{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-023","code":"wm-xct-023-party-role","url":"https://ver.cy/models/wm-xct-023-party-role/","name":"Party Role","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.ROLE"],"industry":["Cross-industry"],"navPath":"NAV.XCT.ROLE","tags":["party","role","xct.role"],"facets":{}},"whatItIs":"Party Role reifies the n-ary link (player, host context, role type, validity) as an addressable assertion so that qualifying facts can attach to it. It covers how such an assertion is identified, classified, scoped, time-bounded, delegated, evidenced, constrained, disputed, superseded, disclosed and retired. It deliberately carries no party master data, no host payload and no permission semantics; those belong to composable sibling models. The mixin is storage- and interface-neutral: RDF, JSON, tabular, document and API projections are views over the same invariants.","purpose":"Provide a reusable, format-neutral structure for asserting that a party plays a named role with respect to a specific object, activity, agreement or other party, together with the scope, validity, authority, provenance, evidence and constraints that make the assertion operable and auditable.","scope":{"in":["Reification of the party-to-host link as a first-class role assertion with its own identity","Role type classification, vocabulary binding strength, and mapping to external role code lists","Host context binding: object, activity/event, agreement, organization, or another party","Player binding across party kinds including organizations, groups, automated agents and vacant posts","Scope qualifiers: spatial, jurisdictional, organizational-unit, quantitative extent and typed characteristics","Role validity period separated from assertion/record time, with retroactive correction and as-of resolution","Status lifecycle, suspension, revocation, succession, acting/interim holdings and coverage gaps","Basis of authority: statutory, contractual, appointment-based or self-declared, with mandate references","Delegation, acting-on-behalf-of chains, sub-delegation and representation/signing limits","Multiplicity, exclusivity, segregation-of-duties and conflict-of-interest constraints","Provenance of the assertion, supporting evidence, corroboration level and dispute handling","Disclosure tiers, retention, tombstoning and erasure of person-identifying role history","Alignment to external standards and the invariants that must survive any projection"],"out":["Party master data such as legal name, registered address, contact details or LEI registration itself","The internal content, state or behaviour of the host object, activity or agreement","Permission sets, entitlements and access-control decisions derived from a role","Organizational structure, reporting hierarchy and post establishment beyond the role reference","Agreement terms, pricing and obligations other than those attached to the role type","Credential issuance, cryptographic proof formats and verification protocol mechanics","Consent capture and lawful-basis determination for processing personal data","Authentication, session and identity-assurance mechanics for the player","Storage engine, wire format and API surface choices"],"boundaries":[{"neighbor":"Party / Agent identity model","distinction":"A role has no independent existence apart from a player and a host; the mixin references the player by identifier and never restates party master data such as name, address or registration."},{"neighbor":"Organization membership (W3C org:Membership, org:Post)","distinction":"org:Membership is a role of an agent specifically within an Organization and org:Post is a holder-independent position. Party Role generalises to arbitrary hosts; where the host is an organization the two overlap and must be reconciled by an explicit ALIGN mapping rather than duplicated."},{"neighbor":"Role-Based Access Control role (INCITS 359 / NIST RBAC)","distinction":"An RBAC role is a permission-bundling construct evaluated by a policy decision point; a party role is a business or legal assertion about who stands in what relation to what. A party role may be an input to authorization but never carries permissions itself."},{"neighbor":"Provenance model (W3C PROV-O)","distinction":"prov:hadRole is scoped to prov:Association and prov:Attribution qualifications of agent involvement in activities and entities. Party Role covers standing roles that exist independently of any recorded activity, so PROV alignment is partial and must not be presented as conformance."},{"neighbor":"Participation / event participant records","distinction":"A participation attaches an actor to a single act occurrence; a party role may be durable and outlive any occurrence. Occurrence-bound participations should reference a role assertion rather than duplicate it."},{"neighbor":"Party-to-party relationship registers (GLEIF Level 2)","distinction":"Structural ownership and consolidation relationships are symmetric-ish records between two legal entities with their own validation regime. This boundary is genuinely fuzzy: parent/subsidiary can be read as a role. The adopting Dimension must choose one representation per relationship type and record the choice."},{"neighbor":"Verifiable credential / attestation model","distinction":"A credential is one possible evidence artifact for a role assertion. Issuer, holder, subject and verifier are roles relative to a credential exchange, not the role being asserted; conflating them produces circular models."},{"neighbor":"Consent and lawful-basis model","distinction":"Statutory role types such as controller and processor carry obligations, but the lawful basis for a given processing operation is a separate determination held elsewhere and referenced from the role assertion."}]},"distinguishingFeatures":["Reifies the link between a party, a host context, a role type and a validity period as its own assertion.","Carries no permission semantics, unlike an RBAC role.","Differs from organization membership, which is one kind of role, and from party-to-party relationships.","Supports delegation, dispute, succession and retroactive correction of role assertions."],"structure":{"bundles":[{"id":"assertion-core","name":"Role Assertion Core","description":"What a Party Role assertion is, how it is identified, and how its role type is classified and governed.","layers":[{"id":"reification-and-identity","name":"Reification and Assertion Identity","description":"The role assertion as a first-class reified n-ary link, and the rules that decide when two records denote the same assertion.","findings":[{"id":"role-assertion-reification","name":"Role assertion as a reified n-ary link","description":"Party Role is not a binary property between a party and a host. It is a reified node joining player, host context, role type and validity, so that qualifying facts such as period, extent, evidence and delegation can attach without polluting either endpoint.","questions":[{"text":"When must a party-to-host link be reified as a Party Role assertion rather than expressed as a direct binary property?","id":"q-reify-trigger","kind":"composition"},{"text":"What is the minimal tuple that makes a Party Role assertion well-formed?","id":"q-minimal-tuple","kind":"definition"},{"text":"Is there a scoping party distinct from the host that defines or acknowledges the role, and how is it recorded?","id":"q-scoper-distinct","kind":"relationship"},{"text":"Which facts are lost when the assertion is projected to a binary shorthand, and is the projection declared lossy?","id":"q-shorthand-loss","kind":"interoperability"}]},{"id":"assertion-identifier-and-sameness","name":"Assertion identifier and sameness rules","description":"Which identifier governs the assertion, what is minted when none exists, and which attribute changes create a new assertion rather than a new version of the existing one.","questions":[{"text":"Which authoritative master-system identifier governs this role assertion, and which body issues it?","id":"q-master-identifier","kind":"identity"},{"text":"What