{
  "format": "vercy-enterprise-model-selection",
  "version": "0.1.0",
  "status": "verified-pins-with-reviewable-draft-assurance",
  "runtimeSnapshotSha256": "b05dccc1797021e086dfc1b5ce5b49678917cf0d495faf0cd84a4441a1509d51",
  "note": "A selection aid for a Dimension agent, not an installed Dimension or a claim of complete company coverage. Re-resolve required closure and compare compatibility at installation. Object relationships do not create mandatory package dependencies. Select only models justified by real needs.",
  "profiles": [
    {
      "id": "small-team",
      "name": "Небольшой коллектив",
      "selectedModelIds": [
        "WM-PER-001",
        "WM-ORG-003",
        "WM-ACT-006",
        "WM-REC-001"
      ],
      "requiredClosure": [
        {
          "id": "vr.wm-act-006",
          "modelId": "WM-ACT-006",
          "aliases": [],
          "slug": "wm-act-006-task",
          "name": "Task",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-act-006-task/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-act-006-task/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-act-006-task/",
          "digest": "sha256:fdbf2bfc5aface45234c4be3fb1cbcc0488bdcc5395e8d8896aa16305a9b8a01",
          "family": "World Models",
          "category": "Activities and processes",
          "domain": [
            "ACT.TSK"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "task",
            "act.tsk"
          ],
          "purpose": "Candidate governed context model for Task; boundary questions remain required.",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification hold: every URL and version pin in the merged register must be re-checked live before publication. Specific items: the two FHIR Task URLs differ between providers (hl7.org/fhir/R5/task.html versus hl7.org/fhir/task.html) and must be reconciled to one version-pinned R5 address; the A2A specification is cited as 'latest released' and must be pinned to an immutable version; the OMG BPMN and CMMN pages were only reachable at specification-metadata depth; and the base records an HTTP 403 on the project-management standards catalogue.",
            "Citation-provenance hold: all iCalendar claims arriving with the accepted Grok findings are anchored to icalendar.org reproductions labelled tier 1 by that provider. Re-anchor each to RFC 5545 at the IETF before publication, and keep the reproduction marked non-primary tier 3 as the base does.",
            "Multi-profile validation hold: the merged model must be exercised against at least four domain profiles before any cross-domain adequacy claim: clinical workflow (FHIR Task), personal and calendaring to-do (VTODO and Microsoft Graph todoTask), organisational human workflow (WS-HumanTask and BPMN), and agent-to-agent execution (A2A). Only the first three are represented in both packs; the agentic profile rests on a single provider.",
            "Retention hold: publish no statutory retention period, lawful basis or erasure right. No legislative or regulatory text was retrieved by either provider, and the retention dimension must ship as a declared gap pointing at a Dimension-supplied schedule.",
            "Conformance-claim hold: the merged model is an alignment union. Block any wording that asserts conformance to FHIR, iCalendar, WS-HumanTask, schema.org or PROV-O; round-trip fidelity per crosswalk has not been tested, and the base already records lossy one-directional mappings for OSLC boolean predicates and for state-vocabulary granularity.",
            "Source-remapping hold: do not emit a draft until Grok-local SRC ids on the two accepted findings are remapped into the merged register and the three newly carried sources (Microsoft Graph todoTask, schema.org Action, FHIR Task detailed descriptions) are added with their own tier and primary flags."
          ],
          "boundary": "The model governs the task instance as a consistency boundary: the task record plus the parts that have no independent identity outside it (status history, role assignments, deadlines, typed inputs and outputs, progress measurements, provenance entries). Reusable task definitions, plans, work orders, projects, parties and produced documents are separate models referenced by typed edges. Storage and interface (JSON, YAML, Markdown, Git, MCP, MongoDB) are projections of these semantics, not part of them.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-003",
          "modelId": "WM-ORG-003",
          "aliases": [],
          "slug": "wm-org-003-team",
          "name": "Team",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-003-team/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-003-team/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-003-team/",
          "digest": "sha256:a42a3ebaeea14fe7b6195a56d57fb34c0b4d6027df4c0ffa7aebf75a79052b0f",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.TEM"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "team",
            "soc.org.tem"
          ],
          "purpose": "Candidate governed context model for Team; boundary questions remain required.",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source and live-version verification is unresolved: all twenty-nine distinct URLs across both packs must be re-fetched and re-pinned before publication, with particular attention to fast-moving or forward-dated version strings including schema.org 30.0 dated 2026-03-19, ESCO v1.2.1 dated 2025-12-10, HR Open 4.5 Final and 4.6 Candidate, the GitHub REST API version 2026-03-10, the Microsoft Graph v1.0 page last updated 2024-10-18, the FEMA RTLT tool version, and the NIST SP 800-53 control release 5.2.0.",
            "Multi-profile domain validation is unresolved: the merged model has not been instantiated against the clinical care-team profile, the workplace-directory profile, the emergency-response typed-resource profile, or the agile-delivery profile. No conformance or alignment language may be published until at least these four profiles have been round-tripped and their loss reports recorded.",
            "Paywalled and landing-page-only evidence must not be published at clause level: ISO 30414:2025 is cited from a committee announcement, ISO 30400:2022 from a catalogue landing page that does not expose a Team term, and ISO 21502 and ArchiMate business collaboration were never obtained. Every claim resting on these must be marked as unverified at clause level or removed.",
            "All seven accepted additions and four of the five accepted functions rest wholly or partly on tier-2 vendor documentation. Each must be re-checked against tier-1 sources for contradiction before publication, and vendor-specific vocabularies for visibility, nesting and archive states must be published as projection detail rather than as base semantics.",
            "Citation provenance for the accepted additions must be repaired: grok asserts RFC 3339 timestamp requirements in membership and post-assignment findings without registering RFC 3339 as a source in its own pack, so every merged node inheriting that claim must be re-pointed at the base RFC 3339 source and re-validated."
          ],
          "boundary": "A Team is a named, bounded collective of two or more actors constituted to perform work together under a shared mandate, whose membership is expressed as time-bounded assignment facts. The model is an aggregate: the team node is the root and the membership-assignment records are governed inside it, following the n-ary reification pattern of org:Membership and FHIR CareTeam.participant. Scope covers identity, classification and capability typing, charter and authority, membership and capability composition, lifecycle and structural change, operating interfaces and footprint, measurement binding, and the governance of team records. Storage and interface (JSON, YAML, Markdown, Git, MCP, MongoDB) are projections and carry no semantics here.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-per-001",
          "modelId": "WM-PER-001",
          "aliases": [
            "H1"
          ],
          "slug": "wm-per-001-person",
          "name": "Person",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-per-001-person/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-per-001-person/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-per-001-person/",
          "digest": "sha256:7a4a71ddd69fdc31b37806958442d1cfca4ec0bf861e54578adb312e0d7a4df3",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.PER.NAT"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "person",
            "soc.per.nat"
          ],
          "purpose": "Natural person as a civil identity and life-course subject",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Reconcile and re-pin the Core Person Vocabulary version before publication: base cites CPV 2.00 (2022-04-01), grok cites CPV 2.1.2 (2026-05-12). Properties grok relies on (Contact Point on Person, residency as Jurisdiction, the gender/sex split, GenericDate) must be confirmed against the live release actually pinned.",
            "Reconcile the ISO/IEC 24760-1 edition: base cites the 2025 edition, grok cites 2019. Both retrievals were catalogue-level only, so no definition, identifier taxonomy or identity-record state vocabulary may be published as canonical from this standard.",
            "Re-verify GDPR Article 9 special-category wording against the EUR-Lex OJ text; the base verified it from an unofficial reproduction (tier 3) after repeated EUR-Lex retrieval failure.",
            "Re-verify CRPD Article 12 and General Comment No. 1 wording against an official UN-hosted text; one provider recorded an HTTP 403 at OHCHR and quoted secondary sources.",
            "Verify every accepted source URL as live and version-pinned, including the two OASIS CIQ v3.0 URL variants, both ICAO Doc 9303 landing pages, and the UN Principles and Recommendations Rev.3 PDF whose body could not be text-extracted (paragraph-level citations are currently absent).",
            "Run domain-profile validation on at least one non-EU profile before publication: the model is EU/UN-weighted (GDPR, eIDAS/EUDI PID, CPV, NIST levels), and a common-law vital-records plus ID-card regime and a Nordic population-register architecture must be mapped into the frame rather than assumed equivalent.",
            "Correct the base coverage-claim counts: it states 7 bundles, 15 layers and 28 findings, but the base structure contains 14 layers; after the accepted addition the merged model is 7 bundles, 14 layers, 29 findings and 14 functions.",
            "Scope the imported alternative-registration-routes finding on publication: only the UN LIA and CRVS-IdM backed portion (host-State or internationally mandated issuance, conferral by an identification authority linked to civil registration, delayed registration) may be presented as sourced; foundling, unknown-parentage and presumed-death-restoration sub-cases must be marked as unsourced operating cases, and the overlap with q-stateless-substitute must be resolved."
