← Files ClaraARCHIVED FILE

privacy/workflows/business-planning.json

15.2 KB · Oct 6, 2026 · 06:02 UTC

↓ Download file

{
  "schema_version": 1,
  "workflow": "business-planning",
  "display_name": "Business Planning",
  "governed_paths": [
    "components.json",
    "skills/business-planning/SKILL.md",
    "repository/plugins/business-planning/.codex-plugin/plugin.json",
    "repository/plugins/business-planning/skills/business-planning/SKILL.md",
    "repository/plugins/business-planning/references/case-contract.md",
    "repository/plugins/business-planning/scripts/run_strategic_plan.py",
    "repository/plugins/business-planning/scripts/planning_cli.py",
    "repository/plugins/business-planning/scripts/planning_workflow.py",
    "repository/plugins/business-planning/scripts/planning_report.py",
    "repository/plugins/business-planning/scripts/business_planning_core.py",
    "repository/plugins/business-planning/scripts/strategic_planning_core.py",
    "repository/plugins/business-planning/scripts/check_dependencies.py",
    "repository/plugins/business-planning/requirements-pdf.txt",
    "repository/plugins/business-planning/scripts/planning_assessment.py",
    "repository/plugins/business-planning/scripts/planning_commercial.py",
    "repository/plugins/business-planning/scripts/planning_cycle.py",
    "repository/plugins/business-planning/scripts/planning_financing.py",
    "repository/plugins/business-planning/scripts/planning_decision_report.py",
    "repository/plugins/business-planning/scripts/planning_presentation.py",
    "repository/plugins/business-planning/references/financing-assessment.md",
    "repository/plugins/_shared/vendor/modules/reporting_table.py",
    "repository/plugins/business-planning/scripts/planning_interaction.py",
    "repository/plugins/business-planning/scripts/planning_site.py",
    "repository/plugins/business-planning/scripts/prepare_report_site.py",
    "repository/plugins/business-planning/assets/report-interaction.js",
    "repository/plugins/business-planning/assets/report-interaction.css",
    "repository/plugins/business-planning/references/sites-delivery.md",
    "scripts/self_relaunch.py",
    "scripts/managed_python_runtime.py",
    "scripts/_managed_python_runtime.py",
    "requirements.txt",
    "repository/plugins/business-planning/scripts/planning_french.py",
    "repository/plugins/business-planning/skills/business-planning/references/geneva.md"
  ],
  "codex_context": {
    "policy": "real_professional_data_may_enter_codex_context",
    "classes": [
      {
        "id": "business-planning-intake",
        "purpose": "Understand the business question, market, customers, operations, economics, cash, options and planning assumptions",
        "content": "The selected model may read the assignment and selected evidence, including company, customer, supplier and personal information when relevant, market evidence, operating and financial data, reviewed assumptions, scenarios, audience and open questions. Both products perform the same business analysis. No automatic anonymization is applied. Company stage and evidence meaning are interpreted by the model and professional, not classified by code."
      },
      {
        "id": "business-planning-analysis-and-report",
        "purpose": "Prepare one business analysis using the shared financial model and report compiler",
        "content": "Both entry points consume one shared reviewed case and locally run the shared Decimal financial engine. Every selected file is hashed and registered with version, role, review status, audience and confidentiality restrictions. The shared report structure, HTML, JSON and CSV preserve selected file names/relative paths, evidence descriptions, confirmed assumptions and hypotheses, source-figure conflicts and professional decisions, complete calculated figures and IDs, chart lineage, limitations and unresolved matters. This full local audit package is not an automatically bounded model-context projection. The workflow instructs the model to use only the reviewed excerpts, assumptions and calculation records needed for the mandate and allowed for the audience; it does not automatically anonymize content or enforce which local artifacts Codex reads. The compiler itself calls no model or external service. Optional PDF uses a provisioned local Chromium renderer with network requests disabled and only validated HTML. Independent contribution files and legacy cases cannot finalize reports. The model also authors the business recommendation, alternatives, next actions and chart selection. User idea snapshots, provisional interpretations, source-backed external numerical facts and optional commercial price/volume drivers can enter this same context. Pending professional review remains explicit and does not silently discard ordinary interpretation. Supporting workpapers are accessible in a collapsed report appendix; this does not remove them from the HTML file. Explicit presentation data includes report language, source-bound comparison tables, captions, proposed responsible roles and timing, decision criteria, source filenames and versions, page or cell locators, and reference URLs. These fields