← Files VeraARCHIVED FILE
privacy/workstreams/presenza-digitale-studio.json
14.3 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "presenza-digitale-studio",
"display_name": "Presenza digitale dello studio",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"schemas",
"assets"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "studio-website-material",
"purpose": "Assess or create a professional studio website, propose its information architecture, copy and visual system, implement a responsive site, and prepare exact preview and release packages for review",
"content": "Selected captures of an existing public website; selected source code, screenshots, studio documents, approved communications, logo, photographs, contact details, team and professional biography, verified services and qualifications, exact studio facts explicitly confirmed in conversation, supplied legal text, intended audiences, proposed sitemap, page copy, studio-profile fields with observed, user-supplied or Vera-default basis, a model-led source-use plan, design tokens, implementation files, browser screenshot evidence, model-led quality assessments, deterministic validation findings, review decisions, package hashes and visible preview or publication receipts. Every selected source file and confirmed fact must be explicitly approved for use in preparing the website. A complete approved source may enter runtime model context during brief mapping; after the brief, work continues from mapped brief facts by default and reopens only the targeted material or complete source named in the source-use plan. Professional names, portraits, contact details and other real studio information may enter the selected runtime model context when supplied, selected or explicitly confirmed for the website. The workflow does not promise automatic anonymization or local-only model processing.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "selected-public-site-inspection",
"kind": "public_research",
"destination": "The exact existing public website and directly referenced public assets selected by the professional",
"purpose": "Observe the current website's content, structure, rendered behavior and public assets before proposing a refresh",
"content": "The selected public URL, ordinary page and asset requests, and captured public HTML, text, metadata and screenshots; no private studio files, client facts, credentials, cookies, tokens or unrelated browsing history",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The intake records the exact selected website destination and asserted user approval before inspection.",
"Inspect only the selected public site and directly relevant pages or assets; do not request credentials, cookies, analytics accounts or private administration access.",
"Capture the exact evidence used into the private run because a URL alone is not a durable source snapshot."
]
},
{
"id": "selected-studio-material-connector",
"kind": "external_connector",
"destination": "A callable connected Drive, document store or supported authenticated browser surface explicitly selected by the professional",
"purpose": "Read only selected studio identity, copy, logo, photography, service, qualification or legal-text material for the website",
"content": "The exact selected studio files and their metadata; no credentials, cookies, one-time codes, unrelated account contents or client-case archive",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The intake records the exact connector destination and asserted approval; that route choice is the confirmation and is not requested again.",
"Read only the selected items, stop at account ambiguity or security checkpoints, and snapshot selected bytes into the owner-controlled run.",
"Do not infer permission to publish merely because material was readable through the connector."
]
},
{
"id": "optional-creative-assistance",
"kind": "hosted_service",
"destination": "The exact Creative Production board or image-generation service selected by the professional in the active runtime",
"purpose": "Explore or produce a bounded website visual direction or image when selected studio assets are insufficient",
"content": "The studio identity context selected for website use, exact requested visual purpose and non-sensitive selected reference assets; no client-case files, credentials, private correspondence, unpublished professional claims or unrelated source material",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex"
],
"controls": [
"The intake records the selected service and destination plus asserted user approval before any handoff.",
"Creative output is a proposal and cannot add services, claims, qualifications, testimonials, people or publication approval.",
"The exact returned asset is stored in the private run, inspected in the working site and included only after professional review."
]
},
{
"id": "unlisted-preview-publication",
"kind": "send_or_publish",
"destination": "The exact tokenized preview host or platform selected by the professional",
"purpose": "Publish the exact validated website package at a hard-to-guess review URL",
"content": "The exact preview website files, studio facts and assets selected for website use, noindex directives, destination metadata and visible preview URL; no credentials, cookies, tokens, unselected source files or unrelated run artifacts",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The intake records explicit preview-publication selection, destination and asserted user approval before packaging.",
"Packaging requires current mechanical validation and a ready desktop-and-phone quality assessment; every HTML page must carry noindex before an external preview package is created.",
"Use a hard-to-guess path, omit public navigation, verify the visible URL and bind its receipt to the exact preview package digest. The URL is unlisted, not access-controlled."
]
},
{
"id": "approved-final-publication",
"kind": "send_or_publish",
"destination": "The exact production website platform, repository, account or domain selected by the professional",
"purpose": "Publish the exact accepted release package after professional and destination review",
"content": "The exact accepted website files and public assets plus destination metadata and visible production URL or provider receipt; no credentials, cookies, tokens, unaccepted drafts or unrelated run files",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The intake records explicit final-publication selection, exact destination and asserted user approval; publication is never inferred from design or preview approval.",
"Release packaging requires current mechanical validation, a ready rendered quality assessment and accepted identity-and-claims, responsive-preview and publication-destination reviews bound to the current site digest.",
"Use a callable connector or supported authenticated browser without reading credentials, verify the live URL after publication and bind visible evidence to the exact release package digest."
