← Files ClaraARCHIVED FILE
privacy/workflows/reporting-engine.json
13 KB · Oct 3, 2026 · 06:30 UTC
{
"schema_version": 1,
"workflow": "reporting-engine",
"display_name": "Reporting Engine",
"governed_paths": [
"requirements.txt",
"hooks/cowork-hooks.json",
"scripts/bootstrap_python_dependencies.py",
"scripts/check_dependencies.py",
"skills/clara/references/cowork-runtime.md",
"skills/reporting-engine/SKILL.md",
"contracts/reporting_evidence_handoff_receipt.v1.schema.json",
"scripts/build_monthly_pnl_reporting_handoff.py",
"scripts/record_reporting_contribution.py",
"modules/reporting-engine/README.md",
"modules/reporting-engine/references",
"modules/reporting-engine/requirements.txt",
"modules/reporting-engine/scripts",
"scripts/self_relaunch.py",
"scripts/managed_python_runtime.py",
"scripts/_managed_python_runtime.py",
"components.json",
"scripts/_shared_python_runtime.py",
"requirements-shared-core.txt",
"requirements-shared-ocr.txt",
"constraints-shared-macos-py312.txt",
"scripts/_python_bootstrap.py",
"repository/plugins/management-control-pack/scripts",
"repository/plugins/management-control-pack/assets/budget-report.css",
"repository/plugins/management-control-pack/assets/budget-report.js",
"repository/plugins/_shared/vendor/modules/reporting_table.py",
"scripts/bounded_process.py",
"scripts/artifact_publication.py",
"scripts/case_store.py",
"modules/reporting-engine/catalog",
"repository/plugins/distribution-analysis/scripts/distribution_core.py",
"repository/plugins/distribution-analysis/skills/distribution-analysis/SKILL.md",
"repository/plugins/distribution-analysis/.codex-plugin/plugin.json",
"repository/plugins/management-control-pack/assets/management-report-copy.json"
],
"codex_context": {
"policy": "real_professional_data_may_enter_codex_context",
"classes": [
{
"id": "business-dataset",
"purpose": "Summarize, profile, interpret, validate, and visualize the user's business data",
"content": "CSV, XLSX, or Parquet fields and values; dataset identity; metrics, dimensions, periods, identifiers, members, source notes, and compatibility evidence A short descriptive summary can use already available local tools without a semantic project or reporting run; the supplied values and calculated summary may still enter Codex context. This does not create a reviewed execution or downstream calculation receipt."
},
{
"id": "semantic-and-reporting-artifacts",
"purpose": "Author reusable dataset semantics and choose a source-backed analysis",
"content": "Dataset profiles, intake receipts, semantic layers, evidence, reviewed Sales/Discount/COGS mapping states, role bindings, snapshot attachments, analysis policies, chart plans, exact input and output byte hashes, effective recipe records, rendered charts, authoritative calculation and report validation results, model-authored interpretations, and calculation evidence receipts with stable claim identifiers, dependency edges, verification runs, and shared case-register bindings Explicitly reviewed whole-population scope may have no period column. Nonfinancial metric definitions and units, all-records scope receipts and disclosed legacy Date/Period adapter placeholders can enter model context; those placeholders do not establish source time coverage. These changes add no hosted request."
},
{
"id": "budget-report-context",
"purpose": "Prepare and interpret a reviewed Actual/Budget/Forecast report",
"content": "Source-role inspection includes filenames, columns/types and up to 10 preview rows per table. The model/professional authors mappings, audience and forecast assumptions. After local calculations, model_context.json includes all metric IDs and values, controls and coverage, source hashes, up to 60 calculated rows per section and 60 budget comparison rows with total counts. Raw export populations, original filenames and full pack JSON are excluded from this default post-calculation projection. Directly opening source files adds their read content to model context. The report contains all compiled views and optionally customer, supplier or service names. Clara reuses the management-control core through Reporting Engine with its ordinary project/output scope; it does not require Vera Studio Archive. No automatic redaction is applied."
},
{
"id": "parser-and-attempt-evidence",
"purpose": "Verify reviewed parsing/execution and inspect failed or published analytical results",
"content": "Explicit sheet/CSV parser settings, source hashes, reviewed execution context, generated recipes, output tables/charts, current-generation pointer, retained prior output snapshots, failed staging files and process logs (which may include local paths and business values) can be read by Codex. Normalized temporary CSV input is removed by the managed temporary-directory scope; failed stages, logs and published generations persist until separately removed. No automatic anonymisation is applied. Unsupported distribution mapping names are returned in a local validation error before report artifacts are written; the requested binding names may enter Codex context. The rejection introduces no external destination or additional retained source content. Explicit reporting delivery export creates an additional local copy of the complete reviewed source dataset and source notes, profile, semantic layer, acceptance receipt, current published generation and generated outputs. Its portable descriptor retains relative input paths and receipt hashes; the original execution receipt retains original absolute paths. These copies persist at the selected delivery location. The export itself performs no upload; a separately chosen Cowork or sharing route processes or transfers the selected bundle under that route."
