Vercy Enterprise Program · Public model information Independent research study EM-XCT-05 Disclosure, classification and retention A bounded context-package proposal and joint-disclosure review. Not an enforcement engine, not a deletion engine, not a universal identity model. Research identity Value Card EM-XCT-05 · Shared contract W0 · Being researched (catalogue card retrieved 2026-09-21) Document class Independent English study for the public Vercy Enterprise program. Research, not review of future code, not permission to publish, not a claim about any real company. Date / time 2026-09-21 · retrieval window same calendar day. Future implementation receives a separate frozen audit. Authors Team of four agents on Grok 4.6 architecture (Grok lead; Harper, Benjamin, Lucas). Dispositions below are the team's joint reading of retrieved text. Evidence labels observed = read from a named live URL this session; source-asserted = author's claim in that document; inference = our conclusion; proposal = design of the companion; unverified = not re-checked. Non-claims No universal inference prevention, anonymization, IAM, legal interpretation, or live deletion engine. No ODRL / DPV / NIST conformance. No ISO clause citation. This study assembles a context package only from permitted projections. Each Projection describes exactly one canonical Meta-Object. A composite report is an explicitly identified aggregate with its own boundary, calculation, owner, purpose and disclosure review. Approval of each card is not approval of their combination. A classification code references a pinned scheme and does not itself grant access. A retention condition does not authorize disclosure or destruction. An active hold is not an unrestricted perpetual retention rule. Unknown is not false, zero, unclassified, approved or erased. 1. Boundary and dispositions 1.1 What this contour is allowed to own The research boundary is a Company Dimension assembling a context package from permitted projections. The minimum useful original companion proposed here is a declared review artifact — a ContextPackageProposal bound to a separately identified JointDisclosureReview — that may initially assemble metadata or closed synthetic values under host authority. It is not a data-serving evaluator and not a verified subtype of WM-XCT-003. Four registry candidates were presented. They are not four fields of one policy. Classification assignment, purpose, access grant, output shape, composition risk, retention schedule, hold, disposition execution and destruction evidence stay with their respective owners. 1.2 Disposition of the four candidates Candidate Disposition Reason, pin, and what the companion may carry DisclosurePolicy Reuse / profile of WM-XCT-003 WM-XCT-003 Projection / Disclosure Policy 0.3.0-research.1 already owns declarative output shape (selection, treatment, record scope, grain, shape algebra, templates/fingerprints, bindings, assurance). It expressly excludes runtime decisions, classification assignment, grants, privacy-budget calculation and audit retention. Minting a parallel DisclosurePolicy would collapse shape into policy identity. The companion cites a 003 policy version + compiled template fingerprint as a component. A 003 shape does not cover many objects. ClassificationAssignment Profile / host-binding of WM-XCT-020; executable assignment deferred WM-XCT-020 Classification Binding 0.3.0-research.1 exists as a PATTERN (not mixin). It reifies subject↔scheme+version+term+role+agent+time+basis. Out of scope: scheme internals, mapping tables, access-control evaluation, credential management. Sibling Classification Scheme and Concept Mapping models are unregistered. Companion carries pinned scheme IRI + version + code + assignment-authority ref + assignment-time. A code does not grant access. RetentionConstraint Documented deferral to WM-XCT-035 Landing page retrieved: specification planned, no Bundle/Layer/Finding written, no placeholder YAML published as complete, unversioned, no digest. Do not invent fields, pin it, or delegate executable obligations to it. Companion carries schedule-ref, hold-ref and an unresolved-disposition state only. Matches the already-observed sibling pattern (WM-XCT-012, 021, 022, 026, 028, 036 all REFERENCE an external retention model). ProjectionContract Original bounded companion, lightly decomposed Not a subtype of 003. Two types only: ContextPackageProposal (the review artifact) and JointDisclosureReview (the composition-risk object). Host binding to the Dimension object that owns the source Meta-Object. No new universal WM identity. 1.3 Challenge to the provisional boundary — and the decision to decompose lightly The brief invites a challenge: even the minimum useful companion might be too coarse. Three collapse risks were tested. Collapse A — one policy field for everything Rejected. WM-XCT-003's own out-of-scope list already forbids presenting a data-serving evaluator as its verified subtype. WM-XCT-002 owns the permission instrument and expressly does not own output shape. WM-XCT-020 owns the binding pattern and expressly does not own enforcement or downgrade rules. WM-XCT-035 does not yet own anything executable. Collapsing these into one DisclosurePolicy field would make every sibling's holds untraceable. Collapse B — a Projection that covers many objects Rejected. The enterprise card and RESEARCH-PROTOCOL.md (retrieved) both state that one Projection describes one canonical Meta-Object, and that a composite dashboard or context pack is either a collection of permitted projections or an explicitly modelled aggregate with identity, boundary, owner, calculation and disclosure rules. A Projection does not create a new master and does not grant rights to disclose source facts. The matrix-group adversarial case is exactly this collapse. Collapse C — one companion type that is both review and serve Rejected, and this is the justified decomposition. A declared review artifact is not an enforced disclosure result. Replay of an identical proposal under pinned inputs may reproduce the review decision. Actual serving must re-evaluate current grant, revocation, reclassification and hold. Digest identity does not establish permission or freshness. Therefore: Kept as original types Not minted ContextPackageProposal The review artifact. Pins source object/revision/schema, closed field set, classifications as references, audience, purpose, host-authorization evidence, component membership and digests, joint-review reference, retention/hold references, decision-validity window. JointDisclosureReview Separately identified composition-risk object. Membership, inference notes, reviewer, review-time, invalidation conditions (membership, source revision, audience, purpose or shape change). (none further) No ClassificationAssignment type inside the companion. No RetentionConstraint type. No ContextPackageServe type pretending to be 038. No new WM identity model. 