{
    "model": {
        "rank": 4057,
        "code": "thing-q170963",
        "model_id": "vr.tr.virtual-private-network",
        "name": "virtual private network",
        "purpose": "Enable an AI agent to recognise a virtual private network, assess the connectivity and protection it actually provides, and determine which connection, routing and access changes are authorised.",
        "family": "Thing Registry",
        "category": "Activities and processes",
        "status": "research-draft",
        "kind": "thing",
        "plane": "ACT",
        "domain": "ACT.ACT",
        "industry": "",
        "version": "",
        "url": "/models/thing/q170963/",
        "tier": 2,
        "score": 79,
        "payload": {
            "layer": "wikidata",
            "aliases": [
                "mobile virtual private network",
                "Nym Mixnet",
                "SSL"
            ],
            "aliasCount": 3,
            "merged": 3,
            "knownIn": 79,
            "facets": null,
            "markers": [],
            "lexicalClass": "",
            "senseRank": null,
            "alsoRegisteredAs": null,
            "source": {
                "dataset": "wikidata",
                "item": "Q170963",
                "url": "https://www.wikidata.org/wiki/Q170963",
                "license": "CC0 1.0"
            }
        },
        "research": {
            "vercy": "1.0-draft",
            "publication": {
                "status": "research-draft",
                "adjudicationStatus": "unreviewed",
                "publishableCanonical": false,
                "generatedAt": "2026-09-09T19:22:43Z",
                "providers": [
                    "Codex"
                ],
                "breadth": "recalled by Codex without web access - no source was read",
                "missingProviders": [],
                "pass": 2,
                "cost": {
                    "grok": {
                        "seconds": 25.5,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.4\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a0879e-6126-77a2-a7b9-6a7d5aac7558\n--------\nuser\nDescribe what is already known about one registered thing. Answer as JSON only, no prose around it.\n\nThing: virtual private network\nSense to describe: (none recorded)\nDomain code: ACT.ACT\nAlso known as: (none)\n\n\nContext for this batch of 695 things:\n# Batch 00",
                        "usd": 0,
                        "recall": true
                    },
                    "codex": {
                        "seconds": 64.6,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.4\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a0879e-6138-7320-a22a-6c99c4f3420c\n--------\nuser\nYou are drafting a Vercy meta-model for one registered thing. Answer as JSON only, no prose around it.\n\nThing: virtual private network\nRegistry id: vr.tr.virtual-private-network\nPlane / domain: ACT / ACT.ACT\nRegistry definition: (none recorded)\nNames folded in"
                    }
                }
            },
            "metaModel": {
                "id": "THING-Q170963",
                "registryId": "vr.tr.virtual-private-network",
                "name": "virtual private network",
                "version": "0.1.0-research.1",
                "entryKind": "thing",
                "family": "Thing Registry",
                "domain": [
                    "ACT.ACT"
                ],
                "status": "research-draft"
            },
            "canonicalUrl": "https://ver.cy/models/thing/q170963/",
            "model": {
                "registry_id": "vr.tr.virtual-private-network",
                "name": "virtual private network",
                "purpose": "Enable an AI agent to recognise a virtual private network, assess the connectivity and protection it actually provides, and determine which connection, routing and access changes are authorised.",
                "definition": "A virtual private network (VPN) is a logical network that provides selected users or sites with private connectivity over shared infrastructure through mechanisms such as tunnelling, traffic isolation and, in cryptographic VPNs, authentication and encryption.",
                "scope_statement": "This model owns the virtual private network sense of vr.tr.virtual-private-network: a logical network that connects selected endpoints or networks across shared infrastructure through defined membership, forwarding and isolation mechanisms, with cryptographic protection where implemented; it covers deployed instances and the competing criteria used to classify them.",
                "in_scope": [
                    "VPN membership, participating endpoints, gateways and connected address spaces",
                    "Remote-access and site-to-site arrangements, including provider-provisioned private networks",
                    "Tunnelling, forwarding separation and any cryptographic protection",
                    "Authentication, authorisation and routes that determine effective reachability",
                    "Connection lifecycle, failure behaviour and evidence of delivered protection"
                ],
                "out_of_scope": [
                    "The general architecture and operation of the underlying Internet or carrier network",
                    "Endpoint operating-system security beyond requirements for VPN participation",
                    "Application security and application-level access controls beyond their interaction with VPN reachability",
                    "Proxy services, Tor and encrypted application sessions that do not establish a private network",
                    "The complete commercial or organisational model of a VPN service provider"
                ],
                "distinguishing_features": [
                    "Identify an explicit logical membership or attachment boundary and forwarding behaviour that connects members across shared infrastructure; a product label alone does not establish that it is a VPN.",
                    "Determine whether the mechanism supplies network connectivity or only relays selected application requests; an application proxy is not automatically a VPN.",
                    "Test traffic separation and cryptographic protection independently: a provider-provisioned VPN may isolate forwarding without encrypting payloads.",
                    "Locate the endpoints of protection and the onward path after termination; reaching a VPN gateway does not establish protection all the way to an application.",
                    "Distinguish private network participation from anonymity: changing the visible egress address does not by itself establish unlinkability or eliminate operator visibility."
