# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T13:57:26Z", "synthesisSha256": "85f9c0eca5621de18c92982b9094076091fd51d79a6c2d17a6557f0655fff0da", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ACT-003", "registryId": "vr.wm-act-003", "name": "Process / Workflow", "version": "0.3.0", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.PRC" ], "tags": [ "process", "workflow", "act.prc" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-003-process-workflow/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-003", "model": { "registry_id": "vr.wm-act-003", "model_id": "WM-ACT-003", "name": "Process / Workflow", "entry_kind": "aggregate", "purpose": "Represent repeatable workflow definitions and their separately identified executions, with explicit responsibility, evidence and change control.", "scope_statement": "A bounded process aggregate groups definition families, immutable editions and process-context execution records. It is a logical research aggregate, not a requirement for one database transaction or one custodian. Runs, editions and step occurrences retain distinct keys. External subjects, acts, tasks, methods and cases remain separately mastered.", "in_scope": [ "Definition identity, release, routing and typed input/output contracts", "Role requirements and operation-specific authority evidence", "Run, branch, occurrence and attempt identity with observed state", "Deviation, retry, cancellation, compensation and residual obligations", "Evidence-qualified measurement, migrations and conceptual interchange" ], "out_of_scope": [ "Master ownership of people, organizations, tasks, cases, methods, policies or business payloads", "Implementation of a workflow engine, scheduler, authorization service or process-mining algorithm", "Legal effects of decisions, physical effects of acts, or automatic changes to external subjects", "Operational instructions for dangerous activities; domain controls stay at policy level" ], "boundary_notes": [ { "neighbor": "WM-ACT-002 Act / Action", "distinction": "A step occurrence may reference zero or several act evidence records; correspondence can be many-to-many and never defines either master identity.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "neighbor": "WM-ACT-009 Practice / Method / Procedure", "distinction": "A process edition optionally pins an adopted instruction edition; this model owns flow and execution context, not method publication.", "source_refs": [ "SRC-001", "SRC-004" ] }, { "neighbor": "WM-ACT-006 Task and WM-ACT-004 Service", "distinction": "Task and service records may reference workflow editions or runs. Candidate incoming registry edges are not reversed into mandatory containment.", "source_refs": [ "SRC-001", "SRC-004" ] }, { "neighbor": "Case and subject models", "distinction": "Runtime planning may be profiled, but a persistent case can span several workflows. Workflow state never silently overwrites case or subject state.", "source_refs": [ "SRC-002", "SRC-003" ] }, { "neighbor": "WM-KNW-012 policies or rules", "distinction": "Normative sources are references; model structure and role assignment confer no legal or operational authority.", "source_refs": [ "SRC-008", "SRC-004" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Business Process Model and Notation", "organization": "Object Management Group", "url": "https://www.omg.org/spec/BPMN/2.0.2/PDF", "version_or_date": "2.0.2, December 2013 document; January 2014 adoption", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:55:34Z", "relevance": "Clause 10 process and instance separation; clause 13 execution and compensation. Basis for conceptual process alignment, not a claim of engine conformance." }, { "id": "SRC-002", "title": "Case Management Model and Notation", "organization": "Object Management Group", "url": "https://www.omg.org/spec/CMMN/1.1/PDF", "version_or_date": "1.1, December 2016", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:55:34Z", "relevance": "Section 4.1 distinguishes runtime planning and case context from predefined orchestration. PDF body identifies CMMN despite erroneous browser extraction title." }, { "id": "SRC-003", "title": "State Chart XML: State Machine Notation for Control Abstraction", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/scxml/", "version_or_date": "Recommendation 2015-09-01", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:55:34Z", "relevance": "Sections 3.3-3.7 distinguish compound, parallel, transition and final state semantics. Used for state-configuration questions, not a universal workflow engine mapping." }, { "id": "SRC-004", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:55:34Z", "relevance": "Activity, Entity, Agent, Association and Plan support evidence attribution and the distinction between intended steps and recorded execution. Provenance does not establish truth." }, { "id": "SRC-005", "title": "Common Workflow Language Workflow Description", "organization": "Common Workflow Language project", "url": "https://www.commonwl.org/v1.2/Workflow.html", "version_or_date": "Page identifies v1.2.1 within v1.2 path", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:55:34Z", "relevance": "Section 4.3 supplies a computational counterexample: step inputs, outputs, scatter, conditional skips and nested workflows. Not a general human-workflow profile." }, { "id": "SRC-006", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:55:34Z", "relevance": "Sections 5.6-5.8 provide timestamp grammar and offset examples. Calendar rules, causal order and measured duration are separate adoption concerns." }, { "id": "SRC-007", "title": "RFC 9110: HTTP Semantics", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9110.html", "version_or_date": "June 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:55:34Z", "relevance": "Section 9.2.2 distinguishes idempotent request semantics from unsafe retry assumptions. Only transport-bound operations use this alignment; no exactly-once guarantee is inferred." }, { "id": "SRC-008", "title": "Guide to Attribute Based Access Control Definition and Considerations", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/162/upd2/final", "version_or_date": "SP 800-162, January 2014; updated 2019-08-02", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:55:34Z", "relevance": "Official abstract grounds authorization in subject, object, operation and environmental attributes evaluated against policy. Local governance controls are proposed design, not a compliance certification." } ], "structure": { "bundles": [ { "id": "bundle-definition", "name": "Definition and adoption", "description": "Proposed process model coverage for definition and adoption.", "rationale": "Keep this responsibility visible without taking ownership of external subject records.