{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-007","code":"world-s7-access-enforcement-and-breach","url":"https://ver.cy/models/world-s7-access-enforcement-and-breach/","name":"Access Enforcement & Breach","alternateNames":["S7"],"kind":"world-model","status":"legacy","version":"0.2.0-legacy","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.ENF"],"industry":["Cross-industry"],"navPath":"NAV.XCT.ENF","tags":["access","breach","enforcement","xct.enf"],"facets":{}},"whatItIs":"This meta-model describes what happens when the cluster's promises are broken: reads outside scope, onward sharing, retention past the deadline, grants ignored after revocation.","purpose":"Access violations breaches sanctions and remedies","scope":{"in":[],"out":[],"boundaries":[]},"distinguishingFeatures":["It is its own model because enforcement has a lifecycle and evidence discipline of its own, distinct from the contracts it protects and from the courts that decide contested cases."],"structure":{"bundles":[{"id":"violation","name":"violation","description":"Noticing and investigating","layers":[{"id":"signals","name":"signals","description":"anomalies from the audit log and reports from owners","findings":[]},{"id":"cases","name":"cases","description":"opened proceedings, gathered evidence, referral state","findings":[]}]},{"id":"resolution","name":"resolution","description":"Consequences and redress","layers":[{"id":"sanctions","name":"sanctions","description":"consequences imposed on the violator","findings":[]},{"id":"remedies","name":"remedies","description":"what the harmed party receives, from notification to erasure and restitution","findings":[]}]},{"id":"standing","name":"standing","description":"The violator's ongoing status","layers":[{"id":"complianceStatus","name":"complianceStatus","description":"a grantee's current standing across all cases","findings":[]},{"id":"reinstatement","name":"reinstatement","description":"the path back to good standing after remedies are fulfilled","findings":[]}]}]},"agentConduct":{"may":[],"mustNot":[],"requiresHuman":[]},"ethics":{"considerations":["It records signals, cases, established breaches, the sanctions imposed and the remedies delivered to the harmed party, plus each grantee's resulting standing.","It owns process records only: evidence stays anchored in S4, the harmed owner's rights stay theirs, and reads of enforcement data follow S1/S2 like everything else.","breachNotification: the harmed owner is informed of an established breach touching their objects, with the case evidence they are entitled to."],"affectedParties":[]},"owners":{"steward":"An enforcement registrar archetype keeps cases, sanctions and standing, acting alongside the courts (A19) that decide contested matters.","roles":[],"masterSystems":[]},"relations":[{"target":"world.accessContract","type":"references","note":"the violated instrument, its scope and its obligations define what counts as a breach."},{"target":"world.accessAudit","type":"references","note":"the append-only log is the primary evidence source; signals cite entries and proofs of inclusion."},{"target":"world.ownership","type":"references","note":"the harmed party is resolved through ownership records, including guardians acting for wards."},{"target":"world.privacyAggregation","type":"references","note":"public enforcement statistics are released only at cohort grain under its floors."},{"target":"world.disputeResolution","type":"references","note":"contested cases are decided by the courts model; this model records referrals and receives outcomes."},{"target":"odrl","type":"imports","note":"ALIGN: duty, prohibition and remedy vocabulary mapped onto obligations, sanctions and redress."},{"target":"iso-29100","type":"imports","note":"ALIGN: privacy principles, including redress, that remedy kinds trace to."},{"target":"vr.wm-pol-010","type":"requires"},{"target":"vr.wm-pol-014","type":"requires"},{"target":"vr.wm-xct-004","type":"requires"},{"target":"vr.wm-xct-005","type":"requires"}],"interaction":{"identity":{"applicability":"required","items":[]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":[]},"capabilities":{"applicability":"required","items":["signalRaised: an anomaly or report suggested a violation.","caseOpened: triage found the signal credible and a proceeding began.","caseReferred: a contested or grave case was handed to the courts with its evidence package.","breachEstablished: a violation was found proven, by the enforcing body or by a court.","sanctionImposed: a consequence took effect against the violator.","remedyDelivered: the harmed party received their redress and it was evidenced.","caseDismissed: a case closed without an established breach.","standingReinstated: a violator returned to good standing after fulfilling conditions."]},"hazards":{"applicability":"optional","items":[]},"interfaces":{"applicability":"required","items":["breachNotification: the harmed owner is informed of an established breach touching their objects, with the case evidence they are entitled to.","courtReferral: the evidence package and case record are transmitted to the adjudication model under chain-of-custody terms.","standingCheck: a prospective grantor queries a grantee's current standing before entering a new grant; detail beyond the standing class is not returned.","ownerCaseView: all signals, cases and outcomes touching my objects; omits every other owner's matters.","standingBadge: a grantee's current standing class only; omits case detail and history.","enforcementStatistics: cohort-grain counts of breaches, sanctions and remedies via the S5 machinery; omits all parties."]},"context":{"applicability":"required","items":["It owns process records only: evidence stays anchored in S4, the harmed owner's rights stay theirs, and reads of enforcement data follow S1/S2 like everything else."]}},"sources":[],"openQuestions":["Superseded by a researched world model? Map this legacy card to its successor or retire it."],"resources":{"spec":"/models/world-s7-access-enforcement-and-breach/spec.yaml","agents":"/models/world-s7-access-enforcement-and-breach/AGENTS.md"},"provenance":{"origin":"legacy MMAS card (world-models v0.2)","builtFrom":["models/world-s7-access-enforcement-and-breach/spec.yaml","models/docs/security-ownership-access/S7-access-enforcement-and-breach.md"],"providers":[],"researchStatus":"legacy","generatedAt":"","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"derived","purpose":"filled","distinguishingFeatures":"derived","structure":"thin","agentConduct":"missing","ethics":"derived","owners":"filled","relations":"filled","interaction.identity":"missing","interaction.properties":"not-applicable","interaction.recognition":"missing","interaction.capabilities":"derived","interaction.hazards":"missing","interaction.interfaces":"derived","interaction.context":"filled","sources":"missing"},"notes":{"whatItIs":"First sentence of the legacy card introduction.","interaction.capabilities":"Legacy events listed as state transitions.","structure":"Legacy card: layers named, findings and questions never written.","interaction.properties":"Institutional or informational subject: no invented physical properties."},"score":0.5}}