{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-med-008","code":"wm-med-008-content-provenance-credential","url":"https://ver.cy/models/wm-med-008-content-provenance-credential/","name":"Content Provenance Credential","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"aggregate","plane":"","domain":["INF.MED.PRV"],"industry":["Cross-industry"],"navPath":"NAV.INF.MED.PRV","tags":["content","provenance","credential","inf.med.prv"],"facets":{}},"whatItIs":"Owns content-provenance credential identity and revision; subject asset, rendition, segment and region scope; manifest, claim, assertion and attestation composition; hard and soft content bindings; action, ingredient and derivation references; signer, claim-generator, identity-provider, key, certificate, proof, timestamp and status evidence; embedded, external, repository and durable discovery bindings; validation component results and codes; trust-policy inputs and scoped decision references; human-facing disclosure; privacy, harms, lifecycle, preservation, access, retention, audit and loss-aware interoperability. Media assets, creative works, people, organizations, devices, software, keys, certificates, actions, repositories, rights instruments, evidence and trust decisions remain external masters.","purpose":"Represent an issuer-attributable, integrity-protected and asset-bound set of provenance assertions with verifiable lineage, status, validation and disclosure context.","scope":{"in":["Credential identity, subject and region scope, assertions, manifests, claims, bindings, signatures, times and status","Actions, ingredients, derivation, storage, discovery, recovery, validation, trust inputs and disclosure","Privacy, harms, lifecycle, preservation, access, retention, audit and version-pinned interoperability"],"out":["Owning media-asset, creative-work, party, device, software, key, certificate, action, repository, rights, evidence or accountable trust-decision lifecycles","Treating a hash, filename, URL, watermark, manifest, signature, certificate, trust-list entry, validation result or label as universal asset or credential identity","Inferring factual truth, authorship, copyright, ownership, editorial endorsement, legality, safety or universal trust from provenance or cryptographic validity","Signing, attesting identity, changing trust lists, disclosing protected provenance, revoking credentials or irreversibly deleting records without accountable authority"],"boundaries":[{"neighbor":"WM-MED-002 Media Asset / Rendition","distinction":"The media model owns byte-bearing assets, renditions, technical formats and fixity. This model owns credentials and qualified bindings to those assets without importing media identity."},{"neighbor":"WM-MED-001 Creative Work / Content","distinction":"The work model owns intellectual content and authorship context. Provenance assertions may reference it but do not prove authorship, ownership or truth."},{"neighbor":"C2PA manifest, claim, assertion and manifest store","distinction":"These are profile-specific composition parts or containers. The logical credential record retains their identities and roles without requiring one serialization."},{"neighbor":"Signer, issuer, human identity and organization","distinction":"A signer controls a key, an issuer makes claims, and an optional identity provider attests a person or organization. None is inferred from an asset creator field alone."},{"neighbor":"Validation result and trust decision","distinction":"Validation establishes component outcomes under pinned rules. A verifier separately decides trust for a purpose and context; neither result proves assertion truth."},{"neighbor":"Copyright, rights and editorial policy","distinction":"Credentials can carry or reference rights and editorial assertions, but legal ownership, permission and accountable publication decisions remain external."},{"neighbor":"W3C Verifiable Credential","distinction":"VC 2.0 supplies a broader issuer-holder-verifier claim model. C2PA and VC representations may be mapped only with explicit subject, proof, status and lifecycle semantics."}]},"distinguishingFeatures":["Describes signed claims about how an asset was made and changed, not the media asset or creative work itself.","Binds assertions to exact content through hard or soft bindings, unlike a filename, URL or embedded label.","Differs from a W3C Verifiable Credential about a person: its subject is content and its lineage of ingredients and actions.","A valid signature proves who signed and that content is unchanged, not that the content is true, original or lawful."],"structure":{"bundles":[{"id":"credential-identity-scope-and-asset-binding","name":"Credential identity, scope and asset binding","description":"Groups the governed Resource Consumption concern for credential identity, scope and asset binding.","layers":[{"id":"credential-manifest-claim-and-assertion-boundary","name":"Credential, manifest, claim and assertion boundary","description":"Groups Resource Consumption context for credential, manifest, claim and assertion boundary without importing neighboring master lifecycles.","findings":[{"id":"credential-identifier-namespace-version-issuer-holder-owner-and-master","name":"Credential identifier, namespace, version, issuer, holder, owner and master system","description":"Records credential identifier, namespace, version, issuer, holder, owner and master system as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish credential identifier, namespace, version, issuer, holder, owner and master system?","id":"credential-identifier-namespace-version-issuer-holder-owner-and-master-q01","kind":"identity"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews credential identifier, namespace, version, issuer, holder, owner and master system, and under which authority?","id":"credential-identifier-namespace-version-issuer-holder-owner-and-master-q02","kind":"provenance"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify credential identifier, namespace, version, issuer, holder, owner and master system?","id":"credential-identifier-namespace-version-issuer-holder-owner-and-master-q03","kind":"measurement"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to credential identifier, namespace, version, issuer, holder, owner and master system?","id":"credential-identifier-namespace-version-issuer-holder-owner-and-master-q04","kind":"access"}]},{"id":"manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary","name":"Manifest store, active manifest, claim, assertion, signature