{
    "model": {
        "rank": 3762,
        "code": "thing-q135005",
        "model_id": "vr.tr.phishing",
        "name": "phishing",
        "purpose": "Enable an AI agent to recognise suspected phishing, record the evidence and uncertainty, assess exposure and consequences, and choose proportionate protective actions.",
        "family": "Thing Registry",
        "category": "Activities and processes",
        "status": "research-draft",
        "kind": "thing",
        "plane": "ACT",
        "domain": "ACT.ACT",
        "industry": "",
        "version": "",
        "url": "/models/thing/q135005/",
        "tier": 2,
        "score": 82,
        "payload": {
            "layer": "wikidata",
            "aliases": [
                "CEO fraud",
                "quishing",
                "Drive-by Pharming",
                "DeepPhish",
                "spear phishing"
            ],
            "aliasCount": 5,
            "merged": 5,
            "knownIn": 82,
            "facets": null,
            "markers": [],
            "lexicalClass": "",
            "senseRank": null,
            "alsoRegisteredAs": null,
            "source": {
                "dataset": "wikidata",
                "item": "Q135005",
                "url": "https://www.wikidata.org/wiki/Q135005",
                "license": "CC0 1.0"
            }
        },
        "research": {
            "vercy": "1.0-draft",
            "publication": {
                "status": "research-draft",
                "adjudicationStatus": "unreviewed",
                "publishableCanonical": false,
                "generatedAt": "2026-09-07T15:05:47Z",
                "providers": [
                    "Codex"
                ],
                "breadth": "recalled by Codex without web access - no source was read",
                "missingProviders": [],
                "pass": 2,
                "cost": {
                    "grok": {
                        "seconds": 25.3,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.3\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a07c66-30c0-7030-b2ac-44b38c365562\n--------\nuser\nDescribe what is already known about one registered thing. Answer as JSON only, no prose around it.\n\nThing: phishing\nSense to describe: (none recorded)\nDomain code: ACT.ACT\nAlso known as: (none)\n\n\nContext for this batch of 801 things:\n# Batch 004: 1001 registe",
                        "usd": 0,
                        "recall": true
                    },
                    "codex": {
                        "seconds": 81.2,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.3\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a07c66-30ce-7bf2-bd58-5e8f12728b33\n--------\nuser\nYou are drafting a Vercy meta-model for one registered thing. Answer as JSON only, no prose around it.\n\nThing: phishing\nRegistry id: vr.tr.phishing\nPlane / domain: ACT / ACT.ACT\nRegistry definition: (none recorded)\nNames folded into this entry: (none)\n\n\nContex"
                    }
                }
            },
            "metaModel": {
                "id": "THING-Q135005",
                "registryId": "vr.tr.phishing",
                "name": "phishing",
                "version": "0.1.0-research.1",
                "entryKind": "thing",
                "family": "Thing Registry",
                "domain": [
                    "ACT.ACT"
                ],
                "status": "research-draft"
            },
            "canonicalUrl": "https://ver.cy/models/thing/q135005/",
            "model": {
                "registry_id": "vr.tr.phishing",
                "name": "phishing",
                "purpose": "Enable an AI agent to recognise suspected phishing, record the evidence and uncertainty, assess exposure and consequences, and choose proportionate protective actions.",
                "definition": "Phishing is a form of social engineering in which deceptive communications exploit apparent trustworthiness to induce a recipient to disclose sensitive information, transfer value, or perform an action that compromises security.",
                "scope_statement": "This model owns phishing as a deceptive communicative act or coordinated set of acts intended to induce a recipient to disclose sensitive information, grant access, transfer value, or perform another security-relevant action through misleading claims of identity, authority, or context; it distinguishes suspected attempts, confirmed attempts, and observed consequences.",
                "in_scope": [
                    "Evidence for classifying a communication or interaction as a phishing attempt",
                    "Claimed identities, impersonated relationships, deceptive pretexts, and requested recipient actions",
                    "Delivery channels, destinations, attachments, and linked stages of the interaction",
                    "Recipient exposure, interaction, and separately verified security consequences",
                    "Protective handling, reporting, containment, and authorised simulation status"
                ],
                "out_of_scope": [
                    "Social engineering that does not involve a deceptive communication fitting the adopted phishing boundary",
                    "Malware internals and exploit mechanics beyond their role in the phishing interaction",
                    "General spam classification and unsolicited advertising without evidence of phishing",
                    "Complete fraud, payment recovery, or account compromise investigations",
                    "Threat actor attribution and campaign intelligence beyond evidence linking the modelled attempts",
                    "Design or execution of phishing campaigns and training programmes"
                ],
                "distinguishing_features": [
                    "The interaction contains a misleading identity, authority, relationship, or contextual claim; being unsolicited alone does not establish phishing.",
                    "The recipient is steered toward a security-relevant disclosure or action, possibly through a sequence of apparently harmless preliminary exchanges.",
                    "The deception depends on a recipient interpreting and acting on a communication; a technical compromise requiring no such interaction belongs primarily to another model.",
                    "A convincing display name, familiar branding, or authenticated sending domain does not independently establish that the requested action is legitimate.",
                    "An authorised simulation can reproduce phishing mechanics, so authorisation and harmful intent must be recorded separately from the observed technique."
