← Files VeraARCHIVED FILE

privacy/workstreams/browser-automation.json

40.9 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "browser-automation",
  "display_name": "Vera · Automazione web",
  "role": "workflow",
  "governed_paths": [
    "README.md",
    ".codex-plugin/plugin.json",
    "skills",
    "scripts",
    "references",
    "capabilities",
    "requirements.txt"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "bounded-live-browser-process-discovery",
        "purpose": "Let the model interpret and navigate the exact authorized post-login web process from targeted control and state metadata while an operator demonstrates it, the model explores it, or both",
        "content": "Declared process objective and teaching mode; target-site origin and query-free path; bounded before/after control-state fingerprints; selected control roles, locally identifier-redacted accessible names, labels and placeholders, stable non-dynamic test IDs; headings outside tables and grids; generic visible state markers; declared runtime input values needed for autonomous process exploration or replay; action outcomes; branches; postconditions; uncertainties; and generic download-event metadata. Before guided control metadata leaves the local discovery runtime, recognizable email addresses, UUIDs, Italian fiscal codes, IBAN-like or long mixed alphanumeric codes, separated numeric identifiers and long digit sequences are replaced with a fixed marker; a test ID containing one is withheld. Guided observation uses bounded read-only polling and does not claim a raw click stream. The default live route does not request full authenticated-page snapshots, table or grid rows, form values, message or invoice content, screenshots, network bodies, account identifiers, credentials, one-time codes, cookies, tokens, browser storage, session URLs, or reusable login state. Raw guided observations are ephemeral and excluded from transfer. If one specific private data class or screenshot is genuinely necessary, the workflow identifies that exact data and purpose and requires separate operator confirmation before reading it Explicitly selected same-origin iframe controls use the same projection and redaction; unrelated child frames are counted but not inspected. Observation windows report timestamps, elapsed times and stop reasons. The model reads and authors local teaching checkpoints containing process boundaries, step intent, action, decision reason, outcome, postcondition, evidence basis, unanswered questions and an exact resume instruction. Capture summaries retain only timestamps, counts, stop reasons and state hashes. Checkpoints exclude raw control inventories and are neither developer-transfer approval nor execution evidence.",
        "runtime_profiles": [
          "openai-codex"
        ]
      },
      {
        "id": "sanitized-browser-discovery-developer-pack",
        "purpose": "Let a developer who cannot access the target system understand the demonstrated process and author a process-specific capability from reviewed evidence",
        "content": "The selected model may read the sanitized prompt summary, declared site and process boundary, guided or autonomous actor attribution, semantic milestone and action IDs, action intent, query-free paths, before and after control-state hashes, state-change summaries, outcomes, postconditions, branches, uncertainties, discovery and draft hashes, and the non-executable capability draft. A visual may be included only when the operator selects it, separately reviews it for transfer, and confirms that it contains no private values. The developer pack excludes credentials, cookies, browser storage, session URLs, page HTML, unreviewed screenshots, network bodies, downloaded bytes, observed private values, account identifiers, and raw guided capture. Approval for developer transfer is distinct from approval for capability authoring",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "portable-browser-process-capability",
        "purpose": "Review, validate, run, or hand off a process-specific capability without transferring the discovery account or browser session",
        "content": "Capability identity and version, target site and allowed origins, process objective and exclusions, declared typed input references without observed values, structured output declarations, executable milestones, locator candidates, side-effect classifications, postconditions, transitions, sanitized environment-scoped machine receipts, known limits, and deterministic hashes. Portable bundles exclude credentials, cookies, browser storage, session URLs, page HTML, screenshots, network bodies, downloaded business files, runtime outputs, discovery records, observed private values, and account identifiers",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "owner-only-browser-recovery-proposal",
        "purpose": "Allow the current model to recover from a missing action or nested extraction-field locator for the same read-only or reversible action without silently changing the process contract",
