# Independent final-package audit: Enterprise Disclosure Review 0.1.0, EM-XCT-05 No tools, code execution, web, file access or external communication. Review this frozen original metadata-only companion contract, semantic tree, reference and native harness. Every listed file is supplied completely below. JSON-compatible YAML and JSON are compact-rendered with unchanged parsed values; original byte hashes are provided, not claimed verified by you. Do not infer any external toolchain/source behavior from its pinned name/hash. Toolchain bytes are not supplied. Tests/native reports are executed Codex evidence, not your execution. No provider opinions are included; this is an independent full-package audit after the separate research/prototype stages. Return ACCEPT WITH LIMITS, REVISE or BLOCK for this bounded reviewable-draft reference, with concrete file/function anchors, witnesses and minimal fixes. Distinguish local defects/contradictory claims from explicit trusted-host duties and deferred domain scope. Check two-object identity, immutable revisions, time, digest encoding, active/superseded/withdrawn sets, conflict/mastership, scalar metadata boundaries, exact pins, all five facets, 24 question routes, disposition of external policy/classification/custody, bounds/migration, negative evidence and explicit V3-envelope-versus-nested-validation. A local metadata review is never a source-value serving grant or privacy proof. Do not demand implemented production systems merely because they are explicitly out of scope; do challenge an inaccurate guarantee or unsafe claimed use. Verify completeness and list files actually read/truncation. State your unverified scope. External opinions do not confer or remove the owner's publication authority. This final candidate changes the prototype version to 0.1.0, versions snapshots and evaluator answers, adds unconditional schema/version guards, immediate supersession identity checks, inspection identity-type check, distinct time exclusion reasons, precise reference-closure/retention limitations, structured semantic docs and native storage functions. Existing prototype evidence is not relabeled as review of these new bytes. ## FILE acceptance-results.json ORIGINAL SHA256 2fbc5bee1068199525978faaa78079ab30c8b6763d69a98e8930d36d0e49ade6 {"format":"vercy-disclosure-native-acceptance","executedAt":"2026-09-21T21:42:53Z","passed":3,"failed":0,"profiles":[{"profile":"startup","dimension":"urn:synthetic:dimension:startup","objects":2,"immutableRevisionFacts":3,"native":{"valid":true,"conformanceLevel":"V3","schemas":"https://ver.cy/schemas/dimension/1.0/","counts":{"objects":2,"facts":3,"relations":0,"events":0},"errors":[],"warnings":[{"rule":"V3-CURRENT-TRUTH-CONTESTED","location":"urn:synthetic:review:startup:disclosure.review.revision","message":"multiple current assertions remain visible; no value was guessed"}],"scope":"executable structure and record semantics; does not certify external truth, legal authority, or safety"},"sameVersionRoundtrip":true,"installedCompanionImportReplay":true,"historicalAndCurrentAnswers":[{"format":"vercy-disclosure-inspection","evaluatorVersion":"0.1.0","status":"applicable-review","notServingAuthorization":true,"proposal":{"id":"urn:synthetic:proposal:startup","revision":"1","digest":"sha256:c8dd8884a8a71580d7d2d6ead046218f8a2343dba0fe85d4605d2ab99befb46e"},"snapshotDigest":"sha256:bc1a18164e7a18738819e4d72711b2b59d07826abd079a4e57d236a3d2b7040b","at":"2026-09-21T12:00:00Z","reviewsEvaluated":true,"counted":[{"id":"urn:synthetic:review:startup","revision":"1","digest":"sha256:d6589f92d6d88c7c0bc38ed7ebbd52ec67efc31d9457524cbcab44e7f3148ca2"}],"ignored":[],"withdrawn":[]},{"format":"vercy-disclosure-inspection","evaluatorVersion":"0.1.0","status":"applicable-review","notServingAuthorization":true,"proposal":{"id":"urn:synthetic:proposal:startup","revision":"1","digest":"sha256:c8dd8884a8a71580d7d2d6ead046218f8a2343dba0fe85d4605d2ab99befb46e"},"snapshotDigest":"sha256:3e25ef4e6dd79172a222fa216a6dac5cf21885773fb3e281b61b69280f970edd","at":"2026-09-21T12:00:00Z","reviewsEvaluated":true,"counted":[{"id":"urn:synthetic:review:startup","revision":"2","digest":"sha256:f952daad4dfefe40e190deffe5880d5da442cfa55df77069d5353f61bddd2df5"}],"ignored":[],"withdrawn":[{"id":"urn:synthetic:review:startup","revision":"1","digest":"sha256:d6589f92d6d88c7c0bc38ed7ebbd52ec67efc31d9457524cbcab44e7f3148ca2"}]}],"negativeCasesRejected":["subject","path","revision-storage-key","digest","public-access","master","storage-authority","native-supersession","storage-before-assessment","storage-future","nested-invalid","object-type","cross-Dimension"],"invalidNestedFact":{"native":{"valid":true,"conformanceLevel":"V3","schemas":"https://ver.cy/schemas/dimension/1.0/","counts":{"objects":2,"facts":3,"relations":0,"events":0},"errors":[],"warnings":[{"rule":"V3-CURRENT-TRUTH-CONTESTED","location":"urn:synthetic:review:startup:disclosure.review.revision","message":"multiple current assertions remain visible; no value was guessed"}],"scope":"executable structure and record semantics; does not certify external truth, legal authority, or safety"},"companionRejected":true},"installationPin":{"id":"vr.profile.enterprise-disclosure-review","version":"0.1.0","specDigest":"sha256:0a0b6926ba2faab5b7ce72063397cdd27132fa747e7f9bcd8ef5ea18e09afa71"},"clockMeaning":"Current native storage of synthetic historical records; historical fixture answers use separately declared preserved snapshots, not a current serving decision."},{"profile":"matrix","dimension":"urn:synthetic:dimension:matrix","objects":2,"immutableRevisionFacts":3,"native":{"valid":true,"conformanceLevel":"V3","schemas":"https://ver.cy/schemas/dimension/1.0/","counts":{"objects":2,"facts":3,"relations":0,"events":0},"errors":[],"warnings":[{"rule":"V3-CURRENT-TRUTH-CONTESTED","location":"urn:synthetic:review:matrix:disclosure.review.revision","message":"multiple current assertions remain visible; no value was guessed"}],"scope":"executable structure and record semantics; does not certify external truth, legal authority, or safety"},"sameVersionRoundtrip":true,"installedCompanionImportReplay":true,"historicalAndCurrentAnswers":[{"format":"vercy-disclosure-inspection","evaluatorVersion":"0.1.0","status":"rejected","notServingAuthorization":true,"proposal":{"id":"urn:synthetic:proposal:matrix","revision":"1","digest":"sha256:30a923c06098c4d8e429817e47ac5b71a9831bf5045543fa70b80f3be4366e51"},"snapshotDigest":"sha256:b8c4d5ff6d97727d53041ca90b4400cf6457ac4cb359ff96c05a5361aa0b29b6","at":"2026-09-21T12:00:00Z","reviewsEvaluated":true,"counted":[{"id":"urn:synthetic:review:matrix","revision":"1","digest":"sha256:c8cd3848860a647fbe41b14ff7340b4cd5460ef5e25be805d4570fca3479c833"}],"ignored":[],"withdrawn":[]},{"format":"vercy-disclosure-inspection","evaluatorVersion":"0.1.0","status":"rejected","notServingAuthorization":true,"proposal":{"id":"urn:synthetic:proposal:matrix","revision":"1","digest":"sha256:30a923c06098c4d8e429817e47ac5b71a9831bf5045543fa70b80f3be4366e51"},"snapshotDigest":"sha256:30a15eb2509121e672999727ea1aebee2c482d10bf28f6118f3878158bdc5877","at":"2026-09-21T12:00:00Z","reviewsEvaluated":true,"counted":[{"id":"urn:synthetic:review:matrix","revision":"2","digest":"sha256:d50c70c124d6773888875389f24ba22d4ef9acb3fbd3d2c8b5de9462152d1899"}],"ignored":[],"withdrawn":[{"id":"urn:synthetic:review:matrix","revision":"1","digest":"sha256:c8cd3848860a647fbe41b14ff7340b4cd5460ef5e25be805d4570fca3479c833"}]}],"negativeCasesRejected":["subject","path","revision-storage-key","digest","public-access","master","storage-authority","native-supersession","storage-before-assessment","storage-future","nested-invalid","object-type","cross-Dimension"],"invalidNestedFact":{"native":{"valid":true,"conformanceLevel":"V3","schemas":"https://ver.cy/schemas/dimension/1.0/","counts":{"objects":2,"facts":3,"relations":0,"events":0},"errors":[],"warnings":[{"rule":"V3-CURRENT-TRUTH-CONTESTED","location":"urn:synthetic:review:matrix:disclosure.review.revision","message":"multiple current assertions remain visible; no value was guessed"}],"scope":"executable structure and record semantics; does not certify external truth, legal authority, or safety"},"companionRejected":true},"installationPin":{"id":"vr.profile.enterprise-disclosure-review","version":"0.1.0","specDigest":"sha256:0a0b6926ba2faab5b7ce72063397cdd27132fa747e7f9bcd8ef5ea18e09afa71"},"clockMeaning":"Current native storage of synthetic historical records; historical fixture answers use separately declared preserved snapshots, not a current serving decision."},{"profile":"ai","dimension":"urn:synthetic:dimension:ai","objects":2,"immutableRevisionFacts":3,"native":{"valid":true,"conformanceLevel":"V3","schemas":"https://ver.cy/schemas/dimension/1.0/","counts":{"objects":2,"facts":3,"relations":0,"events":0},"errors":[],"warnings":[{"rule":"V3-CURRENT-TRUTH-CONTESTED","location":"urn:synthetic:review:ai:disclosure.review.revision","message":"multiple current assertions remain visible; no value was guessed"}],"scope":"executable structure and record semantics; does not certify external truth, legal authority, or safety"},"sameVersionRoundtrip":true,"installedCompanionImportReplay":true,"historicalAndCurrentAnswers":[{"format":"vercy-disclosure-inspection","evaluatorVersion":"0.1.0","status":"applicable-review","notServingAuthorization":true,"proposal":{"id":"urn:synthetic:proposal:ai","revision":"1","digest":"sha256:7edbcf914ca751760e6d418deb693c46e130cfa1b76bce20474d6af610c3190e"},"snapshotDigest":"sha256:4db87c122345c704af72d7a31aafd990a177705f0f95b0a9c80b139d9fdb89ff","at":"2026-09-21T12:00:00Z","reviewsEvaluated":true,"counted":[{"id":"urn:synthetic:review:ai","revision":"1","digest":"sha256:3693032c70bbfecada292e6b8811ebc28bf7d4469fa476d8a4b7dd3831b28fee"}],"ignored":[],"withdrawn":[]},{"format":"vercy-disclosure-inspection","evaluatorVersion":"0.1.0","status":"applicable-review","notServingAuthorization":true,"proposal":{"id":"urn:synthetic:proposal:ai","revision":"1","digest":"sha256:7edbcf914ca751760e6d418deb693c46e130cfa1b76bce20474d6af610c3190e"},"snapshotDigest":"sha256:b13f109304a82f00d4e6ed473998c044d4b50a050795dbc803a08f3d8e9580ac","at":"2026-09-21T12:00:00Z","reviewsEvaluated":true,"counted":[{"id":"urn:synthetic:review:ai","revision":"2","digest":"sha256:bc41a889abaa2c6440f3b449b5860bd7c1665dad82a3edcae773e087db7073e1"}],"ignored":[],"withdrawn":[{"id":"urn:synthetic:review:ai","revision":"1","digest":"sha256:3693032c70bbfecada292e6b8811ebc28bf7d4469fa476d8a4b7dd3831b28fee"}]}],"negativeCasesRejected":["subject","path","revision-storage-key","digest","public-access","master","storage-authority","native-supersession","storage-before-assessment","storage-future","nested-invalid","object-type","cross-Dimension"],"invalidNestedFact":{"native":{"valid":true,"conformanceLevel":"V3","schemas":"https://ver.cy/schemas/dimension/1.0/","counts":{"objects":2,"facts":3,"relations":0,"events":0},"errors":[],"warnings":[{"rule":"V3-CURRENT-TRUTH-CONTESTED","location":"urn:synthetic:review:ai:disclosure.review.revision","message":"multiple current assertions remain visible; no value was guessed"}],"scope":"executable structure and record semantics; does not certify external truth, legal authority, or safety"},"companionRejected":true},"installationPin":{"id":"vr.profile.enterprise-disclosure-review","version":"0.1.0","specDigest":"sha256:0a0b6926ba2faab5b7ce72063397cdd27132fa747e7f9bcd8ef5ea18e09afa71"},"clockMeaning":"Current native storage of synthetic historical records; historical fixture answers use separately declared preserved snapshots, not a current serving decision."}],"sourceDigests":{"disclosure.py":"c08df6f075b801b8808a3db4da3d59e6519a2e6949bec6238f9361c5e3e54066","disclosure.schema.json":"45b2f2c82b9d9af72b2b462d3e502098fbd5b166bf8bd705947ba12e1e5cc834","acceptance.py":"764d27946ecf31295a2ad9fc78a6dc19fd3c5ded5cb9202b117e79da36217c98","test_disclosure.py":"dd35bec97e0965c739dbb6449069be5dfadfc8e71083ec679bb1cc9ab1dbdf22","spec.json":"0a0b6926ba2faab5b7ce72063397cdd27132fa747e7f9bcd8ef5ea18e09afa71","runtime-model.reference.json":"123dd5d1a1c64c0be5fbb0041d05d6e96f161b9d8e77eeb0aea69126eca152a6","tool-pins.json":"14d54b08bdbe854a00eda39b8643c73473445312bf2ea4902954eaf716bd9ae7"},"limits":"Three new synthetic Dimensions, explicit installed companion calls. No automatic dispatch, production source/policy/IAM/custody integration, concurrency, existing-Dimension migration or inferred privacy assurance."} END FILE acceptance-results.json ## FILE acceptance.py ORIGINAL SHA256 764d27946ecf31295a2ad9fc78a6dc19fd3c5ded5cb9202b117e79da36217c98 """Three synthetic native installations, explicit storage and nested validation.""" import argparse,copy,hashlib,importlib.util,json,sys,tempfile from datetime import datetime,timedelta,timezone from pathlib import Path import disclosure as d from test_disclosure import fixture HERE=Path(__file__).resolve().parent MID='vr.profile.enterprise-disclosure-review';SLUG='enterprise-disclosure-review' MASTER='urn:synthetic:disclosure-register';WRITER='urn:synthetic:storage-writer' def require(ok,message): if not ok:raise RuntimeError(message) def read(path):return json.loads(Path(path).read_text(encoding='utf-8')) def digest(path):return hashlib.sha256(Path(path).read_bytes()).hexdigest() def native_pair(record,at): object_record_id='urn:vercy:disclosure-object:'+hashlib.sha256(d.canonical({'dimension':record['dimension'],'id':record['id']})).hexdigest() obj={'recordType':'object','schemaVersion':'1.0.0','recordId':object_record_id,'objectId':record['id'],'objectType':MID+':'+record['type'],'name':'Synthetic '+record['type'],'description':'Independent information record; active storage does not mean review applicability','recordedAt':at,'previousRecordId':None,'state':'active','provenance':{'source':MASTER,'synthetic':True},'accessClass':'restricted'} fact={'recordType':'fact','schemaVersion':'1.0.0','factId':d.native_fact_id(record),'subjectId':record['id'],'path':'disclosure.'+record['type']+'.revision','value':record,'unit':None,'validFrom':at,'validTo':None,'recordedAt':at,'supersedes':[],'status':'asserted','provenance':{'source':MASTER,'synthetic':True,'recordDigest':record['digest']},'authority':{'source':WRITER,'rank':0},'masterSystem':MASTER,'accessClass':'restricted'} return obj,fact def run(composer,skill): composer=Path(composer).resolve();skill=Path(skill).resolve();pins=read(HERE/'tool-pins.json') for key,root in [('composerFiles',composer),('skillFiles',skill)]: for name,sha in pins[key].items():require(digest(root/name)==sha,'Changed trusted tool '+name) sys.path.insert(0,str(composer));import composition as c from bootstrap_dimension import bootstrap sys.path.insert(0,str(skill/'scripts'));from write_record import append from validate_dimension import validate as native_validate at=c.now();until=(datetime.now(timezone.utc)+timedelta(days=1)).strftime('%Y-%m-%dT%H:%M:%SZ');reports=[] with tempfile.TemporaryDirectory(prefix='vercy-disclosure-acceptance-') as tmp: root=Path(tmp);assets=root/'assets';assets.mkdir() def desc(name): raw=(HERE/name).read_bytes();dst=assets/SLUG/name;dst.parent.mkdir(exist_ok=True);dst.write_bytes(raw) return {'path':SLUG+'/'+name,'digest':c.digest(raw),'size':len(raw),'mediaType':'application/json' if name.endswith('.json') else 'text/x-python' if name.endswith('.py') else 'text/markdown','sourceUrl':'https://ver.cy/models/'+SLUG+'/versions/0.1.0/'+name} sd=desc('spec.json') release={'modelId':MID,'version':'0.1.0','namespace':'urn:vercy:model:'+MID,'role':'core','publicationStatus':'published','researchAssurance':'reviewable-draft','requires':[],'references':[],'specification':sd,'agents':desc('AGENTS.md'),'installationMode':'native-binding','binding':{'id':'urn:vercy:binding:enterprise-disclosure-review','version':'0.1.0','forSpecificationDigest':sd['digest'],'runtime':desc('runtime-model.reference.json'),'instanceSchema':desc('disclosure.schema.json'),'companionValidator':desc('disclosure.py'),'scope':'Own original metadata contract. Separate V3 envelope, explicit validate_native, full register import and inspect are mandatory; no automatic hook.'},'semanticFingerprint':None,'compatibility':{'decision':'accepted','reviewer':'urn:synthetic:reviewer:installation','evidence':'urn:synthetic:acceptance:disclosure','observedAt':at,'scope':'Synthetic candidate exercise only. Published is a catalogue lifecycle value in the fixture, not a claim the candidate is live.'}} for name in ('startup','matrix','ai'): proposal,review,snapshot,capability=fixture(name);dimension=proposal['dimension'];target=root/name;stage=root/(name+'-stage');policy_path=root/(name+'-policy.json');lock=root/(name+'-lock.json');plan_path=root/(name+'-plan.json') policy={'format':'vercy-composition-policy','version':1,'id':'urn:synthetic:policy:disclosure-installation','dimensionId':dimension,'owner':'urn:synthetic:owner:installation','allowInstall':True,'actors':['urn:synthetic:actor:composer'],'purposes':['Synthetic disclosure installation'],'allowedModelIds':[MID],'allowedOrigins':['https://ver.cy'],'reviewers':['urn:synthetic:reviewer:installation'],'allowReviewableDrafts':True,'validFrom':at,'validUntil':until} policy_path.write_bytes(c.encode(policy));lock.write_bytes(c.encode({'models':[]})) plan={'format':'vercy-composition-plan','schemaVersion':'1.0.0','planId':'urn:synthetic:composition:disclosure:'+name,'revision':1,'supersedes':None,'algorithm':'exact-closure-v1','dimensionId':dimension,'createdAt':at,'validUntil':until,'baseLockDigest':c.digest(lock.read_bytes()),'roots':[{'modelId':MID,'version':'0.1.0'}],'releases':[release],'authority':{'actor':policy['actors'][0],'allowReviewableDrafts':True,'allowedModelIds':[MID],'decision':'allow','owner':policy['owner'],'policyDigest':c.digest(policy_path.read_bytes()),'policyRef':policy['id'],'purpose':policy['purposes'][0]},'provenance':{'classification':'public-synthetic','evidenceKind':'proposal','masterSystem':MASTER,'recordedAt':at,'source':'urn:synthetic:fixture:'+name}} plan_path.write_bytes(c.encode(plan));c.stage(plan_path,assets,policy_path,lock,stage);bootstrap(stage,policy_path,lock,skill,target,'Synthetic disclosure '+name,dimension) installed=target/'models/composed'/SLUG/'disclosure.py' require(c.digest(installed.read_bytes())==release['binding']['companionValidator']['digest'],'Installed code differs') require(c.digest((installed.parent/'disclosure.schema.json').read_bytes())==release['binding']['instanceSchema']['digest'],'Installed schema differs') module_spec=importlib.util.spec_from_file_location('installed_disclosure_'+name,installed);module=importlib.util.module_from_spec(module_spec);module_spec.loader.exec_module(module) corrected=copy.deepcopy(review);corrected['revision']='2';corrected['body']['reviewedAt']='2026-09-21T10:02:00Z';corrected['body']['validFrom']='2026-09-21T10:02:00Z';corrected['body']['supersedes']=module.pin(review);corrected['body']['residualRisk']+=' Corrected explanation; no changed serving authority.';corrected=module.seal(corrected) records=module.import_records([],[proposal,review,corrected],dimension,capability) require(module.import_records(records,[corrected],dimension,capability)==records,'Import replay differs') objects={};stored=[];paths=[] def nested(f,o):return module.validate_native(f,o,dimension=dimension,capability=capability,now=at,master=MASTER,writer=WRITER) for i,record in enumerate(records): obj,fact=native_pair(record,at) if record['id'] not in objects: p=root/(name+'-object-'+str(i)+'.json');p.write_bytes(d.canonical(obj));append(target,'object',p);objects[record['id']]=obj p=root/(name+'-fact-'+str(i)+'.json');p.write_bytes(d.canonical(fact));result=append(target,'fact',p);actual=target/result['written'];paths.append(actual);saved=read(actual) require(nested(saved,objects[record['id']])==record,'Nested roundtrip differs');stored.append(saved['value']) require(module.import_records([],stored,dimension,capability)==records,'Stored register differs') old_answer=module.inspect(stored[0],[stored[1]],snapshot,capability,snapshot['asOf']) current=copy.deepcopy(snapshot);current['activeReviews']=[module.pin(corrected)];current['withdrawnReviews']=[module.pin(review)] answer=module.inspect(stored[0],[stored[2]],current,capability,current['asOf']);expected='rejected' if name=='matrix' else 'applicable-review' require(old_answer['status']==answer['status']==expected,'Stored assessments differ');require(answer['notServingAuthorization'] is True,'Serving boundary lost') native=native_validate(target);require(native['valid'],'Native envelope validation failed') fact=read(paths[-1]);obj=objects[fact['subjectId']];negatives=[] mutations=[('subject',lambda f:f.update(subjectId='urn:synthetic:wrong')),('path',lambda f:f.update(path='disclosure.proposal.revision')),('revision-storage-key',lambda f:f.update(factId='urn:synthetic:wrong')),('digest',lambda f:f['provenance'].update(recordDigest='sha256:'+'0'*64)),('public-access',lambda f:f.update(accessClass='public')),('master',lambda f:f.update(masterSystem='urn:synthetic:wrong')),('storage-authority',lambda f:f['authority'].update(rank=1)),('native-supersession',lambda f:f.update(supersedes=['urn:synthetic:old'])),('storage-before-assessment',lambda f:f.update(recordedAt='2020-01-01T00:00:00Z',validFrom='2020-01-01T00:00:00Z')),('storage-future',lambda f:f.update(recordedAt='2999-01-01T00:00:00Z',validFrom='2999-01-01T00:00:00Z')),('nested-invalid',lambda f:f['value']['body'].update(verdict='grant-access'))] for label,mutate in mutations: bad=copy.deepcopy(fact);mutate(bad);rejected=False try:nested(bad,obj) except module.Invalid:rejected=True require(rejected,'Accepted native '+label);negatives.append(label) bad=copy.deepcopy(fact);bad['value']['body']['verdict']='grant-access';original=paths[-1].read_bytes();paths[-1].write_bytes(d.canonical(bad)) try:outer=native_validate(target);require(outer['valid'],'Fixture must isolate nested semantic validation') finally:paths[-1].write_bytes(original) wrong=copy.deepcopy(obj);wrong['objectType']=MID+':proposal' try:nested(fact,wrong) except module.Invalid:negatives.append('object-type') else:raise RuntimeError('Accepted wrong object type') try:module.validate_native(fact,obj,dimension='urn:synthetic:other',capability={'dimension':'urn:synthetic:other','inspect':True},now=at,master=MASTER,writer=WRITER) except module.Invalid:negatives.append('cross-Dimension') else:raise RuntimeError('Accepted cross-Dimension') native.pop('dimension',None);outer.pop('dimension',None) reports.append({'profile':name,'dimension':dimension,'objects':2,'immutableRevisionFacts':3,'native':native,'sameVersionRoundtrip':True,'installedCompanionImportReplay':True,'historicalAndCurrentAnswers':[old_answer,answer],'negativeCasesRejected':negatives,'invalidNestedFact':{'native':outer,'companionRejected':True},'installationPin':{'id':MID,'version':'0.1.0','specDigest':sd['digest']},'clockMeaning':'Current native storage of synthetic historical records; historical fixture answers use separately declared preserved snapshots, not a current serving decision.'}) names=['disclosure.py','disclosure.schema.json','acceptance.py','test_disclosure.py','spec.json','runtime-model.reference.json','tool-pins.json'] return {'format':'vercy-disclosure-native-acceptance','executedAt':c.now(),'passed':len(reports),'failed':0,'profiles':reports,'sourceDigests':{n:digest(HERE/n) for n in names},'limits':'Three new synthetic Dimensions, explicit installed companion calls. No automatic dispatch, production source/policy/IAM/custody integration, concurrency, existing-Dimension migration or inferred privacy assurance.'