Process / Workflow
Represent repeatable workflow definitions and their separately identified executions, with explicit responsibility, evidence and change control.
Bundle → Layer → Finding → Questions Filled
6 bundles · 12 layers · 12 findings · 48 questions
Definition and adoption Proposed process model coverage for definition and adoption.
Definition identity
A process family groups immutable definition editions. A run points to one edition at a time through an explicit adoption history; neither a file path nor a run identifier identifies the family. A definition can exist before any run.
Separate family, edition and run identity
A process family groups immutable definition editions. A run points to one edition at a time through an explicit adoption history; neither a file path nor a run identifier identifies the family. A definition can exist before any run.
- Which authoritative system, process key and edition identify the definition? identity
- Is this record a definition, a run, a step occurrence or a projection? classification
- What repeatable purpose, trigger and completion criterion delimit this process? definition
- Which adopted method edition is referenced, if any? relationship
Release and migration
Definition release is a local governance decision. Record the approver, effective interval and supersession. Existing runs retain their edition unless an authorized migration records old and new bindings, active work mapping and unresolved effects.
Control release and instance migration separately
Definition release is a local governance decision. Record the approver, effective interval and supersession. Existing runs retain their edition unless an authorized migration records old and new bindings, active work mapping and unresolved effects.
- Who approved this edition and within which process ownership scope? authority
- Is the edition draft, released, deprecated or withdrawn and what use remains permitted? lifecycle
- How does a proposed migration map active steps, outstanding messages and compensation obligations? process
- What change evidence and rollback limits accompany the revision? evidence
Flow and data design Proposed process model coverage for flow and data design.
Control flow
Record nodes, edges, guards, loops and synchronization under a named semantic profile. A drawing alone does not establish executability. Optional case planning and computational scatter need their own constraints, not forced conversion to one universal sequence.
Declare the actual routing semantics
Record nodes, edges, guards, loops and synchronization under a named semantic profile. A drawing alone does not establish executability. Optional case planning and computational scatter need their own constraints, not forced conversion to one universal sequence.
- Which steps, subflows, branches and joins belong to this edition? composition
- How are guard failures, multiple true guards and missing guard data handled? constraint
- Which concurrent branches must finish before a join may proceed? state
- Which loops, optional steps or runtime plans are permitted and how are runaway paths bounded? exception
Data and interface contracts
Describe typed input and output references, validation and availability. Link subject records and external interfaces without absorbing their master data. Missing, null, skipped and failed output states must remain distinguishable in the selected binding.
Keep dependencies distinct from payload ownership
Describe typed input and output references, validation and availability. Link subject records and external interfaces without absorbing their master data. Missing, null, skipped and failed output states must remain distinguishable in the selected binding.
- Which inputs must be available before each step is eligible? requirement
- How are output type, completeness and acceptance checked? quality
- Which system owns each subject or payload and which snapshot was used? relationship
- How are skipped, null, missing and failed outputs represented by the chosen adapter? interoperability
Responsibility and authority Proposed process model coverage for responsibility and authority.
Role requirements
Define eligible roles, capability references and assignment constraints. A lane label, agent capability or claimed delegation is not permission to act. Definition stewardship and execution record custody may be held by different accountable parties.
Separate role suitability from permission
Define eligible roles, capability references and assignment constraints. A lane label, agent capability or claimed delegation is not permission to act. Definition stewardship and execution record custody may be held by different accountable parties.
- Who stewards the definition and who controls each run record? ownership
- Which capabilities and separation-of-duty constraints apply to the step? requirement
- What evidence makes a proposed performer eligible at the intended action time? authority
- What substitution or delegation is allowed when the assigned performer is unavailable? exception
Access and intervention
Proposed policy checks bind actor, target, operation and context. Read access to a definition does not grant access to execution evidence. Intervention, reassignment, cancellation and disclosure have independent scopes, reasons and review records.
Evaluate authority for each operation
Proposed policy checks bind actor, target, operation and context. Read access to a definition does not grant access to execution evidence. Intervention, reassignment, cancellation and disclosure have independent scopes, reasons and review records.
- Which actor may read this definition, run, finding or artifact for the declared purpose? access
- What operation-specific evidence authorizes a state-changing intervention? security
- Which execution details must be minimized or withheld from monitoring and aggregate views? privacy
- Which retention, hold and disposal decisions govern the execution evidence? retention
Execution and observations Proposed process model coverage for execution and observations.
