← Files VeraARCHIVED FILE
privacy/workstreams/management-control-pack.json
8.44 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "management-control-pack",
"display_name": "Management Control Pack",
"role": "workflow",
"governed_paths": [
".codex-plugin/plugin.json",
"skills",
"scripts",
"assets"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance",
"vendor/modules/reporting_table.py"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "management-control-mapping-inspection",
"purpose": "Establish source roles, reporting perimeter, exact columns, accounting categories, signs, periods, controls, and the reviewed recipe before calculation",
"content": "User instructions; supplied export and sheet names; every source column name and observed type; table row counts; and at most the first 10 rows of each table, with cell text bounded to 200 characters. The complete supplied CSV, Excel, or ZIP population is read locally to inventory the tables. Source roles, account meaning, customer identity, and signs are selected through model-led and professional review rather than filename rules. Vera performs no automatic anonymization or pseudonymization. The reviewed recipe also declares the report audience and the source basis/assumptions for remaining-month forecast estimates.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "management-control-post-calculation-review",
"purpose": "Interpret the exact management pack and identify observations, hypotheses, questions, missing evidence, and limitations",
"content": "A bounded model_context.json containing calculated metrics, coverage and control statuses, calculated section rows capped at 60 per section (including monthly series and service profitability), top-party lists capped at 20, and customer rows additionally limited by the reviewed top-customer setting (1 to 50), source IDs and hashes, and limitations. Local code rebuilds this projection from the complete calculated pack and writes a hash-bound validation receipt; the complete pack is not a separate default model input. Raw source populations, absolute paths, and original filenames are excluded from this post-calculation projection by default. Budget comparison rows are separately capped at 60, with the full row count disclosed. All calculation metric IDs remain available. Full report HTML contains all views; the cap applies to the default model projection only.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "management-control-commentary",
"purpose": "Prepare a metric-linked professional-review draft without changing calculated facts",
"content": "The bounded calculated context plus draft observations and hypotheses tied to exact metric IDs, management questions, and limitations. The deterministic finalizer checks pack identity, rejects a blocked pack or failed declared control, and validates commentary schema and metric-reference closure; business causation, accounting correctness, completeness, materiality, and professional approval remain model-led or professional judgments.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "budget-sites-report",
"kind": "send_or_publish",
"destination": "OpenAI Sites through the selected host Sites connector",
"purpose": "Publish the reviewed budget and forecast report for the selected readers",
"content": "The host uploads the complete rendered HTML: entity, all compiled financial comparisons including hidden views, forecast basis, coverage and limitations, metric-linked commentary and optional customer, supplier and service labels. Raw export populations, original files, local paths and the full pack JSON are not copied into dist. The local preparation helper makes no network request. Sites manages hosting and visitor access; retention and deletion are not enforced by the plugin.",
"optional": true,
"requires_confirmation": true,
"controls": [
"An explicit Sites publication request selects this route; host-required action approvals still apply. Invitations need authorized recipients.",
"Source replay must equal the persisted pack. The audience must match the reviewed recipe. Blocked or unsupported budget reports cannot be prepared. A fresh output folder preserves prior versions.",
"All compiled HTML views remain delivered; selection controls do not redact hidden values. No automatic anonymization occurs.",
"Verify deployment and visitor access. Refresh requires new source review and explicit publication using the existing Site ID."
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
],
"security_controls": [
{
"id": "client-engagement-path-isolation",
"control": "Every Codex inspector, calculation, and finalization writer requires a digest-valid Studio Archive management-control-pack context, accepts only exact receipted inputs or current-run outputs, and writes only below that run's output directory."
},
{
"id": "explicit-reviewed-source-mapping",
"control": "The inspector does not assign semantic table roles. The runner requires a recipe bound to the current input inventory and a non-empty reviewer and timestamp with mapping_review.status=reviewed before any calculation."
},
{
"id": "exact-calculation-and-control-boundary",
"control": "Dates must match the reviewed format, monetary values use Decimal arithmetic, reviewed field multipliers encode any sign normalization, categories must close through the reviewed mapping, bank movements remain inside the reporting window, balances remain at or before cutoff, aging uses explicit cutoff buckets, and any failed declared source control total blocks the pack."
},
{
"id": "missing-section-fail-visible",
"control": "A missing or invalid general-ledger contract blocks execution; unavailable optional Budget, aging, bank, concentration, or profitability evidence is preserved as an explicit unavailable section and partial pack rather than replaced by model inference."
},
{
"id": "bounded-post-calculation-model-context",
"control": "The deterministic runner validates exact equality between the bounded projection and a fresh projection rebuilt from the complete calculated pack, hashes both artifacts in model_context_receipt.json, and excludes the complete pack from the default model-read set. The bounded projection excludes raw source populations, absolute paths, and original filenames and exposes only calculated metrics, bounded series, top-ranked rows, controls, lineage IDs, and limitations for interpretation."
},
{
"id": "metric-reference-closure",
"control": "Calculated observations and hypotheses in the final commentary must reference existing metric IDs. The finalizer rejects blocked packs and failed controls, then validates shape and reference closure while preserving draft_pending_professional_review and never assigning semantic correctness or approval."
},
{
"id": "sites-source-replay",
"control": "The preparation helper rebuilds the pack from the hashed inventory and reviewed recipe, requires exact equality with the supplied pack and matching audience, rejects blocked or unsupported reports and requires a new output directory. The HTML is rendered from those checked values. This checks declared audience equality, not the suitability of the audience for private content."
},
{
"id": "receipt-bound-loopback-preview",
"control": "The read-only preview requires a valid current or completed management-control archive context and the exact native commentary receipt and report hash. It serves only pinned report bytes at an unguessable loopback route, revalidates on each request, and exposes no directory or write endpoint. Content Security Policy permits only the bundled report script by exact SHA-256 and blocks external resources, forms and framing."
}
],
"review": {
"reviewed_at": "2026-09-27",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "3d4ba4152946e3e2866c6e131b3846cf295814dcca6d909c0555800f448791ba"
}
}
SHA-256: 1d48c27df1222e53adb784e296e555320b7081e0d1e27ec82f25b55df42cec64