{
    "model": {
        "rank": 3922,
        "code": "thing-q80998",
        "model_id": "vr.tr.firewall",
        "name": "firewall",
        "purpose": "Enable an AI agent to recognise a physical network firewall, assess its traffic-control and operational state, and determine which inspections or changes are authorised.",
        "family": "Thing Registry",
        "category": "Physical world and living systems",
        "status": "research-draft",
        "kind": "thing",
        "plane": "PHY",
        "domain": "PHY.OBJ",
        "industry": "",
        "version": "",
        "url": "/models/thing/q80998/",
        "tier": 2,
        "score": 80,
        "payload": {
            "layer": "wikidata",
            "aliases": [
                "filtering network bridge",
                "firewall software",
                "Firewall as a service",
                "FortiGate",
                "genugate S revision 4.0",
                "Clampd",
                "next-generation firewall",
                "stateful firewall",
                "personal firewall",
                "application firewall",
                "Screened-subnet firewall",
                "virtual firewall",
                "packet filter"
            ],
            "aliasCount": 13,
            "merged": 13,
            "knownIn": 80,
            "facets": null,
            "markers": [],
            "lexicalClass": "",
            "senseRank": null,
            "alsoRegisteredAs": null,
            "source": {
                "dataset": "wikidata",
                "item": "Q80998",
                "url": "https://www.wikidata.org/wiki/Q80998",
                "license": "CC0 1.0"
            }
        },
        "research": {
            "vercy": "1.0-draft",
            "publication": {
                "status": "research-draft",
                "adjudicationStatus": "unreviewed",
                "publishableCanonical": false,
                "generatedAt": "2026-09-09T19:04:35Z",
                "providers": [
                    "Codex"
                ],
                "breadth": "recalled by Codex without web access - no source was read",
                "missingProviders": [],
                "pass": 2,
                "cost": {
                    "grok": {
                        "seconds": 28.5,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.4\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a0878d-c58e-7503-9bb8-351944d9b799\n--------\nuser\nDescribe what is already known about one registered thing. Answer as JSON only, no prose around it.\n\nThing: firewall\nSense to describe: (none recorded)\nDomain code: PHY.OBJ\nAlso known as: (none)\n\n\nContext for this batch of 695 things:\n# Batch 004: 1001 registe",
                        "usd": 0,
                        "recall": true
                    },
                    "codex": {
                        "seconds": 65.1,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.4\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a0878d-c597-71d2-9294-76ce14a8b0f5\n--------\nuser\nYou are drafting a Vercy meta-model for one registered thing. Answer as JSON only, no prose around it.\n\nThing: firewall\nRegistry id: vr.tr.firewall\nPlane / domain: PHY / PHY.OBJ\nRegistry definition: (none recorded)\nNames folded into this entry: (none)\n\n\nContex"
                    }
                }
            },
            "metaModel": {
                "id": "THING-Q80998",
                "registryId": "vr.tr.firewall",
                "name": "firewall",
                "version": "0.1.0-research.1",
                "entryKind": "thing",
                "family": "Thing Registry",
                "domain": [
                    "PHY.OBJ"
                ],
                "status": "research-draft"
            },
            "canonicalUrl": "https://ver.cy/models/thing/q80998/",
            "model": {
                "registry_id": "vr.tr.firewall",
                "name": "firewall",
                "purpose": "Enable an AI agent to recognise a physical network firewall, assess its traffic-control and operational state, and determine which inspections or changes are authorised.",
                "definition": "A network firewall is a hardware or software system that enforces a security policy by permitting or blocking network traffic between hosts or networks; the PHY.OBJ classification is interpreted here as referring to a physical firewall appliance.",
                "scope_statement": "Provisionally covers firewall as a physical network-security appliance in PHY / PHY.OBJ, owning its enforcement boundaries, traffic-decision capabilities, interfaces and operational condition; the registry must still confirm this sense rather than an architectural fire wall.",
                "in_scope": [
                    "Physical appliances whose defining function is enforcing policy on network traffic",
                    "Network interfaces, security zones and traffic paths subject to enforcement",
                    "Filtering capabilities, session handling and effective enforcement state",
                    "Management access, configuration deployment and operational evidence",
                    "Capacity, availability and appliance maintenance dependencies"
                ],
                "out_of_scope": [
                    "Architectural fire walls and fire-resistant building compartments",
                    "Standalone software firewalls and cloud firewall services as independently modelled things",
                    "Organisation-wide security policy and its approval process",
                    "General routing and switching except where they determine firewall enforcement paths",
                    "Endpoint protection and intrusion detection systems without firewall enforcement",
                    "Product catalogues and individual appliance inventories as substitutes for the kind-level model"
                ],
                "distinguishing_features": [
                    "Its defining function includes permitting or blocking network traffic under an explicit policy; forwarding traffic alone does not establish firewall identity.",
                    "For traffic claimed as protected, an identifiable path or redirection mechanism brings that traffic under its enforcement.",
                    "It can enforce traffic decisions rather than merely observe traffic and issue alerts.",
                    "The PHY interpretation requires a physical appliance; a software package or hosted service alone does not satisfy that boundary.",
                    "It controls network communication rather than resisting the physical spread of fire; evidence for the architectural sense would require a different draft."