                ],
                "characteristics": [
                    {
                        "name": "Classification and confidence",
                        "kind": "state",
                        "unit_or_values": "unassessed | suspected phishing | confirmed phishing | legitimate | unresolved; confidence with stated basis",
                        "why_it_matters": "Separates observations from conclusions and supports revising mistaken classifications."
                    },
                    {
                        "name": "Operational phishing boundary",
                        "kind": "category",
                        "unit_or_values": "Named definition and version; included channels, objectives, and exclusions",
                        "why_it_matters": "Makes clear which meaning of phishing governs inclusion and comparison."
                    },
                    {
                        "name": "Communication channel",
                        "kind": "category",
                        "unit_or_values": "email | SMS | voice | messaging platform | social platform | web interaction | other; multiple allowed",
                        "why_it_matters": "Determines what evidence is available and which protective actions apply."
                    },
                    {
                        "name": "Claimed and verified identity",
                        "kind": "relation",
                        "unit_or_values": "Claimed sender or authority linked to independently verified identity, if known",
                        "why_it_matters": "Exposes the trust relationship being asserted without assuming that apparent identity is authentic."
                    },
                    {
                        "name": "Requested recipient action",
                        "kind": "category",
                        "unit_or_values": "disclose information | enter credentials | approve authentication | grant application access | transfer value | open or execute content | continue interaction | other",
                        "why_it_matters": "Connects the deceptive request to the security boundary it could cross."
                    },
                    {
                        "name": "Targeting basis",
                        "kind": "category",
                        "unit_or_values": "broad distribution | role-targeted | individually tailored | unknown; supporting observations",
                        "why_it_matters": "Distinguishes observed personalisation from assumptions about attacker knowledge."
                    },
                    {
                        "name": "Recipient interaction stage",
                        "kind": "state",
                        "unit_or_values": "delivery unknown | delivered | viewed | replied | followed destination | submitted information | approved request | performed requested action; timestamps where available",
                        "why_it_matters": "Supports response decisions without treating every interaction as successful compromise."
                    },
                    {
                        "name": "Observed consequence",
                        "kind": "state",
                        "unit_or_values": "unknown | no consequence observed | information disclosed | access granted | unauthorised access observed | value transferred | code execution observed; multiple allowed",
                        "why_it_matters": "Keeps inferred risk distinct from verified effects."
                    },
                    {
                        "name": "Response latency",
                        "kind": "measurement",
                        "unit_or_values": "Minutes between explicitly identified events, such as report and quarantine",
                        "why_it_matters": "Supports evaluation of response speed while preserving uncertainty in event times."
                    },
                    {
                        "name": "Simulation authorisation",
                        "kind": "state",
                        "unit_or_values": "unknown | verified authorised simulation | outside verified simulation scope",
                        "why_it_matters": "Prevents technique alone from being treated as proof of malicious intent."
                    }
                ],
                "affordances": [
                    "Assess a suspected attempt against an explicit phishing definition and explain the supporting and conflicting evidence.",
                    "Extract claimed identities, requested actions, destinations, and relevant timestamps while preserving original evidence.",
                    "Link related communications into a candidate interaction sequence without assuming common authorship.",
                    "Recommend or perform authorised quarantine, blocking, reporting, and independent sender verification.",
                    "Route observed disclosure, access approval, payment, or execution to the appropriate containment workflow.",
                    "Revise classifications and response priorities as recipient reports and technical evidence arrive."
