{
  "metaModel": {
    "id": "enterprise-disclosure-review",
    "registryId": "vr.profile.enterprise-disclosure-review",
    "version": "0.1.0",
    "name": "Enterprise Disclosure Review",
    "kind": "companion-contract"
  },
  "canonicalUrl": "https://ver.cy/models/enterprise-disclosure-review/versions/0.1.0/spec.json",
  "researchAssurance": "reviewable-draft",
  "researchContour": "EM-XCT-05",
  "model": {
    "purpose": "Describe exact packages of single-object metadata projections, preserve attributed joint-disclosure reviews, and check their applicability under explicit current context."
  },
  "composition": {
    "runtimeImports": [],
    "semanticReferences": [
      {
        "id": "WM-XCT-002",
        "version": "0.3.0-research.1",
        "specDigest": "sha256:9085d977567f3e1fc0b9bb27c6a7c517139f5972a1b95bf4a2bedccdb10bf2db",
        "relation": "boundary-reference-no-findings-selected"
      },
      {
        "id": "WM-XCT-003",
        "version": "0.3.0-research.1",
        "specDigest": "sha256:058191fe49bd1a52d52669211893d91971511f33a2aad1f15407e409d2553edb",
        "relation": "selected-semantic-overlap-not-subtype"
      },
      {
        "id": "WM-XCT-020",
        "version": "0.3.0-research.1",
        "specDigest": "sha256:47aa90ca48b7e367f61c30e454fd7859ba2dc7e2b998bbd4541acb6eda81b9bd",
        "relation": "selected-semantic-overlap-not-subtype"
      },
      {
        "id": "WM-DAT-004",
        "version": "0.3.0-research.1",
        "specDigest": "sha256:0c6fc7db12c33efe0d9283b5830b4c679935dd5b640417e7e315a564b4971c94",
        "relation": "selected-semantic-overlap-not-subtype"
      },
      {
        "id": "WM-KNW-012",
        "version": "0.3.0-research.1",
        "specDigest": "sha256:b7a880e4e07b26f8962e8d3b5b23b33c1062abcb83303ff8f0e8b5a3134e61b8",
        "relation": "selected-semantic-overlap-not-subtype"
      }
    ],
    "delivery": "Original reference, closed schema, synthetic fixtures, contract and native binding; external pins are not executable imports."
  },
  "contract": "# Enterprise Disclosure Review — semantic contract\n\nA bounded original companion for EM-XCT-05. Version 0.1.0 is a bounded reference; the publication manifest records its catalogue lifecycle. It provides metadata records and restricted applicability diagnostics, not a source-value delivery or policy-enforcement service. Publication status and reviewable-draft assurance are distinct. See review.md for actual audit scope and adoption-limits.md before integration.\n\n## Contract\n\nTwo immutable records are supported: a proposal containing 1–32 single-object metadata members, and a review referring to exactly one proposal identity/revision/digest. Members may describe the same or different objects; every member names exactly one, with one consistent revision/digest per referenced ID across the proposal. Different projections of the same object are explicitly separate members. A calculated source aggregate must already be owned/modelled by its domain. The review does not become that domain aggregate.\n\nEvery proposal pins its audience, purpose, environment, known previous-release context and custody-instruction context. Every member pins source revision, source schema, output shape and 1–64 named top-level scalar fields. Every field has 1–8 exact classification-binding references. These are opaque external record pins: identity, revision and digest. This reference does not duplicate external scheme/term definitions, retrieve/interpret artifacts, validate source values or infer a classification order.\n\nThe host snapshot must pin the current proposal itself, contain its complete current context/member declarations, and enumerate the complete active review-pin set. Retiring a proposal changes that current pin. Active and withdrawn review pins must be disjoint; supplied review records must equal the active set. The host attests that the selected fields are scalar leaves of a closed source schema and that its external pins actually resolve to their declared objects, classifications and current custody context. The reference checks exact agreement, not the truth or completeness of those assertions. Merely echoing the caller's proposal as the host snapshot defeats the integration contract. Examples are stamped host-internal synthetic fixtures and are not a source resolver or integration template.\n\nThe whole snapshot is validated against a closed schema and exact identifier grammar before returning any record result. Active review IDs are unique; active/withdrawn overlap is rejected by identity/revision even if their digests differ. Withdrawn-pin existence and historical provenance remain host attestations. Snapshot `asOf` must equal the trusted host's supplied evaluation `now`; this binds the declared time but does not attest clock accuracy or that authority/source observations actually came from that instant. A current snapshot cannot be relabeled as historical evidence without a genuine preserved snapshot from that time.\n\n`inspect()` returns restricted internal applicability diagnostics. It requires a **trusted host assertion** for Dimension and inspect capability before inspecting record contents. This assertion is not an authentication token, signature or user request field. The host must authenticate and authorize the request separately. No result is suitable for forwarding verbatim to a recipient. Uniform HTTP refusal, timing/existence protection and actual serving are not implemented.\n\nCurrent author/reviewer authority, exact context/membership, the complete review set, withdrawal and the half-open review interval `[validFrom, validTo)` affect applicability. Assessment time cannot predate proposal capture, even for an unauthoritative review; future capture is stale. A cleared applicable review yields `applicable-review`. Every return carries `notServingAuthorization=true`, the proposal pin, snapshot digest, evaluation time, counted review pins, ignored pins/verdicts/reasons and the withdrawn-pin list. These are restricted diagnostics. All verdicts, including negative/inconclusive ones, cease to contribute outside their declared windows or current authority; expiration alone never grants clearance, and ignored negatives remain visible alongside any independently valid clearance. Hosts requiring persistent objections need a different explicitly reviewed profile.