← Files VeraARCHIVED FILE
modules/bandi-agevolazioni/skills/bandi-agevolazioni/references/product-thesis.md
8.04 KB · Oct 5, 2026 · 18:29 UTC
# Product thesis — intelligent grant execution ## Radar before instruction The workflow supports both opportunity discovery and application instruction. Before a call is selected, Vera maintains a private, reviewable radar: an opaque company opportunity profile, a professionally selected priority-source registry, professionally reviewed query-scoped source selections, source-first temporal scans, time-aware opportunity observations, bidirectional portfolio matches and economic ranges with explicit assumptions. A confirmed match becomes a sealed handoff into the existing client-bound dossier; it never becomes an eligibility decision by itself. This makes the unit of discovery intelligence one source/profile/opportunity proposal, not an autonomous alert. Vera may recommend contacting a client, but does not contact one. Monitoring metadata records intended scans, immutable coverage snapshots and optional publication cursors; it does not claim that an external scheduler or exhaustive official-source feed exists. ## Thesis The professional grant process already exists: select the governing call, reconstruct requirements, collect beneficiary evidence, assess eligibility and exclusions, qualify costs, prepare documents and fields, draft narratives, cross-check the dossier, and review it before an authorized person uses the portal. Vera should not replace that process with a generic AI answer. Vera should make each professional step more intelligent, reviewable, and resumable through bounded Codex contributions attached to exact case state. The unit of intelligence is therefore one task packet, not an autonomous case decision. A packet contains task-allowlisted, reference-closed reviewed context for one semantic job, reports included and omitted class counts and bytes, and labels source material as untrusted content. It never truncates the first arbitrary records: an over-limit closure fails so the model can request an explicit, fresh-session expansion. Exact professional-selected IDs scope only their over-limit collection while the other required collections remain complete, so the expansion is runnable without positional sampling or a semantic relevance classifier. It does not claim automatic anonymization or legal data minimization; the professional must judge which case facts and excerpts are relevant. A strict response can propose guidance or changes, cites only packet evidence, records provider, model, prompt-template version, input hashes, and output, and starts as `MODEL_SUGGESTED`. A professional must explicitly accept, reject, or return it. Acceptance copies valid proposals into the workbench as `proposed`; ordinary professional confirmation remains separate. ## Model-led jobs Use model reasoning for source interpretation, atomic requirement drafting, evidence mapping, eligibility and exclusion reasoning, cost classification, reviewed portal field preparation, narrative drafting, conflict significance, missing information and red flags, adversarial authority simulation, and contextual workflow guidance. These jobs depend on language, context, and professional meaning. The model must expose rationale, evidence references, requested evidence, alternatives, risk flags, and confidence; it may not invent facts or authority. ## Deterministic controls and their justification - Packet bounding, exact output shape, identifier syntax, reference closure, input hashes, and model attribution are deterministic because they are closed technical contracts whose reproducibility is required for privacy and audit. - Task-specific input allowlists and fresh operator-attested session-reference non-reuse are deterministic because permitted artifact families, ID closure, and equality of opaque references are mechanically verifiable. They do not decide semantic relevance, and the session reference is not provider- authenticated identity. - Narrow credential-value patterns are deterministic because passwords, bearer tokens, private keys and live session material have no legitimate grant- analysis purpose. They are not a general personal-data detector and do not remove names, tax identifiers or other professionally relevant facts. - The intelligence-output byte limit is deterministic because the case loader has a closed artifact-size boundary and must fail before writing an artifact that it cannot safely reload; it does not judge semantic relevance. - Task-to-collection permissions are deterministic because they are a security boundary against an otherwise valid response mutating unrelated case state. - Proposal normalization is deterministic because model work must never acquire professional authority through formatting: facts remain model inferences, assessments remain model-led, issues remain open, and all artifacts remain proposed. - Protected field values stay empty under an exact artifact contract. Browser action effects are inspected semantically. Submission requires separate final user approval; project approval permits only draft preparation. - Stale-input detection and two-phase application are deterministic because the same accepted suggestion must bind to the same bytes and recover without duplicate or partial application. - Automatic next-task selection uses only mechanically observable completeness and review states. It does not infer legal importance, applicability, source authority, or eligibility. - Radar coverage divides review-confirmed checks by applicable, professionally confirmed plan entries because those counts are closed, reproducible execution facts. Proposed, returned and rejected entries are disclosed and excluded. It does not estimate the probability of finding all grants. - Source-first phasing, exact query-dimension claim closure, query-scoped source reference closure, exact temporal-window containment, selected-source registry hash binding, cursor preservation and the scan completion gate are deterministic because their correctness follows from a closed execution and audit contract. Model reasoning proposes which sources cover every category and territory; professional review confirms that semantic selection and still interprets every publication. - Lifecycle preservation and radar reference closure are deterministic because auditability requires confirmed history and opaque client boundaries not to be silently rewritten or crossed. - Studio-workspace path binding, same-client profile-evidence closure, review freshness, and recomputable handoff hashes are deterministic because they are security and audit contracts; they never decide source meaning or eligibility. - Economic net ranges use exact subtraction because every benefit, cost and assumption is supplied semantically while the arithmetic must reproduce. The code does not infer award probability, eligible spend, fees, effort or value. - Exact decimal and ISO-date comparisons remain the only semantic-adjacent rule families, for the bounded reasons in `workflow-method.md`. ## Professional boundary The professional owns source authority, interpretation, applicability, eligibility and exclusion conclusions, cost admissibility, factual acceptance, narrative claims, issue resolution, and dossier disposition. The authorized person additionally owns portal authentication, declarations, signature, and payment. Approved preparation and explicitly authorized final submission follow `portal-preparation.md`. Vera never represents a suggestion, simulation, accepted contribution, or dossier as an authority decision or as ready to file. ## Evaluation thesis Offline tests can prove packet minimization, output strictness, reference closure, non-authoritative state, stale detection, idempotent application, protected-control enforcement, and packaging traceability. They cannot prove legal accuracy. Semantic release evidence requires a separately governed set of licensed or synthetic representative calls reviewed by qualified professionals, with requirement/source precision, missed-material-requirement rate, unsupported claim rate, cost-classification agreement, red-flag recall, and reviewer override patterns reported by task and call family.
SHA-256: 6079d82565bb516f232ad1010d25a6e1af3ec84677470ed9ff5348cc7d7f1696