← Files ClaraARCHIVED FILE

privacy/workflows/advisory-case-director.json

8.71 KB · Oct 3, 2026 · 06:30 UTC

↓ Download file

{
  "schema_version": 1,
  "workflow": "advisory-case-director",
  "display_name": "Direct an advisory case",
  "governed_paths": [
    "contracts/advisory_case_direction_return.v1.schema.json",
    "scripts/advisor_case_core.py",
    "scripts/commit_advisory_workpaper.py",
    "scripts/record_analysis_contribution.py",
    "scripts/record_case_direction_return.py",
    "scripts/verify_advisory_html_delivery.py",
    "skills/advisory-case-director/SKILL.md",
    "skills/advisory-case-director/agents/openai.yaml",
    "skills/advisory-case-director/evals",
    "skills/advisory-case-director/references/case-direction-return.md",
    "skills/advisory-case-director/references/operating-model.md",
    "scripts/self_relaunch.py",
    "scripts/managed_python_runtime.py",
    "scripts/_managed_python_runtime.py",
    "requirements.txt",
    "components.json",
    "scripts/_shared_python_runtime.py",
    "requirements-shared-core.txt",
    "requirements-shared-ocr.txt",
    "constraints-shared-macos-py312.txt",
    "scripts/_python_bootstrap.py",
    "scripts/case_store.py",
    "scripts/case_exchange_safety.py",
    "scripts/decision_narrative.py",
    "scripts/commit_decision_narrative.py",
    "scripts/verify_decision_pack.py",
    "scripts/advisory_delivery.py",
    "scripts/verify_advisory_delivery.py",
    "scripts/bounded_process.py"
  ],
  "codex_context": {
    "policy": "real_professional_data_may_enter_codex_context",
    "classes": [
      {
        "id": "complete-case-state",
        "purpose": "Understand the current answer and direct the advisory case",
        "content": "Assignment contract, case manifest and mandate, real client and stakeholder identities, source materials, interviews, financial or commercial data, material registry, evidence and claim registers, judgement log, open questions, case issues, case brief, case-direction return receipts, current and prior advisory workpapers, the workpaper checkpoint, and working deliverables"
      },
      {
        "id": "case-direction-judgement",
        "purpose": "Choose and explain the next decision-relevant work",
        "content": "Current answer, case-specific reasoning structure, assumptions, contradictions, confidence and conditions, alternative explanations, decision-changing unknowns, ranked next questions, research and analysis briefs, partner-originated questions and judgement, specialist contributions, and the stated effect of new evidence"
      },
      {
        "id": "working-deliverable-round-trip",
        "purpose": "Keep milestone outputs consistent with the living case direction",
        "content": "Working deck, memo, brief, storyline, partner feedback, semantic revisions, residual uncertainty, and the decision to create or revise an output"
      },
      {
        "id": "authored-narrative-and-current-delivery",
        "purpose": "Review the same case answer and qualifications across Markdown, Word and HTML",
        "content": "Committed narrative paragraphs, claim IDs, reviewer identity and status, current case and workpaper bindings, per-format artifacts and visual-review records, output paths and hashes, readiness receipts and mismatch errors. Local transaction recovery files can temporarily contain prior case bytes; source history and bound output artifacts remain separately retained. No automatic anonymisation or extra model service is introduced by these helpers."
      },
      {
        "id": "shared-case-normalization-attempts",
        "purpose": "Inspect case presentation imports and any normalization diagnostics used by this workflow",
        "content": "When a presentation is imported through the shared case helper and requires normalization, local attempt directories retain converted presentation files and converter stdout/stderr logs. They may contain source document content, metadata and local paths, including after failure or cancellation. Reading them supplies their contents to model context. This conditional import path does not mean every workflow execution converts a presentation or sends these files to a hosted service. Retained attempt files remain until separately removed."
      }
    ]
  },
  "ordinary_codex_model_processing": {
    "scope": "content_supplied_to_the_codex_model",
    "account_arrangement": "user_selected_chatgpt_or_codex_account",
    "separate_clara_recipient_or_arrangement": false,
