← Files VeraARCHIVED FILE

modules/bandi-agevolazioni/skills/bandi-agevolazioni/references/product-thesis.md

8.04 KB · Oct 5, 2026 · 18:29 UTC

↓ Download file

# Product thesis — intelligent grant execution

## Radar before instruction

The workflow supports both opportunity discovery and application instruction.
Before a call is selected, Vera maintains a private, reviewable radar: an opaque
company opportunity profile, a professionally selected priority-source
registry, professionally reviewed query-scoped source selections, source-first
temporal scans, time-aware opportunity observations,
bidirectional portfolio matches and economic ranges with explicit assumptions.
A confirmed match becomes a sealed
handoff into the existing client-bound dossier; it never becomes an eligibility
decision by itself.

This makes the unit of discovery intelligence one source/profile/opportunity
proposal, not an autonomous alert. Vera may recommend contacting a client, but
does not contact one. Monitoring metadata records intended scans, immutable
coverage snapshots and optional publication cursors; it does not claim that an
external scheduler or exhaustive official-source feed exists.

## Thesis

The professional grant process already exists: select the governing call,
reconstruct requirements, collect beneficiary evidence, assess eligibility and
exclusions, qualify costs, prepare documents and fields, draft narratives,
cross-check the dossier, and review it before an authorized person uses the
portal. Vera should not replace that process with a generic AI answer. Vera
should make each professional step more intelligent, reviewable, and resumable
through bounded Codex contributions attached to exact case state.

The unit of intelligence is therefore one task packet, not an autonomous case
decision. A packet contains task-allowlisted, reference-closed reviewed context
for one semantic job, reports included and omitted class counts and bytes, and
labels source material as untrusted content. It never truncates the first
arbitrary records: an over-limit closure fails so the model can request an
explicit, fresh-session expansion. Exact professional-selected IDs scope only
their over-limit collection while the other required collections remain
complete, so the expansion is runnable without positional sampling or a
semantic relevance classifier. It does not claim
automatic anonymization or legal data minimization; the professional must judge
which case facts and excerpts are relevant. A strict response
can propose guidance or changes, cites only packet evidence, records provider,
model, prompt-template version, input hashes, and output, and starts as
`MODEL_SUGGESTED`. A professional must explicitly accept, reject, or return it.
Acceptance copies valid proposals into the workbench as `proposed`; ordinary
professional confirmation remains separate.

## Model-led jobs

Use model reasoning for source interpretation, atomic requirement drafting,
evidence mapping, eligibility and exclusion reasoning, cost classification,
reviewed portal field preparation, narrative drafting, conflict significance, missing
information and red flags, adversarial authority simulation, and contextual
workflow guidance. These jobs depend on language, context, and professional
meaning. The model must expose rationale, evidence references, requested
evidence, alternatives, risk flags, and confidence; it may not invent facts or
authority.

## Deterministic controls and their justification

- Packet bounding, exact output shape, identifier syntax, reference closure,
  input hashes, and model attribution are deterministic because they are closed
  technical contracts whose reproducibility is required for privacy and audit.
- Task-specific input allowlists and fresh operator-attested session-reference
  non-reuse are deterministic because permitted artifact families, ID closure,
  and equality of opaque references are mechanically verifiable. They do not
  decide semantic relevance, and the session reference is not provider-
  authenticated identity.
- Narrow credential-value patterns are deterministic because passwords, bearer
  tokens, private keys and live session material have no legitimate grant-
  analysis purpose. They are not a general personal-data detector and do not
  remove names, tax identifiers or other professionally relevant facts.
- The intelligence-output byte limit is deterministic because the case loader
  has a closed artifact-size boundary and must fail before writing an artifact
  that it cannot safely reload; it does not judge semantic relevance.
- Task-to-collection permissions are deterministic because they are a security
  boundary against an otherwise valid response mutating unrelated case state.
- Proposal normalization is deterministic because model work must never acquire
  professional authority through formatting: facts remain model inferences,
  assessments remain model-led, issues remain open, and all artifacts remain
  proposed.
- Protected field values stay empty under an exact artifact contract. Browser
  action effects are inspected semantically. Submission requires separate
  final user approval; project approval permits only draft preparation.
- Stale-input detection and two-phase application are deterministic because the
  same accepted suggestion must bind to the same bytes and recover without
  duplicate or partial application.
- Automatic next-task selection uses only mechanically observable completeness
  and review states. It does not infer legal importance, applicability, source
  authority, or eligibility.
- Radar coverage divides review-confirmed checks by applicable, professionally
  confirmed plan entries because those counts are closed, reproducible
  execution facts. Proposed, returned and rejected entries are disclosed and
  excluded. It does not estimate the probability of finding all grants.
- Source-first phasing, exact query-dimension claim closure, query-scoped source
  reference closure, exact temporal-window containment, selected-source registry
  hash binding, cursor preservation and the scan completion gate are
  deterministic because their correctness follows from a closed execution and
  audit contract. Model reasoning proposes which sources cover every category
  and territory; professional review confirms that semantic selection and still
  interprets every publication.
- Lifecycle preservation and radar reference closure are deterministic because
  auditability requires confirmed history and opaque client boundaries not to
  be silently rewritten or crossed.
- Studio-workspace path binding, same-client profile-evidence closure, review
  freshness, and recomputable handoff hashes are deterministic because they are
  security and audit contracts; they never decide source meaning or eligibility.
- Economic net ranges use exact subtraction because every benefit, cost and
  assumption is supplied semantically while the arithmetic must reproduce. The
  code does not infer award probability, eligible spend, fees, effort or value.
- Exact decimal and ISO-date comparisons remain the only semantic-adjacent rule
  families, for the bounded reasons in `workflow-method.md`.

## Professional boundary

The professional owns source authority, interpretation, applicability,
eligibility and exclusion conclusions, cost admissibility, factual acceptance,
narrative claims, issue resolution, and dossier disposition. The authorized
person additionally owns portal authentication, declarations, signature,
and payment. Approved preparation and explicitly authorized final submission follow `portal-preparation.md`. Vera never represents a suggestion,
simulation, accepted contribution, or dossier as an authority decision or as
ready to file.

## Evaluation thesis

Offline tests can prove packet minimization, output strictness, reference
closure, non-authoritative state, stale detection, idempotent application,
protected-control enforcement, and packaging traceability. They cannot prove
legal accuracy. Semantic release evidence requires a separately governed set of
licensed or synthetic representative calls reviewed by qualified professionals,
with requirement/source precision, missed-material-requirement rate, unsupported
claim rate, cost-classification agreement, red-flag recall, and reviewer
override patterns reported by task and call family.

SHA-256: 6079d82565bb516f232ad1010d25a6e1af3ec84677470ed9ff5348cc7d7f1696