identifier is minted when no authoritative master-system or governed global identifier exists?","id":"q-minted-identifier","kind":"identity"},{"text":"Which attribute changes create a new assertion rather than a new version of the existing one?","id":"q-new-vs-version","kind":"identity"},{"text":"How are duplicate assertions contributed by multiple systems detected, ranked and merged?","id":"q-duplicate-merge","kind":"quality"}]}]},{"id":"classification-and-vocabulary","name":"Role Classification and Vocabulary","description":"The role type itself, the axis it expresses, and the governance of the vocabulary that supplies it.","findings":[{"id":"role-type-and-axes","name":"Role type and classification axes","description":"A role type must declare which axis it expresses. FHIR Provenance separates the functional role with respect to an activity from the structural role indicating competency; contractual and statutory positions form further axes. Collapsing them produces vocabularies that cannot be validated.","questions":[{"text":"Which axis does this role type express: functional participation, structural competency, contractual position or statutory status?","id":"q-classification-axis","kind":"classification"},{"text":"Which controlled vocabulary and version supplies the role type, and what is the binding strength?","id":"q-vocabulary-binding","kind":"classification"},{"text":"May one assertion carry more than one role type, and how is a multi-typed assertion interpreted?","id":"q-multiple-types","kind":"constraint"},{"text":"How is a local or unmapped role term carried without breaking consumers bound to the governed vocabulary?","id":"q-unmapped-term","kind":"interoperability"}]},{"id":"role-vocabulary-governance","name":"Role vocabulary governance","description":"Who owns the role-type vocabulary, how terms are admitted, deprecated and mapped, and what consumers must do when they meet an unknown term from a newer version.","questions":[{"text":"Who owns the role-type vocabulary and by what process are new terms admitted or rejected?","id":"q-vocab-authority","kind":"authority"},{"text":"How are deprecated or superseded terms handled in assertions that already cite them?","id":"q-term-deprecation","kind":"lifecycle"},{"text":"What behaviour is required when a consumer encounters a term from a newer vocabulary version than it knows?","id":"q-unknown-term-behaviour","kind":"interoperability"},{"text":"Are role terms hierarchical, and does a broader term subsume assertions made with a narrower one?","id":"q-term-hierarchy","kind":"classification"}]},{"id":"role-class-kind-exclusions","name":"Role-class kind and exclusions","description":"HL7 RoleClass partitions roles into ontological, partitive and associative (mutual/formal versus passive). This mixin is limited to associative actor functions (especially AssignedEntity, Agent, licensed/qualified as constraints). Ingredient, instance-of-kind and owned-material roles are out of scope.","questions":[{"text":"Which RoleClass kind (assigned, agent, licensed, other associative) does this assignment instantiate?","id":"role-class-kind-exclusions-q01","kind":"classification"},{"text":"Has this record been rejected because it is partitive, ontological or a passive material role?","id":"role-class-kind-exclusions-q02","kind":"validation"},{"text":"Is this assignment a functional AssignedEntity role, an EMP employment relationship, or both as separate records?","id":"role-class-kind-exclusions-q03","kind":"classification"}]}]}]},{"id":"scoping-and-composition","name":"Scoping and Composition","description":"What the role attaches to, who may play it, and how the role is narrowed within its host.","layers":[{"id":"host-context-binding","name":"Host Context Binding","description":"The kinds of host a role may attach to, how the host is referenced, and whether roles cascade to parts and successors.","findings":[{"id":"host-kind-and-reference","name":"Host kind and reference integrity","description":"The host discriminator and the referencing rule that keeps an assertion resolvable when the host is versioned, merged or superseded. PROV separates activity association from entity attribution; ISO 19115-1 binds a party to a role relative to a described resource; TMF669 binds roles to accounts and agreements.","questions":[{"text":"What kind of host does this role attach to: an object, an activity or event, an agreement, an organization, or another party?","id":"q-host-kind","kind":"composition"},{"text":"How is the host referenced so the assertion stays resolvable when the host is versioned or re-identified?","id":"q-host-ref-stability","kind":"relationship"},{"text":"May one assertion span multiple hosts, or is a separate assertion required per host?","id":"q-multi-host","kind":"constraint"},{"text":"What happens to the assertion when its host is deleted, merged or superseded?","id":"q-host-disposal","kind":"lifecycle"}]},{"id":"scope-cascade-and-derivation","name":"Scope cascade, inheritance and derived holdings","description":"Whether a role asserted on a container reaches its parts, whether transitive holdings are distinguished from direct ones, and whether derived assertions are materialised or computed.","questions":[{"text":"Does a role asserted on a container host apply to its parts, and is that reach materialised or computed at query time?","id":"q-cascade-mode","kind":"composition"},{"text":"Are direct and indirect holdings distinguished, and how is the derivation path recorded?","id":"q-direct-vs-indirect","kind":"relationship"},{"text":"When a host is derived from or supersedes another, do existing roles carry over automatically?","id":"q-successor-carryover","kind":"lifecycle"}]}]},{"id":"player-binding","name":"Player Binding","description":"Which parties may play a role, how vacancy is expressed, and how player identity is resolved and re-verified.","findings":[{"id":"player-kind-and-vacancy","name":"Admissible player kinds and vacancy","description":"Roles may be played by natural persons, organizations, collectives, automated agents, or by nobody at all. FHIR permits a PractitionerRole with an empty practitioner for organizational role tracking, and the W3C Organization Ontology defines a Post that exists independently of the person filling it.","questions":[{"text":"Which party kinds are admissible players for this role type: natural person, organization, group, automated agent, or an unfilled post?","id":"q-player-kinds","kind":"constraint"},{"text":"How is a vacant or not-yet-assigned position represented distinctly from a terminated role?","id":"q-vacancy","kind":"state"},{"text":"May a collective such as a team, committee or class of parties hold the role as a single player?","id":"q-collective-holding","kind":"composition"},{"text":"Are automated or AI agents permitted players, and what additional attribution is required when they are?","id":"q-automated-agent","kind":"authority"}]},{"id":"player-identity-resolution","name":"Player identity resolution and re-verification","description":"The identifier priority used to bind the player, how the assertion survives upstream merge or split of the party, and whether pseudonymous or position-only holding is permitted.","questions":[{"text":"Which identifier scheme authoritatively identifies the player, and what is the documented fallback order?","id":"q-player-id-priority","kind":"identity"},{"text":"How is the assertion kept correct when the player is merged, split or re-identified upstream?","id":"q-player-merge","kind":"lifecycle"},{"text":"May a player be pseudonymous or identified only by position, and under what conditions?","id":"q-pseudonymous-player","kind":"privacy"},{"text":"How often must player identity be re-verified, and what happens if re-verification lapses?","id":"q-player-reverification","kind":"validation"}]}]},{"id":"scope-qualifiers","name":"Scope Qualifiers and Extent","description":"Qualifiers that narrow a role within its host: spatial and temporal extent, jurisdiction, organizational unit, quantitative extent and typed