{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-005","code":"world-s5-privacy-aggregation-and-cohort-floor","url":"https://ver.cy/models/world-s5-privacy-aggregation-and-cohort-floor/","name":"Privacy Aggregation & Cohort Floor","alternateNames":["S5"],"kind":"world-model","status":"legacy","version":"0.2.0-legacy","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.PRV"],"industry":["Cross-industry"],"navPath":"NAV.XCT.PRV","tags":["privacy","aggregation","floor","xct.prv"],"facets":{}},"whatItIs":"This meta-model describes how the state of a population is sensed without exposing any person in it: statistics are computed over cohorts, never below a minimum cohort size, with suppression and noise where counts run thin.","purpose":"Aggregated statistics at cohort grain with k-anonymity floors","scope":{"in":[],"out":[],"boundaries":[]},"distinguishingFeatures":["It is its own model because aggregation is a distinct trade with its own artifacts: cohort definitions, k-floors, noise budgets and disclosure review are reusable machinery that many consumers rely on, and the guarantees only hold if that machinery is modelled and checked in one place."],"structure":{"bundles":[{"id":"cohort","name":"cohort","description":"Which population slices may be looked at","layers":[{"id":"definition","name":"definition","description":"dimensions, membership rules and validity windows of cohorts","findings":[]},{"id":"floors","name":"floors","description":"minimum cohort sizes per sensitivity of the underlying data","findings":[]}]},{"id":"computation","name":"computation","description":"Turning members into numbers safely","layers":[{"id":"measures","name":"measures","description":"statistics computed over cohorts and their methods","findings":[]},{"id":"protection","name":"protection","description":"cell suppression, noise addition and privacy budget accounting","findings":[]}]},{"id":"release","name":"release","description":"What actually leaves","layers":[{"id":"review","name":"review","description":"pre-release disclosure checks against floors and budgets","findings":[]},{"id":"publication","name":"publication","description":"released series with method and provenance attached","findings":[]}]}]},"agentConduct":{"may":[],"mustNot":["This meta-model describes how the state of a population is sensed without exposing any person in it: statistics are computed over cohorts, never below a minimum cohort size, with suppression and noise where counts run thin.","seriesSubscription: a consumer receives published series and their revisions; never anything below the published grain.","methodAudit: an auditor examines cohort definitions, floors, budgets and methods; microdata is never in scope."],"requiresHuman":[]},"ethics":{"considerations":[],"affectedParties":[]},"owners":{"steward":"A statistics office steward archetype operates the model within its statutory mandate: it computes and releases, but the underlying data stays with its owners, and the steward's own reads run under S2 contracts and land in the S4 log like anyone else's.","roles":[],"masterSystems":[]},"relations":[{"target":"world.ownership","type":"references","note":"aggregation never transfers control; source objects remain their holders' throughout."},{"target":"world.accessContract","type":"references","note":"sensing requests and series subscriptions are themselves access contracts."},{"target":"world.disclosureScope","type":"references","note":"the aggregation grains that S3 policies point to are defined and enforced here."},{"target":"world.accessAudit","type":"references","note":"every sensing run, review and release is logged."},{"target":"world.person","type":"references","note":"population registers of the person model are the typical cohort source."},{"target":"differential-privacy-practice","type":"imports","note":"ALIGN: noise addition and budget accounting semantics."},{"target":"sdmx","type":"imports","note":"ALIGN: the exchange shape of published statistical series."},{"target":"vr.wm-pol-014","type":"requires"},{"target":"vr.wm-xct-004","type":"requires"}],"interaction":{"identity":{"applicability":"required","items":[]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":[]},"capabilities":{"applicability":"required","items":["cohortDefined: a new population slice was defined and its membership counted.","floorAdjusted: a minimum cohort size was raised or lowered with recorded rationale.","measureComputed: a statistic was computed over a cohort inside the protected environment.","cellSuppressed: a thin cell was withheld or merged before release.","budgetSpent: a release drew down a noise budget, or a budget ran out and blocked further sensing for the period.","reviewPassed: a release candidate cleared disclosure review against floors and budgets.","seriesPublished: reviewed aggregates were released with method and provenance."]},"hazards":{"applicability":"optional","items":[]},"interfaces":{"applicability":"required","items":["seriesSubscription: a consumer receives published series and their revisions; never anything below the published grain.","sensingRequest: a party commissions a new aggregate over defined cohorts; honored only above floors and within budgets.","methodAudit: an auditor examines cohort definitions, floors, budgets and methods; microdata is never in scope.","publicStatistics: published series only; omits cohorts under floor, suppressed cells and all member-level data.","methodologySheet: definitions, floors, suppression and noise methods per series; omits the values' underlying sources.","budgetLedger: budget allocation and spend per source and period; omits what the queries were about."]},"context":{"applicability":"required","items":[]}},"sources":[],"openQuestions":["Superseded by a researched world model? Map this legacy card to its successor or retire it."],"resources":{"spec":"/models/world-s5-privacy-aggregation-and-cohort-floor/spec.yaml","agents":"/models/world-s5-privacy-aggregation-and-cohort-floor/AGENTS.md"},"provenance":{"origin":"legacy MMAS card (world-models v0.2)","builtFrom":["models/world-s5-privacy-aggregation-and-cohort-floor/spec.yaml","models/docs/security-ownership-access/S5-privacy-aggregation-and-cohort-floor.md"],"providers":[],"researchStatus":"legacy","generatedAt":"","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"derived","purpose":"filled","distinguishingFeatures":"derived","structure":"thin","agentConduct":"derived","ethics":"missing","owners":"filled","relations":"filled","interaction.identity":"missing","interaction.properties":"not-applicable","interaction.recognition":"missing","interaction.capabilities":"derived","interaction.hazards":"missing","interaction.interfaces":"derived","interaction.context":"missing","sources":"missing"},"notes":{"whatItIs":"First sentence of the legacy card introduction.","interaction.capabilities":"Legacy events listed as state transitions.","structure":"Legacy card: layers named, findings and questions never written.","interaction.properties":"Institutional or informational subject: no invented physical properties."},"score":0.438}}