{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-007","code":"wm-xct-007-access-breach-enforcement","url":"https://ver.cy/models/wm-xct-007-access-breach-enforcement/","name":"Access Breach / Enforcement","alternateNames":["S7"],"kind":"world-model","status":"published","version":"0.1.0-reviewable-draft","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.ENF"],"industry":["Cross-industry"],"navPath":"NAV.XCT.ENF","tags":["access","breach","enforcement","xct.enf"],"facets":{}},"whatItIs":"A host-attached mixin for resources, agreements or cases that need access-breach accountability. The attachment identifies its host, authority profile and local assertions. It references separately mastered signals, cases, decisions, evidence and grants. It records allegations, assessments and effects without operating access controls, imposing sanctions or deciding legal rights. All structure and local functions are proposed research design.","purpose":"Attach evidence-qualified access violation, enforcement and redress records to a host without taking over its identity or authority.","scope":{"in":["Host and policy revision binding; signals, disputed assertions and investigation references","Authority-qualified findings, precautionary measures, sanctions, notification assessment and remedies","Scoped standing, reinstatement evidence, review, retention and permitted projections"],"out":["Access policy authoring, identity and consent masters, raw audit log ownership, incident command and court or arbitration case management","Executing revocation, surveillance, penalties, payments, notices or erasure; tactical physical enforcement, detention or controlled-item procedures","Universal legal breach definitions, automatic guilt, cross-context reputation scores or executable compliance certification"],"boundaries":[{"neighbor":"WM-XCT-002 Access Contract / Consent","distinction":"Reference the effective policy or grant revision. A breach attachment neither creates consent nor changes a grant."},{"neighbor":"WM-XCT-004 Access Audit","distinction":"Logs and proofs remain audit-owned. The attachment records evidence references and assessment status; a log entry is not a proven violation."},{"neighbor":"WM-ACT-019 Incident / Emergency","distinction":"Response coordination is external. Precautionary containment can precede a responsibility determination and must not be recorded as a punitive sanction by inference."},{"neighbor":"WM-POL-009 Court / Arbitration Case and WM-POL-010 Dispute Forum","distinction":"Legacy A19 is ambiguous across case and forum successors. Reference a case for a proceeding and a forum for authority; do not merge either master into this mixin."},{"neighbor":"WM-XCT-001 Ownership / Stewardship and WM-POL-014 Rights / Entitlements","distinction":"Legacy S1 is split across stewardship and rights. Custody of the attachment does not prove substantive ownership or entitlement."},{"neighbor":"WM-XCT-035 Retention / Disposition and WM-XCT-005 Privacy Aggregation Floor","distinction":"Use external retention rules and separately approved disclosure profiles. Case closure does not erase evidence automatically and an aggregate view is not automatically anonymous."}]},"distinguishingFeatures":["Unlike WM-XCT-002 Access Contract / Consent: Reference the effective policy or grant revision. A breach attachment neither creates consent nor changes a grant.","Unlike WM-XCT-004 Access Audit: Logs and proofs remain audit-owned. The attachment records evidence references and assessment status; a log entry is not a proven violation.","Unlike WM-ACT-019 Incident / Emergency: Response coordination is external. Precautionary containment can precede a responsibility determination and must not be recorded as a punitive sanction by inference.","Unlike WM-POL-009 Court / Arbitration Case and WM-POL-010 Dispute Forum: Legacy A19 is ambiguous across case and forum successors. Reference a case for a proceeding and a forum for authority; do not merge either master into this mixin.","Unlike WM-XCT-001 Ownership / Stewardship and WM-POL-014 Rights / Entitlements: Legacy S1 is split across stewardship and rights. Custody of the attachment does not prove substantive ownership or entitlement.","Unlike WM-XCT-035 Retention / Disposition and WM-XCT-005 Privacy Aggregation Floor: Use external retention rules and separately approved disclosure profiles. Case closure does not erase evidence automatically and an aggregate view is not automatically anonymous."],"structure":{"bundles":[{"id":"b-context","name":"Attachment and applicable authority","description":"Keep host identity, rules and competence