characteristics.","findings":[{"id":"role-extent-and-characteristics","name":"Role extent, quantifiers and typed characteristics","description":"ISO 19115-1 gives CI_Responsibility an extent for the spatial or temporal extent of the role; FHIR narrows a role by location, specialty and service; GLEIF carries relationship qualifiers and quantifiers; TMF669 carries typed name/value characteristics. Together these define how a role is narrowed without multiplying role types.","questions":[{"text":"What spatial, jurisdictional or organizational-unit extent narrows this role within its host?","id":"q-spatial-extent","kind":"spatial"},{"text":"Is a quantitative extent such as a share, quota or threshold part of the role, and in what unit?","id":"q-quantitative-extent","kind":"measurement"},{"text":"Which role-specific characteristics are permitted, and are their names and value types validated?","id":"q-characteristic-typing","kind":"constraint"},{"text":"Do differing qualifiers narrow a single assertion or require separate assertions?","id":"q-qualifier-vs-split","kind":"composition"}]},{"id":"role-local-contact-context","name":"Role-local contact and service context","description":"FHIR records telecom, availability and endpoints on PractitionerRole because they belong to the post, not the person. ISO 19115-1 CI_Party carries contactInfo for the responsible party in that role. Role-local channels must not overwrite party-master contacts.","questions":[{"text":"What contact channels, endpoints or availability windows belong to this assignment rather than to the player master?","id":"role-local-contact-context-q01","kind":"relationship"},{"text":"When role-local contact differs from party-master contact, which must operational systems use?","id":"role-local-contact-context-q02","kind":"decision"},{"text":"Does a change of telecom or availability require a new assignment record, as FHIR recommends when details are not uniform?","id":"role-local-contact-context-q03","kind":"lifecycle"}]}]}]},{"id":"temporal-state-lifecycle","name":"Time, State and Lifecycle","description":"When the role holds, when the system knew it, how its state changes, and how accountability passes between holders.","layers":[{"id":"validity-and-time-semantics","name":"Validity Periods and Time Semantics","description":"The role period, its boundary and precision semantics, and the separation of role time from record time.","findings":[{"id":"role-validity-period","name":"Role validity period","description":"The interval during which the role holds, expressed as RFC 3339 date-times with mandatory seconds and an explicit offset or Z, with declared boundary inclusivity and precision.","questions":[{"text":"What are the start and end instants of the role period, and how is an open-ended role expressed?","id":"q-period-bounds","kind":"temporal"},{"text":"Are period boundaries inclusive or exclusive, and at what precision are they compared?","id":"q-boundary-semantics","kind":"temporal"},{"text":"How is a recurring, rota-based or on-call role period represented without exploding into thousands of assertions?","id":"q-intermittent-period","kind":"temporal"},{"text":"Which offset is recorded, and is it the offset legally relevant to the host's jurisdiction?","id":"q-offset-authority","kind":"temporal"}]},{"id":"assertion-time-and-correction","name":"Assertion time, period types and retroactive correction","description":"Separation of when the role held from when the register learned it, so that a retroactive correction can be told apart from a genuine change, and 'as of D, as known on E' queries can be answered.","questions":[{"text":"When was the assertion recorded, and how does that differ from when the role took effect?","id":"q-recorded-vs-occurred","kind":"temporal"},{"text":"How is a retroactive correction of an erroneous record distinguished from a genuine change in the role itself?","id":"q-correction-vs-change","kind":"provenance"},{"text":"Can the register answer who held role R on host H as of date D as known on date E?","id":"q-as-of-query","kind":"temporal"},{"text":"Which period types beyond the role period are tracked for this assertion?","id":"q-period-types","kind":"temporal"}]}]},{"id":"status-and-succession","name":"Status Lifecycle and Succession","description":"The permitted states of an assertion, the events that move it between them, and how accountability passes from one holder to the next.","findings":[{"id":"role-status-lifecycle","name":"Status lifecycle and state transitions","description":"Two state machines must be kept apart: the substantive state of the role and the registration state of the record. GLEIF separates RelationshipStatus from a nine-value RegistrationStatus; TMF669 carries status with statusReason and emits an explicit state-change event.","questions":[{"text":"What is the permitted state set for a role assertion, and which transitions are legal?","id":"q-state-set","kind":"state"},{"text":"Is the registration state of the record kept distinct from the substantive state of the role?","id":"q-record-vs-role-state","kind":"state"},{"text":"Which reason codes must accompany suspension, revocation and termination?","id":"q-status-reason","kind":"state"},{"text":"Does expiry of the validity period change status automatically, or is an explicit transition event required?","id":"q-lapse-automation","kind":"event"}]},{"id":"succession-and-acting-holdings","name":"Succession, handover and acting holdings","description":"How accountability is carried across a change of holder, whether overlaps or gaps are permitted, and how an interim or deputy holding is distinguished from a substantive one.","questions":[{"text":"Which assertion succeeds which, and is the succession chain recorded explicitly rather than inferred from dates?","id":"q-succession-chain","kind":"relationship"},{"text":"Is an overlap or a gap between successive holders permitted for this role type?","id":"q-overlap-or-gap","kind":"constraint"},{"text":"How is an acting, interim or deputy holding distinguished from a substantive one?","id":"q-acting-holding","kind":"classification"},{"text":"Who is accountable for acts performed during a coverage gap?","id":"q-gap-accountability","kind":"authority"}]}]}]},{"id":"authority-and-constraints","name":"Authority, Delegation and Constraints","description":"What makes a role assertion authoritative, how authority is passed on, and the rules that limit who may hold what.","layers":[{"id":"authority-basis","name":"Basis of Authority and Mandate","description":"The ground on which the role subsists and the obligations that attach to it by operation of law or contract.","findings":[{"id":"basis-of-authority","name":"Basis of authority and conferring instrument","description":"Whether the role rests on statute, contract, appointment, court order or self-declaration; which authority conferred it; and whether registration is constitutive of the role or merely declaratory of it.","questions":[{"text":"On what basis does this role subsist: statute, contract, appointment, court order or self-declaration?","id":"q-authority-basis-kind","kind":"authority"},{"text":"Which authority conferred the role, and is that authority itself identified and within scope?","id":"q-conferring-authority","kind":"authority"},{"text":"Does the role subsist as a matter of fact regardless of registration, or does registration constitute it?","id":"q-constitutive-or-declaratory","kind":"authority"},{"text":"Which jurisdiction's law governs the role, and what applies when jurisdictions conflict?","id":"q-governing-jurisdiction","kind":"authority"}]},{"id":"statutory-role-obligations","name":"Statutory obligations and factual override","description":"Some role types carry non-waivable duties and are determined by conduct rather than declaration. GDPR treats an entity as a controller because it determines purposes and means, requires joint controllers to document their allocation of responsibilities, and requires a binding contract for processors.","questions":[{"text":"Which obligations attach