        "content": "After a first safe action fails because no declared action locator or nested structured extraction-field locator matches, the selected model receives capability and milestone identity, the exact action-or-field target, action intent, operation and effect, declared locator candidates, allowed origins, current origin and query-free path, postcondition kind, and a sanitized failure hash. It does not receive runtime input values through the recovery request. The model may inspect the bounded current page state and return one semantic locator with a bounded rationale and uncertainty. A nested structured-field repair may use one bounded CSS selector only within the already resolved record container, or explicitly reuse the already resolved action root when the field is that root; the field name, read method and maximum record count remain fixed. Execution then restarts from the capability's declared start state. The JavaScript runtime does not call another model service during execution. The owner-only recovery proposal stores the exact target, locator candidate or resolved-root choice, contract hashes, query-free path, sanitized error hashes and outcome; it is non-portable, unapproved for persistence, excluded from clean validation and excluded from the capability handoff",
        "runtime_profiles": [
          "openai-codex"
        ]
      },
      {
        "id": "private-run-output-artifact",
        "purpose": "Keep structured values produced by an authorized capability run in an owner-only local artifact without automatically adding artifact-only values to model context or the portable handoff",
        "content": "Runtime outputs.json may contain the structured values declared by the capability, including private business metadata. Normal Downloads verification lists names locally before and after a browser download event, excludes existing files, waits for a unique stable regular file and hashes only that new file. Names of unrelated files and downloaded contents do not enter model context. Directory correlation assumes no unrelated concurrent download and is identified separately in receipts. Download entries retained there contain the local file path, byte length, and file SHA-256; download sets are always artifact_only. For artifact_only outputs the runtime response exposes only output name, type, record count, aggregate hash, and owner-only artifact path; the model does not open or emit the output values or downloaded-file path unless the operator separately requests interpretation after the applicable exact model-data disclosure. A failed download may expose only a bounded evidence reason code, a categorical control-mechanism hint, and the post-click origin plus query-free path; it does not expose the href, URL query, raw browser error, page content, or downloaded bytes. Values explicitly declared model_and_artifact or model_summary are returned to the selected model context. Runtime input values are represented in the receipt only by SHA-256 hashes. outputs.json is excluded from the portable capability bundle",
        "runtime_profiles": [
          "openai-codex"
        ]
      },
      {
        "id": "private-batch-review",
        "purpose": "Explain invoice decisions and let the professional inspect the saved batch after processing",
        "content": "Authorized invoice identities, descriptions, amounts, proposed and actual account and tax treatment, client guidance, evidence references, observed outcomes, posting references and explicit human checks or correction requests may enter the selected model context. The standard-library helper stores private JSON revisions and offline escaped HTML outside portable packs and published folders; it performs no network calls or accounting actions. No credentials, session URLs or raw browser capture belong in this report.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "saved-teaching-development-request",
        "purpose": "Prepare a reviewed development handoff from saved work without repeating teaching",
        "content": "The model reads selected saved teaching notes from the known case or run folder and drafts sanitized findings, their evidence basis, requested work, gaps, limits and acceptance checks. The local ZIP contains that reviewed text, referenced checkpoint IDs and bounded capture metadata, file hashes and optionally an already reviewed sealed developer pack. Raw checkpoints, business batch reviews, downloaded files, credentials and session data are excluded. The helper makes no network calls. Only an explicitly authorized separate CR submission sends request.json through the existing plugin-feedback service to mparanza.com; the ZIP is not uploaded by that API. The model and operator review semantic privacy; hashes check integrity only.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "econs-automatic-review-acquisition",
        "purpose": "Prepare an invoice review from saved, reviewed Playwright acquisition phases without accounting writes",
