# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-29T11:03:25Z", "synthesisSha256": "42d7a1ef4b1b7a5dd1ba7c51e5a3495177f90bb8a8e9cee237de3c4b2f0d39ca", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-ACT-024", "registryId": "vr.wm-act-024", "name": "Decision / Approval Activity", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "event", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.DEC" ], "tags": [ "decision", "approval", "activity", "act.dec" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-024-decision-approval-activity/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-024", "model": { "registry_id": "vr.wm-act-024", "model_id": "WM-ACT-024", "name": "Decision / Approval Activity", "entry_kind": "event", "purpose": "Provide the context an agent needs to understand, create, inspect and operate a single decision or approval activity occurrence: the authority under which it was taken, the inputs and criteria actually used, the choice among admissible options, and the outcome with its conditions, validity window and contestation path.", "scope_statement": "Scope is one bounded decision or approval occurrence, in the PROV sense of an activity that occurred over a period and bears assigned responsibility. The model records that a decision was taken, by whom, on what authority, from what inputs, with what result and under what conditions. It does not evaluate policy, enforce outcomes, author rule logic, keep audit trails or execute disposition; those remain with referenced models. Storage and interface (JSON, YAML, Markdown, Git, MCP, MongoDB) are projections of this semantics, not part of it.", "in_scope": [ "Identification of a single decision or approval occurrence and the question it answers", "Authority basis, mandate, delegation chain and competence limits under which the decision was taken", "Participants and their roles, independence requirements and multi-party approval facts", "The input and evidence set actually used, fixed by version, digest or as-of time", "The admissible option set, the chosen option and the rejected alternatives with reasons", "Rationale, dissent and the explanation owed to affected parties", "Outcome value, attached conditions and obligations, effective instant and validity window", "Decision status lifecycle, supersession, revocation, suspension and reauthorization triggers", "Human oversight of automated or assisted decisions, contestation, appeal and override records", "Reference bindings and crosswalks to external decision, provenance and authorization vocabularies" ], "out_of_scope": [ "Runtime policy evaluation, rule combining algorithms, obligation discharge and access enforcement", "Audit-trail record structure, storage, immutability guarantees and log retention execution", "Authoring, versioning and testing of decision logic, rule sets, decision tables and hit policies", "The subject entity's own attributes and lifecycle (application, change, budget, dossier, system)", "Workflow orchestration, routing, queueing and task assignment engines", "Party and agent master data, organisational structure and position registries", "Retention schedule definition and disposition or destruction execution", "Cryptographic signature creation, certificate handling and signature validation", "Risk assessment methodology, scoring scales and control assessment procedures", "Notification transport, messaging infrastructure and publication channels", "Constitutive organisational rules (board composition, standing orders) as normative content" ], "boundary_notes": [ { "neighbor": "WM-ACT-002 Activity (registry parent)", "distinction": "Generic activity identity, temporal bounds, participation and status machinery are defined once in the parent; this model adds only decision-specific authority, option set, choice and outcome and must not restate the generic activity surface.", "source_refs": [ "SRC-003" ] }, { "neighbor": "Authorization policy evaluation service (XACML PDP/PEP)", "distinction": "A reference to an evaluator never grants ownership of evaluation. This model records that a decision exists and by what authority; policy evaluation, combining algorithms, obligation discharge and enforcement stay with the PDP and PEP.", "source_refs": [ "SRC-004" ] }, { "neighbor": "Audit trail / event log model", "distinction": "This model states which decision events must be logged and where the log reference lives; audit-record structure, tamper evidence, immutability and log retention are owned by the audit model.", "source_refs": [ "SRC-006", "SRC-012" ] }, { "neighbor": "Records management and disposition model", "distinction": "Retention class and legal-hold status are asserted here as attributes of the decision record; appraisal, schedule definition and destruction execution belong to the records model or the adopting Dimension's retention policy.", "source_refs": [ "SRC-006", "SRC-011" ] }, { "neighbor": "Decision logic / rule model (DMN decision requirement graph)", "distinction": "Design-time decisions, business knowledge models, decision tables and hit policies are authored and versioned there; this model pins the applied version and records deviations from it.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Subject of the decision", "distinction": "The thing decided about keeps its own model and lifecycle; the decision carries a reference plus decision-specific parameters and must not mirror the subject's attributes.", "source_refs": [ "SRC-001", "SRC-009" ] }, { "neighbor": "Electronic signature and seal model", "distinction": "Signature creation and cryptographic validation are external; what is local is the binding of a signature to this decision and the declared meaning of that signature.", "source_refs": [ "SRC-006" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Decision Model and Notation (DMN)", "organization": "Object Management Group", "url": "https://www.omg.org/spec/DMN/", "version_or_date": "Version 1.5, current formal version listed August 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:12:00Z", "relevance": "Normative vocabulary for decision framing: decisions, input data, knowledge sources, authority requirements, decision services and decision logic." }, { "id": "SRC-002", "title": "DMN 1.5 XML Schema (DMN15.xsd)", "organization": "Object Management Group", "url": "https://www.omg.org/spec/DMN/20230324/DMN15.xsd", "version_or_date": "DMN 1.5 schema, namespace date 2023-03-24", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:16:00Z", "relevance": "Confirms exact element names on tDecision (question, allowedAnswers, informationRequirement, knowledgeRequirement, authorityRequirement, supportedObjective, impactedPerformanceIndicator, decisionMaker, decisionOwner, usingProcess, usingTask) and tAuthorityRequirement/tKnowledgeSource." }, { "id": "SRC-003", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:05:00Z", "relevance": "Activity, Agent, Association (hadRole, hadPlan), Delegation/actedOnBehalfOf, used, wasGeneratedBy, wasInformedBy, startedAtTime/endedAtTime: the responsibility and attribution backbone for a decision occurrence." }, { "id": "SRC-004", "title": "eXtensible Access Control Markup Language (XACML) Version 3.0", "organization": "OASIS", "url": "https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html", "version_or_date": "OASIS Standard, 22 January 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:08:00Z", "relevance": "Authorization decision values (Permit, Deny, Indeterminate, NotApplicable), obligations versus advice, and the PDP/PEP/PAP/PIP separation that fixes the evaluation and enforcement boundary of this model." }, { "id": "SRC-005", "title": "NIST SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/37/r2/final", "version_or_date": "Revision 2, December 2018", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:20:00Z", "relevance": "Worked normative pattern for a formal approval: authorizing official, authorization package, authorization decision document, terms and conditions, authorization termination date, time- and event-driven review, and the decision types including denial." }, { "id": "SRC-006", "title": "21 CFR Part 11 — Electronic Records; Electronic Signatures", "organization": "U.S. Food and Drug Administration (via GPO govinfo)", "url": "https://www.govinfo.gov/content/pkg/CFR-2023-title21-vol1/xml/CFR-2023-title21-vol1-part11.xml", "version_or_date": "CFR 2023 edition, Title 21 Part 11 (revised as of 1 April 2023)", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:24:00Z", "relevance": "11.50 requires printed name, date and time, and the meaning (review, approval, responsibility, authorship) of a signature; 11.70 requires inseparable signature-record linking; 11.10(e) requires audit trails retained as long as the record." }, { "id": "SRC-007", "title": "Regulation (EU) 2016/679 (General Data Protection Regulation)", "organization": "European Union (EUR-Lex)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679", "version_or_date": "OJ L 119, 4 May 2016", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:28:00Z", "relevance": "Article 22 on solely automated decisions with the right to human intervention, to express a point of view and to contest; Article 5 accountability and storage limitation; Article 30 records of processing." }, { "id": "SRC-008", "title": "Regulation (EU) 2024/1689 (Artificial Intelligence Act)", "organization": "European Union (EUR-Lex)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689", "version_or_date": "OJ, 12 July 2024", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:32:00Z", "relevance": "Article 14 human oversight including the ability to decide not to use the system and to disregard, override or reverse output; Article 12 logging; Article 26 deployer duties; Article 86 explanation of individual decision-making." }, { "id": "SRC-009", "title": "ODRL Information Model 2.2", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/odrl-model/", "version_or_date": "W3C Recommendation, 15 February 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:36:00Z", "relevance": "Permission, Prohibition, Duty, Constraint, Party and Action provide a tested structure for the conditions and obligations attached to an approval outcome without importing enforcement." }, { "id": "SRC-010", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:40:00Z", "relevance": "Date-time grammar requiring seconds and an explicit time-offset or Z, and the -00:00 convention for an unknown local offset; basis for the timestamp rule and event/observation time separation." }, { "id": "SRC-011", "title": "Records in Contexts Ontology (RiC-O)", "organization": "International Council on Archives", "url": "https://www.ica.org/standards/RiC/ontology", "version_or_date": "Version 1.1, released 22 May 2025", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T09:44:00Z", "relevance": "Activity, Agent, Position, Mandate, Rule, AuthorityRelation and hasOrHadAuthorityOver give archival-grade structure for the