World Models · Published

Health Care Delivery

Give an agent the system-side context needed to understand, populate, inspect and operate health care delivery: which provider organizations offer which services, through which authorized roles and at which physical, mobile, home or virtual locations; what capacity and readiness exist; how demand queues, allocations, referrals and transfers move people toward care; and how those records are stewarded, verified, measured and disclosed. Encounter lifecycle is delegated to the contained model WM-ACT-018; clinical, personal, workforce-qualification, organizational and estates facts stay with their owning models.

AI YAMLAGENTS.mdResearch evidence
Published. Research assurance: reviewable-draft. The Claude + Grok synthesis is published for use and review with caution. It passed structural validation but is not yet a canonical Vercy release because the source and coverage holds below remain open.
Catalogue IDWM-ACT-014
Version0.3.0-research.1
Previous version-
Typeaggregate
ValidationPassed
Synthesis digestsha256:2935218567413d25…
34Sources
6Bundles
16Layers
28Findings
98Questions
19Artifacts
Format-independent logical structure

Bundles → Layers → Findings → Questions + Artifacts

delivery-networkDelivery network2 layers

Who offers which health services, through which authorized roles, and at which physical, mobile, home or virtual delivery locations.

provider-service-topologyProvider-service topology2 findings

The offered service, its classification and modality, and its bindings to an accountable provider organization and to delivery locations.

service-offering-identity

Service offering identity and classification

The identity, classification, specialty and modality of a care service that a provider organization offers, held distinct from the organization that provides it and the place where it is delivered.

Questions
  1. Which identifier authoritatively distinguishes this service offering from every other offering of the same provider?identity
    Expected answer
    • Master-system service identifier and its issuing system
    • Governed global identifier or IRI where one is published
    • Dimension-minted UUID or ULID used only as a fallback
  2. How is the offering classified by category, service type and specialty, and against which governed code systems?classification
    Expected answer
    • Service category code with code system and version
    • Service type code with code system and version
    • Specialty code with code system and version
  3. Which delivery modalities does the offering support, and is each modality independently deliverable?definition
    Expected answer
    • Modality enumeration (inpatient, outpatient, day, mobile, home, virtual)
    • Per-modality deliverable flag
    • Constraints where a modality is only available with another
  4. What is the offering's active status and effective period, and what supersedes it when it is withdrawn or replaced?lifecycle
    Expected answer
    • Active flag and status code
    • Effective period start and end
    • Reference to the superseding offering record
Artifacts
  • Service offering directory entryThe record of record for one offered service, carrying identity, classification, modality, status and effective period.
provider-location-binding

Provider and delivery-location binding

The binding of an offering to the accountable provider organization and delivery unit and to one or more delivery locations, including virtual, mobile and home delivery points, held as references.

Questions
  1. Which provider organization and internal delivery unit is accountable for the offering at each location?composition
    Expected answer
    • Provider organization reference and issuing system
    • Delivery unit reference within the organization hierarchy
    • Accountability start and end
  2. At which physical, mobile, home or virtual locations is the offering delivered, and how is a virtual delivery point represented?spatial
    Expected answer
    • Location references with instance or class mode
    • Location form (building, room, vehicle, area)
    • Virtual service connection detail reference
  3. How are many-to-many bindings between offerings, locations and delivery units represented without duplicating the location or organization record?relationship
    Expected answer
    • Binding record identifier
    • Referenced entity identifiers only, with no copied attributes
    • Rule prohibiting local address, geometry or hierarchy fields
Artifacts
  • Delivery binding recordThe record binding one offering to one accountable delivery unit and one delivery location for a stated period.
authorized-delivery-rolesAuthorized delivery roles2 findings

The time-bounded authorizations under which practitioner roles deliver named services at named locations, and whether those authorizations actually cover operating periods.

role-authorization-binding

Delivery role authorization

A time-bounded authorization for a practitioner role to deliver named services at named locations for a provider organization, referencing the person and their qualifications without restating them.

Questions
  1. Under whose authority is a practitioner role authorized to deliver this service at this location?authority
    Expected answer
    • Authorizing organization reference
    • Authorization instrument reference
    • Scope limits attached to the authorization
  2. What is the authorization period of the role, and how are lapses, suspensions and renewals represented here without restating licensure?temporal
    Expected answer
    • Authorization period start and end
    • Active flag with reason for inactivity
    • Reference to the licensure record that governs eligibility to hold the role
  3. Which services and locations does the role cover, and how is the role kept distinct from the person holding it?relationship
    Expected answer
    • Service offering references covered by the role
    • Location references covered by the role
    • Practitioner reference with no copied personal attributes
Artifacts
  • Delivery role authorization recordThe record of one role's authorization to deliver stated services at stated locations for a stated period.
role-coverage-and-vacancy

Role coverage and vacancy state

A derived, time-bounded assertion of whether authorized roles cover an offering's operating periods, including uncovered periods, temporary cover and on-call arrangement references, expressed as delivery supply rather than as staff rostering.

