{
  "checkedAt": "2026-09-21T20:48:36.824433+00:00",
  "mode": "Codex comparison and disposition; not provider output",
  "rows": [
    {
      "candidate": "DisclosurePolicy / permission",
      "currentId": "vr.wm-xct-002",
      "catalogueId": "WM-XCT-002",
      "version": "0.3.0-research.1",
      "status": "published",
      "installable": true,
      "researchAssurance": "reviewable-draft",
      "specUrl": "https://ver.cy/models/wm-xct-002-access-contract-consent/spec.yaml",
      "specDigest": "sha256:9085d977567f3e1fc0b9bb27c6a7c517139f5972a1b95bf4a2bedccdb10bf2db",
      "relation": "overlap",
      "decision": "Reference permission evidence only; current grant evaluation belongs to the host.",
      "runtimeImport": false,
      "typeConformanceVerified": false,
      "losses": "No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.",
      "fullSpecificationBytesCompared": true,
      "semanticReading": "Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.",
      "findingInventory": [
        "grantor-authority-basis",
        "grantee-designation",
        "party-functional-roles",
        "scope-clause-selection",
        "data-category-sensitivity",
        "purpose-specification",
        "permitted-action-read-semantics",
        "constraints-validity-window",
        "obligations-and-duties",
        "consent-validity-elements",
        "consent-capture-context",
        "consent-record-and-proof",
        "receipt-and-portability",
        "contract-state-model",
        "temporal-semantics",
        "amendment-versioning-reconsent",
        "revocation-and-withdrawal",
        "propagation-and-erasure",
        "entitlement-cutoff",
        "coverage-decision-exchange",
        "fail-closed-handling",
        "multi-grant-conflict",
        "record-provenance-integrity",
        "instrument-identity",
        "retention-of-records",
        "access-to-contract-record",
        "standards-alignment-map",
        "jurisdictional-parameters",
        "instrument-flavour-classification"
      ],
      "selectedFindingIds": [],
      "publicationHolds": [
        "Source liveness and version pinning is unverified for all nineteen accepted sources. Two specific reconciliations are mandatory before publication: pin FHIR Consent to the version-qualified R5 URL rather than the unversioned current URL that will drift, and reconcile the two DPVCG 27560-guide citations that disagree on both host and date (w3c-cg.github.io retrieved 2026-08-23 versus w3id.org Final Community Group Report 15 February 2026).",
        "Domain-profile validation is incomplete. The model has been exercised only against EU/GDPR, the US health sector under 45 CFR 164.508, and a healthcare FHIR profile. At least one non-health, non-EU jurisdiction profile must be run end to end before publication to test whether the instrument-form and flavour parameters actually generalise.",
        "Normative text for ISO/IEC TS 27560:2023 and ISO/IEC 29184:2020 is paywalled; field inventories rest on catalogue pages plus the DPVCG mapping rather than annex text. TS 27560 is a Technical Specification, not an International Standard, and a revision (CD 27560.2) may change mandatory fields. Any field-level claim must be labelled as mapping-derived.",
        "The security dimension is self-declared a gap by the base (key management, token binding, replay resistance, cryptographic proof suites). Now that entitlement cutoff is imported, publication must name the sibling security model that owns these and state plainly that this model does not close them.",
        "Collective, community and Indigenous group permission is unsupported by any source in either pack and must be published as an explicitly unmodelled gap, never approximated through the delegate capacity."