\n\nRejection, inconclusive assessment, absent/expired review, stale context and conflicting eligible verdicts remain distinct. Only one active revision per review identity is accepted, and an active review cannot immediately supersede another still-active review. An explicit startup profile permits self-clearance; segregation profiles require a different reviewer for clearance. An authorized author's rejection or inconclusive assessment still counts under segregation and conflicts with another reviewer's clearance. Qualified ASCII actor strings are compared exactly; the host must bind them to actual distinct people where required, rather than aliases. These are governance choices, not a NIST conformance claim. Early stale/context results have `reviewsEvaluated=false`, with no verdict analysis; counted/ignored visibility applies after review evaluation.\n\nThe `priorReleases` pin records the host's known relevant release context, not all knowledge held by every recipient. Human clearance and exact pins do not prove privacy, prevent subtraction/re-identification, or erase earlier releases. `custodyContext` is an opaque pin to separately owned instructions, including any unresolved hold/schedule conflict. Its equality establishes neither permission nor prohibition to retain, serve or destroy. No actual disposition-state calculation exists here. The host evaluator must return insufficient-context for unresolved custody or unsupported classification comparisons; inspect() does not perform these checks and can report applicable-review while a hold remains unresolved. The matrix example contains an explicit reviewer rejection of a synthetic subtraction risk; the code does not discover the risk itself.\n\nThere is no structured source-value payload field, but free-text `residualRisk` and identifiers can themselves contain sensitive facts. The code neither detects nor redacts them. Authors must avoid copying source values into notes unless their actual record policy permits it. Actor identifiers, notes, diagnostic pins and past revisions need their own access and custody controls. Immutability means no silent in-place revision, not a universal obligation to retain personal data forever; disposal of records remains a separately governed host operation.\n\n## Identity, time and changes\n\nThe digest is SHA-256 over the entire record with only its top-level `digest` member removed. Format, type/version, Dimension, identity, revision and body are included. Encoding is a named local restricted JSON representation: UTF-8, sorted string keys, compact separators, no floats/nonfinite values or Unicode normalization; list order is significant. This is not RFC 8785/JCS. Identifiers use exact scheme-bearing printable ASCII syntax; revisions/member keys use nonempty ASCII letters/digits/dot/underscore/hyphen tokens, with no whitespace. Code uses full-string matching in addition to JSON Schema patterns. No URI equivalence or identifier-alias resolution is claimed.\n\nEncoding rules: keys sort by Unicode scalar/code-point order; quote and backslash use `\\\"` and `\\\\`; backspace/form-feed/newline/carriage-return/tab use `\\b`, `\\f`, `\\n`, `\\r`, `\\t`; other U+0000–001F characters use lowercase four-digit `\\u00xx`; slash, DEL, U+2028/U+2029 and other permitted scalar characters are emitted literally in UTF-8. Integers use ordinary base-10 without a plus sign or leading zeros; booleans/null are lowercase JSON tokens. Surrogates and Python container/string subclasses are rejected. The tests include a literal byte vector with C0 controls, U+2028, quote and backslash. No independently implemented cross-language/native digest compatibility is claimed.\n\nJSON input rejects duplicate keys, invalid UTF-8 and non-integer numeric syntax. Dictionary APIs are not wire parsers; the host must use `load()` for serialized input. No missing offset or leap-second support: timestamps are actual calendar instants in whole UTC seconds with `Z`. Calendar parsing avoids platform-dependent year formatting. Field `kind: number` describes external source metadata only; this format carries no numeric source payload.\n\n`seal()` computes content integrity and validates local structure. It does not approve content. `import_records()` performs a pure transactional immutable merge of the complete local master set: same revision+digest is idempotent; a conflicting revision fails; corrections use a new revision and preserve history. It requires both inspect and record host assertions. It does not persist, authenticate the writer's object-specific role, compare-and-swap a database, or enforce review authority at write time. The host must do those things. Imported unauthoritative reviews may be retained as evidence but cannot count as applicable under a different current authority snapshot.\n\nThe import validates internal review→proposal and optional review→superseded-review pins against that full local set: exact existence/digest, correct type, same proposal identity for supersession, nondecreasing assessment times and acyclic supersession links. Self-supersession of the same identity/revision is invalid. Supersession does not automatically change authority or the host's active set. Same-second corrections can be ordered by the explicit link; opaque revision strings have no numeric/lexical ordering meaning. A snapshot inspection assumes those store-level invariants were enforced at import; it additionally rejects multiple active revisions and a still-active superseded target.\n\nThe inspection check covers only immediate supersession edges in the supplied active records. The host must deactivate transitive superseded ancestors too; inspect cannot recover an omitted intermediate record. Supersession forks and replacement across revisions of the same proposal identity are permitted; current governance must resolve the active set without silently selecting a winner. Import's cycle traversal is defensive; constructing a digest-consistent cycle is not part of the executed fixture evidence. Reference coherence concerns nested reference pins; it does not reserve the envelope's own ID as an external-reference namespace.