{
    "model": {
        "rank": 4064,
        "code": "thing-q93249",
        "model_id": "vr.tr.antivirus-software",
        "name": "antivirus software",
        "purpose": "Enable an AI agent to recognise antivirus software, assess its protection state and limits, and determine which inspection or remediation actions are appropriate and authorised.",
        "family": "Thing Registry",
        "category": "Information and virtual systems",
        "status": "research-draft",
        "kind": "thing",
        "plane": "INF",
        "domain": "INF.MED",
        "industry": "",
        "version": "",
        "url": "/models/thing/q93249/",
        "tier": 2,
        "score": 78,
        "payload": {
            "layer": "wikidata",
            "aliases": [
                "Avira Free AntiVirus",
                "AntiVir PersonalEdition Premium",
                "Avira Antivirus Premium 2012"
            ],
            "aliasCount": 3,
            "merged": 3,
            "knownIn": 78,
            "facets": null,
            "markers": [],
            "lexicalClass": "",
            "senseRank": null,
            "alsoRegisteredAs": null,
            "source": {
                "dataset": "wikidata",
                "item": "Q93249",
                "url": "https://www.wikidata.org/wiki/Q93249",
                "license": "CC0 1.0"
            }
        },
        "research": {
            "vercy": "1.0-draft",
            "publication": {
                "status": "research-draft",
                "adjudicationStatus": "unreviewed",
                "publishableCanonical": false,
                "generatedAt": "2026-09-09T19:23:46Z",
                "providers": [
                    "Codex"
                ],
                "breadth": "recalled by Codex without web access - no source was read",
                "missingProviders": [],
                "pass": 2,
                "cost": {
                    "grok": {
                        "seconds": 25.1,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.4\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a0879f-4096-7d91-89a5-7163af6c2b68\n--------\nuser\nDescribe what is already known about one registered thing. Answer as JSON only, no prose around it.\n\nThing: antivirus software\nSense to describe: (none recorded)\nDomain code: INF.MED\nAlso known as: (none)\n\n\nContext for this batch of 695 things:\n# Batch 004: 10",
                        "usd": 0,
                        "recall": true
                    },
                    "codex": {
                        "seconds": 70.8,
                        "error": "Reading additional input from stdin...\nOpenAI Codex v0.153.4\n--------\nworkdir: R:\\02_PROJECTS\\02_Meta_Models_Platforms\\Ver.cy\\current\\thing-registry-backlog\nmodel: gpt-6-astra\nprovider: openai\napproval: never\nsandbox: read-only\nreasoning effort: none\nreasoning summaries: none\nsession id: 01a0879f-40a6-7cd0-a326-7a88b7dae3c9\n--------\nuser\nYou are drafting a Vercy meta-model for one registered thing. Answer as JSON only, no prose around it.\n\nThing: antivirus software\nRegistry id: vr.tr.antivirus-software\nPlane / domain: INF / INF.MED\nRegistry definition: (none recorded)\nNames folded into this en"
                    }
                }
            },
            "metaModel": {
                "id": "THING-Q93249",
                "registryId": "vr.tr.antivirus-software",
                "name": "antivirus software",
                "version": "0.1.0-research.1",
                "entryKind": "thing",
                "family": "Thing Registry",
                "domain": [
                    "INF.MED"
                ],
                "status": "research-draft"
            },
            "canonicalUrl": "https://ver.cy/models/thing/q93249/",
            "model": {
                "registry_id": "vr.tr.antivirus-software",
                "name": "antivirus software",
                "purpose": "Enable an AI agent to recognise antivirus software, assess its protection state and limits, and determine which inspection or remediation actions are appropriate and authorised.",
                "definition": "Antivirus software is security software designed to detect, block, quarantine or remove malicious software using techniques such as signature matching, heuristic analysis and behavioral monitoring.",
                "scope_statement": "This model owns antivirus software as a software product and its configured deployment for detecting, preventing, containing and remediating malicious software, distinguishing product capabilities from the protection actually operating on a particular device.",
                "in_scope": [
                    "Product, engine and deployment identity, including supported operating environments",
                    "Malware detection methods, inspection coverage and configured exclusions",
                    "Protection readiness, update freshness and dependencies",
                    "Detection verdicts, quarantine and remediation capabilities",
                    "Evidence of effectiveness, operational costs and privacy implications"
                ],
                "out_of_scope": [
                    "Malware families, samples and attack techniques as independently modelled threats",
                    "The protected device, operating system and its overall security posture",
                    "Network firewall policy and network intrusion detection outside antivirus functionality",
                    "Organisation-wide incident response, threat hunting and endpoint detection and response beyond antivirus functions",
                    "Backup services and general data recovery",
                    "Generic software licensing and distribution systems beyond their effects on antivirus operation"
                ],
                "distinguishing_features": [
                    "Provides functionality intended to identify or prevent malicious software; a generic file search or integrity checker alone does not qualify.",
                    "Produces malware-related verdicts or protection decisions using an identifiable inspection mechanism; a firewall that only filters connections does not qualify on that basis.",
                    "May operate on demand, continuously or both; absence of continuous monitoring distinguishes a deployment mode rather than automatically excluding the software.",
                    "When embedded in a security suite or endpoint platform, its malware inspection and handling functions can be identified separately from neighbouring functions.",
                    "A product's advertised capabilities and an installation's enabled, healthy protections are separate records."