} if __name__=='__main__': ap=argparse.ArgumentParser();ap.add_argument('--composer',required=True);ap.add_argument('--skill',required=True);ap.add_argument('--report',required=True);a=ap.parse_args();report=run(a.composer,a.skill);Path(a.report).write_text(json.dumps(report,indent=2)+'\n',encoding='utf-8',newline='\n');print(json.dumps({'passed':report['passed'],'failed':report['failed']})) END FILE acceptance.py ## FILE adoption-limits.md ORIGINAL SHA256 4d408a9a9255e08f4769f25651b1d777bdf1aa6353b3f4cada2e7d46dae2793c # Adoption limits Reviewable draft, metadata only. No authentication, IAM/grant evaluation, policy precedence, real source resolution, source-value projection, transformation, inference detection, privacy budget, recipient delivery, disposal engine, legal conclusion or standards conformance. A manual cleared verdict is an attributed opinion under exact context, never a privacy proof or serving authorization. The host supplies authentic actors and object-specific write authority, an independently resolved complete current snapshot, correct clock, complete local register, active/withdrawn history, actual distinct-person mapping, storage transactions and access/custody controls. All diagnostics are restricted; metadata and free-text notes may themselves be sensitive. The host must deactivate transitive superseded ancestors. Every verdict expires; persistent objections require another profile. Structural bounds are not enterprise-scale or hostile-input performance evidence. Native acceptance uses three new synthetic Dimensions and explicit companion validation. It does not prove automatic engine invocation, production storage correctness, real organizational governance or existing-Dimension conversion. Source/parent research holds remain in crosswalk.json. The broader classification, serving and retention contour stays partially covered. END FILE adoption-limits.md ## FILE agent-guide.md ORIGINAL SHA256 293c4013ed1b7bc2bdb5085f866fff566d4507e7d226bfcbb29c0dc9f7743007 # Agent use Read model-spec.md, spec.json and disclosure.schema.json. Identify the proposal, its exact source members and all bound context. Ask for missing facts by question ID; unknown is not permission. Seal and import only with host-approved write authority. Request a review from an authorized reviewer; preserve rejection/inconclusive/conflict rather than rewriting them. Use load() on wire bytes, validate() on each record, import_records() on the complete bounded register, validate_native() plus native envelope validation for stored facts, and inspect() only under an independently constructed trusted current snapshot. These operations do not fetch source data or contact people. Capability dictionaries are host assertions, never user-supplied credentials. Current access permission is required even for historical data. Return restricted diagnostics only to authorized internal consumers. Never forward them verbatim to recipients. Never infer serving rights, classification comparability, anonymity, source truth, successful delivery or destruction from hashes or review status. A documented proposed action in the question tree does not authorize its execution. Follow the organization's actual access, records and custody decisions. END FILE agent-guide.md ## FILE AGENTS.md ORIGINAL SHA256 293c4013ed1b7bc2bdb5085f866fff566d4507e7d226bfcbb29c0dc9f7743007 # Agent use Read model-spec.md, spec.json and disclosure.schema.json. Identify the proposal, its exact source members and all bound context. Ask for missing facts by question ID; unknown is not permission. Seal and import only with host-approved write authority. Request a review from an authorized reviewer; preserve rejection/inconclusive/conflict rather than rewriting them. Use load() on wire bytes, validate() on each record, import_records() on the complete bounded register, validate_native() plus native envelope validation for stored facts, and inspect() only under an independently constructed trusted current snapshot. These operations do not fetch source data or contact people. Capability dictionaries are host assertions, never user-supplied credentials. Current access permission is required even for historical data. Return restricted diagnostics only to authorized internal consumers. Never forward them verbatim to recipients. Never infer serving rights, classification comparability, anonymity, source truth, successful delivery or destruction from hashes or review status. A documented proposed action in the question tree does not authorize its execution. Follow the organization's actual access, records and custody decisions. END FILE AGENTS.md ## FILE bindings/native-v3.md ORIGINAL SHA256 47a23ba558451ff53fdafcf6ed80042ddbaaa8b0f9ee1cc06f18fa41545cb21c # Native V3 binding The original companion uses `vr.profile.enterprise-disclosure-review`; it does not inherit an access or classification model. Each ContextPackageProposal owns a native object of type `vr.profile.enterprise-disclosure-review:proposal`; each JointDisclosureReview owns a separate `:review` object. Native object ID equals the qualified record identity. Members/fields remain embedded in each proposal revision. Paths `disclosure.proposal.revision` and `disclosure.review.revision` carry one complete immutable record per fact. Use `native_fact_id()` for a storage ID derived from Dimension/id/revision. A different digest for the same identity/revision conflicts at immutable import; do not create a second storage key to conceal it. Native envelopes have unit null, asserted status, empty supersedes, no validTo, accessClass restricted and validity starting at the actual native storage receipt. Storage authority rank 0 identifies the trusted registrar, never the reviewer or permission to disclose. All revisions coexist. Review supersession is the record's own exact `body.supersedes` link; the complete current active set comes from an independent host snapshot. Generic native fact resolution may therefore show peers/contested results: it is not the active-review selector. Fetch the complete authorized register, not only a generic “latest” resolved fact. Current read permission applies to every historical record. Required sequence: authenticate and authorize through the host; validate the native object/fact envelopes with the pinned V3 runtime; call `validate_native(fact, object, dimension=..., capability=..., now=..., master=..., writer=...)`; call `import_records()` with the complete bounded register to enforce internal links, identity-type and immutable history; call `inspect()` with a separately resolved current snapshot. No API is a substitute for the others. V3 does not automatically invoke these companion functions. The native companion enforces object identity/type, Dimension, exact path, deterministic revision key, local record schema/digest, restricted class, storage master/writer/digest receipt, and ordered native object/record/evaluation times. It relies on separate native envelope validation for the complete outer schema and native object revision graph. It does not authenticate the input dictionaries, check a database transaction or enforce a recipient channel. Host clock skew and recovery affect every now/asOf-taking operation; do not silently rewrite receipt times. `acceptance.py` pins the toolchain, creates three temporary synthetic new Dimensions, installs exact specification/code/schema bytes, stores two independent objects and three immutable revision facts, imports and replays the installed companion, preserves an earlier assessment and checks a correction. It exercises 13 negative native cases per profile and demonstrates that an invalid nested verdict can pass the outer native schema while the companion rejects it. The historical fixture snapshot is separate from today's installation receipt; it is not evidence of prior real installation or present serving authority. No production source resolver, current-grant evaluator, persistent store/CAS, removal/retention operation, automatic dispatch or existing-Dimension adapter is supplied. Parent semantic comparisons are optional reading only and require no runtime installation. END FILE bindings/native-v3.md ## FILE boundary-decision.md ORIGINAL SHA256 65f8ca55641832da69e233872e248eee2246a9ce146a6efdc192ee3eeffc67a7 # Boundary decision and alternatives An original companion is narrower than the whole EM-XCT-05 contour. It exports exactly two independent record types: ContextPackageProposal and JointDisclosureReview. A proposal has its own durable identity and immutable revisions; a review has a separate owner, identity, correction chain and finite validity. Members, fields and pins are embedded values, not separately mastered objects. The result of inspect() is an ephemeral diagnostic, not a grant or a third persistent business type. One member refers to one source object. A package may combine different objects and multiple projections of the same object. A source aggregate must have its own domain identity, calculation and disclosure owner before appearing as a source pin. The review assesses the package; it does not calculate that aggregate. The independent studies proposed richer manifests, policy and retention objects. Those are deliberately not duplicated here. Classification scheme/term semantics remain behind exact binding references. Source schema and projection shape are opaque pins. IAM, source resolution, retention floors, disposal deadlines and holds are separate owned contracts; no executable delegation is invented to WM-XCT-035 or WM-XCT-038. Current custody context is bound, but no disposition state is calculated. Alternative: one combined permission/retention Boolean would lose attribution, conflicting verdicts and separate time axes. Alternative: copying every source object would create another master and increase disclosure. Alternative: treating every embedded field as a standalone object imposes needless lifecycle without an independent owner. Exact bounded immutable metadata plus an attributed review is the minimum chosen design, not a universal enterprise privacy ontology. The instance graph (proposal/review/source links), specification graph (semantic comparison only) and delivery graph (code/schema/docs/tests) remain distinct. Supersession must be acyclic; source business links may be cyclic outside this boundary. No mandatory runtime domain imports exist. END FILE boundary-decision.md ## FILE composition.yaml ORIGINAL SHA256 296ebaab4aac3a1baa45ee4a4f0cb4c742f5ee7d01b3a83bd6bd86004b60db78 {"runtimeImports":[],"semanticReferences":[{"id":"WM-XCT-002","version":"0.3.0-research.1","specDigest":"sha256:9085d977567f3e1fc0b9bb27c6a7c517139f5972a1b95bf4a2bedccdb10bf2db","relation":"selected-semantic-overlap-not-subtype"},{"id":"WM-XCT-003","version":"0.3.0-research.1","specDigest":"sha256:058191fe49bd1a52d52669211893d91971511f33a2aad1f15407e409d2553edb","relation":"selected-semantic-overlap-not-subtype"},{"id":"WM-XCT-020","version":"0.3.0-research.1","specDigest":"sha256:47aa90ca48b7e367f61c30e454fd7859ba2dc7e2b998bbd4541acb6eda81b9bd","relation":"selected-semantic-overlap-not-subtype"},{"id":"WM-DAT-004","version":"0.3.0-research.1","specDigest":"sha256:0c6fc7db12c33efe0d9283b5830b4c679935dd5b640417e7e315a564b4971c94","relation":"selected-semantic-overlap-not-subtype"},{"id":"WM-KNW-012","version":"0.3.0-research.1","specDigest":"sha256:b7a880e4e07b26f8962e8d3b5b23b33c1062abcb83303ff8f0e8b5a3134e61b8","relation":"selected-semantic-overlap-not-subtype"}],"delivery":"Original reference, closed schema, synthetic fixtures, contract and native binding; external pins are not executable imports."} END FILE composition.yaml ## FILE crosswalk.json ORIGINAL SHA256 360495b49f99f9d6d6791ecf6e107bbdf2cd47461db26c0f460a4a4034e25931 {"checkedAt":"2026-09-21T20:48:36.824433+00:00","mode":"Codex comparison and disposition; not provider output","rows":[{"candidate":"DisclosurePolicy / permission","currentId":"vr.wm-xct-002","catalogueId":"WM-XCT-002","version":"0.3.0-research.1","status":"published","installable":true,"researchAssurance":"reviewable-draft","specUrl":"https://ver.cy/models/wm-xct-002-access-contract-consent/spec.yaml","specDigest":"sha256:9085d977567f3e1fc0b9bb27c6a7c517139f5972a1b95bf4a2bedccdb10bf2db","relation":"overlap","decision":"Reference permission evidence only; current grant evaluation belongs to the host.","runtimeImport":false,"typeConformanceVerified":false,"losses":"No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.","fullSpecificationBytesCompared":true,"semanticReading":"Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.","findingInventory":["grantor-authority-basis","grantee-designation","party-functional-roles","scope-clause-selection","data-category-sensitivity","purpose-specification","permitted-action-read-semantics","constraints-validity-window","obligations-and-duties","consent-validity-elements","consent-capture-context","consent-record-and-proof","receipt-and-portability","contract-state-model","temporal-semantics","amendment-versioning-reconsent","revocation-and-withdrawal","propagation-and-erasure","entitlement-cutoff","coverage-decision-exchange","fail-closed-handling","multi-grant-conflict","record-provenance-integrity","instrument-identity","retention-of-records","access-to-contract-record","standards-alignment-map","jurisdictional-parameters","instrument-flavour-classification"],"selectedFindingIds":[],"publicationHolds":["Source liveness and version pinning is unverified for all nineteen accepted sources. Two specific reconciliations are mandatory before publication: pin FHIR Consent to the version-qualified R5 URL rather than the unversioned current URL that will drift, and reconcile the two DPVCG 27560-guide citations that disagree on both host and date (w3c-cg.github.io retrieved 2026-08-23 versus w3id.org Final Community Group Report 15 February 2026).","Domain-profile validation is incomplete. The model has been exercised only against EU/GDPR, the US health sector under 45 CFR 164.508, and a healthcare FHIR profile. At least one non-health, non-EU jurisdiction profile must be run end to end before publication to test whether the instrument-form and flavour parameters actually generalise.","Normative text for ISO/IEC TS 27560:2023 and ISO/IEC 29184:2020 is paywalled; field inventories rest on catalogue pages plus the DPVCG mapping rather than annex text. TS 27560 is a Technical Specification, not an International Standard, and a revision (CD 27560.2) may change mandatory fields. Any field-level claim must be labelled as mapping-derived.","The security dimension is self-declared a gap by the base (key management, token binding, replay resistance, cryptographic proof suites). Now that entitlement cutoff is imported, publication must name the sibling security model that owns these and state plainly that this model does not close them.","Collective, community and Indigenous group permission is unsupported by any source in either pack and must be published as an explicitly unmodelled gap, never approximated through the delegate capacity."]},{"candidate":"DisclosurePolicy / shape","currentId":"vr.wm-xct-003","catalogueId":"WM-XCT-003","version":"0.3.0-research.1","status":"published","installable":true,"researchAssurance":"reviewable-draft","specUrl":"https://ver.cy/models/wm-xct-003-projection-disclosure-policy/spec.yaml","specDigest":"sha256:058191fe49bd1a52d52669211893d91971511f33a2aad1f15407e409d2553edb","relation":"overlap","decision":"Reference the exact shape record; no subtype or runtime transformation claim.","runtimeImport":false,"typeConformanceVerified":false,"losses":"No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.","fullSpecificationBytesCompared":true,"semanticReading":"Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.","findingInventory":["selection-scope-and-defaults","path-expression-and-addressing","graph-extent-and-nested-shape","treatment-technique-and-parameters","reversibility-and-recoding","population-and-record-scope","aggregation-grain-declaration","leaving-shape-grain-class","shape-narrowing-and-combination","compiled-template-and-fingerprint","source-schema-binding-and-drift","encoding-and-media-profile","residual-disclosure-and-side-channels","binding-target-and-audience","applicability-conditions","class-to-treatment-matrix","regime-mandated-shapes","element-identifiability-roles","assurance-method-and-evidence","release-set-linkability","policy-expression-crosswalk","selective-disclosure-protocol-fit","self-applied-policy-projection","disclosure-change-classification","served-output-reproducibility","shape-invalidation-signals"],"selectedFindingIds":["selection-scope-and-defaults","graph-extent-and-nested-shape","source-schema-binding-and-drift","residual-disclosure-and-side-channels","binding-target-and-audience","class-to-treatment-matrix","release-set-linkability","shape-invalidation-signals"],"publicationHolds":["Source verification hold: re-check live URLs, version pins and current status for all 14 base sources and the Grok sources backing the accepted additions before publication. ISO/IEC 20889 and 27559 are paywalled and were not read in full, the JSON Schema 2020-12 core document is an expired Internet-Draft, DPV 2.1 is Community Group output, and the XACML Multiple Decision Profile is a committee draft; each must be re-tiered or replaced if it has moved.","Multi-profile validation hold: the merged structure has not been exercised against one instance per accepted grain class (record-level subset, named summary, aggregate-only) nor against a non-JSON medium such as a tabular extract, an RDF graph or free text. Until that is done, the selection and graph-extent findings are asserted to generalise, not shown to.","Jurisdictional profile hold: only US federal and EEA sources were gathered. Regime-mandated-shapes, the identifiability roles and the assurance-method claims must be published as US/EEA-evidenced only, with no implied applicability to APPI, LGPD, DPDP, PIPL or UK DPA regimes.","Ownership gap hold: record-level expert-determination evidence has no named owning model. WM-XCT-005 is scoped to cohort floors and aggregation assurance, so a non-aggregate shape's assurance evidence currently has no home; publish only with this stated as unresolved or after an owner is assigned.","Cross-model retention hold: legal-hold precedence across WM-XCT-004 audit-entry disposition, WM-DAT-004 and Dimension source-data erasure, and WM-KNW-012 destruction of the policy record is unrecorded, so a hold in one owner may strand a tombstone in another. Publish only with the missing precedence explicit."]},{"candidate":"ClassificationAssignment","currentId":"vr.wm-xct-020","catalogueId":"WM-XCT-020","version":"0.3.0-research.1","status":"published","installable":true,"researchAssurance":"reviewable-draft","specUrl":"https://ver.cy/models/wm-xct-020-classification-binding/spec.yaml","specDigest":"sha256:47aa90ca48b7e367f61c30e454fd7859ba2dc7e2b998bbd4541acb6eda81b9bd","relation":"overlap","decision":"Reference exact binding records; no scheme authoring, classification judgment or access grant.","runtimeImport":false,"typeConformanceVerified":false,"losses":"No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.","fullSpecificationBytesCompared":true,"semanticReading":"Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.","findingInventory":["binding-as-reified-assertion","classification-vs-typing-boundary","subject-and-scope-of-application","binding-identifier-and-keys","scheme-and-term-reference-identity","lexical-form-and-language","binding-slot-declaration","permitted-value-space","value-set-slot-binding-reference","binding-strength","multiplicity-and-completeness","asserted-term-and-role","origin-of-binding-assertion","classification-facet-axis","residual-and-unclassifiable-handling","uncoded-text-fallback","assignment-actor-and-method","evidence-and-justification","assignment-authority-and-legal-effect","scheme-custodianship-and-jurisdiction","confidence-and-uncertainty","coding-quality-measurement","temporal-frames-of-a-binding","scheme-version-drift-and-migration","binding-lifecycle-states","supersession-correction-and-dispute","binding-validation-rules","conflict-and-consistency-detection","mapping-derived-bindings","exchange-projection-and-round-trip","parallel-codings-and-translation-set","sensitive-binding-access-and-erasure"],"selectedFindingIds":["binding-as-reified-assertion","scheme-and-term-reference-identity","multiplicity-and-completeness","assignment-authority-and-legal-effect","temporal-frames-of-a-binding","supersession-correction-and-dispute","sensitive-binding-access-and-erasure"],"publicationHolds":["Source verification hold: every accepted source URL must be re-fetched live and version-pinned before publication, including canonicalising the two FHIR R5 URL variants (hl7.org/fhir/terminologies.html versus hl7.org/FHIR/terminologies.html; datatypes.html versus R5/datatypes.html) and adopting the dated DCMI 2020-01-20 URL over the undated latest URL.","Paywalled ISO normative text hold: ISO/IEC TR 11179-2:2019, ISO/IEC 11179-1:2023 and its Part 3 classification package, and ISO 25964-1/-2 were cited from catalogue abstracts, Part 1 terms or NISO-hosted material. Clause-level obligations are unverified and no conformance-sounding claim may be published against them.","Unparsed primary-source hold: the UNSD Best Practice Guidelines PDF and the SDMX Section 2 Information Model PDF could not be machine-parsed in the base run; exhaustiveness, mutual-exclusivity and SDMX hierarchy claims must be re-verified against parsed text before publication.","Multi-profile validation hold: the pattern is validated against health terminology, EU customs rulings, EU statistics and cataloguing profiles only. At least one non-EU legal ruling regime and one commercial product-taxonomy or multi-label machine-learning profile must be run before any general-applicability claim.","Sibling dependency hold: the Classification Scheme, Value Set and Mapping/Correspondence models are unregistered, so REFERENCE composition links point at non-existent registry entries. The entry may publish as a research draft but not as production-ready.","Evidence-gap disclosure hold: confidence semantics, calibration and acceptance thresholds must be published as an explicit declared gap with a non-comparability warning, never as canonical structure.","XKOS citation hold: one provider reported a 404 on a W3C-hosted XKOS URL while the base cites the DDI Alliance URL; the surviving citation must be confirmed live and its revision date pinned."]},{"candidate":"ProjectionContract / source schema","currentId":"vr.wm-dat-004","catalogueId":"WM-DAT-004","version":"0.3.0-research.1","status":"published","installable":true,"researchAssurance":"reviewable-draft","specUrl":"https://ver.cy/models/wm-dat-004-data-schema-data-contract/spec.yaml","specDigest":"sha256:0c6fc7db12c33efe0d9283b5830b4c679935dd5b640417e7e315a564b4971c94","relation":"overlap","decision":"Reference exact source schema; no copied generic schema model or instance compiler.","runtimeImport":false,"typeConformanceVerified":false,"losses":"No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.","fullSpecificationBytesCompared":true,"semanticReading":"Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.","findingInventory":["f-contract-identifier","f-governed-subject","f-dialect-and-vocabulary","f-version-designation","f-contract-status","f-ownership-stewardship","f-object-property-structure","f-keys-and-relationships","f-composition-references-and-shape-targets","f-logical-physical-types","f-encoding-temporal-conventions","f-term-value-domain-binding","f-structural-value-constraints","f-cross-field-constraints","f-quality-rule-declaration","f-validation-outcome-report","f-compatibility-mode","f-schema-resolution-defaults","f-canonical-form-and-fingerprint","f-change-approval-process","f-deprecation-and-sunset","f-producer-consumer-parties","f-obligations-acceptance","f-declared-access-roles","f-service-levels-support","f-classification-privacy-terms","f-server-serialization-binding","f-contract-provenance","f-registry-publication","f-standard-alignment-mapping","f-profile-jurisdictional-conformance"],"selectedFindingIds":["f-dialect-and-vocabulary","f-object-property-structure","f-composition-references-and-shape-targets","f-canonical-form-and-fingerprint","f-classification-privacy-terms"],"publicationHolds":["Live-URL and version-pin verification for the full merged source register is outstanding. Claude's three ODCS citations use 'latest' URLs annotated v3.1.0 while Grok cites the immutable v3.1.0 path; all ODCS references must be repinned to the versioned URL and refetched before publication, and the newly introduced OpenAPI 3.1.1 and ISO/IEC 11179-31:2023 entries must be fetch-verified and tier-assigned.","Direct contradiction about ODCS v3.1.0 field status: Claude's f-governed-subject describes the governed subject as expressed through domain, dataProduct and tenant, while Grok states v3.1.0 deprecated the dataProduct field. This does not block a research draft, but f-governed-subject must not be published naming dataProduct as a live binding mechanism until the v3.1.0 text is reread.","ISO/IEC 11179-3:2023 and 11179-31:2023 were verified only at catalogue-record level because the full texts are paywalled. Every 11179-derived construct (administered item, data element concept, conceptual domain, value domain, registration authority, registration status) must be published as an alignment hypothesis with no clause-level conformance claim.","Domain-profile validation is incomplete. The model has been exercised against a generic enterprise profile and the European public-sector profile (DCAT-AP 3.0.0) only. It must be run against at least one regulated sector profile - clinical, financial reporting or geospatial - before any multi-profile coverage claim, since such regimes may mandate elements this model treats as optional.","The spatial and data-residency dimension is a declared gap in both providers. Publication must state the gap explicitly and must not present server and environment binding as satisfying residency coverage.","The accepted f-declared-access-roles finding must be reviewed at publication to confirm it reads as declaration only. If it drifts into entitlement grants, authentication or key management it breaches the base out-of-scope statement and must be cut back rather than published."]