{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-ai-006","code":"wm-ai-006-model-training-fine-tuning-run","url":"https://ver.cy/models/wm-ai-006-model-training-fine-tuning-run/","name":"Model Training / Fine-tuning Run","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"aggregate","plane":"","domain":["INF.AI.TRN"],"industry":["Cross-industry"],"navPath":"NAV.INF.AI.TRN","tags":["model","training","fine","tuning","run","inf.ai.trn"],"facets":{}},"whatItIs":"Owns one model training or fine-tuning run identity; objective, method and authority; immutable bindings to base model, tokenizer, datasets, code, configuration and environment; topology, stages, attempts, progress, resources, checkpoints, metrics, validation and safety evidence; produced-artifact bindings, lineage, reproducibility limits, terminal outcome, access, correction, retention and projections. Dataset, source code, base model, trained model artifact, evaluation, registry, deployment, infrastructure, secret, policy, provenance, audit and records masters remain external.","purpose":"Represent one governed execution that transforms version-qualified model, data, code and configuration inputs into candidate model artifacts with reconstructable progress, resources, evidence, lineage and outcome.","scope":{"in":["Run identity, experiment and job bindings, objective, method, risk, authority, input versions, configuration, environment, topology, stages, attempts and progress","Resources, costs, energy, checkpoints, metrics, validation and safety references, candidates, derivation, reproducibility, outcome, access, correction, retention and projections"],"out":["Creating or mutating external dataset, code, base-model, trained-model, evaluation, registry, deployment, infrastructure, secret, policy, provenance, audit or records masters","Equating a run with an experiment, checkpoint, trained model, registry entry or deployment, or equating requested resources with observed use","Autonomous training, unrestricted compute allocation, protected-data or secret access, privacy or rights waiver, release, deployment or destructive cleanup"],"boundaries":[{"neighbor":"WM-DAT-001 Dataset","distinction":"The candidate REFERENCE relation binds version-qualified dataset roles, splits, permissions and transformations. Dataset content, rights and lifecycle remain external."},{"neighbor":"WM-SFT-004 produced model artifact","distinction":"The candidate PRODUCES relation records derivation and candidate selection. The artifact master, registry promotion, release and deployment remain external."},{"neighbor":"Experiment, pipeline, job, stage, task, attempt and checkpoint","distinction":"The run is one execution aggregate; reusable definitions and independently addressable execution children retain distinct identities and provenance."},{"neighbor":"AI evaluation, model registry and deployment","distinction":"The run may reference evaluations and emit candidates, but evaluation conclusions, promotion decisions, registry state and deployment state are external authorities."},{"neighbor":"Infrastructure, telemetry, cost and environmental systems","distinction":"External systems own allocation, billing, energy and carbon records. The run stores method-bound requested, allocated and observed references and summaries."},{"neighbor":"MLflow, MLMD, OpenLineage, PROV, Kubeflow, SLSA, OCI, OpenTelemetry, MLPerf, SCI and PyTorch","distinction":"These are versioned experiment, metadata, lineage, runtime, provenance, packaging, telemetry, benchmark, carbon and framework profiles. No mapping is universally applicable or assumed lossless."}]},"distinguishingFeatures":["Records one training or fine-tuning execution, not the resulting model artifact or its registry entry.","Binds immutable versions of base model, tokenizer, data, code, configuration and environment.","Holds checkpoints and metrics as run evidence, while evaluation runs are separate records.","Treats a seed as insufficient proof of reproducibility without environment evidence."],"structure":{"bundles":[{"id":"run-identity-objective-method-and-authority","name":"Run identity, objective, method and authority","description":"Groups governed training-run context for run identity, objective, method and authority.","layers":[{"id":"run-root-experiment-parent-and-definition","name":"Run root, experiment, parent and definition","description":"Groups source-qualified training-run context for run root, experiment, parent and definition.","findings":[{"id":"run-root-identity-namespace-owner-revision-and-current-head","name":"Run root identity, namespace, owner, revision and current head","description":"Records run root identity, namespace, owner, revision and current head as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish run root identity, namespace, owner, revision and current head?","id":"run-root-identity-namespace-owner-revision-and-current-head-q01","kind":"identity"},{"text":"Who may declare, execute, observe, review, correct or rely on run root identity, namespace, owner, revision and current head, under which authority and limits?","id":"run-root-identity-namespace-owner-revision-and-current-head-q02","kind":"composition"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to run root identity, namespace, owner, revision and current head, and which evidence supports them?","id":"run-root-identity-namespace-owner-revision-and-current-head-q03","kind":"privacy"}]},{"id":"experiment-parent-pipeline-job-definition-and-correlation-binding","name":"Experiment, parent, pipeline, job definition and correlation binding","description":"Records experiment, parent, pipeline, job definition and correlation binding as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish experiment, parent, pipeline, job definition and correlation binding?","id":"experiment-parent-pipeline-job-definition-and-correlation-binding-q01","kind":"relationship"},{"text":"Who