      ]
    },
    {
      "candidate": "DisclosurePolicy / shape",
      "currentId": "vr.wm-xct-003",
      "catalogueId": "WM-XCT-003",
      "version": "0.3.0-research.1",
      "status": "published",
      "installable": true,
      "researchAssurance": "reviewable-draft",
      "specUrl": "https://ver.cy/models/wm-xct-003-projection-disclosure-policy/spec.yaml",
      "specDigest": "sha256:058191fe49bd1a52d52669211893d91971511f33a2aad1f15407e409d2553edb",
      "relation": "overlap",
      "decision": "Reference the exact shape record; no subtype or runtime transformation claim.",
      "runtimeImport": false,
      "typeConformanceVerified": false,
      "losses": "No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.",
      "fullSpecificationBytesCompared": true,
      "semanticReading": "Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.",
      "findingInventory": [
        "selection-scope-and-defaults",
        "path-expression-and-addressing",
        "graph-extent-and-nested-shape",
        "treatment-technique-and-parameters",
        "reversibility-and-recoding",
        "population-and-record-scope",
        "aggregation-grain-declaration",
        "leaving-shape-grain-class",
        "shape-narrowing-and-combination",
        "compiled-template-and-fingerprint",
        "source-schema-binding-and-drift",
        "encoding-and-media-profile",
        "residual-disclosure-and-side-channels",
        "binding-target-and-audience",
        "applicability-conditions",
        "class-to-treatment-matrix",
        "regime-mandated-shapes",
        "element-identifiability-roles",
        "assurance-method-and-evidence",
        "release-set-linkability",
        "policy-expression-crosswalk",
        "selective-disclosure-protocol-fit",
        "self-applied-policy-projection",
        "disclosure-change-classification",
        "served-output-reproducibility",
        "shape-invalidation-signals"
      ],
      "selectedFindingIds": [
        "selection-scope-and-defaults",
        "graph-extent-and-nested-shape",
        "source-schema-binding-and-drift",
        "residual-disclosure-and-side-channels",
        "binding-target-and-audience",
        "class-to-treatment-matrix",
        "release-set-linkability",
        "shape-invalidation-signals"
      ],
      "publicationHolds": [
        "Source verification hold: re-check live URLs, version pins and current status for all 14 base sources and the Grok sources backing the accepted additions before publication. ISO/IEC 20889 and 27559 are paywalled and were not read in full, the JSON Schema 2020-12 core document is an expired Internet-Draft, DPV 2.1 is Community Group output, and the XACML Multiple Decision Profile is a committee draft; each must be re-tiered or replaced if it has moved.",
        "Multi-profile validation hold: the merged structure has not been exercised against one instance per accepted grain class (record-level subset, named summary, aggregate-only) nor against a non-JSON medium such as a tabular extract, an RDF graph or free text. Until that is done, the selection and graph-extent findings are asserted to generalise, not shown to.",
        "Jurisdictional profile hold: only US federal and EEA sources were gathered. Regime-mandated-shapes, the identifiability roles and the assurance-method claims must be published as US/EEA-evidenced only, with no implied applicability to APPI, LGPD, DPDP, PIPL or UK DPA regimes.",
        "Ownership gap hold: record-level expert-determination evidence has no named owning model. WM-XCT-005 is scoped to cohort floors and aggregation assurance, so a non-aggregate shape's assurance evidence currently has no home; publish only with this stated as unresolved or after an owner is assigned.",
        "Cross-model retention hold: legal-hold precedence across WM-XCT-004 audit-entry disposition, WM-DAT-004 and Dimension source-data erasure, and WM-KNW-012 destruction of the policy record is unrecorded, so a hold in one owner may strand a tombstone in another. Publish only with the missing precedence explicit."
