{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-001","code":"wm-xct-001-ownership-stewardship","url":"https://ver.cy/models/wm-xct-001-ownership-stewardship/","name":"Ownership / Stewardship","alternateNames":["S1"],"kind":"world-model","status":"published","version":"0.3.1-enterprise.1","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.OWN"],"industry":["Cross-industry"],"navPath":"NAV.XCT.OWN","tags":["ownership","stewardship","xct.own"],"facets":{}},"whatItIs":"This model records assertions of control over a referenced meta-object: the binding of one or more parties to that object in a named control modality (legal title, beneficial interest, custody, administrative controllership, or de-facto technical control), the fractions and co-holding rules that partition it, the encumbrances and holder duties that qualify it, the stewardship and delegated-authority arrangements through which someone other than the holder may act, the substitute or supported decision-making arrangements used where a holder cannot act unaided, and the instruments and events by which control is created, suspended, transferred, succeeded, lapsed or extinguished. It also records the evidentiary basis, assurance and temporal validity of each such assertion, and the governance of the control register itself. It deliberately models control as a time-bounded, source-backed, contestable assertion rather than as a fact, because no register can guarantee that its record matches the underlying legal or physical position.","purpose":"Provide the reusable control facet that can be attached to any meta-object so that an agent can determine who holds it, who may lawfully act for the holder, under what basis and constraints, and how control moved or will move — independently of what the object itself is.","scope":{"in":["Binding of holders/controllers to a referenced meta-object, including group and collective holders, in an explicit control modality","Fractional, joint and several holding, share restructuring and co-holder decision rules","Encumbrances, restrictions and holder responsibilities that qualify control without transferring it","Steward, custodian and processor appointments where operation is separated from beneficial holding","Scoped, revocable delegation of control powers, sub-delegation, and the representation-versus-impersonation distinction","Capacity-related arrangements: supported decision-making, substitute decision-making and their mandatory safeguards and review","Transfer instruments, exclusivity of control, conditions precedent, succession, lapse, abandonment and escheat","Chain-of-title reconstruction, competing claims, dispute status and priority ordering","Evidentiary sources, assurance level, staleness and validity intervals of every control assertion","Authority, recording effect, access, audit, retention and interoperability of the control register itself"],"out":["Identity, attributes and lifecycle of the parties themselves (natural persons, organizations, agents) — held in the person and organization models","Runtime authorization decisions, policy evaluation and enforcement — the access-contract model consumes control records but is not defined here","Substantive intellectual-property rights, licence terms and usage permissions over content, which are rights-in-the-work rather than control-of-the-object","Valuation, price, accounting treatment, tax position and payment settlement of transferred objects","Adjudication procedure for disputed title — only the dispute status and the ingested outcome are held here","Data lineage and derivation history of the object's content, which belong to the provenance model","Physical or logical custody mechanics (storage location, replication, key management) beyond the fact of a custody appointment","Determination of whether any given jurisdiction actually recognises a claimed right; this model records the claimed basis and its evidence, not its legal validity"],"boundaries":[{"neighbor":"Person / Organization models","distinction":"This model holds only a reference and a role for each party (holder, steward, delegate, supported person, beneficial owner). Party identity, legal form, capacity determination and existence lifecycle are resolved externally; a control record must not restate them. LADM makes the same split between LA_Party and the RRR that binds it."},{"neighbor":"Access / authorization contract model","distinction":"Control answers 'who may grant'; access answers 'who may do what, now'. An ODRL-style Policy names an assigner; this model is what makes an assigner's standing checkable. Permission evaluation, obligations discharge and enforcement stay in the access model."},{"neighbor":"Provenance / lineage model","distinction":"PROV attribution and delegation describe responsibility for entities and activities. This model reuses that shape for who acts for whom, but its subject is a standing control relation with validity intervals, not a past activity trace. Where both exist, the control record is the assertion and the provenance record is its trace."},{"neighbor":"Rights and licensing (IPR) model","distinction":"dcterms:rightsHolder conflates owning and managing rights over a resource. This model separates control of the meta-object from rights in the work it represents: a custodian may control a record without holding any IP right in its content, and a rights holder may hold no control record."},{"neighbor":"Audit / evidence log model","distinction":"Every write to, and privileged read of, a control record is an auditable event, but the audit trail itself is a separate append-only model. This model declares what must be logged and by whom, not the log's own structure."},{"neighbor":"Identity credential / key management model","distinction":"Cryptographic control (a verification method authorized for capabilityInvocation) is evidence of control, not the control record. Key rotation is not a transfer of ownership; conflating them makes an operator into an owner. The controlled-identifier document is an artifact this model cites, not one it owns."},{"neighbor":"Dispute resolution / courts model","distinction":"This model carries a dispute flag, the competing claims and the ingested outcome reference. Procedure, evidence weighing and remedies belong to the dispute model; a control record must never encode an adjudication."}]},"distinguishingFeatures":["Records who controls an object and on what basis, not who may read it, which is the access model.","Separates legal title, beneficial holding, stewardship and delegated authority as distinct positions.","Transfers and mandates are append-only events, so the chain of title can be reconstructed.","Exclusive control is enforced at write time: two concurrent dispositions of the same object are rejected."],"structure":{"bundles":[{"id":"control-anchor","name":"Controllability and Anchoring","description":"What makes a meta-object subject to a control record at all, how that record is identified and versioned, which modality of control is asserted, and on what basis.","layers":[{"id":"object-binding","name":"Object Binding and Record Identity","description":"The reference from a control assertion to the meta-object it governs, the controllability of that object, and the identity and version discipline of the assertion itself.","findings":[{"id":"controllable-object-anchor","name":"Controllable object anchor","description":"A control record binds to exactly one referenced meta-object. The reference must resolve, and the object must be of a kind that can bear control: MLETR and UCC Article 12 both gate control on the record being susceptible to exclusive control, and CID makes control turn on the ability to update a canonical resource. Objects that are pure abstractions, aggregates without a canonical instance, or copies without a single authoritative instance are not controllable and must be flagged rather than silently given an owner.","questions":[{"text":"Which single meta-object does this control assertion govern, and does that reference resolve to a canonical instance rather than a copy or a class?","id":"q-anchor-target","kind":"identity"},{"text":"Is the object susceptible to exclusive control, or does it exist as indefinitely reproducible copies with no authoritative instance?","id":"q-anchor-controllable","kind":"classification"},{"text":"Does control extend to the whole object or only to a defined part, aspect or bundle of it?","id":"q-anchor-scope","kind":"composition"},{"text":"If the object is an aggregate, is control asserted over the aggregate, over each member, or over both with different holders?","id":"q-anchor-aggregate","kind":"relationship"}]},{"id":"control-record-identity-versioning","name":"Control record identity and versioning","description":"Identity and version discipline for the assertion itself. LADM derives its core classes from a versioned object with an object identifier, so that a superseded holding remains addressable rather than being overwritten. A control record must therefore be immutably identified, carry a version lineage, and never be identified by the date on which it took effect.","questions":[{"text":"Which identifier authority governs this control record: an authoritative master register, a governed global IRI, or a locally minted UUID/ULID?","id":"q-identity-priority","kind":"identity"},{"text":"Which prior version does this record supersede, and is the superseded version still resolvable?","id":"q-version-lineage","kind":"provenance"},{"text":"Does this new version correct an error in the prior record or record a real-world change of control?","id":"q-correction-vs-change","kind":"classification"}]}]},{"id":"control-nature","name":"Modality and Basis of Control","description":"Which kind