← Files VeraARCHIVED FILE
privacy/services/local-onboarding.json
10.3 KB · Oct 5, 2026 · 18:29 UTC
{
"schema_version": 2,
"service_id": "local-onboarding",
"display_name": "Local onboarding and repeatable voice-first teaching in native OpenAI desktop sessions",
"governed_paths": [
"scripts/local_onboarding.py",
"scripts/local_onboarding_case.py",
"scripts/onboarding_session_start.py",
"hooks/hooks.json",
"skills/vera/references/local-onboarding.md",
"skills/vera/references/tutorial-cases.md",
"skills/vera/SKILL.md",
"scripts/notarized_run_receipt.py",
"assets/onboarding",
"scripts/local_teaching.py",
"skills/learn-with-vera",
"skills/vera/references/workflow-catalog.md",
"marketplace_skill_instructions.json",
"scripts/local_courses.py",
"assets/courses"
],
"runtime_profiles": [
"openai-codex"
],
"external_boundaries": [
{
"id": "public-version-check",
"kind": "hosted_service",
"destination": "Mparanza's fixed HTTPS plugin-version manifest",
"purpose": "Show published version updates independently of tutorial completion",
"content": "Fixed public GET with ordinary connection metadata; no tutorial, profile, lesson, case, plugin-version or local-path content. Details are governed by plugin-update-check.",
"retention": "Only the downloaded public manifest and check time are cached locally when plugin data storage is available. Hosted access-log retention is outside this helper.",
"activation": "automatic_session_start",
"optional": false,
"requires_confirmation": false,
"runtime_profiles": [
"openai-codex"
],
"controls": [
"Profile, lesson and feedback fields are never arguments to the version checker. CR polling and tutorial receipt stamping remain suppressed."
]
}
],
"security_controls": [
{
"id": "local-state-only",
"control": "The stdlib helper retains a confirmed work/preferences summary, language, thread IDs, lesson evidence hashes and optional feedback only in the OS user local onboarding directory. It stores no audio and implements no network transport or hosted interview. The native OpenAI host sees the conversation and the local summaries/results it reads, under the ordinary OpenAI model-processing boundary. This also applies to local ChatGPT Work; the current register calls that OpenAI account boundary openai-codex, and does not certify cloud access to local files. Repeated teaching reads the same confirmed profile and saves each session separately, with a local example collection derived from those checkpoints. The profile is not copied into a hosted teaching service. A specifically requested first course can create its local session and native chat pair without a profile interview; the profile remains unset, and no introduction or understanding is marked complete. Existing introduction records are preserved. The optional Get started with Vera introduction reuses a single supported course and its separate practice; a short resume note stays beside the lesson outputs. It does not reset or complete the separate multi-course programme or introduce a model API, hosted interview or feedback recipient.",
"implemented_by": [
"scripts/local_onboarding.py",
"skills/vera/references/local-onboarding.md",
"scripts/local_teaching.py",
"skills/learn-with-vera/SKILL.md"
],
"on_violation": "Permission errors, corrupt profiles and missing enrolled records require recovery only to resume the optional tutorial. Ordinary work continues without a profile check, server fallback, automatic reset or manufactured completion."
},
{
"id": "onboarding-transmission-suppression",
"control": "Tutorial profiles, lesson artifacts and feedback remain local. Incomplete, inaccessible or active tutorials suppress CR polling; their receipts suppress stamping, including direct retries. Independently, startup may GET the fixed public version manifest with ordinary connection metadata and no tutorial content, installed version or local path, as recorded under plugin-update-check. It does not require a completed profile. Pause/rebind/resume revoke worker tokens for future bounded steps without claiming to cancel a running host command.",
"implemented_by": [
"scripts/onboarding_session_start.py",
"scripts/notarized_run_receipt.py",
"skills/vera/references/local-onboarding.md"
],
"on_violation": "A tutorial receipt returns not_requested/local_onboarding before request construction; missing state leaves onboarding pending."
