{
  "schema_version": 3,
  "workstream": "journal-bank-reconciliation",
  "display_name": "Journal-Bank Reconciliation",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "mcp",
    "assets/review-workbench-adapter.json",
    "assets/journal-bank-review-widget.html"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "bounded-column-mapping-and-run-review",
        "purpose": "Map source columns before deterministic reconciliation and review run-level controls and limitations",
        "content": "User instructions; source file metadata and raw column names; at most the first 20 normalized preview rows per qualified source; mapping assumptions and decisions; aggregate match and exception counts; assurance gates, limitations, review notes and artifact paths; when a worker selection is reviewed, its model/effort, reviewer reference, review status and benchmark digest may be read in the parent runtime. The selection review is retained in local evidence and is not added to the subordinate worker prompt.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "non-identifying-review-index-and-selected-cases",
        "purpose": "Select and interpret review cases without sending the complete ordinary review payload",
        "content": "The model first receives aggregate item-type counts and an index of opaque per-run case handles, item type, normalized categorical review status, recommended action and only the names of present mechanical signal classes; signal values and source facts remain out. Accepted non-interpretive artifact items remain available to the human widget but are omitted. The model can then request at most 25 selected cases per call. Selected context contains only populated mapped fields such as side, dates, signed amounts, currency, description, beneficiary or counterparty, account name, entity, party, direction, deterministic match stage and deltas, and missing-evidence reason. Unmapped raw columns, empty fields, physical source locators, technical row IDs, review write targets, duplicate facts and the redundant absolute amount are omitted. Exact references, movement numbers, shared references and account codes are off by default and can be requested only for selected cases. Real names, descriptions and other accounting facts can remain; opaque handles are routing controls, not anonymization or pseudonymization of the professional case data.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "bounded-luna-residual-resolution",
        "purpose": "Classify, identify, or suggest eligible relationships for unresolved bank movements under the user's selected certainty threshold",
        "content": "One bounded packet containing the complete admitted set of unresolved bank rows and hard-compatible journal candidates; populated canonical signed amount, date, description, beneficiary or counterparty, reference, movement number, account and perimeter fields selected after source-column mapping; and the reviewed matching policy. Unmapped raw columns, empty canonical fields, physical source locators and the redundant absolute amount are omitted. This separate Codex-only worker phase is unchanged by the ordinary review-index transport.",
        "runtime_profiles": [
          "openai-codex"
        ]
      }
    ]
  },
  "external_boundaries": [],
  "security_controls": [
    {
      "id": "generic-worker-output-leaf-check",
      "control": "The shared structured-worker entrypoint checks the caller-supplied output directory for a symlink before resolving the path and before opening authentication boundary inputs or launching a process. Its regression supplies a symlink to another empty directory and verifies rejection without credential access or output writes. This check covers the supplied leaf; it does not claim atomic protection from all concurrent ancestor-path changes."
    },
    {
      "id": "client-engagement-path-isolation",
      "control": "Inspection and reconciliation require a digest-valid Studio Archive journal-bank-reconciliation context, accept bank, journal, sample, and recipe inputs only from that engagement, and write only to the context's run output root or a descendant."
    },
    {
      "id": "qualified-source-and-reviewed-policy-binding",
      "control": "Bank and journal sources emit movements only through bounded tabular adapters and source-bound reviewed mapping receipts. The PDF-table-v1 adapter accepts only text PDFs with a labelled physical column grid, an explicit date header and monetary header, and an exact repeated page-table header; it preserves page, table and row lineage, while generic text, inconsistent tables, OCR-only sources and transaction-like candidate pages outside the recovered table emit zero rows. PDF mappings never qualify automatically and must bind the recovered header, amount/debit/credit roles, numeric convention, the complete current potential-monetary-column list, and explicit exclusions such as running balance. The default tabular-v6 contract remains unchanged; additive tabular-v7 is selected only by a current receipt that explicitly binds Italian textual-month date_locale or exact reviewed non-movement summary labels. The v7 parser accepts only the frozen full Italian month vocabulary and valid Gregorian dates, while summary exclusion requires an exact reviewed label, a blank mapped date, and no stable explicit reference. CSV profiling covers only comma, semicolon, tab, and pipe within fixed byte and row limits; profiling is transport evidence rather than semantic authority, non-default or conflicting delimiters require a current receipt, and ambiguous, unsupported, malformed, ragged, stale, or partly invalid sources emit zero rows. Reviewed mappings bind the field delimiter separately from numeric separators and bind the complete current potential-monetary-column list plus explicit exclusions. Non-canonical direction labels require a complete source-specific mapping to positive, negative, or zero that agrees with the exact signed amount, and the relationship policy is a separate reviewed-decision receipt bound to the current bank and journal artifact digests, currency, unit, entity, party, direction, tolerance, and date-window perimeter."
    },
    {
      "id": "non-reusing-exact-reconciliation",
      "control": "Relationship-v3 matching uses exact-decimal amounts, actual dates where required, distinctive explicit references, stable prepared identities, conflict-free batch snapshots, and non-reusing balanced relationship ledgers. Reviewed one-to-many or many-to-one groups require a shared stable reference and conserved group totals; overlapping groups remain unmatched. Row order cannot award contested evidence, while unmatched, reused, cross-currency, or residual rows keep readiness blocked."