automatically to this role type, and are any of them waivable by agreement?","id":"q-attached-obligations","kind":"requirement"},{"text":"How is a jointly held statutory role and the allocation of duties between holders recorded?","id":"q-joint-allocation","kind":"composition"},{"text":"Can factual conduct override a declared role classification, and what triggers reclassification?","id":"q-factual-override","kind":"classification"},{"text":"Which evidence demonstrates that the obligations attached to the role were discharged?","id":"q-obligation-discharge","kind":"evidence"}]},{"id":"eligibility-preconditions-for-occupancy","name":"Eligibility versus occupancy","description":"FHIR: qualifications do not imply a Role. HL7 QUAL is recognition that would make an entity an appropriate performer; LIC is scoper-certified authorisation to perform activities under a jurisdiction. Occupancy may require referenced credentials to be valid at event time, but this mixin stores references and expiry checks, not the credential body.","questions":[{"text":"Which credentials, licences or qualifications must be valid for this occupancy, and who is the issuing scoper?","id":"eligibility-preconditions-for-occupancy-q01","kind":"requirement"},{"text":"If a required credential expires while the assignment period is still open, does occupancy auto-suspend?","id":"eligibility-preconditions-for-occupancy-q02","kind":"constraint"},{"text":"Is the player eligible but not occupying, and should eligibility be recorded only on the credential sibling?","id":"eligibility-preconditions-for-occupancy-q03","kind":"decision"}]}]},{"id":"delegation-and-representation","name":"Delegation and Representation","description":"Chains of acting on behalf of another, and the limits on what a role holder may bind.","findings":[{"id":"delegation-and-on-behalf-of","name":"Delegation and acting on behalf of","description":"PROV-O reifies delegation as prov:Delegation qualifying prov:actedOnBehalfOf, and FHIR constrains agent.who to differ from agent.onBehalfOf. The mixin carries the delegator, the chain, sub-delegation permission and revocation.","questions":[{"text":"Who delegated the authority for this holding, and is the delegator itself a recorded role holder?","id":"q-delegator","kind":"authority"},{"text":"How deep may a delegation chain go, and is sub-delegation permitted?","id":"q-chain-depth","kind":"constraint"},{"text":"How is a delegation revoked, and what is the effect on acts already performed under it?","id":"q-delegation-revocation","kind":"lifecycle"},{"text":"Must the delegate and the delegator be distinct parties, and how is that enforced?","id":"q-distinct-parties","kind":"validation"}]},{"id":"representation-and-limits","name":"Representation limits and joint action","description":"What a holder may bind the host or scoping party to, expressed as machine-checkable limits rather than prose, and how this differs from system permissions.","questions":[{"text":"What may the holder of this role commit the host or scoping party to, and up to what limit?","id":"q-binding-limit","kind":"constraint"},{"text":"Is joint or countersigned action required, and what quorum applies?","id":"q-joint-action","kind":"constraint"},{"text":"How are representation limits expressed so a system can check them rather than a human reading prose?","id":"q-machine-checkable","kind":"validation"},{"text":"How does representation authority differ from the system permissions granted to the holder?","id":"q-representation-vs-permission","kind":"security"}]},{"id":"ultimate-and-immediate-party","name":"On-behalf-of and ultimate party","description":"PROV actedOnBehalfOf and qualified Delegation record that an agent acted for another. FHIR Provenance.agent.onBehalfOf is the delegating agent and must not equal who. ISO 20022 distinguishes Debtor/Creditor from UltimateDebtor/UltimateCreditor for payments on behalf of another. UN/CEFACT distinguishes direct and indirect representation. Chains must be explicit.","questions":[{"text":"On whose behalf is this player occupying the role, and is that party different from the player?","id":"ultimate-and-immediate-party-q01","kind":"relationship"},{"text":"Who is the ultimate party versus the immediate party in this agency chain?","id":"ultimate-and-immediate-party-q02","kind":"relationship"},{"text":"Is representation direct or indirect, as in UN/CEFACT DEN/DEO, and what instrument authorises it?","id":"ultimate-and-immediate-party-q03","kind":"authority"},{"text":"What plan, mandate or power-of-attorney, if any, did the agent follow (PROV hadPlan)?","id":"ultimate-and-immediate-party-q04","kind":"composition"}]}]},{"id":"multiplicity-and-separation","name":"Multiplicity and Separation of Duties","description":"How many holders a role admits, and which role combinations are forbidden for the same party.","findings":[{"id":"role-multiplicity","name":"Multiplicity, exclusivity and mandatory roles","description":"Cardinality constraints on the assertion: how many parties may hold a role on a host, whether the same party may hold it more than once with different qualifiers, and whether the host is invalid without the role filled.","questions":[{"text":"How many parties may simultaneously hold this role on the same host?","id":"q-holder-cardinality","kind":"constraint"},{"text":"May one party hold the same role on the same host more than once with different qualifiers?","id":"q-repeat-holding","kind":"constraint"},{"text":"Is this role mandatory for the host, and what validates that it is filled?","id":"q-mandatory-role","kind":"requirement"},{"text":"How are joint holders' shares or ranks expressed, and must they sum to a declared total?","id":"q-share-summation","kind":"measurement"}]},{"id":"segregation-and-conflict","name":"Segregation of duties and conflict of interest","description":"Incompatible role pairs, static versus per-transaction exclusion, time-limited exceptions, and declared conflicts of interest. NIST RBAC contributes the static and dynamic separation-of-duty distinction; FHIR contributes the concrete who-is-not-onBehalfOf constraint.","questions":[{"text":"Which role pairs are mutually exclusive for the same party on the same host, and is the exclusion static or evaluated per transaction?","id":"q-incompatible-pairs","kind":"constraint"},{"text":"How is an approved exception to a segregation rule recorded, justified and time-limited?","id":"q-sod-exception","kind":"exception"},{"text":"How are conflicts of interest declared by holders, and who adjudicates them?","id":"q-conflict-declaration","kind":"decision"},{"text":"What must happen to existing assertions when a new segregation rule is introduced?","id":"q-new-rule-backfill","kind":"lifecycle"}]}]}]},{"id":"provenance-evidence-quality","name":"Provenance, Evidence and Quality","description":"Who says this role holds, on what evidence, at what level of corroboration, and what happens when the claim is contested.","layers":[{"id":"assertion-provenance","name":"Assertion Provenance","description":"Provenance of the claim itself, kept strictly separate from provenance of the host.","findings":[{"id":"who-asserted-and-ownership","name":"Asserting agent, source system and record ownership","description":"The agent that made the assertion, the role that agent acted in, the system and record it came from, whether the claim is first-, second- or third-party, and who owns and may change the record.","questions":[{"text":"Which agent asserted this role assertion, and in what role did that agent act when asserting it?","id":"q-asserting-agent","kind":"provenance"},{"text":"Which source system, source record and extraction process produced the assertion?","id":"q-source-system","kind":"provenance"},{"text":"Is the assertion first-party self-declared by the player, second-party from the counterparty, or third-party from an independent source?","id":"q-party-tier","kind":"provenance"},{"text":"Who owns and maintains this role assertion record, and who is permitted to change it?","id":"q-record-ownership","kind":"ownership"}]}]},{"id":"evidence-and-quality","name":"Evidence, Verification