Governance Operations
Credential Metadata Expiry — Reviewer CSV file
Produce an expiry attention queue from credential metadata without reading tokens or testing connections. Prepare a Reviewer CSV file.
Experimental native example · local preview · revision 1
WORKFLOW PREVIEW
See how it works
Use + and − to zoom, F to fit. Press Enter on a node to inspect it.
Private preview. These tested drafts are available for inspection. Adding them to a Vora workspace is still being tested.
What you need
- Authorized supplied job facts matching the original closed input contract.
- Explicit review metadata and target destination fields; no implicit team, channel, list or project selection.
Follow the workflow step by step
Supplied agency job and review metadata
Receive the explicitly supplied manual input packet.
- default: Credential Metadata Expiry
Credential Metadata Expiry
Produce an expiry attention queue from credential metadata without reading tokens or testing connections.
- default: Reviewer CSV file
Reviewer CSV file
Produce an expiry attention queue from credential metadata without reading tokens or testing connections.
Setup and review
- Download the workflow JSON and inspect its jobInput and deliveryMetadata contracts.
- Supply the original agency job input plus explicit review metadata and destination.
- Run in an isolated test and inspect the complete jobResult, target status, holds and escape report before taking an external action.
Inspect every node
Expand a node to inspect its complete settings. Review the runtime and adoption evidence before installing it.
Supplied agency job and review metadata · wfManualTrigger
{
"label": "Supplied agency job and review metadata"
}Credential Metadata Expiry · code
{
"label": "Credential Metadata Expiry",
"code": "return (function(context){\nconst slug=\"credential-metadata-expiry\";\n\nfunction fail(reason){throw new Error('Invalid '+slug+' input: '+reason);}\nfunction safe(value){if(!Number.isSafeInteger(value))fail('unsafe integer arithmetic');return value;}\nfunction nonneg(value,name='quantity'){if(!Number.isSafeInteger(value)||value<0)fail(name+' must be nonnegative');return value;}\nfunction positive(value,name='quantity'){nonneg(value,name);if(value===0)fail(name+' must be positive');return value;}\nfunction ident(value){if(typeof value!=='string'||!value.trim())fail('blank identity');return value.trim();}\nfunction unique(values,key){const seen=new Set();for(const value of values){const k=ident(key?value[key]:value);if(seen.has(k))fail('duplicate identity');seen.add(k);}return values;}\nfunction rows(values,key='id'){return unique(values,key);}\nfunction sum(values){return values.reduce((total,value)=>safe(total+value),0);}\nfunction mul(a,b){return safe(a*b);}\nfunction sorted(values){return [...values].sort((a,b)=>a<b?-1:a>b?1:0);}\nfunction distinct(values){return [...new Set(values)];}\nfunction pair(a,b){return JSON.stringify([a,b]);}\nfunction day(value){if(typeof value!=='string'||!/^\\d{4}-\\d{2}-\\d{2}$/.test(value))fail('invalid calendar date');const n=Date.parse(value+'T00:00:00Z');if(!Number.isFinite(n)||new Date(n).toISOString().slice(0,10)!==value)fail('invalid calendar date');return n/86400000;}\nfunction dayText(value){const date=new Date(mul(value,86400000));if(!Number.isFinite(date.getTime())||date.getUTCFullYear()<0||date.getUTCFullYear()>9999)fail('four-digit calendar range');return date.toISOString().slice(0,10);}\nfunction stamp(value){const match=typeof value==='string'&&value.match(/^(\\d{4}-\\d{2}-\\d{2})T(\\d{2}):(\\d{2}):(\\d{2})(Z|[+-]\\d{2}:\\d{2})$/);if(!match)fail('invalid offset timestamp');day(match[1]);if(+match[2]>23||+match[3]>59||+match[4]>59)fail('invalid clock time');if(match[5]!