Questions
  1. Is the offering covered by at least the minimum authorized roles for each operating period, and what state applies when it is not?state
    Expected answer
    • Coverage state code per operating period
    • Minimum role requirement per period
    • Uncovered period start and end
  2. What distinguishes an unfilled establishment post from a temporarily uncovered operating period, and which of the two is recorded here?definition
    Expected answer
    • Definition boundary statement
    • Reference to the workforce system holding establishment posts
    • Local scope limited to uncovered delivery periods
  3. What evidence and observation time support a coverage assertion, and how confident is it?evidence
    Expected answer
    • Observation instant of the coverage assertion
    • Confidence grade
    • References to the rota or availability records consulted
availability-and-capacityAvailability and operational capacity3 layers

What the delivery network publishes as available, what it can actually deliver, and whether the inputs required to deliver are in place.

published-availabilityPublished availability1 findings

The operating hours, exceptions and access channels that the delivery network publishes, distinguished from bookable operational supply.

service-availability-schedule

Published availability and access channel

The published operating hours, time zone, planned and unplanned exceptions, access channels, referral method and appointment-required flags of an offering at a location, distinguished from the bookable supply held by the scheduling system.

Questions
  1. What are the published operating hours and time zone of the offering at each delivery location?temporal
    Expected answer
    • Days of week and open and close times
    • IANA time zone identifier
    • All-day or closed flag
  2. How are planned closures, holiday exceptions and unplanned suspensions of published availability represented?exception
    Expected answer
    • Exception period with start and end
    • Exception reason description
    • Whether the exception is planned or unplanned
  3. How does published availability differ from bookable supply, and which system of record owns each?definition
    Expected answer
    • Boundary statement separating published hours from bookable slots
    • Reference to the scheduling system of record
    • Rule that bookable slot inventory is never mirrored here
  4. Through which channels can the offering be reached, is a referral or appointment required, and by which method are referrals accepted?access
    Expected answer
    • Access channel enumeration
    • Appointment-required flag
    • Referral method codes and technical endpoint references
Artifacts
  • Published availability statementThe published statement of when and how an offering can be accessed at a location, suitable for a public directory projection.
operational-capacityOperational capacity2 findings

Quantified deliverable capacity and its point-in-time occupancy, with the definitional basis made explicit.

capacity-statement

Capacity statement

A quantified statement of deliverable capacity for an offering at a location over a period, with capacity type, unit and an explicit basis distinguishing physical stock, staffed and immediately available capacity, and surge or overflow capacity.

Questions
  1. What capacity type, unit and quantity are asserted, and over which period or at which instant?measurement
    Expected answer
    • Capacity type code (beds, treatment places, sessions, procedures, contacts)
    • Quantity with unit of measure
    • Period start and end, or instant
  2. Does the quantity count physical stock, staffed and immediately available capacity, or surge and overflow capacity, and which definition profile applies?definition
    Expected answer
    • Capacity basis code
    • Definition profile reference naming inclusions and exclusions
    • Explicit statement on inclusion of surge, overflow, observation and same-day places
  3. Which system asserted the capacity, when was it observed, and when was it received here?provenance
    Expected answer
    • Source system identifier
    • Observation time
    • Ingestion time
  4. To which authority and on what cadence must this capacity be reported, and under which instrument?requirement
    Expected answer
    • Recipient authority reference
    • Reporting cadence and due window
    • Reference to the obligating instrument or rule
Artifacts
  • Capacity statement recordOne immutable, versioned assertion of deliverable capacity for an offering, location, basis and period.
capacity-occupancy-snapshot

Capacity occupancy snapshot

A point-in-time count of occupied and available capacity against a named capacity statement, with an explicit snapshot rule separating single-instant snapshots from period aggregations.

Questions
  1. At which instant is occupancy measured, and is the value a single-instant snapshot or an aggregation over a reporting period?temporal
    Expected answer
    • Snapshot instant with offset
    • Snapshot versus aggregation flag
    • Reporting period when aggregated
  2. Which capacity statement is the denominator for an occupancy figure, and are surge and overflow units included in it?measurement
    Expected answer
    • Capacity statement reference
    • Occupied count and available count
    • Inclusion flags for surge and overflow units
  3. When must small-number occupancy values be suppressed or aggregated before they are disclosed?privacy
    Expected answer
    • Suppression threshold
    • Aggregation level applied
    • Projection in which the rule applies
Artifacts
  • Occupancy snapshot recordOne immutable occupancy observation against a named capacity statement at a stated instant.
service-readinessService readiness1 findings

Whether the tracer inputs required to deliver an offering are present, and which external records those inputs depend on.

readiness-tracer-and-dependency

Readiness tracer items and input dependencies

The readiness of an offering expressed as tracer items across amenities, equipment, standard precautions, diagnostic capacity and commodities, together with references to the externally owned workforce, equipment, estates and commodity records those items depend on.