},
{
"id": "resumable-evidence-and-concurrency",
"control": "Local exclusive save locks and revision checks prevent concurrent chat overwrites; separate enrollment detects a missing profile; lesson completion requires distinct demo/practice artifacts, replayed hashes and an explicit user-understanding attestation. Work and interests are assessed by the native model. Thread tokens coordinate one active lesson, not host authentication. Repeated demonstrations and guided attempts have separate evidence, stale-result checks and exact native thread tokens. A user-selected real-work handoff binds source hashes and a separate destination, rotates the token and refuses use of the tutorial adapter. Real professional execution retains its selected specialist data boundaries and approvals. Before lesson creation and worker dispatch, exact workflow IDs must belong to Vera's catalog and resolve to a skill inside the same installed Vera root. Worker responses identify that product, root and exact skill path; native teacher/worker instructions prohibit cross-product teaching.",
"implemented_by": [
"scripts/local_onboarding.py",
"scripts/local_teaching.py",
"scripts/local_onboarding_case.py"
],
"on_violation": "Stale writes, wrong lesson handoffs or changed evidence are rejected without marking completion."
},
{
"id": "prepared-course-integrity",
"control": "The local loader supports both new teaching kits and explicitly retained published lessons. It verifies own-product identity, authored language, current source fingerprints and attachment hashes, then renders escaped HTML in a fresh ordinary directory without network or model calls. Both formats enumerate prepared artifact hashes; local progress checks reject those bytes even when copied or renamed. The working host must attest actual input, native-run and output files in the paired lesson. Hash and thread checks do not authenticate a host or prove semantic quality. Rendering performs no profile, understanding or execution-completion write. The static public catalogue contains prepared fictional materials and relative-only provenance, with no local execution requests, profile or progress files. Native OpenAI conversation is ordinary model processing, not offline inference. Browser preview is a separate optional local server: it binds only 127.0.0.1 on a free port, serves the rendered kit and relative assets, rejects resolved paths outside the kit and directory listings, and runs only for the lesson preview. It does not upload files, save access logs, change profiles or record completion. Browser/model inspection remains ordinary native model processing; loopback serving is not authentication against other local processes. XML, Markdown and text inputs have escaped reading views while execution keeps the original bytes. The optional results view checks the live execution record and input/output hashes, then renders selected CSV/text outputs in a fresh directory outside the sealed run. It retains source identities, performs no workflow execution or completion write, and uses only the same loopback preview and native model boundaries. PDF reading views render original pages locally with the already declared PyMuPDF dependency. Page images and an original-file download remain inside the lesson; the original PDF bytes remain the execution inputs. Rendering adds no external route or model call.",
"implemented_by": [
"scripts/local_courses.py",
"skills/learn-with-vera/references/prepared-courses.md"
],
"on_violation": "Reject stale, foreign, altered or unavailable course material without fallback or lesson completion."
},
{
"id": "recorded-input-citation-reading",
"control": "Result Markdown links become local reading-page links only for exact absolute paths or exact output-relative paths of hash-verified Markdown, text, CSV or XML inputs recorded in that execution. Relative aliases are generated solely from that allow-list and the actual output directory; links do not discover or fetch files. Original input bytes are copied with a fresh hash check. Unrecorded paths, network URLs and active schemes remain inert text. Source reading pages escape file content and do not execute Markdown or HTML.",
"implemented_by": [
"scripts/local_courses.py",
"skills/learn-with-vera/references/prepared-courses.md"
],
"on_violation": "Input hash or path mismatch rejects the result view; unrecorded citation targets remain inert text."
},
{
"id": "verified-result-reading",
"control": "Hash-verified Word and workbook files have escaped local text/table reading views; original downloads retain exact bytes. Workbook readers disclose unavailable formula values without calculating invented values. Validated website results retain only the native hash-bound inventory of local HTML, CSS, image and font files and are served under a passive CSP sandbox that blocks scripts, forms, popups and external loads. The teacher may read these selected views in the native model context; no new hosted recipient, model call or automatic approval is introduced.",
"implemented_by": [
"scripts/local_courses.py",
"skills/learn-with-vera/references/prepared-courses.md"
],
"on_violation": "Reject changed or unrecorded files before serving the lesson result."
}
],
"review": {
"reviewed_at": "2026-09-29",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_shared_service_source",
"source_fingerprint": "818fec335cb7ad52233d564139d46aff3c98842cc4ede3f09bc267db0bd498ab"
},
"governed_repository_paths": [
"static/shared/learn-with-vera/index.html",
"static/shared/product-function-pages.js",
"plugins/_shared/vendor/modules/courseware",
"scripts/course_materials",
"static/shared/courses",
"scripts/cowork_teaching"
]
}
SHA-256: c2a8bc64961a17496b8924077282ab3b36912d79e41b4a11173c0703c70e2cc8