                ],
                "characteristics": [
                    {
                        "name": "VPN classification",
                        "kind": "category",
                        "unit_or_values": "Remote access, site to site, provider-provisioned, hybrid, or unresolved; categories may overlap",
                        "why_it_matters": "Determines which participants, attachments and operational responsibilities must be represented."
                    },
                    {
                        "name": "Membership and attachment",
                        "kind": "relation",
                        "unit_or_values": "Users, devices, sites or tenant networks linked to VPN endpoints and admission authorities",
                        "why_it_matters": "Makes the private network boundary explicit."
                    },
                    {
                        "name": "Forwarding and encapsulation mechanism",
                        "kind": "category",
                        "unit_or_values": "Named mechanism and version, forwarding context, and encapsulation where applicable",
                        "why_it_matters": "Supports assessment of interoperability, isolation and configuration constraints."
                    },
                    {
                        "name": "Protection properties",
                        "kind": "state",
                        "unit_or_values": "Isolation, peer authentication, confidentiality, integrity and replay protection, each recorded as evidenced, absent, unknown or not applicable",
                        "why_it_matters": "Prevents the word private from standing in for verified security properties."
                    },
                    {
                        "name": "Effective traffic coverage",
                        "kind": "relation",
                        "unit_or_values": "Source, destination, address family, application and DNS traffic mapped to VPN, direct or blocked paths",
                        "why_it_matters": "Shows which traffic actually receives the intended treatment."
                    },
                    {
                        "name": "Operational connection state",
                        "kind": "state",
                        "unit_or_values": "Disabled, negotiating, established, degraded, failed or disconnecting, with observation time",
                        "why_it_matters": "Separates configured intent from present connectivity."
                    },
                    {
                        "name": "Effective reachability",
                        "kind": "relation",
                        "unit_or_values": "Participant-to-resource paths with routing, filtering and authorisation evidence",
                        "why_it_matters": "A connected VPN does not imply permission or ability to reach every private resource."
                    },
                    {
                        "name": "Path performance",
                        "kind": "measurement",
                        "unit_or_values": "Latency in ms, throughput in Mbit/s, loss in percent and effective MTU in bytes, with test path and time",
                        "why_it_matters": "Determines whether the VPN can support the intended workload."
                    },
                    {
                        "name": "Failure traffic policy",
                        "kind": "category",
                        "unit_or_values": "Block, bypass, reroute or mixed, specified by traffic class",
                        "why_it_matters": "Determines what happens to traffic when a connection or protection mechanism fails."
                    }
                ],
                "affordances": [
                    "Classify a proposed or observed VPN and identify evidence missing from its privacy or security claims.",
                    "Trace whether a specified flow uses the VPN, bypasses it or is blocked.",
                    "Assess whether a participant may join and which resources it should reach.",
                    "Establish, revoke or change a connection within recorded administrative authority.",
                    "Diagnose reachability, DNS, MTU and performance failures using scoped observations.",
                    "Check failure behaviour and verify that an authorised configuration change preserves required traffic protection."