},{"candidate":"DisclosurePolicy / governed policy","currentId":"vr.wm-knw-012","catalogueId":"WM-KNW-012","version":"0.3.0-research.1","status":"published","installable":true,"researchAssurance":"reviewable-draft","specUrl":"https://ver.cy/models/wm-knw-012-policy-rule/spec.yaml","specDigest":"sha256:b7a880e4e07b26f8962e8d3b5b23b33c1062abcb83303ff8f0e8b5a3134e61b8","relation":"overlap","decision":"Reference governed policy/authority context; no execution or combining language.","runtimeImport":false,"typeConformanceVerified":false,"losses":"No adapter claims to preserve all parent fields or rules. Opaque pins require an independent host resolver. All original holds remain.","fullSpecificationBytesCompared":true,"semanticReading":"Complete spec parsed and whole finding inventory inspected; boundary, exclusions, holds and selected exact findings/fields read. Full parent citation ratification and runtime implementation validation are not claimed.","findingInventory":["statement-identifier-and-naming","version-identity-and-point-in-time","deontic-modality-force-and-defeasibility","instrument-genre-and-binding-form","issuing-authority-and-mandate","ownership-stewardship-and-roles","jurisdiction-and-territorial-scope","subject-target-action-and-context-scope","rule-slot-inventory-and-atomicity","policy-set-containment-and-inheritance","constraint-expression-binding","parameterization-and-tailoring-values","defined-terms-and-vocabulary-binding","combining-and-hit-policy-declaration","override-and-superiority-relations","derogation-and-waiver-declaration","declared-conflicts-and-alternatives","policy-lifecycle-state-model","amendment-supersession-and-repeal","validity-intervals-and-record-time","authoring-derivation-and-source-mapping","statement-quality-and-review-status","conformance-and-standard-alignment","record-classification-access-and-retention"],"selectedFindingIds":["version-identity-and-point-in-time","issuing-authority-and-mandate","constraint-expression-binding","combining-and-hit-policy-declaration","validity-intervals-and-record-time","record-classification-access-and-retention"],"publicationHolds":["Live source and version verification hold: before publication, confirm every accepted source URL resolves and pin a version for the three access-dated entries that currently carry no version token — SRC-010 (OSCAL catalog concepts), SRC-011 (ELI framework pages) and SRC-012 (ODRL Formal Semantics editor's draft, non-normative). Any source that cannot be resolved and pinned must be downgraded and the nodes resting on it re-checked for remaining primary support.","Single-provider hold: every publication artifact must carry a visible notice that this result was produced by Claude alone and received no independent second-provider review, naming the repository owner's waiver of Grok effective 2026-08-29T09:06:27Z and its stated reason (repeated structured-output failures). The artifact stays a reviewable draft, not a validated model, for as long as that waiver stands.","Timestamp-rule verification hold: SRC-009 is registered as RFC 3339 'updated by RFC 9557', but RFC 9557 is not itself a registered source while the canonicalization and artifact timestamp rules depend on the exact unknown-local-offset clause. Either register the updating RFC and confirm the -00:00 convention survives it, or restate the rule against the pinned RFC 3339 text before freezing the hashing rule.","Boundary-review hold: the frozen registry carries status 'candidate' and review_state 'boundary-review-required', and this audit reclassifies the subject-model entry kind from entity to aggregate on the strength of the service-layer invariants. Publication must surface both the outstanding boundary review and the reclassification, so no downstream consumer treats the entry kind as settled.","Paywalled-source hold: SRC-013 (ISO 37301:2021) grounds lifecycle currency, ownership and compliance-boundary claims but is behind a paywall. Confirm that the cited structure is supported by publicly verifiable scope material or by a licensed reading on record; if neither, downgrade the affected notes to partial support rather than leaving an uncheckable tier-1 citation in a public draft.","Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft."]},{"candidate":"RetentionConstraint","currentId":"vr.wm-xct-035","catalogueId":"WM-XCT-035","version":null,"status":"todo","installable":false,"specDigest":null,"relation":"research-target","decision":"Documented deferral; custodyContext is an opaque host-owned evidence pin, not an executable 035 dependency.","runtimeImport":false,"losses":"No retention schedule/hold evaluator, disposition execution or destruction evidence implemented."}],"composition":{"runtimeImports":[],"semanticReferences":["vr.wm-xct-002","vr.wm-xct-003","vr.wm-xct-020","vr.wm-dat-004","vr.wm-knw-012","vr.wm-xct-035"],"packageContents":"Original metadata-only prototype; parent specs preserved as comparison evidence, not imported types."},"otherNeighbors":"005 is a legacy non-installable entry; 038 is an unversioned todo. No executable delegation. See adjacent-model-checks.json."} END FILE crosswalk.json ## FILE disclosure.py ORIGINAL SHA256 c08df6f075b801b8808a3db4da3d59e6519a2e6949bec6238f9361c5e3e54066 """Metadata-only reviewable reference. All callers/snapshots require a trusted host. No network, payload access, grant evaluation, inference proof or deletion occurs. Bounded reviewable reference; see review.md for the exact external audit scope. """ from pathlib import Path import copy, datetime, hashlib, json, re from jsonschema import Draft202012Validator VERSION='0.1.0' SCHEMA=json.loads(Path(__file__).with_name('disclosure.schema.json').read_text(encoding='utf-8')) if not all(SCHEMA['$defs'][t]['properties']['version']['const']==VERSION for t in ('proposal','review','snapshot')): raise RuntimeError('schema/version mismatch') VALIDATOR=Draft202012Validator(SCHEMA) MAX_BYTES=262144 class Invalid(ValueError):pass class Unauthorized(ValueError):pass def canonical(value): """Restricted JSON: sorted keys, UTF-8, compact, no floats or normalization. List order is significant. Strings preserve code points. This is NOT JCS. Bounds are prototype limits, not a hardened hostile-input parser guarantee. """ def visit(x,depth=0): if depth>20:raise Invalid('depth') if type(x) is str: if len(x)>4096 or any(0xD800<=ord(c)<=0xDFFF for c in x):raise Invalid('string') elif x is None or type(x) is bool:pass elif type(x) is int: if not -(2**53-1)<=x<=2**53-1:raise Invalid('integer') elif type(x) is list: if len(x)>128:raise Invalid('list') for a in x:visit(a,depth+1) elif type(x) is dict: if len(x)>128:raise Invalid('object') for k,v in x.items(): if type(k) is not str:raise Invalid('key') visit(k,depth+1);visit(v,depth+1) else:raise Invalid('unsupported JSON value') visit(value) raw=json.dumps(value,ensure_ascii=False,sort_keys=True,separators=(',',':'),allow_nan=False).encode('utf-8') if len(raw)>MAX_BYTES:raise Invalid('size') return raw def load(raw): if not isinstance(raw,bytes) or len(raw)>MAX_BYTES:raise Invalid('input bytes') def pairs(items): d={} for k,v in items: if k in d:raise Invalid('duplicate JSON key') d[k]=v return d def forbidden(_):raise Invalid('non-integer number') def integer(s): if len(s)>17:raise Invalid('integer') return int(s) try: result=json.loads(raw.decode('utf-8'),object_pairs_hook=pairs,parse_float=forbidden,parse_constant=forbidden,parse_int=integer) canonical(result) except (UnicodeError,RecursionError,json.JSONDecodeError) as e:raise Invalid('JSON') from e return result def native_fact_id(record): """Deterministic storage key for one immutable record revision.""" validate(record) return 'urn:vercy:disclosure-revision:'+hashlib.sha256(canonical({'dimension':record['dimension'],'id':record['id'],'revision':record['revision']})).hexdigest() def validate_native(fact,obj,*,dimension,capability,now,master,writer): """Companion semantic check AFTER separate V3 envelope validation. Host supplies authentic expected Dimension/master/writer and object registry. This is storage binding only, not active selection or disclosure permission. """ authorize(capability,dimension) canonical(fact);canonical(obj) if not isinstance(fact,dict) or not isinstance(obj,dict):raise Invalid('native objects') for name in (master,writer): if type(name) is not str or not re.fullmatch(r'[A-Za-z][A-Za-z0-9+.-]*:[!-~]+',name):raise Invalid('native trusted identity') record=fact.get('value');validate(record) if record['dimension']!=dimension:raise Invalid('native Dimension') typ=record['type'];mid='vr.profile.enterprise-disclosure-review' if obj.get('recordType')!='object' or obj.get('schemaVersion')!='1.0.0' or obj.get('objectId')!=record['id'] or obj.get('objectType')!=mid+':'+typ or obj.get('state')!='active':raise Invalid('native object binding') if fact.get('recordType')!='fact' or fact.get('schemaVersion')!='1.0.0' or fact.get('subjectId')!=record['id'] or fact.get('path')!='disclosure.'+typ+'.revision':raise Invalid('native fact binding') if fact.get('factId')!=native_fact_id(record):raise Invalid('native revision identity') if fact.get('status')!='asserted' or 'unit' not in fact or fact['unit'] is not None or 'validTo' not in fact or fact['validTo'] is not None or fact.get('supersedes')!=[]:raise Invalid('native immutable storage semantics') if fact.get('accessClass')!='restricted' or obj.get('accessClass')!='restricted':raise Invalid('native access class') if fact.get('masterSystem')!=master or fact.get('authority')!={'source':writer,'rank':0}:raise Invalid('native storage authority') if not isinstance(fact.get('provenance'),dict) or fact['provenance'].get('source')!=master or fact['provenance'].get('recordDigest')!=record['digest']:raise Invalid('native storage provenance') recorded=instant(fact.get('recordedAt'));object_at=instant(obj.get('recordedAt'));evaluation=instant(now) declared=instant(record['body']['capturedAt' if typ=='proposal' else 'reviewedAt']) if fact.get('validFrom')!=fact.get('recordedAt') or not object_at<=recorded<=evaluation or not declared<=recorded:raise Invalid('native storage time') return record def hash_body(record): return 'sha256:'+hashlib.sha256(canonical({k:v for k,v in record.items() if k!='digest'})).hexdigest() def instant(s): if not isinstance(s,str):raise Invalid('timestamp') try: m=re.fullmatch(r'([0-9]{4})-([0-9]{2})-([0-9]{2})T([0-9]{2}):([0-9]{2}):([0-9]{2})Z',s) if not m:raise ValueError() return datetime.datetime(*map(int,m.groups()),tzinfo=datetime.timezone.utc) except ValueError as e:raise Invalid('timestamp') from e def pin(record):return {k:record[k] for k in ('id','revision','digest')} def seal(record): if type(record) is not dict:raise Invalid('record object') canonical(record) result=copy.deepcopy(record);result['digest']=hash_body(result);validate(result);return result def exact_identifiers(value,coherence=False): coherent={} def exact_strings(x): if isinstance(x,dict): if coherence and set(x)=={'id','revision','digest'}: previous=coherent.setdefault(x['id'],(x['revision'],x['digest'])) if previous!=(x['revision'],x['digest']):raise Invalid('incoherent reference pin') for k,v in x.items(): pattern=None if k in ('id','dimension','author','reviewer'):pattern=r'[A-Za-z][A-Za-z0-9+.-]*:[!-~]+' elif k in ('revision','key'):pattern=r'[A-Za-z0-9][A-Za-z0-9._-]*' elif k=='name':pattern=r'[A-Za-z_][A-Za-z0-9_]{0,63}' elif k=='digest':pattern=r'sha256:[0-9a-f]{64}' if pattern and (not isinstance(v,str) or not re.fullmatch(pattern,v)):raise Invalid('exact identifier syntax') exact_strings(v) elif isinstance(x,list): for v in x:exact_strings(v) exact_strings(value) def validate(record): canonical(record) errors=list(VALIDATOR.iter_errors(record)) if errors:raise Invalid('record shape') if record['digest']!=hash_body(record):raise Invalid('digest') exact_identifiers(record,coherence=True) b=record['body'] if record['type']=='proposal': instant(b['capturedAt']);members=b['members'] if len({m['key'] for m in members})!=len(members):raise Invalid('duplicate member key') for m in members: if len({f['name'] for f in m['fields']})!=len(m['fields']):raise Invalid('duplicate field') else: a,start,end=map(instant,[b['reviewedAt'],b['validFrom'],b['validTo']]) if not a<=start64:raise Invalid('review set') counted=[];ignored=[];evaluated=False def result(status,reason=None): answer={'format':'vercy-disclosure-inspection','evaluatorVersion':VERSION,'status':status,'notServingAuthorization':True,'proposal':pin(proposal),'snapshotDigest':'sha256:'+hashlib.sha256(canonical(snapshot)).hexdigest(),'at':snapshot['asOf'],'reviewsEvaluated':evaluated,'counted':copy.deepcopy(counted),'ignored':copy.deepcopy(ignored),'withdrawn':copy.deepcopy(snapshot['withdrawnReviews'])} if reason:answer['reason']=reason return answer # Snapshot is a host catalog of current scalar metadata; exact equality avoids # undocumented classification order, schema adaptation, or shape widening. b=proposal['body'];context={k:b[k] for k in ('audience','purpose','environment','priorReleases','custodyContext')} if snapshot['proposal']!=pin(proposal):return result('stale','current-proposal-differs') if b['author'] not in snapshot['proposalAuthors']:return result('insufficient-context','proposal-author') if instant(b['capturedAt'])>now:return result('stale','future-capture') if context!=snapshot['context'] or b['members']!=snapshot['members']:return result('stale','current-inputs-differ') seen={};supplied=[] for r in reviews: validate(r) if r['type']!='review' or r['dimension']!=dimension:raise Invalid('review scope') if r['id']==proposal['id']:raise Invalid('identity changes type') if r['body']['proposal']!=pin(proposal):raise Invalid('review points to another proposal') if instant(r['body']['reviewedAt'])now:reason='future-assessment' elif now=instant(rb['validTo']):reason='expired' if reason: ignored.append({'pin':pin(r),'verdict':rb['verdict'],'reason':reason});continue counted.append(pin(r)) valid.append(rb['verdict']) if not valid:return result('insufficient-context','no-applicable-review') if len(set(valid))>1:return result('conflict','active-review-disagreement') return result('applicable-review' if valid[0]=='cleared' else valid[0]) def import_records(existing,incoming,dimension,capability): """Pure transactional merge of immutable records, not persistent storage. Host must separately authorize writes, retain the full master set and apply compare-and-swap around persistence; this function has no database effects. """ authorize(capability,dimension) if capability.get('record') is not True:raise Unauthorized('unavailable') if type(existing) is not list or type(incoming) is not list or len(existing)+len(incoming)>128:raise Invalid('record bounds') result=copy.deepcopy(existing);known={};types={} for n,r in enumerate(existing+incoming): validate(r) if r['dimension']!=dimension:raise Invalid('record scope') if r['id'] in types and types[r['id']]!=r['type']:raise Invalid('identity changes type') types[r['id']]=r['type'] key=(r['type'],r['id'],r['revision']) if key in known: if known[key]!=r['digest']:raise Invalid('immutable revision conflict') if n=len(existing):result.append(copy.deepcopy(r)) # The supplied store is the complete local proposal/review master set. Domain # source and evidence references remain external; these two internal edges do not. records={(r['id'],r['revision']):r for r in result} edges={} def resolve(p,typ): target=records.get((p['id'],p['revision'])) if target is None or target['type']!=typ or pin(target)!=p:raise Invalid('unresolved internal pin') return target for r in result: if r['type']!='review':continue rb=r['body'];proposal=resolve(rb['proposal'],'proposal') if instant(rb['reviewedAt'])instant(rb['reviewedAt']):raise Invalid('supersession time reversal') edges[(r['id'],r['revision'])]=(prior['id'],prior['revision']) for start in edges: visited=set();node=start while node in edges: if node in visited:raise Invalid('supersession cycle') visited.add(node);node=edges[node] return result END FILE disclosure.py ## FILE disclosure.schema.json ORIGINAL SHA256 45b2f2c82b9d9af72b2b462d3e502098fbd5b166bf8bd705947ba12e1e5cc834 {"$schema":"https://json-schema.org/draft/2020-12/schema","title":"Enterprise Disclosure Review 0.1.0 closed metadata records","oneOf":[{"$ref":"#/$defs/proposal"},{"$ref":"#/$defs/review"}],"$defs":{"pin":{"type":"object","properties":{"id":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"revision":{"type":"string","pattern":"^[A-Za-z0-9][A-Za-z0-9._-]*$","minLength":1,"maxLength":128},"digest":{"type":"string","pattern":"^sha256:[0-9a-f]{64}$"}},"required":["id","revision","digest"],"additionalProperties":false},"time":{"type":"string","pattern":"^\\d{4}-\\d\\d-\\d\\dT\\d\\d:\\d\\d:\\d\\dZ$"},"field":{"type":"object","properties":{"name":{"type":"string","pattern":"^[A-Za-z_][A-Za-z0-9_]{0,63}$"},"kind":{"enum":["string","integer","number","boolean","null"]},"classificationBindings":{"type":"array","items":{"$ref":"#/$defs/pin"},"minItems":1,"maxItems":8,"uniqueItems":true}},"required":["name","kind","classificationBindings"],"additionalProperties":false},"member":{"type":"object","properties":{"key":{"type":"string","pattern":"^[A-Za-z0-9][A-Za-z0-9._-]*$","minLength":1,"maxLength":128},"source":{"$ref":"#/$defs/pin"},"schema":{"$ref":"#/$defs/pin"},"shape":{"$ref":"#/$defs/pin"},"fields":{"type":"array","items":{"$ref":"#/$defs/field"},"minItems":1,"maxItems":64,"uniqueItems":true}},"required":["key","source","schema","shape","fields"],"additionalProperties":false},"proposalBody":{"type":"object","properties":{"author":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"capturedAt":{"$ref":"#/$defs/time"},"audience":{"$ref":"#/$defs/pin"},"purpose":{"$ref":"#/$defs/pin"},"environment":{"$ref":"#/$defs/pin"},"priorReleases":{"$ref":"#/$defs/pin"},"custodyContext":{"$ref":"#/$defs/pin"},"members":{"type":"array","items":{"$ref":"#/$defs/member"},"minItems":1,"maxItems":32,"uniqueItems":true}},"required":["author","capturedAt","audience","purpose","environment","priorReleases","custodyContext","members"],"additionalProperties":false},"reviewBody":{"type":"object","properties":{"proposal":{"$ref":"#/$defs/pin"},"reviewer":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"authority":{"$ref":"#/$defs/pin"},"method":{"$ref":"#/$defs/pin"},"evidence":{"type":"array","items":{"$ref":"#/$defs/pin"},"minItems":1,"maxItems":16,"uniqueItems":true},"reviewedAt":{"$ref":"#/$defs/time"},"validFrom":{"$ref":"#/$defs/time"},"validTo":{"$ref":"#/$defs/time"},"verdict":{"enum":["cleared","rejected","inconclusive"]},"residualRisk":{"type":"string","minLength":1,"maxLength":2048},"supersedes":{"oneOf":[{"$ref":"#/$defs/pin"},{"type":"null"}]}},"required":["proposal","reviewer","authority","method","evidence","reviewedAt","validFrom","validTo","verdict","residualRisk","supersedes"],"additionalProperties":false},"proposal":{"type":"object","properties":{"format":{"const":"vercy-disclosure-research"},"version":{"const":"0.1.0"},"type":{"const":"proposal"},"dimension":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"id":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"revision":{"type":"string","pattern":"^[A-Za-z0-9][A-Za-z0-9._-]*$","minLength":1,"maxLength":128},"body":{"$ref":"#/$defs/proposalBody"},"digest":{"type":"string","pattern":"^sha256:[0-9a-f]{64}$"}},"required":["format","version","type","dimension","id","revision","body","digest"],"additionalProperties":false},"review":{"type":"object","properties":{"format":{"const":"vercy-disclosure-research"},"version":{"const":"0.1.0"},"type":{"const":"review"},"dimension":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"id":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"revision":{"type":"string","pattern":"^[A-Za-z0-9][A-Za-z0-9._-]*$","minLength":1,"maxLength":128},"body":{"$ref":"#/$defs/reviewBody"},"digest":{"type":"string","pattern":"^sha256:[0-9a-f]{64}$"}},"required":["format","version","type","dimension","id","revision","body","digest"],"additionalProperties":false},"snapshot":{"type":"object","properties":{"dimension":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"asOf":{"$ref":"#/$defs/time"},"proposal":{"$ref":"#/$defs/pin"},"context":{"type":"object","properties":{"audience":{"$ref":"#/$defs/pin"},"purpose":{"$ref":"#/$defs/pin"},"environment":{"$ref":"#/$defs/pin"},"priorReleases":{"$ref":"#/$defs/pin"},"custodyContext":{"$ref":"#/$defs/pin"}},"required":["audience","purpose","environment","priorReleases","custodyContext"],"additionalProperties":false},"members":{"type":"array","items":{"$ref":"#/$defs/member"},"minItems":1,"maxItems":32,"uniqueItems":true},"proposalAuthors":{"type":"array","items":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"minItems":0,"maxItems":64,"uniqueItems":true},"reviewers":{"type":"array","items":{"type":"string","pattern":"^[A-Za-z][A-Za-z0-9+.-]*:[!-~]+$","minLength":3,"maxLength":512},"minItems":0,"maxItems":64,"uniqueItems":true},"authority":{"$ref":"#/$defs/pin"},"activeReviews":{"type":"array","items":{"$ref":"#/$defs/pin"},"minItems":0,"maxItems":64,"uniqueItems":true},"withdrawnReviews":{"type":"array","items":{"$ref":"#/$defs/pin"},"minItems":0,"maxItems":64,"uniqueItems":true},"separateReviewer":{"type":"boolean"},"format":{"const":"vercy-disclosure-host-snapshot"},"version":{"const":"0.1.0"}},"required":["dimension","asOf","proposal","context","members","proposalAuthors","reviewers","authority","activeReviews","withdrawnReviews","separateReviewer","format","version"],"additionalProperties":false}},"type":"object","properties":{"format":{},"version":{},"type":{},"dimension":{},"id":{},"revision":{},"body":{},"digest":{}},"required":["format","version","type","dimension","id","revision","body","digest"],"additionalProperties":false} END FILE disclosure.schema.json ## FILE examples/ai.json ORIGINAL SHA256 1100097d1526b8c53e5ad51ca75d8d5d0ccb4a59a6afe5a565a532996e799014 {"fixtureKind":"synthetic-host-internal-only; never accept hostSnapshot or capabilities from a request","proposal":{"format":"vercy-disclosure-research","version":"0.1.0","type":"proposal","dimension":"urn:synthetic:dimension:ai","id":"urn:synthetic:proposal:ai","revision":"1","body":{"author":"urn:synthetic:founder","capturedAt":"2026-09-21T10:00:00Z","audience":{"id":"urn:synthetic:partner","revision":"1","digest":"sha256:946cad4f88aac95b3c9e37b4e7ea4badae9d3bbe4026a081493bf2d9abd014ac"},"purpose":{"id":"urn:synthetic:release-briefing","revision":"1","digest":"sha256:03d14282828be5af5be5e3e52670bb24ce2029fb9001f36dcba0ae4d6c3ce0c0"},"environment":{"id":"urn:synthetic:partner-portal","revision":"1","digest":"sha256:41f7dfc5c0ce4057e0ca4494221b4782752c76bec53842bac55ab7a20b280215"},"priorReleases":{"id":"urn:synthetic:known-prior-release-context","revision":"1","digest":"sha256:889caa5342a3a20d6e2b67e927ee8b42f1eb05a1011aebfc02b18b56b6ee8b3c"},"custodyContext":{"id":"urn:synthetic:custody-instructions","revision":"1","digest":"sha256:0195c787c48baac5b4f33db7dbc4074fe555d0737aa5bdb98496fbd600167671"},"members":[{"key":"release-notes","source":{"id":"urn:synthetic:model-release","revision":"1","digest":"sha256:e6e150076d880836119eb6bedadbb052677caa50b2d66a3e8e48be96d6a89132"},"schema":{"id":"urn:synthetic:release-notes-schema","revision":"1","digest":"sha256:6fe15bc99df48d71a02a24bea5e2b983507f3aa2a7d6e2b3fea53d1105621aee"},"shape":{"id":"urn:synthetic:release-notes-shape","revision":"1","digest":"sha256:6c3b58d5a3d1ecfa23559ad4427867f41fc8059d1a77c8d620ba7209b5287a6d"},"fields":[{"name":"releaseNotes","kind":"string","classificationBindings":[{"id":"urn:synthetic:release-notes-classification","revision":"1","digest":"sha256:93664a398d24cf0112c95485290e939701e896a7f0b3ab95d85f7994ec53ca3d"}]}]}]},"digest":"sha256:7edbcf914ca751760e6d418deb693c46e130cfa1b76bce20474d6af610c3190e"},"reviews":[{"format":"vercy-disclosure-research","version":"0.1.0","type":"review","dimension":"urn:synthetic:dimension:ai","id":"urn:synthetic:review:ai","revision":"1","body":{"proposal":{"id":"urn:synthetic:proposal:ai","revision":"1","digest":"sha256:7edbcf914ca751760e6d418deb693c46e130cfa1b76bce20474d6af610c3190e"},"reviewer":"urn:synthetic:reviewer","authority":{"id":"urn:synthetic:review-authority","revision":"1","digest":"sha256:6c964f0e1770cabc4a253c8afcf6fc3bf27ccac6950a3b2499ac67c880cacbee"},"method":{"id":"urn:synthetic:bounded-manual-review","revision":"1","digest":"sha256:2e8a4b1517263dda35b8df12b36f7bc832a34d9c219b7f38f519a0dfe9e89ae6"},"evidence":[{"id":"urn:synthetic:synthetic-assessment","revision":"1","digest":"sha256:db5b99e40c471b12a69885ecb7a440356b505108170626cf9ba5aa876f705395"}],"reviewedAt":"2026-09-21T10:01:00Z","validFrom":"2026-09-21T10:01:00Z","validTo":"2026-09-22T10:01:00Z","verdict":"cleared","residualRisk":"Synthetic scenario only. No claim of inference