=='Z'&&(+match[5].slice(1,3)>23||+match[5].slice(4)>59))fail('invalid offset');const n=Date.parse(value);if(!Number.isFinite(n))fail('invalid timestamp');return n/1000;}\nfunction stampText(value){const date=new Date(mul(value,1000));if(!Number.isFinite(date.getTime())||date.getUTCFullYear()<0||date.getUTCFullYear()>9999)fail('four-digit calendar range');return date.toISOString();}\nfunction interval(start,end){if(end<=start)fail('reversed or empty interval');}\nfunction normalize(value,key=''){if(typeof value==='string'&&(key==='id'||key.endsWith('Id')||key.endsWith('Ids')||['members','clients','partners','pageIds','expectedIds','jobs','requiredAttendees','requires','dependsOn'].includes(key)))return value.trim();if(Array.isArray(value))return value.map(v=>normalize(v,key));if(value&&typeof value==='object')return Object.fromEntries(Object.entries(value).map(([k,v])=>[k,normalize(v,k)]));return value;}\nfunction graphCheck(nodes,edges){const byId=new Map(rows(nodes).map(n=>[n.id,n]));const visiting=new Set(),done=new Set();function visit(id){if(visiting.has(id))fail('dependency cycle');if(done.has(id))return;const node=byId.get(id);if(!node)fail('unknown dependency reference');visiting.add(id);unique(edges(node));for(const target of edges(node)){if(target===id)fail('self prerequisite');visit(target);}visiting.delete(id);done.add(id);}for(const id of byId.keys())visit(id);return byId;}\nfunction monthNumber(date){day(date);return Number(date.slice(0,4))*12+Number(date.slice(5,7))-1;}\nfunction sweep(items,startKey,endKey,limit){const points=sorted(distinct(items.flatMap(item=>[item[startKey],item[endKey]]))).sort((a,b)=>a-b),out=[];for(let i=0;i+1<points.length;i++){const start=points[i],end=points[i+1],active=sorted(items.filter(item=>item[startKey]<=start&&item[endKey]>start).map(item=>item.id));if(active.length>limit){const last=out.at(-1);if(last&&last.end===start&&JSON.stringify(last.active)===JSON.stringify(active))last.end=end;else out.push({start,end,active});}}return out;}\nfunction httpUrl(value){if(typeof value!=='string'||/[\\u0000-\\u0020\\u007f<>\"\\\\]/.test(value)||/%(?![0-9a-f]{2})/i.test(value))return null;const m=value.match(/^https?:\\/\\/([^/?#]+)([^#]*)(?:#.*)?$/i);if(!m||m[1].includes('@'))return null;const authority=m[1].match(/^([^:]+)(?::(\\d{1,5}))?$/);if(!authority||(authority[2]&&Number(authority[2])>65535))return null;const host=authority[1],labels=host.split('.');if(host.length>253||labels.some(l=>!l||l.length>63||!/^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$/i.test(l)))return null;if(labels.every(l=>/^\\d+$/.test(l))&&(labels.length!==4||labels.some(l=>Number(l)>255||(l.length>1&&l[0]==='0'))))return null;const q=m[2].indexOf('?'),raw=q<0?'':m[2].slice(q+1),query=[];try{if(raw)for(const part of raw.split('&')){const at=part.indexOf('='),key=at<0?part:part.slice(0,at),val=at<0?'':part.slice(at+1);query.push([decodeURIComponent(key.replace(/\\+/g,' ')),decodeURIComponent(val.replace(/\\+/g,' '))]);}}catch{return null;}return {query};}\n\nconst input=normalize(context.input);\nreturn (input=>{\n const asOf=day(input.asOfDate);nonneg(input.warningDays,'warning days');rows(input.credentials);const ids=new Set(input.credentials.map(c=>c.id));for(const d of input.dependencies){ident(d.workflowId);if(!ids.has(d.credentialId))fail('unknown credential reference');}const queue=[];for(const c of input.credentials){const daysRemaining=day(c.expiresDate)-asOf;if(daysRemaining<=input.warningDays)queue.push({credentialId:c.id,daysRemaining,status:daysRemaining<0?'expired':daysRemaining===0?'due_today':'expiring',workflowIds:sorted(distinct(input.dependencies.filter(d=>d.credentialId===c.id).map(d=>d.workflowId)))});}return {queue};\n})(input);\n})({input:context.input.jobInput});\n",
