← Files VeraARCHIVED FILE

privacy/workstreams/previdenza-inps.json

5.62 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "previdenza-inps",
  "display_name": "Previdenza INPS",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "mcp",
    "schemas",
    "assets/previdenza-inps-review-widget.html"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance",
    "vendor/modules/vera_ocr"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "inps-case-evidence",
        "purpose": "Structure facts, resolve evidence conflicts, and apply supported sources to the case",
        "content": "INPS records and exports or captured page evidence; contracts, F24s, emails and scans; extracted text; page quotes; facts; timelines; official sources; calculation basis; draft findings and review decisions",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "geneva-adaptation",
        "purpose": "Prepare the existing professional deliverable under an explicit CH-GE mandate",
        "content": "A Geneva case additionally records the competent Swiss institution, mandate, period and jurisdiction basis. Local contribution evidence uses the existing facts, chronology, authored claims and reviewed arithmetic. The INPS browser and portal-export routes remain specific to Italy; the Geneva adaptation introduces no Swiss portal access or connector.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [
    {
      "id": "official-source-research",
      "kind": "public_research",
      "destination": "Current official public legal and INPS sources",
      "purpose": "Research the confirmed framework and verify material claims",
      "content": "Contribution issue, period, legal-research query and selected public source URLs; public queries exclude personal identifiers",
      "optional": false,
      "requires_confirmation": false,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Use current official sources and record source reference, temporal role, retrieval time, and version note.",
        "Keep external research queries free of personal identifiers and session secrets."
      ]
    },
    {
      "id": "inps-browser-capture",
      "kind": "external_connector",
      "destination": "One already-open, human-authenticated INPS tab through a loopback browser endpoint",
      "purpose": "Capture a read-only current-view snapshot when an official export is not used",
      "content": "Visible page text and screenshot received into the private local run folder; source URL and title are stored only as hashes",
      "optional": true,
      "requires_confirmation": true,
      "runtime_profiles": [
        "openai-codex"
      ],
      "controls": [
        "Invoking the capture command with the exact INPS origin is the explicit route choice; the plugin records route facts and enforced guardrails, not a synthetic approval form.",
        "Restrict attachment to loopback and an exact HTTPS inps.it origin.",
        "Do not navigate, click, submit, download, read cookies or storage, save HTML, close the browser, or capture credentials and one-time codes."
      ]
    },
    {
      "id": "ocr-model-download",
      "kind": "hosted_service",
      "destination": "Configured PaddleOCR model-weight host",
      "purpose": "Download missing OCR model weights before local recognition",
      "content": "Pinned Hugging Face model repository and revision requests plus ordinary connection metadata; no case documents, extracted case content, or approval identifier are sent",
      "optional": true,
      "requires_confirmation": true,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Disabled by default and enabled only when the user explicitly selects the --allow-ocr-model-download route.",
        "The run records route selection and actual network use without treating an arbitrary identifier as authorization.",
        "Only model weights cross the boundary; document recognition remains local."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "private-case-folder",
      "control": "Every mutating CLI stage requires a digest-valid, running Studio Archive previdenza-inps context. External downloads are individually receipted before prepare; prepared inputs stay closed, while portal registration, capture, inventory, validation, reconciliation, and packaging write only inside the exact run output root."
    },
    {
      "id": "no-authentication-material",
      "control": "The workflow never requests or stores SPID/CIE/CNS credentials, cookies, tokens, browser state, or one-time codes."
    },
    {
      "id": "hash-bound-acquisition",
      "control": "Portal exports and conditional captures are hash-bound and revalidated before review decisions are saved or applied."
    },
    {
      "id": "review-reference-lifecycle",
      "control": "Persisted Validate, Render, Save, and Apply calls reuse an opaque, four-hour, server-held reference bound to the exact run and stored review hash; at most 128 live references are retained and private review rows are not echoed in validation results or text fallbacks."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-28",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "fa8e30aec9a7313d7101a105e6f681fdb7370edf386dabcb21e881c1d2a0b10c"
  }
}

SHA-256: d970d06c527151471023c8f6f5f8819b47e62aa0a48e21c2c715da4135cb0341