{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-012","code":"wm-xct-012-provenance","url":"https://ver.cy/models/wm-xct-012-provenance/","name":"Provenance","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.PROV"],"industry":["Cross-industry"],"navPath":"NAV.XCT.PROV","tags":["provenance","xct.prov"],"facets":{}},"whatItIs":"Provenance is modelled as a mix-in applied to a host subject (digital asset, dataset, record, software artifact, physical item, statement or agent output). It covers the origin, derivation graph, responsible agents, activities and plans, custody history, temporal and spatial context, integrity and attestation evidence, verification outcome and confidence, regulatory disclosure, discovery/access, redaction and retention of provenance itself. It does not define the subject's own domain semantics, nor does it re-define agents, rights, retention schedules, access policy or data-quality metrics that belong to composable sibling models; it references them. The model is storage- and interface-neutral: JSON, YAML, Markdown, RDF, JUMBF, Git, MCP and MongoDB are projections of these semantics, not the semantics.","purpose":"Provide a format-neutral, attachable provenance dimension that lets an agent state, verify and govern where a subject came from, what acted on it, who is responsible, in what custody it has been, and how strongly each of those statements is evidenced.","scope":{"in":["Origination: the activity, agent, instrument, place and time at which the subject first came into being, including capture context and whether the account is first-hand or reconstructed.","Derivation and lineage: entity-to-entity relations (derivation, revision, quotation, primary source, ingredient, aggregation, transformation) and the traversable ancestor/descendant graph.","Activities, process steps, plans, algorithms, build definitions and their parameters and resolved dependencies.","Agents, agent types (person, organisation, software agent, mechanism, device), qualified roles, delegation and on-behalf-of responsibility.","Chain of custody: successive holders, accession and transfer events, and changes in ownership or control significant to authenticity.","Time semantics: separation of event/occurrence time from record/observation time, intervals, ordering constraints, invalidation and trusted timestamping.","Integrity evidence: fixity digests, integrity methods, hard content bindings, soft bindings (watermark/fingerprint), signatures and seals.","Attestation layer: who asserts the provenance, the signed envelope, trust anchors, credential status, revocation and validation outcome.","Confidence, completeness, unknown provenance, inferred versus asserted statements, and reconciliation of conflicting provenance claims.","Regulatory disclosure duties attached to provenance: machine-readable marking of synthetic content, training-data lineage summaries, source-of-personal-data disclosure.","Discovery of and access to provenance records, provenance-of-provenance bundling, redaction, minimisation and selective disclosure.","Retention, disposition and deletion of provenance records considered independently of the subject's own retention."],"out":["The host subject's substantive content model, schema or domain semantics (supplied by the host model into which this mix-in is composed).","Rights, licence terms and permissions adjudication; provenance references a rights statement but does not define rights semantics.","The authoritative registry and resolution of agent, organisation and person identity; provenance references governed agent identifiers.","Access-control policy definition and enforcement; provenance records that an access decision occurred as evidence, it is not the policy engine.","Definition of data-quality metrics and thresholds; provenance supplies evidence that quality assessment consumes.","Retention schedules and disposition authorities as legal instruments; provenance cites the applicable schedule identifier.","Cryptographic algorithm registries, key management, PKI and trust-list operation; provenance references keys, certificates and trust lists as external artefacts.","Storage-layer mechanics of versioning systems, object stores, ledgers or content-addressed file layouts; these are projections.","Business-process semantics of supply-chain steps, clinical workflows or build systems beyond the provenance facts they emit.","Physical measurement and sensor semantics; provenance records the observation act, not the observable property model."],"boundaries":[{"neighbor":"Audit log / AuditEvent model","distinction":"Provenance describes how an entity came to be and who is responsible for it; audit logging describes who accessed or attempted an operation on a system. FHIR draws the same line: Provenance is generation-focused while AuditEvent covers usage and other activity. Read events belong to the audit sibling unless they generated a new entity."},{"neighbor":"Version control / revision history model","distinction":"A revision chain is one derivation relation (prov:wasRevisionOf, dcterms:isVersionOf) among many. Commit graphs, branches and merges are a storage projection; this model captures the derivation and responsibility facts that survive migration off any given VCS."},{"neighbor":"Rights and licensing model","distinction":"dcterms:provenance covers changes in ownership and custody significant to authenticity, integrity and interpretation; it is not the licence. Rights holders and licence documents are referenced as external agents and documents."},{"neighbor":"Archival description model (fonds / respect des fonds)","distinction":"In archival practice 'provenance' primarily denotes the creator and the accumulating body of a fonds; here that sense is carried by origination agent plus custody history, while the transformation graph is modelled separately. The homonym must be disambiguated when mapping to RiC-CM."},{"neighbor":"Software bill of materials (SBOM) model","distinction":"An SBOM enumerates composition at a point in time; provenance states how that composition was produced and by whom. SPDX Element creation information and in-toto/SLSA build predicates are alignments, not the SBOM inventory itself."},{"neighbor":"Supply-chain traceability event model (EPCIS)","distinction":"EPCIS what/when/where/why events are an authoritative source of physical-object provenance, but the business-step and disposition vocabularies remain in the traceability sibling; this model consumes the events as origination, transfer and transformation facts."},{"neighbor":"Geospatial lineage metadata","distinction":"ISO 19115 lineage (statement, process step, source) is a domain projection of the same activity/entity structure; the geospatial resolution, reference system and citation fields stay with the geospatial metadata sibling."},{"neighbor":"Content authenticity manifest (C2PA)","distinction":"A C2PA manifest is a signed transport of provenance bound to a media asset. This model treats manifests, claims, assertions and ingredients as artefacts and evidence; JUMBF embedding, codec-specific box hashing and trust-list operation stay outside."},{"neighbor":"Data quality model","distinction":"Provenance is evidence for quality judgements (FAIR R1.2 requires detailed provenance) but does not define accuracy, completeness or fitness metrics; a quality assessment is itself an activity with its own provenance."},{"neighbor":"Records retention and disposition model","distinction":"Disposition authorities, schedules and approval flows belong to the records sibling; provenance records the disposition event and retains the evidence that it happened, and may itself be subject to a different retention period than the subject."