1.4 Existing Vercy candidates — retrieved boundary, not remembered WM-XCT-002 Access Contract / Consent · vr.wm-xct-002 · 0.3.0-research.1 Landing and spec.yaml retrieved this session from https://ver.cy/models/wm-xct-002-access-contract-consent/ and …/spec.yaml. Status: published as reviewable-draft; publishableCanonical false. Entry kind: mixin. Generated 2026-08-23. Synthesis sha256 observed on the YAML wrapper: 478f7f042a8e07f3… . The brief pins a different published-bytes digest (9085d977…) from a Codex compare dated 2026-09-21; that compare is not recomputed here. Provide a format-neutral, machine-readable instrument of permission to read: which party permits which reader to read which slice of data, for which declared purpose, under which conditions and duties, until when, on what evidence of assent, and how that permission is verified, changed and ended. It owns the grant instrument, optional consent act and evidence, instrument lifecycle and termination propagation, and the coverage-decision surface including unevaluable outcomes. It does not own payload data, disclosure shape, the access audit log of exercises, enforcement casework, identity proofing, payload schemas, write/delete/licensing permissions, OAuth/UMA token mechanics, or adjudication of whether a non-consent legal basis is lawful. Consent is one possible basis, not a mandatory precondition. Published holds — preserved, not closed by this companion: (1) source liveness and edition pins for 19 sources, including FHIR Consent to be pinned to version-qualified R5 rather than a drifting current URL, and two DPVCG 27560-guide citations that disagree on host and date; (2) incomplete non-health / non-EU profile validation; (3) paywalled ISO/IEC TS 27560:2023 and ISO/IEC 29184:2020 — field inventories rest on catalogue pages plus DPVCG mapping, not annex text; TS 27560 is a Technical Specification and CD 27560.2 may change mandatory fields; (4) security implementation gap (key management, token binding, replay resistance, cryptographic proof suites) plus entitlement-cutoff now imported; (5) collective, community and Indigenous group permission unsupported by any source and must not be approximated through delegate capacity. Functions observed in the retrieved spec include activate-grant, evaluate-coverage, propagate-termination, apply-retention-disposal (of the instrument record, not the host payload), and conflict-evaluation. The coverage decision returns outcome, obligations, a non-reversible scope fingerprint and a validity window — not parties, purpose text or terms to an enforcer. Default deny. Token or cache must not exceed the grant window. WM-XCT-003 Projection / Disclosure Policy · vr.wm-xct-003 · 0.3.0-research.1 Landing and spec.yaml retrieved from https://ver.cy/models/wm-xct-003-projection-disclosure-policy/ and …/spec.yaml. Status: published as reviewable-draft. Entry kind: mixin. Generated 2026-08-28. Synthesis sha256 observed: 96a40c5bc14bfef3… . Brief pins published-bytes 058191fe… from the same Codex compare; not recomputed. Define, in a storage- and interface-neutral way, the shape data is permitted to leave in — which elements, after which transformations, over which records, at which grain — so one reusable shape specification can be bound to many contracts and audiences and can be reproduced and explained afterwards. It holds no instance data. It specializes a generic governed policy (WM-KNW-012, referenced-not-fetched) with output-shape semantics only. Out of scope, quoted from the retrieved spec: generic policy identity/approval/versioning (KNW-012); ownership (WM-XCT-001); authorization and consent (002); audit trails (004); cohort-floor and privacy-budget computation (005); sensitivity classification assignment (020); source schema semantics (DAT-004); runtime evaluation and enforcement (038); execution of transformations on instance data; legal determination of lawfulness. Holds preserved: (1) source editions, tiers and paywalls (ISO/IEC 20889 and 27559 unread in full; JSON Schema 2020-12 core cited as an expired Internet-Draft; DPV 2.1 cited while live DPV is now 2.3; XACML Multiple Decision Profile is a committee draft); (2) untested grain and media profiles — structure not exercised against one instance per grain class nor against non-JSON media; (3) US/EEA-only evidence; (4) unassigned owner for non-aggregate identifiability / expert-determination evidence; (5) missing cross-model legal-hold precedence across audit-entry disposition (004), source-data erasure (DAT-004 / Dimension) and destruction of the policy record (KNW-012). This companion does not resolve those holds. Normative sentences retrieved and reused as constraints on the companion: default deny — an element that no selection rule names does not leave; no instance data in 003; no local cohort floors — an unresolvable 005 reference makes the shape unfit; compile-before-serve; reference-don't-copy. Shape algebra meet is monotonic (never widens). Grain classes named: record-level subset, named summary, aggregate-only, hybrid. WM-XCT-035 Retention / Disposition · todo Landing retrieved at https://ver.cy/models/wm-xct-035-retention-disposition/ . Observed status text: the specification is planned; the catalogue entry defines a governed target; Bundle → Layer → Finding → Question / Artifact specification has not been written; no placeholder YAML is published as if it were complete. Unversioned. No digest. Non-installable. Research candidate only. No fields are invented below. Executable obligations are not delegated to it. Adjacent names — availability this session Name Availability Use in this companion WM-XCT-020 Classification Binding Retrieved. 0.3.0-research.1 PATTERN. Boundary questions remain required. Pinned scheme+version+term+role reference only. Not an access grant. Not a production dependency. WM-XCT-005 privacy aggregation 404 at the expected path. Named inside 003 only. Referenced-not-fetched. Not a mandatory dependency. Unresolvable floor ⇒ package unfit. WM-XCT-038 runtime enforcement Named by 003. Complete spec not retrieved. Referenced-not-fetched. Companion is not a PDP/PEP. WM-DAT-004 source schema Named by 003. Complete spec not retrieved. Pin slot: schema_id + schema_version. If unbound, fail closed on drift. WM-KNW-012 governed policy Named by 003 as EXTEND target. Complete spec not retrieved. Policy identity, approval and supersession stay there. Companion stores refs. WM-XCT-004 access audit Catalogue 0.2.0-legacy. Not fetched in full. Decision correlation id only. No audit trail owned here. 1.5 Declared review artifact versus enforced disclosure result This distinction is the implementation contract. Declared review (this companion) Enforced disclosure (not this companion) ContextPackageProposal + JointDisclosureReview under pinned inputs. A serve-time decision by a host PDP/PEP (038 or equivalent) against