{
    "model": {
        "rank": 6263,
        "code": "thing-q849340",
        "model_id": "vr.tr.cyberwarfare",
        "name": "cyberwarfare",
        "purpose": "Enable an AI agent to recognise a proposed cyberwarfare activity, assess its evidence, effects and conflict context, and identify permissible defensive, analytical and governance actions.",
        "family": "Thing Registry",
        "category": "Activities and processes",
        "status": "research-draft",
        "kind": "thing",
        "plane": "ACT",
        "domain": "ACT.ACT",
        "industry": "",
        "version": "",
        "url": "/models/thing/q849340/",
        "tier": 2,
        "score": 61,
        "payload": {
            "layer": "wikidata",
            "aliases": [
                "cyberwarfare and China",
                "cyberwarfare by Russia"
            ],
            "aliasCount": 2,
            "merged": 2,
            "knownIn": 61,
            "facets": null,
            "markers": [],
            "lexicalClass": "",
            "senseRank": null,
            "alsoRegisteredAs": null,
            "source": {
                "dataset": "wikidata",
                "item": "Q849340",
                "url": "https://www.wikidata.org/wiki/Q849340",
                "license": "CC0 1.0"
            }
        },
        "research": {
            "vercy": "1.0-draft",
            "publication": {
                "status": "research-draft",
                "adjudicationStatus": "unreviewed",
                "publishableCanonical": false,
                "generatedAt": "2026-09-07T13:29:55Z",
                "providers": [
                    "Codex",
                    "Grok"
                ],
                "missingProviders": [],
                "pass": 2,
                "cost": {
                    "grok": {
                        "usd": 0.00221272,
                        "turns": 1,
                        "seconds": 29.4,
                        "error": null
                    },
                    "codex": {
                        "seconds": 72.1,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.3\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a07c0e-8f23-7d41-b7a0-88d5a9e73d5c\n--------\nuser\nYou are drafting a Vercy meta-model for one registered thing. Answer as JSON only, no prose around it.\n\nThing: cyberwarfare\nRegistry id: vr.tr.cyberwarfare\nPlane / domain: ACT / ACT.ACT\nRegistry definition: (none recorded)\nNames folded into this entry: (none)\n"
                    }
                }
            },
            "metaModel": {
                "id": "THING-Q849340",
                "registryId": "vr.tr.cyberwarfare",
                "name": "cyberwarfare",
                "version": "0.1.0-research.1",
                "entryKind": "thing",
                "family": "Thing Registry",
                "domain": [
                    "ACT.ACT"
                ],
                "status": "research-draft"
            },
            "canonicalUrl": "https://ver.cy/models/thing/q849340/",
            "model": {
                "registry_id": "vr.tr.cyberwarfare",
                "name": "cyberwarfare",
                "purpose": "Enable an AI agent to recognise a proposed cyberwarfare activity, assess its evidence, effects and conflict context, and identify permissible defensive, analytical and governance actions.",
                "definition": "Cyberwarfare is the use of cyber operations by a state, or by actors under state direction or substantial control, to achieve military or political objectives by disrupting, denying, degrading, or destroying an adversary's information systems, data, or dependent critical functions, typically as an instrument of armed conflict or coercion short of conventional force.",
                "scope_statement": "This model owns the characterisation of cyber operations as instruments of conflict, including contested classification, actor relationships, operational dependencies, effects, escalation and constraints on action; it links to separate models for actors, infrastructure, vulnerabilities, incidents and armed conflicts.",
                "in_scope": [
                    "The activity's relationship to strategic objectives, hostilities and other conflict operations",
                    "Evidence supporting or challenging its classification as cyberwarfare",
                    "Actor attribution, sponsorship, direction and degrees of uncertainty",
                    "Cyber-mediated effects on military, civilian and shared systems",
                    "Operational state, propagation, reversibility and escalation pathways",
                    "Authority, civilian protection and response constraints"
                ],
                "out_of_scope": [
                    "General cybercrime investigated without an established conflict nexus",
                    "Routine cybersecurity posture, patching and enterprise risk management",
                    "Vulnerability inventories, exploit implementations and malware construction",
                    "Actor biographies and organisational structures maintained in actor models",
                    "The complete history or legal classification of an armed conflict",
                    "Influence campaigns lacking a material connection to the cyber operations being modelled"
                ],
                "distinguishing_features": [
                    "Record evidence connecting the activity to conflict objectives; a politically charged target or severe outage alone does not establish cyberwarfare.",
                    "Establish that access to, manipulation of or disruption through digital systems materially contributes to the activity, rather than merely supporting communication about it.",
                    "Distinguish collection of information from disruption, manipulation or destruction, while leaving the classification of conflict-linked espionage explicit and contestable.",
                    "Separate evidence of an operator's technical involvement from evidence of state sponsorship, direction or control; one must not stand in for the other.",
                    "Distinguish a cyber incident from a coordinated conflict activity by testing for shared objectives, tasking, timing and relationships among operations."