may declare, execute, observe, review, correct or rely on experiment, parent, pipeline, job definition and correlation binding, under which authority and limits?","id":"experiment-parent-pipeline-job-definition-and-correlation-binding-q02","kind":"evidence"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to experiment, parent, pipeline, job definition and correlation binding, and which evidence supports them?","id":"experiment-parent-pipeline-job-definition-and-correlation-binding-q03","kind":"lifecycle"}]}]},{"id":"objective-training-method-risk-and-authority","name":"Objective, training method, risk and authority","description":"Groups source-qualified training-run context for objective, training method, risk and authority.","findings":[{"id":"task-objective-target-hypothesis-acceptance-and-stop-plan","name":"Task, objective, target, hypothesis, acceptance and stop plan","description":"Records task, objective, target, hypothesis, acceptance and stop plan as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish task, objective, target, hypothesis, acceptance and stop plan?","id":"task-objective-target-hypothesis-acceptance-and-stop-plan-q01","kind":"requirement"},{"text":"Who may declare, execute, observe, review, correct or rely on task, objective, target, hypothesis, acceptance and stop plan, under which authority and limits?","id":"task-objective-target-hypothesis-acceptance-and-stop-plan-q02","kind":"ownership"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to task, objective, target, hypothesis, acceptance and stop plan, and which evidence supports them?","id":"task-objective-target-hypothesis-acceptance-and-stop-plan-q03","kind":"quality"}]},{"id":"pretraining-finetuning-adaptation-method-risk-profile-and-accountable-authority","name":"Pretraining, fine-tuning, adaptation method, risk profile and accountable authority","description":"Records pretraining, fine-tuning, adaptation method, risk profile and accountable authority as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish pretraining, fine-tuning, adaptation method, risk profile and accountable authority?","id":"pretraining-finetuning-adaptation-method-risk-profile-and-accountable-authority-q01","kind":"classification"},{"text":"Who may declare, execute, observe, review, correct or rely on pretraining, fine-tuning, adaptation method, risk profile and accountable authority, under which authority and limits?","id":"pretraining-finetuning-adaptation-method-risk-profile-and-accountable-authority-q02","kind":"measurement"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to pretraining, fine-tuning, adaptation method, risk profile and accountable authority, and which evidence supports them?","id":"pretraining-finetuning-adaptation-method-risk-profile-and-accountable-authority-q03","kind":"security"}]}]}]},{"id":"model-data-code-configuration-and-environment-bindings","name":"Model, data, code, configuration and environment bindings","description":"Groups governed training-run context for model, data, code, configuration and environment bindings.","layers":[{"id":"base-model-tokenizer-dataset-and-split-bindings","name":"Base model, tokenizer, dataset and split bindings","description":"Groups source-qualified training-run context for base model, tokenizer, dataset and split bindings.","findings":[{"id":"base-model-architecture-tokenizer-initialization-freeze-and-adapter-bindings","name":"Base model, architecture, tokenizer, initialization, freeze and adapter bindings","description":"Records base model, architecture, tokenizer, initialization, freeze and adapter bindings as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish base model, architecture, tokenizer, initialization, freeze and adapter bindings?","id":"base-model-architecture-tokenizer-initialization-freeze-and-adapter-bindings-q01","kind":"composition"},{"text":"Who may declare, execute, observe, review, correct or rely on base model, architecture, tokenizer, initialization, freeze and adapter bindings, under which authority and limits?","id":"base-model-architecture-tokenizer-initialization-freeze-and-adapter-bindings-q02","kind":"exception"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to base model, architecture, tokenizer, initialization, freeze and adapter bindings, and which evidence supports them?","id":"base-model-architecture-tokenizer-initialization-freeze-and-adapter-bindings-q03","kind":"retention"}]},{"id":"dataset-role-snapshot-mixture-split-transform-sampling-permission-and-quality","name":"Dataset role, snapshot, mixture, split, transform, sampling, permission and quality","description":"Records dataset role, snapshot, mixture, split, transform, sampling, permission and quality as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish dataset role, snapshot, mixture, split, transform, sampling, permission and quality?","id":"dataset-role-snapshot-mixture-split-transform-sampling-permission-and-quality-q01","kind":"privacy"},{"text":"Who may declare, execute, observe, review, correct or rely on dataset role, snapshot, mixture, split, transform, sampling, permission and quality, under which authority and limits?","id":"dataset-role-snapshot-mixture-split-transform-sampling-permission-and-quality-q02","kind":"provenance"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to dataset role, snapshot, mixture, split, transform, sampling, permission and quality, and which evidence supports them?","id":"dataset-role-snapshot-mixture-split-transform-sampling-permission-and-quality-q03","kind":"interoperability"}]}]},{"id":"code-parameters-dependencies-and-runtime-environment","name":"Code, parameters, dependencies and runtime environment","description":"Groups source-qualified training-run context for code, parameters, dependencies and runtime