# Enterprise Classification Review 0.1.0 This original companion evaluates a frozen classification context and produces a reproducible assessment. It checks an independent category-set assignment, a narrowing profile, or a proposed migration candidate. It never writes a classification onto a live subject. A company can use it before adopting a new category, restricting a local profile, or reviewing a retired code. ## Boundary and identity ClassificationReviewPacket is a locally owned aggregate with a stable id, revision, optional previous content digest, Dimension, owner, purpose and knowledge/effective/target instants. Revision1 has no predecessor; later revisions name a predecessor digest. The reference validates that convention but does not fetch or resolve the packet history. The host retains that history and decides which revision to inspect. A packet is a review context, not a copied Company, Project or Document. ClassificationAssessment is a distinct immutable local result. Its assessmentId hashes the exact packet digest, evaluator build and sorted host approval basis. Different approval evidence or evaluator bytes yield a distinct result. Repeating identical input and basis yields identical bytes; wall-clock generation time is not injected. knowledgeAt is the evidence cut, not a claim that computation physically happened then. The host may separately record actual computation/capture time. CodeReference is a value `(scheme, version, code)`. Equality in this dialect compares exact Unicode strings; there is no case folding, Unicode normalization, numeric coercion, alias resolution or implicit URI normalization. These are qualified assessment coordinates, not a claim that a publisher's enduring concept acquires a new semantic identity every release. Display labels never select a code. A publisher may preserve concept IRIs across releases; this evaluator still demands an explicit release coordinate. SchemeReleaseSnapshot, SlotProfileSnapshot, AssignmentSnapshot and CrosswalkSnapshot are marked frozen value copies, not additional authoritative domain entities. Each carries snapshot id, source identifier, source revision, declared source-byte digest, capture event id/actor/UTC time/method, payload and recomputed local snapshot digest. Capture ownership belongs to the host; scheme meanings, binding assertions and mapping claims remain with their original authorities. sourceDigest is a custody declaration: the evaluator does not fetch or authenticate source bytes. The local digest detects changes to the supplied envelope, not false source statements. WM-KNW-018 and WM-XCT-020 are semantic references, not parents or executable imports. The former owns scheme/concept/graph/mapping concerns, the latter design-time binding slots and instance binding assertions. This companion evaluates a small declared dialect over snapshots. Their published research holds, non-executable schemas and source limitations are not inherited as readiness claims. A profile URI here identifies captured slot rules; it is not a new identity class for the classified subject. ## Inputs and explicit modes The closed packet contract is in classification.schema.json `$defs.packet`; host context and assessment have separate definitions. Snapshot payloads discriminate their kind. Required fields have no implicit defaults; unknown release completeness is represented by complete=false, not by an empty list treated as complete. Identifiers are bounded opaque nonempty strings, not universally validated URI syntax. Synthetic examples use URNs. Modes are profile, assignment, migration and metamodel-migration. profile has no selected assignment; the other modes require at least one. Multiple selected assignments are retained as ambiguous source selection and yield insufficient-context. They are not merged or ranked by revision. A host can select a single corrected assertion and retain its predecessor snapshot as evidence. The correction must name the same binding id, subject and slot with a smaller revision; full source history/mastership verification remains external. Profile-only review checks finite restrictions without a business object. Assignment mode reports source-profile conformance and selected-profile conformance separately. Migration mode evaluates exactly one source assignment with one category and a separate receiving profile. Other migration multiplicities require review; the packet can still retain their evidence. metamodel-migration always refuses automatic model identity/installation migration. An explicit chain-requested inference also returns unsupported; direct-only never traverses a path. No inference result denies SKOS transitivity or claims that unmapped concepts are unequal. ## Profile and membership semantics A profile declares stable source id/version, optional exact parent snapshot pin, subjectClass, classification unit, slot id, exact meaning text, binding strength, release pins, allowed qualified codes and min/max cardinality. The implemented dialect is required finite sets of independent category selections. It is NOT FHIR CodeableConcept, a generic SHACL dialect or translated codings of one concept. All selected categories must belong to the finite set, without duplicates. Other binding strengths produce unsupported rather than successful conformance. Every used release is pinned through a snapshot id/digest. Its concepts have exact codes, definitions, status, selectability and half-open validity intervals. Duplicated codes, duplicate release coordinates inside one profile and duplicate allowed entries are refused. Across the complete packet, captures of the same scheme/version must have exactly equal payloads under the restricted canonical encoding. Equal payloads may have distinct capture envelopes; conflicting definitions, enumeration, status, validity or completeness are refused, including across base and target profiles. The same consistency rule applies to profile id/version, assignment id/revision and crosswalk id/version. It does not establish source truth or compare different