mandate and authority side of a decision and for its record context." }, { "id": "SRC-012", "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final", "version_or_date": "Revision 5, September 2020 (updates through 10 December 2020)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:48:00Z", "relevance": "AC-5 separation of duties and AC-3(2) dual authorization (two-person control) are the only widely adopted normative controls for multi-party approval integrity; also least privilege and change-approval controls." }, { "id": "SRC-013", "title": "Business Process Model and Notation (BPMN) Version 2.0.2", "organization": "Object Management Group", "url": "https://www.omg.org/spec/BPMN/2.0.2/About-BPMN/", "version_or_date": "Version 2.0.2, January 2014", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:52:00Z", "relevance": "Fixes the process/task boundary: the containing process, participants and task routing are modelled in BPMN terms elsewhere, while the decision occurrence itself is modelled here." }, { "id": "SRC-014", "title": "NIST SP 800-37 Rev. 2 Appendix F — Authorization Decisions and Authorization Decision Information (verbatim rendering)", "organization": "bsafes (independent mirror of the NIST publication text)", "url": "https://nist-sp-800-37-r2.bsafes.com/docs/appendix-f-system-and-common-control-authorizations/authorization-decision-information/", "version_or_date": "Mirror of Revision 2, December 2018; consulted 2026-08-29", "source_type": "secondary", "primary_source": false, "authority_tier": 4, "accessed_at": "2026-08-29T09:56:00Z", "relevance": "Readable rendering used to confirm the element list of the authorization decision (decision, terms and conditions, termination date or time-driven frequency, event-driven triggers) because the official artefact is a PDF; SRC-005 remains the authority." } ], "structure": { "bundles": [ { "id": "b-frame", "name": "Decision framing and identity", "description": "What this decision occurrence is, what question it answers, what it concerns and what kind of decision it is.", "rationale": "Before authority or outcome can be interpreted, the occurrence must be individuated and typed; DMN gives the question/allowed-answers framing and PROV gives the activity individuation.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "layers": [ { "id": "l-identity-subject", "name": "Identity and subject", "description": "Identification of the occurrence and the question and subject matter it addresses.", "source_refs": [ "SRC-001", "SRC-003", "SRC-011" ], "findings": [ { "id": "f-decision-instance-identity", "name": "Decision occurrence identity", "description": "How one decision or approval occurrence is identified and kept distinct from its subject, its notice and the rule set applied.", "source_refs": [ "SRC-003", "SRC-005", "SRC-011" ], "questions": [ { "id": "q-id-master-ref", "text": "Which system of record issues the authoritative identifier for this decision occurrence, and what is that identifier?", "kind": "identity", "answer_data": [ "issuing register or system-of-record name", "master decision reference string", "identifier scheme and version" ] }, { "id": "q-id-fallback", "text": "If no master-system reference exists, which governed IRI or Dimension-minted UUID/ULID identifies it, and who mints it?", "kind": "identity", "answer_data": [ "fallback identifier value", "minting authority", "identifier kind (IRI, UUID, ULID)" ] }, { "id": "q-id-separation", "text": "How is this identifier kept distinct from the identifiers of the subject, the decision notice and the applied rule set?", "kind": "relationship", "answer_data": [ "subject reference", "notice artifact reference", "rule set reference", "disambiguation rule" ] }, { "id": "q-id-stability", "text": "Under which later events (correction, re-vote, appeal outcome) does the identifier stay stable rather than being reissued?", "kind": "constraint", "answer_data": [ "stability policy statement", "events forcing a new identifier", "link type to the prior identifier" ] } ], "data_elements": [ { "id": "de-decision-ref", "name": "Decision reference", "description": "Authoritative identifier of the decision occurrence in its system of record.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-011" ] }, { "id": "de-decision-id-scheme", "name": "Identifier scheme", "description": "Scheme and version under which the decision reference is issued.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "de-decision-alt-refs", "name": "Alternate references", "description": "Non-authoritative identifiers used by other systems for the same occurrence.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Identity is pure inline reference data carried on the decision context itself. Emitting a document here would create a second, competing identity carrier; the notice, minutes and dossier are identified within their own findings." }, { "id": "f-decision-question-and-subject", "name": "Question, subject and granularity", "description": "The exact question decided, the subject matter it reaches, the admissible answers and what counts as one occurrence rather than a chain.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-013" ], "questions": [ { "id": "q-subject-question", "text": "What exact question does this decision answer, and whose formulation of it is authoritative?", "kind": "definition", "answer_data": [ "question text", "formulating authority", "language and version of the formulation" ] }, { "id": "q-subject-reach", "text": "Which subject entities, requests or assets does the decision reach, and by which references?", "kind": "relationship", "answer_data": [ "subject reference set", "reference resolution scheme", "reach limitation statement" ] }, { "id": "q-subject-allowed", "text": "Which answers were admissible before the choice was made?", "kind": "constraint", "answer_data": [ "allowed answer set", "source of the admissible set", "whether a null or defer answer was admissible" ] }, { "id": "q-subject-unit", "text": "Is one occurrence a single approval step, a whole approval chain, or one item within a multi-item session?", "kind": "composition", "answer_data": [ "granularity code", "splitting rule for multi-item sessions", "upstream and downstream decision references" ] } ], "data_elements": [ { "id": "de-decision-question", "name": "Decision question", "description": "The question the decision answers, in the authoritative formulation.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "de-decision-subject-ref", "name": "Subject reference", "description": "Reference to the entity or request decided about, resolved in its own owning model.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-009" ] }, { "id": "de-decision-granularity", "name": "Granularity code", "description": "Whether the occurrence is a step, a chain or an item within a session.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "The question, the admissible answer set and the subject references are inline fields; any document that states them (agenda item, request form) belongs to the subject or input models and is referenced, not owned here." } ] }, { "id": "l-typing-boundaries", "name": "Typing and modality", "description": "Classification of the decision and whether it was reached by human, automated or hybrid means.", "source_refs": [ "SRC-004", "SRC-007", "SRC-008" ], "findings": [ { "id": "f-decision-type-and-modality", "name": "Decision type, modality and materiality", "description": "The governed decision-type code, whether the outcome was produced solely by automated processing, and the materiality and reversibility of the decision.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-type-code", "text": "Which decision-type code, from which governed code list and version, classifies this occurrence?", "kind": "classification", "answer_data": [ "decision-type code", "code list identifier and version", "definition of the code" ] }, { "id": "q-type-modality", "text": "Was the outcome produced solely by automated processing, by a human, or by a human acting on an automated recommendation?", "kind": "decision", "answer_data": [ "modality code", "automated component reference", "human decision-maker reference" ] }, { "id": "q-type-materiality", "text": "Which materiality or impact tier applies, and which scale sets that tier?", "kind": "measurement", "answer_data": [ "materiality tier value", "scale identifier and version", "measured or estimated basis" ] }, { "id": "q-type-reversibility", "text": "Is the decision reversible in practice, and what makes it irreversible once acted upon?", "kind": "quality", "answer_data": [ "reversibility flag", "irreversibility cause", "point of no return description" ] } ], "data_elements": [ { "id": "de-decision-type-code", "name": "Decision type code", "description": "Governed classification of the decision (approval, authorization, adjudication, selection, determination, ratification).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005" ] }, { "id": "de-decision-modality", "name": "Decision modality", "description": "Human, automated or human-on-recommendation production of the outcome.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "de-materiality-tier", "name": "Materiality tier", "description": "Impact or materiality band governing scrutiny and review frequency.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Classification is coded inline data resolved against an externally governed code list; the code list itself is a registry owned by the adopting Dimension and is referenced rather than reproduced as an artifact here." } ] } ] }, { "id": "b-authority", "name": "Authority, mandate and participation", "description": "The power under which the decision was taken, its limits and delegation, and who took part with what independence.", "rationale": "DMN authority requirements and knowledge sources, RiC-O mandates and authority relations, and the NIST authorizing official pattern converge on authority as a first-class, citable input to any approval.", "source_refs": [ "SRC-001", "SRC-005", "SRC-011", "SRC-012" ], "layers": [ { "id": "l-authority-basis", "name": "Authority basis and limits", "description": "The instrument conferring the power to decide, its delegation chain and its competence limits.", "source_refs": [ "SRC-002", "SRC-005", "SRC-011" ], "findings": [ { "id": "f-authority-basis-and-mandate", "name": "Authority basis, mandate and delegation", "description": "The instrument that confers the power to take this decision, the position that holds it, and any delegation or substitution under which someone acted on behalf of the holder.