{"schema_version":"1","site":"https://decosa.ai","id":"privilege-log","num":"30","name":"Privilege review and privilege log","tool_name":"Build a privilege log","short":"Privilege log","blurb":"Typed privilege calls for each email or memo in a production set: attorney-client, work product, not privileged, or needs attorney review, with the lawyer involved, the reason checked against the document and a calibrated probability. It drafts log entries that describe without disclosing, catches the ones that leak, gives duplicates the same call, flags outsiders who could waive, and seals it all in a signed record.","status":"live","labels":{"industry":["legal"],"job":["review","attest"],"input":["files","text"],"deploy":["selfhost"],"status":"live","output":["data","record"],"data":["privileged"],"hardware":"gpu-96","licence":"permissive"},"industries":["legal"],"runs_in":["selfhost","crp-legal-matter"],"part_of":[],"built_from":["typed-judgment","signed-record"],"models":"Qwen3.8-27B","where":"Self-host for real matters; hosted for the demo sets only","hardware":"1× RTX PRO 6000 (96 GB) or 1× RTX 5090 (32 GB) for the model; the people map, grouping and leak rules run on CPU","final_artifact":"A draft privilege log (CSV), a review memo for the supervising lawyer, and a signed record and ledger of every call and decision.","self_host_first":true,"verification":{"receipt_coverage":"full","summary":"Receipt per call; leak check; signed record and reviewer ledger","manual_qa":{"hosted":{"date":"2026-09-25","result":"pass","p50_ms":121000,"p95_ms":null,"runs":null,"receipts_per_run":100,"cost_per_run_usd":0.031},"selfhost":{"date":"2026-09-25","result":"pass","method":"Fresh clone of the branch into a clean directory, docker build of docker/api/Dockerfile, the assemble prompt's api service with a named volume, pointed at the already-running local vLLM (Qwen3.8-27B NVFP4 on 127.0.0.1:8114) through host networking; then torn down.","notes":"Verified on 2026-09-25: the image builds, the service starts healthy, info reports logprobs, the harborline-dispute sample passes end to end (copy of HL-002 gets its call, HL-003 goes to review, HL-012 and HL-021 produced, 17 s, 58 attested calls), the signed record verifies and fails when one call is changed, and the CSV export works. The model server's own startup was not re-verified (no new GPU load)."},"known_limits":["Labels are one AI reviewer's (Claude's), not a lawyer's; hard judgment calls are where it errs: 4 of 34 hard privileged held-out emails would have been produced.","About 38% of held-out real email goes to attorney review (26% where the label is clear).","The hosted gateway route slows sharply when the shared gateway is loaded (one 12-email run took 938 s).","Attachments must be sent as separate documents; no OCR, PDF or native file parsing in this version.","Partial privilege (redacting part of a document) is not proposed; such documents go to review."],"nightly_covers":null},"nightly":"https://api.decosa.ai/verify/status"},"eval_summary":{"metrics":[{"name":"Privileged vs not, model call: accuracy / precision / recall","value":"83.9% / 82.3% / 79.7%","unit":null,"n":149,"split":"test","note":"Direct route with logprobs. Clear labels (92): 95.7%; hard labels (57): 64.9%. Dev: 95.9%."},{"name":"AUROC of p(privileged) / ECE","value":"0.908 / 0.058","unit":null,"n":149,"split":"test","note":null},{"name":"Privileged emails the tool would have produced (waiver risk)","value":"4 (6.2% of privileged)","unit":null,"n":64,"split":"test","note":"All four on labels marked hard. Wrongly withheld: 3."},{"name":"Sent to attorney review","value":"57 (38%)","unit":null,"n":149,"split":"test","note":"Auto-decided documents agreeing with the labels: 85 of 92 (92.4%)."},{"name":"Four-way call: exact / Cohen's kappa","value":"80.5% / 0.65","unit":null,"n":149,"split":"test","note":"Kappa 0.83 on clear labels"},{"name":"Planted leaky log descriptions caught","value":"19 of 21","unit":null,"n":37,"split":"synthetic","note":"0 false alarms on 16 clean descriptions; code rules alone 12 of 21."