          ],
          "boundary": "Format-neutral context structure for the natural person as a legally registered identity and data subject. Covers what an agent must know to establish, resolve, evidence, update, disclose, close and audit a person identity. Excludes the human as a biological organism, and excludes any concept that resolves in a composable sibling model (household, organization, address, vital-event record, qualification, authenticator).",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-rec-001",
          "modelId": "WM-REC-001",
          "aliases": [
            "N1"
          ],
          "slug": "wm-rec-001-document-record",
          "name": "Document / Record",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-rec-001-document-record/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-rec-001-document-record/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-rec-001-document-record/",
          "digest": "sha256:0365b603bf30e7c487a6e353a44d02563dd27e918885b9e96f9bb6861be29002",
          "family": "World Models",
          "category": "Information and virtual systems",
          "domain": [
            "INF.REC.DOC"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "document",
            "record",
            "inf.rec.doc"
          ],
          "purpose": "Documents as governed records",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification incomplete: re-verify every accepted source URL live and pin its version before publication. Claude's ISO 15489-1 source returned HTTP 403 and its ISO-attributed claims were read from catalogue abstracts and indexed extracts; re-verify them against Grok's JIS X 0902-1:2019 identical adoption or licensed ISO text before any ISO-derived statement is published.",
            "eIDAS evidence is second-hand on both sides: Claude used the legislation.gov.uk rendition of Article 3 and flags that Regulation (EU) 2024/1183 amendments are not reflected; Grok used a European Commission FAQ guidance page. Re-pin signature, seal and qualified-timestamp tiers to consolidated EU text before publishing the assurance-tier vocabulary.",
            "Instrument version drift must be reconciled to one pinned version each: RiC-O 1.1 (2025, Claude) versus RiC-CM 1.0 (2023, Grok), and C2PA 2.1 (Claude) versus C2PA 2.4 (Grok). Publish only after the record/instantiation split and the hard-binding rule are re-checked against the chosen versions.",
            "Multi-profile domain validation not yet complete: the merged model has been reasoned mainly against archival and government recordkeeping profiles. Validate against at least three materially different profiles — an EU qualified-signature commercial instrument, a US federal case file under 36 CFR, and a media or generated-content asset carrying content credentials — before publication.",
            "Confirm the WM-REC-015 boundary once that model exists, so aggregation-membership references and the record-set exclusion resolve to real structure rather than a placeholder neighbour.",
            "Strip any residual conformance-claim wording inherited from either provider; the published draft must state alignment and mapping only, with lossiness recorded."
          ],
          "boundary": "Covers the record as an aggregate root over its versions, instantiations, signatures, provenance, events, retention assignments, holds and access decisions, from creation or capture through disposition. Excludes the semantics of what the record is about, the agents named in it, the aggregations that hold it, and any particular storage or interface technology.",
          "verifiedAt": "2026-09-21"
        }
      ],
      "remainingCoverage": "Company boundaries, domain-specific profiles, storage bindings, local authority and private instance facts must be established in the owning Dimension. Startup needs neither payroll nor a legal entity by default."
    },
    {
      "id": "company-core",
      "name": "Компания: организационная основа",
      "selectedModelIds": [
        "WM-ORG-001",
        "WM-ORG-002",
        "WM-PER-001",
        "WM-ORG-005",
        "WM-ORG-003",
        "WM-ORG-006",
        "WM-ORG-004",
        "WM-ORG-016",
        "WM-ACT-005",
        "WM-ACT-006",
        "WM-ECO-006",
        "WM-REC-001"
      ],
      "requiredClosure": [
        {
          "id": "vr.wm-act-005",
          "modelId": "WM-ACT-005",
          "aliases": [
            "K5"
          ],
          "slug": "wm-act-005-project",
          "name": "Project",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-act-005-project/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-act-005-project/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-act-005-project/",
          "digest": "sha256:c0d49f2ff60d60b45c7aec999716f1a6ee106dc2e8221659c1af61a7c4747807",
          "family": "World Models",
          "category": "Activities and processes",
          "domain": [
            "ACT.PRJ"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "project",
            "act.prj"
          ],
          "purpose": "Bounded undertakings with goals and resources",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [
            {
              "type": "contains",
              "target": "WM-ACT-006"
            },
            {
              "type": "contains",
              "target": "WM-ACT-031"
            }
          ],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification: none of the roughly thirty distinct URLs across the two providers has been re-resolved by this adjudication. Every accepted source must be fetched live and version-pinned before publication, with particular attention to the two NASA NPR 7120.5F entry points (directive page versus Chapter 2 deep link), GovS 002 v2.1, the PeopleCert PRINCE2 v7 page, schema.org v30.0, IATI 2.03 codelists, DataCite 4.6 and the NARA GRS page.",
            "Paywalled ISO texts: ISO 21500, 21502, 21503, 21504, 21505, 21508 and 21511 were read only as catalogue abstracts, committee pages, ISO news and one tier-4 secondary clause summary. Clause-level fidelity is asserted at abstract level only and the draft must say so; no clause number may be cited as if the purchased text had been read.",
            "Vocabulary currency: ISO/TR 21506:2018 is withdrawn and replaced by ISO 21506:2024, which neither provider retrieved; ISO 21511 is under revision as ISO/DIS 21511 and ISO 21513:2026 on post-project evaluation was not fetched. No term definition may be published as standard-derived until the current editions are checked.",
            "Multi-profile domain validation: the model has not been exercised against more than one delivery regime. Before publication it must be validated against at least a public-sector regime (NASA or GovS 002), an aid-transparency regime (IATI 2.03), a research regime (RAiD/ISO 23527) and an adaptive or agile delivery profile that maintains no control accounts.",
            "Declared gaps must ship as gaps: no data-protection instrument was retrieved live (the EUR-Lex fetch returned no body) and no information-security control standard was retrieved by either provider. Privacy and security coverage must be published as gaps with the jurisdictional instrument left to the adopting Dimension, not asserted.",
            "Accepted grok content needs first-party re-verification: grok's PMI fetch was blocked and taken via search, and the GovS 002 full PDF and Teal Book were not retrieved. Both accepted findings (f-tailoring-and-compliance, f-transition-disposal-and-residual-obligations) lean on SRC-006 and SRC-007, so their supporting text must be confirmed from the primary documents.",
            "Retention is anchored on NARA General Records Schedules as a US federal working example; the applicable disposition authority is jurisdictional and the adopting Dimension must substitute it before the retention finding is treated as operative."