Questions
  1. Which tracer items must be present for this offering to count as ready, and to which readiness domain does each belong?requirement
    Expected answer
    • Readiness domain enumeration
    • Tracer item list with present or absent status
    • Domain-to-item mapping and profile reference
  2. By what method, on which date and by which assessor was readiness observed?evidence
    Expected answer
    • Assessment method identifier and version
    • Assessment date and observation time
    • Assessor reference
  3. Which external inventory, workforce or estates records does a readiness item reference rather than restate?relationship
    Expected answer
    • Dependency reference with owning model
    • Dependency kind
    • Statement that stock levels and asset records are not held locally
  4. How is a composite readiness index derived from domain scores, and what does a missing domain do to it?measurement
    Expected answer
    • Index calculation rule and version
    • Domain score inputs
    • Handling of missing or not-applicable domains
Artifacts
  • Service readiness assessment recordOne completed readiness assessment for an offering at a location, with tracer results, method and assessor.
demand-access-allocationDemand, access and allocation3 layers

The conditions under which people may reach an offering, the demand waiting for it, and the supply-side commitment of capacity against that demand.

access-conditionsAccess conditions2 findings

Service-level eligibility, reach and accommodation attributes that determine who can obtain the offering and how.

eligibility-and-entry-condition

Service eligibility and entry condition

The conditions under which a person may receive an offering, expressed as coded service-level conditions and references to governing policy, never as an individual eligibility determination.

Questions
  1. Which eligibility conditions and qualifying comments apply to the offering, and against which policy are they defined?constraint
    Expected answer
    • Eligibility condition codes
    • Free-text qualifying comment
    • Governing policy reference
  2. Which authority sets each eligibility rule, and in which jurisdiction or profile does it apply?authority
    Expected answer
    • Setting authority reference
    • Jurisdiction or profile identifier
    • Rule effective period
  3. Where is an individual person's eligibility determination recorded, given that this model holds only the service-level rule?decision
    Expected answer
    • Owning model reference for personal determinations
    • Boundary statement excluding personal adjudication
    • Reference pattern used when a queue entry cites a determination
access-accommodation-and-reach

Access accommodation and reach

The reach of an offering over a population or area and the accommodations it provides, including languages, communication support, physical accessibility and remote or home delivery.

Questions
  1. Which population or geographic area does the offering serve, and is service refused outside it?spatial
    Expected answer
    • Coverage area reference
    • Population group reference
    • Behaviour when a request originates outside the area
  2. Which languages and communication supports are available, and are they available for every modality?access
    Expected answer
    • Communication language codes
    • Interpretation or assistive support flags
    • Per-modality availability of each support
  3. Which physical-access and reasonable-adjustment attributes are asserted, and against which standard are they coded?requirement
    Expected answer
    • Accessibility attribute codes with code system
    • Standard or profile against which they are asserted
    • Verification status of each asserted attribute
queue-and-waitingQueue and waiting state3 findings

Registered demand awaiting delivery, the rules that turn it into waiting time, and how it leaves the queue.

demand-registration-entry

Demand registration entry

A registered unit of demand awaiting delivery of a named offering, carrying listing time, priority or urgency class and requested service, and referencing the subject without inlining personal or clinical content.

Questions
  1. Which identifier distinguishes a queue entry, and how are duplicate registrations for the same demand detected?identity
    Expected answer
    • Queue entry identifier and issuing system
    • Duplicate-detection key set
    • Merge or link reference when duplicates are found
  2. Which priority or clinical urgency class is assigned, under which scheme, and who may change it?classification
    Expected answer
    • Priority class code and scheme version
    • Authorized changer role
    • History of class changes with times
  3. How is the subject of the demand referenced without inlining any clinical or demographic content?privacy
    Expected answer
    • Subject reference and issuing system
    • Prohibited field list
    • Pseudonymisation rule for operational projections
  4. Which offering, delivery unit or unnamed service pool is the demand registered against?relationship
    Expected answer
    • Requested offering reference
    • Delivery unit or pool reference
    • Named versus unnamed target flag
Artifacts
  • Queue entry recordThe record of one registered unit of demand, its priority class, listing time, current state and exit.
waiting-clock-rule

Waiting clock rule binding

The definition set that turns queue entries into waiting times: clock start event, pause or exclusion conditions, stop events and censoring. These rules are supplied by an adopting jurisdiction profile; no universal rule is asserted, and the national rule suites needed to fix them were not retrievable in this pass.