prevention.","supersedes":null},"digest":"sha256:3693032c70bbfecada292e6b8811ebc28bf7d4469fa476d8a4b7dd3831b28fee"}],"hostSnapshot":{"format":"vercy-disclosure-host-snapshot","version":"0.1.0","dimension":"urn:synthetic:dimension:ai","asOf":"2026-09-21T12:00:00Z","proposal":{"id":"urn:synthetic:proposal:ai","revision":"1","digest":"sha256:7edbcf914ca751760e6d418deb693c46e130cfa1b76bce20474d6af610c3190e"},"context":{"audience":{"id":"urn:synthetic:partner","revision":"1","digest":"sha256:946cad4f88aac95b3c9e37b4e7ea4badae9d3bbe4026a081493bf2d9abd014ac"},"purpose":{"id":"urn:synthetic:release-briefing","revision":"1","digest":"sha256:03d14282828be5af5be5e3e52670bb24ce2029fb9001f36dcba0ae4d6c3ce0c0"},"environment":{"id":"urn:synthetic:partner-portal","revision":"1","digest":"sha256:41f7dfc5c0ce4057e0ca4494221b4782752c76bec53842bac55ab7a20b280215"},"priorReleases":{"id":"urn:synthetic:known-prior-release-context","revision":"1","digest":"sha256:889caa5342a3a20d6e2b67e927ee8b42f1eb05a1011aebfc02b18b56b6ee8b3c"},"custodyContext":{"id":"urn:synthetic:custody-instructions","revision":"1","digest":"sha256:0195c787c48baac5b4f33db7dbc4074fe555d0737aa5bdb98496fbd600167671"}},"members":[{"key":"release-notes","source":{"id":"urn:synthetic:model-release","revision":"1","digest":"sha256:e6e150076d880836119eb6bedadbb052677caa50b2d66a3e8e48be96d6a89132"},"schema":{"id":"urn:synthetic:release-notes-schema","revision":"1","digest":"sha256:6fe15bc99df48d71a02a24bea5e2b983507f3aa2a7d6e2b3fea53d1105621aee"},"shape":{"id":"urn:synthetic:release-notes-shape","revision":"1","digest":"sha256:6c3b58d5a3d1ecfa23559ad4427867f41fc8059d1a77c8d620ba7209b5287a6d"},"fields":[{"name":"releaseNotes","kind":"string","classificationBindings":[{"id":"urn:synthetic:release-notes-classification","revision":"1","digest":"sha256:93664a398d24cf0112c95485290e939701e896a7f0b3ab95d85f7994ec53ca3d"}]}]}],"proposalAuthors":["urn:synthetic:founder"],"reviewers":["urn:synthetic:reviewer","urn:synthetic:founder"],"authority":{"id":"urn:synthetic:review-authority","revision":"1","digest":"sha256:6c964f0e1770cabc4a253c8afcf6fc3bf27ccac6950a3b2499ac67c880cacbee"},"activeReviews":[{"id":"urn:synthetic:review:ai","revision":"1","digest":"sha256:3693032c70bbfecada292e6b8811ebc28bf7d4469fa476d8a4b7dd3831b28fee"}],"withdrawnReviews":[],"separateReviewer":true}} END FILE examples/ai.json ## FILE examples/matrix.json ORIGINAL SHA256 63199a204156969003e900daea112eba5ff8545f7b21a6ce64e6e2944c04b0a0 {"fixtureKind":"synthetic-host-internal-only; never accept hostSnapshot or capabilities from a request","proposal":{"format":"vercy-disclosure-research","version":"0.1.0","type":"proposal","dimension":"urn:synthetic:dimension:matrix","id":"urn:synthetic:proposal:matrix","revision":"1","body":{"author":"urn:synthetic:founder","capturedAt":"2026-09-21T10:00:00Z","audience":{"id":"urn:synthetic:partner","revision":"1","digest":"sha256:946cad4f88aac95b3c9e37b4e7ea4badae9d3bbe4026a081493bf2d9abd014ac"},"purpose":{"id":"urn:synthetic:release-briefing","revision":"1","digest":"sha256:03d14282828be5af5be5e3e52670bb24ce2029fb9001f36dcba0ae4d6c3ce0c0"},"environment":{"id":"urn:synthetic:partner-portal","revision":"1","digest":"sha256:41f7dfc5c0ce4057e0ca4494221b4782752c76bec53842bac55ab7a20b280215"},"priorReleases":{"id":"urn:synthetic:known-prior-release-context","revision":"1","digest":"sha256:889caa5342a3a20d6e2b67e927ee8b42f1eb05a1011aebfc02b18b56b6ee8b3c"},"custodyContext":{"id":"urn:synthetic:custody-instructions","revision":"1","digest":"sha256:0195c787c48baac5b4f33db7dbc4074fe555d0737aa5bdb98496fbd600167671"},"members":[{"key":"group-summary","source":{"id":"urn:synthetic:group-aggregate","revision":"1","digest":"sha256:d7d876cc7467ae46e456d3576302da3fb14afd02f332d0fd42b65f875a80bbe1"},"schema":{"id":"urn:synthetic:headcount-schema","revision":"1","digest":"sha256:8838d1da5314ca3139288e4599689e8fa8bf2dfbbc1dca6a9f6204270f60da30"},"shape":{"id":"urn:synthetic:headcount-summary-shape","revision":"1","digest":"sha256:82dbf6b6c2ce68e23d95190ef5753a1de975b86318f82bb172d6a63d4af86f3e"},"fields":[{"name":"headcount","kind":"integer","classificationBindings":[{"id":"urn:synthetic:headcount-classification","revision":"1","digest":"sha256:cb74d90a9bc455b72536376706a71af0f9cc71ee9fb2ee73de6e2e0ce744465e"}]}]},{"key":"unit-summary","source":{"id":"urn:synthetic:unit-aggregate","revision":"1","digest":"sha256:2eefb62177f75b2de2932064304dee5f4cde1a011a3402854b668632c446bf8a"},"schema":{"id":"urn:synthetic:headcount-schema","revision":"1","digest":"sha256:8838d1da5314ca3139288e4599689e8fa8bf2dfbbc1dca6a9f6204270f60da30"},"shape":{"id":"urn:synthetic:headcount-summary-shape","revision":"1","digest":"sha256:82dbf6b6c2ce68e23d95190ef5753a1de975b86318f82bb172d6a63d4af86f3e"},"fields":[{"name":"headcount","kind":"integer","classificationBindings":[{"id":"urn:synthetic:headcount-classification","revision":"1","digest":"sha256:cb74d90a9bc455b72536376706a71af0f9cc71ee9fb2ee73de6e2e0ce744465e"}]}]}]},"digest":"sha256:30a923c06098c4d8e429817e47ac5b71a9831bf5045543fa70b80f3be4366e51"},"reviews":[{"format":"vercy-disclosure-research","version":"0.1.0","type":"review","dimension":"urn:synthetic:dimension:matrix","id":"urn:synthetic:review:matrix","revision":"1","body":{"proposal":{"id":"urn:synthetic:proposal:matrix","revision":"1","digest":"sha256:30a923c06098c4d8e429817e47ac5b71a9831bf5045543fa70b80f3be4366e51"},"reviewer":"urn:synthetic:reviewer","authority":{"id":"urn:synthetic:review-authority","revision":"1","digest":"sha256:6c964f0e1770cabc4a253c8afcf6fc3bf27ccac6950a3b2499ac67c880cacbee"},"method":{"id":"urn:synthetic:bounded-manual-review","revision":"1","digest":"sha256:2e8a4b1517263dda35b8df12b36f7bc832a34d9c219b7f38f519a0dfe9e89ae6"},"evidence":[{"id":"urn:synthetic:synthetic-assessment","revision":"1","digest":"sha256:db5b99e40c471b12a69885ecb7a440356b505108170626cf9ba5aa876f705395"}],"reviewedAt":"2026-09-21T10:01:00Z","validFrom":"2026-09-21T10:01:00Z","validTo":"2026-09-22T10:01:00Z","verdict":"rejected","residualRisk":"Synthetic reviewer identifies a subtraction path between group and unit headcounts exposing an individual indicator. This package is rejected. The validator does not calculate that risk.","supersedes":null},"digest":"sha256:c8cd3848860a647fbe41b14ff7340b4cd5460ef5e25be805d4570fca3479c833"}],"hostSnapshot":{"format":"vercy-disclosure-host-snapshot","version":"0.1.0","dimension":"urn:synthetic:dimension:matrix","asOf":"2026-09-21T12:00:00Z","proposal":{"id":"urn:synthetic:proposal:matrix","revision":"1","digest":"sha256:30a923c06098c4d8e429817e47ac5b71a9831bf5045543fa70b80f3be4366e51"},"context":{"audience":{"id":"urn:synthetic:partner","revision":"1","digest":"sha256:946cad4f88aac95b3c9e37b4e7ea4badae9d3bbe4026a081493bf2d9abd014ac"},"purpose":{"id":"urn:synthetic:release-briefing","revision":"1","digest":"sha256:03d14282828be5af5be5e3e52670bb24ce2029fb9001f36dcba0ae4d6c3ce0c0"},"environment":{"id":"urn:synthetic:partner-portal","revision":"1","digest":"sha256:41f7dfc5c0ce4057e0ca4494221b4782752c76bec53842bac55ab7a20b280215"},"priorReleases":{"id":"urn:synthetic:known-prior-release-context","revision":"1","digest":"sha256:889caa5342a3a20d6e2b67e927ee8b42f1eb05a1011aebfc02b18b56b6ee8b3c"},"custodyContext":{"id":"urn:synthetic:custody-instructions","revision":"1","digest":"sha256:0195c787c48baac5b4f33db7dbc4074fe555d0737aa5bdb98496fbd600167671"}},"members":[{"key":"group-summary","source":{"id":"urn:synthetic:group-aggregate","revision":"1","digest":"sha256:d7d876cc7467ae46e456d3576302da3fb14afd02f332d0fd42b65f875a80bbe1"},"schema":{"id":"urn:synthetic:headcount-schema","revision":"1","digest":"sha256:8838d1da5314ca3139288e4599689e8fa8bf2dfbbc1dca6a9f6204270f60da30"},"shape":{"id":"urn:synthetic:headcount-summary-shape","revision":"1","digest":"sha256:82dbf6b6c2ce68e23d95190ef5753a1de975b86318f82bb172d6a63d4af86f3e"},"fields":[{"name":"headcount","kind":"integer","classificationBindings":[{"id":"urn:synthetic:headcount-classification","revision":"1","digest":"sha256:cb74d90a9bc455b72536376706a71af0f9cc71ee9fb2ee73de6e2e0ce744465e"}]}]},{"key":"unit-summary","source":{"id":"urn:synthetic:unit-aggregate","revision":"1","digest":"sha256:2eefb62177f75b2de2932064304dee5f4cde1a011a3402854b668632c446bf8a"},"schema":{"id":"urn:synthetic:headcount-schema","revision":"1","digest":"sha256:8838d1da5314ca3139288e4599689e8fa8bf2dfbbc1dca6a9f6204270f60da30"},"shape":{"id":"urn:synthetic:headcount-summary-shape","revision":"1","digest":"sha256:82dbf6b6c2ce68e23d95190ef5753a1de975b86318f82bb172d6a63d4af86f3e"},"fields":[{"name":"headcount","kind":"integer","classificationBindings":[{"id":"urn:synthetic:headcount-classification","revision":"1","digest":"sha256:cb74d90a9bc455b72536376706a71af0f9cc71ee9fb2ee73de6e2e0ce744465e"}]}]}],"proposalAuthors":["urn:synthetic:founder"],"reviewers":["urn:synthetic:reviewer","urn:synthetic:founder"],"authority":{"id":"urn:synthetic:review-authority","revision":"1","digest":"sha256:6c964f0e1770cabc4a253c8afcf6fc3bf27ccac6950a3b2499ac67c880cacbee"},"activeReviews":[{"id":"urn:synthetic:review:matrix","revision":"1","digest":"sha256:c8cd3848860a647fbe41b14ff7340b4cd5460ef5e25be805d4570fca3479c833"}],"withdrawnReviews":[],"separateReviewer":true}} END FILE examples/matrix.json ## FILE examples/startup.json ORIGINAL SHA256 44968621c7d9fbd0256270ff0a95e5a4665b83094a7c574e0ebee89bdf83023d {"fixtureKind":"synthetic-host-internal-only; never accept hostSnapshot or capabilities from a request","proposal":{"format":"vercy-disclosure-research","version":"0.1.0","type":"proposal","dimension":"urn:synthetic:dimension:startup","id":"urn:synthetic:proposal:startup","revision":"1","body":{"author":"urn:synthetic:founder","capturedAt":"2026-09-21T10:00:00Z","audience":{"id":"urn:synthetic:partner","revision":"1","digest":"sha256:946cad4f88aac95b3c9e37b4e7ea4badae9d3bbe4026a081493bf2d9abd014ac"},"purpose":{"id":"urn:synthetic:release-briefing","revision":"1","digest":"sha256:03d14282828be5af5be5e3e52670bb24ce2029fb9001f36dcba0ae4d6c3ce0c0"},"environment":{"id":"urn:synthetic:partner-portal","revision":"1","digest":"sha256:41f7dfc5c0ce4057e0ca4494221b4782752c76bec53842bac55ab7a20b280215"},"priorReleases":{"id":"urn:synthetic:known-prior-release-context","revision":"1","digest":"sha256:889caa5342a3a20d6e2b67e927ee8b42f1eb05a1011aebfc02b18b56b6ee8b3c"},"custodyContext":{"id":"urn:synthetic:custody-instructions","revision":"1","digest":"sha256:0195c787c48baac5b4f33db7dbc4074fe555d0737aa5bdb98496fbd600167671"},"members":[{"key":"project-name","source":{"id":"urn:synthetic:project","revision":"1","digest":"sha256:2513f132e8ce6f5db5dffb620c821c51cf21749d53fcacaf2bb078f8075ec470"},"schema":{"id":"urn:synthetic:project-schema","revision":"1","digest":"sha256:a5286321f770e7053fc2dd59bbb186f470fad8b90739bea10c365a18277aa0f7"},"shape":{"id":"urn:synthetic:name-only-shape","revision":"1","digest":"sha256:16ddea4ffcc347f412079c04b6ede23653756f7dd7c671a492c09debeae7205e"},"fields":[{"name":"name","kind":"string","classificationBindings":[{"id":"urn:synthetic:name-classification","revision":"1","digest":"sha256:8fe9f79fe703be307af21a1fcb863dd914d2486d68fd30f2f8847468dfc9e540"}]}]}]},"digest":"sha256:c8dd8884a8a71580d7d2d6ead046218f8a2343dba0fe85d4605d2ab99befb46e"},"reviews":[{"format":"vercy-disclosure-research","version":"0.1.0","type":"review","dimension":"urn:synthetic:dimension:startup","id":"urn:synthetic:review:startup","revision":"1","body":{"proposal":{"id":"urn:synthetic:proposal:startup","revision":"1","digest":"sha256:c8dd8884a8a71580d7d2d6ead046218f8a2343dba0fe85d4605d2ab99befb46e"},"reviewer":"urn:synthetic:reviewer","authority":{"id":"urn:synthetic:review-authority","revision":"1","digest":"sha256:6c964f0e1770cabc4a253c8afcf6fc3bf27ccac6950a3b2499ac67c880cacbee"},"method":{"id":"urn:synthetic:bounded-manual-review","revision":"1","digest":"sha256:2e8a4b1517263dda35b8df12b36f7bc832a34d9c219b7f38f519a0dfe9e89ae6"},"evidence":[{"id":"urn:synthetic:synthetic-assessment","revision":"1","digest":"sha256:db5b99e40c471b12a69885ecb7a440356b505108170626cf9ba5aa876f705395"}],"reviewedAt":"2026-09-21T10:01:00Z","validFrom":"2026-09-21T10:01:00Z","validTo":"2026-09-22T10:01:00Z","verdict":"cleared","residualRisk":"Synthetic scenario only. No claim of inference prevention.","supersedes":null},"digest":"sha256:d6589f92d6d88c7c0bc38ed7ebbd52ec67efc31d9457524cbcab44e7f3148ca2"}],"hostSnapshot":{"format":"vercy-disclosure-host-snapshot","version":"0.1.0","dimension":"urn:synthetic:dimension:startup","asOf":"2026-09-21T12:00:00Z","proposal":{"id":"urn:synthetic:proposal:startup","revision":"1","digest":"sha256:c8dd8884a8a71580d7d2d6ead046218f8a2343dba0fe85d4605d2ab99befb46e"},"context":{"audience":{"id":"urn:synthetic:partner","revision":"1","digest":"sha256:946cad4f88aac95b3c9e37b4e7ea4badae9d3bbe4026a081493bf2d9abd014ac"},"purpose":{"id":"urn:synthetic:release-briefing","revision":"1","digest":"sha256:03d14282828be5af5be5e3e52670bb24ce2029fb9001f36dcba0ae4d6c3ce0c0"},"environment":{"id":"urn:synthetic:partner-portal","revision":"1","digest":"sha256:41f7dfc5c0ce4057e0ca4494221b4782752c76bec53842bac55ab7a20b280215"},"priorReleases":{"id":"urn:synthetic:known-prior-release-context","revision":"1","digest":"sha256:889caa5342a3a20d6e2b67e927ee8b42f1eb05a1011aebfc02b18b56b6ee8b3c"},"custodyContext":{"id":"urn:synthetic:custody-instructions","revision":"1","digest":"sha256:0195c787c48baac5b4f33db7dbc4074fe555d0737aa5bdb98496fbd600167671"}},"members":[{"key":"project-name","source":{"id":"urn:synthetic:project","revision":"1","digest":"sha256:2513f132e8ce6f5db5dffb620c821c51cf21749d53fcacaf2bb078f8075ec470"},"schema":{"id":"urn:synthetic:project-schema","revision":"1","digest":"sha256:a5286321f770e7053fc2dd59bbb186f470fad8b90739bea10c365a18277aa0f7"},"shape":{"id":"urn:synthetic:name-only-shape","revision":"1","digest":"sha256:16ddea4ffcc347f412079c04b6ede23653756f7dd7c671a492c09debeae7205e"},"fields":[{"name":"name","kind":"string","classificationBindings":[{"id":"urn:synthetic:name-classification","revision":"1","digest":"sha256:8fe9f79fe703be307af21a1fcb863dd914d2486d68fd30f2f8847468dfc9e540"}]}]}],"proposalAuthors":["urn:synthetic:founder"],"reviewers":["urn:synthetic:reviewer","urn:synthetic:founder"],"authority":{"id":"urn:synthetic:review-authority","revision":"1","digest":"sha256:6c964f0e1770cabc4a253c8afcf6fc3bf27ccac6950a3b2499ac67c880cacbee"},"activeReviews":[{"id":"urn:synthetic:review:startup","revision":"1","digest":"sha256:d6589f92d6d88c7c0bc38ed7ebbd52ec67efc31d9457524cbcab44e7f3148ca2"}],"withdrawnReviews":[],"separateReviewer":false}} END FILE examples/startup.json ## FILE invariants.md ORIGINAL SHA256 b11a6608b2fb5fb56496bc4704b95b32b12ded03bf3050f7496114f7656ea0a4 ## Sixteen semantic invariants 1. Each embedded member names exactly one source object; package membership can span objects but a projection cannot silently do so. 2. Qualified ID, record revision, source/schema revision, lifecycle/applicability and digest remain distinct. 3. All local reference occurrences of an ID agree on revision/digest; the reference cannot carry two purported current versions of that ID in one record. 4. No undeclared source value or nested/wildcard field is accepted by the metadata-only grammar. 5. A missing classification binding or evidence set cannot become an empty/public/clear default. 6. A review pins exactly the proposal identity/revision/digest; membership, shape, audience or any bound context change invalidates that match. 7. A current snapshot pins the proposal itself and independently declares all current member/context values. 8. The complete supplied review set equals the active pin set; duplicate or competing active revisions are invalid. 9. Active and withdrawn sets are disjoint; an active successor cannot leave its superseded target active. 10. Review assessment does not predate proposal capture; applicability uses `[validFrom, validTo)` and future capture is stale. 11. Current author/reviewer catalogs and authority pin are applied; segregation is explicit and actor-alias identity remains a host duty. 12. Conflicting eligible verdicts cannot silently select a winner. Excluded verdicts retain their pin, result and reason in restricted diagnostics. 13. Every returned report identifies its proposal, snapshot digest, evaluation time and counted/ignored records, and explicitly conveys no serving authorization. 14. Same stored identity/revision cannot be repointed; repeat import is idempotent and a failed merge leaves the caller's store unchanged. 15. Local review/proposal and supersession links resolve by exact pin/type, preserve proposal identity and nondecreasing assessment time, and do not cycle. 16. Pin equality, a human clearance and any custody-context reference establish no source truth, inference guarantee, current grant, legal conclusion, completed delivery or destruction. Invariants 1–15 combine local checks with clearly named host attestations; invariant 16 is a semantic boundary and is not a proof produced by unit tests. The final 24 question routes are in spec.json; each names local checks versus host/deferred responsibility. END FILE invariants.md ## FILE lifecycle/transitions.md ORIGINAL SHA256 e455ac70c2c6a71910763972563200871c9e5757ccf7bf7d78f24234f375fd6b # Lifecycle, guards and effects | Operation | Actor and guard | Effect and evidence | |---|---|---| | Draft → immutable proposal revision | Host-authorized proposer; complete closed metadata and qualified pins | seal validates structure/digest; import merges into complete register; host persists atomically and records provenance. No review implied. | | Proposal → revised proposal | Authorized proposer; same identity and new opaque revision, or new identity if package purpose/boundary no longer denotes the same governed proposal | Old bytes retained; new digest; old review pins do not apply. The semantic identity decision is host-owned. | | Record review | Attributed reviewer with separately checked write authority; exact proposal, method, evidence and ordered times | Immutable cleared/rejected/inconclusive assessment; import checks internal links; current read applicability independently checks authority. | | Correct review | Authorized reviewer/correction owner; new revision; optional exact supersedes link with same proposal identity and nondecreasing assessment time | Prior evidence preserved; active selection is a separate governance action, not a side effect of import. | | Select/withdraw current review | Authorized host governance operator; complete history and identity resolved | New external snapshot; no record mutation. Active and withdrawn sets cannot overlap. Host also deactivates transitive predecessors. | | Expiry/context drift/authority change | Evaluated under current authorized snapshot and clock | Derived insufficient-context/stale/conflict/rejected/inconclusive/applicable-review result; historical recorded verdict remains unchanged. | | Replay/import conflict | Authorized host importer; complete bounded store and exact bytes | Exact replay idempotent; same revision with different bytes rejects transaction; no silent winner. | | Dispose record | Separate actual custodian and policy; outside this reference | No method implemented. Neither immutability nor a retained digest proves an obligation to keep records forever or successful erasure. | Capture, assessment, review validity, host snapshot as-of and native storage receipt are separate axes. Revision strings do not order time. Native object active state is storage lifecycle, not an applicable review verdict. Restoration, durable conflict recording and clock recovery are host obligations. END FILE lifecycle/transitions.md ## FILE mastership-and-rights.yaml ORIGINAL SHA256 1e3f52d8e1757d594b5dd2b902e250b988a528d71c05817d3cdb419ae1b95d82 {"facts":[{"fact":"Source identity, revision and fields","semanticOwnerAndMaster":"Domain owner / its actual source master; no HR/ERP assumed","writer":"Domain-authorized writer","readerPurpose":"Only authorized proposal preparers","timeProvenance":"Exact opaque source/schema/shape pins and capture time","conflictRetention":"Source conflict remains unresolved by this companion; source custodian controls retention."},{"fact":"Classification binding","semanticOwnerAndMaster":"Designated classification authority / binding register","writer":"Authorized classifier, outside this module","readerPurpose":"Restricted preparer/reviewer scope","timeProvenance":"Exact binding record pin; source authority owns scheme, term and validity","conflictRetention":"No inferred downgrade or scheme ordering; binding itself may be sensitive."},{"fact":"Proposal revision","semanticOwnerAndMaster":"Company Dimension's proposal register","writer":"Host-authorized proposer","readerPurpose":"Internal reviewers for a declared purpose","timeProvenance":"Immutable author/capture/context; revision tokens are unordered","conflictRetention":"Same ID/revision with different content rejected; current pin selected by host."},{"fact":"Review verdict and evidence","semanticOwnerAndMaster":"Review owner / review register","writer":"Authorized attributed reviewer","readerPurpose":"Authorized review consumers, never automatically the external recipient","timeProvenance":"Assessment time and half-open validity distinct from source/capture time","conflictRetention":"Disagreeing applicable verdicts produce conflict; all evidence retained subject to actual custody rules."},{"fact":"Current authority / active set","semanticOwnerAndMaster":"Host governance register","writer":"Authorized governance operator","readerPurpose":"Internal applicability checker","timeProvenance":"Current snapshot digest and evaluation time bound in report","conflictRetention":"Snapshot completeness, withdrawal and actor identity are host assertions; stale/contradictory snapshots must not be silently repaired."},{"fact":"Supersession","semanticOwnerAndMaster":"Review register","writer":"Reviewer/owner authorized to correct a review","readerPurpose":"Authorized historical readers","timeProvenance":"Exact existing target, same proposal identity, nondecreasing assessment times","conflictRetention":"Local immutable import verifies link/digest/type/cycle constraints. Host explicitly selects active revisions."},{"fact":"Custody / previous releases","semanticOwnerAndMaster":"Named record custodians and disclosure history owners","writer":"Custodian and release recorder","readerPurpose":"Need-to-know reviewers","timeProvenance":"Exact current opaque context pins; distinct custodians may have distinct schedules","conflictRetention":"Equality is not a retention/disclosure/destruction decision. No blanket perpetual evidence-retention rule."}],"trustBoundary":"Source/current-governance/custody systems are host-owned; no credential or authority is derived from a record or capability dictionary."