← Back to catalogue
Published

Incident / Emergency

vr.wm-act-019 · wm-act-019-incident-emergency

Represent one authority-declared operational or emergency incident with revisioned severity, impact, containment, restoration, resolution and review assertions.

World Models Activities and processes ACT.INC

Bundle → Layer → Finding → Questions Filled

7 bundles · 14 layers · 14 findings · 42 questions

Identity and declaration Identify the declared incident and qualify its class and basis.

Incident identity

Bind identity to its accountable namespace. Similar location or timing is insufficient for merging incidents.

Stable qualified record

Bind identity to its accountable namespace. Similar location or timing is insufficient for merging incidents.

  1. Which master namespace and incident identifier distinguish this record from reports and other incidents? identity
  2. Which correlated, duplicate, split or merged incident records exist, and who approved each link? relationship
  3. Which declaration and source revisions establish the identity being reviewed? provenance

Declaration and classification

Record the responsible declaration and profile-specific qualification. Actual, exercise, test, suspected and retracted assertions must not be conflated. Emergency and disaster are not universal severity grades.

Evidenced qualification

Record the responsible declaration and profile-specific qualification. Actual, exercise, test, suspected and retracted assertions must not be conflated. Emergency and disaster are not universal severity grades.

  1. Which competent role declared this incident, under which policy or jurisdiction and effective interval? authority
  2. Which incident class and emergency designation apply, and which assertions remain unconfirmed or exercise-only? classification
  3. What evidence supports rejection or retraction of the declaration without erasing the original report? exception
Evidence and extent Describe what supports the incident and where and when effects apply.

Reports and evidence

Link occurrence and observation masters; distinguish claims, observations, estimates and disputed information. A digest preserves integrity, not truth.

Attributed evidence links

Link occurrence and observation masters; distinguish claims, observations, estimates and disputed information. A digest preserves integrity, not truth.

  1. Which reports and occurrence or observation records support each incident assertion? evidence
  2. Which reports are stale, contradictory or unverified, and what assessment remains pending? quality
  3. Which evidence payloads require a restricted view or an external protected reference? privacy

Time and affected extent

Keep origin, affected footprint and warning area distinct. Unknown onset, intervals and changing extent are valid; nonspatial service impact does not require invented coordinates.

Qualified extent snapshot

Keep origin, affected footprint and warning area distinct. Unknown onset, intervals and changing extent are valid; nonspatial service impact does not require invented coordinates.

  1. What onset interval, report time, declaration time and observation time are supported, with what precision? temporal
  2. Which affected areas or nonspatial service boundaries apply to this assessment revision? spatial
  3. What location uncertainty or disclosure restriction limits the use of this extent? constraint
Severity and impact Preserve distinct graded judgements and attributed consequences.

Severity and priority

Retain scheme and assessor with each grade. Severity, urgency, certainty and resource priority are different assessments; no universal numeric scale is imposed.

Revisioned grading

Retain scheme and assessor with each grade. Severity, urgency, certainty and resource priority are different assessments; no universal numeric scale is imposed.

  1. Which scale, grade and assessor support the current severity assessment? measurement
  2. How does the recorded response priority differ from severity, urgency and confidence? decision
  3. Which reassessment changed the grade or priority, and which earlier value does it supersede? lifecycle

Impact and attribution

Represent attributable effects on people, environment, assets and services through references and assessments. Preserve estimates, uncertainty and counting basis; absence of a report is not zero impact.

Evidence-qualified consequences

Represent attributable effects on people, environment, assets and services through references and assessments. Preserve estimates, uncertainty and counting basis; absence of a report is not zero impact.

  1. Which affected entities or services are linked to this incident, with what attribution basis? composition
  2. What quantity, unit, measurement reference and uncertainty support each impact estimate? measurement
  3. How are overlapping reports, revised totals and unknown impact distinguished from zero harm? validation
Authority and objectives Maintain accountable responsibility and references to response work.

Responsibility and handover

Maintain incident-specific responsibility and handover evidence. Joint coordination does not eliminate each participant mandate; possession of an incident record grants no command authority.