                ],
                "characteristics": [
                    {
                        "name": "Product and engine identity",
                        "kind": "relation",
                        "unit_or_values": "Vendor, product, edition, product version and detection engine version",
                        "why_it_matters": "Links capabilities, support conditions and assessment evidence to the software actually deployed."
                    },
                    {
                        "name": "Protection mode",
                        "kind": "category",
                        "unit_or_values": "On-demand, scheduled, real-time or a documented combination",
                        "why_it_matters": "Determines when inspection occurs and which exposure periods remain."
                    },
                    {
                        "name": "Inspection coverage",
                        "kind": "category",
                        "unit_or_values": "Documented targets such as files, archives, memory, processes, scripts, boot areas or removable media",
                        "why_it_matters": "Prevents an agent from assuming that protection of one target implies protection of all targets."
                    },
                    {
                        "name": "Detection mechanisms",
                        "kind": "category",
                        "unit_or_values": "Documented mechanisms such as signatures, heuristics, behavioural analysis, reputation queries or model-based classification",
                        "why_it_matters": "Identifies what evidence the software uses and which dependencies or limitations must be investigated."
                    },
                    {
                        "name": "Operational protection state",
                        "kind": "state",
                        "unit_or_values": "Active, partially active, disabled, failed or unknown, with observation time and component detail",
                        "why_it_matters": "Installation alone does not establish that protection is operating."
                    },
                    {
                        "name": "Protection update age",
                        "kind": "measurement",
                        "unit_or_values": "Elapsed hours since each relevant engine, signature or detection-content update; unknown where unavailable",
                        "why_it_matters": "Supports freshness assessment against the product's update model and applicable policy."
                    },
                    {
                        "name": "Exclusion configuration",
                        "kind": "relation",
                        "unit_or_values": "Excluded paths, processes, file types or other targets, with matching semantics and approving authority",
                        "why_it_matters": "Makes deliberate inspection gaps visible and reviewable."
                    },
                    {
                        "name": "Permitted response actions",
                        "kind": "category",
                        "unit_or_values": "Report, block, terminate, quarantine, disinfect, delete or restore, as supported and authorised",
                        "why_it_matters": "Separates technical capability from permission to change the protected system."
                    },
                    {
                        "name": "Evaluation evidence",
                        "kind": "relation",
                        "unit_or_values": "Test report linked to product version, settings, platform, date, workload and threat set",
                        "why_it_matters": "Keeps effectiveness and performance claims tied to the conditions under which they were measured."
                    }
                ],
                "affordances": [
                    "Inspect enabled protection components, health signals and update status.",
                    "Run an authorised scan with explicit targets, resource limits and handling policy.",
                    "Update protection components and verify that the update became active.",
                    "Review detections and supporting evidence before selecting a response.",
                    "Quarantine, remediate or restore an item when supported and authorised, recording the outcome.",
                    "Review exclusions and protection settings against the device's intended use and applicable policy."
                ]
            },
            "sources": [],
            "structure": {
                "bundles": [
                    {
                        "id": "antivirus-identity-and-boundaries",
                        "name": "Antivirus identity and boundaries",
                        "description": "Establishes which antivirus software is represented and separates its functions from the surrounding security platform.",
                        "rationale": "An agent must identify the actual engine and deployment before applying capability claims or taking protection actions.",
                        "layers": [
                            {
                                "id": "product-and-engine",
                                "name": "Product and engine",
                                "description": "Identifies the product offering and the malware inspection implementation it uses.",
                                "findings": [
                                    {
                                        "id": "identifiable-antivirus-component",
                                        "name": "Identifiable antivirus component",
                                        "description": "Record the product, edition and engine identities, including any separately supplied inspection component.",
                                        "questions": [
                                            {
                                                "text": "Which product, edition and engine versions identify this antivirus implementation?",
                                                "kind": "definition",
                                                "id": "identifiable-antivirus-component-q01"
                                            },
                                            {
                                                "text": "Which vendor documentation or installed-component evidence establishes these identities?",
                                                "kind": "provenance",
                                                "id": "identifiable-antivirus-component-q02"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "deployment-and-functional-boundary",
                                "name": "Deployment and functional boundary",
                                "description": "Connects the antivirus component to its installation and identifies neighbouring security functions.",
                                "findings": [
                                    {
                                        "id": "deployed-protection-boundary",
                                        "name": "Deployed protection boundary",
                                        "description": "Distinguish the antivirus installation, its protected environment and its management service from broader endpoint or network security functions.",
                                        "questions": [
                                            {
                                                "text": "Which device or execution environment hosts this installation, and which management service controls it?",
                                                "kind": "definition",
                                                "id": "deployed-protection-boundary-q01"
                                            },
                                            {
                                                "text": "Which functions belong to antivirus protection, and which belong to firewall, endpoint investigation or other neighbouring models?",
                                                "kind": "boundary",
                                                "id": "deployed-protection-boundary-q02"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "malware-inspection-and-verdicts",
                        "name": "Malware inspection and verdicts",
                        "description": "Describes what the software can inspect and how its detection results should be interpreted.",
                        "rationale": "Protection coverage and verdict meaning must be explicit to avoid treating uninspected content or an uncertain result as safe.",
                        "layers": [
                            {
                                "id": "inspection-targets-and-gaps",
                                "name": "Inspection targets and gaps",
                                "description": "Records supported inspection targets and limits that prevent their examination.",
                                "findings": [
                                    {
                                        "id": "effective-inspection-coverage",
                                        "name": "Effective inspection coverage",
                                        "description": "Record enabled inspection targets alongside exclusions, access restrictions and limits on encrypted, nested or oversized content.",
                                        "questions": [
                                            {
                                                "text": "Which file, archive, memory, process, script or boot targets can this deployment actually inspect?",