                ],
                "characteristics": [
                    {
                        "name": "Conflict nexus",
                        "kind": "relation",
                        "unit_or_values": "Links to conflicts, hostilities or strategic confrontations, with supporting and contradicting evidence",
                        "why_it_matters": "Supports classification without assuming that every hostile cyber incident constitutes warfare."
                    },
                    {
                        "name": "Classification assessment",
                        "kind": "category",
                        "unit_or_values": "Proposed cyberwarfare; supported under a named definition; contested; excluded under a named definition; unresolved",
                        "why_it_matters": "Makes the governing definition and disagreement visible."
                    },
                    {
                        "name": "Attribution confidence",
                        "kind": "category",
                        "unit_or_values": "Unassessed; low; moderate; high, using an explicitly documented confidence rubric for each attribution claim",
                        "why_it_matters": "Prevents uncertain actor identification from becoming an assumed basis for consequential action."
                    },
                    {
                        "name": "Intended operational effect",
                        "kind": "category",
                        "unit_or_values": "Collection; disruption; denial; degradation; manipulation; destruction; mixed; unknown",
                        "why_it_matters": "Separates the claimed objective from observed outcomes and helps distinguish neighbouring activity types."
                    },
                    {
                        "name": "Operational phase",
                        "kind": "state",
                        "unit_or_values": "Suspected preparation; access established; effects underway; contained; recovering; dormant; terminated; unknown",
                        "why_it_matters": "Supports time-sensitive decisions while distinguishing loss of visibility from termination."
                    },
                    {
                        "name": "Service disruption duration",
                        "kind": "measurement",
                        "unit_or_values": "Hours per affected service, with observation window and uncertainty",
                        "why_it_matters": "Makes persistence of harm assessable without collapsing different services into one severity score."
                    },
                    {
                        "name": "Civilian dependency exposure",
                        "kind": "relation",
                        "unit_or_values": "Links from affected systems to civilian services, populations and shared infrastructure",
                        "why_it_matters": "Exposes indirect harm and dependencies that a target-only assessment would miss."
                    },
                    {
                        "name": "Recovery condition",
                        "kind": "state",
                        "unit_or_values": "Recoverable through restoration; requires replacement; partially recoverable; recovery unverified; unknown",
                        "why_it_matters": "Distinguishes temporary availability loss from persistent integrity damage or physical loss."
                    },
                    {
                        "name": "Response authority",
                        "kind": "relation",
                        "unit_or_values": "Links to responsible decision-makers, applicable mandates, permissions and prohibitions",
                        "why_it_matters": "Separates an agent's technical ability to act from its authority to do so."