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-011" ], "questions": [ { "id": "q-auth-instrument", "text": "Which instrument confers the power to take this decision, and what is its citation, version and effective date?", "kind": "authority", "answer_data": [ "instrument citation", "instrument version", "effective from and until" ] }, { "id": "q-auth-position", "text": "Which position or role, rather than which individual, holds the decision right under that instrument?", "kind": "ownership", "answer_data": [ "position reference", "role name under the instrument", "holder party reference at decision time" ] }, { "id": "q-auth-delegation", "text": "Which agent acted on behalf of which responsible agent, under what delegation instrument and validity period?", "kind": "provenance", "answer_data": [ "delegation chain entries", "delegation instrument reference", "delegation valid-from and valid-until" ] }, { "id": "q-auth-nondelegable", "text": "Which act is reserved to the holder and cannot be delegated to a designated representative?", "kind": "constraint", "answer_data": [ "reserved act description", "source of the reservation", "evidence the reserved act was performed by the holder" ] } ], "data_elements": [ { "id": "de-authority-instrument-ref", "name": "Authority instrument reference", "description": "Citation of the statute, resolution, policy, contract or delegation letter conferring the decision right.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "de-authority-position", "name": "Authority-holding position", "description": "The position or role holding the decision right, distinct from the natural person occupying it.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-005" ] }, { "id": "de-acting-on-behalf-of", "name": "Acted on behalf of", "description": "Responsible agent for whom a subordinate or representative agent acted.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "af-authority-instrument", "name": "Authority or delegation instrument", "description": "The document evidencing the conferral of decision rights or their delegation for this occurrence.", "media_or_form": [ "legal instrument", "board or committee resolution", "policy document", "delegation letter", "standing order" ], "serial": false, "identity_strategy": "Instrument reference issued by the enacting authority's register (act, resolution or letter number plus version); where no such reference exists, a governed IRI minted by the adopting Dimension. An enactment date alone is never the identifier.", "source_refs": [ "SRC-011", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "f-decision-rights-and-limits", "name": "Competence limits and escalation", "description": "The quantitative and categorical bounds on the authority applied, the escalation path when they are exceeded, and any emergency authority.", "source_refs": [ "SRC-004", "SRC-005", "SRC-011", "SRC-012" ], "questions": [ { "id": "q-limit-bounds", "text": "Which value, risk-class, subject-matter or jurisdictional limits bound the authority applied?", "kind": "constraint", "answer_data": [ "limit type", "limit value and unit or class", "limit register reference and version" ] }, { "id": "q-limit-escalation", "text": "What is the escalation path when a request exceeds the holder's limit?", "kind": "process", "answer_data": [ "escalation target position", "escalation trigger condition", "escalation evidence reference" ] }, { "id": "q-limit-emergency", "text": "Under what emergency conditions may a limit be exceeded, and what after-the-fact ratification is required?", "kind": "exception", "answer_data": [ "emergency condition definition", "ratification requirement and deadline", "ratifying authority reference" ] }, { "id": "q-limit-evidence", "text": "How is the limit check evidenced at decision time rather than asserted afterwards?", "kind": "evidence", "answer_data": [ "limit check record", "checked-at timestamp", "checking agent or system reference" ] } ], "data_elements": [ { "id": "de-authority-limit", "name": "Authority limit", "description": "A bound on the decision right expressed as a quantity, class or jurisdiction.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-012" ] }, { "id": "de-escalation-target", "name": "Escalation target", "description": "Position or body to which a request exceeding the limit must be escalated.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Limits and escalation targets are parameters resolved against an external authority or threshold register; carrying them inline as bound values plus a register reference avoids duplicating that register's content and lifecycle inside this model." } ] }, { "id": "l-participation-integrity", "name": "Participation and decision integrity", "description": "Who took part in which role, and the independence and multi-party conditions that make the decision validly constituted.", "source_refs": [ "SRC-003", "SRC-006", "SRC-012" ], "findings": [ { "id": "f-roles-and-participation", "name": "Participant roles and responsibility", "description": "The agents who took part, the role each held with respect to the activity, and who remains accountable for the outcome.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-role-participants", "text": "Which agents participated, in which roles, and with what share of responsibility for the outcome?", "kind": "relationship", "answer_data": [ "participant party reference", "role code", "responsibility statement" ] }, { "id": "q-role-design-vs-runtime", "text": "How is the design-time decision owner or decision maker in the rule model distinguished from the agent who actually decided this occurrence?", "kind": "classification", "answer_data": [ "design-time owner reference from the rule model", "runtime deciding agent reference", "mapping note explaining the difference" ] }, { "id": "q-role-accountable", "text": "Who is accountable for the decision after it is taken, if that differs from who signed it?", "kind": "ownership", "answer_data": [ "accountable party reference", "basis of continuing accountability", "hand-over event if accountability transferred" ] }, { "id": "q-role-required-acts", "text": "Which participants' acts were required for completion and which were advisory only?", "kind": "requirement", "answer_data": [ "required act list by role", "advisory act list", "completion rule reference" ] } ], "data_elements": [ { "id": "de-participant", "name": "Participant entry", "description": "One agent's participation in the decision activity with role, period and act performed.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-accountable-party", "name": "Accountable party", "description": "Party bearing continuing accountability for the decision after it is taken.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Participation is a set of qualified relations to parties held in the adopting Dimension's party model; the correct representation is inline references with role codes, not a locally owned roster document that would fork party master data." }, { "id": "f-independence-and-conflict-control", "name": "Separation of duties and conflict control", "description": "The incompatibility rules, dual-authorization requirements and recusal or conflict declarations that protect the integrity of the decision.", "source_refs": [ "SRC-005", "SRC-006", "SRC-012" ], "questions": [ { "id": "q-sod-rule", "text": "Which separation-of-duties rule applies, and which role pairs are incompatible for this decision type?", "kind": "constraint", "answer_data": [ "separation rule reference", "incompatible role pairs", "scope of the rule across systems" ] }, { "id": "q-sod-dual", "text": "Is dual authorization or two-person control required, and on which criterion is that requirement triggered?", "kind": "requirement", "answer_data": [ "dual authorization flag", "triggering criterion", "identities of the two authorizing parties" ] }, { "id": "q-sod-recusal", "text": "How are declared conflicts of interest, recusals and abstentions recorded, and what effect do they have on validity?", "kind": "exception", "answer_data": [ "declaration entries with declaring party and time", "recusal effect on quorum or tally", "validity consequence statement" ] }, { "id": "q-sod-violation", "text": "How is a self-approval or maker-equals-checker violation detected and recorded?", "kind": "validation", "answer_data": [ "detection rule", "violation record", "remediation or voiding outcome" ] } ], "data_elements": [ { "id": "de-dual-authorization-required", "name": "Dual authorization required", "description": "Whether two-person control applied to this decision.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "de-recusal", "name": "Recusal or conflict declaration", "description": "A declared conflict of interest, recusal or abstention with its declaring party and time.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "These are assertions about how the occurrence was constituted, evaluated against rules held elsewhere; the model records the applicable rule reference and the observed facts, while detection and enforcement of violations belong to the referenced authorization and control models." }, { "id": "f-collective-decision-rules", "name": "Collective decision rules (declared evidence gap)", "description": "Quorum, voting method, thresholds and treatment of abstentions and proxies for decisions taken by a body rather than an individual; no consulted primary standard defines these normatively, so this finding is marked as a gap and must not be treated as canonical.", "source_refs": [ "SRC-011", "SRC-012", "SRC-013" ], "questions": [ { "id": "q-coll-quorum", "text": "What quorum and majority threshold made this decision validly constituted?", "kind": "requirement", "answer_data": [ "quorum requirement and basis", "majority threshold", "constitutive rule reference" ] }, { "id": "q-coll-method", "text": "Which voting method was used, and how were abstentions, proxies and absentees counted?", "kind": "process", "answer_data": [ "voting method code", "counting treatment per category", "proxy authorisation references" ] }, { "id": "q-coll-tally", "text": "What were the counted results for, against and abstaining?", "kind": "measurement", "answer_data": [ "votes in favour", "votes against", "abstentions", "invalid or spoiled votes" ] }, { "id": "q-coll-written", "text": "How were decisions taken by written procedure or by chair's action subsequently ratified?", "kind": "exception", "answer_data": [ "procedure code", "ratification event and time", "ratifying body reference" ] } ], "data_elements": [ { "id": "de-vote-tally", "name": "Vote tally", "description": "Counted results of the vote with treatment of abstentions and proxies.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "de-voting-rule-ref", "name": "Constitutive rule reference", "description": "Reference to the standing orders or constitutive rules setting quorum and threshold.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Tallies and quorum facts are structured inline values; the minutes that evidence them are the artifact of the deliberation finding, and the constitutive rules themselves are owned by the adopting Dimension's governance instruments rather than by this model." } ] } ] }, { "id": "b-inputs", "name": "Inputs, criteria and reasoning", "description": "What the decision used, which criteria applied, which options existed and why the chosen one was chosen.", "rationale": "DMN separates input data from decision logic, PROV records what an activity used, and NIST's authorization package shows that the evidence set is itself a fixed, citable object.