                                                "kind": "boundary",
                                                "id": "effective-inspection-coverage-q01"
                                            },
                                            {
                                                "text": "Which exclusions, permission failures or content limits cause inspection to be skipped or incomplete?",
                                                "kind": "measurement",
                                                "id": "effective-inspection-coverage-q02"
                                            },
                                            {
                                                "text": "How does the software expose skipped and incompletely inspected targets to an agent?",
                                                "kind": "definition",
                                                "id": "effective-inspection-coverage-q03"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "detection-evidence-and-semantics",
                                "name": "Detection evidence and semantics",
                                "description": "Connects detection mechanisms to the meanings and limitations of reported verdicts.",
                                "findings": [
                                    {
                                        "id": "interpretable-malware-verdict",
                                        "name": "Interpretable malware verdict",
                                        "description": "Preserve the reported classification, inspection context and supporting evidence without equating every alert with confirmed malware.",
                                        "questions": [
                                            {
                                                "text": "Which documented mechanisms contribute to this verdict, and what evidence does the product expose?",
                                                "kind": "provenance",
                                                "id": "interpretable-malware-verdict-q01"
                                            },
                                            {
                                                "text": "How are malware, suspicious content, potentially unwanted software, inspection failure and no detection distinguished?",
                                                "kind": "definition",
                                                "id": "interpretable-malware-verdict-q02"
                                            },
                                            {
                                                "text": "What additional evidence is required before acting on an ambiguous or disputed detection?",
                                                "kind": "action",
                                                "id": "interpretable-malware-verdict-q03"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "protection-readiness-and-maintenance",
                        "name": "Protection readiness and maintenance",
                        "description": "Captures whether configured protection is operating and receiving the resources it needs.",
                        "rationale": "A present or recently updated installation may still provide incomplete protection because components, permissions or dependencies have failed.",
                        "layers": [
                            {
                                "id": "runtime-protection-health",
                                "name": "Runtime protection health",
                                "description": "Evaluates the operating state of enabled protection components and scheduled inspection.",
                                "findings": [
                                    {
                                        "id": "verified-protection-operation",
                                        "name": "Verified protection operation",
                                        "description": "Record component health, real-time protection state and scan completion evidence with timestamps.",
                                        "questions": [
                                            {
                                                "text": "Which health signals show that enabled protection components are operating rather than merely installed?",
                                                "kind": "measurement",
                                                "id": "verified-protection-operation-q01"
                                            },
                                            {
                                                "text": "When did each required scan last complete, and which targets or errors remained unresolved?",
                                                "kind": "measurement",
                                                "id": "verified-protection-operation-q02"
                                            },
                                            {
                                                "text": "Which supported recovery action applies when a component stops or a required scan repeatedly fails?",
                                                "kind": "action",
                                                "id": "verified-protection-operation-q03"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "updates-and-service-dependencies",
                                "name": "Updates and service dependencies",
                                "description": "Tracks protection updates and dependencies on support, subscriptions and remote services.",
                                "findings": [
                                    {
                                        "id": "maintained-detection-capability",
                                        "name": "Maintained detection capability",
                                        "description": "Record update freshness and identify which protection functions degrade when updates or external services are unavailable.",
                                        "questions": [
                                            {
                                                "text": "When were the engine and applicable detection contents last successfully updated and activated?",
                                                "kind": "measurement",
                                                "id": "maintained-detection-capability-q01"
                                            },
                                            {
                                                "text": "Which functions depend on connectivity, an active entitlement or continued support for this operating environment?",
                                                "kind": "boundary",
                                                "id": "maintained-detection-capability-q02"
                                            },
                                            {
                                                "text": "What documented freshness criteria and recovery steps apply when updates or remote lookups fail?",
                                                "kind": "action",
                                                "id": "maintained-detection-capability-q03"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "detection-response-and-recovery",
                        "name": "Detection response and recovery",
                        "description": "Models the handling of detected items from initial response through verification or restoration.",
                        "rationale": "Antivirus actions can interrupt workloads or remove needed data, so an agent needs explicit authority, item identity and outcome evidence.",
                        "layers": [
                            {
                                "id": "response-policy-and-authority",
                                "name": "Response policy and authority",
                                "description": "Separates available handling mechanisms from the actions permitted for a particular detection.",
                                "findings": [
                                    {
                                        "id": "authorised-detection-handling",
                                        "name": "Authorised detection handling",
                                        "description": "Associate each response with the detected item, applicable policy, approving authority and expected operational effect.",
                                        "questions": [
                                            {
                                                "text": "Which response actions are supported for this detection and target type?",
                                                "kind": "definition",
                                                "id": "authorised-detection-handling-q01"
                                            },
                                            {
                                                "text": "Which actions may the agent execute automatically, and which require approval under the applicable policy?",
                                                "kind": "action",
                                                "id": "authorised-detection-handling-q02"
                                            },
                                            {
                                                "text": "Which running processes, shared files or essential services could the proposed response affect?",
