← Files VeraARCHIVED FILE
privacy/workstreams/variance-analysis.json
6.17 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 3,
"workstream": "variance-analysis",
"display_name": "Variance Analysis",
"role": "workflow",
"governed_paths": [
".codex-plugin/plugin.json",
"skills",
"scripts",
"mcp",
"assets"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "variance-analysis-mapping-inspection",
"purpose": "Establish the comparison and candidate semantic mapping before calculation",
"content": "User instructions; all source column names and types; detected period or scenario values; mapping proposals and warnings; and at most the first 10 rows projected to candidate period, date, amount, units, discount, COGS, reporting-dimension and calculation-grain columns. The complete file is processed locally for inspection; unrelated columns are omitted from the built-in row preview. A separate targeted inspection may show at most 10 rows from no more than 12 explicitly named columns.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "variance-analysis-post-mapping-review",
"purpose": "Interpret the reconciled variance from reviewed mappings and complete deterministic calculations",
"content": "The complete selected population is calculated locally. The default model context contains mapped variance results, summaries, recipes, prepared-data lineage, standard and root-cause contexts, chart data and images, diagnostics, limitations and hypotheses, but not raw source rows, the original source filename or unmapped column names in the model-use manifest. Exact in-scope source matches can be produced only for a reason-recorded request using reviewed mapped filters and output columns and the exact sealed used-recipe bytes; every exact match is returned without sampling. The review widget payload contains at most the 50 largest driver rows plus artifact and follow-up metadata.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "variance-analysis-review-decisions",
"purpose": "Render and record review decisions without repeatedly copying the full review package through MCP calls",
"content": "The first validation may receive the bounded review payload. When the stored run package matches, later render, save and apply calls use an expiring local token bound to the review_payload.json hash and run ID. Vera performs no automatic anonymization or pseudonymization.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [],
"security_controls": [
{
"id": "client-engagement-path-isolation",
"control": "When hosted by Vera in Codex, inspection and execution validate a digest-valid Studio Archive variance-analysis context, accept only its exact receipted inputs or current-run outputs, and write only to that run's output root or a descendant. Standalone and Clara execution remain explicitly outside this Vera lifecycle."
},
{
"id": "portable-review-persistence",
"control": "Managed run intake persists run-root-relative paths and a portable client identity; the Vera MCP host requires the current absolute context only at execution time and preflights workflow and run identity before saving or applying review decisions."
},
{
"id": "explicit-managed-currency",
"control": "A Vera-managed execution rejects a missing currency argument so the standalone EUR default cannot silently become an accounting assumption in a client run."
},
{
"id": "calculation-judgment-separation",
"control": "The shared variance engine owns exact arithmetic, component calculation, source-total comparison, and reconciliation. Professional or model-led review establishes the accounting perimeter, source basis, semantic causes, favorable/adverse convention, classification, materiality, and selected root-cause alternative; automatic cause attribution is prohibited."
},
{
"id": "draft-until-explicit-review",
"control": "The deterministic Word report is visibly draft_pending_professional_review until the accounting controls pass and the recipe records named professional approval plus an explicitly reviewed root-cause alternative and rationale."
},
{
"id": "structured-data-before-chart-review",
"control": "The workflow requires review of structured result, context, and audit artifacts before chart pixels and treats generated plots as communication and visual-QA artifacts rather than the numerical source of truth."
},
{
"id": "candidate-column-inspection-preview",
"control": "The deterministic inspector still reads the complete input but limits its built-in row preview to the first 10 rows of candidate mapped columns; it records omitted column names and provides a separate explicitly named-column helper for unresolved mapping questions."
},
{
"id": "sealed-post-mapping-model-use",
"control": "A hash-bound model_use_manifest.json makes mapped results and contexts the default after recipe confirmation and omits the original source filename and unmapped column names. The exact-filter drilldown requires the sealed used-recipe file bytes, reapplies reviewed filters and cohort logic over the complete source locally, allows only mapped columns and returns all exact matches without sampling."
},
{
"id": "hash-bound-review-reference",
"control": "The Variance MCP server can issue an expiring in-memory token bound to the stored review payload hash and run ID. Validation returns only a summary and reference; later calls reload and recheck the local package instead of requiring another inline review payload."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "81fa4cf5d887c0ca4afa295fb33eff32bbfc90d7cfb60a305665b62aa0a7d905"
}
}
SHA-256: fb93f4ba51bf364ce19ee6bec4277904df3fe49b4de4ae873629885b26cabd34