← Files VeraARCHIVED FILE

privacy/workstreams/open-item-reconciliation.json

9.4 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "open-item-reconciliation",
  "display_name": "Open-item Reconciliation",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "mcp",
    "assets/review-workbench-adapter.json",
    "assets/open-item-reconciliation-review-widget.html"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "bounded-source-structure-and-mapping",
        "purpose": "Understand source structure and confirm the accounting meaning of columns before deterministic reconciliation",
        "content": "User instructions; selected source names and column labels; a limited set of source rows opened for mapping; proposed and reviewed source roles, field mappings, period, currency, entity, party and evidence assumptions. A professional may still direct the selected runtime to open more source evidence when mapping cannot be resolved from the limited rows; the workflow does not call a model API itself and does not claim that source files are anonymized.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "non-identifying-review-index",
        "purpose": "Let the model select review cases without receiving the complete review payload",
        "content": "One model-visible index containing aggregate item-type counts and, for each model-relevant review item, an opaque per-run case handle, item type, normalized categorical review status, recommended action and the names of present mechanical signal classes. It excludes signal values, item titles, names, descriptions, dates, amounts, source references and identifiers, source paths, workflow record IDs, review write targets and complete row objects. Non-interpretive artifact items accepted by the deterministic workflow remain available to the human widget but are omitted from the index.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "selected-case-context",
        "purpose": "Interpret or verify only the reconciliation cases selected from the index",
        "content": "At most 25 requested cases per call: populated allowlisted accounting fields such as dates, signed amounts, currency, account name, description, beneficiary or counterparty, deterministic status and rule, evidence level, match type, review flags and instructions, relationship or allocation status, exceptions and requested evidence. Physical source locators, technical record IDs, write targets, empty fields, unmapped columns and duplicate facts are omitted. Exact document, invoice, movement and reference values are excluded by default and can be requested only for selected cases when exact identity is required. Real names, descriptions, amounts and other case facts can therefore enter model context; the opaque handle is a routing control, not anonymization or pseudonymization of the professional case data.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [],
  "security_controls": [
    {
      "id": "customer-folder-output-root",
      "control": "Run artifacts are written only below the exact Studio Archive output root at Vera/engagements/<engagement-id>/runs/<run-id>/outputs inside the selected customer folder; the runner does not choose a separate machine-local workspace or published repository path."
    },
    {
      "id": "client-engagement-isolation",
      "control": "The raw-runner CLI loads a digest-valid Studio Archive open-item-reconciliation context from the customer folder, requires the run to be in its running lifecycle state, replays the customer, engagement, run, input and receipt seals plus selected execution-copy bytes, accepts only the context-bound input view and exact output root, and carries the same context into intake, canonical, and assurance records."
    },
    {
      "id": "local-review-service",
      "control": "The review server binds to loopback and constrains review writes to the selected run folder."
    },
    {
      "id": "component-private-review-transport",
      "control": "MCP validation loads review_payload.json inside the local server and returns only a non-identifying index plus a random four-hour reference. Rendering exposes the complete validated payload only in tool-result _meta, which is component-only, while model-visible content and structuredContent contain the index. The widget hydrates from toolResponseMetadata and preserves the complete human review surface."
    },
    {
      "id": "bounded-selected-case-projection",
      "control": "The read-only case-context tool accepts only opaque handles bound to the current in-memory review reference, rejects unknown or duplicate handles, limits each call to 25 cases and 500000 response bytes, projects explicit post-mapping field allowlists, and keeps exact professional identifiers off unless explicitly requested for those selected cases."
    },
    {
      "id": "qualified-source-and-relationship-controls",
      "control": "Row-level reconciliation uses only reviewed source roles and qualified source adapters, and enforces current source receipts, entity, party, currency, evidence-reuse, fan-out, and exact allocation-conservation controls before a row can close. Opposing signed entries for the same document and accounting perimeter withhold automatic bank settlement pending reversal and payment-purpose review; this mechanical conflict does not establish the validity of a reversal. Candidate report figures retain explicit invoice and evidence record references."
    },
    {
      "id": "bounded-trusted-memory-review-transaction",
      "control": "MCP review save and apply operations capture the bounded canonical output tree and modes in parent-process memory, run workflow helpers only against a detached working tree, reject linked, aliased, special, oversized, or unexpected entries, and restore exact trusted bytes and modes on every rejected commit without trusting child-accessible rollback material."
    },
    {
      "id": "parent-owned-review-authorization",
      "control": "The MCP parent derives the operative run, review payload, current decisions, final artifact state, authorized write set, effects, and readiness from the persisted trusted snapshot; caller copies must match exactly, helper output is acknowledgement-only, and parent replay plus current-byte postconditions must close before commit."
    },
    {
      "id": "exact-implementation-and-successor-checkpoint",
      "control": "Every assured Python and MCP entry validates the exact 25-file plugin and shared-assurance implementation tree before loading workflow logic; a later review requires the independently retained predecessor checkpoint, replays the archived predecessor rows, allocations and core checks, and rejects missing, wrong or self-resealed predecessor authority without mutating the canonical tree. Anchored predecessor snapshots recover the current digest-valid customer-run context only within that same managed run; snapshot paths do not authorize a different customer context or bypass the external checkpoint. Managed runs reject completed review rows unless they exactly match applied decisions for that run; standalone record IDs and reviewer labels cannot carry approval to replacement inputs. Preparation, finalization and replay enforce this boundary alongside the retained predecessor transition."
    },
    {
      "id": "duplicate-source-report-lineage",
      "control": "The raw runner uses imported basenames from the context-bound run input manifest to label byte-identical duplicate copies in the local Word report and Excel source inventory while extracting only the canonical input once. These filenames may enter model context when the selected run or reports are opened; no additional original absolute source paths are added."
    },
    {
      "id": "local-review-output-download",
      "control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
    },
    {
      "id": "native-package-and-local-handoff",
      "control": "Vera uses the fixed reconciliation child below the bound Studio Archive outputs root for the exact native assurance tree. Required local model-data disclosures stay at the owning outputs root; archive declarations cover both. No native receipt is rewritten to admit disclosures. The native review page restores same-run applied decisions on reload. Validated archived runs open read-only and native Save/Apply require the running lifecycle before a transaction. These changes add no hosted service or external data route."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-27",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "e33a90d6635f4fdac491d605ae7e46e241def20fe20fc977d231009fee010498"
  }
}

SHA-256: 2740de5ca588c544290bb8e52c68e8021ee35449ab45e5884c947384f0ed634c