← Files VeraARCHIVED FILE
privacy/workstreams/adeguati-assetti.json
4.41 KB · Oct 5, 2026 · 18:29 UTC
{
"schema_version": 3,
"workstream": "adeguati-assetti",
"display_name": "Assessment of organizational, administrative and accounting arrangements",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"references",
"assets",
"requirements.txt"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "arrangements-evidence",
"purpose": "Assess company arrangements, operating evidence, proportionate findings, actions and prior reviews",
"content": "Selected company descriptions, organization charts, staff roles and delegations, procedures, interview notes, minutes, management/accounting reports, forecasts, operating examples, prior reviews, action evidence and professional decisions. Initial assessment, source review, action planning and subsequent review may read complete relevant files and prior records. There is no fixed excerpt limit or automatic anonymization. Local Python verifies source bindings and hashes and renders records; it does not perform semantic assessment. Targeted questions and attributed answers, conflicting accounts, process/risk/control relationships and event-versus-information chronology may enter the same model context. The model revises hypotheses and writes a management discussion brief; the helper only validates linked records and renders them. Construction can also read original interview Markdown, corrected transcripts supplied by the user, methodology catalog, qualified evidence, numerical explanations, attributed professional overrides, control designs, manuals and registers, company adoption evidence, execution samples, strategy objectives, KPI definitions and observations, and exact linked Business Planning or externally reviewed artifacts. The standalone HTML form makes no network requests, captures no audio and exports drafts only on explicit user action. Returning that draft to Codex or Cowork brings its contents into the selected model context. Local actor labels are attribution and are not authenticated professional identities. No hosted audio adapter or automatic upload is included.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "current-source-research",
"kind": "public_research",
"destination": "Current primary and professional public sources selected for the case",
"purpose": "Verify the current source basis for legal and professional proposals",
"content": "Legal or professional research topics, public-source queries and selected source URLs; direct client identifiers are not used in the public research route",
"optional": false,
"requires_confirmation": false,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"Record retrieval, version, temporal scope, and reuse status for selected sources.",
"Keep credentials, authentication codes, cookies, screening-provider tokens, and direct client identifiers out of public research."
]
}
],
"security_controls": [
{
"id": "archive-binding",
"control": "The CLI requires a running portable v2 adeguati-assetti archive context and checks selected source paths against exact run receipts before reading them."
},
{
"id": "record-integrity",
"control": "Records bind source hashes, prior client and engagement identity, and exact proposal digests for decisions; content-addressed output never overwrites an earlier record."
},
{
"id": "construction-revisions",
"control": "The construction CLI validates exact archive receipts and source bytes, rejects cross-client snapshots, uses transactional compare-and-append revisions and idempotency keys, validates intake identity/version, and binds decisions and manual versions to exact dependencies. Offline HTML escapes case data, uses a no-network CSP and has no automatic upload or microphone access."
}
],
"review": {
"reviewed_at": "2026-09-29",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "9b20d1fc4402a78b616271a3984dcbdd3e01d0c546044ec4a45fe84d6d11a340"
}
}
SHA-256: 05002e7a7659b8269bb26008f07630734e32efc55156e40ee4050af3df08c40a