        "content": "The selected Codex model can read exact authorized company codes, invoice identities and numbers, suppliers, invoice states, full line descriptions, existing accounts, VAT codes and amount text, plus review proposals and missing-field exceptions. The collector reads the declared complete population through bounded phase capabilities, checks independent counts and identities, and saves private phase outputs and the existing JSON/HTML batch review after each invoice. Existing mappings remain source evidence, not automatically endorsed proposals. No automatic anonymization or local-only model processing is claimed. The saved profile includes inspected frame selectors and allowed origins; all phases require reviewed discovery. Raw HTML, screenshots, login secrets, cookies and session URLs are outside this acquisition contract. Results remain outside Git and portable developer/capability bundles. For an explicitly bounded trial, the local selection records authorized company codes and invoice IDs; the model selects them from observed list identities. The full source list and independent count remain checked, while only selected invoice details are acquired. Per-client source and selected counts and the limited report scope are retained; an explicit client selection can include a client without the arrival signal but never bypass studio exclusions. Ordinary batch selection uses the observed new-invoice arrival indicator rather than an enabled nightly synchronization setting. The model verifies the meaning of the actual signal when binding the company phase.",
        "runtime_profiles": [
          "openai-codex"
        ]
      },
      {
        "id": "econs-mapping-and-registration-review",
        "purpose": "Review and execute the authorized client-specific ECONS mapping and registration procedure",
        "content": "Full authorized invoice identities and lines, existing account and VAT mappings, exact client-specific pro rata basis, displayed journal amounts and accounting review reasons, posting approval, registration protocol, complete Non contab. verification population and per-client outcome reports. These values may enter the current Codex model context. They stay outside sanitized developer packs and public packages; no second model API is used. Red invoices are read within the consecutive-red bound so the model can review the taught exception against complete observed lines; an eligible model decision still requires the exact two-concordant-association and VAT checks before mapping. The current model separately reviews whether every invoice description is complete before the journal opens; its invoice-bound reason and evidence hash are saved locally. Displayed journal values are saved before journal review, including when that review is interrupted. Contabilizza and final Conferma reg. remain separate stages; a click alone does not establish a completed posting.",
        "runtime_profiles": [
          "openai-codex"
        ]
      },
      {
        "id": "browser-session-and-invoice-prototype-status",
        "purpose": "Resume the same authorized task after a login handoff and report the actual scope and progress of individual invoice downloads",
        "content": "The model receives the handoff-mark result, sanitized session categories, counts, error hashes and owner-only report paths. Session inspection reads tab URLs and inventory metadata locally; only candidate IDs matching the authorized origins are returned as ephemeral task handles, without raw URLs or titles. These handles do not establish the fiscal account. For the Agenzia prototypes the model reads the exact authorized date filters, model-reviewed category accessible names, declared format availability and independent population counts; output summaries contain category/year counts, pages visited, format states, execution mode, prototype status, native-gap markers and sanitized failure metadata. Local append-only run revisions and attempt reports retain file paths, byte lengths, hashes, hashed detail identities, exact XML/P7M/PDF archive metadata and P7M-to-extracted-XML hash bindings; downloaded invoice content and extracted XML are not returned or transferred. Existing authorization and data disclosures govern any targeted account or business-data reading.",
        "runtime_profiles": [
          "openai-codex"
        ]
      },
      {
        "id": "econs-new-conversation-local-setup",
        "purpose": "Recover installed professional instructions and saved or partial screen bindings in a new conversation without retrieving old chats",
        "content": "The host Node helper reads only Vera's known user-local ECONS setup directory. It saves private, hash-bound acquisition and processing profiles, allowed origins and inspected selectors, a studio label, exclusion codes, incomplete setup notes and a prior local run path. The model can read those selected local records and the shipped procedure. It does not scan chats, Downloads, browser profile storage or the rest of the disk, and performs no network calls, package installation or browser actions. Immutable revisions preserve earlier setup; a read-only run retains learned processing bindings. No invoice rows are copied into this setup store, and credentials, cookies, session URLs and reusable approval are prohibited. Prior run references lead only to local reports under the existing invoice-data boundary; saved setup never grants authority for a new posting. The store is excluded from developer packs, remote feedback and public packages.",