current grant, hold, reclassification and schema. May be replayed: identical proposal + identical pins ⇒ same review outcome. Must be re-evaluated. Digest of the proposal is not permission and not freshness. May assemble metadata or closed synthetic values under host authority. Touches instance data. That step is 038 + 003 compile-before-serve, not this model. Invalidation is structural: membership, source revision, audience, purpose or shape change voids the review. Revocation, hold, reclassification or grant expiry voids the serve even if the review object is unchanged. Recipient-visible result of a denied proposal is a uniform refusal. Internal diagnostics may name object, field, policy reason. Those channels are disjoint. Concrete implementation contract, proposal only: a host may persist ContextPackageProposal and JointDisclosureReview as governed records, compute digests over a declared canonical form, and refuse to compile a serve template from an unreviewed, invalidated or expired package. The host must not treat persistence of those records as an access grant, a classification authority, a retention schedule or a destruction order. 2. Comparison schools and primary sources Three schools are compared because they answer different questions. Treating any one as a universal policy language is the error this contour is designed to prevent. Five primary sources were retrieved this session. Paywalled ISO text is recorded as inaccessible, not paraphrased from memory. 2.1 School A — Policy expression (what is offered or agreed) Primary sources: W3C ODRL Information Model 2.2 and ODRL Vocabulary & Expression 2.2, both W3C Recommendations dated 15 February 2018. This-version URLs retrieved: https://www.w3.org/TR/2018/REC-odrl-model-20180215/ and https://www.w3.org/TR/2018/REC-odrl-vocab-20180215/ . Latest published versions still resolve to those Recommendations. The Permissions & Obligations Expression Working Group closed 29 March 2018. A W3C “Future of ODRL” workshop announced for 22–23 June 2026 is not a Recommendation update. No later Rec was found. Retrieved core, Model §§2.1–2.10. A Policy is a group of Rules. Subclasses: Set (generic Rules; default if unspecified), Offer (MUST have assigner; assigner offers, does not grant), Agreement (MUST have assigner AND assignee; assigner has granted). Permission is the ability to exercise an Action over an Asset and MAY include a Duty as precondition. Prohibition is the inability to exercise an Action. Duty is the obligation to exercise an agreed Action; a Duty on a Permission is a precondition. Constraint is a boolean or logical expression refining Action, Party, Asset or Rule conditions. Conflict property values: perm, prohibit, invalid. Default if unspecified: invalid. Multiple conflict values void the Policy. Inheritance: a child MUST replicate parent policy-level Assets, Parties, Actions, profiles, conflict properties and Rules, then expand; non-circular; constraint status is not transferred. Vocabulary retrieved actions include read, use, distribute, delete (“permanently remove all copies after use”), anonymize. The profile property is mandatory if using an ODRL Profile. ODRL does not define enforcement, consent evidence, identity proofing of Parties or Assets, output-shape algebra, classification assignment, or a records schedule. Companion alignment, not conformance: WM-XCT-002 already maps Policy/Agreement, Permission, Prohibition, Duty and the conflict vocabulary, and records that local treatment declarations are finer-grained than ODRL so no round-trip is lossless. This companion inherits that hold. Offer is not Agreement. Anonymize as an ODRL Action has no technique parameters; it is not a de-identification method. 2.2 School A (vocabulary layer) — DPV as Community Group output Primary source: Data Privacy Vocabulary (DPV) version 2.3, Final Community Group Report, 25 February 2026. Canonical URL https://w3id.org/dpv/ resolved this session to 2.3. This-version https://www.w3.org/community/reports/dpvcg/CG-FINAL-dpv-20260225/ . Status text retrieved verbatim: This specification was published by the Data Privacy Vocabularies and Controls Community Group. It is not a W3C Standard nor is it on the W3C Standards Track. DPV is therefore not cited as a Recommendation. Versionless https://w3id.org/dpv/ always points at the latest release; a pin must use a versioned IRI (https://w3id.org/dpv/2.3). WM-XCT-002 cites “ISO/IEC TS 27560:2023 as rendered by the DPVCG guide with DPV 2.1”. Live DPV is now 2.3; 2.1 remains a historical pin. This companion does not silently upgrade that pin. Retrieved concept groups: PersonalData, Purpose, LegalBasis, Processing, TechnicalOrganisationalMeasure, Right, Risk. Consent lifecycle terms observed on the 2.3 surface include ConsentGiven, ConsentWithdrawn, ConsentExpired, ConsentRevoked, ConsentRefused, ConsentInvalidated, ConsentRequested, ConsentUnknown, ConsentStatusValidForProcessing, ConsentStatusInvalidForProcessing. Storage-adjacent terms observed: StorageDuration, StorageDeletion, StorageRestoration. Processing includes Disclose / DiscloseByTransmission. The ISO/IEC TS 27560 mapping is a separate CG guide (https://w3id.org/dpv/guides/consent-27560), not ISO text. ISO/IEC TS 27560:2023 itself is paywalled and was not read; no clause is cited. 2.3 School B — Attribute evaluation (whether a request is covered now) Primary source: NIST Special Publication 800-162, Guide to Attribute Based Access Control (ABAC) Definition and Considerations. January 2014 including updates as of 02 August 2019 (errata table p. ix). DOI 10.6028/NIST.SP.800-162. CSRC record https://csrc.nist.gov/pubs/sp/800/162/upd2/final . PDF https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-162.pdf retrieved this session. Authors: Hu, Ferraiolo, Kuhn, Schnitzer, Sandlin, Miller, Scarfone. An access control method where subject requests to perform operations on objects are granted or denied based on assigned attributes of the subject, assigned attributes of the object, environment conditions, and a set of policies that are specified in terms of those attributes and conditions. (§2.2) Architecture retrieved from §2.4.3: Policy Enforcement Point (PEP) enforces decisions; Policy Decision Point (PDP) computes them; Policy Administration Point (PAP) authors digital policies and metapolicies; Policy Information Point (PIP) retrieves attributes. The PDP mediates and deconflicts digital policies according to metapolicies. Attributes are decision inputs, not authorizations. ABAC does not automatically provide efficient before-the-fact audit of who-has-what, attribute quality, privacy, or trust (§3.1.2.3). Attribute caching is an explicit stale-attribute risk (§3.3.1). Sharing subject attributes can itself leak PII and needs trust agreements (§3.2.1.6). Decision confidence depends on timeliness, relevance, authority, quality, reliability and completeness of inputs (§3.2.3.1). Environment conditions were added to the Figure 8 trust chain in the 2019 errata. Practical engines in this school, retrieved as existence and architecture, not as adopted runtimes: OASIS XACML 3.0 (PEP/PDP/PAP/PIP; combining algorithms resolve competing policies — which 003 explicitly leaves in KNW-012); Open Policy Agent / Rego, a CNCF-graduated general-purpose PDP (https://github.com/open-policy-agent/opa retrieved); AWS Cedar (default-deny, forbid-wins, order-independent, no side effects — public language docs 2025–2026, not a Rec). An ODRL-to-Rego translator (ODRL-PAP, DOME marketplace / SEAMWARE) exists as an alignment experiment and is not an ODRL conformance claim. None of these engines is a classification-assignment authority, a records schedule, or a joint-disclosure reviewer. 