                    }
                ],
                "affordances": [
                    "Assess whether an activity fits a stated cyberwarfare definition and expose competing interpretations.",
                    "Compare attribution hypotheses and identify evidence needed to resolve consequential uncertainty.",
                    "Trace observed and plausible downstream effects through military, civilian and shared service dependencies.",
                    "Track containment, restoration and recurrence against explicit evidence and completion criteria.",
                    "Evaluate proposed defensive or response actions against authority, civilian consequences and escalation concerns.",
                    "Prepare an evidence-linked assessment for human review, including unresolved classifications and decision limits."
                ]
            },
            "sources": [
                {
                    "id": "placeholder",
                    "title": "Research pending",
                    "url": "",
                    "what_it_supports": "Will be replaced after lookups"
                }
            ],
            "structure": {
                "bundles": [
                    {
                        "id": "conflict-characterisation",
                        "name": "Conflict characterisation",
                        "description": "Establishes what activity is being modelled and why a cyberwarfare classification is under consideration.",
                        "rationale": "Cyberwarfare cannot be identified reliably from technical compromise or disruption alone.",
                        "layers": [
                            {
                                "id": "classification-boundary",
                                "name": "Classification boundary",
                                "description": "Records the working definition and its application to the activity.",
                                "findings": [
                                    {
                                        "id": "cyberwarfare-classification-basis",
                                        "name": "Cyberwarfare classification basis",
                                        "description": "An assessment of which defining conditions are supported, contested or unobserved.",
                                        "questions": [
                                            {
                                                "text": "Which working definition of cyberwarfare is being applied, and which conditions does it require?",
                                                "kind": "definition",
                                                "id": "cyberwarfare-classification-basis-q01"
                                            },
                                            {
                                                "text": "What evidence distinguishes this activity from cybercrime, espionage, hacktivism or an unrelated technical failure?",
                                                "kind": "boundary",
                                                "id": "cyberwarfare-classification-basis-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "strategic-and-operational-nexus",
                                "name": "Strategic and operational nexus",
                                "description": "Connects the cyber activity to conflict objectives and related operations.",
                                "findings": [
                                    {
                                        "id": "conflict-objective-link",
                                        "name": "Conflict objective link",
                                        "description": "Records assessed objectives and evidence of coordination with a broader conflict effort.",
                                        "questions": [
                                            {
                                                "text": "What evidence links this operation to an identified conflict objective, and who supplied that evidence?",
                                                "kind": "provenance",
                                                "id": "conflict-objective-link-q01"
                                            },
                                            {
                                                "text": "Which related cyber or non-cyber operations belong to the same activity, and what establishes that boundary beyond coincident timing?",
                                                "kind": "boundary",
                                                "id": "conflict-objective-link-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "attribution-and-direction",
                        "name": "Attribution and direction",
                        "description": "Separates technical observations, operator identity and relationships to conflict parties.",
                        "rationale": "Misattribution or an unsupported inference of state direction can distort both classification and response.",
                        "layers": [
                            {
                                "id": "technical-attribution",
                                "name": "Technical attribution",
                                "description": "Captures the evidentiary basis and alternatives for identifying operators.",
                                "findings": [
                                    {
                                        "id": "operator-attribution-hypotheses",
                                        "name": "Operator attribution hypotheses",
                                        "description": "Maintains competing explanations for observed activity with evidence lineage and confidence.",
                                        "questions": [
                                            {
                                                "text": "Which observations support each operator hypothesis, and which reports repeat a common source rather than provide independent corroboration?",
                                                "kind": "provenance",
                                                "id": "operator-attribution-hypotheses-q01"
                                            },
                                            {
                                                "text": "How does confidence change when shared tooling, compromised infrastructure, deception or missing telemetry are considered?",
                                                "kind": "measurement",
                                                "id": "operator-attribution-hypotheses-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "sponsorship-and-control",
                                "name": "Sponsorship and control",
                                "description": "Examines relationships between operators, sponsors and conflict parties without conflating them.",