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "layers": [ { "id": "l-input-evidence", "name": "Inputs and applied criteria", "description": "The fixed evidence set actually used and the pinned criteria or rule set applied to it.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "findings": [ { "id": "f-input-evidence-set", "name": "Input and evidence set", "description": "The inputs actually used, fixed by version, digest or as-of time, together with what was missing or uncertain.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010" ], "questions": [ { "id": "q-input-used", "text": "Which inputs, documents and datasets were actually used, at which version or as-of time?", "kind": "evidence", "answer_data": [ "input item references", "version or as-of value per item", "inclusion decision per item" ] }, { "id": "q-input-origin", "text": "Where did each input come from and who attested to its accuracy?", "kind": "provenance", "answer_data": [ "source system or party per item", "attestation statement", "attestation time" ] }, { "id": "q-input-gaps", "text": "What was missing, stale or uncertain at decision time, and how was that gap treated?", "kind": "quality", "answer_data": [ "missing item list", "uncertainty or confidence statement", "treatment (assumption, deferral, proceed-with-risk)" ] }, { "id": "q-input-fixation", "text": "How is the package fixed so that later changes at the source do not silently alter what was decided upon?", "kind": "validation", "answer_data": [ "content digest and algorithm", "fixation timestamp", "immutability rule" ] } ], "data_elements": [ { "id": "de-input-item", "name": "Input item", "description": "One input used by the decision with its reference, version and role in the decision.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "de-input-as-of", "name": "Input as-of time", "description": "Observation or as-of time of an input, recorded separately from the decision time.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-003" ] }, { "id": "de-input-digest", "name": "Input package digest", "description": "Digest over the fixed member list of the input package with its algorithm.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [ { "id": "af-decision-input-package", "name": "Decision input package", "description": "The assembled and fixed set of materials placed before the decider, in the sense of an authorization package.", "media_or_form": [ "assembled evidence package", "assessment report set", "structured input record", "submission dossier" ], "serial": false, "identity_strategy": "Package identifier from the assembling system of record plus a content digest over the fixed member list; each member retains its own source identifier and version.", "source_refs": [ "SRC-005", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "f-criteria-and-rule-reference", "name": "Applied criteria and rule-set reference", "description": "Which rule set, policy or decision model was applied at which pinned version, and any recorded departure from it.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009" ], "questions": [ { "id": "q-crit-ruleset", "text": "Which rule set, policy or decision model was applied, at which pinned version?", "kind": "interoperability", "answer_data": [ "rule set reference", "pinned version identifier", "binding time" ] }, { "id": "q-crit-owner", "text": "Who owns that rule set, and is this decision permitted to depart from it?", "kind": "authority", "answer_data": [ "rule set owner reference", "departure permission statement", "approver required for a departure" ] }, { "id": "q-crit-deviation", "text": "If the decision departed from the criteria, what deviation reason and additional approval were recorded?", "kind": "exception", "answer_data": [ "deviation reason code and text", "additional approval reference", "deviation expiry or review date" ] }, { "id": "q-crit-multiple", "text": "Where more than one rule matched, which resolution or hit policy determined the result?", "kind": "constraint", "answer_data": [ "hit or combining policy name", "matched rule references", "resolution outcome" ] } ], "data_elements": [ { "id": "de-rule-set-ref", "name": "Applied rule set reference", "description": "Reference to the rule set, policy or decision model applied, with version pin.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "de-deviation", "name": "Deviation record", "description": "Recorded departure from the applied criteria with reason and additional approval.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Rule content, decision tables, hit policies and their evaluation are owned by the referenced rule and policy-evaluation models. Only the citation, the version pin and the local deviation record belong here, and those are inline reference data." } ] }, { "id": "l-option-reasoning", "name": "Options, rationale and deliberation", "description": "The admissible option space, the reasons connecting inputs to the chosen option, and the record of deliberation and dissent.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-011" ], "findings": [ { "id": "f-option-set-and-alternatives", "name": "Option set and rejected alternatives", "description": "The options on the table at the moment of choice, which was taken and why the others were not.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ], "questions": [ { "id": "q-opt-set", "text": "Which options were on the table when the choice was made?", "kind": "composition", "answer_data": [ "option entries with identifier and description", "source of each option", "option availability window" ] }, { "id": "q-opt-chosen", "text": "Which option was chosen and what stated reason rejected each of the others?", "kind": "decision", "answer_data": [ "chosen option reference", "rejection reason per option", "comparative criteria used" ] }, { "id": "q-opt-null", "text": "Was the null option of deferring or taking no action admissible, and was it considered?", "kind": "constraint", "answer_data": [ "null option admissibility flag", "consideration statement", "consequence of deferral" ] }, { "id": "q-opt-late", "text": "How is an option added late in the process distinguished from one available from the outset?", "kind": "temporal", "answer_data": [ "option introduction time", "introducing party", "effect on prior deliberation" ] } ], "data_elements": [ { "id": "de-option", "name": "Option entry", "description": "One admissible option with its identifier, description and availability.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "de-chosen-option-ref", "name": "Chosen option reference", "description": "Reference to the option actually selected.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "The option space is a structured inline set derived from the admissible answers; the papers describing each option are members of the input package artifact and are referenced from here rather than duplicated." }, { "id": "f-rationale-and-explanation", "name": "Rationale and owed explanation", "description": "The reasoning connecting inputs and criteria to the chosen option, and the explanation owed to affected parties where the decision significantly affects them.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-rat-reasoning", "text": "What reasoning connects the inputs and applied criteria to the chosen option?", "kind": "evidence", "answer_data": [ "rationale text", "criteria weighting or trade-off statement", "decisive factor identification" ] }, { "id": "q-rat-owed", "text": "Which explanation is owed to the affected party, in what form and within what period?", "kind": "privacy", "answer_data": [ "explanation obligation basis", "explanation content and format", "delivery deadline" ] }, { "id": "q-rat-sufficiency", "text": "How complete must the rationale be for the decision to be effectively contestable?", "kind": "quality", "answer_data": [ "sufficiency criterion", "reviewer confirmation", "known omissions in the rationale" ] }, { "id": "q-rat-automation", "text": "Where automated components contributed, what is recorded about their role, logic and limits?", "kind": "interoperability", "answer_data": [ "component reference and version", "role in the decision", "stated limitations and known failure modes" ] } ], "data_elements": [ { "id": "de-rationale", "name": "Rationale", "description": "Recorded reasoning linking evidence and criteria to the chosen option.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "de-automated-contribution", "name": "Automated contribution record", "description": "Role, version and stated limits of any automated component that contributed to the outcome.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "The rationale is inline text bound to the occurrence; when it must be issued to an affected party it travels inside the decision notice artifact defined in the outcome finding, so declaring a second artifact here would duplicate the same statement of reasons." }, { "id": "f-deliberation-and-dissent", "name": "Deliberation events and dissent", "description": "The sessions in which the matter was considered, attendance, and any recorded dissenting or minority position.", "source_refs": [ "SRC-006", "SRC-011", "SRC-013" ], "questions": [ { "id": "q-delib-events", "text": "Which deliberation events took place, when, and who attended each?", "kind": "event", "answer_data": [ "session references with start and end times", "attendance list per session", "matters considered per session" ] }, { "id": "q-delib-dissent", "text": "Which dissenting or minority positions were recorded, and by whom?", "kind": "state", "answer_data": [ "dissent statements", "dissenting party references", "whether dissent is published with the outcome" ] }, { "id": "q-delib-confidential", "text": "Which parts of the deliberation are confidential and which are disclosable?", "kind": "access", "answer_data": [ "confidentiality marking per section", "disclosure basis", "redaction rule" ] }, { "id": "q-delib-certified", "text": "Who certified the minutes and when were they approved?", "kind": "provenance", "answer_data": [ "certifying party reference", "approval time", "approving session reference" ] } ], "data_elements": [ { "id": "de-session", "name": "Deliberation session", "description": "One session in which the matter was considered, with time bounds and attendance.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-013" ] }, { "id": "de-dissent", "name": "Dissent entry", "description": "A recorded minority or dissenting position with its author.