                ],
                "characteristics": [
                    {
                        "name": "Enforcement role",
                        "kind": "category",
                        "unit_or_values": "network firewall appliance; multifunction appliance with firewall role; unresolved",
                        "why_it_matters": "Separates the defining firewall role from optional functions bundled into the same device."
                    },
                    {
                        "name": "Deployment mode",
                        "kind": "category",
                        "unit_or_values": "routed; transparent bridge; other documented mode; unknown",
                        "why_it_matters": "Determines how traffic reaches enforcement and how installation affects network topology."
                    },
                    {
                        "name": "Protected boundary",
                        "kind": "relation",
                        "unit_or_values": "interfaces, zones, networks and traffic directions linked by an enforcement path",
                        "why_it_matters": "Makes claims of protection traceable to specific traffic paths."
                    },
                    {
                        "name": "Inspection capability",
                        "kind": "category",
                        "unit_or_values": "documented support for packet filtering, session tracking, application inspection and encrypted-traffic inspection",
                        "why_it_matters": "Identifies which policy distinctions the appliance can actually enforce."
                    },
                    {
                        "name": "Effective enforcement state",
                        "kind": "state",
                        "unit_or_values": "enforcing; partially enforcing; bypassed; unavailable; unknown",
                        "why_it_matters": "Distinguishes an installed appliance from one currently applying its intended policy."
                    },
                    {
                        "name": "Inspected throughput",
                        "kind": "measurement",
                        "unit_or_values": "bit/s, with inspection features, packet profile and test conditions recorded",
                        "why_it_matters": "Allows capacity comparisons without treating incompatible benchmark conditions as equivalent."
                    },
                    {
                        "name": "Session capacity",
                        "kind": "measurement",
                        "unit_or_values": "concurrent sessions and new sessions/s, with protocol mix and configuration recorded",
                        "why_it_matters": "Exposes capacity limits that bandwidth alone cannot describe."
                    },
                    {
                        "name": "Failure traffic behaviour",
                        "kind": "category",
                        "unit_or_values": "blocks traffic; passes traffic without inspection; transfers enforcement to peer; mixed; unknown, per failure condition",
                        "why_it_matters": "Connects failure modes to both connectivity and protection outcomes."
                    },
                    {
                        "name": "Software and support state",
                        "kind": "state",
                        "unit_or_values": "installed firmware release, update status, support status and enabled feature entitlements",
                        "why_it_matters": "Shows dependencies that can affect available inspection and maintainability."
                    }
                ],
                "affordances": [
                    "Trace whether specified traffic crosses an effective firewall enforcement boundary.",
                    "Inspect effective rules and explain a traffic decision using available policy and session evidence.",
                    "Compare measured traffic load with capacity under matching inspection conditions.",
                    "Prepare and validate an authorised policy change with a recovery path.",
                    "Assess peer takeover or bypass behaviour for a specified failure scenario.",
                    "Collect diagnostic evidence and plan authorised firmware or hardware maintenance."
                ]
            },
            "sources": [],
            "structure": {
                "bundles": [
                    {
                        "id": "identity-and-enforcement-boundary",
                        "name": "Identity and enforcement boundary",
                        "description": "Establishes the appliance sense and the network communications this firewall can govern.",
                        "rationale": "A firewall label does not establish either the intended sense of the word or the extent of protection.",
                        "layers": [
                            {
                                "id": "firewall-role",
                                "name": "Firewall role",
                                "description": "Identifies the defining enforcement function within a physical device.",
                                "findings": [
                                    {
                                        "id": "appliance-sense-and-role",
                                        "name": "Appliance sense and role",
                                        "description": "Record evidence that the thing is a network firewall appliance and distinguish its firewall role from other device functions.",
                                        "questions": [
                                            {
                                                "text": "What registry or source evidence establishes the network-appliance sense rather than the architectural fire-wall sense?",
                                                "kind": "definition",
                                                "id": "appliance-sense-and-role-q01"
                                            },
                                            {
                                                "text": "Which capabilities establish traffic-policy enforcement as a defining role of this appliance?",
                                                "kind": "boundary",
                                                "id": "appliance-sense-and-role-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "protected-traffic-paths",
                                "name": "Protected traffic paths",
                                "description": "Relates interfaces and zones to the traffic paths actually subject to enforcement.",
                                "findings": [
                                    {
                                        "id": "enforcement-coverage",
                                        "name": "Enforcement coverage",
                                        "description": "Record deployment mode, ingress and egress relationships, and paths that can avoid the firewall.",
                                        "questions": [
                                            {
                                                "text": "Which interfaces, zones and traffic directions form each claimed protected boundary?",
                                                "kind": "boundary",
                                                "id": "enforcement-coverage-q01"
                                            },
                                            {
                                                "text": "Which alternate routes, tunnels or asymmetric paths can leave traffic outside that enforcement boundary?",
                                                "kind": "boundary",
                                                "id": "enforcement-coverage-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "traffic-decision-semantics",
                        "name": "Traffic decision semantics",
                        "description": "Describes how effective policy produces decisions for packets, sessions and applications.",
                        "rationale": "An agent needs the actual decision semantics to explain access or evaluate a proposed change.",
                        "layers": [
                            {
                                "id": "rule-evaluation",
