# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "research-draft", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-25T09:59:53Z", "synthesisSha256": "c1104b3d02abd63ae671e3d463be18a591c2ade178464f0f5aa1e3e4f35e0585", "providers": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ACT-005", "registryId": "vr.wm-act-005", "name": "Project", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.PRJ" ], "tags": [ "project", "act.prj" ], "status": "research draft" }, "canonicalUrl": "https://ver.cy/models/wm-act-005-project/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-005", "model": { "registry_id": "vr.wm-act-005", "model_id": "WM-ACT-005", "name": "Project", "entry_kind": "aggregate", "purpose": "Provide the format-neutral context an agent needs to understand, create, inspect and operate one bounded undertaking: its identity, mandate, scope, breakdown, commitments, baselines, lifecycle, performance, uncertainty, records and closure.", "scope_statement": "A Project is a temporary, uniquely-scoped endeavour authorized by a sponsor to deliver defined outputs, outcomes or benefits within agreed constraints (ISO 21500:2021 concepts; ISO 21502:2020 practices; APM 'unique, transient endeavour'). This model owns the project as an aggregate root: identification and registration, authorization and governance, objectives and scope boundary, work breakdown, resource/funding/procurement commitments, lifecycle states and gates, approved baselines and change control, progress measurement, risk/issue/assurance, stakeholders, record provenance and access, and closure with retention. It holds typed edges to contained tasks and milestones/deliverables rather than restating their internals. It is storage- and interface-neutral: JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections of the same semantics.", "in_scope": [ "Project identity, alternate identifiers and registration in an authoritative master system", "Authorization instrument, sponsor, governing body and delegated decision authority", "Objectives, success criteria and the declared scope boundary with exclusions", "Work breakdown structure, control accounts and typed links to contained components", "Resource, budget, cost-baseline and supplier commitments bound to the project", "Lifecycle states, phases, decision gates and permitted transitions", "Approved scope, schedule and cost baselines, their versioning and change control", "Progress and performance measurement including earned value where applicable", "Risk, issue, escalation and independent assurance records", "Stakeholder register, reporting obligations and disclosure duties", "Record provenance, evidence, access classification, closure and retention" ], "out_of_scope": [ "Task-level execution detail, effort logging and assignment mechanics (WM-ACT-006)", "Internal structure and acceptance criteria of milestones and deliverables (WM-ACT-031)", "Programme and portfolio selection, balancing and benefit aggregation (WM-ACT-029; ISO 21503, ISO 21504)", "Schedule network logic, dependency calculus and critical-path computation (sibling plan/schedule model)", "Definitions of repeatable processes and workflows (sibling process model)", "Person and organization master data (sibling person/organization models)", "Financial ledger postings, payroll and statutory accounting", "Contract instrument text and procurement award procedure internals", "Product, system or asset definitions of whatever the project produces", "Generic access-control and audit machinery, which is a service-layer concern" ], "boundary_notes": [ { "neighbor": "Programme and portfolio (WM-ACT-029)", "distinction": "Component selection, balancing against strategy and aggregated benefit realization sit above the project; ISO 21504:2022 explicitly does not give project management guidance and ISO 21503:2022 keeps benefit realization at programme level. The project records only benefits it is itself accountable for.", "source_refs": [ "SRC-018", "SRC-019", "SRC-001" ] }, { "neighbor": "Task (WM-ACT-006)", "distinction": "The project owns decomposition down to work-package or control-account level (ISO 21511:2018); assignable execution units, their states and effort belong to the task model and are referenced by typed edge, not copied.", "source_refs": [ "SRC-004", "SRC-001" ] }, { "neighbor": "Milestone and deliverable (WM-ACT-031)", "distinction": "The project references milestones and deliverables, gates on them and reports variance against them; their acceptance criteria, versions and internal composition are owned by the contained model.", "source_refs": [ "SRC-001", "SRC-004" ] }, { "neighbor": "Plan and schedule (sibling K7)", "distinction": "The project binds authoritative planned/actual dates and approved baselines; activity network logic, durations, float and critical path are schedule-model semantics (GAO-16-89G scheduling practices).", "source_refs": [ "SRC-013", "SRC-001" ] }, { "neighbor": "Process and workflow (sibling K3)", "distinction": "A project is unique and transient; a process is repeatable. Repeatable procedures used inside a project are referenced, and the same work executed as steady-state operations is not a project (APM).", "source_refs": [ "SRC-016", "SRC-002" ] }, { "neighbor": "PROV Activity and Plan (W3C PROV-O)", "distinction": "PROV supplies attribution, generation and plan semantics for alignment. A project is not the provenance graph of every act performed; individual acts resolve to the act model and are related by prov:wasAssociatedWith style edges.", "source_refs": [ "SRC-006" ] }, { "neighbor": "schema.org Project", "distinction": "schema.org types Project as a subtype of Organization (an agent). This conflicts with the ISO/APM definition of a project as a temporary endeavour. Alignment is publication-only and lossy; conformance is not claimed.", "source_refs": [ "SRC-017", "SRC-002", "SRC-016" ] }, { "neighbor": "IATI activity", "distinction": "An IATI activity may be a project, a sub-activity or a funding slice, distinguished by @hierarchy and related-activity edges. IATI is treated as an alignment and publication target, not as the identity authority for a project.", "source_refs": [ "SRC-007", "SRC-021" ] } ] }, "sources": [ { "id": "SRC-001", "title": "ISO 21502:2020 Project, programme and portfolio management — Guidance on project management", "organization": "ISO/TC 258", "url": "https://committee.iso.org/sites/tc258/home/projects/published/iso-21502.html", "version_or_date": "2020 edition, ISO/TC 258 published-project page", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Primary guidance on project management practices: directing, initiating, planning, benefits, scope, resources, schedule, cost, risk, issue, change control, quality, stakeholders, reports, information management, acquisitions and lessons learned; states applicability to predictive, incremental, iterative, adaptive and hybrid approaches." }, { "id": "SRC-002", "title": "SS-ISO 21500:2022 / ISO 21500:2021 Project, programme and portfolio management — Context and concepts", "organization": "Swedish Institute for Standards (SIS), adopting ISO 21500:2021", "url": "https://www.sis.se/en/produkter/sociology-services-company-organization/company-organization-and-management/research-and-development/ss-iso-215002022/", "version_or_date": "ISO 21500:2021, national adoption published 2022-10-06", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Defines the organizational context and underlying concepts for project, programme and portfolio management and positions ISO 21502/21503/21504/21505; basis for the project-versus-operations and project-versus-programme boundaries." }, { "id": "SRC-003", "title": "ISO 21505:2017 Project, programme and portfolio management — Guidance on governance", "organization": "ISO/TC 258", "url": "https://committee.iso.org/sites/tc258/home/projects/published/iso-21505.html", "version_or_date": "2017 edition, ISO/TC 258 published-project page", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Governance context and guidance for governing bodies, sponsors, steering committees and project management offices; supports authority, delegation, assurance and verification findings." }, { "id": "SRC-004", "title": "ISO 21511:2018 Work breakdown structures for project and programme management", "organization": "ISO/TC 258", "url": "https://committee.iso.org/sites/tc258/home/projects/published/iso-21511-ed1.html", "version_or_date": "2018 edition, ISO/TC 258 published-project page", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Terms, concepts, characteristics, uses, integration and relationships of work breakdown structures and their relationship to other breakdown structures; explicitly excludes processes, methods and tools." }, { "id": "SRC-005", "title": "ISO 21508:2018 Earned value management in project and programme management", "organization": "ISO", "url": "https://www.iso.org/standard/63582.html", "version_or_date": "2018 edition, ISO catalogue entry", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Integrates scope, actual cost, budget and schedule for progress and performance assessment; requires decomposition into a work breakdown structure with mutually exclusive scope elements; excludes specific processes, methods and tools." }, { "id": "SRC-006", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Entity, Activity, Agent, Plan and Association with hadPlan; wasGeneratedBy, wasAttributedTo, wasAssociatedWith, actedOnBehalfOf, startedAtTime and endedAtTime give the alignment vocabulary for project provenance, attribution and delegation." }, { "id": "SRC-007", "title": "IATI Activity Standard 2.03 — iati-activity element", "organization": "IATI (International Aid Transparency Initiative)", "url": "https://iatistandard.org/en/iati-standard/203/activity-standard/iati-activities/iati-activity/", "version_or_date": "IATI Standard version 2.03", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "A working, published data model for bounded undertakings: iati-identifier, reporting-org, participating-org, activity-status, activity-date, budget, transaction, planned-disbursement, location, sector, result/indicator, document-link, conditions, plus @hierarchy, @last-updated-datetime and @default-currency." }, { "id": "SRC-008", "title": "IATI ActivityStatus codelist (version 2.03)", "organization": "IATI (International Aid Transparency Initiative)", "url": "https://iatistandard.org/en/iati-standard/203/codelists/activitystatus/", "version_or_date": "IATI Standard version 2.03 codelist", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "A normative, governed lifecycle-state vocabulary: Pipeline/identification, Implementation, Finalisation, Closed, Cancelled, Suspended — evidence that state sets must be declared with their scheme rather than assumed." }, { "id": "SRC-009", "title": "IATI Activity Standard 2.03 — activity-date element and ActivityDateType", "organization": "IATI (International Aid Transparency Initiative)", "url": "https://iatistandard.org/en/iati-standard/203/activity-standard/iati-activities/iati-activity/activity-date/", "version_or_date": "IATI Standard version 2.03", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Type-coded planned start, actual start, planned end and actual end dates with mandatory @iso-date, ordering rules and the rule that actual dates must not be in the future; direct support for the temporal-frame finding." }, { "id": "SRC-010", "title": "Research Activity Identifier (RAiD) Metadata Schema, standardized as ISO 23527:2022", "organization": "Australian Research Data Commons (ARDC), RAiD Registration Authority", "url": "https://metadata.raid.org/en/latest/", "version_or_date": "RAiD Metadata Schema 1.0 documentation; ISO 23527 published December 2022", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "An ISO-standardized persistent identifier and metadata record for projects and sub-projects: identifier, metadata timestamps, date, title, description, contributor, organisation, related object, alternate identifier, alternate URL, related RAiD, access, subject and spatial coverage; core/extended/local component tiers." }, { "id": "SRC-011", "title": "DataCite Metadata Schema 4.6 — resourceTypeGeneral controlled list", "organization": "DataCite", "url": "https://datacite-metadata-schema.readthedocs.io/en/4.6/appendices/appendix-1/resourceTypeGeneral/", "version_or_date": "DataCite Metadata Schema 4.6", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Defines Project as a resource type: 'A planned endeavor or activity, frequently collaborative, intended to achieve a particular aim using allocated resources such as budget, time, and expertise' — an independent, citable definition and a global identifier pathway." }, { "id": "SRC-012", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "July 2002, Proposed Standard (updated by RFC 9557)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Normative timestamp form: numeric offset as local time minus UTC, the Z designator for a zero offset, second values including leap-second handling, and -00:00 reserved for an unknown local offset." }, { "id": "SRC-013", "title": "GAO Schedule Assessment Guide: Best Practices for Project Schedules (GAO-16-89G)", "organization": "U.S. Government Accountability Office", "url": "https://www.gao.gov/products/gao-16-89g", "version_or_date": "GAO-16-89G, published 2015-12-22", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Ten best practices for developing and maintaining a reliable schedule; treats the schedule as a model of time supporting performance measurement against an approved plan and analysis of how change affects the programme." }, { "id": "SRC-014", "title": "GAO Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs (GAO-20-195G)", "organization": "U.S. Government Accountability Office", "url": "https://www.gao.gov/products/gao-20-195g", "version_or_date": "GAO-20-195G, published 2020-03-12", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Cost estimating steps including technical baseline description and work breakdown structure, baselining, risk and uncertainty treatment, and earned value management; supports budget, reserve and performance findings." }, { "id": "SRC-015", "title": "NPR 7120.5F NASA Space Flight Program and Project Management Requirements w/Change 4", "organization": "NASA (NASA Online Directives Information System)", "url": "https://nodis3.gsfc.nasa.gov/displayDir.cfm?t=NPR&c=7120&s=5F", "version_or_date": "Effective 2021-08-03, expiration 2027-02-03", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "A binding institutional regime showing programme and project life cycles, review boards and mandated baseline instruments (Formulation Agreement, Project Plan, Program Commitment Agreement); evidence that gate and baseline artifacts are real, sector-specific obligations." }, { "id": "SRC-016", "title": "What is project management?", "organization": "Association for Project Management (APM)", "url": "https://www.apm.org.uk/resources/what-is-project-management/", "version_or_date": "APM resource page, accessed 2026-08-25", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Defines a project as 'a unique, transient endeavour, undertaken to achieve planned objectives, which could be defined in terms of outputs, outcomes or benefits' and identifies finite timespan as the distinction from ongoing operations." }, { "id": "SRC-017", "title": "schema.org type: Project (version 30.0)", "organization": "Schema.org / W3C Schema.org Community Group", "url": "https://schema.org/Project", "version_or_date": "schema.org release v30.0, 2026-03-19", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Publication-facing type 'an enterprise (potentially individual but typically collaborative), planned to achieve a particular aim', modelled as a subtype of Organization with funder, funding, sponsor, member, parentOrganization and subOrganization; source of a recorded modelling conflict." }, { "id": "SRC-018", "title": "ISO 21504:2022 Project, programme and portfolio management — Guidance on portfolio management", "organization": "ISO", "url": "https://www.iso.org/standard/82867.html", "version_or_date": "2022 edition, ISO catalogue entry", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "States that portfolio management supports organizational strategy and explicitly does not provide guidance on project or programme management; the upper boundary of this model." }, { "id": "SRC-019", "title": "ISO 21503:2022 Project, programme and portfolio management — Guidance on programme management", "organization": "ISO", "url": "https://www.iso.org/standard/82868.html", "version_or_date": "2022 edition, ISO catalogue entry", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Programme-level definitions, prerequisites, roles and responsibilities directed at realizing benefits; distinguishes programme benefit realization from project-level delivery." }, { "id": "SRC-020", "title": "General Records Schedules (GRS)", "organization": "U.S. National Archives and Records Administration (NARA)", "url": "https://www.archives.gov/records-mgmt/grs", "version_or_date": "GRS programme page, last reviewed 2026-06-12", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Shows how disposition authority works in practice: schedules issued by a records authority, mandatory application except in justified circumstances, transmittals for revisions and formal requests for deviation; anchors retention and deletion rules." }, { "id": "SRC-021", "title": "IATI Activity Standard 2.03 — related-activity element", "organization": "IATI (International Aid Transparency Initiative)", "url": "https://iatistandard.org/en/iati-standard/203/activity-standard/iati-activities/iati-activity/related-activity/", "version_or_date": "IATI Standard version 2.03", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Typed inter-record links by @ref and @type, with the rule that hierarchical grouping is always expressed with parent (1) or child (2) edges; a working model for cross-record typed edges." }, { "id": "SRC-022", "title": "ISO 21502:2020 Clause 6 Integrated project management practices / Clause 7 management practices summary", "organization": "Pretesh Biswas (independent consultancy commentary)", "url": "https://preteshbiswas.com/2024/02/07/iso-215022020-clause-6-integrated-project-management-practices/", "version_or_date": "Published 2024-02-07", "source_type": "secondary", "primary_source": false, "authority_tier": 4, "accessed_at": "2026-08-25T11:20:00Z", "relevance": "Secondary corroboration of the clause 7 subclause enumeration (planning, benefits, scope, resources, schedule, cost, risk, issue, change control, quality, stakeholders, communication, organizational change, reports, information and documentation, acquisitions, lessons learned) used only to check for omissions; the paywalled ISO text was not read in full." }, { "id": "SRC-023", "title": "ISO 21502:2020 Project, programme and portfolio management — Guidance on project management", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/74947.html", "version_or_date": "2020-12, Edition 1", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T00:00:00Z", "relevance": "Normative project-management guidance; applicable to any organization and any project regardless of purpose, delivery approach, lifecycle model, complexity, size, cost or duration. Explicitly excludes programme and portfolio management. Delivery approaches include predictive, incremental, iterative, adaptive or hybrid, including agile." }, { "id": "SRC-024", "title": "ISO 21500:2021 Project, programme and portfolio management — Context and concepts", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/75704.html", "version_or_date": "2021-03, Edition 2", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T00:00:00Z", "relevance": "Foundational context for project, programme and portfolio management and for adopting the ISO/TC 258 series. Points to ISO 21502, 21503, 21504 and 21505 for further guidance." }, { "id": "SRC-025", "title": "ISO 21511:2018 Work breakdown structures for project and programme management", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/69702.html", "version_or_date": "2018-05, Edition 1; under revision as ISO/DIS 21511", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T00:00:00Z", "relevance": "Guidance on WBS terms, definitions, concepts, characteristics, uses, integration and relationships with other breakdown structures. Does not prescribe tools. Annexes give examples and related structures." }, { "id": "SRC-026", "title": "Improving project management", "organization": "International Organization for Standardization", "url": "https://www.iso.org/news/ref2645.html", "version_or_date": "2021-03-23", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-25T00:00:00Z", "relevance": "First-party ISO overview of the 21500 series: 21502 practices across the lifecycle including planning and control, risk, issues, change control, benefits, business and societal change and information; also 21503, 21504, 21505 governance, 21508 earned value, 21511 WBS." }, { "id": "SRC-027", "title": "NPR 7120.5F NASA Space Flight Program and Project Management Requirements, Chapter 2", "organization": "National Aeronautics and Space Administration", "url": "https://nodis3.gsfc.nasa.gov/displayDir.cfm?Internal_ID=N_PR_7120_005F_&page_name=Chapter2", "version_or_date": "Effective 2021-08-03, expiration 2027-02-03, with Change 4", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T00:00:00Z", "relevance": "Mandatory NASA space-flight project definition, categorization, Formulation/Implementation lifecycle, KDPs, LCRs, FAD, Formulation Agreement, Project Plan, Decision Authority, Management Agreement, Agency Baseline Commitment, WBS, EVM above cost threshold, Decision Memorandum, continuing-operations initial-capability cost, decommissioning." }, { "id": "SRC-028", "title": "Government Functional Standard GovS 002: Project Delivery", "organization": "Government Project Delivery and Cabinet Office, United Kingdom", "url": "https://www.gov.uk/government/publications/project-delivery-functional-standard", "version_or_date": "Version 2.1, last updated 2025-09-17", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-25T00:00:00Z", "relevance": "Mandated UK government expectations for portfolios, programmes and projects. Eight elements: about the standard; principles; overview and context; governance and roles; portfolio management; programme and project management; planning and control; solution delivery. v2.1 adds policy and evaluation context, senior officer accountable for project delivery, mandatory governance roles, and transition, use and disposal of a solution; references The Teal Book and the Senior Responsible Owner." }, { "id": "SRC-029", "title": "What is a Project, Examples and the Project Lifecycle", "organization": "Project Management