                ]
            },
            "sources": [],
            "structure": {
                "bundles": [
                    {
                        "id": "phishing-boundary-and-evidence",
                        "name": "Phishing boundary and evidence",
                        "description": "Establishes which sense of phishing applies and whether the available evidence supports it.",
                        "rationale": "A suspicious message, a deceptive request, and a proven compromise are different claims that require separate support.",
                        "layers": [
                            {
                                "id": "operational-definition",
                                "name": "Operational definition",
                                "description": "Records the adopted inclusion tests and neighbouring categories.",
                                "findings": [
                                    {
                                        "id": "deceptive-request-test",
                                        "name": "Deceptive request test",
                                        "description": "Record the misleading claim and the security-relevant action sought, including cases where the request emerges across several exchanges.",
                                        "questions": [
                                            {
                                                "text": "Which operational definition governs whether this interaction counts as phishing?",
                                                "kind": "definition",
                                                "id": "deceptive-request-test-q01"
                                            },
                                            {
                                                "text": "What evidence distinguishes it from legitimate outreach, ordinary spam, or another form of fraud?",
                                                "kind": "boundary",
                                                "id": "deceptive-request-test-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "classification-support",
                                "name": "Classification support",
                                "description": "Separates preserved observations, interpretations, and unresolved alternatives.",
                                "findings": [
                                    {
                                        "id": "evidence-backed-classification",
                                        "name": "Evidence-backed classification",
                                        "description": "Record the basis for the current classification, contrary evidence, and any independently verified simulation authorisation.",
                                        "questions": [
                                            {
                                                "text": "Which original communications, recipient reports, or technical records support the classification?",
                                                "kind": "provenance",
                                                "id": "evidence-backed-classification-q01"
                                            },
                                            {
                                                "text": "What evidence would change the classification, including confirmation of an authorised simulation?",
                                                "kind": "boundary",
                                                "id": "evidence-backed-classification-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "impersonation-and-persuasion",
                        "name": "Impersonation and persuasion",
                        "description": "Captures how the interaction makes a deceptive request appear credible or compelling.",
                        "rationale": "Recognising phishing requires understanding the asserted trust relationship and requested departure from normal practice.",
                        "layers": [
                            {
                                "id": "claimed-trust-relationship",
                                "name": "Claimed trust relationship",
                                "description": "Describes the identity, authority, or existing relationship invoked by the communication.",
                                "findings": [
                                    {
                                        "id": "identity-and-authority-claims",
                                        "name": "Identity and authority claims",
                                        "description": "Record who the sender claims to be, why the recipient might trust that claim, and what independent verification establishes.",
                                        "questions": [
                                            {
                                                "text": "Which person, organisation, service, or trusted conversation does the sender claim to represent?",
                                                "kind": "definition",
                                                "id": "identity-and-authority-claims-q01"
                                            },
                                            {
                                                "text": "How was that claim checked through a trusted route independent of the suspicious communication?",
                                                "kind": "provenance",
                                                "id": "identity-and-authority-claims-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "pretext-and-request",
                                "name": "Pretext and request",
                                "description": "Connects the narrative and pressure cues to the action the recipient is asked to take.",
                                "findings": [
                                    {
                                        "id": "induced-security-action",
                                        "name": "Induced security action",
                                        "description": "Record the requested action, stated justification, and any urgency, secrecy, reward, or threat used to discourage verification.",
                                        "questions": [
                                            {
                                                "text": "What exact action is requested, and which information, access, funds, or execution authority would it affect?",
                                                "kind": "definition",
                                                "id": "induced-security-action-q01"
                                            },
                                            {
                                                "text": "Which observable cues encourage the recipient to bypass or abbreviate normal verification?",
                                                "kind": "boundary",
                                                "id": "induced-security-action-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "delivery-and-interaction-path",
                        "name": "Delivery and interaction path",
                        "description": "Describes how the communication reaches the recipient and where subsequent interactions lead.",
                        "rationale": "The deceptive request may span channels, redirects, attachments, and replies rather than reside in one message.",
                        "layers": [
                            {
                                "id": "message-and-channel",
                                "name": "Message and channel",
                                "description": "Preserves channel-specific evidence and distinguishes apparent origin from verified origin.",
                                "findings": [
                                    {
                                        "id": "delivery-origin-evidence",
                                        "name": "Delivery origin evidence",
                                        "description": "Record the delivery channel, apparent sender, available authentication evidence, and limitations on origin verification.",
                                        "questions": [
                                            {
                                                "text": "Through which channel and apparent account, address, or number did the communication arrive?",
                                                "kind": "provenance",
                                                "id": "delivery-origin-evidence-q01"
                                            },
                                            {
                                                "text": "What does the available authentication evidence establish about origin, and what remains unverified about the request?",
                                                "kind": "boundary",