      ]
    },
    {
      "candidate": "ClassificationAssignment",
      "currentId": "vr.wm-xct-020",
      "catalogueId": "WM-XCT-020",
      "version": "0.3.0-research.1",
      "status": "published",
      "installable": true,
      "researchAssurance": "reviewable-draft",
      "specUrl": "https://ver.cy/models/wm-xct-020-classification-binding/spec.yaml",
      "specDigest": "sha256:47aa90ca48b7e367f61c30e454fd7859ba2dc7e2b998bbd4541acb6eda81b9bd",
      "relation": "overlap",
      "decision": "Reference exact binding records; no scheme authoring, classification judgment or access grant.",
      "runtimeImport": false,
      "typeConformanceVerified": false,
      "losses": "No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.",
      "fullSpecificationBytesCompared": true,
      "semanticReading": "Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.",
      "findingInventory": [
        "binding-as-reified-assertion",
        "classification-vs-typing-boundary",
        "subject-and-scope-of-application",
        "binding-identifier-and-keys",
        "scheme-and-term-reference-identity",
        "lexical-form-and-language",
        "binding-slot-declaration",
        "permitted-value-space",
        "value-set-slot-binding-reference",
        "binding-strength",
        "multiplicity-and-completeness",
        "asserted-term-and-role",
        "origin-of-binding-assertion",
        "classification-facet-axis",
        "residual-and-unclassifiable-handling",
        "uncoded-text-fallback",
        "assignment-actor-and-method",
        "evidence-and-justification",
        "assignment-authority-and-legal-effect",
        "scheme-custodianship-and-jurisdiction",
        "confidence-and-uncertainty",
        "coding-quality-measurement",
        "temporal-frames-of-a-binding",
        "scheme-version-drift-and-migration",
        "binding-lifecycle-states",
        "supersession-correction-and-dispute",
        "binding-validation-rules",
        "conflict-and-consistency-detection",
        "mapping-derived-bindings",
        "exchange-projection-and-round-trip",
        "parallel-codings-and-translation-set",
        "sensitive-binding-access-and-erasure"
      ],
      "selectedFindingIds": [
        "binding-as-reified-assertion",
        "scheme-and-term-reference-identity",
        "multiplicity-and-completeness",
        "assignment-authority-and-legal-effect",
        "temporal-frames-of-a-binding",
        "supersession-correction-and-dispute",
        "sensitive-binding-access-and-erasure"
      ],
      "publicationHolds": [
        "Source verification hold: every accepted source URL must be re-fetched live and version-pinned before publication, including canonicalising the two FHIR R5 URL variants (hl7.org/fhir/terminologies.html versus hl7.org/FHIR/terminologies.html; datatypes.html versus R5/datatypes.html) and adopting the dated DCMI 2020-01-20 URL over the undated latest URL.",
        "Paywalled ISO normative text hold: ISO/IEC TR 11179-2:2019, ISO/IEC 11179-1:2023 and its Part 3 classification package, and ISO 25964-1/-2 were cited from catalogue abstracts, Part 1 terms or NISO-hosted material. Clause-level obligations are unverified and no conformance-sounding claim may be published against them.",
        "Unparsed primary-source hold: the UNSD Best Practice Guidelines PDF and the SDMX Section 2 Information Model PDF could not be machine-parsed in the base run; exhaustiveness, mutual-exclusivity and SDMX hierarchy claims must be re-verified against parsed text before publication.",
        "Multi-profile validation hold: the pattern is validated against health terminology, EU customs rulings, EU statistics and cataloguing profiles only. At least one non-EU legal ruling regime and one commercial product-taxonomy or multi-label machine-learning profile must be run before any general-applicability claim.",
        "Sibling dependency hold: the Classification Scheme, Value Set and Mapping/Correspondence models are unregistered, so REFERENCE composition links point at non-existent registry entries. The entry may publish as a research draft but not as production-ready.",
        "Evidence-gap disclosure hold: confidence semantics, calibration and acceptance thresholds must be published as an explicit declared gap with a non-comparability warning, never as canonical structure.",
        "XKOS citation hold: one provider reported a 404 on a W3C-hosted XKOS URL while the base cites the DDI Alliance URL; the surviving citation must be confirmed live and its revision date pinned."
