regulated-case-workbench release-control desk synthetic proof surface

Regulated Case Workbench

A review-first reference workflow for case intake, grounded evidence, redaction preview, approval gates, and signed export handoff. It makes the release path inspectable without presenting staged controls as a compliance certification.

Evidence before narrative Case summaries stay tied to evidence items, timelines, and explicit reviewer watchouts.
Approval before export Policy disposition, redaction preview, and reviewer ownership remain visible before handoff.
Verifiable proof HMAC-SHA256 manifest signatures and audit events close the staged release path.

System boundary

The public page is static. The executable proof runs locally as a Python 3.11+ and FastAPI application with a Vanilla JavaScript reviewer desk. Production identity, durable storage, key management, retention, monitoring, and policy ownership remain customer-specific work.

Public surface

Static HTML on Cloudflare Pages explains the workflow. It does not proxy or imitate the FastAPI runtime.

Application runtime

FastAPI routes and a Vanilla JavaScript workbench expose case, evidence, policy, redaction, and export contracts.

Evidence layer

Local JSONL events and HMAC-SHA256 manifest proof keep the demonstration inspectable and replayable.

Delivery boundary

Docker, CI, and Terraform are implementation scaffolding. SSO, KMS, managed persistence, and approved controls are not active here.

01

Case intake

Start with jurisdiction, domain, urgency, and missing evidence so the queue reads like a real desk.

02

Evidence review

Inspect linked evidence before trusting any narrative summary or release recommendation.

03

Redaction preview

See what leaves the system, what is masked, and where policy boundaries stay visible.

04

Approval gate

Reviewer ownership, policy disposition, and release status read as explicit workflow states.

05

Export handoff

Export only when preview, signature, and audit proof agree on the same release story.

What reviewers can verify

The repository demonstrates release-control mechanics without making certification or production-readiness claims.

  • Case inbox, case detail, handoff brief, and reviewer assignment stay connected.
  • Grounded evidence review appears before policy or release claims.
  • Redaction preview and policy checks stay explicit before export.
  • Runtime scorecard, signature proof, and audit feed close the workflow.
Proof boundary: Synthetic staged cases only. No compliance certification claim, legal conclusion, or production processing claim.

Map one controlled workflow before expanding scope.

A private Secure Workflow Pilot can define one processing boundary, approval gate, audit trail, and deployment runbook against customer-approved requirements.

Do not include regulated records, personal data, credentials, contracts, or production logs in the initial inquiry.

Start a private pilot inquiry