explicit.","layers":[{"id":"l-binding","name":"Attachment identity","description":"Require one explicit host reference per attachment and separate affected resource and party references. Link related attachments without merging identities.","findings":[{"id":"f-binding","name":"Host and subject binding","description":"Require one explicit host reference per attachment and separate affected resource and party references. Link related attachments without merging identities.","questions":[{"text":"Which authoritative host, attachment identifier and local revision identify this enforcement context?","id":"q-binding-1","kind":"identity"},{"text":"Which resources, parties and external cases are affected, and which links remain uncertain?","id":"q-binding-2","kind":"relationship"},{"text":"Which custodian maintains the attachment and which external masters retain grants, rights and evidence?","id":"q-binding-3","kind":"ownership"}]}]},{"id":"l-rules","name":"Policy and authority","description":"Pin the relevant rule and effective interval. A role assignment, a policy expression and legal competence are separate assertions.","findings":[{"id":"f-rules","name":"Applicable rules and delegated competence","description":"Pin the relevant rule and effective interval. A role assignment, a policy expression and legal competence are separate assertions.","questions":[{"text":"Which policy, contract or legal profile revision allegedly governs the action and at what time?","id":"q-rules-1","kind":"requirement"},{"text":"Who may investigate, determine a breach, authorize a measure and review it under this profile?","id":"q-rules-2","kind":"authority"},{"text":"Which exceptions, overriding duties or unresolved rule conflicts affect the alleged violation?","id":"q-rules-3","kind":"exception"}]}]}]},{"id":"b-recognition","name":"Recognition and evidence","description":"Separate observations from evaluated assertions.","layers":[{"id":"l-signals","name":"Signals and triage","description":"Keep a report or anomaly distinct from a finding. Failed attempts, permitted exceptions, accidental events and incomplete evidence remain representable.","findings":[{"id":"f-signals","name":"Observation without presumption","description":"Keep a report or anomaly distinct from a finding. Failed attempts, permitted exceptions, accidental events and incomplete evidence remain representable.","questions":[{"text":"What report or observation raised the concern and what action, target and actor attribution does it actually support?","id":"q-signals-1","kind":"event"},{"text":"Is the concern a suspected access violation, a personal-data breach candidate, another incident or an unresolved category?","id":"q-signals-2","kind":"classification"},{"text":"What triage disposition, priority and next review were recorded, including dismissal or linkage to an existing case?","id":"q-signals-3","kind":"decision"}]}]},{"id":"l-evidence","name":"Evidence and chronology","description":"Preserve supporting and contrary material, source access restrictions and clock uncertainty. A digest checks byte integrity, not factual truth.","findings":[{"id":"f-evidence","name":"Traceable and contestable support","description":"Preserve supporting and contrary material, source access restrictions and clock uncertainty. A digest checks byte integrity, not factual truth.","questions":[{"text":"Which evidence supports or challenges each assertion and where is its authoritative retained copy?","id":"q-evidence-1","kind":"evidence"},{"text":"Who collected, transformed or transferred the evidence and what integrity or custody gaps remain?","id":"q-evidence-2","kind":"provenance"},{"text":"How do occurrence, detection, awareness and recording times differ and what uncertainty affects their order?","id":"q-evidence-3","kind":"temporal"}]}]}]},{"id":"b-determination","name":"Determinations and measures","description":"Separate responsibility, authorization and actual effects.","layers":[{"id":"l-assessment","name":"Assessment and outcomes","description":"Represent each allegation separately with pending, substantiated, unsubstantiated, dismissed or overturned assertions under a versioned local vocabulary. Mixed case outcomes and reopening remain possible.","findings":[{"id":"f-assessment","name":"Per-allegation determinations","description":"Represent each allegation separately with pending, substantiated, unsubstantiated, dismissed or overturned assertions under a versioned local vocabulary. Mixed case outcomes and reopening remain possible.","questions":[{"text":"Which action and rule operands were assessed and what evidence standard or method was