                                "name": "Rule evaluation",
                                "description": "Captures rule matching, precedence and interactions with address translation.",
                                "findings": [
                                    {
                                        "id": "effective-rule-path",
                                        "name": "Effective rule path",
                                        "description": "Record the rule-evaluation sequence and unmatched-traffic behaviour without assuming a universal implementation.",
                                        "questions": [
                                            {
                                                "text": "How are overlapping rules resolved, and what happens when no explicit rule matches?",
                                                "kind": "definition",
                                                "id": "effective-rule-path-q01"
                                            },
                                            {
                                                "text": "Where supported, does address translation occur before or after each relevant policy lookup, and which addresses are matched?",
                                                "kind": "definition",
                                                "id": "effective-rule-path-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "session-and-content-inspection",
                                "name": "Session and content inspection",
                                "description": "Identifies the context and traffic content available to enforcement.",
                                "findings": [
                                    {
                                        "id": "inspection-visibility-and-state",
                                        "name": "Inspection visibility and state",
                                        "description": "Record session behaviour and inspection visibility, including limitations imposed by encryption.",
                                        "questions": [
                                            {
                                                "text": "Which session states and timeouts affect decisions, and how do policy changes affect existing sessions?",
                                                "kind": "definition",
                                                "id": "inspection-visibility-and-state-q01"
                                            },
                                            {
                                                "text": "Which traffic attributes remain visible when payloads are encrypted, and what configured prerequisites enable any deeper inspection?",
                                                "kind": "boundary",
                                                "id": "inspection-visibility-and-state-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "management-and-policy-change",
                        "name": "Management and policy change",
                        "description": "Captures control of the firewall and the transition from proposed policy to active enforcement.",
                        "rationale": "A policy change can affect both network access and the administrator's ability to recover the appliance.",
                        "layers": [
                            {
                                "id": "administrative-control",
                                "name": "Administrative control",
                                "description": "Identifies management paths, authority and configuration ownership.",
                                "findings": [
                                    {
                                        "id": "management-authority",
                                        "name": "Management authority",
                                        "description": "Record who or what can inspect and alter enforcement, including dependencies on central management.",
                                        "questions": [
                                            {
                                                "text": "Which management interfaces and roles permit policy edits, firmware changes or inspection-only access?",
                                                "kind": "action",
                                                "id": "management-authority-q01"
                                            },
                                            {
                                                "text": "Which local or central configuration source is authoritative, and what evidence identifies the active revision?",
                                                "kind": "provenance",
                                                "id": "management-authority-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "change-validation-and-recovery",
                                "name": "Change validation and recovery",
                                "description": "Connects policy deployment with traffic checks and restoration of access.",
                                "findings": [
                                    {
                                        "id": "controlled-policy-transition",
                                        "name": "Controlled policy transition",
                                        "description": "Record how an authorised change is checked, activated and reversed if its effects are unacceptable.",
                                        "questions": [
                                            {
                                                "text": "Which permitted and prohibited traffic cases must be checked before and after activating this change?",
                                                "kind": "action",
                                                "id": "controlled-policy-transition-q01"
                                            },
                                            {
                                                "text": "How can the previous policy and management access be restored if the change disconnects the administrator?",
                                                "kind": "action",
                                                "id": "controlled-policy-transition-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "capacity-and-continuity",
                        "name": "Capacity and continuity",
                        "description": "Relates traffic demand, inspection cost and failure behaviour to continued enforcement.",
                        "rationale": "Connectivity and policy enforcement can degrade differently under overload or component failure.",
                        "layers": [
                            {
                                "id": "traffic-processing-limits",
                                "name": "Traffic processing limits",
                                "description": "Characterises usable capacity under an identified workload and enabled feature set.",
                                "findings": [
                                    {
                                        "id": "conditioned-capacity",
                                        "name": "Conditioned capacity",
                                        "description": "Record throughput, session limits and delay with enough conditions to interpret the measurements.",
                                        "questions": [
                                            {
                                                "text": "What throughput, concurrent-session count and new-session rate are supported with the required inspection features enabled?",
                                                "kind": "measurement",
                                                "id": "conditioned-capacity-q01"
                                            },
                                            {
                                                "text": "Under the expected packet and application mix, how do latency, drops and enforcement behaviour change near saturation?",
                                                "kind": "measurement",
