{
    "model": {
        "rank": 3656,
        "code": "thing-q1487",
        "model_id": "vr.tr.hacker",
        "name": "hacker",
        "purpose": "Let an agent explain the meanings of hacker and hacker culture, describe categories by intent and authorisation, describe legal frameworks and ethical security research, present attributed accounts of state and criminal actors neutrally, and decline operational attack detail.",
        "family": "Thing Registry",
        "category": "Society, people and institutions",
        "status": "research-draft",
        "kind": "thing",
        "plane": "SOC",
        "domain": "SOC.PER",
        "industry": "",
        "version": "",
        "url": "/models/thing/q1487/",
        "tier": 2,
        "score": 83,
        "payload": {
            "layer": "wikidata",
            "aliases": [
                "black hat",
                "hacktivist",
                "Russian hackers",
                "grey hat",
                "cyber soldier",
                "security hacker",
                "bot herder",
                "penetration tester",
                "Initial access broker",
                "script kiddie"
            ],
            "aliasCount": 10,
            "merged": 11,
            "knownIn": 83,
            "facets": null,
            "markers": [],
            "lexicalClass": "",
            "senseRank": null,
            "alsoRegisteredAs": null,
            "source": {
                "dataset": "wikidata",
                "item": "Q1487",
                "url": "https://www.wikidata.org/wiki/Q1487",
                "license": "CC0 1.0"
            }
        },
        "research": {
            "vercy": "1.0-draft",
            "publication": {
                "status": "research-draft",
                "adjudicationStatus": "unreviewed",
                "publishableCanonical": false,
                "generatedAt": "2026-09-12T05:34:49Z",
                "providers": [
                    "Claude"
                ],
                "breadth": "written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify",
                "pass": 2,
                "wave": 2,
                "engine": "claude"
            },
            "metaModel": {
                "id": "THING-Q1487",
                "registryId": "vr.tr.hacker",
                "name": "hacker",
                "version": "0.2.0-wave.2",
                "entryKind": "thing",
                "family": "Thing Registry",
                "domain": [
                    "SOC.PER"
                ],
                "status": "research-draft"
            },
            "canonicalUrl": "https://ver.cy/models/thing/q1487/",
            "model": {
                "registry_id": "vr.tr.hacker",
                "name": "hacker",
                "purpose": "Let an agent explain the meanings of hacker and hacker culture, describe categories by intent and authorisation, describe legal frameworks and ethical security research, present attributed accounts of state and criminal actors neutrally, and decline operational attack detail.",
                "definition": "A person skilled in computing who explores and manipulates systems, in the original sense a creative programmer and enthusiast, and in the security sense a person who finds and exploits weaknesses in computer systems, categorised by intent and authorisation as white hat security researchers working with permission, black hat criminals, and grey hat actors in between, with related terms such as hacktivist and state-affiliated actors; the term is contested between communities and is described here at the level of culture, law and defensive security without operational attack detail.",
                "what_it_is_for": "Skilled computer explorers and security actors.",
                "affordances": [
                    "explain meanings and culture",
                    "describe categories",
                    "describe law and ethical research",
                    "decline operational detail"
                ],
                "distinguishing_features": [
                    "Skill and curiosity",
                    "Intent and authorisation",
                    "Contested term",
                    "Community culture"
                ],
                "appearance": "Not physical; a role and identity.",
                "visual_identification": [
                    "Skilled computer explorer or security actor",
                    "White hat, black hat, grey hat, hacktivist",
                    "A cracker is a term for criminal intrusion; a computer scientist is an academic; a script kiddie lacks skill"
                ],
                "physical_properties": [],
                "families_and_kinds": [
                    "hackers in the programming culture sense",
                    "white hat security researchers",
                    "black hat criminals",
                    "grey hat and hacktivist actors",
                    "state-affiliated actors as described in public reports"
                ],
                "related_models": [
                    {
                        "relation": "is a kind of",
                        "target": "computer scientist",
                        "why": "category"
                    },
                    {
                        "relation": "is related to",
                        "target": "cyberattack",
                        "why": "attacks by malicious actors"
                    },
                    {
                        "relation": "is related to",
                        "target": "error",
                        "why": "software errors exploited or found"
                    },
                    {
                        "relation": "is related to",
                        "target": "free software",
                        "why": "hacker culture and open source"
                    }
                ],
                "identifiers": [],
                "standards_and_regulation": [
                    "Computer misuse and cybercrime laws",
                    "Responsible disclosure and bug bounty frameworks",
                    "Professional ethics for security research"
                ],
                "failure_modes_and_hazards": [
                    "Providing operational attack detail, which must be declined",
                    "Conflating all hackers with criminals",
                    "Attributing attacks to nations without sourcing"
                ],
                "in_scope": [],
                "out_of_scope": [],
                "characteristics": []
            },
            "sources": [],
            "structure": {
                "bundles": [
                    {
                        "id": "understand",
                        "name": "Understand",
                        "description": "What a hacker is.",
                        "rationale": "Boundaries.",
                        "layers": [
                            {
                                "id": "concept",
                                "name": "Concept",
                                "description": "Meanings and categories.",
                                "findings": [
                                    {
                                        "id": "concept-finding",
                                        "name": "Concept",
                                        "description": "Concept.",