environment.","findings":[{"id":"source-code-revision-entrypoint-configuration-hyperparameters-and-seeds","name":"Source code revision, entrypoint, configuration, hyperparameters and seeds","description":"Records source code revision, entrypoint, configuration, hyperparameters and seeds as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish source code revision, entrypoint, configuration, hyperparameters and seeds?","id":"source-code-revision-entrypoint-configuration-hyperparameters-and-seeds-q01","kind":"provenance"},{"text":"Who may declare, execute, observe, review, correct or rely on source code revision, entrypoint, configuration, hyperparameters and seeds, under which authority and limits?","id":"source-code-revision-entrypoint-configuration-hyperparameters-and-seeds-q02","kind":"process"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to source code revision, entrypoint, configuration, hyperparameters and seeds, and which evidence supports them?","id":"source-code-revision-entrypoint-configuration-hyperparameters-and-seeds-q03","kind":"decision"}]},{"id":"packages-images-framework-compiler-driver-hardware-and-environment","name":"Packages, images, framework, compiler, driver, hardware and environment","description":"Records packages, images, framework, compiler, driver, hardware and environment as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish packages, images, framework, compiler, driver, hardware and environment?","id":"packages-images-framework-compiler-driver-hardware-and-environment-q01","kind":"interoperability"},{"text":"Who may declare, execute, observe, review, correct or rely on packages, images, framework, compiler, driver, hardware and environment, under which authority and limits?","id":"packages-images-framework-compiler-driver-hardware-and-environment-q02","kind":"validation"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to packages, images, framework, compiler, driver, hardware and environment, and which evidence supports them?","id":"packages-images-framework-compiler-driver-hardware-and-environment-q03","kind":"state"}]}]}]},{"id":"orchestration-distributed-execution-resources-and-progress","name":"Orchestration, distributed execution, resources and progress","description":"Groups governed training-run context for orchestration, distributed execution, resources and progress.","layers":[{"id":"topology-workers-stages-attempts-and-state","name":"Topology, workers, stages, attempts and state","description":"Groups source-qualified training-run context for topology, workers, stages, attempts and state.","findings":[{"id":"cluster-topology-workers-ranks-parallelism-and-communication-strategy","name":"Cluster topology, workers, ranks, parallelism and communication strategy","description":"Records cluster topology, workers, ranks, parallelism and communication strategy as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish cluster topology, workers, ranks, parallelism and communication strategy?","id":"cluster-topology-workers-ranks-parallelism-and-communication-strategy-q01","kind":"composition"},{"text":"Who may declare, execute, observe, review, correct or rely on cluster topology, workers, ranks, parallelism and communication strategy, under which authority and limits?","id":"cluster-topology-workers-ranks-parallelism-and-communication-strategy-q02","kind":"privacy"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to cluster topology, workers, ranks, parallelism and communication strategy, and which evidence supports them?","id":"cluster-topology-workers-ranks-parallelism-and-communication-strategy-q03","kind":"identity"}]},{"id":"stage-task-attempt-state-transition-retry-resume-and-idempotency","name":"Stage, task, attempt, state transition, retry, resume and idempotency","description":"Records stage, task, attempt, state transition, retry, resume and idempotency as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish stage, task, attempt, state transition, retry, resume and idempotency?","id":"stage-task-attempt-state-transition-retry-resume-and-idempotency-q01","kind":"state"},{"text":"Who may declare, execute, observe, review, correct or rely on stage, task, attempt, state transition, retry, resume and idempotency, under which authority and limits?","id":"stage-task-attempt-state-transition-retry-resume-and-idempotency-q02","kind":"lifecycle"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to stage, task, attempt, state transition, retry, resume and idempotency, and which evidence supports them?","id":"stage-task-attempt-state-transition-retry-resume-and-idempotency-q03","kind":"classification"}]}]},{"id":"progress-optimizer-resources-cost-and-environment","name":"Progress, optimizer, resources, cost and environment","description":"Groups source-qualified training-run context for progress, optimizer, resources, cost and environment.","findings":[{"id":"steps-epochs-batches-samples-tokens-optimizer-scheduler-and-precision","name":"Steps, epochs, batches, samples, tokens, optimizer, scheduler and precision","description":"Records steps, epochs, batches, samples, tokens, optimizer, scheduler and precision as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish steps, epochs, batches, samples, tokens, optimizer, scheduler and precision?","id":"steps-epochs-batches-samples-tokens-optimizer-scheduler-and-precision-q01","kind":"measurement"},{"text":"Who may declare, execute, observe, review, correct or rely on steps, epochs, batches, samples, tokens, optimizer, scheduler and precision, under which authority and limits?","id":"steps-epochs-batches-samples-tokens-optimizer-scheduler-and-precision-q02","kind":"quality"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to steps, epochs, batches, samples, tokens, optimizer, scheduler and precision, and which evidence supports