← Files VeraARCHIVED FILE
privacy/workstreams/client-file-preparation.json
7.02 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "client-file-preparation",
"display_name": "New Client · File Preparation",
"role": "internal_engine",
"governed_paths": [
"skills",
"scripts",
"mcp",
"schemas",
"assets/review-workbench-adapter.json",
"assets/client-file-preparation-review-widget.html"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "client-file-evidence",
"purpose": "Classify the incoming file, interpret evidence, and prepare the studio intake",
"content": "Default model_handoff pages contain one metadata record for every inventoried file with candidate lexical category status, PDF embedded-text coverage (total, processed, text-bearing, text-missing and unprocessed page indexes), and fiscal extraction disposition (including unreadable, unsupported and recognized-without-fields outcomes), exception-only document excerpts up to 600 characters, every mapped fiscal field with its exact value, candidate or reviewed document-kind status, and a citation up to 600 characters, missing-request candidates for professional review, reviewed email requests with the generic CLIENT-001 reference, generic duplicate groups, and XML anomaly or opaque duplicate-group references without invoice party fields. Exact local documents, extracted text, drafts, identifiers, review state, and package state may still enter when selected for professional review or required by the task.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "approved-managed-ocr-runtime",
"kind": "public_research",
"destination": "Python Package Index (PyPI) and PaddleOCR model-weight hosts",
"purpose": "Install and initialize the optional shared PaddleOCR runtime after the user approves the roughly 500 MB first-use download",
"content": "Declared OCR package names and version constraints from the published requirements-ocr.txt, requested OCR language and model files, plus ordinary package-host request metadata; no user files, document contents, prompts, client data, or extracted evidence are sent",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The input preflight requests setup only for images or visual-only PDFs that require OCR.",
"The workflow requires explicit user approval before installation and the automatic document retry that initializes missing OCR models.",
"The installer uses only the published OCR requirements and writes to a fingerprinted user-scoped runtime shared with Vera and Clara."
]
}
],
"security_controls": [
{
"id": "source-and-package-integrity",
"control": "The workflow does not follow source symlinks, binds extraction and resumable checkpoints to source and extracted-text hashes plus exact run settings, rejects source type, size, or byte drift, and seals reviewed outputs by hash. Reviewed fiscal adapter selections are bound to the exact extracted-text hash; every source retains an explicit extraction disposition. OOXML parsing rejects DTDs, entity declarations and external references at the parser boundary across supported encodings."
},
{
"id": "review-persistence-binding",
"control": "Validate, Render, Save, and Apply can reuse an opaque, four-hour server-held binding tied to the exact run and review hashes, so the private review payload is not retransmitted merely to carry state; unknown, expired, cross-run, or mismatched tokens are rejected."
},
{
"id": "purpose-scoped-review-preview",
"control": "After candidate classification, routine high-confidence document rows retain metadata and exact source references without repeated text previews; previews remain for exceptions, and fiscal evidence plus draft text remain available where professional review needs them. The local review renders the existing request_text and draft preview before a decision. Reload restores the same-run applied record through the existing path sanitization; an applied draft replacement is shown only when its recorded effect updated that exact artifact. These views do not send email or add an external route. Read-only local rendering accepts validated running, review-ready and completed contexts; Save/Apply still require a running context. Nested result folders resolve the owning portable run and validate the exact requested descendant before rendering. Archived views also show a localized read-only notice and disable Save/Apply; server-side write validation remains authoritative."
},
{
"id": "purpose-shaped-model-handoff",
"control": "Codex and Cowork use the same hash-listed, deterministically ordered model_handoff pages when available. Every page is preflighted at no more than 2,500 items and 1,500,000 bytes and the complete population is paginated without sampling. Email drafting receives only reviewed requests plus CLIENT-001; XML synthesis receives anomaly and opaque duplicate-group refs without supplier/customer names, customer tax identifiers, or raw duplicate keys."
},
{
"id": "draft-only-email",
"control": "The workflow writes a reviewable email draft and never sends it automatically."
},
{
"id": "private-output-root",
"control": "Every public entry point requires a digest-valid Studio Archive client-file-preparation context, accepts source material only from that engagement's managed inputs or prior artifacts under the same engagement workspace, and writes only to the context's run output root or a descendant."
},
{
"id": "local-review-output-download",
"control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
},
{
"id": "local-browser-private-review-payload",
"control": "The local review server requests component-only private review metadata only for the registered render tool. The browser receives that payload locally; normal MCP callers continue to receive structuredContent. This is transport separation, not anonymization of data selected for model review."
}
],
"review": {
"reviewed_at": "2026-09-26",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "b16ebcc5d9d36f8655e9fee4dd38e6dfc4aade6496ae07e2cc607b7e8b205949"
}
}
SHA-256: 3d402ed1c80756812d6313da46ca95c4f653ee65bc858d52cf65bbca42665957