\n\nHistorical answers need preserved snapshots and current permission to read those records; each returned answer pins its input snapshot. No past serving decision is reusable as a current grant. Prototype R1/R2/R3 records are refused by 0.1.0; preserve and inspect them with their original frozen schema/reference. The release version changes every record digest; do not relabel or automatically reseal old evidence. No automatic mixed-version import, upgrade or downgrade exists. A future release needs explicit migration mappings and separate version dispatch rather than reinterpretation of stored bytes.\n\n## Execution and limits\n\nRun `python test_disclosure.py` with Python 3.11+ and `jsonschema==4.26.0`. This writes a test report and three synthetic fixtures. The reference has no network, data-serving or destruction operation. Input bounds (256 KiB, depth 20, at most 128 entries in a generic list/object, 32 members, 64 fields/member) are reference constraints, not a tested denial-of-service protection. The byte cap can bind before all cardinality maxima are reached. The report records code/schema/test/README hashes and Python/jsonschema versions.\n\nAdditional bounds: at most 64 supplied active reviews, 64 active pins, 64 withdrawn pins and 64 entries per actor catalog; immutable merge requires the complete local master set, and `len(existing)+len(incoming)` cannot exceed 128 even for an idempotent replay. This reference cannot scale by silently partitioning away required internal references. A real rollover/partition/migration design is future work. The test report is written after fixtures and also hashes their exact generated bytes. The code version is checked against all three schema version constants (proposal, review and snapshot) on module load.\n\nThe tests include three profiles, schema/classification/context drift, changed membership/fields/order, known prior-release/custody-context changes, withdrawn authority, reviewer segregation, half-open expiry, equal-authority conflict, incomplete review sets, immutable correction/import, internal supersession links, type preservation, rights assertions, malformed/unsupported JSON, identifier-alias edge cases, nested-field rejection and round-trip. They do not test a real source resolver, policy engine, schema compiler, reviewer judgment, custodian, database concurrency, recipient channel or native V3 engine in this unit suite. Native synthetic checks are recorded separately in acceptance-results.json. See the current test report for the executed count.\n\nThe semantic tree is in spec.json. Native V3 binding stores each proposal/review identity as its own object and each immutable revision as a separate restricted fact. Native storage time is distinct from proposal capture and review validity. All revision facts coexist; native fact supersession does not select the active review. Validate native envelopes, validate_native(), the complete local register through import_records(), and inspect() under independently obtained current host state. The explicit companion calls are not automatically dispatched by V3.\n\n## Release clarifications after the R3 prototype audits\n\nHost snapshots carry an exact format/version and every answer carries evaluatorVersion. Snapshot activeReviews is scoped to the exact proposal revision, not all revisions of that proposal identity. Inspection additionally refuses proposal/review identity collision and any active immediate supersession target by identity/revision, including conflicting digests. Assessment after the evaluation instant, not-yet-valid intervals and expired reviews have distinct ignored reasons. Earlier authority/segregation exclusions remain the first reason if several exclusions apply.\n\nReference coherence enforces one revision/digest per referenced ID across all roles in a record, including evidence. It cannot cite an earlier revision of that same ID as a diff baseline in the same record; use a separately identified externally governed diff artifact, without pretending it is the earlier object itself.\n\nIgnored supplied reviews retain verdict/reason. Withdrawn reviews are represented by pins only; retrieve their historical records under current read authority for their verdict. Maximum string length is 4096 Unicode code points. The closed bounds remain operational limits, not a hostile-input protection claim.\n\nThe 128 bound applies to the complete current local register plus incoming batch; repeated import also consumes the batch count. It is not a monotone lifetime counter. With indefinite historical retention it is effectively a 128-record growth ceiling. Partial disposal leaving an internal dangling proposal/supersession reference makes subsequent import invalid. This implementation offers no tombstone semantics or disposal/migration operation. Any separate host disposal must preserve internal reference closure; replacing records with fabricated tombstones or silently dropping required history is not supported. Retention constraints may forbid even a reference-closed removal, so obtain the actual custody decision.\n\nAt-rest append-only storage and compare-and-swap are host duties. The pure merge detects immutable conflicts only against the supplied register. An independently trusted prior digest or snapshot is needed to detect replacement of an unreferenced stored leaf.\n\nMaximum review validity duration is host policy. The local format requires an end time but permits dates through year 9999; finite validity is not a short-expiry guarantee.\n",
  "structure": {
    "bundles": [
      {
        "id": "DR-B-identity",
        "name": "Identity and classification",
        "description": "Identity and classification for an exact metadata proposal and attributed joint review.",
        "layers": [
          {
            "id": "DR-L-subject",
            "name": "Objects and proposal boundary",
            "description": "Objects and proposal boundary with explicit local and external responsibilities.",
            "findings": [
              {
                "id": "DR-F01",
                "name": "Which single object does each member describe?",
