← Files VeraARCHIVED FILE
privacy/workstreams/bilancio-xbrl-it.json
22.4 KB · Oct 5, 2026 · 18:29 UTC
{
"schema_version": 3,
"workstream": "bilancio-xbrl-it",
"display_name": "Bilancio intelligente",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"mcp",
"rulepacks",
"taxonomy",
"requirements.txt",
"requirements-ocr.txt"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "workflow-operations-and-professional-review",
"purpose": "Create and advance the case, collect professional decisions, inspect bounded review surfaces, and identify approved artifacts",
"content": "User instructions and model-assembled MCP arguments may contain the legal name, tax identifier, registered office, period and rule configuration used to create the case; the selected local source path or file name and ingestion options; reviewed mapping allocations and amounts; schedules; disclosure answers; narrative blocks; issue decisions; approval declarations; task selectors; and model metadata. Model-visible responses contain compact case, revision, state, period, form, validation and artifact status. Dedicated mapping and questionnaire reads and the ten requested professional-review views return at most 500 structured records per page with exact offset, total and has-more metadata; depending on the requested view these records can include document metadata and source anchors, PDF rows and OCR evidence, account codes, descriptions, current and prior balances, mapping candidates and decisions, taxonomy concepts, statement facts and totals, schedules, questions and answers, accepted facts, narrative and prior text, validation issues, review decisions, approval metadata and artifact checksums. The workpaper read returns approval and snapshot hashes plus an opaque resource identifier and exported-artifact metadata, never the immutable snapshot body, local storage paths or artifact bytes. Source files and case.json are not automatically copied into model context.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "annual-accounts-evidence",
"purpose": "Review accounting meaning, mapping candidates, missing disclosures, schedule evidence, narrative drafts, validation issues, and professional decisions for an Italian OIC annual-accounts case",
"content": "User instructions; for account mapping, 1 to 50 exact trial-balance rows with account codes, descriptions, current/prior movements and balances, and source references; for pending PDF guidance, at most 20 sample rows, columns, page/table geometry summaries, OCR confidence and extraction issues; for disclosure activation, at most the first 20 accounts by stable case order plus at most 50 exact optional account, canonical-fact or schedule selectors, with value-free catalogues for discovery; direct entity name, tax identifier, registered office, tenant identifier and out-of-band case identifier are excluded from these packets.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "minimum-context-intelligent-participation",
"purpose": "Provide workflow guidance, mapping proposals, question prioritization, narrative drafts, prior-year comparisons, and issue explanations inside the existing bilancio process",
"content": "Task-specific packets: no more than 50 active questions with only matching prior-answer suggestions; one note section with accepted answers and complete schedule facts linked by the versioned disclosure rule pack plus at most 50 exact optional fact, answer, schedule or prior-text selectors; at most 20 prior and 20 current narrative items per comparison packet; at most 20 detailed items from each workflow-guidance collection; or 1 to 20 exact validation issues. Value-free catalogues and paginated review views allow targeted follow-up without making the complete case unreachable. Every packet contains the exact task, selectors, bounds, disclosed/available counts and a SHA-256 context receipt, which is persisted with a recorded model run. Model output remains non-authoritative and evidence-linked and cannot accept, correct, exclude, promote, approve or export case data.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "geneva-adaptation",
"purpose": "Prepare the existing professional deliverable under an explicit CH-GE mandate",
"content": "The CH-GE local accounts adapter may place selected source trial-balance evidence, entity identity, current/prior amounts, account mappings, Swiss framework assessment, note requirements, cited legal sources and professional decisions in the parent runtime context. It is a separate local presentation adapter within the same accounts workflow; it does not use the Italian server, taxonomy, bounded suggestion packets or XBRL approval/export route described below. The selected model may read the exact imported documents needed to author the adapter input. It makes no network or model call itself.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "official-regulatory-and-taxonomy-research",
"kind": "public_research",
"destination": "Official Unioncamere, XBRL Italia, Normattiva, OIC, XBRL International, and Arelle public sources",
"purpose": "Verify effective rules, filing instructions, taxonomy packages, technical standards, processor releases, and licensing metadata",
"content": "Public legal, accounting, filing, taxonomy, and software-version queries; client names, tax identifiers, balances, and case documents are excluded from queries",
"optional": false,
"requires_confirmation": false,
"controls": [
"Use primary official sources and record effective date, retrieval date, and version or checksum where applicable.",
"Keep client identifiers, balances, source extracts, and case documents out of public research queries."
