{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-004","code":"world-s4-access-audit","url":"https://ver.cy/models/world-s4-access-audit/","name":"Access Audit","alternateNames":["S4"],"kind":"world-model","status":"legacy","version":"0.2.0-legacy","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.AUD"],"industry":["Cross-industry"],"navPath":"NAV.XCT.AUD","tags":["access","audit","xct.aud"],"facets":{}},"whatItIs":"This meta-model is the append-only memory of the cluster: every read, every grant, every denial, recorded once and never rewritten.","purpose":"Append-only log of every read and grant","scope":{"in":[],"out":[],"boundaries":[]},"distinguishingFeatures":["It exists as its own model because evidence has different physics from the data it describes: entries are written by many systems, owned by none of them, chained so that tampering is detectable, and readable above all by the person whose data was touched."],"structure":{"bundles":[{"id":"ledger","name":"ledger","description":"The immutable record itself","layers":[{"id":"entries","name":"entries","description":"sealed records of access events in write order","findings":[]},{"id":"chainIntegrity","name":"chainIntegrity","description":"hash links between entries and periodic published anchors","findings":[]}]},{"id":"evidence","name":"evidence","description":"What each entry proves","layers":[{"id":"attribution","name":"attribution","description":"who read, as which resolved actor, under which contract","findings":[]},{"id":"servedShape","name":"servedShape","description":"which projection policy version and template fingerprint shaped the disclosure","findings":[]}]},{"id":"oversight","name":"oversight","description":"Who may see the log and for how long","layers":[{"id":"ownerVisibility","name":"ownerVisibility","description":"the owner's standing right to their own timeline","findings":[]},{"id":"retentionAndSealing","name":"retentionAndSealing","description":"how long entries persist and when they are sealed from further detail queries","findings":[]}]}]},"agentConduct":{"may":[],"mustNot":["This meta-model is the append-only memory of the cluster: every read, every grant, every denial, recorded once and never rewritten.","An audit registrar archetype operates the log but owns none of its content: it may not read entry payloads beyond what operation requires, and it cannot amend them at all."],"requiresHuman":[]},"ethics":{"considerations":[],"affectedParties":[]},"owners":{"steward":"An audit registrar archetype operates the log but owns none of its content: it may not read entry payloads beyond what operation requires, and it cannot amend them at all.","roles":[],"masterSystems":[]},"relations":[{"target":"world.ownership","type":"references","note":"entries name registered objects, and owner visibility resolves through ownership records."},{"target":"world.accessContract","type":"references","note":"permitted events cite the contract exercised; the log is the contract's execution history."},{"target":"world.disclosureScope","type":"references","note":"each disclosure entry carries the policy version and template fingerprint that shaped it."},{"target":"world.accessEnforcement","type":"references","note":"the log is the primary evidence source for violation signals and enforcement cases."},{"target":"merkle-logs","type":"imports","note":"COMPOSE: the tree structure underlying anchors and inclusion proofs."},{"target":"mu-event","type":"imports","note":"EXTEND: the event primitive that access events specialize."},{"target":"rfc-9162","type":"imports","note":"ALIGN: the verifiable-log pattern of published anchors and third-party auditability."},{"target":"vr.wm-pol-014","type":"requires"},{"target":"vr.wm-xct-007","type":"requires"}],"interaction":{"identity":{"applicability":"required","items":[]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":[]},"capabilities":{"applicability":"required","items":["readRecorded: a permitted read of someone's data was written to the log.","grantRecorded: the creation, amendment or revocation of an access contract was written to the log.","denialRecorded: an attempted read was refused and the refusal preserved.","entrySealed: a batch of events was wrapped, hashed and chained.","anchorPublished: a root hash for a range of entries was made public.","proofIssued: an inclusion proof was produced for a challenged entry.","inconsistencyDetected: a verification failed, indicating tampering or loss between entries and anchors."]},"hazards":{"applicability":"optional","items":[]},"interfaces":{"applicability":"required","items":["ownerAuditFeed: the owner of any object receives, on demand or by subscription, every entry that touched their objects.","oversightExtract: the audit registrar provides aggregate, identity-free extracts for systemic oversight of access patterns.","proofService: any party obtains anchors and inclusion proofs to verify log integrity without reading entry contents.","ownerTimeline: who read my data, when, under which contract; omits every other owner's entries.","readerActivitySummary: aggregate read counts and patterns per reader; omits the identities of touched objects and owners.","integrityBundle: anchors, chain heads and proofs only; omits all event payload."]},"context":{"applicability":"required","items":["The standing beneficiary is the data owner, whose right to their own timeline is not itself contract-gated, while all other access follows S1/S2."]}},"sources":[],"openQuestions":["Superseded by a researched world model? Map this legacy card to its successor or retire it."],"resources":{"spec":"/models/world-s4-access-audit/spec.yaml","agents":"/models/world-s4-access-audit/AGENTS.md"},"provenance":{"origin":"legacy MMAS card (world-models v0.2)","builtFrom":["models/world-s4-access-audit/spec.yaml","models/docs/security-ownership-access/S4-access-audit.md"],"providers":[],"researchStatus":"legacy","generatedAt":"","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"derived","purpose":"filled","distinguishingFeatures":"derived","structure":"thin","agentConduct":"derived","ethics":"missing","owners":"filled","relations":"filled","interaction.identity":"missing","interaction.properties":"not-applicable","interaction.recognition":"missing","interaction.capabilities":"derived","interaction.hazards":"missing","interaction.interfaces":"derived","interaction.context":"filled","sources":"missing"},"notes":{"whatItIs":"First sentence of the legacy card introduction.","interaction.capabilities":"Legacy events listed as state transitions.","structure":"Legacy card: layers named, findings and questions never written.","interaction.properties":"Institutional or informational subject: no invented physical properties."},"score":0.5}}