{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-ai-002","code":"wm-ai-002-ai-agent","url":"https://ver.cy/models/wm-ai-002-ai-agent/","name":"AI Agent","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"entity","plane":"","domain":["INF.AI.AGT"],"industry":["Cross-industry"],"navPath":"NAV.INF.AI.AGT","tags":["ai","agent","inf.ai.agt"],"facets":{}},"whatItIs":"The subject is the durable, versioned agent definition plus the deployment context that makes it operable: identity and classification, capability and protocol surface, delegated authority and credentials, memory and data handling, lifecycle and runtime limits, oversight, and assurance evidence. The model is projection-neutral: JSON, YAML, Markdown, Git, MCP endpoints, graph stores and MongoDB collections are storage or interface projections of the same semantics. External standards are recorded as alignments only; no conformance is asserted without cited evidence.","purpose":"Describe an AI agent as a governed, identifiable non-human actor that holds delegated authority, is bound to tools and memory, operates under policy and oversight, and can be inspected, released, constrained and retired by an accountable party.","scope":{"in":["Agent identity, designation, aliases and version identity of a released agent definition","Architectural archetype, autonomy level, regulatory role and risk classification","Constituent bindings: invoked models, referenced configuration artefacts, callable sub-agents","Declared capability surface: bound tools, accessible resources, declared skills, refusal scope","Protocol bindings, capability advertisement, revision negotiation, descriptor authenticity","Delegated authority: acting principal, delegation chain, credential scope, token audience binding","Action authorisation policy, deny boundaries, consent and human-approval gates","Memory store inventory, write authority, memory provenance and integrity controls","Data categories, purpose limitation, residency constraints, retention and deletion duties","Lifecycle states, release approval, rollback, suspension and decommission obligations","Runtime operating envelope: step, time, concurrency and cost limits and breach behaviour","Human oversight affordances, intervention records, incident handling","Pre-deployment evaluation, in-service monitoring, telemetry conformance, conformity evidence"],"out":["Model training, weights, fine-tuning data and model cards, which belong to the AI system or model sibling","Individual execution traces, spans, token counts and per-run outcomes, which belong to the agent run model","Instruction text, templating and variable schemas of prompts or agent configuration files","Natural-person records, employment and human competence records","Internal implementation of the tools, APIs and services an agent calls","Hosting, network and compute infrastructure topology","Embodied actuation, motion planning and physical safety of robots","Commercial contracting, billing and agent-to-agent payment settlement","Any claim of certification or regulatory compliance not backed by cited evidence"],"boundaries":[{"neighbor":"WM-AI-001 AI system","distinction":"The AI system is the product placed on the market and carries system-level obligations; the agent is one actor it exposes. Model inventory, system risk management and market placement stay in WM-AI-001; actor-level authority, tool bindings, memory and oversight stay here."},{"neighbor":"WM-AI-004 agent run","distinction":"A run is a bounded execution event with traces and outcomes; the agent is the durable actor that runs reference. Correlation identifiers and version references live here; spans, messages and token usage live in WM-AI-004."},{"neighbor":"WM-AI-005 prompt or agent configuration","distinction":"The configuration artefact carries instruction content and parameters; this model carries only the reference, the pinning mode and the approval status of that binding."},{"neighbor":"WM-PER-003 actor or person","distinction":"Human principals, approvers and overseers are references to the person or party model. This model records the delegation relation and accountable role, not the human's own attributes."},{"neighbor":"Tool, server or external service model","distinction":"A tool's own schema, endpoint contract and operator are a separate subject. This model records the binding, its effect class, trust status and approval, not the tool's internal definition."},{"neighbor":"Access-management and credential systems","distinction":"Issuance mechanics, key material and authorisation-server internals stay in the identity domain; this model records which scopes and audiences an agent may hold and under whose delegation."}]},"distinguishingFeatures":["Treats the agent as an identifiable non-human actor holding delegated authority, not as a model or a system.","Unlike an agent run, it is the persistent actor, not one execution.","Unlike a prompt configuration, it carries authority grants, tool bindings and lifecycle, not instruction text.","Distinct from a person record: it never stands in for a natural person's identity or competence."],"structure":{"bundles":[{"id":"agent-identity-and-constitution","name":"Agent identity and constitution","description":"What the agent is as a governed entity: authoritative identifier, designation, version identity, archetype and autonomy class, regulatory role, constituent bindings and definition provenance.","layers":[{"id":"identity-and-designation","name":"Identity and designation","description":"How the agent is uniquely designated, how public and protocol-scoped names relate to the primary key, and how a released version is identified over time.","findings":[{"id":"agent-identifier-and-designation","name":"Agent identifier and designation","description":"The primary identifier designating this agent, the published human-readable designation, and the alias set that resolves to the same agent across protocols and registries.","questions":[{"text":"Which authoritative master-system identifier designates this agent, and which system issues it?","id":"q-id-authoritative","kind":"identity"},{"text":"What human-readable name, description and purpose statement are published for the agent?","id":"q-id-designation","kind":"definition"},{"text":"Which alternate or protocol-scoped identifiers resolve to this same agent?","id":"q-id-alias-resolution","kind":"interoperability"},{"text":"How is a durable agent definition distinguished from a transient in-memory agent instance?","id":"q-id-instance-vs-definition","kind":"classification"}]},{"id":"agent-version-and-change-identity","name":"Agent version and change identity","description":"How a released agent definition is versioned, which fields are frozen so a version denotes one behaviour contract, when each version is effective and superseded, and its derivation lineage.","questions":[{"text":"What versioning scheme identifies a released agent definition, and which changes force a new version?","id":"q-ver-scheme","kind":"constraint"},{"text":"From which instant is each agent version effective, and when was it superseded?","id":"q-ver-effective","kind":"temporal"},{"text":"Which fields are frozen at release so that a version identifier always denotes the same behaviour contract?","id":"q-ver-frozen","kind":"validation"},{"text":"Which prior agent version