                                        "questions": [
                                            {
                                                "text": "What does hacker mean in programming culture and in security, and how do white hat, black hat and grey hat differ?",
                                                "kind": "definition"
                                            },
                                            {
                                                "text": "Is the request seeking operational attack detail, which must be declined?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "culture",
                                "name": "Culture",
                                "description": "Hacker culture.",
                                "findings": [
                                    {
                                        "id": "culture-finding",
                                        "name": "Culture",
                                        "description": "Culture.",
                                        "questions": [
                                            {
                                                "text": "What is hacker culture, and how do its ethics and communities describe themselves?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "Which entry fits open source culture?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "law",
                        "name": "Law",
                        "description": "Law and ethics.",
                        "rationale": "Attribution.",
                        "layers": [
                            {
                                "id": "law",
                                "name": "Law",
                                "description": "Legal frameworks.",
                                "findings": [
                                    {
                                        "id": "law-finding",
                                        "name": "Law",
                                        "description": "Law.",
                                        "questions": [
                                            {
                                                "text": "How do computer misuse laws treat unauthorised access, and how is authorised security testing distinguished, in general terms?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "Is legal advice being sought, which needs a professional?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "research",
                                "name": "Research",
                                "description": "Ethical security research.",
                                "findings": [
                                    {
                                        "id": "research-finding",
                                        "name": "Research",
                                        "description": "Research.",
                                        "questions": [
                                            {
                                                "text": "How do responsible disclosure, bug bounties and penetration testing work within authorisation?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "Which entry fits cybersecurity?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "actors",
                        "name": "Actors",
                        "description": "Criminal and state actors.",
                        "rationale": "Attribution.",
                        "layers": [
                            {
                                "id": "criminal",
                                "name": "Criminal",
                                "description": "Cybercrime.",
                                "findings": [
                                    {
                                        "id": "criminal-finding",
                                        "name": "Criminal",
                                        "description": "Criminal.",
                                        "questions": [
                                            {
                                                "text": "How do public reports describe criminal hacking groups and their impact?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "Is the presentation attributed and free of operational detail?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "state",
                                "name": "State",
                                "description": "State-affiliated actors.",
                                "findings": [
                                    {
                                        "id": "state-finding",
                                        "name": "State",
                                        "description": "State.",
                                        "questions": [
                                            {
                                                "text": "How do governments and researchers attribute activity to state-affiliated actors, and how reliable is attribution, with positions attributed?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "Is the presentation neutral?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "learn",
                        "name": "Learn",
                        "description": "History and teaching.",
                        "rationale": "Education.",
                        "layers": [
                            {
                                "id": "history",
                                "name": "History",
                                "description": "History.",
                                "findings": [
                                    {
                                        "id": "history-finding",
                                        "name": "History",
                                        "description": "History.",
                                        "questions": [
                                            {
                                                "text": "How did the term and culture develop from early computing communities to modern security?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "Which references are standard?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "teach",
                                "name": "Teach",
                                "description": "Teaching.",
                                "findings": [
                                    {
                                        "id": "teach-finding",
                                        "name": "Teach",
                                        "description": "Teaching.",
                                        "questions": [
                                            {
                                                "text": "How can hacking history and ethics be taught in cybersecurity education?",
                                                "kind": "action"
                                            },
                                            {
                                                "text": "Which misconceptions arise?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "openQuestions": [
                "Should hacker culture be a separate entry?",
                "How should legal frameworks be linked?",
                "How should security research resources be linked?"
