{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-rec-013","code":"wm-rec-013-operational-log-trace","url":"https://ver.cy/models/wm-rec-013-operational-log-trace/","name":"Operational Log / Trace","alternateNames":[],"kind":"world-model","status":"published","version":"0.1.0","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"aggregate","plane":"","domain":["INF.REC.LOG"],"industry":["Cross-industry"],"navPath":"NAV.INF.REC.LOG","tags":["operational","log","trace","inf.rec.log"],"facets":{}},"whatItIs":"An operational log or trace is an append-oriented record of technical or business events, written as they happen and kept as evidence of what a system or process did. It covers log streams, audit trails and stored traces as records with retention and integrity duties; live monitoring signals used only for operations are a neighbouring subject.","purpose":"Represent append-oriented technical or business event evidence as a governed retained record.","scope":{"in":["Capture identity, provenance, entry interpretation and uncertain time.","Retained trace relationships, sampling and integrity evidence.","Record access, retention, correction lineage and controlled extracts."],"out":["Live monitoring, alert evaluation, instrumentation deployment and operational control.","Business transaction execution, incident response and adjudication of factual truth or legal admissibility.","Generic records platform implementation, storage engine and cryptographic protocol implementation."],"boundaries":[{"neighbor":"WM-REC-001 Document / Record","distinction":"Registry parent is a candidate generic record alignment; this proposal specializes append-oriented evidence without assuming a validated inherited schema."},{"neighbor":"WM-SFT-017 Telemetry / Operational Signal","distinction":"Telemetry may feed this record; the retained capture has explicit membership, custody and disposition. Live signals and monitoring behavior stay external."},{"neighbor":"WM-ACT-020 Cyber Incident","distinction":"Incident references can explain preservation purpose, but classification and incident response are not owned here."},{"neighbor":"Producer, actor and business operation masters","distinction":"Record assertions and references only; a span status or log message does not change the referenced operation."}]},"distinguishingFeatures":["It is kept as evidence with retention and integrity duties, not only as a live signal.","Entries are appended in time order and are corrected by new entries, not edited.","It covers business audit trails as well as technical logs and stored traces.","Distinct from telemetry used for live monitoring, though the same entries may feed both."],"structure":{"bundles":[{"id":"REC013-B1","name":"Log source and content","description":"Where entries come from and what they contain.","layers":[{"id":"REC013-B1-L1","name":"Source and schema","description":"The producing system and the structure of entries.","findings":[{"id":"REC013-F01","name":"Producing source","description":"The system, component or process that writes the log.","questions":[{"text":"Which system or process wrote the entries, and under which configuration?","id":"REC013-Q01"},{"text":"Which fields and event types does each entry contain?","id":"REC013-Q02"}]},{"id":"REC013-F02","name":"Time and ordering","description":"Timestamps, clock source and sequence of entries.","questions":[{"text":"Which clock source and time zone do the timestamps use?","id":"REC013-Q03"},{"text":"Can the order of entries be established reliably across sources?","id":"REC013-Q04"}]}]}]},{"id":"REC013-B2","name":"Integrity and retention","description":"Whether the record can serve as evidence.","layers":[{"id":"REC013-B2-L1","name":"Integrity","description":"Protection against change and loss.","findings":[{"id":"REC013-F03","name":"Tamper evidence","description":"Controls that show whether entries were altered or removed.","questions":[{"text":"Is the log protected against alteration, for example by hashing or write-once storage?","id":"REC013-Q05"},{"text":"Are there gaps in sequence numbers or time that suggest lost entries?","id":"REC013-Q06"}]}]},{"id":"REC013-B2-L2","name":"Retention","description":"How long entries are kept and when they are destroyed.","findings":[{"id":"REC013-F04","name":"Retention rule","description":"The retention period and its legal or policy basis.","questions":[{"text":"Which retention period applies, and on what basis?","id":"REC013-Q07"},{"text":"Is any entry under legal hold that prevents deletion?","id":"REC013-Q08"}]}]}]},{"id":"REC013-B3","name":"Access and use","description":"Who may read the log and for what.","layers":[{"id":"REC013-B3-L1","name":"Access control","description":"Permissions and purpose of reading.","findings":[{"id":"REC013-F05","name":"Read access","description":"Who read the log and why.","questions":[{"text":"Who has access to the log, and is each access itself recorded?","id":"REC013-Q09"},{"text":"Does the log contain personal data, and is it masked where possible?","id":"REC013-Q10"}]}]}]}]},"agentConduct":{"may":["Search and summarise log entries within granted access for a stated purpose.","Correlate entries across sources by time and trace identifiers.","Flag gaps, clock skew or signs of tampering.","Report on retention compliance of log stores."],"mustNot":["Edit or delete log entries outside the retention rules.","Disable logging or reduce its scope without authorisation.","Use logs to monitor individual employees beyond what policy and law allow.","Expose secrets or personal data found in log entries.","Delete entries under legal hold."],"requiresHuman":["Placing or lifting a legal hold on logs.","Approving release of logs to external parties such as investigators.","Changing retention periods for audit logs."]},"ethics":{"considerations":["Logs often contain personal data and can enable surveillance of users and staff.","Reliable logs are needed to establish accountability after incidents and disputes.","Retaining logs too long increases exposure; deleting them too early destroys evidence."],"affectedParties":["Users whose actions are logged","Employees and operators","Security and audit teams","Investigators and regulators"]},"owners":{"steward":"The system owner, with the security or records function, answers for logging, retention and access.","roles":[{"name":"record custodian","responsibilities":["Approve scope and accountable policy bindings."]