and presentation boundary","description":"Records manifest store, active manifest, claim, assertion, signature and presentation boundary as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish manifest store, active manifest, claim, assertion, signature and presentation boundary?","id":"manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-q01","kind":"composition"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews manifest store, active manifest, claim, assertion, signature and presentation boundary, and under which authority?","id":"manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-q02","kind":"ownership"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify manifest store, active manifest, claim, assertion, signature and presentation boundary?","id":"manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-q03","kind":"evidence"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to manifest store, active manifest, claim, assertion, signature and presentation boundary?","id":"manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-q04","kind":"exception"}]}]},{"id":"asset-subject-region-and-content-binding","name":"Asset subject, region and content binding","description":"Groups Resource Consumption context for asset subject, region and content binding without importing neighboring master lifecycles.","findings":[{"id":"asset-rendition-segment-region-resource-and-credential-subject-binding","name":"Asset, rendition, segment, region, resource and credential-subject binding","description":"Records asset, rendition, segment, region, resource and credential-subject binding as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish asset, rendition, segment, region, resource and credential-subject binding?","id":"asset-rendition-segment-region-resource-and-credential-subject-binding-q01","kind":"relationship"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews asset, rendition, segment, region, resource and credential-subject binding, and under which authority?","id":"asset-rendition-segment-region-resource-and-credential-subject-binding-q02","kind":"authority"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify asset, rendition, segment, region, resource and credential-subject binding?","id":"asset-rendition-segment-region-resource-and-credential-subject-binding-q03","kind":"quality"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to asset, rendition, segment, region, resource and credential-subject binding?","id":"asset-rendition-segment-region-resource-and-credential-subject-binding-q04","kind":"interoperability"}]},{"id":"hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery","name":"Hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery","description":"Records hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery?","id":"hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-q01","kind":"evidence"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery, and under which authority?","id":"hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-q02","kind":"requirement"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery?","id":"hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-q03","kind":"validation"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery?","id":"hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-q04","kind":"decision"}]}]}]},{"id":"assertions-actions-ingredients-and-lineage","name":"Assertions, actions, ingredients and lineage","description":"Groups the governed Resource Consumption concern for assertions, actions, ingredients and lineage.","layers":[{"id":"assertion-identity-payload-and-source","name":"Assertion identity, payload and source","description":"Groups Resource Consumption context for assertion identity, payload and source without importing neighboring master lifecycles.","findings":[{"id":"assertion-label-version-instance-schema-format-source-and-claim-reference","name":"Assertion label, version, instance, schema, format, source and claim reference","description":"Records assertion label, version, instance, schema, format, source and claim reference as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish assertion label, version, instance, schema, format, source and claim reference?","id":"assertion-label-version-instance-schema-format-source-and-claim-reference-q01","kind":"definition"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews assertion label, version, instance, schema, format, source and claim reference, and under which authority?","id":"assertion-label-version-instance-schema-format-source-and-claim-reference-q02","kind":"constraint"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify assertion label, version, instance, schema, format, source and claim reference?","id":"assertion-label-version-instance-schema-format-source-and-claim-reference-q03","kind":"security"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to assertion label, version, instance, schema, format, source and claim reference?","id":"assertion-label-version-instance-schema-format-source-and-claim-reference-q04","kind":"identity"}]},{"id":"asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence","name":"Asserted, gathered or attested metadata, digital source type, confidence and evidence","description":"Records asserted, gathered or attested metadata, digital source type, confidence and evidence as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish asserted, gathered or attested metadata, digital source type, confidence and evidence?","id":"asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-q01","kind":"provenance"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews asserted, gathered or attested metadata, digital source type, confidence and evidence, and under which authority?","id":"asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-q02","kind":"process"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify asserted, gathered or attested metadata, digital source type, confidence and evidence?","id":"asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-q03","kind":"privacy"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to asserted, gathered or attested metadata, digital source type, confidence and evidence?","id":"asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-q04","kind":"classification"}]}]},{"id":"actions-ingredients-and-derivation-chain","name":"Actions, ingredients and derivation chain","description":"Groups Resource Consumption context for actions, ingredients and derivation chain without importing