Questions
  1. Which event starts the waiting clock for this offering, and does a re-referral start a new clock or continue the existing one?definition
    Expected answer
    • Clock start event code and profile reference
    • Re-referral behaviour rule
    • Instant recorded as the clock start
  2. Under what conditions does the clock pause or exclude days, and how are those periods evidenced?temporal
    Expected answer
    • Pause or exclusion reason codes
    • Excluded period start and end
    • Evidence reference for each excluded period
  3. How are completed waits distinguished from ongoing waits that are still censored when a waiting time is published?measurement
    Expected answer
    • Completed versus censored flag
    • Census instant for censored waits
    • Rule for reporting the two populations separately
  4. Which jurisdiction profile supplies the clock rules in force, and what happens to entries created under a superseded profile?validation
    Expected answer
    • Profile identifier and version
    • Profile effective period
    • Migration or recomputation rule for entries under a prior profile
queue-exit-and-removal

Queue exit and removal

How a queue entry leaves the queue - fulfilled, offered and declined, deferred, transferred, removed or expired - with reasons, permitted transitions and the effect on waiting measurement.

Questions
  1. Which terminal and non-terminal states may a queue entry take, and which transitions between them are permitted?state
    Expected answer
    • State enumeration with terminal flags
    • Permitted transition matrix
    • Actor role authorized for each transition
  2. What reason vocabulary explains a removal that is not a fulfilment, and who may record it?event
    Expected answer
    • Removal reason code set
    • Recording actor reference
    • Whether the reason is service-initiated or subject-initiated
  3. How are offers, refusals and non-attendance recorded so that they do not silently reset the waiting measure?exception
    Expected answer
    • Offer and refusal event records with times
    • Non-attendance handling rule under the bound profile
    • Effect on the clock stated explicitly
capacity-allocationCapacity allocation1 findings

Supply-side commitment of capacity units against demand, and the exceptions that release them.

capacity-commitment-and-release

Capacity commitment and allocation exception

The commitment of a capacity unit, authorized role and location to a queue entry or referral, and the exceptions that release the commitment, held as delivery supply and referencing rather than reproducing patient-facing booking records.

Questions
  1. Which capacity unit, authorized role and location are committed, and against which queue entry or referral?process
    Expected answer
    • Committed capacity reference
    • Role and location references
    • Target queue entry or referral reference
  2. How does a supply-side capacity commitment differ from the patient-facing appointment record, and which model owns each?composition
    Expected answer
    • Boundary statement separating commitment from booking
    • Appointment or slot reference held externally
    • Rule prohibiting local storage of booking participant detail
  3. Which events release a committed capacity unit, and is the released capacity returned to the same period?exception
    Expected answer
    • Release event codes (cancellation, reschedule, non-attendance, reallocation)
    • Release instant
    • Whether the unit returns to the originating capacity period
Artifacts
  • Capacity commitment recordThe supply-side record committing a capacity unit, role and location to a named queue entry or referral, and its release.
care-flow-coordinationCare-flow coordination3 layers

Directed movement of demand and delivery responsibility between services, units and organizations, and the reference link to the encounters that result.

referral-routingReferral routing2 findings

Directed requests that another service take on delivery, and what happens to them.

referral-request-and-routing

Referral request and routing

A directed request that a named or unnamed target service take on delivery, carrying source, target, urgency, routing method and a reference to the coded clinical reason held elsewhere.

Questions
  1. Which identifier follows a referral across the sending and receiving organizations?identity
    Expected answer
    • Referral identifier and issuing system
    • Receiving organization's local identifier and its linkage
    • Rule for identifier continuity across organizational boundaries
  2. Is the referral directed to a named offering, a delivery unit, a location or an unnamed pool, and how is that expressed?relationship
    Expected answer
    • Target reference with target kind
    • Performer type code when the target is a pool
    • Preferred location references
  3. How is urgency expressed on a referral, and under which coded scheme?classification
    Expected answer
    • Priority code and scheme version
    • Time target implied by the priority
    • Authorized role for setting or changing priority
  4. How is the clinical reason for a referral referenced without copying clinical content into this model?privacy
    Expected answer
    • Reason reference with owning model
    • Permitted coded reason category
    • Prohibited narrative and attachment fields
Artifacts
  • Referral recordThe delivery-side record of one directed referral, its routing, priority and current disposition.
referral-disposition-and-closure

Referral disposition and closure

The dispositions a referral can reach - acknowledged, accepted, redirected, rejected, withdrawn, expired, completed - with reasons, response-time expectations and chain preservation across redirections.

