← Files ClaraARCHIVED FILE
privacy/workflows/attribute-reporting.json
5.72 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 1,
"workflow": "attribute-reporting",
"display_name": "Retailer Signals",
"governed_paths": [
"skills/attribute-reporting/SKILL.md",
"modules/attribute-reporting/skills/attribute-reporting/SKILL.md",
"modules/attribute-reporting/skills/attribute-reporting/references",
"modules/attribute-reporting/scripts",
"scripts/self_relaunch.py",
"scripts/managed_python_runtime.py",
"scripts/_managed_python_runtime.py",
"requirements.txt",
"components.json"
],
"codex_context": {
"policy": "real_professional_data_may_enter_codex_context",
"classes": [
{
"id": "retailer-product-evidence",
"purpose": "Map product attributes and compare retailer cohorts",
"content": "Retailer and category; structured product, variant, brand, description, price, promotion, ranking, cohort and taxonomy records; public image URLs and locally hydrated product images; package provenance and mapping history"
},
{
"id": "mapping-and-report-judgement",
"purpose": "Resolve ambiguous taxonomy mappings and author and review a checked report",
"content": "Mapping tasks, decisions, evidence, local-image hashes, independent mapping reviews, computed tables, report model, claim ledger, caveats, selected examples, semantic review, browser QA, and correctness verdict"
}
]
},
"ordinary_codex_model_processing": {
"scope": "content_supplied_to_the_codex_model",
"account_arrangement": "user_selected_chatgpt_or_codex_account",
"separate_clara_recipient_or_arrangement": false,
"automatic_anonymisation": false,
"local_filter_or_aggregate": "only_when_useful_for_professional_work",
"plan_visibility": "not_inspected_or_enforced_by_clara"
},
"codex_account_boundary": {
"selected_by": "firm_or_user",
"clara_runtime_enforcement": "none",
"review_timing": "before_professional_use_and_when_account_or_terms_change",
"review_items": [
"account_or_workspace_plan",
"model_training_data_controls",
"retention_and_deletion_controls"
],
"per_case_record_required": false
},
"hosted_service_ids": [
"retail-data"
],
"boundaries_beyond_codex": [
{
"id": "mparanza-retail-data",
"kind": "hosted_service",
"hosted_service_id": "retail-data",
"destination": "Mparanza Attribute Reporting service",
"purpose": "Retrieve the central taxonomy and current structured retail snapshot, create mapping worksets, submit explicitly reviewed mappings, and download rebuilt evidence packages",
"content": "Retailer/category and pinned taxonomy identifiers; evidence and workset identifiers; mapping tasks, decisions, validated mappings, independent mapping review, correction reason when used, and authenticated transport metadata; local HTML reports and local image bytes are not uploaded",
"optional": true,
"requires_confirmation": false,
"controls": [
"The installed current-database route is selected explicitly; existing integrity-checked local packages can be processed without it.",
"Server writes occur only at the explicit mapping-submission checkpoint.",
"The separate hosted-service record states the source-backed access and retention position."
]
},
{
"id": "public-product-image-retrieval",
"kind": "public_research",
"destination": "Public product-image hosts named by the evidence package",
"purpose": "Download product images for local mapping evidence and report review",
"content": "The package-supplied public image URL and ordinary network request metadata; downloaded image bytes remain local and are not sent back with the report",
"optional": true,
"requires_confirmation": false,
"controls": [
"The image hydrator permits supported public raster URLs only and validates address, redirect, byte-size, and hash constraints.",
"Missing images remain a visible partial evidence state rather than triggering an undisclosed alternative route."
]
},
{
"id": "direct-cli-python-dependency-setup",
"kind": "public_research",
"destination": "Python Package Index (PyPI) or the index selected by the user's Python configuration",
"purpose": "Prepare the declared Python dependencies before running a documented workflow CLI",
"content": "Published package requirements and ordinary package-index request metadata. Existing workflow arguments are forwarded to a local Python child; they are not included in the pip install command.",
"optional": false,
"requires_confirmation": false,
"controls": [
"The direct CLI selects published core or registered component requirements before importing workflow modules.",
"The launcher preserves the working directory and arguments in the local child process; this does not redact arguments or change the workflow data boundary.",
"An existing matching runtime is reused. Setup installs into a fingerprinted user-scoped environment and propagates failure; it does not install into the case folder."
]
}
],
"security_controls": [
{
"id": "origin-bound-auth",
"control": "Authentication cookies are kept in a private local auth directory and attached only to the exact approved Mparanza origin."
},
{
"id": "checksummed-packages",
"control": "Downloads are size-limited, checksum-verified, safely extracted, and bound to local transport and package provenance."
}
],
"review": {
"reviewed_at": "2026-09-15",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "aeb580c22f06024f60e35f6600d648afa871e33f261f646c0eedb2e30db1c587"
}
}
SHA-256: e80df202229f87c9867864a28779095e8191344dbffc6d778e55d359b6b93d4d