                                                "id": "delivery-origin-evidence-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "linked-interaction-stages",
                                "name": "Linked interaction stages",
                                "description": "Connects destinations and follow-up exchanges while retaining uncertainty about their relationship.",
                                "findings": [
                                    {
                                        "id": "recipient-action-path",
                                        "name": "Recipient action path",
                                        "description": "Record observed links, QR destinations, attachments, reply routes, and channel changes as parts of a possible interaction sequence.",
                                        "questions": [
                                            {
                                                "text": "Which destinations or follow-up exchanges are evidenced, and how was each connection established?",
                                                "kind": "provenance",
                                                "id": "recipient-action-path-q01"
                                            },
                                            {
                                                "text": "How can relevant destinations or attachments be assessed without exposing the recipient or submitting sensitive information?",
                                                "kind": "action",
                                                "id": "recipient-action-path-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "exposure-and-consequences",
                        "name": "Exposure and consequences",
                        "description": "Separates receipt, recipient actions, and verified effects on information, access, funds, or devices.",
                        "rationale": "Response must follow what actually happened; delivery or a click alone does not establish the full outcome.",
                        "layers": [
                            {
                                "id": "recipient-exposure",
                                "name": "Recipient exposure",
                                "description": "Records who encountered the attempt and which interactions are supported by evidence.",
                                "findings": [
                                    {
                                        "id": "observed-recipient-interaction",
                                        "name": "Observed recipient interaction",
                                        "description": "Distinguish delivery, viewing, replying, destination visits, submissions, and approvals, including gaps in observation.",
                                        "questions": [
                                            {
                                                "text": "Which recipient interactions are directly observed, self-reported, or inferred, and when did they occur?",
                                                "kind": "measurement",
                                                "id": "observed-recipient-interaction-q01"
                                            },
                                            {
                                                "text": "Could automated scanning or incomplete telemetry explain an apparent recipient interaction?",
                                                "kind": "boundary",
                                                "id": "observed-recipient-interaction-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "security-effects",
                                "name": "Security effects",
                                "description": "Records consequences independently from attacker requests and recipient interaction stages.",
                                "findings": [
                                    {
                                        "id": "verified-effect-and-uncertainty",
                                        "name": "Verified effect and uncertainty",
                                        "description": "Record evidence of disclosure, access approval, unauthorised access, transfer, or execution without treating missing evidence as proof of safety.",
                                        "questions": [
                                            {
                                                "text": "What evidence establishes an actual disclosure, access change, transfer, or execution rather than an attempted inducement?",
                                                "kind": "provenance",
                                                "id": "verified-effect-and-uncertainty-q01"
                                            },
                                            {
                                                "text": "Which potentially affected accounts, information, funds, or devices remain unassessed?",
                                                "kind": "measurement",
                                                "id": "verified-effect-and-uncertainty-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "protective-response-and-resolution",
                        "name": "Protective response and resolution",
                        "description": "Connects the evidence and observed exposure to authorised protective actions and closure criteria.",
                        "rationale": "A useful phishing model must guide intervention while preserving evidence and allowing mistaken classifications to be corrected.",
                        "layers": [
                            {
                                "id": "containment-and-routing",
                                "name": "Containment and routing",
                                "description": "Selects protective actions appropriate to the channel, observed interaction, and agent authority.",
                                "findings": [
                                    {
                                        "id": "exposure-matched-response",
                                        "name": "Exposure-matched response",
                                        "description": "Record immediate handling decisions and route disclosed credentials, approved access, transfers, or execution to responsible responders.",
                                        "questions": [
                                            {
                                                "text": "Which quarantine, blocking, reporting, or independent verification actions are warranted and within the agent's authority?",
                                                "kind": "action",
                                                "id": "exposure-matched-response-q01"
                                            },
                                            {
                                                "text": "Which observed consequences require account, payment, device, or information incident response?",
                                                "kind": "action",
                                                "id": "exposure-matched-response-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "resolution-and-correction",
                                "name": "Resolution and correction",
                                "description": "Defines when handling is complete and how later evidence can reopen or correct the case.",
                                "findings": [
                                    {
                                        "id": "closure-with-residual-uncertainty",
                                        "name": "Closure with residual uncertainty",
                                        "description": "Record completed protections, retained evidence, unresolved exposure, and reasons for closure or reclassification.",
                                        "questions": [
                                            {
                                                "text": "What evidence demonstrates that the required protective actions were completed?",
                                                "kind": "measurement",
                                                "id": "closure-with-residual-uncertainty-q01"
                                            },
                                            {
                                                "text": "What new evidence should reopen the case or trigger reversal of an incorrect quarantine or block?",
                                                "kind": "action",
                                                "id": "closure-with-residual-uncertainty-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "evidence-and-external-alignment",
                        "name": "Evidence and external alignment",
                        "description": "What the world already says about this thing, gathered so the model can be checked against it.",
