{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-per-003","code":"wm-per-003-non-human-agent","url":"https://ver.cy/models/wm-per-003-non-human-agent/","name":"Non-human Agent","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Society, people and institutions","entryKind":"entity","plane":"","domain":["SOC.PER.AGT"],"industry":["Cross-industry"],"navPath":"NAV.SOC.PER.AGT","tags":["non","human","agent","soc.per.agt"],"facets":{}},"whatItIs":"Owns the generic actor identity and kind, definition and instance boundary, control and accountable-party bindings, mandate and delegation envelope, capability and behavior assertions, dependency references, operating state, activity and output attribution, oversight, assurance references, privacy, lifecycle and loss-aware projections. External systems own persons, organizations, software, AI systems and models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence objects.","purpose":"Represent a persistent governed non-human actor with explicit identity, control, delegated authority, capabilities, operating state, attribution, oversight and lifecycle while remaining independent of storage and interface format.","scope":{"in":["Persistent non-human agent identity, issuer, kind, aliases, versions, components and successor lineage","Controller, provider, deployer, operator, principal, beneficiary, affected-party and accountable-party bindings","Mandate, delegation, permission references, capabilities, behavior, dependencies, operating envelope, states, attribution, oversight, assurance, privacy, lifecycle and exchange"],"out":["Human person, organization, software product, AI system, AI model, physical embodiment, task, activity, output, credential, policy, access decision, incident and evidence master lifecycles","Claims that the agent is conscious, sentient, intentional, a legal person, a rights-holder or itself legally liable","AI Agent details already owned by WM-AI-002, physical robotics semantics, universal authorization rules or deployment-specific compliance conclusions"],"boundaries":[{"neighbor":"WM-AI-002 AI Agent","distinction":"AI Agent is a specialization that owns AI-specific model, memory, tools, protocols, evaluation and regulatory context; this model supplies the common non-human actor identity, delegation, attribution and lifecycle core."},{"neighbor":"Software, AI System and AI Model","distinction":"Software and models are components or implementations; the governed actor has its own persistent identity, controller, authority and state and may change components without silent identity replacement."},{"neighbor":"Robot, Device and Embodiment","distinction":"A physical body owns geometry, material, pose, mechanics and safety details; this model records only the agent-to-embodiment binding and delegated physical operating envelope."},{"neighbor":"Session, Run, Task and Activity","distinction":"These are bounded execution or work records; the agent is the durable actor referenced from each and keeps only correlation and attribution links."},{"neighbor":"Credential, Access and Policy","distinction":"Credentials and policies provide evidence and authorization inputs; possession or technical ability does not establish current permission."},{"neighbor":"Legal or moral subject","distinction":"Technical autonomy and provenance responsibility do not establish consciousness, intention, rights, duties, personhood or liability; those conclusions require external law, evidence and authority."}]},"distinguishingFeatures":["Covers any non-human actor that acts, including software agents, robots and automated systems, not only AI agents.","Every agent is bound to a controlling and an accountable party.","Separates the agent definition from its running instances.","Makes no claim about consciousness, legal personhood or moral status."],"structure":{"bundles":[{"id":"identity-kind-and-instance-boundary","name":"Identity, kind and instance boundary","description":"Identifies the persistent governed agent and separates it from implementations, deployments, endpoints and sessions.","layers":[{"id":"persistent-identity-and-lineage","name":"Persistent identity and lineage","description":"Stable identifiers, aliases, versions and successor history for the governed actor.","findings":[{"id":"authoritative-agent-identifier-and-master-system","name":"Authoritative agent identifier and master system","description":"The stable actor identifier, issuing authority, namespace, master system, resolution state and local bindings.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for authoritative agent identifier and master system?","id":"authoritative-agent-identifier-and-master-system-q01","kind":"identity"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes authoritative agent identifier and master system, at what event, valid and knowledge time, and with what confidence?","id":"authoritative-agent-identifier-and-master-system-q02","kind":"evidence"},{"text":"How may authoritative agent identifier and master system be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"authoritative-agent-identifier-and-master-system-q03","kind":"validation"}]},{"id":"aliases-version-specialization-and-successor-lineage","name":"Aliases, version, specialization and successor lineage","description":"Names, protocol identifiers, definition versions, specializations, replacements, merges and retirement lineage without identity collapse.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for aliases, version, specialization and successor lineage?","id":"aliases-version-specialization-and-successor-lineage-q01","kind":"lifecycle"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes aliases, version, specialization and successor lineage, at what event, valid and knowledge time, and with what confidence?","id":"aliases-version-specialization-and-successor-lineage-q02","kind":"evidence"},{"text":"How may aliases, version, specialization and successor lineage be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"aliases-version-specialization-and-successor-lineage-q03","kind":"validation"}]}]},{"id":"kind-composition-and-boundary","name":"Kind, composition and boundary","description":"Classification criteria and the distinction among actor, definition, deployment, endpoint, embodiment and session.","findings":[{"id":"nonhuman-agent-kind-and-classification-criteria","name":"Non-human agent kind and classification criteria","description":"Profile-qualified kind such as software, embodied, hybrid or collective machine actor, with observable criteria and prohibited subjecthood inferences.