{
    "model": {
        "rank": 6529,
        "code": "thing-q179550",
        "model_id": "vr.tr.software-bug",
        "name": "software bug",
        "purpose": "Let an agent explain software bugs and their kinds, support finding, reporting and fixing bugs, describe vulnerability handling and disclosure in general terms, and decline exploit development for unauthorised use.",
        "family": "Thing Registry",
        "category": "Cross-cutting context",
        "status": "research-draft",
        "kind": "thing",
        "plane": "XCT",
        "domain": "XCT.QLT",
        "industry": "",
        "version": "",
        "url": "/models/thing/q179550/",
        "tier": 2,
        "score": 60,
        "payload": {
            "layer": "wikidata",
            "aliases": [
                "BootROM exploit",
                "XML injection",
                "null byte injection",
                "Server Side Include Injection",
                "Server Side Template Injection",
                "vulnerability",
                "Year 2010 problem",
                "resource leak",
                "insecure direct object reference",
                "format string attack",
                "cross-site authentication attack",
                "cross-site tracing",
                "open-source vulnerability",
                "Prototype pollution",
                "Embedded Malicious Code",
                "named vulnerability",
                "China National Vulnerability Database",
                "covert channel",
                "XPath injection",
                "HTTP header injection",
                "firmware vulnerability",
                "remote file inclusion",
                "NOBUS",
                "Unauthorized Cross-App Resource Access",
                "arbitrary code execution",
                "cross-site cooking",
                "Default Credential vulnerability",
                "random number generator attack",
                "Structural vulnerability",
                "cross-zone scripting",
                "improper input validation",
                "file inclusion vulnerability",
                "JIT spraying",
                "race condition",
                "HTTP response splitting",
                "transient execution CPU vulnerability",
                "mass assignment vulnerability",
                "physical access",
                "malware vector",
                "virtual machine escape"
            ],
            "aliasCount": 74,
            "merged": 74,
            "knownIn": 60,
            "facets": null,
            "markers": [],
            "lexicalClass": "",
            "senseRank": null,
            "alsoRegisteredAs": null,
            "source": {
                "dataset": "wikidata",
                "item": "Q179550",
                "url": "https://www.wikidata.org/wiki/Q179550",
                "license": "CC0 1.0"
            }
        },
        "research": {
            "vercy": "1.0-draft",
            "publication": {
                "status": "research-draft",
                "adjudicationStatus": "unreviewed",
                "publishableCanonical": false,
                "generatedAt": "2026-09-11T22:38:06Z",
                "providers": [
                    "Claude"
                ],
                "breadth": "written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify",
                "pass": 2,
                "wave": 2,
                "engine": "claude"
            },
            "metaModel": {
                "id": "THING-Q179550",
                "registryId": "vr.tr.software-bug",
                "name": "software bug",
                "version": "0.2.0-wave.2",
                "entryKind": "thing",
                "family": "Thing Registry",
                "domain": [
                    "XCT.QLT"
                ],
                "status": "research-draft"
            },
            "canonicalUrl": "https://ver.cy/models/thing/q179550/",
            "model": {
                "registry_id": "vr.tr.software-bug",
                "name": "software bug",
                "purpose": "Let an agent explain software bugs and their kinds, support finding, reporting and fixing bugs, describe vulnerability handling and disclosure in general terms, and decline exploit development for unauthorised use.",
                "definition": "An error, flaw or fault in software that causes it to behave incorrectly or unexpectedly, from logic and arithmetic errors to crashes and security vulnerabilities such as injection flaws; bugs are found by testing, review and user reports, tracked in issue systems, and fixed through patches, and security-relevant bugs are handled through responsible disclosure.",
                "what_it_is_for": "Defects in software.",
                "affordances": [
                    "explain kinds of bug",
                    "support debugging and reporting",
                    "describe vulnerability handling",
                    "refuse unauthorised exploit help"
                ],
                "distinguishing_features": [
                    "Defect",
                    "Reproducible ideally",
                    "Tracked and fixed",
                    "Security relevance in some cases"
                ],
                "appearance": "Not physical; incorrect behaviour, crashes or error messages.",
                "visual_identification": [
                    "Software behaves incorrectly",
                    "Defect in code or design",
                    "A feature request is not a bug"
                ],
                "physical_properties": [],
                "families_and_kinds": [
                    "logic and arithmetic bugs",
                    "memory and concurrency bugs",
                    "interface and compatibility bugs",
                    "security vulnerabilities such as injection flaws",
                    "performance bugs"
                ],
                "related_models": [
                    {
                        "relation": "is a kind of",
                        "target": "computer error",
                        "why": "category"
                    },
                    {
                        "relation": "is a kind of",
                        "target": "IT risk",
                        "why": "category"
                    },
                    {
                        "relation": "is related to",
                        "target": "open-source software",
                        "why": "bug tracking in projects"
                    },
                    {
                        "relation": "is related to",
                        "target": "data dependency",
                        "why": "concurrency bugs"
                    }
                ],
                "identifiers": [],
                "standards_and_regulation": [
                    "Vulnerability disclosure and CVE conventions",
                    "Software quality standards",
                    "Computer misuse laws"
                ],
                "failure_modes_and_hazards": [
                    "Exploitation of vulnerabilities",
                    "Data loss and outages",
                    "Agents helping exploit systems without authorisation"
                ],
                "in_scope": [],
                "out_of_scope": [],
                "characteristics": []
            },
            "sources": [],
            "structure": {
                "bundles": [
                    {
                        "id": "fix",
                        "name": "Fix",
                        "description": "Finding and fixing bugs.",
                        "rationale": "Debugging.",
                        "layers": [
                            {
                                "id": "diagnose",
                                "name": "Diagnose",
                                "description": "Diagnosing a bug.",
                                "findings": [