    "automatic_anonymisation": false,
    "local_filter_or_aggregate": "only_when_useful_for_professional_work",
    "plan_visibility": "not_inspected_or_enforced_by_clara"
  },
  "codex_account_boundary": {
    "selected_by": "firm_or_user",
    "clara_runtime_enforcement": "none",
    "review_timing": "before_professional_use_and_when_account_or_terms_change",
    "review_items": [
      "account_or_workspace_plan",
      "model_training_data_controls",
      "retention_and_deletion_controls"
    ],
    "per_case_record_required": false
  },
  "hosted_service_ids": [],
  "boundaries_beyond_codex": [
    {
      "id": "bounded-authorized-public-research",
      "kind": "public_research",
      "destination": "Public or otherwise authorized external sources selected for the case",
      "purpose": "Answer one bounded decision-relevant question when external evidence can improve the case direction",
      "content": "Research question, search terms, the minimum non-proprietary case context needed to frame it, selected URLs, retrieved public material, and source-level findings and limitations",
      "optional": true,
      "requires_confirmation": true,
      "controls": [
        "Obtain the user's explicit authorization before launching the external research branch.",
        "Use public or otherwise authorized sources only.",
        "Do not copy proprietary source material into a public query.",
        "Separate market-level findings from unproven target execution or capability claims.",
        "Register the returned report and controlling sources in the case before revising the workpaper."
      ]
    },
    {
      "id": "direct-cli-python-dependency-setup",
      "kind": "public_research",
      "destination": "Python Package Index (PyPI) or the index selected by the user's Python configuration",
      "purpose": "Prepare the published shared Vera, Clara and Lucia core dependencies, and validate the selected workflow, in one user-scoped Python 3.12 environment per operating-system host.",
      "content": "Shared published package names and version constraints plus ordinary package-index request metadata. Client files, prompts, case data and generated work are not included in installer requests. Workflow arguments stay in the local child process.",
      "optional": false,
      "requires_confirmation": false,
      "controls": [
        "Only published shared requirements are installed, never requirements derived from client material or prompts.",
        "One fixed environment outside plugin source and client folders is reused across products and modules. Explicitly approved OCR is retained in the same environment.",
        "A reader lease prevents setup from modifying packages while managed workflows run. Setup validates dependencies before writing the readiness receipt. Failed updates leave execution unavailable until repair.",
        "Older plugin policies cannot downgrade an environment created by a newer shared policy revision."
      ]
    },
    {
      "id": "declared-python312-retrieval",
      "kind": "public_research",
      "destination": "Astral python-build-standalone CPython distributions on GitHub, or the Python download mirror explicitly configured in uv",
      "purpose": "Provision the declared CPython 3.12 workflow interpreter when absent, automatically bootstrapping uv if needed",
      "content": "The fixed CPython 3.12 version request, operating-system and architecture selection, and ordinary download request metadata. Setup does not read client files or add prompts, case material or generated reports to this request.",
      "optional": false,
      "requires_confirmation": false,
      "controls": [
        "Use an installed CPython 3.12 when available; otherwise use uv or automatically download the published uv 0.12.10 wheel, verify its pinned SHA-256, and provision private CPython 3.12 without changing system Python or shell profiles.",
        "Probe the selected interpreter before creating the dependency environment; never fall back to executing workflows with another Python minor version.",
        "A failed download or interpreter probe stops setup; existing environments and client files remain intact."
      ]
    }
  ],
  "security_controls": [],
  "review": {
    "reviewed_at": "2026-09-15",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "87ae622729af596880be297fff338ff13fd314296f09cfc9900f356bc7547401"
  }
}

SHA-256: 93b97412dc4645589c111e74c0886046d7c8f6cc41572997c1fdb24fa5c4b74e