          ],
          "boundary": "A Project is a temporary, uniquely-scoped endeavour authorized by a sponsor to deliver defined outputs, outcomes or benefits within agreed constraints (ISO 21500:2021 concepts; ISO 21502:2020 practices; APM 'unique, transient endeavour'). This model owns the project as an aggregate root: identification and registration, authorization and governance, objectives and scope boundary, work breakdown, resource/funding/procurement commitments, lifecycle states and gates, approved baselines and change control, progress measurement, risk/issue/assurance, stakeholders, record provenance and access, and closure with retention. It holds typed edges to contained tasks and milestones/deliverables rather than restating their internals. It is storage- and interface-neutral: JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections of the same semantics.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-act-006",
          "modelId": "WM-ACT-006",
          "aliases": [],
          "slug": "wm-act-006-task",
          "name": "Task",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-act-006-task/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-act-006-task/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-act-006-task/",
          "digest": "sha256:fdbf2bfc5aface45234c4be3fb1cbcc0488bdcc5395e8d8896aa16305a9b8a01",
          "family": "World Models",
          "category": "Activities and processes",
          "domain": [
            "ACT.TSK"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "task",
            "act.tsk"
          ],
          "purpose": "Candidate governed context model for Task; boundary questions remain required.",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification hold: every URL and version pin in the merged register must be re-checked live before publication. Specific items: the two FHIR Task URLs differ between providers (hl7.org/fhir/R5/task.html versus hl7.org/fhir/task.html) and must be reconciled to one version-pinned R5 address; the A2A specification is cited as 'latest released' and must be pinned to an immutable version; the OMG BPMN and CMMN pages were only reachable at specification-metadata depth; and the base records an HTTP 403 on the project-management standards catalogue.",
            "Citation-provenance hold: all iCalendar claims arriving with the accepted Grok findings are anchored to icalendar.org reproductions labelled tier 1 by that provider. Re-anchor each to RFC 5545 at the IETF before publication, and keep the reproduction marked non-primary tier 3 as the base does.",
            "Multi-profile validation hold: the merged model must be exercised against at least four domain profiles before any cross-domain adequacy claim: clinical workflow (FHIR Task), personal and calendaring to-do (VTODO and Microsoft Graph todoTask), organisational human workflow (WS-HumanTask and BPMN), and agent-to-agent execution (A2A). Only the first three are represented in both packs; the agentic profile rests on a single provider.",
            "Retention hold: publish no statutory retention period, lawful basis or erasure right. No legislative or regulatory text was retrieved by either provider, and the retention dimension must ship as a declared gap pointing at a Dimension-supplied schedule.",
            "Conformance-claim hold: the merged model is an alignment union. Block any wording that asserts conformance to FHIR, iCalendar, WS-HumanTask, schema.org or PROV-O; round-trip fidelity per crosswalk has not been tested, and the base already records lossy one-directional mappings for OSLC boolean predicates and for state-vocabulary granularity.",
            "Source-remapping hold: do not emit a draft until Grok-local SRC ids on the two accepted findings are remapped into the merged register and the three newly carried sources (Microsoft Graph todoTask, schema.org Action, FHIR Task detailed descriptions) are added with their own tier and primary flags."
          ],
          "boundary": "The model governs the task instance as a consistency boundary: the task record plus the parts that have no independent identity outside it (status history, role assignments, deadlines, typed inputs and outputs, progress measurements, provenance entries). Reusable task definitions, plans, work orders, projects, parties and produced documents are separate models referenced by typed edges. Storage and interface (JSON, YAML, Markdown, Git, MCP, MongoDB) are projections of these semantics, not part of them.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-eco-006",
          "modelId": "WM-ECO-006",
          "aliases": [
            "O5"
          ],
          "slug": "wm-eco-006-commercial-contract",
          "name": "Commercial Contract",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-eco-006-commercial-contract/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-eco-006-commercial-contract/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-eco-006-commercial-contract/",
          "digest": "sha256:bddb6456cb3f00e13aa94d02efd23d49c819eefec50154f52abfb94676b6ee56",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ECO.CTR"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "commercial",
            "contract",
            "soc.eco.ctr"
          ],
          "purpose": "Agreements between parties",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification hold: none of the 16 base URLs or the 5 grok-only URLs were re-fetched in this adjudication. Every accepted source must be resolved live and version-pinned before publication, with particular attention to the two different LegalRuleML OS URLs, Akoma Ntoso naming-convention v1.0 versus core v1.0 Part 1, UBL 2.4 Committee Specification status, Incoterms 2020, and eIDAS 'as amended by the European Digital Identity framework'.",
            "Multi-profile validation hold: the merged structure must be exercised against at least three domain profiles before publication - an international CISG sale of goods, a domestic US goods sale where UCC Article 2 and the section 2-201 writing rule apply, and a services or framework-plus-call-off agreement where no goods and no executed single instrument exist.",
            "Writing-rule hold: CISG Article 11 (no writing required), CISG Articles 12 and 96 reservations, and UCC section 2-201 must be carried as co-recorded competing rules with the reservation state per party place of business. Do not publish a single resolved writing rule.",
            "Regional-labelling hold: eIDAS signature assurance levels and the Data Act unfair-term and smart-contract essential-requirement material are EU-regional and must be published as regional alignments, not universal rules, alongside the technology-neutral UNCITRAL reliability test.",
            "No-conformance hold: alignments to UBL, LegalRuleML, Akoma Ntoso, PROV-O and RFC 3339 are declared alignments only. Publication must state the claim level and must not assert tested conformance for any instance without test evidence."
          ],
          "boundary": "Covers the agreement record itself: its identity and classification, the party positions and their authority, how it was concluded and executed, the structure and terms of the agreed text, the obligations and schedule it creates, the record of performance, non-performance, remedy, change, notice and termination, and the governance of that record (provenance, integrity, access, retention, interoperability). Scope is business-to-business commercial contracting, following the HCCH Principles' scope of parties acting in the exercise of their trade or profession. External legal norms, the real-world identity of the parties, procurement award processes and dispute proceedings are referenced, not duplicated.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-001",
          "modelId": "WM-ORG-001",
          "aliases": [
            "O1"
          ],
          "slug": "wm-org-001-organization",
          "name": "Organization",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-001-organization/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-001-organization/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-001-organization/",
          "digest": "sha256:ce27fcf5453fb390d7aea631ab91748404ca25968a8b3af67311bf4c65a76cf1",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.ORG"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "organization",
            "soc.org.org"
          ],
          "purpose": "Any organization: company, NGO, community, institution",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [
            {
              "type": "contains",
              "target": "WM-ORG-002"
            },
            {
              "type": "contains",
              "target": "WM-ORG-003"
            }
          ],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source and live-version verification is incomplete and must be run before publication: every accepted source URL must be re-fetched and its version pin confirmed. The two providers cite different GLEIF URL paths for the same two documents (LEI-CDF 3.1 under /common-data-file-format/current-versions/ versus /common-data-file-format/, and the ELF list under /code-lists/ versus the bare path), so at least one variant in each pair is stale or a redirect and the canonical form must be established.",
            "Multi-profile domain validation has not been performed. The structure must be exercised against at least six distinct profiles before publication: a registered company with an LEI, an unregistered informal collective with no scheme identifier, an international branch holding its own LEI without separate legal personality, a fund with an umbrella and management relationship, a resident government entity formed by statute, and a sole proprietor whose legal person is a natural person. Coverage claims are provisional until each profile is walked end to end.",
            "The EUID and BRIS provisions carried by Commission Implementing Regulation (EU) 2021/1042 were surfaced from indexed EUR-Lex text rather than a full-text read, by the base provider's own admission. The EUID-specific data element must be treated as provisional and verified against the Official Journal before any normative reliance.",
            "FATF Recommendations 24 and 25 were unreachable (HTTP 403), so the beneficial-ownership structure rests on BODS at authority tier 2 rather than on the intergovernmental requirement it implements. The ownership layer must be re-grounded before it is published as an authority-backed structure.",
            "The base naming finding asks which single name form is the legal name, which is wrong for multilingual jurisdictions where RegOrg and SEMIC CBV make legalName a repeatable language-tagged literal with several co-equal legal names. The naming layer must be reframed to admit multiple co-equal legal names, with the RegOrg prohibition on storing translations in alternative-name fields, before that layer is published as normative.",
            "ISO 17442-1:2020 and ISO 20275 were cited from standards-catalogue landing pages, not normative text. Any statement in the synthesized model that reads as a conformance or eligibility rule derived from those standards must be marked alignment-only until the normative text is obtained.",
            "ISO 5009 is carried by the base as a tier-1 primary source for official organizational roles while the other provider records it as discovered but not fetched. The official-roles finding's specific claims (role counts, jurisdiction coverage, tie to ELF, exclusion of internal functional titles) must be confirmed against the fetched code list before publication."