of control is being asserted and what makes the assertion admissible.","findings":[{"id":"control-modality-classification","name":"Control modality classification","description":"'Ownership' is not a single relation. The sources support at least five distinguishable modalities: legal title or tenure right (LADM LA_Right), beneficial interest (AMLR beneficial owner), custody or possession-equivalent control (MLETR, UCC-12), administrative controllership and accountability (GDPR controller; NIST information owner; ISO/IEC 27002 asset owner), and de-facto technical control (CID controller). These have different transfer rules, different evidence and different consequences; the EU Data Act explicitly refuses to convert a data holder's position into a new right. The modality must therefore be an explicit, non-defaulted field.","questions":[{"text":"Which control modality does this record assert — legal title, beneficial interest, custody, administrative controllership, or de-facto technical control?","id":"q-modality-which","kind":"classification"},{"text":"Do several modalities over this object coexist with different parties, and are they recorded as separate assertions rather than merged?","id":"q-modality-stack","kind":"relationship"},{"text":"Does the asserted modality carry a transferable right, or only accountability without any proprietary claim?","id":"q-modality-implications","kind":"authority"},{"text":"If the modality is unknown, is the record held as unclassified rather than defaulted to legal title?","id":"q-modality-defaulting","kind":"exception"}]},{"id":"basis-of-control","name":"Basis and admissibility of control","description":"Every control assertion must name the ground that created it and the source document evidencing that ground — LADM binds each class to a source, and MLETR conditions control on a reliable method being used. The basis distinguishes a first registration from a derivative acquisition, and records whether the recording itself is constitutive of the right or merely declaratory of it, which changes what an agent may infer from a silent register.","questions":[{"text":"What legal, contractual, customary or administrative ground creates this control, and is it original or derivative?","id":"q-basis-ground","kind":"provenance"},{"text":"Which source documents evidence the basis, and what is their type and reliability?","id":"q-basis-evidence","kind":"evidence"},{"text":"Is recording in this register constitutive of the control, or merely declaratory of a control that exists independently?","id":"q-basis-recording-effect","kind":"authority"},{"text":"If the basis is customary, communal or informal, is it recorded as legitimate rather than as an absence of tenure?","id":"q-basis-informal","kind":"exception"}]},{"id":"governing-law-and-situs","name":"Applicable law and situs","description":"HCCH Articles 6–8: a trust is governed by the law chosen by the settlor or, failing that, the law of closest connection, ascertained especially from place of administration, situs of assets, residence of the trustee, and objects of the trust. Article 9 allows a severable aspect, particularly administration, to be governed by a different law. Article 15 lists mandatory forum rules that cannot be derogated from by voluntary act. DCMI coverage and Jurisdiction describe spatial applicability or the jurisdiction under which a resource is relevant. FAO VGGT is implemented through national strategies and legislation; it is not self-executing title. Lex rei sitae for tangible objects, lex societatis for legal persons, and chosen trust law may therefore diverge for one meta-object; the mixin records each pointer rather than picking a single world law.","questions":[{"text":"Which law governs this holding or trust, was it chosen or selected by closest connection, and what is the situs of the assets or administration?","id":"governing-law-and-situs-q01","kind":"authority"},{"text":"Are administration or other severable aspects governed by a different law, and which mappings apply?","id":"governing-law-and-situs-q02","kind":"composition"},{"text":"Which HCCH Article 15 mandatory categories (minors, marriage, succession, security interests, insolvency, good faith) override the chosen law for this object?","id":"governing-law-and-situs-q03","kind":"exception"},{"text":"Through which national policy or statute, if any, are VGGT tenure principles applied to this object?","id":"governing-law-and-situs-q04","kind":"interoperability"}]}]}]},{"id":"holding","name":"Holding, Shares and Encumbrances","description":"Who holds the object, in what proportions and under which co-holder decision rules, what encumbers the holding, and what duties the holding carries.","layers":[{"id":"holder-identification","name":"Holder Identification","description":"Binding parties to the object in holder roles, including group and collective holders, and separating the party of record from the party who actually benefits.","findings":[{"id":"holder-party-binding","name":"Holder party binding","description":"The holder side is a set of party references with declared roles, resolved against the person and organization models. LADM distinguishes an individual party from a group party with members, which is what allows a community, a household, a partnership or an unincorporated body to hold without being forced into a legal-person shape. The binding carries a role and a validity interval, not the party's attributes.","questions":[{"text":"Which parties are bound as holders of this object, and in which role does each stand?","id":"q-holder-who","kind":"ownership"},{"text":"Is the holder an individual party or a group party, and if a group, is its membership enumerated or defined by rule?","id":"q-holder-group","kind":"composition"},{"text":"Does every party reference resolve in the person or organization model, and what happens when one does not?","id":"q-holder-resolution","kind":"validation"},{"text":"If no holder can currently be identified, is the object recorded as holder-unknown with a search obligation rather than left with a stale holder?","id":"q-holder-unknown","kind":"exception"}]},{"id":"legal-versus-beneficial-holder","name":"Legal versus beneficial holder","description":"The party of record is not always the party who benefits. AMLR requires adequate, accurate and up-to-date beneficial ownership information precisely because nominee, trustee and layered structures separate the two. Modelling only the record holder makes the register systematically misleading; modelling only the beneficiary makes it unusable for transfer. Both must be recordable, separately sourced and separately access-controlled.","questions":[{"text":"Who ultimately benefits from or controls this object behind the party of record, and through which intermediate chain?","id":"q-beneficial-who","kind":"ownership"},{"text":"Is any party of record acting as a nominee, trustee or custodian for another, and is that fact disclosed on the record?","id":"q-beneficial-nominee","kind":"relationship"},{"text":"How recently was the beneficial-holder information verified, and by what method?","id":"q-beneficial-currency","kind":"quality"},{"text":"Who may see the beneficial-holder layer, given that general public access to such data has been held disproportionate?","id":"q-beneficial-access","kind":"access"}]}]},{"id":"shares-and-coholding","name":"Shares and Co-Holding","description":"How a single holding is partitioned among co-holders and how co-holders decide.","findings":[{"id":"fractional-and-joint-holding","name":"Fractional and joint holding","description":"LADM's generic conceptual model provides an explicit Fraction class precisely because shares must be exact and must sum correctly. Beyond the arithmetic, co-holding needs a decision rule: whether a disposal requires unanimity, a majority by share, or any single holder acting alone. GDPR's joint-controller arrangement shows the same need — joint responsibility is meaningless unless the allocation between the parties is determined and transparent.","questions":[{"text":"What exact fraction does each co-holder hold, and do the fractions sum to unity for the recorded extent?","id":"q-share-fraction","kind":"measurement"},{"text":"Is the co-holding joint (undivided, with survivorship) or several (divided into distinct shares)?","id":"q-share-form","kind":"classification"},{"text":"What threshold of co-holders is required to dispose of, encumber or delegate the object?","id":"q-share-decision","kind":"constraint"},{"text":"Where responsibility rather than value is shared, how is it allocated between the parties and where is that allocation published?","id":"q-share-allocation","kind":"authority"}]}]},{"id":"qualifications","name":"Encumbrances and Holder Duties","description":"Restrictions and responsibilities that qualify a holding without moving it.","findings":[{"id":"restrictions-and-encumbrances","name":"Restrictions and encumbrances","description":"LADM treats restrictions as first-class alongside rights, and UCC Article 12 lets a secured party perfect an interest by taking control of a controllable electronic record — meaning an encumbrance can itself be a control position held by someone other than the holder. Encumbrances must therefore be recorded with their beneficiary, their priority rank and their effect on transferability, not as free text.","questions":[{"text":"What restrictions, security interests or charges currently qualify this holding, and who benefits from each?","id":"q-encumbrance-what","kind":"constraint"},{"text":"In what priority order do competing encumbrances rank, and on what basis is that rank determined?","id":"q-encumbrance-priority","kind":"relationship"},{"text":"Does this encumbrance block, condition or