                        "rationale": "A model that cannot be lined up against existing standards, identifiers and practice cannot be adopted by anyone who already uses them.",
                        "layers": [
                            {
                                "id": "reported-evidence",
                                "name": "Reported evidence",
                                "description": "Findings from the breadth pass, kept separate from the structural claims.",
                                "findings": [
                                    {
                                        "id": "evidence-confidence-notes",
                                        "name": "Check these first",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "This describes the cybersecurity activity; no separate registry sense was supplied.",
                                            "Definitions differ on whether voice and SMS attacks are phishing or neighbouring forms of social engineering; the definition here uses the broader convention.",
                                            "The listed kinds overlap across targeting and delivery method. Identifier scope should be checked against the relevant ATT&CK release; no sources were consulted."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-confidence-notes-q01",
                                                "text": "Which of these check these first hold for the sense of phishing this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-kinds",
                                        "name": "Kinds and varieties",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Spear phishing: tailored to a particular person or organisation",
                                            "Whaling: targeting senior executives or other high-value individuals",
                                            "Email phishing: delivered through email",
                                            "Smishing: delivered through SMS or similar text messaging",
                                            "Vishing: conducted through voice communications",
                                            "QR-code phishing: using a QR code to direct recipients to a deceptive destination"
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-kinds-q01",
                                                "text": "Which of these kinds and varieties hold for the sense of phishing this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-identifiers",
                                        "name": "Identifiers and schemes",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "scheme": "MITRE ATT&CK Enterprise technique identifier",
                                                "value_or_pattern": "T1566",
                                                "note": "Identifies the Phishing technique within ATT&CK's initial-access taxonomy; it does not encompass every use of the term phishing."
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-identifiers-q01",
                                                "text": "Which of these identifiers and schemes hold for the sense of phishing this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-real-world-use",
                                        "name": "Real-world use",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Stealing credentials or other sensitive information",
                                            "Inducing fraudulent payments or changes to payment instructions",
                                            "Delivering malicious attachments or directing recipients to malicious sites",
                                            "Obtaining access to organisational systems as an initial step in an intrusion",
                                            "Conducting authorised simulations to evaluate awareness and reporting behaviour"
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-real-world-use-q01",
                                                "text": "Which of these real-world use hold for the sense of phishing this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-measurements",
                                        "name": "Typical measurements",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "quantity": "Interaction rate in an authorised phishing simulation",
                                                "typical_range": "No universal typical range; depends on the lure, audience, delivery and definition of interaction.",
                                                "unit": "percent of delivered simulation messages or targeted recipients, with denominator specified"
                                            },
                                            {
                                                "quantity": "Reporting rate",
                                                "typical_range": "No universal typical range; depends on reporting facilities, exposure and observation period.",
                                                "unit": "percent of exposed recipients who report the message"
                                            },
                                            {
                                                "quantity": "Time to first report",
                                                "typical_range": "Context-dependent; cases with no report must be recorded separately.",
                                                "unit": "minutes or hours"
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-measurements-q01",
                                                "text": "Which of these typical measurements hold for the sense of phishing this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-failure-modes-and-hazards",
                                        "name": "Failure modes and hazards",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Credential theft can lead to account takeover and further impersonation.",
                                            "Recipients may disclose sensitive information or authorise fraudulent transfers.",
                                            "Malicious links and attachments can enable malware execution or system compromise.",
                                            "Real-time phishing can capture some one-time authentication codes or induce approval of fraudulent login requests.",
                                            "Simulation click rates can misrepresent risk when automated link scanning, message difficulty or recipient exposure are not accounted for."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-failure-modes-and-hazards-q01",
                                                "text": "Which of these failure modes and hazards hold for the sense of phishing this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-regional-variation",
                                        "name": "Regional variation",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Lures adapt to local languages, institutions, payment practices and public events.",
                                            "Delivery channels vary with local adoption of email, SMS, voice and messaging platforms."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-regional-variation-q01",
                                                "text": "Which of these regional variation hold for the sense of phishing this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-neighbours",
                                        "name": "Neighbouring kinds and how to tell them apart",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "name": "Social engineering",
                                                "difference": "The broader category includes interpersonal manipulation without a deceptive electronic message or call; phishing is a communication-mediated subset."
                                            },
                                            {
                                                "name": "Spam",
                                                "difference": "Spam is defined principally by unsolicited messaging; a message is phishing when it uses deception to induce a security-compromising action."
                                            },
                                            {
                                                "name": "Spoofing",
                                                "difference": "Spoofing falsifies an apparent identity or origin; phishing may use spoofing but also requires a deceptive inducement directed at a recipient."
                                            },
                                            {
                                                "name": "Business email compromise",
                                                "difference": "Business email compromise concerns fraud involving business communications or accounts; phishing can enable or constitute part of it, but neither category contains every instance of the other."