} END FILE mastership-and-rights.yaml ## FILE migration.md ORIGINAL SHA256 9081f90ff86cf5e8771d86194c2729f57cdd843bfd0598cb89b2322f10d94293 # Version and migration policy The only implemented transport is complete same-version JSON roundtrip and idempotent immutable import. Version 0.1.0 rejects prototype versions and all unknown versions. The version is included in the digest, so a version edit changes every record and dependent review pin. Preserve old bytes and their original validator. No automatic upgrade, downgrade, mixed-version merge or silent schema reinterpretation is offered. A future governed conversion must explicitly map proposal, review, supersession and external pins, preserve originals and attribution, identify changed meaning and obtain fresh assessments for changed packages. Re-sealing an old review under a new version must never impersonate its reviewer. Rollback is restoration of the complete verified register and matching governance state, not choosing an old clearance as a current grant. Concurrency/CAS, backups and existing-Dimension migration remain host integrations. END FILE migration.md ## FILE model-fields.md ORIGINAL SHA256 7b2c06004d84430b82bc79393a05d046fb35968b356dc1ca69f854536c4e0629 # Record fields All fields, exact grammars, maxima, enumerations and nullability are normative in disclosure.schema.json; no units apply except UTC-second timestamps. The following table identifies field groups and semantic ownership. | Group | Definition / multiplicity | Writer/master / sensitivity | |---|---|---| | Envelope | Exactly one format/version/type/Dimension/id/revision/digest | Host-authorized record owner; metadata may be sensitive | | Proposal capture | One author, one capturedAt, one of each five context pins | Proposal register; source truth owned externally | | Members | 1–32 ordered members; each one key/source/schema/shape, 1–64 fields | Proposal register declares, source/schema owners attest | | Fields | One scalar name/kind, 1–8 classification binding pins | Source and classification authorities; no payload values | | Review | One proposal pin, reviewer, authority, method; 1–16 evidence pins | Review register; restricted attributed judgment | | Review timing | reviewedAt ≤ validFrom < validTo, whole UTC seconds | Reviewer and trusted capture clock; not source-valid time | | Verdict | cleared/rejected/inconclusive, one residualRisk string | Reviewer; free text may carry sensitive facts | | Supersedes | Exactly one null or exact prior-review pin | Correction owner; same proposal identity; no implicit active-set edit | Every independent identity may have multiple immutable revisions. Each review revision refers to exactly one proposal revision; each proposal may have zero or many reviews, with a bounded complete active set for inspection. Source/member/field relationships are embedded per revision; inverse lookups are derived, never alternate masters. Deletion and cross-register retention are outside this contract. Unknown classification/evidence cannot be represented by an empty required set; request missing context before creating a valid record. END FILE model-fields.md ## FILE model-spec.md ORIGINAL SHA256 f20fe507c683b42817de56eeab70cc75874f79abb9b7e2e52894a3f8539b3989 # Enterprise Disclosure Review — semantic contract A bounded original companion for EM-XCT-05. Version 0.1.0 is a bounded reference; the publication manifest records its catalogue lifecycle. It provides metadata records and restricted applicability diagnostics, not a source-value delivery or policy-enforcement service. Publication status and reviewable-draft assurance are distinct. See review.md for actual audit scope and adoption-limits.md before integration. ## Contract Two immutable records are supported: a proposal containing 1–32 single-object metadata members, and a review referring to exactly one proposal identity/revision/digest. Members may describe the same or different objects; every member names exactly one, with one consistent revision/digest per referenced ID across the proposal. Different projections of the same object are explicitly separate members. A calculated source aggregate must already be owned/modelled by its domain. The review does not become that domain aggregate. Every proposal pins its audience, purpose, environment, known previous-release context and custody-instruction context. Every member pins source revision, source schema, output shape and 1–64 named top-level scalar fields. Every field has 1–8 exact classification-binding references. These are opaque external record pins: identity, revision and digest. This reference does not duplicate external scheme/term definitions, retrieve/interpret artifacts, validate source values or infer a classification order. The host snapshot must pin the current proposal itself, contain its complete current context/member declarations, and enumerate the complete active review-pin set. Retiring a proposal changes that current pin. Active and withdrawn review pins must be disjoint; supplied review records must equal the active set. The host attests that the selected fields are scalar leaves of a closed source schema and that its external pins actually resolve to their declared objects, classifications and current custody context. The reference checks exact agreement, not the truth or completeness of those assertions. Merely echoing the caller's proposal as the host snapshot defeats the integration contract. Examples are stamped host-internal synthetic fixtures and are not a source resolver or integration template. The whole snapshot is validated against a closed schema and exact identifier grammar before returning any record result. Active review IDs are unique; active/withdrawn overlap is rejected by identity/revision even if their digests differ. Withdrawn-pin existence and historical provenance remain host attestations. Snapshot `asOf` must equal the trusted host's supplied evaluation `now`; this binds the declared time but does not attest clock accuracy or that authority/source observations actually came from that instant. A current snapshot cannot be relabeled as historical evidence without a genuine preserved snapshot from that time. `inspect()` returns restricted internal applicability diagnostics. It requires a **trusted host assertion** for Dimension and inspect capability before inspecting record contents. This assertion is not an authentication token, signature or user request field. The host must authenticate and authorize the request separately. No result is suitable for forwarding verbatim to a recipient. Uniform HTTP refusal, timing/existence protection and actual serving are not implemented. Current author/reviewer authority, exact context/membership, the complete review set, withdrawal and the half-open review interval `[validFrom, validTo)` affect applicability. Assessment time cannot predate proposal capture, even for an unauthoritative review; future capture is stale. A cleared applicable review yields `applicable-review`. Every return carries `notServingAuthorization=true`, the proposal pin, snapshot digest, evaluation time, counted review pins, ignored pins/verdicts/reasons and the withdrawn-pin list. These are restricted diagnostics. All verdicts, including negative/inconclusive ones, cease to contribute outside their declared windows or current authority; expiration alone never grants clearance, and ignored negatives remain visible alongside any independently valid clearance. Hosts requiring persistent objections need a different explicitly reviewed profile. Rejection, inconclusive assessment, absent/expired review, stale context and conflicting eligible verdicts remain distinct. Only one active revision per review identity is accepted, and an active review cannot immediately supersede another still-active review. An explicit startup profile permits self-clearance; segregation profiles require a different reviewer for clearance. An authorized author's rejection or inconclusive assessment still counts under segregation and conflicts with another reviewer's clearance. Qualified ASCII actor strings are compared exactly; the host must bind them to actual distinct people where required, rather than aliases. These are governance choices, not a NIST conformance claim. Early stale/context results have `reviewsEvaluated=false`, with no verdict analysis; counted/ignored visibility applies after review evaluation. The `priorReleases` pin records the host's known relevant release context, not all knowledge held by every recipient. Human clearance and exact pins do not prove privacy, prevent subtraction/re-identification, or erase earlier releases. `custodyContext` is an opaque pin to separately owned instructions, including any unresolved hold/schedule conflict. Its equality establishes neither permission nor prohibition to retain, serve or destroy. No actual disposition-state calculation exists here. The matrix example contains an explicit reviewer rejection of a synthetic subtraction risk; the code does not discover the risk itself. There is no structured source-value payload field, but free-text `residualRisk` and identifiers can themselves contain sensitive facts. The code neither detects nor redacts them. Authors must avoid copying source values into notes unless their actual record policy permits it. Actor identifiers, notes, diagnostic pins and past revisions need their own access and custody controls. Immutability means no silent in-place revision, not a universal obligation to retain personal data forever; disposal of records remains a separately governed host operation. ## Identity, time and changes The digest is SHA-256 over the entire record with only its top-level `digest` member removed. Format, type/version, Dimension, identity, revision and body are included. Encoding is a named local restricted JSON representation: UTF-8, sorted string keys, compact separators, no floats/nonfinite values or Unicode normalization; list order is significant. This is not RFC 8785/JCS. Identifiers use exact scheme-bearing printable ASCII syntax; revisions/member keys use nonempty ASCII letters/digits/dot/underscore/hyphen tokens, with no whitespace. Code uses full-string matching in addition to JSON Schema patterns. No URI equivalence or identifier-alias resolution is claimed. Encoding rules: keys sort by Unicode scalar/code-point order; quote and backslash use `\"` and `\\`; backspace/form-feed/newline/carriage-return/tab use `\b`, `\f`, `\n`, `\r`, `\t`; other U+0000–001F characters use lowercase four-digit `\u00xx`; slash, DEL, U+2028/U+2029 and other permitted scalar characters are emitted literally in UTF-8. Integers use ordinary base-10 without a plus sign or leading zeros; booleans/null are lowercase JSON tokens. Surrogates and Python container/string subclasses are rejected. The tests include a literal byte vector with C0 controls, U+2028, quote and backslash. No independently implemented cross-language/native digest compatibility is claimed. JSON input rejects duplicate keys, invalid UTF-8 and non-integer numeric syntax. Dictionary APIs are not wire parsers; the host must use `load()` for serialized input. No missing offset or leap-second support: timestamps are actual calendar instants in whole UTC seconds with `Z`. Calendar parsing avoids platform-dependent year formatting. Field `kind: number` describes external source metadata only; this format carries no numeric source payload. `seal()` computes content integrity and validates local structure. It does not approve content. `import_records()` performs a pure transactional immutable merge of the complete local master set: same revision+digest is idempotent; a conflicting revision fails; corrections use a new revision and preserve history. It requires both inspect and record host assertions. It does not persist, authenticate the writer's object-specific role, compare-and-swap a database, or enforce review authority at write time. The host must do those things. Imported unauthoritative reviews may be retained as evidence but cannot count as applicable under a different current authority snapshot. The import validates internal review→proposal and optional review→superseded-review pins against that full local set: exact existence/digest, correct type, same proposal identity for supersession, nondecreasing assessment times and acyclic supersession links. Self-supersession of the same identity/revision is invalid. Supersession does not automatically change authority or the host's active set. Same-second corrections can be ordered by the explicit link; opaque revision strings have no numeric/lexical ordering meaning. A snapshot inspection assumes those store-level invariants were enforced at import; it additionally rejects multiple active revisions and a still-active superseded target. The inspection check covers only immediate supersession edges in the supplied active records. The host must deactivate transitive superseded ancestors too; inspect cannot recover an omitted intermediate record. Supersession forks and replacement across revisions of the same proposal identity are permitted; current governance must resolve the active set without silently selecting a winner. Import's cycle traversal is defensive; constructing a digest-consistent cycle is not part of the executed fixture evidence. Reference coherence concerns nested reference pins; it does not reserve the envelope's own ID as an external-reference namespace. Historical answers need preserved snapshots and current permission to read those records; each returned answer pins its input snapshot. No past serving decision is reusable as a current grant. Prototype R1/R2/R3 records are refused by 0.1.0; preserve and inspect them with their original frozen schema/reference. The release version changes every record digest; do not relabel or automatically reseal old evidence. No automatic mixed-version import, upgrade or downgrade exists. A future release needs explicit migration mappings and separate version dispatch rather than reinterpretation of stored bytes. ## Execution and limits Run `python test_disclosure.py` with Python 3.11+ and `jsonschema==4.26.0`. This writes a test report and three synthetic fixtures. The reference has no network, data-serving or destruction operation. Input bounds (256 KiB, depth 20, at most 128 entries in a generic list/object, 32 members, 64 fields/member) are reference constraints, not a tested denial-of-service protection. The byte cap can bind before all cardinality maxima are reached. The report records code/schema/test/README hashes and Python/jsonschema versions. Additional bounds: at most 64 supplied active reviews, 64 active pins, 64 withdrawn pins and 64 entries per actor catalog; immutable merge requires the complete local master set, and `len(existing)+len(incoming)` cannot exceed 128 even for an idempotent replay. This reference cannot scale by silently partitioning away required internal references. A real rollover/partition/migration design is future work. The test report is written after fixtures and also hashes their exact generated bytes. The code version is checked against both record schema constants on module load. The tests include three profiles, schema/classification/context drift, changed membership/fields/order, known prior-release/custody-context changes, withdrawn authority, reviewer segregation, half-open expiry, equal-authority conflict, incomplete review sets, immutable correction/import, internal supersession links, type preservation, rights assertions, malformed/unsupported JSON, identifier-alias edge cases, nested-field rejection and round-trip. They do not test a real source resolver, policy engine, schema compiler, reviewer judgment, custodian, database concurrency, recipient channel or native V3 engine in this unit suite. Native synthetic checks are recorded separately in acceptance-results.json. See the current test report for the executed count. The semantic tree is in spec.json. Native V3 binding stores each proposal/review identity as its own object and each immutable revision as a separate restricted fact. Native storage time is distinct from proposal capture and review validity. All revision facts coexist; native fact supersession does not select the active review. Validate native envelopes, validate_native(), the complete local register through import_records(), and inspect() under independently obtained current host state. The explicit companion calls are not automatically dispatched by V3. ## Release clarifications after the R3 prototype audits Host snapshots carry an exact format/version and every answer carries evaluatorVersion. Snapshot activeReviews is scoped to the exact proposal revision, not all revisions of that proposal identity. Inspection additionally refuses proposal/review identity collision and any active immediate supersession target by identity/revision, including conflicting digests. Assessment after the evaluation instant, not-yet-valid intervals and expired reviews have distinct ignored reasons. Earlier authority/segregation exclusions remain the first reason if several exclusions apply. Reference coherence enforces one revision/digest per referenced ID across all roles in a record, including evidence. It cannot cite an earlier revision of that same ID as a diff baseline in the same record; use a separately identified externally governed diff artifact, without pretending it is the earlier object itself. Ignored supplied reviews retain verdict/reason. Withdrawn reviews are represented by pins only; retrieve their historical records under current read authority for their verdict. Maximum string length is 4096 Unicode code points. The closed bounds remain operational limits, not a hostile-input protection claim. The 128 bound applies to the complete current local register plus incoming batch; repeated import also consumes the batch count. It is not a monotone lifetime counter. With indefinite historical retention it is effectively a 128-record growth ceiling. Partial disposal leaving an internal dangling proposal/supersession reference makes subsequent import invalid. This implementation offers no tombstone semantics or disposal/migration operation. Any separate host disposal must preserve internal reference closure; replacing records with fabricated tombstones or silently dropping required history is not supported. Retention constraints may forbid even a reference-closed removal, so obtain the actual custody decision. END FILE model-spec.md ## FILE publication-manifest.draft ORIGINAL SHA256 b860a31d02a00c697e80e3ff28c38f55de58cc1fa1d10cf399560c39034062aa { "registryId": "vr.profile.enterprise-disclosure-review", "version": "0.1.0", "registryRole": "original-companion-contract", "status": "candidate-not-published", "immutableRef": "https://ver.cy/models/enterprise-disclosure-review/versions/0.1.0/spec.json", "semanticFingerprint": null, "contourStatus": "partial" } END FILE publication-manifest.draft ## FILE README.md ORIGINAL SHA256 12eef4a96880354b73e5a9bdb1db27afc977a8fffabd24743729c1b07be51bbc # Enterprise Disclosure Review Prepare an exact proposal of single-object metadata projections; record independent reviews of their combined disclosure risks; inspect whether those reviews apply under a trusted current governance snapshot. No result grants permission to serve data. Start with one ContextPackageProposal and one JointDisclosureReview. Run `python test_disclosure.py` after installing requirements.txt. Read model-spec.md for every input boundary, spec.json for the question tree, and adoption-limits.md for host responsibilities. Examples are synthetic startup, matrix group and AI release cases, not claims about real companies. Native synthetic integration: `python acceptance.py --composer PATH_TO_PINNED_COMPOSER --skill PATH_TO_PINNED_VERCY_SKILL --report acceptance-results.json`. tool-pins.json pins every required external tool asset. The composer is a test/toolchain dependency, not an inherited domain model. This tests three fresh Dimensions; no existing-Dimension migration or production adapter is implied. Canonical catalogue: https://ver.cy/models/enterprise-disclosure-review/. Research evidence: https://ver.cy/enterprise/research/em-xct-05/. English authored specification; provider evidence retains its original language. END FILE README.md ## FILE requirements.txt ORIGINAL SHA256 756cc9e506ae4ee1a6f6c0507088b5cfc0dc8ba350fb2d2d46f1ffa72033adb6 jsonschema==4.26.0 END FILE requirements.txt ## FILE research.md ORIGINAL SHA256 ddc96e493fd410e364eaccbf093dae03732d46e90e95060e8d5ac0e5c680c930 # Research and reconciliation Read boundary-decision.md for the chosen two-type design and crosswalk.json for exact predecessor pins and inherited holds. source-verification.json preserves five primary-source comparisons across policy expression, access/disclosure governance and implemented storage behavior. These are design comparisons, not certifications or legal advice. No external schema or classifier is copied. The actual independent Claude and Grok studies, exact common brief, provider identities and response hashes are preserved at https://ver.cy/enterprise/research/em-xct-05/. Their proposed richer objects were reconciled into a bounded metadata-only companion. Record types, field/path limitations, current host duties and unsupported retention mechanisms are explicit. Raw provider opinions are not normalized into claims of code execution or unanimous agreement. END FILE research.md ## FILE runtime-model.reference.json ORIGINAL SHA256 123dd5d1a1c64c0be5fbb0041d05d6e96f161b9d8e77eeb0aea69126eca152a6 {"format":"vercy-runtime-model-schema","schemaVersion":"1.0.0","modelId":"vr.profile.enterprise-disclosure-review","paths":{"disclosure.proposal.revision":{"valueTypes":["object"],"units":[null]},"disclosure.review.revision":{"valueTypes":["object"],"units":[null]}}} END FILE runtime-model.reference.json ## FILE source-verification.json ORIGINAL SHA256 be1aaf130043b48239422b935714962cf173945c5154e706a9192ac9e0fe1b49 {"contour":"EM-XCT-05","stage":"Codex direct research before provider reconciliation","checkedOn":"2026-09-21","claimScope":"Only the named passages were read. This does not verify every claim, historical citation or normative conformance in the parent models.","sources":[{"id":"S1","url":"https://www.w3.org/TR/2018/REC-odrl-model-20180215/","retrievedUrl":"https://www.w3.org/TR/odrl-model/","edition":"ODRL Information Model 2.2, W3C Recommendation, 15 February 2018","sectionsRead":["1.3 Terminology","2.1 Policy","2.9 Inheritance","2.10 Conflict Strategy","3.2 Profile Conformance"],"evidence":"observed","observed":"The model separates policy validation from evaluation and names permission, prohibition and duty. Conflict handling is explicit, defaulting to invalid; an unrecognized declared profile stops processing.","inference":"Our reference must distinguish a well-formed declaration from a current serving decision and reject unsupported policy semantics.","limit":"Conceptual comparison only; no ODRL serializer, evaluator or conformance claim."},{"id":"S2","url":"https://www.w3.org/TR/odrl-vocab/","edition":"ODRL Vocabulary and Expression 2.2, W3C Recommendation, 15 February 2018","sectionsRead":["4.4.4 Anonymize","4.5.19 Purpose"],"evidence":"observed","observed":"Purpose is a rule-action operand; anonymize is an action vocabulary term.","inference":"Naming an action supplies neither an implemented transformation nor a measured disclosure guarantee.","limit":"No anonymization algorithm or quantitative privacy mechanism is imported."},{"id":"S3","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-162.pdf","landingUrl":"https://csrc.nist.gov/pubs/sp/800/162/upd2/final","edition":"NIST SP 800-162, January 2014, updated 2 August 2019","sectionsRead":["Abstract","2.4.3, printed pages 14–16, PDF pages 23–25"],"evidence":"observed","observed":"ABAC evaluates subject, object, operation and context attributes under policy. Decision, enforcement, information and administration are distinct cooperating functions.","inference":"A package review artifact must not present itself as enforcement. Host authentication, fresh attributes and atomic serving controls are separate integration requirements.","limit":"No complete ABAC implementation or NIST certification is claimed."},{"id":"S4","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-188.pdf","landingUrl":"https://csrc.nist.gov/pubs/sp/800/188/final","edition":"NIST SP 800-188, September 2023","sectionsRead":["Abstract","3.4 closing discussion, printed page 33","3.5 Five Safes, printed pages 33–34","3.6 Disclosure Review Boards, printed pages 34–35"],"evidence":"observed","observed":"Repeated releases and external data can create disclosure risks despite vetted individual queries. Review boards provide accountable governance; project, people, data, setting and output risks require distinct consideration.","inference":"Pin the exact combination and its relevant prior-release context. A positive manual review is an attributed assessment, not a mathematical guarantee against inference.","limit":"US government guidance is used for design comparison, not a universal enterprise law or a claim of anonymization."},{"id":"S5","url":"https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock.html","edition":"Living vendor documentation read 21 September 2026","sectionsRead":["How Object Lock works","Legal holds","How deletes work with S3 Object Lock"],"evidence":"observed","observed":"Retention and hold protection attaches to object versions. A hold can remain after retention expires. A simple delete may create a delete marker while leaving a protected version intact.","inference":"Stop-serving, a deletion marker, actual version destruction and verified disposal must be separate records; a hold and retention schedule are independent constraints.","limit":"This is a concrete storage counterexample, not an S3 adapter or general legal-retention rule. No vendor-specific code is copied."}],"schools":["Policy expression standards","Access and disclosure governance guidance","Implemented versioned storage behavior"],"unavailable":[{"url":"https://w3c.github.io/dpv/2.0/dpv/","result":"Moved page only; substantive vocabulary not read"},{"url":"https://w3id.org/dpv/2.1/","result":"Browser research tool returned Internal Error; no field or version claim adopted"}],"licensing":"Original paraphrases and original proposed contracts only. No third-party schema or classifier is copied; confirm licenses before any future import."} END FILE source-verification.json ## FILE spec.json ORIGINAL SHA256 0a0b6926ba2faab5b7ce72063397cdd27132fa747e7f9bcd8ef5ea18e09afa71 {"metaModel":{"id":"enterprise-disclosure-review","registryId":"vr.profile.enterprise-disclosure-review","version":"0.1.0","name":"Enterprise Disclosure Review","kind":"companion-contract"},"canonicalUrl":"https://ver.cy/models/enterprise-disclosure-review/versions/0.1.0/spec.json","researchAssurance":"reviewable-draft","researchContour":"EM-XCT-05","model":{"purpose":"Describe exact packages of single-object metadata projections, preserve attributed joint-disclosure reviews, and check their applicability under explicit current context."},"composition":{"runtimeImports":[],"semanticReferences":[{"id":"WM-XCT-002","version":"0.3.0-research.1","specDigest":"sha256:9085d977567f3e1fc0b9bb27c6a7c517139f5972a1b95bf4a2bedccdb10bf2db","relation":"selected-semantic-overlap-not-subtype"},{"id":"WM-XCT-003","version":"0.3.0-research.1","specDigest":"sha256:058191fe49bd1a52d52669211893d91971511f33a2aad1f15407e409d2553edb","relation":"selected-semantic-overlap-not-subtype"},{"id":"WM-XCT-020","version":"0.3.0-research.1","specDigest":"sha256:47aa90ca48b7e367f61c30e454fd7859ba2dc7e2b998bbd4541acb6eda81b9bd","relation":"selected-semantic-overlap-not-subtype"},{"id":"WM-DAT-004","version":"0.3.0-research.1","specDigest":"sha256:0c6fc7db12c33efe0d9283b5830b4c679935dd5b640417e7e315a564b4971c94","relation":"selected-semantic-overlap-not-subtype"},{"id":"WM-KNW-012","version":"0.3.0-research.1","specDigest":"sha256:b7a880e4e07b26f8962e8d3b5b23b33c1062abcb83303ff8f0e8b5a3134e61b8","relation":"selected-semantic-overlap-not-subtype"}],"delivery":"Original reference, closed schema, synthetic fixtures, contract and native binding; external pins are not executable imports."},"contract":"# Enterprise Disclosure Review — semantic contract\n\nA bounded original companion for EM-XCT-05. Version 0.1.0 is a bounded reference; the publication manifest records its catalogue lifecycle. It provides metadata records and restricted applicability diagnostics, not a source-value delivery or policy-enforcement service. Publication status and reviewable-draft assurance are distinct. See review.md for actual audit scope and adoption-limits.md before integration.