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "layers": [ { "id": "layer-identity", "name": "Definition identity", "description": "A process family groups immutable definition editions. A run points to one edition at a time through an explicit adoption history; neither a file path nor a run identifier identifies the family. A definition can exist before any run.", "source_refs": [ "SRC-001", "SRC-004" ], "findings": [ { "id": "definition-record", "name": "Separate family, edition and run identity", "description": "A process family groups immutable definition editions. A run points to one edition at a time through an explicit adoption history; neither a file path nor a run identifier identifies the family. A definition can exist before any run.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "definition-record-q1", "text": "Which authoritative system, process key and edition identify the definition?", "kind": "identity", "answer_data": [ "master-system", "process-key", "edition-id" ] }, { "id": "definition-record-q2", "text": "Is this record a definition, a run, a step occurrence or a projection?", "kind": "classification", "answer_data": [ "record-kind", "root-reference" ] }, { "id": "definition-record-q3", "text": "What repeatable purpose, trigger and completion criterion delimit this process?", "kind": "definition", "answer_data": [ "purpose", "trigger", "completion-criterion" ] }, { "id": "definition-record-q4", "text": "Which adopted method edition is referenced, if any?", "kind": "relationship", "answer_data": [ "method-reference", "edition", "adoption-basis" ] } ], "data_elements": [ { "id": "definition-record-data-identity", "name": "Identity tuple", "description": "Candidate identity tuple. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "definition-record-data-purpose", "name": "Purpose and trigger", "description": "Candidate purpose and trigger. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "definition-record-data-method", "name": "Adopted method reference", "description": "Candidate adopted method reference. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "definition-record-artifact", "name": "Definition manifest", "description": "Versioned evidence for separate family, edition and run identity, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-release", "name": "Release and migration", "description": "Definition release is a local governance decision. Record the approver, effective interval and supersession. Existing runs retain their edition unless an authorized migration records old and new bindings, active work mapping and unresolved effects.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "findings": [ { "id": "edition-governance", "name": "Control release and instance migration separately", "description": "Definition release is a local governance decision. Record the approver, effective interval and supersession. Existing runs retain their edition unless an authorized migration records old and new bindings, active work mapping and unresolved effects.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "questions": [ { "id": "edition-governance-q1", "text": "Who approved this edition and within which process ownership scope?", "kind": "authority", "answer_data": [ "approver", "authority-evidence", "scope" ] }, { "id": "edition-governance-q2", "text": "Is the edition draft, released, deprecated or withdrawn and what use remains permitted?", "kind": "lifecycle", "answer_data": [ "release-state", "effective-interval", "new-run-policy" ] }, { "id": "edition-governance-q3", "text": "How does a proposed migration map active steps, outstanding messages and compensation obligations?", "kind": "process", "answer_data": [ "mapping", "unmapped-items", "migration-decision" ] }, { "id": "edition-governance-q4", "text": "What change evidence and rollback limits accompany the revision?", "kind": "evidence", "answer_data": [ "change-reason", "evidence", "rollback-limit" ] } ], "data_elements": [ { "id": "edition-governance-data-release", "name": "Release decision", "description": "Candidate release decision. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] }, { "id": "edition-governance-data-migration", "name": "Migration records", "description": "Candidate migration records. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] } ], "artifacts": [ { "id": "edition-governance-artifact", "name": "Release and migration record", "description": "Versioned evidence for control release and instance migration separately, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-design", "name": "Flow and data design", "description": "Proposed process model coverage for flow and data design.", "rationale": "Keep this responsibility visible without taking ownership of external subject records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005" ], "layers": [ { "id": "layer-control", "name": "Control flow", "description": "Record nodes, edges, guards, loops and synchronization under a named semantic profile. A drawing alone does not establish executability. Optional case planning and computational scatter need their own constraints, not forced conversion to one universal sequence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ], "findings": [ { "id": "flow-semantics", "name": "Declare the actual routing semantics", "description": "Record nodes, edges, guards, loops and synchronization under a named semantic profile. A drawing alone does not establish executability. Optional case planning and computational scatter need their own constraints, not forced conversion to one universal sequence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ], "questions": [ { "id": "flow-semantics-q1", "text": "Which steps, subflows, branches and joins belong to this edition?", "kind": "composition", "answer_data": [ "node-set", "edge-set", "subflow-pins" ] }, { "id": "flow-semantics-q2", "text": "How are guard failures, multiple true guards and missing guard data handled?", "kind": "constraint", "answer_data": [ "guard-language", "priority", "unknown-policy" ] }, { "id": "flow-semantics-q3", "text": "Which concurrent branches must finish before a join may proceed?", "kind": "state", "answer_data": [ "join-policy", "active-branch-set", "completion-evidence" ] }, { "id": "flow-semantics-q4", "text": "Which loops, optional steps or runtime plans are permitted and how are runaway paths bounded?", "kind": "exception", "answer_data": [ "iteration-rule", "planning-authority", "termination-bound" ] } ], "data_elements": [ { "id": "flow-semantics-data-graph", "name": "Scoped flow graph", "description": "Candidate scoped flow graph. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ] }, { "id": "flow-semantics-data-semantics", "name": "Semantic profile pin", "description": "Candidate semantic profile pin. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "flow-semantics-artifact", "name": "Flow definition artifact", "description": "Versioned evidence for declare the actual routing semantics, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-data", "name": "Data and interface contracts", "description": "Describe typed input and output references, validation and availability. Link subject records and external interfaces without absorbing their master data. Missing, null, skipped and failed output states must remain distinguishable in the selected binding.", "source_refs": [ "SRC-001", "SRC-005", "SRC-004" ], "findings": [ { "id": "io-contract", "name": "Keep dependencies distinct from payload ownership", "description": "Describe typed input and output references, validation and availability. Link subject records and external interfaces without absorbing their master data. Missing, null, skipped and failed output states must remain distinguishable in the selected binding.", "source_refs": [ "SRC-001", "SRC-005", "SRC-004" ], "questions": [ { "id": "io-contract-q1", "text": "Which inputs must be available before each step is eligible?", "kind": "requirement", "answer_data": [ "input-schema", "requiredness", "availability-rule" ] }, { "id": "io-contract-q2", "text": "How are output type, completeness and acceptance checked?", "kind": "quality", "answer_data": [ "output-schema", "validator", "acceptance-result" ] }, { "id": "io-contract-q3", "text": "Which system owns each subject or payload and which snapshot was used?", "kind": "relationship", "answer_data": [ "master-reference", "snapshot", "retrieval-time" ] }, { "id": "io-contract-q4", "text": "How are skipped, null, missing and failed outputs represented by the chosen adapter?", "kind": "interoperability", "answer_data": [ "adapter-version", "state-mapping", "loss-report" ] } ], "data_elements": [ { "id": "io-contract-data-ports", "name": "Input and output contracts", "description": "Candidate input and output contracts. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-004" ] }, { "id": "io-contract-data-bindings", "name": "External bindings", "description": "Candidate external bindings. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-004" ] } ], "artifacts": [ { "id": "io-contract-artifact", "name": "Input and output contract", "description": "Versioned evidence for keep dependencies distinct from payload ownership, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-005", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-responsibility", "name": "Responsibility and authority", "description": "Proposed process model coverage for responsibility and authority.", "rationale": "Keep this responsibility visible without taking ownership of external subject records.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "layers": [ { "id": "layer-roles", "name": "Role requirements", "description": "Define eligible roles, capability references and assignment constraints. A lane label, agent capability or claimed delegation is not permission to act. Definition stewardship and execution record custody may be held by different accountable parties.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "findings": [ { "id": "role-eligibility", "name": "Separate role suitability from permission", "description": "Define eligible roles, capability references and assignment constraints. A lane label, agent capability or claimed delegation is not permission to act. Definition stewardship and execution record custody may be held by different accountable parties.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "questions": [ { "id": "role-eligibility-q1", "text": "Who stewards the definition and who controls each run record?", "kind": "ownership", "answer_data": [ "definition-steward", "run-custodian", "scope" ] }, { "id": "role-eligibility-q2", "text": "Which capabilities and separation-of-duty constraints apply to the step?", "kind": "requirement", "answer_data": [ "capability-reference", "conflict-rule" ] }, { "id": "role-eligibility-q3", "text": "What evidence makes a proposed performer eligible at the intended action time?", "kind": "authority", "answer_data": [ "role-assignment", "validity", "authorization-evidence" ] }, { "id": "role-eligibility-q4", "text": "What substitution or delegation is allowed when the assigned performer is unavailable?", "kind": "exception", "answer_data": [ "delegate", "scope", "expiry", "approval" ] } ], "data_elements": [ { "id": "role-eligibility-data-roles", "name": "Role and capability requirements", "description": "Candidate role and capability requirements. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] }, { "id": "role-eligibility-data-custody", "name": "Custody and stewardship references", "description": "Candidate custody and stewardship references. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] } ], "artifacts": [ { "id": "role-eligibility-artifact", "name": "Role and delegation matrix", "description": "Versioned evidence for separate role suitability from permission, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-access", "name": "Access and intervention", "description": "Proposed policy checks bind actor, target, operation and context. Read access to a definition does not grant access to execution evidence. Intervention, reassignment, cancellation and disclosure have independent scopes, reasons and review records.", "source_refs": [ "SRC-008", "SRC-004" ], "findings": [ { "id": "operation-authorization", "name": "Evaluate authority for each operation", "description": "Proposed policy checks bind actor, target, operation and context. Read access to a definition does not grant access to execution evidence. Intervention, reassignment, cancellation and disclosure have independent scopes, reasons and review records.", "source_refs": [ "SRC-008", "SRC-004" ], "questions": [ { "id": "operation-authorization-q1", "text": "Which actor may read this definition, run, finding or artifact for the declared purpose?", "kind": "access", "answer_data": [ "actor", "target", "purpose", "policy-decision" ] }, { "id": "operation-authorization-q2", "text": "What operation-specific evidence authorizes a state-changing intervention?", "kind": "security", "answer_data": [ "operation", "authority", "decision-time", "expiry" ] }, { "id": "operation-authorization-q3", "text": "Which execution details must be minimized or withheld from monitoring and aggregate views?", "kind": "privacy", "answer_data": [ "field-policy", "recipient", "redaction-rule" ] }, { "id": "operation-authorization-q4", "text": "Which retention, hold and disposal decisions govern the execution evidence?", "kind": "retention", "answer_data": [ "retention-rule", "hold-scope", "disposal-authority" ] } ], "data_elements": [ { "id": "operation-authorization-data-policy", "name": "Operation policy binding", "description": "Candidate operation policy binding. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-004" ] }, { "id": "operation-authorization-data-decisions", "name": "Authorization decision records", "description": "Candidate authorization decision records. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-004" ] } ], "artifacts": [ { "id": "operation-authorization-artifact", "name": "Access decision evidence", "description": "Versioned evidence for evaluate authority for each operation, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-008", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-execution", "name": "Execution and observations", "description": "Proposed process model coverage for execution and observations.", "rationale": "Keep this responsibility visible without taking ownership of external subject records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "layer-runs", "name": "Run lifecycle", "description": "A run has a stable scoped identifier, edition binding and local lifecycle. Waiting, suspended, failed, cancelled and completed states are not interchangeable. Workflow completion does not certify a subject outcome or update a separate case master.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "findings": [ { "id": "run-record", "name": "Track one run independently of its subject", "description": "A run has a stable scoped identifier, edition binding and local lifecycle. Waiting, suspended, failed, cancelled and completed states are not interchangeable. Workflow completion does not certify a subject outcome or update a separate case master.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "questions": [ { "id": "run-record-q1", "text": "What run identifier and initiating evidence distinguish this occurrence from a duplicate request?", "kind": "identity", "answer_data": [ "run-id", "initiation-key", "trigger-evidence" ] }, { "id": "run-record-q2", "text": "What is the run state and which active branch configuration supports it?", "kind": "state", "answer_data": [ "state", "branch-configuration", "observation-time" ] }, { "id": "run-record-q3", "text": "What evidence establishes completion, cancellation or failure and any remaining obligations?", "kind": "lifecycle", "answer_data": [ "terminal-reason", "outcome", "residual-obligations" ] }, { "id": "run-record-q4", "text": "Which case, task or service references this run without sharing its identity?", "kind": "relationship", "answer_data": [ "external-reference", "relation-kind", "master-system" ] } ], "data_elements": [ { "id": "run-record-data-run", "name": "Run identity and edition binding", "description": "Candidate run identity and edition binding. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "run-record-data-state", "name": "Run state evidence", "description": "Candidate run state evidence. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "run-record-artifact", "name": "Run lifecycle record", "description": "Versioned evidence for track one run independently of its subject, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-steps", "name": "Step occurrences and time", "description": "Each repeated or parallel step occurrence gets its own identity, with separate attempt identities for retries. Capture performer, inputs, outcome and event time apart from observation time. Atomic acts are optional evidence references with no one-to-one claim.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ], "findings": [ { "id": "step-evidence", "name": "Preserve occurrences, attempts and observation limits", "description": "Each repeated or parallel step occurrence gets its own identity, with separate attempt identities for retries. Capture performer, inputs, outcome and event time apart from observation time. Atomic acts are optional evidence references with no one-to-one claim.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ], "questions": [ { "id": "step-evidence-q1", "text": "Which run, step occurrence, iteration or branch and attempt does this observation concern?", "kind": "identity", "answer_data": [ "run-id", "step-id", "occurrence-id", "attempt-id" ] }, { "id": "step-evidence-q2", "text": "When did the event happen and when was it observed, with what offset and uncertainty?", "kind": "temporal", "answer_data": [ "event-time", "observed-time", "offset", "uncertainty" ] }, { "id": "step-evidence-q3", "text": "Who asserted the step result and which input, output and act evidence supports it?", "kind": "provenance", "answer_data": [ "assertor", "input-ref", "output-ref", "act-refs" ] }, { "id": "step-evidence-q4", "text": "How are late, duplicated, conflicting or missing observations represented?", "kind": "quality", "answer_data": [ "event-key", "ordering-basis", "conflict-state", "missingness" ] } ], "data_elements": [ { "id": "step-evidence-data-occurrence", "name": "Occurrence and attempt keys", "description": "Candidate occurrence and attempt keys. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] }, { "id": "step-evidence-data-observation", "name": "Execution observation", "description": "Candidate execution observation. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] }, { "id": "step-evidence-data-acts", "name": "Atomic act references", "description": "Candidate atomic act references. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "step-evidence-artifact", "name": "Step observation journal", "description": "Versioned evidence for preserve occurrences, attempts and observation limits, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-resilience", "name": "Exceptions and recovery", "description": "Proposed process model coverage for exceptions and recovery.", "rationale": "Keep this responsibility visible without taking ownership of external subject records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-deviations", "name": "Deviation and escalation", "description": "A deviation records the affected edition and path, evidence, impact and disposition. Permitted runtime planning is not automatically a breach. Escalation requests a decision; recording it neither authorizes an exception nor proves recovery.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-008" ], "findings": [ { "id": "deviation-record", "name": "Distinguish allowed variation from nonconformance", "description": "A deviation records the affected edition and path, evidence, impact and disposition. Permitted runtime planning is not automatically a breach. Escalation requests a decision; recording it neither authorizes an exception nor proves recovery.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-008" ], "questions": [ { "id": "deviation-record-q1", "text": "What observed behavior differs from the adopted rule and what remains uncertain?", "kind": "exception", "answer_data": [ "expected-rule", "observation", "uncertainty" ] }, { "id": "deviation-record-q2", "text": "Is this allowed variation, missing evidence, an execution failure or an unauthorized deviation?", "kind": "classification", "answer_data": [ "classification", "basis", "reviewer" ] }, { "id": "deviation-record-q3", "text": "Who can approve or reject the proposed disposition and under which authority?", "kind": "decision", "answer_data": [ "decision-maker", "authority", "disposition" ] }, { "id": "deviation-record-q4", "text": "Which unresolved impact and follow-up obligations survive escalation closure?", "kind": "evidence", "answer_data": [ "impact", "open-obligations", "closure-evidence" ] } ], "data_elements": [ { "id": "deviation-record-data-deviation", "name": "Deviation assessment", "description": "Candidate deviation assessment. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-008" ] }, { "id": "deviation-record-data-resolution", "name": "Resolution and obligations", "description": "Candidate resolution and obligations. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-008" ] } ], "artifacts": [ { "id": "deviation-record-artifact", "name": "Deviation and escalation record", "description": "Versioned evidence for distinguish allowed variation from nonconformance, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-recovery", "name": "Retry and compensation", "description": "Recovery proposals preserve prior attempts and unknown external outcomes. Cancellation can stop future work without reversing effects. Compensation is separately authorized work with its own result and possible failure. Transport idempotence alone does not establish business exactly-once execution.", "source_refs": [ "SRC-001", "SRC-007", "SRC-004", "SRC-008" ], "findings": [ { "id": "recovery-contract", "name": "Do not equate retry, cancel and reversal", "description": "Recovery proposals preserve prior attempts and unknown external outcomes. Cancellation can stop future work without reversing effects. Compensation is separately authorized work with its own result and possible failure. Transport idempotence alone does not establish business exactly-once execution.", "source_refs": [ "SRC-001", "SRC-007", "SRC-004", "SRC-008" ], "questions": [ { "id": "recovery-contract-q1", "text": "What proves a retry is safe when the previous attempt outcome is unknown?", "kind": "constraint", "answer_data": [ "operation-semantics", "dedup-scope", "external-status", "retry-limit" ] }, { "id": "recovery-contract-q2", "text": "Which timeout, backoff and escalation policy applies to this failure?", "kind": "process", "answer_data": [ "timeout-rule", "retry-budget", "escalation-target" ] }, { "id": "recovery-contract-q3", "text": "Who authorized cancellation or compensation and for which effects?", "kind": "authority", "answer_data": [ "authorization", "effect-scope", "remaining-work" ] }, { "id": "recovery-contract-q4", "text": "Which effects remain irreversible, partially compensated or unconfirmed?", "kind": "state", "answer_data": [ "effect-ledger", "compensation-result", "residual-state" ] } ], "data_elements": [ { "id": "recovery-contract-data-recovery", "name": "Recovery decision", "description": "Candidate recovery decision. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-004", "SRC-008" ] }, { "id": "recovery-contract-data-effects", "name": "Effect and compensation evidence", "description": "Candidate effect and compensation evidence. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-007", "SRC-004", "SRC-008" ] } ], "artifacts": [ { "id": "recovery-contract-artifact", "name": "Recovery decision and outcome record", "description": "Versioned evidence for do not equate retry, cancel and reversal, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-007", "SRC-004", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance", "name": "Assurance and exchange", "description": "Proposed process model coverage for assurance and exchange.", "rationale": "Keep this responsibility visible without taking ownership of external subject records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-008" ], "layers": [ { "id": "layer-measurement", "name": "Measurement and conformance", "description": "Assessments pin the definition, observation set and metric rule. Distinguish elapsed, working and waiting time; incomplete runs need explicit inclusion rules. A trace can disagree with a model because the evidence is incomplete. Performance data does not itself justify personnel ranking.", "source_refs": [ "SRC-004", "SRC-006", "SRC-008", "SRC-001" ], "findings": [ { "id": "assessment-evidence", "name": "Qualify metrics by population and evidence", "description": "Assessments pin the definition, observation set and metric rule. Distinguish elapsed, working and waiting time; incomplete runs need explicit inclusion rules. A trace can disagree with a model because the evidence is incomplete. Performance data does not itself justify personnel ranking.", "source_refs": [ "SRC-004", "SRC-006", "SRC-008", "SRC-001" ], "questions": [ { "id": "assessment-evidence-q1", "text": "Which metric formula, unit, population and observation window produced this value?", "kind": "measurement", "answer_data": [ "formula", "unit", "population", "window" ] }, { "id": "assessment-evidence-q2", "text": "How are pauses, calendar effects, clock error and unfinished runs treated?", "kind": "temporal", "answer_data": [ "clock-basis", "calendar", "pause-policy", "censoring-rule" ] }, { "id": "assessment-evidence-q3", "text": "Which paths were tested and which deviations reflect missing evidence rather than a proved breach?", "kind": "validation", "answer_data": [ "edition", "test-paths", "evidence-gaps", "assessment" ] }, { "id": "assessment-evidence-q4", "text": "What disclosure assessment permits this aggregate without exposing individual execution details?", "kind": "privacy", "answer_data": [ "purpose", "aggregation-rule", "disclosure-review" ] } ], "data_elements": [ { "id": "assessment-evidence-data-metric", "name": "Metric definition and result", "description": "Candidate metric definition and result. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-006", "SRC-008", "SRC-001" ] }, { "id": "assessment-evidence-data-assessment", "name": "Conformance assessment", "description": "Candidate conformance assessment. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-006", "SRC-008", "SRC-001" ] } ], "artifacts": [ { "id": "assessment-evidence-artifact", "name": "Measurement and conformance report", "description": "Versioned evidence for qualify metrics by population and evidence, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-004", "SRC-006", "SRC-008", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-exchange", "name": "Interchange and limitations", "description": "A mapping pins a notation edition, adapter and supported subset. Distinguish structural validity from execution equivalence and operational fitness. BPMN, CMMN, SCXML and CWL cover different concerns; none is asserted as an interchangeable universal schema.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-004" ], "findings": [ { "id": "mapping-profile", "name": "Declare mapping scope and semantic loss", "description": "A mapping pins a notation edition, adapter and supported subset. Distinguish structural validity from execution equivalence and operational fitness. BPMN, CMMN, SCXML and CWL cover different concerns; none is asserted as an interchangeable universal schema.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-004" ], "questions": [ { "id": "mapping-profile-q1", "text": "Which notation edition, profile and adapter version are used for this exchange?", "kind": "interoperability", "answer_data": [ "notation", "edition", "profile", "adapter" ] }, { "id": "mapping-profile-q2", "text": "Which unsupported constructs or semantic losses block execution or round-trip claims?", "kind": "validation", "answer_data": [ "unsupported-set", "loss-report", "refusal-rule" ] }, { "id": "mapping-profile-q3", "text": "What original artifact and transformation history accompany the exported projection?", "kind": "provenance", "answer_data": [ "source-artifact", "digest", "transform-history" ] }, { "id": "mapping-profile-q4", "text": "Which adversarial fixtures and independent reviews remain necessary before operational adoption?", "kind": "requirement", "answer_data": [ "fixture-set", "review-holds", "acceptance-owner" ] } ], "data_elements": [ { "id": "mapping-profile-data-mapping", "name": "Mapping and loss declaration", "description": "Candidate mapping and loss declaration. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-004" ] }, { "id": "mapping-profile-data-fixtures", "name": "Acceptance fixture references", "description": "Candidate acceptance fixture references. Nested instance schema and profile constraints remain an adoption hold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-004" ] } ], "artifacts": [ { "id": "mapping-profile-artifact", "name": "Interchange profile report", "description": "Versioned evidence for declare mapping scope and semantic loss, preserving scope, provenance, unknowns and authorized corrections.", "media_or_form": [ "application/json", "human-readable controlled record" ], "serial": true, "identity_strategy": "Authoritative master-system ID first; otherwise owner namespace plus stable local ID. Store revision and sequence separately; digest verifies bytes, not identity or truth.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-check-definition", "name": "Check a definition proposal", "description": "Proposed local operation, unimplemented. Read-only assessment; no release or execution.", "inputs": [ "definition edition", "semantic profile", "graph and port contracts" ], "outputs": [ "diagnostics and unresolved constraints" ], "preconditions": [ "Read access and resolvable edition pin" ], "effects": [ "Read-only assessment; no release or execution", "On missing authority, stale revision or unresolved required input, refuse mutation and record the reason." ], "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] }, { "id": "fn-record-release", "name": "Record an approved release", "description": "Proposed local operation, unimplemented. Append local release decision; do not deploy a definition or migrate runs.", "inputs": [ "approved edition", "authority evidence", "expected revision" ], "outputs": [ "release evidence or explicit refusal" ], "preconditions": [ "Release approval and custody scope verified", " expected revision matches" ], "effects": [ "Append local release decision; do not deploy a definition or migrate runs", "On missing authority, stale revision or unresolved required input, refuse mutation and record the reason." ], "source_refs": [ "SRC-004", "SRC-008" ] }, { "id": "fn-register-run", "name": "Register an evidenced run", "description": "Proposed local operation, unimplemented. Record initiation evidence only; do not start external work.", "inputs": [ "external initiation evidence", "edition pin", "run key" ], "outputs": [ "local run record or duplicate/refusal result" ], "preconditions": [ "Authorized recorder", " admissible edition", " duplicate key checked" ], "effects": [ "Record initiation evidence only; do not start external work", "On missing authority, stale revision or unresolved required input, refuse mutation and record the reason." ], "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] }, { "id": "fn-record-observation", "name": "Record a step observation", "description": "Proposed local operation, unimplemented. Append observation; duplicate events do not duplicate effects; do not execute the step.", "inputs": [ "run and occurrence keys", "attempt", "times", "provenance" ], "outputs": [ "accepted observation or conflict record" ], "preconditions": [ "Authorized source", " known run", " schema and event key checked" ], "effects": [ "Append observation; duplicate events do not duplicate effects; do not execute the step", "On missing authority, stale revision or unresolved required input, refuse mutation and record the reason." ], "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] }, { "id": "fn-assess-recovery", "name": "Assess a recovery proposal", "description": "Proposed local operation, unimplemented. Read-only assessment; no retry, cancellation or compensation is performed.", "inputs": [ "attempt history", "effect evidence", "retry or compensation policy" ], "outputs": [ "recovery recommendation with uncertainty or refusal" ], "preconditions": [ "Authorized reader", " policy and current state available" ], "effects": [ "Read-only assessment; no retry, cancellation or compensation is performed", "On missing authority, stale revision or unresolved required input, refuse mutation and record the reason." ], "source_refs": [ "SRC-001", "SRC-007", "SRC-008" ] }, { "id": "fn-report-conformance", "name": "Build a scoped assessment", "description": "Proposed local operation, unimplemented. Create a local report only; do not certify engine or legal conformance.", "inputs": [ "edition", "trace snapshot", "metric or mapping rules" ], "outputs": [ "assessment with evidence gaps and disclosure limits" ], "preconditions": [ "Authorized analyst", " explicit population and purpose", " protected export policy" ], "effects": [ "Create a local report only; do not certify engine or legal conformance", "On missing authority, stale revision or unresolved required input, refuse mutation and record the reason." ], "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-008" ] } ], "composition": [ { "target": "WM-ACT-002", "relation": "REFERENCE", "purpose": "Optional act evidence for a step occurrence; no one-to-one requirement.", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "target": "WM-ACT-009", "relation": "REFERENCE", "purpose": "Pin an instruction edition when adopted; candidate registry relationship qualified as optional.", "required": false, "source_refs": [ "SRC-004", "SRC-001" ] }, { "target": "WM-KNW-012", "relation": "REFERENCE", "purpose": "Resolve applicable policy or rule editions and authority separately.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "https://www.omg.org/spec/BPMN/2.0.2", "relation": "ALIGN", "purpose": "Conceptual flow and instance alignment; executable mapping deferred.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "https://www.omg.org/spec/CMMN/1.1", "relation": "ALIGN", "purpose": "Optional runtime-planning profile; does not absorb external case masters.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "https://www.w3.org/TR/scxml/", "relation": "ALIGN", "purpose": "State configuration alignment with explicit semantic differences.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "https://www.commonwl.org/v1.2/Workflow.html", "relation": "ALIGN", "purpose": "Computational workflow profile only; not a universal runtime.