                                                "kind": "boundary",
                                                "id": "authorised-detection-handling-q03"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "quarantine-and-remediation-outcomes",
                                "name": "Quarantine and remediation outcomes",
                                "description": "Tracks isolated items, completed remediation and conditions for restoration.",
                                "findings": [
                                    {
                                        "id": "traceable-remediation-and-restoration",
                                        "name": "Traceable remediation and restoration",
                                        "description": "Preserve original item identity and location, response results, residual concerns and the evidence supporting any restoration.",
                                        "questions": [
                                            {
                                                "text": "What evidence confirms that blocking, quarantine or remediation succeeded, and what remains unresolved?",
                                                "kind": "measurement",
                                                "id": "traceable-remediation-and-restoration-q01"
                                            },
                                            {
                                                "text": "How is a quarantined item linked to its original location, detection evidence and retention conditions?",
                                                "kind": "provenance",
                                                "id": "traceable-remediation-and-restoration-q02"
                                            },
                                            {
                                                "text": "What review and authorisation are required to restore an item or reverse a false-positive response?",
                                                "kind": "action",
                                                "id": "traceable-remediation-and-restoration-q03"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "effectiveness-and-operational-tradeoffs",
                        "name": "Effectiveness and operational tradeoffs",
                        "description": "Assesses evidence for protection quality alongside performance, compatibility and data handling.",
                        "rationale": "An agent must judge whether protection is suitable for the actual workload without generalising beyond test evidence or ignoring its operational effects.",
                        "layers": [
                            {
                                "id": "protection-quality-evidence",
                                "name": "Protection quality evidence",
                                "description": "Records bounded evaluation results for detection, prevention and false positives.",
                                "findings": [
                                    {
                                        "id": "contextualised-effectiveness-results",
                                        "name": "Contextualised effectiveness results",
                                        "description": "Bind each reported result to its test population, date, version, configuration and outcome definition.",
                                        "questions": [
                                            {
                                                "text": "Which inspected reports support effectiveness claims for the relevant version and configuration?",
                                                "kind": "provenance",
                                                "id": "contextualised-effectiveness-results-q01"
                                            },
                                            {
                                                "text": "How were detection, successful prevention and false-positive rates measured, including their denominators?",
                                                "kind": "measurement",
                                                "id": "contextualised-effectiveness-results-q02"
                                            },
                                            {
                                                "text": "Which threats and operating conditions were outside the evaluation and therefore remain unassessed?",
                                                "kind": "boundary",
                                                "id": "contextualised-effectiveness-results-q03"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "workload-fit-and-data-handling",
                                "name": "Workload fit and data handling",
                                "description": "Examines inspection overhead, coexistence requirements and information sent outside the protected device.",
                                "findings": [
                                    {
                                        "id": "acceptable-protection-footprint",
                                        "name": "Acceptable protection footprint",
                                        "description": "Record workload impact, compatibility evidence and remote data flows before changing protection settings.",
                                        "questions": [
                                            {
                                                "text": "What CPU, memory, storage I/O and application-latency effects occur during representative scans and real-time inspection?",
                                                "kind": "measurement",
                                                "id": "acceptable-protection-footprint-q01"
                                            },
                                            {
                                                "text": "Which compatibility or coexistence requirements constrain use with other security software and critical applications?",
                                                "kind": "boundary",
                                                "id": "acceptable-protection-footprint-q02"
                                            },
                                            {
                                                "text": "Which samples, file metadata or telemetry may leave the device, and which controls and permissions govern that transfer?",
                                                "kind": "action",
                                                "id": "acceptable-protection-footprint-q03"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "evidence-and-external-alignment",
                        "name": "Evidence and external alignment",
                        "description": "What the world already says about this thing, gathered so the model can be checked against it.",
                        "rationale": "A model that cannot be lined up against existing standards, identifiers and practice cannot be adopted by anyone who already uses them.",
                        "layers": [
                            {
                                "id": "reported-evidence",
                                "name": "Reported evidence",
                                "description": "Findings from the breadth pass, kept separate from the structural claims.",
                                "findings": [
                                    {
                                        "id": "evidence-confidence-notes",
                                        "name": "Check these first",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "This describes the functional software category, rather than a particular product, release, licensed copy or installation.",
                                            "Standards are recalled references, not verified citations; applicability and edition-specific requirements need checking.",
                                            "No universal typical detection rate or false-positive rate is defensible without specifying testing methodology, samples, configuration and date."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-confidence-notes-q01",
                                                "text": "Which of these check these first hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-kinds",
                                        "name": "Kinds and varieties",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Real-time endpoint protection",
                                            "On-demand malware scanners",
                                            "Centrally managed enterprise antivirus",
                                            "Gateway antivirus for email or file traffic",
                                            "Bootable rescue scanners"
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-kinds-q01",
                                                "text": "Which of these kinds and varieties hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-identifiers",
                                        "name": "Identifiers and schemes",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "scheme": "Common Platform Enumeration (CPE)",
                                                "value_or_pattern": "cpe:2.3:a:<vendor>:<product>:<version>:...",
                                                "note": "Identifies particular antivirus software products and versions, where catalogued; it does not identify the general concept."