}]},"distinguishingFeatures":["Provenance describes where something came from and how it was made, not whether it is true or good.","It differs from an audit log, which records access and actions on a system.","Derivation, custody and creation are separate relations.","Absent provenance is explicit, never inferred."],"structure":{"bundles":[{"id":"subject-anchoring-and-record-identity","name":"Subject Anchoring and Provenance Record Identity","description":"Establishes precisely what the provenance is about, at what granularity, and how the provenance assertion itself is identified, versioned and made subject to its own provenance.","layers":[{"id":"subject-anchor","name":"Subject Anchor and Granularity","description":"How the provenance statement is bound to the thing it describes, including granularity, fixed aspects and the contract by which the mix-in attaches to a host model.","findings":[{"id":"provenance-subject-anchor","name":"Provenance subject anchor","description":"The identified target that the provenance record describes, expressed so that a verifier can decide whether a given bitstream or record in hand is the subject.","questions":[{"text":"Which identified entity, at which identifier authority, is this provenance record about?","id":"what-is-the-subject","kind":"identity"},{"text":"By what mechanism does a verifier confirm that an artifact in hand is the anchored subject?","id":"how-is-subject-matched","kind":"validation"},{"text":"Does this record anchor more than one subject, and are the statements distributive or joint over them?","id":"multiple-subjects","kind":"composition"},{"text":"What happens to the anchor when the subject is re-encoded, re-serialised or migrated to another format?","id":"anchor-stability","kind":"lifecycle"}]},{"id":"subject-granularity-and-fixed-aspects","name":"Subject granularity and fixed aspects","description":"The level at which provenance is asserted (conceptual work, representation, file, bitstream, byte range, record field, physical instance) and which aspects of the entity are held fixed by the statement.","questions":[{"text":"At which granularity level is this provenance asserted, and is the same statement inherited by finer levels?","id":"granularity-level","kind":"classification"},{"text":"Which aspects of the entity does the statement treat as fixed, such that changing them yields a different entity?","id":"fixed-aspects","kind":"definition"},{"text":"If provenance covers only part of the subject, which part is covered and what is explicitly not covered?","id":"partial-coverage","kind":"constraint"}]},{"id":"mixin-attachment-contract","name":"Mix-in attachment contract","description":"The obligations a host model accepts when it composes this provenance mix-in: which provenance elements become required, where they attach, and what the host must expose for anchoring.","questions":[{"text":"Which provenance elements become mandatory for every instance of the host entity once the mix-in is applied?","id":"required-on-attach","kind":"requirement"},{"text":"Where does provenance attach — on the host entity, on each of its versions, or on a separate assertion object?","id":"attachment-point","kind":"composition"},{"text":"What must the host model guarantee about its own identifiers and version boundaries for provenance to remain verifiable?","id":"host-obligations","kind":"interoperability"}]}]},{"id":"provenance-record-identity","name":"Provenance Record Identity and Meta-Provenance","description":"Identity, immutability and versioning of the provenance assertion itself, and the provenance of that assertion.","findings":[{"id":"provenance-assertion-record-identity","name":"Provenance assertion record identity","description":"How an individual provenance assertion or bundle is identified, versioned and treated as append-only, so that statements can be cited, superseded and audited without silent mutation.","questions":[{"text":"What identifier does this provenance assertion carry, and who minted it?","id":"assertion-id","kind":"identity"},{"text":"Is the assertion immutable once issued, and how is a correction expressed?","id":"assertion-immutability","kind":"lifecycle"},{"text":"How are successive assertions about the same subject ordered and reconciled into a current view?","id":"assertion-versioning","kind":"state"},{"text":"Which agent issued the assertion, as distinct from the agents named inside it?","id":"assertion-authorship","kind":"provenance"}]},{"id":"provenance-of-provenance","name":"Provenance of the provenance record","description":"Treating a provenance bundle as an entity in its own right so that its own origin, author, transformations and trust can be described and audited.","questions":[{"text":"Is this provenance bundle itself described as an entity with its own generation activity and responsible agent?","id":"bundle-as-entity","kind":"provenance"},{"text":"How many levels of provenance-about-provenance are retained, and where does the chain terminate?","id":"meta-depth","kind":"constraint"},{"text":"When provenance from several sources is merged, what records which statement came from which source bundle?","id":"aggregation-provenance","kind":"provenance"}]}]}]},{"id":"origin-derivation-and-lineage","name":"Origin, Derivation and Lineage","description":"Where the subject came from: its origination, its sources and ingredients, the derivation relations that connect it to prior entities, and how far the resulting lineage can be traversed and trusted.","layers":[{"id":"origination-and-source","name":"Origination and Source","description":"The first-instance creation or capture of the subject and the identified prior resources it came from.","findings":[{"id":"origination-event","name":"Origination event","description":"The act by which the subject first came into existence, including the instrument or device used, the responsible agent, the place and the generation time.","questions":[{"text":"Which activity generated the subject, and what type of origination was it (capture, authoring, synthesis, derivation, accession)?","id":"origination-activity","kind":"event"},{"text":"What instrument, device or software produced the subject, and at what version?","id":"origination-instrument","kind":"provenance"},{"text":"Was the origination observed and recorded at the time, or reconstructed after the fact?","id":"first-hand-or-reconstructed","kind":"evidence"},{"text":"If origination is unknown, is that recorded explicitly rather than left absent?","id":"origination-completeness","kind":"quality"}]},{"id":"primary-source-and-ingredients","name":"Primary sources and ingredients","description":"The identified prior resources that contributed to the subject, distinguishing a primary source from intermediate sources and recording each contributor with its own provenance status.","questions":[{"text":"Which prior entities were used as sources or ingredients, and in what role did each contribute?","id":"which-sources","kind":"relationship"},{"text":"Which source, if any, is the primary source — the originating rather than intermediate account?","id":"primary-source-flag","kind":"classification"},{"text":"For each source, is its own provenance known, absent, or explicitly unknown?","id":"source-provenance-status","kind":"quality"},{"text":"Which dependencies were resolved at the time of production, and were they pinned by digest?","id":"resolved-dependencies","kind":"constraint"}]}]},{"id":"derivation-graph","name":"Derivation Graph and Traversal","description":"The typed relations that link entities across generations and the practical limits of traversing them.","findings":[{"id":"derivation-and-influence-relations","name":"Derivation and influence relations","description":"The typed entity-to-entity relations — derivation, revision, quotation, primary source, instantiation, removal, membership, transformation — and the qualification that records how and by which activity each relation came about.","questions":[{"text":"Which typed relation holds between the subject and each related entity, and is a weaker generic influence relation being used because the specific type is unknown?","id":"relation-type","kind":"relationship"},{"text":"Through which activity, role and time did the relation come about?","id":"relation-qualification","kind":"process"},{"text":"For transformations that consume inputs and produce new outputs, is the input-to-output correspondence one-to-one, many-to-one or unresolvable?","id":"transformation-semantics","kind":"composition"},{"text":"Is the relation asserted forwards from the subject, backwards from a descendant, or both, and which direction is authoritative?","id":"directionality","kind":"authority"}]},{"id":"lineage-completeness-and-traversal","name":"Lineage completeness and traversal limits","description":"How far back and forward the lineage is claimed to be complete, where it is truncated, and how unknown provenance is represented rather than implied by absence.","questions":[{"text":"Over what span is the lineage claimed complete, and is completeness asserted or merely not contradicted?","id":"claimed-completeness","kind":"quality"},{"text":"At which nodes does the recorded lineage stop, and