may enter the selected model context when it authors or reviews the case. URLs are rendered as reader-visible links; the compiler does not fetch them, and PDF rendering blocks network requests. The PDF contains reader-facing source references but hides the technical appendix and expandable workpapers that remain in the HTML. An explicit draft-PDF request can render a partial assessment with a draft label; this does not establish professional approval or remove audience restrictions. Authored comparison groups bind period and scenario labels to existing checked tables. Browser controls only select visibility; all figures and interpretations stay in the report. Shared scales remain fixed across group views. An explicitly requested Sites export retains the same complete HTML and embedded workpapers, and records its exact hash before host-managed publication. Missing inputs in one scenario do not suppress independently complete scenarios; unavailable scenario calculations and dependent claims remain explicit in the report."
      },
      {
        "id": "business-planning-iteration-and-financing",
        "purpose": "Continue the same business case and assess its proposed financing",
        "content": "The selected model may also read the previous registered planning snapshot, the current question, new customer or competitor evidence, changed assumptions, exact input differences, reconsidered conclusions, proposed tests and reopening conditions. Financing assessments may include borrower and existing-debt evidence, proposed lender or investor identity and terms, funding purpose, bank repayment scenarios or equity milestones, cash runway and ownership/return discussion. These are case data, not automatically anonymized. The prior snapshot is hashed and case-bound, and its embedded source restrictions are checked for the new audience. Old case approval cannot silently approve changed inputs. Earlier report folders are preserved; Clara permits revision folders beneath business-plan. The current report contains the cycle and financing reasoning; internal workpapers contain history and exact differences. No lender or investor application is sent by the compiler."
      },
      {
        "id": "review-attestations-and-local-retention",
        "purpose": "Assess the provenance and limits of source release and professional review records",
        "content": "Declared reviewer identities, timezone-aware review timestamps, rationale, audience-release decisions and exact source hashes can enter model context and are retained in the local case/report package. These are operator-supplied assertions, not authenticated proof of the reviewer or semantic correctness. The compiler does not automatically delete the case, HTML, JSON, CSV or completed PDF. On a caught PDF failure it removes the incomplete PDF while retaining validated non-PDF outputs and an error receipt. Collapsing HTML appendices or hiding them in print does not redact their contents from the HTML."
      },
      {
        "id": "blocked-assessment-retention",
        "purpose": "Explain a blocked plan without presenting rejected interpretation as a conclusion",
        "content": "When calculation contradictions block the plan, submitted narrative and assessment remain in the case record for diagnosis, while accepted narrative is empty and the report withholds the assessment conclusion. Retained source/case contents can still enter Codex context when read; report suppression is not deletion or anonymisation."
      }
    ]
  },
  "ordinary_codex_model_processing": {
    "scope": "content_supplied_to_the_codex_model",
    "account_arrangement": "user_selected_chatgpt_or_codex_account",
    "separate_clara_recipient_or_arrangement": false,
    "automatic_anonymisation": false,
    "local_filter_or_aggregate": "only_when_useful_for_professional_work",
    "plan_visibility": "not_inspected_or_enforced_by_clara"
  },
  "codex_account_boundary": {
    "selected_by": "firm_or_user",
    "clara_runtime_enforcement": "none",
    "review_timing": "before_professional_use_and_when_account_or_terms_change",
    "review_items": [
      "account_or_workspace_plan",
      "model_training_data_controls",
      "retention_and_deletion_controls"
    ],
    "per_case_record_required": false
  },
  "hosted_service_ids": [],
  "boundaries_beyond_codex": [
    {
      "id": "planning-public-research",
      "kind": "public_research",
      "destination": "Host-provided search services and public market, competitor and financier websites selected for the mandate",
      "purpose": "Investigate pricing, demand, competitor developments and actual financing requirements for the current planning question",
      "content": "Queries based on public product, market and financier facts; public URLs and relevant retrieved pages or excerpts. The skill prohibits private case documents, unpublished forecasts, interview details and personal identifiers in queries. The compiler itself performs no network research.",
      "optional": true,
      "requires_confirmation": true,
      "controls": [
        "A research mandate or explicit route choice is authorization; clarify an optional unchosen route once, not once per query.",