                                            },
                                            {
                                                "scheme": "Cryptographic file hash",
                                                "value_or_pattern": "SHA-256: 64 hexadecimal characters",
                                                "note": "Identifies an exact installer, executable or malware sample by its bytes, rather than identifying a product across versions."
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-identifiers-q01",
                                                "text": "Which of these identifiers and schemes hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-standards-and-regulation",
                                        "name": "Standards and regulation",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "NIST SP 800-53, control SI-3, Malicious Code Protection - issued by the US National Institute of Standards and Technology.",
                                            "ISO/IEC 27002 - issued by ISO and IEC; includes guidance on protection against malware."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-standards-and-regulation-q01",
                                                "text": "Which of these standards and regulation hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-real-world-use",
                                        "name": "Real-world use",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Scanning downloaded files, attachments and removable media before execution or opening.",
                                            "Monitoring endpoints for malicious files and suspicious execution behavior.",
                                            "Quarantining or removing detected malware during incident response.",
                                            "Applying centrally managed protection policies and collecting detection reports across organizational devices.",
                                            "Scanning a compromised system from a separate recovery environment."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-real-world-use-q01",
                                                "text": "Which of these real-world use hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-measurements",
                                        "name": "Typical measurements",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "quantity": "Detection rate",
                                                "typical_range": "0-100 by definition; observed results depend on the test corpus and conditions.",
                                                "unit": "%"
                                            },
                                            {
                                                "quantity": "False-positive rate",
                                                "typical_range": "0-100 by definition; meaningful comparison requires a specified benign test corpus.",
                                                "unit": "%"
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-measurements-q01",
                                                "text": "Which of these typical measurements hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-failure-modes-and-hazards",
                                        "name": "Failure modes and hazards",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Missing new, obfuscated or otherwise evasive malware.",
                                            "Misclassifying legitimate software as malicious and disrupting work through blocking or quarantine.",
                                            "Losing protection because updates fail, protection is disabled or configuration is inadequate.",
                                            "Increasing resource consumption or causing compatibility problems with applications and other security software.",
                                            "Introducing vulnerabilities through privileged scanning components that process attacker-controlled files."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-failure-modes-and-hazards-q01",
                                                "text": "Which of these failure modes and hazards hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-regional-variation",
                                        "name": "Regional variation",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            "Rules governing telemetry, sample submission and cross-border data transfers can affect cloud-assisted scanning deployments.",
                                            "Government procurement restrictions and approved-product requirements can affect which antivirus products organizations may deploy."
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-regional-variation-q01",
                                                "text": "Which of these regional variation hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    },
                                    {
                                        "id": "evidence-neighbours",
                                        "name": "Neighbouring kinds and how to tell them apart",
                                        "description": "Recalled without web access and unsourced; every item is a lead to verify.",
                                        "evidence": [
                                            {
                                                "name": "Anti-malware software",
                                                "difference": "The terms substantially overlap in modern usage; antivirus historically emphasized viruses, while anti-malware explicitly names the broader threat category."
                                            },
                                            {
                                                "name": "Endpoint detection and response",
                                                "difference": "EDR emphasizes endpoint telemetry, investigation and response workflows; antivirus emphasizes malware detection and prevention, although suites combine them."
                                            },
                                            {
                                                "name": "Firewall",
                                                "difference": "A firewall controls network traffic according to policy; antivirus evaluates files or execution behavior for malicious content or activity."
                                            },
                                            {
                                                "name": "Computer virus",
                                                "difference": "A virus is malicious code that replicates by infecting other code or host objects; antivirus is software intended to defend against malware."
                                            },
                                            {
                                                "name": "Antivirus software installation",
                                                "difference": "An installation is a deployed instance with a particular version, configuration and update state; the registered thing here is the software category."