why — unknown provenance, redaction, out-of-scope, or an external boundary?","id":"truncation-points","kind":"exception"},{"text":"What depth, breadth and cost limits apply when an agent traverses the graph, and what is returned when a limit is hit?","id":"traversal-limits","kind":"process"},{"text":"How are cycles or self-referential derivations detected and reported?","id":"cycle-handling","kind":"validation"}]},{"id":"generation-usage-and-communication-constraints","name":"Generation, usage and communication","description":"Generation is the completion of production of a new entity by an activity. Usage is the beginning of utilizing an entity. Communication is exchange of some unspecified entity between two activities.","questions":[{"text":"Which activity generated this entity, at what time, and in what role?","id":"generation-usage-and-communication-constraints-q01","kind":"event"},{"text":"Which entities did this activity use, at what times, and did usage consume them?","id":"generation-usage-and-communication-constraints-q02","kind":"event"},{"text":"Was this activity informed by another activity, implying an unspecified exchanged entity?","id":"generation-usage-and-communication-constraints-q03","kind":"relationship"},{"text":"Is there at most one generation of this entity in this instance, as required for valid PROV?","id":"generation-usage-and-communication-constraints-q04","kind":"validation"}]}]}]},{"id":"agency-activity-and-custody","name":"Agency, Activity and Custody","description":"Who and what acted, under whose authority, with which plan, and in whose hands the subject has been over time.","layers":[{"id":"activities-and-plans","name":"Activities, Process Steps and Plans","description":"The acts that operated on the subject and the plans, algorithms, mandates and authorisations that governed them.","findings":[{"id":"activity-and-process-step","name":"Activity and process step","description":"An act occurring over a period that used and generated entities, described with enough parameter detail to explain or reproduce its effect on the subject.","questions":[{"text":"What identifies this activity and what type of act was it?","id":"activity-identity-type","kind":"identity"},{"text":"Which parameters were externally supplied and which were internal to the executing platform?","id":"activity-parameters","kind":"process"},{"text":"Which entities did the activity use, and which did it generate or invalidate?","id":"activity-inputs-outputs","kind":"composition"},{"text":"Is the activity claimed to be reproducible, and what would be needed to repeat it?","id":"activity-reproducibility","kind":"evidence"}]},{"id":"plan-mandate-and-authorisation","name":"Plan, mandate and authorisation","description":"The plan, policy, mandate or legal authority under which an activity was carried out, distinguishing what was intended from what occurred.","questions":[{"text":"Which plan, protocol, workflow or algorithm was the activity intended to follow?","id":"governing-plan","kind":"authority"},{"text":"Under which mandate, policy or legal basis was the activity authorised?","id":"legal-mandate","kind":"authority"},{"text":"Did execution deviate from the plan, and is the deviation recorded?","id":"plan-versus-execution","kind":"exception"}]},{"id":"start-end-and-invalidation-events","name":"Start, end and invalidation","description":"Activities are delimited by start and end events; entities cease to be available after invalidation. These instantaneous events carry optional times and triggering entities or activities.","questions":[{"text":"Which entity or activity started this activity, and at what time?","id":"start-end-and-invalidation-events-q01","kind":"lifecycle"},{"text":"Which entity or activity ended this activity, and at what time?","id":"start-end-and-invalidation-events-q02","kind":"lifecycle"},{"text":"Which activity invalidated this entity, at what time, and is the entity no longer available for use?","id":"start-end-and-invalidation-events-q03","kind":"state"}]}]},{"id":"agents-and-attribution","name":"Agents, Attribution and Delegation","description":"The parties and mechanisms bearing responsibility, their qualified roles, and the chain by which responsibility is delegated.","findings":[{"id":"agent-identity-type-and-role","name":"Agent identity, type and role","description":"Identification and typing of each responsible party — person, organisation, position, software agent or mechanism — together with the qualified role it played.","questions":[{"text":"Which identifier and authority identify each responsible agent?","id":"agent-identity","kind":"identity"},{"text":"What kind of agent is it — person, group, organisation, position, software agent or device?","id":"agent-type","kind":"classification"},{"text":"In what role did the agent participate in the activity or in relation to the entity?","id":"agent-role","kind":"relationship"},{"text":"Where a natural person is named, is a position or organisational role recorded as well so that the record survives staff change?","id":"agent-substitutability","kind":"privacy"}]},{"id":"delegation-and-responsibility-chain","name":"Delegation and responsibility chain","description":"How responsibility passes upward from an acting agent to the party on whose behalf it acted, including the separation of the tool that generated a claim from the party that signed it.","questions":[{"text":"On whose behalf did each acting agent operate, and how far up does the chain go?","id":"on-behalf-of","kind":"ownership"},{"text":"Which component generated the provenance claim, and which party signed it — are they the same?","id":"generator-versus-signer","kind":"authority"},{"text":"Which named party accepts responsibility for the accuracy of the assertion?","id":"liability-locus","kind":"ownership"}]},{"id":"chain-of-custody-and-transfer","name":"Chain of custody and transfer","description":"The ordered succession of parties that held or controlled the subject, and the accession, transfer and disposition events that moved it between them.","questions":[{"text":"Which parties have held or controlled the subject, in what order, and over which intervals?","id":"custody-sequence","kind":"temporal"},{"text":"What transfer, accession or acquisition event moved custody, and under what instrument?","id":"transfer-events","kind":"event"},{"text":"Did legal ownership change at the same time as physical or logical custody?","id":"ownership-versus-custody","kind":"ownership"},{"text":"What evidence supports each custody claim, and does any interval rest on inference alone?","id":"custody-evidence","kind":"evidence"}]}]}]},{"id":"temporal-and-spatial-context","name":"Temporal and Spatial Context","description":"When each provenance fact occurred versus when it was recorded, the ordering rules that make a provenance instance internally consistent, the trust placed in clocks, and where activities took place.","layers":[{"id":"time-semantics","name":"Time Semantics and Ordering","description":"Distinct time axes, ordering constraints and externally trusted time.","findings":[{"id":"event-time-versus-record-time","name":"Event time versus record time","description":"Separate recording of when a provenance-relevant event occurred and when it was observed, ingested or recorded, each with an explicit offset, so that late, backdated and replayed records remain interpretable.","questions":[{"text":"Which time axes are recorded for this fact — occurrence, observation, ingestion, publication, validity — and which are mandatory?","id":"which-time-axes","kind":"temporal"},{"text":"Is each timestamp expressed with an explicit UTC offset or Z, and is the local zone offset at the place of the event preserved separately?","id":"offset-and-zone","kind":"temporal"},{"text":"What is the permitted gap between occurrence and recording, and how is a backdated or late record flagged?","id":"latency-and-backdating","kind":"constraint"},{"text":"What precision is claimed for each timestamp, and is a coarse value being stored in a fine-grained field?","id":"precision-and-granularity","kind":"measurement"}]},{"id":"ordering-and-validity-constraints","name":"Ordering and validity constraints","description":"The consistency conditions that make a provenance instance safe to reason over, including generation-before-use ordering, single generation per entity, invalidation and non-reflexive specialisation.","questions":[{"text":"Which ordering constraints