and Quality","description":"Documents and credentials substantiating the role, the corroboration level reached, and how contested or erroneous assertions are handled.","findings":[{"id":"evidence-and-verification","name":"Supporting evidence and the verification act","description":"GLEIF grades validation from entity-supplied-only to fully corroborated and types the validation documents used; W3C VC makes evidence revocable and time-bounded; FHIR warns that a qualification held by a practitioner does not by itself imply a role.","questions":[{"text":"Which document or credential evidences this role, and is it held or only referenced?","id":"q-evidence-reference","kind":"evidence"},{"text":"What corroboration level applies to this assertion?","id":"q-corroboration-level","kind":"quality"},{"text":"What process must be completed before an asserted role is treated as verified?","id":"q-verification-process","kind":"process"},{"text":"Does a licence or qualification held by the player imply this role, or must the role be asserted separately?","id":"q-qualification-implication","kind":"classification"}]},{"id":"quality-and-dispute","name":"Assertion quality, dispute and annulment","description":"Confidence measures, representation of a contested claim while the dispute is open, and the distinction between an assertion that has ended and one that was never true.","questions":[{"text":"What confidence or data-quality measure attaches to this assertion, and how is it computed?","id":"q-quality-score","kind":"quality"},{"text":"How is a disputed or challenged assertion represented while the dispute remains open?","id":"q-dispute-open","kind":"exception"},{"text":"How is an assertion that was never true distinguished from one that has legitimately ended?","id":"q-annulment","kind":"state"},{"text":"What triggers automatic re-validation or lapse of an unverified assertion?","id":"q-staleness-trigger","kind":"validation"}]}]}]},{"id":"governance-access-retention","name":"Disclosure, Access and Retention","description":"Who may see a role assertion, on what basis, and how long role history survives erasure pressure without breaking accountability chains.","layers":[{"id":"disclosure-and-privacy","name":"Disclosure and Privacy","description":"Publication tiers, minimization, role-only disclosure and recipient logging.","findings":[{"id":"disclosure-tiers-and-minimization","name":"Disclosure tiers, minimization and recipient logging","description":"Which parts of an assertion may be published, which are restricted, whether the role can be disclosed without disclosing the holder, and which recipients have received it.","questions":[{"text":"Which parts of a role assertion may be published, and which are restricted to named recipients?","id":"q-disclosure-tier","kind":"access"},{"text":"What is the legal basis for disclosing a natural person's role assertion, and which model holds that basis?","id":"q-disclosure-basis","kind":"privacy"},{"text":"Can the role be disclosed without disclosing the holder's identity?","id":"q-role-only-disclosure","kind":"privacy"},{"text":"Which recipients have received this assertion, and is each disclosure itself recorded?","id":"q-recipient-log","kind":"access"}]}]},{"id":"retention-and-erasure","name":"Retention, Erasure and Tombstones","description":"How long ended role history is kept, and how erasure is reconciled with accountability chains that depend on it.","findings":[{"id":"retention-erasure-tombstones","name":"Retention classes, tombstones and legal hold","description":"Ended roles are the backbone of historical accountability, so deletion cannot be unconditional. The model requires a retention class, a tombstone that preserves referential integrity when content is erased, and an explicit legal hold mechanism.","questions":[{"text":"How long must an ended role assertion be retained, and on whose authority is that period set?","id":"q-retention-class","kind":"retention"},{"text":"When an erasure request is honoured, what tombstone remains so accountability chains do not break?","id":"q-tombstone","kind":"retention"},{"text":"Is hard deletion of a role assertion ever permitted, and what is the escalation path?","id":"q-hard-delete","kind":"exception"},{"text":"How is a legal hold applied to role history and subsequently released?","id":"q-legal-hold","kind":"authority"}]}]}]},{"id":"interoperability-and-projection","name":"Interoperability and Projection","description":"How the mixin maps onto external role constructs, where those constructs conflict, and what must survive any projection.","layers":[{"id":"external-alignment","name":"External Standard Alignment","description":"Mapping to external role constructs with explicit relation strength, and the register of known conflicts.","findings":[{"id":"alignment-and-conflicts","name":"Alignment mappings, conflicts and conformance claims","description":"Each external target is mapped with an explicit relation (exact, broader, narrower, related) and the mapping evidence is recorded. Conflicts are registered rather than resolved by assertion, and no conformance is claimed without evidence.","questions":[{"text":"Which external construct does this assertion or role type map to, and is the mapping exact, broader, narrower or merely related?","id":"q-alignment-relation","kind":"interoperability"},{"text":"Where an external standard restricts roles to activity associations, how is an object-scoped role expressed without misusing that standard?","id":"q-activity-only-restriction","kind":"interoperability"},{"text":"Which conflicts between aligned standards are known, and which interpretation prevails in this Dimension?","id":"q-conflict-precedence","kind":"decision"},{"text":"What evidence supports any claim of conformance to an aligned standard?","id":"q-conformance-evidence","kind":"evidence"}]},{"id":"participation-vs-standing-role","name":"Participation versus role boundary","description":"Standing Party Role occupancy is not a statement that the player performed a particular act. FHIR Provenance.agent.type records how an agent participated in an activity; PractitionerRole records what the practitioner may perform for an organisation over a period. ISO 20022 PartyRole on a Payment is activity-instance scoped and should be linked as participation-like use of this mixin, not stored as a second identity model.","questions":[{"text":"Is this record a standing assignment or an activity-instance participation, and which sibling holds the other?","id":"participation-vs-standing-role-q01","kind":"classification"},{"text":"If linked to a participation, what participation type (performer, author, enterer, verifier) applies to the activity?","id":"participation-vs-standing-role-q02","kind":"relationship"},{"text":"Does this Dimension forbid merging standing occupancy and act-participation into a single undifferentiated role record?","id":"participation-vs-standing-role-q03","kind":"constraint"}]}]},{"id":"projection-and-exchange","name":"Projection and Exchange Invariants","description":"What must hold in every serialization and interface so that the same assertion is recognisable across projections.","findings":[{"id":"projection-invariants","name":"Projection invariants and canonical form","description":"Fields that are semantically load-bearing must survive every projection; conveniences such as hyperlinks and denormalized labels must be marked projection-local. A canonical form is required for hashing and change detection.","questions":[{"text":"Which fields are invariant across every projection, and which exist only within a particular projection?","id":"q-invariant-fields","kind":"interoperability"},{"text":"What canonical serialization is used for hashing and change detection?","id":"q-canonical-form","kind":"validation"},{"text":"How are references expressed so they resolve in both a graph projection and a document or tabular projection?","id":"q-reference-resolution","kind":"interoperability"},{"text":"How is a filtered or partial projection marked so consumers do not treat it as complete?","id":"q-partial-projection","kind":"quality"}]}]}]}]},"agentConduct":{"may":["Assert a party role with evidence and validity period.","Resolve who held a role at a given time.","Record a delegation within declared limits.","Map a role type to an external vocabulary term."],"mustNot":["Treat holding a role as permission to access data or act.","Assert a role for a party without evidence.","Extend a delegation beyond what the delegator held.","Delete past role assertions needed to show who acted in a role.","Disclose role registers beyond their declared audience."],"requiresHuman":["Appointing or removing a holder of a role with legal authority.","Resolving a disputed role assertion.","Approving retroactive correction of a role record."]