Institute", "url": "https://www.pmi.org/about/what-is-a-project", "version_or_date": "PMI public definition page, retrieved 2026-08-25", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-25T00:00:00Z", "relevance": "Official PMI definition: a project is a temporary endeavor undertaken to create a unique product, service, or result. Describes a project lifecycle of phases culminating in deliverables, including feasibility, design and build. Direct HTTP fetch was blocked; wording is taken from the live PMI page as returned by search of that URL." }, { "id": "SRC-030", "title": "PRINCE2 Project Management Practitioner (Version 7)", "organization": "PeopleCert", "url": "https://www.peoplecert.org/browse-certifications/project-programme-and-portfolio-management/PRINCE2-2/PRINCE2-7-practitioner-3581", "version_or_date": "PRINCE2 Project Management Version 7", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-25T00:00:00Z", "relevance": "Seven principles, seven practices addressed continuously through the lifecycle, seven processes from initiation to delivery, defined roles, people management, sustainability and ESG, digital and data management, and mandatory tailoring to project context." } ], "structure": { "bundles": [ { "id": "b-mandate-and-identity", "name": "Mandate and identity", "description": "Who and what this project is, who authorized it, who owns it and why the investment is justified.", "rationale": "ISO 21500:2021 places projects inside an organizational and strategic context, and ISO 21505:2017 makes governing bodies and sponsors the source of mandate. Nothing downstream (scope, baselines, spend) is interpretable without a resolvable identity and an authorization instrument, so identity and mandate form the first bundle.", "source_refs": [ "SRC-002", "SRC-003", "SRC-001", "SRC-010" ], "layers": [ { "id": "l-identity-and-registration", "name": "Identity and registration", "description": "Resolvable identification and governed classification of the project across the master system and external registries.", "source_refs": [ "SRC-010", "SRC-011", "SRC-007", "SRC-001" ], "findings": [ { "id": "f-project-identity", "name": "Project identity and identifier reconciliation", "description": "Which identifier authoritatively designates this project, which system issued it, which governed global identifiers also designate it, and how duplicate or superseding records are resolved.", "source_refs": [ "SRC-010", "SRC-011", "SRC-007", "SRC-001" ], "questions": [ { "id": "q-master-identifier", "text": "Which system of record issues the authoritative identifier for this project, and what is that identifier?", "kind": "identity", "answer_data": [ "Master system name and instance", "Authoritative identifier value", "Identifier scheme and syntax rule", "Issuing date-time of assignment" ] }, { "id": "q-global-identifiers", "text": "Which governed global identifiers, such as a RAiD, a funder award number or a published activity identifier, also designate this project?", "kind": "interoperability", "answer_data": [ "Identifier type", "Identifier value", "Issuing registry or registration agency", "Resolution URL" ] }, { "id": "q-identity-collision-rule", "text": "What rule decides identity when two records appear to describe the same undertaking under different identifiers?", "kind": "validation", "answer_data": [ "Match criteria set", "Precedence order between schemes", "Merge, supersede or reject decision", "Deciding role and decision time" ] }, { "id": "q-identifier-stability", "text": "Does the identifier survive renaming, re-scoping, transfer or merger, and what event forces a new identifier?", "kind": "lifecycle", "answer_data": [ "Stability policy statement", "Re-issue trigger list", "Superseded-by reference", "Retained alias list" ] } ], "data_elements": [ { "id": "de-project-identifier", "name": "Project identifier", "description": "Authoritative identifier of the project issued by its master system of record.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-007" ] }, { "id": "de-identifier-scheme", "name": "Identifier scheme", "description": "Scheme or namespace under which the authoritative identifier is issued, including scheme version where governed.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-011" ] }, { "id": "de-alternate-identifier", "name": "Alternate identifier", "description": "Any further identifier designating the same project, each recorded with its issuing registry and resolution target.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-007" ] }, { "id": "de-superseded-by-project", "name": "Superseded-by project reference", "description": "Reference to the project record that replaces this one after a merge, split or re-charter.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-021" ] } ], "artifacts": [ { "id": "a-identifier-registration-record", "name": "Identifier registration record", "description": "The record evidencing assignment of the authoritative identifier and any registered global identifiers, with issuing authority and assignment time.", "media_or_form": [ "registry entry", "identifier landing page", "structured assignment record" ], "serial": false, "identity_strategy": "Keyed by the authoritative master-system identifier; each governed global identifier is stored as an alternate identifier bound to its issuing registry and resolution URL. Names, acronyms and charter dates are search aids only and never keys.", "source_refs": [ "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "f-project-classification", "name": "Classification, type and delivery approach", "description": "How the project is typed against governed vocabularies: project type, delivery approach, sector or thematic codes, and the criterion separating it from operations or a process instance.", "source_refs": [ "SRC-001", "SRC-007", "SRC-016", "SRC-017" ], "questions": [ { "id": "q-project-type-vocabulary", "text": "Which project type and domain classification apply, and under which controlled vocabulary and vocabulary version?", "kind": "classification", "answer_data": [ "Type code", "Scheme URI", "Scheme version", "Assignment scope note" ] }, { "id": "q-delivery-approach", "text": "Is delivery predictive, incremental, iterative, adaptive or hybrid, and may that approach change during the life cycle?", "kind": "state", "answer_data": [ "Delivery approach code", "Effective period of the approach", "Change trigger and approver", "Tailoring note" ] }, { "id": "q-classification-assertor", "text": "Which sector, thematic or funding-scheme codes are asserted for this project and who asserted each of them?", "kind": "provenance", "answer_data": [ "Code value and scheme", "Asserting party", "Assertion time", "Assertion basis or evidence" ] }, { "id": "q-project-versus-operations", "text": "What criterion establishes that this record is a transient endeavour rather than business-as-usual or a repeatable process instance?", "kind": "definition", "answer_data": [ "Finite timespan evidence", "Uniqueness statement", "Distinguishing test applied", "Referenced process model, if any" ] } ], "data_elements": [ { "id": "de-project-type-code", "name": "Project type code", "description": "Governed type classification of the project within a named scheme.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "de-delivery-approach-code", "name": "Delivery approach code", "description": "Recorded delivery approach: predictive, incremental, iterative, adaptive or hybrid.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-classification-scheme-uri", "name": "Classification scheme URI", "description": "Resolvable identifier and version of each vocabulary used to classify the project.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-011" ] } ], "artifacts": [ { "id": "a-classification-binding", "name": "Classification binding table", "description": "Table binding the project to external code lists with scheme URI, scheme version, code, asserting party and assertion time.", "media_or_form": [ "code-list binding table", "vocabulary mapping record" ], "serial": false, "identity_strategy": "Composite key of project identifier plus scheme URI plus code; a new binding row is created when the scheme version changes rather than mutating the existing row.", "source_refs": [ "SRC-007", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "l-authority-and-mandate", "name": "Authority and mandate", "description": "The instrument that authorized the project, the parties accountable for it, and the investment justification that keeps it authorized.", "source_refs": [ "SRC-003", "SRC-001", "SRC-015", "SRC-014" ], "findings": [ { "id": "f-charter-and-authorization", "name": "Authorization instrument and mandate limits", "description": "What authorized the project to exist and spend, who signed it, what tolerances bound the project manager, and how authorization behaves on re-baseline, pause or transfer.", "source_refs": [ "SRC-003", "SRC-001", "SRC-015" ], "questions": [ { "id": "q-authorization-instrument", "text": "Which instrument authorized this project to start, and which role signed it?", "kind": "authority", "answer_data": [ "Instrument type and reference", "Signing role and party", "Authorization scope statement", "Signature or approval evidence" ] }, { "id": "q-authorization-evidence", "text": "What decision record evidences the authorization, when did it take effect, and where is that record held?", "kind": "evidence", "answer_data": [ "Decision record reference", "Decision effective time", "Record location or repository", "Retention custodian" ] }, { "id": "q-delegated-tolerance", "text": "What tolerances or delegated limits on cost, time, scope and risk constrain the project manager before escalation is required?", "kind": "constraint", "answer_data": [ "Tolerance dimension", "Threshold value and unit", "Escalation target role", "Tolerance review cadence" ] }, { "id": "q-authorization-continuity", "text": "What happens to the authorization when the project is re-baselined, suspended or transferred to another owner?", "kind": "lifecycle", "answer_data": [ "Re-authorization trigger", "Revision number of the instrument", "Continuity or lapse rule", "Effective and recorded times of the change" ] } ], "data_elements": [ { "id": "de-authorization-instrument-ref", "name": "Authorization instrument reference", "description": "Reference to the charter, agreement or directive that authorizes the project.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-015" ] }, { "id": "de-authorizing-body", "name": "Authorizing body reference", "description": "The party or governing body that granted authorization.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-authorization-effective-time", "name": "Authorization effective time", "description": "Instant from which the authorization takes effect, distinct from the time the record was captured.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-003" ] }, { "id": "de-delegated-tolerance", "name": "Delegated tolerance", "description": "A bounded delegation of authority expressed as a dimension, threshold and escalation target.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] } ], "artifacts": [ { "id": "a-project-charter", "name": "Project charter or authorization decision record", "description": "The signed instrument establishing the project, its mandate, sponsor and delegated limits, retained across revisions.", "media_or_form": [ "signed document", "governing-body decision minute", "structured authorization record" ], "serial": true, "identity_strategy": "Named by the master project identifier plus artifact kind plus a zero-padded monotonic revision number; superseded revisions are retained and marked superseded-by, never overwritten.", "source_refs": [ "SRC-001", "SRC-015", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "f-sponsor-and-governing-body", "name": "Sponsor, owner and governing body", "description": "Who is accountable for the project, which body directs it, which decisions are reserved rather than delegated, and how a change of ownership is recorded.", "source_refs": [ "SRC-003", "SRC-001", "SRC-002" ], "questions": [ { "id": "q-accountable-sponsor", "text": "Who is the accountable sponsor and which organization owns the project record?", "kind": "ownership", "answer_data": [ "Sponsor role holder reference", "Owning organization reference", "Accountability statement", "Effective period of the accountability" ] }, { "id": "q-reserved-decisions", "text": "Which decisions are reserved to the governing body rather than delegated to the project manager?", "kind": "authority", "answer_data": [ "Reserved decision list", "Delegation boundary condition", "Quorum or approval rule", "Reference to the delegation schedule" ] }, { "id": "q-assurance-independence", "text": "How is independence of assurance and handling of conflicts of interest arranged in this governance structure?", "kind": "decision", "answer_data": [ "Assurance reporting line", "Independence criterion", "Conflict declaration record", "Escalation route when independence fails" ] }, { "id": "q-ownership-transfer", "text": "How is a change of sponsor, owning organization or governing body recorded, and from what time is it effective?", "kind": "event", "answer_data": [ "Transfer event record", "Prior and new party references", "Effective time and recorded time", "Authorizing decision reference" ] } ], "data_elements": [ { "id": "de-sponsor-org-ref", "name": "Sponsoring organization reference", "description": "Reference to the organization that charters, funds and owns the project record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "de-governing-body-ref", "name": "Governing body reference", "description": "Reference to the steering committee, board or equivalent that directs the project.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-reserved-decision", "name": "Reserved decision", "description": "A decision type retained by the governing body, with its approval rule.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "a-governance-terms-of-reference", "name": "Governance terms of reference and delegation schedule", "description": "Terms of reference for the governing body together with the schedule of delegated and reserved decisions.", "media_or_form": [ "terms of reference", "delegation matrix", "responsibility assignment record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic version; each version records the authorizing decision and its effective time, and prior versions remain retrievable.", "source_refs": [ "SRC-003", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "f-business-case-and-funding", "name": "Investment justification and funding commitment", "description": "The justification that keeps the project authorized, who committed what funding under which award and conditions, and which benefits the project itself is accountable for.", "source_refs": [ "SRC-001", "SRC-019", "SRC-007", "SRC-014" ], "questions": [ { "id": "q-business-case-revalidation", "text": "What justification supports continued investment, and when was it last re-validated against actual performance?", "kind": "decision", "answer_data": [ "Business case reference", "Last re-validation time", "Re-validation outcome", "Deciding body" ] }, { "id": "q-funding-conditions", "text": "Which funders committed what amounts under which award or agreement, and what conditions attach to each commitment?", "kind": "constraint", "answer_data": [ "Funder reference", "Committed amount, currency and period", "Award or agreement identifier", "Condition text and compliance evidence" ] }, { "id": "q-benefit-accountability-split", "text": "Which benefits is this project accountable for, and which are owned by a parent programme or by operations?", "kind": "relationship", "answer_data": [ "Benefit statement", "Accountable party", "Owning model reference", "Realization horizon" ] }, { "id": "q-tranche-release-evidence", "text": "What evidence must exist before the next funding tranche or stage authorization is released?", "kind": "evidence", "answer_data": [ "Required evidence item", "Assessing role", "Decision point reference", "Consequence of non-satisfaction" ] } ], "data_elements": [ { "id": "de-business-case-ref", "name": "Business case reference", "description": "Reference to the investment justification document or structured record.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-014" ] }, { "id": "de-funding-commitment", "name": "Funding commitment", "description": "A committed sum from a named funder, with currency, period, award reference and conditions.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "de-award-identifier", "name": "Award or grant identifier", "description": "Governed identifier of the award, grant or funding agreement under which the project is financed.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-010" ] }, { "id": "de-benefit-claim-ref", "name": "Benefit claim reference", "description": "Reference to a benefit the project is accountable for, resolvable to the owning benefit or programme record.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-001" ] } ], "artifacts": [ { "id": "a-business-case", "name": "Business case and funding decision record", "description": "The investment justification with its funding commitments, conditions and re-validation history.", "media_or_form": [ "document", "structured investment record", "funding decision minute" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic version; each version pins the cost estimate and benefit assumptions current at its approval time.", "source_refs": [ "SRC-014", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "f-tailoring-and-compliance", "name": "Tailoring and compliance", "description": "ISO 21502 is guidance, not a certified management system, and is delivery-approach-neutral. PRINCE2 Version 7 requires the method to be tailored to the project's size, context and complexity. NASA requires a Compliance Matrix attached to the Formulation Agreement or Project Plan, allows tailoring with permission of the requirement owner, and records deviations and waivers. GovS 002 is mandated for UK departments and arm's length bodies but is designed to apply to all types of government projects. Alignment with a named method is evidence, not proof of conformance. Competing method stacks (PMI process groups, PRINCE2 processes, NASA phases A–F, ISO lifecycle practices) must be recorded as the adopted profile, not merged into a false universal process.", "source_refs": [ "SRC-027", "SRC-030", "SRC-023", "SRC-028" ], "questions": [ { "id": "f-tailoring-and-compliance-q01", "text": "Which method profile is actually in force, and is any conformance claimed with evidence?", "kind": "classification", "answer_data": [ "adopted_method_profile (string[])", "conformance_claim (none|aligned|evidenced-conformant)", "evidence_refs (string[])" ] }, { "id": "f-tailoring-and-compliance-q02", "text": "Who approved each tailoring or waiver, and what expiry or conditions apply?", "kind": "authority", "answer_data": [ "tailoring_decisions (object[])", "waiver_set (object[])", "approver_refs (string[])" ] }, { "id": "f-tailoring-and-compliance-q03", "text": "Where is the live compliance matrix, and which requirements remain unmet?", "kind": "evidence", "answer_data": [ "compliance_matrix_ref (string)", "unmet_requirements (string[])", "last_verified_at (rfc3339)" ] }, { "id": "f-tailoring-and-compliance-q04", "text": "How does the adopted profile map to partner methods when more than one organization is directing work?", "kind": "interoperability", "answer_data": [ "partner_method_maps (object[])", "conflict_notes (text[])" ] } ], "data_elements": [ { "id": "f-tailoring-and-compliance-data01", "name": "adopted_method_profile", "description": "Named methods in force, such as ISO 21502 practices, PRINCE2 7, NASA NPR 7120.5, GovS 002, local hybrid.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-030", "SRC-027", "SRC-028" ] }, { "id": "f-tailoring-and-compliance-data02", "name": "tailoring_decisions", "description": "Requirement or practice tailored, rationale, approver, evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-027", "SRC-030" ] }, { "id": "f-tailoring-and-compliance-data03", "name": "compliance_matrix_ref", "description": "Reference to the live compliance or tailoring matrix.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-027" ] }, { "id": "f-tailoring-and-compliance-data04", "name": "conformance_claim", "description": "none, aligned, or evidenced-conformant, never implied.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-028" ] }, { "id": "f-tailoring-and-compliance-data05", "name": "waiver_set", "description": "Waivers or deviations with owner, expiry and conditions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-027" ] } ], "artifacts": [ { "id": "f-tailoring-and-compliance-artifact01", "name": "Compliance or tailoring matrix", "description": "NASA-style Compliance Matrix or equivalent mapping of required practices to adopted, tailored or waived status.", "media_or_form": [ "matrix attached to the Formulation Agreement or Project Plan" ], "serial": false, "identity_strategy": "Identified by compliance_matrix_ref pointing at the live matrix for project_master_id.", "source_refs": [ "SRC-027", "SRC-030" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-scope-and-structure", "name": "Scope and structure", "description": "What the project has committed to achieve and deliver, where its boundary lies, and how the total scope is decomposed and linked to contained records.", "rationale": "ISO 21502:2020 treats defining, controlling and confirming scope as a distinct practice, and ISO 21511:2018 makes the work breakdown structure the framework for managing the whole scope of work. ISO 21508:2018 further requires decomposition into mutually exclusive scope elements before performance can be measured, so objectives, boundary and breakdown must be a bundle in their own right.