was this version derived from?","id":"q-ver-lineage","kind":"provenance"}]}]},{"id":"classification-and-autonomy","name":"Classification and autonomy","description":"How the agent is typed by architecture and by the autonomy it may exercise, and how it is classified under applicable regulatory and risk frameworks.","findings":[{"id":"agent-typology-and-autonomy-level","name":"Agent typology and autonomy level","description":"The architectural archetype implemented and the autonomy the agent may exercise without a human decision point, including whether it may act on its own initiative.","questions":[{"text":"What level of autonomy is the agent authorised to exercise without a human decision point?","id":"q-aut-level","kind":"classification"},{"text":"Which architectural archetype does the agent implement: single actor, orchestrator, sub-agent or scripted workflow?","id":"q-aut-archetype","kind":"composition"},{"text":"Can the agent initiate activity without a human or upstream request, and under which trigger conditions?","id":"q-aut-initiative","kind":"event"},{"text":"How often is the assigned autonomy level re-justified against observed behaviour?","id":"q-aut-review","kind":"validation"}]},{"id":"regulatory-role-and-risk-classification","name":"Regulatory role and risk classification","description":"Which regulatory role the operator holds per jurisdiction, the risk tier and use-case category, the disclosure duties that follow, and the evidence supporting the classification.","questions":[{"text":"Is the operator of this agent a provider or a deployer in each jurisdiction where it operates?","id":"q-reg-actor-role","kind":"ownership"},{"text":"Which regulatory risk tier and use-case category does the agent fall into?","id":"q-reg-risk-tier","kind":"classification"},{"text":"Which disclosure duties apply when the agent interacts with natural persons or emits synthetic content?","id":"q-reg-disclosure","kind":"requirement"},{"text":"What evidence supports the assigned risk classification, and who signed it off?","id":"q-reg-evidence","kind":"evidence"}]}]},{"id":"constitution-and-provenance","name":"Constitution and provenance","description":"Which components the agent is assembled from, and who authored, derived and approved the definition.","findings":[{"id":"agent-constituent-bindings","name":"Agent constituent bindings","description":"The models invoked, the configuration artefacts governing instructions, the callable sub-agents, and whether each binding is pinned or floating.","questions":[{"text":"Which model or models does the agent invoke, and are those bindings pinned or floating?","id":"q-cmp-model-binding","kind":"composition"},{"text":"Which configuration artefact governs the agent's instructions, and at which version?","id":"q-cmp-config-binding","kind":"relationship"},{"text":"Which sub-agents or delegate agents may this agent instantiate or call?","id":"q-cmp-subagents","kind":"relationship"},{"text":"What happens to the agent's identity and approvals when a bound component is substituted?","id":"q-cmp-substitution","kind":"decision"}]},{"id":"definition-provenance-and-attribution","name":"Definition provenance and attribution","description":"Who authored, derived and approved the definition, how responsibility for outputs is attributed, and how the provenance record itself is protected.","questions":[{"text":"Which party authored and which party approved this agent definition?","id":"q-prv-author","kind":"provenance"},{"text":"From which template, framework or upstream agent definition was this definition derived?","id":"q-prv-derivation","kind":"provenance"},{"text":"How is responsibility for the agent's outputs attributed back to a responsible party?","id":"q-prv-attribution","kind":"ownership"},{"text":"How is the provenance record protected against later undetected modification?","id":"q-prv-integrity","kind":"security"}]}]}]},{"id":"capability-and-interoperability","name":"Capability and interoperability","description":"What the agent can do and how that surface is declared, discovered, negotiated and trusted by other parties.","layers":[{"id":"capability-surface","name":"Capability surface","description":"The concrete tool and resource bindings the agent holds and the skills it declares to callers.","findings":[{"id":"tool-and-resource-bindings","name":"Tool and resource bindings","description":"Which tools and data resources the agent is bound to, which cause irreversible effects, how each provider is vetted, and how a binding change is detected and re-approved.","questions":[{"text":"Which tools, functions and data resources is the agent bound to, and from which servers or providers?","id":"q-tul-inventory","kind":"composition"},{"text":"Which bound tools are read-only and which cause irreversible or externally visible effects?","id":"q-tul-effect-class","kind":"classification"},{"text":"How is each tool provider vetted, and are tool descriptions treated as untrusted content?","id":"q-tul-trust","kind":"security"},{"text":"How is a change to a bound tool's schema, description or endpoint detected and re-approved?","id":"q-tul-change","kind":"event"}]},{"id":"skill-and-task-declaration","name":"Skill and task declaration","description":"The task types the agent declares, the input and output modalities per skill, the requests it must refuse or route away, and the evidence each declared skill is met.","questions":[{"text":"Which skills or task types does the agent declare that it can perform?","id":"q-skl-declaration","kind":"definition"},{"text":"Which input and output content types does the agent accept and produce per skill?","id":"q-skl-io-modes","kind":"interoperability"},{"text":"Which requests must the agent refuse or route elsewhere?","id":"q-skl-refusal","kind":"exception"},{"text":"What evidence shows the agent performs each declared skill at the stated quality?","id":"q-skl-evidence","kind":"evidence"}]}]},{"id":"protocol-and-discovery","name":"Protocol conformance and discovery","description":"Which protocols and revisions the agent speaks, how it advertises and negotiates them, and how consumers verify a descriptor is authentic.","findings":[{"id":"protocol-conformance-and-advertisement","name":"Protocol conformance and advertisement","description":"Protocol bindings and revisions per endpoint, negotiation and failure behaviour, descriptor authenticity, and the evidence behind any conformance claim.","questions":[{"text":"Which agent and tool protocols, at which revisions, does the agent speak on each endpoint?","id":"q-prt-bindings","kind":"interoperability"},{"text":"How does the agent negotiate protocol revisions and behave when no mutually supported revision exists?","id":"q-prt-negotiation","kind":"process"},{"text":"How can a consumer verify that a published capability descriptor genuinely belongs to this agent?","id":"q-prt-authenticity","kind":"security"},{"text":"Which conformance claims are asserted, and what test evidence supports them?","id":"q-prt-conformance","kind":"validation"}]},{"id":"discovery-manifest-and-locators","name":"Discovery manifest and locators","description":"A2A requires a self-describing Agent Card covering identity, capabilities, skills, interfaces and authentication, commonly retrieved from a well-known URI. FIPA Directory Facilitators provide yellow-pages service