"outputVar": "jobResult",
"timeout": 3000,
"memoryLimit": 64
}Reviewer CSV file · code
{
"label": "Reviewer CSV file",
"code": "const jobResult=context.jobResult;\nconst delivery=(function(context){\nreturn ((function(originalResult,metadata,destination){\nfunction stableResult(value,depth=0){\n if(depth>64)throw new Error('Result nesting exceeds 64');\n if(value===null||typeof value==='string'||typeof value==='boolean')return JSON.stringify(value);\n if(typeof value==='number'&&Number.isFinite(value))return JSON.stringify(value);\n if(Array.isArray(value)){\n if(Object.keys(value).length!==value.length||Array.from({length:value.length},(_,i)=>i).some(i=>!Object.hasOwn(value,i)))throw new Error('Result contains sparse data');\n return '['+value.map(item=>stableResult(item,depth+1)).join(',')+']';\n }\n if(value&&typeof value==='object')return '{'+Object.keys(value).sort().map(key=>JSON.stringify(key)+':'+stableResult(value[key],depth+1)).join(',')+'}';\n throw new Error('Result is not JSON data');\n}\nfunction utf8Length(text){\n let bytes=0;\n for(let i=0;i<text.length;i++){\n const code=text.charCodeAt(i);\n if(code<128)bytes++;else if(code<2048)bytes+=2;\n else if(code>=55296&&code<=56319&&i+1<text.length&&text.charCodeAt(i+1)>=56320&&text.charCodeAt(i+1)<=57343){bytes+=4;i++;}\n else bytes+=3;\n }\n return bytes;\n}\nfunction chunkText(text,maximum){\n const chunks=[];\n for(let start=0;start<text.length;){let end=Math.min(start+maximum,text.length);const last=text.charCodeAt(end-1),next=text.charCodeAt(end);if(end<text.length&&last>=55296&&last<=56319&&next>=56320&&next<=57343)end--;chunks.push(text.slice(start,end));start=end;}\n return chunks;\n}\nfunction deliveryState(rendererId,originalResult,metadata,destination,destinationKeys){\n const output={rendererId,status:'HELD',originalResult,drafts:[],holds:[],escapeReport:[]};\n const hold=(code,message)=>{output.holds.push({code,message});return {output,json:''};};\n const object=value=>value&&typeof value==='object'&&!Array.isArray(value);\n const exact=(value,keys)=>object(value)&&Object.keys(value).length===keys.length&&keys.every(key=>Object.hasOwn(value,key));\n const keys=['workflowId','canonicalIntentId','title','reviewUrl'],maxima=[128,200,200,1000];\n if(!exact(metadata,keys)||keys.some((key,i)=>typeof metadata[key]!=='string'||!metadata[key].length||metadata[key].length>maxima[i]||/[\\u0000-\\u001f\\u007f]/.test(metadata[key]))||!/^https?:\\/\\/[^\\s<>\"']+$/.test(metadata.reviewUrl))return hold('INVALID_METADATA','Metadata must provide bounded workflowId, canonicalIntentId, title and an HTTP(S) reviewUrl.');\n if(!exact(destination,destinationKeys)||destinationKeys.some(key=>typeof destination[key]!=='string'||!destination[key].length||destination[key].length>200||destination[key]!==destination[key].trim()||/[\\u0000-\\u001f\\u007f]/.test(destination[key])))return hold('INVALID_DESTINATION','Destination fields must be exactly: '+destinationKeys.join(', ')+'.');\n let json;\n try{if(!object(originalResult))throw new Error('Primary result must be a JSON object');json=stableResult(originalResult);}catch(error){return hold('INVALID_RESULT',error.message);}\n if(json.length>32768||utf8Length(json)>65536)return hold('RESULT_BOUND_EXCEEDED','Original result exceeds this renderer profile; full original result is retained.');\n return {output,json};\n}\nfunction escapeHtml(text){return text.replace(/&/g,'&').replace(/</g,'<').replace(/>/g,'>').replace(/\"/g,'"').replace(/'/g,''');}\nfunction escapeMarkdown(text){return text.replace(/&/g,'&').replace(/[\\\\`*{}\\[\\]()#+\\-.!