\n\n## Contract\n\nTwo immutable records are supported: a proposal containing 1–32 single-object metadata members, and a review referring to exactly one proposal identity/revision/digest. Members may describe the same or different objects; every member names exactly one, with one consistent revision/digest per referenced ID across the proposal. Different projections of the same object are explicitly separate members. A calculated source aggregate must already be owned/modelled by its domain. The review does not become that domain aggregate.\n\nEvery proposal pins its audience, purpose, environment, known previous-release context and custody-instruction context. Every member pins source revision, source schema, output shape and 1–64 named top-level scalar fields. Every field has 1–8 exact classification-binding references. These are opaque external record pins: identity, revision and digest. This reference does not duplicate external scheme/term definitions, retrieve/interpret artifacts, validate source values or infer a classification order.\n\nThe host snapshot must pin the current proposal itself, contain its complete current context/member declarations, and enumerate the complete active review-pin set. Retiring a proposal changes that current pin. Active and withdrawn review pins must be disjoint; supplied review records must equal the active set. The host attests that the selected fields are scalar leaves of a closed source schema and that its external pins actually resolve to their declared objects, classifications and current custody context. The reference checks exact agreement, not the truth or completeness of those assertions. Merely echoing the caller's proposal as the host snapshot defeats the integration contract. Examples are stamped host-internal synthetic fixtures and are not a source resolver or integration template.\n\nThe whole snapshot is validated against a closed schema and exact identifier grammar before returning any record result. Active review IDs are unique; active/withdrawn overlap is rejected by identity/revision even if their digests differ. Withdrawn-pin existence and historical provenance remain host attestations. Snapshot `asOf` must equal the trusted host's supplied evaluation `now`; this binds the declared time but does not attest clock accuracy or that authority/source observations actually came from that instant. A current snapshot cannot be relabeled as historical evidence without a genuine preserved snapshot from that time.\n\n`inspect()` returns restricted internal applicability diagnostics. It requires a **trusted host assertion** for Dimension and inspect capability before inspecting record contents. This assertion is not an authentication token, signature or user request field. The host must authenticate and authorize the request separately. No result is suitable for forwarding verbatim to a recipient. Uniform HTTP refusal, timing/existence protection and actual serving are not implemented.\n\nCurrent author/reviewer authority, exact context/membership, the complete review set, withdrawal and the half-open review interval `[validFrom, validTo)` affect applicability. Assessment time cannot predate proposal capture, even for an unauthoritative review; future capture is stale. A cleared applicable review yields `applicable-review`. Every return carries `notServingAuthorization=true`, the proposal pin, snapshot digest, evaluation time, counted review pins, ignored pins/verdicts/reasons and the withdrawn-pin list. These are restricted diagnostics. All verdicts, including negative/inconclusive ones, cease to contribute outside their declared windows or current authority; expiration alone never grants clearance, and ignored negatives remain visible alongside any independently valid clearance. Hosts requiring persistent objections need a different explicitly reviewed profile.\n\nRejection, inconclusive assessment, absent/expired review, stale context and conflicting eligible verdicts remain distinct. Only one active revision per review identity is accepted, and an active review cannot immediately supersede another still-active review. An explicit startup profile permits self-clearance; segregation profiles require a different reviewer for clearance. An authorized author's rejection or inconclusive assessment still counts under segregation and conflicts with another reviewer's clearance. Qualified ASCII actor strings are compared exactly; the host must bind them to actual distinct people where required, rather than aliases. These are governance choices, not a NIST conformance claim. Early stale/context results have `reviewsEvaluated=false`, with no verdict analysis; counted/ignored visibility applies after review evaluation.\n\nThe `priorReleases` pin records the host's known relevant release context, not all knowledge held by every recipient. Human clearance and exact pins do not prove privacy, prevent subtraction/re-identification, or erase earlier releases. `custodyContext` is an opaque pin to separately owned instructions, including any unresolved hold/schedule conflict. Its equality establishes neither permission nor prohibition to retain, serve or destroy. No actual disposition-state calculation exists here. The matrix example contains an explicit reviewer rejection of a synthetic subtraction risk; the code does not discover the risk itself.\n\nThere is no structured source-value payload field, but free-text `residualRisk` and identifiers can themselves contain sensitive facts. The code neither detects nor redacts them. Authors must avoid copying source values into notes unless their actual record policy permits it. Actor identifiers, notes, diagnostic pins and past revisions need their own access and custody controls. Immutability means no silent in-place revision, not a universal obligation to retain personal data forever; disposal of records remains a separately governed host operation.\n\n## Identity, time and changes\n\nThe digest is SHA-256 over the entire record with only its top-level `digest` member removed. Format, type/version, Dimension, identity, revision and body are included. Encoding is a named local restricted JSON representation: UTF-8, sorted string keys, compact separators, no floats/nonfinite values or Unicode normalization; list order is significant. This is not RFC 8785/JCS. Identifiers use exact scheme-bearing printable ASCII syntax; revisions/member keys use nonempty ASCII letters/digits/dot/underscore/hyphen tokens, with no whitespace. Code uses full-string matching in addition to JSON Schema patterns. No URI equivalence or identifier-alias resolution is claimed.\n\nEncoding rules: keys sort by Unicode scalar/code-point order; quote and backslash use `\\\"` and `\\\\`; backspace/form-feed/newline/carriage-return/tab use `\\b`, `\\f`, `\\n`, `\\r`, `\\t`; other U+0000–001F characters use lowercase four-digit `\\u00xx`; slash, DEL, U+2028/U+2029 and other permitted scalar characters are emitted literally in UTF-8. Integers use ordinary base-10 without a plus sign or leading zeros; booleans/null are lowercase JSON tokens. Surrogates and Python container/string subclasses are rejected. The tests include a literal byte vector with C0 controls, U+2028, quote and backslash. No independently implemented cross-language/native digest compatibility is claimed.\n\nJSON input rejects duplicate keys, invalid UTF-8 and non-integer numeric syntax. Dictionary APIs are not wire parsers; the host must use `load()` for serialized input. No missing offset or leap-second support: timestamps are actual calendar instants in whole UTC seconds with `Z`. Calendar parsing avoids platform-dependent year formatting. Field `kind: number` describes external source metadata only; this format carries no numeric source payload.\n\n`seal()` computes content integrity and validates local structure. It does not approve content. `import_records()` performs a pure transactional immutable merge of the complete local master set: same revision+digest is idempotent; a conflicting revision fails; corrections use a new revision and preserve history. It requires both inspect and record host assertions. It does not persist, authenticate the writer's object-specific role, compare-and-swap a database, or enforce review authority at write time. The host must do those things. Imported unauthoritative reviews may be retained as evidence but cannot count as applicable under a different current authority snapshot.\n\nThe import validates internal review→proposal and optional review→superseded-review pins against that full local set: exact existence/digest, correct type, same proposal identity for supersession, nondecreasing assessment times and acyclic supersession links. Self-supersession of the same identity/revision is invalid. Supersession does not automatically change authority or the host's active set. Same-second corrections can be ordered by the explicit link; opaque revision strings have no numeric/lexical ordering meaning. A snapshot inspection assumes those store-level invariants were enforced at import; it additionally rejects multiple active revisions and a still-active superseded target.\n\nThe inspection check covers only immediate supersession edges in the supplied active records. The host must deactivate transitive superseded ancestors too; inspect cannot recover an omitted intermediate record. Supersession forks and replacement across revisions of the same proposal identity are permitted; current governance must resolve the active set without silently selecting a winner. Import's cycle traversal is defensive; constructing a digest-consistent cycle is not part of the executed fixture evidence. Reference coherence concerns nested reference pins; it does not reserve the envelope's own ID as an external-reference namespace.\n\nHistorical answers need preserved snapshots and current permission to read those records; each returned answer pins its input snapshot. No past serving decision is reusable as a current grant. Prototype R1/R2/R3 records are refused by 0.1.0; preserve and inspect them with their original frozen schema/reference. The release version changes every record digest; do not relabel or automatically reseal old evidence. No automatic mixed-version import, upgrade or downgrade exists. A future release needs explicit migration mappings and separate version dispatch rather than reinterpretation of stored bytes.\n\n## Execution and limits\n\nRun `python test_disclosure.py` with Python 3.11+ and `jsonschema==4.26.0`. This writes a test report and three synthetic fixtures. The reference has no network, data-serving or destruction operation. Input bounds (256 KiB, depth 20, at most 128 entries in a generic list/object, 32 members, 64 fields/member) are reference constraints, not a tested denial-of-service protection. The byte cap can bind before all cardinality maxima are reached. The report records code/schema/test/README hashes and Python/jsonschema versions.\n\nAdditional bounds: at most 64 supplied active reviews, 64 active pins, 64 withdrawn pins and 64 entries per actor catalog; immutable merge requires the complete local master set, and `len(existing)+len(incoming)` cannot exceed 128 even for an idempotent replay. This reference cannot scale by silently partitioning away required internal references. A real rollover/partition/migration design is future work. The test report is written after fixtures and also hashes their exact generated bytes. The code version is checked against both record schema constants on module load.\n\nThe tests include three profiles, schema/classification/context drift, changed membership/fields/order, known prior-release/custody-context changes, withdrawn authority, reviewer segregation, half-open expiry, equal-authority conflict, incomplete review sets, immutable correction/import, internal supersession links, type preservation, rights assertions, malformed/unsupported JSON, identifier-alias edge cases, nested-field rejection and round-trip. They do not test a real source resolver, policy engine, schema compiler, reviewer judgment, custodian, database concurrency, recipient channel or native V3 engine in this unit suite. Native synthetic checks are recorded separately in acceptance-results.json. See the current test report for the executed count.\n\nThe semantic tree is in spec.json. Native V3 binding stores each proposal/review identity as its own object and each immutable revision as a separate restricted fact. Native storage time is distinct from proposal capture and review validity. All revision facts coexist; native fact supersession does not select the active review. Validate native envelopes, validate_native(), the complete local register through import_records(), and inspect() under independently obtained current host state. The explicit companion calls are not automatically dispatched by V3.\n\n## Release clarifications after the R3 prototype audits\n\nHost snapshots carry an exact format/version and every answer carries evaluatorVersion. Snapshot activeReviews is scoped to the exact proposal revision, not all revisions of that proposal identity. Inspection additionally refuses proposal/review identity collision and any active immediate supersession target by identity/revision, including conflicting digests. Assessment after the evaluation instant, not-yet-valid intervals and expired reviews have distinct ignored reasons. Earlier authority/segregation exclusions remain the first reason if several exclusions apply.\n\nReference coherence enforces one revision/digest per referenced ID across all roles in a record, including evidence. It cannot cite an earlier revision of that same ID as a diff baseline in the same record; use a separately identified externally governed diff artifact, without pretending it is the earlier object itself.\n\nIgnored supplied reviews retain verdict/reason. Withdrawn reviews are represented by pins only; retrieve their historical records under current read authority for their verdict. Maximum string length is 4096 Unicode code points. The closed bounds remain operational limits, not a hostile-input protection claim.\n\nThe 128 bound applies to the complete current local register plus incoming batch; repeated import also consumes the batch count. It is not a monotone lifetime counter. With indefinite historical retention it is effectively a 128-record growth ceiling. Partial disposal leaving an internal dangling proposal/supersession reference makes subsequent import invalid. This implementation offers no tombstone semantics or disposal/migration operation. Any separate host disposal must preserve internal reference closure; replacing records with fabricated tombstones or silently dropping required history is not supported. Retention constraints may forbid even a reference-closed removal, so obtain the actual custody decision.\n","structure":{"bundles":[{"id":"DR-B-identity","name":"Identity and classification","description":"Identity and classification for an exact metadata proposal and attributed joint review.","layers":[{"id":"DR-L-subject","name":"Objects and proposal boundary","description":"Objects and proposal boundary with explicit local and external responsibilities.","findings":[{"id":"DR-F01","name":"Which single object does each member describe?","description":"Coverage: local-structure; external identity truth.","questions":[{"id":"DR-Q01","text":"Which single object does each member describe?","kind":"governed-context","answer_data":["One qualified source pin per member; locally unique member key","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A01","name":"One qualified source pin per member; locally unique member key","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT01","description":"Validate exact member grammar; ask domain steward for identity evidence. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local-structure; external identity truth"},{"id":"DR-F02","name":"Which exact source revision and schema were used?","description":"Coverage: local-equality; host resolution.","questions":[{"id":"DR-Q02","text":"Which exact source revision and schema were used?","kind":"governed-context","answer_data":["Source and schema pins plus proposal capture time","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A02","name":"Source and schema pins plus proposal capture time","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT02","description":"Compare exact pins; request independently resolved source metadata. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local-equality; host resolution"},{"id":"DR-F03","name":"Is this a projection, a package or a domain aggregate?","description":"Coverage: modeled boundary; calculation outside scope.","questions":[{"id":"DR-Q03","text":"Is this a projection, a package or a domain aggregate?","kind":"governed-context","answer_data":["Proposal boundary; one object per member; separately owned aggregate definition","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A03","name":"Proposal boundary; one object per member; separately owned aggregate definition","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT03","description":"Keep member/package identities distinct; ask domain owner for aggregate calculation. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"modeled boundary; calculation outside scope"}]},{"id":"DR-L-classification","name":"Classification references","description":"Classification references with explicit local and external responsibilities.","findings":[{"id":"DR-F04","name":"Which classification binds every selected field?","description":"Coverage: local cardinality; external binding interpretation.","questions":[{"id":"DR-Q04","text":"Which classification binds every selected field?","kind":"governed-context","answer_data":["One or more exact classification-binding pins per field; external scheme and term","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A04","name":"One or more exact classification-binding pins per field; external scheme and term","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT04","description":"Reject missing bindings; ask classification authority for pinned scheme and term. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local cardinality; external binding interpretation"},{"id":"DR-F05","name":"Who may correct or downgrade a classification?","description":"Coverage: host-only authority; no classification mutation.","questions":[{"id":"DR-Q05","text":"Who may correct or downgrade a classification?","kind":"governed-context","answer_data":["Current classification authority and correction evidence","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A05","name":"Current classification authority and correction evidence","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT05","description":"Request a governed correction; do not change an opaque pin as a downgrade. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"host-only authority; no classification mutation"},{"id":"DR-F06","name":"Are schemes or compartments comparable?","description":"Coverage: deferred comparison engine.","questions":[{"id":"DR-Q06","text":"Are schemes or compartments comparable?","kind":"governed-context","answer_data":["Explicit pinned mapping and combination rule from classification owner","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A06","name":"Explicit pinned mapping and combination rule from classification owner","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT06","description":"Return insufficient-context for unsupported comparison. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"deferred comparison engine"}]}]},{"id":"DR-B-disclosure","name":"Proposed disclosure and current authority","description":"Proposed disclosure and current authority for an exact metadata proposal and attributed joint review.","layers":[{"id":"DR-L-shape","name":"Closed metadata shape","description":"Closed metadata shape with explicit local and external responsibilities.","findings":[{"id":"DR-F07","name":"Which fields are proposed for disclosure?","description":"Coverage: local declaration; no payload serving.","questions":[{"id":"DR-Q07","text":"Which fields are proposed for disclosure?","kind":"governed-context","answer_data":["Exact ordered field names/kinds, shape/schema pins and complete current declarations","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A07","name":"Exact ordered field names/kinds, shape/schema pins and complete current declarations","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT07","description":"Validate metadata selection; ask host for separate current serving authorization. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local declaration; no payload serving"},{"id":"DR-F08","name":"Can nested values introduce another object?","description":"Coverage: local syntax; scalar truth is host attestation.","questions":[{"id":"DR-Q08","text":"Can nested values introduce another object?","kind":"governed-context","answer_data":["Closed scalar source-field attestation; declared top-level field grammar","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A08","name":"Closed scalar source-field attestation; declared top-level field grammar","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT08","description":"Reject nested/wildcard field names; require separate member for another object. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local syntax; scalar truth is host attestation"},{"id":"DR-F09","name":"Can notes, identifiers, counts or errors reveal withheld facts?","description":"Coverage: manual assessment; no leakage detector.","questions":[{"id":"DR-Q09","text":"Can notes, identifiers, counts or errors reveal withheld facts?","kind":"governed-context","answer_data":["Residual-risk review and restricted diagnostic-channel design","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A09","name":"Residual-risk review and restricted diagnostic-channel design","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT09","description":"Record concern; keep reports internal; ask host to assess side channels. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"manual assessment; no leakage detector"}]},{"id":"DR-L-authority","name":"Current authority and freshness","description":"Current authority and freshness with explicit local and external responsibilities.","findings":[{"id":"DR-F10","name":"What current grant permits this audience and purpose?","description":"Coverage: outside implementation; mandatory before serving.","questions":[{"id":"DR-Q10","text":"What current grant permits this audience and purpose?","kind":"governed-context","answer_data":["Actual host policy/grant decision with fresh subject/object/operation/context","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A10","name":"Actual host policy/grant decision with fresh subject/object/operation/context","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT10","description":"Request host decision; no review status establishes a grant. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"outside implementation; mandatory before serving"},{"id":"DR-F11","name":"Has context changed since assessment?","description":"Coverage: local exact comparison; host completeness.","questions":[{"id":"DR-Q11","text":"Has context changed since assessment?","kind":"governed-context","answer_data":["Current proposal, member, classification, audience, purpose, environment, prior-release and custody pins","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A11","name":"Current proposal, member, classification, audience, purpose, environment, prior-release and custody pins","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT11","description":"Compare all declared current inputs; return stale on disagreement. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local exact comparison; host completeness"},{"id":"DR-F12","name":"May an earlier result be reused now?","description":"Coverage: local applicability; cache/atomic serving external.","questions":[{"id":"DR-Q12","text":"May an earlier result be reused now?","kind":"governed-context","answer_data":["Fresh authorized snapshot, current clock and complete active review set","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A12","name":"Fresh authorized snapshot, current clock and complete active review set","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT12","description":"Reevaluate; retain old snapshot only as historical evidence. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local applicability; cache/atomic serving external"}]}]},{"id":"DR-B-composition","name":"Joint review and aggregate boundaries","description":"Joint review and aggregate boundaries for an exact metadata proposal and attributed joint review.","layers":[{"id":"DR-L-membership","name":"Exact joint context","description":"Exact joint context with explicit local and external responsibilities.","findings":[{"id":"DR-F13","name":"Which exact component set was jointly reviewed?","description":"Coverage: local exact pinning.","questions":[{"id":"DR-Q13","text":"Which exact component set was jointly reviewed?","kind":"governed-context","answer_data":["Review proposal pin and exact ordered member/field set","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A13","name":"Review proposal pin and exact ordered member/field set","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT13","description":"Refuse review for a different revision/digest; request new review after change. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local exact pinning"},{"id":"DR-F14","name":"What combined inference risk was assessed?","description":"Coverage: local attribution; no inference proof.","questions":[{"id":"DR-Q14","text":"What combined inference risk was assessed?","kind":"governed-context","answer_data":["Attributed verdict, method, evidence, residualRisk and bounded validity","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A14","name":"Attributed verdict, method, evidence, residualRisk and bounded validity","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT14","description":"Keep rejection/inconclusive/conflict; request qualified human assessment. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local attribution; no inference proof"},{"id":"DR-F15","name":"Which earlier releases were considered?","description":"Coverage: local context binding; not all recipient knowledge.","questions":[{"id":"DR-Q15","text":"Which earlier releases were considered?","kind":"governed-context","answer_data":["Exact known priorReleases context and its assumptions","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A15","name":"Exact known priorReleases context and its assumptions","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT15","description":"Request missing release history; stale if current context differs. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local context binding; not all recipient knowledge"}]},{"id":"DR-L-aggregate","name":"Domain aggregates and assessment scope","description":"Domain aggregates and assessment scope with explicit local and external responsibilities.","findings":[{"id":"DR-F16","name":"Who owns a source aggregate and its calculation?","description":"Coverage: outside implementation.","questions":[{"id":"DR-Q16","text":"Who owns a source aggregate and its calculation?","kind":"governed-context","answer_data":["External aggregate identity, grain, lineage and semantic owner","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A16","name":"External aggregate identity, grain, lineage and semantic owner","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT16","description":"Ask source domain owner; never invent calculated values here. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"outside implementation"},{"id":"DR-F17","name":"Which privacy mechanism or grain applies?","description":"Coverage: deferred privacy mechanisms.","questions":[{"id":"DR-Q17","text":"Which privacy mechanism or grain applies?","kind":"governed-context","answer_data":["Pinned external mechanism, parameters and evaluation evidence","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A17","name":"Pinned external mechanism, parameters and evaluation evidence","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT17","description":"Require a separately verified implementation and explicit limits. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"deferred privacy mechanisms"},{"id":"DR-F18","name":"Does a review apply to another recipient or environment?","description":"Coverage: local binding; no transferable grant.","questions":[{"id":"DR-Q18","text":"Does a review apply to another recipient or environment?","kind":"governed-context","answer_data":["Exact audience/purpose/environment and review proposal pin","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A18","name":"Exact audience/purpose/environment and review proposal pin","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT18","description":"Return stale when context differs; obtain new proposal/review. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local binding; no transferable grant"}]}]},{"id":"DR-B-continuity","name":"Continuity and custody","description":"Continuity and custody for an exact metadata proposal and attributed joint review.","layers":[{"id":"DR-L-storage","name":"Expiry and custody boundaries","description":"Expiry and custody boundaries with explicit local and external responsibilities.","findings":[{"id":"DR-F19","name":"When must serving stop versus evidence remain?","description":"Coverage: local review expiry only.","questions":[{"id":"DR-Q19","text":"When must serving stop versus evidence remain?","kind":"governed-context","answer_data":["Separate current serving policy and custody instructions; review expiry","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A19","name":"Separate current serving policy and custody instructions; review expiry","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT19","description":"Reevaluate review window; ask host to stop serving and custodian to decide retention. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local review expiry only"},{"id":"DR-F20","name":"Who controls source, output, cache and backup copies?","description":"Coverage: outside implementation; opaque context pin.","questions":[{"id":"DR-Q20","text":"Who controls source, output, cache and backup copies?","kind":"governed-context","answer_data":["Externally resolved custodyContext and scoped custody/lineage map","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A20","name":"Externally resolved custodyContext and scoped custody/lineage map","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT20","description":"Identify missing custodian; request owner decision. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"outside implementation; opaque context pin"},{"id":"DR-F21","name":"Do retention, destruction deadlines and holds conflict?","description":"Coverage: deferred disposition engine.","questions":[{"id":"DR-Q21","text":"Do retention, destruction deadlines and holds conflict?","kind":"governed-context","answer_data":["Separate current constraints and hold evidence from custodians","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A21","name":"Separate current constraints and hold evidence from custodians","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT21","description":"Return insufficient-context until actual custodian resolves; perform no destruction. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"deferred disposition engine"}]},{"id":"DR-L-disposition","name":"Disposal and migration evidence","description":"Disposal and migration evidence with explicit local and external responsibilities.","findings":[{"id":"DR-F22","name":"Was disposal requested, executed or verified?","description":"Coverage: outside implementation.","questions":[{"id":"DR-Q22","text":"Was disposal requested, executed or verified?","kind":"governed-context","answer_data":["Distinct actual request, execution and verification receipts","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A22","name":"Distinct actual request, execution and verification receipts","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT22","description":"Keep unknown execution unknown; a marker is not destruction. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"outside implementation"},{"id":"DR-F23","name":"What evidence may survive disposal?","description":"Coverage: outside implementation.","questions":[{"id":"DR-Q23","text":"What evidence may survive disposal?","kind":"governed-context","answer_data":["Actual minimal-evidence policy and exact record/copy scope","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A23","name":"Actual minimal-evidence policy and exact record/copy scope","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT23","description":"Request authorized custody decision without perpetual-retention assumption. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"outside implementation"},{"id":"DR-F24","name":"Can the register migrate without losing meaning?","description":"Coverage: local roundtrip; cross-version migration deferred.","questions":[{"id":"DR-Q24","text":"Can the register migrate without losing meaning?","kind":"governed-context","answer_data":["Complete same-version records, exact pins, source version and explicit loss analysis","If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."]}],"artifacts":[{"id":"DR-A24","name":"Complete same-version records, exact pins, source version and explicit loss analysis","description":"Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."}],"actions":[{"id":"DR-ACT24","description":"Roundtrip same version; refuse unsupported version conversion. Proposed operation only; requires the named host/domain authority."}],"implementationScope":"local roundtrip; cross-version migration deferred"}]}]}]},"statistics":{"bundles":4,"layers":8,"findings":24,"questions":24,"artifacts":24,"actions":24},"catalogue":{"alternateNames":["EM-XCT-05","Context Package Proposal","Joint Disclosure Review","Disclosure classification and custody"],"domain":["Enterprise","Disclosure review","Information governance"],"tags":["disclosure","classification","projection","review","custody"],"adoption":"Start with one exact metadata proposal and one attributed review. Pin source/schema/shape/classification and audience/purpose/environment/prior-release/custody context. Preserve immutable revisions and inspect them against independently resolved current governance state. Three synthetic new-Dimension examples exercise the explicit native binding.","limits":"No result grants access, serves source values, proves privacy or executes disposal. Current authority, pin resolution, snapshot completeness and custody remain host responsibilities."},"invariants":"## Sixteen semantic invariants\n\n1. Each embedded member names exactly one source object; package membership can span objects but a projection cannot silently do so.\n2. Qualified ID, record revision, source/schema revision, lifecycle/applicability and digest remain distinct.\n3. All local reference occurrences of an ID agree on revision/digest; the reference cannot carry two purported current versions of that ID in one record.\n4. No undeclared source value or nested/wildcard field is accepted by the metadata-only grammar.\n5. A missing classification binding or evidence set cannot become an empty/public/clear default.\n6. A review pins exactly the proposal identity/revision/digest; membership, shape, audience or any bound context change invalidates that match.\n7. A current snapshot pins the proposal itself and independently declares all current member/context values.\n8. The complete supplied review set equals the active pin set; duplicate or competing active revisions are invalid.\n9. Active and withdrawn sets are disjoint; an active successor cannot leave its superseded target active.\n10. Review assessment does not predate proposal capture; applicability uses `[validFrom, validTo)` and future capture is stale.\n11. Current author/reviewer catalogs and authority pin are applied; segregation is explicit and actor-alias identity remains a host duty.\n12. Conflicting eligible verdicts cannot silently select a winner. Excluded verdicts retain their pin, result and reason in restricted diagnostics.\n13. Every returned report identifies its proposal, snapshot digest, evaluation time and counted/ignored records, and explicitly conveys no serving authorization.\n14. Same stored identity/revision cannot be repointed; repeat import is idempotent and a failed merge leaves the caller's store unchanged.\n15. Local review/proposal and supersession links resolve by exact pin/type, preserve proposal identity and nondecreasing assessment time, and do not cycle.\n16. Pin equality, a human clearance and any custody-context reference establish no source truth, inference guarantee, current grant, legal conclusion, completed delivery or destruction.\n\nInvariants 1–15 combine local checks with clearly named host attestations; invariant 16 is a semantic boundary and is not a proof produced by unit tests. The final 24 question routes are in spec.json; each names local checks versus host/deferred responsibility.\n\n"} END FILE spec.json ## FILE test-results.json ORIGINAL SHA256 2693f38387a1326f164cd88060b22aa339aa836ce9a37096f9e21781e13478a2 {"status":"passed","passed":true,"testsRun":108,"failures":0,"errors":0,"scope":"Codex reference behavior checks; native integration has a separate report; no privacy/security conformance","codeSha256":"c08df6f075b801b8808a3db4da3d59e6519a2e6949bec6238f9361c5e3e54066","inputHashes":{"disclosure.py":"c08df6f075b801b8808a3db4da3d59e6519a2e6949bec6238f9361c5e3e54066","disclosure.schema.json":"45b2f2c82b9d9af72b2b462d3e502098fbd5b166bf8bd705947ba12e1e5cc834","test_disclosure.py":"dd35bec97e0965c739dbb6449069be5dfadfc8e71083ec679bb1cc9ab1dbdf22","README.md":"12eef4a96880354b73e5a9bdb1db27afc977a8fffabd24743729c1b07be51bbc"},"exampleHashes":{"ai.json":"1100097d1526b8c53e5ad51ca75d8d5d0ccb4a59a6afe5a565a532996e799014","matrix.json":"63199a204156969003e900daea112eba5ff8545f7b21a6ce64e6e2944c04b0a0","startup.json":"44968621c7d9fbd0256270ff0a95e5a4665b83094a7c574e0ebee89bdf83023d"},"python":"3.12.14 (main, Aug 25 2026, 14:01:42) [MSC v.1944 64 bit (AMD64)]","jsonschema":"4.26.0"} END FILE test-results.json ## FILE test_disclosure.py ORIGINAL SHA256 dd35bec97e0965c739dbb6449069be5dfadfc8e71083ec679bb1cc9ab1dbdf22 import copy,hashlib,json,unittest,sys,importlib.metadata from pathlib import Path import disclosure as d def p(name,rev='1'): return {'id':'urn:synthetic:'+name,'revision':rev,'digest':'sha256:'+hashlib.sha256((name+rev).encode()).hexdigest()} def fixture(profile='startup'): member={'key':'project-name','source':p('project'),'schema':p('project-schema'),'shape':p('name-only-shape'), 'fields':[{'name':'name','kind':'string','classificationBindings':[p('name-classification')]}]} members=[member] if profile=='matrix': member['key']='group-summary';member['source']=p('group-aggregate');member['fields'][0]['name']='headcount';member['fields'][0]['kind']='integer' member['schema']=p('headcount-schema');member['shape']=p('headcount-summary-shape');member['fields'][0]['classificationBindings']=[p('headcount-classification')] other=copy.deepcopy(member);other['key']='unit-summary';other['source']=p('unit-aggregate');members.append(other) if profile=='ai': member['key']='release-notes';member['source']=p('model-release');member['fields'][0]['name']='releaseNotes' member['schema']=p('release-notes-schema');member['shape']=p('release-notes-shape');member['fields'][0]['classificationBindings']=[p('release-notes-classification')] proposal=d.seal({'format':'vercy-disclosure-research','version':d.VERSION,'type':'proposal','dimension':'urn:synthetic:dimension:'+profile,'id':'urn:synthetic:proposal:'+profile,'revision':'1', 'body':{'author':'urn:synthetic:founder','capturedAt':'2026-09-21T10:00:00Z','audience':p('partner'),'purpose':p('release-briefing'),'environment':p('partner-portal'),'priorReleases':p('known-prior-release-context'),'custodyContext':p('custody-instructions'),'members':members}}) review=d.seal({'format':'vercy-disclosure-research','version':d.VERSION,'type':'review','dimension':proposal['dimension'],'id':'urn:synthetic:review:'+profile,'revision':'1', 'body':{'proposal':d.pin(proposal),'reviewer':'urn:synthetic:reviewer','authority':p('review-authority'),'method':p('bounded-manual-review'),'evidence':[p('synthetic-assessment')],'reviewedAt':'2026-09-21T10:01:00Z','validFrom':'2026-09-21T10:01:00Z','validTo':'2026-09-22T10:01:00Z','verdict':'cleared','residualRisk':'Synthetic scenario only. No claim of inference prevention.','supersedes':None}}) if profile=='matrix': review['body']['verdict']='rejected';review['body']['residualRisk']='Synthetic reviewer identifies a subtraction path between group and unit headcounts exposing an individual indicator. This package is rejected. The validator does not calculate that risk.';review=d.seal(review) snapshot={'format':'vercy-disclosure-host-snapshot','version':d.VERSION,'dimension':proposal['dimension'],'asOf':'2026-09-21T12:00:00Z','proposal':d.pin(proposal),'context':{k:copy.deepcopy(proposal['body'][k]) for k in ('audience','purpose','environment','priorReleases','custodyContext')},'members':copy.deepcopy(members),'proposalAuthors':['urn:synthetic:founder'],'reviewers':['urn:synthetic:reviewer','urn:synthetic:founder'],'authority':p('review-authority'),'activeReviews':[d.pin(review)],'withdrawnReviews':[],'separateReviewer':profile!='startup'} cap={'dimension':proposal['dimension'],'inspect':True,'record':True} return proposal,review,snapshot,cap class ResearchPrototype(unittest.TestCase): def setUp(self):self.p,self.r,self.s,self.c=fixture();self.now='2026-09-21T12:00:00Z' def answer(self,**kw): s=kw.get('snapshot',self.s) if 'now' in kw and 'snapshot' not in kw: s=copy.deepcopy(s);s['asOf']=kw['now'] return d.inspect(kw.get('proposal',self.p),kw.get('reviews',[self.r]),s,kw.get('capability',self.c),kw.get('now',self.now)) def reseal_review(self):self.r=d.seal(self.r);self.s['activeReviews']=[d.pin(self.r)] def test_three_profiles(self): for profile in ('startup','matrix','ai'): with self.subTest(profile=profile): a,b,s,c=fixture(profile);self.assertEqual(d.inspect(a,[b],s,c,self.now)['status'],'rejected' if profile=='matrix' else 'applicable-review') def test_clearance_explicitly_not_authorization(self):self.assertIs(self.answer()['notServingAuthorization'],True) def test_startup_explicit_self_review(self): self.r['body']['reviewer']=self.p['body']['author'];self.reseal_review();self.assertEqual(self.answer()['status'],'applicable-review') def test_segregated_profile_refuses_self_review(self): self.s['separateReviewer']=True;self.r['body']['reviewer']=self.p['body']['author'];self.reseal_review();self.assertEqual(self.answer()['status'],'insufficient-context') def test_revoked_reviewer(self):self.s['reviewers']=[];self.assertEqual(self.answer()['status'],'insufficient-context') def test_revoked_author(self):self.s['proposalAuthors']=[];self.assertEqual(self.answer()['status'],'insufficient-context') def test_changed_authority(self):self.s['authority']=p('review-authority','2');self.assertEqual(self.answer()['status'],'insufficient-context') def test_withdrawn_clearance(self):self.s['withdrawnReviews']=[d.pin(self.r)];self.s['activeReviews']=[];self.assertEqual(self.answer(reviews=[])['status'],'insufficient-context') def test_future_review(self):self.assertEqual(self.answer(now='2026-09-21T10:00:30Z')['status'],'insufficient-context') def test_expiry_is_exclusive(self):self.assertEqual(self.answer(now=self.r['body']['validTo'])['status'],'insufficient-context') def test_start_is_inclusive(self):self.assertEqual(self.answer(now=self.r['body']['validFrom'])['status'],'applicable-review') def test_future_capture(self):self.assertEqual(self.answer(now='2026-09-20T10:00:00Z')['status'],'stale') def test_context_drift(self): for k in self.s['context']: with self.subTest(key=k): s=copy.deepcopy(self.s);s['context'][k]=p(k,'changed');self.assertEqual(self.answer(snapshot=s)['status'],'stale') def test_source_schema_shape_classification_drift(self): for k in ('source','schema','shape'): with self.subTest(key=k): s=copy.deepcopy(self.s);s['members'][0][k]=p(k,'2');self.assertEqual(self.answer(snapshot=s)['status'],'stale') self.s['members'][0]['fields'][0]['classificationBindings']=[p('binding','2')];self.assertEqual(self.answer()['status'],'stale') def test_added_member_needs_new_review(self): m=copy.deepcopy(self.p['body']['members'][0]);m['key']='another';self.p['body']['members'].append(m);self.p=d.seal(self.p);self.s['members']=self.p['body']['members'] self.s['proposal']=d.pin(self.p) with self.assertRaisesRegex(d.Invalid,'review points to another proposal'):self.answer() def test_added_field_needs_new_review(self): f={'name':'budget','kind':'number','classificationBindings':[p('budget-binding')]};self.p['body']['members'][0]['fields'].append(f);self.p=d.seal(self.p);self.s['members']=self.p['body']['members'] self.s['proposal']=d.pin(self.p) with self.assertRaisesRegex(d.Invalid,'review points to another proposal'):self.answer() def test_reordered_members_changes_pin(self): a,b,s,c=fixture('matrix');a['body']['members'].reverse();a=d.seal(a);s['members']=a['body']['members'] s['proposal']=d.pin(a) with self.assertRaisesRegex(d.Invalid,'review points to another proposal'):d.inspect(a,[b],s,c,self.now) def test_current_unknown_member(self): self.s['members']=[] with self.assertRaisesRegex(d.Invalid,'snapshot shape'):self.answer() def test_hidden_review_not_ignored(self):self.s['activeReviews'].append(p('hidden-review'));self.assertEqual(self.answer()['status'],'insufficient-context') def test_empty_review_set_is_not_clearance(self):self.s['activeReviews']=[];self.assertEqual(self.answer(reviews=[])['status'],'insufficient-context') def test_conflicting_active_reviews(self): other=copy.deepcopy(self.r);other['id']='urn:synthetic:other-review';other['body']['verdict']='rejected';other=d.seal(other);self.s['activeReviews'].append(d.pin(other));self.assertEqual(self.answer(reviews=[self.r,other])['status'],'conflict') def test_inconclusive_is_not_clearance(self):self.r['body']['verdict']='inconclusive';self.reseal_review();self.assertEqual(self.answer()['status'],'inconclusive') def test_rejection_is_not_clearance(self):self.r['body']['verdict']='rejected';self.reseal_review();self.assertEqual(self.answer()['status'],'rejected') def test_missing_capability_before_record_diagnostics(self): with self.assertRaisesRegex(d.Unauthorized,'^unavailable$'):self.answer(proposal={'bad':True},capability={}) def test_cross_dimension_capability(self): self.c['dimension']='urn:synthetic:other' with self.assertRaises(d.Unauthorized):self.answer() def test_cross_dimension_review(self): self.r['dimension']='urn:synthetic:other';self.reseal_review() with self.assertRaises(d.Invalid):self.answer() def test_pre_capture_review(self): self.r['body']['reviewedAt']='2026-09-21T09:59:59Z';self.reseal_review() with self.assertRaises(d.Invalid):self.answer() def test_zero_validity_interval(self): self.r['body']['validTo']=self.r['body']['validFrom'] with self.assertRaises(d.Invalid):d.seal(self.r) def test_invalid_calendar_date(self): self.p['body']['capturedAt']='2026-02-30T00:00:00Z' with self.assertRaises(d.Invalid):d.seal(self.p) def test_missing_offset(self): with self.assertRaises(d.Invalid):self.answer(now='2026-09-21T12:00:00') def test_tampered_digest(self): self.p['body']['author']='urn:synthetic:someone' with self.assertRaisesRegex(d.Invalid,'digest'):d.validate(self.p) def test_no_payload_field(self): self.p['body']['members'][0]['values']={'budget':100} with self.assertRaises(d.Invalid):d.seal(self.p) def test_no_nested_or_wildcard_fields(self): for name in ('owner.email','*','/notes/title','notes[0]'): with self.subTest(name=name): x=copy.deepcopy(self.p);x['body']['members'][0]['fields'][0]['name']=name with self.assertRaises(d.Invalid):d.seal(x) def test_no_object_or_array_kind(self): for kind in ('object','array'): with self.subTest(kind=kind): x=copy.deepcopy(self.p);x['body']['members'][0]['fields'][0]['kind']=kind with self.assertRaises(d.Invalid):d.seal(x) def test_missing_classification_not_public(self): self.p['body']['members'][0]['fields'][0]['classificationBindings']=[] with self.assertRaises(d.Invalid):d.seal(self.p) def test_two_classification_schemes_representable(self): self.p['body']['members'][0]['fields'][0]['classificationBindings'].append(p('second-scheme-binding'));d.seal(self.p) def test_duplicate_field_rejected(self): f=copy.deepcopy(self.p['body']['members'][0]['fields'][0]);f['kind']='integer';self.p['body']['members'][0]['fields'].append(f) with self.assertRaises(d.Invalid):d.seal(self.p) def test_duplicate_member_key(self): m=copy.deepcopy(self.p['body']['members'][0]);m['source']=p('different');self.p['body']['members'].append(m) with self.assertRaises(d.Invalid):d.seal(self.p) def test_same_binding_revision_conflict(self): f=self.p['body']['members'][0]['fields'][0];other=copy.deepcopy(f['classificationBindings'][0]);other['digest']='sha256:'+'0'*64;f['classificationBindings'].append(other) with self.assertRaisesRegex(d.Invalid,'incoherent reference pin'):d.seal(self.p) def test_duplicate_json_keys(self): with self.assertRaises(d.Invalid):d.load(b'{"a":1,"a":2}') def test_float_and_nonfinite_json(self): for raw in (b'{"a":1.0}',b'{"a":NaN}',b'{"a":Infinity}'): with self.assertRaises(d.Invalid):d.load(raw) def test_roundtrip(self):self.assertEqual(d.load(d.canonical(self.p)),self.p) def test_unsupported_version(self): self.p['version']='0.0.0-prototype.1' with self.assertRaises(d.Invalid):d.seal(self.p) def test_idempotent_import(self): existing=d.import_records([],[self.p,self.r],self.p['dimension'],self.c);again=d.import_records(existing,[self.p,self.r],self.p['dimension'],self.c);self.assertEqual(existing,again) def test_immutable_revision_conflict_transactional(self): x=copy.deepcopy(self.p);x['body']['purpose']=p('other');x=d.seal(x);existing=[self.p] with self.assertRaises(d.Invalid):d.import_records(existing,[x],self.p['dimension'],self.c) self.assertEqual(existing,[self.p]) def test_correction_preserves_history(self): x=copy.deepcopy(self.p);x['revision']='2';x['body']['purpose']=p('new-purpose');x=d.seal(x);result=d.import_records([self.p],[x],self.p['dimension'],self.c);self.assertEqual(len(result),2) def test_import_needs_write_assertion(self): self.c['record']=False with self.assertRaises(d.Unauthorized):d.import_records([],[self.p],self.p['dimension'],self.c) def