descriptions. Extended cards may be released only after authentication. Locators are identifiers plus access hints, not the storage format.","questions":[{"text":"Where is this agent's discovery manifest published, and which protocol bindings, tenants and protocol versions does it advertise?","id":"discovery-manifest-and-locators-q01","kind":"interoperability"},{"text":"Does the agent offer an authenticated extended discovery card, and which additional skills or interfaces appear only after authentication?","id":"discovery-manifest-and-locators-q02","kind":"access"},{"text":"Which optional interaction capabilities (streaming, push notifications, extensions) does the agent declare, and how are undeclared capabilities rejected?","id":"discovery-manifest-and-locators-q03","kind":"classification"},{"text":"Which default input and output media types does the agent accept across skills?","id":"discovery-manifest-and-locators-q04","kind":"interoperability"}]}]}]},{"id":"authority-delegation-and-access-control","name":"Authority, delegation and access control","description":"On whose behalf the agent acts, what it may do, which credentials carry that permission, and where a human decision is required before it acts.","layers":[{"id":"delegation-and-credentials","name":"Delegation and credentials","description":"The chain from an originating human principal to the agent and its sub-agents, and the credentials carrying the granted authority.","findings":[{"id":"principal-and-delegation-chain","name":"Principal and delegation chain","description":"The principal on whose behalf the agent acts, the full chain to sub-agents, the non-delegable authorities, and each delegation's validity window.","questions":[{"text":"On whose behalf is the agent acting for a given activity, and how is that principal identified?","id":"q-dlg-principal","kind":"authority"},{"text":"What is the full delegation chain from the originating human principal to this agent and its sub-agents?","id":"q-dlg-chain","kind":"relationship"},{"text":"Which authorities may never be sub-delegated onward to another agent?","id":"q-dlg-limits","kind":"constraint"},{"text":"For how long and under which conditions does a delegation remain valid?","id":"q-dlg-validity","kind":"temporal"}]},{"id":"credential-scope-and-token-binding","name":"Credential scope and token binding","description":"The credentials the agent may present, their binding to an intended resource audience, the minimum scope per skill, and rotation and revocation.","questions":[{"text":"Which credentials, tokens or keys can the agent present, and who issued each?","id":"q-crd-inventory","kind":"security"},{"text":"How is each token bound to its intended resource audience, and is pass-through forbidden?","id":"q-crd-audience","kind":"constraint"},{"text":"What is the minimum scope set required for each declared skill?","id":"q-crd-minimisation","kind":"requirement"},{"text":"How are agent credentials rotated, revoked and re-issued?","id":"q-crd-rotation","kind":"process"}]}]},{"id":"permission-boundaries-and-consent","name":"Permission boundaries and consent","description":"The policy authorising each action, the categorical prohibitions, the bounded blast radius, and the points where a human must consent.","findings":[{"id":"action-authorization-policy","name":"Action authorisation policy","description":"Which policy decision point authorises each action, which actions are categorically forbidden, how far a single action can reach, and how an emergency deviation is approved.","questions":[{"text":"Which policy decision point authorises each agent action, and is the decision made per request?","id":"q-pol-decision-point","kind":"access"},{"text":"Which actions, targets or environments are categorically forbidden to the agent?","id":"q-pol-deny","kind":"constraint"},{"text":"What is the maximum blast radius of a single authorised action, and how is it bounded?","id":"q-pol-blast-radius","kind":"measurement"},{"text":"How is an emergency deviation from policy requested, approved and recorded?","id":"q-pol-override","kind":"exception"}]},{"id":"human-approval-and-consent-gates","name":"Human approval and consent gates","description":"Which operations require explicit human consent, what evidences that consent, whether approval is per action, per session or standing, and how rubber-stamping is resisted.","questions":[{"text":"Which operations require explicit user consent before the agent may proceed?","id":"q-cns-points","kind":"decision"},{"text":"What is recorded to evidence that consent or approval was given, by whom and when?","id":"q-cns-evidence","kind":"evidence"},{"text":"Does a granted approval cover a single action, a session or a standing authorisation?","id":"q-cns-duration","kind":"temporal"},{"text":"How is the oversight interface protected against approval fatigue and rubber-stamping?","id":"q-cns-fatigue","kind":"quality"}]},{"id":"standing-goals-and-stop-criteria","name":"Goals and success criteria","description":"An ISO AI agent takes actions to achieve its goals. Goal statements, in-scope objectives, explicit out-of-scope objectives and measurable success or stop criteria belong on the agent record so that goal hijack can be detected against a baseline. Run-specific tasks remain WM-AI-004.","questions":[{"text":"What standing goals and in-scope objectives is this agent authorised to pursue?","id":"standing-goals-and-stop-criteria-q01","kind":"definition"},{"text":"Which objectives are explicitly out of scope, and which stop or success criteria terminate pursuit of a goal?","id":"standing-goals-and-stop-criteria-q02","kind":"constraint"},{"text":"Who may change the agent's goal set, and what evidence is required before a goal mutation is accepted?","id":"standing-goals-and-stop-criteria-q03","kind":"decision"}]}]},{"id":"accountable-roles","name":"Accountable roles","description":"Which named parties are accountable for the agent, how duties are separated, and how accountability survives organisational change.","findings":[{"id":"ownership-and-accountability-assignment","name":"Ownership and accountability assignment","description":"The organisation and roles accountable in production, separation of build, approval and operation duties, escalation contacts and response targets, and accountability transfer.","questions":[{"text":"Which named organisation and role is accountable for this agent in production?","id":"q-own-accountable","kind":"ownership"},{"text":"How are build, approval and operation duties separated across roles?","id":"q-own-separation","kind":"authority"},{"text":"Who is contactable, and within what response time, when the agent misbehaves?","id":"q-own-escalation","kind":"process"},{"text":"What happens to accountability when the owning team, vendor or contract changes?","id":"q-own-handover","kind":"lifecycle"}]}]}]},{"id":"memory-state-and-data-governance","name":"Memory, state and data governance","description":"What the agent remembers, what may write into that memory, which data it may process for which purpose, and how long anything is kept.","layers":[{"id":"memory-architecture","name":"Memory architecture","description":"Which stores hold agent state, how they are scoped and isolated, and how their contents are kept trustworthy.","findings":[{"id":"memory-store-inventory","name":"Memory store