← Files ClaraARCHIVED FILE

privacy/workflows/clara.json

16.8 KB · Oct 4, 2026 · 12:28 UTC

↓ Download file

{
  "schema_version": 1,
  "workflow": "clara",
  "display_name": "Clara Advisory Case",
  "governed_paths": [
    "README.md",
    ".claude-plugin/plugin.json",
    ".codex-plugin/plugin.json",
    "requirements.txt",
    "agents/clara.md",
    "hooks/cowork-hooks.json",
    "hooks/hooks.json",
    "skills/clara/SKILL.md",
    "skills/clara/references/cowork-runtime.md",
    "skills/clara/references/workflow-catalog.md",
    "contracts/advisory_case_direction_return.v1.schema.json",
    "contracts/preparation_audit_envelope.v2.schema.json",
    "contracts/real_data_pilot_intake.v1.schema.json",
    "contracts/real_data_pilot_intake.v2.schema.json",
    "contracts/real_data_pilot_intake_receipt.v1.schema.json",
    "contracts/real_data_pilot_intake_receipt.v2.schema.json",
    "contracts/real_data_pilot_mechanical_error_register.v1.schema.json",
    "contracts/real_data_pilot_retention_approval.v1.schema.json",
    "contracts/real_data_pilot_sanitized_error_class_summary_candidate.v1.schema.json",
    "contracts/real_data_pilot_sanitized_error_class_summary.v1.schema.json",
    "contracts/real_data_pilot_semantic_review.v1.schema.json",
    "contracts/real_data_pilot_semantic_review_receipt.v1.schema.json",
    "contracts/real_general_ledger_preparation_case.v1.schema.json",
    "contracts/real_general_ledger_semantic_decisions.v1.schema.json",
    "scripts",
    "scripts/_shared_python_runtime.py",
    "requirements-shared-core.txt",
    "requirements-shared-ocr.txt",
    "constraints-shared-macos-py312.txt",
    "scripts/_python_bootstrap.py",
    "skills/clara/references/case-operations.md"
  ],
  "codex_context": {
    "policy": "real_professional_data_may_enter_codex_context",
    "classes": [
      {
        "id": "case-and-source-material",
        "purpose": "Understand and organize an advisory engagement",
        "content": "Client and project labels; objectives and audience; company, participant and stakeholder identities; source documents, decks, spreadsheets, notes, transcripts, recordings, dates, facts, financial or operating data, constraints, risks, and open questions"
      },
      {
        "id": "advisory-judgement-and-evidence",
        "purpose": "Weigh evidence and prepare decision-ready advice",
        "content": "Material summaries; stable evidence receipts and claim records; source limitations; quotation and transcript provenance; calculation inputs, methods, outputs, verification runs, and artifact bindings; consultant and advisor judgement; Codex inferences; claim dependencies; contradictions; hypotheses; options; recommendations; implementation conditions; pending inclusion decisions; case issues; case-direction branch and validator returns; output appearances; correction and recheck succession; and pseudonymous but linkable audit metadata such as exact source and output digests, byte counts, stable IDs, dates, counts, and cross-receipt hashes"
      },
      {
        "id": "human-visible-outputs",
        "purpose": "Draft and review workpapers, briefs, decks, memos, decision packs, and narrated videos",
        "content": "Narrative, charts, claims, citations, speaker notes, narration scripts, hash-bound Mparanza voice requests and returned OpenAI audio artifacts, localized AI-voice disclosures, accepted Vera handoff references, review findings, approved content, and final deliverables"
      },
      {
        "id": "recovery-narrative-and-execution-artifacts",
        "purpose": "Recover interrupted local work and verify that the current output matches reviewed case evidence",
        "content": "Transaction preimages can temporarily retain prior case bytes; immutable capture notes and case history retain source content. Model-authored decision paragraphs, approved claim IDs, reviewer attestations, workpaper bindings and per-format readiness records may enter context. Reporting and media attempts retain staging outputs, stdout/stderr logs, rendered snapshots, source/output hashes, paths and failure details. Local normalization can include full tabular data; reduced previews do not prove complete source review. No cleanup of these files establishes deletion of other case copies, browser downloads or provider data."
      }
    ]
  },
  "ordinary_codex_model_processing": {
    "scope": "content_supplied_to_the_codex_model",
    "account_arrangement": "user_selected_chatgpt_or_codex_account",
    "separate_clara_recipient_or_arrangement": false,
    "automatic_anonymisation": false,
    "local_filter_or_aggregate": "only_when_useful_for_professional_work",
    "plan_visibility": "not_inspected_or_enforced_by_clara"
  },
  "codex_account_boundary": {
    "selected_by": "firm_or_user",
    "clara_runtime_enforcement": "none",
    "review_timing": "before_professional_use_and_when_account_or_terms_change",
    "review_items": [
      "account_or_workspace_plan",
      "model_training_data_controls",
      "retention_and_deletion_controls"
    ],
    "per_case_record_required": false
  },
  "hosted_service_ids": [
    "hosted-voice",
    "plugin-feedback",
    "plugin-update-check",
    "research-video-voice"
  ],
  "boundaries_beyond_codex": [
    {
      "id": "authorized-public-research",
      "kind": "public_research",
      "destination": "Public or otherwise authorized external sources selected for the engagement",
      "purpose": "Obtain current industry, market, governance, legal, or other external context relevant to the advisory question",
      "content": "Research questions, search terms, selected URLs, retrieved public material, and concise source takeaways; queries may reflect engagement facts when Codex uses them",