Questions
  1. Which dispositions may a referral reach, and which actor is entitled to set each one?state
    Expected answer
    • Disposition state enumeration
    • Authorized actor role per disposition
    • Permitted transition matrix
  2. When a referral is redirected, is it the same referral or a new one, and how is the chain preserved?lifecycle
    Expected answer
    • Same-record versus new-record rule
    • Chain reference to the prior referral
    • Rule for preserving the original clock start across the chain
  3. What time targets apply between referral sent, acknowledged and accepted, and how is a breach recorded?temporal
    Expected answer
    • Sent, acknowledged and accepted instants
    • Target intervals from the bound profile
    • Breach flag with reason
transfer-and-handoffTransfer and handoff1 findings

Movement of delivery responsibility between services, units, locations or organizations, with milestones and the point at which responsibility passes.

responsibility-transfer-milestone

Transfer of delivery responsibility

The record of delivery responsibility passing from a sending to a receiving service, unit or organization, with timestamped milestones, an explicit responsibility-transfer point and a continuity exception when the transfer fails.

Questions
  1. Which sending and receiving offering, delivery unit and location are party to the transfer?composition
    Expected answer
    • Sending offering, unit and location references
    • Receiving offering, unit and location references
    • Cross-organization flag
  2. At which milestone does delivery responsibility pass from the sending to the receiving service?ownership
    Expected answer
    • Named responsibility-transfer milestone
    • Instant at which responsibility passed
    • Rule when the milestone is never reached
  3. Which milestones are timestamped, and what is recorded when a milestone is missing?event
    Expected answer
    • Milestone set with instants (requested, accepted, departed, arrived, failed)
    • Missing-milestone marker with reason
    • Source system for each milestone
  4. What is recorded when a transfer fails or continuity of delivery is broken?exception
    Expected answer
    • Failure reason code
    • Fallback receiving service reference
    • Reference to the externally owned incident record, if one was raised
Artifacts
  • Transfer of responsibility recordThe record of one transfer of delivery responsibility with its parties, milestones and outcome.
encounter-flow-linkageEncounter flow linkage1 findings

The reference boundary between delivery-system records and the encounters owned by the contained model.

encounter-reference-binding

Encounter reference and delivery attribution

The link from delivery-system records to encounters owned by WM-ACT-018, carrying only the external encounter reference plus delivery-side attribution keys such as the offering, delivery unit, location, fulfilled queue entry and consumed capacity commitment.

Questions
  1. Which encounter identifier and issuing system are carried here, and how is the reference resolved?interoperability
    Expected answer
    • Encounter identifier and issuing system
    • Resolution endpoint or model reference
    • Behaviour when the reference cannot be resolved
  2. Which delivery-side keys are attached to an encounter reference?composition
    Expected answer
    • Attributed offering reference
    • Delivery unit and location references
    • Fulfilled queue entry and consumed capacity commitment references
  3. Which encounter fields must never be copied into this model, and what is the fallback when the contained model is unavailable?constraint
    Expected answer
    • Prohibited field list covering status, participants, actual timing and discharge disposition
    • Degraded-mode rule stating that counts are marked incomplete rather than reconstructed
    • Statement that this model never derives or asserts encounter state
  4. Can one encounter satisfy more than one queue entry or referral, and how is that represented?relationship
    Expected answer
    • Cardinality rule between encounter references and delivery records
    • Link record structure for many-to-many cases
    • Rule preventing double counting in delivery measures
quality-and-performanceQuality, measurement and disruption3 layers

The quality commitments a delivery unit asserts, the computable measures used to describe delivery performance, and declarations that delivery is degraded.

quality-commitmentDelivery quality commitments1 findings

The quality-management standards, accreditations and service-level commitments a delivery unit asserts, held as references with the evidence of record held elsewhere.

quality-commitment-reference

Quality commitment reference

The quality-management systems, standards and service-level commitments a delivery unit asserts over a named scope of offerings and sites, referencing certificates and policies issued and held by other parties.

Questions
  1. Which quality management system or standard does the delivery unit assert, and over which scope of offerings and sites?authority
    Expected answer
    • Standard or management-system reference with edition
    • Scope statement naming offerings and locations
    • Asserting organization reference
  2. Which quality dimensions does a stated commitment address?quality
    Expected answer
    • Dimension codes (safe, effective, timely, efficient, equitable, people-centred, integrated)
    • Commitment text or service-level target per dimension
    • Level at which the commitment applies (national, district, facility)
  3. What evidence supports a certification or accreditation claim, and where is the certificate of record held?evidence
    Expected answer
    • Certificate reference and issuing body
    • Validity period
    • Statement that the certificate of record is held by the issuing body
operational-measurementOperational measurement2 findings

Computable definitions of delivery measures and the result statements produced from them.

delivery-measure-specification

Delivery measure specification

The computable definition of a delivery measure: initial population, denominator, numerator and exclusion criteria, stratifiers, supplemental data, scoring method, unit and improvement notation, with inputs owned by other models named as references.