                                                "id": "conditioned-capacity-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "failure-and-peer-takeover",
                                "name": "Failure and peer takeover",
                                "description": "Describes traffic outcomes when the appliance or an availability dependency fails.",
                                "findings": [
                                    {
                                        "id": "failure-specific-enforcement",
                                        "name": "Failure-specific enforcement",
                                        "description": "Record failure outcomes separately for power loss, interface loss, inspection-process failure and peer communication loss.",
                                        "questions": [
                                            {
                                                "text": "For each relevant failure, is traffic blocked, bypassed or transferred to a peer, and what evidence supports that outcome?",
                                                "kind": "measurement",
                                                "id": "failure-specific-enforcement-q01"
                                            },
                                            {
                                                "text": "Where a peer exists, which policy and session states are synchronised, and how is takeover tested without conflicting active enforcement?",
                                                "kind": "action",
                                                "id": "failure-specific-enforcement-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "enforcement-evidence-and-upkeep",
                        "name": "Enforcement evidence and upkeep",
                        "description": "Connects observed traffic decisions with the hardware, software and service dependencies needed to sustain inspection.",
                        "rationale": "Configured intent needs observable evidence, while maintenance can change the capabilities available to enforce it.",
                        "layers": [
                            {
                                "id": "decision-observability",
                                "name": "Decision observability",
                                "description": "Defines the evidence available to explain traffic handling and recognise gaps in visibility.",
                                "findings": [
                                    {
                                        "id": "traceable-traffic-decisions",
                                        "name": "Traceable traffic decisions",
                                        "description": "Record how logs, counters and captures associate traffic with the policy and enforcement state active at the time.",
                                        "questions": [
                                            {
                                                "text": "Which evidence links a permitted or blocked connection to a rule, timestamp and active configuration revision?",
                                                "kind": "provenance",
                                                "id": "traceable-traffic-decisions-q01"
                                            },
                                            {
                                                "text": "Which logging omissions, sampling, clock errors or export failures could prevent reconstruction of the decision?",
                                                "kind": "boundary",
                                                "id": "traceable-traffic-decisions-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "inspection-dependencies-and-maintenance",
                                "name": "Inspection dependencies and maintenance",
                                "description": "Tracks dependencies whose condition or expiry can change firewall operation.",
                                "findings": [
                                    {
                                        "id": "sustained-inspection-capability",
                                        "name": "Sustained inspection capability",
                                        "description": "Record applicable firmware, inspection updates, entitlements, certificates and physical service requirements.",
                                        "questions": [
                                            {
                                                "text": "Which inspection functions depend on subscriptions, external services, certificates or updates, and what happens when each becomes unavailable?",
                                                "kind": "boundary",
                                                "id": "sustained-inspection-capability-q01"
                                            },
                                            {
                                                "text": "What firmware and physical maintenance procedures preserve or restore the required enforcement configuration?",
                                                "kind": "action",
                                                "id": "sustained-inspection-capability-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "evidence-and-external-alignment",
                        "name": "Evidence and external alignment",
                        "description": "What the world already says about this thing, gathered so the model can be checked against it.",
                        "rationale": "A model that cannot be lined up against existing standards, identifiers and practice cannot be adopted by anyone who already uses them.",
                        "layers": [
                            {
                                "id": "reported-evidence",
                                "name": "Reported evidence",
                                "description": "Findings from the breadth pass, kept separate from the structural claims.",
                                "findings": [
                                    {
                                        "id": "evidence-confidence-notes",
                                        "name": "Check these first",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "The intended sense is unresolved: firewall can also mean a fire-resisting wall or a vehicle fire barrier. PHY.OBJ alone does not establish the network-appliance interpretation.",
                                            "The listed kinds overlap: inspection method and forwarding mode are independent characteristics.",
                                            "Throughput, concurrent connections, connection establishment rate and latency require product-specific figures and stated test conditions; no generic typical ranges are asserted."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-confidence-notes-q01",
                                                "text": "Which of these check these first hold for the sense of firewall this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-kinds",
                                        "name": "Kinds and varieties",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Packet-filtering firewall",
                                            "Stateful inspection firewall",
                                            "Application-proxy firewall",
                                            "Next-generation firewall",
                                            "Transparent bridge firewall",
                                            "Routed firewall"
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-kinds-q01",
                                                "text": "Which of these kinds and varieties hold for the sense of firewall this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-identifiers",
                                        "name": "Identifiers and schemes",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "scheme": "Manufacturer model and serial number",
                                                "value_or_pattern": "Vendor-specific model designation and unit serial number",
                                                "note": "The model identifies a product design; the serial number identifies an individual appliance."