      "optional": true,
      "requires_confirmation": false,
      "controls": [
        "Use public or authorized sources only.",
        "Do not copy proprietary case material into a public research source or shared playbook."
      ]
    },
    {
      "id": "optional-hosted-voice",
      "kind": "hosted_service",
      "hosted_service_id": "hosted-voice",
      "destination": "Mparanza Hosted Voice and its configured realtime/transcription provider",
      "purpose": "Capture or upload a spoken debrief and return a transcript bundle",
      "content": "Compact case context when enabled, live or uploaded recording content, source metadata, transcript, and media metadata",
      "optional": true,
      "requires_confirmation": false,
      "controls": [
        "Hosted Voice is used only after the user selects a voice capture or upload route.",
        "The separate hosted-service record states the source-backed access and retention position."
      ]
    },
    {
      "id": "consented-plugin-feedback",
      "kind": "hosted_service",
      "hosted_service_id": "plugin-feedback",
      "destination": "Mparanza plugin feedback service",
      "purpose": "Transmit a technical problem or improvement suggestion to the developer and check its status",
      "content": "The exact sanitized request approved by the user, plugin name and version, request kind, idempotency metadata, and later receipt identifiers and status tokens",
      "optional": true,
      "requires_confirmation": true,
      "controls": [
        "Clara's host-specific instructions require the assistant to show and sanitize the exact submission before invoking the helper; the helper enforces the required bounded diagnostic schema for problems but cannot detect personal data.",
        "The skill instructs Codex to exclude client, source, case, credential, secret, and identifying material.",
        "The skill requires separate consent for problem reports, follow-up evidence, and suggestions; the command-line helper cannot prove that consent occurred.",
        "Claude Cowork stores opaque receipts under its user-scoped plugin data directory and polls them with a trusted SessionStart hook."
      ]
    },
    {
      "id": "automatic-plugin-update-check",
      "kind": "hosted_service",
      "hosted_service_id": "plugin-update-check",
      "destination": "Mparanza public plugin-version manifest",
      "purpose": "Notify the user when a newer Clara version is published",
      "content": "A GET request with a fixed update-check User-Agent; no case files, prompts, transcripts, or client content are included by the plugin",
      "optional": false,
      "requires_confirmation": false,
      "controls": [
        "The request uses a fixed HTTPS manifest URL and a three-second timeout.",
        "The check is rate-limited locally and fails open without blocking Clara.",
        "This custom update check is included only in the OpenAI package, not the Claude Cowork package."
      ]
    },
    {
      "id": "approved-research-video-voice",
      "kind": "hosted_service",
      "hosted_service_id": "research-video-voice",
      "destination": "Authenticated Mparanza Research Video Voice and OpenAI speech service configured by Mparanza",
      "purpose": "Generate scene-level narration audio from an explicitly approved Research Video script without a user API key",
      "content": "Mparanza receives exact approved narration, language, scene identifiers, plan and approval hashes, and explicit confirmation. OpenAI receives each scene's narration plus fixed speech policy. Images, sources, Vera artifacts, source-basis notes, and local paths remain local.",
      "optional": true,
      "requires_confirmation": true,
      "controls": [
        "The workflow creates the narration-only request only after exact script and plan approval.",
        "Mparanza requires a valid session but currently applies no Research Video email allowlist.",
        "The hosted application builds the ZIP in memory and does not write the request or audio to application storage; OpenAI retention is not established by plugin source."
      ]
    },
    {
      "id": "automatic-core-python-dependency-retrieval",
      "kind": "public_research",
      "destination": "Python Package Index (PyPI) or the package index selected by the user's Python configuration",
      "purpose": "Prepare the published shared Vera, Clara and Lucia core dependencies, and validate the selected workflow, in one user-scoped Python 3.12 environment per operating-system host.",
      "content": "Shared published package names and version constraints plus ordinary package-index request metadata. Client files, prompts, case data and generated work are not included in installer requests. Workflow arguments stay in the local child process.",
      "optional": false,
      "requires_confirmation": false,
      "controls": [
        "Only published shared requirements are installed, never requirements derived from client material or prompts.",
        "One fixed environment outside plugin source and client folders is reused across products and modules. Explicitly approved OCR is retained in the same environment.",
        "A reader lease prevents setup from modifying packages while managed workflows run. Setup validates dependencies before writing the readiness receipt. Failed updates leave execution unavailable until repair.",
        "Older plugin policies cannot downgrade an environment created by a newer shared policy revision.",
        "Readiness probes the managed interpreter locally with isolated Python and site loading disabled. CPython 3.12 and its platform must match receipt and policy independently of the initial launcher; this probe transmits no data.",