                                "findings": [
                                    {
                                        "id": "direction-relationship",
                                        "name": "Direction relationship",
                                        "description": "Distinguishes claimed affiliation, material support, tasking and operational control.",
                                        "questions": [
                                            {
                                                "text": "What evidence supports sponsorship, tasking or control separately from the operator's claimed allegiance?",
                                                "kind": "provenance",
                                                "id": "direction-relationship-q01"
                                            },
                                            {
                                                "text": "Which responsibility assessments remain unresolved if operator identity is supported but direction by a conflict party is not?",
                                                "kind": "boundary",
                                                "id": "direction-relationship-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "effects-and-civilian-dependencies",
                        "name": "Effects and civilian dependencies",
                        "description": "Relates intended and observed cyber effects to services, populations and recovery conditions.",
                        "rationale": "A compromised system does not by itself reveal the scale, distribution or persistence of harm.",
                        "layers": [
                            {
                                "id": "effect-assessment",
                                "name": "Effect assessment",
                                "description": "Separates operator intent, technical changes and demonstrated consequences.",
                                "findings": [
                                    {
                                        "id": "observed-effect-and-causation",
                                        "name": "Observed effect and causation",
                                        "description": "Records effects with causal evidence, baselines and uncertainty.",
                                        "questions": [
                                            {
                                                "text": "Which losses of availability, integrity, confidentiality or physical function were observed, over what duration and against what baseline?",
                                                "kind": "measurement",
                                                "id": "observed-effect-and-causation-q01"
                                            },
                                            {
                                                "text": "What evidence attributes these effects to the cyber operation rather than concurrent physical damage, operator error or unrelated failure?",
                                                "kind": "provenance",
                                                "id": "observed-effect-and-causation-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "shared-infrastructure-and-spillover",
                                "name": "Shared infrastructure and spillover",
                                "description": "Examines consequences beyond the initially affected systems.",
                                "findings": [
                                    {
                                        "id": "civilian-and-cross-border-effects",
                                        "name": "Civilian and cross-border effects",
                                        "description": "Maps shared dependencies, propagation and indirect harm, separating observed effects from scenarios.",
                                        "questions": [
                                            {
                                                "text": "Which civilian or third-party services depend on affected military or shared infrastructure, including outside the immediate conflict area?",
                                                "kind": "boundary",
                                                "id": "civilian-and-cross-border-effects-q01"
                                            },
                                            {
                                                "text": "Which downstream harms are observed, which are projected, and what assumptions determine their estimated extent?",
                                                "kind": "measurement",
                                                "id": "civilian-and-cross-border-effects-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "operational-state-and-response",
                        "name": "Operational state and response",
                        "description": "Supports decisions about continuing effects, recovery, authority and escalation.",
                        "rationale": "An agent needs explicit evidence of operational state and clear action limits before recommending or performing a response.",
                        "layers": [
                            {
                                "id": "containment-and-recovery",
                                "name": "Containment and recovery",
                                "description": "Tracks whether harmful activity has stopped and affected functions can be trusted again.",
                                "findings": [
                                    {
                                        "id": "cessation-and-restoration-evidence",
                                        "name": "Cessation and restoration evidence",
                                        "description": "Distinguishes apparent quiet, containment, removal of access and verified recovery.",
                                        "questions": [
                                            {
                                                "text": "What observations distinguish operational cessation from dormant access, adversary adaptation or loss of monitoring?",
                                                "kind": "measurement",
                                                "id": "cessation-and-restoration-evidence-q01"
                                            },
                                            {
                                                "text": "Which authorised containment and restoration actions protect essential services, preserve evidence and establish trustworthy recovery?",
                                                "kind": "action",
                                                "id": "cessation-and-restoration-evidence-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "authority-and-escalation",
