# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T14:24:50Z", "synthesisSha256": "5fa91c74c789fd95c187d235c0c61ee2e105dd0ca6cc7dcb1e68285fd57cd898", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ACT-018", "registryId": "vr.wm-act-018", "name": "Encounter", "version": "1.0.0", "previousVersions": [ { "version": "0.2.0-legacy", "url": "https://github.com/ver-cy/world-models/blob/feat/mega-model-registry/models/events-phenomena/X5-encounter-and-interaction.md" } ], "entryKind": "event", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.ENC" ], "tags": [ "encounter", "act.enc" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-018-encounter/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-018", "model": { "registry_id": "vr.wm-act-018", "model_id": "WM-ACT-018", "name": "Encounter", "entry_kind": "event", "purpose": "Describe a bounded interaction among parties while preserving separate participation, exchange, perspective, acknowledgement and outcome evidence.", "scope_statement": "One encounter occurrence or explicitly planned, attempted or disputed encounter record. An occurred encounter needs evidence of engagement involving at least two distinct parties represented by role entries under an adopted interaction profile; incomplete identity is allowed without inventing parties. The two-party criterion is a local boundary decision, not a universal standard definition. Records persist independently of the event they describe.", "in_scope": [ "Encounter-specific binding to occurrence identity, interaction kind, engagement criterion and segment bounds", "Human, organization, group or automated-agent participation by reference with scoped roles and authority", "Physical, remote, hybrid and bounded asynchronous channels, exchange references and timing uncertainty", "Separate private accounts, proposed shared records, scoped acknowledgements, disputed outcomes and follow-up references", "Policy-qualified access, evidence provenance, record corrections, retention and mapping limits" ], "out_of_scope": [ "Generic occurrence identity issuance, lifecycle engine and conflict resolution belong to WM-ACT-015 or the adopting master", "Scheduling, message transport, contract formation, payment settlement and task execution remain in their masters", "Clinical care delivery and clinical observations or diagnoses are external domains, not mandatory content of every encounter", "Person, organization, location, authority, consent, audit, retention execution and signature verification engines", "Persistent relationships, unrestricted broadcasts and unobserved co-presence without evidence of interaction", "Operational guidance for dangerous activities; any such encounter uses policy-level references only" ], "boundary_notes": [ { "neighbor": "WM-ACT-015 Occurrence / Event", "distinction": "Accept conceptual EXTEND for the encounter-specific engagement and perspective facets; delegate generic event identity and state machinery. Executable inheritance awaits a pinned binding.", "source_refs": [ "SRC-002", "SRC-004" ] }, { "neighbor": "WM-ACT-014 Health Care Delivery", "distinction": "Incoming containment is conditional on a clinical profile. A generic meeting or negotiation is not thereby a healthcare event; this model cannot own care delivery.", "source_refs": [ "SRC-003" ] }, { "neighbor": "WM-ACT-046 Clinical Observation / Diagnosis", "distinction": "Outgoing candidate containment is narrowed to optional external references in clinical profiles. Observations and diagnoses keep independent masters and need not exist for an encounter.", "source_refs": [ "SRC-003" ] }, { "neighbor": "Appointment, message, transaction and persistent relationship masters", "distinction": "Invitations and calendar responses are plans; a message is an exchange artifact; a transaction outcome needs its own authoritative record; a recurring relationship is not one encounter.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] }, { "neighbor": "Legacy X5 and unreviewed supplement", "distinction": "Retain party perspectives and optional mutual records. Reject mandatory countersigning, a single channel, one immutable record forever and universal all-party-consent disclosure. Multiple scoped revisions and disputed or absent outcomes are permitted.", "source_refs": [ "SRC-003", "SRC-006", "SRC-007", "SRC-008" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Internet Calendaring and Scheduling Core Object Specification (iCalendar)", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc5545", "version_or_date": "RFC 5545, September 2009; updates require profile review", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T14:23:40Z", "relevance": "Sections 3.2.12, 3.2.16, 3.6.1 and 3.8: scheduled events, participant response, recurrence and identifiers. Calendar acceptance does not establish attendance." }, { "id": "SRC-002", "title": "PROV-O: The PROV Ontology", "organization": "W3C", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation, 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T14:23:40Z", "relevance": "Sections 3.1-3.3: agents, activities, records, attribution, qualified roles, delegation and derivation. These are vocabulary alignments, not proof of authority or truth." }, { "id": "SRC-003", "title": "FHIR Encounter", "organization": "HL7 International", "url": "https://hl7.org/fhir/R5/encounter.html", "version_or_date": "FHIR R5 5.0.0; Encounter trial-use page", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T14:23:40Z", "relevance": "Sections 8.11.1, 8.11.2 and 8.11.6: clinical interaction, planning versus occurrence, variable granularity, participants, locations and partOf. Clinical scope is not imposed on the generic model." }, { "id": "SRC-004", "title": "Activity Vocabulary", "organization": "W3C", "url": "https://www.w3.org/TR/activitystreams-vocabulary/", "version_or_date": "Recommendation, 2017-05-23", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T14:23:40Z", "relevance": "Core Activity, actor, object, result, instrument, context and inReplyTo support exchange references and continuity. Activity alone does not imply reciprocal engagement." }, { "id": "SRC-005", "title": "Date and Time on the Internet: Timestamps", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002; updates require profile review", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T14:23:40Z", "relevance": "Sections 4 and 5 support offset-qualified recording instants. Duration, business calendars and precision of observations need separate semantics." }, { "id": "SRC-006", "title": "XML Signature Syntax and Processing Version 1.1", "organization": "W3C", "url": "https://www.w3.org/TR/xmldsig-core1/", "version_or_date": "Recommendation, 2013-04-11", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T14:23:40Z", "relevance": "Sections 3.2 and 8 distinguish verification, transformed signed content and application trust. Used to bound acknowledgement evidence, not mandate XML or infer legal agreement." }, { "id": "SRC-007", "title": "Data protection basics", "organization": "European Data Protection Board", "url": "https://www.edpb.europa.eu/sme/learn-the-basics/data-protection-basics_en", "version_or_date": "Undated living guidance, selected sections reviewed 2026-10-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T14:23:40Z", "relevance": "Personal and sensitive data, purpose limitation, minimisation, security and storage limitation. EU/EEA guidance is a regional policy input, not universal law." }, { "id": "SRC-008", "title": "Process personal data lawfully", "organization": "European Data Protection Board", "url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en", "version_or_date": "Undated living guidance, selected sections reviewed 2026-10-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T14:23:40Z", "relevance": "Legal bases, consent conditions and sensitive-data restrictions rebut universal all-party-consent assumptions. Actual recording, disclosure and representative authority need jurisdiction-specific review." } ], "structure": { "bundles": [ { "id": "binding", "name": "Encounter boundary", "description": "Encounter-specific questions about encounter boundary.", "rationale": "Separate this concern to preserve interaction evidence without taking ownership of referenced systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "layers": [ { "id": "interaction-binding", "name": "Interaction criterion", "description": "Bind the occurrence master to a declared interaction segment. Similar participants, timing or meeting links alone cannot prove two reports describe the same encounter.