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-016" ], "layers": [ { "id": "l-objectives-and-scope-boundary", "name": "Objectives and scope boundary", "description": "The measurable ends the project is accountable for and the declared limit of what it will and will not do.", "source_refs": [ "SRC-016", "SRC-001", "SRC-007" ], "findings": [ { "id": "f-objectives-and-success-criteria", "name": "Objectives and success criteria", "description": "The outputs, outcomes or benefits the project is accountable for, the measurable criteria that decide whether each is met, who judges satisfaction, and how conflicting objectives are prioritized.", "source_refs": [ "SRC-016", "SRC-007", "SRC-001" ], "questions": [ { "id": "q-objective-statement", "text": "What objectives is this project accountable for, expressed as outputs, outcomes or benefits?", "kind": "requirement", "answer_data": [ "Objective statement", "Objective category", "Accountable role", "Linked scope element" ] }, { "id": "q-success-criterion-target", "text": "What measurable criterion, indicator, baseline value and target decides whether each objective has been met?", "kind": "measurement", "answer_data": [ "Indicator name and definition", "Measurement unit and method", "Baseline value", "Target value and target period" ] }, { "id": "q-objective-satisfaction-judge", "text": "Who determines that a success criterion has been satisfied, and on what evidence?", "kind": "validation", "answer_data": [ "Deciding role", "Evidence item reference", "Decision time", "Dispute or re-measurement route" ] }, { "id": "q-objective-priority-conflict", "text": "How are objectives prioritized, and which one yields when two objectives cannot both be satisfied?", "kind": "constraint", "answer_data": [ "Priority rank or weighting", "Trade-off rule", "Authorizing role for trade-offs", "Recorded trade-off decisions" ] } ], "data_elements": [ { "id": "de-objective-statement", "name": "Objective statement", "description": "A stated objective of the project expressed as an output, outcome or benefit.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-016", "SRC-001" ] }, { "id": "de-success-criterion", "name": "Success criterion", "description": "Indicator, method, baseline and target that make an objective testable.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007", "SRC-016" ] }, { "id": "de-target-value", "name": "Target value", "description": "Quantified target for an indicator, with unit and target period.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-objective-priority", "name": "Objective priority", "description": "Relative priority or weighting used to resolve conflicts between objectives.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "a-objectives-and-results-register", "name": "Objectives, indicators and results register", "description": "Register of objectives with indicators, baselines, targets, actuals and the evidence supporting each measurement.", "media_or_form": [ "register", "indicator and results table", "structured results record" ], "serial": false, "identity_strategy": "Composite key of project identifier plus objective key plus indicator key; measured periods are attributes inside the row and never used as the row key.", "source_refs": [ "SRC-007", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "f-scope-boundary-and-exclusions", "name": "Scope boundary, exclusions and scope confirmation", "description": "What is inside the authorized scope of work, what is explicitly excluded, which assumptions bound the statement, who may move the boundary, and how delivery of scope is confirmed.", "source_refs": [ "SRC-001", "SRC-004", "SRC-022" ], "questions": [ { "id": "q-scope-inclusion-exclusion", "text": "What work is inside the authorized scope and what is explicitly excluded from it?", "kind": "definition", "answer_data": [ "Scope statement", "Explicit exclusion list", "Boundary interface note", "Scope baseline version" ] }, { "id": "q-scope-change-authority", "text": "Which role must approve a movement of the scope boundary, and above what threshold does approval escalate?", "kind": "authority", "answer_data": [ "Approving role", "Escalation threshold", "Change request reference", "Approval decision time" ] }, { "id": "q-scope-delivery-confirmation", "text": "How is delivery of the scope confirmed, and who accepts it on behalf of the sponsor?", "kind": "validation", "answer_data": [ "Confirmation method", "Accepting role", "Confirmation record reference", "Outstanding exception list" ] }, { "id": "q-scope-assumptions", "text": "Which assumptions and constraints does the stated scope depend on, and what happens if one proves false?", "kind": "constraint", "answer_data": [ "Assumption statement", "Dependency on external party", "Invalidation consequence", "Linked risk entry" ] } ], "data_elements": [ { "id": "de-scope-statement", "name": "Scope statement", "description": "Authoritative statement of the work the project is authorized to perform.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "de-scope-exclusion", "name": "Scope exclusion", "description": "Work explicitly declared outside the project boundary.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-scope-assumption", "name": "Scope assumption", "description": "An assumption the scope statement depends on, linkable to a risk entry.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-014" ] }, { "id": "de-scope-confirmation-record", "name": "Scope confirmation record reference", "description": "Reference to the record confirming that delivered scope has been accepted.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-022" ] } ], "artifacts": [ { "id": "a-scope-baseline-statement", "name": "Scope baseline statement", "description": "The approved scope statement with exclusions and assumptions, held as the scope component of the baseline set.", "media_or_form": [ "document", "structured scope record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic baseline version; content hash recorded so that later performance reporting can prove which scope it was measured against.", "source_refs": [ "SRC-001", "SRC-013" ] } ], "inline_only_rationale": null } ] }, { "id": "l-breakdown-and-linkage", "name": "Breakdown and linkage", "description": "Decomposition of the total scope and the typed edges binding the project to contained and external records.", "source_refs": [ "SRC-004", "SRC-005", "SRC-021", "SRC-014" ], "findings": [ { "id": "f-work-breakdown-structure", "name": "Work breakdown structure and control accounts", "description": "How the authorized scope is decomposed into mutually exclusive elements, how those elements are coded and kept stable, at which level performance is controlled, and how the structure relates to other breakdown structures.", "source_refs": [ "SRC-004", "SRC-005", "SRC-014", "SRC-013" ], "questions": [ { "id": "q-decomposition-coverage", "text": "Does the decomposition cover the entire authorized scope of work without overlap between elements, and how was that verified?", "kind": "composition", "answer_data": [ "Element list with parent references", "Coverage verification method", "Overlap exceptions found", "Verifying role and time" ] }, { "id": "q-wbs-coding-stability", "text": "What coding scheme identifies breakdown elements, and do element codes survive a re-baseline?", "kind": "identity", "answer_data": [ "Code syntax rule", "Code stability policy", "Retired or reused code register", "Mapping to prior baseline codes" ] }, { "id": "q-control-account-level", "text": "At which level of the breakdown is cost and schedule performance controlled and reported?", "kind": "measurement", "answer_data": [ "Control account level", "Control account owner role", "Budget assigned per control account", "Measurement technique per account" ] }, { "id": "q-breakdown-structure-alignment", "text": "How does this breakdown relate to other breakdown structures used by the organization, such as organizational, product, cost or risk breakdowns?", "kind": "interoperability", "answer_data": [ "Related structure name and owner", "Mapping rule between structures", "Level correspondence", "Known mismatches" ] } ], "data_elements": [ { "id": "de-wbs-element", "name": "Breakdown element", "description": "A scope element in the decomposition, with parent reference, level and dictionary entry.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-wbs-code", "name": "Breakdown element code", "description": "Stable code identifying a breakdown element within the project.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "de-control-account-level", "name": "Control account level", "description": "The breakdown level designated as the control account for performance measurement.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-014" ] } ], "artifacts": [ { "id": "a-work-breakdown-structure", "name": "Work breakdown structure and dictionary", "description": "The decomposition of total scope with element codes, parent references and dictionary entries defining each element's content.", "media_or_form": [ "hierarchical structure", "breakdown dictionary", "structured element list" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic version; each element keyed by its stable breakdown code and parent reference, so ordering is explicit rather than positional.", "source_refs": [ "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "f-component-links-and-dependencies", "name": "Contained components and external dependencies", "description": "Which tasks, milestones and deliverables the project contains, by what link type, which external dependencies condition delivery, and what happens to those links when the project is cancelled, merged or split.", "source_refs": [ "SRC-021", "SRC-004", "SRC-001", "SRC-006" ], "questions": [ { "id": "q-contained-components", "text": "Which tasks, milestones and deliverables belong to this project, and under which typed edge is each held?", "kind": "composition", "answer_data": [ "Target record identifier", "Link type code", "Link direction", "Link assertion time and asserting party" ] }, { "id": "q-external-dependencies", "text": "Which dependencies on other projects, suppliers or external events condition this project's delivery?", "kind": "relationship", "answer_data": [ "Dependency target reference", "Dependency nature", "Needed-by date", "Owner of the dependency" ] }, { "id": "q-cross-model-link-resolution", "text": "How are cross-model links expressed so a consumer can resolve them without access to the project's storage system?", "kind": "interoperability", "answer_data": [ "Link serialization form", "Target identifier scheme", "Resolution endpoint", "Fallback when the target is unresolvable" ] }, { "id": "q-link-disposition-on-closure", "text": "What happens to contained components and their links when the project is cancelled, merged or split?", "kind": "lifecycle", "answer_data": [ "Disposition rule per link type", "Reassignment target", "Orphan handling policy", "Event record of the disposition" ] } ], "data_elements": [ { "id": "de-contained-component-ref", "name": "Contained component reference", "description": "Typed reference from the project to a contained task, milestone or deliverable record.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-021", "SRC-004" ] }, { "id": "de-link-type-code", "name": "Link type code", "description": "Governed code naming the semantics of a typed edge, such as contains, depends-on or delivered-by.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-021" ] }, { "id": "de-external-dependency", "name": "External dependency", "description": "A dependency on a record outside the project, with nature, needed-by date and responsible party.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-001" ] } ], "artifacts": [ { "id": "a-component-link-set", "name": "Typed edge set", "description": "The set of typed edges binding the project to contained components, parent programme and external dependencies.", "media_or_form": [ "typed edge list", "link table", "graph fragment" ], "serial": false, "identity_strategy": "Each edge keyed by source identifier, link type and target identifier; hierarchical grouping is always expressed with explicit parent or child edge types rather than inferred from nesting or array order.", "source_refs": [ "SRC-021", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-resources-and-commitments", "name": "Resources and commitments", "description": "The people, money and supplier obligations bound to the project, and the authority behind each commitment.", "rationale": "ISO 21502:2020 separates resource management and cost management as distinct practices, and GAO-20-195G treats the time-phased budget and reserves as prerequisites of credible cost management. Commitments are made by parties outside the project, so they need their own bundle with explicit ownership and authority.", "source_refs": [ "SRC-001", "SRC-014", "SRC-022", "SRC-003" ], "layers": [ { "id": "l-organization-and-people", "name": "Project organization and people", "description": "Roles in the project organization and the time-bounded commitment of people and physical resources to it.", "source_refs": [ "SRC-001", "SRC-003", "SRC-015" ], "findings": [ { "id": "f-project-organization-and-roles", "name": "Project organization and role assignment", "description": "Which roles exist, who holds each and for what period, what decision rights attach to each role, and what competencies or clearances gate role holding.", "source_refs": [ "SRC-001", "SRC-003", "SRC-015" ], "questions": [ { "id": "q-role-holders", "text": "Which roles exist in the project organization and who currently holds each one?", "kind": "ownership", "answer_data": [ "Role name and definition", "Role holder reference", "Appointment record", "Deputy or alternate" ] }, { "id": "q-role-decision-rights", "text": "What responsibility, accountability and decision rights attach to each role?", "kind": "authority", "answer_data": [ "Responsibility statement", "Accountable versus consulted distinction", "Decision rights list", "Escalation target" ] }, { "id": "q-role-time-bounds", "text": "Over what period is each role assignment valid, and what record evidences a handover?", "kind": "temporal", "answer_data": [ "Assignment start and end", "Handover record reference", "Effective and recorded times", "Overlap or gap note" ] }, { "id": "q-role-prerequisites", "text": "Which competencies, certifications or clearances must be held before a person may occupy a role?", "kind": "requirement", "answer_data": [ "Prerequisite type", "Verification evidence", "Verifying party", "Expiry of the prerequisite" ] } ], "data_elements": [ { "id": "de-project-role", "name": "Project role", "description": "A defined role in the project organization with its responsibilities and decision rights.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "de-role-holder-ref", "name": "Role holder reference", "description": "Reference to the person or team occupying a role, resolved against the person or organization model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "de-role-validity-period", "name": "Role validity period", "description": "Start and end of a role assignment, with effective and recorded times.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-001" ] } ], "artifacts": [ { "id": "a-responsibility-assignment-record", "name": "Project organization and responsibility assignment record", "description": "Record of the project organization structure with role definitions, holders, validity periods and decision rights.", "media_or_form": [ "responsibility assignment matrix", "organization structure record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic version; assignments keyed by role code and holder reference, with validity periods as attributes rather than keys.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "f-resource-allocation-commitment", "name": "Resource allocation and commitment", "description": "Which resources are committed to the project in what quantity and period, who owns them, how contention is resolved, and what is recorded when an allocation changes mid-flight.", "source_refs": [ "SRC-001", "SRC-018", "SRC-014" ], "questions": [ { "id": "q-committed-resources", "text": "Which resources are committed to this project, in what quantity, and over which period?", "kind": "measurement", "answer_data": [ "Resource reference and type", "Committed quantity and unit", "Commitment period", "Breakdown element consuming it" ] }, { "id": "q-resource-commitment-authority", "text": "Who owns each committed resource and what instrument binds that commitment?", "kind": "ownership", "answer_data": [ "Resource owning party", "Commitment instrument reference", "Authorizing role", "Commitment firmness level" ] }, { "id": "q-resource-contention", "text": "How is over-allocation or contention with other projects detected, and who arbitrates it?", "kind": "exception", "answer_data": [ "Detection rule", "Arbitrating body", "Arbitration outcome record", "Effect on the schedule baseline" ] }, { "id": "q-allocation-change-event", "text": "What is recorded when resources are added, moved or withdrawn while work is in progress?", "kind": "event", "answer_data": [ "Change event type", "Prior and new allocation values", "Effective time and recorded time", "Reason and authorizing role" ] } ], "data_elements": [ { "id": "de-resource-allocation", "name": "Resource allocation", "description": "A commitment of a named resource to project work, with quantity, period and consuming breakdown element.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-014" ] }, { "id": "de-allocated-quantity", "name": "Allocated quantity", "description": "Quantity of a resource committed, expressed with an explicit unit of measure.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-014" ] }, { "id": "de-allocation-owner-ref", "name": "Allocation owner reference", "description": "Reference to the party that owns and releases the committed resource.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-018" ] } ], "artifacts": [ { "id": "a-resource-commitment-record", "name": "Resource commitment record", "description": "Record binding resources to project work for a period, with owning party, authorizing role and change history.", "media_or_form": [ "allocation record", "commitment agreement", "structured resource ledger" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic sequence; each entry references the resource owner's own identifier so that the owning party retains authority over its own allocation data.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "l-funding-and-procurement", "name": "Budget and procurement", "description": "The approved cost baseline with its reserves and assumptions, and the externally sourced portion of scope.", "source_refs": [ "SRC-014", "SRC-005", "SRC-001", "SRC-007" ], "findings": [ { "id": "f-budget-and-cost-baseline", "name": "Budget, reserves and cost baseline", "description": "The approved time-phased budget with currency and price base, the distinction between baseline, commitment, forecast and actual cost, the reserves and who may release them, and the economic assumptions embedded in the numbers.", "source_refs": [ "SRC-014", "SRC-005", "SRC-007", "SRC-001" ], "questions": [ { "id": "q-approved-budget", "text": "What is the approved budget, in which currency and price base, and how is it phased across periods?", "kind": "measurement", "answer_data": [ "Budget amount per period", "Currency code", "Price base or reference year", "Phasing method" ] }, { "id": "q-cost-value-distinction", "text": "What distinguishes cost baseline from commitment, forecast and actual cost in this record?", "kind": "definition", "answer_data": [ "Definition per cost value type", "Source system per type", "Cut-off rule for actuals", "Reconciliation rule" ] }, { "id": "q-reserve-release-authority", "text": "Which contingency and management reserves exist, and which role may release each of them?", "kind": "authority", "answer_data": [ "Reserve type and amount", "Holding level", "Releasing role", "Release decision record" ] }, { "id": "q-cost-assumptions", "text": "Which exchange-rate, inflation and escalation assumptions underlie the cost figures?", "kind": "constraint", "answer_data": [ "Assumption type and value", "Assumption source", "Applicable period", "Sensitivity or uncertainty range" ] } ], "data_elements": [ { "id": "de-approved-budget-amount", "name": "Approved budget amount", "description": "Budgeted amount for a period, with currency and price base, forming part of the cost baseline.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-007" ] }, { "id": "de-currency-code", "name": "Currency code", "description": "Currency of a monetary value, recorded as an explicit code rather than implied by locale.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-reserve-amount", "name": "Reserve amount", "description": "Contingency or management reserve held against the project, with the role authorized to release it.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "de-actual-cost-to-date", "name": "Actual cost to date", "description": "Cost actually incurred as at the stated data date, distinct from commitment and forecast.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-014" ] } ], "artifacts": [ { "id": "a-cost-baseline", "name": "Time-phased cost baseline", "description": "The approved time-phased budget by control account with reserves, currency, price base and economic assumptions.", "media_or_form": [ "time-phased budget", "financial baseline record" ], "serial": true, "identity_strategy": "Project identifier plus baseline type plus monotonic version, with a content hash; superseded cost baselines are retained so historic performance remains reproducible.", "source_refs": [ "SRC-014", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "f-procurement-and-supplier-commitment", "name": "Externally delivered scope and supplier commitments", "description": "Which scope elements are delivered by external parties, under which agreement references, on what acceptance and payment conditions, and how supplier performance is evidenced without importing contract internals.", "source_refs": [ "SRC-001", "SRC-007", "SRC-022", "SRC-003" ], "questions": [ { "id": "q-external-scope-elements", "text": "Which breakdown elements are delivered by external suppliers, and under which agreement reference is each held?", "kind": "relationship", "answer_data": [ "Breakdown element reference", "Supplier party reference", "Agreement identifier", "Delivery model" ] }, { "id": "q-supplier-acceptance-conditions", "text": "What acceptance and payment conditions govern each supplier commitment?", "kind": "requirement", "answer_data": [ "Acceptance condition", "Payment trigger", "Accepting role", "Withholding or retention rule" ] }, { "id": "q-supplier-schedule-risk", "text": "Which supplier obligations create dependency or risk for the project schedule, and how are they monitored?", "kind": "constraint", "answer_data": [ "Obligation and needed-by date", "Linked risk entry", "Monitoring cadence", "Contingency if the obligation slips" ] }, { "id": "q-supplier-performance-evidence", "text": "How is supplier performance evidenced, and what route exists when performance is disputed?", "kind": "evidence", "answer_data": [ "Performance evidence type", "Evidencing party", "Dispute route", "Escalation authority" ] } ], "data_elements": [ { "id": "de-procurement-agreement-ref", "name": "Procurement agreement reference", "description": "Reference to the contract or agreement under which external scope is delivered; the instrument's text stays in the contract model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "de-supplier-org-ref", "name": "Supplier organization reference", "description": "Reference to the external party delivering part of the scope.