Questions
  1. What are the initial population, denominator, numerator and exclusion criteria of the measure?measurement
    Expected answer
    • Population criteria expressions with their type codes
    • Exclusion and exception criteria
    • Reference to the criteria library and its version
  2. Which stratifiers and supplemental data are required, and which are prohibited because they would re-identify small groups?privacy
    Expected answer
    • Required stratifier list
    • Prohibited stratifier list with rationale
    • Minimum cell size before a stratum may be published
  3. Which measure inputs are owned by other models, and how are they resolved without recomputing their state?composition
    Expected answer
    • Input reference list with owning model
    • Resolution mechanism and version pinning
    • Statement that referenced record states are consumed as published, never derived here
  4. Is an increase or a decrease in the measure an improvement, and what scoring method and unit apply?definition
    Expected answer
    • Improvement notation code
    • Scoring method (proportion, ratio, continuous variable, cohort)
    • Scoring unit
Artifacts
  • Delivery measure specificationThe versioned, computable definition of one delivery measure and its populations, stratifiers and scoring.
measure-result-and-comparability

Measure result and comparability

A computed result for a named measure version over a stated period and population, carrying computation provenance, input digests and explicit comparability caveats.

Questions
  1. Which measure version, input artifacts and computation run produced this result?provenance
    Expected answer
    • Measure specification identifier and version
    • Input artifact identifiers with content digests
    • Computation run identifier and executing agent
  2. What reporting period and time zone does the result cover, and when was it computed and published?temporal
    Expected answer
    • Reporting period start and end with offsets
    • Computation instant
    • Publication instant
  3. Which definitional or coverage differences prevent this result from being compared with another jurisdiction or period?quality
    Expected answer
    • Definition profile identifiers for each compared series
    • Coverage and completeness caveats
    • Break-in-series markers
Artifacts
  • Measure result statementOne immutable computed result for a measure version, period and stratum, with provenance and caveats.
delivery-disruptionDelivery disruption1 findings

Declarations that delivery is degraded, diverted, suspended or over capacity.

delivery-disruption-declaration

Delivery disruption declaration

A declaration that delivery of named offerings at named locations is degraded, diverted, suspended or over capacity, with affected scope, timing, restoration expectation and escalation reference, stopping short of investigation and cause attribution.

Questions
  1. What kind of disruption is declared, and against which severity scale?classification
    Expected answer
    • Disruption type code (outage, diversion, capacity breach, access failure)
    • Severity scale identifier and level
    • Whether the disruption is planned or unplanned
  2. Which offerings, locations and populations are affected, and are alternatives named?state
    Expected answer
    • Affected offering and location references
    • Affected population or area reference
    • Alternative offering references, where designated
  3. When did the disruption start, when was it declared, and what restoration time is expected?temporal
    Expected answer
    • Disruption start instant
    • Declaration instant
    • Expected restoration instant with confidence
  4. To whom is the declaration escalated, and where is any resulting investigation record held?authority
    Expected answer
    • Escalation recipient references
    • Notification obligation reference
    • Reference to the externally owned investigation record
Artifacts
  • Service disruption noticeOne immutable declaration of disrupted delivery with its scope, timing, escalation and closure.
governance-provenance-disclosureGovernance, provenance and disclosure2 layers

Who owns each record class, how records are verified, identified and timestamped, and under what constraints they are disclosed and retired.

stewardship-and-provenanceStewardship, verification and provenance4 findings

Ownership and asserted authority per record class, attestation and verification of directory records, and the identity and time rules applied to every record.

record-stewardship-and-authority

Record stewardship and asserted authority

Which actor owns each record class in this model, on what basis they assert authority to publish or amend it, in which jurisdiction or profile, and what happens to stewardship on merger, closure or service transfer.

Questions
  1. Which steward owns each record class in this model?ownership
    Expected answer
    • Record class enumeration
    • Steward reference per class
    • Delegation arrangements where stewardship is shared
  2. On what basis does a steward assert authority to publish or amend a record class?authority
    Expected answer
    • Authority basis reference (licence, contract, statutory duty, internal delegation)
    • Effective period of the authority
    • Limits on the assertion
  3. What happens to stewardship when a provider organization merges, closes or transfers a service?lifecycle
    Expected answer
    • Successor steward reference
    • Handover instant and instrument
    • Treatment of records created under the prior steward
directory-verification-and-attestation

Directory verification and attestation

Attestation by a responsible party that a directory record is accurate, and verification of attested fields against primary sources, with verification status, method, date and re-verification due date.

Questions
  1. Who attested to the accuracy of a directory record, and at what instant?evidence
    Expected answer
    • Attesting actor reference and role
    • Attestation instant
    • Fields covered by the attestation
  2. Against which primary source and by what method was an attested field verified?validation
    Expected answer
    • Primary source reference
    • Verification method identifier
    • Verification outcome per field
  3. How stale may a verified field become before it must be re-verified or marked unreliable?temporal
    Expected answer
    • Maximum age per field class
    • Next re-verification due date
    • State applied when the due date passes
Artifacts
  • Verification and attestation recordThe record of one attestation and its verification against primary sources for a named set of directory fields.
identifier-and-time-provenance

Identifier and time provenance

The identity assignment rules, the separation of event, observation and ingestion time, supersession linkage and the boundary between provenance held here and the externally owned audit trail.

