{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-030","code":"wm-xct-030-notification-subscription","url":"https://ver.cy/models/wm-xct-030-notification-subscription/","name":"Notification / Subscription","alternateNames":[],"kind":"world-model","status":"published","version":"0.1.0","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.NTF"],"industry":["Cross-industry"],"navPath":"NAV.XCT.NTF","tags":["notification","subscription","xct.ntf"],"facets":{}},"whatItIs":"A notification subscription is a standing record that a party wants to be told about a class of events, with a filter, a delivery channel and preferences such as frequency and quiet hours. It governs which notifications are sent and how; the events themselves and the messages delivered are separate subjects, and so is a paid service subscription.","purpose":"Describe host-attached event interests, subscription control evidence and delivery preferences with explicit authority and channel limits.","scope":{"in":["Host attachment and local interest identity, subscriber and receiver references.","Event selection parameters, channel preferences, timing, urgency and withdrawal intent.","Evidence of confirmed subscription state, delivery limits, profile mappings and record governance."],"out":["Paid service subscriptions, billing, entitlement products and contract lifecycle.","Event truth, event registers, message payload lifecycle and recipient identity masters.","Network dispatch, subscription protocol execution, matching engines, scheduling, deduplication, replay, retries and enforcement.","Generic consent adjudication, legal service of notices, safety-critical alert certification and audit-trail implementation."],"boundaries":[{"neighbor":"WM-REC-003","distinction":"Candidate optional Message binding: notification payloads, message identity and message lifecycle stay message-owned."},{"neighbor":"WM-ACT-015","distinction":"Candidate optional Occurrence / Event binding: point to triggering facts without reproducing event identity or lifecycle."},{"neighbor":"WM-XCT-002","distinction":"Candidate optional Access Contract / Consent binding: retain scoped authority references, never infer entitlement or legal consent from a subscription."},{"neighbor":"WM-PER-014","distinction":"Candidate optional Preference / Personal Profile binding: use only selected notification preferences and preserve general profile ownership."},{"neighbor":"WM-KNW-013","distinction":"Candidate optional rule binding: pin selector or precedence rule and operands; evaluator execution and generic rule lifecycle remain external."},{"neighbor":"WM-XCT-004","distinction":"Candidate optional Access Audit binding: reference access evidence without implementing or redefining an audit trail."},{"neighbor":"Mixin versus standalone subscription entity","distinction":"The registry mixin classification is retained. Local interest entries have keys only within a host attachment; independently managed transport subscriptions are referenced entities, not a new root owned by this mixin."}]},"distinguishingFeatures":["It is a standing interest, separate from the events it matches and the messages it causes.","Delivery preferences belong to the subscriber, not to the publisher of events.","It depends on consent or entitlement and must be easy to end.","Distinct from a commercial subscription, which is a paid service agreement."],"structure":{"bundles":[{"id":"XCT030-B1","name":"Subscription","description":"Who wants to know what.","layers":[{"id":"XCT030-B1-L1","name":"Interest and filter","description":"The subscriber, the event class and filters.","findings":[{"id":"XCT030-F01","name":"Subscriber and topic","description":"Who subscribed to which events.","questions":[{"text":"Who is the subscriber, and which topic or event class did they subscribe to?","id":"XCT030-Q01"},{"text":"Which filter narrows the events, such as location, severity or subject?","id":"XCT030-Q02"}]},{"id":"XCT030-F02","name":"Consent basis","description":"The consent or entitlement behind the subscription.","questions":[{"text":"Did the subscriber opt in, and when and how was consent recorded?","id":"XCT030-Q03"},{"text":"Is the subscriber entitled to see the events covered?","id":"XCT030-Q04"}]}]}]},{"id":"XCT030-B2","name":"Delivery","description":"How notifications reach the subscriber.","layers":[{"id":"XCT030-B2-L1","name":"Channel and preferences","description":"Channels, frequency and quiet hours.","findings":[{"id":"XCT030-F03","name":"Channel","description":"The endpoint used for delivery.","questions":[{"text":"Which channel and endpoint deliver the notifications?","id":"XCT030-Q05"},{"text":"Is the endpoint verified and still reachable?","id":"XCT030-Q06"}]},{"id":"XCT030-F04","name":"Preferences","description":"Frequency, batching, language and quiet hours.","questions":[{"text":"Should notifications be immediate or batched into digests?","id":"XCT030-Q07"},{"text":"Which quiet hours and language preferences apply?","id":"XCT030-Q08"}]}]}]},{"id":"XCT030-B3","name":"Lifecycle","description":"How the subscription starts and ends.","layers":[{"id":"XCT030-B3-L1","name":"Status and expiry","description":"Active, paused, expired or cancelled.","findings":[{"id":"XCT030-F05","name":"Subscription status","description":"The state of the subscription and how to end it.","questions":[{"text":"Is the subscription