        "runtime_profiles": [
          "openai-codex"
        ]
      },
      {
        "id": "persistent-browser-process-lifecycle",
        "purpose": "Select an exact professional process in a fresh conversation and interpret linked teaching, attempts, reviewed feedback and qualification",
        "content": "The current model reads the scoped local process catalog, professional objectives and exclusions, input declarations, selected business parameters supplied by the user, interpreted teaching summaries, artifact/report paths, opaque process and attempt IDs, measured execution duration, counts and hashes, explicit reasons for missing host/model/token measurements, reviewed result judgments, registered release provenance and actual CR status. It writes model-sanitized development/problem descriptions for exact content review. The owner-private SQLite register and attempt directories persist independently of conversations and plugin cache versions. The opaque local machine fingerprint is derived locally from the host name, home path and platform; those source values are not returned or transmitted by the lifecycle helpers. Runtime output values remain governed by their existing delivery declarations; no output values or runtime input hashes are copied into the external technical projection. Model and token measurements are null unless actual host telemetry is supplied with its source. Installed process bindings carry developer-declared process/release lineage but never import another environment qualification. On a developer machine, an authorized export from the existing CR administration command may be matched to the exact reviewed request. The register retains its opaque CR/submission identity, status and export hash as separate administration provenance, not the raw export or status tokens and not a local submission receipt.",
        "runtime_profiles": [
          "openai-codex"
        ]
      }
    ]
  },
  "external_boundaries": [
    {
      "id": "codex-existing-chrome-process-discovery-and-replay",
      "kind": "external_connector",
      "destination": "The authorized operator's existing Google Chrome profile and the explicitly bounded website origins connected through the ChatGPT Chrome extension",
      "purpose": "Teach, discover or replay one authorized browser process in guided, autonomous or hybrid mode with model-led interpretation and Playwright actions while preserving operator-owned authentication",
      "content": "The workflow opens a fresh task tab in the connected Chrome profile unless the operator explicitly identifies an existing tab. During guided observation or autonomous exploration, the selected Codex model receives the declared objective, actor attribution, targeted control and generic state metadata after local identifier-pattern redaction, before and after fingerprints, the target origin and query-free path, declared process inputs when required by active exploration or replay, transition outcomes, branches, postconditions, uncertainties, structured output counts and hashes, and generic download-event metadata. Playwright actions send the declared navigation, filters, values, and other authorized interactions to the target website in the ordinary browser session. Authentication and profile or workspace selection remain with the operator. Full authenticated-page snapshots, business rows, message or invoice content, screenshots, network bodies, browser state, credentials, runtime artifact_only values, downloaded business bytes, and recognizable identifiers embedded in returned guided control text are excluded by default and never placed in the portable capability",
      "optional": true,
      "requires_confirmation": true,
      "runtime_profiles": [
        "openai-codex"
      ],
      "controls": [
        "Use the live boundary only when the operator explicitly requests guided, autonomous or hybrid discovery or execution on an authorized site, account, and process; bind one session to the declared mode, origins, start state, end state, inputs, outputs, model-visible data classes, and side effects.",
        "Use Google Chrome connected under Settings → Computer Use → Google Chrome and the existing extension profile, following the current connection documentation. Create a fresh task tab unless the operator explicitly identifies one existing tab; never enumerate unrelated tabs or launch a standalone Playwright browser, temporary profile, alternate browser controller, or repeated visibility probe.",
        "Authentication and account, taxpayer, company, or workspace selection belong to the operator. Vera never asks for, inspects, types, stores, or transfers a username when used for secret entry, password, PIN, one-time code, SPID/CIE/CNS material, QR code, cookie, token, browser storage, session URL, or reusable login state.",
        "A mixed invoice-download and saved-password request keeps its supported post-login route. Vera explains its operator-owned authentication boundary, uses a confirmed authorized session when available, and hands a required new login to the operator. Saved procedure steps do not retain authentication. No separate enterprise RPA system or credential vault is required by this route; browser availability and target-process validation are checked separately. This clarification adds no credential access, storage or external recipient.",