    },
    {
      "id": "bounded-validated-luna-resolution-funnel",
      "control": "Codex-only residual resolution validates the current deterministic receipts and material-value replay before admitting the complete eligible residual to one size-capped candidate packet for a pinned deny-default Codex worker (Luna/max by default, or an explicitly reviewed selection). It never automatically chunks an over-cap residual: no worker launches and every movement remains in the human-review queue. The packet is projected after mapping and omits unmapped raw columns, empty canonical fields, physical source locators, and the derived absolute amount. Raw output is non-authoritative until strict schema, graph, lifecycle, launch-receipt, evidence non-reuse, and evidence checks pass. Accepted decisions update only sibling certainty-funnel, human-review-queue, and operational-review-payload artifacts under the recorded threshold; Luna cannot assign perfect_match or mutate canonical matches, ledgers, receipts, assurance gates, or report readiness."
    },
    {
      "id": "component-private-review-transport",
      "control": "MCP validation can load the sibling review JSON inside the local server and returns only a non-identifying index plus a random four-hour reference. Rendering exposes the complete validated payload only in tool-result _meta, which is component-only, while model-visible content and structuredContent contain the index. The widget hydrates from toolResponseMetadata and retains the complete human review surface. The local widget displays the existing native bank and journal dates and amounts, shared references and deltas with localized labels. Read-only reopening resolves and validates the owning portable run, including nested result folders. Archived results show a read-only notice and disabled save/apply buttons; server write authority still requires a running run. This adds no model payload or external route."
    },
    {
      "id": "bounded-selected-case-projection",
      "control": "The read-only case-context tool accepts only opaque handles bound to the current in-memory review reference, rejects unknown or duplicate handles, limits each call to 25 cases and 500000 response bytes, projects explicit post-mapping field allowlists, and keeps exact professional identifiers off unless explicitly requested for those selected cases."
    },
    {
      "id": "bounded-trusted-memory-review-transaction",
      "control": "MCP save and apply capture the complete regular single-link output tree, bytes, and root/directory/file modes in bounded parent-process memory before child execution; linked, aliased, special, over-count, over-file-size, and over-total-size trees fail before mutation, and rejected operations restore only from the trusted image with fixed path-free errors and no transaction residue."
    },
    {
      "id": "independent-preflight-and-application-postcondition",
      "control": "The MCP parent reconstructs and replays the persisted assurance baseline, validates the child file/mode delta against an explicit write set, derives every effect, count, path, gate transition, readiness status, limitation, next action, reviewed application decision, receipt bundle, and final reviewed envelope from trusted request and run state, and treats child stdout only as a bounded acknowledgement."
    },
    {
      "id": "current-byte-workbook-replay",
      "control": "A regenerated Journal–Bank XLSX must remain a bounded well-formed OOXML package with deterministic core and ZIP timestamps and member order, the exact entry and presentation contract, no duplicate, hidden, extra, traversal, formula, namespace, CRC, or XML content. Every visible worksheet must close cell-for-cell to the canonical CSV schedules, and every declared match or relationship-residual material value is replayed sequentially across the complete prepared, CSV, and read-only XLSX populations without random worksheet access."
    },
    {
      "id": "current-byte-final-artifact-closure",
      "control": "After the audit, review handoff, receipt bundle, and assurance envelope are written, a bounded fixed-point pass refreshes the final artifact manifest and execution trace, requires every listed output path and byte count to match the current files, and validates the current final-artifacts receipt without creating a recursive receipt for the receipt bundle itself."
    },
    {
      "id": "sanitized-helper-and-rollback-failures",
      "control": "Child startup, nonzero exit, oversized, empty, malformed, forged status-zero, preflight divergence, workbook tamper, and rollback failure paths return fixed bounded messages; helper stdout, tracebacks, absolute client paths, recovery paths, and unvalidated child fields are not copied into responses or execution traces."
    },
    {
      "id": "reviewable-blocked-native-package",
      "control": "A source-qualification or relationship-authority block emits no matches or material-value ledger, but still closes the exact reviewable initial package with normalized and unmatched partitions, empty match and residual schedules, a blocked relationship ledger, workbook, per-side source outcomes, audit, review payload, handoff, receipts, assurance envelope and final artifact manifest."
    },
    {
      "id": "reviewed-native-model-selection",
      "control": "An alternative worker model requires a reviewed-decision receipt bound to the workflow, model, effort and benchmark digest. CLI selection files are authorized engagement inputs. This checks a local review declaration, not reviewer authentication or benchmark quality; it never changes native host qualification or read boundaries. The default remains Luna. Configuration and review identity remain bound during replay and recovery."
    },
    {
      "id": "source-execution-with-inert-bytecode-cache",
      "control": "Python entrypoints redirect bytecode lookup and disable bytecode writes before validating and loading the declared source implementation. Cache directories and regular bytecode files are excluded from the source receipt set; they are not treated as executable authority. Optional explicit repair removes only ordinary single-link .pyc files directly inside cache folders under this component own vendor tree, without traversing symlinks or falling back to shared vendor roots. This local maintenance path does not add model calls or external destinations."
    },
    {
      "id": "local-review-output-download",
      "control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
    },
    {
      "id": "current-host-profile-qualification",
      "control": "The fixed source registry includes the reviewed macOS 26A428 / Codex CLI 0.155.0-alpha.16 profile. Production OS sandbox text, disabled tools, read-only CLI arguments and allowed data paths are unchanged. Qualification retains an actual normal launch and positive/negative image controls under a separately documented diagnostic envelope; those diagnostic helper/process permissions are not deployed. Dependency inspection reads this same registry and is not itself launch qualification. Unknown or changed hosts fail closed. No model payload or external destination is added."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-26",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "59b498d5adee0482e0198548eb09f129f5681b3396bc1028968df756a48ed1a6"
  }
}