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "af-deliberation-minutes", "name": "Deliberation minutes and voting record", "description": "The certified record of the sessions, attendance, discussion, votes and dissent leading to the decision.", "media_or_form": [ "minutes", "voting record", "transcript", "written-procedure record" ], "serial": true, "identity_strategy": "Register code plus zero-padded session sequence assigned by the secretariat, bound to the decision reference; the sequence is the identifying part, numbers are never reused, and gaps are recorded explicitly.", "source_refs": [ "SRC-011", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-outcome", "name": "Outcome, conditions and hand-over", "description": "The choice made, the terms attached to it, its validity window, and how it is communicated and handed to whatever executes it.", "rationale": "NIST's authorization decision and XACML's decision values plus obligations show that an outcome is not a single token: it carries conditions, validity and hand-over duties that must be modelled explicitly.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009" ], "layers": [ { "id": "l-chosen-outcome", "name": "Outcome and attached terms", "description": "The outcome value from a governed vocabulary and the conditions, obligations and validity attached to it.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-014" ], "findings": [ { "id": "f-outcome-and-disposition", "name": "Outcome value and disposition", "description": "The recorded outcome from a governed vocabulary, its mapping to external decision values, and the instants at which it was decided and recorded.", "source_refs": [ "SRC-004", "SRC-005", "SRC-010", "SRC-014" ], "questions": [ { "id": "q-out-value", "text": "What is the outcome value, from which governed outcome vocabulary and version?", "kind": "decision", "answer_data": [ "outcome value", "vocabulary identifier and version", "definition of the value" ] }, { "id": "q-out-mapping", "text": "How does the outcome map to the referenced authorization model's decision values, and where does that mapping lose meaning?", "kind": "interoperability", "answer_data": [ "target value mapping", "unmappable cases (conditional approval, deferral)", "mapping caveat text" ] }, { "id": "q-out-nondecision", "text": "How are 'no applicable authority' and 'could not decide' distinguished from an explicit refusal?", "kind": "classification", "answer_data": [ "non-decision codes", "cause of the non-decision", "follow-up obligation" ] }, { "id": "q-out-instants", "text": "At what instant did the decision take effect, and how does that differ from when it was recorded?", "kind": "temporal", "answer_data": [ "decided-at instant", "recorded-at instant", "clock and offset used for each" ] } ], "data_elements": [ { "id": "de-outcome-value", "name": "Outcome value", "description": "The governed code expressing the decision result.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-decided-at", "name": "Decided at", "description": "Event time at which the decision was taken.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-003" ] }, { "id": "de-recorded-at", "name": "Recorded at", "description": "Observation or ingestion time at which the decision was captured in the record.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-010" ] } ], "artifacts": [ { "id": "af-decision-notice", "name": "Decision notice", "description": "The issued statement of the decision, its terms and its validity, in the sense of an authorization decision document or determination letter.", "media_or_form": [ "decision notice", "authorization decision document", "determination letter", "resolution extract" ], "serial": true, "identity_strategy": "Notice number from the issuing register's monotonic series, bound to the decision's master reference; a superseding notice takes a new number and cites the prior number rather than reusing it.", "source_refs": [ "SRC-005", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "f-conditions-obligations-and-validity", "name": "Conditions, obligations and validity window", "description": "Binding terms and limitations attached to the outcome, obligations placed on the recipient, and the period and triggers governing validity.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-014" ], "questions": [ { "id": "q-cond-terms", "text": "Which conditions, limitations and restrictions attach to the outcome, and which of them are binding rather than advisory?", "kind": "constraint", "answer_data": [ "condition entries", "binding versus advisory flag per entry", "consequence of non-satisfaction" ] }, { "id": "q-cond-obligations", "text": "Which obligations must the recipient discharge, by when, and what follows if they are not discharged?", "kind": "requirement", "answer_data": [ "obligation entries with due dates", "responsible party per obligation", "default consequence" ] }, { "id": "q-cond-window", "text": "From when until when is the decision valid, and is validity time-driven, event-driven or open-ended?", "kind": "temporal", "answer_data": [ "valid-from instant", "valid-until instant or termination date", "review frequency or open-ended flag" ] }, { "id": "q-cond-triggers", "text": "Which events trigger mandatory review or automatic lapse of the decision?", "kind": "event", "answer_data": [ "trigger event definitions", "effect on validity", "party obliged to report the trigger" ] } ], "data_elements": [ { "id": "de-condition", "name": "Condition entry", "description": "A limitation or restriction placed on the outcome, marked binding or advisory.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-obligation", "name": "Obligation entry", "description": "A duty imposed on the recipient with its due date and responsible party.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-004" ] }, { "id": "de-valid-until", "name": "Valid until", "description": "Termination instant of the decision's validity, where the decision is not open-ended.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "Conditions and obligations are structured inline data so they can be queried and monitored; their human-readable statement is carried by the decision notice artifact, and the discharge of any obligation is executed and evidenced by the referenced enforcement and process models." } ] }, { "id": "l-communication-handover", "name": "Communication and execution hand-over", "description": "How the outcome reaches its addressees and how it is handed to whatever must act on it, without this model taking on execution.", "source_refs": [ "SRC-004", "SRC-005", "SRC-013" ], "findings": [ { "id": "f-communication-and-handover", "name": "Notification, acknowledgement and execution hand-over", "description": "Communication of the outcome to addressees with evidence of acknowledgement, and the hand-over of the decision to the systems that act on it while enforcement stays outside this model.", "source_refs": [ "SRC-004", "SRC-005", "SRC-008", "SRC-013" ], "questions": [ { "id": "q-comm-recipients", "text": "To whom must the outcome be communicated, in what form, and within what period?", "kind": "process", "answer_data": [ "recipient references", "required form per recipient", "communication deadline" ] }, { "id": "q-comm-ack", "text": "How are receipt of the notice and acceptance of its terms evidenced, and what happens if acknowledgement fails?", "kind": "evidence", "answer_data": [ "acknowledgement records with time", "acceptance statement", "non-acknowledgement handling rule" ] }, { "id": "q-comm-handover", "text": "Which downstream system consumes this decision, and what exactly is in the hand-over payload?", "kind": "interoperability", "answer_data": [ "consuming system reference", "payload element list", "hand-over time" ] }, { "id": "q-comm-boundary", "text": "Which model owns enforcement of the outcome, and how is drift between the decided outcome and the enforced state detected?", "kind": "authority", "answer_data": [ "enforcing model reference", "drift detection mechanism reference", "reporting path for detected drift" ] } ], "data_elements": [ { "id": "de-recipient", "name": "Recipient", "description": "Party to whom the decision must be communicated.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-008" ] }, { "id": "de-acknowledgement", "name": "Acknowledgement record", "description": "Evidence that a recipient received the notice and accepted its terms.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-014" ] }, { "id": "de-handover-target", "name": "Hand-over target", "description": "Reference to the system or model that acts on the decision.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "The communicated document is the decision notice already declared in the outcome finding; what is local here is inline delivery, acknowledgement and hand-over metadata. Execution status itself is a reference into the enforcing model, never a locally owned state." } ] } ] }, { "id": "b-lifecycle", "name": "Lifecycle, oversight and contestation", "description": "How the decision changes state over time, how automated decisions are overseen, and how the decision can be challenged, overridden or undone.", "rationale": "Authorization termination dates and event-driven review, GDPR's right to human intervention and contestation, and the AI Act's override duties all require an explicit post-decision surface.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008" ], "layers": [ { "id": "l-decision-state", "name": "Decision state and change", "description": "Permitted states of a decision occurrence and the ways it is superseded, revoked, suspended or renewed.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "f-decision-status-lifecycle", "name": "Decision status lifecycle", "description": "The permitted states of the decision occurrence, the legal transitions between them and who may cause each.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-013" ], "questions": [ { "id": "q-life-states", "text": "What are the permitted states of the decision occurrence and which transitions between them are legal?", "kind": "lifecycle", "answer_data": [ "state vocabulary", "allowed transition pairs", "terminal states" ] }, { "id": "q-life-effective", "text": "Which state means decided but not yet effective, and which means effective but suspended?", "kind": "state", "answer_data": [ "state definitions", "distinguishing conditions", "effect on downstream rights" ] }, { "id": "q-life-transition-authority", "text": "Who may cause each transition, and may that differ from who took the original decision?", "kind": "authority", "answer_data": [ "authorised position per transition", "basis for a different actor", "evidence of the transition act" ] }, { "id": "q-life-timestamps", "text": "How is each transition timestamped, and by whose clock and offset?", "kind": "temporal", "answer_data": [ "transition timestamp", "clock or system reference", "offset recorded with the value" ] } ], "data_elements": [ { "id": "de-status", "name": "Decision status", "description": "Current state of the decision occurrence.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de-status-transition", "name": "Status transition", "description": "A recorded state change with actor, reason and time.