← Files VeraARCHIVED FILE
privacy/workstreams/centrale-rischi-review.json
8 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "centrale-rischi-review",
"display_name": "Centrale Rischi Review",
"role": "workflow",
"governed_paths": [
".codex-plugin/plugin.json",
"skills",
"scripts",
"assets"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "centrale-rischi-mapping-inspection",
"purpose": "Establish the exact exposure table, columns, duration classes, risk families, report perimeter and reviewed recipe before calculation",
"content": "User instructions; supplied PDF or export and normalized table labels; stable table IDs; every source column name and observed type; table row counts; each table's source SHA-256 hash; the inventory SHA-256 hash; and at most the first 10 rows of each table, with cell text bounded to 200 characters. The complete native-text PDF or supplied CSV or Excel population is read locally to normalize and inventory tables. The full PDF normalization remains a local review artifact by default. Intermediary names, risk categories, dates, amounts, guarantees and prejudicial descriptions may appear in bounded previews and are not automatically anonymized or pseudonymized. Source roles, duration meaning and exposure-family meaning remain model-led and professionally reviewed rather than keyword-classified.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "centrale-rischi-post-calculation-review",
"purpose": "Interpret exact calculated CR facts and identify observations, hypotheses, questions, missing evidence and limitations",
"content": "A bounded model_context.json containing status, entity name, currency, latest reference month, metrics, maturity and risk-category summaries, up to 50 category-movement rows, up to 36 monthly rows, up to 20 previous-record review rows, the top 20 calculated overruns, top 20 exposure-linked guarantees, up to 20 supplied prejudicial events, and up to 20 rows from each separate population of guarantees received, guarantors of the holder, ceded debtors, other risk information, summary totals, inframonthly events and information requests, together with coverage, controls, assurance levels and limitations. Bounded previous-record, exception and auxiliary rows may include intermediary, guarantor, guaranteed-party or ceded-debtor names, dates, categories, relationship or record status, types, reasons, amounts, source pages, row locators and extraction confidence. The current raw source population, previous records beyond the bounded projection, absolute paths, original filenames and source-document hashes are excluded by default.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "centrale-rischi-commentary",
"purpose": "Prepare an evidence-linked professional-review draft without changing calculated facts",
"content": "The bounded calculated context plus draft observations and hypotheses tied to existing evidence references: metric IDs, control IDs or source-row locators present in that context, together with professional questions and limitations. The finalizer validates schema, blocks failed controls, and checks evidence-reference closure; duration meaning, exposure-family meaning, materiality, causation, credit judgment and professional approval remain model-led or professional judgments.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [],
"security_controls": [
{
"id": "client-engagement-path-isolation",
"control": "Every Codex inspector, calculation and finalization writer requires a digest-valid Studio Archive centrale-rischi-review context, accepts only exact receipted inputs or current-run outputs, and writes only below that run's output directory."
},
{
"id": "explicit-reviewed-value-mapping",
"control": "The PDF adapter recognizes only mechanically reviewable table shapes and the inspector does not assign duration meaning or exposure family. Calculation requires an inventory-bound recipe with a named, timestamped reviewed mapping that exhaustively maps each observed original-duration, residual-duration and risk-category value."
},
{
"id": "exact-calculation-boundary",
"control": "Dates and monetary values must parse exactly. Previous or corrected PDF records are retained with provenance but excluded from current and monthly totals. The runner calculates overruns per current row only after a reviewed suffering classification and applies max(used minus operational granted, zero) only to non-suffering rows, without offsetting another operation or intermediary. Utilization is reported by reviewed risk category rather than as one indiscriminate cross-category ratio. Declared control totals outside tolerance block the analysis."
},
{
"id": "missing-evidence-fail-visible",
"control": "Pregiudizievoli, guarantees received, guarantors of the holder, ceded debtors, other risk information, summary totals, inframonthly events, information requests, multi-month movements and financial-statement ratios remain explicitly unavailable when no row was extracted or supplied for the required population; an empty generated review sheet is not treated as proof of an empty source population, and the workflow never substitutes zero, model inference or a universal credit threshold."
},
{
"id": "bounded-post-calculation-model-context",
"control": "The deterministic post-calculation projection excludes the current raw source population, previous records beyond the bounded review projection, absolute paths and original filenames. It exposes only calculated metrics, bounded category movements and monthly series, bounded previous-record and exception rows, up to 20 rows from each separate PDF information population, coverage, controls, assurance levels and limitations. Source-document hashes are excluded from projected rows."
},
{
"id": "evidence-reference-closure",
"control": "Final observations and hypotheses must reference an existing metric ID, control ID or source-row locator present in the bounded model context. The finalizer validates shape and evidence-reference closure while preserving draft_pending_professional_review and never assigning source meaning, materiality, causation, credit judgment or approval."
},
{
"id": "acquisition-adapter-separation",
"control": "Portal navigation, browser automation and PEC retrieval remain upstream evidence-acquisition routes with their own authorization and receipts. Native-text PDF normalization is a local intake adapter that writes separate review tables and a receipt before the normalized workbook enters the ordinary reviewed calculation contract. Exact supported table shapes are extracted; mechanically ambiguous merged grids are quarantined for professional review instead of entering client facts."
},
{
"id": "pdf-layout-provenance",
"control": "A PDF-derived normalization retains the source document hash, page, table region, row locator, current-versus-previous record status and available validity dates. The supported input is the official digital Centrale Rischi report; an image-only copy is rejected with a request for that original digital report. When calculation receives the original PDF again, it verifies the source hash, the run-local normalization receipt and the exact normalized-workbook hash before applying the reviewed recipe; missing, changed or substituted artifacts fail closed."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "36212f01c85b7f9208f02f4f8e9bb94286d043a48d65291f8dad905cc2102153"
}
}
SHA-256: b7e4c9b66f3909328619eafe3bae99a446a8f3a13d78472f684fac12c64b2e54