← Files VeraARCHIVED FILE

privacy/workstreams/check-entries.json

10.8 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "check-entries",
  "display_name": "Vouching",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "mcp",
    "assets/review-workbench-adapter.json",
    "assets/check-entries-review-widget.html"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "bounded-entry-and-support-structure",
        "purpose": "Understand the prepared sample and selected support batch before deterministic checks",
        "content": "User instructions; the selected Journal Sampling handoff and support batch; and inspection.json. The inspection artifact can expose the first 20 prepared rows from the complete normalized population with prepared-entry and qualification IDs, journal fields and source locators; metadata for every selected PDF including filename, path, support and qualification IDs, capture hash, extractability, text length and error; and one structured record for every parsed FatturaPA document including source name, document type and polarity, invoice number and date, total and currency, supplier and customer names and tax IDs. The complete normalized population is replayed locally for qualification and one-to-one sample closure, the selected support batch is parsed locally in full, and matching is performed only for sampled entries. A professional may direct the selected runtime to open additional exact evidence when structure or sufficiency cannot be resolved; the workflow does not claim that source files are anonymized.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "non-identifying-review-index",
        "purpose": "Let the model select sampled-entry and support cases without receiving the complete review payload",
        "content": "Aggregate item-type counts and, for each model-relevant item, an opaque per-run case handle, item type, normalized categorical review status, recommended action and only the names of present mechanical signal classes. Signal values, item titles, names, descriptions, dates, amounts, invoice and movement numbers, tax identifiers, source paths and filenames, prepared-entry and support-artifact IDs, review write targets and complete row objects are excluded. Accepted PDF inventory and non-interpretive artifact items remain available to the human widget but are omitted.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "selected-entry-and-support-case-context",
        "purpose": "Interpret or verify only cases selected from the review index",
        "content": "At most 25 requested cases per call: populated allowlisted fields such as status, entry date, signed amount, account name, description, beneficiary or counterparty, currency, checks, mismatches, review notes, support type and match signals, professional and assurance status, extracted amount, date or beneficiary, missing-document reason and bounded extracted evidence facts. Physical paths and filenames, prepared-entry and support-artifact IDs, write targets, empty and unmapped fields and duplicate facts are omitted. Exact movement, invoice, account, tax and reference identifiers are represented only as presence facts by default and can be requested for selected cases when exact identity comparison is required. Real names and case facts can remain; opaque handles are routing controls, not anonymization or pseudonymization of the professional case data.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [
    {
      "id": "accounting-system-export",
      "kind": "external_connector",
      "destination": "User-selected accounting-system provider",
      "purpose": "Acquire an invoice ZIP or folder export when the user chooses connection instead of supplying local support",
      "content": "Authorized read/export request for the selected client and period; the resulting export is stored and mechanically prepared locally, and relevant entries or evidence may enter the selected runtime's model context",
      "optional": true,
      "requires_confirmation": true,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Use only a callable provider-specific connector after the user chooses it and confirms access authority.",
        "Restrict the action to read/export for the selected client and period.",
        "Vera and the helper scripts do not request credentials, tokens, cookies, or one-time codes."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "sealed-upstream-and-support-replay",
      "control": "The Journal Sampling assurance envelope and normalized receipt are replayed before and after support extraction; every support artifact is captured once and its receipt, bounded parser result, qualification, comparison, numeric ledger, and final assurance replay use the same bytes."
    },
    {
      "id": "same-client-engagement-gate",
      "control": "Every product CLI requires a digest-valid running Studio Archive check-entries context, replays its customer-folder manifests and exact selected bytes, accepts support only from that run's receipt-bound execution view, requires the normalized journal, normalization diagnostics, and journal sample to be declared artifacts of one available Journal Sampling run in the same client engagement, and writes only to the exact inspection or checks child of the Check Entries output root."
    },
    {
      "id": "exact-sample-population-handoff",
      "control": "Before inspection or checking, Check Entries restricts the qualified normalized population to the physical source locators in the exact bound journal_sample.csv artifact; an empty sample, duplicate sample locators, or any sample row that does not close one-for-one to the population fails closed."
    },
    {
      "id": "complete-support-membership",
      "control": "A selected support directory is sealed as a complete canonical relative-path manifest; added, removed, replaced, Unicode/case aliases, temporary-prefixed files, symbolic links, hard-link aliases, and special filesystem entries fail closed."
    },
    {
      "id": "source-bound-professional-decisions",
      "control": "Party, support-relationship, currency, and direction exceptions are accepted only as reviewed-decision receipts bound to the exact normalized journal, prepared entry, support artifact and locator; free-text names or amount/date coincidence cannot promote a result."
    },
    {
      "id": "component-private-review-transport",
      "control": "MCP validation can load review_payload.json inside the local server and returns only a non-identifying index plus a random four-hour reference. Rendering exposes the complete digest-valid payload only in tool-result _meta, which is component-only, while model-visible content and structuredContent contain the index. The widget hydrates from toolResponseMetadata and retains the complete human review surface."
    },
    {
      "id": "bounded-selected-case-projection",
      "control": "The read-only case-context tool accepts only opaque handles bound to the current in-memory review reference, rejects unknown or duplicate handles, limits each call to 25 cases and 500000 response bytes, projects explicit post-mapping field allowlists, recursively strips physical and technical identifiers from evidence facts, and keeps exact professional identifiers off unless explicitly requested for those selected cases."
    },
    {
      "id": "transactional-review-writes",
      "control": "MCP save and apply capture the bounded canonical output tree and modes in parent-process memory, execute workflow helpers only against a detached working tree, reject linked, aliased, special, oversized, swapped, or unexpected entries, and restore exact trusted bytes and modes if revision, workbook, assurance, manifest, trace, or commit validation fails."
    },
    {
      "id": "trusted-review-application-postcondition",
      "control": "Inside the transaction, the MCP parent derives run, review, current UI, final state, decisions, effects, paths, gates, readiness, and professional status from the trusted persisted image; supplied copies must match exactly, helper JSON is acknowledgement-only, and every source, run, implementation, review, audit, envelope, and current-output binding is replayed before commit."
    },
    {
      "id": "sanitized-helper-failures",
      "control": "Workflow-child startup, nonzero exit, oversized, empty, malformed, wrongly typed, and contradictory status-zero results fail with bounded fixed messages; child stdout, traceback text, absolute client paths, and unvalidated result fields are not copied into the MCP response or execution trace."
    },
    {
      "id": "exact-initial-transition-and-successor-output-sets",
      "control": "Run, validate, render, save and apply enforce the same workflow-owned physical file and directory perimeter for the initial package, bounded review transition and accepted successor; foreign files, links, hardlink aliases, special entries and post-preflight swaps fail closed, and late failures restore the exact prior tree."
    },
    {
      "id": "source-execution-with-inert-bytecode-cache",
      "control": "Python entrypoints redirect bytecode lookup and disable bytecode writes before validating and loading the declared source implementation. Cache directories and regular bytecode files are excluded from the source receipt set; they are not treated as executable authority. Optional explicit repair removes only ordinary single-link .pyc files directly inside cache folders under this component own vendor tree, without traversing symlinks or falling back to shared vendor roots. This local maintenance path does not add model calls or external destinations."
    },
    {
      "id": "local-review-output-download",
      "control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-28",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "7ab1fdd5ab99aed82c5527b95249c8cd0c698bab3974374d982b4dcbbda679cf"
  }
}

SHA-256: d7afa99388347059c08d19fbfb8ea3c629bed3f24943940458caf853d4afc49b