merely notify a transfer of control?","id":"q-encumbrance-effect","kind":"constraint"},{"text":"What event releases the encumbrance, and is release recorded as a separate assertion?","id":"q-encumbrance-release","kind":"lifecycle"}]},{"id":"holder-responsibilities","name":"Holder responsibilities","description":"Control carries obligations, not only powers. LADM places responsibilities beside rights and restrictions; NIST defines the information owner by responsibility for controls across the whole information lifecycle; ISO/IEC 27002 control 5.9 requires a named owner accountable for the asset and timely reassignment on transfer or role change; ODRL models the same shape as a Duty. Recording duties makes an unattended or orphaned object detectable.","questions":[{"text":"What responsibilities attach to holding this object, and are they duties of the holder, of a steward, or of both?","id":"q-duty-what","kind":"requirement"},{"text":"How is discharge of each responsibility evidenced, and what is the consequence of non-discharge?","id":"q-duty-discharge","kind":"evidence"},{"text":"When the named owner leaves a role or the object is transferred, what triggers timely reassignment of the responsibility?","id":"q-duty-reassignment","kind":"process"},{"text":"Which objects currently carry responsibilities with no assigned bearer?","id":"q-duty-unassigned","kind":"quality"}]}]}]},{"id":"stewardship-delegation","name":"Stewardship, Delegation and Capacity","description":"Control exercised by someone who is not the holder: appointed stewards and custodians, scoped delegated authority, and arrangements where the holder cannot act unaided.","layers":[{"id":"steward-appointment","name":"Steward and Custodian Appointment","description":"Appointment of a party to operate or safeguard an object on the holder's behalf without beneficial holding.","findings":[{"id":"steward-custodian-appointment","name":"Steward and custodian appointment","description":"A steward operates an object under the holder's instruction and gains no beneficial position, as GDPR's processor acts only on behalf of the controller and dcterms:provenance treats custody changes as significant to authenticity in their own right. The appointment must carry its instruction limits, duty set, term and accountability route, so that a steward acting beyond instruction is detectable and can be reclassified as an independent controller.","questions":[{"text":"Which party is appointed steward or custodian, over which extent of the object, and by whose authority?","id":"q-steward-who","kind":"authority"},{"text":"What may the steward do only on instruction, and what may it decide independently?","id":"q-steward-limits","kind":"constraint"},{"text":"What happens if a steward determines purposes and means of its own, rather than acting on instruction?","id":"q-steward-excess","kind":"exception"},{"text":"For what term does the appointment run, and what must the steward do on termination — return, transfer or destroy?","id":"q-steward-term","kind":"lifecycle"}]},{"id":"trust-arrangement-and-separate-fund","name":"Trust parties and separate fund","description":"HCCH Trusts Convention Article 2 defines a trust as a relationship created inter vivos or on death by a settlor when assets are placed under the control of a trustee for a beneficiary or a specified purpose. Characteristics: the assets are a separate fund and not part of the trustee's own estate; title stands in the trustee or another on the trustee's behalf; the trustee has the power and the duty, in respect of which the trustee is accountable, to manage, employ or dispose of the assets. Reservation of settlor powers, and the trustee also being a beneficiary, are not necessarily inconsistent with a trust. Article 11 requires that personal creditors of the trustee have no recourse against trust assets and that those assets do not fall into the trustee's insolvency, matrimonial property or death estate. The Convention applies only to voluntarily created trusts evidenced in writing (Article 3) and does not bind States to recognise trusts whose significant elements connect to non-trust States (Article 13).","questions":[{"text":"Who is the settlor, who are the trustees, who are the beneficiaries or what is the purpose, and is the trustee also a beneficiary?","id":"trust-arrangement-and-separate-fund-q01","kind":"relationship"},{"text":"Do the assets constitute a separate fund that is excluded from the trustee's personal, insolvency, matrimonial and death estates, and where is that ring-fence recorded?","id":"trust-arrangement-and-separate-fund-q02","kind":"constraint"},{"text":"Which law governs the trust, was it chosen by the settlor or selected by closest connection, and is recognition refused under Article 13?","id":"trust-arrangement-and-separate-fund-q03","kind":"authority"},{"text":"What powers and duties does the trustee have to manage, employ or dispose, to delegate, to create security interests, and to account, and how is the trustee removed?","id":"trust-arrangement-and-separate-fund-q04","kind":"requirement"}]}]},{"id":"delegated-authority","name":"Delegated Authority","description":"Scoped, revocable grants of specific control powers, their verification, and the attribution of acts performed under them.","findings":[{"id":"delegation-mandate-scope","name":"Delegation mandate scope","description":"A mandate grants named powers, never more than the granting position holds. CID's capabilityDelegation and DID's notion of a delegate express the mechanism; ODRL's assigner/assignee and constraint model express the scoping; PROV records that the delegating agent retains some responsibility. Sub-delegation must be explicit, because silent sub-delegation is the main way scope escapes its origin.","questions":[{"text":"Which specific powers are delegated, over which object extent, and under what constraints of time, place, purpose or value?","id":"q-mandate-powers","kind":"authority"},{"text":"From which control position does the mandate flow, and is every delegated power contained within that position?","id":"q-mandate-source","kind":"relationship"},{"text":"May the delegate sub-delegate, to whom, and does the chain depth have a hard limit?","id":"q-mandate-subdelegation","kind":"composition"},{"text":"When the delegate acts, is the act attributed to the delegate representing the holder, or does the delegate become indistinguishable from the holder?","id":"q-mandate-attribution","kind":"provenance"}]},{"id":"mandate-verification-revocation","name":"Mandate verification and revocation","description":"A mandate is only useful if a counterparty can check, at the moment of reliance, that it exists, is in scope and is unrevoked. Revocation is never instantaneous in a distributed setting, so the model must record the revocation timestamp, the publication timestamp and the reliance rule that governs acts falling in the gap. RFC 8693's may_act shows the same pattern: authorization to become an actor is a checkable statement, not an ambient property.","questions":[{"text":"At the moment of reliance, what evidence shows the mandate was live, in scope and unrevoked?","id":"q-verify-live","kind":"validation"},{"text":"When was the mandate revoked, when was that revocation published, and how large was the gap?","id":"q-revoke-when","kind":"temporal"},{"text":"Are acts performed in good faith during the revocation propagation gap treated as valid, void, or voidable?","id":"q-revoke-gap","kind":"exception"},{"text":"How can a mandate be verified when the issuing register is unreachable, and what assurance is lost?","id":"q-verify-offline","kind":"interoperability"}]}]},{"id":"capacity-and-collective","name":"Capacity and Collective Authority","description":"Arrangements where the holder cannot act unaided, and holdings whose authority is collective rather than individual.","findings":[{"id":"capacity-support-arrangements","name":"Capacity and decision-support arrangements","description":"CRPD Article 12 recognises legal capacity on an equal basis and requires access to support in exercising it; where any measure relating to legal capacity is used it must respect the person's rights, will and preferences, be free of conflict of interest and undue influence, be proportional and tailored, apply for the shortest time possible, and be subject to regular review by a competent, independent and impartial authority. A control model must therefore default to supported decision-making and treat full substitution as a bounded, reviewable exception carrying an expiry — not as a permanent 'guardian' field.","questions":[{"text":"Is this arrangement supported decision-making, partially substituted, or fully substituted, and why was the least restrictive option not sufficient?","id":"q-capacity-mode","kind":"classification"},{"text":"Which safeguards are recorded: conflict-of-interest screening, proportionality, tailoring, and the shortest-time limit?","id":"q-capacity-safeguards","kind":"requirement"},{"text":"Which competent, independent and impartial authority reviews the arrangement, and when is the next review due?","id":"q-capacity-review","kind":"authority"},{"text":"How are the person's own will and preferences recorded and given effect within the arrangement?","id":"q-capacity-will","kind":"requirement"}]},{"id":"collective-authority-to-control","name":"Collective and community authority to control","description":"Some holdings vest in a people, community or governing body rather than in an individual or a corporate person. CARE asserts that Indigenous Peoples' rights and interests in Indigenous data must be recognised and their authority to control empowered, and that Indigenous data governance comprises both stewardship and the processes implementing