                ]
            },
            "sources": [],
            "structure": {
                "bundles": [
                    {
                        "id": "vpn-identity-and-boundaries",
                        "name": "VPN identity and boundaries",
                        "description": "Establishes what qualifies as this VPN and which entities form its private network.",
                        "rationale": "VPN terminology spans cryptographic tunnels and provider-managed isolation, so recognition requires an explicit interpretation.",
                        "layers": [
                            {
                                "id": "classification-and-instance",
                                "name": "Classification and instance",
                                "description": "Records the definition being applied and the concrete arrangement it describes.",
                                "findings": [
                                    {
                                        "id": "vpn-qualification",
                                        "name": "VPN qualification",
                                        "description": "Record the criteria under which the arrangement counts as a VPN, including whether privacy means forwarding isolation, cryptographic protection or both.",
                                        "questions": [
                                            {
                                                "text": "Which definition and authority classify this arrangement as a VPN, and what observable criteria do they require?",
                                                "kind": "definition",
                                                "id": "vpn-qualification-q01"
                                            },
                                            {
                                                "text": "What distinguishes this instance from an application proxy, a local virtual network or an ordinary encrypted session?",
                                                "kind": "boundary",
                                                "id": "vpn-qualification-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "participants-and-attachments",
                                "name": "Participants and attachments",
                                "description": "Identifies VPN members, connection endpoints and attached networks.",
                                "findings": [
                                    {
                                        "id": "private-network-membership",
                                        "name": "Private network membership",
                                        "description": "Record participating users, devices, sites or tenants and distinguish them from gateways and infrastructure that transport their traffic.",
                                        "questions": [
                                            {
                                                "text": "Which entities are members, which terminate VPN connections, and which only provide transport?",
                                                "kind": "boundary",
                                                "id": "private-network-membership-q01"
                                            },
                                            {
                                                "text": "Which configuration or control-plane evidence establishes each attachment and its owning authority?",
                                                "kind": "provenance",
                                                "id": "private-network-membership-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "isolation-protection-and-trust",
                        "name": "Isolation, protection and trust",
                        "description": "Separates logical traffic isolation from cryptographic guarantees and operator trust.",
                        "rationale": "An agent must assess the mechanisms and endpoints of protection rather than infer them from the VPN label.",
                        "layers": [
                            {
                                "id": "separation-and-cryptography",
                                "name": "Separation and cryptography",
                                "description": "Records how traffic is separated and which security properties are implemented.",
                                "findings": [
                                    {
                                        "id": "evidenced-protection",
                                        "name": "Evidenced protection",
                                        "description": "Record forwarding separation, encapsulation and negotiated cryptographic properties as separate claims with supporting evidence.",
                                        "questions": [
                                            {
                                                "text": "What mechanism prevents traffic from entering another tenant's or participant group's forwarding context?",
                                                "kind": "boundary",
                                                "id": "evidenced-protection-q01"
                                            },
                                            {
                                                "text": "Which peer authentication, encryption, integrity and replay protections are actually active on each protected segment?",
                                                "kind": "measurement",
                                                "id": "evidenced-protection-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "termination-and-observation",
                                "name": "Termination and observation",
                                "description": "Maps where protection ends and what intermediaries can observe.",
                                "findings": [
                                    {
                                        "id": "trust-and-visibility-boundary",
                                        "name": "Trust and visibility boundary",
                                        "description": "Record protection termination points, operator control and visibility into payloads or metadata, accounting for separate application encryption.",
                                        "questions": [
                                            {
                                                "text": "Where does each VPN protection terminate, and which onward segments rely on different protection?",
                                                "kind": "boundary",
                                                "id": "trust-and-visibility-boundary-q01"
                                            },
                                            {
                                                "text": "What evidence supports claims about operator visibility, logging and retention, and what remains unverified?",
                                                "kind": "provenance",
                                                "id": "trust-and-visibility-boundary-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "traffic-selection-and-reachability",
                        "name": "Traffic selection and reachability",
                        "description": "Determines which traffic traverses the VPN and which destinations become reachable.",
                        "rationale": "Tunnel establishment alone cannot establish coverage, prevent bypass or explain access failures.",
                        "layers": [
                            {
                                "id": "routes-and-traffic-selection",
                                "name": "Routes and traffic selection",
                                "description": "Captures effective routing and selection across traffic classes and address families.",
                                "findings": [
                                    {
                                        "id": "effective-vpn-coverage",
                                        "name": "Effective VPN coverage",
                                        "description": "Record actual VPN, direct and blocked paths rather than relying only on full-tunnel or split-tunnel labels.",
                                        "questions": [
                                            {
                                                "text": "Which IPv4, IPv6, application and local-network flows traverse the VPN under the effective routing and policy rules?",
                                                "kind": "measurement",
                                                "id": "effective-vpn-coverage-q01"
                                            },
                                            {
                                                "text": "Which bypasses are intended exceptions, and which violate the stated traffic-coverage requirement?",
                                                "kind": "boundary",
                                                "id": "effective-vpn-coverage-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "dns-and-destination-access",
                                "name": "DNS and destination access",
                                "description": "Connects name resolution, addressing and filtering to usable destination paths.",
                                "findings": [
                                    {
                                        "id": "resolved-and-permitted-paths",
                                        "name": "Resolved and permitted paths",
                                        "description": "Record DNS resolver selection, overlapping address spaces, translation and access filters that affect private or external destinations.",
                                        "questions": [
                                            {
                                                "text": "Which resolver handles each relevant namespace, and do its requests follow the intended VPN or direct path?",
                                                "kind": "measurement",
                                                "id": "resolved-and-permitted-paths-q01"