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for non-human agent kind and classification criteria?","id":"nonhuman-agent-kind-and-classification-criteria-q01","kind":"classification"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes non-human agent kind and classification criteria, at what event, valid and knowledge time, and with what confidence?","id":"nonhuman-agent-kind-and-classification-criteria-q02","kind":"evidence"},{"text":"How may non-human agent kind and classification criteria be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"nonhuman-agent-kind-and-classification-criteria-q03","kind":"validation"}]},{"id":"agent-definition-deployment-endpoint-embodiment-session-boundary","name":"Agent, definition, deployment, endpoint, embodiment and session boundary","description":"Typed component and realization references with separate identifiers, masters, versions and lifecycles.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for agent, definition, deployment, endpoint, embodiment and session boundary?","id":"agent-definition-deployment-endpoint-embodiment-session-boundary-q01","kind":"composition"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes agent, definition, deployment, endpoint, embodiment and session boundary, at what event, valid and knowledge time, and with what confidence?","id":"agent-definition-deployment-endpoint-embodiment-session-boundary-q02","kind":"evidence"},{"text":"How may agent, definition, deployment, endpoint, embodiment and session boundary be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"agent-definition-deployment-endpoint-embodiment-session-boundary-q03","kind":"validation"}]}]}]},{"id":"control-accountability-and-stakeholders","name":"Control, accountability and stakeholders","description":"Records who creates, controls, operates, benefits from and remains answerable for the agent.","layers":[{"id":"control-and-operating-parties","name":"Control and operating parties","description":"Time-qualified bindings for parties with technical or organizational control.","findings":[{"id":"owner-controller-provider-and-deployer-bindings","name":"Owner, controller, provider and deployer bindings","description":"External party references, role basis, control surface, jurisdiction, validity and change history.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for owner, controller, provider and deployer bindings?","id":"owner-controller-provider-and-deployer-bindings-q01","kind":"relationship"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes owner, controller, provider and deployer bindings, at what event, valid and knowledge time, and with what confidence?","id":"owner-controller-provider-and-deployer-bindings-q02","kind":"evidence"},{"text":"How may owner, controller, provider and deployer bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"owner-controller-provider-and-deployer-bindings-q03","kind":"validation"}]},{"id":"operator-beneficiary-customer-and-affected-party-bindings","name":"Operator, beneficiary, customer and affected-party bindings","description":"Operational, beneficiary, service-recipient and affected-party roles with scope, time and source.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for operator, beneficiary, customer and affected-party bindings?","id":"operator-beneficiary-customer-and-affected-party-bindings-q01","kind":"relationship"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes operator, beneficiary, customer and affected-party bindings, at what event, valid and knowledge time, and with what confidence?","id":"operator-beneficiary-customer-and-affected-party-bindings-q02","kind":"evidence"},{"text":"How may operator, beneficiary, customer and affected-party bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"operator-beneficiary-customer-and-affected-party-bindings-q03","kind":"validation"}]}]},{"id":"accountability-and-responsibility","name":"Accountability and responsibility","description":"Answerability, escalation and the boundary between provenance responsibility and legal conclusions.","findings":[{"id":"accountable-party-oversight-owner-and-escalation-contact","name":"Accountable party, oversight owner and escalation contact","description":"Who answers for deployment and use, receives escalation and has power to intervene, with delegated scope and availability.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for accountable party, oversight owner and escalation contact?","id":"accountable-party-oversight-owner-and-escalation-contact-q01","kind":"authority"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes accountable party, oversight owner and escalation contact, at what event, valid and knowledge time, and with what confidence?","id":"accountable-party-oversight-owner-and-escalation-contact-q02","kind":"evidence"},{"text":"How may accountable party, oversight owner and escalation contact be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"accountable-party-oversight-owner-and-escalation-contact-q03","kind":"validation"}]},{"id":"activity-responsibility-attribution-versus-liability-and-personhood","name":"Activity responsibility attribution versus liability and personhood","description":"PROV responsibility claims and explicit non-inference of intention, consciousness, legal personality, rights, duties or liability.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for activity responsibility attribution versus liability and personhood?","id":"activity-responsibility-attribution-versus-liability-and-personhood-q01","kind":"provenance"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes activity responsibility attribution versus liability and personhood, at what event, valid and knowledge time, and with what confidence?","id":"activity-responsibility-attribution-versus-liability-and-personhood-q02","kind":"evidence"},{"text":"How may activity responsibility attribution versus liability and personhood be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"activity-responsibility-attribution-versus-liability-and-personhood-q03","kind":"validation"}]}]}]},{"id":"authority-mandate-and-delegation","name":"Authority, mandate and delegation","description":"Defines the purpose-bound authority under which the agent may act.","layers":[{"id":"principal-mandate-and-delegation-chain","name":"Principal, mandate and delegation chain","description":"The accountable principal, mandate, purpose and traceable chain of acting on behalf of another.","findings":[{"id":"principal-mandate-purpose-resource-jurisdiction-and-interval","name":"Principal, mandate, purpose, resource, jurisdiction and interval","description":"The source authority, permitted purposes and targets, territorial or logical scope and validity interval.