are enforced, and which are merely reported as warnings?","id":"ordering-checks","kind":"validation"},{"text":"Has the entity been invalidated, destroyed or expired, and at what time?","id":"invalidation","kind":"lifecycle"},{"text":"When two statements share an identifier, are they merged, and what happens if their attributes conflict?","id":"merge-uniqueness","kind":"validation"},{"text":"Is the provenance instance normalised and declared valid, and against which constraint set?","id":"instance-validity","kind":"quality"}]},{"id":"trusted-timestamping","name":"Trusted timestamping and clock trust","description":"Use of an external time authority to prove that a provenance assertion existed at a point in time, and the treatment of self-declared clocks as weaker evidence.","questions":[{"text":"Is a trusted time-stamp token present, and which time authority issued it?","id":"timestamp-authority","kind":"evidence"},{"text":"For timestamps without an external token, what clock produced them and what is its known accuracy?","id":"clock-source","kind":"provenance"},{"text":"How is the assertion evaluated after the signing credential expires, and does the time-stamp preserve its evidential value?","id":"post-expiry-validity","kind":"lifecycle"}]}]},{"id":"place-and-jurisdiction","name":"Place and Jurisdiction","description":"Where activities occurred and which legal order governs the resulting provenance facts.","findings":[{"id":"activity-location-and-jurisdiction","name":"Activity location and jurisdiction","description":"The physical or logical place at which an activity occurred or an object was observed, and the jurisdiction whose rules attach to that fact.","questions":[{"text":"At what place did the activity occur or the observation take place?","id":"where-occurred","kind":"spatial"},{"text":"Where a physical place is meaningless, what logical location applies — system, region, tenancy or endpoint?","id":"logical-location","kind":"spatial"},{"text":"Which jurisdiction governs the activity and the resulting provenance record, and does it differ from where the record is stored?","id":"governing-jurisdiction","kind":"authority"}]}]}]},{"id":"integrity-evidence-and-trust","name":"Integrity Evidence, Attestation and Trust","description":"The evidence that makes provenance believable: fixity values, content bindings, signed attestations, trust anchors and credential status, and the resulting verification outcome and confidence.","layers":[{"id":"fixity-and-binding","name":"Fixity and Content Binding","description":"Digest-based integrity evidence and the methods that bind a provenance record to the bytes or the perceptual content of its subject.","findings":[{"id":"fixity-and-integrity-methods","name":"Fixity and integrity methods","description":"Recorded digests and other integrity methods over the subject, their algorithms, who computed them and when they were last verified.","questions":[{"text":"Which digest values over which algorithms are recorded for the subject, and over exactly what byte extent?","id":"which-digests","kind":"evidence"},{"text":"Who or what computed each digest, and is it independently reproducible?","id":"digest-originator","kind":"provenance"},{"text":"When was fixity last verified, with what outcome, and on what schedule is it re-checked?","id":"fixity-check-history","kind":"process"},{"text":"What happens when a digest algorithm is deprecated — are historic digests retained alongside new ones?","id":"algorithm-agility","kind":"lifecycle"}]},{"id":"subject-binding-hard-and-soft","name":"Hard and soft binding to the subject","description":"The mechanisms that tie a provenance record to its subject — cryptographic hard bindings over byte or box ranges, and soft bindings such as watermarks and perceptual fingerprints that survive re-encoding but do not prove integrity.","questions":[{"text":"Which binding methods are in force, and does the record rely on a hard binding, a soft binding, or both?","id":"binding-method","kind":"classification"},{"text":"What does each binding actually prove — byte integrity, perceptual identity, or mere association?","id":"binding-strength","kind":"evidence"},{"text":"Is the provenance carried inside the subject, alongside it, or only in an external store, and what happens if it is stripped?","id":"embedded-or-detached","kind":"interoperability"},{"text":"Is the binding machine-readable and detectable by a third party without prior arrangement?","id":"machine-readability","kind":"requirement"}]}]},{"id":"attestation-and-trust","name":"Attestation, Signature and Trust Status","description":"The signed envelope carrying provenance and the trust machinery that decides whether its signer is acceptable.","findings":[{"id":"signed-attestation-envelope","name":"Signed attestation envelope","description":"The separation between the payload of provenance statements, the predicate type that types it, and the signature that binds it to a signer identity.","questions":[{"text":"What is the envelope structure — payload, payload type, signature — and which parts are covered by the signature?","id":"envelope-structure","kind":"security"},{"text":"Which identity signed the assertion, evidenced by which credential?","id":"signer-identity","kind":"identity"},{"text":"Which statements does the signer originate and take responsibility for, and which were merely gathered from other components?","id":"created-versus-gathered","kind":"authority"},{"text":"Can the signature be verified without the original transport, and what canonical form must be reconstructed?","id":"detached-signature","kind":"validation"}]},{"id":"trust-anchors-and-revocation","name":"Trust anchors, credential status and revocation","description":"How a verifier decides that a signer is acceptable, and how expiry, revocation and trust-list changes alter a previously accepted verdict over time.","questions":[{"text":"Against which trust anchors or trust lists is the signer evaluated, and who curates that list?","id":"trust-anchor-set","kind":"authority"},{"text":"What was the credential status at signing time and at verification time — valid, expired, revoked or unknown?","id":"credential-status","kind":"state"},{"text":"Can a previously trusted assertion become untrusted, and is the earlier verdict retained rather than overwritten?","id":"verdict-stability","kind":"lifecycle"},{"text":"How is an assertion from an unrecognised but cryptographically sound signer treated?","id":"unknown-signer","kind":"exception"}]},{"id":"claim-generator-signer-and-builder-trust","name":"Claim generator, signer and builder","description":"C2PA distinguishes claim generator, signer and actor. SLSA builder.id is the transitive closure of the trusted build platform. Signer identity is the basis of the C2PA trust model and must be paired with accepted builder identities for SLSA.","questions":[{"text":"Which hardware or software generated the claim, on which operating system, and against which specification version?","id":"claim-generator-signer-and-builder-trust-q01","kind":"authority"},{"text":"Who is the credential holder that signed the claim, and which certificate, EKU and trust list apply?","id":"claim-generator-signer-and-builder-trust-q02","kind":"authority"},{"text":"What builder.id represents the trusted platform, and which fields were tenant-generated rather than control-plane-generated?","id":"claim-generator-signer-and-builder-trust-q03","kind":"security"}]}]},{"id":"verification-and-confidence","name":"Verification Outcome and Confidence","description":"The reportable result of checking provenance and the honest expression of uncertainty, gaps and disagreement.","findings":[{"id":"verification-outcome-and-status","name":"Verification outcome and status codes","description":"The graded outcome of verification — structurally well-formed, cryptographically valid, trusted — expressed with per-check status codes rather than a single boolean.","questions":[{"text":"What grade did verification reach, and which specific checks passed, failed or were skipped?","id":"outcome-grade","kind":"validation"},{"text":"When some checks fail, is the remaining provenance still usable and under what caveat?","id":"partial-failure","kind":"exception"},{"text":"How does a producer retract or correct a previously published provenance statement it now knows to be wrong?","id":"error-declaration-q","kind":"process"},{"text":"How often is verification repeated, and what triggers an