them?","id":"steps-epochs-batches-samples-tokens-optimizer-scheduler-and-precision-q03","kind":"relationship"}]},{"id":"requested-allocated-observed-compute-storage-network-cost-energy-and-emissions","name":"Requested, allocated and observed compute, storage, network, cost, energy and emissions","description":"Records requested, allocated and observed compute, storage, network, cost, energy and emissions as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish requested, allocated and observed compute, storage, network, cost, energy and emissions?","id":"requested-allocated-observed-compute-storage-network-cost-energy-and-emissions-q01","kind":"measurement"},{"text":"Who may declare, execute, observe, review, correct or rely on requested, allocated and observed compute, storage, network, cost, energy and emissions, under which authority and limits?","id":"requested-allocated-observed-compute-storage-network-cost-energy-and-emissions-q02","kind":"security"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to requested, allocated and observed compute, storage, network, cost, energy and emissions, and which evidence supports them?","id":"requested-allocated-observed-compute-storage-network-cost-energy-and-emissions-q03","kind":"authority"}]}]}]},{"id":"checkpoints-metrics-validation-quality-and-safety","name":"Checkpoints, metrics, validation, quality and safety","description":"Groups governed training-run context for checkpoints, metrics, validation, quality and safety.","layers":[{"id":"checkpoints-progress-metrics-and-selection","name":"Checkpoints, progress metrics and selection","description":"Groups source-qualified training-run context for checkpoints, progress metrics and selection.","findings":[{"id":"checkpoint-identity-step-digest-completeness-reason-retention-and-resume","name":"Checkpoint identity, step, digest, completeness, reason, retention and resume","description":"Records checkpoint identity, step, digest, completeness, reason, retention and resume as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish checkpoint identity, step, digest, completeness, reason, retention and resume?","id":"checkpoint-identity-step-digest-completeness-reason-retention-and-resume-q01","kind":"evidence"},{"text":"Who may declare, execute, observe, review, correct or rely on checkpoint identity, step, digest, completeness, reason, retention and resume, under which authority and limits?","id":"checkpoint-identity-step-digest-completeness-reason-retention-and-resume-q02","kind":"retention"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to checkpoint identity, step, digest, completeness, reason, retention and resume, and which evidence supports them?","id":"checkpoint-identity-step-digest-completeness-reason-retention-and-resume-q03","kind":"requirement"}]},{"id":"loss-metric-series-effective-parameters-selection-rule-and-observed-best","name":"Loss and metric series, effective parameters, selection rule and observed best","description":"Records loss and metric series, effective parameters, selection rule and observed best as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish loss and metric series, effective parameters, selection rule and observed best?","id":"loss-metric-series-effective-parameters-selection-rule-and-observed-best-q01","kind":"quality"},{"text":"Who may declare, execute, observe, review, correct or rely on loss and metric series, effective parameters, selection rule and observed best, under which authority and limits?","id":"loss-metric-series-effective-parameters-selection-rule-and-observed-best-q02","kind":"interoperability"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to loss and metric series, effective parameters, selection rule and observed best, and which evidence supports them?","id":"loss-metric-series-effective-parameters-selection-rule-and-observed-best-q03","kind":"constraint"}]}]},{"id":"validation-data-quality-privacy-and-safety-evidence","name":"Validation, data quality, privacy and safety evidence","description":"Groups source-qualified training-run context for validation, data quality, privacy and safety evidence.","findings":[{"id":"validation-split-evaluation-reference-leakage-contamination-and-generalization","name":"Validation split, evaluation reference, leakage, contamination and generalization","description":"Records validation split, evaluation reference, leakage, contamination and generalization as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish validation split, evaluation reference, leakage, contamination and generalization?","id":"validation-split-evaluation-reference-leakage-contamination-and-generalization-q01","kind":"validation"},{"text":"Who may declare, execute, observe, review, correct or rely on validation split, evaluation reference, leakage, contamination and generalization, under which authority and limits?","id":"validation-split-evaluation-reference-leakage-contamination-and-generalization-q02","kind":"decision"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to validation split, evaluation reference, leakage, contamination and generalization, and which evidence supports them?","id":"validation-split-evaluation-reference-leakage-contamination-and-generalization-q03","kind":"event"}]},{"id":"data-quality-bias-privacy-security-safety-red-team-and-incident-references","name":"Data quality, bias, privacy, security, safety, red-team and incident references","description":"Records data quality, bias, privacy, security, safety, red-team and incident references as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish data quality, bias, privacy, security, safety, red-team and incident references?","id":"data-quality-bias-privacy-security-safety-red-team-and-incident-references-q01","kind":"security"},{"text":"Who may declare, execute, observe, review, correct or rely on data quality, bias, privacy, security, safety, red-team and incident references, under which authority and