        "Keep research read-only; do not contact customers, competitors, banks or investors or submit applications without explicit authority.",
        "Query selection and compliance with these instructions remain model-led; there is no automatic anonymization or query-content classifier."
      ]
    },
    {
      "id": "planning-sites-report",
      "kind": "send_or_publish",
      "destination": "OpenAI Sites through the selected host Sites connector",
      "purpose": "Publish the validated financial report for the user-selected audience",
      "content": "On an explicit Sites route, the host uploads the complete validated report HTML and static Site source to OpenAI Sites, including company information, financial figures, all comparison views, assumptions, source names and relative paths, embedded case workpapers and review records. Hidden or collapsed material remains delivered. Original source files are not separately copied into the public output. Sites manages hosting and visitor access. The helper performs no upload and creates no invitation. Sharing and retention depend on the selected Sites account and service; Vera and Clara do not enforce retention or deletion.",
      "optional": true,
      "requires_confirmation": true,
      "controls": [
        "An explicit request to publish through Sites chooses this route; host action-time approval and access checks still apply.",
        "The preparation helper requires a matching report audience, replays the source hashes and report, rejects blocked reports and refuses to overwrite earlier Site candidates.",
        "Only the configured dist output is published. All embedded report data remains included; no automatic anonymization or redaction.",
        "Verify deployment status and intended visitor access. Invitations and messages require authorized recipients; recurring updates require a separate user request."
      ]
    },
    {
      "id": "direct-cli-python-dependency-setup",
      "kind": "public_research",
      "destination": "Python Package Index (PyPI) or the index selected by the user's Python configuration",
      "purpose": "Prepare the declared Python dependencies before running a documented workflow CLI",
      "content": "Published package requirements and ordinary package-index request metadata. Existing workflow arguments are forwarded to a local Python child; they are not included in the pip install command.",
      "optional": false,
      "requires_confirmation": false,
      "controls": [
        "The direct CLI selects published core or registered component requirements before importing workflow modules.",
        "The launcher preserves the working directory and arguments in the local child process; this does not redact arguments or change the workflow data boundary.",
        "An existing matching runtime is reused. Setup installs into a fingerprinted user-scoped environment and propagates failure; it does not install into the case folder."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "clara-case-workspace-isolation",
      "control": "The Clara entry point accepts the case only from the selected workspace root, all selected sources inside that workspace, and outputs only in its business-plan directory."
    },
    {
      "id": "source-identity-and-lineage",
      "control": "The shared runner verifies the SHA-256 of every selected file, checks input-reference closure, and replays the complete calculated report before export. Altered calculated values or chart data reject compilation."
    },
    {
      "id": "audience-bound-report-export",
      "control": "Every selected source must allow the report audience in intended_audience and confidentiality.allowed_audiences, or have an explicit reviewed audience-release decision bound to its exact SHA-256. Otherwise the compiler rejects all report-package writes. This enforces the declared source restrictions; it does not authenticate the named reviewer or establish that a release was actually authorized."
    },
    {
      "id": "authoritative-narrative-figures",
      "control": "Calculated financial claims require canonical calculation IDs and exact values. External numerical facts can bind to source-backed evidence IDs with exact values and units. Disagreement blocks readiness; missing inputs or material reviews/conflicts withhold capital recommendations. Ordinary provisional interpretation remains visible. Numeric literals in narrative are rejected. Semantic classification and conclusions remain model-led and subject to professional review."
    },
    {
      "id": "pdf-network-interception",
      "control": "The optional local Chromium PDF renderer installs a request-abort route before loading the validated generated HTML. Reference URLs remain links; the compiler does not fetch them. This control is limited to that rendering page and does not restrict independent host browsing or connectors."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-15",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "fc38b8bc896e9590850360e79e8c2fa715b2051f6f7061aa756f93c006812497"
  }
}

SHA-256: 8567d0b5ce653b47fdbb87f7a230a2d1cbe0b1979ce3b1ae1eacee8461c8c1b2