← Files LuciaARCHIVED FILE
privacy/workstreams/apertura-pratica.json
5.52 KB · Oct 2, 2026 · 00:30 UTC
{
"schema_version": 3,
"workstream": "apertura-pratica",
"display_name": "Fascicolo nuova pratica",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"schemas",
"references",
"assets",
"evals"
],
"governed_repository_paths": [
"plugins/studio-archive/scripts/archive_core.py",
"plugins/studio-archive/scripts/studio_archive.py",
"plugins/studio-archive/scripts/client_ledger.py",
"plugins/studio-archive/mcp/server.cjs",
"plugins/vera/scripts/model_data_report.py",
"plugins/vera/skills/vera/references/model-data-report-contract.md",
"plugins/studio-archive/scripts/build_model_data_report.py"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "legal-matter-opening-material",
"purpose": "Prepare a new client matter or a new matter for an existing client for lawyer review",
"content": "Selected identity and contact material; client, assisted-party, counterparty and other relevant party names, aliases and identifiers; requested work, facts, jurisdiction and procedural posture; engagement scope, exclusions, authority and fee status; conflict-register search references and candidate matches; possible deadline triggers and source references; confidentiality restrictions; conditional AML applicability material; privacy and retention posture; missing items; original imported filenames (including aliases for identical bytes), evidence names, bytes and SHA-256 receipts; model provenance; proposed folder plan; lawyer review decisions and final package status. The workflow does not promise automatic anonymization, automatic conflict clearance, binding deadline calculation, engagement acceptance or local-only model processing.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "optional-current-official-source-research",
"kind": "public_research",
"destination": "Current official legal, regulatory, bar and public-authority sources selected for the matter-opening question",
"purpose": "Verify current professional boundaries or a generic legal source needed to frame an intake issue",
"content": "Generic law, authority, provision, date, jurisdiction and topic queries plus public source URLs; no client identity, party identity, private facts, conflict-register content, documents, credentials, cookies or session material",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"Use generic topic-level queries and keep client, party and matter identifiers out of public research.",
"Record the exact source URL, authority and retrieval date before using it as a source reference.",
"Keep credentials, cookies, tokens, one-time codes and private register content out of research requests."
]
}
],
"security_controls": [
{
"id": "private-path-and-immutable-evidence",
"control": "Initialization rejects repository paths, uses owner-only permissions and atomic writes; evidence intake accepts only regular non-linked files, snapshots bytes without moving or renaming originals, and records size and SHA-256."
},
{
"id": "dedicated-legal-opening-validator",
"control": "The validator checks exhaustive schema structure, reference closure, immutable evidence hashes, professional-gate completeness and receipt freshness while explicitly leaving conflict, deadline, applicability and engagement judgments to the lawyer."
},
{
"id": "digest-bound-explicit-review",
"control": "Review decisions bind the exact intake and substantive review payload digests, require a named reviewer and explicit user confirmation, and become stale when the intake changes."
},
{
"id": "no-automatic-file-operation-or-acceptance",
"control": "The workflow proposes a folder plan but never moves, renames or deletes source files and never claims that a client, engagement, conflict result or deadline was accepted automatically."
},
{
"id": "conditional-aml-boundary",
"control": "AML applicability is represented as a separate professional assessment with applicable, not-applicable or uncertain status; the workflow does not infer applicability merely because a client or matter is new."
},
{
"id": "local-model-data-report-finalization",
"control": "Durable Studio Archive finalization requires run-bound, hash-consistent model-data JSON and Markdown reports. The shared local helper validates supplied phase evidence and writes these artifacts without contacting a model or requesting a server attestation; it does not independently prove provider transmission or infer zero transmission from missing telemetry."
},
{
"id": "session-bound-archive-configuration",
"control": "Studio Archive separates default configuration by host session identity, holds a process lock on configured state and rejects configuration changes during an operation. These controls do not anonymize case data or prove provider transmission."
}
],
"review": {
"reviewed_at": "2026-09-15",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "bd9649dab7d783792491ac745c4924f2f047310b592f8505e2da47417419cb8e"
}
}
SHA-256: a3d9ce4de893cb936f4805623fc7e702889950994d302b3a00aafd5af25b2a78