          ],
          "boundary": "WM-ORG-001 models the organization as an externally addressable actor: its designations, scheme-qualified identifiers, legal form and activity classification, declared purpose and scale, formation and registry standing, lifecycle and succession, external control/ownership and official representation, physical and electronic presence, and the provenance, quality, access and interoperability governance of the organization record itself. Internal composition (units, teams), person-level records, employment relations and constitutive rule detail are delegated to sibling models. Storage in JSON, YAML, Markdown, Git, MongoDB or exposure over MCP or HTTP are projections of this semantics, never part of it.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-002",
          "modelId": "WM-ORG-002",
          "aliases": [
            "O2"
          ],
          "slug": "wm-org-002-organizational-unit",
          "name": "Organizational Unit",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-002-organizational-unit/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-002-organizational-unit/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-002-organizational-unit/",
          "digest": "sha256:9e3e80da4db6db6589991102b91af4af1a00080cd348848250b63f70a97b2330",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.UNT"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "organizational",
            "unit",
            "soc.org.unt"
          ],
          "purpose": "Internal structure of organizations",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [
            {
              "type": "contains",
              "target": "WM-ORG-004"
            }
          ],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source and live-version verification is outstanding for all sixteen base sources and for the two imported W3C ORG and CPOV anchors. Resolve the dated W3C ORG REC URI against the latest-version URI, confirm CPOV 2.1.2, schema.org v30.0 and the Peppol ICD list are still current, and pin FHIR deliberately, since the base cites R5 and the secondary provider cites R4.",
            "ISO-derived structure is guidance-grade, not requirement-grade. ISO 37000:2021, ISO 30414:2018, ISO 15489-1:2016 and ISO/IEC 6523-1:2023 are paywalled and were reviewed only through committee decks, catalogue metadata and deployment profiles, so the delegated-authority, assurance and segregation findings must not be published as normatively sourced until clause text is verified.",
            "ESRS S1-6 clause text was not machine-parsed; headcount, FTE, breakdown and the fifty-employee country threshold are stated at summary level and must be checked against Annex I of Commission Delegated Regulation (EU) 2023/2772 before any compliance-adjacent claim.",
            "Unit-grain staffing measurement has no primary standard. Established-versus-filled counts, budgeted FTE and establishment complement are local controls; publish the measurement layer and record-staffing-snapshot as extension-grade with that limitation visible.",
            "Multi-profile validation is incomplete. The model was tested chiefly against public-sector (CPOV/COFOG), healthcare (FHIR), EU reporting (IFRS 8, ESRS S1), directory (LDAP/SCIM) and e-invoicing (ISO/IEC 6523) profiles. Private-sector matrix organizations, military, academic-collegiate, ecclesiastical and cooperative unit forms are not validated and must not be presented as covered.",
            "Council Regulation (EEC) No 696/93 was not retrieved from EUR-Lex; the statistical-unit boundary currently rests on a Eurostat glossary entry that cites it, and must be confirmed against the regulation text.",
            "Regional scope must be stated on the face of any draft: CPOV, ESRS and the statistical-unit framework are EU instruments, NARA General Records Schedules bind US federal agencies only, financial alignment assumes IFRS rather than ASC 280, and employee consultation duties before a reorganization are jurisdiction-conditioned."
          ],
          "boundary": "This model covers an organizational unit as a subdivision that, in the words of the W3C Organization Ontology, 'only has full recognition within the context of that Organization'. It governs unit identity, classification, containment and reporting relationships, delegated mandate and decision rights, authorized establishment and measured staffing, structural change acts and their temporal validity, plus the provenance, retention, disclosure and interoperability rules that make the structure record operable. It deliberately stops at the boundaries of legal organizational identity, of the post/position as an object in its own right, of employment relationships, of physical sites, and of statistical or financial reporting units that are derived from - but not identical to - internal structure.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-003",
          "modelId": "WM-ORG-003",
          "aliases": [],
          "slug": "wm-org-003-team",
          "name": "Team",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-003-team/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-003-team/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-003-team/",
          "digest": "sha256:a42a3ebaeea14fe7b6195a56d57fb34c0b4d6027df4c0ffa7aebf75a79052b0f",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.TEM"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "team",
            "soc.org.tem"
          ],
          "purpose": "Candidate governed context model for Team; boundary questions remain required.",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source and live-version verification is unresolved: all twenty-nine distinct URLs across both packs must be re-fetched and re-pinned before publication, with particular attention to fast-moving or forward-dated version strings including schema.org 30.0 dated 2026-03-19, ESCO v1.2.1 dated 2025-12-10, HR Open 4.5 Final and 4.6 Candidate, the GitHub REST API version 2026-03-10, the Microsoft Graph v1.0 page last updated 2024-10-18, the FEMA RTLT tool version, and the NIST SP 800-53 control release 5.2.0.",
            "Multi-profile domain validation is unresolved: the merged model has not been instantiated against the clinical care-team profile, the workplace-directory profile, the emergency-response typed-resource profile, or the agile-delivery profile. No conformance or alignment language may be published until at least these four profiles have been round-tripped and their loss reports recorded.",
            "Paywalled and landing-page-only evidence must not be published at clause level: ISO 30414:2025 is cited from a committee announcement, ISO 30400:2022 from a catalogue landing page that does not expose a Team term, and ISO 21502 and ArchiMate business collaboration were never obtained. Every claim resting on these must be marked as unverified at clause level or removed.",
            "All seven accepted additions and four of the five accepted functions rest wholly or partly on tier-2 vendor documentation. Each must be re-checked against tier-1 sources for contradiction before publication, and vendor-specific vocabularies for visibility, nesting and archive states must be published as projection detail rather than as base semantics.",
            "Citation provenance for the accepted additions must be repaired: grok asserts RFC 3339 timestamp requirements in membership and post-assignment findings without registering RFC 3339 as a source in its own pack, so every merged node inheriting that claim must be re-pointed at the base RFC 3339 source and re-validated."
          ],
          "boundary": "A Team is a named, bounded collective of two or more actors constituted to perform work together under a shared mandate, whose membership is expressed as time-bounded assignment facts. The model is an aggregate: the team node is the root and the membership-assignment records are governed inside it, following the n-ary reification pattern of org:Membership and FHIR CareTeam.participant. Scope covers identity, classification and capability typing, charter and authority, membership and capability composition, lifecycle and structural change, operating interfaces and footprint, measurement binding, and the governance of team records. Storage and interface (JSON, YAML, Markdown, Git, MCP, MongoDB) are projections and carry no semantics here.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-004",
          "modelId": "WM-ORG-004",
          "aliases": [
            "O2",
            "O3"
          ],
          "slug": "wm-org-004-position",
          "name": "Position",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-004-position/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-004-position/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-004-position/",
          "digest": "sha256:084bbd188562897813d79bca48bc75b1612d03dae3a8f55b7ade9ed9c13c2b23",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.POS"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "position",
            "soc.org.pos"
          ],
          "purpose": "Candidate governed context model for Position; boundary questions remain required.",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification is incomplete: every base URL and version pin must be re-resolved at publication time. In particular the base cites 5 CFR and 29 CFR from the Cornell LII reproduction because eCFR and opm.gov were unreachable in its run, while grok reached eCFR current as of 2026-08-20 and the OPM classification standards PDF; re-verify and dual-cite or swap to the official host before publishing.",
            "Source identifiers collide across providers with different underlying documents (SRC-002 is HR Open in the base and Popolo in grok, among others). All sources must be re-keyed during merge and every accepted addition re-pointed, and the merged source list re-verified as live, before any draft is published.",
            "ISO 30400:2022 must not be cited as defining position, job, role or FTE: grok's own note concedes the term text was not inspectable behind the paywall, so only the standard's existence, date and scope are supportable. The ISCO-08 citation must likewise resolve to an authoritative ILO or UNSD host rather than the third-party netlify mirror used by grok.",
            "Retention and disposition periods remain a declared gap. No fetched primary source in either pack states a retention period for position records, descriptions or classification decisions; the structure may be published only as a required local determination, never as canonical guidance.",
            "Multi-profile domain validation is outstanding. Evidence concentrates on US federal General Schedule classification, UK FCA prescribed responsibilities, EU pay transparency and a single HCM vendor API. Before publication the model must be exercised against at least a civic or legislative profile (Popolo post with constituency), a healthcare profile (FHIR PractitionerRole unnamed slot) and a non-US private-sector profile, and every regional assumption must be labelled a jurisdiction profile rather than a universal requirement.",
            "Published boundary notes must carry grok's disambiguations verbatim in substance: HL7 FHIR PractitionerRole is aligned, not equated, to a classified position, and the financial, geospatial and sports senses of the word position are excluded, including schema.org's Quarterback example of a named position."