},"ethics":{"considerations":["Roles can reveal sensitive affiliations such as union membership, health roles or political office.","Wrongly asserted roles can make people responsible for acts they did not do.","Public role registers must balance transparency with personal safety."],"affectedParties":["Role holders","Organizations hosting the roles","Parties who rely on role claims"]},"owners":{"steward":"Designate a single accountable owner for the Party Role package who is itself recorded as a Party Role assertion on the package, so the governance model is self-describing.","roles":[{"name":"Party Role steward","responsibilities":["Own the Party Role package for the adopting Dimension and maintain its registered host applications","Approve creation, correction and retirement of assertions outside the automated path","Maintain the identity priority decisions and the register of authoritative master systems","Answer boundary questions between this mixin and its sibling models"]},{"name":"Role vocabulary authority","responsibilities":["Own the role type vocabulary, admit and reject terms, and publish versioned releases","Assign each term a classification axis and maintain broader and successor relations","Manage deprecation with transition periods and successor mappings","Prevent reuse of retired term IRIs for new meanings"]},{"name":"Assertion verifier","responsibilities":["Execute the verification procedure and record the corroboration level reached","Validate evidence references against their content hashes and expiry","Issue serial verification reports and raise exceptions for stale or missing evidence","Maintain independence from the asserting party for exact and high-tier verifications"]},{"name":"Constraint and segregation officer","responsibilities":["Maintain the cardinality constraint set and the segregation of duties ruleset","Adjudicate conflict of interest declarations and approve time-limited exceptions with compensating controls","Run backfill scans when a new rule is introduced and set remediation deadlines","Reconcile conferred representation authority against permissions granted in the access model"]},{"name":"Privacy and retention officer","responsibilities":["Assign disclosure tiers and approve movements of fields to wider tiers","Maintain retention classes, legal holds and the disposition log","Handle erasure requests, tombstone creation and recipient notification","Assess re-identification risk for role-only and pseudonymous disclosures"]},{"name":"Interoperability custodian","responsibilities":["Maintain the alignment crosswalk, conflict register and conformance claim statuses","Verify that no direct external property is reused outside the scope its standard permits","Own the canonical projection profile and validate that each projection preserves invariants","Manage version negotiation expectations with external consumers"]}],"masterSystems":[]},"relations":[{"target":"Party / Agent identity model (person, organization, group, automated agent)","type":"references","note":"Supplies the player and scoping-party identity that this mixin references but never restates; identifier schemes such as LEI or ORCID are resolved there."},{"target":"Role type vocabulary / concept scheme model","type":"references","note":"Supplies governed role terms, their axis assignment, status, broader relations and successor mappings; the mixin binds to a named vocabulary version rather than embedding terms."},{"target":"Identifier and identity-resolution mixin","type":"composes","note":"Supplies the identity priority ladder, minting rules and alias retention used for assertion identifiers and for resolving player and host references through merges and splits."},{"target":"Temporal validity (bitemporal period) mixin","type":"composes","note":"Supplies interval semantics, boundary inclusivity, the separation of effective time from knowledge time, and RFC 3339 timestamp rules used by every period on an assertion."},{"target":"Provenance and assertion-record mixin","type":"composes","note":"Supplies the qualified agent-activity-entity pattern used to record who asserted the role, under what plan, from what source, and when it was recorded versus when it occurred."},{"target":"Activity / event model (host context)","type":"references","note":"Provides activity and event hosts for activity-scoped roles; the mixin supplies the role qualification while the activity model supplies the occurrence."},{"target":"Object / resource model (host context)","type":"references","note":"Provides object and resource hosts for object-scoped roles such as custodian, owner and rights holder, which PROV-O cannot express through hadRole alone."},{"target":"Agreement / contract model","type":"references","note":"Supplies the agreements that confer contractual roles and the binding instruments required where a role acts on another party's behalf."},{"target":"Organization and organizational structure model","type":"aligned","note":"Overlaps where the host is an organization; org:Membership and org:Post must be mapped to the assertion and position constructs rather than duplicated, with the precedence decision recorded."},{"target":"Access control / authorization policy model","type":"aligned","note":"Consumes party roles as inputs to policy decisions; the boundary is that this mixin carries no permissions and an RBAC role is a different construct that happens to share the word."},{"target":"Evidence and attestation model (verifiable credentials, filed documents)","type":"references","note":"Supplies the documents and credentials that substantiate a role assertion, together with their validity windows and revocation status."},{"target":"Consent and lawful-basis model","type":"references","note":"Holds the lawful basis relied upon for processing and disclosing role assertions about natural persons; the mixin references it rather than determining it."},{"target":"Retention and disposition schedule model","type":"references","note":"Supplies retention classes, disposal triggers and legal hold mechanics applied to ended role assertions and their history."},{"target":"Jurisdiction and legal mandate model","type":"references","note":"Supplies the statutes, orders and jurisdictional scopes cited as the basis of authority and as the source of obligations attaching to statutory role types."},{"target":"Party-to-party relationship register model (ownership, consolidation)","type":"aligned","note":"Adjacent construct for structural relationships between legal entities; the adopting Dimension must decide per relationship type whether it is a role assertion or a relationship record and record that decision to avoid double representation."},{"target":"Party / Agent identity model","type":"neighbor","note":"A role has no independent existence apart from a player and a host; the mixin references the player by identifier and never restates party master data such as name, address or registration."},{"target":"Organization membership (W3C org:Membership, org:Post)","type":"neighbor","note":"org:Membership is a role of an agent specifically within an Organization and org:Post is a holder-independent position. Party Role generalises to arbitrary hosts; where the host is an organization the two overlap and must be reconciled by an explicit ALIGN mapping rather than duplicated."