Run lifecycle
A run has a stable scoped identifier, edition binding and local lifecycle. Waiting, suspended, failed, cancelled and completed states are not interchangeable. Workflow completion does not certify a subject outcome or update a separate case master.
Track one run independently of its subject
A run has a stable scoped identifier, edition binding and local lifecycle. Waiting, suspended, failed, cancelled and completed states are not interchangeable. Workflow completion does not certify a subject outcome or update a separate case master.
- What run identifier and initiating evidence distinguish this occurrence from a duplicate request? identity
- What is the run state and which active branch configuration supports it? state
- What evidence establishes completion, cancellation or failure and any remaining obligations? lifecycle
- Which case, task or service references this run without sharing its identity? relationship
Step occurrences and time
Each repeated or parallel step occurrence gets its own identity, with separate attempt identities for retries. Capture performer, inputs, outcome and event time apart from observation time. Atomic acts are optional evidence references with no one-to-one claim.
Preserve occurrences, attempts and observation limits
Each repeated or parallel step occurrence gets its own identity, with separate attempt identities for retries. Capture performer, inputs, outcome and event time apart from observation time. Atomic acts are optional evidence references with no one-to-one claim.
- Which run, step occurrence, iteration or branch and attempt does this observation concern? identity
- When did the event happen and when was it observed, with what offset and uncertainty? temporal
- Who asserted the step result and which input, output and act evidence supports it? provenance
- How are late, duplicated, conflicting or missing observations represented? quality
Exceptions and recovery Proposed process model coverage for exceptions and recovery.
Deviation and escalation
A deviation records the affected edition and path, evidence, impact and disposition. Permitted runtime planning is not automatically a breach. Escalation requests a decision; recording it neither authorizes an exception nor proves recovery.
Distinguish allowed variation from nonconformance
A deviation records the affected edition and path, evidence, impact and disposition. Permitted runtime planning is not automatically a breach. Escalation requests a decision; recording it neither authorizes an exception nor proves recovery.
- What observed behavior differs from the adopted rule and what remains uncertain? exception
- Is this allowed variation, missing evidence, an execution failure or an unauthorized deviation? classification
- Who can approve or reject the proposed disposition and under which authority? decision
- Which unresolved impact and follow-up obligations survive escalation closure? evidence
Retry and compensation
Recovery proposals preserve prior attempts and unknown external outcomes. Cancellation can stop future work without reversing effects. Compensation is separately authorized work with its own result and possible failure. Transport idempotence alone does not establish business exactly-once execution.
Do not equate retry, cancel and reversal
Recovery proposals preserve prior attempts and unknown external outcomes. Cancellation can stop future work without reversing effects. Compensation is separately authorized work with its own result and possible failure. Transport idempotence alone does not establish business exactly-once execution.
- What proves a retry is safe when the previous attempt outcome is unknown? constraint
- Which timeout, backoff and escalation policy applies to this failure? process
- Who authorized cancellation or compensation and for which effects? authority
- Which effects remain irreversible, partially compensated or unconfirmed? state
Assurance and exchange Proposed process model coverage for assurance and exchange.
Measurement and conformance
Assessments pin the definition, observation set and metric rule. Distinguish elapsed, working and waiting time; incomplete runs need explicit inclusion rules. A trace can disagree with a model because the evidence is incomplete. Performance data does not itself justify personnel ranking.
Qualify metrics by population and evidence
Assessments pin the definition, observation set and metric rule. Distinguish elapsed, working and waiting time; incomplete runs need explicit inclusion rules. A trace can disagree with a model because the evidence is incomplete. Performance data does not itself justify personnel ranking.
- Which metric formula, unit, population and observation window produced this value? measurement
- How are pauses, calendar effects, clock error and unfinished runs treated? temporal
- Which paths were tested and which deviations reflect missing evidence rather than a proved breach? validation
- What disclosure assessment permits this aggregate without exposing individual execution details? privacy
Interchange and limitations
A mapping pins a notation edition, adapter and supported subset. Distinguish structural validity from execution equivalence and operational fitness. BPMN, CMMN, SCXML and CWL cover different concerns; none is asserted as an interchangeable universal schema.