                "description": "Coverage: local-structure; external identity truth.",
                "questions": [
                  {
                    "id": "DR-Q01",
                    "text": "Which single object does each member describe?",
                    "kind": "governed-context",
                    "answer_data": [
                      "One qualified source pin per member; locally unique member key",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A01",
                    "name": "One qualified source pin per member; locally unique member key",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT01",
                    "description": "Validate exact member grammar; ask domain steward for identity evidence. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local-structure; external identity truth"
              },
              {
                "id": "DR-F02",
                "name": "Which exact source revision and schema were used?",
                "description": "Coverage: local-equality; host resolution.",
                "questions": [
                  {
                    "id": "DR-Q02",
                    "text": "Which exact source revision and schema were used?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Source and schema pins plus proposal capture time",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A02",
                    "name": "Source and schema pins plus proposal capture time",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT02",
                    "description": "Compare exact pins; request independently resolved source metadata. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local-equality; host resolution"
              },
              {
                "id": "DR-F03",
                "name": "Is this a projection, a package or a domain aggregate?",
                "description": "Coverage: modeled boundary; calculation outside scope.",
                "questions": [
                  {
                    "id": "DR-Q03",
                    "text": "Is this a projection, a package or a domain aggregate?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Proposal boundary; one object per member; separately owned aggregate definition",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A03",
                    "name": "Proposal boundary; one object per member; separately owned aggregate definition",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT03",
                    "description": "Keep member/package identities distinct; ask domain owner for aggregate calculation. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "modeled boundary; calculation outside scope"
              }
            ]
          },
          {
            "id": "DR-L-classification",
            "name": "Classification references",
            "description": "Classification references with explicit local and external responsibilities.",
            "findings": [
              {
                "id": "DR-F04",
                "name": "Which classification binds every selected field?",
                "description": "Coverage: local cardinality; external binding interpretation.",
                "questions": [
                  {
                    "id": "DR-Q04",
                    "text": "Which classification binds every selected field?",
                    "kind": "governed-context",
                    "answer_data": [
                      "One or more exact classification-binding pins per field; external scheme and term",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A04",
                    "name": "One or more exact classification-binding pins per field; external scheme and term",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT04",
                    "description": "Reject missing bindings; ask classification authority for pinned scheme and term. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local cardinality; external binding interpretation"
              },
              {
                "id": "DR-F05",
                "name": "Who may correct or downgrade a classification?",
                "description": "Coverage: host-only authority; no classification mutation.",
                "questions": [
                  {
                    "id": "DR-Q05",
                    "text": "Who may correct or downgrade a classification?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Current classification authority and correction evidence",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A05",
                    "name": "Current classification authority and correction evidence",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT05",
                    "description": "Request a governed correction; do not change an opaque pin as a downgrade. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "host-only authority; no classification mutation"
              },
              {
                "id": "DR-F06",
                "name": "Are schemes or compartments comparable?",
                "description": "Coverage: deferred comparison engine.",
                "questions": [
                  {
                    "id": "DR-Q06",
                    "text": "Are schemes or compartments comparable?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Explicit pinned mapping and combination rule from classification owner",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A06",
                    "name": "Explicit pinned mapping and combination rule from classification owner",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT06",
                    "description": "Host evaluator returns insufficient-context for unsupported comparison. Proposed operation only; requires the named host/domain authority. inspect() does not perform this check; applicable-review does not establish comparison or custody resolution."
                  }
                ],
                "implementationScope": "deferred comparison engine"
              }
            ]
          }
        ]
      },
      {
        "id": "DR-B-disclosure",
        "name": "Proposed disclosure and current authority",