inventory","description":"The stores read and written, which persist beyond a session and where, how memory is isolated between tenants and sessions, and which source wins on conflict.","questions":[{"text":"Which memory stores does the agent read from and write to, and what is each store's scope?","id":"q-mem-kinds","kind":"composition"},{"text":"Which memory persists beyond a session, and in which storage locality is it held?","id":"q-mem-persistence","kind":"spatial"},{"text":"How is memory isolated between tenants, users and sessions?","id":"q-mem-isolation","kind":"privacy"},{"text":"When stored memory conflicts with current instructions or retrieved context, which source prevails?","id":"q-mem-precedence","kind":"constraint"}]},{"id":"memory-write-integrity","name":"Memory write integrity","description":"What may write into durable memory and under whose authority, the provenance each item carries, controls against poisoning, and correction or quarantine of bad items.","questions":[{"text":"What is permitted to write into durable agent memory, and under whose authority?","id":"q-mwi-write-authority","kind":"authority"},{"text":"For each memory item, what records its origin, observation time and confidence?","id":"q-mwi-provenance","kind":"provenance"},{"text":"Which controls detect and contain poisoned or adversarially injected memory?","id":"q-mwi-poisoning","kind":"security"},{"text":"How is an incorrect memory item corrected, quarantined or rolled back?","id":"q-mwi-correction","kind":"process"}]}]},{"id":"data-protection-and-retention","name":"Data protection and retention","description":"Which data categories the agent may process for which purposes, and how long each record class is kept before deletion.","findings":[{"id":"data-category-and-purpose-limits","name":"Data category and purpose limits","description":"Categories of personal, confidential or regulated data permitted, declared purposes for each, cross-boundary transfer conditions, and verification of minimisation.","questions":[{"text":"Which categories of personal, confidential or regulated data may the agent process?","id":"q-dat-categories","kind":"privacy"},{"text":"For which declared purposes may each data category be used, and what use is forbidden?","id":"q-dat-purpose","kind":"constraint"},{"text":"Under which conditions may data leave a jurisdiction, tenant or trust boundary?","id":"q-dat-transfer","kind":"access"},{"text":"How is it verified that the agent requests only the data it needs?","id":"q-dat-minimisation","kind":"validation"}]},{"id":"retention-and-deletion-rules","name":"Retention and deletion rules","description":"How long each class of record, log and memory is retained and on what clock, deletion triggers and verification, legal holds, and resolution of conflicting duties.","questions":[{"text":"How long is each class of agent record, log and memory retained, and from which clock does the period run?","id":"q-ret-period","kind":"retention"},{"text":"Which events trigger deletion, and how is deletion verified across replicas and backups?","id":"q-ret-trigger","kind":"event"},{"text":"How does a legal hold or open investigation suspend normal deletion?","id":"q-ret-hold","kind":"exception"},{"text":"How are conflicting duties resolved between audit retention and erasure rights?","id":"q-ret-conflict","kind":"decision"}]}]}]},{"id":"lifecycle-and-runtime-operation","name":"Lifecycle and runtime operation","description":"How an agent moves through its governed states, how releases are approved and rolled back, and how it is bounded and overseen while running.","layers":[{"id":"lifecycle-and-change-control","name":"Lifecycle and change control","description":"The legal states of an agent, transitions between them, and the approval and rollback controls governing releases.","findings":[{"id":"agent-lifecycle-state-model","name":"Agent lifecycle state model","description":"States an agent may occupy, legal transitions, preconditions for production, conditions forcing suspension, and decommission obligations.","questions":[{"text":"Which lifecycle states may an agent occupy, and which transitions between them are legal?","id":"q-lif-states","kind":"lifecycle"},{"text":"What must be true before an agent may move into an active production state?","id":"q-lif-preconditions","kind":"state"},{"text":"Which conditions force immediate suspension or withdrawal of the agent?","id":"q-lif-suspension","kind":"event"},{"text":"What must be preserved, migrated or destroyed when the agent is retired?","id":"q-lif-decommission","kind":"retention"}]},{"id":"release-approval-and-rollback","name":"Release approval and rollback","description":"Approval gates before production, which changes are material and force re-approval, rollback speed and target, and the record proving who approved on what evidence.","questions":[{"text":"Which approval gates must be passed before an agent version reaches production?","id":"q-rel-gate","kind":"decision"},{"text":"Which changes count as material and therefore require re-approval?","id":"q-rel-materiality","kind":"classification"},{"text":"How quickly can a released agent version be rolled back, and to which known-good state?","id":"q-rel-rollback","kind":"process"},{"text":"What record proves who approved a release, on what evidence and at what time?","id":"q-rel-record","kind":"evidence"}]},{"id":"directory-registration-and-lease","name":"Directory registration and lease","description":"An agent must register with the AMS of its home platform to obtain a valid AID. DF registration advertises services and may carry a lease time after which the DF may silently remove the entry. Register, deregister, modify and search are the management functions.","questions":[{"text":"Is this agent registered with its home AMS, and which ams-agent-description (name, ownership, state) is stored?","id":"directory-registration-and-lease-q01","kind":"lifecycle"},{"text":"Which Directory Facilitators hold a description of this agent, and when does each registration lease expire or renew?","id":"directory-registration-and-lease-q02","kind":"temporal"},{"text":"What search constraints, access restrictions and exception codes apply when other agents look up this agent?","id":"directory-registration-and-lease-q03","kind":"access"}]}]},{"id":"runtime-control-and-execution-linkage","name":"Runtime control and execution linkage","description":"How humans supervise and stop the agent, how its consumption is bounded, and how running activity ties back to the exact agent version.","findings":[{"id":"human-oversight-and-intervention","name":"Human oversight and intervention","description":"Affordances letting a competent person understand, monitor and interrupt the agent in use, the stop mechanism and residual state, counter-measures to automation bias, and intervention records.","questions":[{"text":"Which interface affordances let a competent person understand, monitor and interrupt the agent while it is in use?","id":"q-ovs-design","kind":"requirement"},{"text":"How is the agent stopped mid-task, and what state does a stop leave behind?","id":"q-ovs-stop","kind":"process"},{"text":"How does the oversight design counter automation bias and over-reliance on agent output?","id":"q-ovs-bias","kind":"quality"},{"text":"What is recorded when a human overrides, corrects or halts the