                                    {
                                        "id": "diagnose-finding",
                                        "name": "Diagnose",
                                        "description": "Diagnosis.",
                                        "questions": [
                                            {
                                                "text": "What might cause this incorrect behaviour, and how can it be reproduced and isolated?",
                                                "kind": "action"
                                            },
                                            {
                                                "text": "Which debugging tools and techniques apply?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "report",
                                "name": "Report",
                                "description": "Reporting bugs.",
                                "findings": [
                                    {
                                        "id": "report-finding",
                                        "name": "Report",
                                        "description": "Reporting.",
                                        "questions": [
                                            {
                                                "text": "How should a bug be reported with steps, environment and expected behaviour?",
                                                "kind": "action"
                                            },
                                            {
                                                "text": "How is a bug prioritised and tracked?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "understand",
                        "name": "Understand",
                        "description": "Kinds of bug.",
                        "rationale": "Classification.",
                        "layers": [
                            {
                                "id": "kinds",
                                "name": "Kinds",
                                "description": "Categories.",
                                "findings": [
                                    {
                                        "id": "kinds-finding",
                                        "name": "Kinds",
                                        "description": "Categories.",
                                        "questions": [
                                            {
                                                "text": "What kinds of bugs exist, from logic errors to memory, concurrency and compatibility bugs?",
                                                "kind": "definition"
                                            },
                                            {
                                                "text": "Which famous bugs illustrate them?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "prevent",
                                "name": "Prevent",
                                "description": "Preventing bugs.",
                                "findings": [
                                    {
                                        "id": "prevent-finding",
                                        "name": "Prevent",
                                        "description": "Prevention.",
                                        "questions": [
                                            {
                                                "text": "How do testing, code review, static analysis and safe languages reduce bugs?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "Which practices suit this project?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "security",
                        "name": "Security",
                        "description": "Vulnerabilities.",
                        "rationale": "Boundaries.",
                        "layers": [
                            {
                                "id": "vulnerability",
                                "name": "Vulnerability",
                                "description": "Security bugs.",
                                "findings": [
                                    {
                                        "id": "vulnerability-finding",
                                        "name": "Vulnerability",
                                        "description": "Vulnerabilities.",
                                        "questions": [
                                            {
                                                "text": "What are vulnerability classes such as injection flaws, in general terms, and how are they prevented?",
                                                "kind": "definition"
                                            },
                                            {
                                                "text": "Is the request seeking to exploit a system without authorisation, which must be declined?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "disclosure",
                                "name": "Disclosure",
                                "description": "Disclosure.",
                                "findings": [
                                    {
                                        "id": "disclosure-finding",
                                        "name": "Disclosure",
                                        "description": "Disclosure.",
                                        "questions": [
                                            {
                                                "text": "How does responsible disclosure work, and how are vulnerabilities catalogued?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "How should a discovered vulnerability be reported?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "learn",
                        "name": "Learn",
                        "description": "History and teaching.",
                        "rationale": "Context.",
                        "layers": [
                            {
                                "id": "history",
                                "name": "History",
                                "description": "History of bugs.",
                                "findings": [
                                    {
                                        "id": "history-finding",
                                        "name": "History",
                                        "description": "History.",
                                        "questions": [
                                            {
                                                "text": "Where does the term bug come from, and which historical bugs had major consequences?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "text": "Which references are standard?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "teach",
                                "name": "Teach",
                                "description": "Teaching debugging.",
                                "findings": [
                                    {
                                        "id": "teach-finding",
                                        "name": "Teach",
                                        "description": "Teaching.",
                                        "questions": [
                                            {
                                                "text": "How can debugging and defensive programming be taught?",
                                                "kind": "action"
                                            },
                                            {
                                                "text": "Which misconceptions arise?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "openQuestions": [
                "Should vulnerability be a separate entry?",
                "How should bug trackers be linked?",
                "How should disclosure policies be linked?"