        "In guided mode use bounded read-only polling of query-free paths and targeted control roles, locally identifier-redacted accessible names, labels and placeholders, stable non-dynamic test IDs and generic state markers. Replace recognizable identifier-shaped substrings before returning metadata to the model, withhold a test ID containing one, and never treat the redaction marker as a literal locator. Do not inject a click logger, claim a raw event stream, retain raw guided capture, or read form values and business rows by default. If one specific private data class or screenshot is necessary, identify the exact data and purpose and require separate operator confirmation before reading it.",
        "Confirm at action time immediately before submitting, sending, signing, paying, publishing, deleting, changing access, uploading private data, or another material external side effect; ordinary read-only and reversible exploration does not require repeated confirmation.",
        "Do not use native accessibility-tree control, screenshot coordinates, or another desktop controller as a Browser Automation fallback. A required operating-system, native-dialog, or non-browser step is recorded as native_gap, handed to the operator, and excluded from capability execution and clean replay evidence.",
        "Write sanitized discovery records, discovery evidence, developer packs and sealed capability bundles only to fresh owner-only local directories outside the Git workspace and published folders; never persist raw page content or overwrite an earlier bundle.",
        "Keep approval for the exact sanitized developer transfer separate from approval for capability authoring. The former permits sealing only the reviewed evidence, discovery record and non-executable draft; the latter is required before promotion. A changed record requires new authoring approval.",
        "Execute promoted capability JSON only through the packaged runtime in the connected Chrome tab. Keep artifact_only output values, local download paths, byte lengths, and file hashes in owner-only outputs.json and expose only output counts, the output-artifact path, and aggregate hashes unless the operator separately requests interpretation.",
        "For a missing action or nested extraction-field locator on the same read-only or reversible action, allow the selected model to propose one semantic locator without another navigation confirmation. A nested structured-field candidate may be a bounded CSS selector only within the already resolved record container, or the model may explicitly choose the resolved action root when that root is the field. The runtime must preserve the exact action-or-field target, action and origin invariants, field name, read method and maximum record count; write a non-portable owner-only recovery proposal; and exclude that run from clean validation. Never use recovery for consequential actions or silently persist the candidate.",
        "Send the reviewed sanitized developer pack only to the intended developer. Send only the separately sealed capability folder to a receiving operator. No browser state, raw guided capture, runtime output, recovery proposal, observed private value, account identifier, or downloaded business file travels with the capability."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "pre-action-origin-boundary",
      "control": "Before each non-navigation action the runtime checks the current origin both before and after asynchronous locator resolution. Extraction also checks immediately before reading each candidate. Existing post-action checks remain. Regressions cover a disallowed initial origin and navigation during input or extraction locator resolution, and verify that the guarded input or read does not occur. These checks do not claim atomic isolation against every possible browser navigation race."
    },
    {
      "id": "model-led-browser-extension-runtime",
      "control": "The workflow binds to the existing Chrome extension profile, creates a fresh task tab by default, uses the model for semantic page and branch interpretation, and uses Playwright for bounded actions and assertions. It has no native desktop-control fallback: a required native or non-browser step is a native_gap handed to the operator and excluded from capability execution and clean replay evidence. A connected Chrome binding replaces the old launcher and visibility ritual; unavailable Chrome produces one setup instruction rather than repeated launch attempts."
    },
    {
      "id": "targeted-model-context-by-default",
      "control": "Authenticated discovery queries targeted control and generic state metadata rather than full page snapshots, table or grid rows, form values, message or invoice content, or screenshots. Guided observation uses bounded read-only polling of before and after states and does not retain a raw click stream. Reading one necessary private data class or screenshot requires a separate exact disclosure and operator confirmation."
