← Files VeraARCHIVED FILE
privacy/workstreams/comunicazione-professionale.json
18.6 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "comunicazione-professionale",
"display_name": "Comunicazione professionale",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"schemas",
"prompts",
"assets",
"evals"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "professional-communication-material",
"purpose": "Assess whether a professional development warrants communication and prepare source-backed studio-formatted drafts and visual stories for review",
"content": "The workflow never scans the Studio archive, mailbox or workspace broadly: the professional enumerates exact current sources and any exact prior communications. There is no internal sampling or row/column cap; every selected supported file is snapshotted and processed in full. For prior communications, local code replaces mechanically detectable email addresses, phone numbers, tax identifiers, bank-account identifiers and case numbers with stable placeholders. Model phase 1, in a dedicated session, receives only those stripped prior communications; names, organizations, addresses, locations, roles and identifying combinations may still be visible because semantic pseudonymization requires them. It returns one complete derivative per item plus a contextual identity mapping that is stored locally and never routed downstream. Model phase 2, in a fresh session, receives only the candidate derivatives and reviews residual contextual identification; it does not receive originals, stripped inputs, mappings or the first transcript. Only a ready result unlocks generation. After acceptance, transient stripped inputs and both dedicated history packets are deleted with a digest-bound receipt; original snapshots and the combined identity map remain owner-controlled. Model phase 3, generation, receives selected current-source snapshots, task instructions, Studio/audience/channel information and only the cleared pseudonymized derivatives. Model phase 4, claim assurance, receives only the answer contract, proposed contribution and selected current-source snapshots. Model phase 5, editorial assessment, receives only the proposed contribution and completed claim assurance. Model phase 6, visual assessment, receives only accepted copy, the exact visual manifest and exact rendered files. Claim, editorial and visual packets exclude every prior communication and identity map. Codex and Cowork use the same shared core mechanics. The optional Creative Production boundary is Codex-only and receives only accepted public slide copy and minimal Studio visual context as separately described. This is purpose-preserving pseudonymization, not anonymization or local-only model processing, and session separation is operator-attested rather than a provider-authenticated file sandbox or model-call receipt.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "official-public-research",
"kind": "public_research",
"destination": "Public official legal, tax, regulatory, social-security, corporate, accounting, grant and issuing-authority sources selected for the communication topic",
"purpose": "Locate current authoritative material using generic topic-level queries before a professional claim is proposed",
"content": "Generic norm, authority, measure, date, topic and document queries plus public source metadata and bytes; no client identity, case facts, recipient list, private prior communication, credentials, cookies or session material",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The intake records explicit route selection, destination and asserted approval metadata before a run is prepared.",
"Use generic topic-level queries and keep client identity, case facts and private studio history out of public search requests.",
"Capture exact selected source bytes into the run before confirming claims; a URL string alone is not registered evidence."
]
},
{
"id": "selected-studio-history-connector",
"kind": "external_connector",
"destination": "No active destination: direct connector history intake is blocked until a route can write exact user-selected items locally without returning their content to the calling model",
"purpose": "Reserved future route for exact professional-selected history retrieval without bypassing local identifier stripping",
"content": "No content is currently transmitted by this route; the professional exports each selected post, article, email, newsletter, FAQ, alert or circular to a supported local file",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"Preparation fails closed when the history-connector route is selected because current connector responses cannot guarantee local stripping before model access.",
"The professional selects and exports exact communications to supported local files; the workflow never searches or inspects account history.",
"Store selected history as immutable local snapshots and use it only to propose a reviewable profile; do not copy distinctive passages or infer private beliefs."
]
},
{
"id": "optional-creative-production-board",
"kind": "hosted_service",
"destination": "The Creative Production board in the exact OpenAI Codex workspace selected by the professional",
"purpose": "Compare four to six non-publishable art-direction references for a render story accepted by the independent editorial assessor before Vera creates exact final graphics",
"content": "The exact editorially accepted public slide copy, reader-use descriptions, public source notes, contribution and story digests, minimal Studio colors and social-format rules, and the selected logo snapshot path and hash when present. The handoff excludes source bytes, selected prior communications, client facts, recipient data, credentials, session material and internal source or claim IDs. Returned board metadata, reference images and the user-selected item are snapshotted only in the owner-controlled run for translation and review.",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex"
],
"controls": [
"The intake records explicit Creative Production route selection, exact board destination and asserted approval metadata; that route choice is the confirmation and is not requested again.",
"The deterministic handoff builder rechecks input and contribution integrity, allows only a reviewed publish contribution with a render story, binds every exact slide and the minimal Studio visual context to digests, and excludes source bytes, history text, client facts, recipient data and internal traceability IDs.",
"Creative Production output is declared non-publishable and cannot change claims, copy, dates, numbers, public source notes, Studio identity or logo. A user-confirmed decision records the exact board, revisions, item IDs, snapshotted references, selected item and supported translation tokens. Every preview and release manifest binds that decision and records each selected token as visibly applied or mechanically not applicable; it cannot claim that a token influenced bytes when it had no target. If the skill or board is unavailable, an explicit fallback is recorded and the run continues with the internal visual system."