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-acceptance-condition", "name": "Acceptance condition", "description": "Condition that must be satisfied for externally delivered scope to be accepted.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-022" ] } ], "artifacts": [ { "id": "a-procurement-register", "name": "Supplier commitment register", "description": "Register of agreement references, supplier parties, procured scope elements and acceptance conditions, holding references rather than contract text.", "media_or_form": [ "register", "reference list", "structured commitment table" ], "serial": false, "identity_strategy": "Keyed by project identifier plus agreement identifier plus procured breakdown element; the authoritative agreement identifier is the one issued by the contracting system of record.", "source_refs": [ "SRC-001", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-time-lifecycle-and-baselines", "name": "Time, lifecycle and baselines", "description": "Where the project is in its life, what dates and gates govern it, and what approved baselines performance is measured against.", "rationale": "ISO 21502:2020 organizes projects around a life cycle with directing and controlling practices; IATI publishes a governed six-value status vocabulary and type-coded planned and actual dates; GAO-16-89G and NASA NPR 7120.5F show that baselines and decision gates are formally controlled instruments. These are distinct from scope and from performance reporting and warrant their own bundle.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009", "SRC-013", "SRC-015" ], "layers": [ { "id": "l-lifecycle-and-gates", "name": "Lifecycle states and decision gates", "description": "The controlled state set, permitted transitions, phase model and gate decisions that let work continue.", "source_refs": [ "SRC-008", "SRC-001", "SRC-015", "SRC-003" ], "findings": [ { "id": "f-lifecycle-state-and-transitions", "name": "Lifecycle state and permitted transitions", "description": "The project's current state within a declared vocabulary, who may trigger which transitions on what evidence, how suspension and cancellation differ from completion, and how effective time is separated from recorded time.", "source_refs": [ "SRC-008", "SRC-001", "SRC-012" ], "questions": [ { "id": "q-current-state-vocabulary", "text": "Which lifecycle state is the project in, and which governed vocabulary and version defines the permitted state set?", "kind": "state", "answer_data": [ "State code", "Vocabulary URI and version", "State definition text", "Time the state became effective" ] }, { "id": "q-permitted-transitions", "text": "Which state transitions are permitted, who may trigger each, and what evidence must accompany it?", "kind": "lifecycle", "answer_data": [ "Transition pair", "Authorized triggering role", "Required evidence", "Rejected-transition handling" ] }, { "id": "q-abnormal-termination", "text": "How are suspension, cancellation and premature closure distinguished from normal completion in the record?", "kind": "exception", "answer_data": [ "Termination state code", "Reason code and narrative", "Disposition of open commitments", "Authorizing decision reference" ] }, { "id": "q-state-time-separation", "text": "What is recorded as the time a state change took effect versus the time it was entered into the system?", "kind": "temporal", "answer_data": [ "Effective time", "Recorded or ingestion time", "Recording actor and system", "Latency or backdating note" ] } ], "data_elements": [ { "id": "de-lifecycle-state", "name": "Lifecycle state", "description": "Current state of the project drawn from a declared, versioned vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "de-state-effective-time", "name": "State effective time", "description": "Instant from which the current state applies, in RFC 3339 form with an explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-008" ] }, { "id": "de-state-recorded-time", "name": "State recorded time", "description": "Instant at which the state change was captured in the record, distinct from when it took effect.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-007" ] }, { "id": "de-transition-reason", "name": "Transition reason", "description": "Reason code and narrative for a state change, particularly for suspension or cancellation.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-001" ] } ], "artifacts": [ { "id": "a-state-transition-log", "name": "State transition log", "description": "Append-only log of state changes with effective time, recorded time, actor, reason and supporting evidence.", "media_or_form": [ "append-only event log", "status history record" ], "serial": true, "identity_strategy": "Each entry keyed by project identifier plus monotonic sequence number; corrections are appended as new superseding entries and never overwrite prior entries.", "source_refs": [ "SRC-008", "SRC-012", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "f-phases-and-decision-gates", "name": "Phases and decision gates", "description": "The life cycle model in use, entry and exit criteria per phase, which gates require a governing-body decision, what outcomes a gate may produce, and how tailoring changes the gate set.", "source_refs": [ "SRC-015", "SRC-001", "SRC-003" ], "questions": [ { "id": "q-phase-criteria", "text": "Which life cycle model and phases apply, and what are the entry and exit criteria for each phase?", "kind": "process", "answer_data": [ "Phase name and sequence", "Entry criteria", "Exit criteria", "Owning role per phase" ] }, { "id": "q-gate-decision-authority", "text": "Which decision gates require a governing-body decision before further work or spend is permitted?", "kind": "authority", "answer_data": [ "Gate identifier", "Deciding body", "Pre-conditions and required products", "Consequence of proceeding without a decision" ] }, { "id": "q-gate-outcome-types", "text": "What outcomes may a gate decision take, and how is a conditional pass with actions recorded?", "kind": "decision", "answer_data": [ "Outcome code set", "Condition or action list", "Action owner and due date", "Decision time and minute reference" ] }, { "id": "q-gate-tailoring", "text": "How does a tailored, adaptive or hybrid delivery approach change the applicable gate set?", "kind": "classification", "answer_data": [ "Tailoring decision reference", "Gates added, removed or merged", "Approving authority for tailoring", "Justification" ] } ], "data_elements": [ { "id": "de-phase", "name": "Phase", "description": "A named life cycle phase with sequence, entry and exit criteria.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-001" ] }, { "id": "de-gate-decision", "name": "Gate decision", "description": "A recorded decision at a gate, with outcome code, conditions and deciding body.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-003" ] }, { "id": "de-gate-decision-time", "name": "Gate decision time", "description": "Instant of the gate decision, recorded with an explicit offset.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-015" ] } ], "artifacts": [ { "id": "a-gate-decision-record", "name": "Gate decision record", "description": "Formal record of a phase gate or key decision point, with the products reviewed, the outcome and any conditions.", "media_or_form": [ "decision record", "review board minute", "structured gate outcome" ], "serial": true, "identity_strategy": "Project identifier plus gate identifier plus monotonic decision sequence; the decision time is metadata inside the record and is never used as its key.", "source_refs": [ "SRC-015", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "l-temporal-frame", "name": "Temporal frame", "description": "Authoritative planned and actual dates for the project and the rules that make them comparable across systems.", "source_refs": [ "SRC-009", "SRC-012", "SRC-010", "SRC-013" ], "findings": [ { "id": "f-project-dates-and-time-semantics", "name": "Project dates and time semantics", "description": "Type-coded planned and actual start and end dates, which of them is authoritative, how precision, offset and working calendar are expressed, the ordering rules that constrain them, and how re-baselined dates stay distinguishable from original ones.", "source_refs": [ "SRC-009", "SRC-012", "SRC-013", "SRC-010" ], "questions": [ { "id": "q-planned-actual-dates", "text": "What are the planned and actual start and end dates, and which source is authoritative for each?", "kind": "temporal", "answer_data": [ "Date type code", "Date value and precision", "Authoritative source system", "Last update time" ] }, { "id": "q-date-precision-and-calendar", "text": "How are date precision, time offset and the applicable working calendar or fiscal year expressed?", "kind": "interoperability", "answer_data": [ "Precision indicator", "Offset or Z designator", "Working calendar reference", "Fiscal year convention" ] }, { "id": "q-date-ordering-rules", "text": "Which validation rules prevent an actual date being recorded in the future or out of order relative to its planned counterpart?", "kind": "validation", "answer_data": [ "Ordering constraint set", "Future-date rejection rule", "Minimum required date types", "Violation handling" ] }, { "id": "q-rebaselined-dates", "text": "How are re-baselined dates kept distinguishable from the dates in the original approved baseline?", "kind": "provenance", "answer_data": [ "Baseline version reference per date", "Original baseline value", "Change decision reference", "Variance computed against which baseline" ] } ], "data_elements": [ { "id": "de-planned-start-date", "name": "Planned start date", "description": "Expected commencement date of the project, date-precision, bound to a named baseline version.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-013" ] }, { "id": "de-actual-start-date", "name": "Actual start date", "description": "Date the project actually began; must not be in the future relative to the recording time.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-planned-end-date", "name": "Planned end date", "description": "Expected completion date under the current approved schedule baseline.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-013" ] }, { "id": "de-actual-end-date", "name": "Actual end date", "description": "Date the project actually ended; must not be in the future relative to the recording time.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-working-calendar-ref", "name": "Working calendar reference", "description": "Reference to the working calendar and holiday rules used to interpret durations and dates.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Project dates are typed attributes of the project record and of the baseline, charter and status artifacts that already carry them; materializing a separate date artifact would create a second, competing source of truth for actual start and end. The dates are therefore held inline as type-coded values with an explicit baseline reference, mirroring the IATI activity-date pattern where dates are attributes of the activity rather than separate documents." } ] }, { "id": "l-baselines-and-change", "name": "Baselines and change control", "description": "The approved reference against which performance is judged, and the controlled route by which it may move.", "source_refs": [ "SRC-013", "SRC-014", "SRC-005", "SRC-001" ], "findings": [ { "id": "f-baseline-set-and-versioning", "name": "Approved baseline set and versioning", "description": "Which scope, schedule and cost baselines are currently approved, what authority established each, how superseded baselines are retained for reproducibility, and what forces a re-baseline rather than an in-baseline change.", "source_refs": [ "SRC-013", "SRC-014", "SRC-005", "SRC-015" ], "questions": [ { "id": "q-current-baseline-versions", "text": "Which scope, schedule and cost baselines are currently approved, and what version identifies each?", "kind": "identity", "answer_data": [ "Baseline type", "Version identifier", "Content hash", "Coverage note" ] }, { "id": "q-baseline-approval", "text": "Which approval established the current baseline and from what instant does it apply?", "kind": "authority", "answer_data": [ "Approving body", "Approval decision reference", "Effective time", "Scope of the approval" ] }, { "id": "q-superseded-baseline-retention", "text": "How are superseded baselines retained so that historic performance figures remain reproducible?", "kind": "provenance", "answer_data": [ "Superseded baseline reference", "Retention location", "Immutability mechanism", "Link from performance data to baseline version" ] }, { "id": "q-rebaseline-trigger", "text": "Which conditions require a full re-baseline rather than a change applied within the existing baseline?", "kind": "constraint", "answer_data": [ "Threshold or trigger condition", "Deciding authority", "Required analysis", "Communication obligation" ] } ], "data_elements": [ { "id": "de-baseline-version", "name": "Baseline version", "description": "Version identifier of an approved baseline component.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-014" ] }, { "id": "de-baseline-type", "name": "Baseline type", "description": "Which dimension the baseline covers: scope, schedule, cost or an integrated performance measurement baseline.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-014" ] }, { "id": "de-baseline-approval-time", "name": "Baseline approval time", "description": "Instant at which a baseline was approved, with explicit offset.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-015" ] }, { "id": "de-superseded-baseline-ref", "name": "Superseded baseline reference", "description": "Reference from the current baseline to the version it replaced.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [ { "id": "a-baseline-package", "name": "Approved baseline package", "description": "Immutable snapshot bundling the approved scope, schedule and cost baselines with their approval evidence.", "media_or_form": [ "immutable snapshot", "versioned package", "structured baseline record" ], "serial": true, "identity_strategy": "Project identifier plus baseline type plus zero-padded monotonic version, with a named-algorithm content hash; the approval date is metadata inside the package and never forms the key.", "source_refs": [ "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "f-change-control", "name": "Change control against baselines", "description": "How change requests are raised, impact-assessed and decided, which thresholds escalate them, how a decided change links to the baseline version it altered, and how rejected requests are retained.", "source_refs": [ "SRC-001", "SRC-022", "SRC-014", "SRC-003" ], "questions": [ { "id": "q-change-request-flow", "text": "How is a change request raised, assessed for scope, schedule, cost and risk impact, and decided?", "kind": "process", "answer_data": [ "Request record fields", "Impact assessment method", "Deciding role or body", "Decision outcome codes" ] }, { "id": "q-change-escalation-threshold", "text": "Which thresholds move a change decision beyond the project manager's delegated authority?", "kind": "authority", "answer_data": [ "Threshold dimension and value", "Escalation target", "Approval evidence", "Emergency deviation route" ] }, { "id": "q-change-baseline-link", "text": "What links an approved change to the specific baseline version it altered?", "kind": "relationship", "answer_data": [ "Change request identifier", "Prior and resulting baseline versions", "Affected breakdown elements", "Application time" ] }, { "id": "q-rejected-change-retention", "text": "How long are rejected and withdrawn change requests retained, and who may see them?", "kind": "retention", "answer_data": [ "Retention period", "Disposition action", "Access restriction", "Retention authority reference" ] } ], "data_elements": [ { "id": "de-change-request", "name": "Change request", "description": "A proposed alteration to a baseline, with originator, description and requested effect.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-022" ] }, { "id": "de-change-impact-assessment", "name": "Change impact assessment", "description": "Assessed effect of a change on scope, schedule, cost, risk and benefits.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-001" ] }, { "id": "de-change-decision-code", "name": "Change decision code", "description": "Outcome of the change decision, such as approved, rejected, deferred or withdrawn.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "a-change-request-register", "name": "Change request register", "description": "Register of change requests with impact assessments, decisions, authorizing roles and the baseline versions affected.", "media_or_form": [ "register", "decision log", "structured change record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic request number; decisions are appended as new entries linked to the request number, and rejected requests are retained rather than deleted.", "source_refs": [ "SRC-001", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-performance-and-uncertainty", "name": "Performance and uncertainty", "description": "How the project is actually going, how that is measured and reported, and how threats, problems and quality are handled.", "rationale": "ISO 21508:2018 defines earned value as the integration of scope, cost, budget and schedule for progress and performance assessment, and GAO-16-89G frames the schedule as the instrument for measuring performance against an approved plan. ISO 21502:2020 keeps risk, issue and quality as separate practices. Measurement and uncertainty are therefore grouped apart from the baselines they are measured against.", "source_refs": [ "SRC-005", "SRC-013", "SRC-014", "SRC-001" ], "layers": [ { "id": "l-measurement-and-reporting", "name": "Measurement and reporting", "description": "Quantified progress against the approved baseline and the obligation to report it.", "source_refs": [ "SRC-005", "SRC-014", "SRC-001", "SRC-007" ], "findings": [ { "id": "f-progress-and-earned-value", "name": "Progress measurement and earned value", "description": "How physical progress is measured per control account, which indices and variances are computed against which baseline, the data date of the performance figures, the checks that keep them internally consistent, and what is used when earned value does not apply.", "source_refs": [ "SRC-005", "SRC-014", "SRC-013" ], "questions": [ { "id": "q-progress-technique", "text": "How is physical progress measured for each control account, using which technique, unit and frequency?", "kind": "measurement", "answer_data": [ "Measurement technique code", "Unit of measure", "Measurement frequency", "Responsible role" ] }, { "id": "q-performance-data-date", "text": "What is the data date of the performance figures, and how often are they refreshed?", "kind": "temporal", "answer_data": [ "Data date", "Refresh cadence", "Last computation time", "Lag between data date and publication" ] }, { "id": "q-performance-consistency-check", "text": "Which checks confirm that reported earned value is consistent with actual cost, schedule status and the named baseline?", "kind": "validation", "answer_data": [ "Consistency rule set", "Tolerance for discrepancy", "Failed-check handling", "Verifying role" ] }, { "id": "q-earned-value-inapplicable", "text": "When is earned value not an appropriate measure for this project, and what alternative measure is used instead?", "kind": "constraint", "answer_data": [ "Inapplicability condition", "Alternative measure and method", "Approval of the alternative", "Comparability limitation" ] } ], "data_elements": [ { "id": "de-control-account-progress", "name": "Control account progress", "description": "Measured progress for a control account at a stated data date, with technique and unit.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-014" ] }, { "id": "de-earned-value-metric", "name": "Earned value metric", "description": "A computed performance value or index, recorded with the baseline version it was computed against.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-performance-data-date", "name": "Performance data date", "description": "The as-of instant for a set of performance figures, separate from the time they were computed or ingested.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-005" ] } ], "artifacts": [ { "id": "a-performance-measurement-record", "name": "Performance measurement dataset", "description": "Periodic dataset of progress, earned value and variance by control account, bound to a data date and a baseline version.", "media_or_form": [ "periodic dataset", "measurement table", "structured performance record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic period sequence; the data date and baseline version are recorded inside the dataset so that reruns are reproducible and periods are never used as identifiers.", "source_refs": [ "SRC-005", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "f-status-reporting-and-forecast", "name": "Status reporting, forecast and disclosure", "description": "Who must receive which report at what cadence and detail, what forecast is asserted and on what basis, how report assertions trace to underlying performance data, and which external disclosure obligations apply.", "source_refs": [ "SRC-001", "SRC-007", "SRC-014", "SRC-003" ], "questions": [ { "id": "q-report-obligations", "text": "Who must receive which report, at what cadence and at what level of detail?", "kind": "requirement", "answer_data": [ "Recipient role or body", "Report type", "Cadence and due offset", "Detail or projection level" ] }, { "id": "q-forecast-basis", "text": "What forecast of final cost and completion date is asserted, and on what basis is it derived?", "kind": "measurement", "answer_data": [ "Forecast value and type", "Derivation method", "Assumptions and confidence range", "Forecast as-of date" ] }, { "id": "q-report-traceability", "text": "How is each reported assertion traced back to the underlying performance data and its data date?", "kind": "provenance", "answer_data": [ "Source dataset reference", "Data date of the source", "Transformation or aggregation applied", "Preparing and approving roles" ] }, { "id": "q-external-disclosure", "text": "Which external transparency or funder-reporting obligations apply to this project's status, and what must be published?", "kind": "access", "answer_data": [ "Obligation source", "Publication target and schema", "Fields required to be public", "Fields withheld and the ground for withholding" ] } ], "data_elements": [ { "id": "de-report-obligation", "name": "Report obligation", "description": "An obligation to deliver a specified report to a named recipient at a stated cadence.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "de-forecast-value", "name": "Forecast value", "description": "Forecast final cost, completion date or benefit level, with its derivation basis.