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for principal, mandate, purpose, resource, jurisdiction and interval?","id":"principal-mandate-purpose-resource-jurisdiction-and-interval-q01","kind":"authority"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes principal, mandate, purpose, resource, jurisdiction and interval, at what event, valid and knowledge time, and with what confidence?","id":"principal-mandate-purpose-resource-jurisdiction-and-interval-q02","kind":"evidence"},{"text":"How may principal, mandate, purpose, resource, jurisdiction and interval be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"principal-mandate-purpose-resource-jurisdiction-and-interval-q03","kind":"validation"}]},{"id":"delegation-chain-subdelegation-conditions-and-revocation","name":"Delegation chain, subdelegation, conditions and revocation","description":"Each delegator, delegate, allowed onward delegation, conditions, expiry, suspension and revocation effect.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for delegation chain, subdelegation, conditions and revocation?","id":"delegation-chain-subdelegation-conditions-and-revocation-q01","kind":"relationship"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes delegation chain, subdelegation, conditions and revocation, at what event, valid and knowledge time, and with what confidence?","id":"delegation-chain-subdelegation-conditions-and-revocation-q02","kind":"evidence"},{"text":"How may delegation chain, subdelegation, conditions and revocation be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"delegation-chain-subdelegation-conditions-and-revocation-q03","kind":"validation"}]}]},{"id":"permission-credentials-and-policy","name":"Permission, credentials and policy","description":"External policy and credential evidence that constrains actions at decision time.","findings":[{"id":"permission-prohibition-duty-constraint-and-approval-gate","name":"Permission, prohibition, duty, constraint and approval gate","description":"Referenced policy rules, actions, targets, conditions, duties, exceptions and human or organizational confirmation class.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for permission, prohibition, duty, constraint and approval gate?","id":"permission-prohibition-duty-constraint-and-approval-gate-q01","kind":"security"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes permission, prohibition, duty, constraint and approval gate, at what event, valid and knowledge time, and with what confidence?","id":"permission-prohibition-duty-constraint-and-approval-gate-q02","kind":"evidence"},{"text":"How may permission, prohibition, duty, constraint and approval gate be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"permission-prohibition-duty-constraint-and-approval-gate-q03","kind":"validation"}]},{"id":"credential-scope-audience-holder-validity-and-status","name":"Credential scope, audience, holder, validity and status","description":"Credential references and observations with issuer, subject, audience, proof, expiry and status while secrets stay external.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for credential scope, audience, holder, validity and status?","id":"credential-scope-audience-holder-validity-and-status-q01","kind":"evidence"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes credential scope, audience, holder, validity and status, at what event, valid and knowledge time, and with what confidence?","id":"credential-scope-audience-holder-validity-and-status-q02","kind":"evidence"},{"text":"How may credential scope, audience, holder, validity and status be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"credential-scope-audience-holder-validity-and-status-q03","kind":"validation"}]}]}]},{"id":"capability-behaviour-constraints-and-dependencies","name":"Capability, behaviour, constraints and dependencies","description":"Describes what the agent can do, how it behaves and the envelope in which claims remain valid.","layers":[{"id":"capabilities-skills-and-interfaces","name":"Capabilities, skills and interfaces","description":"Declared and observed action surfaces plus machine-readable access bindings.","findings":[{"id":"declared-observed-and-verified-capability-surface","name":"Declared, observed and verified capability surface","description":"Actions, inputs, outputs, quality limits, confidence, evaluation basis and contexts in which the capability is available.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for declared, observed and verified capability surface?","id":"declared-observed-and-verified-capability-surface-q01","kind":"requirement"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes declared, observed and verified capability surface, at what event, valid and knowledge time, and with what confidence?","id":"declared-observed-and-verified-capability-surface-q02","kind":"evidence"},{"text":"How may declared, observed and verified capability surface be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"declared-observed-and-verified-capability-surface-q03","kind":"validation"}]},{"id":"skill-protocol-interface-action-property-and-event-bindings","name":"Skill, protocol, interface, action, property and event bindings","description":"Versioned A2A, WoT or domain binding references with authentication, media, schema and negotiation metadata.