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "manual-tebeni-validation",
"kind": "send_or_publish",
"destination": "User-selected official TEBENI validation and visualization service",
"purpose": "Perform the official external validation and rendering check after local validation",
"content": "The approved XBRL instance selected by the user and the returned validation or rendering report",
"optional": true,
"requires_confirmation": true,
"controls": [
"Vera does not automate an undocumented browser workflow or transmit the instance without the user's explicit route choice.",
"The workflow exports a checksum-bound approved instance for manual upload and treats the returned external report as evidence, not as silent approval."
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "optional-managed-ocr-download",
"kind": "hosted_service",
"destination": "Configured Python package indexes and PaddleOCR public model sources",
"purpose": "Install the optional persistent PaddleOCR runtime and recognition models needed for image-only trial-balance PDFs",
"content": "Public package names, versions, platform metadata, and OCR model identifiers only; client documents, extracted text, entity identifiers, balances, and case metadata are excluded",
"optional": true,
"requires_confirmation": true,
"controls": [
"Ask the exact OCR installation question and proceed only after the user's explicit approval.",
"Install the published shared OCR recipe in the same Vera, Clara and Lucia environment and validate the exact XBRL OCR pins. Stage and verify declared model assets under the shared runtime lock; do not transmit the PDF or case content to package or model sources.",
"Accept exact dependency pins only; record the installed package versions and SHA-256 plus size of every required OCR model file; verify the complete receipt on every reuse; and surface drift, tampering, or installation failure instead of weakening the review gate."
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
],
"security_controls": [
{
"id": "safe-trial-balance-ingestion",
"control": "The deterministic importer accepts only bounded regular CSV, XLSX, or PDF files and rejects symbolic links. CSV/XLSX intake rejects duplicate account identifiers, headers that collide after alias normalization, non-finite or exponent monetary lexicals, ambiguous double signs, and operationally unbounded values; XLSX opens without macros or external-link resolution. PDF intake extracts only page/table/text or OCR geometry into a non-authoritative candidate and retains the source SHA-256."
},
{
"id": "reviewed-pdf-trial-balance-boundary",
"control": "A readable or scanned PDF extraction cannot create canonical entries. It remains PENDING_REVIEW with candidate-hash-bound page methods and table coverage plus page, table, row, source column, bounding box, method, raw value and OCR confidence. Any page still requiring OCR, incompatible table, or unaligned row blocks the whole source; pages without detected tables require exact reviewed non-accounting dispositions. An authenticated professional must accept the exact candidate hash, confirm all four review declarations, supply or confirm a one-to-one accounting-column mapping, and record corrections and exclusions with reasons. A non-account exclusion requires zero or blank selected monetary fields; a non-zero summary exclusion must name accepted account rows and reconcile every monetary field within parser tolerance. Only then may reviewed rows pass through the existing Decimal/parser controls. Bounded model context may explain extraction issues but cannot accept, correct, exclude, or promote rows; parser-convention confirmation remains a separate gate."
},
{
"id": "revision-and-approval-integrity",
"control": "Every mutating command requires the current revision, an approval binds the exact canonical snapshot and input manifest hashes, and a later mutation invalidates and archives that approval before a new revision is created."
},
{
"id": "taxonomy-and-export-integrity",
"control": "The catalogue builder requires the expected official-package SHA-256 and bounded traversal-safe ZIP extraction, distinguishes reportable items from tuples and non-item schema concepts, and preserves tuple and relationship metadata. Export reads the catalogue once, requires the exact catalogue hash approved during local review, re-renders from those captured bytes, requires byte identity with the approved XBRL candidate, emits the exact checksum-verified preview bytes shown to the reviewer, and writes checksums for every artifact. Review and export artifacts are written to a sibling staging directory and published atomically only after completion, so a failed job does not leave a partial destination."
},
{
"id": "offline-local-xbrl-validation",
"control": "Before approval, the current substantive case is rendered through one captured checksum-bound catalogue payload and the pinned Arelle interface runs structural and XBRL 2.1 calculation validation with offline internet connectivity. The candidate must remain byte-identical across validation; candidate, catalogue, package, and report hashes enter the approval snapshot, and substantive changes invalidate that review."