2.4 School C — Records disposition (how long, under which hold, with what evidence) Primary source: NIST Special Publication 800-188, De-Identifying Government Datasets: Techniques and Governance. Final, September 2023 (CSRC date 14 September 2023). DOI 10.6028/NIST.SP.800-188. PDF https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-188.pdf retrieved. Authors: Garfinkel, Near, Dajani, Singer, Guttman. Keywords retrieved: data life cycle, de-identification, differential privacy, direct identifiers, Disclosure Review Board, k-anonymity, privacy, pseudonymization, quasi-identifiers, re-identification, synthetic data, The Five Safes. Retrieved statements used as constraints, not as implemented techniques: De-identification is any process of removing the association between identifying data and the data subject. It is not a guarantee. Agencies should evaluate goals and residual risk before using it. Data-sharing models named: publishing de-identified data, publishing synthetic data, a query interface that incorporates de-identification, or sharing in non-public protected enclaves (§3.4). Repeated releases may compromise privacy if combined. A Disclosure Review Board oversees proposed releases; approvals should not be indefinite; the DRB may delegate review but not to those who performed the de-identification (§3.6). Prescriptive standards such as HIPAA Safe Harbor typically provide no mathematically provable assurance that following the procedure produces the intended privacy-preserving outcome (§3.7.2). Aggregation does not inherently protect privacy and is not sufficient for formal privacy guarantees (§4.3.8). Composition of de-identification results is unpredictable without controls (§4.3.11) — this is the matrix-group joint-inference case in the brief. Encryption or hashing of direct identifiers is not recommended as de-identification because it is reversible or brute-forceable (§4.3.2). Applications requiring provable guarantees should use formal methods such as differential privacy (§4.6.2). A low confirmed re-identification probability is not safety if the conditional rate is high (§4.6.3). ISO 15489-1:2016 (records management, edition 2) is paywalled. Existence and abstract scope are recorded; no clause is cited. NARA General Records Schedules, as public US practice, treat disposition authorities as legally mandatory (44 U.S.C. 3303a(d) is the public statute citation, not an ISO clause). A hold suspends disposition; it does not rewrite the schedule into perpetual retention. “Destroy when no longer needed” is hard to automate. This is the pattern already used by retrieved Vercy siblings: carry a schedule reference and a hold reference; emit readiness (eligible / blocked / retained / externally governed / not assessed); execute nothing. 2.5 What the three schools refuse to do for each other Question School A ODRL / DPV School B ABAC / PDP School C DRB / records May this party read this slice for this purpose? Offer or Agreement can declare it. Default conflict = invalid. Not a live decision. This is the PDP question. Answer is time-bounded and input-quality-bounded. Not this school's question. In what shape may it leave? odrl:anonymize / aggregate / derive have no field parameters. Insufficient. XACML obligations have no native output-shape type. Insufficient. Sharing model (release / enclave / query) is chosen here; field algebra is not. Does the combination of two approved cards leak an individual indicator? No composition review object. Permit + permit can still compose. Combining algorithms are not a DRB. This is the DRB / joint-review question. 800-188 §4.3.11: composition is unpredictable without controls. May we destroy it now? odrl:delete is an Action on an Asset, not a schedule or a hold register. Deny-serve is not destroy. Only if the schedule is due, no hold applies, an owner executes, and evidence is retained. Fifth primary source, used as a supporting records-practice pin rather than a third school of its own: the public NARA / 44 U.S.C. disposition frame above, together with the already-retrieved Vercy sibling pattern. Commercial data-policy platforms (Immuta-class, remembered category) were not retrieved as contracts this session and contribute no fields. 3. Types, identities, lifecycle, fields, relationships, owners 3.1 Exported types (closed set) Two original types. Everything else is a reference slot. Schema version, object revision, policy revision and status remain separate identifiers. No type below is a WM identity model. ContextPackageProposal Identity-class: a governed review record, weakly hosted by a Dimension object. Identifier precedence (proposal): mastering-system id, then governed IRI, then Dimension-assigned ULID. Digest over canonical form verifies integrity and is never the identifier. Cardinality: one proposal addresses exactly one primary source object revision; additional objects enter only as members of a JointDisclosureReview, never as silent extras. Field Kind Card. Rule package_id identifier 1 Required. Never reused after retirement. package_revision identifier 1 Required. Distinct from schema version and from status. schema_id / schema_version identifier 1 Required. The companion's own schema pin. Drift of this schema voids instances. host_object_id reference 1 Required. The canonical Meta-Object. One object per proposal. host_object_revision identifier 1 Required. Source revision pin. Change invalidates the package. source_schema_id / source_schema_version identifier 1 Required or explicitly unbound. Unbound or drifted ⇒ fail closed. DAT-004 pin if resolvable. permitted_field_set collection 1 Required. Closed. Unknown or new field fails closed. Default deny. classification_refs[] object 0..n Each item: scheme IRI + scheme version + term/code + optional role + assignment-authority ref + assignment-time. Missing scheme version is unbound, not unclassified. audience_id reference 1 Required. Legal-entity or named recipient class, not a role nickname. purpose_code code 1 Required. From a pinned purpose vocabulary (DPV Purpose or Dimension register). Version of that