neighboring master lifecycles.","findings":[{"id":"capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters","name":"Capture, create, edit, generate, transform or publish action, actor, tool, time and parameters","description":"Records capture, create, edit, generate, transform or publish action, actor, tool, time and parameters as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish capture, create, edit, generate, transform or publish action, actor, tool, time and parameters?","id":"capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-q01","kind":"event"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews capture, create, edit, generate, transform or publish action, actor, tool, time and parameters, and under which authority?","id":"capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-q02","kind":"event"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify capture, create, edit, generate, transform or publish action, actor, tool, time and parameters?","id":"capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-q03","kind":"retention"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to capture, create, edit, generate, transform or publish action, actor, tool, time and parameters?","id":"capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-q04","kind":"composition"}]},{"id":"ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain","name":"Ingredient, parent, derived, composed, rendition relationship, redaction and chain","description":"Records ingredient, parent, derived, composed, rendition relationship, redaction and chain as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish ingredient, parent, derived, composed, rendition relationship, redaction and chain?","id":"ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-q01","kind":"lifecycle"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews ingredient, parent, derived, composed, rendition relationship, redaction and chain, and under which authority?","id":"ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-q02","kind":"measurement"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify ingredient, parent, derived, composed, rendition relationship, redaction and chain?","id":"ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-q03","kind":"access"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to ingredient, parent, derived, composed, rendition relationship, redaction and chain?","id":"ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-q04","kind":"relationship"}]}]}]},{"id":"signer-cryptography-time-and-credential-status","name":"Signer, cryptography, time and credential status","description":"Groups the governed Resource Consumption concern for signer, cryptography, time and credential status.","layers":[{"id":"signer-controller-key-and-signature","name":"Signer, controller, key and signature","description":"Groups Resource Consumption context for signer, controller, key and signature without importing neighboring master lifecycles.","findings":[{"id":"signer-claim-generator-identity-provider-certificate-chain-policy-and-eku","name":"Signer, claim generator, identity provider, certificate chain, policy and extended key usage","description":"Records signer, claim generator, identity provider, certificate chain, policy and extended key usage as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish signer, claim generator, identity provider, certificate chain, policy and extended key usage?","id":"signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-q01","kind":"authority"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews signer, claim generator, identity provider, certificate chain, policy and extended key usage, and under which authority?","id":"signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-q02","kind":"evidence"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify signer, claim generator, identity provider, certificate chain, policy and extended key usage?","id":"signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-q03","kind":"exception"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to signer, claim generator, identity provider, certificate chain, policy and extended key usage?","id":"signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-q04","kind":"state"}]},{"id":"signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest","name":"Signature suite, algorithm, key ID, protected payload, canonicalization and digest","description":"Records signature suite, algorithm, key id, protected payload, canonicalization and digest as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish signature suite, algorithm, key id, protected payload, canonicalization and digest?","id":"signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-q01","kind":"security"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews signature suite, algorithm, key id, protected payload, canonicalization and digest, and under which authority?","id":"signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-q02","kind":"quality"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify signature suite, algorithm, key id, protected payload, canonicalization and digest?","id":"signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-q03","kind":"interoperability"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to signature suite, algorithm, key id, protected payload, canonicalization and digest?","id":"signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-q04","kind":"lifecycle"}]}]},{"id":"trusted-time-status-and-algorithm-lifecycle","name":"Trusted time, status and algorithm lifecycle","description":"Groups Resource Consumption context for trusted time, status and algorithm lifecycle without importing neighboring master lifecycles.","findings":[{"id":"claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks","name":"Claimed signing time, trusted timestamp, validation, ingestion and observation clocks","description":"Records claimed signing time, trusted timestamp, validation, ingestion and observation clocks as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish claimed signing time, trusted timestamp, validation, ingestion and observation clocks?","id":"claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-q01","kind":"temporal"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews claimed signing time, trusted timestamp, validation, ingestion and observation clocks, and under which authority?","id":"claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-q02","kind":"validation"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify claimed signing time, trusted timestamp, validation, ingestion and observation clocks?","id":"claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-q03","kind":"decision"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to claimed signing time, trusted timestamp, validation, ingestion and observation clocks?","id":"claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-q04","kind":"temporal"}]},{"id":"certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility","name":"Certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility","description":"Records certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility?","id":"certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-q01","kind":"lifecycle"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility, and under which authority?","id":"certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-q02","kind":"security"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility?","id":"certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-q03","kind":"identity"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility?","id":"certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-q04","kind":"spatial"}]}]}]},{"id":"storage-discovery-versioning-and-preservation","name":"Storage, discovery, versioning and preservation","description":"Groups the governed Resource Consumption concern for storage, discovery, versioning and preservation.","layers":[{"id":"manifest-store-location-and-durable-discovery","name":"Manifest store location and durable discovery","description":"Groups Resource Consumption context for manifest store location and durable discovery without importing neighboring master lifecycles.","findings":[{"id":"embedded-external-cloud-repository-location-active-selection-and-receipt","name":"Embedded, external, cloud or repository location, active selection and receipt","description":"Records embedded, external, cloud or repository location, active selection and receipt as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish embedded, external, cloud or repository location, active selection and receipt?","id":"embedded-external-cloud-repository-location-active-selection-and-receipt-q01","kind":"access"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews embedded, external, cloud or repository location, active selection and receipt, and under which authority?","id":"embedded-external-cloud-repository-location-active-selection-and-receipt-q02","kind":"privacy"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify embedded, external, cloud or repository location, active selection and receipt?","id":"embedded-external-cloud-repository-location-active-selection-and-receipt-q03","kind":"classification"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to embedded, external, cloud or repository location, active selection and receipt?","id":"embedded-external-cloud-repository-location-active-selection-and-receipt-q04","kind":"provenance"}]},{"id":"soft-binding-query-repository-response-candidate-confidence-collision-and-recovery","name":"Soft-binding query, repository response, candidate confidence, collision and recovery","description":"Records soft-binding query, repository response, candidate confidence, collision and recovery as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish soft-binding query, repository response, candidate confidence, collision and recovery?","id":"soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-q01","kind":"process"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews soft-binding query, repository response, candidate confidence, collision and recovery, and under which authority?","id":"soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-q02","kind":"retention"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify soft-binding query, repository response, candidate confidence, collision and recovery?","id":"soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-q03","kind":"composition"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to soft-binding query, repository response, candidate confidence, collision and recovery?","id":"soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-q04","kind":"ownership"}]}]},{"id":"manifest-lifecycle-preservation-and-failure","name":"Manifest lifecycle, preservation and failure","description":"Groups Resource Consumption context for manifest lifecycle, preservation and failure without importing neighboring master lifecycles.","findings":[{"id":"standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate","name":"Standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate","description":"Records standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate?","id":"standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-q01","kind":"lifecycle"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate, and under which authority?","id":"standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-q02","kind":"access"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate?","id":"standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-q03","kind":"relationship"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate?","id":"standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-q04","kind":"authority"}]},{"id":"removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state","name":"Removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state","description":"Records removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state?","id":"removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-q01","kind":"state"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state, and under which authority?","id":"removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-q02","kind":"exception"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state?","id":"removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-q03","kind":"state"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state?","id":"removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-q04","kind":"requirement"}]}]}]},{"id":"validation-trust-decision-and-human-interpretation","name":"Validation, trust decision and human interpretation","description":"Groups the governed Resource Consumption concern for validation, trust decision and human interpretation.","layers":[{"id":"validation-result-and-trust-policy","name":"Validation result and trust policy","description":"Groups Resource Consumption context for validation result and trust policy without importing neighboring