applied?","id":"q-assessment-1","kind":"validation"},{"text":"What outcome is recorded for each allegation and which reasons, reviewer and unresolved objections qualify it?","id":"q-assessment-2","kind":"state"},{"text":"How are impact and severity assessed separately from responsibility and what limits qualify any counts?","id":"q-assessment-3","kind":"measurement"}]}]},{"id":"l-measures","name":"Measures and execution evidence","description":"Separate precautionary containment from formal sanctions and distinguish proposed, authorized, attempted and observed effects. No source grants this mixin enforcement authority.","findings":[{"id":"f-measures","name":"Precautionary and punitive effects","description":"Separate precautionary containment from formal sanctions and distinguish proposed, authorized, attempted and observed effects. No source grants this mixin enforcement authority.","questions":[{"text":"Is the measure precautionary, remedial or punitive and what authority, purpose and review limit support it?","id":"q-measures-1","kind":"authority"},{"text":"Which external executor and decision record govern the measure and what refusal, partial completion or failure was observed?","id":"q-measures-2","kind":"process"},{"text":"What approved safeguards govern uncertain access decisions, emergency exceptions and revocation propagation?","id":"q-measures-3","kind":"security"}]}]}]},{"id":"b-response","name":"Notification and redress","description":"Track communication and remedy obligations separately.","layers":[{"id":"l-notice","name":"Notice and reporting","description":"Assess notification requirements promptly under the applicable profile without waiting for final attribution or sanction. Do not impose a universal deadline or infer receipt from dispatch.","findings":[{"id":"f-notice","name":"Recipient-specific notification assessment","description":"Assess notification requirements promptly under the applicable profile without waiting for final attribution or sanction. Do not impose a universal deadline or infer receipt from dispatch.","questions":[{"text":"Which recipients, thresholds, awareness triggers and timing rules apply to each notification assessment?","id":"q-notice-1","kind":"requirement"},{"text":"Why was notification required, withheld, phased or delayed and who reviewed that reasoning?","id":"q-notice-2","kind":"exception"},{"text":"What approved content version was dispatched and what delivery, receipt or correction evidence exists?","id":"q-notice-3","kind":"event"}]}]},{"id":"l-redress","name":"Remedies and verification","description":"Track redress obligations and evidence of fulfillment independently of sanctions. An ODRL remedy state is not legal exoneration or erasure of historical evidence.","findings":[{"id":"f-redress","name":"Obligations and redress progress","description":"Track redress obligations and evidence of fulfillment independently of sanctions. An ODRL remedy state is not legal exoneration or erasure of historical evidence.","questions":[{"text":"Which remedies address which allegations, affected interests and beneficiaries?","id":"q-redress-1","kind":"composition"},{"text":"What completion criteria, responsible roles and deadlines govern each remedy and what partial or disputed performance exists?","id":"q-redress-2","kind":"lifecycle"},{"text":"Who verified remedy completion and what residual harm, limitations or follow-up remain?","id":"q-redress-3","kind":"validation"}]}]}]},{"id":"b-review","name":"Review and scoped standing","description":"Support corrections and qualified status projections.","layers":[{"id":"l-review","name":"Challenge and review","description":"Keep review routes and procedural rights profile-specific. Record challenge, stay, correction and outcome references without assuming every appeal suspends every measure.","findings":[{"id":"f-review","name":"Corrections and external proceedings","description":"Keep review routes and procedural rights profile-specific. Record challenge, stay, correction and outcome references without assuming every appeal suspends every measure.","questions":[{"text":"What authorized view, reasons and opportunity to challenge are available to each affected participant?","id":"q-review-1","kind":"access"},{"text":"Which external case and forum handle a referral or challenge and what transmission authority applies?","id":"q-review-2","kind":"relationship"},{"text":"What review outcome changes the determination or measure and how are prior assertions superseded?","id":"q-review-3","kind":"lifecycle"}]}]},{"id":"l-standing","name":"Standing and reinstatement","description":"Standing is a limited projection with source cases, policy