            ],
            "statistics": {
                "bundles": 4,
                "layers": 8,
                "findings": 8,
                "questions": 16
            }
        },
        "draft": {
            "generator": "vr.draft.v3",
            "status": "draft-generated",
            "researched": false,
            "archetype": "abstract concept",
            "method": "Written from the archetype playbook - what this kind of thing needs beyond identity and provenance - and from the structure that recurred across 6,333 models already researched by two engines. Applied to this entry by rule. No source was read for this thing and no claim here is researched. This entry carries no facets of its own, so they were inferred from its domain - a guess about a whole domain applied to one thing.",
            "facetsInferred": true,
            "nextPass": "A researcher replaces this draft with a sourced specification. Treat every sentence below as a proposal to argue with.",
            "purpose": "Give an agent a durable, checkable way to recognise a software bug, record what state it is in, and decide what may be done with it.",
            "whatItIs": "Let an agent explain software bugs and their kinds, support finding, reporting and fixing bugs, describe vulnerability handling and disclosure in general terms, and decline exploit development for unauthorised use.",
            "characteristics": {
                "substance": "abstract",
                "origin": "conceptual",
                "agency": "inert"
            },
            "whatYouCanDoWithIt": [
                "observed and measured"
            ],
            "distinguishingFeatures": [
                "Names folded into this entry, which a task may need to split apart again: BootROM exploit, XML injection, null byte injection, Server Side Include Injection, Server Side Template Injection, vulnerability, Year 2010 problem, resource leak, insecure direct object reference, format string attack, cross-site authentication attack, cross-site tracing.",
                "74 finer distinctions are held as aliases rather than separate entries, because telling them apart needs a task that asks for it.",
                "Described in 60 Wikipedia languages, which is a measure of how widely the thing is known, not of how important it is."
            ],
            "openQuestionsForResearch": [
                "Which of the bundles below does a real task actually need, and which are ceremony?",
                "What does this thing have that the facets do not capture at all?",
                "Which neighbouring kind is most often confused with a software bug, and on what evidence are they told apart?"
            ],
            "whatItIsMadeOf": "an abstraction with no physical instance",
            "physicalCharacter": [
                "Does nothing on its own; everything it does, something else did to it.",
                "These come from the domain this entry sits in rather than from the entry itself, so treat them as a first guess about the whole domain applied to one thing."
            ],
            "whatCanBeDoneWithIt": [
                "observe it, measure it, record its state"
            ],
            "howItIsRecognised": [
                "Nothing to see. What is recognised is an instance of it, and which instances count is exactly what is argued about."