]
},
{
"id": "approved-send-or-publication",
"kind": "send_or_publish",
"destination": "The exact recipient set, email account, website destination or social account selected by the professional",
"purpose": "Send, upload or publish the exact accepted final communication package after visible destination verification",
"content": "Accepted communication copy and selected accepted attachments or graphics plus destination metadata; no credentials, cookies, session tokens, one-time codes or unaccepted drafts",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The intake records explicit send-or-publish route selection, exact destination and asserted approval metadata before a run is prepared.",
"Require fresh accepted semantic reviews, separate acceptance of exact rendered bytes when present, acceptance of the exact packaged channel files, a successful validation receipt, and final_ready status; immediately before receipt recording, recompute input, contribution, package, output-file and validation-receipt integrity.",
"Never request or store authentication secrets and never mark sent, uploaded or published without a user-confirmed visible receipt or URL bound to the exact accepted package digest and validation-receipt digest."
]
}
],
"security_controls": [
{
"id": "path-bound-private-studio-workspace",
"control": "Workspace initialization requires explicit user confirmation, asserted owner and retention owner, owner-only permissions and an exact bound path outside the Git repository or published roots. Run creation commits from a private staging directory, cleans incomplete same-run staging state on retry, and every mutating command uses a non-blocking operating-system writer lock plus atomic file replacement."
},
{
"id": "integrity-bound-selected-input-snapshots",
"control": "Preparation accepts only regular non-symlink selected files, copies them into owner-only run storage, records byte size and SHA-256, rejects duplicate identities, and binds the complete intake plus source register to one digest. Review, render, package, validation and delivery gates recompute that digest and fail when a source, history item, profile snapshot, logo, register field or intake field is missing or changed."
},
{
"id": "local-stripping-and-isolated-history-pseudonymization",
"control": "The professional must enumerate every exact prior communication in the intake; the workflow does not scan Studio storage or account history. Local preparation extracts complete readable text and replaces mechanically recognizable email addresses, phone numbers, Italian tax codes and labelled tax IDs, valid IBANs and labelled account IDs, and labelled case numbers using fixed auditable patterns before model use. The reversible mapping stays in owner-only local storage and is excluded from the isolated model packet. One isolated model pass receives only those stripped documents and must produce one complete pseudonymized derivative per selected item plus a separate contextual identity mapping. Recording requires exact input binding, every selected history ID once and in order, preservation of every locally inserted placeholder, rejection of normalized mapped-identity reappearance, rejection of newly introduced mechanically detectable identifiers, the bundled prompt hash, affirmative model-assessed semantic dimensions, derivative hashes, owner-only mapping storage and a distinct host session. It stages rather than releases those derivatives. A second fresh model session receives only the candidate derivatives and must clear contextual residual identification without seeing originals, maps, stripped inputs or the first transcript. Only a ready, complete, digest-bound assessment promotes the derivatives. The recorder then deletes transient stripped inputs and both dedicated history packets, records their hashes in a cleanup receipt, retains original snapshots and the identity map locally, and routes only projected derivative paths and hashes to generation. Contribution recording fails when either record or cleanup receipt is missing, when any derivative or map changes, or when a session is reused. These checks materially reduce exposure but do not certify anonymity or a provider-level file-access sandbox; contextual identities may be visible to the selected runtime in the isolated first pass."
},
{
"id": "phase-specific-model-input-packets",
"control": "Generation receives selected current-source snapshots and only the independently cleared pseudonymized history derivatives. Before claim assurance, editorial assessment or visual assessment, a deterministic builder writes one digest-bound allow-list of exact file paths, sizes and SHA-256 hashes for that phase. Claim assurance receives the answer contract, proposed contribution and selected current sources; editorial assessment receives the contribution and completed assurance; visual assessment receives accepted copy, the exact manifest and rendered files. The corresponding recorders fail on a missing, stale, changed or mismatched packet. Every downstream packet rejects history derivatives, history records, identity maps, stripped inputs and history-session packets. Editorial packet preparation validates the completed claim assurance, including answer-contract conformity and explicit professional-judgment routing, before writing or replacing the packet."