            ],
            "statistics": {
                "bundles": 4,
                "layers": 8,
                "findings": 8,
                "questions": 16
            }
        },
        "draft": {
            "generator": "vr.draft.v3",
            "status": "draft-generated",
            "researched": false,
            "archetype": "occupation or role",
            "method": "Written from the archetype playbook - what this kind of thing needs beyond identity and provenance - and from the structure that recurred across 6,333 models already researched by two engines. Applied to this entry by rule. No source was read for this thing and no claim here is researched. This entry carries no facets of its own, so they were inferred from its domain - a guess about a whole domain applied to one thing.",
            "facetsInferred": true,
            "nextPass": "A researcher replaces this draft with a sourced specification. Treat every sentence below as a proposal to argue with.",
            "purpose": "Give an agent a durable, checkable way to recognise a hacker, record what state it is in, and decide what may be done with it.",
            "whatItIs": "Let an agent explain the meanings of hacker and hacker culture, describe categories by intent and authorisation, describe legal frameworks and ethical security research, present attributed accounts of state and criminal actors neutrally, and decline operational attack detail.",
            "characteristics": {
                "substance": "social",
                "origin": "natural",
                "agency": "autonomous",
                "mobility": "self-moving"
            },
            "whatYouCanDoWithIt": [
                "observed and measured"
            ],
            "distinguishingFeatures": [
                "Names folded into this entry, which a task may need to split apart again: black hat, hacktivist, Russian hackers, grey hat, cyber soldier, security hacker, bot herder, penetration tester, Initial access broker, script kiddie.",
                "11 finer distinctions are held as aliases rather than separate entries, because telling them apart needs a task that asks for it.",
                "Described in 83 Wikipedia languages, which is a measure of how widely the thing is known, not of how important it is."
            ],
            "openQuestionsForResearch": [
                "Which of the bundles below does a real task actually need, and which are ceremony?",
                "What does this thing have that the facets do not capture at all?",
                "Which neighbouring kind is most often confused with a hacker, and on what evidence are they told apart?"
            ],
            "whatItIsMadeOf": "a social arrangement between people",
            "physicalCharacter": [
                "Moves under its own power or of its own accord.",
                "Acts on its own behalf.",
                "These come from the domain this entry sits in rather than from the entry itself, so treat them as a first guess about the whole domain applied to one thing."
            ],
            "whatCanBeDoneWithIt": [
                "observe it, measure it, record its state"
            ],
            "howItIsRecognised": [
                "Not recognisable by appearance, and guessing from dress or setting is how an agent gets this wrong. Recognised by qualification, licence or engagement."