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for skill, protocol, interface, action, property and event bindings?","id":"skill-protocol-interface-action-property-and-event-bindings-q01","kind":"interoperability"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes skill, protocol, interface, action, property and event bindings, at what event, valid and knowledge time, and with what confidence?","id":"skill-protocol-interface-action-property-and-event-bindings-q02","kind":"evidence"},{"text":"How may skill, protocol, interface, action, property and event bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"skill-protocol-interface-action-property-and-event-bindings-q03","kind":"validation"}]}]},{"id":"behaviour-state-and-transition","name":"Behaviour, state and transition","description":"Observable response patterns and governed operational states.","findings":[{"id":"behaviour-policy-mode-trigger-and-observable-signature","name":"Behaviour policy, mode, trigger and observable signature","description":"Expected responses under stated conditions, recognizable signatures, confidence, prohibited inference and drift indicators.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for behaviour policy, mode, trigger and observable signature?","id":"behaviour-policy-mode-trigger-and-observable-signature-q01","kind":"process"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes behaviour policy, mode, trigger and observable signature, at what event, valid and knowledge time, and with what confidence?","id":"behaviour-policy-mode-trigger-and-observable-signature-q02","kind":"evidence"},{"text":"How may behaviour policy, mode, trigger and observable signature be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"behaviour-policy-mode-trigger-and-observable-signature-q03","kind":"validation"}]},{"id":"registered-configured-ready-active-paused-degraded-and-stopped-state","name":"Registered, configured, ready, active, paused, degraded and stopped state","description":"Current state, allowed transitions, actor and authority, reason, event and valid times, safe-state target and history.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for registered, configured, ready, active, paused, degraded and stopped state?","id":"registered-configured-ready-active-paused-degraded-and-stopped-state-q01","kind":"state"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes registered, configured, ready, active, paused, degraded and stopped state, at what event, valid and knowledge time, and with what confidence?","id":"registered-configured-ready-active-paused-degraded-and-stopped-state-q02","kind":"evidence"},{"text":"How may registered, configured, ready, active, paused, degraded and stopped state be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"registered-configured-ready-active-paused-degraded-and-stopped-state-q03","kind":"validation"}]}]},{"id":"dependencies-envelope-hazards-and-failure","name":"Dependencies, envelope, hazards and failure","description":"Conditions and components on which capability and safe behaviour depend.","findings":[{"id":"tool-model-memory-service-and-embodiment-dependencies","name":"Tool, model, memory, service and embodiment dependencies","description":"Pinned external component references, trust state, version, availability, data boundary and degraded-mode effect.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for tool, model, memory, service and embodiment dependencies?","id":"tool-model-memory-service-and-embodiment-dependencies-q01","kind":"composition"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes tool, model, memory, service and embodiment dependencies, at what event, valid and knowledge time, and with what confidence?","id":"tool-model-memory-service-and-embodiment-dependencies-q02","kind":"evidence"},{"text":"How may tool, model, memory, service and embodiment dependencies be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"tool-model-memory-service-and-embodiment-dependencies-q03","kind":"validation"}]},{"id":"operating-envelope-prohibition-hazard-failure-and-recovery","name":"Operating envelope, prohibition, hazard, failure and recovery","description":"Resource, time, cost, environment and safety limits, forbidden actions, failure signatures, containment and recovery path.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for operating envelope, prohibition, hazard, failure and recovery?","id":"operating-envelope-prohibition-hazard-failure-and-recovery-q01","kind":"constraint"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes operating envelope, prohibition, hazard, failure and recovery, at what event, valid and knowledge time, and with what confidence?","id":"operating-envelope-prohibition-hazard-failure-and-recovery-q02","kind":"evidence"},{"text":"How may operating envelope, prohibition, hazard, failure and recovery be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"operating-envelope-prohibition-hazard-failure-and-recovery-q03","kind":"validation"}]}]}]},{"id":"operation-attribution-and-oversight","name":"Operation, attribution and oversight","description":"Connects agent state and execution context to activities, outputs and intervention controls.","layers":[{"id":"activation-deployment-and-session-context","name":"Activation, deployment and session context","description":"Which approved configuration is active where and how executions correlate to it.","findings":[{"id":"deployment-configuration-release-and-activation-binding","name":"Deployment, configuration, release and activation binding","description":"Pinned external deployment and configuration references, approval, environment, activation authority and effective interval.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for deployment, configuration, release and activation binding?","id":"deployment-configuration-release-and-activation-binding-q01","kind":"composition"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes deployment, configuration, release and activation binding, at what event, valid and knowledge time, and with what confidence?","id":"deployment-configuration-release-and-activation-binding-q02","kind":"evidence"},{"text":"How may deployment, configuration, release and activation binding be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"deployment-configuration-release-and-activation-binding-q03","kind":"validation"}]},{"id":"session-run-correlation-and-temporal-context","name":"Session, run, correlation and temporal context","description":"External session and run references, correlation identifiers and distinct event, valid, observation, knowledge and ingestion times.