                                            },
                                            {
                                                "text": "For a target resource, which route, address overlap, translation or filter determines reachability?",
                                                "kind": "boundary",
                                                "id": "resolved-and-permitted-paths-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "admission-and-authorised-control",
                        "name": "Admission and authorised control",
                        "description": "Connects VPN participation and administrative changes to identifiable authority.",
                        "rationale": "Network membership, peer authentication and permission to access resources are distinct decisions.",
                        "layers": [
                            {
                                "id": "identity-and-admission",
                                "name": "Identity and admission",
                                "description": "Records how peers or attachments are recognised and admitted.",
                                "findings": [
                                    {
                                        "id": "admission-evidence",
                                        "name": "Admission evidence",
                                        "description": "Record credentials, certificates, device requirements or provider provisioning that establish participation, without assuming every VPN authenticates individual users.",
                                        "questions": [
                                            {
                                                "text": "What authenticates or authoritatively provisions each peer or attachment, and which identity does that establish?",
                                                "kind": "provenance",
                                                "id": "admission-evidence-q01"
                                            },
                                            {
                                                "text": "How can an authorised operator revoke membership, and what happens to existing sessions or forwarding state?",
                                                "kind": "action",
                                                "id": "admission-evidence-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "access-and-change-authority",
                                "name": "Access and change authority",
                                "description": "Separates access permissions from permission to administer VPN behaviour.",
                                "findings": [
                                    {
                                        "id": "bounded-vpn-actions",
                                        "name": "Bounded VPN actions",
                                        "description": "Record who may reach resources and who may change peers, routes, protection settings or bypass exceptions.",
                                        "questions": [
                                            {
                                                "text": "Which resources may each admitted participant access, and where is that permission enforced?",
                                                "kind": "boundary",
                                                "id": "bounded-vpn-actions-q01"
                                            },
                                            {
                                                "text": "Which VPN changes may the agent perform, under whose authority, and with what verification and rollback conditions?",
                                                "kind": "action",
                                                "id": "bounded-vpn-actions-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "operation-and-failure-behaviour",
                        "name": "Operation and failure behaviour",
                        "description": "Assesses live service state, workload suitability and behaviour when connectivity or protection changes.",
                        "rationale": "A VPN can appear connected while traffic is unusable, bypassing protection or retaining obsolete access.",
                        "layers": [
                            {
                                "id": "live-state-and-path-quality",
                                "name": "Live state and path quality",
                                "description": "Distinguishes control-plane success from working data paths.",
                                "findings": [
                                    {
                                        "id": "usable-connectivity",
                                        "name": "Usable connectivity",
                                        "description": "Record negotiation or provisioning state alongside representative end-to-end traffic tests and path constraints.",
                                        "questions": [
                                            {
                                                "text": "What evidence shows that representative permitted flows work beyond a connected status indicator?",
                                                "kind": "measurement",
                                                "id": "usable-connectivity-q01"
                                            },
                                            {
                                                "text": "What latency, throughput, loss and effective MTU are observed for the intended workload and path?",
                                                "kind": "measurement",
                                                "id": "usable-connectivity-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "failure-and-recovery",
                                "name": "Failure and recovery",
                                "description": "Captures traffic handling during outages, transitions and restoration.",
                                "findings": [
                                    {
                                        "id": "protection-through-transitions",
                                        "name": "Protection through transitions",
                                        "description": "Record whether traffic blocks, bypasses or reroutes during relevant failures and whether recovery restores the intended access boundary.",
                                        "questions": [
                                            {
                                                "text": "During tunnel loss, gateway failure, rekeying or device network changes, which traffic blocks, bypasses or uses an alternate path?",
                                                "kind": "measurement",
                                                "id": "protection-through-transitions-q01"
                                            },
                                            {
                                                "text": "Which authorised recovery action restores service, and how will the agent verify routes, DNS handling and revoked access afterward?",
                                                "kind": "action",
                                                "id": "protection-through-transitions-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "evidence-and-external-alignment",
                        "name": "Evidence and external alignment",
                        "description": "What the world already says about this thing, gathered so the model can be checked against it.",
                        "rationale": "A model that cannot be lined up against existing standards, identifiers and practice cannot be adopted by anyone who already uses them.",
                        "layers": [
                            {
                                "id": "reported-evidence",
                                "name": "Reported evidence",
                                "description": "Findings from the breadth pass, kept separate from the structural claims.",
                                "findings": [
                                    {
                                        "id": "evidence-confidence-notes",
                                        "name": "Check these first",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "This describes the networking concept, including enterprise and provider VPNs, rather than only commercial consumer VPN services.",
                                            "Privacy can mean traffic isolation rather than encryption: provider-provisioned VPNs do not inherently encrypt customer traffic.",
                                            "The listed kinds use overlapping classification axes; deployment topology and network service layer are separate distinctions."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-confidence-notes-q01",
                                                "text": "Which of these check these first hold for the sense of virtual private network this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-kinds",
                                        "name": "Kinds and varieties",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Remote-access VPN",
                                            "Site-to-site VPN",
                                            "Provider-provisioned Layer 2 VPN",
                                            "Provider-provisioned Layer 3 VPN"
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-kinds-q01",
                                                "text": "Which of these kinds and varieties hold for the sense of virtual private network this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-identifiers",
                                        "name": "Identifiers and schemes",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "scheme": "BGP/MPLS VPN route distinguisher",
                                                "value_or_pattern": "8-byte value commonly represented as administrator:assigned-number",
                                                "note": "Distinguishes otherwise overlapping address prefixes in BGP/MPLS VPN routing; it is not a universal VPN identifier."