Questions
  1. Which identifier is authoritative for a record when several systems issue one?identity
    Expected answer
    • Authoritative master-system identifier with issuing system
    • Secondary governed global identifier or IRI
    • Dimension-minted UUID or ULID used only as fallback
  2. Which of event time, observation time and ingestion time does a given field carry, and are all three required?temporal
    Expected answer
    • Per-field time-kind declaration
    • Rule requiring separate recording when the three differ
    • Behaviour when only one time is available
  3. How is a superseded record version linked to its replacement and to the agent that made the change?provenance
    Expected answer
    • Supersedes and superseded-by references
    • Changing agent reference and role
    • Reason for the change
  4. What provenance must this model hold, and what belongs to the external audit trail?security
    Expected answer
    • Local provenance field set
    • Reference to the audit model that owns access events
    • Statement that referencing an audit record confers no audit-trail ownership
directory-discovery-and-endpoints

Directory discovery, projections and endpoints

Consumers query where care is offered, hours, specialties and how to connect electronically. Public projections omit capacity, staffing, encounters and sensitive practitioner contacts. Endpoints describe connectivity; they do not grant this model ownership of the target FHIR server, XCA actor or audit log. Federated directories must preserve time-stamped updates and deprecation status rather than hard-delete.

Questions
  1. Which projection (public directory, professional referral search, internal network, capacity heatmap) is being served, and which finding classes are included or omitted?access
    Expected answer
    • projection (code)
    • included_finding_ids (id[])
    • omitted_finding_ids (id[])
    • small_number_suppression (boolean)
  2. What electronic endpoints are published for this organization or affiliation, with connection type, managing organization for support, and applicable network context?interoperability
    Expected answer
    • endpoint_id (identifier)
    • connection_type (Coding)
    • address (url)
    • managing_organization_ref (reference)
    • affiliation_context_ref (reference) - endpoint on Organization versus OrganizationAffiliation
    • payload_type (CodeableConcept[])
  3. For federated ingest, what is the source directory, last-update watermark, conflict-resolution policy, and deprecation status of each entry?provenance
    Expected answer
    • source_directory_uri (uri)
    • update_watermark_time (date-time)
    • conflict_policy_uri (uri)
    • deprecated (boolean)
    • refresh_interval (duration)
Artifacts
  • directory_endpoint_recordElectronic access point bound to an organization or affiliation. Not the target system's operational log. Populated by publishEndpoint and directoryQuery.
  • directory_projection_viewNamed filtered view over provision records. Materialised only if the adopting Dimension stores views; otherwise derived. Populated by directoryQuery.
disclosure-and-retentionDisclosure and retention2 findings

Named projections with their permitted field sets and purposes, and retention and disposition instructions whose execution is delegated.

projection-and-disclosure-control

Projection and disclosure constraint

Named projections of this model - public directory, operational, and person-linked - with the fields each may contain, the purposes and recipient classes for which each is released, and the aggregation or suppression required before publication. Evaluation and enforcement of any release decision are owned by the access-authorization model.

Questions
  1. Which fields may appear in each named projection, and which are excluded by construction?access
    Expected answer
    • Projection identifier and name
    • Allowed field list per projection
    • Excluded field list with rationale
  2. For which purpose and recipient class is each projection released?privacy
    Expected answer
    • Purpose codes
    • Recipient class codes
    • Conditions attached to release
  3. What aggregation or suppression must be applied before a capacity, queue or flow projection is published?requirement
    Expected answer
    • Minimum aggregation level
    • Small-number suppression threshold
    • Rounding or perturbation rule
  4. Which model evaluates and enforces a release decision, given that this model only declares the constraint?authority
    Expected answer
    • Access-authorization model reference
    • Statement that no evaluation or enforcement occurs here
    • Failure behaviour when the evaluator is unavailable
Artifacts
  • Projection definitionThe versioned definition of one named projection: permitted fields, purposes, recipient classes and suppression rules.
retention-and-disposition-instruction

Retention and disposition instruction

The retention class assigned to each record class of this model, legal-hold marking, the tombstone that must survive deletion so that references from other models do not dangle, and the evidence of executed disposition. Periods and execution are owned externally.

