← Files VeraARCHIVED FILE

privacy/workstreams/fusione-guidata.json

4.72 KB · Oct 4, 2026 · 12:28 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "fusione-guidata",
  "display_name": "Fusione guidata — P1",
  "role": "workflow",
  "governed_paths": [
    ".codex-plugin/plugin.json",
    "scripts",
    "skills"
  ],
  "governed_repository_paths": [
    "plugins/vera/scripts/model_data_report.py",
    "plugins/studio-archive/scripts/client_ledger.py"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "merger-case-review",
        "purpose": "Review evidenced domestic OIC incorporation workpapers, exact calculations, model-authored dossier sections and scoped professional confirmations.",
        "content": "Company and shareholder identities, legal forms, residence, ownership and rights; selected Studio Archive client and engagement identities, receipt metadata and paths; selected document bytes, locators and hashes; reviewed valuations, balances, exact allocations, accounting policies, fiscal registers, calendar events and assumptions; rule citations, applicability intervals and source errors; draft dossier sections, exact approval content and change impacts. The helper processes complete selected files locally and exports only scopes permitted for the declared actor. No fixed semantic subset or automatic anonymization is promised.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "merger-run-disclosure",
        "purpose": "Describe measured local case processing and its model-exposure limitations.",
        "content": "Scoped current records and accessible immutable history, local item counts, source fingerprints and a readable model-data report. Real-case exports default to not_measurable for model exposure because the local helper cannot inspect the host context. Synthetic demos explicitly contain no client data. The canonical report is built locally with no server receipt request.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [
    {
      "id": "current-source-research",
      "kind": "public_research",
      "destination": "Case-selected official legal and professional public sources",
      "purpose": "Verify current and temporally applicable sources for decisive professional questions",
      "content": "Generic legal and professional research topics and public URLs; no direct client identifiers or confidential plan excerpts in public queries",
      "optional": false,
      "requires_confirmation": false,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Record source rank, dates, inspected scope, applicability and limits.",
        "Keep names, tax identifiers, credentials, private amounts and case text out of public research queries."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "case-and-company-scope",
      "control": "Each dependency checks its exact operation ID, object, version and hash. Reads, imports, writes and reports require the declared actor grant and all inherited company scopes. New cross-case evidence requires an explicit file import. These are logical helper checks, not identity authentication, encryption or OS isolation."
    },
    {
      "id": "explicit-snapshot-import",
      "control": "Only explicitly selected ordinary files within the selected company source roots can be imported; symlink paths and oversized files fail. Preserved document bytes are hash-checked on review and retrieval. Generic put cannot fabricate acquired Evidence or Artifact records."
    },
    {
      "id": "immutable-approval-history",
      "control": "SQLite transactions, expected-version checks and immutable-record triggers preserve revisions. Approval requires a reviewer/administrator grant and an exact unchanged target with no unresolved or stale dependencies. Generic put cannot fabricate Decision records. Confirmations are recorded assertions, not verified signatures."
    },
    {
      "id": "explicit-archive-receipt",
      "control": "Only a company-scoped administrator can bind an existing client and open engagement. Imports verify exact manifest identities and fingerprints, receipt digest and file bytes, and preserve a case-local snapshot. The helper never discovers folders or writes to the source archive. These checks do not authenticate the declared operator."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-30",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "217abc331041ca71b88a70c4e57d7e58746a3a6401132dcbddcfc06eb8ad38bc"
  }
}

SHA-256: 6c7446d825445a14840f17bd7cc688dc426958f4db5818455ccd1416e64e1161