← Files VeraARCHIVED FILE

privacy/workstreams/concordato-plan-review.json

9.83 KB · Oct 4, 2026 · 12:28 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "concordato-plan-review",
  "display_name": "Concordato Preventivo Review",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "mcp",
    "assets/review-workbench-adapter.json",
    "assets/concordato-plan-review-widget.html"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "procedure-and-document-evidence",
        "purpose": "Identify the concordato preventivo procedure, governing framework, authoritative proposal, plan, attestation, court material, and document perimeter",
        "content": "User instructions; debtor and procedure identifiers; court and filing details; plan, proposal, attestation, professional and court documents; extracted text; document versions, roles, evidence locators, and reviewer judgment bases",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "creditor-and-treatment-evidence",
        "purpose": "Reconstruct and review the creditor perimeter, priority, classes, voting treatment, recoveries, timing, disputes, and liquidation comparator",
        "content": "Creditor names and identifiers; claim amounts and status; secured, privileged, unsecured, subordinated, tax, and social-security information; classes; vote and treatment data; proposed and liquidation recoveries; payment timing; evidence locators; professional assessments and follow-up",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "plan-economics-and-feasibility-evidence",
        "purpose": "Review sources and uses, liquidity, distributions, milestones, assumptions, consistency, and feasibility evidence",
        "content": "Business-plan and accounting data; assets and disposals; financing and external contributions; procedure costs; cash flows and liquidity; distributions; milestones; assumptions; recalculations; inconsistencies; missing evidence; and reviewer findings",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "professional-review-decisions-codex",
        "purpose": "Record review questions, issues, evidence requests, reviewer decisions, and professional handoff material in Codex or ChatGPT",
        "content": "During substantive analysis: semantic case-model decisions, judgment bases, open and resolved issues, severity and ownership, requested documents, reviewer notes and actions, generated workpapers, summaries, and review memos. After semantic confirmation, reference-bound validate and render expose only run status, total and per-type counts, a small persisted review reference, and the bounded on-demand tool contract to the model; complete review rows, run intake, current decisions, final-artifact state, technical paths, source filenames, sizes, hashes, and artifact references are hydrated locally for the component. A purpose-selected on-demand call may expose at most 25 requested review items with substantive procedure, creditor, treatment, amount, issue, evidence-locator, and reviewer context preserved, while technical metadata is removed and source filenames are replaced with stable aliases. The exact source file remains available when a specific evidence question requires it; the workflow does not reopen the whole case by default.",
        "runtime_profiles": [
          "openai-codex"
        ]
      },
      {
        "id": "professional-review-decisions-cowork",
        "purpose": "Record review questions, issues, evidence requests, reviewer decisions, and professional handoff material in Cowork",
        "content": "During substantive analysis, Cowork may read the same semantic case-model decisions, judgment bases, issues, requested documents, reviewer notes, generated workpapers, summaries, and review memos needed for the professional task. Studio Archive supplies the same portable customer-run context as in Codex. When the packaged MCP interface is callable and used, the same reference-bound component-only result and at-most-25-item on-demand projection apply. If MCP is unavailable in either runtime, the same file-based handoff begins with the delivered semantic review and may open only the exact review or source files needed for an unresolved professional question; the 25-item MCP limit does not apply to that symmetric fallback.",
        "runtime_profiles": [
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [],
  "security_controls": [
    {
      "id": "private-output-root",
      "control": "The review runner requires a digest-valid Studio Archive concordato-plan-review context, accepts case sources and reviewed recipes only from that engagement, and writes only to the context's run output root or a descendant."
    },
    {
      "id": "stable-source-capture",
      "control": "Supported source bytes are captured before parsing and replayed against sealed receipts before review writes."
    },
    {
      "id": "reviewed-semantic-model-boundary",
      "control": "Filename cues remain non-operative; every captured source must receive a reviewer-confirmed semantic document classification, and the complete case model is normalized and bound to current source receipts before semantic reporting gates can pass."
    },
    {
      "id": "assurance-withheld-by-contract",
      "control": "The reviewed case model can authorize semantic schedules and professional reporting artifacts, but legal opinion, plan attestation, reviewer authentication, final professional conclusion, and publication remain separate and explicitly withheld."
    },
    {
      "id": "bounded-trusted-memory-review-transaction",
      "control": "MCP review save and apply capture the bounded canonical output tree and modes in parent-process memory, run helpers only against a detached working tree, reject links, aliases, special or oversized entries, and restore exact trusted bytes and modes on any rejected commit."
    },
    {
      "id": "parent-owned-assurance-authorization",
      "control": "The MCP parent binds caller run, review, current decisions, final state, source-role decisions, and output paths to the persisted trusted snapshot, replays every source, implementation, gate, ledger, review, final, and assurance-envelope receipt, and treats child output only as a bounded acknowledgement before commit."
    },
    {
      "id": "reference-bound-component-only-review-transport",
      "control": "After semantic confirmation, MCP validate, render, save, and apply accept only the customer-run context, an exact persisted review reference, and reviewer decisions where applicable. Complete review and artifact state is rehydrated from the assured local run and placed only in component-visible tool-result metadata; model-visible results contain counts and status. The only detailed MCP model path is an explicit purpose-selected read of at most 25 items, with technical paths, hashes, sizes, and artifact references removed and source filenames replaced by stable aliases. Codex/ChatGPT uses this result-envelope boundary; Cowork uses the same boundary when its optional packaged MCP interface and a compatible customer-run context are callable and selected. Cowork's connected-folder fallback is file-based and is not covered by the 25-item MCP bound."
    },
    {
      "id": "immutable-semantic-and-mutable-presentation-separation",
      "control": "The assurance envelope remains bound to immutable semantic evidence and cannot be overwritten by an item edit. Authorized edits to envelope-bound artifacts create separate revision files, while the regenerable Concordato summary DOCX is treated as a mutable presentation artifact whose current bytes are closed by the final-artifact index and predecessor-linked whole-output successor."
    },
    {
      "id": "exact-implementation-formula-output-and-successor-closure",
      "control": "Assured commands validate the exact 27-file implementation tree before workflow imports; semantic authority is source-bound and independent from the optional numerical source-role and calculation-formula decisions; numerical ledgers close every material appendix address; and save or apply seals an exact physical-output successor bound to the prior closure."
    },
    {
      "id": "source-execution-with-inert-bytecode-cache",
      "control": "Python entrypoints redirect bytecode lookup and disable bytecode writes before validating and loading the declared source implementation. Cache directories and regular bytecode files are excluded from the source receipt set; they are not treated as executable authority. Optional explicit repair removes only ordinary single-link .pyc files directly inside cache folders under this component own vendor tree, without traversing symlinks or falling back to shared vendor roots. This local maintenance path does not add model calls or external destinations."
    },
    {
      "id": "local-review-output-download",
      "control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-28",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "1dc0573f27e1aada98b17b15be8203a69f968eb37ffae2c184b730c8e76d12f7"
  }
}

SHA-256: 3ddbc8a14d7ebe95d292d3aeb2612246c04f9ee49b87c7fbd3d5977331357b7e