                                            },
                                            {
                                                "scheme": "BGP route target extended community",
                                                "value_or_pattern": "Commonly represented as autonomous-system-number:assigned-number or IPv4-address:assigned-number",
                                                "note": "Controls route import and export in provider VPNs; multiple VPN routing instances may share a route target."
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-identifiers-q01",
                                                "text": "Which of these identifiers and schemes hold for the sense of virtual private network this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-standards-and-regulation",
                                        "name": "Standards and regulation",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "IETF RFC 4301, Security Architecture for the Internet Protocol: architecture for IPsec protection.",
                                            "IETF RFC 7296, Internet Key Exchange Protocol Version 2 (IKEv2): authentication and security association establishment for IPsec.",
                                            "IETF RFC 4364, BGP/MPLS IP Virtual Private Networks (VPNs): provider-provisioned IP VPN architecture.",
                                            "IETF RFC 4026, Provider Provisioned Virtual Private Network (VPN) Terminology: terminology for provider VPN services."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-standards-and-regulation-q01",
                                                "text": "Which of these standards and regulation hold for the sense of virtual private network this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-real-world-use",
                                        "name": "Real-world use",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Giving remote workers access to organisational networks.",
                                            "Connecting branch offices and data centres across shared transport networks.",
                                            "Connecting private networks to cloud environments.",
                                            "Providing separate customer routing environments on telecommunications infrastructure.",
                                            "Protecting traffic between a user device and a VPN gateway when using untrusted access networks."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-real-world-use-q01",
                                                "text": "Which of these real-world use hold for the sense of virtual private network this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-measurements",
                                        "name": "Typical measurements",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "quantity": "Tunnel throughput",
                                                "typical_range": "Deployment-dependent; constrained by underlying links, processing capacity and encapsulation overhead.",
                                                "unit": "bit/s"
                                            },
                                            {
                                                "quantity": "Added round-trip latency",
                                                "typical_range": "No universal range; depends on gateway location, routing, congestion and processing.",
                                                "unit": "ms"
                                            },
                                            {
                                                "quantity": "Effective tunnel MTU",
                                                "typical_range": "Usually below the underlying path MTU because encapsulation consumes packet space.",
                                                "unit": "bytes"
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-measurements-q01",
                                                "text": "Which of these typical measurements hold for the sense of virtual private network this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-failure-modes-and-hazards",
                                        "name": "Failure modes and hazards",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Routing or DNS configuration errors can send traffic outside the intended tunnel.",
                                            "Compromised credentials, endpoints or gateways can permit unauthorised access.",
                                            "MTU mismatches and failed path MTU discovery can cause fragmentation or stalled connections.",
                                            "Overlapping addresses or incorrect route import and export policies can disrupt connectivity or breach isolation.",
                                            "Protection may end at the VPN gateway; a VPN does not inherently provide anonymity, trustworthy endpoints or encryption to the final destination."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-failure-modes-and-hazards-q01",
                                                "text": "Which of these failure modes and hazards hold for the sense of virtual private network this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-neighbours",
                                        "name": "Neighbouring kinds and how to tell them apart",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "name": "Proxy server",
                                                "difference": "A proxy intermediates selected application connections; a VPN provides logical network connectivity and routing or forwarding for participating endpoints."
                                            },
                                            {
                                                "name": "VLAN",
                                                "difference": "A VLAN partitions a Layer 2 network into logical broadcast domains; it does not by itself establish VPN connectivity across an intervening network."
                                            },
                                            {
                                                "name": "IPsec",
                                                "difference": "IPsec is a suite of network-layer security mechanisms that can implement a VPN; VPNs can also use other mechanisms."