}],"dataset":"200 emails from Enron lawyers' mailboxes in the public corpus (198 labelled; 49 dev, 149 test), a 28-email synthetic set and 37 planted log descriptions. Dev was used to write the prompts and review rules; test was run once after the rules were frozen, with nothing changed because of it.","held_out":true,"caveats":["Labels are one AI reviewer's (Claude), not a lawyer's; 72 of 198 are marked hard judgment calls.","Small sample; publish your own measured precision and recall on a labelled sample of the matter before relying on it.","The held-out Enron set was run on the direct (self-host, logprobs) route only; the hosted gateway route was measured only on the 28 synthetic emails.","On hard calls the model alone is barely better than chance (kappa 0.28); the review queue, not the model, is the safeguard."],"date":"2026-09-25","doc_url":"https://decosa.ai/metrics/evals/privilege-log"},"stack":{"summary":"Send the documents of a production set and say who the lawyers are. Code maps every address to a role and flags outsiders, personal accounts and lawyers who are only copied; it groups exact copies, near-duplicate drafts, threads and emails that quote each other. An open model answers three typed questions per document (the privilege call, whether it asks for or gives legal advice, whether it was prepared because of litigation) through the typed-judgment engine, and code turns them into withhold, produce or needs attorney review. The reason is checked against the document by the grounding checker. For each withheld document the model drafts a Rule 26(b)(5)(A) log description, and a leak check (code rules plus a typed judge) rejects drafts that give the advice away. Everything is sealed in a signed hash-chained record, and the lawyer's confirm-or-change decisions go into a signed ledger. It drafts; a lawyer decides.","tagline":"A typed privilege call for every email or memo, with the lawyer involved, a grounded reason and a calibrated probability; log entries that describe without disclosing; the same call for every copy; one signed record.","deployment":"self-host-first","regulatory_note":"A review aid for lawyers, not legal advice and not a privilege determination. Fed. R. Civ. P. 26(b)(5)(A) requires a party withholding documents as privileged or work product to expressly claim it and describe each document in a way that lets others assess the claim without revealing the protected content; the attorney who signs discovery responses certifies them under Rule 26(g), so every call and log entry here is a draft for that attorney. A wrong 'not privileged' can waive privilege; Fed. R. Evid. 502(b) protects inadvertent disclosure only where reasonable steps were taken, and a Rule 502(d) order (non-waiver regardless of care) is the safer footing for any AI-assisted review. Courts have judged generative-AI review by the same reasonableness and proportionality standard as earlier technology-assisted review (Schulte v. LinkedIn, N.D. Cal., 30 Jun 2026); the signed record and ledger document which model, prompt and lawyer produced each call. Confidentiality: ABA Formal Opinion 512 (29 Jul 2024) asks lawyers to understand how an AI tool uses what they put in, to protect client information, and to get informed consent before putting it into a self-learning tool; United States v. Heppner (S.D.N.Y., Feb 2026) held a defendant's chats with a consumer AI service not privileged, partly because its terms allowed disclosure to third parties. Run real matters on your own machine; the hosted demo is for the fictional and public sample sets only. Model licence: Apache-2.0 (Qwen3.8-27B). The Enron emails are public records released by FERC (2003), used here as a small research sample. Checked 25 Sep 2026.","components":[{"id":"reviewer","role":"Reviewer: people map, waiver flags, duplicate and thread grouping, review rules, leak rules, consistency, signed record and ledger (no model; CPU)","name":"decosa-api privilege module (decosa_api/verticals/privilege)","hf_repo":null,"license":"AGPL-3.0-or-later","params":null,"quant":null,"vram_gb":0,"memory_gb_estimate":null,"engine":"Python 3.12; the typed-judgment engine (vertical 24) for the questions and the grounding checker (vertical 17) for the reason","receipt_coverage":"partial","in_hosted_demo":null,"tiers":["lite","standard","wanted"],"alternative_to":null},{"id":"judge","role":"Model: the typed privilege call, the two element questions, the grounding check of the reason, the log description and the leak judge","name":"Qwen3.8-27B (NVFP4)","hf_repo":"nvidia/Qwen3.8-27B-NVFP4","license":"Apache-2.0","params":"27.8B","quant":"NVFP4 (MLP NVFP4, GDN/attention FP8) + FP8 KV cache; MTP head, 3 draft tokens","vram_gb":20,"memory_gb_estimate":null,"engine":"vLLM 0.29.0, temperature 0, thinking off, prefix caching, top-20 logprobs on the direct route","receipt_coverage":"strong","in_hosted_demo":true,"tiers":["lite","standard"],"alternative_to":null},{"id":"gemma-judge","role":"Faster model for the typed calls at volume (alternate)","name":"Gemma-4-26B-A4B-it","hf_repo":"google/gemma-4-26B-A4B-it","license":"Apache-2.0","params":"26B","quant":"BF16 (49 GB)","vram_gb":49,"memory_gb_estimate":null,"engine":"vLLM","receipt_coverage":"none","in_hosted_demo":false,"tiers":["alternates"],"alternative_to":null},{"id":"glm-wanted","role":"Second judge on the calls the 27B is least sure of","name":"GLM-5.3-Flash","hf_repo":"zai-org/GLM-5.3-Flash","license":"MIT","params":"321B","quant":"NVFP4 on NVIDIA (nvidia/GLM-5.3-Flash-NVFP4, about 170-186 GB, unconfirmed); MLX 4-bit on a Mac (165 GB)","vram_gb":null,"memory_gb_estimate":170,"engine":"SGLang SM120 build, TP2 on 2x 96 GB (vLLM is broken on sm_120 for this model, and the SGLang build hung on our server), or mlx-lm on a Mac with 192 GB or more","receipt_coverage":"none","in_hosted_demo":false,"tiers":["wanted"],"alternative_to":null}],"tiers":[{"id":"lite","label":"Lite · one 32 GB card, self-hosted","summary":"The same model and prompts on a single RTX 5090, one call per question with log-probabilities. The grounding check of the reason can be switched off (DECOSA_PRIVILEGE_GROUNDING=0) to save one call per document.","components":["reviewer","judge"],"hardware":"1x RTX 5090 32 GB","quality_evidence":[{"metric":"Calls on held-out Enron email","value":"not measured separately: the same weights and prompts as the standard tier, so the calls should match; speed on a 5090 not measured","source":"not measured yet"}],"latency_note":"estimate: not timed on a 5090.","in_hosted_demo":false,"receipt_coverage":"partial","receipt_note":"Self-hosted: calls and records are signed by your own box, not countersigned by the gateway.","hosting":null},{"id":"standard","label":"Standard · one 96 GB card (measured; hosted demo)","summary":"Qwen3.8-27B on an RTX PRO 6000. Self-hosted it uses log-probabilities (about 5 calls per document); the hosted demo, whose gateway does not pass log-probabilities through yet, samples the privilege call 5 times instead.","components":["reviewer","judge"],"hardware":"1x RTX PRO 6000 96 GB","quality_evidence":[{"metric":"Privileged vs not, model call, 149 held-out Enron emails (64 privileged by our labels): accuracy / precision / recall / AUROC of p(privileged)","value":"83.9% / 82.3% / 79.7% / 0.908","source":"docs/evals/privilege-log.md, direct route with logprobs; labels written by Claude (an AI agent), not a lawyer"},{"metric":"After the review rules: privileged emails the tool would have produced / non-privileged it would have withheld / sent to attorney review","value":"4 of 64 (6.2%) / 3 of 85 / 57 of 149 (38%); decided without review: 92, of which 92.4% agree with the labels","source":"docs/evals/privilege-log.md, same run"},{"metric":"The same, on the 92 held-out emails whose label we marked clear (not a judgment call)","value":"accuracy 95.7%, 0 privileged produced, 0 wrongly withheld, 26% to review","source":"docs/evals/privilege-log.md; all 4 misses and 3 over-withholds were on the 57 emails we marked as hard calls"},{"metric":"Four-way call (attorney-client / work product / both / not privileged), held out","value":"80.5% exact, Cohen's kappa 0.65","source":"docs/evals/privilege-log.md"},{"metric":"Planted leaky log descriptions caught (21 leaky, 16 clean, synthetic documents)","value":"19 of 21 caught, 0 of 16 false alarms (code rules alone 12 of 21; the judge catches paraphrases)","source":"docs/evals/privilege-log.md, leak-check stage, direct route"},{"metric":"Drafted log descriptions that leaked (87 on held-out Enron, 18 on the synthetic set)","value":"1 first draft flagged (a subject phrase copied from the email), rewritten; 0 in the final log by the code rules","source":"docs/evals/privilege-log.md"},{"metric":"Synthetic set (28 emails): labels met / expected flags and groups met / consistency across copies, drafts and threads / same decision on a re-run","value":"0 privileged