      ]
    },
    {
      "candidate": "ProjectionContract / source schema",
      "currentId": "vr.wm-dat-004",
      "catalogueId": "WM-DAT-004",
      "version": "0.3.0-research.1",
      "status": "published",
      "installable": true,
      "researchAssurance": "reviewable-draft",
      "specUrl": "https://ver.cy/models/wm-dat-004-data-schema-data-contract/spec.yaml",
      "specDigest": "sha256:0c6fc7db12c33efe0d9283b5830b4c679935dd5b640417e7e315a564b4971c94",
      "relation": "overlap",
      "decision": "Reference exact source schema; no copied generic schema model or instance compiler.",
      "runtimeImport": false,
      "typeConformanceVerified": false,
      "losses": "No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.",
      "fullSpecificationBytesCompared": true,
      "semanticReading": "Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.",
      "findingInventory": [
        "f-contract-identifier",
        "f-governed-subject",
        "f-dialect-and-vocabulary",
        "f-version-designation",
        "f-contract-status",
        "f-ownership-stewardship",
        "f-object-property-structure",
        "f-keys-and-relationships",
        "f-composition-references-and-shape-targets",
        "f-logical-physical-types",
        "f-encoding-temporal-conventions",
        "f-term-value-domain-binding",
        "f-structural-value-constraints",
        "f-cross-field-constraints",
        "f-quality-rule-declaration",
        "f-validation-outcome-report",
        "f-compatibility-mode",
        "f-schema-resolution-defaults",
        "f-canonical-form-and-fingerprint",
        "f-change-approval-process",
        "f-deprecation-and-sunset",
        "f-producer-consumer-parties",
        "f-obligations-acceptance",
        "f-declared-access-roles",
        "f-service-levels-support",
        "f-classification-privacy-terms",
        "f-server-serialization-binding",
        "f-contract-provenance",
        "f-registry-publication",
        "f-standard-alignment-mapping",
        "f-profile-jurisdictional-conformance"
      ],
      "selectedFindingIds": [
        "f-dialect-and-vocabulary",
        "f-object-property-structure",
        "f-composition-references-and-shape-targets",
        "f-canonical-form-and-fingerprint",
        "f-classification-privacy-terms"
      ],
      "publicationHolds": [
        "Live-URL and version-pin verification for the full merged source register is outstanding. Claude's three ODCS citations use 'latest' URLs annotated v3.1.0 while Grok cites the immutable v3.1.0 path; all ODCS references must be repinned to the versioned URL and refetched before publication, and the newly introduced OpenAPI 3.1.1 and ISO/IEC 11179-31:2023 entries must be fetch-verified and tier-assigned.",
        "Direct contradiction about ODCS v3.1.0 field status: Claude's f-governed-subject describes the governed subject as expressed through domain, dataProduct and tenant, while Grok states v3.1.0 deprecated the dataProduct field. This does not block a research draft, but f-governed-subject must not be published naming dataProduct as a live binding mechanism until the v3.1.0 text is reread.",
        "ISO/IEC 11179-3:2023 and 11179-31:2023 were verified only at catalogue-record level because the full texts are paywalled. Every 11179-derived construct (administered item, data element concept, conceptual domain, value domain, registration authority, registration status) must be published as an alignment hypothesis with no clause-level conformance claim.",
        "Domain-profile validation is incomplete. The model has been exercised against a generic enterprise profile and the European public-sector profile (DCAT-AP 3.0.0) only. It must be run against at least one regulated sector profile - clinical, financial reporting or geospatial - before any multi-profile coverage claim, since such regimes may mandate elements this model treats as optional.",
        "The spatial and data-residency dimension is a declared gap in both providers. Publication must state the gap explicitly and must not present server and environment binding as satisfying residency coverage.",
        "The accepted f-declared-access-roles finding must be reviewed at publication to confirm it reads as declaration only. If it drifts into entitlement grants, authentication or key management it breaches the base out-of-scope statement and must be cut back rather than published."