that control. VGGT requires respect for communal, indigenous, customary and informal tenure. This is a distinct authority shape: consent is given by a governance process, is often non-transferable, and may persist even where a third party physically holds the object.","questions":[{"text":"Which community or governing body holds authority to control, and by what internal process is a decision reached?","id":"q-collective-body","kind":"authority"},{"text":"Where a third party physically holds the object, does collective authority persist independently of that custody?","id":"q-collective-vs-custody","kind":"relationship"},{"text":"Is the collective authority alienable at all, and if not, how is that non-transferability enforced against downstream recipients?","id":"q-collective-transfer","kind":"constraint"},{"text":"What return or benefit flows back to the community from uses of the object, and how is it reported?","id":"q-collective-benefit","kind":"requirement"}]}]}]},{"id":"transfer","name":"Transfer, Succession and Exclusivity","description":"How control originates, moves, lapses and ends, and what prevents two parties from claiming it at once.","layers":[{"id":"conveyance","name":"Conveyance","description":"Voluntary transfer of control between parties, its instrument, its exclusivity guarantee and its validity.","findings":[{"id":"transfer-instrument-execution","name":"Transfer instrument and execution","description":"A transfer is an event with an instrument, named parties, conditions precedent and at least three distinct times: when the instrument was executed, when the transfer took legal or operational effect, and when the register recorded it. Conflating them makes backdating undetectable and makes it impossible to answer who held the object at a past instant.","questions":[{"text":"Which parties transfer and receive control, in which modality, and over which extent of the object?","id":"q-transfer-parties","kind":"event"},{"text":"When was the instrument executed, when did the transfer take effect, and when was it recorded?","id":"q-transfer-times","kind":"temporal"},{"text":"What conditions precedent must be satisfied before the transfer takes effect, and which remain outstanding?","id":"q-transfer-conditions","kind":"constraint"},{"text":"Is the transfer for consideration, gratuitous, or an administrative reassignment, and is that fact relevant to its reversibility?","id":"q-transfer-consideration","kind":"classification"}]},{"id":"exclusivity-and-double-transfer","name":"Exclusivity and double-transfer prevention","description":"MLETR requires a reliable method establishing exclusive control by a single person and identifying that person; UCC Article 12 defines control as including the exclusive power to prevent others from availing themselves of the benefit and the exclusive power to transfer. Operationally this means the register must guarantee a single authoritative position per object-and-modality at every instant, detect and reject concurrent dispositions, and be able to prove which of two competing transfers came first.","questions":[{"text":"What reliable method establishes that exactly one party is in control of this object in this modality at this instant?","id":"q-exclusivity-method","kind":"validation"},{"text":"How are two concurrent transfer attempts on the same object detected, ordered and resolved?","id":"q-exclusivity-concurrent","kind":"process"},{"text":"If the register forks or is replicated, which replica is authoritative and how is a divergent branch reconciled?","id":"q-exclusivity-fork","kind":"exception"},{"text":"How is a non-authoritative copy of the object or its instrument marked so it cannot be presented as the controlled instance?","id":"q-exclusivity-copies","kind":"security"}]},{"id":"transfer-validity-and-acquisition","name":"Transfer validity and good-faith acquisition","description":"Not every executed transfer is a valid one. UCC Article 12's qualifying-purchaser rules show that a system may protect a good-faith acquirer even against a defect upstream, which means a control record must be able to represent a transfer that is void, voidable, or valid-but-defective, and must record whether downstream acquirers are protected. Silently deleting a bad transfer destroys the very evidence needed to resolve the consequences.","questions":[{"text":"Is this transfer valid, void, voidable or subject to a pending challenge, and on what ground?","id":"q-validity-status","kind":"state"},{"text":"If a transfer is set aside, which downstream transfers and encumbrances are affected, and which acquirers are protected?","id":"q-validity-downstream","kind":"relationship"},{"text":"How is an invalid transfer corrected — by reversal entry, annulment or restitution — and is the original entry preserved?","id":"q-validity-remedy","kind":"process"}]}]},{"id":"succession-and-lapse","name":"Succession, Lapse and Chain of Title","description":"Involuntary movement of control on death, dissolution, abandonment or lapse, and the reconstruction of the full history of a holding.","findings":[{"id":"succession-dissolution-lapse","name":"Succession, dissolution and lapse","description":"Control can move without any act of the holder: on death, on dissolution of a legal person, on expiry of a term, on abandonment, or by operation of law to the state. CRPD Article 12(5) requires equal rights to own and inherit property and protection against arbitrary deprivation, which constrains how a lapse may be declared. An interim state — estate in administration, holder deceased but successor undetermined — must be representable, because forcing an immediate successor invents a fact.","questions":[{"text":"What event opened the succession or lapse — death, dissolution, term expiry, abandonment or operation of law?","id":"q-succession-trigger","kind":"event"},{"text":"Who, if anyone, controls the object between the trigger event and the vesting of a successor?","id":"q-succession-interim","kind":"state"},{"text":"By what rule does control vest in the successor, and when does vesting take effect relative to the trigger?","id":"q-succession-vesting","kind":"process"},{"text":"Before declaring abandonment or lapse, what diligent search was performed and over what period?","id":"q-succession-abandonment","kind":"evidence"}]},{"id":"chain-of-title-reconstruction","name":"Chain of title reconstruction","description":"dcterms:provenance defines exactly this: a statement of changes in ownership and custody significant for authenticity, integrity and interpretation. An agent must be able to reconstruct, for any past instant, who held the object and under what basis, and to detect where the chain has a gap, an overlap or an unevidenced link — because a chain that silently interpolates is worse than one that admits a hole.","questions":[{"text":"Who held this object in a given modality at a specified past instant, and on what basis?","id":"q-chain-asof","kind":"temporal"},{"text":"Where does the chain have gaps, overlaps or links with no evidencing source?","id":"q-chain-gaps","kind":"quality"},{"text":"What is the earliest recorded control position, and is it a genuine origin or merely the register's own start date?","id":"q-chain-root","kind":"provenance"},{"text":"For links inherited from a predecessor register or migration, what mapping and loss occurred?","id":"q-chain-migration","kind":"interoperability"}]},{"id":"involuntary-deprivation-and-lapse-events","name":"Involuntary and abandonment events","description":"FAO VGGT requires States to safeguard legitimate tenure rights against arbitrary loss including forced evictions, and treats expropriation among transfers and other changes. HCCH Article 11 ring-fences trust assets from the trustee's insolvency; Article 15(e)–(f) preserves insolvency-creditor protection and good-faith third-party rules, which may defeat a trust or a transfer. FATF notes misuse of corporate vehicles for sanctions evasion; a freeze or confiscation is an exceptional restriction or transfer effect. Abandonment, bona vacantia, escheat and adverse possession are widely attested in domestic law but lack a single global primary instrument in this source set; they are recorded only as jurisdiction-tagged exceptional events, not as universal classes. Dispute procedure itself belongs to the courts model; this finding stores the resulting effect.","questions":[{"text":"What exceptional event affected which holdings, what is the effect on title, and which authority ordered it?","id":"involuntary-deprivation-and-lapse-events-q01","kind":"event"},{"text":"In which jurisdiction is this event class recognised, and is it a universal mixin class or a tagged local doctrine?","id":"involuntary-deprivation-and-lapse-events-q02","kind":"exception"},{"text":"Does a good-faith third-party or insolvency-creditor rule under HCCH Article 15 defeat or qualify this holding or this trust?","id":"involuntary-deprivation-and-lapse-events-q03","kind":"constraint"}]}]}]},{"id":"assurance","name":"State, Time, Evidence and Contestation","description":"The lifecycle states of a control assertion, its temporal semantics, the evidence and assurance behind it, and the handling of competing claims.","layers":[{"id":"state-and-time","name":"State and Temporal Semantics","description":"Lifecycle states of a control assertion and the separation of event, effective, observation and record time.","findings":[{"id":"control-record-lifecycle-states","name":"Control record lifecycle states","description":"A control assertion moves through determinate states — proposed, pending conditions, effective, suspended, disputed, superseded, terminated — with defined transitions and defined authorities for each transition. LADM's versioned-object foundation