vocabulary recorded. shape_policy_ref reference 0..1 WM-XCT-003 policy version + compiled template fingerprint. Absence means metadata-only package. grant_evidence_ref reference 0..1 Citation of a 002/038 coverage decision id + validity horizon. Citation is not a grant. component_membership[] object 1..n Each: component kind + identifier + revision + content digest + algorithm. Changed membership voids the joint review. joint_review_id reference 1 Required. Even a single-object package has a review that records “no additional members”. review_status code 1 pending | approved | rejected | invalidated. Unknown is not approved. retention_ref reference 0..1 Schedule identity + version owned elsewhere. Absence ⇒ disposition_state = not-assessed. hold_ref reference 0..n Hold identity + issuing authority. Presence forces disposition_state away from eligible-handoff. disposition_state code 1 unresolved | not-assessed | blocked-unknown | eligible-handoff. Never auto-picked as a destruction date. decision_validity_until timestamp 1 RFC 3339 with explicit offset. Review replay is valid only inside this window. Serve still re-evaluates. recorded_at / recorded_by timestamp / ref 1 Required. Record time is not valid time of the source object. canonical_digest digest 1 Algorithm identifier recorded beside the value. Digest ≠ identifier ≠ permission. JointDisclosureReview Identity-class: a governed composition-risk record, not a Projection and not an aggregate master of the underlying objects. One review covers one closed membership set. Change of any invalidation condition requires a new review, not an in-place edit. Field Kind Card. Rule review_id / review_revision identifier 1 / 1 Required. Distinct from package_id. membership[] object 1..n Each: package_id + package_revision + host_object_id + host_object_revision + shape fingerprint. Closed set. audience_id / purpose_code reference / code 1 / 1 Must match every member or the review is invalid. inference_notes text 0..1 Human or structured note. Presence of a note is not a mathematical proof that inference is impossible. 800-188 §4.3.11. cohort_floor_ref reference 0..1 WM-XCT-005 instrument if resolvable. Unresolvable ⇒ review cannot reach approved for any aggregate-only or hybrid grain. reviewer_id / reviewed_at reference / ts 1 / 1 Required for approved or rejected. pending may omit reviewer. verdict code 1 pending | approved | rejected | invalidated. approved is time-bounded. invalidation_conditions collection 1 At minimum: membership change, any source revision change, audience change, purpose change, shape change, classification upgrade of a member, new hold on a member. validity_until timestamp 1 RFC 3339 with offset. Not perpetual. 800-188 §3.6: approvals should not be indefinite. 3.2 Lifecycle Proposal states: drafted → submitted → pending-review → approved | rejected → superseded | invalidated → retained-as-evidence | tombstoned. Approved does not imply currently-servable. A parallel serve-eligibility flag, if a host keeps one, is computed at serve time from current grant + hold + classification + schema and is not a field of this model. Review states: pending → approved | rejected → invalidated. Invalidated is terminal for that revision. A new review is a new identity, with supersedes-ref optional. Time: recorded_at is record time. decision_validity_until and validity_until are decision horizons. Host-object valid time stays on the source. Schema version ≠ package revision ≠ review revision ≠ status. All timestamps RFC 3339 with explicit offset; a value lacking an offset is rejected rather than assumed UTC (alignment with 002 canonicalization, observed). Correction: a wrong proposal is superseded, not silently edited. Idempotent submit of the same canonical digest returns the existing package_id. Rights: the host object owner is master of source facts; the Dimension owner is master of the proposal record; the reviewer is master of the verdict; the retention owner (035, deferred) is master of schedule and hold; the PDP owner (038, referenced-not-fetched) is master of serve-time decisions. Conflicts: two approved reviews with overlapping membership and different verdicts for the same audience+purpose do not silently combine. The host records a restricted unresolved-composition state. Equal-authority conflict is not overwritten. Competing hold and erase instructions produce disposition_state = unresolved and require the retention owner — they do not pick a date. 3.3 Relationships and mastership Edge Kind Master / reader / purpose Proposal → host object REFERENCE Host object owner is master of the object. Proposal stores id+revision only. Proposal → 003 shape policy REFERENCE 003 owner is master of shape. Proposal stores policy version + template fingerprint. Proposal → 002/038 decision REFERENCE Citation of coverage evidence. Not a copy of the grant. Not current permission. Proposal → 020 binding REFERENCE Scheme+version+term. 020 owner is master of the binding. Code ≠ grant. Proposal → JointDisclosureReview REFERENCE Required. Review owner is master of the verdict. Proposal → retention / hold REFERENCE 035 deferred. Schedule and hold owners stay external. Companion never executes destroy. Proposal → DAT-004 schema REFERENCE Pin only. Unbound or drifted ⇒ fail closed. Review → member proposals COMPOSITION (identified) The review is the aggregate. It does not become master of member objects. 4. Five canonical facets For every exported type the five required facets are covered as required / optional / not-applicable / delegated, with reasons and exact pins for actual delegation. Another taxonomy is not substituted. 4.1 ContextPackageProposal Facet Coverage Reason and pin identity-class Required package_id + package_revision + schema_id/version + canonical_digest. Digest is integrity, not identity. No new WM identity scheme is minted; identifier precedence follows the Dimension rule already used by 002/003. direct-properties Required Closed permitted_field_set, audience, purpose, validity window, review_status, disposition_state. These are properties of the proposal, not of the host object. recognition-observation Delegated Whether two proposals address the same host object is recognition of the host identifier, owned by the host identity model (EM-XCT-01 / WM-XCT-011, not closed here). The companion stores host_object_id as given. Alias/same-as (WM-XCT-036) is not imported. capabilities-behaviour-actions Required (narrow) submit, supersede, invalidate, cite. Explicitly not: evaluate-coverage (002), compile-output-template against instance data (003/038), assign classification (020), execute disposition (035). A host may implement the four narrow actions. context-evidence Required + delegated Required locally: recorded_at, recorded_by, canonical_digest, grant_evidence_ref, component digests. Delegated: audit trail of reads (004), legal-hold register (035), identity proofing of parties (out of 002). Pins: 002 decision-correlation-id pattern; 003 assemble-disclosure-provenance-tuple as a cited shape, not copied. 