},{"target":"Role-Based Access Control role (INCITS 359 / NIST RBAC)","type":"neighbor","note":"An RBAC role is a permission-bundling construct evaluated by a policy decision point; a party role is a business or legal assertion about who stands in what relation to what. A party role may be an input to authorization but never carries permissions itself."},{"target":"Provenance model (W3C PROV-O)","type":"neighbor","note":"prov:hadRole is scoped to prov:Association and prov:Attribution qualifications of agent involvement in activities and entities. Party Role covers standing roles that exist independently of any recorded activity, so PROV alignment is partial and must not be presented as conformance."},{"target":"Participation / event participant records","type":"neighbor","note":"A participation attaches an actor to a single act occurrence; a party role may be durable and outlive any occurrence. Occurrence-bound participations should reference a role assertion rather than duplicate it."},{"target":"Party-to-party relationship registers (GLEIF Level 2)","type":"neighbor","note":"Structural ownership and consolidation relationships are symmetric-ish records between two legal entities with their own validation regime. This boundary is genuinely fuzzy: parent/subsidiary can be read as a role. The adopting Dimension must choose one representation per relationship type and record the choice."},{"target":"Verifiable credential / attestation model","type":"neighbor","note":"A credential is one possible evidence artifact for a role assertion. Issuer, holder, subject and verifier are roles relative to a credential exchange, not the role being asserted; conflating them produces circular models."},{"target":"Consent and lawful-basis model","type":"neighbor","note":"Statutory role types such as controller and processor carry obligations, but the lawful basis for a given processing operation is a separate determination held elsewhere and referenced from the role assertion."}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier issued by the system of record for the artifact's subject, where such a system exists and is named in the Dimension package.","Governed global identifier or IRI from an external authority, such as an LEI, ORCID, DID or a standard vocabulary term IRI, where no master-system identifier applies.","UUIDv7 per RFC 9562, or a ULID, minted in the adopting Dimension's namespace, used only as the last resort and recorded as such.","A date, a name, a role label, a file path or a sequence position is never an identifier; serial numbering is a naming convention layered on top of a real identifier, not a substitute for one."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A role assertion names a party, a role type, a host context and a validity period, with status and evidence.","Often confused with a job title, an access role and the party itself."]},"capabilities":{"applicability":"required","items":["Assert a party role: Create a new role assertion binding a player to a host with a role type, validity and authority basis.","Resolve role holders as of a time: Answer who held a given role on a given host at a given effective time, optionally as the register knew it at a second time.","Resolve roles held by a party: Return the roles a party holds or held across hosts, respecting cascade rules and disclosure tiers.","Validate a role assertion: Check an assertion against well-formedness, vocabulary binding, temporal, cardinality, segregation and representation constraints.","Transition role status: Move an assertion between substantive or registration states with a reason and effective instant.","Correct a role assertion retroactively: Record a correction to a previously asserted fact without losing what the register previously believed.","Record a delegation: Record that a holder exercises a role on behalf of another party, with scope, limits and revocability.","Verify role evidence: Examine the evidence supporting an assertion and record the corroboration level reached.","Succeed a role holder: End one holding and begin its successor in the same position, recording the handover and any gap or overlap.","Map a role type to an external term: Record or update a crosswalk entry between a local role type and an external construct, with relation strength and evidence.","Apply a retention or erasure decision: Execute a retention, redaction, tombstoning or hold decision against an assertion and its history.","Publish a role register snapshot: Emit an as-of, tier-appropriate projection of the role register for external consumption."]},"hazards":{"applicability":"required","items":["Fraud through false claims of authority.","Stale roles let former holders keep acting.","Over-exposure of affiliations puts people at risk."]},"interfaces":{"applicability":"required","items":["W3C Organization Ontology (org:Membership, org:Post).","W3C PROV-O.","HL7 FHIR PractitionerRole.","W3C Verifiable Credentials Data Model.","ANSI INCITS 359 RBAC, for mapping only."]},"context":{"applicability":"required","items":["GDPR is used as the worked example of statutory roles because it is publicly citable and precise. Adopters outside the EU and EEA must substitute their own equivalents; the controller/processor pattern is not universal and the obligation attachment mechanism, not the specific roles, is what generalises.","Publication duties for roles such as company directors, beneficial owners and licensed professionals vary sharply by jurisdiction. The disclosure tier model is deliberately parameterised rather than prescribing a default public tier.","The identifier priority assumes governed global identifiers such as LEI and ORCID are available. In jurisdictions or sectors where they are not, the UUIDv7 fallback will be used far more often than the ladder implies, weakening cross-system resolution.","Legal effect of a role frequently depends on local civil time (for example an appointment effective at midnight local). The model records an offset per RFC 3339 and additionally a jurisdictional time zone identifier, but does not resolve which prevails where they disagree.","Names, honorifics and legal capacity rules for who may hold a role differ by jurisdiction and are delegated entirely to the party model; no assumption of a Western name or capacity model is embedded here.","Retention periods are stated as classes rather than durations because statutory minimums for role history differ by sector and country.","Healthcare licensing and PractitionerRole usage are jurisdiction-specific; FHIR example bindings are not a world code list.","ISO 19115-1 responsible-party practice is described via ICSM (Australia) guidance; other profiles may constrain CI_RoleCode differently.","UN/CEFACT trade roles assume cross-border commercial process semantics that may not fit domestic public-sector posts.","Retention, erasure and public-directory publication depend on local public-records, employment and data-protection law.","Company-officer and signing-authority roles (SGNOFF) vary by corporate law and were not taken from a specific companies statute."]