        "description": "Proposed disclosure and current authority for an exact metadata proposal and attributed joint review.",
        "layers": [
          {
            "id": "DR-L-shape",
            "name": "Closed metadata shape",
            "description": "Closed metadata shape with explicit local and external responsibilities.",
            "findings": [
              {
                "id": "DR-F07",
                "name": "Which fields are proposed for disclosure?",
                "description": "Coverage: local declaration; no payload serving.",
                "questions": [
                  {
                    "id": "DR-Q07",
                    "text": "Which fields are proposed for disclosure?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Exact ordered field names/kinds, shape/schema pins and complete current declarations",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A07",
                    "name": "Exact ordered field names/kinds, shape/schema pins and complete current declarations",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT07",
                    "description": "Validate metadata selection; ask host for separate current serving authorization. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local declaration; no payload serving"
              },
              {
                "id": "DR-F08",
                "name": "Can nested values introduce another object?",
                "description": "Coverage: local syntax; scalar truth is host attestation.",
                "questions": [
                  {
                    "id": "DR-Q08",
                    "text": "Can nested values introduce another object?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Closed scalar source-field attestation; declared top-level field grammar",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A08",
                    "name": "Closed scalar source-field attestation; declared top-level field grammar",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT08",
                    "description": "Reject nested/wildcard field names; require separate member for another object. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local syntax; scalar truth is host attestation"
              },
              {
                "id": "DR-F09",
                "name": "Can notes, identifiers, counts or errors reveal withheld facts?",
                "description": "Coverage: manual assessment; no leakage detector.",
                "questions": [
                  {
                    "id": "DR-Q09",
                    "text": "Can notes, identifiers, counts or errors reveal withheld facts?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Residual-risk review and restricted diagnostic-channel design",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A09",
                    "name": "Residual-risk review and restricted diagnostic-channel design",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT09",
                    "description": "Record concern; keep reports internal; ask host to assess side channels. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "manual assessment; no leakage detector"
              }
            ]
          },
          {
            "id": "DR-L-authority",
            "name": "Current authority and freshness",
            "description": "Current authority and freshness with explicit local and external responsibilities.",
            "findings": [
              {
                "id": "DR-F10",
                "name": "What current grant permits this audience and purpose?",
                "description": "Coverage: outside implementation; mandatory before serving.",
                "questions": [
                  {
                    "id": "DR-Q10",
                    "text": "What current grant permits this audience and purpose?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Actual host policy/grant decision with fresh subject/object/operation/context",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A10",
                    "name": "Actual host policy/grant decision with fresh subject/object/operation/context",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT10",
                    "description": "Request host decision; no review status establishes a grant. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "outside implementation; mandatory before serving"
              },
              {
                "id": "DR-F11",
                "name": "Has context changed since assessment?",
                "description": "Coverage: local exact comparison; host completeness.",
                "questions": [
                  {
                    "id": "DR-Q11",
                    "text": "Has context changed since assessment?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Current proposal, member, classification, audience, purpose, environment, prior-release and custody pins",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A11",
                    "name": "Current proposal, member, classification, audience, purpose, environment, prior-release and custody pins",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT11",
                    "description": "Compare all declared current inputs; return stale on disagreement. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local exact comparison; host completeness"
              },
              {
                "id": "DR-F12",
                "name": "May an earlier result be reused now?",
                "description": "Coverage: local applicability; cache/atomic serving external.",
                "questions": [
                  {
                    "id": "DR-Q12",
                    "text": "May an earlier result be reused now?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Fresh authorized snapshot, current clock and complete active review set",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A12",
                    "name": "Fresh authorized snapshot, current clock and complete active review set",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT12",
                    "description": "Reevaluate; retain old snapshot only as historical evidence. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local applicability; cache/atomic serving external"