4.2 JointDisclosureReview Facet Coverage Reason and pin identity-class Required review_id + review_revision. Distinct namespace from package_id so a review cannot be mistaken for a package or a host object. direct-properties Required membership set, audience, purpose, verdict, validity_until, invalidation_conditions. inference_notes optional. recognition-observation Not applicable The review does not claim that member objects are the same subject. Membership is set identity, not entity resolution. capabilities-behaviour-actions Required (narrow) open-review, record-verdict, invalidate. Not: compute k-anonymity, spend a privacy budget (005, referenced-not-fetched), serve data, destroy data. 800-188 §3.6 DRB may delegate review but not to those who performed the de-identification — reviewer_id is therefore required on approved/rejected and must be distinct from the package recorder where both are known. context-evidence Required reviewer, reviewed_at, membership digests, cohort_floor_ref (if any). Residual-risk quantification is not-applicable here and is not supplied by a human approval (800-188 §3.7.2, §4.3.8, §4.3.11). Delegations that are pins of retrieved models: output shape → WM-XCT-003 0.3.0-research.1; permission instrument → WM-XCT-002 0.3.0-research.1; classification binding pattern → WM-XCT-020 0.3.0-research.1 (boundary-review-required); retention execution → WM-XCT-035 (todo, no spec); runtime serve → WM-XCT-038 (referenced-not-fetched); schema semantics → WM-DAT-004 (referenced-not-fetched); policy identity/approval → WM-KNW-012 (referenced-not-fetched); audit trail → WM-XCT-004 0.2.0-legacy (not fetched in full). A referenced-not-fetched neighbour is not treated as an executable import. 5. Routes, invariants, negatives, profiles 5.1 Fifteen Bundle → Layer → Finding → Question → Artifact → Action routes These are research routes for the companion, not an installed Vercy bundle pack. Permitted actions are the narrow set from §4. “Refuse” is a permitted action. “Serve instance data” and “destroy” are never permitted actions of this companion. ID Bundle Layer Finding Question Artifact Permitted action R01 Identity pins Source binding One object per proposal Which host object revision is pinned? Proposal record submit only if host_object_id + revision resolve; else refuse R02 Identity pins Schema pin Schema version is not object revision Which source schema version is in force? Schema pin block submit only with schema_id+version or explicit unbound; drift ⇒ invalidate R03 Field closure Default deny Unknown field fails closed Is every requested path in permitted_field_set? Closed field set refuse package if any path is unknown or new R04 Classification Pinned scheme A code is not a grant Which scheme IRI+version+term applies? classification_refs[] cite 020-style binding; never treat term as permit R05 Classification Downgrade signal Reclassification is an input, not a local edit Has any member class changed since review? Reclassification notice (external) invalidate review; do not locally lower a class R06 Purpose / audience Declared purpose Purpose-limited disclosure expires Which pinned purpose vocabulary version is used? purpose_code + vocab version invalidate on purpose change; do not infer purpose R07 Grant citation Coverage evidence Citation is not current permission Which 002/038 decision id and horizon are cited? grant_evidence_ref cite only; serve-time re-evaluation is out of scope here R08 Shape 003 component A shape does not cover many objects Which 003 policy version and template fingerprint? shape_policy_ref attach fingerprint or declare metadata-only R09 Composition Joint review Card approval ≠ combination approval Does membership equal the reviewed set? JointDisclosureReview open-review; approved only for the closed set R10 Composition Inference note A note is not a proof What residual channel is recorded? inference_notes + optional 005 ref record note; refuse approved-aggregate if 005 unresolvable R11 Freshness Validity window Digest ≠ freshness When does this review expire? decision_validity_until invalidate at horizon; refuse replay outside window R12 Retention Schedule reference A condition does not authorize destroy Which external schedule version is cited? retention_ref cite or mark not-assessed; never pick a date R13 Retention Hold A hold is not perpetual retention Is any hold_ref active? hold_ref set disposition_state away from eligible-handoff R14 Disposition conflict Unresolved state Competing instructions stay visible Do hold and erase-request compete? disposition_state = unresolved expose restricted unresolved record; do not execute R15 Refusal channel Uniform deny Denied ≠ missing ≠ internal diagnostic What may a recipient see on refuse? Recipient-visible refusal card emit uniform refusal; keep diagnostics on the internal channel 5.2 Eight testable invariants ID Name Test I1 Single-object pin A ContextPackageProposal with two host_object_id values, or with a membership set that names an object not listed on its JointDisclosureReview, is invalid. I2 Four version axes schema_version, host_object_revision, package_revision and review_status are pairwise distinct fields. A writer that stores “version=active” in one slot fails the invariant. I3 Unknown is not a default An unbound classification, an unresolvable 005 floor, an unresolvable retention schedule, or an unknown field is not rewritten as unclassified, zero, false, approved or erased. I4 Code ≠ grant ≠ shape ≠ hold A classification_ref does not imply grant_evidence_ref. A grant_evidence_ref does not imply a 003 fingerprint. A retention_ref does not imply a hold_ref. A hold_ref does not imply eligible-handoff. I5 Joint review closure If membership, any source revision, audience, purpose or shape fingerprint differs from the review record, verdict cannot remain approved. I6 Replay ≠ serve Two evaluations of the same canonical_digest inside decision_validity_until must reproduce the same review_status. They must not be treated as a current PEP decision. I7 Hold blocks eligibility If any hold_ref is present and not recorded as released, disposition_state ∈ {unresolved, blocked-unknown} and never eligible-handoff. I8 Uniform external refusal Recipient-visible representations of rejected, invalidated, unknown-object and unauthorized-object are indistinguishable from one another in object existence, field names, omitted counts and restricted policy reasons. 5.3 Ten meaningful semantic negatives ID Negative Why it is semantic, not stylistic N1 DisclosurePolicy is not ProjectionContract. 003 owns shape. The companion owns a review of a closed package. Neither owns a grant. N2 Offer is not Agreement. ODRL 2.2 §2.1.2–2.1.3. An assigner offering is not a grant to an assignee. N3 De-identified is not anonymous. 