← Files VeraARCHIVED FILE
privacy/workstreams/journal-sampling.json
6.96 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "journal-sampling",
"display_name": "Journal Sampling",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"mcp",
"assets/review-workbench-adapter.json",
"assets/journal-sampling-review-widget.html"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "journal-qualification-and-sampling",
"purpose": "Resolve source mappings and produce and explain the sampling design",
"content": "User instructions; the current Studio Archive client, engagement and run context needed to locate the managed source; the exact journal input selected by that context; source headers and a bounded preview during mapping; reviewed mappings; normalized journal rows when the professional task requires their interpretation; complete-population statistics computed locally; sampling parameters; diagnostics; and selected sample rows",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "minimized-sample-review",
"purpose": "Review the sampling basis and at most 750 selected entries without transporting the complete local assurance envelope",
"content": "model_review_context.json: method, seed, filters, requested size, complete-population counts, the population assurance proof, sampling-control evidence, allowed review actions, artifact statuses and at most 750 selected rows with the 17 canonical journal columns. Names, descriptions, dates, amounts, identifiers and other row content remain when they are part of the professional review. Exact known file and directory references are replaced by stable opaque ref-* aliases; the full run_intake.json, review_payload.json, ui_decisions.json, final_artifacts.json, source-path list, filesystem paths, timestamps and client-engagement object remain local. Codex and Cowork begin from the same minimized file and portable Studio Archive run. When MCP is available, the current context path lets the local server resolve and verify complete records and persist the bounded review; otherwise the packaged files and Studio Archive CLI preserve the same limits and run lifecycle. Complete artifacts are opened only for a specific unresolved question.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [],
"security_controls": [
{
"id": "qualified-source-before-population",
"control": "Only a bounded source-family adapter or complete source-bound reviewed mapping may emit canonical journal rows; every monetary candidate must be disposed, generic PDF layouts abstain, and failed or unsupported qualification emits no population for sampling."
},
{
"id": "client-engagement-path-isolation",
"control": "Every product CLI requires a digest-valid running Studio Archive journal-sampling context, replays its customer-folder manifests and receipt-bound bytes, accepts exactly one journal execution copy selected by the run input manifest, and writes normalization and sample artifacts only below that run's exact output root. The context is sealed into diagnostics and review artifacts."
},
{
"id": "sealed-population-and-implementation-replay",
"control": "Sampling replays current original-source, captured-parse, reviewed-decision, normalized-population, implementation, and assurance receipts and blocks if the qualified population or its complete monetary disposition has changed."
},
{
"id": "bounded-trusted-memory-review-transaction",
"control": "MCP review save and apply capture the bounded canonical output tree and modes in parent-process memory, execute helpers only against a detached working tree, reject links, aliases, special or oversized entries, and restore exact trusted bytes and modes on failure."
},
{
"id": "parent-owned-review-authorization",
"control": "The MCP parent binds caller run, review, decision, and final objects to the persisted trusted snapshot, reconstructs authorized staged arguments, independently validates the persisted result and readiness, and treats helper-returned paths, effects, and status only as non-authoritative acknowledgements."
},
{
"id": "digest-bound-model-review-projection",
"control": "The deterministic review builder creates model_review_context.json from an allowlisted semantic projection, replaces exact known technical references with stable opaque aliases, removes the client-engagement object, source-path list, timestamps and filesystem paths, and binds the projection to the complete local review digest. MCP tools accept that projection and the current managed-context locator, load full control artifacts locally, reject any projection or caller-state mismatch, and return path-minimized review results. This is technical pseudonymization of references, not anonymization of professional journal data."
},
{
"id": "exact-sample-output-and-successor-chain",
"control": "The sample stage and each review successor seal the exact regular single-link file, directory and mode set, archive every trusted predecessor under its canonical stage identity, bind the successor to the predecessor manifest, and freshly rederive decisions, effects, counts and non-final gates before accepting save or apply."
},
{
"id": "source-execution-with-inert-bytecode-cache",
"control": "Python entrypoints redirect bytecode lookup and disable bytecode writes before validating and loading the declared source implementation. Cache directories and regular bytecode files are excluded from the source receipt set; they are not treated as executable authority. Optional explicit repair removes only ordinary single-link .pyc files directly inside cache folders under this component own vendor tree, without traversing symlinks or falling back to shared vendor roots. This local maintenance path does not add model calls or external destinations."
},
{
"id": "local-review-output-download",
"control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "39cbb0e73b77e4a2217479048fc1c1151bbf9745ad36f2ebc242927f40d53d27"
}
}
SHA-256: 3ce1ae838fcb986db6bc2b1a6cfaa071ad0da02c71b26bb7b8d603b2da56a88d