    },
    {
      "id": "guided-control-identifier-redaction",
      "control": "Before guided accessible names, labels, placeholders or test IDs leave the local discovery runtime, fixed patterns replace recognizable email addresses, UUIDs, Italian fiscal codes, IBAN-like and long mixed alphanumeric codes, separated numeric identifiers and long digit sequences. A dynamic test ID containing one is withheld, redacted values feed the state fingerprint, and regression tests verify both removal and preservation of short functional terms such as F24. This is a mechanically enforced identifier-exclusion boundary, not automatic anonymization or a semantic relevance decision."
    },
    {
      "id": "separate-reviewed-developer-transfer",
      "control": "The evidence-pack validator requires exact hashes and action coverage and keeps the transfer record separate from the discovery record's capability-authoring approval. The developer pack is owner-only, non-overwriting, contains only the reviewed sanitized evidence, discovery record, non-executable draft and any explicitly selected reviewed visual, and does not imply that the capability is executable."
    },
    {
      "id": "portable-capability-secret-and-evidence-exclusion",
      "control": "The standard-library validator rejects forbidden secret and capture fields, email-address literals, unbounded or query-bearing origins, missing semantic locators, consequential actions without action-time confirmation, private-evidence retention, and portable bundles that claim to contain discovery evidence. HTTPS remains mandatory for non-loopback origins; local synthetic processes may use HTTP only for the exact loopback hosts 127.0.0.1, localhost, or ::1 with an explicit valid port. Sealing is deterministic, owner-only, and non-overwriting."
    },
    {
      "id": "environment-scoped-validation",
      "control": "A capability may claim validated_local only when the finalizer verifies two distinct passed machine receipts with the same execution contract, reviewed discovery, capability version, declared terminal, required outputs, and environment, with no model recovery, locator edits or retained private evidence. Changing the runtime boundary invalidates prior validation evidence. The Windows acceptance run observed a Gmail no-results terminal path and an intermittent extraction failure for a valid non-empty query; the revised draft distinguishes mailbox-ready, results-available, no-results, and transient/loading states and allows one bounded recovery wait. Gmail remains a non-executable draft under the Chrome-only native-gap contract until renewed authoring review and two new clean replays."
    },
    {
      "id": "bounded-model-locator-recovery",
      "control": "When a declared action or nested extraction-field locator is missing, the first run returns a sanitized recovery request and stops. The current model may then inspect the bounded state and propose one semantic locator only for the same read-only or reversible action before a restart from the declared start state. A nested structured-field proposal may use one bounded CSS selector scoped inside the already resolved record container, or explicitly reuse the resolved action root when the field is that root. The runtime preserves the exact action-or-field target, action ID, intent, operation, effect, inputs, outputs, field name, read method, maximum record count, postcondition and allowed origin; never invokes another model service internally; never permits recovery for a consequential action; never mutates the capability; writes a hash-linked owner-only proposal marked unapproved for persistence; and marks the run ineligible for clean validation."
    },
    {
      "id": "reviewed-discovery-provenance",
      "control": "A draft is not executable. Promotion requires the operator-reviewed and approved exact browser-discovery/v2 record, its canonical SHA-256, approval ID, and timestamp. A changed record or capability repair must return through review rather than inheriting approval silently."
    },
    {
      "id": "machine-generated-run-receipts",
      "control": "The connected-Chrome runtime writes owner-only outputs, receipt, and run-lock files. Receipts contain hashes, counts, sanitized action outcomes and environment rather than raw errors, input values, or output values. Failed download receipts may add only a bounded evidence reason code, a categorical control-mechanism hint, and post-click origin plus query-free path; hrefs, URL queries, raw browser errors, page content, and downloaded bytes remain excluded. The finalizer rejects validation fields alone and requires canonical receipt, output, and run-lock artifacts whose cross-hashes and action sequence agree. This proves artifact consistency, not cryptographic attestation of a physical operator or website. The portable bundle excludes outputs.json."
    },
    {
      "id": "scaffolds-do-not-claim-live-support",
      "control": "The Agenzia and TeamSystem source packages remain scaffold until authorized live discovery supplies actual controls, branches, postconditions and clean replay evidence. Brand or process names alone cannot be described as executable support."