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-identifiers-q01",
                                                "text": "Which of these identifiers and schemes hold for the sense of firewall this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-standards-and-regulation",
                                        "name": "Standards and regulation",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy - National Institute of Standards and Technology; guidance rather than a product certification.",
                                            "RFC 3511, Benchmarking Methodology for Firewall Performance - Internet Engineering Task Force."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-standards-and-regulation-q01",
                                                "text": "Which of these standards and regulation hold for the sense of firewall this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-real-world-use",
                                        "name": "Real-world use",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Controlling traffic between an organisation's internal network and the internet.",
                                            "Separating internal network segments with different security requirements.",
                                            "Restricting access to publicly exposed services in a demilitarised zone.",
                                            "Enforcing permitted communication paths between industrial network zones.",
                                            "Recording allowed and denied connections for operational investigation."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-real-world-use-q01",
                                                "text": "Which of these real-world use hold for the sense of firewall this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-failure-modes-and-hazards",
                                        "name": "Failure modes and hazards",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Overly permissive or incorrectly ordered rules allow unintended access.",
                                            "Incorrect rules block legitimate traffic and interrupt services.",
                                            "Exhaustion of connection tables or processing capacity causes dropped traffic or outages.",
                                            "Firmware vulnerabilities or compromised administration interfaces allow policy changes or device takeover.",
                                            "Fail-open behaviour or unintended bypass paths permit traffic without the intended inspection."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-failure-modes-and-hazards-q01",
                                                "text": "Which of these failure modes and hazards hold for the sense of firewall this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-neighbours",
                                        "name": "Neighbouring kinds and how to tell them apart",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "name": "Router",
                                                "difference": "A router primarily forwards packets between networks; a firewall primarily enforces traffic security policy, although one device can perform both functions."
                                            },
                                            {
                                                "name": "Intrusion detection system",
                                                "difference": "An intrusion detection system identifies and reports suspected attacks; a firewall directly permits or blocks traffic."
                                            },
                                            {
                                                "name": "Intrusion prevention system",
                                                "difference": "An intrusion prevention system blocks traffic based on detected attack patterns or behaviour; a firewall enforces access policy, with substantial overlap in combined products."
                                            },
                                            {
                                                "name": "Web application firewall",
                                                "difference": "A web application firewall specialises in HTTP application traffic and application-layer attacks; a general network firewall governs broader network communication."
                                            },
                                            {
                                                "name": "Building fire wall",
                                                "difference": "A building fire wall is a physical construction intended to restrict fire spread, not a network security device."
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-neighbours-q01",
                                                "text": "Which of these neighbouring kinds and how to tell them apart hold for the sense of firewall this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "openQuestions": [
                "Does vr.tr.firewall denote a network-security appliance, an architectural fire wall, or a broader firewall concept that requires a different boundary?",
                "Does an existing Vercy world model already own this concept, requiring a registry link instead of a separate model?",
                "Which capabilities are essential to the registered kind, and which belong only to optional multifunction-appliance variants?",
                "Which authoritative sources establish applicable security evaluations, certification schemes and physical appliance requirements, including their versions and limits?",
                "Which comparable sources can establish representative capacity ranges and failure behaviours without generalising from one product family?"
            ],
            "statistics": {
                "bundles": 6,
                "layers": 11,
                "findings": 17,
                "questions": 27
            }
        },
        "draft": {
            "generator": "vr.draft.v3",
            "status": "draft-generated",
            "researched": false,
            "archetype": "device, machine or tool",
            "method": "Written from the archetype playbook - what this kind of thing needs beyond identity and provenance - and from the structure that recurred across 6,333 models already researched by two engines. Applied to this entry by rule. No source was read for this thing and no claim here is researched. This entry carries no facets of its own, so they were inferred from its domain - a guess about a whole domain applied to one thing.",
            "facetsInferred": true,
            "nextPass": "A researcher replaces this draft with a sourced specification. Treat every sentence below as a proposal to argue with.",
            "purpose": "Give an agent a durable, checkable way to recognise a firewall, record what state it is in, and decide what may be done with it.",
            "whatItIs": "Enable an AI agent to recognise a physical network firewall, assess its traffic-control and operational state, and determine which inspections or changes are authorised.",
            "characteristics": {
                "substance": "material",
                "origin": "manufactured",
                "agency": "inert",
                "mobility": "varies"
            },
            "whatYouCanDoWithIt": [
                "observed and measured"
            ],
            "distinguishingFeatures": [
                "Names folded into this entry, which a task may need to split apart again: filtering network bridge, firewall software, Firewall as a service, FortiGate, genugate S revision 4.0, Clampd, next-generation firewall, stateful firewall, personal firewall, application firewall, Screened-subnet firewall, virtual firewall.",
                "13 finer distinctions are held as aliases rather than separate entries, because telling them apart needs a task that asks for it.",
                "Described in 80 Wikipedia languages, which is a measure of how widely the thing is known, not of how important it is."
            ],
            "openQuestionsForResearch": [
                "Which of the bundles below does a real task actually need, and which are ceremony?",
                "What does this thing have that the facets do not capture at all?",
                "Which neighbouring kind is most often confused with a firewall, and on what evidence are they told apart?"