            ],
            "relatedModels": [
                {
                    "relation": "covers",
                    "note": "Finer kinds folded into this entry because telling them apart needs a task that asks for it. Each is a model waiting to be split out when one does.",
                    "targets": [
                        "black hat",
                        "hacktivist",
                        "Russian hackers",
                        "grey hat",
                        "cyber soldier",
                        "security hacker",
                        "bot herder",
                        "penetration tester",
                        "Initial access broker",
                        "script kiddie"
                    ]
                }
            ],
            "standing": "Described in 83 Wikipedia languages, which measures how widely it is written about rather than how important or how common it is. 11 finer distinctions are held inside this entry as names rather than as separate models.",
            "structure": {
                "bundles": [
                    {
                        "id": "identity-and-classification",
                        "name": "Identity, naming and classification",
                        "description": "How an agent tells one hacker from another, and a hacker from things that resemble it.",
                        "rationale": "Recognition comes before every other claim. Without stable identity nothing else in the model can be trusted to be about the same thing twice.",
                        "layers": [
                            {
                                "id": "naming-and-identifiers",
                                "name": "Names and identifiers",
                                "description": "The names this thing goes by and the identifiers that survive translation and time.",
                                "findings": [
                                    {
                                        "id": "preferred-name-and-aliases",
                                        "name": "Preferred name, aliases and local names",
                                        "description": "Which name to use, which names mean the same thing, and which merely sound similar.",
                                        "questions": [
                                            {
                                                "id": "preferred-name-and-aliases-q01",
                                                "text": "What identifies and describes the name of a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q02",
                                                "text": "Who or what asserted this about the name of a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q03",
                                                "text": "What may an agent decide or do once the name of a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "stable-identifiers",
                                        "name": "Stable identifiers and external keys",
                                        "description": "Identifiers that keep pointing at this kind of thing across systems and languages.",
                                        "questions": [
                                            {
                                                "id": "stable-identifiers-q01",
                                                "text": "What identifies and describes an identifier for a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q02",
                                                "text": "Who or what asserted this about an identifier for a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q03",
                                                "text": "What may an agent decide or do once an identifier for a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "classification-and-granularity",
                                "name": "Classification and granularity",
                                "description": "Where a hacker sits among kinds, and how finely a task needs to cut it.",
                                "findings": [
                                    {
                                        "id": "kind-and-parents",
                                        "name": "Kind, parents and neighbouring kinds",
                                        "description": "The classes this thing belongs to and the ones it is next to.",
                                        "questions": [
                                            {
                                                "id": "kind-and-parents-q01",
                                                "text": "What identifies and describes the kind of a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q02",
                                                "text": "Who or what asserted this about the kind of a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q03",
                                                "text": "What may an agent decide or do once the kind of a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "distinguishing-features",
                                        "name": "Distinguishing features",
                                        "description": "What separates a hacker from the things most often confused with it.",
                                        "questions": [
                                            {
                                                "id": "distinguishing-features-q01",
                                                "text": "What identifies and describes what distinguishes a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q02",
                                                "text": "Who or what asserted this about what distinguishes a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q03",
                                                "text": "What may an agent decide or do once what distinguishes a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "place-and-movement",
                        "name": "Place and movement",
                        "description": "Where a hacker is, how it got there and where it may go (self-moving).",
                        "rationale": "A thing that can move needs its position recorded with a time, or every later claim about it is about a place it has left.",
                        "layers": [
                            {
                                "id": "location-and-placement",
                                "name": "Location and placement",
                                "description": "Position, containment and the reference frame the position is given in.",
                                "findings": [
                                    {
                                        "id": "position-and-frame",
                                        "name": "Position, container and reference frame",
                                        "description": "Where a hacker is, and what that position is measured against.",
                                        "questions": [
                                            {
                                                "id": "position-and-frame-q01",
                                                "text": "What identifies and describes the location of a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "position-and-frame-q02",
                                                "text": "Who or what asserted this about the location of a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "position-and-frame-q03",
                                                "text": "What may an agent decide or do once the location of a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "movement-and-transfer",
