← Files ClaraARCHIVED FILE

privacy/workflows/advisory-deliverable-validator.json

12.6 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 1,
  "workflow": "advisory-deliverable-validator",
  "display_name": "Advisory Deliverable Validator",
  "governed_paths": [
    "contracts/advisory_case_direction_return.v1.schema.json",
    "contracts/advisory_contract.v1.schema.json",
    "contracts/advisory_claim_register.v1.schema.json",
    "contracts/advisory_evidence_register.v1.schema.json",
    "scripts/advisor_case_core.py",
    "scripts/advisory_evidence_lineage.py",
    "scripts/capture_advisory_web_evidence.py",
    "scripts/commit_advisory_workpaper.py",
    "scripts/finalize_hosted_transcript.py",
    "scripts/integrate_transcript_review.py",
    "scripts/record_analysis_contribution.py",
    "scripts/record_case_direction_return.py",
    "scripts/record_reporting_contribution.py",
    "scripts/verify_advisory_html_delivery.py",
    "skills/advisory-deliverable-validator/SKILL.md",
    "skills/advisory-deliverable-validator/evals",
    "skills/advisory-deliverable-validator/references",
    "skills/advisory-deliverable-validator/scripts",
    "skills/advisory-case-director/references/case-direction-return.md",
    "skills/claim-basis-map/scripts/render_claim_basis_map.py",
    "skills/html-deck/scripts/build_html_deck.py",
    "scripts/self_relaunch.py",
    "scripts/managed_python_runtime.py",
    "scripts/_managed_python_runtime.py",
    "requirements.txt",
    "components.json",
    "scripts/_shared_python_runtime.py",
    "requirements-shared-core.txt",
    "requirements-shared-ocr.txt",
    "constraints-shared-macos-py312.txt",
    "scripts/_python_bootstrap.py",
    "scripts/case_store.py",
    "scripts/case_exchange_safety.py",
    "scripts/decision_narrative.py",
    "scripts/commit_decision_narrative.py",
    "scripts/verify_decision_pack.py",
    "scripts/advisory_delivery.py",
    "scripts/verify_advisory_delivery.py",
    "scripts/public_http.py",
    "scripts/bounded_process.py",
    "scripts/advisory_lineage_labels.py"
  ],
  "codex_context": {
    "policy": "real_professional_data_may_enter_codex_context",
    "classes": [
      {
        "id": "deliverable-contract-and-selected-evidence",
        "purpose": "Validate the completed advisory deliverable against its declared contract and available evidence",
        "content": "The complete selected deliverable text or visible slide content; for HTML, extracted text and links excluding script, style, and template blocks while the full file bytes remain covered by the local hash; advisory_contract.json; selected source files or model-requested excerpts; filenames and local paths; citations, links, figures, calculations, data provenance, assumptions, contradictions, missing evidence, recommendations, decision context, audience, scope, and professional-judgement policy The readable local review includes selected source names and clickable source paths, recorded corrections, claim-evidence relationships and exact review statuses; those paths and report contents may enter context when read."
      },
      {
        "id": "format-check-and-review-artifacts",
        "purpose": "Compose the advisory review with authoritative Clara format-specific checks and prepare any correction",
        "content": "Claim Basis Map audit records, HTML deck plans and ledgers, static and browser-QA reports bound to the reviewed deliverable bytes, Reporting Engine semantic/calculation/render artifacts, Deck Correction completion records, referenced artifact paths and hashes, one model-authored assessment per bounded coverage unit, model-led findings, the case-direction validation return, correction drafts, the corrected artifact's second preparation inventory and second review, explicit professional-judgement and correction approval records including approver and evidence references, residual uncertainties, professional-review items, workpaper checkpoint, and delivery-readiness receipt"
      },
      {
        "id": "advisory-claim-and-evidence-lineage",
        "purpose": "Preserve and review the evidence, dependencies, derivations and output appearances of advisory claims",
        "content": "advisory_evidence_register.json and advisory_claim_register.json; source observations and limitations; management and interview assertions; public capture URLs and normalized text; exact transcript, calculation input/output/verification and output-appearance paths, hashes and byte counts; claim statements, evidence relationships, dependency and supersession graphs, reasoning, uncertainty, judgement boundaries, model-selected chain assessments, coverage units and targeted recheck decisions"
      },
      {
        "id": "authored-narrative-and-current-delivery",
        "purpose": "Review the same case answer and qualifications across Markdown, Word and HTML",
        "content": "Committed narrative paragraphs, claim IDs, reviewer identity and status, current case and workpaper bindings, per-format artifacts and visual-review records, output paths and hashes, readiness receipts and mismatch errors. Local transaction recovery files can temporarily contain prior case bytes; source history and bound output artifacts remain separately retained. No automatic anonymisation or extra model service is introduced by these helpers."
      },
      {
        "id": "complete-current-text-navigation",
        "purpose": "Expose text omitted by untracked-claim heuristics for active-model review",
        "content": "The current-deck audit retains every supplied extracted text item, including short headlines, numeric labels and footnotes, with source slide/shape metadata. Explicit coverage metadata states that semantic review has not been performed and non-text visual meaning requires separate inspection. This expands review visibility, not automatic materiality classification or anonymisation."
      },
      {
        "id": "shared-case-normalization-attempts",
        "purpose": "Inspect case presentation imports and any normalization diagnostics used by this workflow",
        "content": "When a presentation is imported through the shared case helper and requires normalization, local attempt directories retain converted presentation files and converter stdout/stderr logs. They may contain source document content, metadata and local paths, including after failure or cancellation. Reading them supplies their contents to model context. This conditional import path does not mean every workflow execution converts a presentation or sends these files to a hosted service. Retained attempt files remain until separately removed."