                                "name": "Authority and escalation",
                                "description": "Records decision authority, applicable assessments and possible consequences of response.",
                                "findings": [
                                    {
                                        "id": "response-decision-envelope",
                                        "name": "Response decision envelope",
                                        "description": "Defines supported actions, required review and unresolved constraints without assuming a settled legal classification.",
                                        "questions": [
                                            {
                                                "text": "Who may authorise each proposed action, and which legal, policy and civilian-protection assessments must be resolved for that action?",
                                                "kind": "action",
                                                "id": "response-decision-envelope-q01"
                                            },
                                            {
                                                "text": "How could the proposed response affect shared infrastructure or be interpreted by conflict parties, and what uncertainty requires human review?",
                                                "kind": "action",
                                                "id": "response-decision-envelope-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "evidence-and-external-alignment",
                        "name": "Evidence and external alignment",
                        "description": "What the world already says about this thing, gathered so the model can be checked against it.",
                        "rationale": "A model that cannot be lined up against existing standards, identifiers and practice cannot be adopted by anyone who already uses them.",
                        "layers": [
                            {
                                "id": "reported-evidence",
                                "name": "Reported evidence",
                                "description": "Findings from the breadth pass, kept separate from the structural claims.",
                                "findings": [
                                    {
                                        "id": "evidence-kinds",
                                        "name": "Kinds and varieties",
                                        "description": "Reported by the breadth pass; each item needs checking against its source before it becomes normative.",
                                        "evidence": [
                                            "state-on-state offensive cyber operations against military C2 and weapons systems",
                                            "attacks on civilian critical infrastructure (energy, water, finance, transport, communications)",
                                            "intelligence-driven cyber espionage in support of military or political objectives",
                                            "information operations and influence campaigns delivered through cyber means",
                                            "cyber operations in support of kinetic campaigns (C4ISR disruption, air-defence suppression)",
                                            "denial and disruption (DDoS, wiper malware, ransomware used as a weapon)",
                                            "supply-chain and firmware/prepositioning operations against national systems",
                                            "proxy and deniable operations conducted by patriotic hackers, contractors, or APT groups under state control"
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-kinds-q01",
                                                "text": "Which of these kinds and varieties hold for the sense of cyberwarfare this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "openQuestions": [
                "Which authoritative definition should govern inclusion, particularly for cyber operations below an armed-conflict threshold?",
                "When should conflict-linked espionage, preparatory access and influence-support operations form part of a cyberwarfare activity rather than remain linked neighbouring activities?",
                "What evidence standards and confidence rubrics should distinguish operator attribution, sponsorship, direction and responsibility?",
                "How should civilian and cross-border consequences be assessed when dependency information, baselines or telemetry are incomplete?",
                "What criteria should determine the boundaries and end state of a cyberwarfare campaign when access persists across incidents and periods of apparent inactivity?"
            ],
            "statistics": {
                "bundles": 5,
                "layers": 9,
                "findings": 9,
                "questions": 17
            }
        },
        "draft": {
            "generator": "vr.draft.v3",
            "status": "draft-generated",
            "researched": false,
            "archetype": "abstract concept",
            "method": "Written from the archetype playbook - what this kind of thing needs beyond identity and provenance - and from the structure that recurred across 6,333 models already researched by two engines. Applied to this entry by rule. No source was read for this thing and no claim here is researched. This entry carries no facets of its own, so they were inferred from its domain - a guess about a whole domain applied to one thing.",
            "facetsInferred": true,
            "nextPass": "A researcher replaces this draft with a sourced specification. Treat every sentence below as a proposal to argue with.",
            "purpose": "Give an agent a durable, checkable way to recognise a cyberwarfare, record what state it is in, and decide what may be done with it.",
            "whatItIs": "Enable an AI agent to recognise a proposed cyberwarfare activity, assess its evidence, effects and conflict context, and identify permissible defensive, analytical and governance actions.",
            "characteristics": {
                "substance": "activity",
                "origin": "conceptual",
                "agency": "inert"
            },
            "whatYouCanDoWithIt": [
                "observed and measured"
            ],
            "distinguishingFeatures": [
                "Names folded into this entry, which a task may need to split apart again: cyberwarfare and China, cyberwarfare by Russia.",
                "2 finer distinctions are held as aliases rather than separate entries, because telling them apart needs a task that asks for it.",
                "Described in 61 Wikipedia languages, which is a measure of how widely the thing is known, not of how important it is."