                                "name": "Movement and transfer",
                                "description": "How a hacker moves on its own.",
                                "findings": [
                                    {
                                        "id": "movement-events",
                                        "name": "Movement events and constraints",
                                        "description": "What counts as a movement, what records it and what limits it.",
                                        "questions": [
                                            {
                                                "id": "movement-events-q01",
                                                "text": "What identifies and describes the movement of a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "movement-events-q02",
                                                "text": "Who or what asserted this about the movement of a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "movement-events-q03",
                                                "text": "What may an agent decide or do once the movement of a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "state-and-lifecycle",
                        "name": "State and lifecycle",
                        "description": "The states a hacker passes through and the events that move it between them.",
                        "rationale": "Most decisions about a thing depend on what state it is in now, which is a claim with a time on it, not a property.",
                        "layers": [
                            {
                                "id": "lifecycle-stages",
                                "name": "Lifecycle stages",
                                "description": "From coming into existence to ceasing to be one of these.",
                                "findings": [
                                    {
                                        "id": "stages-and-transitions",
                                        "name": "Stages and transitions",
                                        "description": "The stages worth naming and what moves a hacker between them.",
                                        "questions": [
                                            {
                                                "id": "stages-and-transitions-q01",
                                                "text": "What identifies and describes the lifecycle of a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q02",
                                                "text": "Who or what asserted this about the lifecycle of a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q03",
                                                "text": "What may an agent decide or do once the lifecycle of a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "observations-and-status",
                                "name": "Observations and current status",
                                "description": "What is observed about a hacker, how often and by whom.",
                                "findings": [
                                    {
                                        "id": "observation-record",
                                        "name": "Observation record",
                                        "description": "How an observation of a hacker is recorded so that it can be superseded rather than overwritten.",
                                        "questions": [
                                            {
                                                "id": "observation-record-q01",
                                                "text": "What identifies and describes an observation of a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q02",
                                                "text": "Who or what asserted this about an observation of a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q03",
                                                "text": "What may an agent decide or do once an observation of a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "people-and-responsibility",
                        "name": "People, roles and responsibility",
                        "description": "Who stands in what relation to a hacker.",
                        "rationale": "Social things are defined by the relations people hold to them, and those relations change without the thing changing.",
                        "layers": [
                            {
                                "id": "roles-and-parties",
                                "name": "Roles and parties",
                                "description": "The roles that exist around a hacker and who fills them.",
                                "findings": [
                                    {
                                        "id": "role-assignments",
                                        "name": "Role assignments and their validity",
                                        "description": "Who holds which role over a hacker, from when, and on whose authority.",
                                        "questions": [
                                            {
                                                "id": "role-assignments-q01",
                                                "text": "What identifies and describes a role over a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "role-assignments-q02",
                                                "text": "Who or what asserted this about a role over a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "role-assignments-q03",
                                                "text": "What may an agent decide or do once a role over a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "ownership-and-accountability",
                                "name": "Ownership and accountability",
                                "description": "Who answers for a hacker and who may decide about it.",
                                "findings": [
                                    {
                                        "id": "accountability",
                                        "name": "Accountability and decision rights",
                                        "description": "Where responsibility for a hacker sits when something goes wrong.",
                                        "questions": [
                                            {
                                                "id": "accountability-q01",
                                                "text": "What identifies and describes responsibility for a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "accountability-q02",
                                                "text": "Who or what asserted this about responsibility for a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "accountability-q03",
                                                "text": "What may an agent decide or do once responsibility for a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "competence-and-licence",
                        "name": "Competence, qualification and licence",
                        "description": "What someone must be able to do, and be permitted to do, as hacker.",
                        "rationale": "The permission is jurisdictional and the competence is not, and conflating them is how an agent concludes someone may practise when they may not.",
                        "layers": [
                            {
                                "id": "competences",
                                "name": "Competences and qualifications",
                                "description": "Skills and credentials the role assumes.",
                                "findings": [
                                    {