                                            },
                                            {
                                                "name": "Tor",
                                                "difference": "Tor uses multiple relays to limit linkage between origin and destination; a conventional VPN ordinarily concentrates trust in its gateway or provider."
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-neighbours-q01",
                                                "text": "Which of these neighbouring kinds and how to tell them apart hold for the sense of virtual private network this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "openQuestions": [
                "Which reference definitions should govern this registry entry, particularly the inclusion of provider-provisioned VPNs without payload encryption?",
                "Should an instance denote a complete private network, a service configuration or an individual connection, and how should those levels relate?",
                "Where should this entry draw its boundary with application-scoped VPN products, zero-trust network access and other selective access services?",
                "What evidence and observation periods are sufficient to substantiate isolation, traffic-coverage and operator logging claims?",
                "Which deployment-specific failure tests are required before an agent can judge that the VPN preserves its intended protection during transitions?"
            ],
            "statistics": {
                "bundles": 6,
                "layers": 11,
                "findings": 18,
                "questions": 28
            }
        },
        "draft": {
            "generator": "vr.draft.v3",
            "status": "draft-generated",
            "researched": false,
            "archetype": "abstract concept",
            "method": "Written from the archetype playbook - what this kind of thing needs beyond identity and provenance - and from the structure that recurred across 6,333 models already researched by two engines. Applied to this entry by rule. No source was read for this thing and no claim here is researched. This entry carries no facets of its own, so they were inferred from its domain - a guess about a whole domain applied to one thing.",
            "facetsInferred": true,
            "nextPass": "A researcher replaces this draft with a sourced specification. Treat every sentence below as a proposal to argue with.",
            "purpose": "Give an agent a durable, checkable way to recognise a virtual private network, record what state it is in, and decide what may be done with it.",
            "whatItIs": "Enable an AI agent to recognise a virtual private network, assess the connectivity and protection it actually provides, and determine which connection, routing and access changes are authorised.",
            "characteristics": {
                "substance": "activity",
                "origin": "conceptual",
                "agency": "inert"
            },
            "whatYouCanDoWithIt": [
                "observed and measured"
            ],
            "distinguishingFeatures": [
                "Names folded into this entry, which a task may need to split apart again: mobile virtual private network, Nym Mixnet, SSL.",
                "3 finer distinctions are held as aliases rather than separate entries, because telling them apart needs a task that asks for it.",
                "Described in 79 Wikipedia languages, which is a measure of how widely the thing is known, not of how important it is."
            ],
            "openQuestionsForResearch": [
                "Which of the bundles below does a real task actually need, and which are ceremony?",
                "What does this thing have that the facets do not capture at all?",
                "Which neighbouring kind is most often confused with a virtual private network, and on what evidence are they told apart?"
            ],
            "whatItIsMadeOf": "something that happens over time",
            "physicalCharacter": [
                "Does nothing on its own; everything it does, something else did to it.",
                "These come from the domain this entry sits in rather than from the entry itself, so treat them as a first guess about the whole domain applied to one thing."
            ],
            "whatCanBeDoneWithIt": [
                "observe it, measure it, record its state"
            ],
            "howItIsRecognised": [
                "Nothing to see. What is recognised is an instance of it, and which instances count is exactly what is argued about."
            ],
            "relatedModels": [
                {
                    "relation": "covers",
                    "note": "Finer kinds folded into this entry because telling them apart needs a task that asks for it. Each is a model waiting to be split out when one does.",
                    "targets": [
                        "mobile virtual private network",
                        "Nym Mixnet",
                        "SSL"
                    ]
                }
            ],
            "standing": "Described in 79 Wikipedia languages, which measures how widely it is written about rather than how important or how common it is. 3 finer distinctions are held inside this entry as names rather than as separate models.",
            "structure": {
                "bundles": [
                    {
                        "id": "identity-and-classification",
                        "name": "Identity, naming and classification",
                        "description": "How an agent tells one virtual private network from another, and a virtual private network from things that resemble it.",
                        "rationale": "Recognition comes before every other claim. Without stable identity nothing else in the model can be trusted to be about the same thing twice.",
                        "layers": [
                            {
                                "id": "naming-and-identifiers",
                                "name": "Names and identifiers",
                                "description": "The names this thing goes by and the identifiers that survive translation and time.",
                                "findings": [
                                    {
                                        "id": "preferred-name-and-aliases",
                                        "name": "Preferred name, aliases and local names",
                                        "description": "Which name to use, which names mean the same thing, and which merely sound similar.",
                                        "questions": [
                                            {
                                                "id": "preferred-name-and-aliases-q01",
                                                "text": "What identifies and describes the name of a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q02",
                                                "text": "Who or what asserted this about the name of a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q03",
                                                "text": "What may an agent decide or do once the name of a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "stable-identifiers",
                                        "name": "Stable identifiers and external keys",
                                        "description": "Identifiers that keep pointing at this kind of thing across systems and languages.",
                                        "questions": [
                                            {
                                                "id": "stable-identifiers-q01",
                                                "text": "What identifies and describes an identifier for a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q02",
                                                "text": "Who or what asserted this about an identifier for a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q03",
                                                "text": "What may an agent decide or do once an identifier for a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "classification-and-granularity",
                                "name": "Classification and granularity",
                                "description": "Where a virtual private network sits among kinds, and how finely a task needs to cut it.",
                                "findings": [
                                    {