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "State and transitions are inline attributes of the occurrence. The durable trace of transitions is written to the referenced audit-log model, whose record structure and immutability guarantees this model must not define." }, { "id": "f-supersession-revocation-and-reauthorization", "name": "Supersession, revocation and reauthorization", "description": "How a decision is replaced, revoked or suspended, what becomes of the rights and obligations it created, and what forces a fresh decision instead of an amendment.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-014" ], "questions": [ { "id": "q-sup-linkage", "text": "Which decision supersedes or revokes which, and from what effective instant?", "kind": "lifecycle", "answer_data": [ "superseding and superseded references", "action type", "effective instant of the change" ] }, { "id": "q-sup-carryover", "text": "What happens to obligations and rights created by the superseded or revoked decision?", "kind": "relationship", "answer_data": [ "carry-over rule per obligation", "terminated rights list", "transitional period" ] }, { "id": "q-sup-reauth", "text": "Which elapsed periods or events force reauthorization rather than amendment?", "kind": "event", "answer_data": [ "reauthorization trigger definitions", "due date", "responsible authority" ] }, { "id": "q-sup-retroactive", "text": "Is retroactive revocation permitted here, and what evidence must support it?", "kind": "exception", "answer_data": [ "retroactivity permission and basis", "required evidence", "effect on acts already performed" ] } ], "data_elements": [ { "id": "de-supersedes-ref", "name": "Supersession link", "description": "Reference from this decision to the decision it supersedes or revokes.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "de-revocation-reason", "name": "Revocation reason", "description": "Coded reason for revocation, suspension or withdrawal.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-014" ] }, { "id": "de-reauthorization-due", "name": "Reauthorization due", "description": "Instant by which a fresh decision is required.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "Supersession is a relation between decision occurrences plus reason codes and instants; the replacing decision issues its own notice artifact, so no separate document is owned by this finding." } ] }, { "id": "l-oversight-contestation", "name": "Oversight and contestation", "description": "Human oversight of automated decisions and the paths by which a decision is challenged, reviewed or overridden.", "source_refs": [ "SRC-007", "SRC-008", "SRC-012" ], "findings": [ { "id": "f-human-oversight-of-automation", "name": "Human oversight of automated decisions", "description": "Assignment and exercise of oversight where the outcome is produced or materially shaped by automation, including disregard, override and reversal.", "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-hov-assignment", "text": "Who is assigned oversight of this automated or assisted decision, and with what competence and means to intervene?", "kind": "authority", "answer_data": [ "oversight party reference", "competence evidence", "available intervention means" ] }, { "id": "q-hov-intervention", "text": "Was the automated output disregarded, overridden or reversed, and on what basis?", "kind": "exception", "answer_data": [ "intervention type", "basis and reasoning", "intervention time and actor" ] }, { "id": "q-hov-basis", "text": "On what legal or policy basis is a solely automated decision permitted for this decision type?", "kind": "requirement", "answer_data": [ "permitting basis code", "safeguard set applied", "affected-party rights available" ] }, { "id": "q-hov-substantive", "text": "What evidence shows the human intervention was substantive rather than a formality?", "kind": "evidence", "answer_data": [ "reviewed material references", "time spent or review depth indicator", "reviewer's independent findings" ] } ], "data_elements": [ { "id": "de-oversight-assignment", "name": "Oversight assignment", "description": "Assignment of a human overseer to an automated or assisted decision.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-override-event", "name": "Override event", "description": "Recorded disregard, override or reversal of an automated output.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "Oversight facts are inline assertions about this occurrence; the capability of the AI system to be overseen, and the logging of its operation, belong to the AI system's own model and to the referenced audit-log model." }, { "id": "f-contestation-and-override", "name": "Contestation, appeal and ratification", "description": "Who may challenge the decision, how the review is conducted and how emergency overrides or after-the-fact ratifications are recorded.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-012" ], "questions": [ { "id": "q-con-standing", "text": "Who may contest this decision, on what grounds, and within what period?", "kind": "access", "answer_data": [ "eligible contestant classes", "admissible grounds", "deadline and its start event" ] }, { "id": "q-con-outcome", "text": "How does the review outcome relate to the original decision: confirm, amend, replace or remit?", "kind": "lifecycle", "answer_data": [ "review outcome code", "link to the original decision", "effect on validity in the interim" ] }, { "id": "q-con-independence", "text": "Which body reviews the decision, and must it be independent of the original decider?", "kind": "ownership", "answer_data": [ "reviewing body reference", "independence requirement and basis", "conflict declarations of reviewers" ] }, { "id": "q-con-emergency", "text": "How are emergency overrides and after-the-fact ratifications of this decision recorded?", "kind": "exception", "answer_data": [ "override event record", "ratification decision reference", "deadline for ratification" ] } ], "data_elements": [ { "id": "de-contestation", "name": "Contestation entry", "description": "A challenge to the decision with contestant, grounds and submission time.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "de-appeal-outcome", "name": "Review outcome", "description": "Coded result of the review of a contested decision.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [ { "id": "af-contestation-dossier", "name": "Contestation submission and review determination", "description": "The challenge as submitted and the reviewing body's determination on it.", "media_or_form": [ "appeal submission", "objection notice", "review determination", "ratification record" ], "serial": true, "identity_strategy": "Case reference from the reviewing body's register plus a sequence within that case; every item cites the contested decision's master reference, and sequence numbers are never reused.", "source_refs": [ "SRC-007", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-assurance", "name": "Attribution, record and interoperability", "description": "How the decision is attributed and attested, how its record is kept and disclosed, and how it maps to external vocabularies.", "rationale": "PROV supplies attribution structure, 21 CFR 11 supplies the meaning-of-signature requirement, and archival and data-protection sources supply the record, retention and disclosure surface that a decision context must reference without owning.", "source_refs": [ "SRC-003", "SRC-006", "SRC-007", "SRC-011" ], "layers": [ { "id": "l-attribution-attestation", "name": "Attribution and attestation", "description": "Who is recorded as responsible, under what plan, and how the decision is signed.", "source_refs": [ "SRC-003", "SRC-006", "SRC-010" ], "findings": [ { "id": "f-attribution-and-plan", "name": "Attribution, plan and activity timing", "description": "The qualified association between the decision activity and its responsible agents, the procedure followed, and the separation of activity time from recording time.", "source_refs": [ "SRC-003", "SRC-005", "SRC-010", "SRC-011" ], "questions": [ { "id": "q-attr-association", "text": "Which agent was associated with the decision activity, in which role, and following which plan or procedure version?", "kind": "provenance", "answer_data": [ "agent reference", "role code", "plan or procedure reference and version" ] }, { "id": "q-attr-times", "text": "What are the start and end times of the decision activity, and how are they distinguished from recording or ingestion time?", "kind": "temporal", "answer_data": [ "started-at instant", "ended-at instant", "recorded-at or ingested-at instant" ] }, { "id": "q-attr-informed", "text": "Which prior activities informed this decision and which entities did it generate?", "kind": "relationship", "answer_data": [ "informing activity references", "generated entity references", "generation instants" ] }, { "id": "q-attr-asserter", "text": "How is a provenance assertion made by the deciding system distinguished from one asserted by a third party?", "kind": "quality", "answer_data": [ "asserting party reference", "assertion time", "confidence or verification status" ] } ], "data_elements": [ { "id": "de-association", "name": "Association entry", "description": "Qualified association of an agent with the decision activity, carrying role and plan.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-plan-ref", "name": "Plan or procedure reference", "description": "Reference to the procedure, standing instruction or policy the agent followed.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-011" ] }, { "id": "de-started-at", "name": "Activity start", "description": "Instant at which the decision activity began.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "Attribution is a graph of qualified relations expressed inline and projectable to PROV; it is not a document. Serialising it into an artifact would freeze one projection and duplicate the referenced audit and party models." }, { "id": "f-signature-and-attestation", "name": "Signature and its declared meaning", "description": "Signatures applied to the decision, the meaning each carries, and their inseparable binding to the signed record; verification itself is external.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-sig-meaning", "text": "What meaning is attached to each signature: review, approval, responsibility or authorship?", "kind": "evidence", "answer_data": [ "meaning code per signature", "signer printed name", "execution instant" ] }, { "id": "q-sig-identity", "text": "Which signer identity is bound to the signature, and how was that identity authenticated?", "kind": "identity", "answer_data": [ "signer party reference", "authentication method", "credential or certificate reference" ] }, { "id": "q-sig-binding", "text": "How is the signature bound to the record so it cannot be excised, copied or transferred to another record?", "kind": "security", "answer_data": [ "binding mechanism", "covered content description", "tamper-evidence indicator" ] }, { "id": "q-sig-verification", "text": "Which model verifies the signature, and where is the verification result referenced from here?", "kind": "validation", "answer_data": [ "verifying model reference", "verification result reference", "verification time" ] } ], "data_elements": [ { "id": "de-signature", "name": "Signature entry", "description": "One signature applied to the decision with signer, instant and binding reference.