out-of-cycle re-verification?","id":"reverification-cadence","kind":"process"}]},{"id":"confidence-gaps-and-conflicts","name":"Confidence, gaps and conflicting claims","description":"Explicit representation of how strongly each provenance statement is supported, where evidence is missing, and how two irreconcilable accounts of the same subject are held side by side.","questions":[{"text":"Is each statement directly recorded, inferred from other statements, or asserted without supporting evidence?","id":"assertion-basis","kind":"evidence"},{"text":"How is confidence expressed, and is the scale defined well enough to be compared across producers?","id":"confidence-expression","kind":"measurement"},{"text":"When two producers assert incompatible provenance for the same subject, are both retained and how is precedence decided?","id":"conflicting-accounts","kind":"decision"},{"text":"Does absence of a provenance statement mean the fact is unknown, not applicable, or withheld?","id":"absence-semantics","kind":"definition"}]}]}]},{"id":"governance-disclosure-and-exchange","name":"Governance, Disclosure and Exchange","description":"The obligations attached to provenance in law and policy, how provenance is discovered and accessed, how it is redacted or minimised, how long it is kept, and how it maps to neighbouring vocabularies.","layers":[{"id":"regulatory-disclosure","name":"Regulatory Disclosure Duties","description":"Provenance facts that specific legal instruments require to be recorded, marked or disclosed.","findings":[{"id":"synthetic-content-and-training-disclosure","name":"Synthetic content marking and training-data lineage","description":"Provenance obligations for AI-generated or manipulated output, including machine-readable marking, detectability, deepfake disclosure and summary-level disclosure of training content.","questions":[{"text":"Was the subject wholly or partly generated or manipulated by an AI system, and which parts?","id":"ai-generation-status","kind":"classification"},{"text":"By what mechanism is the AI-generated status marked so that it is machine-readable and detectable downstream?","id":"marking-mechanism","kind":"requirement"},{"text":"What summary of training content is available for the generating model, and at what level of detail?","id":"training-lineage","kind":"provenance"},{"text":"Where a person must be told that content is artificially generated or manipulated, when and how is that disclosure made?","id":"disclosure-to-humans","kind":"process"}]},{"id":"personal-data-source-disclosure","name":"Personal data source and recipient disclosure","description":"Provenance duties that arise when the subject contains personal data: telling a data subject where the data came from, recording processing activities, and communicating rectification or erasure to every recipient.","questions":[{"text":"From which source did the personal data originate, and can that be stated to the data subject on request?","id":"personal-data-source-q","kind":"provenance"},{"text":"To which recipients has the data been disclosed, so that rectification or erasure can be communicated to each?","id":"recipient-register","kind":"relationship"},{"text":"Which record of processing activities does this provenance feed, and which controller or processor maintains it?","id":"processing-record","kind":"ownership"},{"text":"Does the provenance record itself contain personal data about contributing agents, and is that necessary and minimised?","id":"provenance-as-personal-data","kind":"privacy"}]}]},{"id":"access-redaction-and-privacy","name":"Discovery, Access, Redaction and Minimisation","description":"How consumers find and obtain provenance, and how producers withhold parts of it without destroying verifiability.","findings":[{"id":"provenance-discovery-and-access","name":"Provenance discovery and access","description":"Interface-neutral means by which a consumer holding only the subject can locate the provenance record about it, and the query surface that returns lineage.","questions":[{"text":"Given only the subject, by what mechanism does a consumer locate provenance about it?","id":"discovery-mechanism","kind":"interoperability"},{"text":"What query surface is offered — record retrieval, ancestor traversal, descendant traversal — and with what parameters?","id":"query-surface","kind":"access"},{"text":"Is there a channel by which downstream users notify the producer of derived works, and is that channel trusted?","id":"pingback-and-downstream","kind":"process"},{"text":"What availability and durability are guaranteed for provenance retrieval, and what does a consumer do when the record is unreachable?","id":"availability-guarantees","kind":"quality"}]},{"id":"redaction-and-selective-disclosure","name":"Redaction, minimisation and selective disclosure","description":"Removing or withholding parts of a provenance record for privacy, confidentiality or legal reasons while keeping the remainder verifiable and keeping the fact of removal visible.","questions":[{"text":"Which provenance elements have been redacted, and is the fact of redaction recorded even when the content is gone?","id":"redaction-target","kind":"privacy"},{"text":"Does the record still verify after redaction, and which checks necessarily fail?","id":"verifiability-after-redaction","kind":"validation"},{"text":"Who is authorised to redact, and can a downstream party redact statements made by an upstream producer?","id":"who-may-redact","kind":"authority"},{"text":"Are different views of the provenance released to different audiences, and how are those views kept consistent?","id":"tiered-disclosure","kind":"access"}]}]},{"id":"retention-and-interoperability","name":"Retention, Disposition and Vocabulary Alignment","description":"How long provenance is kept and how it maps to the neighbouring standards it must exchange with.","findings":[{"id":"provenance-retention-and-disposition","name":"Provenance retention and disposition","description":"Retention of the provenance record considered separately from the subject, including minimum statutory retention, disposition execution and the evidence that disposition occurred.","questions":[{"text":"For how long must this provenance record be retained, under which authority, and does that differ from the subject's own retention?","id":"retention-period-q","kind":"retention"},{"text":"Does provenance survive deletion of the subject, and in what reduced form?","id":"survives-subject-deletion","kind":"lifecycle"},{"text":"When provenance is destroyed, what evidence of the destruction is itself retained?","id":"disposition-evidence","kind":"evidence"},{"text":"How does a legal hold or investigation suspend disposition, and who may lift it?","id":"legal-hold-q","kind":"exception"}]},{"id":"vocabulary-alignment-and-crosswalk","name":"Vocabulary alignment and crosswalk","description":"Recorded mappings between this model's elements and external provenance vocabularies, expressed as alignments with known lossy points rather than conformance claims.","questions":[{"text":"To which external vocabularies is a mapping maintained, at which versions?","id":"which-alignments","kind":"interoperability"},{"text":"For each mapped element, is the mapping exact, broader, narrower or approximate, and what is lost on round trip?","id":"mapping-fidelity","kind":"quality"},{"text":"Is conformance to any external standard claimed, and what evidence supports the claim?","id":"conformance-claim","kind":"validation"},{"text":"How is drift handled when a mapped external vocabulary publishes a new version?","id":"version-drift","kind":"lifecycle"}]}]}]}]},"agentConduct":{"may":["Record provenance events and derivations with agents and times.","Verify sealed provenance assertions.","Traverse lineage to find sources of a result.","Redact personal provenance fields when required."],"mustNot":["Treat valid provenance as proof of authenticity or lawfulness.","Delete or alter recorded provenance silently.","Reconstruct details the creator withheld.","Infer facts from missing provenance."],"requiresHuman":["Resolving conflicting provenance claims.","Disposition of provenance records.","Regulatory disclosure of provenance."]