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-005" ] }, { "id": "de-report-last-updated-time", "name": "Report last-updated time", "description": "Instant at which the reported data was last updated, supporting consumer freshness checks.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-012" ] } ], "artifacts": [ { "id": "a-status-report", "name": "Periodic status report", "description": "Report covering a defined period with progress against objectives, forecast, top risks and issues, and its traceability to the underlying data.", "media_or_form": [ "report", "structured status record", "published data record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus zero-padded monotonic sequence; the reporting period is stored inside the report as bounded RFC 3339 instants and is never the identifier.", "source_refs": [ "SRC-001", "SRC-007", "SRC-012" ] } ], "inline_only_rationale": null } ] }, { "id": "l-risk-issue-and-assurance", "name": "Risk, issue and assurance", "description": "Registered uncertainty, live problems and independent checks on both the outputs and the management of the project.", "source_refs": [ "SRC-001", "SRC-003", "SRC-014", "SRC-015" ], "findings": [ { "id": "f-risk-register", "name": "Risk register and response ownership", "description": "Which threats and opportunities are registered, how likelihood and impact are assessed and scaled, who owns each risk and its authorized response, what the risk endangers, and when a risk becomes an issue.", "source_refs": [ "SRC-001", "SRC-014", "SRC-003", "SRC-022" ], "questions": [ { "id": "q-risk-assessment-scale", "text": "Which risks are registered, and on what scale are likelihood and impact assessed?", "kind": "measurement", "answer_data": [ "Risk statement", "Likelihood scale and value", "Impact scale, dimension and value", "Assessment date and assessor" ] }, { "id": "q-risk-owner-response", "text": "Who owns each risk and which response has been authorized for it?", "kind": "ownership", "answer_data": [ "Risk owner reference", "Response type", "Response actions and due dates", "Authorizing role" ] }, { "id": "q-risk-threat-target", "text": "Which objectives, milestones or deliverables does each risk threaten?", "kind": "relationship", "answer_data": [ "Threatened target reference", "Nature of exposure", "Exposure quantification", "Linked contingency reserve" ] }, { "id": "q-risk-to-issue-trigger", "text": "At what point does a registered risk become an issue, and what triggers escalation?", "kind": "exception", "answer_data": [ "Materialization criterion", "Escalation trigger and target", "Resulting issue reference", "Notification obligation" ] }, { "id": "q-risk-review-staleness", "text": "How often is the register reviewed, and how is a stale or unreviewed entry detected?", "kind": "quality", "answer_data": [ "Review cadence", "Last review time per entry", "Staleness threshold", "Remediation action" ] } ], "data_elements": [ { "id": "de-risk-entry", "name": "Risk entry", "description": "A registered threat or opportunity with statement, assessment, response and owner.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-014" ] }, { "id": "de-risk-response-code", "name": "Risk response code", "description": "Authorized treatment of a risk, such as avoid, reduce, transfer, share or accept.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-risk-owner-ref", "name": "Risk owner reference", "description": "Reference to the party accountable for managing a specific risk.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "a-risk-register", "name": "Risk register", "description": "Register of threats and opportunities with assessments, responses, owners, review history and links to threatened targets.", "media_or_form": [ "register", "risk table", "structured risk record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic risk number; assessments are appended as dated revisions so the assessment history stays reconstructable.", "source_refs": [ "SRC-001", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "f-issue-and-escalation", "name": "Issue management and escalation", "description": "Which problems are open and since when, who is accountable, what escalation path and time limits apply, how an issue differs from a risk, change request or defect, and what evidence closes it.", "source_refs": [ "SRC-001", "SRC-022", "SRC-003" ], "questions": [ { "id": "q-open-issues", "text": "Which issues are currently open, since when, and who is accountable for resolving each?", "kind": "state", "answer_data": [ "Issue statement", "Open since time", "Accountable role", "Current status code" ] }, { "id": "q-issue-escalation-path", "text": "What escalation path and time limit apply to an issue that is not resolved at project level?", "kind": "process", "answer_data": [ "Escalation level sequence", "Time limit per level", "Receiving body", "Notification record" ] }, { "id": "q-issue-versus-risk", "text": "How is an issue distinguished in this record from a risk, a change request and a product defect?", "kind": "definition", "answer_data": [ "Discriminating definition", "Routing rule", "Cross-reference to the related record", "Reclassification history" ] }, { "id": "q-issue-closure-evidence", "text": "What evidence is required to close an issue, and who verifies it?", "kind": "evidence", "answer_data": [ "Closure evidence type", "Verifying role", "Closure time", "Residual risk raised on closure" ] } ], "data_elements": [ { "id": "de-issue-entry", "name": "Issue entry", "description": "A live problem affecting the project, with accountability and status.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-022" ] }, { "id": "de-issue-open-time", "name": "Issue open time", "description": "Instant the issue was raised, with explicit offset, distinct from when it was recorded.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-001" ] }, { "id": "de-escalation-level", "name": "Escalation level", "description": "Current escalation level of an issue within the governance structure.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "a-issue-log", "name": "Issue and escalation log", "description": "Log of raised issues with accountability, escalation history, resolution evidence and closure decisions.", "media_or_form": [ "log", "register", "structured issue record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic issue number; escalation and status changes are appended with effective and recorded times rather than overwriting the entry.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "f-quality-assurance-and-review", "name": "Quality requirements and independent assurance", "description": "What quality requirements apply to project outputs and to the management of the project, which independent reviews are mandated and by whom, how non-conformity is handled, and how assurance evidence is retained for audit.", "source_refs": [ "SRC-001", "SRC-003", "SRC-015", "SRC-022" ], "questions": [ { "id": "q-quality-requirements", "text": "Which quality requirements apply to the project's outputs and, separately, to the way the project is managed?", "kind": "requirement", "answer_data": [ "Requirement statement", "Applicable standard or specification", "Verification method", "Responsible role" ] }, { "id": "q-mandated-assurance", "text": "Which independent assurance or peer reviews are mandated, by which authority, and at what points?", "kind": "authority", "answer_data": [ "Review type", "Mandating authority", "Trigger point or cadence", "Independence requirement" ] }, { "id": "q-nonconformity-handling", "text": "What process handles a detected non-conformity, and how is corrective action tracked to closure?", "kind": "process", "answer_data": [ "Non-conformity record fields", "Corrective action and owner", "Due date and closure criterion", "Escalation on repeat failure" ] }, { "id": "q-assurance-evidence-retention", "text": "How is assurance evidence retained so that an auditor can reconstruct what was reviewed and concluded?", "kind": "evidence", "answer_data": [ "Evidence artifact reference", "Retention period and authority", "Immutability mechanism", "Auditor access route" ] } ], "data_elements": [ { "id": "de-quality-requirement", "name": "Quality requirement", "description": "A stated quality requirement applying to project outputs or to project management itself.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-022" ] }, { "id": "de-assurance-review", "name": "Assurance review", "description": "An independent review event with scope, reviewers, findings and conclusion.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-015" ] }, { "id": "de-nonconformity-record", "name": "Non-conformity record", "description": "A detected non-conformity with corrective action, owner and closure state.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "a-assurance-review-report", "name": "Assurance or independent review report", "description": "Report of an independent review with scope, evidence examined, findings, conclusion and required actions.", "media_or_form": [ "review report", "audit record", "structured assurance finding set" ], "serial": true, "identity_strategy": "Project identifier plus review type plus monotonic sequence; the reviewing body and review period are attributes inside the report, and superseded drafts are retained with a superseded-by marker.", "source_refs": [ "SRC-003", "SRC-015" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-stakeholders-records-and-closure", "name": "Stakeholders, records and closure", "description": "Who has an interest in the project, how its record is evidenced and protected, and how it ends and is retained.", "rationale": "ISO 21502:2020 keeps stakeholder involvement and management of information and documentation as explicit practices, W3C PROV-O supplies the attribution vocabulary for evidencing a record, and NARA's General Records Schedules show how disposition authority actually binds. Closure and retention are the point where a project stops being operated and starts being evidence, which is a distinct concern from execution.", "source_refs": [ "SRC-001", "SRC-006", "SRC-020", "SRC-007" ], "layers": [ { "id": "l-stakeholders-and-obligations", "name": "Stakeholders and engagement", "description": "The parties with an interest in the project, their capacity, and how engagement is planned and evidenced.", "source_refs": [ "SRC-001", "SRC-007", "SRC-010" ], "findings": [ { "id": "f-stakeholder-register-and-engagement", "name": "Stakeholder register and engagement", "description": "Which parties are stakeholders and in what capacity, who owns each relationship, which attributes are personal data, how engagement is evidenced, and which locations or jurisdictions the project touches.", "source_refs": [ "SRC-001", "SRC-007", "SRC-010", "SRC-022" ], "questions": [ { "id": "q-stakeholder-capacity", "text": "Which parties are stakeholders of this project, and in what capacity does each participate?", "kind": "relationship", "answer_data": [ "Party reference", "Participation role code", "Interest and influence assessment", "Identification basis and date" ] }, { "id": "q-engagement-ownership", "text": "Who owns the engagement relationship with each stakeholder group, and what commitments have been made to them?", "kind": "ownership", "answer_data": [ "Relationship owner role", "Commitment made", "Commitment due date", "Escalation contact" ] }, { "id": "q-stakeholder-personal-data", "text": "Which stakeholder attributes constitute personal data, and how is their processing minimized and limited?", "kind": "privacy", "answer_data": [ "Personal data field list", "Processing purpose", "Minimization measure applied", "Applicable jurisdiction and basis" ] }, { "id": "q-engagement-evidence", "text": "How is engagement planned, carried out and evidenced over the life of the project?", "kind": "process", "answer_data": [ "Engagement activity type", "Planned cadence", "Evidence record reference", "Feedback disposition" ] }, { "id": "q-project-locations", "text": "Which locations, jurisdictions or affected communities does the project operate in or affect?", "kind": "spatial", "answer_data": [ "Location name and geometry or coordinates", "Jurisdiction code", "Nature of the relationship to the location", "Precision and source of the location data" ] } ], "data_elements": [ { "id": "de-stakeholder-entry", "name": "Stakeholder entry", "description": "A registered stakeholder with participation role, interest assessment and relationship owner.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "de-stakeholder-role-code", "name": "Stakeholder role code", "description": "Governed code for the capacity in which a party participates, such as funder, implementer or beneficiary.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-project-location", "name": "Project location", "description": "A location the project operates in or affects, with geometry or coordinates and stated precision.", "value_kind": "geometry", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "a-stakeholder-register", "name": "Stakeholder register and engagement plan", "description": "Register of stakeholders with capacity, interest, relationship owner, engagement plan and evidence of engagement.", "media_or_form": [ "register", "engagement plan", "structured stakeholder record" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic version; each stakeholder row keyed by the party's own authoritative identifier so that person and organization master data are referenced rather than copied.", "source_refs": [ "SRC-001", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "l-records-provenance-and-access", "name": "Record provenance and access", "description": "How the project record is attributed and evidenced, and who may see which part of it.", "source_refs": [ "SRC-006", "SRC-001", "SRC-003", "SRC-007" ], "findings": [ { "id": "f-record-provenance-and-evidence", "name": "Record provenance, attribution and integrity", "description": "Who asserted each part of the project record, from which system and when, how derived values trace to their sources, and how integrity of retained artifacts is demonstrated.", "source_refs": [ "SRC-006", "SRC-001", "SRC-012", "SRC-007" ], "questions": [ { "id": "q-assertion-attribution", "text": "Which agent and system asserted each element of the project record, and on whose behalf did they act?", "kind": "provenance", "answer_data": [ "Asserting agent reference", "Acting-on-behalf-of relation", "Source system identifier", "Assertion time" ] }, { "id": "q-derivation-trace", "text": "For a derived or aggregated value, which source records was it generated from and by which activity?", "kind": "evidence", "answer_data": [ "Source record references", "Generating activity or process", "Derivation rule or method", "Generation time" ] }, { "id": "q-record-integrity", "text": "How is the integrity of a retained artifact demonstrated when it is later relied on as evidence?", "kind": "validation", "answer_data": [ "Hash algorithm and value", "Sealing or signing mechanism", "Verification procedure", "Custody chain record" ] }, { "id": "q-observation-versus-event-time", "text": "Where event time and ingestion time differ, how does the record keep both and signal which was used in a calculation?", "kind": "temporal", "answer_data": [ "Event time value", "Ingestion or observation time value", "Time basis used per computation", "Backdating or correction flag" ] } ], "data_elements": [ { "id": "de-assertion-agent-ref", "name": "Asserting agent reference", "description": "Reference to the agent responsible for an assertion in the record, aligned to PROV attribution.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-record-ingestion-time", "name": "Record ingestion time", "description": "Instant the assertion entered the record, held separately from the time of the event it describes.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-007" ] }, { "id": "de-artifact-content-hash", "name": "Artifact content hash", "description": "Named-algorithm digest of a retained artifact, used to demonstrate that it has not changed.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-020" ] } ], "artifacts": [ { "id": "a-provenance-record", "name": "Provenance record", "description": "Structured provenance for the project record: agents, activities, generation and derivation relations, and integrity digests.", "media_or_form": [ "provenance graph", "attribution log", "structured provenance record" ], "serial": false, "identity_strategy": "Each provenance statement keyed by the identifier of the entity it describes plus the asserting agent plus the assertion time; statements are immutable and corrections are added as new statements.", "source_refs": [ "SRC-006", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "f-access-classification-and-confidentiality", "name": "Access classification and confidentiality", "description": "How parts of the project record are classified for access, which parts are commercially or personally sensitive, how access is granted, time-bounded and revoked, and what is logged.", "source_refs": [ "SRC-003", "SRC-001", "SRC-007", "SRC-010" ], "questions": [ { "id": "q-access-classification", "text": "What access classification applies to each bundle, layer, finding and artifact of this project record?", "kind": "access", "answer_data": [ "Classification level", "Scope of the classification", "Classifying authority", "Review or downgrade date" ] }, { "id": "q-sensitive-content", "text": "Which content is commercially sensitive or personally identifying and therefore restricted even inside the owning organization?", "kind": "security", "answer_data": [ "Sensitive element list", "Sensitivity ground", "Permitted role list", "Redaction rule for wider release" ] }, { "id": "q-access-grant-lifecycle", "text": "How is an access grant requested, time-bounded, reviewed and revoked?", "kind": "lifecycle", "answer_data": [ "Granting role", "Grant scope and expiry", "Review cadence", "Revocation trigger and record" ] }, { "id": "q-mandated-openness", "text": "Which parts must nevertheless be published because of a transparency or funder obligation, and which may be withheld?", "kind": "exception", "answer_data": [ "Mandated-public field list", "Obligation source", "Withholding ground", "Approver of the withholding decision" ] } ], "data_elements": [ { "id": "de-access-classification", "name": "Access classification", "description": "Classification level assigned to a part of the project record.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-003" ] }, { "id": "de-access-grant", "name": "Access grant", "description": "A scoped, time-bounded grant of access to a named party or role.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-010" ] }, { "id": "de-public-disclosure-flag", "name": "Public disclosure flag", "description": "Whether an element is required to be published under a transparency or funder obligation.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "a-access-policy-record", "name": "Access policy and grant register", "description": "Record of classifications, grants, expiries, revocations and the authority behind each, together with the access log requirements.", "media_or_form": [ "policy record", "grant register", "access log" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic version for the policy, with grants keyed by grantee identifier plus scope plus grant sequence; expiries are attributes, never keys.", "source_refs": [ "SRC-003", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "l-closure-and-retention", "name": "Closure and retention", "description": "How the project ends, what is learned and handed over, and how the record is retained or disposed of afterwards.", "source_refs": [ "SRC-001", "SRC-020", "SRC-008", "SRC-019" ], "findings": [ { "id": "f-closure-and-lessons", "name": "Closure, handover and lessons", "description": "What conditions permit closure, how the closure outcome is classified, what is handed over to operations or a parent programme, and how lessons are captured so they can be found by later projects.", "source_refs": [ "SRC-001", "SRC-008", "SRC-019", "SRC-022" ], "questions": [ { "id": "q-closure-conditions", "text": "What conditions must be satisfied before the project may be formally closed, and who confirms them?", "kind": "requirement", "answer_data": [ "Closure condition list", "Confirming role", "Outstanding exception disposition", "Closure decision reference" ] }, { "id": "q-closure-outcome-classification", "text": "How is the closure outcome classified, distinguishing completion from cancellation, merger and abandonment?", "kind": "classification", "answer_data": [ "Outcome code and vocabulary", "Reason narrative", "Residual obligations", "Final state effective time" ] }, { "id": "q-handover-targets", "text": "What is handed over at closure, to whom, and who becomes accountable for continuing benefits and support?", "kind": "ownership", "answer_data": [ "Handover item list", "Receiving party", "Acceptance evidence", "Post-closure benefit owner" ] }, { "id": "q-lessons-capture", "text": "How are lessons captured, classified and made discoverable to later projects?", "kind": "quality", "answer_data": [ "Lesson statement and context", "Classification tags", "Publication target", "Review or validation of the lesson" ] } ], "data_elements": [ { "id": "de-closure-outcome-code", "name": "Closure outcome code", "description": "Classified outcome of closure drawn from a declared vocabulary.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "de-handover-item", "name": "Handover item", "description": "An item transferred at closure, with receiving party and acceptance evidence.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-019" ] }, { "id": "de-lesson-entry", "name": "Lesson entry", "description": "A captured lesson with context, classification and publication target.