Declare mapping scope and semantic loss
A mapping pins a notation edition, adapter and supported subset. Distinguish structural validity from execution equivalence and operational fitness. BPMN, CMMN, SCXML and CWL cover different concerns; none is asserted as an interchangeable universal schema.
- Which notation edition, profile and adapter version are used for this exchange? interoperability
- Which unsupported constructs or semantic losses block execution or round-trip claims? validation
- What original artifact and transformation history accompany the exported projection? provenance
- Which adversarial fixtures and independent reviews remain necessary before operational adoption? requirement
Classifiers Filled
- Family
- World Models
- Category
- Activities and processes
- Entry kind
- aggregate
- Navigation path
- NAV.ACT.PRC
- Domain
- ACT.PRC
- Industry
- Cross-industry
- Tags
- processworkflowact.prc
- Also called
- K3
What it is Filled
A bounded process aggregate groups definition families, immutable editions and process-context execution records. It is a logical research aggregate, not a requirement for one database transaction or one custodian. Runs, editions and step occurrences retain distinct keys. External subjects, acts, tasks, methods and cases remain separately mastered.
In scope
- Definition identity, release, routing and typed input/output contracts
- Role requirements and operation-specific authority evidence
- Run, branch, occurrence and attempt identity with observed state
- Deviation, retry, cancellation, compensation and residual obligations
- Evidence-qualified measurement, migrations and conceptual interchange
Out of scope
- Master ownership of people, organizations, tasks, cases, methods, policies or business payloads
- Implementation of a workflow engine, scheduler, authorization service or process-mining algorithm
- Legal effects of decisions, physical effects of acts, or automatic changes to external subjects
- Operational instructions for dangerous activities; domain controls stay at policy level
Why it exists Filled
Represent repeatable workflow definitions and their separately identified executions, with explicit responsibility, evidence and change control.
Distinguishing features Derived, awaiting review
- Unlike WM-ACT-002 Act / Action: A step occurrence may reference zero or several act evidence records; correspondence can be many-to-many and never defines either master identity.
- Unlike WM-ACT-009 Practice / Method / Procedure: A process edition optionally pins an adopted instruction edition; this model owns flow and execution context, not method publication.
- Unlike WM-ACT-006 Task and WM-ACT-004 Service: Task and service records may reference workflow editions or runs. Candidate incoming registry edges are not reversed into mandatory containment.
- Unlike Case and subject models: Runtime planning may be profiled, but a persistent case can span several workflows. Workflow state never silently overwrites case or subject state.
- Unlike WM-KNW-012 policies or rules: Normative sources are references; model structure and role assignment confer no legal or operational authority.
Note: Derived from boundary notes against neighbouring models.
What robots and AI may and may not do Derived, awaiting review
Must not
- Deny access unless policy authorizes the actor, object, operation and context; definition visibility never implies run-data visibility.
May
- Check a definition proposal: Proposed local operation, unimplemented. Read-only assessment; no release or execution.
- Record an approved release: Proposed local operation, unimplemented. Append local release decision; do not deploy a definition or migrate runs.
- Register an evidenced run: Proposed local operation, unimplemented. Record initiation evidence only; do not start external work.
- Record a step observation: Proposed local operation, unimplemented. Append observation; duplicate events do not duplicate effects; do not execute the step.
- Assess a recovery proposal: Proposed local operation, unimplemented. Read-only assessment; no retry, cancellation or compensation is performed.
- Build a scoped assessment: Proposed local operation, unimplemented. Create a local report only; do not certify engine or legal conformance.
Note: Derived from functions, policies, CRUD and access rules; prohibitions were not authored for agents as such.
Moral aspects Derived, awaiting review
- Protect execution data and minimize worker surveillance; aggregate disclosure needs an explicit review.
- Jurisdiction, sector, privacy, labor, retention and intervention rules require qualified adoption profiles.
Note: Sentences mentioning harm, privacy, consent or similar, collected from the specification.
Owners Filled
Steward
Accountable process steward reference with authority scope
Roles
- Process steward
- Approve definition scope and release evidence.
- Execution custodian
- Maintain run records and scoped retention.
- Authorized performer
- Supply evidence within assigned operation authority.
- Evidence reviewer
- Challenge observations, uncertainty and conformance claims.
- Access administrator
- Maintain scoped disclosure policy without claiming process authority.