              }
            ]
          }
        ]
      },
      {
        "id": "DR-B-composition",
        "name": "Joint review and aggregate boundaries",
        "description": "Joint review and aggregate boundaries for an exact metadata proposal and attributed joint review.",
        "layers": [
          {
            "id": "DR-L-membership",
            "name": "Exact joint context",
            "description": "Exact joint context with explicit local and external responsibilities.",
            "findings": [
              {
                "id": "DR-F13",
                "name": "Which exact component set was jointly reviewed?",
                "description": "Coverage: local exact pinning.",
                "questions": [
                  {
                    "id": "DR-Q13",
                    "text": "Which exact component set was jointly reviewed?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Review proposal pin and exact ordered member/field set",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A13",
                    "name": "Review proposal pin and exact ordered member/field set",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT13",
                    "description": "Refuse review for a different revision/digest; request new review after change. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local exact pinning"
              },
              {
                "id": "DR-F14",
                "name": "What combined inference risk was assessed?",
                "description": "Coverage: local attribution; no inference proof.",
                "questions": [
                  {
                    "id": "DR-Q14",
                    "text": "What combined inference risk was assessed?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Attributed verdict, method, evidence, residualRisk and bounded validity",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A14",
                    "name": "Attributed verdict, method, evidence, residualRisk and bounded validity",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT14",
                    "description": "Keep rejection/inconclusive/conflict; request qualified human assessment. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local attribution; no inference proof"
              },
              {
                "id": "DR-F15",
                "name": "Which earlier releases were considered?",
                "description": "Coverage: local context binding; not all recipient knowledge.",
                "questions": [
                  {
                    "id": "DR-Q15",
                    "text": "Which earlier releases were considered?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Exact known priorReleases context and its assumptions",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A15",
                    "name": "Exact known priorReleases context and its assumptions",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT15",
                    "description": "Request missing release history; stale if current context differs. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local context binding; not all recipient knowledge"
              }
            ]
          },
          {
            "id": "DR-L-aggregate",
            "name": "Domain aggregates and assessment scope",
            "description": "Domain aggregates and assessment scope with explicit local and external responsibilities.",
            "findings": [
              {
                "id": "DR-F16",
                "name": "Who owns a source aggregate and its calculation?",
                "description": "Coverage: outside implementation.",
                "questions": [
                  {
                    "id": "DR-Q16",
                    "text": "Who owns a source aggregate and its calculation?",
                    "kind": "governed-context",
                    "answer_data": [
                      "External aggregate identity, grain, lineage and semantic owner",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A16",
                    "name": "External aggregate identity, grain, lineage and semantic owner",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT16",
                    "description": "Ask source domain owner; never invent calculated values here. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "outside implementation"
              },
              {
                "id": "DR-F17",
                "name": "Which privacy mechanism or grain applies?",
                "description": "Coverage: deferred privacy mechanisms.",
                "questions": [
                  {
                    "id": "DR-Q17",
                    "text": "Which privacy mechanism or grain applies?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Pinned external mechanism, parameters and evaluation evidence",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A17",
                    "name": "Pinned external mechanism, parameters and evaluation evidence",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT17",
                    "description": "Require a separately verified implementation and explicit limits. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "deferred privacy mechanisms"
              },
              {
                "id": "DR-F18",
                "name": "Does a review apply to another recipient or environment?",
                "description": "Coverage: local binding; no transferable grant.",
                "questions": [
                  {
                    "id": "DR-Q18",
                    "text": "Does a review apply to another recipient or environment?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Exact audience/purpose/environment and review proposal pin",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A18",
                    "name": "Exact audience/purpose/environment and review proposal pin",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT18",
                    "description": "Return stale when context differs; obtain new proposal/review. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local binding; no transferable grant"