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "findings": [ { "id": "engagement", "name": "Encounter identity and engagement", "description": "Bind the occurrence master to a declared interaction segment. Similar participants, timing or meeting links alone cannot prove two reports describe the same encounter.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "questions": [ { "id": "engagement-q1", "kind": "identity", "text": "Which occurrence master and party-local identifiers refer to this encounter, and what evidence supports their reconciliation?", "answer_data": [ "master namespace", "master ID", "party-local aliases", "matching evidence", "unresolved match state" ] }, { "id": "engagement-q2", "kind": "definition", "text": "What engagement criterion distinguishes this interaction from a plan, unanswered attempt, broadcast or mere co-presence?", "answer_data": [ "profile reference", "interaction kind", "criterion", "observed engagement", "attempt or dispute state" ] }, { "id": "engagement-q3", "kind": "composition", "text": "What makes this one segment rather than a recurring series, parent encounter or separate follow-up?", "answer_data": [ "segment rule", "parent reference", "series reference", "split rationale" ] } ], "data_elements": [ { "id": "engagement-data-occurrence-binding", "name": "occurrence-binding", "description": "Authoritative occurrence master reference with namespace; do not issue a competing generic identity.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "engagement-data-engagement-assessment", "name": "engagement-assessment", "description": "Profile, kind, distinct party-role evidence, classification and unresolved evidence state.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "engagement-data-segment-links", "name": "segment-links", "description": "Parent, series and aliases with relation meaning, evidence and match state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "engagement-artifact", "name": "Encounter binding assessment", "description": "Optional review artifact for encounter identity and engagement; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "progress-assertions", "name": "Encounter progress", "description": "Record encounter-specific progress assertions against the occurrence master. An imported planned or cancelled record is not evidence that interaction happened; record correction is not a new occurrence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-002" ], "findings": [ { "id": "progress", "name": "Planned and observed progress", "description": "Record encounter-specific progress assertions against the occurrence master. An imported planned or cancelled record is not evidence that interaction happened; record correction is not a new occurrence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-002" ], "questions": [ { "id": "progress-q1", "kind": "state", "text": "Which current progress assertion is planned, attempted, active, ended, cancelled, entered in error or unresolved under the adopted profile?", "answer_data": [ "source state", "mapped state", "profile version", "assertion source" ] }, { "id": "progress-q2", "kind": "event", "text": "What observation supports opening or ending actual engagement rather than merely opening or closing its record?", "answer_data": [ "trigger evidence", "reporting party", "event reference", "observation time" ] }, { "id": "progress-q3", "kind": "exception", "text": "How are no-show, disconnection, resumption and conflicting closure reports represented without forcing agreement?", "answer_data": [ "exception kind", "resumption link", "conflicting assertions", "resolution authority" ] } ], "data_elements": [ { "id": "progress-data-progress-assertion", "name": "progress-assertion", "description": "Profile-qualified state and source assertion; occurred status requires engagement evidence.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-002" ] }, { "id": "progress-data-progress-evidence", "name": "progress-evidence", "description": "Evidence and exceptions linked to the generic event history, without implementing that history here.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-002" ] } ], "artifacts": [ { "id": "progress-artifact", "name": "Encounter progress account", "description": "Optional review artifact for planned and observed progress; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "parties", "name": "Participation and authority", "description": "Encounter-specific questions about participation and authority.", "rationale": "Separate this concern to preserve interaction evidence without taking ownership of referenced systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-007", "SRC-008" ], "layers": [ { "id": "participation", "name": "Party involvement", "description": "Identify participating roles, including representatives, interpreters and automated agents, separately from invitees and observers. Unresolved identity may use protected local placeholders; placeholders are not proof of distinct parties.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "findings": [ { "id": "party-roles", "name": "Actual and intended participants", "description": "Identify participating roles, including representatives, interpreters and automated agents, separately from invitees and observers. Unresolved identity may use protected local placeholders; placeholders are not proof of distinct parties.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "questions": [ { "id": "party-roles-q1", "kind": "relationship", "text": "Which parties actually engaged, were merely invited, observed, or remain unidentified, and what supports each status?", "answer_data": [ "party reference", "role", "involvement state", "evidence", "identity uncertainty" ] }, { "id": "party-roles-q2", "kind": "temporal", "text": "During which segments did each participant join, leave or participate intermittently?", "answer_data": [ "participation interval", "segment reference", "precision", "report source" ] }, { "id": "party-roles-q3", "kind": "classification", "text": "Which participant is a person, organization, group or automated agent, and what principal does the role represent?", "answer_data": [ "actor class", "principal reference", "automation disclosure state", "role qualifier" ] } ], "data_elements": [ { "id": "party-roles-data-party-role-entries", "name": "party-role-entries", "description": "Role entries with protected party references, involvement states, intervals and evidence. At least two distinct engaged parties, not merely two roles of the same party, are needed to assert occurrence under this local profile.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "party-roles-artifact", "name": "Participation register", "description": "Optional review artifact for actual and intended participants; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "representation", "name": "Representation limits", "description": "Keep authority to speak, attest, disclose and bind a principal distinct. Party perspectives are separately stewarded records; stewardship does not settle property rights or authorize disclosure.