          ],
          "boundary": "In scope is everything that is true of a position while it is vacant. A position is the bundle of duties and responsibilities assigned by competent authority (5 CFR 511.101) and modelled as org:Post, which W3C defines as a position existing independently of the person or persons filling it. The model owns identity, titling, duty content, occupational and grade classification, structural placement and reporting, location and work arrangement, capacity (FTE/headcount) and funding, requirements and essential functions, delegated and prescribed authority, risk/screening designations, working conditions, lifecycle and effective-dated change, governance and evidence, and outbound interoperability. It does not own the person, the occupancy relationship, the employment contract, the recruiting workflow, or the taxonomies it aligns to.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-005",
          "modelId": "WM-ORG-005",
          "aliases": [
            "O3"
          ],
          "slug": "wm-org-005-employment",
          "name": "Employment",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-005-employment/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-005-employment/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-005-employment/",
          "digest": "sha256:23532924793e7eae105a9d102050c9cecfa079263e615a1bc55413953bca5aa2",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.EMP"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "employment",
            "soc.org.emp"
          ],
          "purpose": "Relations between persons and organizations",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.",
            "The previous O3 card combined Employment and Membership, while the current registry requires separate WM-ORG-005 and WM-ORG-006 boundaries; this publication replaces that combined boundary only for WM-ORG-005.",
            "The relation ledger marks WM-ORG-005 COMPOSE WM-ORG-016 as candidate rather than approved, and other neighboring model relations are not approved, so all proposed composition remains draft.",
            "National labour-law, public-service, military, seafarer, domestic-work, child-work, platform-work, apprenticeship and collective-bargaining profiles require specialist review.",
            "Certified HR-schema, ICSE-18, ISCO-08, ESCO, W3C ORG and jurisdictional crosswalks, conformance fixtures and rights-impact suites remain unverified.",
            "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft."
          ],
          "boundary": "Owns employment relationship identity, party-role topology, asserted basis and jurisdiction, purpose-qualified classification assertions and determinations, effective term bindings, assignment realization links, relationship state, continuity and separation events, party assertions, evidence quality, privacy and interoperability projections while external systems own parties, positions, assignments, occupations, contracts, payroll, attendance, benefits, tax, social insurance, qualifications, recruitment, access grants and evidence objects.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-006",
          "modelId": "WM-ORG-006",
          "aliases": [
            "O3"
          ],
          "slug": "wm-org-006-membership",
          "name": "Membership",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-006-membership/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-006-membership/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-006-membership/",
          "digest": "sha256:0fd3aeef90ff0dd9a728256ef4f9d6ef57edc4c27b411dde09f377274e210482",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.MEM"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "membership",
            "soc.org.mem"
          ],
          "purpose": "Relations between persons and organizations",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.",
            "The previous O3 card combined Employment and Membership, while the current registry requires separate WM-ORG-005 and WM-ORG-006 boundaries; this publication defines only Membership.",
            "The approved relationship ledger contains no WM-ORG-006 rows, so all proposed sibling composition remains draft.",
            "Company, cooperative, association, union, professional-body, standards-body, club, community, family, religious, political and machine-agent membership profiles require specialist review.",
            "Certified W3C ORG, OWL-Time, ODRL, Verifiable Credentials, LegalRuleML, SKOS, directory and domain-schema crosswalks, conformance fixtures and privacy tests remain unverified.",
            "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft."
          ],
          "boundary": "Owns membership relationship identity, member and organization bindings, governing scheme and type, admission basis and decision effect, role bindings, validity and standing, term references, renewal, suspension, reinstatement and ending events, party assertions, proof projections, privacy and interoperability while external systems own agents, organizations, roles, posts, activities, policies, payments, subscriptions, credentials, access grants, decisions and evidence objects.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-016",
          "modelId": "WM-ORG-016",
          "aliases": [],
          "slug": "wm-org-016-work-assignment",
          "name": "Work Assignment",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-016-work-assignment/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-016-work-assignment/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-016-work-assignment/",
          "digest": "sha256:6994563bdd79ed8edc878f66048a6ab0ae4fde376ba207f34ad5d2a159c994a3",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.ASN"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "work",
            "assignment",
            "soc.org.asn"
          ],
          "purpose": "Person/agent assigned to role, scope and time",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [
            {
              "type": "parent",
              "target": "WM-ORG-005"
            }
          ],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source and live-version verification is not discharged. Every accepted source must be refetched and pinned before publication, with particular attention to the two divergent FHIR PractitionerRole citations across providers (hl7.org/fhir/R5/practitionerrole.html described as R5 Maturity 4 Trial Use versus www.hl7.org/fhir/practitionerrole.html described as R5 5.0.0 generated 26 March 2023), and to the moving pins on ESCO v1.2.1, schema.org v30.0, the eCFR currency date and the revised-text-in-force date for the UK written-particulars section.",
            "Multi-profile domain validation is not discharged. The merged structure has been exercised against healthcare (FHIR PractitionerRole), US federal public service (5 CFR 335), contingent staffing (HR-XML 3.3) and incident management (ICS forms), but must additionally be validated against at least one non-US, non-EU appointing regime and one volunteer or platform-work profile before publication, because the accepted personnel-action and temporary-form nodes are otherwise parochial.",
            "Retention remains a declared gap and must publish as a policy hook with a mandatory declared basis, never as a substantive period. Grok's retention evidence rests on a non-primary mirror of the GDPR employment-context article and on tier-2 regulator guidance; neither establishes a general retention period for assignment records, and the base's own attempts to retrieve primary retention instruments returned HTTP 403.",
            "Workforce measurement remains a declared gap. Effort fraction, full-time-equivalent semantics, headcount boundary conventions and coverage metrics are structured but normatively ungrounded in both providers; they must publish as required declarations by the adopting Dimension, not as canonical definitions.",
            "All nodes derived from a single national personnel code or a single national statute (the accepted personnel-action and time-limited-form findings, and the written-particulars duties in the base) must carry an explicit jurisdiction scope label before publication, and the 'acting' terminology must not be attributed to any cited regulation.",
            "The non-human-agent occupancy branch must publish with an explicit note that no retrieved HR or personnel standard supports a software or robotic agent occupying a work assignment, and that the cited AI Act obligation governs assignment of human oversight rather than authorizing non-human occupancy."
          ],
          "boundary": "A Work Assignment is a reified n-ary relationship between an assignee agent, an organization or unit, a role or post, a bounded work scope and a validity period. The model covers how such a binding is identified, classified, authorized, constrained, changed, evidenced and ended. It deliberately holds no definition of the position itself, no contract terms, no person master data and no task-instance execution state; those belong to sibling models and are referenced. The model is format-neutral: JSON, YAML, Markdown, Git, MCP and MongoDB are projections of this semantics, never its source.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-per-001",
          "modelId": "WM-PER-001",
          "aliases": [
            "H1"
          ],
          "slug": "wm-per-001-person",
          "name": "Person",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-per-001-person/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-per-001-person/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-per-001-person/",
          "digest": "sha256:7a4a71ddd69fdc31b37806958442d1cfca4ec0bf861e54578adb312e0d7a4df3",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.PER.NAT"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "person",
            "soc.per.nat"
          ],
          "purpose": "Natural person as a civil identity and life-course subject",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Reconcile and re-pin the Core Person Vocabulary version before publication: base cites CPV 2.00 (2022-04-01), grok cites CPV 2.1.2 (2026-05-12). Properties grok relies on (Contact Point on Person, residency as Jurisdiction, the gender/sex split, GenericDate) must be confirmed against the live release actually pinned.",
            "Reconcile the ISO/IEC 24760-1 edition: base cites the 2025 edition, grok cites 2019. Both retrievals were catalogue-level only, so no definition, identifier taxonomy or identity-record state vocabulary may be published as canonical from this standard.",
            "Re-verify GDPR Article 9 special-category wording against the EUR-Lex OJ text; the base verified it from an unofficial reproduction (tier 3) after repeated EUR-Lex retrieval failure.",
            "Re-verify CRPD Article 12 and General Comment No. 1 wording against an official UN-hosted text; one provider recorded an HTTP 403 at OHCHR and quoted secondary sources.",
            "Verify every accepted source URL as live and version-pinned, including the two OASIS CIQ v3.0 URL variants, both ICAO Doc 9303 landing pages, and the UN Principles and Recommendations Rev.3 PDF whose body could not be text-extracted (paragraph-level citations are currently absent).",
            "Run domain-profile validation on at least one non-EU profile before publication: the model is EU/UN-weighted (GDPR, eIDAS/EUDI PID, CPV, NIST levels), and a common-law vital-records plus ID-card regime and a Nordic population-register architecture must be mapped into the frame rather than assumed equivalent.",
            "Correct the base coverage-claim counts: it states 7 bundles, 15 layers and 28 findings, but the base structure contains 14 layers; after the accepted addition the merged model is 7 bundles, 14 layers, 29 findings and 14 functions.",
            "Scope the imported alternative-registration-routes finding on publication: only the UN LIA and CRVS-IdM backed portion (host-State or internationally mandated issuance, conferral by an identification authority linked to civil registration, delayed registration) may be presented as sourced; foundling, unknown-parentage and presumed-death-restoration sub-cases must be marked as unsourced operating cases, and the overlap with q-stateless-substitute must be resolved."