},
{
"id": "safe-prior-xbrl-intake",
"control": "The prior-instance parser accepts only bounded regular local files, rejects symbolic links and document type declarations, disables entity and network resolution, requires one schema reference, validates context periods, unit definitions and XML-decimal monetary values, and checks the entity identifier, comparative period and EUR reconciliation unit before attaching source-anchored facts. Explicit dimensions, canonicalized typed dimensions, tuple ancestry, segment/scenario placement and context-fact groups are retained without executing or remotely resolving supplied XML."
},
{
"id": "tenant-isolated-mapping-memory",
"control": "The mapping-memory store rejects a tenant identifier mismatch and symbolic links, hashes the client key within the tenant, gives client mappings precedence, requires explicit tenant-wide scope, verifies the approved snapshot hash, and stores classifications without historical amounts or source anchors."
},
{
"id": "schedule-evidence-integrity",
"control": "Movement and cash-flow schedules accept only normalized decimal fields with observed or user-confirmed source references; exact opening, closing, maturity, secured-payable, inventory movement, statement, reclassification, and cash-change failures remain blocking instead of being repaired by assumptions. Inventory costing method and valuation basis remain free professional conclusions; net-realisable-value, obsolescence, count evidence, and pledged-stock review fields close only with explicit terminal professional states. The inventory statement line must be backed exclusively by reviewed mappings to the selected form's inventory concepts, while cross-class reclassifications remain possible when the exact movement and opening/closing statement tie-outs reconcile."
},
{
"id": "schedule-taxonomy-adapter-boundary",
"control": "A deployment-controlled checksum-locked rule pack selects the official presentation roots permitted for each form and schedule family. Every normalized schedule cell requires a reviewed exact-concept binding or reasoned omission; monetary values permit only explicit sign multipliers, text facts use one exact source, and role-specific tuple paths allow repeated reviewed rows without flattening their structure. Matching primary facts are reconciled instead of duplicated, and repeated inputs, uncovered cells, all-omitted table routes, contradictory facts and out-of-bound concepts fail closed."
},
{
"id": "bounded-supporting-workbook-intake",
"control": "Trial-balance and schedule XLSX intake rejects path traversal, encrypted ZIP members, macros, external links, suspicious compression, oversized expanded packages, more than 20,000 rows, and formulas without trusted cached values; imported schedule cells retain exact source anchors."
},
{
"id": "authenticated-tenant-and-role-service",
"control": "The writable service derives tenant, actor, roles, and originating interface from the authenticated host environment rather than mutation payloads; tenant-scoped paths, capability checks, time-limited support grants, file locks, revision checks, and idempotency records gate every operation. Source and returned-report reads are confined to a deployment-configured input root; taxonomy paths and MCP/HTTP statutory and disclosure rule packs are deployment configuration rather than request data; explicit studio-admin migration accepts only identifiers resolved from the controlled bundled registry; and review/export destinations reject symbolic links in every existing ancestor component."
},
{
"id": "host-malware-scanner-boundary",
"control": "Conversational and worker ingestion require a host-configured scanner command expressed as a JSON argument array and executed without a shell. Parsing proceeds only after a CLEAN verdict; pre/post-scan size and SHA-256 must remain stable, and the engine, signature version, timestamp, document identifier, size and checksum are persisted as an audited receipt."
},
{
"id": "short-lived-artifact-delivery",
"control": "Only reviewer and read-only-auditor roles may issue idempotent artifact grants. Grants last 30 to 900 seconds, are HMAC-signed by a deployment secret, disclose no storage path, bind tenant, case, file and approved manifest checksum, reject non-canonical Base64URL encodings before signature verification, and require safe-path, size and checksum verification again at redemption; issue and download events are audited."
},
{
"id": "explicit-retention-and-deletion-boundary",
"control": "The service has no implicit retention period. An owner-approved host value from 1 to 3,650 days enables studio-admin archiving while preserving approved artifacts. Purge requires the exact case revision and an elapsed recorded cutoff, removes only the validated tenant/case directory, and leaves a checksum-protected idempotent tombstone with hashes and accountability metadata rather than source content."
},
{
"id": "revision-bound-background-jobs",
"control": "Long-running work may be persisted only as checksum-verified, tenant-scoped jobs created by an already authorized requester. Execution is reserved to the internal SERVICE_WORKER role, retries replay through the mutation idempotency ledger, compact status omits source-bearing payloads, and an intervening case revision makes unapplied work terminally STALE. Taxonomy builds accept no request-selected package, registry, path or entry point. Host semantic invocation receives only a minimum-context packet, runs outside the mutation lock, stores the exact response for retry recovery, and may record only a MODEL_SUGGESTED result."