master lifecycles.","findings":[{"id":"well-formed-valid-component-status-code-failure-evidence-validator-and-profile","name":"Well-formed or valid component, status code, failure evidence, validator and profile","description":"Records well-formed or valid component, status code, failure evidence, validator and profile as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish well-formed or valid component, status code, failure evidence, validator and profile?","id":"well-formed-valid-component-status-code-failure-evidence-validator-and-profile-q01","kind":"validation"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews well-formed or valid component, status code, failure evidence, validator and profile, and under which authority?","id":"well-formed-valid-component-status-code-failure-evidence-validator-and-profile-q02","kind":"interoperability"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify well-formed or valid component, status code, failure evidence, validator and profile?","id":"well-formed-valid-component-status-code-failure-evidence-validator-and-profile-q03","kind":"lifecycle"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to well-formed or valid component, status code, failure evidence, validator and profile?","id":"well-formed-valid-component-status-code-failure-evidence-validator-and-profile-q04","kind":"constraint"}]},{"id":"trust-list-anchor-private-store-policy-purpose-context-decision-and-review","name":"Trust list, anchor, private store, policy, purpose, context, decision and review","description":"Records trust list, anchor, private store, policy, purpose, context, decision and review as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish trust list, anchor, private store, policy, purpose, context, decision and review?","id":"trust-list-anchor-private-store-policy-purpose-context-decision-and-review-q01","kind":"decision"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews trust list, anchor, private store, policy, purpose, context, decision and review, and under which authority?","id":"trust-list-anchor-private-store-policy-purpose-context-decision-and-review-q02","kind":"decision"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify trust list, anchor, private store, policy, purpose, context, decision and review?","id":"trust-list-anchor-private-store-policy-purpose-context-decision-and-review-q03","kind":"temporal"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to trust list, anchor, private store, policy, purpose, context, decision and review?","id":"trust-list-anchor-private-store-policy-purpose-context-decision-and-review-q04","kind":"process"}]}]},{"id":"meaning-disclosure-and-accessible-explanation","name":"Meaning, disclosure and accessible explanation","description":"Groups Resource Consumption context for meaning, disclosure and accessible explanation without importing neighboring master lifecycles.","findings":[{"id":"integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction","name":"Integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction","description":"Records integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction?","id":"integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-q01","kind":"classification"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction, and under which authority?","id":"integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-q02","kind":"identity"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction?","id":"integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-q03","kind":"spatial"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction?","id":"integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-q04","kind":"event"}]},{"id":"indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal","name":"Indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal","description":"Records indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal?","id":"indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-q01","kind":"quality"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal, and under which authority?","id":"indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-q02","kind":"classification"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal?","id":"indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-q03","kind":"provenance"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal?","id":"indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-q04","kind":"measurement"}]}]}]},{"id":"privacy-governance-and-interoperability","name":"Privacy, governance and interoperability","description":"Groups the governed Resource Consumption concern for privacy, governance and interoperability.","layers":[{"id":"privacy-safety-harms-and-access-control","name":"Privacy, safety, harms and access control","description":"Groups Resource Consumption context for privacy, safety, harms and access control without importing neighboring master lifecycles.","findings":[{"id":"consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data","name":"Consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data","description":"Records consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data?","id":"consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-q01","kind":"privacy"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data, and under which authority?","id":"consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-q02","kind":"composition"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data?","id":"consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-q03","kind":"ownership"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data?","id":"consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-q04","kind":"evidence"}]},{"id":"surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy","name":"Surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy","description":"Records surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy?","id":"surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-q01","kind":"exception"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy, and under which authority?","id":"surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-q02","kind":"relationship"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy?","id":"surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-q03","kind":"authority"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy?","id":"surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-q04","kind":"quality"}]}]},{"id":"profiles-crosswalk-conformance-and-semantic-loss","name":"Profiles, crosswalk, conformance