                                        "id": "qualification-record",
                                        "name": "Qualifications and how they are evidenced",
                                        "description": "What counts as qualified, and what proves it.",
                                        "questions": [
                                            {
                                                "id": "qualification-record-q01",
                                                "text": "What competences and qualifications does hacker require, and how is each evidenced?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "qualification-record-q02",
                                                "text": "Which qualifications transfer between jurisdictions and which do not?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "licensing",
                                "name": "Licensing and the right to practise",
                                "description": "Who grants permission, where it holds, and when it lapses.",
                                "findings": [
                                    {
                                        "id": "licence-record",
                                        "name": "Licence, issuer and validity",
                                        "description": "The permission, its issuer, its territory and its expiry.",
                                        "questions": [
                                            {
                                                "id": "licence-record-q01",
                                                "text": "Who licenses hacker, in which territory, and for how long?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "id": "licence-record-q02",
                                                "text": "What may an unlicensed person not do, and what must an agent refuse to assume?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "tasks-and-accountability",
                        "name": "Tasks, employment and accountability",
                        "description": "What hacker actually does and who answers for it.",
                        "rationale": "A role is filled by people under an arrangement, and the arrangement decides liability, supervision and who may instruct whom.",
                        "layers": [
                            {
                                "id": "tasks",
                                "name": "Tasks and typical duties",
                                "description": "The work itself, and how it differs by setting.",
                                "findings": [
                                    {
                                        "id": "duty-record",
                                        "name": "Duties and setting",
                                        "description": "What the role does and where the work varies.",
                                        "questions": [
                                            {
                                                "id": "duty-record-q01",
                                                "text": "What tasks define hacker, and how do they differ between settings or seniority?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "duty-record-q02",
                                                "text": "Which tasks may only be done by this role, and which are shared with neighbouring roles?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "accountability",
                                "name": "Employment and accountability",
                                "description": "The relation under which the work is done and where responsibility sits.",
                                "findings": [
                                    {
                                        "id": "responsibility",
                                        "name": "Responsibility and supervision",
                                        "description": "Who instructs, who supervises, who is liable.",
                                        "questions": [
                                            {
                                                "id": "responsibility-q01",
                                                "text": "Under what arrangement does someone act as hacker, and who supervises or is liable?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "responsibility-q02",
                                                "text": "When something goes wrong, what does the model need to have recorded to answer who was responsible?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "provenance-and-evidence",
                        "name": "Provenance, evidence and time",
                        "description": "Where every claim about a hacker came from and when it held.",
                        "rationale": "A claim without a source and a time cannot be superseded, only overwritten, and an agent that overwrites loses the ability to explain itself.",
                        "layers": [
                            {
                                "id": "source-and-authority",
                                "name": "Source and authority",
                                "description": "Who said it, on what evidence, and how strongly.",
                                "findings": [
                                    {
                                        "id": "claim-provenance",
                                        "name": "Claim provenance and confidence",
                                        "description": "The authority behind each claim about a hacker and how confident it is.",
                                        "questions": [
                                            {
                                                "id": "claim-provenance-q01",
                                                "text": "What identifies and describes a claim about a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q02",
                                                "text": "Who or what asserted this about a claim about a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q03",
                                                "text": "What may an agent decide or do once a claim about a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "time-and-versions",
                                "name": "Time, versions and supersession",
                                "description": "When a claim was true, when it was learnt, and what replaced it.",
                                "findings": [
                                    {
                                        "id": "validity-and-supersession",
                                        "name": "Validity period and supersession",
                                        "description": "How an old claim about a hacker is retired without being erased.",
                                        "questions": [
                                            {
                                                "id": "validity-and-supersession-q01",
                                                "text": "What identifies and describes the validity of a claim about a hacker, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q02",
                                                "text": "Who or what asserted this about the validity of a claim about a hacker, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q03",
                                                "text": "What may an agent decide or do once the validity of a claim about a hacker is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "statistics": {
                "bundles": 7,
                "layers": 14,
                "findings": 16,
                "questions": 44
            }
        }
    }
}