agent?","id":"q-ovs-record","kind":"event"}]},{"id":"operating-limits-and-budgets","name":"Operating limits and budgets","description":"Caps on steps, tool calls, recursion depth and wall-clock time per task, token, compute and monetary budgets, the concurrency ceiling, and defined breach behaviour.","questions":[{"text":"What limits cap the agent's steps, tool calls, recursion depth and wall-clock time per task?","id":"q-lim-steps","kind":"constraint"},{"text":"Which token, compute and monetary budgets apply, and what happens when they are exhausted?","id":"q-lim-cost","kind":"measurement"},{"text":"How many concurrent tasks and sessions may the agent hold, and how is contention resolved?","id":"q-lim-concurrency","kind":"state"},{"text":"What is the defined behaviour on limit breach: halt, degrade or escalate?","id":"q-lim-breach","kind":"exception"}]},{"id":"run-and-session-linkage","name":"Run and session linkage","description":"How an execution record references the exact agent version, which correlation identifiers tie activity into one task, how event time is separated from observation time, and what must be captured for reconstruction.","questions":[{"text":"How does an execution record reference the exact agent version that produced it?","id":"q-run-reference","kind":"relationship"},{"text":"Which correlation identifiers tie messages, tool calls and sub-agent activity into one task?","id":"q-run-correlation","kind":"interoperability"},{"text":"How are event time and observation or ingestion time recorded separately for agent activity?","id":"q-run-time-separation","kind":"temporal"},{"text":"What must be captured so that an agent activity can be reconstructed later?","id":"q-run-replay","kind":"evidence"}]}]}]},{"id":"assurance-observability-and-risk","name":"Assurance, observability and risk","description":"What is measured before and during service, what is recorded so behaviour can be audited, and what evidence supports risk and conformity claims.","layers":[{"id":"evaluation-and-monitoring","name":"Evaluation and monitoring","description":"How the agent is tested before release and watched while in service.","findings":[{"id":"pre-deployment-evaluation","name":"Pre-deployment evaluation","description":"Capability, safety and robustness evaluations run against a version, acceptance thresholds and who set them, representativeness of the evaluation set, and evaluation provenance.","questions":[{"text":"Which capability, safety and robustness evaluations were run against this agent version?","id":"q-evl-suite","kind":"measurement"},{"text":"Which acceptance thresholds must be met for release, and who set them?","id":"q-evl-thresholds","kind":"requirement"},{"text":"How well does the evaluation set represent the intended operating context?","id":"q-evl-representative","kind":"quality"},{"text":"When was each evaluation run, on which version, and by whom?","id":"q-evl-provenance","kind":"provenance"}]},{"id":"in-service-performance-monitoring","name":"In-service performance monitoring","description":"Live indicators showing the agent remains inside its accepted envelope, drift detection, the share of activity sampled for human review, and the response when a threshold is crossed.","questions":[{"text":"Which live indicators show that the agent is still performing within its accepted envelope?","id":"q-mon-live-metrics","kind":"measurement"},{"text":"How is behavioural drift caused by model, tool or data change detected?","id":"q-mon-drift","kind":"state"},{"text":"What proportion of agent activity is sampled for human quality review, and how is the sample selected?","id":"q-mon-sampling","kind":"quality"},{"text":"What is the defined response when a monitored indicator crosses its alert threshold?","id":"q-mon-response","kind":"process"}]},{"id":"evaluation-settings-and-validation-status","name":"Evaluation, provenance and quality evidence","description":"NIST AI 800-2 requires evaluations of agent systems to report scaffolding, tool availability, aggregation strategies, agent budget and stopping conditions separately from model inference settings. Quality claims without those settings are not comparable. OWASP assessments provide threat-coverage evidence. Provenance covers who created the agent, from which product or scaffold, and which measurements were observed.","questions":[{"text":"Which inference, scaffolding and task settings were used in the latest evaluation of this agent, and are they sufficient to reproduce the result?","id":"evaluation-settings-and-validation-status-q01","kind":"measurement"},{"text":"What quality, safety or threat-coverage claims are made for this agent, and which artefacts or probe results support them?","id":"evaluation-settings-and-validation-status-q02","kind":"quality"},{"text":"What validation status does this agent currently hold (unevaluated, draft, passed, failed, waived), and who attested it?","id":"evaluation-settings-and-validation-status-q03","kind":"validation"},{"text":"Who created or imported this agent record, from which source system, and at what event versus ingestion times?","id":"evaluation-settings-and-validation-status-q04","kind":"provenance"}]}]},{"id":"observability-and-audit","name":"Observability and audit","description":"What the agent emits so its behaviour can be traced, and how incidents and exceptions are handled and fed back.","findings":[{"id":"telemetry-and-audit-record-conformance","name":"Telemetry and audit record conformance","description":"The attribute schema emitted for agent invocations and tool executions, events that must be logged, controls on recording message content, and log protection and retention.","questions":[{"text":"Which telemetry attribute schema is emitted for agent invocations and tool executions?","id":"q-tel-schema","kind":"interoperability"},{"text":"Which events must be logged so that agent activity remains traceable for its whole lifetime?","id":"q-tel-completeness","kind":"requirement"},{"text":"Which message content may be recorded in telemetry, and how is sensitive content redacted?","id":"q-tel-content","kind":"privacy"},{"text":"How are logs protected from tampering, and for how long are they kept?","id":"q-tel-integrity","kind":"security"}]},{"id":"incident-and-exception-management","name":"Incident and exception management","description":"What counts as an incident, near miss or serious malfunction, reporting recipients and deadlines, pre-authorised containment actions, and feedback into policy and classification.","questions":[{"text":"What counts as an agent incident, near miss or serious malfunction?","id":"q-inc-definition","kind":"definition"},{"text":"To whom and within what deadline must an incident be reported?","id":"q-inc-reporting","kind":"process"},{"text":"Which containment actions are pre-authorised without further approval?","id":"q-inc-containment","kind":"authority"},{"text":"How does an incident feed back into agent policy, limits or classification?","id":"q-inc-feedback","kind":"decision"}]}]},{"id":"risk-and-conformity-evidence","name":"Risk and conformity evidence","description":"The threats the deployment has been assessed against and the documentation that supports risk acceptance and any framework alignment claim.","findings":[{"id":"threat-model-and-conformity-evidence","name":"Threat model and conformity