            ],
            "relatedModels": [
                {
                    "relation": "covers",
                    "note": "Finer kinds folded into this entry because telling them apart needs a task that asks for it. Each is a model waiting to be split out when one does.",
                    "targets": [
                        "BootROM exploit",
                        "XML injection",
                        "null byte injection",
                        "Server Side Include Injection",
                        "Server Side Template Injection",
                        "vulnerability",
                        "Year 2010 problem",
                        "resource leak",
                        "insecure direct object reference",
                        "format string attack",
                        "cross-site authentication attack",
                        "cross-site tracing"
                    ]
                }
            ],
            "standing": "Described in 60 Wikipedia languages, which measures how widely it is written about rather than how important or how common it is. 74 finer distinctions are held inside this entry as names rather than as separate models.",
            "structure": {
                "bundles": [
                    {
                        "id": "identity-and-classification",
                        "name": "Identity, naming and classification",
                        "description": "How an agent tells one software bug from another, and a software bug from things that resemble it.",
                        "rationale": "Recognition comes before every other claim. Without stable identity nothing else in the model can be trusted to be about the same thing twice.",
                        "layers": [
                            {
                                "id": "naming-and-identifiers",
                                "name": "Names and identifiers",
                                "description": "The names this thing goes by and the identifiers that survive translation and time.",
                                "findings": [
                                    {
                                        "id": "preferred-name-and-aliases",
                                        "name": "Preferred name, aliases and local names",
                                        "description": "Which name to use, which names mean the same thing, and which merely sound similar.",
                                        "questions": [
                                            {
                                                "id": "preferred-name-and-aliases-q01",
                                                "text": "What identifies and describes the name of a software bug, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q02",
                                                "text": "Who or what asserted this about the name of a software bug, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q03",
                                                "text": "What may an agent decide or do once the name of a software bug is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "stable-identifiers",
                                        "name": "Stable identifiers and external keys",
                                        "description": "Identifiers that keep pointing at this kind of thing across systems and languages.",
                                        "questions": [
                                            {
                                                "id": "stable-identifiers-q01",
                                                "text": "What identifies and describes an identifier for a software bug, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q02",
                                                "text": "Who or what asserted this about an identifier for a software bug, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q03",
                                                "text": "What may an agent decide or do once an identifier for a software bug is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "classification-and-granularity",
                                "name": "Classification and granularity",
                                "description": "Where a software bug sits among kinds, and how finely a task needs to cut it.",
                                "findings": [
                                    {
                                        "id": "kind-and-parents",
                                        "name": "Kind, parents and neighbouring kinds",
                                        "description": "The classes this thing belongs to and the ones it is next to.",
                                        "questions": [
                                            {
                                                "id": "kind-and-parents-q01",
                                                "text": "What identifies and describes the kind of a software bug, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q02",
                                                "text": "Who or what asserted this about the kind of a software bug, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q03",
                                                "text": "What may an agent decide or do once the kind of a software bug is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "distinguishing-features",
                                        "name": "Distinguishing features",
                                        "description": "What separates a software bug from the things most often confused with it.",
                                        "questions": [
                                            {
                                                "id": "distinguishing-features-q01",
                                                "text": "What identifies and describes what distinguishes a software bug, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q02",
                                                "text": "Who or what asserted this about what distinguishes a software bug, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q03",
                                                "text": "What may an agent decide or do once what distinguishes a software bug is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "state-and-lifecycle",
                        "name": "State and lifecycle",
                        "description": "The states a software bug passes through and the events that move it between them.",
                        "rationale": "Most decisions about a thing depend on what state it is in now, which is a claim with a time on it, not a property.",
                        "layers": [
                            {
                                "id": "lifecycle-stages",
                                "name": "Lifecycle stages",
                                "description": "From coming into existence to ceasing to be one of these.",
                                "findings": [
                                    {
                                        "id": "stages-and-transitions",
                                        "name": "Stages and transitions",
                                        "description": "The stages worth naming and what moves a software bug between them.",
                                        "questions": [
                                            {
                                                "id": "stages-and-transitions-q01",
                                                "text": "What identifies and describes the lifecycle of a software bug, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q02",
                                                "text": "Who or what asserted this about the lifecycle of a software bug, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q03",
                                                "text": "What may an agent decide or do once the lifecycle of a software bug is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "observations-and-status",
                                "name": "Observations and current status",
                                "description": "What is observed about a software bug, how often and by whom.",
                                "findings": [
                                    {
                                        "id": "observation-record",
                                        "name": "Observation record",
                                        "description": "How an observation of a software bug is recorded so that it can be superseded rather than overwritten.",
                                        "questions": [
                                            {
                                                "id": "observation-record-q01",
                                                "text": "What identifies and describes an observation of a software bug, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q02",
                                                "text": "Who or what asserted this about an observation of a software bug, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q03",