    },
    {
      "id": "selected-frame-origin-boundary",
      "control": "Guided observation selects only explicitly identified iframe paths through the connected Chrome frameLocator and locator evaluate APIs. Every selected frame origin, including intermediate nested frames, must match the declared allowed origins before inspecting controls. The target origin is rechecked in the same evaluation that projects controls. The frame uses the existing control metadata redaction and field-value exclusions; sibling frame contents and raw browser errors are excluded. Saved capability execution also selects the reviewed runtime.frame_selectors path, checks frame uniqueness and each actual allowed origin before locator work, before reads/actions and after actions, and applies locator postconditions in that scope. Missing or unapproved frames cannot establish invoice absence. The frame path is included in the execution hash. These checks do not guarantee atomic isolation from all navigation races."
    },
    {
      "id": "single-record-teaching-review",
      "control": "Teaching distinguishes metadata observation, authorized acquisition of one business record, operator review, posting evidence and clean replay. Additional required private data classes are named once and authorized before targeted DOM reads; acquisition uses the existing permitted data boundary. Populated review artifacts remain outside sanitized checkpoints and developer packs. Compact checkpoint summaries preserve declared provenance and questions, verify the revision chain and never establish execution."
    },
    {
      "id": "private-batch-review-history",
      "control": "Exclusive owner-only revision files, hash-chain verification, stale-writer rejection, escaped HTML without external resources and preservation of completed entries. Correction actions link to originals, and human review events are append-only. These checks establish artifact integrity, not semantic correctness or verified browser execution."
    },
    {
      "id": "exact-reviewed-development-export",
      "control": "Prepare a fresh owner-only folder; project only referenced checkpoint evidence metadata; require a reference to actual operator approval and the exact review manifest hash before export. Reject changed, unlisted, oversized or symlink files, unsafe archive paths and invalid source references. Export one ZIP without sending it or inventing a CR number. Observed findings require observed checkpoint references; this does not certify semantic correctness. Partial evidence remains usable with explicit gaps."
    },
    {
      "id": "econs-read-only-profile-and-population-checks",
      "control": "The collector validates all three saved capabilities before browser actions and rejects consequential actions, non-none confirmations, form editing and download operations. The reviewed profile determines the meaning of navigation clicks; code does not infer posting semantics from button names. Exact company/invoice identities, unique IDs, independent row counts and explicit company exclusions govern acquisition. Missing fields remain exceptions; later failures retain earlier review revisions. The managed interpreter invokes fixed local validators and the existing batch report helper with argv and no shell. Fresh run directories must be outside a detected Git checkout; output files use exclusive creation and POSIX owner-only modes. These checks do not attest to live ECONS correctness or Windows ACLs."
    },
    {
      "id": "durable-learning-progress-report",
      "control": "Learning requests route to an initial verified checkpoint before exploration. Every saved revision also creates an owner-only immutable Italian report of declared steps, evidence and gaps. Reports verify the checkpoint hash chain and reject altered report contents; a missing report can be rebuilt without repeating actions. The report does not establish execution or transfer approval. Older conversations can support attributed partial requests without fabricated observations; semantic selection and sanitization remain model and operator responsibilities."
    },
    {
      "id": "econs-verified-processing-and-durable-attempts",
      "control": "Processing validates reviewed phase profiles before actions; requires matching origins, current invoice identity and complete independent row counts; sets association checkboxes true; rereads mappings; verifies displayed journal arithmetic and per-client treatment review; and saves an unverified report before registration. Completion requires a protocol and absence from the same client Non contab. population. Exceptions exit through a reviewed reversible phase; failed exit stops the batch. Exact checks do not certify accounting meaning, live selectors or professional approval. Two clean target-system runs remain necessary. Exact invoice identity and the current detail hash bind the model completeness review before mapping or journal navigation. Non-empty descriptions do not prove full text. Descriptions, review reason and displayed journal values are persisted before the following action or review can fail."