produced, 0 wrongly withheld, 3 to review / 12 of 12 / 7 of 7 groups consistent / 28 of 28 (27 of 28 same privilege type)","source":"docs/evals/privilege-log.md"},{"metric":"Hosted gateway route on the synthetic set (sampled call): privileged produced / wrongly withheld / to review / expectations met","value":"0 / 0 / 3 / 12 of 12; same privileged-vs-not accuracy as the direct route (96.4%), AUROC 0.974","source":"docs/evals/privilege-log.md, hosted route stage"}],"latency_note":"measured on our server, shared card: about a second per document on the direct route; the hosted gateway route took a couple of minutes for the demo when the gateway was quiet.","in_hosted_demo":true,"receipt_coverage":"strong","receipt_note":"Hosted: every call has its own gateway-signed receipt, listed in the signed record.","hosting":null},{"id":"wanted","label":"Wanted · a larger second judge on your own hardware","summary":"GLM-5.3-Flash re-reads the calls Qwen3.8-27B is least sure of, from a different model family. Privileged documents stay on your hardware, never on community providers. Not served yet.","components":["reviewer","judge","glm-wanted"],"hardware":"Your own hardware: 2x 96 GB cards (NVFP4, about 170-186 GB, unconfirmed) or a Mac with 192 GB or more (MLX 4-bit, 165 GB). Estimate; GLM's SGLang SM120 build hung on our server.","quality_evidence":[{"metric":"accuracy and AUROC, same protocol as standard","value":"not measured yet","source":null}],"latency_note":"not measured yet","in_hosted_demo":false,"receipt_coverage":"none","receipt_note":"On your own hardware its calls are attested by the box's key only: not a hosted model there, so no gateway receipts. Never sent to community providers.","hosting":"own-hardware"}],"alternates":[{"id":"fast-judge","label":"Fast option-token judge for volume","components":["gemma-judge"],"hardware":"1x RTX PRO 6000 96 GB (BF16 weights are 49 GB)","use":"A 4B-active judge read through option-token probabilities: cheaper per call, not better. Page 32 suggests the dense Qwen3.5-9B (Apache-2.0) instead. The real blocker is logprob passthrough on the gateway.","status":"not served"}],"services":[{"name":"decosa-api","port":8445,"image":"${DECOSA_REGISTRY}/decosa-api:<tag>","purpose":"GET /privilege/info, /privilege/samples; POST /privilege/review (SSE or JSON); POST /privilege/runs/{id}/decisions; GET /privilege/runs/{id}/export?format=csv|md|record|ledger. Keeps documents in memory for the request and runs for one hour, never on disk; logs counts only."},{"name":"vLLM","port":8114,"image":"vllm/vllm-openai@sha256:c2914767605584b6d8f45686b82de173ecc99e781897aa3d0a66dacd72c51ae1","purpose":"Qwen3.8-27B NVFP4 behind our gateway (hosted) or called directly with logprobs (self-host)."}],"tools":[{"name":"Enron email corpus (CMU copy, via the Hugging Face dataset corbt/enron-emails)","url":"https://www.cs.cmu.edu/~enron/","license":"Public record released by FERC in 2003; distributed by CMU as a research resource, with a request to respect the privacy of the people in it","purpose":"The eval's real email: 200 messages sampled from Enron lawyers' mailboxes and labelled by hand (50 dev, 150 held out). Eight of them are the public sample set in the demo."},{"name":"Harborline synthetic set","url":null,"license":"Synthetic, written for Decosa (CC0); fictional people and .example domains","purpose":"28 emails with labels and expected flags: an exact duplicate, a near-duplicate draft, advice forwarded to an outside consultant and to a personal account, a lawyer only copied, the other side's settlement letter. Twelve are the demo sample."},{"name":"scripts/privilege_eval.py and docs/evals/privilege-log.md","url":null,"license":"Apache-2.0","purpose":"Rebuilds the split, runs both sets and the planted-leak set through the API, and writes the metrics, the repeat check and the cost per 1,000 documents."},{"name":"POST /record/verify","url":null,"license":"Apache-2.0","purpose":"Checks the signed record or ledger and names the first entry that was changed. The console also verifies it in your browser."}],"hardware":[{"tier":"1x RTX 5090 32 GB","fits":true,"notes":"Qwen3.8-27B NVFP4 needs about 20 GB of weights plus KV cache for a 12,000-character email (about 4k tokens). Estimate: same model and prompts as the measured card, not run here on a 5090."