versions. If an enumeration is incomplete, membership/exclusion cannot establish a complete profile check and the result is insufficient-context. A complete release must contain every referenced allowed code. Declared completeness is an evidence claim requiring host verification; SKOS and a content hash do not establish it. A child profile must preserve subjectClass, unit, slot, meaning, strength and the exact set of release snapshot pins. Its allowed set is a subset, its minimum cannot fall, and its maximum cannot rise. Parent references are exact and ancestry is bounded to8 and acyclic. The effective profile in ordinary assignment/profile mode must descend from the supplied base. A new scheme/release or changed meaning requires a separately reviewed target profile, not a disguised restriction. Profiles may restrict a slot to0..0. A positive minimum over fewer allowed values is unsatisfiable and refused. Removing values emits a coverage question because formerly classifiable subjects may no longer fit. ## Historical conformance and new-use eligibility All timestamps use exactly UTC seconds `YYYY-MM-DDTHH:MM:SSZ`; other valid RFC3339 spellings are outside this first dialect. Intervals are `[start,end)`; null end is open. Capture must be no later than knowledgeAt; assertion time must be no later than its capture. The host review call supplies current time independently and forbids a future knowledge cut. Assertion, effective, target, knowledge and native capture times are not interchangeable. Historical conformance uses the assignment's exact source profile, requested effectiveAt, assignment validity and concept validity. A retired/deprecated concept may remain valid historical evidence within its recorded interval. A proposed assertion can be structurally assessed, but its state is retained and does not become a fact. Disputed/withdrawn assertions are not selected as operative source truth. The reference cannot discover an omitted dispute or a newer authoritative revision. New-use migration eligibility uses targetAt and requires an active, selectable target within its declared interval, in the receiving allowed set. This is a deliberately conservative local policy; other systems may admit deprecated codes. A historical source pass is distinct from a current or planned target recommendation. Future target assessments are conditional on captured evidence, never guarantees of future status or authority. The reference does not implement a live bitemporal query engine. ## Crosswalk and decision rule A crosswalk snapshot names its own source id/version, exact unit/purpose/jurisdiction context, completeness declaration and bounded mapping entries. Each entry has stable source entry id, source and target arrays, predicate, lifecycle state, approving-actor claim, evidence references, validity interval, origin, method/version, optional uninterpreted score and loss note. Empty-to-n and n-to-empty associations can be retained; empty-to-empty is refused. Duplicate members/entry IDs are refused rather than deduplicated. Compound associations remain compound. Direct-only review selects entries whose source array explicitly contains the single qualified source category. Duplicate selected crosswalk IDs are refused. It preserves their predicate, claimed state, score, method, full sources/targets, context and target eligibility. Context mismatch is visible and never globally reused. No candidate is chosen by label, score, array order, latest revision or number of sources. Nonmatching entries remain in the frozen packet even if they are not relevant alternatives in the derived result. A proposed-candidate requires ALL of: source conformance; source claimed asserted; compatible subject class/unit/slot/meaning; complete admitted correspondence context; complete supported source/target profiles; receiving cardinality permits one; at least one applicable direct1:1 exactMatch; every applicable row is direct1:1 exactMatch, claimed approved and separately acknowledged in the supplied host context; one distinct target across ALL applicable rows; active/selectable/allowed target at targetAt. Multiple duplicate approval rows to the same sole target may coexist; they confer no greater authority. Rejected, superseded or temporally inapplicable rows remain visible but are not operative alternatives. A live contested, candidate, compound or nonexact row prevents automatic candidate selection under this strict rule. All applicable targets are collected BEFORE profile eligibility. Excluding one target through a narrower profile never erases competing correspondence evidence or authorizes choosing another. Split, merge, zero-side, nonexact, unacknowledged or conflicting alternatives yield human-review-required. A chain request is unsupported, and direct-only will not follow A→B→C even if SKOS entails conceptual exactness. This is execution scope, not a replacement for SKOS/XKOS semantics. A mapping approval is a captured assertion plus external host acknowledgment, not cryptographic proof of the approver's competence. The assessment candidate is only a proposal. effects is always empty. No API assigns, retracts, changes a business subject ID, approves a mapping, installs a model or executes downloaded code. Legacy model-ID mapping needs complete semantic comparison, an independently authorized installation plan and a separate migration adapter. A caller mislabels its business category namespace at its own semantic risk; this engine still has no automatic identity-replacement operation. ## Host authority, disclosure and storage review(packet,host,actor,purpose,now) checks a separately supplied host context before detailed assessment. The context binds exact packet digest, Dimension, owner, actor, purpose and half-open grant interval. The host must authenticate actor, supply a trusted clock, establish context origin and verify rights to read the COMPLETE packet. Packet fields cannot grant themselves permission. The reference compares declarations; it is not IAM, signature verification, a grant store or a network access