Effective responsibility record

Maintain incident-specific responsibility and handover evidence. Joint coordination does not eliminate each participant mandate; possession of an incident record grants no command authority.

  1. Which accountable incident custodian and responsible authority apply to the current scope? ownership
  2. How are joint responsibilities, limits and unresolved authority conflicts recorded? authority
  3. Which accepted handover changed responsibility, and when did it take effect? event

Objectives and response links

Record incident objectives and references to authorized plans and tasks. Task state may inform an incident assessment but does not execute response or prove objectives achieved.

Bounded response context

Record incident objectives and references to authorized plans and tasks. Task state may inform an incident assessment but does not execute response or prove objectives achieved.

  1. Which authorized incident objectives and acceptance criteria apply for this operational period? requirement
  2. Which response process and task masters support each objective? relationship
  3. Which recorded resource limitations or policy constraints block an objective or require escalation? constraint
Communication and progress Link warning evidence and assess scoped containment and restoration.

Warning and communication references

Retain only incident links to separately mastered warnings and communication interactions. CAP incident references differ from message identifiers, and restricted messages are not public feed entries.

Qualified communication context

Retain only incident links to separately mastered warnings and communication interactions. CAP incident references differ from message identifiers, and restricted messages are not public feed entries.

  1. Which warning or communication records refer to this incident and which audiences are authorized? relationship
  2. Which externally evidenced update, cancellation or expiry applies to each warning reference? state
  3. What mapping preserves message identity, incident links, distribution scope and language without asserting delivery? interoperability

Containment and restoration

Represent containment and restoration as separately scoped incident assertions. Partial restoration, renewed impact and overlapping phases are permitted. External task completion alone is not recovery evidence.

Evidence-backed progress assessments

Represent containment and restoration as separately scoped incident assertions. Partial restoration, renewed impact and overlapping phases are permitted. External task completion alone is not recovery evidence.

  1. Which part of the incident is assessed as contained, restored or still affected? state
  2. Which external observations and acceptance records support a restoration claim? evidence
  3. What renewed impact or conflicting evidence requires reassessment without overwriting the earlier transition? exception
Resolution and learning Track closure revisions, residual obligations and review conclusions.

Resolution and reopening

Record authorized closure or reopening decisions by revision. Closure need not mean zero harm, complete remediation or finished review. A retracted declaration is distinct from a resolved real incident.

Qualified closure decisions

Record authorized closure or reopening decisions by revision. Closure need not mean zero harm, complete remediation or finished review. A retracted declaration is distinct from a resolved real incident.

  1. Which evidence and responsible decision support the claimed incident resolution? decision
  2. Which closure, retraction or reopening revision is current, and what triggered that change? lifecycle
  3. Which residual risks and outstanding obligations have an acknowledged owner after closure? requirement

Learning and follow-up

Keep incident-specific review findings, limitations and recommendations. Action execution and persistent cause analysis remain external; a completed review is not evidence that every action succeeded.

Review conclusions and action references

Keep incident-specific review findings, limitations and recommendations. Action execution and persistent cause analysis remain external; a completed review is not evidence that every action succeeded.

  1. Which review examined this incident and what scope, participants and evidence did it use? process
  2. Which review conclusions are supported, disputed or limited by missing evidence? quality
  3. Which improvement task or problem records address each recommendation, with what completion evidence? relationship
Stewardship and acceptance Control record continuity and expose profile and exchange limitations.

Record stewardship

Apply adopting-Dimension policies to incident-local records. Preserve traceable correction without mandating indefinite personal-data retention; disposition does not close the real incident or delete target masters.

Controlled continuity and disposition

Apply adopting-Dimension policies to incident-local records. Preserve traceable correction without mandating indefinite personal-data retention; disposition does not close the real incident or delete target masters.

  1. Which recipient and purpose authorize access to each incident view or artifact? access
  2. Which retention schedule, preservation hold and approved disposition apply to local incident payloads? retention
  3. What minimal evidence records corrections, redactions or disposal while avoiding retained sensitive payloads? provenance

Exchange and acceptance

Treat standards as conceptual alignments. Local schema validity cannot certify emergency readiness, statutory compliance, message delivery or executable conformance.