              }
            ]
          }
        ]
      },
      {
        "id": "DR-B-continuity",
        "name": "Continuity and custody",
        "description": "Continuity and custody for an exact metadata proposal and attributed joint review.",
        "layers": [
          {
            "id": "DR-L-storage",
            "name": "Expiry and custody boundaries",
            "description": "Expiry and custody boundaries with explicit local and external responsibilities.",
            "findings": [
              {
                "id": "DR-F19",
                "name": "When must serving stop versus evidence remain?",
                "description": "Coverage: local review expiry only.",
                "questions": [
                  {
                    "id": "DR-Q19",
                    "text": "When must serving stop versus evidence remain?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Separate current serving policy and custody instructions; review expiry",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A19",
                    "name": "Separate current serving policy and custody instructions; review expiry",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT19",
                    "description": "Reevaluate review window; ask host to stop serving and custodian to decide retention. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local review expiry only"
              },
              {
                "id": "DR-F20",
                "name": "Who controls source, output, cache and backup copies?",
                "description": "Coverage: outside implementation; opaque context pin.",
                "questions": [
                  {
                    "id": "DR-Q20",
                    "text": "Who controls source, output, cache and backup copies?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Externally resolved custodyContext and scoped custody/lineage map",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A20",
                    "name": "Externally resolved custodyContext and scoped custody/lineage map",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT20",
                    "description": "Identify missing custodian; request owner decision. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "outside implementation; opaque context pin"
              },
              {
                "id": "DR-F21",
                "name": "Do retention, destruction deadlines and holds conflict?",
                "description": "Coverage: deferred disposition engine.",
                "questions": [
                  {
                    "id": "DR-Q21",
                    "text": "Do retention, destruction deadlines and holds conflict?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Separate current constraints and hold evidence from custodians",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A21",
                    "name": "Separate current constraints and hold evidence from custodians",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT21",
                    "description": "Host evaluator returns insufficient-context until actual custodian resolves; perform no destruction. Proposed operation only; requires the named host/domain authority. inspect() does not perform this check; applicable-review does not establish comparison or custody resolution."
                  }
                ],
                "implementationScope": "deferred disposition engine"
              }
            ]
          },
          {
            "id": "DR-L-disposition",
            "name": "Disposal and migration evidence",
            "description": "Disposal and migration evidence with explicit local and external responsibilities.",
            "findings": [
              {
                "id": "DR-F22",
                "name": "Was disposal requested, executed or verified?",
                "description": "Coverage: outside implementation.",
                "questions": [
                  {
                    "id": "DR-Q22",
                    "text": "Was disposal requested, executed or verified?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Distinct actual request, execution and verification receipts",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A22",
                    "name": "Distinct actual request, execution and verification receipts",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT22",
                    "description": "Keep unknown execution unknown; a marker is not destruction. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "outside implementation"
              },
              {
                "id": "DR-F23",
                "name": "What evidence may survive disposal?",
                "description": "Coverage: outside implementation.",
                "questions": [
                  {
                    "id": "DR-Q23",
                    "text": "What evidence may survive disposal?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Actual minimal-evidence policy and exact record/copy scope",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A23",
                    "name": "Actual minimal-evidence policy and exact record/copy scope",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT23",
                    "description": "Request authorized custody decision without perpetual-retention assumption. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "outside implementation"
              },
              {
                "id": "DR-F24",
                "name": "Can the register migrate without losing meaning?",
                "description": "Coverage: local roundtrip; cross-version migration deferred.",
                "questions": [
                  {
                    "id": "DR-Q24",
                    "text": "Can the register migrate without losing meaning?",
                    "kind": "governed-context",
                    "answer_data": [
                      "Complete same-version records, exact pins, source version and explicit loss analysis",
                      "If unavailable: insufficient-context with named missing evidence; lack of read authority remains denied."