},{"tier":"1x RTX PRO 6000 Blackwell 96 GB","fits":true,"notes":"Measured on our server: the eval and the hosted demo ran on this card, shared with other services the whole time."}],"latency":[{"lane":"one document, direct route with logprobs (self-host configuration), 6 calls in flight","typical_ms":1400,"source":"measured on our server 2026-09-25: 149 held-out Enron emails in 215 s on a shared card (about 5 calls per document)"},{"lane":"12-email demo sample, hosted gateway route (privilege call sampled 5 times, about 9 calls per document)","typical_ms":121000,"source":"measured on our server 2026-09-25: 85-135 s over 5 runs with the gateway quiet; 938 s once while other evaluation jobs loaded the shared gateway"},{"lane":"12-email demo sample, self-hosted (clean clone, container build, direct route with logprobs)","typical_ms":17000,"source":"measured on our server 2026-09-25: 58 calls, one run"}],"benchmark":null,"notes":["Withhold or produce is decided on p(privileged) = 1 - p(not privileged), not on the most likely option: attorney-client and 'both' overlap, so a document the model is sure is privileged can split its probability between them. Withhold at 0.7 or more, produce at 0.3 or less, and a lawyer decides in between. The band was set on the 50-email dev split and not changed after the held-out run.","A document also goes to review when an outsider or a personal account is on a possibly privileged document (waiver), when the element answers disagree with the call, when a privileged call has no confirmed lawyer on it, when a near-duplicate was called differently, or when a document that would be produced contains most of a withheld one's words.","Exact copies are judged once and get the same call; each copy's entry says so. Threads with both withheld and produced messages are fine unless a produced message quotes a withheld one, which sends it to review.","The leak check runs on every drafted description: a run of 6 or more words copied from the document, a figure from it, or wording that reports the advice ('advising that ...') is a leak, and a typed judge catches paraphrases. A leaky draft is rewritten once with the findings; if that one leaks too, a fixed generic description is used and the entry says so.","The people map is only as good as the lawyer list and domains you give it: a lawyer missing from the list is treated as an employee, and signature blocks that look like a lawyer's are shown as suggestions to confirm, never used on their own.","Attachments are judged as their own documents; send them with parent_id or family_id so the family check can compare them."]},"buyer_facts":[{"label":"Data retention","value":"Documents are held in memory for the request; the run (calls, log, no document text) for one hour, for the token or key that made it. Nothing is written to disk; logs carry counts only."},{"label":"What leaves the box","value":"Self-hosted: nothing. Hosted demo: the documents go to the model through our gateway, which is why the hosted demo is for the sample sets only."},{"label":"Model cost per 1,000 documents","value":"A dollar or two per thousand documents on the direct route at the gateway's list price (measured); GPU time only when self-hosted."},{"label":"Input","value":"Emails or memos as JSON: id, date, from, to, cc, bcc, subject, body, thread_id, family_id, parent_id, bates. Up to 25 per request hosted, 12,000 characters each; set DECOSA_PRIVILEGE_MAX_DOCS on your own box."},{"label":"Output","value":"Per document: withhold / produce / needs review, p(privileged), the lawyers, a grounded reason and flags. A Rule 26(b)(5)(A) log as CSV, a review memo, a signed record and a signed ledger of each lawyer's decision."}],"data_handling":{"page":"/data#privilege-log","self_host":{"level":"confidential","leaves":"nothing","summary":"Runs on your machine; nothing is sent to Decosa or a third party by default."},"hosted":{"level":"operator-processed","demo_only":true,"summary":"Hosted demo on sample or public data only; self-host for real data.","gpus":"operator-contracted","third_parties":[],"retention":"Documents are held in memory for the request; the run (calls, log, no document text) for one hour, for the token or key that made it. Nothing is written to disk; logs carry counts only.","used_for_training":false,"encrypted_while_processed":false},"sealed_tier":{"applies":false,"note":"The sealed tier (raw chat only, never use-case pipelines) is paused at launch (/docs/sealed-tier)."