},"ethics":{"considerations":["Provenance supports accountability and trust in information and AI outputs.","Provenance can reveal creators' identity, putting journalists and whistleblowers at risk."],"affectedParties":["Creators and contributors","Consumers of information","Auditors"]},"owners":{"steward":"The adopting Dimension must designate a named owner accountable for the provenance application profile, the governed relation and reason vocabularies, and the crosswalk table, with a published contact and dispute channel.","roles":[{"name":"Provenance model owner","responsibilities":["Maintain the application profile, governed vocabularies and crosswalk, and version them on change.","Publish the identifier minting authority, constraint set version, trust anchors and retention authority in force.","Adjudicate boundary disputes with sibling models and record the outcome as a boundary note."]},{"name":"Asserting producer","responsibilities":["Anchor assertions correctly and record occurrence and record times separately with explicit offsets.","Separate statements it originates from statements it merely gathered, and seal assertions with a valid credential.","Issue superseding assertions and error declarations promptly when a published statement is found to be wrong."]},{"name":"Verifier","responsibilities":["Check structural well-formedness, cryptographic validity, trust status and instance constraints, and publish graded outcomes with per-check status codes.","Re-evaluate assertions when trust lists, credential status or constraint sets change, retaining earlier verdicts.","Report unknown signers and partial failures explicitly instead of collapsing them into a pass or fail."]},{"name":"Custodian","responsibilities":["Maintain the chain-of-custody register as an ordered, gap-explicit series and record transfers with their instruments and effective times.","Run fixity checks on the declared cadence and escalate mismatches as integrity exceptions.","Preserve provenance across storage migrations and re-anchor subjects when formats change."]},{"name":"Privacy and disclosure officer","responsibilities":["Approve redactions and audience views, and ensure personal data in provenance is necessary and minimised.","Ensure synthetic-content marking, deepfake disclosure and personal-data source disclosure duties are discharged and evidenced.","Maintain the disclosure and recipient register so that rectification and erasure can be communicated downstream."]},{"name":"Records and retention authority","responsibilities":["Assign the retention period and disposition authority for provenance records independently of the subject.","Impose and lift legal holds and record who did so and on what basis.","Ensure disposition produces a retained disposition record and a tombstone rather than a silent absence."]}],"masterSystems":[]},"relations":[{"target":"Agent and Party model (person, organisation, position, software agent)","type":"references","note":"Provenance names responsible agents and their types and roles but must not maintain its own agent registry; agent identity, deduplication and organisational hierarchy are resolved externally."},{"target":"Event and Activity model","type":"composes","note":"Origination, transformation, transfer, disposition and verification acts are events; the provenance mix-in composes the shared event structure and adds provenance-specific roles for used, generated and invalidated entities."},{"target":"Identifier and Identity Scheme model","type":"references","note":"Supplies the identifier tiers and resolution behaviour that the identity priority rule depends on, including external identifier retention alongside locally minted identifiers."},{"target":"Temporal model (instants, intervals, calendars, offsets)","type":"aligned","note":"Provenance depends on a shared time representation with explicit offsets and separable occurrence and record axes; the temporal model owns calendar and interval semantics, provenance owns which axis means what."},{"target":"Place and Jurisdiction model","type":"references","note":"Activity location, read point, business location and governing jurisdiction are resolved against an external gazetteer and legal-order registry rather than defined here."},{"target":"Rights and Licensing model","type":"references","note":"Provenance records custody and ownership changes and points at rights statements and licences; the terms, permissions and obligations themselves are owned by the rights model."},{"target":"Trust, Keys and Credentials model","type":"references","note":"Signer credentials, trust lists, revocation status and time authorities are external objects whose lifecycle provenance consumes but does not govern."},{"target":"Records Retention and Disposition model","type":"references","note":"Retention schedules, disposition authorities and legal holds are defined externally; provenance cites the schedule and records the disposition event and its evidence."},{"target":"Access and Authorization model","type":"references","note":"Visibility classes and audience views on provenance are enforced by the access model; provenance records the decision as evidence and does not implement policy."},{"target":"Data Quality and Assessment model","type":"extends","note":"Quality assessment consumes provenance as evidence and, being itself an activity, generates provenance; the two models extend each other without either owning the other's vocabulary."},{"target":"Content Asset and Dataset models (host subjects)","type":"composes","note":"This model is applied to host entity models as a dimension; the host supplies the subject, its identifier stability and its version boundaries, and accepts the provenance application profile."},{"target":"W3C PROV family (PROV-DM, PROV-O, PROV-CONSTRAINTS, PROV-AQ)","type":"aligned","note":"Primary external alignment for entity/activity/agent structure, qualified influence, validity constraints and discovery; alignment is recorded in the crosswalk and no conformance is claimed without validation evidence."},{"target":"PREMIS Data Dictionary and archival description (RiC-CM)","type":"aligned","note":"Alignment for preservation events, object granularity, fixity and for the creator/custody sense of provenance; the homonym between archival provenance and derivation lineage is recorded as a mapping caution."},{"target":"Content authenticity and software supply-chain attestation (C2PA, in-toto/SLSA, SPDX)","type":"aligned","note":"Alignment for signed transport, subject binding by digest, build provenance predicates and element-level creation information; these are evidence carriers, not replacements for the semantic model."},{"target":"Traceability event exchange (GS1 EPCIS) and geospatial lineage (ISO 19115 MRL)","type":"aligned","note":"Domain projections that supply authoritative origination, transfer and process-step facts; their business-step, disposition and geospatial vocabularies remain with those siblings."},{"target":"Clinical provenance and audit (HL7 FHIR Provenance and AuditEvent)","type":"aligned","note":"Alignment for the occurred-versus-recorded distinction, entity roles and the generation-versus-usage boundary that separates provenance from audit logging."},{"target":"Audit log / AuditEvent model","type":"neighbor","note":"Provenance describes how an entity came to be and who is responsible for it; audit logging describes who accessed or attempted an operation on a system. FHIR draws the same line: Provenance is generation-focused while AuditEvent covers usage and other activity. Read events belong to the audit sibling unless they generated a new entity."},{"target":"Version control / revision history model","type":"neighbor","note":"A revision chain is one derivation relation (prov:wasRevisionOf, dcterms:isVersionOf) among many. Commit graphs, branches and merges are a storage projection; this model captures the derivation and responsibility facts that survive migration off any given VCS."},{"target":"Rights and licensing model","type":"neighbor","note":"dcterms:provenance covers changes in ownership and custody significant to authenticity, integrity and interpretation; it is not the licence. Rights holders and licence documents are referenced as external agents and documents."},{"target":"Archival description model (fonds / respect des fonds)","type":"neighbor","note":"In archival practice 'provenance' primarily denotes the creator and the accumulating body of a fonds; here that sense is carried by origination agent plus custody history, while the transformation graph is modelled separately. The homonym must be disambiguated when mapping to RiC-CM."