active, paused or expired?","id":"XCT030-Q09"},{"text":"How can the subscriber unsubscribe, and is it honoured at once?","id":"XCT030-Q10"}]}]}]}]},"agentConduct":{"may":["Create subscriptions the user asks for and confirm them.","Deliver notifications according to the subscriber's channel and preferences.","Batch or suppress notifications in quiet hours as set.","Remind users of active subscriptions and how to end them."],"mustNot":["Subscribe a person without their consent.","Ignore or delay an unsubscribe request.","Send notifications about events the subscriber is not entitled to see.","Use a notification channel for unrelated marketing.","Share subscriber endpoints with third parties."],"requiresHuman":["Subscribing on behalf of another person.","Overriding quiet hours outside emergencies defined in policy.","Changing the consent basis of existing subscriptions."]},"ethics":{"considerations":["Unwanted notifications are intrusive and can amount to spam or harassment.","Alert fatigue causes important warnings to be missed.","Subscription data reveals interests, locations and habits."],"affectedParties":["Subscribers","Publishers of events","People named in notified events"]},"owners":{"steward":"The subscriber controls the subscription; the operator of the notification service keeps the record and honours it.","roles":[{"name":"Dimension steward","responsibilities":["Own the profile, namespace and risk acceptance; approve schema and semantic migrations."]},{"name":"Subscriber or authorized delegate","responsibilities":["Express scoped preferences and withdrawal intent within evidenced authority."]},{"name":"Notification record custodian","responsibilities":["Maintain revisions, evidence references and restricted access; never infer remote state from intent."]},{"name":"Channel operator","responsibilities":["Own endpoint verification, dispatch, retries and receipt semantics in the external delivery service."]},{"name":"Privacy and access reviewer","responsibilities":["Review data minimization, permission scope, disclosure and retention exceptions."]},{"name":"Conformance reviewer","responsibilities":["Assess binding loss, fixtures, failures and unsupported protocol features."]}],"masterSystems":["Notification service","Consent and preference management system"]},"relations":[{"target":"WM-REC-003","type":"references","note":"Candidate optional Message binding: notification payloads, message identity and message lifecycle stay message-owned."},{"target":"WM-ACT-015","type":"references","note":"Candidate optional Occurrence / Event binding: point to triggering facts without reproducing event identity or lifecycle."},{"target":"WM-XCT-002","type":"references","note":"Candidate optional Access Contract / Consent binding: retain scoped authority references, never infer entitlement or legal consent from a subscription."},{"target":"WM-PER-014","type":"references","note":"Candidate optional Preference / Personal Profile binding: use only selected notification preferences and preserve general profile ownership."},{"target":"WM-KNW-013","type":"references","note":"Candidate optional rule binding: pin selector or precedence rule and operands; evaluator execution and generic rule lifecycle remain external."},{"target":"WM-XCT-004","type":"references","note":"Candidate optional Access Audit binding: reference access evidence without implementing or redefining an audit trail."},{"target":"WebSub Recommendation 2026-06-02","type":"aligned","note":"Conceptual topic, callback, confirmation and lease mapping; requires independently tested adapter."},{"target":"MQTT Version 5.0","type":"aligned","note":"Conceptual topic-filter and subscription-option mapping; no end-to-end exactly-once guarantee."},{"target":"RFC 8639","type":"aligned","note":"Optional configured or dynamic notification subscription profile; network-management rules are not universal."},{"target":"RFC 8030 and Push API Working Draft 2026-10-05","type":"aligned","note":"Optional web push profile with protected endpoint and permission evidence; draft API support is not assumed."},{"target":"RFC 8058","type":"aligned","note":"Optional one-click email withdrawal profile, distinct from arbitrary link retrieval and other channel methods."},{"target":"CloudEvents v1.0.2","type":"aligned","note":"Event envelope references and correlation only; source plus event id is scoped identity, not a delivery contract."},{"target":"WM-REC-003","type":"neighbor","note":"Candidate optional Message binding: notification payloads, message identity and message lifecycle stay message-owned."},{"target":"WM-ACT-015","type":"neighbor","note":"Candidate optional Occurrence / Event binding: point to triggering facts without reproducing event identity or lifecycle."},{"target":"WM-XCT-002","type":"neighbor","note":"Candidate optional Access Contract / Consent binding: retain scoped authority references, never infer entitlement or legal consent from a subscription."},{"target":"WM-PER-014","type":"neighbor","note":"Candidate optional Preference / Personal Profile binding: use only selected notification preferences and preserve general profile ownership."},{"target":"WM-KNW-013","type":"neighbor","note":"Candidate optional rule binding: pin selector or precedence rule and operands; evaluator execution and generic rule lifecycle remain external."