Task 14.1 inventory dated 2026-09-15. It covers 12 source-verified planes × 9 modalities = 108 explicit cells, with 45 flows and 63 fail-closed non-flows.
“FLOW” means payload or a stated minimized projection crosses the plane. It does not mean every downstream privacy control is complete. Each JSON flow cell carries the full required fields and all six destination dispositions.
| Plane | text |
structured-record |
document-pdf |
image-screenshot |
audio |
video |
code |
three-d-scene |
telemetry-evidence |
|---|---|---|---|---|---|---|---|---|---|
session-http |
FLOW | FLOW | — | — | — | — | — | — | FLOW |
operator-http |
FLOW | FLOW | — | — | — | — | — | — | FLOW |
prompt-assembly |
FLOW | FLOW | FLOW | — | — | — | FLOW | — | FLOW |
member-domain-tools |
FLOW | FLOW | — | — | — | — | — | — | — |
client-tool-bridge |
FLOW | FLOW | — | FLOW | — | — | — | — | — |
retrieval |
FLOW | FLOW | FLOW | — | — | — | — | — | — |
operator-tools |
FLOW | FLOW | — | — | — | — | — | — | FLOW |
memory-and-session |
FLOW | FLOW | — | — | — | — | — | — | — |
workbench-intent |
FLOW | FLOW | FLOW | FLOW | FLOW | FLOW | FLOW | FLOW | FLOW |
model-provider |
FLOW | FLOW | FLOW | FLOW | FLOW | — | FLOW | — | FLOW |
voice |
FLOW | — | — | — | FLOW | — | — | — | — |
audit-and-evidence |
FLOW | FLOW | — | — | — | — | — | — | FLOW |
Open requirements exposed by the inventory#
| Cell | Field | Owner task | Exact condition |
|---|---|---|---|
audit-and-evidence/structured-record |
deletion |
14.4 |
Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained. |
audit-and-evidence/structured-record |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer. |
audit-and-evidence/structured-record |
retention |
14.5 |
Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5. |
audit-and-evidence/telemetry-evidence |
deletion |
14.4 |
Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained. |
audit-and-evidence/telemetry-evidence |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer. |
audit-and-evidence/telemetry-evidence |
retention |
14.5 |
Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5. |
audit-and-evidence/text |
deletion |
14.4 |
Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained. |
audit-and-evidence/text |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer. |
audit-and-evidence/text |
retention |
14.5 |
Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5. |
client-tool-bridge/image-screenshot |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer. |
client-tool-bridge/structured-record |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer. |
client-tool-bridge/text |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer. |
member-domain-tools/structured-record |
deletion |
14.4 |
Covered V1 subject stores join deletion fanout; total domain and artifact propagation is Task 14.4. |
member-domain-tools/structured-record |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for member-domain-tools must be admitted before transfer. |
member-domain-tools/structured-record |
retention |
14.5 |
Retention belongs to each domain store and is not yet joined into one enforceable policy. |
member-domain-tools/text |
deletion |
14.4 |
Covered V1 subject stores join deletion fanout; total domain and artifact propagation is Task 14.4. |
member-domain-tools/text |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for member-domain-tools must be admitted before transfer. |
member-domain-tools/text |
retention |
14.5 |
Retention belongs to each domain store and is not yet joined into one enforceable policy. |
memory-and-session/structured-record |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for memory-and-session must be admitted before transfer. |
memory-and-session/structured-record |
retention |
14.5 |
Expiry/salience metadata exists for operator memory; a total operator-visible retention policy remains Task 14.5. |
memory-and-session/text |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for memory-and-session must be admitted before transfer. |
memory-and-session/text |
retention |
14.5 |
Expiry/salience metadata exists for operator memory; a total operator-visible retention policy remains Task 14.5. |
model-provider/audio |
deletion |
14.4 |
No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation. |
model-provider/audio |
destination:storage |
14.2 |
Establish provider-side storage and buffering for every model leg carrying audio. |
model-provider/audio |
modelLeg:speech-to-text |
14.2 |
The speech-to-text leg has no independently verified provider storage, retention, training, residency, or subprocessor record. |
model-provider/audio |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
model-provider/audio |
retention |
14.5 |
Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2. |
model-provider/code |
deletion |
14.4 |
No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation. |
model-provider/code |
destination:storage |
14.2 |
Establish provider-side storage and buffering for every model leg carrying code. |
model-provider/code |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
model-provider/code |
retention |
14.5 |
Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2. |
model-provider/document-pdf |
deletion |
14.4 |
No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation. |
model-provider/document-pdf |
destination:storage |
14.2 |
Establish provider-side storage and buffering for every model leg carrying document-pdf. |
model-provider/document-pdf |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
model-provider/document-pdf |
retention |
14.5 |
Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2. |
model-provider/image-screenshot |
deletion |
14.4 |
No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation. |
model-provider/image-screenshot |
destination:storage |
14.2 |
Establish provider-side storage and buffering for every model leg carrying image-screenshot. |