]
},
{
"id": "optional-openai-sites-build-and-hosting",
"kind": "send_or_publish",
"destination": "The exact OpenAI Sites project selected by the professional in Codex",
"purpose": "Build, version and deploy the accepted informational website through the selected Sites project",
"content": "The exact accepted public website payload and assets, a digest-only Vera release binding, Sites source commit and deployment archive, project and version identifiers, selected access level, deployed URL and desktop-and-phone deployed-page screenshots; no source evidence files, credentials, cookies, authorization headers, tokens or unrelated run artifacts",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex"
],
"controls": [
"The preview or final route records provider sites, the exact destination and asserted user approval before any Sites handoff.",
"The Sites project lives in the private run, stores only project_id in hosting metadata and keeps temporary source credentials outside Vera artifacts.",
"The workflow builds and rehashes a deterministic website payload from the current Vera package, requires that exact payload and current binding inside the retained deployment archive, and checks that hosting metadata names the same Sites project and that the server bundle is present.",
"Delivery is recorded only for a succeeded version and deployment whose URL and deployment identifier match a completed desktop-and-phone browser review with retained PNG evidence. Shared or public access additionally requires explicit user approval."
]
}
],
"security_controls": [
{
"id": "owner-controlled-private-workspace",
"control": "Workspace initialization requires asserted owner, retention owner, explicit user confirmation and an exact directory outside a Git repository or published static/shared root. Files, symlinks, filesystem roots, the home directory and non-empty unmanaged directories are rejected. Run outputs use owner-only permissions, atomic JSON replacement and a private staging directory before the run becomes visible."
},
{
"id": "immutable-selected-source-snapshots",
"control": "Run preparation requires at least one regular non-symlink selected file or one exact fact explicitly confirmed by the user in conversation, and every selected item must carry approved_for_website_use=true for the website purpose. Files are copied into the private run and confirmed facts are serialized into immutable evidence snapshots; each records the website-use approval, byte size and SHA-256, duplicate evidence IDs are rejected and intake plus source register are bound to one digest. Every later gate rechecks the approval and rehashes the snapshots. A public URL alone is not treated as captured evidence."
},
{
"id": "purpose-bound-post-brief-source-use",
"control": "The site brief records exactly one source-use item for every registered evidence ID. The model states the professional purpose and chooses mapped_brief_only, targeted_material or full_source_required; deterministic code verifies only schema shape, unique IDs and exact source-register coverage. Downstream design, copy and build work use mapped brief facts by default, reopen only the named targeted material when required, and use a complete selected source only when the recorded professional reason requires it. No deterministic keyword or personal-data classifier substitutes for that semantic judgment."
},
{
"id": "model-led-design-and-fact-provenance",
"control": "Information architecture, copy, visual direction and rendered quality remain model-led proposals. Every studio-profile field is labelled observed, user supplied or Vera default; observed and user-supplied fields require selected evidence IDs, and claim records cannot reference an unknown source ID. Deterministic code does not decide aesthetics, professional truth, accessibility compliance or legal sufficiency."
},
{
"id": "mechanical-site-validation",
"control": "The validator recomputes a complete file inventory and site digest and checks only mechanically verifiable properties including metadata, one H1, alternative-text presence, duplicate IDs, local reference closure, unsafe schemes, placeholders and preview indexing posture. Forms, embedded documents, iframes, remote active scripts and executable data URLs are blocked because the workflow is scoped to informational sites; passive HTTPS assets remain visible warnings."
},
{
"id": "digest-bound-render-and-professional-review",
"control": "The model-led browser assessment must include distinct desktop and phone viewports with retained PNG paths, hashes and verified dimensions, bind current site and validation digests, identify its weakest element and cannot be ready with viewport issues, console issues or weak or blocked dimensions. Identity-and-claims, responsive-preview and publication-destination decisions are recorded separately against the same current evidence, brief, site, validation and quality-assessment digests; any changed dependency or screenshot bytes invalidate stale reviews and packages."
},
{
"id": "exact-package-and-visible-delivery-binding",
"control": "Preview and release packages reject every symlink and non-regular file, copy exact site bytes atomically, record and rehash every packaged file, and bind intake, brief, validation, quality-assessment and current review digests. Preview packaging additionally requires an explicitly selected route and noindex, nofollow and noarchive on every HTML page; release packaging rejects every preview robots directive and requires all current professional review scopes. Delivery recording revalidates the complete package, exact selected destination, non-empty user confirmation and visible URL or provider receipt. Sites deliveries additionally bind the exact website payload to the current Vera package, source commit, deployment archive, project metadata, server bundle, saved version, succeeded deployment and deployed browser evidence."
}
],
"review": {
"reviewed_at": "2026-09-12",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "62e62981fb28606cab5d48025cd367b59b70aee261b61d36d0be6eec42f3cb3c"
}
}
SHA-256: 9562def986d149411ed4e31b1251c83c3413f2a6b5cd391d088b369de3a8c594