                                            },
                                            {
                                                "name": "Pharming",
                                                "difference": "Pharming redirects users to fraudulent destinations through technical manipulation, such as altered name resolution, without necessarily persuading them through a deceptive message."
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-neighbours-q01",
                                                "text": "Which of these neighbouring kinds and how to tell them apart hold for the sense of phishing this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "openQuestions": [
                "Which authoritative operational definition should govern this registry entry, particularly for voice phishing, payment diversion, and consent-based access deception?",
                "Should authorised simulations be instances of phishing with a distinct authorisation state, or related activities outside the entry's extension?",
                "What evidence threshold should distinguish suspected from confirmed phishing when sender compromise or deceptive intent cannot be independently established?",
                "Where should one phishing act end and a multi-message interaction or campaign begin, especially when the request develops across channels?",
                "Which privacy-preserving evidence and retention practices are sufficient to support classification, correction, and incident handoff?"
            ],
            "statistics": {
                "bundles": 6,
                "layers": 11,
                "findings": 18,
                "questions": 28
            }
        },
        "draft": {
            "generator": "vr.draft.v3",
            "status": "draft-generated",
            "researched": false,
            "archetype": "abstract concept",
            "method": "Written from the archetype playbook - what this kind of thing needs beyond identity and provenance - and from the structure that recurred across 6,333 models already researched by two engines. Applied to this entry by rule. No source was read for this thing and no claim here is researched. This entry carries no facets of its own, so they were inferred from its domain - a guess about a whole domain applied to one thing.",
            "facetsInferred": true,
            "nextPass": "A researcher replaces this draft with a sourced specification. Treat every sentence below as a proposal to argue with.",
            "purpose": "Give an agent a durable, checkable way to recognise a phishing, record what state it is in, and decide what may be done with it.",
            "whatItIs": "Enable an AI agent to recognise suspected phishing, record the evidence and uncertainty, assess exposure and consequences, and choose proportionate protective actions.",
            "characteristics": {
                "substance": "activity",
                "origin": "conceptual",
                "agency": "inert"
            },
            "whatYouCanDoWithIt": [
                "observed and measured"
            ],
            "distinguishingFeatures": [
                "Names folded into this entry, which a task may need to split apart again: CEO fraud, quishing, Drive-by Pharming, DeepPhish, spear phishing.",
                "5 finer distinctions are held as aliases rather than separate entries, because telling them apart needs a task that asks for it.",
                "Described in 82 Wikipedia languages, which is a measure of how widely the thing is known, not of how important it is."
            ],
            "openQuestionsForResearch": [
                "Which of the bundles below does a real task actually need, and which are ceremony?",
                "What does this thing have that the facets do not capture at all?",
                "Which neighbouring kind is most often confused with a phishing, and on what evidence are they told apart?"
            ],
            "whatItIsMadeOf": "something that happens over time",
            "physicalCharacter": [
                "Does nothing on its own; everything it does, something else did to it.",
                "These come from the domain this entry sits in rather than from the entry itself, so treat them as a first guess about the whole domain applied to one thing."
            ],
            "whatCanBeDoneWithIt": [
                "observe it, measure it, record its state"
            ],
            "howItIsRecognised": [
                "Nothing to see. What is recognised is an instance of it, and which instances count is exactly what is argued about."