model-provider/image-screenshot |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
model-provider/image-screenshot |
retention |
14.5 |
Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2. |
model-provider/structured-record |
deletion |
14.4 |
No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation. |
model-provider/structured-record |
destination:storage |
14.2 |
Establish provider-side storage and buffering for every model leg carrying structured-record. |
model-provider/structured-record |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
model-provider/structured-record |
retention |
14.5 |
Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2. |
model-provider/telemetry-evidence |
deletion |
14.4 |
No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation. |
model-provider/telemetry-evidence |
destination:storage |
14.2 |
Establish provider-side storage and buffering for every model leg carrying telemetry-evidence. |
model-provider/telemetry-evidence |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
model-provider/telemetry-evidence |
retention |
14.5 |
Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2. |
model-provider/text |
deletion |
14.4 |
No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation. |
model-provider/text |
destination:storage |
14.2 |
Establish provider-side storage and buffering for every model leg carrying text. |
model-provider/text |
modelLeg:computer-use-planning |
14.2 |
The computer-use-planning leg has no independently verified provider storage, retention, training, residency, or subprocessor record. |
model-provider/text |
modelLeg:embedding |
14.2 |
The embedding leg has no independently verified provider storage, retention, training, residency, or subprocessor record. |
model-provider/text |
modelLeg:escalation |
14.2 |
The escalation leg has no independently verified provider storage, retention, training, residency, or subprocessor record. |
model-provider/text |
modelLeg:judge |
14.2 |
The judge leg has no independently verified provider storage, retention, training, residency, or subprocessor record. |
model-provider/text |
modelLeg:text-to-speech |
14.2 |
The text-to-speech leg has no independently verified provider storage, retention, training, residency, or subprocessor record. |
model-provider/text |
modelLeg:turn |
14.2 |
The turn leg has no independently verified provider storage, retention, training, residency, or subprocessor record. |
model-provider/text |
modelLeg:vision |
14.2 |
The vision leg has no independently verified provider storage, retention, training, residency, or subprocessor record. |
model-provider/text |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
model-provider/text |
retention |
14.5 |
Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2. |
model-provider/text |
upstreamSource:apps/oshun/bff/src/assistant/model-registry.ts |
15.1 |
Refresh the model-leg contract's nested binding for apps/oshun/bff/src/assistant/model-registry.ts before using it as current source proof. |
operator-http/structured-record |
deletion |
14.4 |
Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work. |
operator-http/structured-record |
retention |
14.5 |
The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions. |
operator-http/telemetry-evidence |
deletion |
14.4 |
Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work. |
operator-http/telemetry-evidence |
retention |
14.5 |
The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions. |
operator-http/text |
deletion |
14.4 |
Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work. |
operator-http/text |
retention |
14.5 |
The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions. |
operator-tools/structured-record |
deletion |
14.4 |
Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4. |
operator-tools/structured-record |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer. |
operator-tools/structured-record |
retention |
14.5 |
Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable. |
operator-tools/telemetry-evidence |
deletion |
14.4 |
Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4. |
operator-tools/telemetry-evidence |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer. |
operator-tools/telemetry-evidence |
retention |
14.5 |
Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable. |
operator-tools/text |
deletion |
14.4 |
Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4. |
operator-tools/text |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer. |
operator-tools/text |
retention |
14.5 |
Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable. |
prompt-assembly/code |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer. |
prompt-assembly/document-pdf |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer. |
prompt-assembly/structured-record |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer. |
prompt-assembly/telemetry-evidence |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer. |
prompt-assembly/text |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer. |
retrieval/document-pdf |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer. |
retrieval/structured-record |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer. |
retrieval/text |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer. |
session-http/structured-record |
retention |
14.5 |
No duration is enforced at this plane; Task 14.5 owns the policy. |
session-http/telemetry-evidence |
retention |
14.5 |
No duration is enforced at this plane; Task 14.5 owns the policy. |
session-http/text |
retention |
14.5 |
No duration is enforced at this plane; Task 14.5 owns the policy. |
voice/audio |
deletion |
14.4 |
No durable local raw-audio store is admitted; provider-side lifecycle remains unproved. |
voice/audio |
destination:storage |
14.2 |
Establish provider-side storage and buffering for the voice audio route. |
voice/audio |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
voice/audio |