          ],
          "boundary": "Format-neutral context structure for the natural person as a legally registered identity and data subject. Covers what an agent must know to establish, resolve, evidence, update, disclose, close and audit a person identity. Excludes the human as a biological organism, and excludes any concept that resolves in a composable sibling model (household, organization, address, vital-event record, qualification, authenticator).",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-rec-001",
          "modelId": "WM-REC-001",
          "aliases": [
            "N1"
          ],
          "slug": "wm-rec-001-document-record",
          "name": "Document / Record",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-rec-001-document-record/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-rec-001-document-record/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-rec-001-document-record/",
          "digest": "sha256:0365b603bf30e7c487a6e353a44d02563dd27e918885b9e96f9bb6861be29002",
          "family": "World Models",
          "category": "Information and virtual systems",
          "domain": [
            "INF.REC.DOC"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "document",
            "record",
            "inf.rec.doc"
          ],
          "purpose": "Documents as governed records",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification incomplete: re-verify every accepted source URL live and pin its version before publication. Claude's ISO 15489-1 source returned HTTP 403 and its ISO-attributed claims were read from catalogue abstracts and indexed extracts; re-verify them against Grok's JIS X 0902-1:2019 identical adoption or licensed ISO text before any ISO-derived statement is published.",
            "eIDAS evidence is second-hand on both sides: Claude used the legislation.gov.uk rendition of Article 3 and flags that Regulation (EU) 2024/1183 amendments are not reflected; Grok used a European Commission FAQ guidance page. Re-pin signature, seal and qualified-timestamp tiers to consolidated EU text before publishing the assurance-tier vocabulary.",
            "Instrument version drift must be reconciled to one pinned version each: RiC-O 1.1 (2025, Claude) versus RiC-CM 1.0 (2023, Grok), and C2PA 2.1 (Claude) versus C2PA 2.4 (Grok). Publish only after the record/instantiation split and the hard-binding rule are re-checked against the chosen versions.",
            "Multi-profile domain validation not yet complete: the merged model has been reasoned mainly against archival and government recordkeeping profiles. Validate against at least three materially different profiles — an EU qualified-signature commercial instrument, a US federal case file under 36 CFR, and a media or generated-content asset carrying content credentials — before publication.",
            "Confirm the WM-REC-015 boundary once that model exists, so aggregation-membership references and the record-set exclusion resolve to real structure rather than a placeholder neighbour.",
            "Strip any residual conformance-claim wording inherited from either provider; the published draft must state alignment and mapping only, with lossiness recorded."
          ],
          "boundary": "Covers the record as an aggregate root over its versions, instantiations, signatures, provenance, events, retention assignments, holds and access decisions, from creation or capture through disposition. Excludes the semantics of what the record is about, the agents named in it, the aggregations that hold it, and any particular storage or interface technology.",
          "verifiedAt": "2026-09-21"
        }
      ],
      "remainingCoverage": "Company boundaries, domain-specific profiles, storage bindings, local authority and private instance facts must be established in the owning Dimension. Startup needs neither payroll nor a legal entity by default."
    },
    {
      "id": "software-team",
      "name": "Команда программного продукта",
      "selectedModelIds": [
        "WM-ORG-001",
        "WM-PER-001",
        "WM-ORG-003",
        "WM-ACT-005",
        "WM-ACT-006",
        "WM-SFT-001",
        "WM-REC-001"
      ],
      "requiredClosure": [
        {
          "id": "vr.wm-act-005",
          "modelId": "WM-ACT-005",
          "aliases": [
            "K5"
          ],
          "slug": "wm-act-005-project",
          "name": "Project",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-act-005-project/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-act-005-project/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-act-005-project/",
          "digest": "sha256:c0d49f2ff60d60b45c7aec999716f1a6ee106dc2e8221659c1af61a7c4747807",
          "family": "World Models",
          "category": "Activities and processes",
          "domain": [
            "ACT.PRJ"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "project",
            "act.prj"
          ],
          "purpose": "Bounded undertakings with goals and resources",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [
            {
              "type": "contains",
              "target": "WM-ACT-006"
            },
            {
              "type": "contains",
              "target": "WM-ACT-031"
            }
          ],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification: none of the roughly thirty distinct URLs across the two providers has been re-resolved by this adjudication. Every accepted source must be fetched live and version-pinned before publication, with particular attention to the two NASA NPR 7120.5F entry points (directive page versus Chapter 2 deep link), GovS 002 v2.1, the PeopleCert PRINCE2 v7 page, schema.org v30.0, IATI 2.03 codelists, DataCite 4.6 and the NARA GRS page.",
            "Paywalled ISO texts: ISO 21500, 21502, 21503, 21504, 21505, 21508 and 21511 were read only as catalogue abstracts, committee pages, ISO news and one tier-4 secondary clause summary. Clause-level fidelity is asserted at abstract level only and the draft must say so; no clause number may be cited as if the purchased text had been read.",
            "Vocabulary currency: ISO/TR 21506:2018 is withdrawn and replaced by ISO 21506:2024, which neither provider retrieved; ISO 21511 is under revision as ISO/DIS 21511 and ISO 21513:2026 on post-project evaluation was not fetched. No term definition may be published as standard-derived until the current editions are checked.",
            "Multi-profile domain validation: the model has not been exercised against more than one delivery regime. Before publication it must be validated against at least a public-sector regime (NASA or GovS 002), an aid-transparency regime (IATI 2.03), a research regime (RAiD/ISO 23527) and an adaptive or agile delivery profile that maintains no control accounts.",
            "Declared gaps must ship as gaps: no data-protection instrument was retrieved live (the EUR-Lex fetch returned no body) and no information-security control standard was retrieved by either provider. Privacy and security coverage must be published as gaps with the jurisdictional instrument left to the adopting Dimension, not asserted.",
            "Accepted grok content needs first-party re-verification: grok's PMI fetch was blocked and taken via search, and the GovS 002 full PDF and Teal Book were not retrieved. Both accepted findings (f-tailoring-and-compliance, f-transition-disposal-and-residual-obligations) lean on SRC-006 and SRC-007, so their supporting text must be confirmed from the primary documents.",
            "Retention is anchored on NARA General Records Schedules as a US federal working example; the applicable disposition authority is jurisdictional and the adopting Dimension must substitute it before the retention finding is treated as operative."
          ],
          "boundary": "A Project is a temporary, uniquely-scoped endeavour authorized by a sponsor to deliver defined outputs, outcomes or benefits within agreed constraints (ISO 21500:2021 concepts; ISO 21502:2020 practices; APM 'unique, transient endeavour'). This model owns the project as an aggregate root: identification and registration, authorization and governance, objectives and scope boundary, work breakdown, resource/funding/procurement commitments, lifecycle states and gates, approved baselines and change control, progress measurement, risk/issue/assurance, stakeholders, record provenance and access, and closure with retention. It holds typed edges to contained tasks and milestones/deliverables rather than restating their internals. It is storage- and interface-neutral: JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections of the same semantics.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-act-006",
          "modelId": "WM-ACT-006",
          "aliases": [],
          "slug": "wm-act-006-task",
          "name": "Task",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-act-006-task/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-act-006-task/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-act-006-task/",
          "digest": "sha256:fdbf2bfc5aface45234c4be3fb1cbcc0488bdcc5395e8d8896aa16305a9b8a01",
          "family": "World Models",
          "category": "Activities and processes",
          "domain": [
            "ACT.TSK"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "task",
            "act.tsk"
          ],
          "purpose": "Candidate governed context model for Task; boundary questions remain required.",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification hold: every URL and version pin in the merged register must be re-checked live before publication. Specific items: the two FHIR Task URLs differ between providers (hl7.org/fhir/R5/task.html versus hl7.org/fhir/task.html) and must be reconciled to one version-pinned R5 address; the A2A specification is cited as 'latest released' and must be pinned to an immutable version; the OMG BPMN and CMMN pages were only reachable at specification-metadata depth; and the base records an HTTP 403 on the project-management standards catalogue.",
            "Citation-provenance hold: all iCalendar claims arriving with the accepted Grok findings are anchored to icalendar.org reproductions labelled tier 1 by that provider. Re-anchor each to RFC 5545 at the IETF before publication, and keep the reproduction marked non-primary tier 3 as the base does.",
            "Multi-profile validation hold: the merged model must be exercised against at least four domain profiles before any cross-domain adequacy claim: clinical workflow (FHIR Task), personal and calendaring to-do (VTODO and Microsoft Graph todoTask), organisational human workflow (WS-HumanTask and BPMN), and agent-to-agent execution (A2A). Only the first three are represented in both packs; the agentic profile rests on a single provider.",
            "Retention hold: publish no statutory retention period, lawful basis or erasure right. No legislative or regulatory text was retrieved by either provider, and the retention dimension must ship as a declared gap pointing at a Dimension-supplied schedule.",
            "Conformance-claim hold: the merged model is an alignment union. Block any wording that asserts conformance to FHIR, iCalendar, WS-HumanTask, schema.org or PROV-O; round-trip fidelity per crosswalk has not been tested, and the base already records lossy one-directional mappings for OSLC boolean predicates and for state-vocabulary granularity.",
            "Source-remapping hold: do not emit a draft until Grok-local SRC ids on the two accepted findings are remapped into the merged register and the three newly carried sources (Microsoft Graph todoTask, schema.org Action, FHIR Task detailed descriptions) are added with their own tier and primary flags."