control boundary. It cannot detect a coherently forged host context supplied by its own caller. Read permission alone is not mapping approval. Each acknowledgment binds exact crosswalk snapshot digest, entry id, approver and an evidence reference. Changing a snapshot invalidates the old acknowledgment. The host verifies the approver's authority and source custody before providing that acknowledgment. Assessment retains the exact basis used so later replay can reproduce the historical decision; this retained basis never authorizes a new read or operation. The complete packet, evidence identifiers, scores, meanings, decisions and approval basis may be sensitive. The initial binding is restricted, all-or-nothing, within one owning Dimension. The host controls disclosure, storage permissions, retention, correction history and disposal. No redacted projection, cross-Universe exchange or erasure workflow ships. Possession of this Python library or a digest is not an access grant. inspect_snapshot checks consistency of already-authorized historical data and returns authorized=false; it does not authenticate evidence. Private data may not be published with the public package. ## Integrity, failure and replay Original restricted canonical encoding: Python sorted-key compact UTF-8 JSON, ordered arrays, integer values only, exact booleans, null and strings. Floating point, duplicate JSON keys, nonstring keys, C0/C1/DEL controls and unpaired surrogates are refused. No BOM. No RFC8785/JCS claim. Other Unicode remains lexically distinct; UIs must render unfamiliar/format characters safely. Snapshot digests omit only their own digest field. Packet digest includes full input. Build id includes the evaluator and closed schema bytes. Approval basis is sorted for assessment identity; the packet's array order remains part of its content identity. Shape/integrity errors raise Invalid; unauthorized calls raise uniform Denied; CLI reports rejected-input or not-authorized. Schema parsing errors are not successful assessments. Domain outcomes distinguish local nonconformance, outside-valid-time, insufficient-context, unsupported and human review. Both assignment and concept interval exclusions use outside-valid-time in detailed results. Per-check evidence/questions remain even when a top-level priority summarizes them. Current priority is insufficient-context, unsupported, nonconformance, review, candidate-only, then conforms-to-local-profile. A pass means only the checks implemented over the supplied snapshots. It does not prove organizational truth or full standards conformance. The public review call validates the returned assessment and combined {packet,assessment} against their schemas and1MiB canonical ceiling. A packet that fits alone may be refused if its complete replayable result would exceed that ceiling. No result is truncated. Historical replay still requires the caller's current disclosure authorization. Captured corrections of a selected assignment and proposed assignment state emit notices; they do not override the host's explicitly selected historical revision. An explicit chain-requested flag is unsupported in every mode. Irrelevant host approvals remain recorded basis, can change assessment identity and grant no authority by themselves. Limits:1MiB canonical value,2MiB raw input, nesting32,32 snapshots,8 release pins/profile,256 members/allowed values,32 selections/assignment,8 selected assignments/crosswalks,64 entries/crosswalk,16 sources/targets/entry,64 host acknowledgments, ancestry8. The ancestry cap counts the complete chain including previously compiled ancestors. Profile min/max may describe up to256 categories, but a minimum above the32-selection instance capacity yields unsupported even in profile-only mode. A larger maximum alone does not make a profile unusable when a permitted smaller selection fits. This is a finite reference implementation, not enterprise throughput infrastructure. The CLI reads bounded files and emits a result; no database or network connector is included. inspect_snapshot re-evaluates every stored result using the exact installed build and recorded approval basis, rejecting changed claims, missing fields or forged results. Source authenticity and current authority remain external. migrate_snapshot only round-trips the current exact version/build; other versions raise an explicit refusal. There is no silent downgrade, writable restore, host transfer or existing-Dimension migration. Identical packet and basis create no new assessment identity or approval. ## Native V3 binding and assurance Native materialization creates ONE local ClassificationAssessment object with one restricted classification.assessment.snapshot fact. It contains the exact packet and assessment. Its object ID derives from the local assessment digest, never from renaming the classified subject. The packet references external subjects unchanged. One aggregate object has its own owner, purpose, boundary and deterministic calculation; it is not a multi-subject federation projection. Native validFrom is capture time for the recorded assessment; business effective/target/knowledge instants remain in the nested value. The fact is asserted evidence that an assessment record exists, not an assertion that its classifications are true. No supersession chain is accepted by this first native binding. Different evidence/build produces a distinct assessment; repeated recording of the same assessment ID is refused by the Vercy writer. The host retains the first recording and controls aggregate history. Generic native validation checks the outer envelope and declared object path. The installed companion validator MUST also replay the closed nested packet/assessment. A native pass alone cannot establish nested semantics, authenticity or current access. Tests and native acceptance reports are separate from the independent S1 studies; a frozen no-tools audit is still required before publication. Published lifecycle and reviewable-draft assurance remain separate from completing the broader EM-XCT-09 contour.