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-signature-meaning", "name": "Signature meaning", "description": "Declared meaning of the signature such as review, approval, responsibility or authorship.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "af-signature-manifestation", "name": "Signature manifestation block", "description": "The human-readable manifestation showing signer name, execution date and time, and the meaning of the signature, carried with the signed record.", "media_or_form": [ "human-readable signature block", "electronic signature manifestation", "seal" ], "serial": false, "identity_strategy": "Identified by the signed artifact's identifier plus the signer reference and the execution instant; the manifestation is never identified by date alone and is never detachable from the record it signs.", "source_refs": [ "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "l-record-access-interop", "name": "Record, access and alignment", "description": "The durable record and its disposition boundary, who may see what, and how the context maps to external standards.", "source_refs": [ "SRC-006", "SRC-007", "SRC-011" ], "findings": [ { "id": "f-record-and-disposition-boundary", "name": "Decision record and disposition boundary", "description": "The durable record produced by the decision, the retention class asserted for it, and the explicit statement that disposition is executed elsewhere.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008", "SRC-011" ], "questions": [ { "id": "q-rec-retention", "text": "Which retention class and schedule apply to the decision record and, separately, to its deliberation content?", "kind": "retention", "answer_data": [ "retention class per content type", "schedule reference", "minimum retention period" ] }, { "id": "q-rec-executor", "text": "Which model or policy executes disposition, and what does this model keep as a tombstone afterwards?", "kind": "authority", "answer_data": [ "executing model or policy reference", "tombstone element list", "disposition-executed-at instant" ] }, { "id": "q-rec-hold", "text": "What blocks destruction while the decision still confers rights or imposes obligations?", "kind": "constraint", "answer_data": [ "hold condition", "hold authority reference", "hold release event" ] }, { "id": "q-rec-erasure", "text": "How are erasure requests for personal data reconciled with the obligation to keep the decision record?", "kind": "privacy", "answer_data": [ "erasure request reference", "overriding legal basis", "redaction or partial-erasure outcome" ] } ], "data_elements": [ { "id": "de-record-ref", "name": "Decision record reference", "description": "Reference to the durable record of the decision in the records model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-006" ] }, { "id": "de-retention-class", "name": "Retention class", "description": "Asserted retention class for the decision record and its parts.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] }, { "id": "de-legal-hold", "name": "Legal hold flag", "description": "Whether disposition is currently suspended by a hold.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "This finding is deliberately a boundary declaration: the record object, its schedule and its destruction belong to the referenced records-management model. Only the record reference, the asserted retention class and the hold flag are inline here, so no artifact may be owned locally." }, { "id": "f-access-and-disclosure", "name": "Access, confidentiality and mandatory disclosure", "description": "Who may read the outcome, the rationale and the deliberation, what personal data are involved, and which disclosures override the default restriction.", "source_refs": [ "SRC-004", "SRC-007", "SRC-008", "SRC-012" ], "questions": [ { "id": "q-acc-readers", "text": "Which parties may read the outcome, the rationale and the deliberation, and on what basis each?", "kind": "access", "answer_data": [ "reader class per content scope", "basis for access", "approval needed for exceptional access" ] }, { "id": "q-acc-personal", "text": "Which personal data appear in the decision context, and under what lawful basis are they held?", "kind": "privacy", "answer_data": [ "personal data element list", "lawful basis code", "data subject categories" ] }, { "id": "q-acc-marking", "text": "What confidentiality marking applies to each part, and who may downgrade it?", "kind": "security", "answer_data": [ "marking per part", "downgrade authority", "downgrade event record" ] }, { "id": "q-acc-mandatory", "text": "Which mandatory disclosures to a data subject, auditor, supervisory authority or court override the default restriction?", "kind": "exception", "answer_data": [ "disclosure trigger", "content required to be disclosed", "redaction applied" ] } ], "data_elements": [ { "id": "de-confidentiality-marking", "name": "Confidentiality marking", "description": "Classification applied to a part of the decision context.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-lawful-basis", "name": "Lawful basis", "description": "Basis on which personal data in the decision context are processed.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "Access rules are inline policy parameters bound to content scopes; the evaluation and enforcement of any access request, and the logging of reads, belong to the referenced authorization and audit models." }, { "id": "f-standards-alignment", "name": "External alignment and crosswalk", "description": "Mappings from this decision context to external decision, provenance, authorization, policy and archival vocabularies, with recorded conflicts and no conformance claim.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-009", "SRC-011" ], "questions": [ { "id": "q-map-targets", "text": "Which external vocabularies is this decision context mapped to, and at which versions?", "kind": "interoperability", "answer_data": [ "target vocabulary identifiers", "target versions", "mapped element pairs" ] }, { "id": "q-map-loss", "text": "Where does the mapping to authorization decision values lose or distort meaning?", "kind": "classification", "answer_data": [ "unmappable local values", "distortion description", "fallback representation" ] }, { "id": "q-map-conformance", "text": "What evidence would be required before claiming conformance to any of these standards?", "kind": "validation", "answer_data": [ "conformance criteria per standard", "test or profile reference", "current claim status" ] }, { "id": "q-map-maintenance", "text": "Who maintains each mapping and when was it last checked against the source version?", "kind": "provenance", "answer_data": [ "mapping owner", "last checked instant", "source version at last check" ] } ], "data_elements": [ { "id": "de-alignment-mapping", "name": "Alignment mapping entry", "description": "One mapping from a local element to an external vocabulary term, with direction and caveat.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] }, { "id": "de-mapping-checked-at", "name": "Mapping checked at", "description": "Instant at which the mapping was last verified against the target version.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "Alignments are reference data: term pairs, versions and caveats. Publishing them as an artifact would imply a normative crosswalk document this model has no authority to issue, and alignment is explicitly not a conformance claim." } ] } ] } ] }, "functions": [ { "id": "fn-open-decision-activity", "name": "Open decision activity", "description": "Register a new decision or approval occurrence with its question, subject and proposed type.", "inputs": [ "decision question text", "subject reference set", "proposed decision-type code", "requesting party reference" ], "outputs": [ "decision occurrence with master or minted identifier", "initial status of proposed", "opened-at timestamp" ], "preconditions": [ "each subject reference resolves in its owning model", "the decision-type code exists in the bound code-list version" ], "effects": [ "a distinct, addressable decision occurrence exists", "no authority, option or outcome is yet asserted" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-010" ] }, { "id": "fn-bind-authority-and-participants", "name": "Bind authority and participants", "description": "Record the authority instrument, the holding position, any delegation and the participating agents with their roles.", "inputs": [ "authority instrument reference and version", "holding position reference", "participant references with role codes", "delegation instrument reference" ], "outputs": [ "recorded authority binding", "participant role set", "reference to the external eligibility or authorization check" ], "preconditions": [ "the instrument is in force at the intended decision time", "every participant resolves in the party model" ], "effects": [ "the asserted authority basis and the reference to its verification are recorded", "verification and enforcement remain with the referenced authorization model" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-011" ] }, { "id": "fn-assemble-input-package", "name": "Assemble input package", "description": "Fix the evidence set used by the decision with versions, as-of times and a content digest.", "inputs": [ "input item references", "version or as-of value per item", "sufficiency statement" ], "outputs": [ "fixed input package with digest", "list of known gaps and assumptions" ], "preconditions": [ "each input resolves and is readable by the deciding parties", "observation times are available or explicitly marked unknown" ], "effects": [ "the package is immutable once fixed", "later source changes do not alter what was decided upon" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-010" ] }, { "id": "fn-record-deliberation-and-votes", "name": "Record deliberation and votes", "description": "Capture sessions, attendance, tallies, abstentions and dissent leading up to the decision.", "inputs": [ "session records with time bounds", "attendance list", "vote entries", "dissent statements" ], "outputs": [ "deliberation record", "vote tally", "minutes artifact reference" ], "preconditions": [ "the constitutive rule reference is bound or its absence is explicitly declared", "recusals are declared before the vote is counted" ], "effects": [ "deliberation facts are recorded without implying an outcome", "confidential sections are marked at capture time" ], "source_refs": [ "SRC-011", "SRC-012", "SRC-013" ] }, { "id": "fn-record-decision-outcome", "name": "Record