and semantic loss","description":"Groups Resource Consumption context for profiles, crosswalk, conformance and semantic loss without importing neighboring master lifecycles.","findings":[{"id":"c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk","name":"C2PA, VC, Data Integrity, JOSE, COSE, X.509, PROV, Annotation and IPTC crosswalk","description":"Records c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk?","id":"c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-q01","kind":"interoperability"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk, and under which authority?","id":"c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-q02","kind":"state"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk?","id":"c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-q03","kind":"requirement"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk?","id":"c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-q04","kind":"validation"}]},{"id":"profile-version-license-conformance-transformation-round-trip-and-semantic-loss","name":"Profile, version, license, conformance, transformation, round trip and semantic loss","description":"Records profile, version, license, conformance, transformation, round trip and semantic loss as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.","questions":[{"text":"Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish profile, version, license, conformance, transformation, round trip and semantic loss?","id":"profile-version-license-conformance-transformation-round-trip-and-semantic-loss-q01","kind":"requirement"},{"text":"Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews profile, version, license, conformance, transformation, round trip and semantic loss, and under which authority?","id":"profile-version-license-conformance-transformation-round-trip-and-semantic-loss-q02","kind":"lifecycle"},{"text":"Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify profile, version, license, conformance, transformation, round trip and semantic loss?","id":"profile-version-license-conformance-transformation-round-trip-and-semantic-loss-q03","kind":"constraint"},{"text":"Which security, privacy, retention, disclosure and interoperability checks apply to profile, version, license, conformance, transformation, round trip and semantic loss?","id":"profile-version-license-conformance-transformation-round-trip-and-semantic-loss-q04","kind":"security"}]}]}]}]},"agentConduct":{"may":["Read and validate a provenance credential and report each validation result with its code.","Trace actions and ingredients of an asset back through referenced manifests.","Recover a credential from a repository or durable binding when the embedded copy was stripped.","Show a viewer a minimal provenance summary that respects disclosure rules."],"mustNot":["Present a valid signature or trusted signer as proof of factual truth, authorship or copyright.","Sign or attest a credential with a key the agent does not hold under declared authority.","Strip, alter or re-sign a manifest to hide earlier actions or ingredients.","Treat a missing credential as evidence that content is fake.","Disclose redacted provenance details, such as creator location or identity, to unauthorized recipients.","Change trust lists or revoke credentials on its own judgement."],"requiresHuman":["Issuing a credential under an organization's signing identity.","Revoking a credential or redacting assertions.","Changing the trust policy or trust list used for validation."]},"ethics":{"considerations":["Provenance can expose the identity, location or devices of journalists, activists and sources; redaction must remain possible.","Labels on credentialed content can unfairly discredit authentic content that lacks a credential.","Disclosure of AI generation or editing helps audiences judge content and should not be removed silently.","Trust lists concentrate power over whose content counts as credible."],"affectedParties":["Creators and editors named in assertions","Audiences who rely on provenance labels","People depicted in the content","Sources and witnesses whose safety depends on redaction"]},"owners":{"steward":"Declare the Dimension owner, credential master, issuer authority, signer and key custodian, identity provider, TSA, repository operator, validator, trust-policy owner, privacy steward and independent reviewer.","roles":[{"name":"Dimension owner","responsibilities":["Own namespace, mastership, delegation, access, retention and federation rules."]},{"name":"Credential steward","responsibilities":["Own credential identity, scope, schema, lifecycle, revision and interoperability policy."]},{"name":"Issuer or assertion authority","responsibilities":["Own the meaning, source and authority of credential claims and assertions."]},{"name":"Signer and key custodian","responsibilities":["Control approved signing credentials, proof profiles, rotation and compromise response."]},{"name":"Identity or attestation provider","responsibilities":["Own separately scoped signer, human or organizational identity evidence."]},{"name":"Timestamp or status authority","responsibilities":["Own trusted-time, revocation, suspension and refresh evidence."]},{"name":"Repository and preservation custodian","responsibilities":["Own durable storage, recovery, receipts, retention and revalidation triggers."]},{"name":"Validator or verifier","responsibilities":["Run pinned validation and trust policy, preserving component evidence and limitations."]},{"name":"Privacy and harm reviewer","responsibilities":["Own minimization, consent, redaction, disclosure, misuse and remedy controls."]},{"name":"Independent auditor","responsibilities":["Review identity, binding, proof, trust, validation, lifecycle and access without rewriting originals."]}],"masterSystems":[]},"relations":[{"target":"WM-MED-002 Media Asset / Rendition","type":"composes","note":"Bind credentials to exact media assets, renditions, segments or regions while the media model retains identity and technical mastership."},{"target":"WM-MED-001 Creative Work / Content","type":"references","note":"Resolve intellectual work context without using provenance as proof of authorship, ownership or truth."},{"target":"Party, identity, device, software, key, certificate, action, repository, rights, evidence and decision masters","type":"references","note":"Resolve actors, mechanisms, events, custody, legal context and accountable decisions without importing their lifecycles."