evidence","description":"Agent-specific threats assessed, residual risks accepted and by whom, the documentation demonstrating alignment to an applicable framework, and the currency of the assessment.","questions":[{"text":"Which agent-specific threats has this deployment been assessed against?","id":"q-rsk-threat-model","kind":"security"},{"text":"Which residual risks are accepted, by whom, and with what compensating controls?","id":"q-rsk-residual","kind":"decision"},{"text":"Which documentation set demonstrates alignment to the applicable framework or regulation?","id":"q-rsk-conformity","kind":"evidence"},{"text":"When was the risk assessment last refreshed, and what triggers a re-assessment?","id":"q-rsk-currency","kind":"temporal"}]}]}]}]},"agentConduct":{"may":["Register an agent definition and publish its capability descriptor.","Request a scoped authority grant from an accountable party.","Emit activity telemetry and record oversight interventions.","Report its own revocation or retirement state to callers."],"mustNot":["Hold or use authority that was not explicitly granted.","Forward a received credential unchanged to another service.","Take irreversible or externally visible action without the required consent.","Trust tool descriptions, agent cards or retrieved content as instructions.","Claim conformance to a protocol or standard without evidence."],"requiresHuman":["Granting or widening delegated authority.","Approving release of an agent to production.","Restoring an agent after revocation."]},"ethics":{"considerations":["People affected by an agent's actions need a clear accountable party behind it.","Agents acting with personal credentials can expose private data at scale.","Users should be able to tell they are dealing with an agent and not a person."],"affectedParties":["People who interact with or are acted on by the agent","Principals who delegate authority","Operators and owners of the agent"]},"owners":{"steward":"The adopting Dimension MUST name a single accountable owner package for WM-AI-002 records and publish the owning organisation and role before any agent record is created.","roles":[{"name":"Agent owner (accountable deployer)","responsibilities":["Hold named accountability for the agent in production","Approve authority grants, tool bindings and autonomy level","Sign residual risk acceptances and release decisions"]},{"name":"Agent builder and maintainer","responsibilities":["Author and maintain the agent definition and its constituent bindings","Submit versions for release approval with evidence attached","Keep capability descriptors and documentation current with the released version"]},{"name":"Oversight operator","responsibilities":["Monitor live agent behaviour against the accepted envelope","Exercise intervention, pause and stop authority","Record interventions with reason, affected activity and timing"]},{"name":"Risk and compliance reviewer","responsibilities":["Validate regulatory role, risk classification and disclosure duties","Review evaluation evidence and the conformity dossier","Trigger re-assessment when a re-assessment condition occurs"]},{"name":"Identity and access administrator","responsibilities":["Issue, scope, rotate and revoke agent credentials and delegations","Enforce audience binding and the prohibition on token pass-through","Review break-glass grants independently of the requester"]},{"name":"Data steward","responsibilities":["Approve data categories, purposes, memory scope and isolation boundaries","Approve redaction rules for telemetry content recording","Own the retention schedule and authorise erasure and legal holds"]}],"masterSystems":[]},"relations":[{"target":"WM-AI-001 (AI system)","type":"composes","note":"An AI system exposes one or more agent actors. System-level obligations, model inventory and market placement remain in WM-AI-001; actor-level authority, tool bindings, memory and oversight remain here so the two are not duplicated."},{"target":"WM-AI-005 (prompt or agent configuration)","type":"references","note":"The agent references the instruction or configuration artefact that governs its behaviour, with a version and pin mode. Instruction text, templating and variables are modelled there, not here."},{"target":"WM-AI-004 (agent run or execution record)","type":"references","note":"Each execution record references the exact agent version that produced it, giving execution provenance. Spans, messages, token usage and outcomes belong to WM-AI-004."},{"target":"WM-PER-003 (parent actor or person model)","type":"child","note":"The AI agent specialises the generic responsibility-bearing actor. Human principals, approvers and overseers are recorded there and referenced from delegation and accountability findings."},{"target":"W3C PROV-O provenance vocabulary","type":"aligned","note":"Align agent, activity, entity, attribution, association, delegation and derivation semantics with a published provenance ontology rather than inventing local provenance terms. Alignment only; no conformance is claimed."},{"target":"OpenTelemetry GenAI semantic conventions for agent spans","type":"aligned","note":"Align agent and tool operation naming and identifier attributes with a shared telemetry vocabulary. The convention is at Development stability, so the alignment is advisory and versioned separately."},{"target":"A2A Agent Card and task lifecycle","type":"aligned","note":"Align published capability advertisement, skills, modalities, security schemes and card signatures with an inter-agent discovery format. The card name is treated as an alias, never a primary key."},{"target":"Model Context Protocol tool and resource primitives and authorization","type":"aligned","note":"Align tool and resource binding semantics, consent requirements, revision negotiation and audience-bound token handling with a published tool-integration protocol."},{"target":"Regulation (EU) 2024/1689 provider and deployer obligations","type":"aligned","note":"Align role determination, risk classification, logging for traceability, human oversight and transparency findings with the applicable regulatory obligations where the agent falls in scope."},{"target":"NIST AI RMF 1.0 and the Generative AI Profile","type":"aligned","note":"Align governance, mapping, measurement and management findings with a voluntary risk framework and its generative-AI companion, noting that neither squarely covers tool-using autonomous agents."},{"target":"NIST SP 800-207 zero trust access policy","type":"aligned","note":"Align per-request authorisation, least privilege and continuous verification of agent actions with zero-trust tenets rather than a bespoke local access theory."},{"target":"Tool or external service model (sibling; no registry identifier assigned in the supplied extract)","type":"references","note":"Tool schemas, endpoint contracts and operators belong to a separate subject that this model only references. Marked as an unresolved boundary because the sibling model identifier was not present in the registry extract."},{"target":"Embodied or robotic agent extension (not registered)","type":"extends","note":"Physical siting, actuation safety and mechanical harm surfaces are outside this model. An extension would be required before applying WM-AI-002 to embodied agents; recorded as a gap rather than asserted as covered."