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for session, run, correlation and temporal context?","id":"session-run-correlation-and-temporal-context-q01","kind":"temporal"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes session, run, correlation and temporal context, at what event, valid and knowledge time, and with what confidence?","id":"session-run-correlation-and-temporal-context-q02","kind":"evidence"},{"text":"How may session, run, correlation and temporal context be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"session-run-correlation-and-temporal-context-q03","kind":"validation"}]}]},{"id":"activity-and-output-attribution","name":"Activity and output attribution","description":"Traceable associations among agent, activity, principal, plan, inputs and outputs.","findings":[{"id":"activity-association-plan-role-and-delegation-attribution","name":"Activity association, plan, role and delegation attribution","description":"Which agent was associated with an activity, in which role, under which plan and on whose behalf.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for activity association, plan, role and delegation attribution?","id":"activity-association-plan-role-and-delegation-attribution-q01","kind":"provenance"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes activity association, plan, role and delegation attribution, at what event, valid and knowledge time, and with what confidence?","id":"activity-association-plan-role-and-delegation-attribution-q02","kind":"evidence"},{"text":"How may activity association, plan, role and delegation attribution be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"activity-association-plan-role-and-delegation-attribution-q03","kind":"validation"}]},{"id":"output-entity-generation-attribution-and-derivation","name":"Output entity generation, attribution and derivation","description":"Generated or influenced output references, activity, sources, agent version and provenance bundle.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for output entity generation, attribution and derivation?","id":"output-entity-generation-attribution-and-derivation-q01","kind":"provenance"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes output entity generation, attribution and derivation, at what event, valid and knowledge time, and with what confidence?","id":"output-entity-generation-attribution-and-derivation-q02","kind":"evidence"},{"text":"How may output entity generation, attribution and derivation be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"output-entity-generation-attribution-and-derivation-q03","kind":"validation"}]}]},{"id":"oversight-intervention-and-safe-state","name":"Oversight, intervention and safe state","description":"Approval, monitoring, interruption, handoff and containment controls.","findings":[{"id":"human-or-organizational-oversight-approval-and-intervention","name":"Human or organizational oversight, approval and intervention","description":"Oversight role, competence reference, information supplied, approval gates, intervention controls and response evidence.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for human or organizational oversight, approval and intervention?","id":"human-or-organizational-oversight-approval-and-intervention-q01","kind":"authority"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes human or organizational oversight, approval and intervention, at what event, valid and knowledge time, and with what confidence?","id":"human-or-organizational-oversight-approval-and-intervention-q02","kind":"evidence"},{"text":"How may human or organizational oversight, approval and intervention be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"human-or-organizational-oversight-approval-and-intervention-q03","kind":"validation"}]},{"id":"monitoring-alert-escalation-suspension-handoff-and-failsafe","name":"Monitoring, alert, escalation, suspension, handoff and fail-safe","description":"Signals, thresholds, accountable recipient, timeout, suspension authority, safe-state behavior and recovery confirmation.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for monitoring, alert, escalation, suspension, handoff and fail-safe?","id":"monitoring-alert-escalation-suspension-handoff-and-failsafe-q01","kind":"process"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes monitoring, alert, escalation, suspension, handoff and fail-safe, at what event, valid and knowledge time, and with what confidence?","id":"monitoring-alert-escalation-suspension-handoff-and-failsafe-q02","kind":"evidence"},{"text":"How may monitoring, alert, escalation, suspension, handoff and fail-safe be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"monitoring-alert-escalation-suspension-handoff-and-failsafe-q03","kind":"validation"}]}]}]},{"id":"assurance-evidence-privacy-and-lifecycle","name":"Assurance, evidence, privacy and lifecycle","description":"Records bounded assurance claims, observations, incidents and durable lifecycle governance.","layers":[{"id":"assurance-monitoring-and-incidents","name":"Assurance, monitoring and incidents","description":"Risk, evaluation, limitation, telemetry and incident references.","findings":[{"id":"risk-evaluation-assurance-limitation-and-acceptance","name":"Risk, evaluation, assurance, limitation and acceptance","description":"External assessment references, test context, metrics, thresholds, residual risks, approver, validity and non-claims.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for risk, evaluation, assurance, limitation and acceptance?","id":"risk-evaluation-assurance-limitation-and-acceptance-q01","kind":"validation"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes risk, evaluation, assurance, limitation and acceptance, at what event, valid and knowledge time, and with what confidence?","id":"risk-evaluation-assurance-limitation-and-acceptance-q02","kind":"evidence"},{"text":"How may risk, evaluation, assurance, limitation and acceptance be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"risk-evaluation-assurance-limitation-and-acceptance-q03","kind":"validation"}]},{"id":"monitoring-drift-anomaly-incident-impact-and-corrective-action","name":"Monitoring, drift, anomaly, incident, impact and corrective action","description":"Observed signals and externally mastered incident or corrective-action references with severity, scope and status.