}
]
},
"ordinary_codex_model_processing": {
"scope": "content_supplied_to_the_codex_model",
"account_arrangement": "user_selected_chatgpt_or_codex_account",
"separate_clara_recipient_or_arrangement": false,
"automatic_anonymisation": false,
"local_filter_or_aggregate": "only_when_useful_for_professional_work",
"plan_visibility": "not_inspected_or_enforced_by_clara"
},
"codex_account_boundary": {
"selected_by": "firm_or_user",
"clara_runtime_enforcement": "none",
"review_timing": "before_professional_use_and_when_account_or_terms_change",
"review_items": [
"account_or_workspace_plan",
"model_training_data_controls",
"retention_and_deletion_controls"
],
"per_case_record_required": false
},
"hosted_service_ids": [],
"boundaries_beyond_codex": [
{
"id": "declared-python-dependency-retrieval",
"kind": "public_research",
"destination": "Python Package Index (PyPI)",
"purpose": "Prepare the published shared Vera, Clara and Lucia core dependencies, and validate the selected workflow, in one user-scoped Python 3.12 environment per operating-system host.",
"content": "Shared published package names and version constraints plus ordinary package-index request metadata. Client files, prompts, case data and generated work are not included in installer requests. Workflow arguments stay in the local child process.",
"optional": true,
"requires_confirmation": false,
"controls": [
"Only published shared requirements are installed, never requirements derived from client material or prompts.",
"One fixed environment outside plugin source and client folders is reused across products and modules. Explicitly approved OCR is retained in the same environment.",
"A reader lease prevents setup from modifying packages while managed workflows run. Setup validates dependencies before writing the readiness receipt. Failed updates leave execution unavailable until repair.",
"Older plugin policies cannot downgrade an environment created by a newer shared policy revision."
]
},
{
"id": "direct-cli-python-dependency-setup",
"kind": "public_research",
"destination": "Python Package Index (PyPI) or the index selected by the user's Python configuration",
"purpose": "Prepare the published shared Vera, Clara and Lucia core dependencies, and validate the selected workflow, in one user-scoped Python 3.12 environment per operating-system host.",
"content": "Shared published package names and version constraints plus ordinary package-index request metadata. Client files, prompts, case data and generated work are not included in installer requests. Workflow arguments stay in the local child process.",
"optional": false,
"requires_confirmation": false,
"controls": [
"Only published shared requirements are installed, never requirements derived from client material or prompts.",
"One fixed environment outside plugin source and client folders is reused across products and modules. Explicitly approved OCR is retained in the same environment.",
"A reader lease prevents setup from modifying packages while managed workflows run. Setup validates dependencies before writing the readiness receipt. Failed updates leave execution unavailable until repair.",
"Older plugin policies cannot downgrade an environment created by a newer shared policy revision."
]
},
{
"id": "declared-python312-retrieval",
"kind": "public_research",
"destination": "Astral python-build-standalone CPython distributions on GitHub, or the Python download mirror explicitly configured in uv",
"purpose": "Provision the declared CPython 3.12 workflow interpreter when absent, automatically bootstrapping uv if needed",
"content": "The fixed CPython 3.12 version request, operating-system and architecture selection, and ordinary download request metadata. Setup does not read client files or add prompts, case material or generated reports to this request.",
"optional": false,
"requires_confirmation": false,
"controls": [
"Use an installed CPython 3.12 when available; otherwise use uv or automatically download the published uv 0.12.10 wheel, verify its pinned SHA-256, and provision private CPython 3.12 without changing system Python or shell profiles.",
"Probe the selected interpreter before creating the dependency environment; never fall back to executing workflows with another Python minor version.",
"A failed download or interpreter probe stops setup; existing environments and client files remain intact."
]
},
{
"id": "budget-sites-report",
"kind": "send_or_publish",
"destination": "OpenAI Sites through the selected host Sites connector",
"purpose": "Publish the reviewed budget and forecast report for the selected readers",
"content": "The host uploads the complete rendered HTML: entity, all compiled financial comparisons including hidden views, forecast basis, coverage and limitations, metric-linked commentary and optional customer, supplier and service labels. Raw export populations, original files, local paths and the full pack JSON are not copied into dist. The local preparation helper makes no network request. Sites manages hosting and visitor access; retention and deletion are not enforced by the plugin.",
"optional": true,
"requires_confirmation": true,
"controls": [
"An explicit Sites publication request selects this route; host-required action approvals still apply. Invitations need authorized recipients.",
"Source replay must equal the persisted pack. The audience must match the reviewed recipe. Blocked or unsupported budget reports cannot be prepared. A fresh output folder preserves prior versions.",
"All compiled HTML views remain delivered; selection controls do not redact hidden values. No automatic anonymization occurs.",
"Verify deployment and visitor access. Refresh requires new source review and explicit publication using the existing Site ID."
]
}
],
"security_controls": [
{
"id": "local-budget-preview",
"control": "The optional stdlib budget preview binds only 127.0.0.1 and serves one opaque route for the selected native dashboard. It checks its exact byte count and SHA-256 against the adjacent execution receipt, permits only the current bundled presentation script, rejects active embeds and event attributes, and pins both report and receipt for the server lifetime. Its CSP blocks external resources and forms, retains an opaque sandbox origin and permits the known script plus print dialogs. Other routes and changed files are rejected. It writes no access logs, does not serve input files or receipts, and makes no upload. Loopback and the opaque URL are not authentication against other local processes; opening the report in Codex remains ordinary native model processing."
}
],
"review": {
"reviewed_at": "2026-09-15",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "2c0f86b78755fdf363ead03afe8ebd0fc766159ab18a3cd7465d7eb001f98e6a"
}
}
SHA-256: 7739fac500b4848a7e084cab280e7aa76161b2afc09a99836f91decc68b3f2f5