← Files VeraARCHIVED FILE
privacy/workstreams/sales-plan.json
4.44 KB · Oct 5, 2026 · 18:29 UTC
{
"schema_version": 3,
"workstream": "sales-plan",
"display_name": "Plan",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"mcp"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "sales-plan-assumption-intake",
"purpose": "Interpret and confirm commercial and FX assumptions against reviewed Actuals",
"content": "User instructions and the exact case-selected Actual columns: source row ID, period, reviewed product, customer, country, channel or other dimensions, transaction currency, units when used, gross sales, discounts and COGS when used, and the reporting-currency FX rate; plus period mappings, assumptions, scopes, priorities, overlap behavior, bases and rationale. The strict input contract rejects additional unmapped columns. Relevant Actual rows and member labels may reach the model when needed to establish an exact assumption scope.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
},
{
"id": "sales-plan-post-assumption-review",
"purpose": "Review a complete deterministic Actual-to-Plan calculation without loading every scenario row by default",
"content": "The engine processes every observed in-scope Actual row and writes the complete Actual and Plan scenario. The default model context after calculation contains the assumption ledger, scenario summary, reconciliation and prepared-evidence lineage; missing-metric warnings in reconciliation include the metric name and exact affected source row IDs, and unavailable amounts remain blank rather than becoming partial totals; the model-use manifest does not repeat the original Actual filename. Row-level scenario data is available only through a reason-recorded exact row-ID or column filter with explicitly requested output columns; the helper scans the complete sealed scenario and returns all exact matches without sampling. Vera performs no automatic anonymization or pseudonymization.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [],
"security_controls": [
{
"id": "client-engagement-path-isolation",
"control": "Case preparation and Plan execution require a digest-valid Studio Archive sales-plan context, accept the reviewed case and Actuals only from that engagement, and write only to the context's run output root or a descendant."
},
{
"id": "reviewed-plan-assumptions",
"control": "The Plan engine accepts only a reviewed assumption contract bound to the exact source hash and period mapping. The contract explicitly chooses priority or compound behavior for same-driver overlaps and the basis for discount and COGS assumptions. The engine fails on unmatched scopes, unsupported drivers, ambiguous priority winners, incompatible driver combinations, missing or nonpositive driver metrics, impossible same-currency FX, or stale source evidence."
},
{
"id": "fresh-pinned-plan-output",
"control": "The dispatcher requires a fresh regular output directory, pins its identity, records exact output hashes, parses and hashes the same stable Actual-source bytes, and verifies the case, Actual source, and implementation remain unchanged throughout execution."
},
{
"id": "prepared-plan-boundary",
"control": "The evidence manifest and execution receipt force report_ready=false so a reproducible Plan cannot be presented as professional approval of the assumptions or result."
},
{
"id": "sealed-post-assumption-model-use",
"control": "Every Plan run writes a hash-bound model_use_manifest.json without repeating the original Actual filename. The ledger, summary, reconciliation and lineage are the default model context; the full prepared scenario is excluded by default and can be queried only through exact row IDs or filters and explicit columns. The helper scans every sealed scenario row and returns all exact matches without sampling."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "db79a9912ad9bce693c4c3ef89d63085c3ab6583d0fe5333a0b1f29c36668755"
}
}
SHA-256: 87dd0a2f897140cdea4fc2e1e67fc435c7776ab0b1074cfa044dcdda0fe842f5