← Files VeraARCHIVED FILE

privacy/workstreams/passive-invoice-audit.json

9.91 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "passive-invoice-audit",
  "display_name": "Intelligent Passive-Invoice Audit",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "references"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance"
  ],
  "governed_repository_paths": [
    "plugins/client-file-preparation/scripts/parse_fatturapa_xml.py",
    "plugins/journal-bank-reconciliation/scripts/semantic_review.py",
    "plugins/vera/agents/passive-invoice-reviewer.md",
    "plugins/vera/references/passive-invoice-cowork.md"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "ledger-mapping-and-run-review",
        "purpose": "Review the supplied ledger structure, exact source-to-canonical field mapping, run scope, outputs and limitations",
        "content": "User instructions; source filenames and metadata; exact ledger headers and a bounded source sample needed to review the map; population, matching, deterministic exception and performance summaries; output paths and limitations; when a worker selection is reviewed, its model/effort, reviewer reference, review status and benchmark digest may be read in the parent runtime. The selection review is retained in local evidence and is not added to the subordinate worker prompt.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "compact-luna-invoice-review-packets",
        "purpose": "Determine whether each matched invoice has a concrete material reason for professional review",
        "content": "Batched but independently judged compact records for matched invoices: opaque invoice ID and source reference, supplier name and tax identifier, date, number, document type, currency, invoice-line descriptions and values, VAT summaries and structured flags, bounded causale and related-document references, withholding and stamp summaries, actual booked account codes, descriptions, line descriptions and amounts, ledger reference, deterministic findings, and at most five professional-linked reviewed historical treatments. Raw XML, payment instructions and IBAN, the complete ledger population, unmapped ledger columns, credentials and unrelated client files are omitted from the worker prompt. Codex sends the packet through its native capsule. Cowork writes the same bounded packet and schema to cowork_request.json for the packaged Haiku subagent; the parent retains the returned JSON and actual host invocation record. The host record binds content and requested configuration but does not independently authenticate the model identity.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "geneva-adaptation",
        "purpose": "Prepare the existing professional deliverable under an explicit CH-GE mandate",
        "content": "For Geneva, the parent runtime may read selected original invoice documents to prepare a reviewed canonical extraction, including party identifiers, dates, currency, amounts, descriptions, tax summaries and exact source locators. The subordinate worker receives the same compact matched-invoice packet, with source format, extraction hash and locators; it does not receive the raw original file. Extraction-review identities and dates remain local review declarations, not authenticated proof of professional correctness.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [],
  "security_controls": [
    {
      "id": "managed-client-run-boundary",
      "control": "The audit entrypoint requires a portable Studio Archive context for the exact passive-invoice-audit workflow, verifies every external input against its immutable run receipt, and confines outputs to that customer run. Evaluation discovers the owning run from the result artifact and applies the same input and output boundary."
    },
    {
      "id": "immutable-sources-and-output-isolation",
      "control": "The workflow reads supplied invoice and ledger files without modifying them, writes only below the selected audit output directory, stages archive XML as content-addressed copies, and never exposes an ERP, filing, payment, or posting operation."
    },
    {
      "id": "reviewed-ledger-map-and-non-forced-matching",
      "control": "Ledger rows enter only through an explicit canonical-to-source header map. Every mapped monetary column uses the same reviewed number convention; accounting parentheses denote a negative amount, conflicting signs reject, and explicit zero never invokes missing-value fallback. Matching requires exact structured invoice references with corroborating supplier, date or amount evidence, or the exact supplier-date-amount combination; multiple candidates, duplicates, missing invoices and ledger orphans remain explicit instead of being forced."
    },
    {
      "id": "deterministic-accounting-check-boundary",
