← Files VeraARCHIVED FILE
privacy/workstreams/report-builder.json
7.95 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "report-builder",
"display_name": "Report Builder",
"role": "workflow",
"governed_paths": [
"skills",
"references",
"scripts",
"mcp",
"assets/review-workbench-adapter.json",
"assets/report-builder-review-widget.html"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "financial-report-evidence",
"purpose": "Map source tables, write the report narrative, and review the generated report",
"content": "User instructions; a bounded inspection packet with source file and sheet names, table identifiers, row and column counts, header candidates, numeric-candidate row positions, extraction diagnostics, and at most eight preview rows per table with numeric values redacted; when the preview is insufficient, one purpose-labelled expansion containing one exact table, at most 16 selected columns and at most 100 selected source rows with cell text, number formats, formula/cache status and source coordinates; selected mappings; the editable narrative recipe; generated report diagnostics, drafts, artifacts and review decisions. The complete cell inventory is not model-visible by default and remains in private deterministic control state. After a valid source-bound numeric-measure review, generated report previews may also include the exact included literal measures, their physical source coordinates and explicit exclusions, capped at eight rows and six displayed columns. This affects reviewed report evidence, not the default raw-cell inspection boundary.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [],
"security_controls": [
{
"id": "client-engagement-path-isolation",
"control": "Inspection and report building require a digest-valid Studio Archive report-builder context, accept imported sources or prior artifacts only from the same engagement, and write only to the context's run output root or a descendant."
},
{
"id": "persisted-review-integrity-replay",
"control": "For a persisted run, the MCP parent derives run, review, current decisions, final state, and protected files from the transaction's trusted image, exact-compares supplied copies, and replays current external-source, archive-container/member, review-payload, final-gallery, and output-byte receipts before review save or apply writes; stale state aborts before mutation."
},
{
"id": "bounded-trusted-memory-review-transaction",
"control": "MCP save and apply capture the bounded canonical output tree and modes in parent-process memory, execute helpers only against a detached working tree, reject linked, aliased, special, oversized, swapped, or unexpected entries, and restore exact trusted bytes and modes after any rejected commit."
},
{
"id": "parent-owned-integrity-and-authorization",
"control": "Helper JSON is acknowledgement-only: the MCP parent validates run, review, final-gallery and protected-file identity, authorizes the write set and effects, checks current source and archive derivation receipts, and independently reseals and revalidates review_integrity after every committed mutation."
},
{
"id": "allowlisted-public-gallery",
"control": "The final artifact gallery is rebuilt from an exact output allowlist with current byte counts and SHA-256 receipts; extracted inputs, private source state, integrity state and revision backups are excluded."
},
{
"id": "private-source-location-index",
"control": "Absolute source roots are retained only in the run-local private source index. Review payloads, final galleries, report data and public source receipts expose source file names or relative receipt paths instead."
},
{
"id": "review-write-containment",
"control": "Persisted review manifests use fixed names inside the selected run folder, editable artifact targets are resolved and checked against that folder before a write, and supported inputs or prior outputs that are symbolic links, hard links, or special files are rejected before read or mutation."
},
{
"id": "archive-member-identity",
"control": "ZIP members are normalized to one portable canonical identity, duplicate or symbolic-link members are rejected, extracted bytes are checked against the captured archive manifest, and later review replays the archive-to-member derivation receipts."
},
{
"id": "reviewed-numeric-public-surface",
"control": "Public table inventories and preview rows withhold raw numeric candidate cells; only source-bound reviewed ledger values may appear as totals, and generated spreadsheet strings are written as literal text rather than formulas."
},
{
"id": "bounded-model-context-with-lossless-expansion",
"control": "Deterministic inspection still processes the full source population, but inspection.json omits both full cell inventories and redacts numeric preview values. The complete inventory stays in private inspection_control.json. Codex and Cowork may obtain additional evidence only through a purpose-labelled packet selecting one exact table, at most 16 exact columns and at most 100 source rows; repeated packets preserve access to the full population. Each default and expanded packet records exact bounds and a SHA-256 context receipt. The workflow instructions prohibit raw-source or private-control fallback when the bounded helper is unavailable."
},
{
"id": "sanitized-helper-failures",
"control": "MCP helper-process failures expose one terminal exception only; Python tracebacks and absolute local paths are removed before the message reaches the review surface."
},
{
"id": "exact-implementation-output-and-predecessor-continuity",
"control": "Public Python and MCP surfaces validate the exact transitive implementation tree, prepared-output receipts and physical file/directory set; every later review requires the prior integrity checkpoint supplied outside the candidate report tree, replays the archived predecessor transition, and rejects alternative honest predecessor substitution before mutation. Source receipts use the exact full-plugin or projected ChatGPT layout; mixed layouts are rejected. Inert bytecode caches are excluded from that executable source contract."
},
{
"id": "source-execution-with-inert-bytecode-cache",
"control": "Python entrypoints redirect bytecode lookup and disable bytecode writes before validating and loading the declared source implementation. Cache directories and regular bytecode files are excluded from the source receipt set; they are not treated as executable authority. Optional explicit repair removes only ordinary single-link .pyc files directly inside cache folders under this component own vendor tree, without traversing symlinks or falling back to shared vendor roots. This local maintenance path does not add model calls or external destinations."
},
{
"id": "local-review-output-download",
"control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "05efde14c283cdbdb0dee95da2d8515eb5feafa66056dfee3f705d5ebe834c08"
}
}
SHA-256: 0d08ae3ae80453820a920275c482f7c849b7ec9b5d06a974d0c71d301ca7887b