_|>~<]/g,'\\\\$&');}\nfunction markdownReviewText(metadata,json){\n const runs=json.match(/`+/g)||[],fence='`'.repeat(Math.max(3,...runs.map(run=>run.length+1)));\n return '# '+escapeMarkdown(metadata.title)+'\\n\\nWorkflow: '+escapeMarkdown(metadata.workflowId)+'\\nCanonical job: '+escapeMarkdown(metadata.canonicalIntentId)+'\\nReview: <'+metadata.reviewUrl.replace(/&/g,'&')+'>\\n\\n'+fence+'json\\n'+json+'\\n'+fence+'\\n';\n}\nfunction plainReviewText(metadata,json){return metadata.title+'\\nWorkflow: '+metadata.workflowId+'\\nCanonical job: '+metadata.canonicalIntentId+'\\nReview: '+metadata.reviewUrl+'\\n\\n'+json;}\nfunction finishDraft(state,draft,texts=[],textMaximum=32768,byteMaximum=131072){\n if(texts.some(text=>text.length>textMaximum)||utf8Length(JSON.stringify(draft))>byteMaximum){state.output.holds.push({code:'TARGET_BOUND_EXCEEDED',message:'Draft exceeds the target or Vora profile bound; no draft is emitted and the full original result is retained.'});return state.output;}\n state.output.status='PREPARED';state.output.drafts=[draft];return state.output;\n}\nreturn (function reviewerCsv(originalResult,metadata,destination){\n const state=deliveryState('reviewer-csv',originalResult,metadata,destination,[]);if(state.output.holds.length)return state.output;\n const fields=['workflowId','canonicalIntentId','title','reviewUrl','resultJson'];\n const values=[metadata.workflowId,metadata.canonicalIntentId,metadata.title,metadata.reviewUrl,state.json].map((value,index)=>{\n if(/^\\s*[=+\\-@]/.test(value)){const escapedValue=\"'\"+value;state.output.escapeReport.push({field:fields[index],method:'prefix-apostrophe-v1',originalValue:value,escapedValue});return escapedValue;}return value;\n });\n const quote=value=>'\"'+value.replace(/\"/g,'\"\"')+'\"';\n const text=fields.map(quote).join(',')+'\\r\\n'+values.map(quote).join(',')+'\\r\\n';\n return finishDraft(state,{mediaType:'text/csv; charset=utf-8',text},[text]);\n})(originalResult,metadata,destination);\n}))(context.input.jobResult,context.input.deliveryMetadata.metadata,context.input.deliveryMetadata.destination);\n\n})({input:{jobResult,deliveryMetadata:context.input.deliveryMetadata}});\nreturn {jobResult,delivery};\n",
"outputVar": "result",
"timeout": 3000,
"memoryLimit": 64
}Input and output contracts
Input
{
"type": "object",
"properties": {
"jobInput": {
"type": "object",
"properties": {
"asOfDate": {
"type": "string",
"maxLength": 2000
},
"warningDays": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991
},
"credentials": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"maxLength": 2000
},
"expiresDate": {
"type": "string",
"maxLength": 2000
}
},
"required": [
"id",
"expiresDate"
],
"additionalProperties": false
},
"maxItems": 100
},
"dependencies": {
"type": "array",
"items": {
"type": "object",
"properties": {
"workflowId": {
"type": "string",
"maxLength": 2000
},
"credentialId": {
"type": "string",
"maxLength": 2000
}
},
"required": [
"workflowId",
"credentialId"
],
"additionalProperties": false
},
"maxItems": 100
}
},
"required": [
"asOfDate",
"warningDays",
"credentials",
"dependencies"
],
"additionalProperties": false
},
"deliveryMetadata": {
"type": "object",
"properties": {
"metadata": {
"type": "object",
"properties": {
"workflowId": {
"type": "string",
"maxLength": 128
},
"canonicalIntentId": {
"type": "string",
"maxLength": 200
},
"title": {
"type": "string",
"maxLength": 200
},
"reviewUrl": {
"type": "string",
"maxLength": 1000
}
},
"required": [
"workflowId",
"canonicalIntentId",
"title",
"reviewUrl"
],
"additionalProperties": false