retention |
14.5 |
Local buffers are request-scoped, but provider retention is unmeasured and owned by Task 14.2. |
voice/text |
deletion |
14.4 |
No durable local raw-audio store is admitted; provider-side lifecycle remains unproved. |
voice/text |
destination:storage |
14.2 |
Establish provider-side storage and buffering for the voice text route. |
voice/text |
providerTransfer |
14.2 |
Routing enforcement is recorded, but provider practice and subprocessors require independent review. |
voice/text |
retention |
14.5 |
Local buffers are request-scoped, but provider retention is unmeasured and owned by Task 14.2. |
workbench-intent/audio |
deletion |
14.4 |
Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified. |
workbench-intent/audio |
destination:artifact |
14.4 |
Register the owning audio artifact store, owner, identity mapping, and deletion propagation path. |
workbench-intent/audio |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/audio |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
workbench-intent/code |
deletion |
14.4 |
Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified. |
workbench-intent/code |
destination:artifact |
14.4 |
Register the owning code artifact store, owner, identity mapping, and deletion propagation path. |
workbench-intent/code |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/code |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
workbench-intent/document-pdf |
deletion |
14.4 |
Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified. |
workbench-intent/document-pdf |
destination:artifact |
14.4 |
Register the owning document-pdf artifact store, owner, identity mapping, and deletion propagation path. |
workbench-intent/document-pdf |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/document-pdf |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
workbench-intent/image-screenshot |
deletion |
14.4 |
Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified. |
workbench-intent/image-screenshot |
destination:artifact |
14.4 |
Register the owning image-screenshot artifact store, owner, identity mapping, and deletion propagation path. |
workbench-intent/image-screenshot |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/image-screenshot |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
workbench-intent/structured-record |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/structured-record |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
workbench-intent/telemetry-evidence |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/telemetry-evidence |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
workbench-intent/text |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/text |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
workbench-intent/three-d-scene |
deletion |
14.4 |
Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified. |
workbench-intent/three-d-scene |
destination:artifact |
14.4 |
Register the owning three-d-scene artifact store, owner, identity mapping, and deletion propagation path. |
workbench-intent/three-d-scene |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/three-d-scene |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
workbench-intent/video |
deletion |
14.4 |
Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified. |
workbench-intent/video |
destination:artifact |
14.4 |
Register the owning video artifact store, owner, identity mapping, and deletion propagation path. |
workbench-intent/video |
providerTransfer |
14.2 |
Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer. |
workbench-intent/video |
retention |
14.5 |
Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5. |
Integrity and scope#
Record digest:
6820699cfc49fbe2a1fc01069c20b19d570399b81e6bd77c792d2218ac057b75.
- Every Task 4.1 plane and every admitted modality intersect in exactly one explicit flow or not-applicable cell.
- Every flow records source, purpose, actor/tenant binding, classification, prompt and provider transfer, all six destination kinds, retention, deletion, and owner.
- Every flow cell participates in at least one typed edge, and every admitted model leg maps to concrete transfer cells, provider targets, and source-bound implementation references.
- Unknown or partial lifecycle facts remain open requirements with a named owner task; they never default to absent, safe, or complete.
- A stale nested source digest in an upstream authority is exposed as an owned discrepancy while the current runtime file is bound directly.
- Cross-plane edges may narrow authority and classification but may not widen either.
- A new plane, modality, provider leg, destination kind, or source binding invalidates this inventory until regenerated and reviewed.
Limitations#
- This is a source-bound inventory and flow map, not proof that every listed retention, deletion, minimization, or provider control is deployed.
- Task 14.2 owns provider and subprocessor practice; Task 14.3 owns end-to-end minimization; Task 14.4 owns complete rights propagation; Task 14.5 owns retention and audited access; Task 14.7 owns creative-media licence and consent.
- Artifact modalities on the workbench plane describe manifests and references, not an assertion that raw binary payloads are stored in PostgreSQL.
- The unregistered artifact-custody endpoint is an explicit inventory gap, not a claim that its store, owner, retention, or deletion behavior is known.
- Media generation, video understanding, and 3D provider legs remain unadmitted; their cells stay explicit not-applicable entries rather than disappearing.
- Task 13.6 recovery results are local measured evidence for eleven families and do not prove production backup, provider deletion, or legal compliance.
- The Task 15.1 model-leg record has a stale nested model-registry source digest; Task 14.1 binds the current file and exposes the discrepancy rather than silently treating the older digest as fresh.