means a superseded state remains addressable rather than being erased. The state must be explicit so that an agent never treats a pending or disputed assertion as an operative one.","questions":[{"text":"What is the current state of this control assertion, and which transition produced it?","id":"q-state-current","kind":"state"},{"text":"Which transitions are permitted from the current state, and who is authorised to make each?","id":"q-state-transitions","kind":"lifecycle"},{"text":"Which states are operative for reliance purposes, and which must a relying agent refuse to act on?","id":"q-state-operative","kind":"decision"},{"text":"What suspends a control assertion without terminating it, and what restores it?","id":"q-state-suspension","kind":"exception"}]},{"id":"temporal-semantics","name":"Temporal semantics of control","description":"Four times matter and must not be merged: when the underlying event occurred, from when the control is effective, when the register observed or ingested it, and when the record was written. LADM's versioned objects carry lifespan bounds for exactly this reason. All are RFC 3339 with seconds and an explicit offset or Z, because a local time without offset makes cross-jurisdiction ordering of competing dispositions undecidable.","questions":[{"text":"Over what interval is this control assertion effective, and is the end open or determinate?","id":"q-time-interval","kind":"temporal"},{"text":"When was this fact observed or ingested, and how far did it lag the event it records?","id":"q-time-observation","kind":"temporal"},{"text":"Does every recorded timestamp carry seconds and an explicit UTC offset or Z, and what is the local civil-time context where it matters?","id":"q-time-offset","kind":"validation"},{"text":"Does this record change the past, and if so what was believed true before the retroactive change?","id":"q-time-retroactive","kind":"provenance"}]}]},{"id":"evidence-and-assurance","name":"Evidence and Assurance","description":"What backs a control assertion and how much weight an agent may place on it.","findings":[{"id":"evidentiary-sources-and-attestation","name":"Evidentiary sources and attestation","description":"LADM binds every core class to a source; verifiable credentials give a machine-checkable attestation shape and make explicit that the party presenting an attestation is often not its subject. A control record must therefore distinguish the issuer of an attestation, the subject it concerns, the party presenting it, and the integrity data that lets a verifier check it was not altered.","questions":[{"text":"Who issued each evidencing attestation, about which subject, and who presented it to the register?","id":"q-evidence-issuer","kind":"evidence"},{"text":"What integrity data proves the evidencing source has not been altered since issuance?","id":"q-evidence-integrity","kind":"security"},{"text":"Is the evidence independent of the party it benefits, or self-asserted?","id":"q-evidence-independence","kind":"quality"},{"text":"Does the evidencing source itself expire or require renewal, and what happens to the control record when it does?","id":"q-evidence-expiry","kind":"lifecycle"}]},{"id":"assurance-and-currency","name":"Assurance level and currency","description":"AMLR's requirement that beneficial ownership information be adequate, accurate and up to date generalises: every control assertion needs a stated assurance level, a last-verified time, and a staleness policy. VGGT's recognition of informal and customary tenure means low assurance must be an honest recorded value, not grounds for treating a holding as non-existent.","questions":[{"text":"What assurance level does this control assertion carry, and what evidence and verification method produced it?","id":"q-assurance-level","kind":"quality"},{"text":"When was the assertion last verified, and by what date does it become stale for reliance purposes?","id":"q-assurance-staleness","kind":"temporal"},{"text":"For informal, customary or unregistered holdings, how is low assurance recorded without implying the holding is invalid?","id":"q-assurance-lowconfidence","kind":"exception"}]}]},{"id":"contestation","name":"Contestation","description":"Competing claims over the same object and their resolution status.","findings":[{"id":"competing-claims-and-dispute-status","name":"Competing claims and dispute status","description":"Because a register records assertions rather than facts, two irreconcilable claims can coexist. VGGT's recognition of overlapping customary and formal tenure makes this normal rather than exceptional. The model must hold both claims, mark the object as contested, apply a stated priority rule where one exists, and ingest an outcome reference from the dispute model without itself adjudicating.","questions":[{"text":"Which claims over this object are irreconcilable, and in what respect do they conflict?","id":"q-claims-competing","kind":"relationship"},{"text":"Is there a stated priority rule between the competing claims, and what does it yield?","id":"q-claims-priority","kind":"constraint"},{"text":"While contested, which operations on the object are frozen, permitted or permitted only with notice?","id":"q-claims-effect","kind":"constraint"},{"text":"How is a resolution ingested from the dispute forum, and what does it change in the control record?","id":"q-claims-outcome","kind":"process"}]}]}]},{"id":"register-governance","name":"Governance of the Control Register","description":"The authority that maintains control records, who may read them, what must be retained or erased, and how the model aligns to external standards.","layers":[{"id":"register-authority","name":"Register Authority and Access","description":"Who maintains the register, what its recording confers, and who may see what.","findings":[{"id":"register-authority-and-competence","name":"Register authority and competence","description":"A control register has a maintaining authority whose competence is bounded by object class, jurisdiction and modality. NIST's information owner is defined by statutory or operational authority; LADM presumes a land administration authority. Where an object falls outside the register's competence, its records are at best evidentiary, and the register must say so rather than presenting them as authoritative.","questions":[{"text":"Which authority maintains this register, over which object classes, modalities and territory?","id":"q-authority-who","kind":"authority"},{"text":"What does an entry in this register confer — constitutive effect, a rebuttable presumption, or evidence only?","id":"q-authority-effect","kind":"authority"},{"text":"How are records outside the register's competence marked, and what may an agent infer from them?","id":"q-authority-outside","kind":"exception"},{"text":"Where two registers claim competence over the same object, which prevails and how is the conflict surfaced?","id":"q-authority-overlap","kind":"interoperability"}]},{"id":"control-data-access-and-disclosure","name":"Control data access and disclosure","description":"Ownership data is not inherently public. The CJEU held that giving the general public access to beneficial ownership information is a serious and disproportionate interference with Charter Articles 7 and 8, since a legitimate-interest regime achieves comparable results. The register must therefore default to restricted access, define disclosure tiers, apply a legitimate-interest test, and log privileged reads — while still supporting the minimal current-holder extract a counterparty genuinely needs.","questions":[{"text":"Which audience tiers may read which layers of the control record, and what is the default for an unclassified requester?","id":"q-access-tier","kind":"access"},{"text":"How is a requester's legitimate interest established and recorded before privileged disclosure?","id":"q-access-interest","kind":"privacy"},{"text":"What is the minimum disclosure that satisfies a given purpose — current holder only, or the full record?","id":"q-access-minimisation","kind":"privacy"},{"text":"Which reads are logged, with what detail, and for how long is the read log kept?","id":"q-access-logging","kind":"security"}]}]},{"id":"continuity","name":"Retention, Deletion and Interoperability","description":"How long control history is kept against erasure and portability rights, and how the model maps onto external standards without overclaiming conformance.","findings":[{"id":"retention-archival-and-deletion","name":"Retention, archival and deletion","description":"Control history and personal-data rights pull in opposite directions. dcterms:provenance treats the ownership and custody chain as essential to authenticity, and a chain with holes cannot support reliance; GDPR nonetheless grants rectification and, in defined circumstances, erasure. The resolution is explicit: define which elements are permanent register content, which are erasable identifying attributes held by reference in the party model, and use tombstoning rather than physical deletion of links.","questions":[{"text":"How long is each class of control record retained, and what legal or operational basis sets that period?","id":"q-retention-period","kind":"retention"},{"text":"When a party exercises an erasure or rectification right, which elements can be removed and which must survive as an anonymised or tombstoned link?","id":"q-retention-erasure","kind":"retention"},{"text":"How is chain integrity preserved when an intermediate record is redacted or tombstoned?","id":"q-retention-integrity","kind":"quality"},{"text":"On decommissioning of the register, who takes custody of the historical control records and under what terms?","id":"q-retention-archive","kind":"lifecycle"}]},{"id":"interoperability-and-alignment","name":"Interoperability