      }
    ]
  },
  "ordinary_codex_model_processing": {
    "scope": "content_supplied_to_the_codex_model",
    "account_arrangement": "user_selected_chatgpt_or_codex_account",
    "separate_clara_recipient_or_arrangement": false,
    "automatic_anonymisation": false,
    "local_filter_or_aggregate": "only_when_useful_for_professional_work",
    "plan_visibility": "not_inspected_or_enforced_by_clara"
  },
  "codex_account_boundary": {
    "selected_by": "firm_or_user",
    "clara_runtime_enforcement": "none",
    "review_timing": "before_professional_use_and_when_account_or_terms_change",
    "review_items": [
      "account_or_workspace_plan",
      "model_training_data_controls",
      "retention_and_deletion_controls"
    ],
    "per_case_record_required": false
  },
  "hosted_service_ids": [],
  "boundaries_beyond_codex": [
    {
      "id": "selected-public-source-capture",
      "kind": "public_research",
      "destination": "The exact public HTTP or HTTPS source selected for evidence collection or a targeted final recheck",
      "purpose": "Preserve a time-bound public response and normalized text so the model can author and later recheck a scoped advisory observation",
      "content": "The exact selected public URL and ordinary request metadata; the public response is stored locally with requested and final URL, byte count, capture scope and hashes; no case files, prompts, transcripts, credentials or unrelated browsing data are sent",
      "optional": true,
      "requires_confirmation": false,
      "controls": [
        "The helper runs only for an exact source explicitly selected during evidence collection or by the model-led recheck decision; it does not crawl, search, or open every URL in a deliverable.",
        "Only credential-free public HTTP or HTTPS destinations on standard ports are allowed; DNS results and every redirect destination must be globally routable.",
        "The response is capped at one million bytes, stored locally with hashes, and described as source identity rather than proof that the model-authored observation is true or complete."
      ]
    },
    {
      "id": "direct-cli-python-dependency-setup",
      "kind": "public_research",
      "destination": "Python Package Index (PyPI) or the index selected by the user's Python configuration",
      "purpose": "Prepare the published shared Vera, Clara and Lucia core dependencies, and validate the selected workflow, in one user-scoped Python 3.12 environment per operating-system host.",
      "content": "Shared published package names and version constraints plus ordinary package-index request metadata. Client files, prompts, case data and generated work are not included in installer requests. Workflow arguments stay in the local child process.",
      "optional": false,
      "requires_confirmation": false,
      "controls": [
        "Only published shared requirements are installed, never requirements derived from client material or prompts.",
        "One fixed environment outside plugin source and client folders is reused across products and modules. Explicitly approved OCR is retained in the same environment.",
        "A reader lease prevents setup from modifying packages while managed workflows run. Setup validates dependencies before writing the readiness receipt. Failed updates leave execution unavailable until repair.",
        "Older plugin policies cannot downgrade an environment created by a newer shared policy revision."
      ]
    },
    {
      "id": "declared-python312-retrieval",
      "kind": "public_research",
      "destination": "Astral python-build-standalone CPython distributions on GitHub, or the Python download mirror explicitly configured in uv",
      "purpose": "Provision the declared CPython 3.12 workflow interpreter when absent, automatically bootstrapping uv if needed",
      "content": "The fixed CPython 3.12 version request, operating-system and architecture selection, and ordinary download request metadata. Setup does not read client files or add prompts, case material or generated reports to this request.",
      "optional": false,
      "requires_confirmation": false,
      "controls": [
        "Use an installed CPython 3.12 when available; otherwise use uv or automatically download the published uv 0.12.10 wheel, verify its pinned SHA-256, and provision private CPython 3.12 without changing system Python or shell profiles.",
        "Probe the selected interpreter before creating the dependency environment; never fall back to executing workflows with another Python minor version.",
        "A failed download or interpreter probe stops setup; existing environments and client files remain intact."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "lineage-artifact-binding",
      "control": "Evidence artifacts, lineage inventories, the deliverable, contract, HTML static and browser-QA results, validator return, workpaper checkpoint, and corrected output are bound by local paths, byte counts and SHA-256; deterministic checks validate references, register currency, and dependency closure without making semantic support decisions."
    },
    {
      "id": "public-address-pinning",
      "control": "The public capture transport validates destination addresses and redirects, connects to a vetted numeric address while preserving the original TLS hostname, and does not use environment proxy settings. This prevents DNS re-resolution from silently changing the approved destination; it does not certify source content."
    },
    {
      "id": "public-response-deadline",
      "control": "Pinned public capture shares an elapsed-time budget across address attempts, redirects and HTTP header/body reads. A deadline watchdog shuts down the owned socket; expired partial responses are rejected before capture artifacts or lineage records are written. Synchronous system DNS lookups cannot be interrupted here, including the capture helper’s pre/post validation, so this is not a total wall-clock guarantee for the capture command. No additional recipient, payload, log or retained file is introduced."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-15",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "f6280077c923e33609a111d4fa2d04f32445b0ce39de707213e4d3b8943ef224"
  }
}

SHA-256: fadeb6a52cfa6093d06888543f3c422480b5880479366213d101b7bc34d7a147