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "https://www.w3.org/TR/prov-o/", "relation": "ALIGN", "purpose": "Evidence attribution for plans, activities and agents, without truth certification.", "required": false, "source_refs": [ "SRC-004" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Accountable process steward reference with authority scope", "Execution record custodian reference and retention/access policy", "Pinned semantic profile, namespace and master-system registry", "Definition, run and artifact identity resolution rules" ], "namespace_guidance": "Use an owner-controlled namespace and stable process, edition, run and occurrence keys. Never encode names, dates or mutable state as identity. No named company is prescribed as owner.", "registry_links": [ "vr.wm-act-003", "WM-ACT-002", "WM-ACT-009", "WM-KNW-012" ] }, "canon_and_patch": { "canonicalization_rules": [ "This research package remains a noncanonical reviewable draft under the single-provider waiver.", "Preserve separately keyed editions and evidence. Do not flatten concurrency or null/missing distinctions." ], "patch_rules": [ "Edit drafts with expected-revision checks; released editions receive a new revision and change record.", "Append corrections and explicit migration records; forbid silent rewriting of historical edition bindings." ], "compatibility_rules": [ "Version guards, input/output contracts and state semantics; require an explicit loss assessment for adapters.", "Existing runs retain their adopted edition until an authorized, evidenced migration; replacement does not erase earlier obligations." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier", "Owner namespace plus stable local identifier", "Digest as content integrity evidence only" ], "timestamp_rule": "Record event and observation times in RFC 3339 with seconds and explicit UTC offset; preserve source precision and uncertainty. Unknown time remains unknown, never synthesized from a filename.", "serial_naming_rule": "Use stable artifact ID plus a separate sequence and revision. Timestamps are metadata, never the primary identity.", "integrity_rule": "Retain digest, media type, origin, transformation and authorized correction links. Digest equality proves byte equality only. Minimize retained payloads and honor lawful disposition." }, "policies": [ "All local operations require declared custody, purpose and operation-specific authority; proposed functions confer none.", "Separate observation, inference and unknown state. Late evidence can revise an assessment without rewriting an event.", "Protect execution data and minimize worker surveillance; aggregate disclosure needs an explicit review.", "Specialized or dangerous activities require qualified domain policy review; this generic model contains no operational domain instructions.", "Retention and access are local proposed controls requiring applicable policy review, not claims derived from a notation standard." ], "crud": { "read": [ "Resolve pinned editions and check bundle, layer, finding and artifact access before returning any data." ], "create": [ "Create locally scoped records only with authority and duplicate checks; a run record does not start a real workflow." ], "update": [ "Use expected revision, preserve provenance and review changes to authority, routing, mappings or instance bindings." ], "delete": [ "Retire definitions while resolvable references remain necessary. Apply retention and legal holds to evidence; controlled deletion or redaction may remove payloads with minimal lawful tombstones.", "Do not equate append-only audit design with indefinite personal-data retention. Deletion of a record does not undo external effects." ] }, "roles": [ { "name": "Process steward", "responsibilities": [ "Approve definition scope and release evidence." ] }, { "name": "Execution custodian", "responsibilities": [ "Maintain run records and scoped retention." ] }, { "name": "Authorized performer", "responsibilities": [ "Supply evidence within assigned operation authority." ] }, { "name": "Evidence reviewer", "responsibilities": [ "Challenge observations, uncertainty and conformance claims." ] }, { "name": "Access administrator", "responsibilities": [ "Maintain scoped disclosure policy without claiming process authority." ] } ], "access": { "default_rule": "Deny access unless policy authorizes the actor, object, operation and context; definition visibility never implies run-data visibility.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency access, if permitted by adopted policy, is scoped, time-limited and reviewed; record justification and affected records." ], "audit_requirements": [ "Record actor, operation, target, policy version, decision, time and evidence reference with minimal necessary payload." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read AGENTS.md and research holds first.", "Read spec.yaml, owner policies and pinned semantic profile.", "Resolve master identities, authority and evidence before local population or validation." ] } }, "coverage": { "claim": "Source-grounded proposed process aggregate with separately identified definition editions and execution records. A separate frozen local Codex no-tools self-audit found no critical contradiction. Independent review, source/version checks, adoption profiles and executable conformance remain holds. This is a noncanonical reviewable draft, not a workflow engine or a universal process standard.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Family, edition, run, occurrence and attempt keys are distinct." }, { "dimension": "lifecycle", "status": "covered", "notes": "Release, runtime states, terminal reasons and supersession are recorded." }, { "dimension": "relationships", "status": "covered", "notes": "External acts, methods, policies and subjects remain references." }, { "dimension": "temporal", "status": "covered", "notes": "Event and observation times, uncertainty and calendar assumptions are explicit." }, { "dimension": "provenance", "status": "covered", "notes": "Attribution, snapshots, corrections and transformation evidence are proposed." }, { "dimension": "ownership", "status": "covered", "notes": "Definition stewardship and execution custody are separate scopes." }, { "dimension": "validation", "status": "gap", "notes": "Research structure validated; nested schemas, executable profiles and fixtures remain incomplete." }, { "dimension": "access", "status": "covered", "notes": "Operation-specific access at all four structural scopes." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual mappings only; round-trip and execution equivalence unproven." }, { "dimension": "properties", "status": "covered", "notes": "Purpose, trigger, release status and runtime state are direct nonphysical properties." }, { "dimension": "recognition", "status": "covered", "notes": "Classify definitions, runs, occurrences and projections before assigning identity." }, { "dimension": "capabilities and behavior", "status": "covered", "notes": "Distinguish proposed local operations, external actions, authority, effects and reversibility." }, { "dimension": "physical measurement", "status": "not-applicable", "notes": "The workflow aggregate is abstract; physical observations belong to referenced subjects or acts." }, { "dimension": "provider assurance", "status": "gap", "notes": "Only Codex research; separate local self-audit cannot replace independent external review." } ], "known_omissions": [ "Independent second-provider review is waived.", "Direct HTTP checks are not attempted under the owner-reported sandbox restriction; browser content access is recorded separately.", "Nested schemas, executable mappings, concurrency tests and model-specific neighbor version pins remain incomplete.", "No complete BPMN, CMMN, SCXML, CWL or event-log conformance is implemented.", "Jurisdiction, sector, privacy, labor, retention and intervention rules require qualified adoption profiles." ], "conflicts": [], "regional_assumptions": [ "No jurisdiction or industry is assumed. Technical specifications support conceptual distinctions, not legal authority.", "Human, automated and mixed workflows need distinct adopted profiles; computational examples do not define all processes." ], "adversarial_checks": [ "Duplicate initiation and retry after an unknown external result must not imply another authorized effect.", "A parallel branch completion cannot be treated as whole-run success.", "Missing evidence, optional runtime planning and actual rule violations must remain distinguishable.", "Edition migration must account for pending work and compensation obligations.", "Workflow completion cannot alter the state or legal status of a separate case.", "Correcting or disposing of evidence must reconcile traceability with retention and access policy." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The logical process family groups separately identified definitions, editions, runs and step occurrences with explicit identity and custody boundaries. Aggregate does not imply one transaction or one owner. The registry standalone-mm value is a record-plane classification; external subject, method, case, task and act masters remain separate." }, "decisions": [ { "concept": "Process aggregate boundary", "disposition": "accepted", "rationale": "The model explicitly groups definition and execution records without conflating their identities, custody or transactional lifecycles." }, { "concept": "Legacy one-to-one step and act mapping", "disposition": "rejected", "rationale": "Occurrences and attempts preserve process context; atomic acts are optional evidence links and neither identity is derived from the other." }, { "concept": "Method and incoming registry relationships", "disposition": "qualified", "rationale": "Adopted method editions are pinned when present. Incoming service, task and cross-cutting references do not become mandatory reverse containment." }, { "concept": "Definition release and migration", "disposition": "accepted", "rationale": "New editions do not silently replace the binding of an active run; explicit migration accounts for active work and unresolved obligations." }, { "concept": "Routing and data semantics", "disposition": "accepted with profile hold", "rationale": "Parallel joins, unknown guards, loops, optional planning and skipped outputs remain explicit questions for the selected profile, not universal execution claims." }, { "concept": "Role, custody and operation permission", "disposition": "separated", "rationale": "Eligibility and capability do not authorize an action. Definition stewardship, run custody and operation-specific access remain separate scopes." }, { "concept": "Run state and external subject state", "disposition": "separated", "rationale": "Local completion, failure or cancellation is not a state change in a separate case or subject and does not establish legal or physical effects." }, { "concept": "Occurrence and observation identity", "disposition": "accepted", "rationale": "Occurrence, branch and attempt keys separate repeated work from duplicate observations; timestamps preserve event time, observation time and uncertainty." }, { "concept": "Deviation and permitted runtime planning", "disposition": "qualified", "rationale": "The proposal distinguishes variation, missing evidence, failure and unauthorized deviation rather than declaring every unplanned path nonconformant." }, { "concept": "Retry, cancellation and compensation", "disposition": "accepted with effect limits", "rationale": "Unknown results, partial compensation and irreversible effects survive local closure. HTTP idempotence cannot establish business exactly-once behavior." }, { "concept": "Proposed local operations", "disposition": "accepted as unimplemented", "rationale": "All six functions record or assess local evidence with authority and refusal conditions; none starts external work or performs cancellation, retry or compensation." }, { "concept": "Measurement, disclosure and retention", "disposition": "accepted with policy dependency", "rationale": "Metric populations, timing assumptions and evidence gaps are explicit. Disclosure and disposal require scoped policy, avoiding perpetual retention or automatic worker ranking." }, { "concept": "Interchange and source assurance", "disposition": "limited", "rationale": "Mappings are conceptual and selected source readings remain bounded. Direct HTTP was not attempted; the extraction-title and page-version anomalies are documented, not hidden." }, { "concept": "Independent review and executable acceptance", "disposition": "held", "rationale": "A local self-audit supplies no independent provider agreement. Nested schemas, pinned neighbor bindings and adversarial runtime fixtures remain unimplemented adoption gates." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not an independent second-provider review.", "Live source and version verification is incomplete. Direct HTTP was not attempted under the owner-reported sandbox restriction and no status was measured. Selected browser content and source-specific limits are documented; the coordinator must run check_sources.py and review versions, errata, licensing and claim support.", "Jurisdiction, sector, privacy, labor, retention, intervention authority and dangerous-domain controls need qualified adoption profiles before operational use. No legal effect or compliance certification is claimed.", "Nested instance schemas, pinned neighbor bindings, executable notation mappings, state and concurrency semantics, timer/calendar rules and adversarial fixtures remain incomplete. No workflow runtime, round-trip fidelity or conformance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore independent external review and verify source versions, errata, licensing and applicability before canonical promotion.", "Develop adoption profiles and executable schemas with fixtures for duplicate initiation, parallel completion, missing guards, late events, unknown retry outcomes, compensation failure, edition migration and lawful evidence disposal.", "Implement and test bounded BPMN, CMMN, SCXML, CWL and provenance mappings, including unsupported constructs, round-trip loss and references to independently mastered neighbors." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 12, "questions": 48, "artifacts": 12, "functions": 6 } }