                                        "id": "kind-and-parents",
                                        "name": "Kind, parents and neighbouring kinds",
                                        "description": "The classes this thing belongs to and the ones it is next to.",
                                        "questions": [
                                            {
                                                "id": "kind-and-parents-q01",
                                                "text": "What identifies and describes the kind of a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q02",
                                                "text": "Who or what asserted this about the kind of a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q03",
                                                "text": "What may an agent decide or do once the kind of a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "distinguishing-features",
                                        "name": "Distinguishing features",
                                        "description": "What separates a virtual private network from the things most often confused with it.",
                                        "questions": [
                                            {
                                                "id": "distinguishing-features-q01",
                                                "text": "What identifies and describes what distinguishes a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q02",
                                                "text": "Who or what asserted this about what distinguishes a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q03",
                                                "text": "What may an agent decide or do once what distinguishes a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "state-and-lifecycle",
                        "name": "State and lifecycle",
                        "description": "The states a virtual private network passes through and the events that move it between them.",
                        "rationale": "Most decisions about a thing depend on what state it is in now, which is a claim with a time on it, not a property.",
                        "layers": [
                            {
                                "id": "lifecycle-stages",
                                "name": "Lifecycle stages",
                                "description": "From coming into existence to ceasing to be one of these.",
                                "findings": [
                                    {
                                        "id": "stages-and-transitions",
                                        "name": "Stages and transitions",
                                        "description": "The stages worth naming and what moves a virtual private network between them.",
                                        "questions": [
                                            {
                                                "id": "stages-and-transitions-q01",
                                                "text": "What identifies and describes the lifecycle of a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q02",
                                                "text": "Who or what asserted this about the lifecycle of a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q03",
                                                "text": "What may an agent decide or do once the lifecycle of a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "observations-and-status",
                                "name": "Observations and current status",
                                "description": "What is observed about a virtual private network, how often and by whom.",
                                "findings": [
                                    {
                                        "id": "observation-record",
                                        "name": "Observation record",
                                        "description": "How an observation of a virtual private network is recorded so that it can be superseded rather than overwritten.",
                                        "questions": [
                                            {
                                                "id": "observation-record-q01",
                                                "text": "What identifies and describes an observation of a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q02",
                                                "text": "Who or what asserted this about an observation of a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q03",
                                                "text": "What may an agent decide or do once an observation of a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "process-and-outcome",
                        "name": "Process, inputs and outcome",
                        "description": "How a virtual private network proceeds, what it needs and what it leaves behind.",
                        "rationale": "An activity is known by its steps and its results, and both have to be recordable while it is still running.",
                        "layers": [
                            {
                                "id": "steps-and-sequence",
                                "name": "Steps and sequence",
                                "description": "The steps of a virtual private network, their order and what may run in parallel.",
                                "findings": [
                                    {
                                        "id": "steps-and-preconditions",
                                        "name": "Steps, preconditions and completion",
                                        "description": "What has to be true before each step of a virtual private network and what marks it done.",
                                        "questions": [
                                            {
                                                "id": "steps-and-preconditions-q01",
                                                "text": "What identifies and describes a step of a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "steps-and-preconditions-q02",
                                                "text": "Who or what asserted this about a step of a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "steps-and-preconditions-q03",
                                                "text": "What may an agent decide or do once a step of a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "inputs-and-results",
                                "name": "Inputs, resources and results",
                                "description": "What a virtual private network consumes and what it produces.",
                                "findings": [
                                    {
                                        "id": "inputs-and-outputs",
                                        "name": "Inputs, outputs and side effects",
                                        "description": "The resources a virtual private network takes and the results it leaves, wanted or not.",
                                        "questions": [
                                            {
                                                "id": "inputs-and-outputs-q01",
                                                "text": "What identifies and describes the inputs and results of a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "inputs-and-outputs-q02",
                                                "text": "Who or what asserted this about the inputs and results of a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "inputs-and-outputs-q03",
                                                "text": "What may an agent decide or do once the inputs and results of a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "definitions-in-contest",
                        "name": "Definitions and who holds them",
                        "description": "What virtual private network is taken to mean, and by whom.",
                        "rationale": "When a field disagrees about a concept, the disagreement is the content. A model that picks one definition silently destroys the information.",
                        "layers": [
                            {
                                "id": "competing-definitions",
                                "name": "Competing definitions",