                                                "text": "What may an agent decide or do once an observation of a software bug is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "definitions-in-contest",
                        "name": "Definitions and who holds them",
                        "description": "What software bug is taken to mean, and by whom.",
                        "rationale": "When a field disagrees about a concept, the disagreement is the content. A model that picks one definition silently destroys the information.",
                        "layers": [
                            {
                                "id": "competing-definitions",
                                "name": "Competing definitions",
                                "description": "The main readings and the traditions behind them.",
                                "findings": [
                                    {
                                        "id": "definition-map",
                                        "name": "Definitions and their holders",
                                        "description": "Each definition with the school or body that holds it.",
                                        "questions": [
                                            {
                                                "id": "definition-map-q01",
                                                "text": "Which definitions of software bug are in use, and which tradition or body holds each?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "definition-map-q02",
                                                "text": "What turns on the difference between them in practice?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "operationalisation",
                                "name": "Operationalisation",
                                "description": "How it is measured or applied when it has to be.",
                                "findings": [
                                    {
                                        "id": "operational-record",
                                        "name": "Measures and proxies",
                                        "description": "Instruments and indicators used to stand in for it.",
                                        "questions": [
                                            {
                                                "id": "operational-record-q01",
                                                "text": "How is software bug operationalised or measured in practice, and by what instrument?",
                                                "kind": "measurement"
                                            },
                                            {
                                                "id": "operational-record-q02",
                                                "text": "What does that operationalisation leave out, and when does that matter?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "instances-and-use",
                        "name": "Instances, use and consequence",
                        "description": "What counts as an instance of software bug and what follows from calling something that.",
                        "rationale": "Applying a concept is an act with consequences, so a model must say what the label licenses and what it does not.",
                        "layers": [
                            {
                                "id": "instances",
                                "name": "What counts as an instance",
                                "description": "Clear cases, borderline cases and non-cases.",
                                "findings": [
                                    {
                                        "id": "instance-tests",
                                        "name": "Tests for an instance",
                                        "description": "What would settle whether something falls under it.",
                                        "questions": [
                                            {
                                                "id": "instance-tests-q01",
                                                "text": "What would settle whether something is an instance of software bug?",
                                                "kind": "boundary"
                                            },
                                            {
                                                "id": "instance-tests-q02",
                                                "text": "Which borderline cases are argued about, and on what grounds?",
                                                "kind": "definition"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "consequence",
                                "name": "Consequence of application",
                                "description": "Rights, duties or decisions that follow from the label.",
                                "findings": [
                                    {
                                        "id": "consequence-record",
                                        "name": "What the label licenses",
                                        "description": "What an agent may do once something is classified this way.",
                                        "questions": [
                                            {
                                                "id": "consequence-record-q01",
                                                "text": "What follows practically once something is treated as software bug?",
                                                "kind": "action"
                                            },
                                            {
                                                "id": "consequence-record-q02",
                                                "text": "What must an agent not infer from the label alone?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "provenance-and-evidence",
                        "name": "Provenance, evidence and time",
                        "description": "Where every claim about a software bug came from and when it held.",
                        "rationale": "A claim without a source and a time cannot be superseded, only overwritten, and an agent that overwrites loses the ability to explain itself.",
                        "layers": [
                            {
                                "id": "source-and-authority",
                                "name": "Source and authority",
                                "description": "Who said it, on what evidence, and how strongly.",
                                "findings": [
                                    {
                                        "id": "claim-provenance",
                                        "name": "Claim provenance and confidence",
                                        "description": "The authority behind each claim about a software bug and how confident it is.",
                                        "questions": [
                                            {
                                                "id": "claim-provenance-q01",
                                                "text": "What identifies and describes a claim about a software bug, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q02",
                                                "text": "Who or what asserted this about a claim about a software bug, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q03",
                                                "text": "What may an agent decide or do once a claim about a software bug is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "time-and-versions",
                                "name": "Time, versions and supersession",
                                "description": "When a claim was true, when it was learnt, and what replaced it.",
                                "findings": [
                                    {
                                        "id": "validity-and-supersession",
                                        "name": "Validity period and supersession",
                                        "description": "How an old claim about a software bug is retired without being erased.",
                                        "questions": [
                                            {
                                                "id": "validity-and-supersession-q01",
                                                "text": "What identifies and describes the validity of a claim about a software bug, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q02",
                                                "text": "Who or what asserted this about the validity of a claim about a software bug, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q03",
                                                "text": "What may an agent decide or do once the validity of a claim about a software bug is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "statistics": {
                "bundles": 5,
                "layers": 10,
                "findings": 12,
                "questions": 32
            }
        }
    }
}