}},"sources":[{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium (W3C)"},{"title":"The Organization Ontology","url":"https://www.w3.org/TR/vocab-org/","note":"World Wide Web Consortium (W3C)"},{"title":"ODRL Vocabulary & Expression 2.2","url":"https://www.w3.org/TR/odrl-vocab/","note":"World Wide Web Consortium (W3C)"},{"title":"Verifiable Credentials Data Model v2.0","url":"https://www.w3.org/TR/vc-data-model-2.0/","note":"World Wide Web Consortium (W3C)"},{"title":"Resource PractitionerRole (FHIR R5)","url":"https://hl7.org/fhir/R5/practitionerrole.html","note":"Health Level Seven International (HL7)"},{"title":"Resource Provenance (FHIR R5)","url":"https://hl7.org/fhir/R5/provenance.html","note":"Health Level Seven International (HL7)"},{"title":"TMF669 Party Role Management API, PartyRole resource schema v4.0.0","url":"https://raw.githubusercontent.com/tmforum-apis/TMF669_PartyRole/master/TMF669-PartyRole-v4.0.0.swagger.json","note":"TM Forum"},{"title":"Level 2 Data: Relationship Record (RR) CDF Format 2.1","url":"https://www.gleif.org/en/about-lei/common-data-file-format/current-versions/level-2-data-relationship-record-rr-cdf-2-1-format","note":"Global Legal Entity Identifier Foundation (GLEIF)"},{"title":"Regulation (EU) 2016/679 (General Data Protection Regulation)","url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng","note":"European Union"},{"title":"RFC 3339: Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/rfc/rfc3339","note":"Internet Engineering Task Force (IETF)"},{"title":"RFC 9562: Universally Unique IDentifiers (UUIDs)","url":"https://www.rfc-editor.org/rfc/rfc9562.html","note":"Internet Engineering Task Force (IETF)"},{"title":"Role - Schema.org Type","url":"https://schema.org/Role","note":"Schema.org / W3C Schema.org Community Group"},{"title":"CRediT - Contributor Roles Taxonomy (ANSI/NISO Z39.104-2022)","url":"https://credit.niso.org/","note":"National Information Standards Organization (NISO)"},{"title":"DataCite Metadata Schema 4.6 - contributorType","url":"https://datacite-metadata-schema.readthedocs.io/en/4.6/appendices/appendix-1/contributorType/","note":"DataCite e.V."},{"title":"Role Based Access Control (RBAC) project","url":"https://csrc.nist.gov/projects/role-based-access-control","note":"National Institute of Standards and Technology (NIST), Computer Security Resource Center"},{"title":"CodeSystem: v3 Code System RoleClass","url":"https://terminology.hl7.org/CodeSystem-v3-RoleClass.html","note":"Health Level Seven International (HL7) Terminology"},{"title":"class - CI_Responsibility (ISO 19115-1 metadata profile documentation)","url":"https://icsm-au.github.io/metadata-working-group/defs/class-CI_Responsibility.html","note":"Intergovernmental Committee on Surveying and Mapping (ICSM), Australia and New Zealand"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/2013/REC-prov-o-20130430/","note":"World Wide Web Consortium (W3C)"},{"title":"FHIR Resource PractitionerRole","url":"https://hl7.org/fhir/practitionerrole.html","note":"Health Level Seven International (HL7)"},{"title":"unece:PartyRoleCodeList","url":"https://vocabulary.uncefact.org/PartyRoleCodeList","note":"United Nations Economic Commission for Europe (UN/CEFACT)"},{"title":"HL7 CodeSystem RoleClass","url":"https://terminology.hl7.org/en/CodeSystem-v3-RoleClass.html","note":"Health Level Seven International (HL7)"},{"title":"ISO20022 types — Role and PartyRole component restructure","url":"https://www.ibm.com/docs/en/ftmfm/4.0.8?topic=types-iso20022","note":"IBM (documenting the ISO 20022 business model)"},{"title":"unece:partyRoleCode","url":"https://vocabulary.uncefact.org/partyRoleCode","note":"United Nations Economic Commission for Europe (UN/CEFACT)"},{"title":"FHIR Resource Provenance","url":"https://hl7.org/fhir/provenance.html","note":"Health Level Seven International (HL7)"}],"openQuestions":["ISO 20022 BusinessRole and PartyRole from the Registration Authority business model or message dictionary, not vendor documentation: claude's two fetches timed out and grok fell back to tier-3 IBM docs, leaving financial-messaging adopters ungrounded.","EDM Council FIBO PartyInRole / agent-in-role: both providers identified it as directly relevant and neither could render a citable class definition, so the financial-industry treatment of party-in-role is absent from both packs.","GS1 EPCIS 2.0 owning_party versus possessing_party on supply-chain events, which would supply an independent case of object-scoped roles separating legal from physical control; the specification PDF could not be parsed.","Multilingual role labels, honorifics, transliteration and the label-versus-coded-function precedence rule, which need an explicit contract with the vocabulary sibling model rather than a finding here.","A constraint expression language for machine-checkable representation and signing limits: the base requires machine-checkability but no cited source supplies a suitable expression language for this purpose.","Whether any authority publishes a reusable role-incompatibility or segregation-of-duties matrix; grok found none in primary sources, so incompatibilities are currently Dimension-local by default rather than by evidence.","Basis for any maximum delegation chain depth: the base depth limit is a model-imposed safeguard with no standard behind it and should stay a local policy parameter until evidence exists.","NIST SP 800-162 (ABAC) alongside INCITS 359, to test whether the no-permissions boundary holds equally against attribute-based authorization, which neither provider examined.","No primary source was obtained for ISO 20022's BusinessRole definition; two fetch attempts timed out, so the ISO 20022 view of role-versus-actor is absent from the grounding and is a genuine evidence gap for financial-messaging adopters.","ISO 19115-1 itself is paywalled and was not read directly; CI_Responsibility and CI_RoleCode are grounded in ICSM's public documentation of it, so exact normative wording is not verified.","The HL7 v3 RoleClass page rendered navigation only on direct fetch; the player/scoper definitions were confirmed via the search index against the same URL. The scoping-party construct therefore has the weakest verification in the model.","FIBO's PartyInRole was identified as directly relevant but its ontology page could not be rendered, so the financial-industry treatment of party-in-role is not cited as support anywhere.","GS1 EPCIS 2.0 (owning_party versus possessing_party on supply-chain events) would have been a strong independent case of object-scoped roles distinguishing legal from physical control; the specification PDF could not be parsed and the distinction is not represented in the model.","Role naming and honorifics, multilingual role labels, and transliteration are not modelled; they are delegated to the vocabulary model without a specified contract.","Machine-readable representation limits are required but no constraint expression language is prescribed, because no cited source supplies one for this purpose.","No cited source establishes a maximum delegation chain depth; the depth limit is a model-imposed safeguard and should be treated as a local policy parameter, not a standard.","Group and collective players are permitted but the internal accountability decomposition within a collective is not modelled and is left to the party model.","The role-only disclosure and re-identification risk guidance is stated as a requirement without a cited methodology for assessing that risk.","EDM Council FIBO PartyInRole / agent-in-role was discovered but the ontology viewer page did not yield a citable class definition in this run; treat FIBO as an ungrounded alignment candidate.","NIST RBAC / INCITS 359 and ABAC (SP 800-162) were not fetched; permission objects remain a sibling and a dedicated RBAC alignment is a gap.","GDPR controller/processor and eIDAS representative powers were not taken from legislative text; legal-capacity roles are a regional gap.","Verifiable Credentials for role occupancy are emerging and lack a primary source in this bundle.","A universal role-conflict matrix does not exist in the cited sources; incompatibilities are Dimension-local.","RACI, Open Contracting party roles and GLEIF relationship records were not grounded.","Robotics-specific operator roles were out of demand (factor_robotics 0.00) and are omitted.","UN/CEFACT list is much larger than the findings enumerate; adopting Dimensions must snapshot the list rather than rely on this mixin to enumerate every code."],"resources":{"spec":"/models/wm-xct-023-party-role/spec.yaml","agents":"/models/wm-xct-023-party-role/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-023"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-xct-023-party-role/spec.yaml","ver-cy/world-models/card-supplements/wm-xct-023-party-role.json"],"providers":["Claude","Grok"],"researchStatus":"reviewable-draft","generatedAt":"2026-08-23T06:03:39Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}