version and as-of time, never a universal reputation badge. Reinstatement evidence does not create a new access grant.","findings":[{"id":"f-standing","name":"Scoped derived status","description":"Standing is a limited projection with source cases, policy version and as-of time, never a universal reputation badge. Reinstatement evidence does not create a new access grant.","questions":[{"text":"What standing can be derived for this subject, scope and policy version from active decision records?","id":"q-standing-1","kind":"state"},{"text":"Which stale, missing, stayed or overturned inputs prevent a reliable standing projection?","id":"q-standing-2","kind":"quality"},{"text":"Which conditions and authorized verification support reinstatement and which separate grant decision remains necessary?","id":"q-standing-3","kind":"authority"}]}]}]},{"id":"b-continuity","name":"Stewardship and exchange","description":"Protect evidence and preserve adoption limits.","layers":[{"id":"l-retention","name":"Record stewardship","description":"Balance protected evidence with lawful storage limits. Keep minimal authorized continuity metadata while applying disposition rules to payloads, copies and projections.","findings":[{"id":"f-retention","name":"Retention holds and restricted views","description":"Balance protected evidence with lawful storage limits. Keep minimal authorized continuity metadata while applying disposition rules to payloads, copies and projections.","questions":[{"text":"Which retention schedule, trigger, scoped hold and disposition authority apply to each evidence or case record?","id":"q-retention-1","kind":"retention"},{"text":"What personal or sensitive information is necessary in each permitted view and how are redactions and onward disclosure controlled?","id":"q-retention-2","kind":"privacy"},{"text":"How are corrections and authorized erasure propagated to copies and derived standing while lawful continuity evidence remains?","id":"q-retention-3","kind":"lifecycle"}]}]},{"id":"l-exchange","name":"Interoperability and assurance","description":"Map concepts explicitly and report losses. This research structure neither implements an access engine nor certifies source, legal or runtime conformance.","findings":[{"id":"f-exchange","name":"Mappings and adoption gates","description":"Map concepts explicitly and report losses. This research structure neither implements an access engine nor certifies source, legal or runtime conformance.","questions":[{"text":"Which pinned mappings preserve policy decisions, obligations, evidence lineage and timestamp semantics in export?","id":"q-exchange-1","kind":"interoperability"},{"text":"Which profile and runtime restrictions prevent a local record operation from triggering an external enforcement action?","id":"q-exchange-2","kind":"constraint"},{"text":"Which adversarial fixtures and independent reviews are still required before this profile is operationally accepted?","id":"q-exchange-3","kind":"validation"}]}]}]}]},"agentConduct":{"may":["Record a qualified signal: Proposed and unimplemented. Append a local observation without establishing a breach.","Link evidence and contrary material: Proposed and unimplemented. Record evidence lineage and evaluation links while leaving the source master unchanged.","Record a determination reference: Proposed and unimplemented. Append an authorized external determination for one allegation; do not adjudicate guilt.","Record a measure result: Proposed and unimplemented. Record the evidence of an external measure, notice or remedy operation; do not execute it.","Project scoped standing: Proposed and unimplemented. Compute a proposed local view from eligible evidence-qualified records, with no grant changes.","Validate a restricted export: Proposed and unimplemented. Check a proposed evidence view and mapping for completeness and access before local serialization."],"mustNot":["No automated attribution of guilt, public accusation, universal standing score or implicit grant modification","Deny by default for attachment reads and writes unless the host policy explicitly authorizes purpose, role, scope and record view.","This is the proposed local storage rule, not a claim that every XACML enforcement profile is deny-biased."],"requiresHuman":[]},"ethics":{"considerations":["Privacy and records custodian","This is the proposed local storage rule, not a claim that every XACML enforcement profile is deny-biased.","Access policy authoring, identity and consent masters, raw audit log ownership, incident command and court or arbitration case management","Executing revocation, surveillance, penalties, payments, notices