800-188 treats de-identification as risk-limiting, not as a guarantee. 003 already records that 45 CFR 164.514 de-identified is not equivalent to anonymous under EU law. N4 Aggregation is not privacy. 800-188 §4.3.8. A named summary that subtracts from another named summary is the matrix-group case. N5 Hold is not a new schedule. A hold suspends eligibility. It does not rewrite retention_ref into perpetual retention. N6 Stop-serving is not destroy. Revoking a grant or expiring a review stops new reads. Destruction is a different owner, a different record, and a different evidence object. N7 Tombstone is not erasure of evidence. A tombstone retains identifier and reason so deletion is distinguishable from never-existed. Destroying the tombstone is a separate, usually forbidden, act. N8 Digest equality is not authorization. Two packages with the same digest may still be unservable because the current grant was revoked. N9 Denied is not missing. A recipient must not be able to distinguish “this object exists and you may not see it” from “no such object” via the external channel. N10 Approved review is not current classification. A later 020 reclassification is an input signal that invalidates the review. The review does not freeze the class. 5.4 Three synthetic profiles Startup profile — one project object Host object: a project record. Public name is in permitted_field_set. Internal budget is not. Partner audience + declared purpose pin one approved name revision. An unknown field or a source-schema drift fails closed (I3, R03, R02). A denied request uses the uniform external refusal (I8, N9). Internal diagnostics on a separate channel may name the field and the policy reason. The package is metadata-only if no 003 fingerprint is attached. No claim is made that the partner cannot later learn the budget by other means. Matrix-group profile — separately permitted summaries Two proposals, two host objects or two grains of one object, each individually approvable as a named summary. Their combination lets a recipient subtract totals and infer a small team's individual metric. A JointDisclosureReview with both members is required before any joint package is even a candidate for serve-time evaluation. Changed membership, source revision, audience, purpose or shape invalidates that review (I5). The review may record an inference note; the note is not a proof (N4, 800-188 §4.3.8 and §4.3.11). A cohort threshold, if a 005 instrument later exists, is a referenced floor, not a local default. A real aggregate is this review object, not a Projection pretending to cover many objects. AI-organization profile — model-release object Public release notes sit in one proposal. Restricted evaluation details sit in another, with a tighter audience and a purpose that expires. Purpose expiry invalidates the restricted proposal's review even if the object revision is unchanged (R06). Current authorization, reclassification or hold changes affect new reads, including of cached copies — but this companion does not reach into recipient caches; it records that immutable past evidence and current serving authority are distinct (N6, N8, I6). Source history, derived caches, output packages, policy evidence and backups may have distinct custodians and distinct disposal obligations; those custodians are references, not fields invented for 035. No automatic erasure from every recipient is claimed. 5.5 Correction, idempotency, rights, conflict, round-trip, migration, disposal limits Correction: supersede, do not mutate. The superseded revision remains readable to the extent its own review and grant allow, so that an as-at question about “what package was approved on date D” stays answerable. Idempotency: submit(canonical_digest) returns the existing package_id when the digest matches a live revision. A different digest is a new revision, not an overwrite. Rights: see §3.2. Domain objects and grants stay with their owners. This companion writes only its two record types. Conflict: equal-authority disagreement on a joint review produces unresolved-composition, not a silent winner. Competing hold and erase produce disposition_state = unresolved and a handoff to the retention owner. Round-trip: exporting a proposal and re-importing it through the same canonical form must yield byte-identical digest or a declared-loss report. Undeclared loss is divergence, not “close enough”. Encodings (JSON, YAML, Markdown) are projections of the canonical field set, never the definition of it — alignment with 002/003 observed canonicalization rules. Migration: a companion schema_version change is a new schema_id/version. Existing proposals are not silently reinterpreted. A mapping table, if a host writes one, is a separate artifact with mapping-fidelity values (exact / broader / narrower / related / none), copied as a pattern from 002, not as a conformance claim. Disposal limits of this companion: it may mark a proposal tombstoned (identifier + reason retained). It may not destroy host data, audit entries, hold registers, or recipient copies. It may not treat a tombstone as proof that every cache is gone. Disposal of the proposal record itself is a Dimension act under whatever retention model eventually exists (035 deferred; KNW-012 named by 003 as the owner of policy-record destruction — referenced-not-fetched). 6. Strongest counterexamples Each counterexample is a reason the companion stays small. An ontology that merely names the failure is not a control. The preferred control is fail-closed plus a visible unresolved state. Nested object paths and metadata leaks A permitted field “release.notes.title” is approved. The path “release.notes.author.email” is not in the closed set but is returned by a wildcard or graph-expansion default. 003 default-deny and this companion's permitted_field_set are the control. Graph extent, if used, must be an explicit member of the field set, not a runtime convenience. Metadata of the proposal itself (reviewer name, omitted-field count, rejection reason) is a second leak surface and is projected by a separate, narrower shape. Unknown labels A payload arrives with classification label “Restricted-Internal” that is not in the pinned scheme version. Treating it as unclassified, as the nearest broader class, or as approved is I3 failure. Correct behaviour: classification_refs item recorded as unbound; review cannot reach approved; external channel remains uniform refusal. Multiple schemes and compartments The same field carries a 020 binding under scheme A (public) and scheme B (export-controlled). The companion stores both refs and does not compute a meet. A host that needs a meet belongs in 003 class-matrix checking, which 003 already names and which this companion only cites. Two schemes are not one code. Joint inference Startup name card + matrix headcount card + matrix compensation-total card. Each card is a permitted projection. The combination reveals an individual metric. Control is JointDisclosureReview over the closed membership, invalidated by any membership change. Control is not a cohort number written on one of the cards. 