Profile and conformance limits

Treat standards as conceptual alignments. Local schema validity cannot certify emergency readiness, statutory compliance, message delivery or executable conformance.

  1. Which pinned target profile and neighbor bindings can represent this incident without losing qualifiers? interoperability
  2. Which acceptance fixtures test conflicting reports, partial restoration, reopening and restricted warnings? validation
  3. Which publication or operational use must be refused because review, authority or disclosure evidence is missing? security

Classifiers Filled

Family
World Models
Category
Activities and processes
Entry kind
entity
Navigation path
NAV.ACT.INC
Domain
ACT.INC
Industry
Cross-industry
Tags
incidentemergencyact.inc
Also called
X3

What it is Filled

A persistent incident record rooted in an evidenced declaration by a competent operator or authority. Reports can be linked while qualification is pending; a pending report is not silently promoted to a declared incident. A declaration may later be retracted. The record persists through reassessment, handover, partial recovery, closure and reopening.

In scope

  • Qualified incident identity, declaration basis, classification and ownership
  • Revisioned severity, impact, extent, evidence and incident state assessments
  • Incident-specific response objectives, task references, warning references and transition decisions
  • Closure, residual obligations, review findings and controlled record continuity

Out of scope

  • Raw occurrence and measurement masters, persistent problem management and defect remediation
  • Executing response processes or tasks, dispatching resources, issuing warnings or transmitting messages
  • Independent cyber or AI incident qualification, clinical treatment, legal emergency powers and tactical procedures
  • Whole-of-society disaster risk management, hazard prediction and long-term reconstruction programmes
  • Runtime conformance, automated emergency decisions and generic audit or retention execution services

Why it exists Filled

Represent one authority-declared operational or emergency incident with revisioned severity, impact, containment, restoration, resolution and review assertions.

Distinguishing features Derived, awaiting review

  • Unlike WM-ACT-015: Occurrence evidence supports a declaration but keeps its own occurrence identity and lifecycle.
  • Unlike WM-MAT-008: Observation and measurement records remain external masters; local impact assessments reference values, method, uncertainty and time.
  • Unlike WM-KNW-014: Persistent problems and cause claims are referenced, not solved or assigned a new problem lifecycle here.
  • Unlike WM-SFT-014: Software defects may be implicated; incident restoration does not prove defect remediation.
  • Unlike WM-ACT-006: Containment, restoration and remediation tasks retain task execution and assignment ownership; only incident-specific links and assessments are local.
  • Unlike WM-ACT-027: Warning and communication interactions own message content, delivery and cancellation; incident records only reference them.
  • Unlike WM-ACT-020: Cyber incident qualification can correlate with the same emergency but remains independently governed. No forced identity equivalence or cybersecurity workflow inheritance.
  • Unlike WM-AI-010: Incoming AI incident report linkage does not give this model ownership of reporting taxonomy or reporting duties.
  • Unlike WM-ACT-042: Incident response process definitions and execution are external context; this model records incident state and references response evidence only.
  • Unlike Hazard, disaster and sustained situation: An emergency designation is profile-specific; reported harm, threatened harm and slow onset may support an incident declaration. A hazard or long-running situation alone is not automatically an incident record.

Note: Derived from boundary notes against neighbouring models.

What robots and AI may and may not do Derived, awaiting review

Must not

  • Keep reports awaiting qualification in a distinct linked intake state; creation alone cannot establish a real declaration.
  • Deny incident-content access unless recipient, purpose and scope are authorized; possession of a public warning grants no access to the incident file.

May

  • Resolve an incident reference: Proposed local operation, not implemented. Resolve qualified identity conservatively; return ambiguity rather than merge by geography or time.
  • Record an existing declaration: Proposed local operation, not implemented. Record evidence of a competent declaration or retraction; do not declare an emergency or confer legal powers.
  • Record an incident assessment revision: Proposed local operation, not implemented. Attach supported severity, impact, extent or progress assessment with its author and scope; do not calculate hazard forecasts or execute response.
  • Link an external response record: Proposed local operation, not implemented. Bind existing task, warning or response evidence to an incident objective or assertion. Neither dispatch work nor send or cancel a warning.
  • Record closure or reopening evidence: Proposed local operation, not implemented. Record an authorized incident decision, criteria and residual obligations; do not independently resolve the incident or accept risk.
  • Prepare an authorized incident view: Proposed local operation, not implemented. Build a local recipient-scoped projection retaining uncertainty and mapping losses; no transmission and no presumption that aggregate data is anonymous.