},{"target":"C2PA 2.4 Content Credentials, crJSON, Attestations and Soft Binding API","type":"aligned","note":"Project the principal content-provenance ecosystem while preserving format independence and exposing version-specific semantics."},{"target":"C2PA implementation, UX, security, harms, AI/ML, identity and conformance guidance","type":"aligned","note":"Project implementation and governance controls separately from normative credential structure."},{"target":"W3C Verifiable Credentials 2.0, Data Integrity, VC JOSE/COSE, Controlled Identifiers and Bitstring Status","type":"aligned","note":"Project generic credential, proof, controller and status semantics with explicit non-equivalence to C2PA roles."},{"target":"PROV-O and Web Annotation","type":"aligned","note":"Project derivation, activity, agent and region-scoped assertion graphs."},{"target":"COSE, X.509 PKIX and Time-Stamp Protocol","type":"aligned","note":"Project protected envelopes, certificate paths, revocation and trusted-time evidence without making one proof suite canonical."},{"target":"HTTP Digest Fields, JSON Canonicalization and RFC 3339","type":"aligned","note":"Project digest, deterministic representation and unambiguous clock rules where adopted profiles require them."},{"target":"IPTC Photo Metadata and NIST Generative AI Profile","type":"aligned","note":"Project digital-source vocabulary and complementary AI transparency and risk-control context."},{"target":"WM-MED-002 Media Asset / Rendition","type":"neighbor","note":"The media model owns byte-bearing assets, renditions, technical formats and fixity. This model owns credentials and qualified bindings to those assets without importing media identity."},{"target":"WM-MED-001 Creative Work / Content","type":"neighbor","note":"The work model owns intellectual content and authorship context. Provenance assertions may reference it but do not prove authorship, ownership or truth."},{"target":"C2PA manifest, claim, assertion and manifest store","type":"neighbor","note":"These are profile-specific composition parts or containers. The logical credential record retains their identities and roles without requiring one serialization."},{"target":"Signer, issuer, human identity and organization","type":"neighbor","note":"A signer controls a key, an issuer makes claims, and an optional identity provider attests a person or organization. None is inferred from an asset creator field alone."},{"target":"Validation result and trust decision","type":"neighbor","note":"Validation establishes component outcomes under pinned rules. A verifier separately decides trust for a purpose and context; neither result proves assertion truth."},{"target":"Copyright, rights and editorial policy","type":"neighbor","note":"Credentials can carry or reference rights and editorial assertions, but legal ownership, permission and accountable publication decisions remain external."},{"target":"W3C Verifiable Credential","type":"neighbor","note":"VC 2.0 supplies a broader issuer-holder-verifier claim model. C2PA and VC representations may be mapped only with explicit subject, proof, status and lifecycle semantics."},{"target":"WM-XCT-012","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Authoritative credential or manifest identifier issued by the declared credential master.","Issuer-qualified globally resolvable IRI whose subject and revision semantics match the credential.","Adopting-Dimension UUID or ULID when no authoritative external identifier exists."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A provenance credential carries a signed claim, assertions and a content binding, usually in a manifest store.","Confused with plain metadata such as EXIF or XMP, with watermarks and with person-level verifiable credentials."]},"capabilities":{"applicability":"required","items":["Register provenance credential: Create one stable credential identity, subject scope and master authority without claiming media identity or truth.","Compose credential assertions: Add typed assertions and claim references with explicit source, schema, instance, scope and evidence.","Bind credential to content: Create hard or soft bindings to an exact asset, rendition, segment or region.","Record action and ingredient lineage: Append capture, edit, generation, transformation and ingredient relationships without importing their external lifecycles.","Issue and sign credential: Protect a canonical claim with an authorized signing key and an explicitly pinned proof profile.","Timestamp and publish status: Attach trusted-time evidence and publish applicable revocation, suspension or refresh information.","Store, embed or externalize credential: Place a manifest store in or outside an asset while preserving resolvability, receipts and integrity.","Recover durable credential: Use fingerprint or watermark evidence to query repositories and return ranked credential candidates.","Validate credential: Validate structure, claim, signature, time, status, assertions, ingredients and asset binding as separate components.","Evaluate trust and disclose: Apply verifier purpose and trust policy, then present accessible provenance without implying factual truth.","Revise, redact, revoke or tombstone: Append an authorized lifecycle change while preserving prior credential and validation history.","Validate and project crosswalk: Produce version-pinned C2PA, VC, PROV, IPTC or generic projections with explicit semantic loss."]},"hazards":{"applicability":"required","items":["Forged or replayed manifests attached to unrelated content.","Soft-binding matches that link a credential to the wrong asset.","Expired or revoked signing certificates accepted without a time-stamp check.","Privacy harm from provenance fields published without redaction.","Overtrust in content because it shows a provenance badge."]},"interfaces":{"applicability":"required","items":["C2PA Technical Specification for manifests, claims and assertions.","JUMBF, ISO/IEC 19566-5, for embedding manifests.","X.509 certificates and IETF RFC 5280 profile.","COSE signatures, IETF RFC 9052.","Time-Stamp Protocol, IETF RFC 3161.","XMP, ISO 16684-1, for metadata references.","W3C Verifiable Credentials Data Model 2.0 for identity assertions."]},"context":{"applicability":"required","items":["Identity, electronic-signature, evidentiary, copyright, privacy, biometric, consumer-protection, records and disclosure duties depend on jurisdiction and purpose.","C2PA trust lists and conformance results are ecosystem-specific signals and do not create universal legal or factual trust.","IPTC digital-source terms are media-industry vocabulary and must not be treated as complete technical descriptions of AI generation or editing."]