            ],
            "relatedModels": [
                {
                    "relation": "covers",
                    "note": "Finer kinds folded into this entry because telling them apart needs a task that asks for it. Each is a model waiting to be split out when one does.",
                    "targets": [
                        "CEO fraud",
                        "quishing",
                        "Drive-by Pharming",
                        "DeepPhish",
                        "spear phishing"
                    ]
                }
            ],
            "standing": "Described in 82 Wikipedia languages, which measures how widely it is written about rather than how important or how common it is. 5 finer distinctions are held inside this entry as names rather than as separate models.",
            "structure": {
                "bundles": [
                    {
                        "id": "identity-and-classification",
                        "name": "Identity, naming and classification",
                        "description": "How an agent tells one phishing from another, and a phishing from things that resemble it.",
                        "rationale": "Recognition comes before every other claim. Without stable identity nothing else in the model can be trusted to be about the same thing twice.",
                        "layers": [
                            {
                                "id": "naming-and-identifiers",
                                "name": "Names and identifiers",
                                "description": "The names this thing goes by and the identifiers that survive translation and time.",
                                "findings": [
                                    {
                                        "id": "preferred-name-and-aliases",
                                        "name": "Preferred name, aliases and local names",
                                        "description": "Which name to use, which names mean the same thing, and which merely sound similar.",
                                        "questions": [
                                            {
                                                "id": "preferred-name-and-aliases-q01",
                                                "text": "What identifies and describes the name of a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q02",
                                                "text": "Who or what asserted this about the name of a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q03",
                                                "text": "What may an agent decide or do once the name of a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "stable-identifiers",
                                        "name": "Stable identifiers and external keys",
                                        "description": "Identifiers that keep pointing at this kind of thing across systems and languages.",
                                        "questions": [
                                            {
                                                "id": "stable-identifiers-q01",
                                                "text": "What identifies and describes an identifier for a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q02",
                                                "text": "Who or what asserted this about an identifier for a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q03",
                                                "text": "What may an agent decide or do once an identifier for a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "classification-and-granularity",
                                "name": "Classification and granularity",
                                "description": "Where a phishing sits among kinds, and how finely a task needs to cut it.",
                                "findings": [
                                    {
                                        "id": "kind-and-parents",
                                        "name": "Kind, parents and neighbouring kinds",
                                        "description": "The classes this thing belongs to and the ones it is next to.",
                                        "questions": [
                                            {
                                                "id": "kind-and-parents-q01",
                                                "text": "What identifies and describes the kind of a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q02",
                                                "text": "Who or what asserted this about the kind of a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q03",
                                                "text": "What may an agent decide or do once the kind of a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "distinguishing-features",
                                        "name": "Distinguishing features",
                                        "description": "What separates a phishing from the things most often confused with it.",
                                        "questions": [
                                            {
                                                "id": "distinguishing-features-q01",
                                                "text": "What identifies and describes what distinguishes a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q02",
                                                "text": "Who or what asserted this about what distinguishes a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q03",
                                                "text": "What may an agent decide or do once what distinguishes a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "state-and-lifecycle",
                        "name": "State and lifecycle",
                        "description": "The states a phishing passes through and the events that move it between them.",
                        "rationale": "Most decisions about a thing depend on what state it is in now, which is a claim with a time on it, not a property.",
                        "layers": [
                            {
                                "id": "lifecycle-stages",
                                "name": "Lifecycle stages",
                                "description": "From coming into existence to ceasing to be one of these.",
                                "findings": [
                                    {
                                        "id": "stages-and-transitions",
                                        "name": "Stages and transitions",
                                        "description": "The stages worth naming and what moves a phishing between them.",
                                        "questions": [
                                            {
                                                "id": "stages-and-transitions-q01",
                                                "text": "What identifies and describes the lifecycle of a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q02",
                                                "text": "Who or what asserted this about the lifecycle of a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q03",
                                                "text": "What may an agent decide or do once the lifecycle of a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "observations-and-status",
                                "name": "Observations and current status",
                                "description": "What is observed about a phishing, how often and by whom.",
                                "findings": [
                                    {
                                        "id": "observation-record",
                                        "name": "Observation record",
                                        "description": "How an observation of a phishing is recorded so that it can be superseded rather than overwritten.",
                                        "questions": [
                                            {
                                                "id": "observation-record-q01",
                                                "text": "What identifies and describes an observation of a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q02",
                                                "text": "Who or what asserted this about an observation of a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q03",
                                                "text": "What may an agent decide or do once an observation of a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "process-and-outcome",
                        "name": "Process, inputs and outcome",
                        "description": "How a phishing proceeds, what it needs and what it leaves behind.",
                        "rationale": "An activity is known by its steps and its results, and both have to be recordable while it is still running.",
                        "layers": [
                            {
                                "id": "steps-and-sequence",
                                "name": "Steps and sequence",
                                "description": "The steps of a phishing, their order and what may run in parallel.",
                                "findings": [
                                    {
                                        "id": "steps-and-preconditions",
                                        "name": "Steps, preconditions and completion",
                                        "description": "What has to be true before each step of a phishing and what marks it done.",
                                        "questions": [
                                            {
                                                "id": "steps-and-preconditions-q01",
                                                "text": "What identifies and describes a step of a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "steps-and-preconditions-q02",
                                                "text": "Who or what asserted this about a step of a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "steps-and-preconditions-q03",