limits?","id":"data-quality-bias-privacy-security-safety-red-team-and-incident-references-q02","kind":"state"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to data quality, bias, privacy, security, safety, red-team and incident references, and which evidence supports them?","id":"data-quality-bias-privacy-security-safety-red-team-and-incident-references-q03","kind":"temporal"}]}]}]},{"id":"outputs-lineage-reproducibility-and-outcome","name":"Outputs, lineage, reproducibility and outcome","description":"Groups governed training-run context for outputs, lineage, reproducibility and outcome.","layers":[{"id":"candidate-final-artifacts-and-derivation","name":"Candidate and final artifacts and derivation","description":"Groups source-qualified training-run context for candidate and final artifacts and derivation.","findings":[{"id":"candidate-output-final-selection-packaging-format-digest-and-signature","name":"Candidate output, final selection, packaging, format, digest and signature","description":"Records candidate output, final selection, packaging, format, digest and signature as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish candidate output, final selection, packaging, format, digest and signature?","id":"candidate-output-final-selection-packaging-format-digest-and-signature-q01","kind":"evidence"},{"text":"Who may declare, execute, observe, review, correct or rely on candidate output, final selection, packaging, format, digest and signature, under which authority and limits?","id":"candidate-output-final-selection-packaging-format-digest-and-signature-q02","kind":"identity"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to candidate output, final selection, packaging, format, digest and signature, and which evidence supports them?","id":"candidate-output-final-selection-packaging-format-digest-and-signature-q03","kind":"composition"}]},{"id":"base-data-code-configuration-checkpoint-builder-and-artifact-derivation","name":"Base, data, code, configuration, checkpoint, builder and artifact derivation","description":"Records base, data, code, configuration, checkpoint, builder and artifact derivation as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish base, data, code, configuration, checkpoint, builder and artifact derivation?","id":"base-data-code-configuration-checkpoint-builder-and-artifact-derivation-q01","kind":"provenance"},{"text":"Who may declare, execute, observe, review, correct or rely on base, data, code, configuration, checkpoint, builder and artifact derivation, under which authority and limits?","id":"base-data-code-configuration-checkpoint-builder-and-artifact-derivation-q02","kind":"classification"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to base, data, code, configuration, checkpoint, builder and artifact derivation, and which evidence supports them?","id":"base-data-code-configuration-checkpoint-builder-and-artifact-derivation-q03","kind":"evidence"}]}]},{"id":"reproducibility-nondeterminism-comparison-and-acceptance","name":"Reproducibility, nondeterminism, comparison and acceptance","description":"Groups source-qualified training-run context for reproducibility, nondeterminism, comparison and acceptance.","findings":[{"id":"replay-recipe-randomness-determinism-nondeterminism-and-environment-equivalence","name":"Replay recipe, randomness, determinism, nondeterminism and environment equivalence","description":"Records replay recipe, randomness, determinism, nondeterminism and environment equivalence as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish replay recipe, randomness, determinism, nondeterminism and environment equivalence?","id":"replay-recipe-randomness-determinism-nondeterminism-and-environment-equivalence-q01","kind":"validation"},{"text":"Who may declare, execute, observe, review, correct or rely on replay recipe, randomness, determinism, nondeterminism and environment equivalence, under which authority and limits?","id":"replay-recipe-randomness-determinism-nondeterminism-and-environment-equivalence-q02","kind":"relationship"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to replay recipe, randomness, determinism, nondeterminism and environment equivalence, and which evidence supports them?","id":"replay-recipe-randomness-determinism-nondeterminism-and-environment-equivalence-q03","kind":"ownership"}]},{"id":"baseline-comparison-outcome-quality-safety-compliance-publication-and-deployment-decision","name":"Baseline comparison, outcome, quality, safety, compliance, publication and deployment decision","description":"Records baseline comparison, outcome, quality, safety, compliance, publication and deployment decision as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish baseline comparison, outcome, quality, safety, compliance, publication and deployment decision?","id":"baseline-comparison-outcome-quality-safety-compliance-publication-and-deployment-decision-q01","kind":"decision"},{"text":"Who may declare, execute, observe, review, correct or rely on baseline comparison, outcome, quality, safety, compliance, publication and deployment decision, under which authority and limits?","id":"baseline-comparison-outcome-quality-safety-compliance-publication-and-deployment-decision-q02","kind":"authority"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to baseline comparison, outcome, quality, safety, compliance, publication and deployment decision, and which evidence supports them?","id":"baseline-comparison-outcome-quality-safety-compliance-publication-and-deployment-decision-q03","kind":"measurement"}]}]}]},{"id":"failure-governance-access-retention-correction-and-projections","name":"Failure, governance, access, retention, correction and projections","description":"Groups governed training-run context for failure, governance, access, retention, correction and