or erasure; tactical physical enforcement, detention or controlled-item procedures","WM-XCT-002 Access Contract / Consent","A breach attachment neither creates consent nor changes a grant.","WM-XCT-035 Retention / Disposition and WM-XCT-005 Privacy Aggregation Floor"],"affectedParties":[]},"owners":{"steward":"Identify the responsible enforcement registrar role and host custodian without using company names as owners","roles":[{"name":"Enforcement registrar","responsibilities":["Maintain host bindings, case references and qualified record revisions"]},{"name":"Investigator","responsibilities":["Collect permitted evidence and record uncertainty and contrary material"]},{"name":"Authorized decision reviewer","responsibilities":["Verify competence, reasons, measure scope and challenge handling"]},{"name":"Remedy verifier","responsibilities":["Evaluate completion evidence without granting access or absolving responsibility"]},{"name":"Privacy and records custodian","responsibilities":["Approve restricted views, retention schedules and disposition holds"]},{"name":"Independent assessor","responsibilities":["Evaluate mappings, adversarial fixtures and remaining assurance gaps"]}],"masterSystems":[]},"relations":[{"target":"WM-XCT-002","type":"references","note":"Candidate binding to the effective access instrument; resolve its identity and revision before use."},{"target":"WM-XCT-004","type":"references","note":"Candidate binding to audit evidence masters; do not copy their lifecycle."},{"target":"WM-XCT-001","type":"references","note":"Candidate custodian and stewardship binding; substantive rights remain separately evidenced."},{"target":"WM-POL-014","type":"references","note":"Candidate rights and entitlement reference when relevant; legacy S1 does not select a unique successor."},{"target":"WM-ACT-019","type":"references","note":"Candidate incident response context; operational command remains external."},{"target":"WM-POL-009","type":"references","note":"Optional external adjudication case; legacy A19 also refers to a forum, so resolve explicitly."},{"target":"WM-POL-010","type":"references","note":"Optional forum authority reference distinct from a proceeding."},{"target":"WM-XCT-035","type":"references","note":"Candidate retention and disposition profile with scoped legal holds."},{"target":"WM-XCT-005","type":"references","note":"Candidate aggregate disclosure policy; no automatic anonymity guarantee."},{"target":"ODRL 2.2","type":"aligned","note":"Conceptual policy, duty and remedy alignment; not a mapping implementation or legal judgment."},{"target":"XACML 3.0","type":"aligned","note":"Conceptual decision and enforcement-point distinction; selected bias and obligations need a runtime profile."},{"target":"PROV-O","type":"aligned","note":"Conceptual evidence derivation and attribution; not a truth or authority certificate."},{"target":"WM-XCT-002 Access Contract / Consent","type":"neighbor","note":"Reference the effective policy or grant revision. A breach attachment neither creates consent nor changes a grant."},{"target":"WM-XCT-004 Access Audit","type":"neighbor","note":"Logs and proofs remain audit-owned. The attachment records evidence references and assessment status; a log entry is not a proven violation."},{"target":"WM-ACT-019 Incident / Emergency","type":"neighbor","note":"Response coordination is external. Precautionary containment can precede a responsibility determination and must not be recorded as a punitive sanction by inference."},{"target":"WM-POL-009 Court / Arbitration Case and WM-POL-010 Dispute Forum","type":"neighbor","note":"Legacy A19 is ambiguous across case and forum successors. Reference a case for a proceeding and a forum for authority; do not merge either master into this mixin."},{"target":"WM-XCT-001 Ownership / Stewardship and WM-POL-014 Rights / Entitlements","type":"neighbor","note":"Legacy S1 is split across stewardship and rights. Custody of the attachment does not prove substantive ownership or entitlement."},{"target":"WM-XCT-035 Retention / Disposition and WM-XCT-005 Privacy Aggregation Floor","type":"neighbor","note":"Use external retention rules and separately approved disclosure profiles. Case closure does not erase evidence automatically and an aggregate view is not automatically anonymous."