and standards alignment","description":"The model aligns with, rather than conforms to, external standards: LADM's party/RRR/administrative-unit pattern, PROV's attribution and delegation, ODRL's assigner/assignee and duty, CID's controller and capability relationships, and dcterms' rightsHolder and provenance. Each alignment is partial and each has a known conflict; claiming conformance without a tested profile and evidence would be false. Portability under GDPR Article 20 also requires an export shape that a receiving system can actually ingest.","questions":[{"text":"For each external standard, which elements of this model map, which map only partially, and which have no counterpart?","id":"q-interop-mapping","kind":"interoperability"},{"text":"Where does an external standard's semantics conflict with this model's, and which prevails in an export?","id":"q-interop-conflict","kind":"interoperability"},{"text":"Is a conformance claim to any external standard being made, and what test evidence supports it?","id":"q-interop-conformance","kind":"validation"},{"text":"What export shape lets a holder move their control records to another system in a structured, machine-readable form?","id":"q-interop-portability","kind":"interoperability"}]}]}]}]},"agentConduct":{"may":["Resolve the current controller of an object for a given date.","Verify a delegated authority before acting on its basis.","Reconstruct the chain of title from recorded events.","Record a competing claim and route it for resolution."],"mustNot":["Invent a holder, basis or control modality where none is recorded.","Overwrite or delete past control records instead of adding a compensating entry.","Disclose beneficial-holder or capacity-arrangement layers without a recorded basis.","Act under a mandate after the parent title was transferred or restricted.","Treat possession or access as proof of ownership."],"requiresHuman":["Executing a transfer of control.","Establishing or changing an arrangement affecting a person's legal capacity.","Resolving competing ownership claims."]},"ethics":{"considerations":["Control records decide who may use and dispose of property and data; errors can dispossess people.","Substitute decision-making affects personal autonomy and must stay an exception with review.","Beneficial ownership transparency helps fight abuse but can expose people to risk."],"affectedParties":["Holders and owners","People under capacity arrangements","Counterparties relying on title"]},"owners":{"steward":"The adopting Dimension must publish a register charter naming the maintaining authority, its competence scope by object class, modality and territory, and the recording effect of an entry (constitutive, presumptive or evidentiary only).","roles":[{"name":"Register authority (root registrar)","responsibilities":["Maintain the register charter, competence scope and recording effect, and publish amendments with effective dates.","Enforce exclusivity at write time and adjudicate ordering of concurrent dispositions.","Approve and version the control modality vocabulary and basis code lists.","Refuse and record entries outside the register's competence rather than accepting them silently."]},{"name":"Control record steward","responsibilities":["Operate assertion, transfer, share restructuring and succession functions within the charter.","Maintain assurance levels, re-verification cadence and remediation of stale or unevidenced records.","Ensure every record carries a basis, an evidencing source and separated effective and ingestion timestamps.","Escalate holder-unknown, unassigned-duty and chain-gap findings rather than filling them by inference."]},{"name":"Disclosure controller","responsibilities":["Apply the disclosure policy, run and record legitimate-interest determinations, and maintain the minimal projections per purpose.","Ensure beneficial-holder and capacity layers are never exposed in public projections.","Ensure privileged reads are logged with requester, purpose, fields returned and RFC 3339 instant.","Review redaction rules whenever a new projection or export shape is introduced."]},{"name":"Safeguards reviewer","responsibilities":["Verify that every capacity arrangement records a least-restrictive-alternative justification, conflict screening, proportionality assessment, expiry and independent review authority.","Track next-review dates and move lapsed arrangements out of effect rather than allowing silent continuation.","Ensure the person's expressed will and preferences are recorded, and that deviations are justified.","Reject arrangements that lack an expiry or a competent independent reviewer."]},{"name":"Interoperability custodian","responsibilities":["Maintain crosswalks against pinned versions of LADM, ODRL, PROV-O, CID/DID, VC and DCMI, with loss and conflict annotations.","Block conformance claims unsupported by retained test evidence and label exports alignment-only by default.","Re-test crosswalks when a target standard publishes a new version and mark affected exports degraded until re-tested.","Maintain the portability export shape and its documented exclusions."]},{"name":"Dispute liaison","responsibilities":["Register competing claims, apply the frozen-operation set and surface contested notices on all extracts.","Ingest adjudicated outcomes as new records without deleting prior entries.","Track residual appeal status and keep contested flags accurate.","Ensure the register never records an adjudication of its own."]}],"masterSystems":[]},"relations":[{"target":"Every meta-object in the catalogue (the control facet)","type":"composes","note":"Attach the control facet — holder, modality, basis, validity, assurance — to any meta-object without embedding domain semantics into it, so that control can be asked of anything the catalogue registers."},{"target":"Meta-object core identity primitive","type":"extends","note":"Every control assertion anchors to the core object identity; this model extends that primitive with a control facet rather than minting a parallel identity for the object."},{"target":"Person model (natural persons)","type":"references","note":"Holders, beneficial holders, delegates, stewards and supported persons are natural persons resolved in the person model; this model holds only references and roles."},{"target":"Organization model (legal persons and bodies)","type":"references","note":"Organizations, communities and public bodies appear as holders, stewards, register authorities and review authorities; their identity, legal form and existence lifecycle live in their own model."},{"target":"Access / authorization contract model","type":"references","note":"Every access grant must resolve its grantor against a live control record here; this model supplies grantor standing, the access model supplies permissions, prohibitions and duties."},{"target":"Access and change audit model","type":"references","note":"Privileged reads of control data and all register mutations are logged in the audit model; this model declares what must be logged, not the log's structure."},{"target":"Provenance and lineage model","type":"aligned","note":"Control transitions are emitted as provenance-compatible attribution and delegation statements, so that responsibility for an object's control history is queryable alongside its content lineage."},{"target":"Rights, licensing and IPR model","type":"references","note":"Rights in the work are distinguished from control of the object; a rights holder is referenced here but rights terms, licences and permitted uses are defined there."},{"target":"Dispute resolution and adjudication model","type":"references","note":"Contested claims are flagged here and adjudicated there; outcomes flow back as ingested transfer, annulment or confirmation records."},{"target":"Identity credential and key management model","type":"references","note":"Cryptographic verification methods evidence control but do not constitute it; key rotation must not be interpretable as a transfer of ownership."},{"target":"ISO 19152-1:2024 LADM generic conceptual model","type":"aligned","note":"Adopt the party / right-restriction-responsibility / administrative-unit pattern, the fraction and versioned-object primitives, and the source association; alignment only, since this model covers non-spatial meta-objects LADM does not address."},{"target":"W3C ODRL Information Model 2.2","type":"aligned","note":"Reuse the assigner/assignee role functions, constraint shape and Duty class for mandates and holder responsibilities, without adopting ODRL as the control record's own encoding."},{"target":"W3C Controlled Identifiers v1.0 and DID v1.1","type":"aligned","note":"Map the de-facto technical control modality and the delegation primitive onto controller, capabilityInvocation and capabilityDelegation; DID v1.1 is a Candidate Recommendation, so the alignment is provisional."},{"target":"W3C PROV-O","type":"aligned","note":"Express acting-for relations as qualified delegation with roles, preserving the principle that the delegating agent retains some responsibility."},{"target":"W3C Verifiable Credentials Data Model 2.0","type":"aligned","note":"Use the credential shape for attestations of control and for delegation mandates, keeping issuer, subject and presenting holder distinct."},{"target":"DCMI Metadata Terms","type":"aligned","note":"Map the chain of title to dcterms:provenance and rights-holder references to dcterms:rightsHolder, recording that rightsHolder conflates owning and managing and therefore cannot be a lossless target."