain reviewable and decisions remain pending unless persisted artifacts prove save and apply. A text-only unbound supplied review cannot persist or execute changes",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "google-drive-client-archive",
"kind": "external_connector",
"destination": "The user's explicitly authorized Google Workspace account through Google Drive API v3, limited operationally to one client folder bound by stable Drive folder ID",
"purpose": "Snapshot, transiently read, and after separate approval reorganize one My Drive or Shared Drive client archive while preserving Drive file identities",
"content": "Restricted-scope OAuth authorization; exact root folder, Shared Drive, file and parent IDs; names, relative paths, MIME types, sizes, modified times, versions, capabilities and available binary checksums; transient supported binary downloads or Google-native exports used for semantic classification; reviewed target folder paths and filenames; API-created folder IDs; move responses; original and applied parent, name and version state; journal and rollback outcomes",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex"
],
"controls": [
"Require explicit installed-app or administrator-provided authorization for the restricted https://www.googleapis.com/auth/drive scope; keep client secrets outside run artifacts and store refresh tokens only in Studio Archive's owner-only private state directory.",
"Bind one stable Vera client ID to one exact user-selected Drive folder ID, support My Drive and Shared Drive parameters, reject an incomplete listing, and never widen to a studio-wide or all-Drive organization run.",
"Snapshot at most 5,000 non-shortcut files and 2 GB of known binary sizes; preserve stable file and parent IDs, versions, capabilities and available checksums, and import only the sealed JSON receipt into the engagement.",
"Project every snapshot row through an opaque item reference and remove raw Drive IDs, capabilities, versions, checksums and path-ID suffixes before model-led classification; preserve the complete population and every purpose-relevant name, projected path, type, size and date.",
"Open evidence only for an opaque item reference present in the exact engagement snapshot; resolve its file ID locally, revalidate parent, name, version, MIME type, Shared Drive and available checksums, return bounded extracted text without raw execution identifiers, and delete transient download or export bytes immediately.",
"Treat Drive names and document content as untrusted evidence. Model reasoning proposes semantic category and probable duplicates; mechanically verified checksums, IDs, versions, containment and collision checks own the execution boundary.",
"Persist professional decisions first and require a second explicit apply approval. Immediately before each move, re-read the exact file ID and reject changed state, missing move capability, cross-drive targets, occupied names or duplicate names.",
"Move by updating the same file's parent and name, never by copying, overwriting, trashing or deleting. Journal original and applied state, attempt rollback on failure, and leave newly created empty folders in place rather than silently deleting them.",
"Do not transmit Drive content or credentials to a Mparanza service. Only evidence intentionally opened for the active task may enter the user's selected runtime model context."
]
}
],
"security_controls": [
{
"id": "exact-client-run-and-snapshot-binding",
"control": "Every entry point requires a digest-valid Studio Archive archive-organization context for one registered client and run. The folder snapshot is a bounded immutable input receipt for at most 5,000 ordinary files and 2 GB, excludes the Vera ledger, records skipped links or special entries, and follows no symbolic link."
},
{
"id": "semantic-proposal-boundary",
"control": "Model reasoning owns document meaning, category, practice, anomalies, and probable-duplicate judgment across every opaque inventory item; filenames and directories are hints only. Model proposals bind to the opaque inventory and item references. Deterministic code locally rehydrates immutable snapshot rows and owns schema closure, exact SHA-256 duplicates, path templates, containment, collisions, and byte identity."
},
{
"id": "persistent-professional-review",
"control": "The workflow always writes a dry-run plan and pending ui_decisions.json first. The model-facing review excludes raw source identities, hashes, byte counts, Drive IDs and absolute paths while preserving every semantic field and duplicate relationship. In Codex and Cowork local-folder mode, when local MCP is callable, validation binds the review to a random four-hour hash-checked reference so the full payload is not repeated and a reference bound to the stored customer run supports render, save and approval without repeating the absolute context path. Without local MCP, canonical files remain reviewable and decisions remain pending unless persisted artifacts prove save and apply. A text-only unbound supplied plan remains review-only and cannot persist or execute changes. Every proposed move, quarantine, or blocked item requires a persisted collaborator decision before approved_plan.json can be created; the reviewer alias is an accountability label and not an authentication claim."
},
{
"id": "separate-explicit-filesystem-approval",
"control": "Applying review decisions creates only approved_plan.json. A distinct explicit apply command is still required before filesystem changes, so saved or bulk review actions cannot silently authorize execution."
},
{
"id": "no-overwrite-rehash-and-recovery",
"control": "Local apply re-hashes every source after review, rejects missing, changed, linked, escaping, reserved, colliding, or existing targets, creates each target exclusively, and verifies copied bytes before removing the source path. Drive apply revalidates stable file ID, parent, name, version, MIME type, Shared Drive, capabilities and available checksums before using parent/name updates, and rejects occupied or duplicate target names. Neither mode automatically deletes duplicates; both persist every operation, attempt rollback on failure, and expose a guarded explicit rollback for unchanged destinations."
},
{
"id": "private-output-root",
"control": "Policies, proposals, plans, review decisions, approvals, and journals are written only beneath the exact Studio Archive run output directory. Approved client-file destinations remain inside the same selected client root and cannot enter the Vera ledger subtree."
},
{
"id": "local-review-output-download",
"control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
},
{
"id": "local-browser-private-review-payload",
"control": "The local review server requests component-only private review metadata only for the registered render tool. The browser receives that payload locally; normal MCP callers continue to receive structuredContent. This is transport separation, not anonymization of data selected for model review. Reload restores the persisted applied decisions for the same plugin and run through the existing browser path sanitization. It does not apply decisions again or change the external routes. Read-only local rendering accepts validated running, review-ready and completed contexts; Save/Apply still require a running context. Nested result folders resolve the owning portable run and validate the exact requested descendant before rendering. Archived views also show a localized read-only notice and disable Save/Apply; server-side write validation remains authoritative."
}
],
"review": {
"reviewed_at": "2026-09-26",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "a947bd3d4daef2293f8407aa059d985b57e3518457b46bf6dfc1100752f7b616"
}
}
SHA-256: fda8c01cb2dc5d9d53b49f94b53e7a9f552bcb264460f40116461a2aed77022f