            ],
            "openQuestionsForResearch": [
                "Which of the bundles below does a real task actually need, and which are ceremony?",
                "What does this thing have that the facets do not capture at all?",
                "Which neighbouring kind is most often confused with a cyberwarfare, and on what evidence are they told apart?"
            ],
            "whatItIsMadeOf": "something that happens over time",
            "physicalCharacter": [
                "Does nothing on its own; everything it does, something else did to it.",
                "These come from the domain this entry sits in rather than from the entry itself, so treat them as a first guess about the whole domain applied to one thing."
            ],
            "whatCanBeDoneWithIt": [
                "observe it, measure it, record its state"
            ],
            "howItIsRecognised": [
                "Nothing to see. What is recognised is an instance of it, and which instances count is exactly what is argued about."
            ],
            "relatedModels": [
                {
                    "relation": "covers",
                    "note": "Finer kinds folded into this entry because telling them apart needs a task that asks for it. Each is a model waiting to be split out when one does.",
                    "targets": [
                        "cyberwarfare and China",
                        "cyberwarfare by Russia"
                    ]
                }
            ],
            "standing": "Described in 61 Wikipedia languages, which measures how widely it is written about rather than how important or how common it is. 2 finer distinctions are held inside this entry as names rather than as separate models.",
            "structure": {
                "bundles": [
                    {
                        "id": "identity-and-classification",
                        "name": "Identity, naming and classification",
                        "description": "How an agent tells one cyberwarfare from another, and a cyberwarfare from things that resemble it.",
                        "rationale": "Recognition comes before every other claim. Without stable identity nothing else in the model can be trusted to be about the same thing twice.",
                        "layers": [
                            {
                                "id": "naming-and-identifiers",
                                "name": "Names and identifiers",
                                "description": "The names this thing goes by and the identifiers that survive translation and time.",
                                "findings": [
                                    {
                                        "id": "preferred-name-and-aliases",
                                        "name": "Preferred name, aliases and local names",
                                        "description": "Which name to use, which names mean the same thing, and which merely sound similar.",
                                        "questions": [
                                            {
                                                "id": "preferred-name-and-aliases-q01",
                                                "text": "What identifies and describes the name of a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q02",
                                                "text": "Who or what asserted this about the name of a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q03",
                                                "text": "What may an agent decide or do once the name of a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "stable-identifiers",
                                        "name": "Stable identifiers and external keys",
                                        "description": "Identifiers that keep pointing at this kind of thing across systems and languages.",
                                        "questions": [
                                            {
                                                "id": "stable-identifiers-q01",
                                                "text": "What identifies and describes an identifier for a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q02",
                                                "text": "Who or what asserted this about an identifier for a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q03",
                                                "text": "What may an agent decide or do once an identifier for a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "classification-and-granularity",
                                "name": "Classification and granularity",
                                "description": "Where a cyberwarfare sits among kinds, and how finely a task needs to cut it.",
                                "findings": [
                                    {
                                        "id": "kind-and-parents",
                                        "name": "Kind, parents and neighbouring kinds",
                                        "description": "The classes this thing belongs to and the ones it is next to.",
                                        "questions": [
                                            {
                                                "id": "kind-and-parents-q01",
                                                "text": "What identifies and describes the kind of a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q02",
                                                "text": "Who or what asserted this about the kind of a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q03",
                                                "text": "What may an agent decide or do once the kind of a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "distinguishing-features",
                                        "name": "Distinguishing features",
                                        "description": "What separates a cyberwarfare from the things most often confused with it.",
                                        "questions": [
                                            {
                                                "id": "distinguishing-features-q01",
                                                "text": "What identifies and describes what distinguishes a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q02",
                                                "text": "Who or what asserted this about what distinguishes a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q03",
                                                "text": "What may an agent decide or do once what distinguishes a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "state-and-lifecycle",
                        "name": "State and lifecycle",
                        "description": "The states a cyberwarfare passes through and the events that move it between them.",
                        "rationale": "Most decisions about a thing depend on what state it is in now, which is a claim with a time on it, not a property.",
                        "layers": [
                            {
                                "id": "lifecycle-stages",