},{"target":"Software bill of materials (SBOM) model","type":"neighbor","note":"An SBOM enumerates composition at a point in time; provenance states how that composition was produced and by whom. SPDX Element creation information and in-toto/SLSA build predicates are alignments, not the SBOM inventory itself."},{"target":"Supply-chain traceability event model (EPCIS)","type":"neighbor","note":"EPCIS what/when/where/why events are an authoritative source of physical-object provenance, but the business-step and disposition vocabularies remain in the traceability sibling; this model consumes the events as origination, transfer and transformation facts."},{"target":"Geospatial lineage metadata","type":"neighbor","note":"ISO 19115 lineage (statement, process step, source) is a domain projection of the same activity/entity structure; the geospatial resolution, reference system and citation fields stay with the geospatial metadata sibling."},{"target":"Content authenticity manifest (C2PA)","type":"neighbor","note":"A C2PA manifest is a signed transport of provenance bound to a media asset. This model treats manifests, claims, assertions and ingredients as artefacts and evidence; JUMBF embedding, codec-specific box hashing and trust-list operation stay outside."},{"target":"Data quality model","type":"neighbor","note":"Provenance is evidence for quality judgements (FAIR R1.2 requires detailed provenance) but does not define accuracy, completeness or fitness metrics; a quality assessment is itself an activity with its own provenance."},{"target":"Records retention and disposition model","type":"neighbor","note":"Disposition authorities, schedules and approval flows belong to the records sibling; provenance records the disposition event and retains the evidence that it happened, and may itself be subject to a different retention period than the subject."}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier issued by the system of record for the subject or the event, retained with its issuing authority.","Governed global identifier or IRI from a recognised scheme where no master-system identifier exists.","UUID (time-ordered, such as UUIDv7) or ULID minted by the adopting Dimension, recorded together with the minting authority and minting time.","Content digest may serve as a matching key for immutable artifacts but is a binding, not an identity, and never replaces an assigned identifier for mutable or versioned subjects.","A date, a filename, a path, a display label or a sequence position is never used as an identifier."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["Recognised by entity, activity and agent statements with times.","Confused with metadata, a version history, a signature and an audit trail."]},"capabilities":{"applicability":"required","items":["Anchor provenance to a subject: Bind a provenance assertion to one or more identified subjects at a declared granularity, with descriptors and a match rule that lets a verifier decide whether an artifact in hand is the subject.","Record a provenance event: Create an append-only record of an origination, transformation, transfer, disposition or verification act, with separate occurrence and recorded times, responsible agents and used and generated entities.","Assert a derivation relation: Record a typed relation between the subject and a prior entity, optionally qualified by the activity, role and times through which the relation arose.","Seal a provenance assertion: Produce a signed envelope over a typed provenance payload, distinguishing statements the signer originates from statements gathered from other components, and attach a trusted time-stamp where available.","Verify a provenance assertion: Check an assertion for structural well-formedness, cryptographic validity and trust against a declared trust list, returning a graded outcome with per-check status codes.","Verify subject fixity: Recompute digests over the anchored extent of the subject and compare them with recorded values, recording the outcome as evidence regardless of result.","Validate provenance instance consistency: Normalise a provenance instance and check it against ordering, uniqueness and impossibility constraints, reporting violations rather than silently repairing them.","Traverse lineage: Return ancestors or descendants of a subject to a bounded depth, marking truncation points, unknown-provenance nodes and per-edge assertion sources.","Resolve provenance for a subject: Given only a subject, locate provenance about it through embedded records, link relations, a resolver service or soft-binding lookup, and report which mechanism succeeded.","Redact a provenance element: Remove or withhold a provenance element for privacy, confidentiality or legal reasons while retaining a visible placeholder and a reason, and re-evaluate what still verifies.","Record a custody or ownership transfer: Append a transfer event moving custody or ownership of the subject between identified parties, with the instrument relied on and the effective time.","Emit a regulatory disclosure: Produce the machine-readable marking and human-facing notice required when the subject is artificially generated or manipulated, or when the source of personal data must be disclosed.","Reconcile conflicting provenance claims: Group incompatible accounts of the same subject, apply the declared precedence rule, and retain all sides with the decision and its basis.","Apply retention and disposition to provenance: Evaluate the retention period applicable to a provenance record, execute disposition when due and not suspended, and retain evidence that disposition occurred."]},"hazards":{"applicability":"required","items":["Forged provenance making false content look trusted.","Exposure of creators.","Lost lineage preventing correction of errors."]},"interfaces":{"applicability":"required","items":["C2PA content credentials specification.","GS1 EPCIS 2.0.","ISO 19115 lineage metadata.","W3C Verifiable Credentials Data Model 2.0."]},"context":{"applicability":"required","items":["The disclosure duties modelled here are EU-specific: Regulation (EU) 2024/1689 for synthetic-content marking, deepfake disclosure, high-risk logging and training-content summaries, and Regulation (EU) 2016/679 for source-of-personal-data disclosure, recipient notification and storage limitation. Equivalent or conflicting obligations in the United States, United Kingdom, China, India and elsewhere were not researched and must be added by the adopting Dimension.","NARA's Universal ERM Requirements are United States federal-government requirements; their capture, transfer and disposition expectations are used here as an authoritative pattern, not as a globally applicable rule.","GS1 EPCIS is voluntary in most markets but is relied on by sector-specific regimes (for example US food traceability); the model treats it as an alignment, not a mandate.","The legal weight of digital signatures and trusted time-stamps varies by jurisdiction (for example eIDAS in the EU versus other electronic-signature regimes); the model records signature and time-stamp evidence without asserting its legal effect anywhere.","Time representation assumes RFC 3339 and the proleptic Gregorian calendar; non-Gregorian calendar systems, historical calendar changes and uncertain or fuzzy historical dating (common in archival provenance) are not represented.","Language and script of names, place names and free-text statements are not modelled; multilingual provenance statements and transliteration provenance are left to the adopting Dimension.","RFC 3339 timestamps with explicit offsets are required even where local archives store civil dates only.","C2PA Trust List and X.509-only signing reflect a primarily industry PKI practice; other regions may require eIDAS or national PKI profiles as additional acceptance policy.","CIDOC title versus custody is expressed for museum practice and may not match common-law versus civil-law transfer of stolen goods; legal title outcome is out of scope.","EPCIS adoption in pharmaceutical traceability (for example DSCSA in the United States) is a jurisdictional overlay on the same event model, not a separate provenance type.","English is the normative language of the cited W3C Recommendations; translations are non-normative."]