projections.","layers":[{"id":"failure-cancel-recovery-cleanup-and-records","name":"Failure, cancellation, recovery, cleanup and records","description":"Groups source-qualified training-run context for failure, cancellation, recovery, cleanup and records.","findings":[{"id":"warning-error-failure-early-stop-cancellation-root-cause-and-impact","name":"Warning, error, failure, early stop, cancellation, root cause and impact","description":"Records warning, error, failure, early stop, cancellation, root cause and impact as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish warning, error, failure, early stop, cancellation, root cause and impact?","id":"warning-error-failure-early-stop-cancellation-root-cause-and-impact-q01","kind":"exception"},{"text":"Who may declare, execute, observe, review, correct or rely on warning, error, failure, early stop, cancellation, root cause and impact, under which authority and limits?","id":"warning-error-failure-early-stop-cancellation-root-cause-and-impact-q02","kind":"requirement"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to warning, error, failure, early stop, cancellation, root cause and impact, and which evidence supports them?","id":"warning-error-failure-early-stop-cancellation-root-cause-and-impact-q03","kind":"exception"}]},{"id":"recovery-rollback-cleanup-retention-legal-hold-disposition-and-proof","name":"Recovery, rollback, cleanup, retention, legal hold, disposition and proof","description":"Records recovery, rollback, cleanup, retention, legal hold, disposition and proof as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish recovery, rollback, cleanup, retention, legal hold, disposition and proof?","id":"recovery-rollback-cleanup-retention-legal-hold-disposition-and-proof-q01","kind":"retention"},{"text":"Who may declare, execute, observe, review, correct or rely on recovery, rollback, cleanup, retention, legal hold, disposition and proof, under which authority and limits?","id":"recovery-rollback-cleanup-retention-legal-hold-disposition-and-proof-q02","kind":"constraint"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to recovery, rollback, cleanup, retention, legal hold, disposition and proof, and which evidence supports them?","id":"recovery-rollback-cleanup-retention-legal-hold-disposition-and-proof-q03","kind":"provenance"}]}]},{"id":"access-correction-audit-and-interoperability","name":"Access, correction, audit and interoperability","description":"Groups source-qualified training-run context for access, correction, audit and interoperability.","findings":[{"id":"identity-secret-data-rights-role-purpose-access-audit-correction-and-current-head","name":"Identity, secret, data rights, role, purpose, access, audit, correction and current head","description":"Records identity, secret, data rights, role, purpose, access, audit, correction and current head as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish identity, secret, data rights, role, purpose, access, audit, correction and current head?","id":"identity-secret-data-rights-role-purpose-access-audit-correction-and-current-head-q01","kind":"access"},{"text":"Who may declare, execute, observe, review, correct or rely on identity, secret, data rights, role, purpose, access, audit, correction and current head, under which authority and limits?","id":"identity-secret-data-rights-role-purpose-access-audit-correction-and-current-head-q02","kind":"event"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to identity, secret, data rights, role, purpose, access, audit, correction and current head, and which evidence supports them?","id":"identity-secret-data-rights-role-purpose-access-audit-correction-and-current-head-q03","kind":"process"}]},{"id":"mlflow-mlmd-openlineage-prov-kubeflow-slsa-oci-otel-mlperf-sci-projections","name":"MLflow, MLMD, OpenLineage, PROV, Kubeflow, SLSA, OCI, OpenTelemetry, MLPerf and SCI projections","description":"Records mlflow, mlmd, openlineage, prov, kubeflow, slsa, oci, opentelemetry, mlperf and sci projections as source-qualified training-run context while dataset, source code, base model, trained model artifact, evaluation, registry, deployment, secrets, policy and infrastructure masters remain external.","questions":[{"text":"What stable identity, version-qualified values, scope and explicit unknowns establish mlflow, mlmd, openlineage, prov, kubeflow, slsa, oci, opentelemetry, mlperf and sci projections?","id":"mlflow-mlmd-openlineage-prov-kubeflow-slsa-oci-otel-mlperf-sci-projections-q01","kind":"interoperability"},{"text":"Who may declare, execute, observe, review, correct or rely on mlflow, mlmd, openlineage, prov, kubeflow, slsa, oci, opentelemetry, mlperf and sci projections, under which authority and limits?","id":"mlflow-mlmd-openlineage-prov-kubeflow-slsa-oci-otel-mlperf-sci-projections-q02","kind":"temporal"},{"text":"Which planned, event, effective, recorded, ingested and knowledge times apply to mlflow, mlmd, openlineage, prov, kubeflow, slsa, oci, opentelemetry, mlperf and sci projections, and which evidence supports them?","id":"mlflow-mlmd-openlineage-prov-kubeflow-slsa-oci-otel-mlperf-sci-projections-q03","kind":"validation"}]}]}]}]},"agentConduct":{"may":["Record run configuration, inputs and environment from the training system.","Collect metrics, checkpoints and resource usage.","Propose early stop or resume from a checkpoint for approval.","Compare runs and report differences in inputs and results."],"mustNot":["Allocate compute beyond an approved budget.","Add training data without verified rights or consent.","Expose secrets, protected data or memorized training examples.","Publish or deploy a produced model.","Delete checkpoints or logs needed for audit."],"requiresHuman":["Approving use of a dataset whose rights or consent are unclear.","Selecting a produced artifact as a release candidate.","Approving large compute spend."]