      "control": "Bounded XML parsing extracts structured FatturaPA fields and Decimal code performs invoice, VAT, ledger-total, balance, currency, duplicate and reference checks before semantic review; Luna is not used to replace mechanically exact arithmetic."
    },
    {
      "id": "qualified-native-luna-worker",
      "control": "In Codex, the semantic adapter reuses the pinned journal-bank native Codex Seatbelt capsule, defaults to gpt-5.6-luna or uses an explicitly reviewed alternative, validates the configured effort and strict schema, supplies compact content over stdin, retains response/event/stderr/receipt evidence, fails closed on qualification or model mismatch, and contains no direct model API client or API-key path."
    },
    {
      "id": "content-bound-restartable-job",
      "control": "SQLite binds the audit to source, ledger, mapping, workflow and control digests; packet changes fail closed, completed content-addressed chunks are not repeated, interrupted chunks become pending, results are upserted by invoice ID, and content-bound chunk checkpoints plus validated native Luna artifacts recover results published immediately before interruption. Incomplete ordinary artifacts are preserved before retry and unsafe links fail closed. Explicit model selections and the complete review declaration bind the job fingerprint, native-artifact recovery and chunk checkpoints; a changed review cannot reuse the prior job. Runtime identity is bound to the job and checkpoints; native artifact recovery is limited to Codex. Missing Cowork responses remain awaiting_semantic_review, never successfully screened."
    },
    {
      "id": "exception-focused-advisory-output",
      "control": "The XLSX workpaper contains professional-review exceptions and ledger orphans while full-population JSONL retains reconstruction evidence. The only non-exception label is no_issue_detected, which the workflow explicitly prevents from being described as correct, approved, verified or audit passed."
    },
    {
      "id": "isolated-synthetic-corruption",
      "control": "Synthetic evaluation accepts only an explicit mutation plan whose source is professionally labelled acceptable and already matched, unflagged and free of deterministic exceptions; it copies the packet to a separate output with a synthetic identifier, changes only booked account identifiers and descriptions while preserving ordinary line descriptions, retains original and replacement treatment, and never mutates the real ledger, packet, job database or source file."
    },
    {
      "id": "reviewed-native-model-selection",
      "control": "An alternative worker model requires a reviewed-decision receipt bound to the workflow, model, effort and benchmark digest. CLI selection files are authorized engagement inputs. This checks a local review declaration, not reviewer authentication or benchmark quality; it never changes native host qualification or read boundaries. The default remains Luna. Configuration and review identity remain bound during replay and recovery. This option applies only to Codex; Cowork rejects Codex model-selection receipts and nondefault effort overrides."
    },
    {
      "id": "cowork-host-recorded-handoff",
      "control": "The packaged Cowork agent requests Haiku with Read access and instructions limited to the exact request. The engine rejects symlink handoff files, wrong request/response digests, missing invocation identity, invalid result types or incomplete invoice coverage. These checks do not independently authenticate the host or enforce an OS read sandbox. The workflow does not invent usage, timing, model identity or review completion."
    },
    {
      "id": "current-host-profile-qualification",
      "control": "The fixed source registry includes the reviewed macOS 26A428 / Codex CLI 0.155.0-alpha.16 profile. Production OS sandbox text, disabled tools, read-only CLI arguments and allowed data paths are unchanged. Qualification retains an actual normal launch and positive/negative image controls under a separately documented diagnostic envelope; those diagnostic helper/process permissions are not deployed. Dependency inspection reads this same registry and is not itself launch qualification. Unknown or changed hosts fail closed. No model payload or external destination is added."
    },
    {
      "id": "geneva-source-binding",
      "control": "Reviewed invoice inputs require a content-bound review declaration and exact original-file hashes within the population directory. Source or extraction changes reject reuse. The existing matching, arithmetic, currency checks, job binding and native worker boundary remain active."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-28",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "2675a268f283738cafd9f0d0851dca7ed646c28ddafd224d62941686b4b4cc64"
  }
}

SHA-256: b8c002d32d2cf9b1a774a412e4f7f04a5e9eed210905d086f5a3285f619ba811