},
{
"id": "exhaustive-artifact-and-secret-field-validation",
"control": "Exhaustive JSON Schemas reject unknown intake and contribution fields; a recursive normalized-key guard rejects password, passcode, PIN, OTP, cookie, session-cookie, token, API-key, client-secret, private-key, secret-key and credential fields from model contributions."
},
{
"id": "digest-bound-professional-review",
"control": "Each model contribution is stored with an exact version snapshot and bound to recomputed input and contribution digests plus explicit model provenance. Every gate compares the current workbench with its version snapshot. Review events require user confirmation and locally asserted reviewer identity; superseding a returned or rejected contribution creates a new version, archives prior derived render and package artifacts under the earlier contribution version, and invalidates prior decisions. Rendered-output decisions additionally bind the exact visual-manifest digest."
},
{
"id": "studio-profile-isolation-and-promotion",
"control": "Selected prior communications can create only a reviewable profile proposal. A Studio with no selected history may receive a complete first proposal from an explicit format brief, supplied brand facts and Vera defaults, but cannot use observed-history provenance. Every profile field is labelled observed-history, user-supplied or Vera-default with exact evidence coverage; unsupported channels cannot silently become observed Studio practice. Persistence requires a fresh accepted studio-profile review, versions the prior profile and logo asset in the same exact bound workspace, preserves the field basis and adoption record, and writes a format digest over brand, asset and profile. Later unchanged runs snapshot the stored profile and logo and reject conflicting brand or logo intake unless an explicit profile-revision basis was supplied."
},
{
"id": "accepted-package-render-and-receipt",
"control": "Deterministic renderers operate only after required semantic review acceptance, reject text that cannot fit declared safe geometry, measure circular headers, footers and contact rails, verify extractable PDF text without silent truncation, and record exact output, layout, font and visual-manifest hashes. The isolated visual assessment must bind every carousel slide and each rendered PDF with its exact page count before release. Packaging preserves the contribution's reviewed public source text and URL instead of injecting a generic profile note. It requires user-confirmed acceptance of the current render digest when present, writes validation_pending, and validation of publishable communication additionally requires user-confirmed acceptance bound to the exact package digest. For an already accepted no_publish contribution, validation instead checks the six internal record kinds, exact accepted recommendation text and current semantic review event bindings; no packaged-output approval is invented. An explicit package rejection remains blocking. The resulting no_publication_recommended status cannot authorize external delivery. External receipt recording rechecks current outputs and receipt bindings, requires the approved exact destination and user-confirmed visible evidence, and cannot overwrite prior evidence."
},
{
"id": "digest-bound-creative-direction-handoff",
"control": "The optional Creative Production handoff is emitted only for an explicitly selected route and a contribution already accepted by the independent editorial assessor. It recomputes input and immutable contribution integrity, binds the visual story and each exact slide to SHA-256 digests, limits shared context to public slide copy and minimal Studio visual identity, and labels every direction non-publishable. Rendering is blocked until a current user-confirmed selected-board decision or explicit fallback exists; the decision snapshots references and binds board and translation digests. The final manifest records supported tokens as applied or not applicable and its verifier recomputes that classification from the exact accepted story."
},
{
"id": "qualified-editorial-and-claim-assurance",
"control": "A live editorial assessor is accepted only when its exact provider, model and prompt-template SHA-256 has a current digest-bound result on the blinded product-reviewed high-bar corpus, with no false-ready critical case. History pseudonymization, derivative-only privacy review, generation, claim assurance, live editorial assessment, benchmark qualification and visual assessment record distinct host session IDs and exact prompt hashes; the provenance explicitly states that it is operator-attested and not provider-authenticated. Each contribution is also bound to an answer contract and a separate full-material-claim assurance record that covers every contract dimension and keeps source identity, semantic support, reasoning and professional judgment distinct. Deterministic code scores fixed benchmark outcomes and enforces record closure; it never assigns semantic quality, contextual identifiability or source support."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "a0eda30ad0112c652a44ead1e950d82c07e1fe56a1d3949d3f7efdf5dc8307f4"
}
}
SHA-256: 21e118362c1c41545613d04cb2fb2baee1435daf6936de3fccee66b39f7a3ba8