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ], "findings": [ { "id": "authority", "name": "Delegation and perspective stewardship", "description": "Keep authority to speak, attest, disclose and bind a principal distinct. Party perspectives are separately stewarded records; stewardship does not settle property rights or authorize disclosure.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ], "questions": [ { "id": "authority-q1", "kind": "authority", "text": "What mandate, scope and effective period allow a representative to act for a principal in this interaction?", "answer_data": [ "principal reference", "mandate reference", "scope", "effective interval", "verification state" ] }, { "id": "authority-q2", "kind": "ownership", "text": "Who stewards each party account and shared record, and under what accountable policy?", "answer_data": [ "perspective ID", "custodian role", "joint-governance reference", "applicable policy" ] }, { "id": "authority-q3", "kind": "constraint", "text": "Which proposed commitments or acknowledgements exceed the recorded mandate and require referral?", "answer_data": [ "proposed action", "mandate limit", "referral role", "refusal reason" ] } ], "data_elements": [ { "id": "authority-data-representation-evidence", "name": "representation-evidence", "description": "Principal, delegate, mandate reference, permitted action and verification limitations.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] }, { "id": "authority-data-perspective-stewardship", "name": "perspective-stewardship", "description": "Record custodians and governance references without asserting universal bilateral ownership.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "authority-artifact", "name": "Representation assessment", "description": "Optional review artifact for delegation and perspective stewardship; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "context", "name": "Channel and time", "description": "Encounter-specific questions about channel and time.", "rationale": "Separate this concern to preserve interaction evidence without taking ownership of referenced systems.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005" ], "layers": [ { "id": "channel-segments", "name": "Communication setting", "description": "An interaction may move among in-person, remote and written channels. Store protected endpoint and place references per segment, never access credentials or transport machinery.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "findings": [ { "id": "channels", "name": "Channels and locations", "description": "An interaction may move among in-person, remote and written channels. Store protected endpoint and place references per segment, never access credentials or transport machinery.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "questions": [ { "id": "channels-q1", "kind": "spatial", "text": "Which physical or virtual locations and channel segments contextualize the encounter?", "answer_data": [ "segment ID", "channel kind", "place reference", "endpoint reference", "valid interval" ] }, { "id": "channels-q2", "kind": "requirement", "text": "What language, interpretation or accessibility arrangements affected participation and record interpretation?", "answer_data": [ "language", "arrangement reference", "affected parties", "reported limitations" ] }, { "id": "channels-q3", "kind": "security", "text": "Which channel identifiers or recording references must be withheld from each audience?", "answer_data": [ "sensitivity", "recipient scope", "recording reference", "redaction rule" ] } ], "data_elements": [ { "id": "channels-data-channel-segments", "name": "channel-segments", "description": "Mode, protected endpoints, location references and validity intervals; unknown channel remains explicit.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] }, { "id": "channels-data-communication-qualifiers", "name": "communication-qualifiers", "description": "Language, interpretation and accessibility evidence, with no inferred competence.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "channels-artifact", "name": "Channel context map", "description": "Optional review artifact for channels and locations; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "time-claims", "name": "Timing semantics", "description": "Keep planned bounds, observed engagement periods, participant intervals and record ingestion instants separate. Elapsed or connected time does not automatically measure attention, billable service or clinical care.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "findings": [ { "id": "timing", "name": "Bounds and timing uncertainty", "description": "Keep planned bounds, observed engagement periods, participant intervals and record ingestion instants separate. Elapsed or connected time does not automatically measure attention, billable service or clinical care.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "questions": [ { "id": "timing-q1", "kind": "temporal", "text": "What are the planned and observed bounds, their time zones, precision and reporting sources?", "answer_data": [ "planned period", "actual period", "zone reference", "offset", "precision", "source" ] }, { "id": "timing-q2", "kind": "measurement", "text": "If a duration is reported, which segments, units and exclusions define it and how uncertain is it?", "answer_data": [ "duration value", "unit", "method", "excluded gaps", "uncertainty" ] }, { "id": "timing-q3", "kind": "quality", "text": "How are late reports, unknown ends, clock disagreements and date-only evidence preserved?", "answer_data": [ "ingestion instant", "uncertainty interval", "conflicting clocks", "raw time value", "quality flag" ] } ], "data_elements": [ { "id": "timing-data-time-assertions", "name": "time-assertions", "description": "Typed planned, actual and recorded times; preserve date-only and partial values rather than fabricate precision.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] }, { "id": "timing-data-duration-assessment", "name": "duration-assessment", "description": "Value, unit, method, included intervals and uncertainty; no automatic billing effect.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "timing-artifact", "name": "Timing assertion sheet", "description": "Optional review artifact for bounds and timing uncertainty; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "exchange", "name": "Exchanges and accounts", "description": "Encounter-specific questions about exchanges and accounts.", "rationale": "Separate this concern to preserve interaction evidence without taking ownership of referenced systems.", "source_refs": [ "SRC-002", "SRC-004", "SRC-006", "SRC-007" ], "layers": [ { "id": "exchange-links", "name": "Exchange references", "description": "Index exchanged messages, documents, object references and statements by source and recipient role. A transport receipt is not understanding, agreement, transfer of title or settlement.", "source_refs": [ "SRC-002", "SRC-004" ], "findings": [ { "id": "items", "name": "Items and statements exchanged", "description": "Index exchanged messages, documents, object references and statements by source and recipient role. A transport receipt is not understanding, agreement, transfer of title or settlement.", "source_refs": [ "SRC-002", "SRC-004" ], "questions": [ { "id": "items-q1", "kind": "relationship", "text": "What item or statement was exchanged, by which role and toward which recipient or audience?", "answer_data": [ "item master reference", "sender role", "recipient scope", "exchange kind" ] }, { "id": "items-q2", "kind": "evidence", "text": "What distinguishes asserted dispatch, receipt, review and disputed delivery for this exchange?", "answer_data": [ "delivery assertion", "evidence reference", "reported status", "dispute" ] }, { "id": "items-q3", "kind": "privacy", "text": "Which content can be referenced without copying sensitive payload into the encounter?", "answer_data": [ "minimal metadata", "payload master", "access scope", "retention reference" ] } ], "data_elements": [ { "id": "items-data-exchange-index", "name": "exchange-index", "description": "External item references, direction, delivery assertions and evidence; no message sending or goods-transfer functions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "items-artifact", "name": "Exchange index", "description": "Optional review artifact for items and statements exchanged; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "record-versions", "name": "Perspective records", "description": "Keep a unilateral account distinct from a shared proposal and an acknowledged revision. Multiple documents and translations may describe one encounter; preserve derivation and limited visibility.