test_identity_cannot_change_type(self): self.r['id']=self.p['id'];self.r['revision']='2';self.r=d.seal(self.r) with self.assertRaises(d.Invalid):d.import_records([self.p],[self.r],self.p['dimension'],self.c) def test_actor_catalog_cannot_be_substring(self): self.s['reviewers']='urn:synthetic:reviewer-extra' with self.assertRaises(d.Invalid):self.answer() def test_duplicate_reviews_not_votes(self): with self.assertRaises(d.Invalid):self.answer(reviews=[self.r,self.r]) def test_input_bound(self): with self.assertRaises(d.Invalid):d.load(b' '*262145) def test_missing_dimension_cannot_authorize(self): for snapshot in (None,{}): with self.assertRaisesRegex(d.Unauthorized,'^unavailable$'):self.answer(proposal={'bad':True},snapshot=snapshot,capability={'inspect':True}) def test_newline_field_alias(self): f=copy.deepcopy(self.p['body']['members'][0]['fields'][0]);f['name']='name\n';self.p['body']['members'][0]['fields'].append(f) with self.assertRaisesRegex(d.Invalid,'exact identifier syntax'):d.seal(self.p) def test_hidden_identity_characters(self): for char in ('\n','\u200b','\u202e','\x00','\ufeff'): with self.subTest(char=repr(char)): x=copy.deepcopy(self.p);x['id']+=char with self.assertRaises(d.Invalid):d.seal(x) def test_unpinned_current_proposal_not_applicable(self): self.s['proposal']=p('retired-proposal');self.assertEqual(self.answer()['reason'],'current-proposal-differs') def test_missing_proposal_pin_rejected(self): del self.s['proposal'] with self.assertRaisesRegex(d.Invalid,'snapshot shape'):self.answer() def test_self_supersession_different_digest(self): self.r['body']['supersedes']={'id':self.r['id'],'revision':self.r['revision'],'digest':'sha256:'+'0'*64} with self.assertRaisesRegex(d.Invalid,'self supersession'):d.seal(self.r) def test_active_superseded_review_rejected(self): other=copy.deepcopy(self.r);other['id']='urn:synthetic:replacement';other['body']['supersedes']=d.pin(self.r);other=d.seal(other);self.s['activeReviews'].append(d.pin(other)) with self.assertRaisesRegex(d.Invalid,'superseded review still active'):self.answer(reviews=[self.r,other]) def test_active_withdrawn_overlap_rejected(self): self.s['withdrawnReviews']=[d.pin(self.r)] with self.assertRaisesRegex(d.Invalid,'active and withdrawn overlap'):self.answer() def test_predate_checked_even_without_authority(self): self.r['body']['reviewedAt']='2026-09-21T09:59:59Z';self.reseal_review();self.s['reviewers']=[] with self.assertRaisesRegex(d.Invalid,'review predates proposal'):self.answer() def test_reference_revision_coherence(self): m=copy.deepcopy(self.p['body']['members'][0]);m['key']='other';m['source']['revision']='2';self.p['body']['members'].append(m) with self.assertRaisesRegex(d.Invalid,'incoherent reference pin'):d.seal(self.p) def test_binding_revision_coherence(self): field=self.p['body']['members'][0]['fields'][0];other=copy.deepcopy(field['classificationBindings'][0]);other['revision']='2';field['classificationBindings'].append(other) with self.assertRaisesRegex(d.Invalid,'incoherent reference pin'):d.seal(self.p) def test_expired_negative_preserved_in_report(self): other=copy.deepcopy(self.r);other['id']='urn:synthetic:expired-negative';other['body']['verdict']='rejected';other['body']['validTo']='2026-09-21T11:00:00Z';other=d.seal(other);self.s['activeReviews'].append(d.pin(other));a=self.answer(reviews=[self.r,other]);self.assertEqual(a['status'],'applicable-review');self.assertEqual(a['ignored'],[{'pin':d.pin(other),'verdict':'rejected','reason':'expired'}]);self.assertEqual(a['counted'],[d.pin(self.r)]) def test_answer_binds_inputs(self): a=self.answer();self.assertEqual(a['proposal'],d.pin(self.p));self.assertEqual(a['snapshotDigest'],'sha256:'+hashlib.sha256(d.canonical(self.s)).hexdigest());self.assertEqual(a['at'],self.now) def test_multiple_active_revisions_rejected(self): other=copy.deepcopy(self.r);other['revision']='2';other=d.seal(other);self.s['activeReviews'].append(d.pin(other)) with self.assertRaisesRegex(d.Invalid,'multiple active revisions'):self.answer(reviews=[self.r,other]) def test_invalid_utf8(self): with self.assertRaisesRegex(d.Invalid,'JSON'):d.load(b'{"x":"\xff"}') def test_huge_integer(self): with self.assertRaisesRegex(d.Invalid,'integer'):d.load(b'{"x":'+b'1'*5000+b'}') def test_year_before_1000_platform_independent(self):self.assertEqual(d.instant('0999-01-01T00:00:00Z').year,999) def test_leap_second_refused(self): with self.assertRaisesRegex(d.Invalid,'timestamp'):d.instant('2026-12-31T23:59:60Z') def test_exponent_number_refused(self): with self.assertRaisesRegex(d.Invalid,'non-integer number'):d.load(b'{"x":1e2}') def test_unpaired_surrogate_refused(self): with self.assertRaisesRegex(d.Invalid,'string'):d.load(b'{"x":"\\ud800"}') def test_unsafe_integer_refused(self): with self.assertRaisesRegex(d.Invalid,'integer'):d.load(b'{"x":9007199254740992}') def test_import_rejects_dangling_proposal(self): with self.assertRaisesRegex(d.Invalid,'unresolved internal pin'):d.import_records([],[self.r],self.p['dimension'],self.c) def test_import_valid_supersession_chain(self): other=copy.deepcopy(self.r);other['revision']='2';other['body']['supersedes']=d.pin(self.r);other['body']['reviewedAt']='2026-09-21T10:02:00Z';other['body']['validFrom']='2026-09-21T10:02:00Z';other=d.seal(other) self.assertEqual(len(d.import_records([self.p,self.r],[other],self.p['dimension'],self.c)),3) def test_import_rejects_wrong_supersession_type(self): self.r['body']['supersedes']=d.pin(self.p);self.r=d.seal(self.r) with self.assertRaisesRegex(d.Invalid,'unresolved internal pin'):d.import_records([],[self.p,self.r],self.p['dimension'],self.c) def test_import_rejects_unknown_supersession(self): self.r['body']['supersedes']=p('unknown-review');self.r=d.seal(self.r) with self.assertRaisesRegex(d.Invalid,'unresolved internal pin'):d.import_records([],[self.p,self.r],self.p['dimension'],self.c) def test_import_cross_dimension(self): self.p['dimension']='urn:synthetic:elsewhere';self.p=d.seal(self.p) with self.assertRaisesRegex(d.Invalid,'record scope'):d.import_records([],[self.p],self.c['dimension'],self.c) def test_snapshot_extra_keys(self): self.s['allowServe']=True with self.assertRaisesRegex(d.Invalid,'snapshot shape'):self.answer() def test_self_objection_still_counts_under_segregation(self): self.s['separateReviewer']=True for verdict in ('rejected','inconclusive'): other=copy.deepcopy(self.r);other['id']='urn:synthetic:author-objection';other['body']['reviewer']=self.p['body']['author'];other['body']['verdict']=verdict;other=d.seal(other);self.s['activeReviews']=[d.pin(self.r),d.pin(other)] with self.subTest(verdict=verdict):self.assertEqual(self.answer(reviews=[self.r,other])['status'],'conflict') def test_withdrawn_newline_alias_rejected(self): other=d.pin(self.r);other['id']+='\n';self.s['withdrawnReviews']=[other] with self.assertRaisesRegex(d.Invalid,'exact identifier syntax'):self.answer() def test_malformed_snapshot_before_stale(self): self.s['proposal']=p('different');self.s['withdrawnReviews']='garbage' with self.assertRaisesRegex(d.Invalid,'snapshot shape'):self.answer() def test_malformed_snapshot_authority(self): self.s['authority']={'invalid':True} with self.assertRaisesRegex(d.Invalid,'snapshot shape'):self.answer() def test_snapshot_multiple_active_revisions_before_completeness(self): other=d.pin(self.r);other['revision']='2';self.s['activeReviews'].append(other) with self.assertRaisesRegex(d.Invalid,'multiple active revisions'):self.answer() def test_active_withdrawn_different_digest_rejected(self): other=d.pin(self.r);other['digest']='sha256:'+'0'*64;self.s['withdrawnReviews']=[other] with self.assertRaisesRegex(d.Invalid,'active and withdrawn overlap'):self.answer() def test_snapshot_time_must_equal_evaluation_time(self): with self.assertRaisesRegex(d.Invalid,'snapshot time mismatch'):d.inspect(self.p,[self.r],self.s,self.c,'2026-09-21T11:00:00Z') def test_golden_encoding_controls_and_separator(self): expected=b'{"a":"\\n\\t\\u0000\xe2\x80\xa8","z":"\\\"\\\\"}' self.assertEqual(d.canonical({'z':'"\\','a':'\n\t\x00\u2028'}),expected) def test_container_subclass_rejected(self): class FalseString(str): def __eq__(self,other):return True x=copy.deepcopy(self.r);x['body']['reviewer']=FalseString('urn:evil') with self.assertRaisesRegex(d.Invalid,'unsupported JSON value'):d.seal(x) def test_non_object_seal(self): with self.assertRaisesRegex(d.Invalid,'record object'):d.seal([]) def test_stale_report_marks_reviews_not_evaluated(self): self.s['proposal']=p('other');self.assertIs(self.answer()['reviewsEvaluated'],False) def test_snapshot_actor_newline_rejected(self): self.s['reviewers'].append('urn:synthetic:reviewer\n') with self.assertRaisesRegex(d.Invalid,'actor catalog syntax'):self.answer() def test_snapshot_unknown_version(self): self.s['version']='unknown' with self.assertRaisesRegex(d.Invalid,'snapshot shape'):self.answer() def test_snapshot_version_required(self): del self.s['version'] with self.assertRaisesRegex(d.Invalid,'snapshot shape'):self.answer() def test_every_answer_binds_evaluator_version(self): self.assertEqual(self.answer()['evaluatorVersion'],d.VERSION) self.s['proposal']=p('another') self.assertEqual(self.answer()['evaluatorVersion'],d.VERSION) def test_cross_type_identity_on_inspection(self): self.r['id']=self.p['id'];self.r['revision']='2';self.reseal_review() with self.assertRaisesRegex(d.Invalid,'identity changes type'):self.answer() def test_active_supersession_with_forged_digest(self): prior=copy.deepcopy(self.r);self.r['revision']='2';self.r['body']['supersedes']=d.pin(prior);self.r['body']['supersedes']['digest']='sha256:'+'0'*64;self.r=d.seal(self.r) # A distinct successor ID avoids the independent one-active-revision rule. self.r['id']='urn:synthetic:successor';self.r=d.seal(self.r);self.s['activeReviews']=[d.pin(prior),d.pin(self.r)] with self.assertRaisesRegex(d.Invalid,'incoherent supersession pin'):self.answer(reviews=[prior,self.r]) def test_future_assessment_reason(self): self.assertEqual(self.answer(now='2026-09-21T10:00:30Z')['ignored'][0]['reason'],'future-assessment') def test_not_yet_valid_reason(self): self.r['body']['validFrom']='2026-09-21T13:00:00Z';self.reseal_review() self.assertEqual(self.answer()['ignored'][0]['reason'],'not-yet-valid') def test_expired_reason(self): self.assertEqual(self.answer(now=self.r['body']['validTo'])['ignored'][0]['reason'],'expired') def test_import_reversing_supersession_time(self): prior=copy.deepcopy(self.r);prior['body']['reviewedAt']='2026-09-21T10:02:00Z';prior['body']['validFrom']='2026-09-21T10:02:00Z';prior=d.seal(prior) nxt=copy.deepcopy(self.r);nxt['revision']='2';nxt['body']['supersedes']=d.pin(prior);nxt=d.seal(nxt) with self.assertRaisesRegex(d.Invalid,'supersession time reversal'):d.import_records([],[self.p,prior,nxt],self.p['dimension'],self.c) def test_import_cross_proposal_supersession(self): other=copy.deepcopy(self.p);other['id']='urn:synthetic:other-proposal';other=d.seal(other) nxt=copy.deepcopy(self.r);nxt['revision']='2';nxt['body']['proposal']=d.pin(other);nxt['body']['supersedes']=d.pin(self.r);nxt=d.seal(nxt) with self.assertRaisesRegex(d.Invalid,'supersession crosses proposal identity'):d.import_records([],[self.p,other,self.r,nxt],self.p['dimension'],self.c) def test_duplicate_stored_revision(self): with self.assertRaisesRegex(d.Invalid,'duplicate stored revision'):d.import_records([self.p,self.p],[],self.p['dimension'],self.c) def test_import_review_before_capture(self): self.p['body']['capturedAt']='2026-09-21T10:02:00Z';self.p=d.seal(self.p);self.r['body']['proposal']=d.pin(self.p);self.r=d.seal(self.r) with self.assertRaisesRegex(d.Invalid,'review predates proposal'):d.import_records([],[self.p,self.r],self.p['dimension'],self.c) def test_partial_disposal_breaks_internal_links(self): with self.assertRaisesRegex(d.Invalid,'unresolved internal pin'):d.import_records([self.r],[],self.p['dimension'],self.c) def test_string_bound(self): with self.assertRaisesRegex(d.Invalid,'string'):d.canonical('a'*4097) def test_depth_bound(self): x=0 for _ in range(22):x=[x] with self.assertRaisesRegex(d.Invalid,'depth'):d.canonical(x) def test_container_bounds(self): for x in ([None]*129,{str(i):None for i in range(129)}): with self.subTest(container=type(x).__name__),self.assertRaises(d.Invalid):d.canonical(x) def test_actor_list_substring_does_not_authorize(self): self.s['reviewers']=['urn:synthetic:reviewer-longer'] self.assertEqual(self.answer()['status'],'insufficient-context') def test_optimized_module_still_rejects_schema_version_mismatch(self): import tempfile,subprocess with tempfile.TemporaryDirectory(prefix='disclosure-version-test-') as tmp: root=Path(tmp);(root/'disclosure.py').write_bytes(Path(d.__file__).read_bytes()) schema=copy.deepcopy(d.SCHEMA);schema['$defs']['proposal']['properties']['version']['const']='wrong' (root/'disclosure.schema.json').write_text(json.dumps(schema),encoding='utf-8') run=subprocess.run([sys.executable,'-O','-c','import disclosure'],cwd=root,capture_output=True,text=True) self.assertNotEqual(run.returncode,0);self.assertIn('schema/version mismatch',run.stderr) if __name__=='__main__': suite=unittest.defaultTestLoader.loadTestsFromTestCase(ResearchPrototype);result=unittest.TextTestRunner(verbosity=2).run(suite) examples=Path(__file__).with_name('examples');examples.mkdir(exist_ok=True) for profile in ('startup','matrix','ai'): a,b,s,c=fixture(profile);(examples/(profile+'.json')).write_text(json.dumps({'fixtureKind':'synthetic-host-internal-only; never accept hostSnapshot or capabilities from a request','proposal':a,'reviews':[b],'hostSnapshot':s},indent=2)+'\n',encoding='utf-8',newline='\n') report={'status':'passed' if result.wasSuccessful() else 'failed','passed':result.wasSuccessful(),'testsRun':result.testsRun,'failures':len(result.failures),'errors':len(result.errors),'scope':'Codex reference behavior checks; native integration has a separate report; no privacy/security conformance','codeSha256':hashlib.sha256(Path(d.__file__).read_bytes()).hexdigest(),'inputHashes':{n:hashlib.sha256(Path(__file__).with_name(n).read_bytes()).hexdigest() for n in ('disclosure.py','disclosure.schema.json','test_disclosure.py','README.md')},'exampleHashes':{x.name:hashlib.sha256(x.read_bytes()).hexdigest() for x in examples.glob('*.json')},'python':sys.version,'jsonschema':importlib.metadata.version('jsonschema')} Path(__file__).with_name('test-results.json').write_text(json.dumps(report,indent=2)+'\n',encoding='utf-8',newline='\n') raise SystemExit(not result.wasSuccessful()) END FILE test_disclosure.py ## FILE tool-pins.json ORIGINAL SHA256 14d54b08bdbe854a00eda39b8643c73473445312bf2ea4902954eaf716bd9ae7 {"composerVersion":"0.1.1","composerFiles":{"composition.py":"78aa1c6c29f14c7adedefd7dd8b3683c845118c49bb48d04c5e92ae4989ce06e","bootstrap_dimension.py":"5eb5491ecedcfa56ffe63d07383e9a650eed42a5d73f667c2feb2f34ea5180f5","composition-plan.schema.json":"cc33e9ee4522cd586a2e1fb07307e6aa5361bf7cf3ca99a419c0f434d0e8a079","policy.schema.json":"92e0386696c974b1e8a312b60ca08d981c223e9925c8f70dabdfa135b9041543"},"skillFiles":{"SKILL.md":"bbd714f5a0de9fad7b26df12be7fb31ce5935f3f54f3cd1037688121383cf963","agents/openai.yaml":"f7234977b2cb542bc0fb1e7665a8a27684e0fa1400696dd6e086b4fef3829cb0","mcp/server.py":"ef3b937e4ebcaa5d737f03f11e6ce5e0be80885e184c88a555e7a0d7b4c0e133","references/autonomous-runtime.md":"ae9d728a214cb296dd97b9d172b60651270e77afcbab632fce04e84dd0a3453a","references/compatibility.md":"b7c0b0ee6d16084f1422b9cb813d23c3f03cc45d047d17a43568067ebde34460","references/concept-map.md":"c216fc5ffd94a55a254f2b61e1ef5630eb8ec09a5ae70db1617318662c43c3a1","references/dimension-bootstrap.md":"7ab614fd1eba0326861d7d2d36cd690b99f26dd0f3333190401bf0782d8a6ed7","references/federation-routing.md":"fb025d2cc62db14c553e0b364c70a47e6385d519d419dec706fb6cf483658159","references/mcp-server.md":"7d1233ea34b34e927acf352c12bc367f58fda5bde249fb3e5e99aa05cff724ad","references/memory-autostart.md":"d3b831e39f2dd5f32abc97d9748ef426e72c3f31e7dbcfff65296b4bf7de5e2e","references/model-lifecycle.md":"9689f560884e12092ffa1fe0068e28f603095b6ffe8c719493f8f595fb3a06ee","references/model-resolution-api.md":"f008dc97daa193b827b9eab76dbc574f104f8d464909cd5d0e71cb8a97749261","references/presets.md":"71503847c1d67f1a227600cce96e5941ea4f3ac1cda1575fe849f18815962cb2","references/public-entry.md":"15155eec00a259dfdf6a0469ccaceba444fcba635f1a42080b36063d924d22a6","references/runtime-records.md":"71c495b38db59f048fe1ec27cd54e608adfeee5160e4d96141b18e43d6b1e809","references/storage-selection.md":"2dd3b10bab2235d04fd3b7cf5411249bf54774efc734b9d08f93483c546bcc5a","references/validation.md":"8c35e27e4fc6103b489ad8b34bd7b79eeb86a8e557752726e8f351ab4edfc9d0","references/whole-object.md":"17d9a1275015c0152267f5a4a39659244ed16c25e81e748256a9324dc5bb7b66","schemas/compatibility.schema.json":"bb32246583b04cedaff9d5e2aae75cca6e9afa014d73a6d4fcc9306054dec78a","schemas/conflict-policy.schema.json":"dece868961a56fe0f50b93564986fb5862b5cbca6ecba138db894f9ea8f6a6c5","schemas/dimension.schema.json":"b6645174e73f551d7bf27642c1887538a8e6d695d586d5101995e69dfa42ce57","schemas/event.schema.json":"e0fbf7551d3b409bf8c04aad6cb6e2caa1dcbf3e703cee9ffe6ab23664f38db6","schemas/fact.schema.json":"f15f9f652c44547384ed8ca7c0c5454a73ea7385de3ec18d8fed09502994ad0a","schemas/object.schema.json":"ff7cab00542db5388946d0704b9aa3c33a49fc8057ec1df6ace7be00e1e43a0a","schemas/relation.schema.json":"2b3b97267fbc400492948886af21010fd6592752c547269f723e7b989279135a","schemas/runtime-model.schema.json":"2ce263747b220d16980bea70f1bca9c3bba59eeec90233d6c9b880759a902c42","scripts/build_index.py":"807539c6d4522d0cbf8782e3a1466a471fa36895cb304b21ee704cb513112319","scripts/create_dimension.py":"4cc00b03be88e9a2348eb681137d0b813b10aa0b76edc881f3e9ecf8345d5b8f","scripts/migrate_dimension.py":"daae4db10760e9d44380c0606d016557ac3e52401f3a711ee11b5ad8c053f02a","scripts/poll_model_requests.py":"91c4aede63bb2eee48e5d49fcdf59d75b0e23eb12511d012c419eb141167fea9","scripts/query_dimension.py":"0c6e35345a91bdd85b7b129fedbb35f4359f6d786b39b927cc92870b65209c0c","scripts/reconcile_models.py":"4fcf76ebaa08ebdbefd2f9ac6824337f8f7d0e9d0c05329f4b3b1669f6260236","scripts/register_memory.py":"9479de2b71669042a73a2393280cc99c096795bf79f0a7eb3294025d2e82e406","scripts/resolve_model_need.py":"25fb98bd2549c0bb7b743cebb62e666a14acd1bd7fa1a2de8548ae9f1d901d5d","scripts/select_storage.py":"c08cdc15374cc496711cb2a6d3403808c008415abccfa3f3cf12f3015df400d3","scripts/self_test.py":"fe9b493b5e7c33a58f97c4fe8c1b01b3457e5eca6e5e2732fbd3497bae402158","scripts/validate_dimension.py":"815a938361420373b18448dda4caa5604d314230cf53fc6a07a9dcb96dd57df4","scripts/vercy.py":"80e31ef4d4e02bab94859163f7975cbe9678e0b31db7d51ae7acd8506b65e20d","scripts/vercy_runtime.py":"e538c64b9c824b503768b63dba5dc66a81c19ac7626eb9116579ba2925528664","scripts/write_record.py":"c60274820fd3e5a55ec790f7e64fb0e0a7e218b7fe107f02d0fcb125091da4e5","assets/dimension/AGENTS.md.template":"b435e4bc805e2aa084c648167350fd050993dab0aaa1d194697558de5586f69d","assets/dimension/compatibility.yaml":"41244d13b2e8763f2f23c44f1ffefc7dde4801b4a54f5faa852d977e0f648a4f","assets/dimension/context-routing.yaml":"52f3a4f8951e2faf3be8d6bd23af51fdfc477a347cc79db55bbcd3d717cd3f67","assets/dimension/dimension.yaml":"e92c299d857962293f2a1c13d70717beff0ec955b3ab84ea1e2763d2cff3b1d7","assets/dimension/federation.yaml":"358bf49507eb3f5c1e9fb86e45d9cc0ee9d14a8dc371f3af95af56dab0e6327b","assets/dimension/memory.yaml":"50d47c53ee2be80d293a051c7c909cb2afdf8204f9a76eadfe5673eb6cd589b4","assets/dimension/vercy.lock":"f360ae2f60e1d3f02bda506c3aed9587d6435a7d0200bef542888df32b469c99","assets/icons/vercy-logo-1024.png":"8043b9a7080d1b64fea402ba0db8d42efb366862214fc1d68d8a99086401a705","assets/icons/vercy-logo-512.png":"3832e0a25cec92cf22392a27c44b37524213844598c61a12d5032e3fea5fd690","assets/presets/ai-subject.yaml":"ed547e7628d8c4509ed1873312b45f0521036b5235a3b795a2f2a0e4a147c3b7","assets/presets/index.yaml":"69e79eb66cec03ab07badb301b0b4ebfb15b74b34daffeae78e7f11529140892","assets/presets/kernel.yaml":"b699f89fc1d040e05584bb21e00a419a7704230caba42adc37cb70631defb43d","assets/presets/organizational.yaml":"e70c6d196f1b5626f2e7646252dad4f2be961b7908ae198e9bc1d405cffad2a3","assets/presets/personal.yaml":"c201473267e64958b9844e3557f8efc95b8be790581135c42c8c38566c841483","assets/presets/reality.yaml":"2779668f8eeca66b74ff31527c323d3461f821089769ef5d7951c13afbfcad66","assets/dimension/bindings/storage.yaml":"044db01cf746678283a98c96be0d1fb8a94997393b9161a5a32e59dfc813ba5c","assets/dimension/data/index.md":"f10a3c8283ddc1ae608c6848cd561ac9b9d80a05ca684420ac185fa920b8b351","assets/dimension/migrations/index.yaml":"9a20ae6fef67ca51d4c07a27558deb20af2a7b3dafe76893783ac01e86c0dce6","assets/dimension/policies/access.yaml":"3b58ce30f6de01923dbbab069df0721552c3b9ab8ba405c30ac353ffb392779f","assets/dimension/policies/autonomy.yaml":"6629691e60540e42eabeb63f746bcb99f79f383d7c85a57217e551d4ecc6ea27","assets/dimension/policies/conflict-resolution.yaml":"241e97baa79198e4b02885f24ad1143b7ebfc3dbf52dc07e4bccb01ef31c72b2","assets/dimension/policies/lifecycle.md":"91755112dd7854a7cb06598fcb53233c68b626bb015ca7f5a3a9307258eab232","assets/dimension/policies/model-deployment.yaml":"637fc3ac655b7f5c2f36c814113b03803bce4366e62cb24bbeb4f36dba525771","assets/dimension/registries/events.yaml":"8babba185339394a775d953024c857f6bcd4f6c1037bff9019af5c8512435fef","assets/dimension/registries/meta-models.yaml":"4efb434d716f2c10a1c01deb79e44873ced31599446edab8b213e3fd7201206b","assets/dimension/registries/meta-objects.yaml":"c1b417a3019d93c594dae9854951d57c3fcd73d73a88f258b3a13c8cb5e7e3d3","assets/dimension/registries/model-links.yaml":"ecbac80f14627245ecdc5af12bb30331b88f688e8ebeaa34fba44ddc16e0c898","assets/dimension/registries/model-requests.yaml":"7f01232fd4b812d942eed0e88f154f751e7f9fb1707402a5b6b4aaa16bdba319","assets/dimension/data/events/README.md":"fa20d1960e40eee352679debcab28df245f9bef695ca72a27d28b69ab8e18737","assets/dimension/data/facts/README.md":"80433bcda7964cb8819692bd442628f56b35aa6fca96bfde0d527b2d3ed38138","assets/dimension/data/objects/README.md":"264ebb5440729741322828fd5e3c8a747c77a1662b0e64ab5ff9ce1a978ff4b8","assets/dimension/data/relations/README.md":"d7a7d3e09a3c8d0c2e0304ffe89e5fa01ad9bde730497185a7a9da7d5bf51a22","assets/presets/organizational/commercial-company.yaml":"ce8ee74e8fa61eec9583471f6b4982e920d172af3299bbfc2ed08163a6cbde2b","assets/presets/organizational/community.yaml":"31cabe5a146e2b38d173f2cb08f7e5d0df60bbcf7f273082ba97b0dd7560f001","assets/presets/organizational/family.yaml":"094438b226ed56859c72327d354e55e6ed2cd6c2658a1423ad345c326ac1a9c9","assets/presets/organizational/state.yaml":"a2aaac7f20feaffe2494406ddc5b71629027fed6c04e94f65950dac991f6ff13"}} END FILE tool-pins.json ## FILE whole-object-coverage.yaml ORIGINAL SHA256 66f81e0647897b1c8ee77a6798bec3a26fe756fdc38c0b8eaf0c9e53a21eba77 {"canonicalFacets":["identity-class","direct-properties","recognition-observation","capabilities-behaviour-actions","context-evidence"],"types":{"ContextPackageProposal":{"identity-class":{"status":"required","coverage":"Format/version, Dimension, qualified proposal ID, opaque revision, content digest; one collection, independent from its members' object identities."},"direct-properties":{"status":"required","coverage":"Finite exact member/field set and all audience/purpose/environment/context pins; schema supplies type, cardinality and nullability."},"recognition-observation":{"status":"required","coverage":"Author and capture time state who recorded which exact source revision/context. Host identity resolution and truth remain external, with no unpinned delegated-type claim."},"capabilities-behaviour-actions":{"status":"required","coverage":"Seal, validate, import immutable revisions, inspect applicability against a trusted snapshot; these operations do not grant access or deliver values."},"context-evidence":{"status":"required","coverage":"Exact source/schema/shape/classification/prior-release/custody pins. The host resolves them independently."}},"JointDisclosureReview":{"identity-class":{"status":"required","coverage":"Independent review ID/revision/digest and exact proposal reference; reviewer and assessed object are distinct roles."},"direct-properties":{"status":"required","coverage":"Verdict, risk statement, assessment/validity times and optional supersession pin."},"recognition-observation":{"status":"required","coverage":"Method/evidence pins and assessed proposal establish the declared observation context; no calibrated confidence or inference-prevention proof."},"capabilities-behaviour-actions":{"status":"required","coverage":"Record a verdict, correct through another immutable revision, validate internal references, count or exclude it under current host state; no authorizing or deleting action."},"context-evidence":{"status":"required","coverage":"Reviewer/authority/method/evidence pins, relation to proposal and previous review, current authority and completeness supplied by host snapshot."}}},"embeddedValues":"Members, fields and pins have no independent exported lifecycle; diagnostics are ephemeral. Physical dimensions do not apply to these information records."} END FILE whole-object-coverage.yaml END COMPLETE FROZEN CANDIDATE. Return verdict and actual read scope.