},"ethics":{"considerations":["Training data may contain personal data and copyrighted work used without permission.","Bias in data and objectives carries into the model and affects people later.","Large runs have real energy and water costs that should be measured and reported."],"affectedParties":["People whose data or work is in the training set","Future users and subjects of the model","Communities affected by compute energy use"]},"owners":{"steward":"Dimension owner, accountable AI owner and training mandate","roles":[{"name":"AI system owner and accountable deployer","responsibilities":["Own purpose, risk acceptance, release boundaries and accountable use of resulting artifacts."]},{"name":"Model or ML engineer","responsibilities":["Define method and configuration, execute within delegation and preserve reproducible evidence."]},{"name":"Data owner and data steward","responsibilities":["Authorize dataset versions, roles, rights, privacy, quality and permitted transformations."]},{"name":"Platform or infrastructure operator","responsibilities":["Provide approved runtime, resource, telemetry, isolation, secret and incident controls."]},{"name":"Independent evaluator, safety and security reviewer","responsibilities":["Review evaluation, abuse, privacy, security, safety and red-team evidence without becoming the run owner."]},{"name":"Model registry and release steward","responsibilities":["Validate artifact identity, provenance, approval and promotion into separate registry and deployment systems."]},{"name":"Privacy, legal and records steward","responsibilities":["Own lawful processing, intellectual-property, disclosure, correction, hold, retention and disposition profiles."]}],"masterSystems":[]},"relations":[{"target":"WM-DAT-001 Dataset","type":"references","note":"Bind candidate training, validation, evaluation and auxiliary dataset snapshots without owning their content, rights or lifecycle."},{"target":"WM-SFT-004 produced model artifact","type":"references","note":"Represent the candidate PRODUCES ledger edge by a non-owning output reference and derivation record, without granting registry, release, deployment or cascade authority."},{"target":"Source code, base model, tokenizer, evaluation, registry, deployment, infrastructure, secret, policy, provenance, audit and records models","type":"references","note":"Resolve authoritative inputs, controls, evidence and lifecycle records without absorbing their ownership."},{"target":"MLflow, MLMD, OpenLineage, PROV, Kubeflow, SLSA, OCI, OpenTelemetry, MLPerf, SCI and PyTorch","type":"aligned","note":"Project version-pinned execution, lineage, packaging, telemetry, benchmark, environmental and reproducibility views with information-loss declarations."},{"target":"WM-DAT-001 Dataset","type":"neighbor","note":"The candidate REFERENCE relation binds version-qualified dataset roles, splits, permissions and transformations. Dataset content, rights and lifecycle remain external."},{"target":"WM-SFT-004 produced model artifact","type":"neighbor","note":"The candidate PRODUCES relation records derivation and candidate selection. The artifact master, registry promotion, release and deployment remain external."},{"target":"Experiment, pipeline, job, stage, task, attempt and checkpoint","type":"neighbor","note":"The run is one execution aggregate; reusable definitions and independently addressable execution children retain distinct identities and provenance."},{"target":"AI evaluation, model registry and deployment","type":"neighbor","note":"The run may reference evaluations and emit candidates, but evaluation conclusions, promotion decisions, registry state and deployment state are external authorities."},{"target":"Infrastructure, telemetry, cost and environmental systems","type":"neighbor","note":"External systems own allocation, billing, energy and carbon records. The run stores method-bound requested, allocated and observed references and summaries."},{"target":"MLflow, MLMD, OpenLineage, PROV, Kubeflow, SLSA, OCI, OpenTelemetry, MLPerf, SCI and PyTorch","type":"neighbor","note":"These are versioned experiment, metadata, lineage, runtime, provenance, packaging, telemetry, benchmark, carbon and framework profiles. No mapping is universally applicable or assumed lossless."},{"target":"WM-SFT-004","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier for each run, attempt, checkpoint, metric series, event or output binding, qualified by issuer, namespace and record kind.","Governed globally resolvable run IRI.","Dimension UUID or ULID when neither preceding identifier exists."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A training run names a base model or initialization, datasets, code and configuration versions, an objective and start and end times.","Often confused with an experiment, a model artifact, an evaluation run or a pipeline run."]},"capabilities":{"applicability":"required","items":["Register a model training or fine-tuning run: Governed operation to register a model training or fine-tuning run without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Resolve immutable run inputs: Governed operation to resolve immutable run inputs without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Declare method, objective and authority: Governed operation to declare method, objective and authority without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Record dispatch and bind execution: Governed operation to record dispatch and bind execution without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Record progress, resources and telemetry: Governed operation to record progress, resources and telemetry without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Checkpoint, resume and retry: Governed operation to checkpoint, resume and retry without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Record metrics, validation and safety evidence: Governed operation to record metrics, validation and safety evidence without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Finalize, cancel, fail or early-stop a run: Governed operation to finalize, cancel, fail or early-stop a run without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Bind and select a produced model artifact: Governed operation to bind and select a produced model artifact without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup.","Correct, project, retain, disclose and audit: Governed operation to correct, project, retain, disclose and audit without autonomous training, resource acquisition, secret retrieval, privacy decision, release, deployment or destructive cleanup."]