},{"target":"WM-AI-001 AI system","type":"neighbor","note":"The AI system is the product placed on the market and carries system-level obligations; the agent is one actor it exposes. Model inventory, system risk management and market placement stay in WM-AI-001; actor-level authority, tool bindings, memory and oversight stay here."},{"target":"WM-AI-004 agent run","type":"neighbor","note":"A run is a bounded execution event with traces and outcomes; the agent is the durable actor that runs reference. Correlation identifiers and version references live here; spans, messages and token usage live in WM-AI-004."},{"target":"WM-AI-005 prompt or agent configuration","type":"neighbor","note":"The configuration artefact carries instruction content and parameters; this model carries only the reference, the pinning mode and the approval status of that binding."},{"target":"WM-PER-003 actor or person","type":"neighbor","note":"Human principals, approvers and overseers are references to the person or party model. This model records the delegation relation and accountable role, not the human's own attributes."},{"target":"Tool, server or external service model","type":"neighbor","note":"A tool's own schema, endpoint contract and operator are a separate subject. This model records the binding, its effect class, trust status and approval, not the tool's internal definition."},{"target":"Access-management and credential systems","type":"neighbor","note":"Issuance mechanics, key material and authorisation-server internals stay in the identity domain; this model records which scopes and audiences an agent may hold and under whose delegation."},{"target":"WM-PER-003","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier issued by the system of record for the agent, such as the deployment platform's agent registry identifier or a provider-assigned hosted agent identifier.","Governed global identifier or IRI minted in the owning Dimension's HTTPS namespace and resolvable to the agent identity record.","UUID or ULID assigned by the adopting Dimension when neither of the above exists, recorded together with the reason no governed identifier was available.","Protocol-scoped names, endpoint URIs and display names are aliases only and MUST NOT be used as primary keys; a release date, version date or any other date is never an identifier.","Transient in-memory agent instance identifiers MUST NOT be promoted to primary keys, because they do not survive the process that created them."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["An agent has an identifier, an accountable owner, a capability descriptor, granted scopes and bound tools.","Often confused with the AI system it runs in, a single run, a prompt configuration and a human user account."]},"capabilities":{"applicability":"required","items":["Register agent definition: Create the authoritative agent record, assign its identifier per the identity priority and bind it to an accountable owner and a regulatory role determination.","Publish capability descriptor: Emit the externally retrievable descriptor listing identity, declared skills, modalities, protocol revisions, endpoints and security schemes, signed so consumers can verify origin.","Grant delegated authority: Record a delegation from a principal to the agent with an explicit scope, resource audience, non-delegable exclusions and validity window.","Revoke agent authority: Withdraw a delegation or credential immediately and propagate the revocation to sub-agents and dependent grants.","Evaluate release readiness: Run the required evaluations against a candidate agent version and compare results with the acceptance thresholds set by the responsible authority.","Transition lifecycle state: Move the agent to a new governed lifecycle state, recording actor, reason, guard evidence and the entry instant.","Record oversight intervention: Capture a human override, correction, pause or halt with the intervening party, the affected activity and both event and ingestion times.","Emit agent activity telemetry: Emit conformant telemetry for agent invocation and tool execution operations, applying the content recording mode and redaction rules.","Apply retention and erasure: Enforce the retention schedule across agent records, logs and memory, honouring legal holds and verifying deletion across replicas and backups.","Search agent directory: Query AMS white pages or DF yellow pages with a partial description template and search constraints.","Bind or unbind tools: Attach or detach MCP tools and resources to the agent's standing inventory, with consent and schema validation requirements.","Deregister agent: Remove AMS and DF descriptions so the AID can be released and message delivery no longer targets the agent."]},"hazards":{"applicability":"required","items":["Excessive authority used beyond the principal's intent.","Prompt injection through tool or retrieved content.","Credential leakage through token pass-through.","Irreversible actions taken without oversight."]},"interfaces":{"applicability":"required","items":["OAuth 2.0 (RFC 6749) and token exchange (RFC 8693) for delegated authority.","Model Context Protocol for tool binding.","W3C Decentralized Identifiers and Verifiable Credentials.","OpenTelemetry for activity telemetry."]},"context":{"applicability":"required","items":["Regulation (EU) 2024/1689 obligations are assumed only where the agent is placed on the EU market or its output is used in the EU. General application is 2 August 2026, with prohibited practices from 2 February 2025, general-purpose AI governance from 2 August 2025 and certain high-risk categories from 2 December 2027 and 2 August 2028.","NIST AI RMF, the Generative AI Profile and SP 800-207 are voluntary in the United States unless imposed by contract, procurement condition or a sector regulator.","Data residency rules, erasure rights and incident-reporting deadlines vary by jurisdiction and are modelled as parameters on the agent record, never as global constants.","No global agent identifier registry exists in any jurisdiction reviewed, so identifier authority is Dimension-local and cross-organisation resolution depends on alias mapping.","Sector overlays such as finance, health and critical infrastructure are assumed to add obligations rather than replace those modelled here; none was retrieved or verified during this research.","EU provider/deployer fields are required in substance only when the exposing system is in territorial scope of Regulation 2024/1689.","FIPA AMS/DF patterns remain normative in some industrial multi-agent platforms and are treated as an alignment even where LLM-agent products do not implement them.","A2A well-known Agent Card discovery assumes internet or enterprise HTTP locators; offline or mesh agents need equivalent locators.","NIST AI 800-2 is an initial public draft of evaluation practice, not a binding US regulation."]