                                                "text": "What may an agent decide or do once a step of a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "inputs-and-results",
                                "name": "Inputs, resources and results",
                                "description": "What a phishing consumes and what it produces.",
                                "findings": [
                                    {
                                        "id": "inputs-and-outputs",
                                        "name": "Inputs, outputs and side effects",
                                        "description": "The resources a phishing takes and the results it leaves, wanted or not.",
                                        "questions": [
                                            {
                                                "id": "inputs-and-outputs-q01",
                                                "text": "What identifies and describes the inputs and results of a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "inputs-and-outputs-q02",
                                                "text": "Who or what asserted this about the inputs and results of a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "inputs-and-outputs-q03",
                                                "text": "What may an agent decide or do once the inputs and results of a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "definitions-in-contest",
                        "name": "Definitions and who holds them",
                        "description": "What phishing is taken to mean, and by whom.",
                        "rationale": "When a field disagrees about a concept, the disagreement is the content. A model that picks one definition silently destroys the information.",
                        "layers": [
                            {
                                "id": "competing-definitions",
                                "name": "Competing definitions",
                                "description": "The main readings and the traditions behind them.",
                                "findings": [
                                    {
                                        "id": "definition-map",
                                        "name": "Definitions and their holders",
                                        "description": "Each definition with the school or body that holds it.",
                                        "questions": [
                                            {
                                                "id": "definition-map-q01",
                                                "text": "Which definitions of phishing are in use, and which tradition or body holds each?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "definition-map-q02",
                                                "text": "What turns on the difference between them in practice?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "operationalisation",
                                "name": "Operationalisation",
                                "description": "How it is measured or applied when it has to be.",
                                "findings": [
                                    {
                                        "id": "operational-record",
                                        "name": "Measures and proxies",
                                        "description": "Instruments and indicators used to stand in for it.",
                                        "questions": [
                                            {
                                                "id": "operational-record-q01",
                                                "text": "How is phishing operationalised or measured in practice, and by what instrument?",
                                                "kind": "measurement"
                                            },
                                            {
                                                "id": "operational-record-q02",
                                                "text": "What does that operationalisation leave out, and when does that matter?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "instances-and-use",
                        "name": "Instances, use and consequence",
                        "description": "What counts as an instance of phishing and what follows from calling something that.",
                        "rationale": "Applying a concept is an act with consequences, so a model must say what the label licenses and what it does not.",
                        "layers": [
                            {
                                "id": "instances",
                                "name": "What counts as an instance",
                                "description": "Clear cases, borderline cases and non-cases.",
                                "findings": [
                                    {
                                        "id": "instance-tests",
                                        "name": "Tests for an instance",
                                        "description": "What would settle whether something falls under it.",
                                        "questions": [
                                            {
                                                "id": "instance-tests-q01",
                                                "text": "What would settle whether something is an instance of phishing?",
                                                "kind": "boundary"
                                            },
                                            {
                                                "id": "instance-tests-q02",
                                                "text": "Which borderline cases are argued about, and on what grounds?",
                                                "kind": "definition"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "consequence",
                                "name": "Consequence of application",
                                "description": "Rights, duties or decisions that follow from the label.",
                                "findings": [
                                    {
                                        "id": "consequence-record",
                                        "name": "What the label licenses",
                                        "description": "What an agent may do once something is classified this way.",
                                        "questions": [
                                            {
                                                "id": "consequence-record-q01",
                                                "text": "What follows practically once something is treated as phishing?",
                                                "kind": "action"
                                            },
                                            {
                                                "id": "consequence-record-q02",
                                                "text": "What must an agent not infer from the label alone?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "provenance-and-evidence",
                        "name": "Provenance, evidence and time",
                        "description": "Where every claim about a phishing came from and when it held.",
                        "rationale": "A claim without a source and a time cannot be superseded, only overwritten, and an agent that overwrites loses the ability to explain itself.",
                        "layers": [
                            {
                                "id": "source-and-authority",
                                "name": "Source and authority",
                                "description": "Who said it, on what evidence, and how strongly.",
                                "findings": [
                                    {
                                        "id": "claim-provenance",
                                        "name": "Claim provenance and confidence",
                                        "description": "The authority behind each claim about a phishing and how confident it is.",
                                        "questions": [
                                            {
                                                "id": "claim-provenance-q01",
                                                "text": "What identifies and describes a claim about a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q02",
                                                "text": "Who or what asserted this about a claim about a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q03",
                                                "text": "What may an agent decide or do once a claim about a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "time-and-versions",
                                "name": "Time, versions and supersession",
                                "description": "When a claim was true, when it was learnt, and what replaced it.",
                                "findings": [
                                    {
                                        "id": "validity-and-supersession",
                                        "name": "Validity period and supersession",
                                        "description": "How an old claim about a phishing is retired without being erased.",
                                        "questions": [
                                            {
                                                "id": "validity-and-supersession-q01",
                                                "text": "What identifies and describes the validity of a claim about a phishing, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q02",
                                                "text": "Who or what asserted this about the validity of a claim about a phishing, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q03",
                                                "text": "What may an agent decide or do once the validity of a claim about a phishing is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "statistics": {
                "bundles": 6,
                "layers": 12,
                "findings": 14,
                "questions": 38
            }
        }
    }
}