                                "description": "The main readings and the traditions behind them.",
                                "findings": [
                                    {
                                        "id": "definition-map",
                                        "name": "Definitions and their holders",
                                        "description": "Each definition with the school or body that holds it.",
                                        "questions": [
                                            {
                                                "id": "definition-map-q01",
                                                "text": "Which definitions of virtual private network are in use, and which tradition or body holds each?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "definition-map-q02",
                                                "text": "What turns on the difference between them in practice?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "operationalisation",
                                "name": "Operationalisation",
                                "description": "How it is measured or applied when it has to be.",
                                "findings": [
                                    {
                                        "id": "operational-record",
                                        "name": "Measures and proxies",
                                        "description": "Instruments and indicators used to stand in for it.",
                                        "questions": [
                                            {
                                                "id": "operational-record-q01",
                                                "text": "How is virtual private network operationalised or measured in practice, and by what instrument?",
                                                "kind": "measurement"
                                            },
                                            {
                                                "id": "operational-record-q02",
                                                "text": "What does that operationalisation leave out, and when does that matter?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "instances-and-use",
                        "name": "Instances, use and consequence",
                        "description": "What counts as an instance of virtual private network and what follows from calling something that.",
                        "rationale": "Applying a concept is an act with consequences, so a model must say what the label licenses and what it does not.",
                        "layers": [
                            {
                                "id": "instances",
                                "name": "What counts as an instance",
                                "description": "Clear cases, borderline cases and non-cases.",
                                "findings": [
                                    {
                                        "id": "instance-tests",
                                        "name": "Tests for an instance",
                                        "description": "What would settle whether something falls under it.",
                                        "questions": [
                                            {
                                                "id": "instance-tests-q01",
                                                "text": "What would settle whether something is an instance of virtual private network?",
                                                "kind": "boundary"
                                            },
                                            {
                                                "id": "instance-tests-q02",
                                                "text": "Which borderline cases are argued about, and on what grounds?",
                                                "kind": "definition"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "consequence",
                                "name": "Consequence of application",
                                "description": "Rights, duties or decisions that follow from the label.",
                                "findings": [
                                    {
                                        "id": "consequence-record",
                                        "name": "What the label licenses",
                                        "description": "What an agent may do once something is classified this way.",
                                        "questions": [
                                            {
                                                "id": "consequence-record-q01",
                                                "text": "What follows practically once something is treated as virtual private network?",
                                                "kind": "action"
                                            },
                                            {
                                                "id": "consequence-record-q02",
                                                "text": "What must an agent not infer from the label alone?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "provenance-and-evidence",
                        "name": "Provenance, evidence and time",
                        "description": "Where every claim about a virtual private network came from and when it held.",
                        "rationale": "A claim without a source and a time cannot be superseded, only overwritten, and an agent that overwrites loses the ability to explain itself.",
                        "layers": [
                            {
                                "id": "source-and-authority",
                                "name": "Source and authority",
                                "description": "Who said it, on what evidence, and how strongly.",
                                "findings": [
                                    {
                                        "id": "claim-provenance",
                                        "name": "Claim provenance and confidence",
                                        "description": "The authority behind each claim about a virtual private network and how confident it is.",
                                        "questions": [
                                            {
                                                "id": "claim-provenance-q01",
                                                "text": "What identifies and describes a claim about a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q02",
                                                "text": "Who or what asserted this about a claim about a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q03",
                                                "text": "What may an agent decide or do once a claim about a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "time-and-versions",
                                "name": "Time, versions and supersession",
                                "description": "When a claim was true, when it was learnt, and what replaced it.",
                                "findings": [
                                    {
                                        "id": "validity-and-supersession",
                                        "name": "Validity period and supersession",
                                        "description": "How an old claim about a virtual private network is retired without being erased.",
                                        "questions": [
                                            {
                                                "id": "validity-and-supersession-q01",
                                                "text": "What identifies and describes the validity of a claim about a virtual private network, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q02",
                                                "text": "Who or what asserted this about the validity of a claim about a virtual private network, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q03",
                                                "text": "What may an agent decide or do once the validity of a claim about a virtual private network is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "statistics": {
                "bundles": 6,
                "layers": 12,
                "findings": 14,
                "questions": 38
            }
        }
    }
}