},"hazards":{"applicability":"required","items":["Training on leaked, unlicensed or poisoned data.","Lost lineage making a model impossible to audit.","Runaway compute cost from failed restarts.","Secrets exposed through logs or checkpoints."]},"interfaces":{"applicability":"required","items":["W3C PROV-O.","OpenLineage run events.","SLSA provenance for build and training artifacts.","OCI image specification for training environments.","OpenTelemetry for runtime telemetry.","SPDX 3.0 AI and Dataset profiles."]},"context":{"applicability":"required","items":["Training data rights, privacy, intellectual property, security, safety, export, environmental reporting, records and high-risk AI obligations depend on jurisdiction, industry and use case.","The EU AI Act and GDPR are European Union profiles; NIST publications are voluntary United States public-authority guidance unless adopted by policy or contract.","MLflow, MLMD, OpenLineage, Kubeflow, SLSA, OCI, OpenTelemetry, MLPerf, SCI and PyTorch are versioned profiles, not universal lossless schemas."]}},"sources":[{"title":"Artificial Intelligence Risk Management Framework (AI RMF 1.0)","url":"https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10","note":"National Institute of Standards and Technology"},{"title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","note":"National Institute of Standards and Technology"},{"title":"Secure Software Development Practices for Generative AI and Dual-Use Foundation Models","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218A.pdf","note":"National Institute of Standards and Technology"},{"title":"Regulation (EU) 2024/1689 Artificial Intelligence Act","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","note":"European Union"},{"title":"Regulation (EU) 2016/679 General Data Protection Regulation","url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","note":"European Union"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"OpenLineage Object Model","url":"https://openlineage.io/docs/spec/object-model/","note":"OpenLineage"},{"title":"MLflow Tracking","url":"https://mlflow.org/docs/latest/ml/tracking/","note":"MLflow"},{"title":"ML Metadata","url":"https://www.tensorflow.org/tfx/guide/mlmd","note":"TensorFlow"},{"title":"Kubeflow Trainer Overview","url":"https://www.kubeflow.org/docs/components/trainer/overview/","note":"Kubeflow"},{"title":"SLSA Terminology","url":"https://slsa.dev/spec/v1.1/terminology","note":"Open Source Security Foundation"},{"title":"Open Container Initiative Image Format Specification","url":"https://github.com/opencontainers/image-spec/tree/v1.1.1","note":"Open Container Initiative"},{"title":"OpenTelemetry Specification","url":"https://opentelemetry.io/docs/specs/otel/","note":"OpenTelemetry"},{"title":"MLPerf Training","url":"https://mlcommons.org/benchmarks/training/","note":"MLCommons"},{"title":"Software Carbon Intensity Specification","url":"https://sci.greensoftware.foundation/","note":"Green Software Foundation"},{"title":"Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/info/rfc3339/","note":"Internet Engineering Task Force"},{"title":"Reproducibility","url":"https://docs.pytorch.org/docs/2.14/notes/randomness.html","note":"PyTorch"}],"openQuestions":["Approve or reject candidate dataset-reference and produced-model relations and register code, base-model, evaluation, registry, deployment, infrastructure, secret, provenance and records relations.","Create task and method profiles for pretraining, supervised and preference fine-tuning, continual learning, distillation, adapter tuning and other training methods.","Validate jurisdiction and organization-specific data-rights, privacy, intellectual-property, export, security, safety, cost, energy, incident, retention and release policies.","Test release-pinned MLflow, MLMD, OpenLineage, PROV, Kubeflow, SLSA, OCI, OpenTelemetry, MLPerf, SCI and PyTorch mappings with conformance, round-trip and information-loss evidence.","Refresh the NIST AI RMF mapping after a new normative revision and obtain supplemental independent external review before canonical promotion.","Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.","The relation-ledger edges WM-AI-006 REFERENCE WM-DAT-001 and WM-AI-006 PRODUCES WM-SFT-004 are candidates and grant no target ownership, mutation, release or cascade authority.","Pretraining, supervised and preference fine-tuning, continual learning, distillation, adapter tuning and other methods require explicit profiles.","NIST AI RMF 1.0 is under revision; this result pins the inspected 1.0 publication and does not predict the revision."],"resources":{"spec":"/models/wm-ai-006-model-training-fine-tuning-run/spec.yaml","agents":"/models/wm-ai-006-model-training-fine-tuning-run/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/publications/wm-ai-006-model-training-fine-tuning-run"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-ai-006-model-training-fine-tuning-run/spec.yaml","ver-cy/world-models/card-supplements/wm-ai-006-model-training-fine-tuning-run.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-09-06T11:34:09Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}