},
"destination": {
"type": "object",
"properties": {},
"required": [],
"additionalProperties": false
}
},
"required": [
"metadata",
"destination"
],
"additionalProperties": false
}
},
"required": [
"jobInput",
"deliveryMetadata"
],
"additionalProperties": false
}Output
{
"type": "object",
"properties": {
"jobResult": {
"type": "object",
"properties": {
"queue": {
"type": "array",
"items": {
"type": "object",
"properties": {
"credentialId": {
"type": "string",
"maxLength": 2000
},
"daysRemaining": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991
},
"status": {
"type": "string",
"maxLength": 2000
},
"workflowIds": {
"type": "array",
"items": {
"type": "string",
"maxLength": 2000
},
"maxItems": 1000
}
},
"required": [
"credentialId",
"daysRemaining",
"status",
"workflowIds"
],
"additionalProperties": false
},
"maxItems": 1000
}
},
"required": [
"queue"
],
"additionalProperties": false
},
"delivery": {
"type": "object",
"properties": {
"rendererId": {
"type": "string",
"maxLength": 128,
"enum": [
"reviewer-csv"
]
},
"status": {
"type": "string",
"maxLength": 16,
"enum": [
"PREPARED",
"HELD"
]
},
"originalResult": {
"type": "object",
"properties": {
"queue": {
"type": "array",
"items": {
"type": "object",
"properties": {
"credentialId": {
"type": "string",
"maxLength": 2000
},
"daysRemaining": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991
},
"status": {
"type": "string",
"maxLength": 2000
},
"workflowIds": {
"type": "array",
"items": {
"type": "string",
"maxLength": 2000
},
"maxItems": 1000
}
},
"required": [
"credentialId",
"daysRemaining",
"status",
"workflowIds"
],
"additionalProperties": false
},
"maxItems": 1000
}
},
"required": [
"queue"
],
"additionalProperties": false
},
"drafts": {
"type": "array",
"items": {
"type": "object",
"properties": {
"mediaType": {
"type": "string",
"maxLength": 80,
"enum": [
"text/csv; charset=utf-8"
]
},
"text": {
"type": "string",
"maxLength": 32768
}
},
"required": [
"mediaType",
"text"
],
"additionalProperties": false
},
"maxItems": 1,
"minItems": 0
},
"holds": {
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string",
"maxLength": 128
},
"message": {
"type": "string",
"maxLength": 2000
}
},
"required": [
"code",
"message"
],
"additionalProperties": false
},
"maxItems": 10,
"minItems": 0
},
"escapeReport": {
"type": "array",
"items": {
"type": "object",
"properties": {
"field": {
"type": "string",
"maxLength": 256
},
"method": {
"type": "string",
"maxLength": 80
},
"originalValue": {
"type": "string",
"maxLength": 32768
},
"escapedValue": {
"type": "string",
"maxLength": 32768
}
},
"required": [
"field",
"method",
"originalValue",
"escapedValue"
],
"additionalProperties": false
},
"maxItems": 1000,
"minItems": 0
}
},
"required": [
"rendererId",
"status",
"originalResult",
"drafts",
"holds",
"escapeReport"
],
"additionalProperties": false
}
},
"required": [
"jobResult",
"delivery"
],
"additionalProperties": false
}Related implementations
Compare implementations for this job · Primary business workflow
All five fields are quoted, embedded double quotes are doubled, records end in CRLF. Formula-like cells beginning with optional whitespace then = + - @ receive one leading apostrophe. escapeReport records field, originalValue and escapedValue; remove that one recorded prefix to recover the exact original. The complete stable result JSON occupies resultJson; no spreadsheet import or formula execution is performed. Original result, including original reasons/holds, is preserved without mutation. Missing/extra destination fields or invalid metadata hold the draft. No truncation: overflow returns HELD with an empty drafts array and full original result.