Links to other meta-models Filled
references
- WM-ACT-002 - Optional act evidence for a step occurrence; no one-to-one requirement.
- WM-ACT-009 - Pin an instruction edition when adopted; candidate registry relationship qualified as optional.
- WM-KNW-012 - Resolve applicable policy or rule editions and authority separately.
aligned
- https://www.omg.org/spec/BPMN/2.0.2 - Conceptual flow and instance alignment; executable mapping deferred.
- https://www.omg.org/spec/CMMN/1.1 - Optional runtime-planning profile; does not absorb external case masters.
- https://www.w3.org/TR/scxml/ - State configuration alignment with explicit semantic differences.
- https://www.commonwl.org/v1.2/Workflow.html - Computational workflow profile only; not a universal runtime.
- https://www.w3.org/TR/prov-o/ - Evidence attribution for plans, activities and agents, without truth certification.
neighbor
- WM-ACT-002 Act / Action - A step occurrence may reference zero or several act evidence records; correspondence can be many-to-many and never defines either master identity.
- WM-ACT-009 Practice / Method / Procedure - A process edition optionally pins an adopted instruction edition; this model owns flow and execution context, not method publication.
- WM-ACT-006 Task and WM-ACT-004 Service - Task and service records may reference workflow editions or runs. Candidate incoming registry edges are not reversed into mandatory containment.
- Case and subject models - Runtime planning may be profiled, but a persistent case can span several workflows. Workflow state never silently overwrites case or subject state.
- WM-KNW-012 policies or rules - Normative sources are references; model structure and role assignment confer no legal or operational authority.
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Filled
- Authoritative master-system identifier
- Owner namespace plus stable local identifier
- Digest as content integrity evidence only
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Filled
- Check a definition proposal: Proposed local operation, unimplemented. Read-only assessment; no release or execution.
- Record an approved release: Proposed local operation, unimplemented. Append local release decision; do not deploy a definition or migrate runs.
- Register an evidenced run: Proposed local operation, unimplemented. Record initiation evidence only; do not start external work.
- Record a step observation: Proposed local operation, unimplemented. Append observation; duplicate events do not duplicate effects; do not execute the step.
- Assess a recovery proposal: Proposed local operation, unimplemented. Read-only assessment; no retry, cancellation or compensation is performed.
- Build a scoped assessment: Proposed local operation, unimplemented. Create a local report only; do not certify engine or legal conformance.
Hazards and failure modes optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Derived, awaiting review
- PROV-O: The PROV Ontology
- RFC 3339: Date and Time on the Internet: Timestamps
- RFC 9110: HTTP Semantics
Context of use required Filled
- No jurisdiction or industry is assumed. Technical specifications support conceptual distinctions, not legal authority.
- Human, automated and mixed workflows need distinct adopted profiles; computational examples do not define all processes.
Sources Filled
- Business Process Model and Notation - Object Management Group
- Case Management Model and Notation - Object Management Group
- State Chart XML: State Machine Notation for Control Abstraction - World Wide Web Consortium
- PROV-O: The PROV Ontology - World Wide Web Consortium
- Common Workflow Language Workflow Description - Common Workflow Language project
- RFC 3339: Date and Time on the Internet: Timestamps - Internet Engineering Task Force
- RFC 9110: HTTP Semantics - Internet Engineering Task Force
- Guide to Attribute Based Access Control Definition and Considerations - National Institute of Standards and Technology
Open questions
- Restore independent external review and verify source versions, errata, licensing and applicability before canonical promotion.
- Develop adoption profiles and executable schemas with fixtures for duplicate initiation, parallel completion, missing guards, late events, unknown retry outcomes, compensation failure, edition migration and lawful evidence disposal.
- Implement and test bounded BPMN, CMMN, SCXML, CWL and provenance mappings, including unsupported constructs, round-trip loss and references to independently mastered neighbors.
- Independent second-provider review is waived.
- Direct HTTP checks are not attempted under the owner-reported sandbox restriction; browser content access is recorded separately.
- Nested schemas, executable mappings, concurrency tests and model-specific neighbor version pins remain incomplete.
- No complete BPMN, CMMN, SCXML, CWL or event-log conformance is implemented.
- Jurisdiction, sector, privacy, labor, retention and intervention rules require qualified adoption profiles.
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-act-003-process-workflow/spec.yaml