},"external_calls":[]},"console":{"href":"/legal/privilege-log","input":"privilege","lanes":[{"id":"calls","title":"Calls","kind":"list"},{"id":"consistency","title":"Consistency","kind":"list"},{"id":"log","title":"Privilege log","kind":"list"},{"id":"record","title":"Signed record","kind":"json"}],"samples":[{"n":1,"id":"harborline-dispute","title":"Harborline dispute","deep_link":"/legal/privilege-log?sample=1&autorun=0"},{"n":2,"id":"enron-legal","title":"Enron legal","deep_link":"/legal/privilege-log?sample=2&autorun=0"}],"deep_link_params":{"sample":"1-based index into samples, or a sample id","autorun":"1 = start the run once the sample is loaded; 0 (default) = only preselect","reduce-motion":"1 = turn off animations"}},"api":{"base":"https://api.decosa.ai","contract":"/api/contract.json","contract_markdown":"/api/contract.md","reference":"/docs/api","keys":"/account/keys"},"prompts":{"hosted":"/prompts/privilege-log-hosted.md","selfhost":"/prompts/privilege-log-selfhost.md","assemble":"/prompts/privilege-log-assemble.md","mac":"/prompts/privilege-log-mac.md"},"rehearsal":{"bundle":"/samples/privilege-log.zip","bundle_url":"https://decosa.ai/samples/privilege-log.zip","folder":"/samples/privilege-log/","expected":"/samples/privilege-log/expected.json","files":["/samples/privilege-log/expected.json","/samples/privilege-log/inputs/emails.json","/samples/privilege-log/inputs/people.json"],"bytes":2805,"checks":["the general counsel's legal advice (HL-002) is withheld as privileged or sent to review","the ops update with a lawyer only copied (HL-021) is produced","HL-021 is flagged: a lawyer only copied","the forward to an outside consultant (HL-003) is flagged for its outside party","the second custodian's copy (HL-004) is judged once, as a copy of HL-002","every drafted log description passed the leak check","the log (CSV) lists the withheld advice and leaves out the produced ops update","the produced ops update is not on the privilege log","the signed record verifies","a record with its call counts changed no longer verifies","every model call has a signed receipt"],"licence":"Synthetic, written for Decosa (CC0): Harborline Freight, Calder & Voss LLP and every person are fictional.","about":"Four synthetic emails from the fictional Harborline Freight: the general counsel's legal advice on a lease, the same email kept by a second custodian, that advice forwarded to an outside consultant, and a weekly ops update with the general counsel only copied. The advice must be withheld (or sent to review), the ops update produced, the duplicate treated as one document, the forward flagged for its outside party, and the log must end in a signed record that verifies.","run":{"containers":"docker compose exec api python scripts/rehearse.py privilege-log","checkout":"python scripts/rehearse.py privilege-log --bundle privilege-log.zip --base-url http://127.0.0.1:8445","mac":".venv/bin/python scripts/rehearse.py privilege-log"},"guidance":"Set up with a coding agent (we recommend Claude Code with Claude Opus 5.5; any capable coding agent works) on mock data only, run the rehearsal until every check passes, then run your own data locally yourself. Never give the agent real data during setup."},"hardware_fit":{"check":"/self-host/hardware?use=privilege-log","data":"/api/hardware.json","tiers":[{"id":"lite","gpu_gb":57.6,"basis":"stack","unknown":[]},{"id":"standard","gpu_gb":57.6,"basis":"stack","unknown":[]},{"id":"wanted","gpu_gb":249.6,"basis":"estimate","unknown":[]},{"id":"alternate-fast-judge","gpu_gb":57,"basis":"estimate","unknown":[]}],"mac":{"fit":"full","memory_gb":32}},"links":{"page":"/legal/privilege-log","json":"/use-cases/privilege-log.json","metrics":"/metrics/privilege-log","console":"/legal/privilege-log","console_sample":"/legal/privilege-log?sample=1&autorun=0","stack":"/legal/privilege-log#stack","try_live":"/legal/privilege-log","watch":"/legal/privilege-log","build":"/legal/privilege-log#build","self_host":"/legal/privilege-log#self-host","prompts":{"hosted":"/prompts/privilege-log-hosted.md","selfhost":"/prompts/privilege-log-selfhost.md","assemble":"/prompts/privilege-log-assemble.md","mac":"/prompts/privilege-log-mac.md"}}}