}},"sources":[{"title":"PROV-DM: The PROV Data Model","url":"https://www.w3.org/TR/prov-dm/","note":"World Wide Web Consortium (W3C)"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium (W3C)"},{"title":"Constraints of the PROV Data Model","url":"https://www.w3.org/TR/prov-constraints/","note":"World Wide Web Consortium (W3C)"},{"title":"PROV-AQ: Provenance Access and Query","url":"https://www.w3.org/TR/prov-aq/","note":"World Wide Web Consortium (W3C)"},{"title":"Content Credentials: C2PA Technical Specification","url":"https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html","note":"Coalition for Content Provenance and Authenticity (C2PA)"},{"title":"SLSA Provenance (predicate type https://slsa.dev/provenance/v1)","url":"https://slsa.dev/spec/v1.1/provenance","note":"Open Source Security Foundation (OpenSSF) / SLSA project"},{"title":"in-toto Attestation Framework — Statement layer (spec v1)","url":"https://github.com/in-toto/attestation/blob/main/spec/v1/statement.md","note":"in-toto project (Cloud Native Computing Foundation)"},{"title":"DCMI Metadata Terms","url":"https://www.dublincore.org/specifications/dublin-core/dcmi-terms/","note":"Dublin Core Metadata Initiative (DCMI)"},{"title":"RO-Crate 1.1 Specification — Provenance of entities","url":"https://www.researchobject.org/ro-crate/specification/1.1/provenance.html","note":"RO-Crate community / Research Object initiative"},{"title":"FHIR Provenance resource (Release 5)","url":"https://www.hl7.org/fhir/provenance.html","note":"Health Level Seven International (HL7)"},{"title":"Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689","note":"European Union (European Parliament and Council)"},{"title":"Regulation (EU) 2016/679 (General Data Protection Regulation)","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679","note":"European Union (European Parliament and Council)"},{"title":"Metadata for Resource Lineage (MRL) XML schema, ISO 19115-3","url":"https://schemas.isotc211.org/19115/-3/mrl/2.0/","note":"ISO/TC 211 Geographic information/Geomatics"},{"title":"EPCIS and CBV Standard","url":"https://ref.gs1.org/standards/epcis/","note":"GS1"},{"title":"SPDX 3.0.1 Specification — Core model, Element class","url":"https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Classes/Element/","note":"SPDX project (The Linux Foundation)"},{"title":"Records in Contexts — Conceptual Model (RiC-CM) 1.0","url":"https://www.ica.org/app/uploads/2023/12/RiC-CM-1.0.pdf","note":"International Council on Archives (ICA), Expert Group on Archival Description"},{"title":"PREMIS Data Dictionary for Preservation Metadata, Version 3.0","url":"https://www.loc.gov/standards/premis/v3/premis-3-0-final.pdf","note":"PREMIS Editorial Committee / Library of Congress"},{"title":"FAIR Principles (Findable, Accessible, Interoperable, Reusable)","url":"https://www.go-fair.org/fair-principles/","note":"GO FAIR International Support and Coordination Office"},{"title":"Universal Electronic Records Management (ERM) Requirements","url":"https://www.archives.gov/records-mgmt/policy/universalermrequirements","note":"U.S. National Archives and Records Administration (NARA)"},{"title":"PREMIS Data Dictionary for Preservation Metadata, Version 3.0","url":"https://www.loc.gov/standards/premis/v3/","note":"Library of Congress"},{"title":"SLSA Build Provenance","url":"https://slsa.dev/spec/v1.2/build-provenance","note":"Open Source Security Foundation (OpenSSF) SLSA"},{"title":"DCMI Metadata Terms: Provenance","url":"https://www.dublincore.org/specifications/dublin-core/dcmi-terms/terms/provenance/","note":"Dublin Core Metadata Initiative"},{"title":"EPCIS and Core Business Vocabulary","url":"https://www.gs1.org/standards/epcis","note":"GS1"},{"title":"Definition of the CIDOC Conceptual Reference Model","url":"https://www.cidoc-crm.org/","note":"CIDOC CRM Special Interest Group / ICOM"},{"title":"ISO 14721:2025 Space Data System Practices — Reference model for an open archival information system (OAIS)","url":"https://www.iso.org/standard/87471.html","note":"International Organization for Standardization / CCSDS"},{"title":"in-toto Attestation Framework","url":"https://github.com/in-toto/attestation","note":"in-toto project / Linux Foundation"},{"title":"ISO 19115-1:2014 Geographic information — Metadata — Part 1: Fundamentals","url":"https://www.iso.org/standard/53798.html","note":"International Organization for Standardization, ISO/TC 211"},{"title":"Dublin Core to PROV Mapping","url":"https://www.w3.org/TR/prov-dc/","note":"World Wide Web Consortium (W3C)"}],"openQuestions":["Clause-level alignment to paywalled ISO 19115-1 and ISO 8000 provenance and data-quality requirements.","Jurisdiction-specific evidentiary admissibility, chain-of-custody and records-retention profiles.","Fine-grained privacy-preserving provenance, zero-knowledge disclosure and confidential-computing attestations.","Operational federation, provenance query and pingback abuse controls across mutually untrusted providers.","Domain-specific provenance profiles for science workflows, healthcare, cultural heritage, geospatial data and AI training corpora.","Ledger- or blockchain-anchored provenance registries and their consensus, immutability and cross-organisation notarisation properties are not modelled; anchoring is treated as a projection, but a sibling model is likely needed and no source was consulted for it.","Cultural-heritage ownership provenance in the art-historical sense (exhibition history, sale records, restitution claims, CIDOC CRM alignment) was not researched and is not covered beyond generic custody intervals.","Machine-learning-specific lineage artefacts such as model cards, datasheets for datasets, feature lineage and evaluation provenance are only partially reached through the training-summary and generating-model elements.","Sensor and observation provenance beyond EPCIS sensor elements — for example W3C SSN/SOSA observation procedures and sensor calibration lineage — was not researched.","Nanopublication and scholarly citation provenance, including retraction propagation across the citation graph, is not covered.","The PREMIS Data Dictionary v3.0 full text could not be retrieved directly: the host returned HTTP 403 to the research agent. Version, date and the five-entity model were confirmed from Library of Congress index pages, but no element-level quotation from the document underpins any node here.","The OAIS Reference Model (CCSDS 650.0-M-2 / ISO 14721) could not be retrieved live (HTTP 403), so its treatment of Provenance Information as a component of Preservation Description Information is deliberately not cited or relied on, despite being directly on point.","NIST AI 100-4 on reducing risks from synthetic content could not be parsed from its published PDF, so watermark robustness and detection limitations are represented only through C2PA's soft-binding treatment and the AI Act's detectability requirement.","No cost, performance or scale characteristics of lineage traversal at large graph sizes are modelled beyond declared limits; practical query economics are left to the interface projection.","Provenance for streaming, continuously updated and derived-on-read resources is only partially addressed through the anchor qualifier; sub-second and per-record streaming lineage was not researched.","Forensic laboratory chain-of-custody procedures (for example ASTM E1492 or SWGDE) lack a primary source adopted in this pass and remain a sibling gap.","ISO 23494 biotechnology provenance and related lab-sample standards were not grounded in a retrieved primary text.","ML training-data lineage, model-card provenance and dataset-licence enforcement have no single primary standard equivalent to PROV or C2PA; C2PA AI disclosure is only an alignment.","Quantum-safe signature migration for long-term archives is unspecified by the cited primary sources.","1970 UNESCO cultural-property export rules and national patrimony statutes are legal overlays, not technical provenance types.","Live multi-hop reconstruction of implicit PROV blank nodes from sparse Dublin Core records is an implementation strategy, not a required Dimension behaviour.","Region-specific eIDAS or national trust-list programmes beyond the C2PA Trust List are not enumerated."],"resources":{"spec":"/models/wm-xct-012-provenance/spec.yaml","agents":"/models/wm-xct-012-provenance/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-012"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-xct-012-provenance/spec.yaml","ver-cy/world-models/card-supplements/wm-xct-012-provenance.json"],"providers":["Claude","Grok"],"researchStatus":"reviewable-draft","generatedAt":"2026-08-22T21:06:30Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}