}},"sources":[{"title":"Content Credentials: C2PA Technical Specification","url":"https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"Content Credentials JSON File Format","url":"https://spec.c2pa.org/specifications/specifications/2.4/crJSON/crjson-format.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"Attestation in the C2PA Framework","url":"https://spec.c2pa.org/specifications/specifications/1.4/attestations/attestation.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"C2PA Soft Binding API","url":"https://spec.c2pa.org/specifications/specifications/2.4/softbinding/Decoupled.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"C2PA Implementation Guidance","url":"https://spec.c2pa.org/specifications/specifications/2.2/guidance/Guidance.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"C2PA User Experience Guidance","url":"https://spec.c2pa.org/specifications/specifications/2.2/ux/UX_Recommendations.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"C2PA Security Considerations","url":"https://spec.c2pa.org/specifications/specifications/2.4/security/Security_Considerations.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"C2PA Harms Modelling","url":"https://spec.c2pa.org/specifications/specifications/2.4/security/Harms_Modelling.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"Guidance for Artificial Intelligence and Machine Learning","url":"https://spec.c2pa.org/specifications/specifications/2.3/ai-ml/ai_ml.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"Human and Organizational Identity Recommendation","url":"https://spec.c2pa.org/specifications/specifications/2.4/identity/identity.html","note":"Coalition for Content Provenance and Authenticity"},{"title":"C2PA Conformance Explorer","url":"https://spec.c2pa.org/conformance-explorer/","note":"Coalition for Content Provenance and Authenticity"},{"title":"Verifiable Credentials Data Model v2.0","url":"https://www.w3.org/TR/vc-data-model-2.0/","note":"World Wide Web Consortium"},{"title":"Verifiable Credential Data Integrity 1.0","url":"https://www.w3.org/TR/vc-data-integrity/","note":"World Wide Web Consortium"},{"title":"Securing Verifiable Credentials using JOSE and COSE","url":"https://www.w3.org/TR/vc-jose-cose/","note":"World Wide Web Consortium"},{"title":"Controlled Identifiers v1.0","url":"https://www.w3.org/TR/cid-1.0/","note":"World Wide Web Consortium"},{"title":"Bitstring Status List v1.0","url":"https://www.w3.org/TR/vc-bitstring-status-list/","note":"World Wide Web Consortium"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"Web Annotation Data Model","url":"https://www.w3.org/TR/annotation-model/","note":"World Wide Web Consortium"},{"title":"CBOR Object Signing and Encryption Structures","url":"https://www.rfc-editor.org/rfc/rfc9052.html","note":"Internet Engineering Task Force"},{"title":"Internet X.509 Public Key Infrastructure Certificate and CRL Profile","url":"https://www.rfc-editor.org/rfc/rfc5280.html","note":"Internet Engineering Task Force"},{"title":"Internet X.509 Public Key Infrastructure Time-Stamp Protocol","url":"https://www.rfc-editor.org/rfc/rfc3161.html","note":"Internet Engineering Task Force"},{"title":"Digest Fields","url":"https://www.rfc-editor.org/rfc/rfc9530.html","note":"Internet Engineering Task Force"},{"title":"JSON Canonicalization Scheme","url":"https://www.rfc-editor.org/rfc/rfc8785.html","note":"Internet Engineering Task Force"},{"title":"Date and Time on the Internet","url":"https://www.rfc-editor.org/rfc/rfc3339.html","note":"Internet Engineering Task Force"},{"title":"IPTC Photo Metadata User Guide","url":"https://www.iptc.org/std/photometadata/documentation/userguide/","note":"International Press Telecommunications Council"},{"title":"Artificial Intelligence Risk Management Framework: Generative AI Profile","url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","note":"National Institute of Standards and Technology"}],"openQuestions":["Image, video, audio, document, live-stream, model, sensor, news, legal and health-domain specialist profiles for Content Provenance Credential assertions, bindings, validation and trust policies.","Decentralized transparency logs, anonymous credentials, zero-knowledge proofs, post-quantum migration and biometric identity integration as future extensions.","Versioned algorithm migration policies for deprecated or compromised cryptographic algorithms with specific timelines, validator update requirements and legacy credential revalidation paths.","Jurisdiction-specific compliance profiles for EU (eIDAS, GDPR), UK (PSTI), US (state evidence rules, FTC Act), China (state control) and other major regulatory regions addressing electronic-signature validity, evidentiary admissibility, privacy and consent duties.","Soft-binding recovery confidence thresholds, false-positive bounds, collision resolution policies and audit trails for ambiguous fingerprint matches with multiple candidate credentials.","Operational credential revocation, suspension and refresh policies with specific time windows, repository consistency guarantees, offline verifier update mechanisms and legacy trust-anchor lifecycle.","Harm review and remedy frameworks for surveillance, coercion, exclusion, spoofing, re-identification and removal scenarios with specific disclosure, escalation, audit and user-appeal procedures.","Image, video, audio, document, live-stream, model, sensor, news, legal, health and jurisdiction-specific profiles require specialist review.","Media assets, creative works, parties, identities, devices, software, keys, certificates, actions, repositories, rights, evidence and trust decisions remain neighboring masters.","Decentralized transparency logs, anonymous credentials, zero-knowledge proofs, post-quantum migration, biometric identity and forensic truth assessment remain future profiles."],"resources":{"spec":"/models/wm-med-008-content-provenance-credential/spec.yaml","agents":"/models/wm-med-008-content-provenance-credential/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-med-008"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-med-008-content-provenance-credential/spec.yaml","ver-cy/world-models/card-supplements/wm-med-008-content-provenance-credential.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-09-07T11:55:32Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}