},{"name":"capture operator","responsibilities":["Record collection and export quality without altering source assertions."]},{"name":"authorized analyst","responsibilities":["Read purpose-limited views and label inference and uncertainty."]},{"name":"records reviewer","responsibilities":["Review retention, preservation and disposition evidence."]},{"name":"security reviewer","responsibilities":["Review integrity trust basis and disclosure restrictions."]}],"masterSystems":["Log management platforms","Security information and event management systems","Audit trail stores"]},"relations":[{"target":"WM-REC-001","type":"aligned","note":"Candidate registry parent alignment; pin a reviewed record profile before inheritance."},{"target":"WM-SFT-017","type":"references","note":"Optional source signal reference; no monitoring lifecycle is imported."},{"target":"WM-ACT-020","type":"references","note":"Optional incident reference for evidence use and preservation; no incident response execution."},{"target":"W3C Trace Context","type":"aligned","note":"Optional trace identifier projection, with explicit version and trust-boundary policy."},{"target":"OpenTelemetry logs and traces","type":"aligned","note":"Optional mappings with field loss and revision pins; no implementation conformance implied."},{"target":"IETF syslog","type":"aligned","note":"Optional message and signed-evidence profiles; transport and cryptographic deployment remain external."},{"target":"W3C PROV-O","type":"aligned","note":"Optional provenance vocabulary for derivatives and attribution."},{"target":"WM-REC-001 Document / Record","type":"neighbor","note":"Registry parent is a candidate generic record alignment; this proposal specializes append-oriented evidence without assuming a validated inherited schema."},{"target":"WM-SFT-017 Telemetry / Operational Signal","type":"neighbor","note":"Telemetry may feed this record; the retained capture has explicit membership, custody and disposition. Live signals and monitoring behavior stay external."},{"target":"WM-ACT-020 Cyber Incident","type":"neighbor","note":"Incident references can explain preservation purpose, but classification and incident response are not owned here."},{"target":"Producer, actor and business operation masters","type":"neighbor","note":"Record assertions and references only; a span status or log message does not change the referenced operation."},{"target":"WM-REC-001","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["A log is identified by its source system, stream or file name and the time range covered.","Entries carry timestamps and, where available, sequence numbers and trace or request identifiers."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A log has timestamped, append-only entries from a named source under a retention rule.","Often confused with live metrics dashboards, configuration records or ordinary documents."]},"capabilities":{"applicability":"required","items":["Entries can be collected, indexed, correlated, archived and destroyed on schedule.","Logs can be sealed or hashed to provide tamper evidence."]},"hazards":{"applicability":"required","items":["Leakage of credentials or personal data written into logs.","Loss or tampering that removes evidence after an incident.","Misleading conclusions from unsynchronised clocks across sources."]},"interfaces":{"applicability":"required","items":["IETF RFC 5424 Syslog Protocol.","W3C Trace Context for trace identifiers.","OpenTelemetry log and trace data models."]},"context":{"applicability":"required","items":["Used in IT operations, security monitoring, financial audit and regulatory compliance.","Retention and access are shaped by data protection law and sector record-keeping rules."]}},"sources":[{"title":"Logs Data Model","url":"https://opentelemetry.io/docs/specs/otel/logs/data-model/","note":"OpenTelemetry project"},{"title":"Tracing API","url":"https://opentelemetry.io/docs/specs/otel/trace/api/","note":"OpenTelemetry project"},{"title":"Trace Context","url":"https://www.w3.org/TR/trace-context/","note":"World Wide Web Consortium"},{"title":"RFC 5424: The Syslog Protocol","url":"https://www.rfc-editor.org/rfc/rfc5424","note":"Internet Engineering Task Force"},{"title":"SP 800-92: Guide to Computer Security Log Management","url":"https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-92.pdf","note":"National Institute of Standards and Technology"},{"title":"RFC 5848: Signed Syslog Messages","url":"https://www.rfc-editor.org/rfc/rfc5848","note":"Internet Engineering Task Force"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"Tracing SDK","url":"https://opentelemetry.io/docs/specs/otel/trace/sdk/","note":"OpenTelemetry project"},{"title":"NIST SP 800-92 Guide to Computer Security Log Management (NIST)"}],"openQuestions":["Pin source revisions and compatible log, trace and propagation profiles; review errata and current integrity requirements.","Develop nested schemas and fixtures for delayed entries, missing parents, duplicate IDs, sampled spans, redaction, partial export and disposition across copies.","Obtain independent external review and qualified sector policy review before promotion beyond reviewable-draft.","No independently reviewed external-provider result.","Direct HTTP checks are not executed in the blocked sandbox; source versions, errata and immutable living-document pins remain open.","Candidate object groups are not executable nested instance schemas; adapters, scale testing and adversarial fixtures remain future work.","Sector-specific audit obligations, privacy applicability and business audit semantics require qualified profile review.","Historical integrity references do not establish current algorithm suitability."],"resources":{"spec":"/models/wm-rec-013-operational-log-trace/spec.yaml","agents":"/models/wm-rec-013-operational-log-trace/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-rec-013"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-rec-013-operational-log-trace/spec.yaml","ver-cy/world-models/card-supplements/wm-rec-013-operational-log-trace.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-10-06T12:20:14Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"An operational log is an information record with no physical properties to measure.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-06, unreviewed). Written from the card's existing content and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}