          ],
          "boundary": "The model governs the task instance as a consistency boundary: the task record plus the parts that have no independent identity outside it (status history, role assignments, deadlines, typed inputs and outputs, progress measurements, provenance entries). Reusable task definitions, plans, work orders, projects, parties and produced documents are separate models referenced by typed edges. Storage and interface (JSON, YAML, Markdown, Git, MCP, MongoDB) are projections of these semantics, not part of them.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-001",
          "modelId": "WM-ORG-001",
          "aliases": [
            "O1"
          ],
          "slug": "wm-org-001-organization",
          "name": "Organization",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-001-organization/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-001-organization/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-001-organization/",
          "digest": "sha256:ce27fcf5453fb390d7aea631ab91748404ca25968a8b3af67311bf4c65a76cf1",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.ORG"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "organization",
            "soc.org.org"
          ],
          "purpose": "Any organization: company, NGO, community, institution",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [
            {
              "type": "contains",
              "target": "WM-ORG-002"
            },
            {
              "type": "contains",
              "target": "WM-ORG-003"
            }
          ],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source and live-version verification is incomplete and must be run before publication: every accepted source URL must be re-fetched and its version pin confirmed. The two providers cite different GLEIF URL paths for the same two documents (LEI-CDF 3.1 under /common-data-file-format/current-versions/ versus /common-data-file-format/, and the ELF list under /code-lists/ versus the bare path), so at least one variant in each pair is stale or a redirect and the canonical form must be established.",
            "Multi-profile domain validation has not been performed. The structure must be exercised against at least six distinct profiles before publication: a registered company with an LEI, an unregistered informal collective with no scheme identifier, an international branch holding its own LEI without separate legal personality, a fund with an umbrella and management relationship, a resident government entity formed by statute, and a sole proprietor whose legal person is a natural person. Coverage claims are provisional until each profile is walked end to end.",
            "The EUID and BRIS provisions carried by Commission Implementing Regulation (EU) 2021/1042 were surfaced from indexed EUR-Lex text rather than a full-text read, by the base provider's own admission. The EUID-specific data element must be treated as provisional and verified against the Official Journal before any normative reliance.",
            "FATF Recommendations 24 and 25 were unreachable (HTTP 403), so the beneficial-ownership structure rests on BODS at authority tier 2 rather than on the intergovernmental requirement it implements. The ownership layer must be re-grounded before it is published as an authority-backed structure.",
            "The base naming finding asks which single name form is the legal name, which is wrong for multilingual jurisdictions where RegOrg and SEMIC CBV make legalName a repeatable language-tagged literal with several co-equal legal names. The naming layer must be reframed to admit multiple co-equal legal names, with the RegOrg prohibition on storing translations in alternative-name fields, before that layer is published as normative.",
            "ISO 17442-1:2020 and ISO 20275 were cited from standards-catalogue landing pages, not normative text. Any statement in the synthesized model that reads as a conformance or eligibility rule derived from those standards must be marked alignment-only until the normative text is obtained.",
            "ISO 5009 is carried by the base as a tier-1 primary source for official organizational roles while the other provider records it as discovered but not fetched. The official-roles finding's specific claims (role counts, jurisdiction coverage, tie to ELF, exclusion of internal functional titles) must be confirmed against the fetched code list before publication."
          ],
          "boundary": "WM-ORG-001 models the organization as an externally addressable actor: its designations, scheme-qualified identifiers, legal form and activity classification, declared purpose and scale, formation and registry standing, lifecycle and succession, external control/ownership and official representation, physical and electronic presence, and the provenance, quality, access and interoperability governance of the organization record itself. Internal composition (units, teams), person-level records, employment relations and constitutive rule detail are delegated to sibling models. Storage in JSON, YAML, Markdown, Git, MongoDB or exposure over MCP or HTTP are projections of this semantics, never part of it.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-org-003",
          "modelId": "WM-ORG-003",
          "aliases": [],
          "slug": "wm-org-003-team",
          "name": "Team",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-org-003-team/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-org-003-team/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-org-003-team/",
          "digest": "sha256:a42a3ebaeea14fe7b6195a56d57fb34c0b4d6027df4c0ffa7aebf75a79052b0f",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.ORG.TEM"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "team",
            "soc.org.tem"
          ],
          "purpose": "Candidate governed context model for Team; boundary questions remain required.",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source and live-version verification is unresolved: all twenty-nine distinct URLs across both packs must be re-fetched and re-pinned before publication, with particular attention to fast-moving or forward-dated version strings including schema.org 30.0 dated 2026-03-19, ESCO v1.2.1 dated 2025-12-10, HR Open 4.5 Final and 4.6 Candidate, the GitHub REST API version 2026-03-10, the Microsoft Graph v1.0 page last updated 2024-10-18, the FEMA RTLT tool version, and the NIST SP 800-53 control release 5.2.0.",
            "Multi-profile domain validation is unresolved: the merged model has not been instantiated against the clinical care-team profile, the workplace-directory profile, the emergency-response typed-resource profile, or the agile-delivery profile. No conformance or alignment language may be published until at least these four profiles have been round-tripped and their loss reports recorded.",
            "Paywalled and landing-page-only evidence must not be published at clause level: ISO 30414:2025 is cited from a committee announcement, ISO 30400:2022 from a catalogue landing page that does not expose a Team term, and ISO 21502 and ArchiMate business collaboration were never obtained. Every claim resting on these must be marked as unverified at clause level or removed.",
            "All seven accepted additions and four of the five accepted functions rest wholly or partly on tier-2 vendor documentation. Each must be re-checked against tier-1 sources for contradiction before publication, and vendor-specific vocabularies for visibility, nesting and archive states must be published as projection detail rather than as base semantics.",
            "Citation provenance for the accepted additions must be repaired: grok asserts RFC 3339 timestamp requirements in membership and post-assignment findings without registering RFC 3339 as a source in its own pack, so every merged node inheriting that claim must be re-pointed at the base RFC 3339 source and re-validated."