                                            }
                                        ],
                                        "questions": [
                                            {
                                                "id": "evidence-neighbours-q01",
                                                "text": "Which of these neighbouring kinds and how to tell them apart hold for the sense of antivirus software this model covers, and on what evidence?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "openQuestions": [
                "Does the existing world-model catalogue already cover antivirus software, requiring this registry entry to link to that publication?",
                "Should this entry include gateway and server-side antivirus implementations, and what deployment-specific extensions would they require?",
                "Which primary sources establish a useful common vocabulary for verdicts and remediation outcomes across products?",
                "How should protection readiness be assessed for products whose detection capability depends substantially on remote services rather than locally versioned detection content?",
                "Which evaluation evidence and workload-specific thresholds are sufficient to judge effectiveness, false-positive burden and performance acceptability?"
            ],
            "statistics": {
                "bundles": 6,
                "layers": 11,
                "findings": 19,
                "questions": 37
            }
        },
        "draft": {
            "generator": "vr.draft.v3",
            "status": "draft-generated",
            "researched": false,
            "archetype": "work, medium or creative form",
            "method": "Written from the archetype playbook - what this kind of thing needs beyond identity and provenance - and from the structure that recurred across 6,333 models already researched by two engines. Applied to this entry by rule. No source was read for this thing and no claim here is researched. This entry carries no facets of its own, so they were inferred from its domain - a guess about a whole domain applied to one thing.",
            "facetsInferred": true,
            "nextPass": "A researcher replaces this draft with a sourced specification. Treat every sentence below as a proposal to argue with.",
            "purpose": "Give an agent a durable, checkable way to recognise a antivirus software, record what state it is in, and decide what may be done with it.",
            "whatItIs": "Enable an AI agent to recognise antivirus software, assess its protection state and limits, and determine which inspection or remediation actions are appropriate and authorised.",
            "characteristics": {
                "substance": "information",
                "origin": "conceptual",
                "agency": "inert"
            },
            "whatYouCanDoWithIt": [
                "read and interpreted",
                "observed and measured"
            ],
            "distinguishingFeatures": [
                "Names folded into this entry, which a task may need to split apart again: Avira Free AntiVirus, AntiVir PersonalEdition Premium, Avira Antivirus Premium 2012.",
                "3 finer distinctions are held as aliases rather than separate entries, because telling them apart needs a task that asks for it.",
                "Described in 78 Wikipedia languages, which is a measure of how widely the thing is known, not of how important it is."
            ],
            "openQuestionsForResearch": [
                "Which of the bundles below does a real task actually need, and which are ceremony?",
                "What does this thing have that the facets do not capture at all?",
                "Which neighbouring kind is most often confused with a antivirus software, and on what evidence are they told apart?"
            ],
            "whatItIsMadeOf": "content that has to be carried by something else",
            "physicalCharacter": [
                "Does nothing on its own; everything it does, something else did to it.",
                "These come from the domain this entry sits in rather than from the entry itself, so treat them as a first guess about the whole domain applied to one thing."
            ],
            "whatCanBeDoneWithIt": [
                "read it and act on what it says",
                "observe it, measure it, record its state"
            ],
            "howItIsRecognised": [
                "What is seen is a copy or a performance, not the work. Recognising the work means recognising the content through whatever is carrying it."
            ],
            "relatedModels": [
                {
                    "relation": "covers",
                    "note": "Finer kinds folded into this entry because telling them apart needs a task that asks for it. Each is a model waiting to be split out when one does.",
                    "targets": [
                        "Avira Free AntiVirus",
                        "AntiVir PersonalEdition Premium",
                        "Avira Antivirus Premium 2012"
                    ]
                }
            ],
            "standing": "Described in 78 Wikipedia languages, which measures how widely it is written about rather than how important or how common it is. 3 finer distinctions are held inside this entry as names rather than as separate models.",
            "structure": {
                "bundles": [
                    {
                        "id": "identity-and-classification",
                        "name": "Identity, naming and classification",
                        "description": "How an agent tells one antivirus software from another, and a antivirus software from things that resemble it.",
                        "rationale": "Recognition comes before every other claim. Without stable identity nothing else in the model can be trusted to be about the same thing twice.",
                        "layers": [
                            {
                                "id": "naming-and-identifiers",
                                "name": "Names and identifiers",
                                "description": "The names this thing goes by and the identifiers that survive translation and time.",
                                "findings": [
                                    {
                                        "id": "preferred-name-and-aliases",
                                        "name": "Preferred name, aliases and local names",
                                        "description": "Which name to use, which names mean the same thing, and which merely sound similar.",
                                        "questions": [
                                            {
                                                "id": "preferred-name-and-aliases-q01",
                                                "text": "What identifies and describes the name of a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q02",
                                                "text": "Who or what asserted this about the name of a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "preferred-name-and-aliases-q03",
                                                "text": "What may an agent decide or do once the name of a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "stable-identifiers",
                                        "name": "Stable identifiers and external keys",
                                        "description": "Identifiers that keep pointing at this kind of thing across systems and languages.",
                                        "questions": [
                                            {
                                                "id": "stable-identifiers-q01",
                                                "text": "What identifies and describes an identifier for a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q02",
                                                "text": "Who or what asserted this about an identifier for a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stable-identifiers-q03",
                                                "text": "What may an agent decide or do once an identifier for a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "classification-and-granularity",
                                "name": "Classification and granularity",
                                "description": "Where a antivirus software sits among kinds, and how finely a task needs to cut it.",
                                "findings": [
                                    {
                                        "id": "kind-and-parents",
                                        "name": "Kind, parents and neighbouring kinds",
                                        "description": "The classes this thing belongs to and the ones it is next to.",
                                        "questions": [
                                            {
                                                "id": "kind-and-parents-q01",
                                                "text": "What identifies and describes the kind of a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q02",