            ],
            "whatItIsMadeOf": "matter you can touch",
            "physicalCharacter": [
                "Mobility varies between examples.",
                "Does nothing on its own; everything it does, something else did to it.",
                "These come from the domain this entry sits in rather than from the entry itself, so treat them as a first guess about the whole domain applied to one thing."
            ],
            "whatCanBeDoneWithIt": [
                "observe it, measure it, record its state"
            ],
            "howItIsRecognised": [
                "Recognised by form, by the arrangement of its controls, and by markings - a plate, a model number, a certification mark. Form alone rarely separates two models that do very different things."
            ],
            "relatedModels": [
                {
                    "relation": "covers",
                    "note": "Finer kinds folded into this entry because telling them apart needs a task that asks for it. Each is a model waiting to be split out when one does.",
                    "targets": [
                        "filtering network bridge",
                        "firewall software",
                        "Firewall as a service",
                        "FortiGate",
                        "genugate S revision 4.0",
                        "Clampd",
                        "next-generation firewall",
                        "stateful firewall",
                        "personal firewall",
                        "application firewall",
                        "Screened-subnet firewall",
                        "virtual firewall"
                    ]
                }
            ],
            "standing": "Described in 80 Wikipedia languages, which measures how widely it is written about rather than how important or how common it is. 13 finer distinctions are held inside this entry as names rather than as separate models.",
            "structure": {
                "bundles": [
                    {
                        "id": "identity-and-classification",
                        "name": "Identity, naming and classification",
                        "description": "How an agent tells one firewall from another, and a firewall from things that resemble it.",
                        "rationale": "Recognition comes before every other claim. Without stable identity nothing else in the model can be trusted to be about the same thing twice.",
                        "layers": [
                            {
                                "id": "naming-and-identifiers",
                                "name": "Names and identifiers",
                                "description": "The names this thing goes by and the identifiers that survive translation and time.",
                                "findings": [
                                    {
                                        "id": "preferred-name-and-aliases",
                                        "name": "Preferred name, aliases and local names",
                                        "description": "Which name to use, which names mean the same thing, and which merely sound similar.",
                                        "questions": [
                                            {
                                                "id": "preferred-name-and-aliases-q01",
                                                "text": "What identifies and describes the name of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q02",
                                                "text": "Who or what asserted this about the name of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q03",
                                                "text": "What may an agent decide or do once the name of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "stable-identifiers",
                                        "name": "Stable identifiers and external keys",
                                        "description": "Identifiers that keep pointing at this kind of thing across systems and languages.",
                                        "questions": [
                                            {
                                                "id": "stable-identifiers-q01",
                                                "text": "What identifies and describes an identifier for a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q02",
                                                "text": "Who or what asserted this about an identifier for a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q03",
                                                "text": "What may an agent decide or do once an identifier for a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "classification-and-granularity",
                                "name": "Classification and granularity",
                                "description": "Where a firewall sits among kinds, and how finely a task needs to cut it.",
                                "findings": [
                                    {
                                        "id": "kind-and-parents",
                                        "name": "Kind, parents and neighbouring kinds",
                                        "description": "The classes this thing belongs to and the ones it is next to.",
                                        "questions": [
                                            {
                                                "id": "kind-and-parents-q01",
                                                "text": "What identifies and describes the kind of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q02",
                                                "text": "Who or what asserted this about the kind of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q03",
                                                "text": "What may an agent decide or do once the kind of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "distinguishing-features",
                                        "name": "Distinguishing features",
                                        "description": "What separates a firewall from the things most often confused with it.",
                                        "questions": [
                                            {
                                                "id": "distinguishing-features-q01",
                                                "text": "What identifies and describes what distinguishes a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q02",
                                                "text": "Who or what asserted this about what distinguishes a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q03",
                                                "text": "What may an agent decide or do once what distinguishes a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "form-and-composition",
                        "name": "Form, composition and condition",
                        "description": "What a firewall is made of, what shape and size it takes, and what state it is in.",
                        "rationale": "A physical thing can be measured, and a model that cannot record its measurements cannot support any decision that depends on them.",
                        "layers": [
                            {
                                "id": "form-and-dimensions",
                                "name": "Form and dimensions",
                                "description": "Shape, size, mass and the ranges these take across examples.",
                                "findings": [
                                    {
                                        "id": "measurable-dimensions",
                                        "name": "Measurable dimensions and their units",
                                        "description": "The quantities worth recording and the units they are recorded in.",
                                        "questions": [
                                            {
                                                "id": "measurable-dimensions-q01",
                                                "text": "What identifies and describes the dimensions of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "measurable-dimensions-q02",
                                                "text": "Who or what asserted this about the dimensions of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "measurable-dimensions-q03",
                                                "text": "What may an agent decide or do once the dimensions of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "material-and-composition",
                                "name": "Material and composition",
                                "description": "Materials, parts and how they are put together.",
                                "findings": [
                                    {
                                        "id": "parts-and-materials",
                                        "name": "Parts and materials",
                                        "description": "What a firewall is built from and which parts are replaceable.",
                                        "questions": [
                                            {
                                                "id": "parts-and-materials-q01",
                                                "text": "What identifies and describes the composition of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "parts-and-materials-q02",