          ],
          "boundary": "A Team is a named, bounded collective of two or more actors constituted to perform work together under a shared mandate, whose membership is expressed as time-bounded assignment facts. The model is an aggregate: the team node is the root and the membership-assignment records are governed inside it, following the n-ary reification pattern of org:Membership and FHIR CareTeam.participant. Scope covers identity, classification and capability typing, charter and authority, membership and capability composition, lifecycle and structural change, operating interfaces and footprint, measurement binding, and the governance of team records. Storage and interface (JSON, YAML, Markdown, Git, MCP, MongoDB) are projections and carry no semantics here.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-per-001",
          "modelId": "WM-PER-001",
          "aliases": [
            "H1"
          ],
          "slug": "wm-per-001-person",
          "name": "Person",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-per-001-person/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-per-001-person/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-per-001-person/",
          "digest": "sha256:7a4a71ddd69fdc31b37806958442d1cfca4ec0bf861e54578adb312e0d7a4df3",
          "family": "World Models",
          "category": "Society, people and institutions",
          "domain": [
            "SOC.PER.NAT"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "person",
            "soc.per.nat"
          ],
          "purpose": "Natural person as a civil identity and life-course subject",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Reconcile and re-pin the Core Person Vocabulary version before publication: base cites CPV 2.00 (2022-04-01), grok cites CPV 2.1.2 (2026-05-12). Properties grok relies on (Contact Point on Person, residency as Jurisdiction, the gender/sex split, GenericDate) must be confirmed against the live release actually pinned.",
            "Reconcile the ISO/IEC 24760-1 edition: base cites the 2025 edition, grok cites 2019. Both retrievals were catalogue-level only, so no definition, identifier taxonomy or identity-record state vocabulary may be published as canonical from this standard.",
            "Re-verify GDPR Article 9 special-category wording against the EUR-Lex OJ text; the base verified it from an unofficial reproduction (tier 3) after repeated EUR-Lex retrieval failure.",
            "Re-verify CRPD Article 12 and General Comment No. 1 wording against an official UN-hosted text; one provider recorded an HTTP 403 at OHCHR and quoted secondary sources.",
            "Verify every accepted source URL as live and version-pinned, including the two OASIS CIQ v3.0 URL variants, both ICAO Doc 9303 landing pages, and the UN Principles and Recommendations Rev.3 PDF whose body could not be text-extracted (paragraph-level citations are currently absent).",
            "Run domain-profile validation on at least one non-EU profile before publication: the model is EU/UN-weighted (GDPR, eIDAS/EUDI PID, CPV, NIST levels), and a common-law vital-records plus ID-card regime and a Nordic population-register architecture must be mapped into the frame rather than assumed equivalent.",
            "Correct the base coverage-claim counts: it states 7 bundles, 15 layers and 28 findings, but the base structure contains 14 layers; after the accepted addition the merged model is 7 bundles, 14 layers, 29 findings and 14 functions.",
            "Scope the imported alternative-registration-routes finding on publication: only the UN LIA and CRVS-IdM backed portion (host-State or internationally mandated issuance, conferral by an identification authority linked to civil registration, delayed registration) may be presented as sourced; foundling, unknown-parentage and presumed-death-restoration sub-cases must be marked as unsourced operating cases, and the overlap with q-stateless-substitute must be resolved."
          ],
          "boundary": "Format-neutral context structure for the natural person as a legally registered identity and data subject. Covers what an agent must know to establish, resolve, evidence, update, disclose, close and audit a person identity. Excludes the human as a biological organism, and excludes any concept that resolves in a composable sibling model (household, organization, address, vital-event record, qualification, authenticator).",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-rec-001",
          "modelId": "WM-REC-001",
          "aliases": [
            "N1"
          ],
          "slug": "wm-rec-001-document-record",
          "name": "Document / Record",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-rec-001-document-record/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-rec-001-document-record/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-rec-001-document-record/",
          "digest": "sha256:0365b603bf30e7c487a6e353a44d02563dd27e918885b9e96f9bb6861be29002",
          "family": "World Models",
          "category": "Information and virtual systems",
          "domain": [
            "INF.REC.DOC"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "document",
            "record",
            "inf.rec.doc"
          ],
          "purpose": "Documents as governed records",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source verification incomplete: re-verify every accepted source URL live and pin its version before publication. Claude's ISO 15489-1 source returned HTTP 403 and its ISO-attributed claims were read from catalogue abstracts and indexed extracts; re-verify them against Grok's JIS X 0902-1:2019 identical adoption or licensed ISO text before any ISO-derived statement is published.",
            "eIDAS evidence is second-hand on both sides: Claude used the legislation.gov.uk rendition of Article 3 and flags that Regulation (EU) 2024/1183 amendments are not reflected; Grok used a European Commission FAQ guidance page. Re-pin signature, seal and qualified-timestamp tiers to consolidated EU text before publishing the assurance-tier vocabulary.",
            "Instrument version drift must be reconciled to one pinned version each: RiC-O 1.1 (2025, Claude) versus RiC-CM 1.0 (2023, Grok), and C2PA 2.1 (Claude) versus C2PA 2.4 (Grok). Publish only after the record/instantiation split and the hard-binding rule are re-checked against the chosen versions.",
            "Multi-profile domain validation not yet complete: the merged model has been reasoned mainly against archival and government recordkeeping profiles. Validate against at least three materially different profiles — an EU qualified-signature commercial instrument, a US federal case file under 36 CFR, and a media or generated-content asset carrying content credentials — before publication.",
            "Confirm the WM-REC-015 boundary once that model exists, so aggregation-membership references and the record-set exclusion resolve to real structure rather than a placeholder neighbour.",
            "Strip any residual conformance-claim wording inherited from either provider; the published draft must state alignment and mapping only, with lossiness recorded."
          ],
          "boundary": "Covers the record as an aggregate root over its versions, instantiations, signatures, provenance, events, retention assignments, holds and access decisions, from creation or capture through disposition. Excludes the semantics of what the record is about, the agents named in it, the aggregations that hold it, and any particular storage or interface technology.",
          "verifiedAt": "2026-09-21"
        },
        {
          "id": "vr.wm-sft-001",
          "modelId": "WM-SFT-001",
          "aliases": [
            "N4"
          ],
          "slug": "wm-sft-001-software-product",
          "name": "Software Product",
          "version": "0.3.0-research.1",
          "status": "published",
          "installable": true,
          "specUrl": "https://ver.cy/models/wm-sft-001-software-product/spec.yaml",
          "agentsUrl": "https://ver.cy/models/wm-sft-001-software-product/AGENTS.md",
          "pageUrl": "https://ver.cy/models/wm-sft-001-software-product/",
          "digest": "sha256:db17c148b0866c2d11683bced2dd6c30b59266f2eda3ee23708e16610982f356",
          "family": "World Models",
          "category": "Information and virtual systems",
          "domain": [
            "INF.SFT.PRD"
          ],
          "industry": [
            "Cross-industry"
          ],
          "tags": [
            "software",
            "product",
            "inf.sft.prd"
          ],
          "purpose": "Software described in full context",
          "requires": [],
          "unresolvedRequires": [],
          "relations": [],
          "assurance": "reviewable-draft",
          "publicationHolds": [
            "Source and live-version verification for every accepted source before publication: the providers disagree on SPDX 3.0.1 publisher attribution (Linux Foundation alone versus Linux Foundation with OMG), on the CycloneDX pin (1.6 with ECMA-424 June 2024 versus 1.7 with ECMA-424 December 2025), and on the ECMA-427 PURL edition; SLSA v1.1 is recorded as retired in favour of v1.2. Each URL must be re-fetched and each pin restated before any alignment claim is published.",
            "Field-level verification of the 2026 CISA minimum elements against the source PDF tables. The providers give divergent readings of the same document: the base speaks of declared depth and adds component hash and licence, while the source provider claims Depth is replaced by Coverage and Supplier Name by Component Producer, and itself admits the PDF body was not fully field-extracted. No element name from this document may be bound in the published draft until the tables are read directly.",
            "Multi-domain profile validation across at least five delivery profiles before the coverage claim stands: commercial on-premises application, open-source library in a package ecosystem, container image, firmware-as-software, and SaaS-only offering with no distributable artifact. The base states that release and integrity findings degrade for the SaaS case; that degradation must be exercised rather than asserted.",
            "Clause-level confirmation of ISO/IEC 19770-2:2015 and NISTIR 8060 for the accepted tag-type finding, since the source provider states the 19770-2 XML schema annexes were not retrieved in full and the tag information model was carried via RFC 9393 and paraphrase.",
            "Paywalled-standard limitation must be restated at publication: alignment to ISO/IEC/IEEE 12207:2026 and ISO/IEC 25010:2023 rests on catalogue-level scope statements, not clause-level reading, and no conformance to SPDX, CycloneDX, CSAF, ISO 19770-2 or 12207 is claimed."
          ],
          "boundary": "This model is the host aggregate for software regarded simultaneously as a published offering (product line, releases, distributable artifacts, licences) and as an operated system (deployed instances, environments, effective configuration, advisories). It is an aggregate rather than a plain entity because release, deployment and advisory records have independent lifecycles yet are only meaningful when anchored to one product identity. It is format-neutral: SPDX, CycloneDX, CSAF, JSON, Git, MongoDB and MCP are projections of these findings, not their semantics. Component-internal and package-ecosystem detail is delegated to WM-SFT-007 by COMPOSE and is not restated here.",
          "verifiedAt": "2026-09-21"
        }
      ],
      "remainingCoverage": "Company boundaries, domain-specific profiles, storage bindings, local authority and private instance facts must be established in the owning Dimension. Startup needs neither payroll nor a legal entity by default."
    }
  ]
}