}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier and namespace","Owner-issued stable record identifier scoped to host and attachment","Content digest as integrity aid only, never sufficient subject identity"]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":[]},"capabilities":{"applicability":"required","items":["Record a qualified signal: Proposed and unimplemented. Append a local observation without establishing a breach.","Link evidence and contrary material: Proposed and unimplemented. Record evidence lineage and evaluation links while leaving the source master unchanged.","Record a determination reference: Proposed and unimplemented. Append an authorized external determination for one allegation; do not adjudicate guilt.","Record a measure result: Proposed and unimplemented. Record the evidence of an external measure, notice or remedy operation; do not execute it.","Project scoped standing: Proposed and unimplemented. Compute a proposed local view from eligible evidence-qualified records, with no grant changes.","Validate a restricted export: Proposed and unimplemented. Check a proposed evidence view and mapping for completeness and access before local serialization."]},"hazards":{"applicability":"optional","items":[]},"interfaces":{"applicability":"required","items":["PROV-O: The PROV Ontology"]},"context":{"applicability":"required","items":["NIST publications are control and incident-response guidance, not a universal legal mandate","EDPB guidance and Charter Article 47 are bounded EU examples; applicability and jurisdiction must be supplied by the adopting profile"]}},"sources":[{"title":"ODRL Information Model 2.2","url":"https://www.w3.org/TR/odrl-model/","note":"World Wide Web Consortium"},{"title":"eXtensible Access Control Markup Language Version 3.0","url":"https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html","note":"OASIS Open"},{"title":"Incident Response Recommendations and Considerations for Cybersecurity Risk Management","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf","note":"National Institute of Standards and Technology"},{"title":"Security and Privacy Controls for Information Systems and Organizations","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf","note":"National Institute of Standards and Technology"},{"title":"Guidelines 9/2022 on personal data breach notification under GDPR","url":"https://www.edpb.europa.eu/system/files/2023-04/edpb_guidelines_202209_personal_data_breach_notification_v2.0_en.pdf","note":"European Data Protection Board"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/rfc/rfc3339.html","note":"Internet Engineering Task Force"},{"title":"EU Charter Article 47 - Right to an effective remedy and to a fair trial","url":"https://fra.europa.eu/en/eu-charter/charter/article/47-right-effective-remedy-and-fair-trial","note":"European Union Agency for Fundamental Rights"}],"openQuestions":["Complete direct source checks, version reconciliation and qualified current-law applicability review without treating HTTP success as claim verification.","Implement and test profiles for mixed outcomes, uncertain authority, early notification, partial effects, stayed sanctions, stale standing, overturned allegations and lawful scoped disposal.","Restore independent external review before canonical or publishable-draft promotion.","Independent second-provider review is absent under the owner waiver","Direct HTTP checks were not attempted under the owner-reported sandbox block; no HTTP status measured","SP 800-53 release 5.2.0 is announced but changes are not reconciled with the selected 2020 PDF","Current consolidated law, sector-specific sanctions, employment rules and physical access profiles require qualified review","Candidate object fields lack nested schemas, executable calendars, pinned neighbor interfaces and acceptance fixtures"],"resources":{"spec":"/models/wm-xct-007-access-breach-enforcement/spec.yaml","agents":"/models/wm-xct-007-access-breach-enforcement/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-007"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-xct-007-access-breach-enforcement/spec.yaml"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-10-06T13:39:40Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"derived","structure":"filled","agentConduct":"derived","ethics":"derived","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"missing","interaction.capabilities":"filled","interaction.hazards":"missing","interaction.interfaces":"derived","interaction.context":"filled","sources":"filled"},"notes":{"distinguishingFeatures":"Derived from boundary notes against neighbouring models.","agentConduct":"Derived from functions, policies, CRUD and access rules; prohibitions were not authored for agents as such.","ethics":"Sentences mentioning harm, privacy, consent or similar, collected from the specification.","interaction.properties":"Institutional or informational subject: no invented physical properties."},"score":0.75}}