← Files VeraARCHIVED FILE

privacy/workstreams/new-client.json

7.93 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "new-client",
  "display_name": "New Client",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "mcp",
    "schemas",
    "assets/review-workbench-adapter.json",
    "assets/new-client-review-widget.html"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "relationship-case-evidence",
        "purpose": "Prepare identity, engagement, privacy, AI-applicability, AML, document, and monitoring proposals for professional review",
        "content": "Promoted file-preparation model_handoff pages use one metadata record per file, exception-only excerpts, every mapped fiscal field with bounded citation, reviewed email requests under CLIENT-001, and XML anomaly or opaque duplicate-group refs without invoice party fields; selected exact evidence may still enter when required. Professional setup may also place identity, representative and beneficial-owner facts; engagement terms; privacy and AML records; source, template, chronology, and evidence passages; calculations; temporal-horizon state; gaps; proposals, review decisions, and package state in model context.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "geneva-adaptation",
        "purpose": "Prepare the existing professional deliverable under an explicit CH-GE mandate",
        "content": "The Geneva setup adapter reads imported identity, mandate, ownership, AML-applicability and privacy-role evidence, source passages and locators, a requested/received/missing document plan, official legal references, limitations and declared professional decisions. These authored data may enter the parent runtime context. The local adapter makes no network or model call; it does not use the Italian AML score. Existing Italy-specific UI and promotion controls below describe the ordinary Italian route.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [
    {
      "id": "current-source-research",
      "kind": "public_research",
      "destination": "Current primary and professional public sources selected for the case",
      "purpose": "Verify the current source basis for legal and professional proposals",
      "content": "Legal or professional research topics, public-source queries and selected source URLs; direct client identifiers are not used in the public research route",
      "optional": false,
      "requires_confirmation": false,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Record retrieval, version, temporal scope, and reuse status for selected sources.",
        "Keep credentials, authentication codes, cookies, screening-provider tokens, and direct client identifiers out of public research."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "owner-only-package",
      "control": "Initialization, phase-one promotion, and packaging require a digest-valid Studio Archive new-client context and write the owner-only dossier only inside its exact run output root; promotion accepts phase-one artifacts only from the same client engagement."
    },
    {
      "id": "upstream-package-integrity",
      "control": "Before promotion, the workflow verifies the sealed phase-one source snapshot and every declared output's type, size, byte hash, and package binding; drift is rejected. Inventory classification metadata in the candidate-aware format must remain category_status=candidate and category_basis=lexical_hint; professional decisions remain in the reviewed field handoff."
    },
    {
      "id": "phase-one-purpose-shaped-handoff",
      "control": "When the promoted phase-one run contains model_handoff.json, Codex and Cowork use its complete hash-listed page set as the default phase-one context. Email drafting is limited to reviewed request items under CLIENT-001 and XML synthesis to anomaly or opaque duplicate-group refs; exact local professional artifacts remain available when required."
    },
    {
      "id": "temporal-apply-gate",
      "control": "Apply re-derives the earliest inclusive deadline from persisted evidence, identity, source, and template dates and rejects stale approval without writing final outputs."
    },
    {
      "id": "review-persistence-binding",
      "control": "Save and Apply use an opaque, bounded-lifetime server-held binding tied to the run and review hashes; unknown, expired, or mismatched tokens are rejected."
    },
    {
      "id": "no-session-secrets",
      "control": "Validators reject credentials, authentication codes, cookies, tokenized session URLs, and provider tokens from artifacts and model-review payloads."
    },
    {
      "id": "whole-delivery-integrity",
      "control": "After final copy, the workflow requires owner-only modes, validates host-neutral assistant-authored text and final run-ID consistency, and seals every delivered file except the manifest itself with size and SHA-256 receipts."
    },
    {
      "id": "local-review-output-download",
      "control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
    },
    {
      "id": "local-browser-private-review-payload",
      "control": "The local review server requests component-only private review metadata only for the registered render tool. The browser receives that payload locally; normal MCP callers continue to receive structuredContent. This is transport separation, not anonymization of data selected for model review. Reload restores the persisted applied decisions for the same plugin and run through the existing browser path sanitization. It does not apply decisions again or change the external routes. Read-only local rendering accepts validated running, review-ready and completed contexts; Save/Apply still require a running context. Nested result folders resolve the owning portable run and validate the exact requested descendant before rendering. Archived views also show a localized read-only notice and disable Save/Apply; server-side write validation remains authoritative."
    },
    {
      "id": "local-browser-saved-review-details",
      "control": "After successful native validation or saving, the loopback review server restores the persisted notes, edited values and requested-document list in the local browser. The normal MCP model response remains minimized and widget state still excludes free-text decisions. Browser payloads retain the existing path sanitization and bound-run checks. Reopening does not save or apply decisions; the native validity and professional-review gates are unchanged. Reading this local browser in Codex still puts that selected content in the model context."
    },
    {
      "id": "geneva-source-binding",
      "control": "Geneva setup requires the exact running Studio Archive context and imported source hashes. Decisions bind the proposal, calculated result, workflow, client and engagement. Content-addressed JSON and Markdown retain prior drafts and reject changed artifacts; a declared reviewer is not independently authenticated."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-26",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "7edb5c72b8045b3e78c2ac6dc2c9f73d5fa8b2cdd4f4f3999fb65e73b53d5fa9"
  }
}

SHA-256: 5c0c9d7c020ee08bd886fbe2c70c832ea05bb1f91b0d9e2c6f41044c9abe4dc1