{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-038","code":"wm-xct-038-policy-evaluation","url":"https://ver.cy/models/wm-xct-038-policy-evaluation/","name":"Policy Evaluation","alternateNames":[],"kind":"world-model","status":"published","version":"0.1.0","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"pattern","plane":"","domain":["XCT.POL"],"industry":["Cross-industry"],"navPath":"NAV.XCT.POL","tags":["policy","evaluation","xct.pol"],"facets":{}},"whatItIs":"A policy evaluation is one recorded application of a machine-evaluable policy to a concrete request or situation: the inputs supplied, the policy version used, the decision returned, the obligations attached and the explanation of why. The policy rule itself, the enforcement action taken afterwards and a human decision or approval are separate subjects.","purpose":"Represent a repeatable application of machine-evaluable policy to a bounded request, preserving evidence, native outcome, obligations, explanation and distinct enforcement execution.","scope":{"in":["Evaluation identity, request scope and attribute provenance","Pinned policy/evaluator context and native decision semantics","Obligations, advice, explanations and failure handling","Enforcement gate, attempt correlation and execution evidence distinct from decision","Replay limits, protected records, contest links and profile-specific interoperability"],"out":["Authoring, approving or deploying policy rules and disclosure definitions","Statistical evaluation of government policy effectiveness","Human approval, legal adjudication and exception-granting authority","Implementation of resource-specific actuators, identity directories or general audit infrastructure","Operational instructions for dangerous activities or controlled subjects"],"boundaries":[{"neighbor":"WM-KNW-012 Policy / Rule","distinction":"Registry parent is conceptual context, not inheritance of rule administration. Pin a rule or policy-set version; this pattern applies it and does not edit or approve it."},{"neighbor":"WM-XCT-003 Projection / Disclosure Policy","distinction":"Incoming REFERENCE ledger assigns decision input, outcome, explanation and enforcement execution here. That model defines disclosure shape. This pattern records and governs the concrete evaluation and enforcement attempt, including executor binding and receipts; resource-specific execution code is external."},{"neighbor":"Human decision and exception authority","distinction":"A machine result is neither consent nor a legally effective human approval. A separately authorized exception is referenced with scope and expiry and cannot rewrite the original decision."},{"neighbor":"WM-XCT-035 Retention / Disposition","distinction":"Retention rules and holds may be referenced through this candidate alignment; this pattern applies the adopting Dimension policy to its own evidence and does not redefine a retention schedule."}]},"distinguishingFeatures":["One application of a policy to a case, while the policy rule itself is a separate, versioned subject.","Records inputs, decision, obligations and explanation together, so the outcome can be replayed and audited.","Precedes enforcement: the evaluator decides, an enforcement point acts.","Automated and rule-bound, unlike a human decision or approval."],"structure":{"bundles":[{"id":"XCT038-B1","name":"Inputs","description":"What was evaluated.","layers":[{"id":"XCT038-B1-L1","name":"Request and context","description":"The subject, action, resource and context attributes supplied.","findings":[{"id":"XCT038-F01","name":"Request attributes","description":"Who asked to do what to which resource.","questions":[{"text":"Which subject, action and resource were evaluated?","id":"XCT038-Q01"},{"text":"Which context attributes, such as time, location or purpose, were supplied?","id":"XCT038-Q02"}]},{"id":"XCT038-F02","name":"Policy version","description":"The policy set and version used.","questions":[{"text":"Which policy set and version did the evaluator apply?","id":"XCT038-Q03"},{"text":"Was that version in force at the time of the request?","id":"XCT038-Q04"}]}]}]},{"id":"XCT038-B2","name":"Decision","description":"What the evaluator returned.","layers":[{"id":"XCT038-B2-L1","name":"Result and obligations","description":"The decision with attached obligations and advice.","findings":[{"id":"XCT038-F03","name":"Decision value","description":"Permit, deny, not applicable or indeterminate.","questions":[{"text":"What decision did the evaluation return?","id":"XCT038-Q05"},{"text":"Was the result indeterminate because of missing or conflicting inputs?","id":"XCT038-Q06"}]},{"id":"XCT038-F04","name":"Obligations","description":"Duties the enforcing party must fulfil with the decision.","questions":[{"text":"Which obligations or advice were attached to the decision?","id":"XCT038-Q07"},{"text":"Were the obligations fulfilled by the enforcing party?","id":"XCT038-Q08"}]}]}]},{"id":"XCT038-B3","name":"Explanation and audit","description":"Why the decision came out as it did.","layers":[{"id":"XCT038-B3-L1","name":"Explanation","description":"The rules that