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007" ], "findings": [ { "id": "accounts", "name": "Private and shared accounts", "description": "Keep a unilateral account distinct from a shared proposal and an acknowledged revision. Multiple documents and translations may describe one encounter; preserve derivation and limited visibility.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007" ], "questions": [ { "id": "accounts-q1", "kind": "provenance", "text": "Which author, source material and transformation produced this account or translation?", "answer_data": [ "author role", "source reference", "derivation", "translation qualifier", "recorded time" ] }, { "id": "accounts-q2", "kind": "access", "text": "Which portions are private notes, shared proposals or content approved for a named audience?", "answer_data": [ "view class", "scope", "recipient rule", "approval evidence" ] }, { "id": "accounts-q3", "kind": "lifecycle", "text": "How does a corrected account relate to earlier versions without silently replacing acknowledged content?", "answer_data": [ "record identity", "revision", "supersedes reference", "correction reason", "affected acknowledgements" ] } ], "data_elements": [ { "id": "accounts-data-account-versions", "name": "account-versions", "description": "Record identity, immutable version key, source attribution, perspective class and lawful supersession links.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "accounts-artifact", "name": "Perspective account manifest", "description": "Optional review artifact for private and shared accounts; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "outcomes", "name": "Acknowledgement and consequences", "description": "Encounter-specific questions about acknowledgement and consequences.", "rationale": "Separate this concern to preserve interaction evidence without taking ownership of referenced systems.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-008" ], "layers": [ { "id": "acknowledgement", "name": "Acknowledgement scope", "description": "Acknowledge exact record versions and scope per party. Silence, attendance, a digest or technical signature validity does not establish shared agreement; unsigned or disputed encounters remain representable.", "source_refs": [ "SRC-006", "SRC-002", "SRC-008" ], "findings": [ { "id": "attestations", "name": "Scoped acknowledgement evidence", "description": "Acknowledge exact record versions and scope per party. Silence, attendance, a digest or technical signature validity does not establish shared agreement; unsigned or disputed encounters remain representable.", "source_refs": [ "SRC-006", "SRC-002", "SRC-008" ], "questions": [ { "id": "attestations-q1", "kind": "evidence", "text": "What exact revision and content scope did each party acknowledge, reject or leave unanswered?", "answer_data": [ "party role", "record revision", "scope", "stance", "evidence" ] }, { "id": "attestations-q2", "kind": "validation", "text": "What signature or acknowledgement validation result is available, and what trust or authority questions remain unresolved?", "answer_data": [ "method", "verifier report", "signed payload reference", "trust limitation", "mandate assessment" ] }, { "id": "attestations-q3", "kind": "exception", "text": "How are partial agreement, withdrawal, coercion concerns and later corrections recorded without rewriting prior assertions?", "answer_data": [ "qualification", "dispute reference", "withdrawal assertion", "supersession", "review role" ] } ], "data_elements": [ { "id": "attestations-data-attestation-entries", "name": "attestation-entries", "description": "Per-party, per-version and per-scope stance with method and evidence; independent legal effect remains external.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-002", "SRC-008" ] } ], "artifacts": [ { "id": "attestations-artifact", "name": "Acknowledgement matrix", "description": "Optional review artifact for scoped acknowledgement evidence; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-006", "SRC-002", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "follow-up", "name": "Consequences and continuation", "description": "Distinguish observed, proposed, agreed and disputed results, including no agreement. Link subsequent encounters and obligations to their masters without executing actions or determining legal or clinical effects.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ], "findings": [ { "id": "results", "name": "Outcomes and follow-up references", "description": "Distinguish observed, proposed, agreed and disputed results, including no agreement. Link subsequent encounters and obligations to their masters without executing actions or determining legal or clinical effects.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ], "questions": [ { "id": "results-q1", "kind": "decision", "text": "Which result was observed or proposed, who supports it, and which qualifications or disagreements remain?", "answer_data": [ "result type", "asserting role", "supporting parties", "qualifiers", "dispute" ] }, { "id": "results-q2", "kind": "relationship", "text": "Which external task, commitment, transaction or clinical record carries any resulting obligation or observation?", "answer_data": [ "target master reference", "relation", "responsible role", "authority evidence" ] }, { "id": "results-q3", "kind": "composition", "text": "Which later encounter continues this one, and how is continuation distinguished from a child segment or recurring schedule?", "answer_data": [ "next encounter", "link kind", "basis", "parent or series distinction" ] } ], "data_elements": [ { "id": "results-data-result-assertions", "name": "result-assertions", "description": "Outcome claims with attribution and support; no mandatory agreed outcome.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "results-data-follow-up-links", "name": "follow-up-links", "description": "Typed references to external masters; referential validation cannot establish completion.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "results-artifact", "name": "Outcome and continuation register", "description": "Optional review artifact for outcomes and follow-up references; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "governance", "name": "Disclosure and record continuity", "description": "Encounter-specific questions about disclosure and record continuity.", "rationale": "Separate this concern to preserve interaction evidence without taking ownership of referenced systems.