                                "name": "Lifecycle stages",
                                "description": "From coming into existence to ceasing to be one of these.",
                                "findings": [
                                    {
                                        "id": "stages-and-transitions",
                                        "name": "Stages and transitions",
                                        "description": "The stages worth naming and what moves a cyberwarfare between them.",
                                        "questions": [
                                            {
                                                "id": "stages-and-transitions-q01",
                                                "text": "What identifies and describes the lifecycle of a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q02",
                                                "text": "Who or what asserted this about the lifecycle of a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q03",
                                                "text": "What may an agent decide or do once the lifecycle of a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "observations-and-status",
                                "name": "Observations and current status",
                                "description": "What is observed about a cyberwarfare, how often and by whom.",
                                "findings": [
                                    {
                                        "id": "observation-record",
                                        "name": "Observation record",
                                        "description": "How an observation of a cyberwarfare is recorded so that it can be superseded rather than overwritten.",
                                        "questions": [
                                            {
                                                "id": "observation-record-q01",
                                                "text": "What identifies and describes an observation of a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q02",
                                                "text": "Who or what asserted this about an observation of a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q03",
                                                "text": "What may an agent decide or do once an observation of a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "process-and-outcome",
                        "name": "Process, inputs and outcome",
                        "description": "How a cyberwarfare proceeds, what it needs and what it leaves behind.",
                        "rationale": "An activity is known by its steps and its results, and both have to be recordable while it is still running.",
                        "layers": [
                            {
                                "id": "steps-and-sequence",
                                "name": "Steps and sequence",
                                "description": "The steps of a cyberwarfare, their order and what may run in parallel.",
                                "findings": [
                                    {
                                        "id": "steps-and-preconditions",
                                        "name": "Steps, preconditions and completion",
                                        "description": "What has to be true before each step of a cyberwarfare and what marks it done.",
                                        "questions": [
                                            {
                                                "id": "steps-and-preconditions-q01",
                                                "text": "What identifies and describes a step of a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "steps-and-preconditions-q02",
                                                "text": "Who or what asserted this about a step of a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "steps-and-preconditions-q03",
                                                "text": "What may an agent decide or do once a step of a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "inputs-and-results",
                                "name": "Inputs, resources and results",
                                "description": "What a cyberwarfare consumes and what it produces.",
                                "findings": [
                                    {
                                        "id": "inputs-and-outputs",
                                        "name": "Inputs, outputs and side effects",
                                        "description": "The resources a cyberwarfare takes and the results it leaves, wanted or not.",
                                        "questions": [
                                            {
                                                "id": "inputs-and-outputs-q01",
                                                "text": "What identifies and describes the inputs and results of a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "inputs-and-outputs-q02",
                                                "text": "Who or what asserted this about the inputs and results of a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "inputs-and-outputs-q03",
                                                "text": "What may an agent decide or do once the inputs and results of a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "definitions-in-contest",
                        "name": "Definitions and who holds them",
                        "description": "What cyberwarfare is taken to mean, and by whom.",
                        "rationale": "When a field disagrees about a concept, the disagreement is the content. A model that picks one definition silently destroys the information.",
                        "layers": [
                            {
                                "id": "competing-definitions",
                                "name": "Competing definitions",
                                "description": "The main readings and the traditions behind them.",
                                "findings": [
                                    {
                                        "id": "definition-map",
                                        "name": "Definitions and their holders",
                                        "description": "Each definition with the school or body that holds it.",
                                        "questions": [
                                            {
                                                "id": "definition-map-q01",
                                                "text": "Which definitions of cyberwarfare are in use, and which tradition or body holds each?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "definition-map-q02",
                                                "text": "What turns on the difference between them in practice?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "operationalisation",
                                "name": "Operationalisation",
                                "description": "How it is measured or applied when it has to be.",
                                "findings": [