        "Documented direct CLIs select the published dependency contract before importing workflow modules. No case path, prompt, or source content is used to construct the package request.",
        "An OS lock serializes setup. Validated immutable generations are published by an atomic active pointer; previous generations remain locally available for existing readers until the local cache is removed. Failed unpublished generations are removed, and symlink pointers or targets are rejected.",
        "The direct launcher preserves CLI arguments and working directory in a local managed Python child and propagates its exit status. Arguments are not part of pip installation requests; local argument forwarding is not redaction."
      ]
    },
    {
      "id": "selected-module-python-dependency-retrieval",
      "kind": "public_research",
      "destination": "Python Package Index (PyPI) or the package index selected by the user's Python configuration",
      "purpose": "Prepare the published shared Vera, Clara and Lucia core dependencies, and validate the selected workflow, in one user-scoped Python 3.12 environment per operating-system host.",
      "content": "Shared published package names and version constraints plus ordinary package-index request metadata. Client files, prompts, case data and generated work are not included in installer requests. Workflow arguments stay in the local child process.",
      "optional": true,
      "requires_confirmation": false,
      "controls": [
        "Only published shared requirements are installed, never requirements derived from client material or prompts.",
        "One fixed environment outside plugin source and client folders is reused across products and modules. Explicitly approved OCR is retained in the same environment.",
        "A reader lease prevents setup from modifying packages while managed workflows run. Setup validates dependencies before writing the readiness receipt. Failed updates leave execution unavailable until repair.",
        "Older plugin policies cannot downgrade an environment created by a newer shared policy revision.",
        "Readiness probes the managed interpreter locally with isolated Python and site loading disabled. CPython 3.12 and its platform must match receipt and policy independently of the initial launcher; this probe transmits no data.",
        "An OS lock serializes setup. Validated immutable generations are published by an atomic active pointer; previous generations remain locally available for existing readers until the local cache is removed. Failed unpublished generations are removed, and symlink pointers or targets are rejected.",
        "Direct module CLIs select their registered component requirements; Reporting Engine execution/render entrypoints also select the declared render requirements. The setup request does not contain workflow CLI arguments."
      ]
    },
    {
      "id": "approved-managed-ocr-runtime",
      "kind": "public_research",
      "destination": "Python Package Index (PyPI)",
      "purpose": "Enable the published optional PaddleOCR feature in the same shared environment after user approval.",
      "content": "Package names and constraints from requirements-shared-ocr.txt and ordinary package-index request metadata; no client files or document content are sent by setup.",
      "optional": true,
      "requires_confirmation": true,
      "controls": [
        "The input preflight requests this setup only for images or visual-only PDFs that require local OCR.",
        "The Clara skill requires explicit user approval before the managed installer runs.",
        "The installer uses only the published OCR recipe in the same shared environment as core dependencies, and retains this feature across subsequent core updates."
      ]
    },
    {
      "id": "declared-python312-retrieval",
      "kind": "public_research",
      "destination": "Astral python-build-standalone CPython distributions on GitHub, or the Python download mirror explicitly configured in uv",
      "purpose": "Provision the declared CPython 3.12 workflow interpreter when absent, automatically bootstrapping uv if needed",
      "content": "The fixed CPython 3.12 version request, operating-system and architecture selection, and ordinary download request metadata. Setup does not read client files or add prompts, case material or generated reports to this request.",
      "optional": false,
      "requires_confirmation": false,
      "controls": [
        "Use an installed CPython 3.12 when available; otherwise use uv or automatically download the published uv 0.12.10 wheel, verify its pinned SHA-256, and provision private CPython 3.12 without changing system Python or shell profiles.",
        "Probe the selected interpreter before creating the dependency environment; never fall back to executing workflows with another Python minor version.",
        "A failed download or interpreter probe stops setup; existing environments and client files remain intact."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "m6-exact-local-source-boundary",
      "control": "M6 raw workbooks and row- or account-level prepared outputs remain in an owner-only private pilot root at a fixed opaque source locator; group/other permission bits and macOS extended ACLs are rejected at audit validation. They are not committed, packaged, or published. Ordinary model processing remains within the user-selected Codex account and this workflow adds no separate external recipient."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-30",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "f8388e621b748446d07ee652a618d0e57540c4e3e573a6961aa3118649b067e2"
  }
}

SHA-256: 048068fddbde336592b6f18adc47331d90c3d03d4db2c24ea85f3cae554572cf