      ]
    },
    {
      "candidate": "DisclosurePolicy / governed policy",
      "currentId": "vr.wm-knw-012",
      "catalogueId": "WM-KNW-012",
      "version": "0.3.0-research.1",
      "status": "published",
      "installable": true,
      "researchAssurance": "reviewable-draft",
      "specUrl": "https://ver.cy/models/wm-knw-012-policy-rule/spec.yaml",
      "specDigest": "sha256:b7a880e4e07b26f8962e8d3b5b23b33c1062abcb83303ff8f0e8b5a3134e61b8",
      "relation": "overlap",
      "decision": "Reference governed policy/authority context; no execution or combining language.",
      "runtimeImport": false,
      "typeConformanceVerified": false,
      "losses": "No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.",
      "fullSpecificationBytesCompared": true,
      "semanticReading": "Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.",
      "findingInventory": [
        "statement-identifier-and-naming",
        "version-identity-and-point-in-time",
        "deontic-modality-force-and-defeasibility",
        "instrument-genre-and-binding-form",
        "issuing-authority-and-mandate",
        "ownership-stewardship-and-roles",
        "jurisdiction-and-territorial-scope",
        "subject-target-action-and-context-scope",
        "rule-slot-inventory-and-atomicity",
        "policy-set-containment-and-inheritance",
        "constraint-expression-binding",
        "parameterization-and-tailoring-values",
        "defined-terms-and-vocabulary-binding",
        "combining-and-hit-policy-declaration",
        "override-and-superiority-relations",
        "derogation-and-waiver-declaration",
        "declared-conflicts-and-alternatives",
        "policy-lifecycle-state-model",
        "amendment-supersession-and-repeal",
        "validity-intervals-and-record-time",
        "authoring-derivation-and-source-mapping",
        "statement-quality-and-review-status",
        "conformance-and-standard-alignment",
        "record-classification-access-and-retention"
      ],
      "selectedFindingIds": [
        "version-identity-and-point-in-time",
        "issuing-authority-and-mandate",
        "constraint-expression-binding",
        "combining-and-hit-policy-declaration",
        "validity-intervals-and-record-time",
        "record-classification-access-and-retention"
      ],
      "publicationHolds": [
        "Live source and version verification hold: before publication, confirm every accepted source URL resolves and pin a version for the three access-dated entries that currently carry no version token — SRC-010 (OSCAL catalog concepts), SRC-011 (ELI framework pages) and SRC-012 (ODRL Formal Semantics editor's draft, non-normative). Any source that cannot be resolved and pinned must be downgraded and the nodes resting on it re-checked for remaining primary support.",
        "Single-provider hold: every publication artifact must carry a visible notice that this result was produced by Claude alone and received no independent second-provider review, naming the repository owner's waiver of Grok effective 2026-08-29T09:06:27Z and its stated reason (repeated structured-output failures). The artifact stays a reviewable draft, not a validated model, for as long as that waiver stands.",
        "Timestamp-rule verification hold: SRC-009 is registered as RFC 3339 'updated by RFC 9557', but RFC 9557 is not itself a registered source while the canonicalization and artifact timestamp rules depend on the exact unknown-local-offset clause. Either register the updating RFC and confirm the -00:00 convention survives it, or restate the rule against the pinned RFC 3339 text before freezing the hashing rule.",
        "Boundary-review hold: the frozen registry carries status 'candidate' and review_state 'boundary-review-required', and this audit reclassifies the subject-model entry kind from entity to aggregate on the strength of the service-layer invariants. Publication must surface both the outstanding boundary review and the reclassification, so no downstream consumer treats the entry kind as settled.",
        "Paywalled-source hold: SRC-013 (ISO 37301:2021) grounds lifecycle currency, ownership and compliance-boundary claims but is behind a paywall. Confirm that the cited structure is supported by publicly verifiable scope material or by a licensed reading on record; if neither, downgrade the affected notes to partial support rather than leaving an uncheckable tier-1 citation in a public draft.",
        "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft."
      ]
    },
    {
      "candidate": "RetentionConstraint",
      "currentId": "vr.wm-xct-035",
      "catalogueId": "WM-XCT-035",
      "version": null,
      "status": "todo",
      "installable": false,
      "specDigest": null,
      "relation": "research-target",
      "decision": "Documented deferral; custodyContext is an opaque host-owned evidence pin, not an executable 035 dependency.",
      "runtimeImport": false,
      "losses": "No retention schedule/hold evaluator, disposition execution or destruction evidence implemented."
    }
  ],
  "composition": {
    "runtimeImports": [],
    "semanticReferences": [
      "vr.wm-xct-002",
      "vr.wm-xct-003",
      "vr.wm-xct-020",
      "vr.wm-dat-004",
      "vr.wm-knw-012",
      "vr.wm-xct-035"
    ],
    "packageContents": "Original metadata-only prototype; parent specs preserved as comparison evidence, not imported types."
  },
  "otherNeighbors": "005 is a legacy non-installable entry; 038 is an unversioned todo. No executable delegation. See adjacent-model-checks.json."
}
