← Files VeraARCHIVED FILE
privacy/workstreams/prompt-optimizer.json
7.38 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "prompt-optimizer",
"display_name": "Answer Planner",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"mcp",
"assets/review-workbench-adapter.json",
"assets/prompt-optimizer-review-widget.html"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "question-and-prompt",
"purpose": "Understand the professional question, define the answer and validation contract, write route-specific generation instructions, and review their semantic conformance",
"content": "The question and facts typed or attached by the user, including names or other personal facts when material; inferred legal, tax, or compliance framing; answer contract including document type, validation scope, correction policy, and professional-judgment policy; generation route and instructions; model-led prompt-to-question and prompt-to-contract conformance assessments; source-domain sidecars; diagnostics and review decisions. The canonical review record references the full prompt audit instead of duplicating that audit in each failed check, and it does not include a question-text preview. In the shared Vera and Lucia legal-question journey the original answer contract records a model-led adversarial_policy (required or not_required) and rationale from the requested result and explicit user instructions. Informational research finishes after validation; an opinion on a concrete position or an explicit opposing-opinion request includes the opposing examination. Research mode does not determine this policy. The preparation also records the user choice between an available installed OpenAI Deep Research skill and ordinary research. The installed skill receives the same full prepared brief, answer contract, selected case material and curated source list in the current host; its public queries and selected source text may enter that host model context. This is distinct from the separately chosen manual ChatGPT handoff and does not itself select another account, grant connected-source access or create a new model API route.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "source-domain-research",
"kind": "public_research",
"destination": "Public official and reliable-source websites",
"purpose": "Curate qualified source domains for the confirmed legal framework and issue",
"content": "Legal or tax issue research terms and public-source URLs; queries can reflect case facts when the selected model runtime uses them",
"optional": false,
"requires_confirmation": false,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The selected model runtime chooses domains from the confirmed framework; deterministic scripts do not choose legal sources.",
"The workflow does not request credentials or authenticated-source access."
]
},
{
"id": "chatgpt-deep-research-handoff",
"kind": "hosted_service",
"destination": "ChatGPT Deep Research in the separate ChatGPT account or workspace chosen by the user",
"purpose": "Generate the answer when the user chooses the optional chatgpt_deep_research route",
"content": "The full optimized_prompt.md including material client names, facts, dates, amounts and questions, plus source_domains_comma.txt. The manual paste is a transfer to ChatGPT model processing, separate from the originating Codex or Cowork session. No automatic anonymization or local-only processing is promised.",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"Before handoff identify the exact prompt and destination. Obtain the route choice if not already explicit; the user pastes the reviewed content into their chosen ChatGPT account. No script uploads it.",
"The user checks the destination account or workspace plan, training controls and retention before professional use or when terms change. Vera cannot inspect or enforce them. Codex and Cowork runtime profiles do not describe this separate destination."
]
}
],
"security_controls": [
{
"id": "client-engagement-path-isolation",
"control": "Question inspection and prompt validation require a digest-valid Studio Archive prompt-optimizer context, accept the question and working artifacts only from that engagement, and write only to the context's run output root or a descendant."
},
{
"id": "hash-bound-canonical-review",
"control": "final_artifacts.json binds the canonical review_payload.json with SHA-256. In Codex or Cowork, when local MCP is callable, validation can reload that regular local file through the managed run reference and issue a random, in-memory, four-hour token, so render/save/apply do not require the complete payload to be resent at every step. Without local MCP, both runtimes consume the same canonical local review records and keep decisions pending unless persisted artifacts prove save and apply; unmanaged or legacy runs may still use an inline payload."
},
{
"id": "local-review-output-download",
"control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
},
{
"id": "local-browser-private-review-payload",
"control": "The local review server requests component-only private review metadata only for the registered render tool. The browser receives that payload locally; normal MCP callers continue to receive structuredContent. This is transport separation, not anonymization of data selected for model review. Reload restores the persisted applied decisions for the same plugin and run through the existing browser path sanitization. It does not apply decisions again or change the external routes. Read-only local rendering accepts validated running, review-ready and completed contexts; Save/Apply still require a running context. Nested result folders resolve the owning portable run and validate the exact requested descendant before rendering. Archived views also show a localized read-only notice and disable Save/Apply; server-side write validation remains authoritative."
}
],
"review": {
"reviewed_at": "2026-09-26",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "6bf7e97ded6c4f74bbff00c77d38306aee99d4664a921d6f32cff5ddc35ae1dc"
},
"governed_repository_paths": [
"plugins/deep-research-validator/skills/legal-tax-answer-review/references/adversarial-scope.md",
"plugins/deep-research-validator/skills/legal-tax-answer-review/references/research-choice.md"
]
}
SHA-256: efc82372a65de57760412e65702da8d3cf519b7e0f19ac3b549334d5105b1304