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for monitoring, drift, anomaly, incident, impact and corrective action?","id":"monitoring-drift-anomaly-incident-impact-and-corrective-action-q01","kind":"evidence"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes monitoring, drift, anomaly, incident, impact and corrective action, at what event, valid and knowledge time, and with what confidence?","id":"monitoring-drift-anomaly-incident-impact-and-corrective-action-q02","kind":"evidence"},{"text":"How may monitoring, drift, anomaly, incident, impact and corrective action be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"monitoring-drift-anomaly-incident-impact-and-corrective-action-q03","kind":"validation"}]}]},{"id":"privacy-retention-and-agent-lifecycle","name":"Privacy, retention and agent lifecycle","description":"Purpose-bound disclosure and governed suspension, retirement and tombstoning.","findings":[{"id":"data-category-purpose-access-disclosure-retention-and-deletion","name":"Data category, purpose, access, disclosure, retention and deletion","description":"Field and artifact sensitivity, purpose, audience, access policy, retention class, legal hold and disposition evidence.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for data category, purpose, access, disclosure, retention and deletion?","id":"data-category-purpose-access-disclosure-retention-and-deletion-q01","kind":"privacy"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes data category, purpose, access, disclosure, retention and deletion, at what event, valid and knowledge time, and with what confidence?","id":"data-category-purpose-access-disclosure-retention-and-deletion-q02","kind":"evidence"},{"text":"How may data category, purpose, access, disclosure, retention and deletion be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"data-category-purpose-access-disclosure-retention-and-deletion-q03","kind":"validation"}]},{"id":"suspension-revocation-retirement-replacement-and-tombstone","name":"Suspension, revocation, retirement, replacement and tombstone","description":"Authorized lifecycle endings, surviving delegations and credentials, successor, endpoint withdrawal, retention and durable identity tombstone.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for suspension, revocation, retirement, replacement and tombstone?","id":"suspension-revocation-retirement-replacement-and-tombstone-q01","kind":"lifecycle"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes suspension, revocation, retirement, replacement and tombstone, at what event, valid and knowledge time, and with what confidence?","id":"suspension-revocation-retirement-replacement-and-tombstone-q02","kind":"evidence"},{"text":"How may suspension, revocation, retirement, replacement and tombstone be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"suspension-revocation-retirement-replacement-and-tombstone-q03","kind":"validation"}]}]}]},{"id":"interoperability-governance-and-agent-operations","name":"Interoperability, governance and agent operations","description":"Controls projections, mapping loss and safe automated maintenance.","layers":[{"id":"profiles-projections-and-mapping-loss","name":"Profiles, projections and mapping loss","description":"Versioned external representations and explicit non-equivalence.","findings":[{"id":"prov-agent-softwareagent-association-and-delegation-projection","name":"PROV Agent, SoftwareAgent, association and delegation projection","description":"Loss-aware mapping of agent identity, activity association, attribution and acted-on-behalf-of relations.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for prov agent, softwareagent, association and delegation projection?","id":"prov-agent-softwareagent-association-and-delegation-projection-q01","kind":"interoperability"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes prov agent, softwareagent, association and delegation projection, at what event, valid and knowledge time, and with what confidence?","id":"prov-agent-softwareagent-association-and-delegation-projection-q02","kind":"evidence"},{"text":"How may prov agent, softwareagent, association and delegation projection be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"prov-agent-softwareagent-association-and-delegation-projection-q03","kind":"validation"}]},{"id":"a2a-agent-card-wot-description-and-credential-projection","name":"A2A Agent Card, WoT description and credential projection","description":"Versioned discovery, affordance and proof projections with authentication, disclosure, omission and round-trip limits.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for a2a agent card, wot description and credential projection?","id":"a2a-agent-card-wot-description-and-credential-projection-q01","kind":"interoperability"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes a2a agent card, wot description and credential projection, at what event, valid and knowledge time, and with what confidence?","id":"a2a-agent-card-wot-description-and-credential-projection-q02","kind":"evidence"},{"text":"How may a2a agent card, wot description and credential projection be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"a2a-agent-card-wot-description-and-credential-projection-q03","kind":"validation"}]}]},{"id":"safe-agent-control-and-validation","name":"Safe agent control and validation","description":"Authorized operations, invariants, concurrency and recovery.","findings":[{"id":"operation-authority-purpose-preconditions-idempotency-and-evidence","name":"Operation authority, purpose, preconditions, idempotency and evidence","description":"Classifies each read, bind, delegate, activate, suspend, attribute, disclose and retire action with proof and effect.