                                                "text": "Who or what asserted this about the composition of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "parts-and-materials-q03",
                                                "text": "What may an agent decide or do once the composition of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "condition-and-integrity",
                                "name": "Condition and integrity",
                                "description": "Wear, damage, health and the difference between working and broken.",
                                "findings": [
                                    {
                                        "id": "condition-assessment",
                                        "name": "Condition, damage and health",
                                        "description": "How the condition of a firewall is judged and by whom.",
                                        "questions": [
                                            {
                                                "id": "condition-assessment-q01",
                                                "text": "What identifies and describes the condition of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "condition-assessment-q02",
                                                "text": "Who or what asserted this about the condition of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "condition-assessment-q03",
                                                "text": "What may an agent decide or do once the condition of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "place-and-movement",
                        "name": "Place and movement",
                        "description": "Where a firewall is, how it got there and where it may go (varies).",
                        "rationale": "A thing that can move needs its position recorded with a time, or every later claim about it is about a place it has left.",
                        "layers": [
                            {
                                "id": "location-and-placement",
                                "name": "Location and placement",
                                "description": "Position, containment and the reference frame the position is given in.",
                                "findings": [
                                    {
                                        "id": "position-and-frame",
                                        "name": "Position, container and reference frame",
                                        "description": "Where a firewall is, and what that position is measured against.",
                                        "questions": [
                                            {
                                                "id": "position-and-frame-q01",
                                                "text": "What identifies and describes the location of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "position-and-frame-q02",
                                                "text": "Who or what asserted this about the location of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "position-and-frame-q03",
                                                "text": "What may an agent decide or do once the location of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "movement-and-transfer",
                                "name": "Movement and transfer",
                                "description": "How a firewall is carried, installed or relocated.",
                                "findings": [
                                    {
                                        "id": "movement-events",
                                        "name": "Movement events and constraints",
                                        "description": "What counts as a movement, what records it and what limits it.",
                                        "questions": [
                                            {
                                                "id": "movement-events-q01",
                                                "text": "What identifies and describes the movement of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "movement-events-q02",
                                                "text": "Who or what asserted this about the movement of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "movement-events-q03",
                                                "text": "What may an agent decide or do once the movement of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "state-and-lifecycle",
                        "name": "State and lifecycle",
                        "description": "The states a firewall passes through and the events that move it between them.",
                        "rationale": "Most decisions about a thing depend on what state it is in now, which is a claim with a time on it, not a property.",
                        "layers": [
                            {
                                "id": "lifecycle-stages",
                                "name": "Lifecycle stages",
                                "description": "From coming into existence to ceasing to be one of these.",
                                "findings": [
                                    {
                                        "id": "stages-and-transitions",
                                        "name": "Stages and transitions",
                                        "description": "The stages worth naming and what moves a firewall between them.",
                                        "questions": [
                                            {
                                                "id": "stages-and-transitions-q01",
                                                "text": "What identifies and describes the lifecycle of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q02",
                                                "text": "Who or what asserted this about the lifecycle of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q03",
                                                "text": "What may an agent decide or do once the lifecycle of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "observations-and-status",
                                "name": "Observations and current status",
                                "description": "What is observed about a firewall, how often and by whom.",
                                "findings": [
                                    {
                                        "id": "observation-record",
                                        "name": "Observation record",
                                        "description": "How an observation of a firewall is recorded so that it can be superseded rather than overwritten.",
                                        "questions": [
                                            {
                                                "id": "observation-record-q01",
                                                "text": "What identifies and describes an observation of a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q02",
                                                "text": "Who or what asserted this about an observation of a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q03",
                                                "text": "What may an agent decide or do once an observation of a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "function-and-principle",
                        "name": "Function and operating principle",
                        "description": "What firewall is for and how it achieves it.",
                        "rationale": "Two devices with the same name can work on different principles, and the principle is what predicts failure and constrains use.",
                        "layers": [
                            {
                                "id": "intended-function",
                                "name": "Intended function",
                                "description": "The job it does, and the jobs it is used for anyway.",
                                "findings": [
                                    {
                                        "id": "function-record",
                                        "name": "Function, principle and variants",
                                        "description": "What it does, how, and which variants do it differently.",
                                        "questions": [
                                            {
                                                "id": "function-record-q01",
                                                "text": "What function does firewall perform, on what operating principle, and which variants differ in that principle?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "function-record-q02",
                                                "text": "What use falls outside the intended function but happens in practice?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "capacity-and-rating",
                                "name": "Capacity and rating",
                                "description": "The numbers that say what it can do and where it stops.",
                                "findings": [
                                    {
                                        "id": "ratings",
                                        "name": "Ratings and their conditions",
                                        "description": "Rated capacity, power, throughput and the conditions each assumes.",
                                        "questions": [
                                            {
