← Files VeraARCHIVED FILE

privacy/workstreams/business-planning.json

10.1 KB · Oct 5, 2026 · 18:29 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "business-planning",
  "display_name": "Business Planning",
  "role": "workflow",
  "governed_paths": [
    ".codex-plugin/plugin.json",
    "skills",
    "references",
    "scripts",
    "assets"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance",
    "vendor/modules/reporting_table.py"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "business-planning-intake",
        "purpose": "Understand the business question, market, customers, operations, economics, cash, options and planning assumptions",
        "content": "The selected model may read the assignment and selected evidence, including company, customer, supplier and personal information when relevant, market evidence, operating and financial data, reviewed assumptions, scenarios, audience and open questions. Both products perform the same business analysis. No automatic anonymization is applied. Company stage and evidence meaning are interpreted by the model and professional, not classified by code.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "business-planning-analysis-and-report",
        "purpose": "Prepare one business analysis using the shared financial model and report compiler",
        "content": "Both entry points consume one shared reviewed case and locally run the shared Decimal financial engine. Every selected file is hashed and registered with version, role, review status, audience and confidentiality restrictions. The shared report structure, HTML, JSON and CSV preserve selected file names/relative paths, evidence descriptions, confirmed assumptions and hypotheses, source-figure conflicts and professional decisions, complete calculated figures and IDs, chart lineage, limitations and unresolved matters. This full local audit package is not an automatically bounded model-context projection. The workflow instructs the model to use only the reviewed excerpts, assumptions and calculation records needed for the mandate and allowed for the audience; it does not automatically anonymize content or enforce which local artifacts Codex reads. The compiler itself calls no model or external service. Optional PDF uses a provisioned local Chromium renderer with network requests disabled and only validated HTML. Independent contribution files and legacy cases cannot finalize reports. The model also authors the business recommendation, alternatives, next actions and chart selection. User idea snapshots, provisional interpretations, source-backed external numerical facts and optional commercial price/volume drivers can enter this same context. Pending professional review remains explicit and does not silently discard ordinary interpretation. Supporting workpapers are accessible in a collapsed report appendix; this does not remove them from the HTML file. Explicit presentation data includes report language, source-bound comparison tables, captions, proposed responsible roles and timing, decision criteria, source filenames and versions, page or cell locators, and reference URLs. These fields may enter the selected model context when it authors or reviews the case. URLs are rendered as reader-visible links; the compiler does not fetch them, and PDF rendering blocks network requests. The PDF contains reader-facing source references but hides the technical appendix and expandable workpapers that remain in the HTML. An explicit draft-PDF request can render a partial assessment with a draft label; this does not establish professional approval or remove audience restrictions. Authored comparison groups bind period and scenario labels to existing checked tables. Browser controls only select visibility; all figures and interpretations stay in the report. Shared scales remain fixed across group views. An explicitly requested Sites export retains the same complete HTML and embedded workpapers, and records its exact hash before host-managed publication.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "business-planning-iteration-and-financing",
        "purpose": "Continue the same business case and assess its proposed financing",
        "content": "The selected model may also read the previous registered planning snapshot, the current question, new customer or competitor evidence, changed assumptions, exact input differences, reconsidered conclusions, proposed tests and reopening conditions. Financing assessments may include borrower and existing-debt evidence, proposed lender or investor identity and terms, funding purpose, bank repayment scenarios or equity milestones, cash runway and ownership/return discussion. These are case data, not automatically anonymized. The prior snapshot is hashed and case-bound, and its embedded source restrictions are checked for the new audience. Old case approval cannot silently approve changed inputs. Earlier report folders are preserved; Clara permits revision folders beneath business-plan. The current report contains the cycle and financing reasoning; internal workpapers contain history and exact differences. No lender or investor application is sent by the compiler.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [
    {
      "id": "planning-public-research",
      "kind": "public_research",
      "destination": "Host-provided search services and public market, competitor and financier websites selected for the mandate",
      "purpose": "Investigate pricing, demand, competitor developments and actual financing requirements for the current planning question",
      "content": "Queries based on public product, market and financier facts; public URLs and relevant retrieved pages or excerpts. The skill prohibits private case documents, unpublished forecasts, interview details and personal identifiers in queries. The compiler itself performs no network research.",
      "optional": true,
      "requires_confirmation": true,
      "controls": [
        "A research mandate or explicit route choice is authorization; clarify an optional unchosen route once, not once per query.",
        "Keep research read-only; do not contact customers, competitors, banks or investors or submit applications without explicit authority.",
        "Query selection and compliance with these instructions remain model-led; there is no automatic anonymization or query-content classifier."
      ],
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ]
    },
    {
      "id": "planning-sites-report",
      "kind": "send_or_publish",
      "destination": "OpenAI Sites through the selected host Sites connector",
      "purpose": "Publish the validated financial report for the user-selected audience",
      "content": "On an explicit Sites route, the host uploads the complete validated report HTML and static Site source to OpenAI Sites, including company information, financial figures, all comparison views, assumptions, source names and relative paths, embedded case workpapers and review records. Hidden or collapsed material remains delivered. Original source files are not separately copied into the public output. Sites manages hosting and visitor access. The helper performs no upload and creates no invitation. Sharing and retention depend on the selected Sites account and service; Vera and Clara do not enforce retention or deletion.",
      "optional": true,
      "requires_confirmation": true,
      "controls": [
        "An explicit request to publish through Sites chooses this route; host action-time approval and access checks still apply.",
        "The preparation helper requires a matching report audience, replays the source hashes and report, rejects blocked reports and refuses to overwrite earlier Site candidates.",
        "Only the configured dist output is published. All embedded report data remains included; no automatic anonymization or redaction.",
        "Verify deployment status and intended visitor access. Invitations and messages require authorized recipients; recurring updates require a separate user request."
      ],
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ]
    }
  ],
  "security_controls": [
    {
      "id": "client-engagement-path-isolation",
      "control": "The Vera entry point checks the shared case and every selected source against exact Studio Archive receipts and restricts outputs to that run."
    },
    {
      "id": "source-identity-and-lineage",
      "control": "The shared runner verifies the SHA-256 of every selected file, checks input-reference closure, and replays the complete calculated report before export. Altered calculated values or chart data reject compilation."
    },
    {
      "id": "audience-bound-report-export",
      "control": "Every selected source must allow the report audience in intended_audience and confidentiality.allowed_audiences, or have an explicit reviewed audience-release decision bound to its exact SHA-256. Otherwise the compiler rejects all report-package writes."
    },
    {
      "id": "authoritative-narrative-figures",
      "control": "Calculated financial claims require canonical calculation IDs and exact values. External numerical facts can bind to source-backed evidence IDs with exact values and units. Disagreement blocks readiness, clears accepted narrative in the compiled plan and withholds the assessment in HTML while preserving the submitted case and calculation/source/issue evidence; missing inputs or material reviews/conflicts withhold capital recommendations. Ordinary provisional interpretation remains visible. Numeric literals in narrative are rejected. Semantic classification and conclusions remain model-led and subject to professional review."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-28",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "9c10c0c4ee334c5b74c316924d07d767b35612803db026c1121065dcf2180292"
  }
}

SHA-256: e1555f0896469eb18ede7468f7427f7fffe4554ef23b83ad7ecec5a5b34dc47b