← Files VeraARCHIVED FILE

privacy/workstreams/registro-imprese-sari.json

6.15 KB · Oct 3, 2026 · 06:30 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "registro-imprese-sari",
  "display_name": "Registro Imprese e SARI",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "mcp",
    "schemas",
    "assets/registro-imprese-sari-review-widget.html"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance",
    "vendor/modules/vera_ocr"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "practice-case-and-sources",
        "purpose": "Frame the case, apply current official guidance, and draft the professional-review practice plan",
        "content": "Case facts and local evidence; DIRE or SARI screenshots and OCR; dates and chamber; official-source passages and provenance; proposed classifications, recipient positions, filing steps, questions and review decisions. For CH-GE this also includes the actual Geneva registry, Swiss enterprise identifier and source-backed local registration steps; language does not select jurisdiction.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [
    {
      "id": "official-public-research",
      "kind": "public_research",
      "destination": "Public SARI, Registro Imprese, DIRE, chamber, INPS, INAIL, SUAP, and IVASS sources relevant to the case; for CH-GE, Geneva registry, Zefix and Fedlex public sources",
      "purpose": "Select current official guidance and record its provenance",
      "content": "Competent chamber and generic topical query, selected public content ID, public page metadata and official-source URLs; no client identifiers or case narrative",
      "optional": false,
      "requires_confirmation": false,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Use generic topical searches without names, tax codes, VAT numbers, contact details, addresses, or case narrative.",
        "Keep the public browser flow read-only and do not export cookies or use login, contact, assistance, upload, or submission routes.",
        "A human selects the relevant SARI content before it is registered."
      ]
    },
    {
      "id": "authorized-sari-json",
      "kind": "external_connector",
      "destination": "Exact public SARI host and selected chamber tenant",
      "purpose": "Search public metadata and fetch one human-selected SARI card through the conditional connector",
      "content": "Generic topical query or selected card ID, tenant and expected chamber; public metadata and card response",
      "optional": true,
      "requires_confirmation": true,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Require a separate written rights-holder permission reference; invoking the connector is the explicit network-route choice and creates no second approval identifier.",
        "Allow only the exact HTTPS SARI host and path, reject redirects, cap results and bytes, and fetch at most one selected card.",
        "Keep anonymous cookies in memory and never call login, support, upload, or submission routes."
      ]
    },
    {
      "id": "ocr-model-download",
      "kind": "hosted_service",
      "destination": "Configured PaddleOCR model-weight host",
      "purpose": "Download missing OCR model weights before local recognition",
      "content": "Pinned Hugging Face model repository and revision requests plus ordinary connection metadata; no case screenshots, extracted case content, or approval identifier are sent",
      "optional": true,
      "requires_confirmation": true,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Disabled by default and enabled only when the user explicitly selects the --allow-ocr-model-download route.",
        "The run records route selection and actual network use without treating an arbitrary identifier as authorization.",
        "Only model weights cross the boundary; screenshot recognition remains local."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "private-case-folder",
      "control": "Initialization, inventory, and packaging require a digest-valid Studio Archive registro-imprese-sari context, accept local evidence only from that engagement, and write generated artifacts only inside its exact run output root."
    },
    {
      "id": "reject-secret-and-session-material",
      "control": "Case and review validators reject credential, authentication-token, cookie, signature, and session-material fields before persistence."
    },
    {
      "id": "purpose-scoped-review-and-reference",
      "control": "The review package omits the wholesale client_identity object after its required values have been mapped into proposed filing fields, while retaining case purpose, proposals, evidence extracts, risks, and missing information; persisted MCP phases reuse a four-hour run- and hash-bound opaque reference instead of retransmitting those private rows."
    },
    {
      "id": "exact-known-identifier-query-guard",
      "control": "Before the optional public SARI connector transmits a query, it rejects both mechanically recognizable identifier formats and exact values already recorded as the case client reference or client identity; it does not attempt semantic PII classification."
    },
    {
      "id": "loopback-review-transport",
      "control": "The optional local browser transport binds only to 127.0.0.1 on an OS-selected port and secret path, rejects foreign Host/Origin and non-JSON writes, exposes only the existing save/apply operations for one exact run-bound opaque token, and reuses native ownership/hash/lifecycle validation. Archived cases render read-only; native writes still require a running run. No remote assets or data transfer are introduced."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-27",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "b82e6c021853b39f40b2d644737ca041bf37f1581501ed8d36f5f8d5ca3a0b4c"
  }
}

SHA-256: 031b72bd3b10ee396472feecadb3b142434d5c9f1091957b8b2b697fe119f76d