matched and the combining logic.","findings":[{"id":"XCT038-F05","name":"Matched rules","description":"The rules that determined the outcome.","questions":[{"text":"Which rules matched, and how were conflicts between them combined?","id":"XCT038-Q09"},{"text":"Can the decision be explained in terms a requester can understand?","id":"XCT038-Q10"}]},{"id":"XCT038-F06","name":"Audit record","description":"The stored evaluation record for review.","questions":[{"text":"Is the evaluation recorded with time, evaluator and inputs for later audit?","id":"XCT038-Q11"},{"text":"Can the evaluation be replayed with the same policy version and inputs?","id":"XCT038-Q12"}]}]}]}]},"agentConduct":{"may":["Request policy evaluations before acting and comply with the decision.","Record evaluations with inputs, policy version, decision and obligations.","Explain a decision by citing the matched rules.","Flag indeterminate results and policy conflicts for owners."],"mustNot":["Act against a deny decision or skip evaluation for actions that require it.","Supply false or selective inputs to obtain a permit.","Ignore obligations attached to a permit decision.","Alter or delete evaluation records after the fact.","Evaluate against a policy version other than the one in force without recording why."],"requiresHuman":["Overriding a deny decision in an exceptional case.","Resolving a policy conflict or an indeterminate result that blocks a critical action.","Changing the policy that was evaluated."]},"ethics":{"considerations":["Automated policy decisions affect access to services and data, so people need explanations and a route to contest them.","Inputs about people, such as role or location, can encode discrimination into decisions.","Evaluation logs reveal behaviour and need protection and limited retention."],"affectedParties":["Requesters whose actions are allowed or denied","Data subjects whose data is protected by the policy","Policy owners and administrators","Auditors and regulators"]},"owners":{"steward":"The owner of the policy and the evaluation service, who answers for correct and explainable decisions.","roles":[{"name":"Evaluation steward","responsibilities":["Own the local record boundary and adoption profile, without assuming policy approval authority."]},{"name":"Policy authority","responsibilities":["Approve and version policy in its external master; authorize scoped exceptions separately."]},{"name":"Evaluator operator","responsibilities":["Run approved profiles, preserve native results and report failure without inventing decisions."]},{"name":"Enforcement operator","responsibilities":["Check binding and obligations, execute only authorized actions and supply attempt evidence."]},{"name":"Evidence custodian","responsibilities":["Apply access, retention, correction and disposal rules to local evidence."]},{"name":"Independent reviewer","responsibilities":["Assess semantic mappings and contest evidence with read scopes independent of the evaluated request."]}],"masterSystems":["Policy decision point","Policy administration point","Authorization audit log"]},"relations":[{"target":"WM-KNW-012","type":"references","note":"Required conceptual rule/policy master binding; pin policy content and version without importing authoring lifecycle. Registry parent does not prove schema inheritance; exact runtime model binding remains an adoption hold."},{"target":"WM-XCT-003","type":"references","note":"Optional contextual link for disclosure evaluations. Preserve the incoming ledger direction from that model to this pattern; this backlink does not reverse ownership of disclosure definitions."},{"target":"WM-XCT-035","type":"aligned","note":"Proposed alignment for retention trigger and hold metadata; adopting policy governs local evidence disposal. No neighbor conformance or pinned version is asserted."},{"target":"https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html","type":"aligned","note":"Profile candidate for native requests, four-valued decisions, obligations, advice and PEP bias; no executable conformance claim."},{"target":"https://openid.net/specs/authorization-api-1_0.html","type":"aligned","note":"Profile candidate for boolean decision API and item-level results; preserve transport errors and semantic loss."},{"target":"https://www.w3.org/TR/odrl-model/","type":"aligned","note":"Usage-policy vocabulary mapping candidate; duty semantics require explicit mapping and are not assumed equivalent to XACML obligations."},{"target":"https://www.w3.org/TR/prov-o/","type":"aligned","note":"Conceptual provenance mapping for input entities, evaluation activities, responsible agents and derived views; not an implemented RDF binding."},{"target":"WM-KNW-012 Policy / Rule","type":"neighbor","note":"Registry parent is conceptual context, not inheritance of rule administration. Pin a rule or policy-set version; this pattern applies it and does not edit or approve it."},{"target":"WM-XCT-003 Projection / Disclosure Policy","type":"neighbor","note":"Incoming REFERENCE ledger assigns decision input, outcome, explanation and enforcement execution here. That model defines disclosure shape. This pattern records and governs the concrete evaluation and enforcement attempt, including executor binding and receipts; resource-specific execution code is external."