Supplied input: vora-agency-credential-metadata-expiry · 1. Draft/result: reviewer-csv · RFC 4180 / Vora reversible formula-escape profile v1.
Mapping and loss rules
- All five fields are quoted, embedded double quotes are doubled, records end in CRLF.
- Formula-like cells beginning with optional whitespace then = + - @ receive one leading apostrophe. escapeReport records field, originalValue and escapedValue; remove that one recorded prefix to recover the exact original.
- The complete stable result JSON occupies resultJson; no spreadsheet import or formula execution is performed.
- Original result, including original reasons/holds, is preserved without mutation.
- Missing/extra destination fields or invalid metadata hold the draft.
- No truncation: overflow returns HELD with an empty drafts array and full original result.
This binding consumes supplied data. It does not establish an authenticated connector or a provider write.
Example input and result
These examples use synthetic data. Credential references are replaced with portable example labels for display. This result was checked with the supplied-data operation; it is not the original native fixture receipt.
Input
{
"jobInput": {
"asOfDate": "2026-10-07",
"warningDays": 7,
"credentials": [
{
"id": "example-ref-1",
"expiresDate": "2026-10-08"
}
],
"dependencies": [
{
"workflowId": "w",
"credentialId": "example-ref-1"
}
]
},
"deliveryMetadata": {
"metadata": {
"workflowId": "agency-credential-metadata-expiry",
"canonicalIntentId": "governance-operations.credential-metadata-expiry",
"title": "Credential Metadata Expiry",
"reviewUrl": "https://example.test/workflows/credential-metadata-expiry/"
},
"destination": {}
}
}Expected result
{
"jobResult": {
"queue": [
{
"credentialId": "example-ref-1",
"daysRemaining": 1,
"status": "expiring",
"workflowIds": [
"w"
]
}
]
},
"delivery": {
"rendererId": "reviewer-csv",
"status": "PREPARED",
"originalResult": {
"queue": [
{
"credentialId": "example-ref-1",
"daysRemaining": 1,
"status": "expiring",
"workflowIds": [
"w"
]
}
]
},
"drafts": [
{
"mediaType": "text/csv; charset=utf-8",
"text": "\"workflowId\",\"canonicalIntentId\",\"title\",\"reviewUrl\",\"resultJson\"\r\n\"agency-credential-metadata-expiry\",\"governance-operations.credential-metadata-expiry\",\"Credential Metadata Expiry\",\"https://example.test/workflows/credential-metadata-expiry/\",\"{\"\"queue\"\":[{\"\"credentialId\"\":\"\"example-ref-1\"\",\"\"daysRemaining\"\":1,\"\"status\"\":\"\"expiring\"\",\"\"workflowIds\"\":[\"\"w\"\"]}]}\"\r\n"
}
],
"holds": [],
"escapeReport": []
}
}Success means: Produce an expiry attention queue from credential metadata without reading tokens or testing connections.
When something goes wrong
- Review original business holds and target holds separately. Correct the relevant supplied input and rerun without discarding the original job result.
Limits and costs
- This prepares a target-specific review draft from the original agency decision. The complete original job result and business holds remain visible. A held target produces no draft. No provider request, send, import, issue creation or publication occurs.
- No paid model calls or metered third-party operations are declared in this pure graph. Vora plan availability, compute and quotas still apply; pricing has not been verified by this batch.