},{"target":"Person / Organization models","type":"neighbor","note":"This model holds only a reference and a role for each party (holder, steward, delegate, supported person, beneficial owner). Party identity, legal form, capacity determination and existence lifecycle are resolved externally; a control record must not restate them. LADM makes the same split between LA_Party and the RRR that binds it."},{"target":"Access / authorization contract model","type":"neighbor","note":"Control answers 'who may grant'; access answers 'who may do what, now'. An ODRL-style Policy names an assigner; this model is what makes an assigner's standing checkable. Permission evaluation, obligations discharge and enforcement stay in the access model."},{"target":"Provenance / lineage model","type":"neighbor","note":"PROV attribution and delegation describe responsibility for entities and activities. This model reuses that shape for who acts for whom, but its subject is a standing control relation with validity intervals, not a past activity trace. Where both exist, the control record is the assertion and the provenance record is its trace."},{"target":"Rights and licensing (IPR) model","type":"neighbor","note":"dcterms:rightsHolder conflates owning and managing rights over a resource. This model separates control of the meta-object from rights in the work it represents: a custodian may control a record without holding any IP right in its content, and a rights holder may hold no control record."},{"target":"Audit / evidence log model","type":"neighbor","note":"Every write to, and privileged read of, a control record is an auditable event, but the audit trail itself is a separate append-only model. This model declares what must be logged and by whom, not the log's own structure."},{"target":"Identity credential / key management model","type":"neighbor","note":"Cryptographic control (a verification method authorized for capabilityInvocation) is evidence of control, not the control record. Key rotation is not a transfer of ownership; conflating them makes an operator into an owner. The controlled-identifier document is an artifact this model cites, not one it owns."},{"target":"Dispute resolution / courts model","type":"neighbor","note":"This model carries a dispute flag, the competing claims and the ingested outcome reference. Procedure, evidence weighing and remedies belong to the dispute model; a control record must never encode an adjudication."}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier issued by the competent register, court, notary or issuing authority (instrument number, grant reference, filing reference).","Governed global identifier or IRI minted in the adopting Dimension's ownership namespace and resolvable through the Dimension's registry.","UUID (v4 or v7) or ULID assigned by the adopting Dimension, recorded together with the fact that no higher tier was available.","A content digest may accompany but never replace an identifier, because the same instrument may be validly reissued with identical content; a date is never an identifier."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A control position names an object, a holder, a modality such as owner or steward and a basis such as deed, contract or law.","Confused with possession, access permission, authorship and the custodian who only holds an object."]},"capabilities":{"applicability":"required","items":["Anchor a controllable object: Admit a meta-object into the control register by recording its reference, controllability class, extent and registration basis, making it capable of bearing control assertions.","Assert a control position: Record that one or more parties hold a referenced object in a stated modality, with basis, shares, encumbrances, validity interval and assurance level.","Resolve the current controller: Return the operative holder or controller of a named object in a named modality at a given instant, with the minimum disclosure the requester's purpose requires.","Verify delegated authority: Determine whether a claimed delegate holds live, in-scope, unrevoked authority to perform a specific act over a specific object, and record the verification as counterparty evidence.","Execute a transfer of control: Move control of an object from transferor to transferee under an instrument, enforcing exclusivity, conditions precedent and required consents.","Restructure holding shares: Change the co-holders, fractions or co-holding form of a single holding, subject to the recorded decision rule.","Establish or review a capacity arrangement: Create, review, vary or terminate a support or substitute decision-making arrangement over a holding, enforcing the mandatory safeguards.","Open a succession or lapse: Record the trigger event that removes a holder without an act of transfer, place the holding in an interim state, and apply the vesting rule when a successor is determined.","Record and resolve a competing claim: Register an irreconcilable claim over an object, freeze the operations the register's rules require, and ingest an outcome from the dispute forum without adjudicating.","Evaluate control assurance: Assess a control record or a population of records for adequacy, accuracy, currency and chain completeness, and schedule remediation.","Export an aligned projection: Emit control records in an external standard's shape for portability or interchange, carrying explicit loss and conflict warnings and no unwarranted conformance claim.","Appoint steward: Appoint a custodian or trustee-like operator with duties, term and accountability route, without conferring beneficial ownership.","Grant or revoke mandate: Issue, constrain, sub-delegate, expire or revoke a scoped grant of control powers that must not exceed the live parent title.","Reconstruct chain of title: Return the ordered transfer and provenance history of one object, omitting unrelated holdings of the parties.","Record restriction: Attach a restriction, responsibility, prohibition or duty to a title, with interval and an optional pointer to a secured-transactions sibling.","Resolve beneficial owners: Return the natural persons who ultimately own or control, the control pathway, currency timestamp and any open discrepancy, distinct from legal owners."]},"hazards":{"applicability":"required","items":["Double disposition of the same object.","Fraudulent transfer through forged or expired mandates.","Exposure of beneficial owners or vulnerable persons."]},"interfaces":{"applicability":"required","items":["W3C ODRL Information Model 2.2.","W3C Decentralized Identifiers (DIDs) v1.0.","W3C Verifiable Credentials Data Model 2.0.","EU Anti-Money Laundering rules on beneficial ownership registers."]},"context":{"applicability":"required","items":["Access, disclosure and beneficial-ownership defaults are calibrated to EU law (GDPR, AMLR and the CJEU's WM/Sovim judgment). Jurisdictions with open-by-default corporate or land registers will need a different default and should record that divergence in the register charter.","The transfer-validity and good-faith-acquisition finding is shaped by UCC Article 12, a US uniform act whose enactment is state-by-state and incomplete; take-free rules are not universal.","MLETR is a model law requiring national enactment; exclusive-control semantics apply only where enacted, and the number of enacting states remains small.","The capacity findings assume a CRPD-ratifying jurisdiction. States that have not ratified, or that entered reservations to Article 12, will not require the safeguards this model treats as validity conditions.","VGGT's recognition of customary, communal and informal tenure is voluntary guidance, not binding law; a jurisdiction may refuse to recognise an informal holding that this model records as legitimate.","CARE's authority-to-control is not legally enforceable in most jurisdictions and operates as a governance commitment; a Dimension adopting it must give it effect through its own charter and contracts.","Land-specific alignment assumes LADM Edition II; jurisdictions still on ISO 19152:2012 use different class names and lack the georegulation framing.","Torrens indefeasibility is a jurisdictional property, not a mixin default.","Common-law trusts are defined by HCCH Article 2; civil-law fiducie, treuhand and waqf are not assumed equivalent without an adopting-Dimension mapping.","Forced heirship and matrimonial property (HCCH Article 15) override chosen trust law in many civil-law forums.","Beneficial-ownership percentage thresholds (often 25 percent) are local implementations, not the FATF definition.","Publicity of legal-owner registers versus confidentiality of BO registers varies by State.","Guardianship of adults remains lawful in States that have not fully implemented CRPD Article 12.","Digital-asset succession without key recovery is operationally common and legally unsettled outside a few statutes."]