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ], "layers": [ { "id": "disclosure", "name": "Authorized views", "description": "Assess collection, recording, transcription and disclosure separately under an adopting legal and purpose profile. Universal consent of all named parties is not assumed; absent or conflicting authority blocks local release.", "source_refs": [ "SRC-007", "SRC-008" ], "findings": [ { "id": "views", "name": "Recording and disclosure authority", "description": "Assess collection, recording, transcription and disclosure separately under an adopting legal and purpose profile. Universal consent of all named parties is not assumed; absent or conflicting authority blocks local release.", "source_refs": [ "SRC-007", "SRC-008" ], "questions": [ { "id": "views-q1", "kind": "authority", "text": "Which applicable rule and approved purpose authorize this specific recording, transcription or disclosure?", "answer_data": [ "operation", "purpose", "legal or policy basis", "jurisdiction", "decision reference" ] }, { "id": "views-q2", "kind": "privacy", "text": "Whose data and sensitive inferences occur in the proposed view, including nonparticipants mentioned in the record?", "answer_data": [ "affected data categories", "third-party impact", "minimisation", "protection requirements" ] }, { "id": "views-q3", "kind": "access", "text": "What evidence authorizes the recipient and exact scope, and when must the proposed release be refused or escalated?", "answer_data": [ "recipient", "permitted scope", "conditions", "expiry", "refusal or referral" ] } ], "data_elements": [ { "id": "views-data-view-authority", "name": "view-authority", "description": "Operation-specific recipient and purpose assessment with external approval reference; not a consent or policy engine.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "views-artifact", "name": "Disclosure assessment", "description": "Optional review artifact for recording and disclosure authority; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "disposition", "name": "Retention and correction", "description": "Different accounts and recordings may have different retention rules. Referenced disposition authorities control execution; local correction history must not justify indefinite retention of personal content.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ], "findings": [ { "id": "continuity", "name": "Correction and disposition obligations", "description": "Different accounts and recordings may have different retention rules. Referenced disposition authorities control execution; local correction history must not justify indefinite retention of personal content.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ], "questions": [ { "id": "continuity-q1", "kind": "retention", "text": "Which retention rule, trigger, hold and disposition authority apply to each account and retained copy?", "answer_data": [ "artifact revision", "schedule reference", "trigger", "hold scope", "authority" ] }, { "id": "continuity-q2", "kind": "lifecycle", "text": "How can a party dispute or correct its account while preserving other parties assertions and signed-version meaning?", "answer_data": [ "correction request", "affected scope", "review decision", "supersession reference" ] }, { "id": "continuity-q3", "kind": "constraint", "text": "What minimal lawful evidence can remain after payload erasure, and which remote copies cannot be claimed deleted?", "answer_data": [ "minimal tombstone", "erasure evidence", "remaining copies", "lawful basis", "verification limit" ] } ], "data_elements": [ { "id": "continuity-data-disposition-references", "name": "disposition-references", "description": "Per-artifact schedules, holds and disposal evidence references; no deletion of remote masters.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] }, { "id": "continuity-data-correction-records", "name": "correction-records", "description": "Scoped corrections and review outcomes governed by retention policy.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "continuity-artifact", "name": "Record continuity assessment", "description": "Optional review artifact for correction and disposition obligations; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "assurance", "name": "Evidence and interoperability", "description": "Encounter-specific questions about evidence and interoperability.", "rationale": "Separate this concern to preserve interaction evidence without taking ownership of referenced systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006" ], "layers": [ { "id": "evidence-quality", "name": "Assertion quality", "description": "Record support and limitations for each encounter assertion. Presence logs, transcripts and party recollections can conflict; attribution and integrity do not decide which account is true.", "source_refs": [ "SRC-002", "SRC-006" ], "findings": [ { "id": "quality", "name": "Conflicting evidence and recognition", "description": "Record support and limitations for each encounter assertion. Presence logs, transcripts and party recollections can conflict; attribution and integrity do not decide which account is true.", "source_refs": [ "SRC-002", "SRC-006" ], "questions": [ { "id": "quality-q1", "kind": "provenance", "text": "Which evidence supports or contradicts each material encounter assertion and who supplied it?", "answer_data": [ "assertion ID", "supporting reference", "contrary reference", "source role" ] }, { "id": "quality-q2", "kind": "quality", "text": "What limits arise from missing segments, transcript errors, interpretation or inferred participation?", "answer_data": [ "limitation kind", "affected scope", "confidence qualifier", "review status" ] }, { "id": "quality-q3", "kind": "validation", "text": "Which discrepancies need an authorized reviewer instead of automatic account merging?", "answer_data": [ "conflict class", "review role", "merge refusal", "resolution reference" ] } ], "data_elements": [ { "id": "quality-data-assertion-evidence", "name": "assertion-evidence", "description": "Support and contrary evidence with attribution, transformation and uncertainty; truth resolution is delegated.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] } ], "artifacts": [ { "id": "quality-artifact", "name": "Evidence qualification report", "description": "Optional review artifact for conflicting evidence and recognition; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-002", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "mapping", "name": "Profile bindings", "description": "Map only declared encounter facets to pinned external schemas. The general model is not identical to a clinical Encounter, a calendar event or a generic Activity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-002" ], "findings": [ { "id": "interoperability", "name": "Profile mapping and loss", "description": "Map only declared encounter facets to pinned external schemas. The general model is not identical to a clinical Encounter, a calendar event or a generic Activity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-002" ], "questions": [ { "id": "interoperability-q1", "kind": "interoperability", "text": "Which source and target versions map identity, state, parties, bounds and acknowledgement scope without loss?", "answer_data": [ "binding version", "field mapping", "code mapping", "unmapped fields" ] }, { "id": "interoperability-q2", "kind": "constraint", "text": "Which mandatory target fields or unsupported semantics require refusal, a qualified extension or a specialist profile?", "answer_data": [ "target constraint", "loss reason", "extension namespace", "decision" ] }, { "id": "interoperability-q3", "kind": "validation", "text": "Which fixtures establish that no-show, partial participation, disputed records and clinical references survive the mapping?", "answer_data": [ "fixture references", "expected invariants", "test results", "remaining gaps" ] } ], "data_elements": [ { "id": "interoperability-data-profile-binding", "name": "profile-binding", "description": "Pinned mapping proposal, target scope, loss report and test evidence; no conformance assertion without fixtures.