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for operation authority, purpose, preconditions, idempotency and evidence?","id":"operation-authority-purpose-preconditions-idempotency-and-evidence-q01","kind":"security"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes operation authority, purpose, preconditions, idempotency and evidence, at what event, valid and knowledge time, and with what confidence?","id":"operation-authority-purpose-preconditions-idempotency-and-evidence-q02","kind":"evidence"},{"text":"How may operation authority, purpose, preconditions, idempotency and evidence be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"operation-authority-purpose-preconditions-idempotency-and-evidence-q03","kind":"validation"}]},{"id":"prewrite-postwrite-validation-conflict-concurrency-and-recovery","name":"Pre-write and post-write validation, conflict, concurrency and recovery","description":"Identity, boundary, authority, state, time, provenance, privacy, stale-head and rollback checks with immutable audit evidence.","questions":[{"text":"What exact values, references, qualifiers and explicit unknowns must be recorded for pre-write and post-write validation, conflict, concurrency and recovery?","id":"prewrite-postwrite-validation-conflict-concurrency-and-recovery-q01","kind":"validation"},{"text":"Which controller, operator, principal, authority, observation and evidence establishes pre-write and post-write validation, conflict, concurrency and recovery, at what event, valid and knowledge time, and with what confidence?","id":"prewrite-postwrite-validation-conflict-concurrency-and-recovery-q02","kind":"evidence"},{"text":"How may pre-write and post-write validation, conflict, concurrency and recovery be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?","id":"prewrite-postwrite-validation-conflict-concurrency-and-recovery-q03","kind":"validation"}]}]}]}]},"agentConduct":{"may":["Declare its own identity, controller, mandate and capabilities.","Attribute its outputs and actions to itself in records.","Report its operating state and errors.","Refuse tasks outside its mandate."],"mustNot":["Act outside its delegated mandate.","Pretend to be a human or another agent.","Delegate authority it does not have.","Hide its accountable party when asked.","Claim rights, sentience or legal personhood."],"requiresHuman":["Granting or extending mandates.","Deploying agents that act in the physical world or with financial effect.","Decommissioning an agent with ongoing obligations."]},"ethics":{"considerations":["People must know when they deal with a machine and who is responsible for it.","Accountability gaps appear when agents act through long delegation chains.","Claims about agent sentience can mislead and manipulate users."],"affectedParties":["People interacting with agents","Controllers and accountable parties","Third parties affected by agent actions"]},"owners":{"steward":"Dimension identity, owner, agent registrar, delegation authority, oversight owner and namespace","roles":[{"name":"Dimension owner","responsibilities":["Own namespace, mastership, delegation, access, retention and federation rules."]},{"name":"Agent registrar","responsibilities":["Maintain persistent identity, kind, boundary, aliases and successor lineage."]},{"name":"Controller or provider","responsibilities":["Declare the controlled agent and maintain accurate configuration, capability and limitation references."]},{"name":"Deployer or operator","responsibilities":["Operate only within current delegation and envelope and preserve activation, oversight and incident evidence."]},{"name":"Delegating principal","responsibilities":["Grant, constrain, suspend and revoke purpose-bound authority within its own authority."]},{"name":"Accountable and oversight owner","responsibilities":["Review consequential action, intervene, receive escalation and accept or reject residual risk."]},{"name":"Safety, privacy and access steward","responsibilities":["Apply minimum disclosure, monitoring, incident, retention and security controls."]},{"name":"Independent auditor","responsibilities":["Review identity, delegation, state, attribution, controls and evidence without rewriting source records."]}],"masterSystems":[]},"relations":[{"target":"WM-AI-002 AI Agent","type":"child","note":"Reuse the generic governed actor core while AI-specific model, memory, tool, protocol, evaluation and regulation semantics stay in the specialization."},{"target":"Person, Organization, Software, AI System, AI Model, Embodiment, Task, Activity, Output, Policy, Credential, Incident and Evidence models","type":"references","note":"Connect the agent to externally mastered parties, components, executions, rules and evidence without identity or lifecycle duplication."},{"target":"W3C PROV-DM and PROV-O","type":"aligned","note":"Project agent, SoftwareAgent, association, attribution, delegation, specialization and revision provenance."},{"target":"A2A Protocol Specification","type":"aligned","note":"Publish an optional discovery and protocol projection through Agent Cards, skills, capabilities and interfaces."},{"target":"ODRL Information Model 2.2 and Verifiable Credentials Data Model 2.0","type":"aligned","note":"Represent purpose-bound authority policy and portable evidence without importing authorization or credential lifecycles."},{"target":"Web of Things Thing Description 1.1","type":"aligned","note":"Project optional properties, actions, events, forms and security metadata for networked or embodied agent interfaces."},{"target":"WM-AI-002 AI Agent","type":"neighbor","note":"AI Agent is a specialization that owns AI-specific model, memory, tools, protocols, evaluation and regulatory context; this model supplies the common non-human actor identity, delegation, attribution and lifecycle core."},{"target":"Software, AI System and AI Model","type":"neighbor","note":"Software and models are components or implementations; the governed actor has its own persistent identity, controller, authority and state and may change components without silent identity replacement."},{"target":"Robot, Device and Embodiment","type":"neighbor","note":"A physical body owns geometry, material, pose, mechanics and safety details; this model records only the agent-to-embodiment binding and delegated physical operating envelope."},{"target":"Session, Run, Task and Activity","type":"neighbor","note":"These are bounded execution or work records; the agent is the durable actor referenced from each and keeps only correlation and attribution links."},{"target":"Credential, Access and Policy","type":"neighbor","note":"Credentials and policies provide evidence and authorization inputs; possession or technical ability does not establish current permission."},{"target":"Legal or moral subject","type":"neighbor","note":"Technical autonomy and provenance responsibility do not establish consciousness, intention, rights, duties, personhood or liability; those conclusions require external law, evidence and authority."