Questions
  1. Which retention class applies to each record class in this model, and which policy sets its period?retention
    Expected answer
    • Retention class code per record class
    • Retention policy reference and version
    • Trigger event that starts the retention period
  2. How is a legal hold recorded, and what does it suspend?constraint
    Expected answer
    • Legal hold flag and scope
    • Instrument imposing the hold
    • Operations suspended while the hold is active
  3. What must survive deletion as a tombstone so that references from other models do not dangle?requirement
    Expected answer
    • Minimum tombstone field set (identifier, record class, disposition instant, successor reference)
    • Prohibited residual content
    • Behaviour of resolvers encountering a tombstone
  4. What evidence proves that a disposition was executed, and which model holds that evidence?evidence
    Expected answer
    • Disposition evidence reference
    • Executing model or Dimension policy reference
    • Statement that execution is not performed by this model
Artifacts
  • Retention and disposition instructionThe instruction assigning a retention class, hold state and tombstone requirement to a record class of this model, for execution by the owning policy model.

Publication holds

  • Source verification is incomplete: re-resolve all 18 base sources live with version pins before publication. The base research recorded HTTP 403 or empty responses for the ISO catalogue page, OECD Health at a Glance and the national waiting-time rule suites, and Grok recorded failures for ISO OBP, the ISO 7101 HTML page and the NHS ODS full page.
  • The accepted finding and both accepted functions cite Grok SRC-009 (IHE mCSD v4.0.0 volume 1, 2025-05-21). That source must be imported into the merged source list and the source_refs remapped to the merged identifier; do not publish the imported node while its supporting source is absent from the merged evidence pack.
  • Grok SRC-017 (NHS England Digital ORD API catalogue entry) rests on search snippets rather than a retrieved page. Live-verify it or reduce the deactivate-with-tombstone function's refs to the mCSD source before publication.
  • Multi-profile validation is outstanding: bind and exercise at least two jurisdiction profiles across waiting-clock rules, capacity basis inclusions, eligibility, retention periods and small-number suppression thresholds. The model supplies no defaults, so a single-profile publication would misrepresent portability.
  • Confirm the WM-ACT-014 CONTAINS WM-ACT-018 edge, currently review_state candidate in planning/VERCY-MODEL-RELATIONS.csv. If the edge is re-typed, the encounter-reference finding and every delivery-flow measure depending on it must be re-adjudicated. Register the candidate REFERENCE edges to the person, organization, place, personal-health, access, retention and audit models.
  • Validate that the imported directory projection view artifact resolves as a derived instance of the base projection definition, carrying the definition version and input digests, and does not stand up as a second competing projection record of record.
  • Pin the FHIR release explicitly: the base aligns to R5 while IHE mCSD 4.0.0 and the HL7 national directory guide are R4-based. A projection cannot satisfy both without a stated version choice and mapping.
  • Publication dependencies remain open: the Specification, Storage type, Interface and Processes URLs required by AGENTS.md, and https://ver.cy/model-agent-protocol.md, are unverified.
  • No terminology value sets are asserted for service type, specialty, priority, removal reason or provider class; neither provider verified a terminology source in this pass, so coded-value bindings must be supplied and verified by the adopting Dimension before publication.

Deferred research

  • Waiting-clock rule suites: the base recorded NHS England RTT and AIHW METeOR as unretrievable (403) and left waiting-clock-rule as a profile binding, while Grok retrieved NHS England RTT status and the WLMDS live. Re-verify those pages and fold them in as a named England jurisdiction profile bound to the base waiting-clock-rule finding, never as a universal state machine.
  • Licence-to-operate versus accreditation award: adjudicate with the organization model whether a service-level authorization-to-operate precondition (CLIA, pharmacy authority, radiation licence) belongs to this aggregate as a deliverability constraint, or whether all such facts are referenced from the organization and place models as the base boundary note currently asserts.
  • Schedule, Slot and Appointment ownership: the base assigns bookable supply to the scheduling neighbour while Grok holds Schedule and Slot locally. Adjudicate where slot-level bookable capacity sits relative to the base capacity-commitment-and-release finding before either model publishes.
  • EpisodeOfCare and longitudinal administrative grouping: neither provider models it locally and both flag it as unresolved between WM-ACT-018, the personal-health model and this aggregate.
  • Patient transport and ambulance dispatch: the base neither includes nor explicitly excludes it and Grok splits EMS service offering (in) from vehicle tracking (out). Adjudicate against a transport or emergency-response model, together with ambulance offload-delay measures.
  • Provider affiliation and delivery-network topology: HIE, IDN and network membership with role codes and effective periods appears only in Grok and only inside a provider-registry wrapper this plan rejects. Determine whether delivery-network membership is a delivery fact belonging here or an organization-model relationship.
  • ISO 7101:2023 normative clause text and OECD comparative access and waiting-time indicator definitions were unretrievable for both providers; both quality-commitment and comparability claims stay reference-only until the normative text is reviewed.
  • Social-care delivery scope: ISO/DIS 13940 edition 2 adds social care and SHA ICHA-HP HP.2 is residential long-term care, leaving it unresolved whether social-care delivery is in this aggregate or an adopting-profile extension.