800-188 §4.3.11: composition without controls is unpredictable. A human approval is not a proof (N4). Repeated releases The same approved package is served on day 1 and day 90. Between the two serves a neighbouring package was also served. 800-188 §3.4: repeated releases may compromise privacy if combined. The companion's validity window bounds the review, not the recipient's memory. No claim is made that a new review retracts prior bytes. Stale decisions grant_evidence_ref points at a 002 coverage decision whose validity_end has passed, or whose instrument was withdrawn. Digest of the proposal is unchanged. I6: review may still replay; serve must re-evaluate. 800-162 §3.3.1 names attribute caching as a first-class stale-input risk. Concurrent host updates require an atomic freshness boundary or an explicit limited decision validity — this companion supplies the latter as decision_validity_until, not the former. Cache and recipient copies A partner cached the approved name last quarter. The grant expired. This companion can invalidate its own review and can cite propagate-termination on the 002 instrument. It cannot claim erasure from the partner's disk. Distinct custodians for source, cache, output package, policy evidence and backup are references, not a distributed-delete protocol. Competing hold and erase instructions A legal hold_ref is active. A data-subject erase request arrives. Silently picking the earlier date, the later date, or “delete everywhere except the hold” without an owner is forbidden. disposition_state = unresolved. The restricted record names the two instruction refs and the retention owner. Stop-serving may still occur via grant withdrawal; that is N6, not destroy. Classification downgrade A reviewer approves a package while a field is bound to “public”. An authority later binds it to “restricted”. Leaving the review approved is N10 failure. The invalidation_conditions list includes classification upgrade of a member. A local writer that lowers the stored class to keep the review alive is outside this model and is a 020-owner act, not a companion act. Denied-versus-missing distinguishability Response A: HTTP 404, empty body. Response B: HTTP 403, body “budget is classified, 1 field omitted”. Response B teaches the recipient that the object exists, that a field named budget exists, that a count of omitted fields is 1, and that a restricted policy reason applies. I8 forbids B on the recipient-visible channel. Internal diagnostics may look like B. The two channels have different audiences and different shapes. 6.1 Why a small executable boundary is preferred The companion is executable only in the narrow sense that a host can persist two record types, compute a digest, compare membership sets, and refuse to treat an unreviewed or invalidated package as an input to a compiler. That is already enough to fail the startup unknown-field case, the matrix joint-inference case, and the denied-versus-missing case on the review plane. Adding a universal identity model, a PDP, a de-identification library, or a deletion engine would not make those cases stronger; it would hide owner boundaries that 002, 003, 020 and the 035 todo page already insist on keeping visible. 7. Retrieval and verification limits 7.1 What was actually retrieved this session Observed, live URLs, 2026-09-21: WM-XCT-002 landing and spec.yaml wrapper. WM-XCT-003 landing and spec.yaml wrapper. WM-XCT-035 landing (todo text). WM-XCT-020 spec.yaml and HTML (0.3.0-research.1 PATTERN). EM-XCT-05 enterprise card at https://ver.cy/enterprise/models/em-xct-05/ (Being researched; listed candidates 002, 003, 035). EM-XCT-01 and EM-XCT-04 cards for contour comparison. RESEARCH-PROTOCOL.md fragment on Projection versus aggregate. Catalogue pages at https://ver.cy/models/ . ODRL Model 2.2 and Vocab 2.2 Recommendation pages. DPV 2.3 Final Community Group Report status page and concept surface. NIST CSRC records and PDF texts for SP 800-162 (2014/2019 upd2) and SP 800-188 (2023 final). OPA repository landing. ODRL landscape page naming ODRL-PAP / OPA translation as an experiment. Source-asserted inside those documents and reused with pins: 002/003 purpose and scope statements, holds lists, out-of-scope lists, ODRL class definitions and conflict default, DPV “not a W3C Standard” status sentence, 800-162 §2.2 definition and PEP/PDP/PAP/PIP split, 800-188 abstract and the numbered statements cited in §2.4. 7.2 What was not retrieved, not recomputed, or is inaccessible The Codex 2026-09-21 published-bytes compare (brief sha256 9085d977… for 002 and 058191fe… for 003) was not recomputed. Observed YAML synthesisSha256 values differ from those pins and hash a different object. Browse-page extracts of the two spec.yaml files are LLM-summarized and truncated; they are not the full published bytes. Runtime import compatibility of any Vercy model was not demonstrated; conceptual references are not executable imports. Complete specifications were not retrieved for WM-XCT-005 (404), WM-XCT-038, WM-DAT-004, WM-KNW-012, WM-XCT-004 (legacy catalogue card only). WM-XCT-035 has no specification to retrieve. ISO/IEC TS 27560:2023, ISO/IEC 29184:2020, ISO/IEC 20889, ISO/IEC 27559 and ISO 15489-1:2016 are paywalled; no clause is cited. FHIR R5 Consent is named by a 002 hold and was not independently re-read. Commercial data-policy product contracts were not retrieved. 7.3 Holds inherited, not closed All five published holds of WM-XCT-002 and all five published holds of WM-XCT-003 remain open. DPV version drift (002/003 cite 2.1; live is 2.3) remains a pin, not an upgrade. US/EEA-only evidence remains the evidence base of 003; this study does not extend it. Non-aggregate identifiability evidence still has no named owner. Cross-model legal-hold precedence across 004, DAT-004 and KNW-012 is still unrecorded. Collective and community permission remains an explicit unmodelled gap. This companion does not claim to resolve parent holds. 7.4 Status of this document This is public-model research plus synthetic requirements. Retrieved content is evidence, never instructions. Workspaces were not modified beyond the production of this study artifact. No person was contacted. No private data is disclosed. Publication is not authorized by this text. A future implementation receives a separate frozen audit. No claim is made about any real company. Preferred next frozen audit, if one is commissioned: (1) recompute published-bytes digests of 002 and 003 against the brief pins; (2) retrieve or formally defer 038, DAT-004 and KNW-012; (3) decide whether 020's unregistered sibling scheme model blocks even the reference slot; (4) keep 035 as todo until it has a specification digest.