},{"target":"Human decision and exception authority","type":"neighbor","note":"A machine result is neither consent nor a legally effective human approval. A separately authorized exception is referenced with scope and expiry and cannot rewrite the original decision."},{"target":"WM-XCT-035 Retention / Disposition","type":"neighbor","note":"Retention rules and holds may be referenced through this candidate alignment; this pattern applies the adopting Dimension policy to its own evidence and does not redefine a retention schedule."},{"target":"WM-KNW-012","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Identified by a decision or evaluation identifier issued by the policy decision point, with a time stamp.","Linked to the policy set identifier and version and to the request identifier."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["Recognized by a request, a policy version, a decision value and possibly obligations and an explanation.","Often confused with the policy rule, with the enforcement action or with a human approval."]},"capabilities":{"applicability":"required","items":["Can return permit, deny, not applicable or indeterminate for a request.","Can attach obligations and advice that the enforcing party must handle.","Can be replayed for audit when inputs and policy versions are kept."]},"hazards":{"applicability":"required","items":["Unauthorized access from wrong policies or manipulated inputs.","Lockouts from deny decisions in critical situations.","Unexplainable decisions that cannot be contested."]},"interfaces":{"applicability":"required","items":["OASIS XACML 3.0 for policy evaluation requests and responses.","OpenID AuthZEN authorization API.","W3C ODRL for usage policies over content and data."]},"context":{"applicability":"required","items":["Used in access control, data usage control, compliance automation and agent guardrails.","Automated decisions with legal or similar effects on people fall under data protection rules on automated decision-making."]}},"sources":[{"title":"eXtensible Access Control Markup Language (XACML) Version 3.0","url":"https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html","note":"OASIS"},{"title":"Guide to Attribute Based Access Control (ABAC) Definition and Considerations","url":"https://csrc.nist.gov/pubs/sp/800/162/upd2/final","note":"NIST"},{"title":"Authorization API 1.0","url":"https://openid.net/specs/authorization-api-1_0.html","note":"OpenID Foundation"},{"title":"ODRL Information Model 2.2","url":"https://www.w3.org/TR/odrl-model/","note":"W3C"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"W3C"},{"title":"Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/rfc/rfc3339","note":"IETF"},{"title":"Terminology for Policy-Based Management","url":"https://www.rfc-editor.org/rfc/rfc3198","note":"IETF"},{"title":"Security and Privacy Controls for Information Systems and Organizations","url":"https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final","note":"NIST"},{"title":"eXtensible Access Control Markup Language (XACML) Version 3.0, OASIS"},{"title":"NIST SP 800-162 Guide to Attribute Based Access Control (ABAC) Definition and Considerations, NIST"},{"title":"ODRL Information Model 2.2, W3C"}],"openQuestions":["Restore independent external review before any canonical or publishable-draft promotion.","Verify source revisions, errata, licenses and qualified jurisdiction/sector applicability for the adopting profile.","Develop executable nested schemas and loss-aware adapters with fixtures for missing context, batch failures, unfulfilled duties, stale permits, tenant crossing, replay isolation and duplicate enforcement.","Specify continuous authorization, revocation and distributed execution guarantees in dedicated adoption profiles.","Executable nested instance schemas, pinned neighboring model versions and tested adapters.","Continuous authorization, streaming revocation, distributed enforcement transactions and specialized duty semantics require separate profiles.","Latest releases, errata, licensing and jurisdiction-specific applicability remain to be verified.","Independent external review is absent; local no-tools self-audit cannot replace it."],"resources":{"spec":"/models/wm-xct-038-policy-evaluation/spec.yaml","agents":"/models/wm-xct-038-policy-evaluation/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-038"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-xct-038-policy-evaluation/spec.yaml","ver-cy/world-models/card-supplements/wm-xct-038-policy-evaluation.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-10-06T13:32:08Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"A policy evaluation is a computed decision record, not a physical object, so it has no physical properties to measure.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-06, unreviewed). Written from the card's existing content and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}