}},"sources":[{"title":"Model Context Protocol Specification","url":"https://modelcontextprotocol.io/specification/2026-07-28","note":"Model Context Protocol project"},{"title":"Model Context Protocol - Authorization","url":"https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization","note":"Model Context Protocol project"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium (W3C)"},{"title":"RFC 3339 - Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/rfc/rfc3339","note":"Internet Engineering Task Force (IETF)"},{"title":"RFC 9728 - OAuth 2.0 Protected Resource Metadata","url":"https://www.rfc-editor.org/rfc/rfc9728.html","note":"Internet Engineering Task Force (IETF)"},{"title":"AI Risk Management Framework (NIST AI 100-1)","url":"https://www.nist.gov/itl/ai-risk-management-framework","note":"National Institute of Standards and Technology (NIST)"},{"title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)","url":"https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence","note":"National Institute of Standards and Technology (NIST)"},{"title":"AI Act - Regulatory framework for artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","note":"European Commission, Directorate-General for Communications Networks, Content and Technology"},{"title":"Article 14: Human Oversight - EU Artificial Intelligence Act","url":"https://artificialintelligenceact.eu/article/14/","note":"EU Artificial Intelligence Act information portal (Future of Life Institute)"},{"title":"Agent2Agent (A2A) Protocol Specification","url":"https://a2a-protocol.org/latest/specification/","note":"A2A Project (Linux Foundation)"},{"title":"OpenTelemetry Semantic Conventions for Generative AI - Agent spans","url":"https://github.com/open-telemetry/semantic-conventions-genai/blob/main/docs/gen-ai/gen-ai-agent-spans.md","note":"OpenTelemetry (Cloud Native Computing Foundation)"},{"title":"NIST Special Publication 800-207: Zero Trust Architecture","url":"https://csrc.nist.gov/pubs/sp/800/207/final","note":"National Institute of Standards and Technology (NIST)"},{"title":"OWASP Top 10 for Large Language Model Applications","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/","note":"OWASP Foundation (OWASP GenAI Security Project)"},{"title":"ISO/IEC 22989:2022 Information technology — Artificial intelligence — Artificial intelligence concepts and terminology","url":"https://www.iso.org/standard/74296.html","note":"ISO/IEC JTC 1/SC 42"},{"title":"FIPA Agent Management Specification SC00023J","url":"https://www.fipa.org/specs/fipa00023/SC00023J.html","note":"Foundation for Intelligent Physical Agents (FIPA)"},{"title":"FIPA ACL Message Structure Specification SC00061G","url":"https://www.fipa.org/specs/fipa00061/SC00061G.html","note":"Foundation for Intelligent Physical Agents (FIPA)"},{"title":"Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng","note":"European Union (European Parliament and Council)"},{"title":"NIST AI 800-2 Initial Public Draft: Practices for Automated Benchmark Evaluations of Language Models","url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.800-2.ipd.pdf","note":"National Institute of Standards and Technology (NIST CAISI)"},{"title":"OWASP Top 10 for Agentic Applications for 2026 and Agentic AI Threats and Mitigations v1.1","url":"https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/","note":"OWASP Foundation / Gen AI Security Project (Agentic Security Initiative)"}],"openQuestions":["Lateral peer-agent relations: which peers an agent may discover, delegate to or refuse, and the trust root for inter-agent authentication beyond transport security and descriptor signatures. Both providers record this as a gap and neither retrieved a source defining a trust anchor.","Opaque-execution constraint: whether an agent must withhold internal plans, memory and tool implementations from protocol peers while exposing tools explicitly to its host, and whether that belongs as a constraint on the existing protocol-conformance finding.","Agent memory schema: no ISO or IEC schema defines working, episodic or long-term agent memory. Investigate context-compression and unbounded-horizon memory and their interaction with stopping conditions, plus peer-facing memory opacity.","Identity semantics: adopt an explicit name-equality rule and lifetime immutability constraint for the primary identifier on the existing identity finding, and confirm no cross-organisation agent identifier registry exists in any reviewed jurisdiction.","FIPA platform state vocabulary: decide whether the initiated, active, suspended, waiting and transit state set with per-state message buffering becomes the normative vocabulary or remains an alignment against the adopting Dimension's own states.","Emerging standards watch: NIST CAISI agent standards deliverables on durable identity and authorization, IETF and community discovery drafts, and agent payment or mandate protocols, none of which had sufficient primary multi-organisation backing in either evidence pack.","Assess whether the deployed registration warrants a separate entry from the versioned agent definition once the registration and lease structure is exercised against a second platform profile.","Agent-to-agent trust establishment beyond transport authentication and card signatures: no retrieved primary source defines the trust root, so the model records signature verification without prescribing a trust anchor.","Statutory log-retention periods and serious-incident reporting deadlines under Regulation (EU) 2024/1689 were derived from the Commission's official summary page rather than verified article by article, because EUR-Lex was not retrievable during this research.","ISO/IEC 42001 and ISO/IEC 22989 could not be retrieved (HTTP 403), so terminology for agent, autonomy and heteronomy rests on non-ISO sources and no ISO alignment is asserted.","Embodied and robotic agents, actuation safety and physical harm surfaces are not modelled.","Agent commerce: payments, contracting, pricing and settlement between agents are not modelled.","Multi-agent emergent behaviour, coalition formation and market-level effects are only partially reached through delegation-chain and sub-agent findings.","Model-level properties such as training data, weights and fine-tuning are deliberately excluded and belong to the AI system or model sibling.","Human competence, training and certification of overseers are referenced but modelled in the person or party sibling, not here.","No primary ISO or IEC schema for LLM long-term memory, episodic memory or memory-poisoning mitigations beyond OWASP threat language.","IETF and community drafts (AID DNS discovery, SAMP, A2A WebFinger) are emerging and not treated as canonical.","NIST CAISI AI Agent Standards Initiative (announced 2026-02-17) has not yet issued a durable identity or authorization standard; this model should be revisited when those deliverables appear.","OWASP Agentic Skills Top 10 and payment/mandate protocols (for example AP2 or x402) lack sufficient primary, multi-organisation backing in the sources fetched for this run.","Physical embodiment, swarm orchestration topologies and agent legal personhood are out of scope or unsupported.","ISO/IEC 42001 AI management systems and ISO/IEC 23894 risk management apply to organisations and systems, not to a single agent record, and were not inlined."],"resources":{"spec":"/models/wm-ai-002-ai-agent/spec.yaml","agents":"/models/wm-ai-002-ai-agent/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-ai-002"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-ai-002-ai-agent/spec.yaml","ver-cy/world-models/card-supplements/wm-ai-002-ai-agent.json"],"providers":["Claude","Grok"],"researchStatus":"reviewable-draft","generatedAt":"2026-08-26T12:43:23Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}