}},"sources":[{"title":"Controlled Identifiers v1.0","url":"https://www.w3.org/TR/cid-1.0/","note":"World Wide Web Consortium (W3C)"},{"title":"Decentralized Identifiers (DIDs) v1.1","url":"https://www.w3.org/TR/did-1.1/","note":"World Wide Web Consortium (W3C)"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium (W3C)"},{"title":"ODRL Information Model 2.2","url":"https://www.w3.org/TR/odrl-model/","note":"World Wide Web Consortium (W3C)"},{"title":"Verifiable Credentials Data Model v2.0","url":"https://www.w3.org/TR/vc-data-model-2.0/","note":"World Wide Web Consortium (W3C)"},{"title":"UNCITRAL Model Law on Electronic Transferable Records (MLETR)","url":"https://uncitral.un.org/en/texts/ecommerce/modellaw/electronic_transferable_records","note":"United Nations Commission on International Trade Law (UNCITRAL)"},{"title":"Regulation (EU) 2016/679 (General Data Protection Regulation)","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679","note":"European Union"},{"title":"Regulation (EU) 2023/2854 (Data Act)","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202302854","note":"European Union"},{"title":"Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation)","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401624","note":"European Union"},{"title":"Convention on the Rights of Persons with Disabilities, Article 12 — Equal recognition before the law","url":"https://www.un.org/development/desa/disabilities/convention-on-the-rights-of-persons-with-disabilities/article-12-equal-recognition-before-the-law.html","note":"United Nations"},{"title":"RFC 8693: OAuth 2.0 Token Exchange","url":"https://www.rfc-editor.org/rfc/rfc8693.html","note":"Internet Engineering Task Force (IETF)"},{"title":"DCMI Metadata Terms","url":"https://www.dublincore.org/specifications/dublin-core/dcmi-terms/","note":"Dublin Core Metadata Initiative (DCMI)"},{"title":"ISO 19152-1:2024 Geographic information — Land Administration Domain Model (LADM) — Part 1: Generic conceptual model","url":"https://www.iso.org/standard/81263.html","note":"International Organization for Standardization (ISO)"},{"title":"The CARE Principles for Indigenous Data Governance","url":"https://datascience.codata.org/articles/10.5334/dsj-2020-043","note":"Global Indigenous Data Alliance / CODATA Data Science Journal (Carroll et al.)"},{"title":"Voluntary Guidelines on the Responsible Governance of Tenure of Land, Fisheries and Forests in the Context of National Food Security (VGGT)","url":"https://www.fao.org/tenure/voluntary-guidelines/en/","note":"Food and Agriculture Organization of the United Nations / Committee on World Food Security"},{"title":"NIST Computer Security Resource Center Glossary — information owner","url":"https://csrc.nist.gov/glossary/term/information_owner","note":"National Institute of Standards and Technology (NIST)"},{"title":"ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection — Information security controls","url":"https://www.iso.org/standard/75652.html","note":"International Organization for Standardization / International Electrotechnical Commission"},{"title":"Judgment in Joined Cases C-37/20 and C-601/20, WM and Sovim SA v Luxembourg Business Registers","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62020CJ0037","note":"Court of Justice of the European Union"},{"title":"2022 Amendments to the Uniform Commercial Code (new Article 12, Controllable Electronic Records)","url":"https://www.uniformlaws.org/committees/community-home?CommunityKey=1457c422-ddb7-40b0-8c76-39a1991651ac","note":"Uniform Law Commission / American Law Institute"},{"title":"ISO 27002 Control 5.9 — Inventory of Information and Other Associated Assets","url":"https://www.isms.online/iso-27002/control-5-9-inventory-of-information-and-other-associated-assets/","note":"ISMS.online"},{"title":"The first five parts of LADM Edition II have been published — ISO 19152-1:2024 Geographic information — Land Administration Domain Model (LADM) — Part 1: Generic conceptual model","url":"https://ojs.sites.ufsc.br/index.php/fig/article/download/8753/7293/33065","note":"FIG / ISO TC 211 (LADM Edition II overview by standard co-editors)"},{"title":"ODRL Information Model 2.2","url":"https://www.w3.org/TR/2018/REC-odrl-model-20180215/","note":"W3C"},{"title":"UNCITRAL Model Law on Electronic Transferable Records (MLETR)","url":"https://uncitral.un.org/sites/uncitral.un.org/files/media-documents/uncitral/en/mletr_ebook_e.pdf","note":"United Nations Commission on International Trade Law"},{"title":"Guidance on Beneficial Ownership of Legal Persons (Recommendation 24)","url":"https://www.fatf-gafi.org/content/dam/fatf-gafi/guidance/Guidance-Beneficial-Ownership-Legal-Persons.pdf","note":"Financial Action Task Force"},{"title":"Voluntary Guidelines on the Responsible Governance of Tenure of Land, Fisheries and Forests in the Context of National Food Security — At a glance","url":"https://www.fao.org/3/a-i3016e.pdf","note":"Food and Agriculture Organization of the United Nations"},{"title":"Convention of 1 July 1985 on the Law Applicable to Trusts and on their Recognition","url":"https://www.hcch.net/en/instruments/conventions/full-text/?cid=59","note":"Hague Conference on Private International Law (HCCH)"},{"title":"Convention on the Rights of Persons with Disabilities, Article 12 — Equal recognition before the law","url":"https://www.ohchr.org/en/instruments-mechanisms/instruments/convention-rights-persons-disabilities","note":"United Nations / OHCHR"},{"title":"ISO 19115-1 CI_RoleCode — function performed by the responsible party","url":"https://schemas.isotc211.org/resources/codelists/ISO19115-1.1.cit.CI-RoleCode/","note":"ISO/TC 211 Implementation Schemas"}],"openQuestions":["Tenure-form typology from VGGT (public, private, communal, indigenous, customary, informal, mixed) as an axis orthogonal to control modality — determine whether it belongs as an added dimension inside control-modality-classification or as a distinct finding, and how it interacts with the non-defaulting modality rule.","FATF concealment typology as enrichment of legal-versus-beneficial-holder: nominee shareholders and directors, layered legal persons, bearer-share immobilisation, and control through other means beyond any local percentage threshold.","ISO 19115-1 CI_RoleCode alignment, including confirmation from the live TC 211 codelist that no 'steward' code exists, so the model does not emit a non-canonical role code in exports.","Valuation and consideration sibling: Claude's checklist records this as its only outright gap, with ISO 19152-4 named as the untested alignment target and no registered sibling model.","Archival custody transfer anchor: OAIS (ISO 14721 / CCSDS 650.0-M-3) could not be retrieved, so the custody and successor-custodian elements currently rest only on DCMI and GDPR.","Whether an autonomous software agent or a DAO can hold rather than merely exercise control — both providers leave legal personality for non-human holders unresolved, and no consulted source settles it.","Placement of a transfer-watch / legitimate-interest notification capability: whether it belongs to this control mixin or to a sibling eventing or access model, given that the mixin already excludes runtime authorization and audit.","Jurisdiction-specific property, trust, succession and matrimonial-property law is not modelled; only the basis code and its evidencing source are carried, so an agent cannot determine from this model whether a claimed right is actually valid anywhere.","The normative clause text of ISO 19152-1:2024 and ISO/IEC 27002:2022 is paywalled and was not read directly; LADM's class structure was confirmed at catalogue level and through secondary technical summaries, and control 5.9's wording through a secondary explainer (SRC-020). Attribute-level LADM alignment is therefore unverified.","Trust law specifically — the split between legal and equitable title, trustee duties and beneficiary rights — is approximated through the beneficial-holder and steward findings rather than modelled natively; civil-law systems without a trust concept will map imperfectly.","Bailment, lien-by-possession, pledge and other possession-derived positions are only partially covered by the custody modality and the encumbrance finding.","Escheat and bona vacantia are named as a succession trigger but the state-acquisition procedure and its notice requirements are not modelled.","No valuation, consideration or settlement semantics; the reference to a settlement record held elsewhere is a placeholder for an unregistered sibling model.","OAIS (ISO 14721 / CCSDS 650.0-M-3) was sought as an anchor for archival custody transfer but could not be retrieved; the custody and successor-custodian elements therefore rest on DCMI and GDPR rather than on the archival standard.","Automated agents as holders — whether an autonomous software agent can hold rather than merely exercise control — is left open; CID and DID permit an autonomous software controller, but no source consulted resolves whether that constitutes holding.","CIDOC CRM ownership and custody properties (P51, P52, P30) were not fetched as primary text and are not canonical here.","PREMIS preservation rights and agent roles were not fetched.","GDPR controller and processor are a data-protection sibling, not modelled as title; they were not fetched as primary support.","RUFADAA and other digital-asset fiduciary statutes are regional and omitted as classes.","UNIDROIT Cape Town Convention, UCC Article 9 and the Hague Securities Convention were not fetched; security-interest procedure is out of scope.","Social Tenure Domain Model (STDM) and continuum-of-land-rights graphics are secondary to VGGT and LADM and were not fetched.","Adverse possession, prescription, bona vacantia, escheat, community property and orphan-works regimes lack a single global primary instrument in this source set and are jurisdiction-tagged gaps.","DAO, smart-contract and non-person holders lack primary legal personality support here.","ISO 19152 full text is paywalled; Party and RRR structure is taken from the Edition II co-editor paper, not from a purchased ISO PDF.","ISO 19115-1 has no steward code; older profiles that listed steward are not used as if they were the current TC 211 list."],"resources":{"spec":"/models/wm-xct-001-ownership-stewardship/spec.yaml","agents":"/models/wm-xct-001-ownership-stewardship/AGENTS.md","source":"https://ver.cy/enterprise/research/em-xct-02/"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-xct-001-ownership-stewardship/spec.yaml","ver-cy/world-models/card-supplements/wm-xct-001-ownership-stewardship.json"],"providers":["Claude","Grok"],"researchStatus":"reviewable-draft","generatedAt":"2026-09-21T18:15:11.379001+00:00","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}