    },
    {
      "id": "turn-scoped-browser-handoff-and-same-tab-recovery",
      "control": "The handoff helper calls the current host markHandoff API on the actual task tab and reports failure without claiming retention. The skill requires a new mark before each unfinished turn. Session diagnosis probes the selected tab and reacquires only the same ID once; other allowed-origin candidate IDs are reported without selecting an account. Exact missing-tab, empty-inventory and unavailable-binding outcomes remain distinct and do not infer an extension cause. Reports exclude raw URLs, titles, identifiers and browser errors."
    },
    {
      "id": "explicit-execution-mode-and-durable-invoice-prototype",
      "control": "Receipt v3 defaults execution mode to unverified. Simulated or unverified runs cannot pass capability finalization; only an explicit live_connected_chrome declaration is eligible, without claiming cryptographic attestation. Real-browser fixture results remain limited to that fixture. The individual invoice runner always retains prototype status, writes initial and per-download revisions and final outputs on handled failures, rejects repeated detail identities and checks download counts against independently observed totals. These checks do not establish live Agenzia compatibility, account correctness or professional validation."
    },
    {
      "id": "persistent-attempt-and-reviewed-cr-lineage",
      "control": "The local register uses owner-only paths, parameterized SQLite writes, immutable records with hashes and explicit attempt IDs. Runtime attempts have an exclusive execution-start marker, exact registered contract hash checks, current host capability checks and a local machine fingerprint. Missing or corrupt linked output evidence remains an unverified partial report and cannot qualify. Qualification reuses the existing full two-clean-live-receipt finalizer, requires exact result reviews and an accepted elapsed-time bound, and is suspended by later unfinished/failed/recovered/incorrect or slow results. These checks establish record consistency, not cryptographic browser/account attestation. External feedback reuses the existing exact reviewed archive and client, transmits only the frozen structured body, records the actual returned CR, keeps tokens in the CR client store, and deduplicates uncertain retries across client version updates. It does not upload ZIPs, fiscal documents, customer identifiers, input values or output values. Written findings still require semantic sanitization and actual transmission authorization."
    },
    {
      "id": "named-operation-exact-procedure-binding",
      "control": "A source-owned named skill carries its process description, exact executable contract and hash, authored result checks and model-data boundary. The public skill invokes only its adjacent binding; it never selects from the development catalog. Local drafts cannot silently replace or invalidate the released version. Package checks reject an altered procedure binding. Export creates reviewable source and does not publish, attest to professional correctness or import another machine qualification. The shared executor and reviewed technical-feedback boundary are unchanged."
    },
    {
      "id": "resumable-agenzia-artifact-acquisition",
      "control": "The category/year acquisition runner requires a model-reviewed explicit plan with exact single-year filters, independently observed counts, and declared original/PDF availability. It verifies browser-event and stable-directory evidence, preserves XML/P7M originals byte-for-byte, extracts only CMS-encapsulated FatturaPA XML with a source hash binding, verifies a native PDF signature, and never claims P7M signature, certificate, signer, or revocation validation. Native Print to PDF remains an operator-owned native_gap and excludes the run from clean browser validation. Fresh owner-only directories, exclusive writes, append-only hash-linked revisions and attempt reports, retained-artifact verification, duplicate detail rejection, exact page/count reconciliation, and bounded page/invoice limits prevent blind overwrite or completion claims after incomplete work. The model receives only category/year aggregates, format states, native-gap markers, prototype status, owner-only report paths, and sanitized errors; invoice bytes and extracted content stay outside model context and portable bundles. Simulated tests do not establish target-site compatibility. CR-49 still requires two clean repetitions on the exact released version, including the requested category and resume evidence."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-15",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "e0203175d93fc35b5b249eb7536bdf0efcbb0b6b6fbc894c960858c84cdf1f6f"
  }
}

SHA-256: c36fc47bfa1fefbd54e0ee997e13c25783506f2e277ec950d5769aeedd9b47a4