                                                "id": "ratings-q01",
                                                "text": "What ratings characterise firewall, in what units, and under what stated conditions?",
                                                "kind": "measurement"
                                            },
                                            {
                                                "id": "ratings-q02",
                                                "text": "What happens beyond the rating - degradation, refusal, damage - and how is that detected?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "operation-and-state",
                        "name": "Operation, controls and state",
                        "description": "How firewall is operated and what state it is in right now.",
                        "rationale": "An agent acting on a device needs its current state and the controls that change it, not just its specification.",
                        "layers": [
                            {
                                "id": "controls-and-modes",
                                "name": "Controls and modes",
                                "description": "What can be set, what that changes, and what is interlocked.",
                                "findings": [
                                    {
                                        "id": "control-surface",
                                        "name": "Control surface and interlocks",
                                        "description": "The settings available and the conditions that block them.",
                                        "questions": [
                                            {
                                                "id": "control-surface-q01",
                                                "text": "What controls and modes does firewall have, and what does each change?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "control-surface-q02",
                                                "text": "Which actions are interlocked or forbidden in which state, and what must be true before acting?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "condition-and-maintenance",
                                "name": "Condition and maintenance",
                                "description": "Wear, service intervals, consumables and the line between working and broken.",
                                "findings": [
                                    {
                                        "id": "service-record",
                                        "name": "Condition, service and consumables",
                                        "description": "What is consumed, what is serviced, and how condition is judged.",
                                        "questions": [
                                            {
                                                "id": "service-record-q01",
                                                "text": "What consumables and service does firewall need, at what interval, and on whose authority?",
                                                "kind": "measurement"
                                            },
                                            {
                                                "id": "service-record-q02",
                                                "text": "What evidence separates a unit that is working from one that is out of service?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "kind-model-unit",
                        "name": "Kind, model and unit",
                        "description": "Whether a claim about firewall is about the kind, a product line, or one physical unit.",
                        "rationale": "This is the boundary most often got wrong for made things, and getting it wrong mixes a catalogue entry with the machine in the yard.",
                        "layers": [
                            {
                                "id": "level-of-reference",
                                "name": "Level of reference",
                                "description": "The three levels and what belongs at each.",
                                "findings": [
                                    {
                                        "id": "level-rules",
                                        "name": "What belongs to kind, model and unit",
                                        "description": "Which properties are shared by all of them and which are not.",
                                        "questions": [
                                            {
                                                "id": "level-rules-q01",
                                                "text": "Which facts about firewall hold for every one of them, which for a model, and which only for one unit?",
                                                "kind": "boundary"
                                            },
                                            {
                                                "id": "level-rules-q02",
                                                "text": "What identifies an individual unit, and what should an agent do when it has only the kind?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "standards-and-conformity",
                                "name": "Standards and conformity",
                                "description": "The standards a working example must meet and who attests it.",
                                "findings": [
                                    {
                                        "id": "conformity",
                                        "name": "Standards, marks and attestation",
                                        "description": "Which standard applies, who certifies, and what the mark means.",
                                        "questions": [
                                            {
                                                "id": "conformity-q01",
                                                "text": "Which standards govern firewall, issued by whom, and what does conformity actually assert?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "id": "conformity-q02",
                                                "text": "What may an agent conclude from a certification mark, and what may it not?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "provenance-and-evidence",
                        "name": "Provenance, evidence and time",
                        "description": "Where every claim about a firewall came from and when it held.",
                        "rationale": "A claim without a source and a time cannot be superseded, only overwritten, and an agent that overwrites loses the ability to explain itself.",
                        "layers": [
                            {
                                "id": "source-and-authority",
                                "name": "Source and authority",
                                "description": "Who said it, on what evidence, and how strongly.",
                                "findings": [
                                    {
                                        "id": "claim-provenance",
                                        "name": "Claim provenance and confidence",
                                        "description": "The authority behind each claim about a firewall and how confident it is.",
                                        "questions": [
                                            {
                                                "id": "claim-provenance-q01",
                                                "text": "What identifies and describes a claim about a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q02",
                                                "text": "Who or what asserted this about a claim about a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q03",
                                                "text": "What may an agent decide or do once a claim about a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "time-and-versions",
                                "name": "Time, versions and supersession",
                                "description": "When a claim was true, when it was learnt, and what replaced it.",
                                "findings": [
                                    {
                                        "id": "validity-and-supersession",
                                        "name": "Validity period and supersession",
                                        "description": "How an old claim about a firewall is retired without being erased.",
                                        "questions": [
                                            {
                                                "id": "validity-and-supersession-q01",
                                                "text": "What identifies and describes the validity of a claim about a firewall, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q02",
                                                "text": "Who or what asserted this about the validity of a claim about a firewall, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q03",
                                                "text": "What may an agent decide or do once the validity of a claim about a firewall is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "statistics": {
                "bundles": 8,
                "layers": 17,
                "findings": 19,
                "questions": 51
            }
        }
    }
}