                                    {
                                        "id": "operational-record",
                                        "name": "Measures and proxies",
                                        "description": "Instruments and indicators used to stand in for it.",
                                        "questions": [
                                            {
                                                "id": "operational-record-q01",
                                                "text": "How is cyberwarfare operationalised or measured in practice, and by what instrument?",
                                                "kind": "measurement"
                                            },
                                            {
                                                "id": "operational-record-q02",
                                                "text": "What does that operationalisation leave out, and when does that matter?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "instances-and-use",
                        "name": "Instances, use and consequence",
                        "description": "What counts as an instance of cyberwarfare and what follows from calling something that.",
                        "rationale": "Applying a concept is an act with consequences, so a model must say what the label licenses and what it does not.",
                        "layers": [
                            {
                                "id": "instances",
                                "name": "What counts as an instance",
                                "description": "Clear cases, borderline cases and non-cases.",
                                "findings": [
                                    {
                                        "id": "instance-tests",
                                        "name": "Tests for an instance",
                                        "description": "What would settle whether something falls under it.",
                                        "questions": [
                                            {
                                                "id": "instance-tests-q01",
                                                "text": "What would settle whether something is an instance of cyberwarfare?",
                                                "kind": "boundary"
                                            },
                                            {
                                                "id": "instance-tests-q02",
                                                "text": "Which borderline cases are argued about, and on what grounds?",
                                                "kind": "definition"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "consequence",
                                "name": "Consequence of application",
                                "description": "Rights, duties or decisions that follow from the label.",
                                "findings": [
                                    {
                                        "id": "consequence-record",
                                        "name": "What the label licenses",
                                        "description": "What an agent may do once something is classified this way.",
                                        "questions": [
                                            {
                                                "id": "consequence-record-q01",
                                                "text": "What follows practically once something is treated as cyberwarfare?",
                                                "kind": "action"
                                            },
                                            {
                                                "id": "consequence-record-q02",
                                                "text": "What must an agent not infer from the label alone?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "provenance-and-evidence",
                        "name": "Provenance, evidence and time",
                        "description": "Where every claim about a cyberwarfare came from and when it held.",
                        "rationale": "A claim without a source and a time cannot be superseded, only overwritten, and an agent that overwrites loses the ability to explain itself.",
                        "layers": [
                            {
                                "id": "source-and-authority",
                                "name": "Source and authority",
                                "description": "Who said it, on what evidence, and how strongly.",
                                "findings": [
                                    {
                                        "id": "claim-provenance",
                                        "name": "Claim provenance and confidence",
                                        "description": "The authority behind each claim about a cyberwarfare and how confident it is.",
                                        "questions": [
                                            {
                                                "id": "claim-provenance-q01",
                                                "text": "What identifies and describes a claim about a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q02",
                                                "text": "Who or what asserted this about a claim about a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q03",
                                                "text": "What may an agent decide or do once a claim about a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "time-and-versions",
                                "name": "Time, versions and supersession",
                                "description": "When a claim was true, when it was learnt, and what replaced it.",
                                "findings": [
                                    {
                                        "id": "validity-and-supersession",
                                        "name": "Validity period and supersession",
                                        "description": "How an old claim about a cyberwarfare is retired without being erased.",
                                        "questions": [
                                            {
                                                "id": "validity-and-supersession-q01",
                                                "text": "What identifies and describes the validity of a claim about a cyberwarfare, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q02",
                                                "text": "Who or what asserted this about the validity of a claim about a cyberwarfare, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q03",
                                                "text": "What may an agent decide or do once the validity of a claim about a cyberwarfare is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "statistics": {
                "bundles": 6,
                "layers": 12,
                "findings": 14,
                "questions": 38
            }
        }
    }
}