},
{
"id": "bounded-professional-review-views",
"control": "The review-view service authorizes every tenant-scoped read, caps collection pages at 500 records, returns compact preview and artifact resource identifiers rather than file bytes or arbitrary host paths, and excludes the immutable approval snapshot payload from the approval/export view. Dedicated mapping and questionnaire reads use the same maximum with explicit pagination. The workpaper read verifies the snapshot hash but returns only approval/hash/resource and exported-artifact metadata, not the snapshot body."
},
{
"id": "authenticated-http-adapter",
"control": "The optional HTTP adapter accepts authentication only as a host-injected RequestContext, never from tenant or role request fields. Case creation rejects request-selected statutory rule packs; mutations require an Idempotency-Key and current If-Match revision; stale writes return a conflict; and read routes return structured resources rather than source or artifact bytes."
},
{
"id": "canonical-case-record-integrity",
"control": "Canonical case and idempotency JSON records and their SHA-256 sidecars are written through bounded non-symlink temporary paths and every load verifies the sidecar before parsing. Missing, malformed, mismatched, or symlinked record/checksum pairs fail closed."
},
{
"id": "minimum-context-model-suggestion-boundary",
"control": "Semantic tasks receive the same bounded packet builders in Codex and Cowork. Mapping is capped at 50 exact accounts; disclosure activation starts with 20 accounts and accepts at most 50 exact optional selectors; questions are capped at 50; narrative uses rule-linked accepted evidence plus at most 50 exact selectors; prior-year collections and workflow-guidance collections are capped at 20; and issue explanation accepts at most 20 exact issues. Packets mark document content as untrusted, omit direct entity identity and out-of-band routing identifiers, carry a SHA-256 context receipt and counts, and provide lossless selector or pagination follow-up. Catalogue-only references are not citeable evidence. Strict output schemas and evidence-reference closure keep mapping, narrative, disclosure and workflow outputs MODEL_SUGGESTED until a separate professional decision. Raw case/source fallback is prohibited when packet tooling is unavailable."
},
{
"id": "statutory-presentation-coverage-boundary",
"control": "Selected-form primary-statement requirements come only from checksum-bound official presentation and calculation relationships plus a versioned host-controlled policy. Every absent current or comparative leaf requires an explicit professional zero or not-applicable decision and reason; bounded model guidance may explain gaps but cannot create facts, confirm absence, derive authoritative totals, or make incomplete coverage exportable."
},
{
"id": "manual-external-validation-addendum",
"control": "A user-supplied TEBENI report is accepted only as a bounded local regular file after local validation and approval, checksum-recorded as a non-authoritative external result, and attached without modifying or invalidating the approved accounting snapshot."
},
{
"id": "client-history-minimisation",
"control": "Approved client-history memory is tenant- and client-key scoped and retains only the selected form, accepted answer decisions, accepted narrative text, and recurring rule identifiers; it excludes direct identity, current amounts, and source anchors, and every future suggestion remains unconfirmed or stale until reviewed again."
},
{
"id": "reviewed-taxonomy-fact-boundary",
"control": "Additional text, monetary, dimensional, and nil facts require exportable evidence status and exact source or derivation provenance; model-suggested states cannot be recorded, dimensional QNames are validated, and nil output requires both a professional reason and a catalogue concept that explicitly permits nil."
},
{
"id": "review-and-audit-integrity",
"control": "Structural blockers cannot be overridden; professional overrides are limited to HIGH issues and bind the exact issue fingerprint and reviewer reason. Material audit events record tenant, case, revision, actor, originating interface, and before/after content hashes."
},
{
"id": "geneva-source-binding",
"control": "The Geneva adapter requires a running Studio Archive context and exact imported source hashes, complete one-to-one reviewed mappings and balanced current/prior trial balances. Decisions bind the workflow, client, engagement, exact proposal and arithmetic. Outputs are content-addressed private drafts, never statutory approval or filing-ready artifacts. The Italy-specific authenticated service and XBRL controls do not apply to this local adapter."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "1b0d68b87918b96f4474eb26000f97f508555b01d87a1783fd8f8b33fca154d5"
}
}
SHA-256: bfd3863f53718dc4ff16a8ba2ebca7a99ba4ad3e3945baaf9449a790f99717cc