Ownership and asserted authority per record class, attestation and verification of directory records, and the identity and time rules applied to every record.
record-stewardship-and-authority
Record stewardship and asserted authority
Which actor owns each record class in this model, on what basis they assert authority to publish or amend it, in which jurisdiction or profile, and what happens to stewardship on merger, closure or service transfer.
Questions
- Which steward owns each record class in this model?ownership
Expected answer
- Record class enumeration
- Steward reference per class
- Delegation arrangements where stewardship is shared
- On what basis does a steward assert authority to publish or amend a record class?authority
Expected answer
- Authority basis reference (licence, contract, statutory duty, internal delegation)
- Effective period of the authority
- Limits on the assertion
- What happens to stewardship when a provider organization merges, closes or transfers a service?lifecycle
Expected answer
- Successor steward reference
- Handover instant and instrument
- Treatment of records created under the prior steward
directory-verification-and-attestation
Directory verification and attestation
Attestation by a responsible party that a directory record is accurate, and verification of attested fields against primary sources, with verification status, method, date and re-verification due date.
Questions
- Who attested to the accuracy of a directory record, and at what instant?evidence
Expected answer
- Attesting actor reference and role
- Attestation instant
- Fields covered by the attestation
- Against which primary source and by what method was an attested field verified?validation
Expected answer
- Primary source reference
- Verification method identifier
- Verification outcome per field
- How stale may a verified field become before it must be re-verified or marked unreliable?temporal
Expected answer
- Maximum age per field class
- Next re-verification due date
- State applied when the due date passes
Artifacts
- Verification and attestation recordThe record of one attestation and its verification against primary sources for a named set of directory fields.
identifier-and-time-provenance
Identifier and time provenance
The identity assignment rules, the separation of event, observation and ingestion time, supersession linkage and the boundary between provenance held here and the externally owned audit trail.
Questions
- Which identifier is authoritative for a record when several systems issue one?identity
Expected answer
- Authoritative master-system identifier with issuing system
- Secondary governed global identifier or IRI
- Dimension-minted UUID or ULID used only as fallback
- Which of event time, observation time and ingestion time does a given field carry, and are all three required?temporal
Expected answer
- Per-field time-kind declaration
- Rule requiring separate recording when the three differ
- Behaviour when only one time is available
- How is a superseded record version linked to its replacement and to the agent that made the change?provenance
Expected answer
- Supersedes and superseded-by references
- Changing agent reference and role
- Reason for the change
- What provenance must this model hold, and what belongs to the external audit trail?security
Expected answer
- Local provenance field set
- Reference to the audit model that owns access events
- Statement that referencing an audit record confers no audit-trail ownership
directory-discovery-and-endpoints
Directory discovery, projections and endpoints
Consumers query where care is offered, hours, specialties and how to connect electronically. Public projections omit capacity, staffing, encounters and sensitive practitioner contacts. Endpoints describe connectivity; they do not grant this model ownership of the target FHIR server, XCA actor or audit log. Federated directories must preserve time-stamped updates and deprecation status rather than hard-delete.
Questions
- Which projection (public directory, professional referral search, internal network, capacity heatmap) is being served, and which finding classes are included or omitted?access
Expected answer
- projection (code)
- included_finding_ids (id[])
- omitted_finding_ids (id[])
- small_number_suppression (boolean)
- What electronic endpoints are published for this organization or affiliation, with connection type, managing organization for support, and applicable network context?interoperability
Expected answer
- endpoint_id (identifier)
- connection_type (Coding)
- address (url)
- managing_organization_ref (reference)
- affiliation_context_ref (reference) - endpoint on Organization versus OrganizationAffiliation
- payload_type (CodeableConcept[])
- For federated ingest, what is the source directory, last-update watermark, conflict-resolution policy, and deprecation status of each entry?provenance
Expected answer
- source_directory_uri (uri)
- update_watermark_time (date-time)
- conflict_policy_uri (uri)
- deprecated (boolean)
- refresh_interval (duration)
Artifacts
- directory_endpoint_recordElectronic access point bound to an organization or affiliation. Not the target system's operational log. Populated by publishEndpoint and directoryQuery.
- directory_projection_viewNamed filtered view over provision records. Materialised only if the adopting Dimension stores views; otherwise derived. Populated by directoryQuery.