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-022" ] } ], "artifacts": [ { "id": "a-closure-report", "name": "Closure report and lessons record", "description": "Final account of outcome against objectives, handover items and acceptance, residual obligations and captured lessons.", "media_or_form": [ "closure report", "lessons record", "structured closure dataset" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic version; the closure decision time is metadata inside the report, and any post-closure correction is a new version with a superseded-by link.", "source_refs": [ "SRC-001", "SRC-019" ] } ], "inline_only_rationale": null }, { "id": "f-retention-archiving-and-deletion", "name": "Retention, archiving and deletion", "description": "Which disposition authority governs the project record, how long each class of content is kept, how legal holds override disposition, and how deletion or redaction is executed and evidenced without destroying the audit trail.", "source_refs": [ "SRC-020", "SRC-001", "SRC-003", "SRC-010" ], "questions": [ { "id": "q-disposition-authority", "text": "Which disposition authority or retention schedule governs this project's records, and who issued it?", "kind": "retention", "answer_data": [ "Schedule or authority identifier", "Issuing body", "Applicable record classes", "Deviation approval route" ] }, { "id": "q-retention-periods", "text": "How long is each class of project content retained, and what event starts the retention clock?", "kind": "temporal", "answer_data": [ "Record class", "Retention period", "Trigger event starting the clock", "Final disposition action" ] }, { "id": "q-legal-hold-override", "text": "How does a legal hold or live audit obligation override the normal disposition of a project record?", "kind": "exception", "answer_data": [ "Hold instrument reference", "Scope of the hold", "Imposing authority", "Release condition and record" ] }, { "id": "q-deletion-execution", "text": "How is deletion or redaction executed and evidenced so that the audit trail survives the removal?", "kind": "security", "answer_data": [ "Deletion or redaction method", "Tombstone content", "Authorizing role and legal basis", "Verification of execution" ] } ], "data_elements": [ { "id": "de-retention-schedule-ref", "name": "Retention schedule reference", "description": "Reference to the disposition authority or retention schedule applied to the project record.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "de-retention-period", "name": "Retention period", "description": "Duration a record class is retained, with the event that starts the period.", "value_kind": "duration", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "de-legal-hold-flag", "name": "Legal hold flag", "description": "Whether a hold suspends disposition of the record or a part of it.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020", "SRC-003" ] }, { "id": "de-disposition-event", "name": "Disposition event", "description": "A recorded transfer, destruction or redaction action, with actor, authority and time.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-020", "SRC-006" ] } ], "artifacts": [ { "id": "a-retention-and-disposition-record", "name": "Retention schedule application and disposition record", "description": "Record of the applied schedule, per-class retention periods, holds, executed dispositions and their tombstones.", "media_or_form": [ "disposition record", "retention schedule application", "tombstone log" ], "serial": true, "identity_strategy": "Project identifier plus artifact kind plus monotonic disposition sequence; each entry cites the disposition authority identifier and retains a tombstone describing what was removed, by whom and under what basis.", "source_refs": [ "SRC-020", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "f-transition-disposal-and-residual-obligations", "name": "Closeout, disposal and evaluation", "description": "PRINCE2 includes closing a project as a process. NASA includes decommissioning review to evaluate readiness for closeout, final delivery of remaining deliverables and safe disposal of assets, and requires archival of mission and science data. GovS 002 version 2.1 added clauses covering the transition, use and disposal of a solution, and added evaluation context. ISO/TC 258 has published ISO 21513:2026 guidance on post-project and post-programme evaluation; that text was not retrieved here and is an emerging alignment, not an implemented finding. Close may be completed, cancelled, merged or abandoned; warranty or liability tails may outlive operational close. Disposal and benefits handover can belong partly to operations or a programme; the project still records residual obligations.", "source_refs": [ "SRC-027", "SRC-028", "SRC-030", "SRC-026" ], "questions": [ { "id": "f-transition-disposal-and-residual-obligations-q01", "text": "How was this project closed or why is it not yet closeable, including cancelled, merged or abandoned dispositions?", "kind": "state", "answer_data": [ "close_disposition (string)", "closed_at (rfc3339)", "blocking_open_items (string[])" ] }, { "id": "f-transition-disposal-and-residual-obligations-q02", "text": "What was handed over to operations or another owner, and what disposal or decommissioning actions remain?", "kind": "process", "answer_data": [ "handover_records (object[])", "disposal_actions (object[])", "accepting_owner_ref (string)" ] }, { "id": "f-transition-disposal-and-residual-obligations-q03", "text": "Which warranty, archive, classified-material or liability obligations survive close, and until when?", "kind": "constraint", "answer_data": [ "residual_obligations (object[])", "obligation_end_at (rfc3339)", "owning_party_after_close (string)" ] }, { "id": "f-transition-disposal-and-residual-obligations-q04", "text": "Where is the post-project evaluation, which questions did it answer, and is ISO 21513 used only as alignment?", "kind": "evidence", "answer_data": [ "evaluation_ref (string)", "evaluation_date (rfc3339)", "standards_aligned (string[])", "lessons_refs (string[])" ] } ], "data_elements": [ { "id": "f-transition-disposal-and-residual-obligations-data01", "name": "close_disposition", "description": "completed, cancelled, merged, abandoned, transferred.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-030", "SRC-027" ] }, { "id": "f-transition-disposal-and-residual-obligations-data02", "name": "handover_records", "description": "What was handed to operations, a programme or another project, with acceptance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-028", "SRC-027" ] }, { "id": "f-transition-disposal-and-residual-obligations-data03", "name": "disposal_actions", "description": "Asset or solution disposal, decommissioning and residual hazard actions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-027", "SRC-028" ] }, { "id": "f-transition-disposal-and-residual-obligations-data04", "name": "residual_obligations", "description": "Warranty, liability, data-archive or classified-material obligations after close.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-027", "SRC-028" ] }, { "id": "f-transition-disposal-and-residual-obligations-data05", "name": "evaluation_ref", "description": "Post-project evaluation or lessons product reference.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-028", "SRC-030", "SRC-026" ] }, { "id": "f-transition-disposal-and-residual-obligations-data06", "name": "closed_at", "description": "Event time of close decision or completion.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-027", "SRC-030" ] } ], "artifacts": [ { "id": "f-transition-disposal-and-residual-obligations-artifact01", "name": "Closeout, handover and evaluation report", "description": "Disposition, accepted deliverables, residual obligations, disposal actions and post-project evaluation or lessons.", "media_or_form": [ "report" ], "serial": false, "identity_strategy": "Identified by project_master_id plus close_disposition and closed_at, with a reference to the post-project evaluation product.", "source_refs": [ "SRC-027", "SRC-028", "SRC-030" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-register-project", "name": "Register project", "description": "Create a project record with a resolvable identity and a declared authorization posture.", "inputs": [ "Master system reference", "Proposed or issued authoritative identifier", "Project name and type classification", "Sponsoring organization reference" ], "outputs": [ "Project record with authoritative identifier", "Identifier registration record", "Provenance statement of creation" ], "preconditions": [ "The master system of record is named and reachable, or an explicit mint request is authorized", "The sponsoring organization reference resolves", "No existing record already carries the same authoritative identifier" ], "effects": [ "A project record exists in state proposed or authorized", "Identity and classification findings are populated", "Creation is attributed to an agent with an ingestion timestamp" ], "source_refs": [ "SRC-010", "SRC-011", "SRC-006" ] }, { "id": "fn-authorize-project", "name": "Authorize project", "description": "Record the instrument, body and effective time that authorize the project and set its delegated tolerances.", "inputs": [ "Authorization instrument reference", "Authorizing body reference", "Delegated tolerance set", "Effective time" ], "outputs": [ "Charter or authorization artifact revision", "Updated mandate finding", "State transition entry" ], "preconditions": [ "A project record exists", "The authorizing body holds the reserved decision for authorization", "The instrument reference resolves to a retained artifact" ], "effects": [ "The project moves to an authorized state", "Tolerances become enforceable for change escalation", "The prior charter revision is retained and marked superseded" ], "source_refs": [ "SRC-003", "SRC-001", "SRC-015" ] }, { "id": "fn-establish-baseline", "name": "Establish baseline", "description": "Approve and freeze a scope, schedule or cost baseline as the reference for performance measurement.", "inputs": [ "Baseline type", "Candidate baseline content", "Approving body reference", "Approval time" ], "outputs": [ "Immutable baseline package with version and content hash", "Superseded-by link on the prior baseline", "Approval decision record" ], "preconditions": [ "The scope is decomposed into mutually exclusive elements", "The approving body is authorized for the baseline type", "Any dependent change requests are decided" ], "effects": [ "A new current baseline version exists", "Prior baselines remain retrievable for reproducing historic variance", "Performance measurement is bound to the new version" ], "source_refs": [ "SRC-013", "SRC-014", "SRC-005" ] }, { "id": "fn-transition-lifecycle-state", "name": "Transition lifecycle state", "description": "Move the project to a new state in its declared vocabulary, recording effective and recorded times separately.", "inputs": [ "Target state code and vocabulary version", "Effective time", "Triggering actor", "Reason code and evidence reference" ], "outputs": [ "Appended state transition entry", "Updated current state", "Notification to obligated recipients" ], "preconditions": [ "The transition is permitted from the current state", "The triggering actor holds the authority for that transition", "Required evidence for the transition is attached" ], "effects": [ "Current state changes from the effective time", "History remains append-only and reconstructable", "Downstream reporting and access rules re-evaluate" ], "source_refs": [ "SRC-008", "SRC-001", "SRC-012" ] }, { "id": "fn-record-gate-decision", "name": "Record gate decision", "description": "Capture a governing-body decision at a phase gate, including conditional outcomes and required actions.", "inputs": [ "Gate identifier", "Products reviewed", "Deciding body reference", "Outcome code and conditions" ], "outputs": [ "Gate decision record", "Action items with owners and due dates", "Authorization to proceed or to hold" ], "preconditions": [ "Gate entry criteria are evidenced", "The deciding body is quorate and independent where required", "The applicable gate set reflects any approved tailoring" ], "effects": [ "Continuation of work is authorized, conditioned or stopped", "Conditions become tracked obligations", "Assurance evidence is retained for audit" ], "source_refs": [ "SRC-015", "SRC-003", "SRC-001" ] }, { "id": "fn-decide-change-request", "name": "Decide change request", "description": "Assess a proposed change against baselines and tolerances, decide it and link the decision to the affected baseline version.", "inputs": [ "Change request record", "Impact assessment across scope, schedule, cost and risk", "Deciding role reference" ], "outputs": [ "Change decision with outcome code", "Link from the change to prior and resulting baseline versions", "Updated tolerance consumption" ], "preconditions": [ "A current approved baseline exists", "The deciding role is within the delegated threshold or the change has been escalated", "Impact assessment is complete" ], "effects": [ "Approved changes trigger a controlled baseline update", "Rejected and withdrawn requests are retained with their reasoning", "Traceability from performance data to the correct baseline is preserved" ], "source_refs": [ "SRC-001", "SRC-014", "SRC-003" ] }, { "id": "fn-record-performance-measurement", "name": "Record performance measurement", "description": "Ingest or compute progress and earned value at a stated data date against a named baseline version.", "inputs": [ "Control account progress values", "Actual cost values", "Baseline version reference", "Data date" ], "outputs": [ "Performance measurement dataset", "Computed variances and indices", "Consistency check results" ], "preconditions": [ "A performance measurement baseline is approved", "Measurement techniques are declared per control account", "The data date is not in the future relative to the recording time" ], "effects": [ "Performance figures become reportable and reproducible", "Inconsistent data is flagged rather than silently published", "Forecast derivation gains a dated basis" ], "source_refs": [ "SRC-005", "SRC-014", "SRC-012" ] }, { "id": "fn-link-component", "name": "Link component", "description": "Create or retire a typed edge between the project and a contained, parent or external record.", "inputs": [ "Source project identifier", "Target record identifier and scheme", "Link type code", "Asserting agent" ], "outputs": [ "Typed edge in the link set", "Provenance statement for the assertion", "Validation result on target resolvability" ], "preconditions": [ "The target record exists and its identifier resolves", "The link type is in the governed link vocabulary", "Hierarchical grouping uses explicit parent or child edge types" ], "effects": [ "Containment and dependency become traversable without storage-specific nesting", "Retired edges are marked rather than removed", "Closure disposition rules can be applied per link type" ], "source_refs": [ "SRC-021", "SRC-004", "SRC-006" ] }, { "id": "fn-publish-status-report", "name": "Publish status report", "description": "Produce and release a periodic report to obligated recipients at the required cadence and detail, honouring disclosure and withholding rules.", "inputs": [ "Reporting period bounds", "Performance dataset reference", "Forecast values", "Recipient and obligation set" ], "outputs": [ "Status report artifact", "Publication record for externally mandated fields", "Traceability links to source data" ], "preconditions": [ "Performance data exists with a data date inside or before the period", "Access classification has been applied to each field", "Withholding decisions are approved where fields are suppressed" ], "effects": [ "Reporting obligations are discharged and evidenced", "Consumers can check freshness through a last-updated time", "Withheld fields carry a recorded ground rather than silently vanishing" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-003" ] }, { "id": "fn-close-and-dispose-project", "name": "Close and apply disposition", "description": "Formally close the project, classify the outcome, hand over residual obligations and place the record under its retention schedule.", "inputs": [ "Closure conditions evidence", "Closure outcome code", "Handover items and receiving parties", "Applicable retention schedule reference" ], "outputs": [ "Closure report and lessons record", "Final state transition entry", "Retention and disposition record" ], "preconditions": [ "Open issues and change requests are dispositioned or transferred", "Scope delivery is confirmed or the shortfall is recorded", "No legal hold blocks the intended disposition path" ], "effects": [ "The project reaches a terminal state with a classified outcome", "Post-closure accountability for benefits and support is assigned", "Records enter a scheduled retention regime with holds honoured" ], "source_refs": [ "SRC-001", "SRC-020", "SRC-008" ] }, { "id": "fn-validate-project-record", "name": "Validate project record", "description": "Run the model's validation rules over a project record and report violations without mutating the record.", "inputs": [ "Project record", "Active vocabulary versions", "Validation rule set" ], "outputs": [ "Violation list with severity and rule reference", "Pass or fail summary", "Suggested remediation per violation" ], "preconditions": [ "The record's declared vocabularies resolve", "Baseline references resolve to retained packages" ], "effects": [ "Date ordering, future-date, identifier resolution and breakdown-coverage defects are surfaced", "Records failing required checks can be blocked from publication", "Validation runs are themselves attributable and timestamped" ], "source_refs": [ "SRC-009", "SRC-004", "SRC-012", "SRC-006" ] }, { "id": "fn-commit-resources", "name": "Commit resources", "description": "Bind allocations of people, funds or assets from a resource owner to WBS elements for a stated period.", "inputs": [ "Resource owner commitment", "Target WBS elements and period" ], "outputs": [ "Allocation records bound to WBS elements for a stated period" ], "preconditions": [ "A resource-owning party has committed the resource" ], "effects": [ "People, funds or assets are committed to the project while ownership stays with the providing party" ], "source_refs": [ "SRC-027", "SRC-028" ] }, { "id": "fn-raise-risk-or-issue", "name": "Raise risk or issue", "description": "Log an uncertain threat or opportunity or a realized issue, assign ownership and response, and escalate exceptions beyond tolerance.", "inputs": [ "Identified threat, opportunity or realized issue" ], "outputs": [ "Register entry with owner and response" ], "preconditions": [ "Tolerances for manage-by-exception are defined" ], "effects": [ "Exceptions beyond tolerance are escalated without deleting the project-level record" ], "source_refs": [ "SRC-026", "SRC-030", "SRC-027" ] }, { "id": "fn-tailor-and-exchange", "name": "Tailor method and exchange record", "description": "Record the method profile and tailoring, and export or import a projection under a named interchange profile without claiming unearned conformance.", "inputs": [ "Adopted method profile and tailoring decisions", "Named interchange profile" ], "outputs": [ "Recorded method profile, tailoring and waivers", "Exported or imported projection under the named profile" ], "preconditions": [ "Tailoring is approved by the requirement owner or authorized approver" ], "effects": [ "Alignment is recorded without being upgraded to a conformance claim", "Mapping losses of the exchange are declared" ], "source_refs": [ "SRC-027", "SRC-030", "SRC-006" ] } ], "composition": [ { "target": "WM-ACT-006 Task", "relation": "CHILD", "purpose": "The project contains assignable work units; the project holds decomposition to work-package or control-account level and delegates execution detail, effort and task state to the task model through typed contains edges.", "required": true, "source_refs": [ "SRC-004", "SRC-021" ] }, { "target": "WM-ACT-031 Milestone and Deliverable", "relation": "CHILD", "purpose": "The project contains dated checkpoints and defined outputs; it gates and reports against them while their acceptance criteria and internal versions stay in the contained model.", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "target": "WM-ACT-029 Programme and Portfolio", "relation": "REFERENCE", "purpose": "Reference upward to the parent programme or portfolio that selected and contains this project; benefit aggregation and component balancing remain there. The containment edge is asserted from the parent side and must not be duplicated as a child edge here.", "required": false, "source_refs": [ "SRC-019", "SRC-018", "SRC-021" ] }, { "target": "Organization model (sponsoring and participating parties)", "relation": "REFERENCE", "purpose": "Resolve the sponsoring organization, governing body, funders and suppliers by their own authoritative identifiers instead of copying organization master data into the project record.", "required": true, "source_refs": [ "SRC-007", "SRC-003" ] }, { "target": "Person model (role holders and contributors)", "relation": "REFERENCE", "purpose": "Resolve role holders, risk owners and contributors, keeping personal data minimized in the project record and governed by the person model.", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] }, { "target": "Plan and schedule model", "relation": "REFERENCE", "purpose": "Bind the approved schedule baseline and authoritative dates while leaving activity network logic, durations, float and critical-path computation to the schedule model.", "required": false, "source_refs": [ "SRC-013", "SRC-001" ] }, { "target": "Act and action model", "relation": "REFERENCE", "purpose": "Resolve performed work to recorded acts for provenance and effort evidence without turning the project record into an activity log.", "required": false, "source_refs": [ "SRC-006", "SRC-001" ] }, { "target": "Process and workflow model", "relation": "REFERENCE", "purpose": "Reference repeatable procedures applied inside the unique undertaking, preserving the project-versus-process distinction.", "required": false, "source_refs": [ "SRC-016", "SRC-002" ] }, { "target": "Ownership and access service models", "relation": "MIX-IN", "purpose": "Inherit record ownership, access grant and audit machinery from the catalogue's ownership and access models rather than defining bespoke access control inside this model.", "required": true, "source_refs": [ "SRC-003", "SRC-010" ] }, { "target": "W3C PROV-O", "relation": "ALIGN", "purpose": "Align project provenance to Entity, Activity, Agent, Plan and Association, using wasAttributedTo, wasAssociatedWith, actedOnBehalfOf, startedAtTime and endedAtTime for attribution and delegation. Alignment only; conformance is not asserted.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "ISO 21502:2020 project management practices", "relation": "ALIGN", "purpose": "Align the management-practice findings to the standard's clause structure for benefits, scope, resources, schedule, cost, risk, issue, change control, quality, stakeholders, reports, information management, acquisitions and lessons learned.", "required": false, "source_refs": [ "SRC-001", "SRC-022" ] }, { "target": "ISO 21511:2018 work breakdown structures", "relation": "ALIGN", "purpose": "Align decomposition semantics and relationships to other breakdown structures; the standard gives guidance rather than a mandate, so a WBS is expected but not required by this model.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "ISO 21508:2018 earned value management", "relation": "ALIGN", "purpose": "Align progress and performance measurement to earned value concepts where an organization applies them, including the prerequisite of mutually exclusive scope elements.