Note: Derived from functions, policies, CRUD and access rules; prohibitions were not authored for agents as such.

Moral aspects Derived, awaiting review

  • Correct by supersession; erasure and redaction follow an approved retention or privacy rule with minimal lawful change evidence.
  • Minimize personal data and sensitive infrastructure detail.
  • Local legal powers, reportability, mandatory time limits, privacy and records rules need qualified jurisdiction and sector profiles.
  • An emergency designation is profile-specific; reported harm, threatened harm and slow onset may support an incident declaration.

Note: Sentences mentioning harm, privacy, consent or similar, collected from the specification.

Owners Filled

Steward

Accountable incident custodian and competent operator or authority, with evidenced mandate

Roles

Incident custodian
Maintain identity, reference continuity and permitted local records.
Competent incident authority
Supply evidenced declarations, responsibility decisions and resolution approvals within its mandate.
Authorized assessor
Record scoped assessments with uncertainty and supporting evidence.
Response liaison
Reconcile references and handover evidence without acquiring task execution authority.
Records and access officer
Approve recipient views, exceptions, retention, holds and disposition.
Review facilitator
Document supported lessons, dissent and improvement references.

Links to other meta-models Filled

references

  • WM-ACT-015 - Occurrence evidence supports a declaration but keeps its own occurrence identity and lifecycle. Candidate model binding must be pinned before integration.
  • WM-MAT-008 - Observation and measurement records remain external masters; local impact assessments reference values, method, uncertainty and time. Candidate model binding must be pinned before integration.
  • WM-KNW-014 - Persistent problems and cause claims are referenced, not solved or assigned a new problem lifecycle here. Candidate model binding must be pinned before integration.
  • WM-SFT-014 - Software defects may be implicated; incident restoration does not prove defect remediation. Candidate model binding must be pinned before integration.
  • WM-ACT-006 - Containment, restoration and remediation tasks retain task execution and assignment ownership; only incident-specific links and assessments are local. Candidate model binding must be pinned before integration.
  • WM-ACT-027 - Warning and communication interactions own message content, delivery and cancellation; incident records only reference them. Candidate model binding must be pinned before integration.
  • WM-ACT-020 - Cyber incident qualification can correlate with the same emergency but remains independently governed. No forced identity equivalence or cybersecurity workflow inheritance. Candidate model binding must be pinned before integration.
  • WM-AI-010 - Incoming AI incident report linkage does not give this model ownership of reporting taxonomy or reporting duties. Candidate model binding must be pinned before integration.
  • WM-ACT-042 - Incident response process definitions and execution are external context; this model records incident state and references response evidence only. Candidate model binding must be pinned before integration.

aligned

  • NIMS 2017 - Conceptual incident coordination vocabulary; US applicability requires review.
  • CAP 1.2 - Warning reference mapping only; no message producer or consumer conformance.
  • PROV-O 2013 - Conceptual assertion attribution and revision links, not truth certification.

neighbor

  • WM-ACT-015 - Occurrence evidence supports a declaration but keeps its own occurrence identity and lifecycle.
  • WM-MAT-008 - Observation and measurement records remain external masters; local impact assessments reference values, method, uncertainty and time.
  • WM-KNW-014 - Persistent problems and cause claims are referenced, not solved or assigned a new problem lifecycle here.
  • WM-SFT-014 - Software defects may be implicated; incident restoration does not prove defect remediation.
  • WM-ACT-006 - Containment, restoration and remediation tasks retain task execution and assignment ownership; only incident-specific links and assessments are local.
  • WM-ACT-027 - Warning and communication interactions own message content, delivery and cancellation; incident records only reference them.
  • WM-ACT-020 - Cyber incident qualification can correlate with the same emergency but remains independently governed. No forced identity equivalence or cybersecurity workflow inheritance.
  • WM-AI-010 - Incoming AI incident report linkage does not give this model ownership of reporting taxonomy or reporting duties.
  • WM-ACT-042 - Incident response process definitions and execution are external context; this model records incident state and references response evidence only.
  • Hazard, disaster and sustained situation - An emergency designation is profile-specific; reported harm, threatened harm and slow onset may support an incident declaration. A hazard or long-running situation alone is not automatically an incident record.