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-002" ] } ], "artifacts": [ { "id": "interoperability-artifact", "name": "Mapping loss report", "description": "Optional review artifact for profile mapping and loss; instantiate only when evidence and policy justify it. Not every encounter must have this document.", "media_or_form": [ "structured record", "human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system record identifier and revision first; otherwise governed URI or local opaque UUID. Encounter binding and version are explicit; dates and party names are not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "bind-encounter", "name": "Bind encounter evidence", "description": "Proposed local operation, not implemented. Prepare an encounter-specific projection linked to the authoritative occurrence master.", "inputs": [ "master occurrence reference", "profile", "engagement evidence", "party-local aliases" ], "outputs": [ "binding assessment or refusal" ], "preconditions": [ "Verified actor role, purpose and scope for every referenced record", "Evidence and profile supplied; unknown authority or unresolved identity prevents assertions that depend on them", "Mutation requires expected revision and idempotency key; conflict or stale revision causes refusal" ], "effects": [ "Creates only a local binding assessment; never creates a historical event by inference." ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "record-participation", "name": "Record participation assertion", "description": "Proposed local operation, not implemented. Append a role-scoped participation account without upgrading invitation to attendance.", "inputs": [ "party role", "source account", "interval", "mandate reference" ], "outputs": [ "participation revision or conflict referral" ], "preconditions": [ "Verified actor role, purpose and scope for every referenced record", "Evidence and profile supplied; unknown authority or unresolved identity prevents assertions that depend on them", "Mutation requires expected revision and idempotency key; conflict or stale revision causes refusal" ], "effects": [ "Appends attributable participation evidence; does not invite, admit or impersonate a party." ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "index-exchange", "name": "Index an exchange", "description": "Proposed local operation, not implemented. Link an already evidenced exchange to its item master and permitted audience.", "inputs": [ "item master reference", "sender role", "recipient scope", "delivery evidence" ], "outputs": [ "exchange index entry or refusal" ], "preconditions": [ "Verified actor role, purpose and scope for every referenced record", "Evidence and profile supplied; unknown authority or unresolved identity prevents assertions that depend on them", "Mutation requires expected revision and idempotency key; conflict or stale revision causes refusal" ], "effects": [ "Records a local reference only; sends no message, transfers no goods and establishes no settlement." ], "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "record-acknowledgement", "name": "Record scoped acknowledgement", "description": "Proposed local operation, not implemented. Record an existing party assertion against exact content and version, preserving disagreement.", "inputs": [ "record revision", "party mandate", "scope", "stance", "verification evidence" ], "outputs": [ "attestation entry or unresolved verification" ], "preconditions": [ "Verified actor role, purpose and scope for every referenced record", "Evidence and profile supplied; unknown authority or unresolved identity prevents assertions that depend on them", "Mutation requires expected revision and idempotency key; conflict or stale revision causes refusal" ], "effects": [ "Appends evidence; neither signs for a party nor converts technical validation into legal agreement." ], "source_refs": [ "SRC-002", "SRC-006", "SRC-008" ] }, { "id": "link-result", "name": "Link result and continuation", "description": "Proposed local operation, not implemented. Record a qualified outcome and references to external follow-up masters.", "inputs": [ "attributed result", "supporting parties", "target master", "relation meaning" ], "outputs": [ "result register revision or referral" ], "preconditions": [ "Verified actor role, purpose and scope for every referenced record", "Evidence and profile supplied; unknown authority or unresolved identity prevents assertions that depend on them", "Mutation requires expected revision and idempotency key; conflict or stale revision causes refusal" ], "effects": [ "No obligation, clinical diagnosis or external task is created, accepted or completed by this operation." ], "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "prepare-view", "name": "Prepare an authorized local view", "description": "Proposed local operation, not implemented. Construct a minimal local review view from externally approved purpose and recipient scopes.", "inputs": [ "recipient authorization", "purpose", "approved scope", "artifact revisions", "policy decision" ], "outputs": [ "redacted local view with omissions or refusal" ], "preconditions": [ "Verified actor role, purpose and scope for every referenced record", "Evidence and profile supplied; unknown authority or unresolved identity prevents assertions that depend on them", "Mutation requires expected revision and idempotency key; conflict or stale revision causes refusal" ], "effects": [ "Produces a local candidate only; transmission, recording and disclosure execution require their own authority." ], "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "assess-mapping", "name": "Assess profile mapping", "description": "Proposed local operation, not implemented. Compare declared encounter facets with a pinned target contract and record loss.", "inputs": [ "source profile", "target version", "mapping proposal", "fixture results" ], "outputs": [ "mapping loss report and unresolved constraints" ], "preconditions": [ "Verified actor role, purpose and scope for every referenced record", "Evidence and profile supplied; unknown authority or unresolved identity prevents assertions that depend on them", "Mutation requires expected revision and idempotency key; conflict or stale revision causes refusal" ], "effects": [ "Records assessment; no target write or conformance certification occurs." ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "composition": [ { "target": "WM-ACT-015", "relation": "EXTEND", "purpose": "Conceptual specialization of occurrence through engagement, party perspectives and scoped acknowledgement. Generic identity, event history, authority and conflict machinery stay in the occurrence master; runtime binding must be pinned.", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "target": "WM-ACT-014", "relation": "REFERENCE", "purpose": "Optional clinical context for the incoming care-delivery containment candidate; no generic requirement that every encounter belongs to care delivery.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "WM-ACT-046", "relation": "REFERENCE", "purpose": "Optional clinical observation or diagnosis reference. Candidate CONTAINS is qualified as a profile association; no mandatory child and no locally owned diagnosis lifecycle.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "RFC 5545", "relation": "ALIGN", "purpose": "Calendar plan, attendee and recurrence references only; not evidence of actual engagement.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "PROV-O 2013-04-30", "relation": "ALIGN", "purpose": "Attribution and derivation vocabulary alignment; no evidence truth or authority inference.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "FHIR R5 5.0.0 Encounter", "relation": "ALIGN", "purpose": "Selected clinical profile comparison only; no universal FHIR resource equivalence or implemented mapping.