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "IATI Activity Standard 2.03", "relation": "ALIGN", "purpose": "Align publication of identity, status, type-coded dates, budgets, participating organizations, locations and results for projects under aid transparency obligations; IATI activities are not necessarily one-to-one with projects.", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-009", "SRC-021" ] }, { "target": "RAiD (ISO 23527:2022) and DataCite Metadata Schema 4.6", "relation": "ALIGN", "purpose": "Align to governed global project identifiers and citable project metadata so that a project can be referenced persistently outside its master system.", "required": false, "source_refs": [ "SRC-010", "SRC-011" ] }, { "target": "schema.org Project", "relation": "ALIGN", "purpose": "Provide a lossy publication mapping for web discovery only. schema.org types Project as a subtype of Organization, which conflicts with the temporary-endeavour definition, so the mapping must not be reversed into the canonical model.", "required": false, "source_refs": [ "SRC-017", "SRC-016" ] }, { "target": "Records disposition authority (for example a NARA General Records Schedule or an equivalent national schedule)", "relation": "EXTEND", "purpose": "Extend the retention finding with the jurisdiction's binding disposition authority, which supplies retention periods, hold rules and deviation procedures that this model deliberately does not invent.", "required": false, "source_refs": [ "SRC-020" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name a single accountable owner package for WM-ACT-005 records and register the sponsoring organization as the record owner, with contributing parties retaining ownership of their own allocation and supplier data.", "Declare which system is the authoritative master for project identifiers, publish its resolution endpoint, and state the mint policy used when no master identifier exists.", "Declare every controlled vocabulary the Dimension binds to lifecycle state, project type, delivery approach, link type and closure outcome, each with a scheme URI and version.", "Publish a retention schedule and an access policy, and name the disposition authority they derive from, before any project record is shared beyond the owning organization.", "Declare which sibling models resolve contained tasks, milestones and deliverables so that containment edges never dangle." ], "namespace_guidance": "Canonical terms live under a stable dotted namespace such as world.project with sub-namespaces mirroring the bundles. Dimension-local extensions use a Dimension-scoped prefix and are never promoted into the canonical namespace without a model version change. External scheme codes from IATI, RAiD, DataCite or an organizational breakdown coding system are bound as alternate identifiers or classification bindings carrying their scheme URI and version; they are never overloaded onto canonical field names.", "registry_links": [ "Registry entry vr.wm-act-005 at nav path NAV.ACT.PRJ is the canonical registration for this model and the source of its containment relations.", "Contained models WM-ACT-006 and WM-ACT-031 must resolve through the same registry so that typed edges can be validated.", "The parent relation from WM-ACT-029 is asserted at the parent side; this model records only a reference to avoid a duplicated containment edge.", "Alignment targets are registered as external standards with their version, not as owned models." ] }, "canon_and_patch": { "canonicalization_rules": [ "The canonical form is a format-neutral record graph. JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections and must round-trip identifiers, typed links, times, units and currencies without loss.", "Instants are canonicalized to RFC 3339 with seconds and an explicit numeric offset or Z. Values that are genuinely date-precision, such as a planned start date, retain date precision and declare it rather than being widened to a midnight instant.", "Monetary values are canonicalized as amount plus explicit currency code plus price base plus period; a bare number is never canonical. Quantities always carry an explicit unit of measure.", "Ordered and hierarchical structures such as the breakdown, phases and link sets are canonicalized by explicit code and parent reference, never by array position or file ordering.", "Every classification value is canonicalized as scheme URI plus scheme version plus code, so that a code is never interpretable only by local convention." ], "patch_rules": [ "Patches apply against a declared record version or baseline version; a patch that would alter approved baseline content must be expressed as a change request decision rather than a direct field update.", "Append-only structures, including the state transition log, gate decisions, performance datasets, status reports and disposition records, accept insert operations only; a correction is a new entry that supersedes an earlier one by explicit reference.", "Every patch carries the acting agent, the system, a reason, the effective time and the recorded time.", "A patch that removes personal data executes as redaction with a tombstone, never as a silent field clear." ], "compatibility_rules": [ "Adding an optional data element, an alternate identifier scheme or a new artifact kind is backward compatible; changing the meaning of an existing lifecycle state, link type or closure outcome code is not.", "Controlled vocabularies are versioned and each record pins the scheme version under which it was classified, so a vocabulary revision never silently reinterprets historic records.", "Removing a required element, narrowing a cardinality or re-keying an artifact requires a new model major version and a migration note recorded in the registry.", "Alignment mappings may change independently of the canonical model and must state which external standard version they target." ] }, "artifact_rules": { "identity_priority": [ "The authoritative master-system identifier issued by the system of record for the project, stored together with the identifying system and the assignment time, is the primary key for every artifact and link.", "A governed global identifier or IRI where one exists, such as a RAiD under ISO 23527, a funder award identifier, a published activity identifier or a DOI, recorded as an alternate identifier with its issuing registry and resolution URL.", "A UUID or ULID minted by the adopting Dimension, used only when neither of the above exists, and retained as a stable local alias once a master identifier later appears.", "A name, acronym, charter date, reporting period or fiscal year is never an identifier; such values may serve only as search aids and must not appear as a key." ], "timestamp_rule": "All instants use RFC 3339 with explicit seconds and an explicit numeric offset or Z; -00:00 is reserved for a known UTC value whose local offset is unknown. Event time, meaning when the thing itself happened such as a gate decision, a state change taking effect or an actual start, is recorded separately from observation or ingestion time, meaning when the fact was captured in the record, whenever the two differ; performance data additionally carries its own data date. Date-precision values keep date precision with a declared precision indicator rather than being coerced into instants, and an actual date is never later than the recorded time at which it was asserted.", "serial_naming_rule": "Serial artifacts such as charter revisions, baseline packages, gate decisions, status reports, change requests, risk entries and disposition records are named as master project identifier, then artifact kind, then a zero-padded monotonically increasing sequence. The reporting period, effective time or approval date is metadata inside the artifact and must never be used as the sequence key or as a substitute for it.", "integrity_rule": "Each retained artifact records a named-algorithm content hash, the agent and system that produced it, and the record or baseline version it was derived from. Superseded artifacts are retained and marked superseded-by rather than overwritten, so that historic performance figures, gate decisions and approvals stay reproducible; deletion under a retention schedule leaves a tombstone stating what was removed, by whom and under which authority." }, "policies": [ "No project record claims budget, resource or supplier commitments while it is unauthorized; such a record is held in a proposed state and marked as lacking an authorization instrument.", "Approved baselines are immutable. Performance may only be reported against a named baseline version, and a variance figure without a baseline reference is invalid.", "Personal data in stakeholder, role and allocation records is minimized to what the project function requires and is retained only under a declared retention schedule and jurisdictional basis.", "External standards are recorded as alignments with any conflict noted; conformance to a standard is never asserted without evidence of an assessment.", "Every structural claim in this model traces to a cited source; a node without primary support is marked as a gap rather than presented as canonical.", "A project record is created only from an authorizing instrument; informal task lists do not mint a project.", "Baselines and Management Agreement parameters change only through recorded change control or a signed gate decision.", "Need-to-know is the default; contributing parties see their allocations, not necessarily the full charter or classified annexes.", "Method tailoring is explicit. Alignment with ISO, PMI, PRINCE2, NASA or GovS 002 is never silently upgraded to a conformance claim.", "Event time and ingestion time are both stored when they differ, including for delayed status ingest from scheduling tools." ], "crud": { "read": [ "The default read granularity is the project header: identity, classification, lifecycle state, planned and actual dates, sponsor and parent reference.", "Reading cost, performance, supplier or personal-data findings requires an explicit scope grant naming the finding or artifact.", "Every read of a restricted finding or artifact is logged with requester, scope, purpose, outcome and an RFC 3339 timestamp with offset.", "Consumers must be able to read the last-updated time so that staleness can be assessed without privileged access." ], "create": [ "Creating a project requires either a resolvable master-system identifier or an authorized mint request together with a sponsoring organization reference.", "Creation records the authorization instrument reference, or an explicit marker that the record is proposed and unauthorized.", "Containment edges are created only after the target task, milestone or deliverable record exists and resolves.", "Creation is attributed to an agent and carries an ingestion timestamp distinct from any event time it asserts." ], "update": [ "Updates to baseline-controlled content, meaning approved scope, schedule and cost, pass through change control and never as direct field writes.", "Non-baseline updates record the acting agent, reason, effective time and recorded time.", "A classification change pins the vocabulary scheme version in force at the time of the change and retains the prior binding.", "State changes are appended to the transition log rather than mutating history." ], "delete": [ "Project records are not hard-deleted while any live obligation exists, including funder reporting, audit, statutory retention or a legal hold.", "Cancellation, suspension and abandonment are lifecycle transitions with recorded reasons, not deletions.", "Deletion of personal data inside a retained project record executes as redaction with a tombstone recording what was removed, by whom and on what basis.", "Executed disposition is itself a recorded event citing the disposition authority that permitted it." ] }, "roles": [ { "name": "Sponsor", "responsibilities": [ "Hold accountability for the project and its business case", "Authorize the charter, baselines and closure within delegated limits", "Own the project record on behalf of the sponsoring organization", "Approve withholding of otherwise disclosable information" ] }, { "name": "Governing body or steering committee", "responsibilities": [ "Take reserved decisions including gate outcomes and re-baselines", "Set and review delegated tolerances", "Commission independent assurance and act on its findings", "Approve transfers of ownership and terminal outcomes" ] }, { "name": "Project manager", "responsibilities": [ "Steward the project record and keep it current and internally consistent", "Operate scope, schedule, cost, risk, issue and change practices within tolerance", "Escalate beyond delegated thresholds without delay", "Discharge reporting obligations at the agreed cadence and detail" ] }, { "name": "Registrar or data steward", "responsibilities": [ "Assign and reconcile identifiers and maintain alternate identifier bindings", "Maintain controlled vocabularies, scheme versions and link-type governance", "Run validation and reject records that fail required checks", "Apply canonicalization, patch and compatibility rules across projections" ] }, { "name": "Assurance reviewer or auditor", "responsibilities": [ "Conduct independent review of outputs and of project management itself", "Verify artifact integrity and reconstruct decisions from retained evidence", "Report non-conformities and track corrective action to closure", "Operate under time-bounded, logged access grants" ] }, { "name": "Resource or supplier owner", "responsibilities": [ "Bind and withdraw allocations of people, funds and assets for stated periods", "Own their own allocation and performance data within the project record", "Notify contention and inability to sustain a commitment", "Evidence supplier performance and respond to disputes" ] }, { "name": "Records custodian", "responsibilities": [ "Apply the disposition authority and per-class retention periods", "Impose and release legal holds and record both", "Execute disposition with tombstones and verify execution", "Preserve access logs at least as long as the records they describe" ] } ], "access": { "default_rule": "Deny by default beyond the sponsoring organization. Project header findings, meaning identity, classification, lifecycle state and planned dates, are readable by the owning organization and by the governance body of any parent programme or portfolio; everything else requires an explicit, scoped and time-bounded grant recorded against a named grantee.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Publicly funded projects may carry a mandated transparency obligation that makes selected fields public, in which case the obligation source and the published field set are recorded and any withheld field carries a stated ground.", "Commercially sensitive cost, reserve, procurement and supplier findings remain restricted even inside the owning organization and are readable only by named roles.", "Personal data within stakeholder, role and allocation records is restricted to named administrators and to the individuals themselves where a jurisdictional right applies.", "Assurance reviewers and auditors receive time-bounded read access across all findings for a declared review scope, which expires automatically at the end of the review.", "A legal hold overrides both scheduled deletion and any narrowing of access that would impede the hold.", "Contributing parties retain read access to their own allocation and supplier data after the project closes, for the duration of their own retention obligations.", "Statutory audit and inspector-general access to the full file.", "Classified or compartmented annexes visible only to cleared principals.", "Partner-shared subsets defined by agreement, excluding unshared financial or personnel data.", "Lawful whistleblowing or safety-reporting channels that bypass the project manager." ], "audit_requirements": [ "Log the actor, scope, stated purpose, outcome and an RFC 3339 timestamp with explicit offset for every access to a restricted finding or artifact.", "Record every grant, modification, expiry and revocation of access together with the authorizing role and the effective time.", "Retain access logs at least as long as the retention period of the records they describe, and place them under the same legal holds.", "Make the audit trail reconstructable after redaction by preserving tombstones that survive the removal of the underlying content.", "Log reads of charter, baseline and gate artifacts with principal, scope, event time and ingestion time.", "Log mutations to identity, justification, baselines, allocations and close disposition.", "Retain audit records at least as long as the project file retention schedule." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Owner or maintainer", "Registry ID", "Model ID", "Vocabulary and scheme versions in force" ], "read_order": [ "AGENTS.md first: resolve Name, Type, Specification URL, Storage type URL, Interface URL and Processes URL before any read or write, including when the store is MongoDB or an MCP server rather than a file tree.", "Specification URL: load the model scope, boundaries, bundle and finding structure, and the out-of-scope list so that sibling-model concerns are not written here.", "Storage type URL: learn the projection in use and its canonicalization rules for identifiers, times, units, currencies and typed links.", "Interface URL: bind to the read and write interface and discover the access scopes and audit obligations it enforces.", "Processes URL: follow the governed create, update, change-control, reporting, closure and disposition procedures.", "Only then read the project record itself, starting from the identity and lifecycle-state findings and resolving the authorization instrument before trusting any commitment data." ] } }, "coverage": { "claim": "Covers the decision and operating surface of a single bounded project as an aggregate root — identity and registration, authorization and mandate limits, objectives and scope boundary, work breakdown and typed component links, resource/budget/supplier commitments, lifecycle states and gates, approved baselines and change control, progress and earned value, risk/issue/assurance, stakeholders, record provenance and access, and closure with transition, disposal and retention — relative only to the cited ISO 21500-series concept and guidance pages, NASA NPR 7120.5F, UK GovS 002, GAO cost and schedule guides, IATI 2.03, RAiD/ISO 23527, DataCite 4.6, W3C PROV-O, NARA GRS, APM and PMI/PRINCE2 public material. Completeness is claimed only against those retrieved sources and only for the project layer; task execution, milestone and deliverable internals, programme and portfolio aggregation, schedule-network calculus and process definitions are delegated to sibling models. Privacy and information-security control coverage are declared gaps, not claims. No universal or exhaustive completeness is claimed.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Master-system identifier first, governed global identifiers such as RAiD and award numbers second, Dimension-minted UUID or ULID last; collision, stability and supersession rules are asked explicitly and dates are barred from being keys." }, { "dimension": "lifecycle", "status": "covered", "notes": "Declared, versioned state vocabulary with permitted transitions, abnormal termination distinct from completion, phases and gate decisions, and closure with classified outcome. IATI ActivityStatus supplies a real governed example rather than an invented state set." }, { "dimension": "relationships", "status": "covered", "notes": "Typed containment edges to tasks and milestones/deliverables, upward reference to programme or portfolio, external dependencies, supplier links and risk-to-target links; hierarchy is expressed by explicit parent or child edge types after the IATI related-activity rule." }, { "dimension": "temporal", "status": "covered", "notes": "Type-coded planned and actual dates with ordering and future-date rules, RFC 3339 instants with seconds and explicit offset, event time separated from ingestion time, performance data date, working calendar and fiscal-year conventions referenced rather than assumed." }, { "dimension": "provenance", "status": "covered", "notes": "PROV-O aligned attribution, delegation and derivation; asserting agent and source system recorded per assertion; content hashes and superseded-by links keep historic baselines and decisions reproducible." }, { "dimension": "ownership", "status": "covered", "notes": "Sponsor and owning organization, governing body, reserved versus delegated decisions, resource and supplier owners retaining their own data, and post-closure benefit ownership handover." }, { "dimension": "validation", "status": "covered", "notes": "A dedicated validation function plus rules for date ordering, future dates, identifier resolution, breakdown coverage without overlap, earned-value consistency and vocabulary version pinning." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default beyond the owning organization with bundle, layer, finding and artifact scopes; mandated-transparency, commercial-sensitivity, personal-data, assurance and legal-hold exceptions are enumerated with audit obligations." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Disposition authority, per-class retention periods with a trigger event, legal-hold override, and redaction with tombstones that preserve the audit trail. Anchored on NARA General Records Schedules as a working authority; the applicable schedule is jurisdictional and must be supplied by the adopting Dimension." }, { "dimension": "interoperability", "status": "covered", "notes": "Alignments to ISO 21502, ISO 21511, ISO 21508, IATI 2.03, RAiD/ISO 23527, DataCite 4.6, PROV-O and schema.org, each recorded as an alignment with version, with the schema.org modelling conflict stated rather than smoothed over." }, { "dimension": "classification", "status": "covered", "notes": "Project type, delivery approach and sector or thematic codes are bound with scheme URI and version and with an explicit assertor, and the project-versus-operations test is asked directly." }, { "dimension": "measurement and performance", "status": "covered", "notes": "Control-account progress techniques, earned value against a named baseline, data date, consistency checks, forecast basis and an explicit question about when earned value does not apply." }, { "dimension": "authority and governance", "status": "covered", "notes": "Authorization instrument, governing body, reserved decisions, delegated tolerances, escalation thresholds, gate decision authority and independence of assurance." }, { "dimension": "scope and change control", "status": "covered", "notes": "Scope statement with exclusions and assumptions, scope confirmation, breakdown coverage, immutable baselines and a change-control route that links each decision to the baseline version it altered." }, { "dimension": "spatial", "status": "covered", "notes": "Locations, jurisdictions and affected communities are carried with geometry and stated precision, supported by IATI location and RAiD spatial coverage. Applies conditionally: many software or research projects will leave it empty." }, { "dimension": "privacy", "status": "gap", "notes": "Personal data is minimized, restricted and redacted with tombstones, but no data-protection instrument was retrieved live during this research: the EUR-Lex GDPR fetch returned no body, so no privacy-law source is cited. The specific lawful basis, retention limit and data-subject rights must be supplied by the adopting Dimension's jurisdiction." }, { "dimension": "security", "status": "gap", "notes": "Access classification, grant lifecycle and audit logging are specified, but no information-security control standard was retrieved and cited. Cryptographic, transport and key-management controls are deliberately left to a sibling security service model rather than asserted here without support." } ], "known_omissions": [ "No sibling risk model is confirmed in the registry, so risk and issue registers are held inline in this model; if a dedicated risk model exists they should move there and be referenced.", "Contract and procurement instrument internals are excluded and no alignment to a contracting data standard such as OCDS was performed.", "Benefit realization after closure is referenced but not modelled; ISO 21503 places sustained benefit realization at programme level.", "Sector-specific regimes are not covered: construction information management, defence earned-value system compliance, clinical trial registration and safety cases each add mandatory structure.", "No alignment was verified to scheduling exchange formats such as project XML or P6 exchange files, so schedule interoperability beyond dates is unproven.", "Resource cost rates, payroll and internal recharge mechanics are excluded as accounting concerns.", "Sustainability, environmental and social safeguard obligations are not modelled.", "Full ISO texts were not read: ISO 21500, 21502, 21505, 21511 and 21508 are paywalled and only official scope abstracts, committee pages and one secondary clause summary were available, so clause-level fidelity is asserted at abstract level only.", "ISO 21502, 21500, 21511 and 21505 full texts are paywalled; clause-level field lists are inferred from abstracts, TOC fragments, ISO news and first-party summaries, not from the purchased standards.", "ISO 21506:2024 vocabulary, ISO 21508:2026 EVM, ISO 21512:2024 EVM implementation guidance and ISO 21513:2026 post-project evaluation were not fetched; they are emerging or adjacent alignments.", "ISO/DIS 21520 AI concepts and ISO/WD 21514 requirements and 21515 competency are under development and excluded.", "PMI page HTTP fetch was blocked; the official definition is taken from the live PMI URL via search. PMBOK Guide 7 performance domains were not used as a primary schema.", "UK GovS 002 full PDF and The Teal Book v3 (including a reported programme and project data standard) were not retrieved; landing-page and search descriptions were used.", "DIN 69901, IPMA ICB, FIDIC/CSI construction structures, BIM information models, GAO cost-estimating guides and MS Project/PMXML schemas were not retrieved.", "Legal-entity joint-venture project companies, multi-currency treasury, sanctions screening, indigenous consultation and classified compartment rules lack primary support here and remain gaps." ], "conflicts": [ "schema.org types Project as a subtype of Organization, that is an agent, while ISO 21500/21502, APM and DataCite treat a project as a temporary endeavour or activity. The mapping is publication-only and lossy, and the canonical model follows the endeavour reading.", "There is no single normative lifecycle-state vocabulary. IATI publishes six governed statuses, NASA uses phases with key decision points, and ISO 21502 accepts predictive, incremental, iterative, adaptive and hybrid life cycles. The model therefore requires the state set to be declared with its scheme and version rather than assuming one.", "Project granularity is not standardized. IATI allows sub-activities via a hierarchy attribute and related-activity edges, and RAiD covers projects and sub-projects alike, so where a project ends and a task begins is a Dimension-level decision that this model can only constrain, not settle.", "ISO/TR 21506:2018 vocabulary has been withdrawn and replaced by ISO 21506:2024, so term definitions may have shifted; no 2024 text was available for this research and no definition is cited from either edition.", "Earned value presumes a decomposed breakdown with control accounts, which ISO 21508 requires; adaptive and agile delivery frequently does not maintain them, so performance measurement must permit declared alternatives rather than mandating earned value.", "ISO 21511 gives guidance on work breakdown structures but explicitly excludes processes, methods and tools and is not a mandate, so a breakdown is treated as expected practice rather than a normative requirement of this model.", "PMI temporary-endeavor language conflicts with NASA continuing-operations projects that have an unspecified Phase E end and use initial capability cost. Record the variant; do not force an end date.", "ISO 21500:2012 guidance on project management is withdrawn; 21500:2021 is context and 21502:2020 is project guidance. Consumers still citing 21500:2012 as the project-management standard are stale.", "PMI lifecycle phase names, PRINCE2 processes, NASA A–F and ISO 21502 delivery-approach-neutral phases are competing framings. Store a named lifecycle_model rather than a single universal phase enum.", "Work-package versus WM-ACT-006 task, and milestone/deliverable versus WM-ACT-031, can double-master the same object if containment is implemented as copy instead of typed link.", "ISO 21502 includes benefits inside project practice; many programme methods place benefit realization above the project. Model contribution here and realization owner as a reference.", "EVM is mandatory in some NASA and contract regimes and explicitly not required for other work types; it cannot be a required field of every project." ], "regional_assumptions": [ "Monetary values assume explicit currency codes in the manner of IATI's default-currency attribute; price base, fiscal-year boundaries and escalation conventions vary by jurisdiction and organization and must be declared, not inferred.", "Public transparency duties apply only to publicly funded or aid-funded projects; IATI publication and comparable funder registries are obligations of particular funding regimes, not general requirements.", "Retention and disposition are anchored on a US federal example, NARA's General Records Schedules; other jurisdictions have their own binding schedules and the adopting Dimension must substitute the applicable authority.", "Personal-data handling assumes a jurisdiction with storage-limitation and minimization duties; the specific regime was not verified during this research and differs materially between regions.", "Working calendars, public holidays and week conventions are locale-specific and are referenced by identifier rather than embedded in the model.", "NASA NPR 7120.5F gate and baseline obligations are US federal spaceflight requirements used here as evidence that such regimes exist, not as a general requirement on all projects.", "NASA NPR 7120.5F is mandatory for NASA space-flight projects and is used here as a high-rigour operating profile, not as a global law.", "GovS 002 and SRO accountability apply to UK government departments and arm's length bodies; other public sectors differ.", "PRINCE2 Version 7 is widely used in UK and Commonwealth public delivery; PMI vocabulary is more common in US private-sector practice.", "EIA-748 EVM and US federal certification thresholds are jurisdiction-specific.", "Records retention, classified markings and personal-data rules are jurisdiction-specific and only sketched." ], "adversarial_checks": [ "Searched for a normative requirement that a project must have a work breakdown structure. ISO 21511:2018 provides guidance and explicitly excludes processes, methods and tools, so the breakdown finding is presented as expected practice with declared coverage questions rather than as a mandate.", "Tested whether a charter date, name or reporting period could serve as an identifier. Rejected: identity priority names the master-system identifier first and explicitly bars names, acronyms, dates and periods from being keys, and the serial naming rule bars periods from sequence keys.", "Tested whether benefits realization belongs to the project. ISO 21503:2022 places benefit realization at programme level and ISO 21504:2022 states it does not give project guidance, so only benefits the project is itself accountable for are retained, with an explicit split question.", "Checked whether schema.org/Project could serve as the canonical shape. Rejected: it is a subtype of Organization, which contradicts the temporary-endeavour definition, and the conflict is recorded instead of being quietly reconciled.", "Checked whether an IATI activity is equivalent to a project. Rejected: the hierarchy attribute and parent/child related-activity edges allow sub-activities and funding slices, so IATI is treated as an alignment and publication target, not an identity authority.", "Tested whether a single lifecycle state vocabulary could be asserted as canonical. Rejected after comparing IATI's six statuses, NASA's phase and key-decision-point model and ISO 21502's five delivery approaches; the model requires the vocabulary to be declared and version-pinned.", "Tested whether earned value could be required for all projects. Rejected: ISO 21508 presumes mutually exclusive decomposed scope elements, so the measurement finding asks directly when earned value is inapplicable and what replaces it.", "Attempted to verify a privacy-law source live and failed; rather than citing an unverified instrument, privacy is recorded as a gap with a regional assumption, and security is likewise marked a gap because no control standard was retrieved.", "If a consumer treats a Git repo, Mongo collection or MCP tool list as the project, they have collapsed projection into semantics; AGENTS.md and the identity priority forbid that.", "If a date, gate name or version timestamp is used as the primary key, the identity priority rule is violated.", "If agile product-mode work is ingested as a never-ending project without an authorizing instrument, PMI uniqueness/temporariness and ISO 21502 authorization context are violated unless a bounded undertaking is declared.", "If programme, plan, process and project are stored as one object, NASA 2.1.1.1, ISO 21502's exclusion of programme/portfolio guidance and PMI project-versus-process contrast are all violated.", "If baseline numbers are edited in place without a change event, NASA Management Agreement and ISO change-control practice are violated and earned-value meaning collapses." ] }, "researchAdjudication": { "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "Both providers independently reached entry_kind=aggregate for vr.wm-act-005 and drew the same containment lines: the project owns decomposition to work-package/control-account level and holds typed edges to WM-ACT-006 tasks and WM-ACT-031 milestones/deliverables rather than restating their internals, references WM-ACT-029 programme/portfolio upward, and delegates schedule-network logic, repeatable process definitions and person/organization master data to siblings. Claude's boundary_notes additionally settle the three hard cases with evidence — schema.org's Project-as-Organization modelling is declared a lossy publication-only alignment rather than reconciled, IATI activity is an alignment and publication target rather than an identity authority, and PROV Activity/Plan supplies attribution semantics without the project becoming the provenance graph of every act. That is a complete, non-overlapping boundary, so the model boundary and entry kind are fixed before any node is accepted." }, "decisions": [ { "concept": "Base provider selection", "disposition": "claude as base", "rationale": "Not chosen on size. Claude's scope_statement, in_scope/out_of_scope and eight sourced boundary_notes settle every adjacent model (programme/portfolio, task, milestone/deliverable, plan/schedule, process, PROV, schema.org, IATI) with an explicit ownership rule and typed-edge delegation, and its six bundles decompose without overlap. Grok reorganizes much of the same material but leaves boundary work partly as method caveats rather than model boundaries." }, { "concept": "Entry kind", "disposition": "accepted as aggregate", "rationale": "Both providers independently assert aggregate and both implement it the same way — the project owns registration, mandate, breakdown and baselines while contained tasks and milestones/deliverables are referenced by typed edge, never copied. No adjudication needed beyond recording the agreement." }, { "concept": "Method tailoring, waivers and compliance matrix", "disposition": "accepted into l-authority-and-mandate", "rationale": "Wholly net-new against the base and backed by three independent regimes (NASA compliance matrix with deviations and waivers, PRINCE2 tailoring, GovS 002 mandated application). It also gives the base a structural home for the alignment-is-not-conformance rule that Claude otherwise states only in prose." }, { "concept": "Transition, disposal and residual obligations at close", "disposition": "accepted into l-closure-and-retention", "rationale": "Asset disposal, decommissioning, data archival and the warranty, classified-material and liability tail that outlives operational close appear nowhere in the base closure or retention findings and are not listed among its known omissions. Partial overlap on close disposition is accepted because the net-new half is material and the layer is the exact right home." }, { "concept": "Charter and continued business justification (grok)", "disposition": "rejected as duplicative", "rationale": "The base already holds the authorization instrument, signer, delegated tolerances and authorization continuity on re-baseline, suspension or transfer in f-charter-and-authorization, and business-case re-validation against actual performance in f-business-case-and-funding. Withdrawal of justification is already reachable through the abnormal-termination question." }, { "concept": "Goals, scope, benefits and boundaries (grok)", "disposition": "rejected as duplicative", "rationale": "Fully covered by f-objectives-and-success-criteria and f-scope-boundary-and-exclusions, including the benefit accountability split between project, parent programme and operations that grok raises. Adding it would create a second scope statement inside the same model." }, { "concept": "Provenance, ownership and access (grok)", "disposition": "rejected as duplicative", "rationale": "The base splits the same content into f-record-provenance-and-evidence and f-access-classification-and-confidentiality, both PROV-aligned, both with bundle/layer/finding/artifact access scoping and audit obligations. Software ingest agents are already reachable through the asserting-agent-and-system question." }, { "concept": "Retention, deletion and interoperability (grok)", "disposition": "rejected as a finding, exchange half deferred", "rationale": "Roughly half the finding duplicates f-retention-archiving-and-deletion (disposition authority, legal hold, tombstones). The genuinely new part — a named interchange profile and an explicit aligned-not-conformant declaration — deserves its own evidence rather than riding into the base attached to duplicate retention structure, so it is deferred instead." }, { "concept": "Grok bundles identity-and-classification and intent-and-authorization", "disposition": "rejected as reorganization", "rationale": "Both are alternative groupings of content the base already holds in b-mandate-and-identity and b-scope-and-structure; their child findings match base findings at 0.6 to 0.94 similarity. Accepting them would fork the model's top-level shape without adding evidence." }, { "concept": "Base-only bundle b-time-lifecycle-and-baselines", "disposition": "retained", "rationale": "Grok scatters lifecycle, gates, dates, baselines and change across three bundles. Keeping the base grouping preserves the single place where an approved baseline, the change that altered it and the effective-versus-recorded time of the transition are reconciled, which is the property that makes performance figures reproducible." }, { "concept": "Continuing-operations projects with unspecified end", "disposition": "deferred, recorded as a conflict note", "rationale": "Grok's NASA evidence (Phase E with unspecified end, initial capability cost instead of full life-cycle cost) sits in tension with the base purpose statement's temporary endeavour framing. It is a declared variant, not a contradiction — the base already asks the project-versus-operations criterion — so it goes to deferred research rather than blocking a draft." }, { "concept": "schema.org Project typed as a subtype of Organization", "disposition": "resolved as lossy publication-only alignment", "rationale": "Both providers reached the same resolution independently: follow the ISO/APM temporary-endeavour reading, record the modelling conflict rather than smoothing it, and claim no conformance. Resolved, therefore not a critical conflict." }, { "concept": "Earned value as a required field of every project", "disposition": "resolved as conditional with declared alternatives", "rationale": "ISO 21508 presumes decomposed control accounts and NASA explicitly exempts non-developmental, steady-state and basic-research work below its threshold. Both providers converge on requiring a declared measurement method with named alternatives, which the base already asks directly." }, { "concept": "Grok functions authorize, baseline, report, control-change, decide-gate, transition, close-and-evaluate", "disposition": "rejected as duplicative", "rationale": "Each maps one-to-one onto an existing base function (fn-authorize-project, fn-establish-baseline, fn-publish-status-report with fn-record-performance-measurement, fn-decide-change-request, fn-record-gate-decision, fn-transition-lifecycle-state, fn-close-and-dispose-project). Only the three operations with no base counterpart were taken." } ], "publicationHolds": [ "Source verification: none of the roughly thirty distinct URLs across the two providers has been re-resolved by this adjudication. Every accepted source must be fetched live and version-pinned before publication, with particular attention to the two NASA NPR 7120.5F entry points (directive page versus Chapter 2 deep link), GovS 002 v2.1, the PeopleCert PRINCE2 v7 page, schema.org v30.0, IATI 2.03 codelists, DataCite 4.6 and the NARA GRS page.", "Paywalled ISO texts: ISO 21500, 21502, 21503, 21504, 21505, 21508 and 21511 were read only as catalogue abstracts, committee pages, ISO news and one tier-4 secondary clause summary. Clause-level fidelity is asserted at abstract level only and the draft must say so; no clause number may be cited as if the purchased text had been read.", "Vocabulary currency: ISO/TR 21506:2018 is withdrawn and replaced by ISO 21506:2024, which neither provider retrieved; ISO 21511 is under revision as ISO/DIS 21511 and ISO 21513:2026 on post-project evaluation was not fetched. No term definition may be published as standard-derived until the current editions are checked.", "Multi-profile domain validation: the model has not been exercised against more than one delivery regime. Before publication it must be validated against at least a public-sector regime (NASA or GovS 002), an aid-transparency regime (IATI 2.03), a research regime (RAiD/ISO 23527) and an adaptive or agile delivery profile that maintains no control accounts.", "Declared gaps must ship as gaps: no data-protection instrument was retrieved live (the EUR-Lex fetch returned no body) and no information-security control standard was retrieved by either provider. Privacy and security coverage must be published as gaps with the jurisdictional instrument left to the adopting Dimension, not asserted.", "Accepted grok content needs first-party re-verification: grok's PMI fetch was blocked and taken via search, and the GovS 002 full PDF and Teal Book were not retrieved. Both accepted findings (f-tailoring-and-compliance, f-transition-disposal-and-residual-obligations) lean on SRC-006 and SRC-007, so their supporting text must be confirmed from the primary documents.", "Retention is anchored on NARA General Records Schedules as a US federal working example; the applicable disposition authority is jurisdictional and the adopting Dimension must substitute it before the retention finding is treated as operative." ], "deferredResearch": [ "Open-ended undertakings: reconcile NASA continuing-operations projects (unspecified Phase E end, initial capability cost in place of a full life-cycle end) with the temporary-endeavour framing, and decide whether f-lifecycle-state-and-transitions or f-project-dates-and-time-semantics needs an explicit open-ended-horizon question rather than assuming a planned end.", "Interchange profile and conformance posture: research a dedicated interoperability finding covering the named import/export profile, which concepts are declared aligned rather than conformant, and the projection-is-not-semantics rule, with its own evidence instead of arriving attached to duplicate retention structure.", "Post-project evaluation: ISO 21513:2026 was not retrieved by either provider. Fetch it and decide whether formal post-project evaluation is a distinct finding or an extension of closure and lessons.", "Sibling risk model: the base holds risk and issue registers inline because no dedicated risk model is confirmed in the registry. Confirm the registry state; if such a model exists, move f-risk-register and f-issue-and-escalation there and replace them with typed references.", "Schedule and contracting interoperability: no alignment was verified to scheduling exchange formats (P6, project XML) or to a contracting data standard such as OCDS, so schedule interoperability beyond typed dates and supplier-commitment exchange both remain unproven.", "Exception as a first-class event: verify whether the base delegated-tolerance and escalation-threshold questions fully capture PRINCE2 manage-by-exception semantics, or whether raising, recording and closing an exception needs its own state and evidence trail." ] }, "statistics": { "sources": 30, "bundles": 6, "layers": 14, "findings": 30, "questions": 122, "artifacts": 29, "functions": 14 } }