                    ]
                  }
                ],
                "artifacts": [
                  {
                    "id": "DR-A24",
                    "name": "Complete same-version records, exact pins, source version and explicit loss analysis",
                    "description": "Evidence to collect; not a claim that the companion creates, resolves or validates every external artifact."
                  }
                ],
                "actions": [
                  {
                    "id": "DR-ACT24",
                    "description": "Roundtrip same version; refuse unsupported version conversion. Proposed operation only; requires the named host/domain authority."
                  }
                ],
                "implementationScope": "local roundtrip; cross-version migration deferred"
              }
            ]
          }
        ]
      }
    ]
  },
  "statistics": {
    "bundles": 4,
    "layers": 8,
    "findings": 24,
    "questions": 24,
    "artifacts": 24,
    "actions": 24
  },
  "catalogue": {
    "alternateNames": [
      "EM-XCT-05",
      "Context Package Proposal",
      "Joint Disclosure Review",
      "Disclosure classification and custody"
    ],
    "domain": [
      "Enterprise",
      "Disclosure review",
      "Information governance"
    ],
    "tags": [
      "disclosure",
      "classification",
      "projection",
      "review",
      "custody"
    ],
    "adoption": "Start with one exact metadata proposal and one attributed review. Pin source/schema/shape/classification and audience/purpose/environment/prior-release/custody context. Preserve immutable revisions and inspect them against independently resolved current governance state. Three synthetic new-Dimension examples exercise the explicit native binding.",
    "limits": "No result grants access, serves source values, proves privacy or executes disposal. Current authority, pin resolution, snapshot completeness and custody remain host responsibilities."
  },
  "invariants": "## Sixteen semantic invariants\n\n1. Each embedded member names exactly one source object; package membership can span objects but a projection cannot silently do so.\n2. Qualified ID, record revision, source/schema revision, lifecycle/applicability and digest remain distinct.\n3. All local reference occurrences of an ID agree on revision/digest; the reference cannot carry two purported current versions of that ID in one record.\n4. No undeclared source value or nested/wildcard field is accepted by the metadata-only grammar.\n5. A missing classification binding or evidence set cannot become an empty/public/clear default.\n6. A review pins exactly the proposal identity/revision/digest; membership, shape, audience or any bound context change invalidates that match.\n7. A current snapshot pins the proposal itself and independently declares all current member/context values.\n8. The complete supplied review set equals the active pin set; duplicate or competing active revisions are invalid.\n9. Active and withdrawn sets are disjoint; an active successor cannot leave its superseded target active.\n10. Review assessment does not predate proposal capture; applicability uses `[validFrom, validTo)` and future capture is stale.\n11. Current author/reviewer catalogs and authority pin are applied; segregation is explicit and actor-alias identity remains a host duty.\n12. Conflicting eligible verdicts cannot silently select a winner. Excluded verdicts retain their pin, result and reason in restricted diagnostics.\n13. Every returned report identifies its proposal, snapshot digest, evaluation time and counted/ignored records, and explicitly conveys no serving authorization.\n14. Within a supplied register, the same identity/revision cannot be repointed; repeat import is idempotent and a failed merge leaves the caller's store unchanged.\n15. Local review/proposal and supersession links resolve by exact pin/type, preserve proposal identity and nondecreasing assessment time, and do not cycle.\n16. Pin equality, a human clearance and any custody-context reference establish no source truth, inference guarantee, current grant, legal conclusion, completed delivery or destruction.\n\nInvariants 1–15 combine local checks with clearly named host attestations; invariant 16 is a semantic boundary and is not a proof produced by unit tests. The final 24 question routes are in spec.json; each names local checks versus host/deferred responsibility.\n\n"
}