                                                "text": "Who or what asserted this about the kind of a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "kind-and-parents-q03",
                                                "text": "What may an agent decide or do once the kind of a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    },
                                    {
                                        "id": "distinguishing-features",
                                        "name": "Distinguishing features",
                                        "description": "What separates a antivirus software from the things most often confused with it.",
                                        "questions": [
                                            {
                                                "id": "distinguishing-features-q01",
                                                "text": "What identifies and describes what distinguishes a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q02",
                                                "text": "Who or what asserted this about what distinguishes a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "distinguishing-features-q03",
                                                "text": "What may an agent decide or do once what distinguishes a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "state-and-lifecycle",
                        "name": "State and lifecycle",
                        "description": "The states a antivirus software passes through and the events that move it between them.",
                        "rationale": "Most decisions about a thing depend on what state it is in now, which is a claim with a time on it, not a property.",
                        "layers": [
                            {
                                "id": "lifecycle-stages",
                                "name": "Lifecycle stages",
                                "description": "From coming into existence to ceasing to be one of these.",
                                "findings": [
                                    {
                                        "id": "stages-and-transitions",
                                        "name": "Stages and transitions",
                                        "description": "The stages worth naming and what moves a antivirus software between them.",
                                        "questions": [
                                            {
                                                "id": "stages-and-transitions-q01",
                                                "text": "What identifies and describes the lifecycle of a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q02",
                                                "text": "Who or what asserted this about the lifecycle of a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "stages-and-transitions-q03",
                                                "text": "What may an agent decide or do once the lifecycle of a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "observations-and-status",
                                "name": "Observations and current status",
                                "description": "What is observed about a antivirus software, how often and by whom.",
                                "findings": [
                                    {
                                        "id": "observation-record",
                                        "name": "Observation record",
                                        "description": "How an observation of a antivirus software is recorded so that it can be superseded rather than overwritten.",
                                        "questions": [
                                            {
                                                "id": "observation-record-q01",
                                                "text": "What identifies and describes an observation of a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q02",
                                                "text": "Who or what asserted this about an observation of a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "observation-record-q03",
                                                "text": "What may an agent decide or do once an observation of a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "content-and-access",
                        "name": "Content, encoding and access",
                        "description": "What a antivirus software says, how it is encoded and who may read it.",
                        "rationale": "An informational thing carries content that can be copied, versioned and withheld, none of which its physical carrier explains.",
                        "layers": [
                            {
                                "id": "content-and-encoding",
                                "name": "Content and encoding",
                                "description": "The content itself, its format and its language.",
                                "findings": [
                                    {
                                        "id": "content-and-format",
                                        "name": "Content, format and language",
                                        "description": "What a antivirus software contains and in what form it is held.",
                                        "questions": [
                                            {
                                                "id": "content-and-format-q01",
                                                "text": "What identifies and describes the content of a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "content-and-format-q02",
                                                "text": "Who or what asserted this about the content of a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "content-and-format-q03",
                                                "text": "What may an agent decide or do once the content of a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "access-and-rights",
                                "name": "Access, rights and retention",
                                "description": "Who may read, copy or change it, and for how long it is kept.",
                                "findings": [
                                    {
                                        "id": "access-rules",
                                        "name": "Access rules and retention",
                                        "description": "The permissions attached to a antivirus software and the period it survives.",
                                        "questions": [
                                            {
                                                "id": "access-rules-q01",
                                                "text": "What identifies and describes access to a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "access-rules-q02",
                                                "text": "Who or what asserted this about access to a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "access-rules-q03",
                                                "text": "What may an agent decide or do once access to a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "work-and-manifestation",
                        "name": "Work, version and copy",
                        "description": "Which level of antivirus software a statement is about.",
                        "rationale": "The work, the edition, the file and the copy in hand are four things; rights and content attach to different ones.",
                        "layers": [
                            {
                                "id": "levels",
                                "name": "Levels of the thing",
                                "description": "Work, expression, manifestation and item, in plain terms.",
                                "findings": [
                                    {
                                        "id": "level-rules",
                                        "name": "What belongs at each level",
                                        "description": "Which facts hold for the work and which only for one copy.",
                                        "questions": [
                                            {
                                                "id": "level-rules-q01",
                                                "text": "For antivirus software, which facts belong to the work itself, which to a version, and which to a single copy?",
                                                "kind": "boundary"
                                            },
                                            {
                                                "id": "level-rules-q02",
                                                "text": "What identifier exists at each level, and which one is being cited?",
                                                "kind": "definition"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "versions",
                                "name": "Versions, editions and variants",
                                "description": "How versions differ and which is canonical to whom.",
                                "findings": [