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "Activity Vocabulary 2017-05-23", "relation": "ALIGN", "purpose": "Exchange and continuity vocabulary alignment; generic activities do not establish encounter engagement.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "XML Signature 1.1", "relation": "ALIGN", "purpose": "Signed-scope and verification-evidence alignment only; signature execution and legal effect are external.", "required": false, "source_refs": [ "SRC-006" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Accountable record custodian and participating-party roles with scope-specific authority evidence", "Interaction profile defining engagement, segment granularity, unknown handling and occurrence-master binding", "Jurisdiction and sector profile, recipient policy, retention schedule and escalation roles" ], "namespace_guidance": "Use the occurrence master namespace and a governed encounter facet namespace. Party-local aliases remain attributed and provisional until reconciled; no names or dates as sole identity.", "registry_links": [ "vr.wm-act-018", "WM-ACT-015 conceptual extension; runtime binding pending", "WM-ACT-014 and WM-ACT-046 conditional clinical references" ] }, "canon_and_patch": { "canonicalization_rules": [ "Never collapse intended participation, observed engagement, record acknowledgement and legally effective agreement.", "Preserve distinct party accounts and source values; do not merge encounters solely because the parties and times match." ], "patch_rules": [ "Require expected revision, actor, purpose, evidence and idempotency key for local mutation.", "Acknowledged content is not silently overwritten. Link new revisions, scope corrections and maintain only the history lawful under retention rules." ], "compatibility_rules": [ "Pin profile, occurrence binding and mapping versions; report information loss before export.", "Refuse a mapping that discards disagreement, signed scope, temporal precision or recipient restrictions." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with namespace and revision", "Governed global identifier or stable record URI", "Local opaque UUID or ULID with reconciliation state" ], "timestamp_rule": "Recording instants use RFC 3339 with seconds and an explicit offset or Z. Distinguish event time, participation time, acknowledgement time and observation or ingestion time. Preserve date-only evidence, source timezone, precision and uncertainty without invented midnight values.", "serial_naming_rule": "Use opaque encounter binding, artifact type and immutable sequence or revision; no party names or private endpoint details in filenames.", "integrity_rule": "Preserve content digest, algorithm, exact signed scope and transformation provenance when available. A digest or valid signature does not prove truth, informed agreement, authority or legal effect." }, "policies": [ "Reviewable draft under the single-provider waiver; local self-audit is not independent external review.", "Profile decisions about engagement and boundaries are local design proposals, not universal normative requirements.", "Recording, transcription, disclosure, binding outcomes and automated representation each require applicable authority. Do not assume all-party consent is either always necessary or always sufficient.", "Contact metadata and aggregate interaction graphs can remain sensitive; no automatic anonymisation or unrestricted publication claim.", "Dangerous encounters remain at policy level; the model provides no operational instructions for weapons, detention or controlled items." ], "crud": { "read": [ "Return only the authorized perspective and scope with provenance, disputes and unknowns visible." ], "create": [ "Create a local record only with occurrence binding, declared engagement profile and accountable custodian. Planned and unresolved records must not assert occurrence." ], "update": [ "Append attributable local corrections against expected revision; route generic event changes and external record changes to their masters." ], "delete": [ "The adopting retention and disposition authority owns execution. Observe applicable schedules, scoped holds, correction and erasure duties; no perpetual personal-data history.", "Where lawful, retain a minimal non-identifying tombstone and disposal evidence reference. Local deletion does not erase a counterparty copy, external master or historical event." ] }, "roles": [ { "name": "Encounter record custodian", "responsibilities": [ "Maintain binding, profile and scoped record continuity" ] }, { "name": "Party or authorized representative", "responsibilities": [ "Supply and qualify only assertions within the evidenced mandate" ] }, { "name": "Evidence reviewer", "responsibilities": [ "Examine contradictory reports, identity matches and acknowledgement scope" ] }, { "name": "Privacy and records officer", "responsibilities": [ "Approve recipient views, retention and disposition policy references" ] }, { "name": "Profile maintainer", "responsibilities": [ "Pin schema mappings and record conformance limits" ] } ], "access": { "default_rule": "Deny access unless actor, purpose, recipient and exact perspective scope are authorized; participation alone grants no right to all private accounts.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Any emergency, mandatory disclosure or special-category processing exception needs an explicit applicable basis, minimal scope and accountable review; no blanket bypass." ], "audit_requirements": [ "Reference access, export, correction and disposal evidence with actor, purpose, scope, revision and result under a minimal-data retention policy. The audit master owns execution and retention of its records." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md and custodian authority/access policies", "spec.yaml with research holds", "Pinned occurrence and interaction profile, source records and permitted perspective" ] } }, "coverage": { "claim": "Source-grounded proposed structure for a bounded encounter event and its separately governed accounts. Local no-tools self-audit completed. Clinical and privacy sources are scoped examples, not universal definitions. Independent review, source verification, specialist profiles and executable conformance remain holds; this is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Occurrence binding, party-local aliases and conservative reconciliation." }, { "dimension": "lifecycle", "status": "covered", "notes": "Encounter progress assertions separate planned, actual, disputed and corrected records; generic machinery delegated." }, { "dimension": "relationships", "status": "covered", "notes": "Party roles, optional clinical masters and typed follow-up links." }, { "dimension": "temporal", "status": "covered", "notes": "Planned and actual bounds, participation intervals, duration method and uncertainty." }, { "dimension": "provenance", "status": "covered", "notes": "Attributed assertions, sources, transformations and contrary evidence." }, { "dimension": "ownership", "status": "covered", "notes": "Role-based custodianship with separately governed perspectives; property rights not inferred." }, { "dimension": "validation", "status": "gap", "notes": "Research validation available; executable instance schemas and profile fixtures remain pending." }, { "dimension": "access", "status": "covered", "notes": "Perspective and recipient-specific views with separate operation authority." }, { "dimension": "retention and deletion", "status": "covered", "notes": "External disposition authority, scoped holds and lawful minimal evidence." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual mappings and loss questions only; no certification." }, { "dimension": "direct properties", "status": "covered", "notes": "Kind, mode, progress and bounds are nonphysical properties; mass and dimensions are not applicable to this event." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Engagement criterion and evidence separate plans, attempts, co-presence and actual interaction." }, { "dimension": "capabilities and hazards", "status": "covered", "notes": "Seven proposed local functions with refusal conditions; false agreement, identity collapse and unauthorized disclosure are explicit risks." }, { "dimension": "context and evidence", "status": "covered", "notes": "Channel, language, clinical context and regional rules remain qualified." } ], "known_omissions": [ "Independent second-provider review remains absent.", "Direct HTTP and response hashes are unmeasured under the owner-reported sandbox restriction; coordinator verification is pending.", "Executable nested schemas, event bindings, mapping fixtures, target versions and conformance testing remain incomplete.", "Sector and jurisdiction rules for recording, representation, signatures, sensitive data, retention and compelled disclosure need qualified review.", "Nonclinical trade, mediated group interaction, cross-border interpretation and asynchronous segment boundaries need additional profile evidence." ], "conflicts": [], "regional_assumptions": [ "EDPB guidance concerns EU/EEA data protection; it does not settle national recording or signature law or worldwide privacy duties.", "FHIR R5 is a selected clinical schema example, not a current-release or universal encounter claim." ], "adversarial_checks": [ "Reject a scheduled acceptance or mere co-presence as proof that reciprocal engagement occurred.", "Reject mandatory clinical observations, mutual records and agreed outcomes for every encounter.", "Reject the universal all-party-consent rule and automatic authority from participation.", "Reject deriving truth, contract formation or unlimited disclosure from signature validity.", "Reject loss of disagreements and private-view restrictions during mapping." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "event", "status": "accepted", "rationale": "The root denotes bounded engagement among distinct parties, while records can exist before, after or without proven occurrence. The registry standalone-mm value is a record-plane classification. Generic occurrence machinery, parties, schedules, messages, transactions and clinical records retain their own masters." }, "decisions": [ { "concept": "Encounter event versus record", "disposition": "accepted", "rationale": "The model preserves event identity without confusing a planned, attempted, disputed or persistent record with proof that interaction occurred." }, { "concept": "Distinct party engagement", "disposition": "qualified", "rationale": "The two-party criterion is explicit local design. Two roles of one party do not establish two parties, and incomplete identities remain provisional without requiring mutual assent." }, { "concept": "Occurrence extension", "disposition": "accepted conceptually", "rationale": "WM-ACT-015 retains generic identity and lifecycle machinery. Local findings and functions bind only encounter-specific evidence; pinned executable inheritance is deferred." }, { "concept": "Clinical containment candidates", "disposition": "narrowed", "rationale": "Incoming WM-ACT-014 containment is conditional on clinical context. Outgoing WM-ACT-046 containment becomes optional references and cannot require clinical observations or diagnoses in every encounter." }, { "concept": "Channels and temporal granularity", "disposition": "qualified", "rationale": "Hybrid and intermittent participation and separate planned, actual and recorded times are supported; adopted segment rules and duration methods prevent automatic billing or attention inferences." }, { "concept": "Representation and stewardship", "disposition": "separated", "rationale": "Party involvement, mandate, record custodianship and recipient authority remain distinct. No blanket property or disclosure right follows from participation." }, { "concept": "Exchange and outcome effect", "disposition": "separated", "rationale": "Dispatch, receipt, understanding, agreement, obligation and settlement are not collapsed. Outcomes are optional, attributed and may remain disputed; external masters own operative effects." }, { "concept": "Mutual records and signatures", "disposition": "legacy restrictions rejected", "rationale": "An encounter need not have a countersigned record or agreed outcome. Multiple scoped account revisions and party acknowledgements preserve exact content without inferring legal agreement from technical validity." }, { "concept": "Consent and disclosure", "disposition": "profile qualified", "rationale": "The legacy universal all-party-consent rule is unsupported. Separate operation, purpose, recipient and applicable-authority assessments preserve regional and sensitive-data limits." }, { "concept": "Retention and correction", "disposition": "accepted with external authority", "rationale": "Local revision history is subject to lawful retention and erasure. Disposition execution and remote copies remain external; minimal tombstones cannot justify indefinite personal-data retention." }, { "concept": "Proposed functions and candidate artifacts", "disposition": "accepted as design only", "rationale": "All seven operations are unimplemented local record functions with authority, evidence, revision and refusal conditions. Fourteen artifact designs are optional forms, not mandatory per-instance documents." }, { "concept": "Source and mapping assurance", "disposition": "limited and deferred", "rationale": "Eight sources support selected conceptual claims, but web text access is not direct HTTP measurement or latest-version verification. Nested schemas, pinned bindings and adversarial mapping fixtures remain incomplete." }, { "concept": "Provider independence", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the owner override. This distinct no-tools phase is a Codex self-audit and cannot establish independent provider agreement." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate Codex no-tools self-audit is not a second-provider review.", "Source and version verification remains incomplete. Selected official sections were reviewed through the web reader, but direct HTTP checks were not attempted under the owner-reported sandbox restriction: no status or response-body hash was measured. The coordinator must run check_sources.py and review versions, updates, errata and licensing; HTTP success alone is not claim verification.", "Qualified jurisdiction and sector review is required for interaction granularity, representation, recording, transcription, signatures, sensitive data, disclosure and retention. Clinical and EU/EEA privacy examples do not establish universal requirements or current applicable law.", "Executable nested instance schemas, pinned occurrence and neighbor bindings, external mappings, signature verification integration and adversarial conformance fixtures remain incomplete. No operational, clinical or legal-compliance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore independent external review and complete claim, version, update, licensing and source-response verification before canonical promotion.", "Develop jurisdiction and sector profiles for disputed, mediated, automated, asynchronous and clinical encounters while preserving separate authority and evidence ownership.", "Build nested schemas and mapping fixtures for duplicate-party roles, no-show, hybrid participation, conflicting closure, partial acknowledgements, corrected signed content, scoped erasure and unmappable target constraints." ] }, "statistics": { "sources": 8, "bundles": 7, "layers": 14, "findings": 14, "questions": 42, "artifacts": 14, "functions": 7 } }