}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier for the governed agent, qualified by issuer.","Governed globally resolvable agent IRI with explicit master-system binding.","Adopting-Dimension UUID or ULID when no authoritative external identifier exists."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A non-human agent has an identifier, a kind, a controller, an accountable party and a mandate.","It is confused with the software product it runs on, with its human operator and with a service account."]},"capabilities":{"applicability":"required","items":["Register non-human agent: Create the persistent actor identity, kind, master binding and explicit boundaries.","Bind control and accountability parties: Append time-qualified owner, controller, provider, deployer, operator and accountable-party bindings.","Grant purpose-bound delegation: Attach an authorized mandate with principal, purpose, resources, interval, constraints and subdelegation rule.","Constrain, suspend or revoke delegation: Reduce or end delegated authority without erasing prior grants or activity provenance.","Declare capability and limits: Record declared, observed or verified ability with context, evidence, confidence and prohibitions.","Bind interface and dependency: Pin a protocol, skill, tool, model, memory, service or embodiment and state its trust and degraded-mode effect.","Transition operational state: Activate, pause, degrade, suspend, stop or recover the agent under a valid transition and authority.","Attribute activity or output: Link an external activity or entity to the exact agent, role, plan, delegation, version and execution context.","Request approval or escalate: Route an action, ambiguity, threshold breach or loss-of-control condition to the accountable authority.","Attach assurance or incident evidence: Reference an evaluation, limitation, risk acceptance, monitoring observation, incident or corrective action.","Project agent profile: Produce a purpose-bound PROV, A2A, WoT or credential view with explicit omissions and mapping loss.","Retire non-human agent: End authority and operation, withdraw discoverability, reconcile credentials and preserve a durable tombstone."]},"hazards":{"applicability":"required","items":["Actions beyond mandate through prompt injection or misconfiguration.","Impersonation of humans or other agents.","Unclear liability after harm."]},"interfaces":{"applicability":"required","items":["W3C Decentralized Identifiers (DIDs) 1.0.","OAuth 2.0 (RFC 6749) for delegated authorization.","ISO/IEC 42001 AI management systems.","Model Context Protocol (MCP)."]},"context":{"applicability":"required","items":["The EU AI Act supplies an EU AI-system profile and does not govern every non-human agent or create universal subject status.","PROV responsibility attribution is a provenance relation and does not decide legal accountability or liability in any jurisdiction.","A2A, WoT, ODRL and Verifiable Credentials are optional interoperability profiles, not mandatory storage or interface formats."]}},"sources":[{"title":"PROV-DM: The PROV Data Model","url":"https://www.w3.org/TR/prov-dm/","note":"World Wide Web Consortium"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"AI Risk Management Framework: Audience","url":"https://airc.nist.gov/airmf-resources/airmf/2-sec-audience/","note":"National Institute of Standards and Technology"},{"title":"A2A Protocol Specification","url":"https://a2a-protocol.org/latest/specification/","note":"A2A Project under the Linux Foundation"},{"title":"Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","note":"European Union"},{"title":"ODRL Information Model 2.2","url":"https://www.w3.org/TR/odrl-model/","note":"World Wide Web Consortium"},{"title":"Verifiable Credentials Data Model v2.0","url":"https://www.w3.org/TR/vc-data-model-2.0/","note":"World Wide Web Consortium"},{"title":"Time Ontology in OWL","url":"https://www.w3.org/TR/owl-time/","note":"World Wide Web Consortium"},{"title":"Web of Things Thing Description 1.1","url":"https://www.w3.org/TR/wot-thing-description11/","note":"World Wide Web Consortium"},{"title":"Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/rfc/rfc3339","note":"Internet Engineering Task Force"}],"openQuestions":["Review the parent and child split with WM-AI-002 and approve exact field ownership, dependency direction and version compatibility.","Approve model identifiers and relation cardinalities for persons, organizations, software, AI systems, models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence.","Develop specialist profiles for software services, embodied robots, autonomous vehicles, swarms, animals and any future legally recognized electronic subject.","Create deterministic fixtures for identity replacement, controller changes, nested delegation, stale credentials, dependency loss, safe-state entry, disputed attribution and private-agent discovery.","Validate certified provenance, discovery, affordance, policy and credential projections with explicit disclosure, loss and round-trip tests.","No independent Claude or Grok result was available; this source-grounded Codex fallback requires later external review before canonical promotion.","WM-AI-002 AI Agent, software, AI system, model, robot or embodiment, task, activity, credential, access, incident and evidence models retain their own detailed semantics.","Animal, swarm, autonomous vehicle, industrial robot, legal electronic person and other jurisdiction or embodiment profiles require specialist review and must not be inferred from this common core.","The frozen relation ledger contains no approved WM-PER-003 dependency rows; composition targets remain descriptive holds until registry relations are reviewed.","Certified PROV, A2A, WoT, ODRL and credential crosswalks, conformance fixtures and round-trip tests remain future work."],"resources":{"spec":"/models/wm-per-003-non-human-agent/spec.yaml","agents":"/models/wm-per-003-non-human-agent/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-per-003"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-per-003-non-human-agent/spec.yaml","ver-cy/world-models/card-supplements/wm-per-003-non-human-agent.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-09-06T01:44:47Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}