                                    {
                                        "id": "version-record",
                                        "name": "Versions and canonicity",
                                        "description": "Differences that matter and who calls one authoritative.",
                                        "questions": [
                                            {
                                                "id": "version-record-q01",
                                                "text": "Which versions or editions of antivirus software exist, and how do they differ substantively?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "version-record-q02",
                                                "text": "Who treats which version as authoritative, and for what purpose?",
                                                "kind": "provenance"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "authorship-and-rights",
                        "name": "Authorship, rights and permitted use",
                        "description": "Who made antivirus software and what may be done with it.",
                        "rationale": "Rights are jurisdictional, time-limited and attached to a level, and an agent that ignores that will copy what it may not.",
                        "layers": [
                            {
                                "id": "authorship",
                                "name": "Authorship and contribution",
                                "description": "Who contributed what, and in what capacity.",
                                "findings": [
                                    {
                                        "id": "contribution-record",
                                        "name": "Contributors and roles",
                                        "description": "The people and bodies behind it, with their roles.",
                                        "questions": [
                                            {
                                                "id": "contribution-record-q01",
                                                "text": "Who authored or contributed to antivirus software, in what roles, and how is that attested?",
                                                "kind": "provenance"
                                            },
                                            {
                                                "id": "contribution-record-q02",
                                                "text": "Where authorship is disputed or anonymous, what is recorded instead?",
                                                "kind": "boundary"
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "rights",
                                "name": "Rights and permissions",
                                "description": "Which rights subsist, where, until when, and what they permit.",
                                "findings": [
                                    {
                                        "id": "rights-record",
                                        "name": "Rights, term and permitted acts",
                                        "description": "The regime in force and what it allows.",
                                        "questions": [
                                            {
                                                "id": "rights-record-q01",
                                                "text": "What rights subsist in antivirus software, in which jurisdictions, and until when?",
                                                "kind": "definition"
                                            },
                                            {
                                                "id": "rights-record-q02",
                                                "text": "Which acts are permitted without further permission, and which must an agent refuse?",
                                                "kind": "action"
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    },
                    {
                        "id": "provenance-and-evidence",
                        "name": "Provenance, evidence and time",
                        "description": "Where every claim about a antivirus software came from and when it held.",
                        "rationale": "A claim without a source and a time cannot be superseded, only overwritten, and an agent that overwrites loses the ability to explain itself.",
                        "layers": [
                            {
                                "id": "source-and-authority",
                                "name": "Source and authority",
                                "description": "Who said it, on what evidence, and how strongly.",
                                "findings": [
                                    {
                                        "id": "claim-provenance",
                                        "name": "Claim provenance and confidence",
                                        "description": "The authority behind each claim about a antivirus software and how confident it is.",
                                        "questions": [
                                            {
                                                "id": "claim-provenance-q01",
                                                "text": "What identifies and describes a claim about a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q02",
                                                "text": "Who or what asserted this about a claim about a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "claim-provenance-q03",
                                                "text": "What may an agent decide or do once a claim about a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            },
                            {
                                "id": "time-and-versions",
                                "name": "Time, versions and supersession",
                                "description": "When a claim was true, when it was learnt, and what replaced it.",
                                "findings": [
                                    {
                                        "id": "validity-and-supersession",
                                        "name": "Validity period and supersession",
                                        "description": "How an old claim about a antivirus software is retired without being erased.",
                                        "questions": [
                                            {
                                                "id": "validity-and-supersession-q01",
                                                "text": "What identifies and describes the validity of a claim about a antivirus software, and in what units or vocabulary?",
                                                "kind": "definition",
                                                "answer_data": [
                                                    "identifiers",
                                                    "types and classes",
                                                    "values with units",
                                                    "explicit unknowns"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q02",
                                                "text": "Who or what asserted this about the validity of a claim about a antivirus software, by which method, and when was it true?",
                                                "kind": "provenance",
                                                "answer_data": [
                                                    "authority",
                                                    "method",
                                                    "evidence",
                                                    "event time",
                                                    "knowledge time"
                                                ]
                                            },
                                            {
                                                "id": "validity-and-supersession-q03",
                                                "text": "What may an agent decide or do once the validity of a claim about a antivirus software is known, and what must it refuse?",
                                                "kind": "action",
                                                "answer_data": [
                                                    "permitted actions",
                                                    "preconditions",
                                                    "refusals",
                                                    "escalation"
                                                ]
                                            }
                                        ]
                                    }
                                ]
                            }
                        ]
                    }
                ]
            },
            "statistics": {
                "bundles": 6,
                "layers": 12,
                "findings": 14,
                "questions": 38
            }
        }
    }
}