What else AI and robots need to interact with it Incomplete

Identity and identifiers required Filled

  • Authoritative master-system identifier with namespace and revision
  • Governed global identifier or stable record URI
  • Local UUID with reconciliation status

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Missing, in the backlog

Not described yet. This gap is in the card backlog.

Capabilities and actions required Filled

  • Resolve an incident reference: Proposed local operation, not implemented. Resolve qualified identity conservatively; return ambiguity rather than merge by geography or time.
  • Record an existing declaration: Proposed local operation, not implemented. Record evidence of a competent declaration or retraction; do not declare an emergency or confer legal powers.
  • Record an incident assessment revision: Proposed local operation, not implemented. Attach supported severity, impact, extent or progress assessment with its author and scope; do not calculate hazard forecasts or execute response.
  • Link an external response record: Proposed local operation, not implemented. Bind existing task, warning or response evidence to an incident objective or assertion. Neither dispatch work nor send or cancel a warning.
  • Record closure or reopening evidence: Proposed local operation, not implemented. Record an authorized incident decision, criteria and residual obligations; do not independently resolve the incident or accept risk.
  • Prepare an authorized incident view: Proposed local operation, not implemented. Build a local recipient-scoped projection retaining uncertainty and mapping losses; no transmission and no presumption that aggregate data is anonymous.

Hazards and failure modes optional Missing, in the backlog

Not described yet. This gap is in the card backlog.

Standards and interfaces required Derived, awaiting review

  • PROV-O: The PROV Ontology
  • RFC 3339: Date and Time on the Internet: Timestamps

Context of use required Filled

  • NIMS is a US framework, WHO sources are public-health institutional examples, and NIST is cybersecurity guidance; none defines universal emergency authority.
  • The model permits prolonged or slow-onset emergencies when an authority declares an incident; the source terminology does not make every hazard or situation an incident.

Sources Filled

  1. National Incident Management System, Third Edition - Federal Emergency Management Agency
  2. Common Alerting Protocol Version 1.2 - OASIS
  3. Sendai Framework terminology: Disaster - United Nations Office for Disaster Risk Reduction
  4. Emergency response framework, Edition 2.1 - World Health Organization
  5. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile - National Institute of Standards and Technology
  6. PROV-O: The PROV Ontology - World Wide Web Consortium
  7. RFC 3339: Date and Time on the Internet: Timestamps - Internet Engineering Task Force
  8. Guidance for after action review (AAR) - World Health Organization

Open questions

  • Verify current primary-source versions, full-text scope, licensing and applicability, then restore independent external review before canonical promotion.
  • Develop jurisdiction and sector profiles with qualified incident authorities, including non-cyber operational incidents, slow onset, contested declarations and responsibility handover.
  • Implement and test nested schemas and mappings against duplicate reports, contradictory impact, partial restoration, reopening, restricted warnings, failed references and lawful disposal.
  • Independent external review remains absent; a local Codex no-tools self-audit is not a second provider.
  • Direct HTTP checks are not attempted under the owner-reported sandbox block. Browser access does not prove current versions, availability, licensing or applicability.
  • Full WHO ERF text was not retrieved; only publication overview claims are admitted. ISO 22320 and EDXL leads from legacy material are not admitted as verified standards evidence.
  • Executable nested instance schemas, CAP mappings, neighbor bindings and adversarial acceptance fixtures are not implemented.
  • Local legal powers, reportability, mandatory time limits, privacy and records rules need qualified jurisdiction and sector profiles.
  • Clinical, hazardous-material, armed-response and other specialist response tactics, mass-casualty operations and long-term reconstruction are outside this policy-level model.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-act-019-incident-emergency/spec.yaml