},{"target":"WM-XCT-004","type":"neighbor","note":"Candidate optional Access Audit binding: reference access evidence without implementing or redefining an audit trail."},{"target":"Mixin versus standalone subscription entity","type":"neighbor","note":"The registry mixin classification is retained. Local interest entries have keys only within a host attachment; independently managed transport subscriptions are referenced entities, not a new root owned by this mixin."},{"target":"wm-rec-003-message","type":"references","note":"Notifications are delivered as messages."},{"target":"wm-xct-002-access-contract-consent","type":"requires","note":"Subscriptions rest on consent or entitlement."},{"target":"wm-per-014-preference-personal-profile","type":"related","note":"Delivery preferences are part of a personal profile."}],"interaction":{"identity":{"applicability":"required","items":["A subscription is identified by an identifier issued by the notification service, linked to the subscriber and topic identifiers."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A subscription names a subscriber, a topic or filter, a channel and a status.","Often confused with a message, an event or a paid service subscription."]},"capabilities":{"applicability":"required","items":["Subscriptions can be created, confirmed, paused, modified, expired and cancelled.","Matching events trigger deliveries according to preferences."]},"hazards":{"applicability":"required","items":["Missed critical alerts due to wrong preferences or dead endpoints.","Notification floods and alert fatigue.","Leakage of sensitive event content to lock screens or shared devices."]},"interfaces":{"applicability":"required","items":["W3C WebSub for web publish and subscribe.","IETF RFC 8030 Generic Event Delivery Using HTTP Push and the W3C Push API.","CloudEvents for describing event data."]},"context":{"applicability":"required","items":["Used in apps, public alerting, monitoring and business systems.","Consent for electronic notifications is regulated by privacy and electronic communications law."]}},"sources":[{"title":"WebSub","url":"https://www.w3.org/TR/2026/REC-websub-20260602/","note":"World Wide Web Consortium"},{"title":"RFC 8030: Generic Event Delivery Using HTTP Push","url":"https://www.rfc-editor.org/rfc/rfc8030","note":"Internet Engineering Task Force"},{"title":"MQTT Version 5.0","url":"https://docs.oasis-open.org/mqtt/mqtt/v5.0/os/mqtt-v5.0-os.html","note":"OASIS"},{"title":"RFC 8639: Subscription to YANG Notifications","url":"https://www.rfc-editor.org/rfc/rfc8639","note":"Internet Engineering Task Force"},{"title":"RFC 8058: Signaling One-Click Functionality for List Email Headers","url":"https://www.rfc-editor.org/rfc/rfc8058","note":"Internet Engineering Task Force"},{"title":"Push API","url":"https://www.w3.org/TR/2026/WD-push-api-20261005/","note":"World Wide Web Consortium"},{"title":"Web Content Accessibility Guidelines (WCAG) 2.2","url":"https://www.w3.org/TR/2024/REC-WCAG22-20241212/","note":"World Wide Web Consortium"},{"title":"RFC 5545: Internet Calendaring and Scheduling Core Object Specification (iCalendar)","url":"https://www.rfc-editor.org/rfc/rfc5545","note":"Internet Engineering Task Force"},{"title":"CloudEvents specification","url":"https://raw.githubusercontent.com/cloudevents/spec/v1.0.2/cloudevents/spec.md","note":"Cloud Native Computing Foundation"},{"title":"WebSub (W3C)","url":"https://www.w3.org/TR/websub/"},{"title":"CloudEvents specification (Cloud Native Computing Foundation)"}],"openQuestions":["Restore independent external review and resolve all source version, errata and applicability questions before canonical promotion.","Build profile-specific schemas and fixtures for activation and withdrawal races, endpoint rotation, civil-time ambiguity, replay gaps, shared subscriptions and duplicate delivery.","Obtain qualified adoption review for mandatory notices, privacy, communications law, emergency overrides, accessibility and retention without universalizing one protocol's rules.","No independent second-provider review; local self-audit cannot replace it.","No executable instance schemas, matching engine, scheduler, protocol adapter or tested conformance fixtures.","Direct HTTP checks were not attempted because the owner reports sandbox blocking; no measured HTTP status or body digest is available. Browser retrieval is documented separately.","No legal, jurisdictional, channel-specific marketing or safety-critical emergency compliance conclusion.","Quiet-hour precedence, batching, multi-device behavior, shared subscriptions and mandatory notices need adoption-specific profiles."],"resources":{"spec":"/models/wm-xct-030-notification-subscription/spec.yaml","agents":"/models/wm-xct-030-notification-subscription/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-030"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-xct-030-notification-subscription/spec.yaml","ver-cy/world-models/card-supplements/wm-xct-030-notification-subscription.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-10-06T12:43:54Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"A notification subscription is an information or software construct; its measurable attributes are configuration and operational data, not physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-06, unreviewed). Written from the card's existing content and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}