← Files VeraARCHIVED FILE
privacy/services/cnc-authenticated-review.json
3.97 KB · Oct 4, 2026 · 12:28 UTC
{
"schema_version": 2,
"service_id": "cnc-authenticated-review",
"display_name": "Authenticated CNC review decisions",
"governed_paths": [
"skills/composizione-negoziata/SKILL.md"
],
"governed_repository_paths": [
"modules/cnc_review/__init__.py",
"modules/cnc_review/api.py",
"templates/vera_cnc_review.html",
"modules/hosted_services/api.py",
"plugins/composizione-negoziata/scripts/cnc_review_client.py",
"plugins/composizione-negoziata/skills/composizione-negoziata/SKILL.md"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"external_boundaries": [
{
"id": "authenticated-professional-review",
"kind": "hosted_service",
"destination": "https://mparanza.com/vera/cnc-review and fixed HTTPS /api/vera/cnc-reviews routes",
"purpose": "Attribute a decision on an exact local version to a signed-in account and enforce case/role ownership",
"content": "Opaque case and node digests, request UUID, exact node version digest, role, decision, authenticated account email, server timestamp and normal connection metadata. The browser displays a locally selected draft; its text, citations and files are not uploaded. Receipt verification sends only its opaque UUID and complete-receipt digest.",
"retention": "Server review metadata and case ownership remain until administrative deletion is requested from Mparanza. Local review files and receipts remain in the studio archive under its retention controls. Deletion prevents later server verification.",
"optional": true,
"requires_confirmation": true,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"The user must choose this hosted route before transmission. The professional personally signs in and confirms; the assistant prepares but never approves.",
"Server session authentication fails closed when disabled; same-origin requests, fixed metadata schema, payload-size and rate limits are enforced. The first authenticated reviewer owns the review scope; other accounts and role changes are rejected.",
"The client uses a fixed HTTPS verification endpoint, rejects redirects, bounds responses and compares the entire retained record and exact local scope/version before authenticating a decision.",
"The local filesystem remains the document-access boundary. Account authentication is not proof of qualification, professional independence, a signature or authority to file.",
"Only the most recently recorded decision for the exact case, node and version can be verified for import; earlier receipts remain historical."
],
"activation": "explicit_user_choice"
}
],
"security_controls": [
{
"id": "explicit-professional-review",
"control": "The routed CNC skill requires the user to choose the hosted route, then the professional personally reviews the exact draft. Ordinary drafting continues without the service.",
"implemented_by": [
"skills/composizione-negoziata/SKILL.md",
"repository:plugins/composizione-negoziata/skills/composizione-negoziata/SKILL.md"
],
"on_violation": "Do not transmit review metadata or claim authenticated approval."
},
{
"id": "account-and-current-decision",
"control": "Signed sessions, same-origin mutation, strict bounded schemas, account ownership and exact current-receipt lookup prevent forged identity and replay of superseded decisions.",
"implemented_by": [
"repository:modules/cnc_review/api.py",
"repository:plugins/composizione-negoziata/scripts/cnc_review_client.py"
],
"on_violation": "Reject the request or receipt; retain the local draft as unapproved."
}
],
"review": {
"reviewed_at": "2026-09-30",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_shared_service_source",
"source_fingerprint": "e25d704c1fd6d22cbf8d75490a1d748973051115e8dd5c514fa8fa42d7c96fcf"
}
}
SHA-256: 8320fea5dd08e13c3335a94a45471501ed2bdd2341b4a74c4993d62ce6faa92e