decision outcome", "description": "Record the chosen option, outcome value, attached conditions and obligations, validity window and deciding agent.", "inputs": [ "chosen option reference", "outcome value and vocabulary version", "conditions and obligations", "valid-from and valid-until", "deciding agent reference", "decided-at instant" ], "outputs": [ "decision outcome with status of decided", "immutable outcome core", "recorded-at instant" ], "preconditions": [ "authority is bound and within limit, or an emergency exception is recorded", "the chosen option is a member of the admissible set", "separation-of-duties and dual-authorization requirements are satisfied or an exception is recorded" ], "effects": [ "the outcome core becomes immutable", "corrections are possible only as a revision or a superseding decision" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-010", "SRC-012" ] }, { "id": "fn-issue-decision-notice", "name": "Issue and acknowledge decision notice", "description": "Produce the decision notice, transmit it to addressees and capture acknowledgement of its terms.", "inputs": [ "recipient references", "notice content including conditions and validity", "delivery form per recipient" ], "outputs": [ "serial-numbered decision notice", "notified-at instants", "acknowledgement records" ], "preconditions": [ "status is decided", "access rules are resolved for each recipient" ], "effects": [ "communication is evidenced", "failure to acknowledge is flagged for follow-up without altering the decision" ], "source_refs": [ "SRC-005", "SRC-007", "SRC-014" ] }, { "id": "fn-supersede-or-revoke-decision", "name": "Supersede, revoke or suspend decision", "description": "Change the standing of an existing decision and link the change to the acting authority and reason.", "inputs": [ "target decision reference", "action type", "reason code", "effective-at instant", "acting authority reference" ], "outputs": [ "updated status with transition record", "supersession or revocation link", "carry-over statement for obligations" ], "preconditions": [ "the acting authority equals or exceeds the original authority, or the instrument permits the action", "retroactivity, if used, is permitted and evidenced" ], "effects": [ "the original record is preserved unchanged and remains readable", "downstream rights and obligations are marked terminated, carried over or transitional" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-014" ] }, { "id": "fn-register-contestation", "name": "Register contestation or override", "description": "Record a challenge, human intervention or emergency override against a decision and the determination that follows.", "inputs": [ "contestant reference", "grounds", "submitted-at instant", "reviewing body reference" ], "outputs": [ "contestation record", "review determination with outcome code", "contestation dossier reference" ], "preconditions": [ "the contestant is within an eligible class", "the submission is within the contest period or an exception is recorded" ], "effects": [ "the original decision is unchanged until determination", "a determination may trigger supersession or revocation as a separate act" ], "source_refs": [ "SRC-005", "SRC-007", "SRC-008" ] }, { "id": "fn-validate-decision-context-completeness", "name": "Validate decision context completeness", "description": "Check a decision occurrence against a bound validation profile and report gaps.", "inputs": [ "decision occurrence reference", "validation profile identifier and version" ], "outputs": [ "completeness report with per-rule results", "gap list with severity" ], "preconditions": [ "a validation profile is bound to the decision type" ], "effects": [ "gaps are reported for human action", "the function never blocks, enforces or remediates, since enforcement belongs to the referenced authorization and process models" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-012" ] }, { "id": "fn-project-decision-context", "name": "Project decision context for exchange", "description": "Emit a storage-neutral projection of the decision context mapped to a target external vocabulary.", "inputs": [ "target vocabulary identifier and version", "redaction profile", "scope selection" ], "outputs": [ "projection with mapping version", "list of unmapped or lossy elements" ], "preconditions": [ "the mapping has been checked against the current target version", "the redaction profile is authorised for the requesting party" ], "effects": [ "a projection is produced without changing the source context", "no conformance claim is emitted, only an alignment statement with caveats" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-009" ] } ], "composition": [ { "target": "WM-ACT-002 (parent activity model)", "relation": "CHILD", "purpose": "Inherit generic activity identity, temporal bounds, participation and status machinery; this model adds only the decision-specific authority, option set, choice and outcome surface and does not restate the generic activity attributes.", "required": true, "source_refs": [ "SRC-003" ] }, { "target": "Party / agent model of the adopting Dimension (person, organisation, position, software agent)", "relation": "REFERENCE", "purpose": "Resolve every participant, authority holder, signer and recipient by reference; party master data, organisational structure and position registries stay in the target model.", "required": true, "source_refs": [ "SRC-003", "SRC-011" ] }, { "target": "Authorization policy evaluation model (XACML-style PDP and PEP)", "relation": "REFERENCE", "purpose": "Carry the decision-request and response reference plus the subject-specific binding parameters; policy evaluation, combining algorithms, obligation discharge and enforcement remain owned by the target.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "Rule / decision-logic model (DMN decision requirement graph and decision tables)", "relation": "REFERENCE", "purpose": "Pin the applied rule-set version and record deviations from it; authoring, versioning, testing and execution of decision logic remain owned by the target.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Records management, retention and disposition model", "relation": "REFERENCE", "purpose": "Bind the decision record reference and asserted retention class; appraisal, schedule definition and destruction execution are owned by the target.", "required": true, "source_refs": [ "SRC-006", "SRC-011" ] }, { "target": "Audit trail / immutable event log model", "relation": "REFERENCE", "purpose": "Name the events this model requires to be logged and where the log lives; audit-record structure, immutability, storage and log retention are owned by the target and are never asserted here.", "required": false, "source_refs": [ "SRC-006", "SRC-012" ] }, { "target": "Electronic signature and seal model", "relation": "REFERENCE", "purpose": "Reference signature objects and their verification results while keeping the declared meaning-of-signature binding local; cryptography, credentials and validation are owned by the target.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "Process and case model (BPMN process, task and case routing)", "relation": "REFERENCE", "purpose": "Reference the containing process, task or case instance; orchestration, routing, queueing and assignment are owned by the target.", "required": false, "source_refs": [ "SRC-013" ] }, { "target": "Risk assessment and determination model", "relation": "REFERENCE", "purpose": "Reference the risk determination that fed the decision; assessment methodology, scoring and control assessment are owned by the target.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "Vote / ballot record model", "relation": "COMPOSE", "purpose": "Compose per-ballot records into a collective decision occurrence where a body decides; ballot mechanics, secrecy and counting procedures belong to the composed model.", "required": false, "source_refs": [ "SRC-012", "SRC-013" ] }, { "target": "OMG Decision Model and Notation 1.5", "relation": "ALIGN", "purpose": "Crosswalk the question, admissible answers, input data, authority requirement and decision-owner concepts; alignment only, with no conformance claim and no import of DMN execution semantics.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "W3C PROV-O (Activity, Association, Delegation, Plan)", "relation": "ALIGN", "purpose": "Crosswalk attribution, roles, plans, delegation and activity timing to PROV terms for provenance interchange.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "OASIS XACML 3.0 decision values, obligations and advice", "relation": "ALIGN", "purpose": "Crosswalk outcome values and the binding versus advisory distinction, with explicit recording of cases that do not map, such as conditional approval and deferral.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "W3C ODRL Information Model 2.2", "relation": "ALIGN", "purpose": "Crosswalk the conditions, duties and constraints attached to an approval outcome to ODRL rule structures without importing policy evaluation.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "ICA Records in Contexts Ontology 1.1 (Mandate, AuthorityRelation, Activity)", "relation": "ALIGN", "purpose": "Crosswalk the authority basis, mandate and record context to archival description terms for long-term interpretability.", "required": false, "source_refs": [ "SRC-011" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension must designate an accountable owner for the decision-context package who is organisationally distinct from the approvers whose decisions the package records.", "The owner package must publish the decision-type code list, the outcome vocabulary, the authority and threshold register reference, and the binding to the Dimension's party model, each with a version.", "The owner must register and keep resolvable the referenced models (party, authorization evaluation, rule logic, records and retention, audit log, signature, process, risk) before any decision instance is created, and must record which of them is unavailable if one is not adopted." ], "namespace_guidance": "Instances are namespaced under the adopting Dimension's own authority, for example /decision//. Identifiers are never minted inside an external standard's namespace; DMN, PROV-O, XACML, ODRL and RiC-O terms appear only as alignment targets in mapping entries, never as identifier prefixes for local instances.", "registry_links": [ "Registry entry vr.wm-act-024 for this model and its status", "Parent model WM-ACT-002 for the generic activity surface", "Decision-type and outcome-value code lists governed by the adopting Dimension", "Authority, delegation and threshold register maintained by the adopting Dimension" ] }, "canon_and_patch": { "canonicalization_rules": [ "Participants are ordered by role code then by party identifier; options by option identifier; conditions and obligations by their identifiers, so that digests are stable across serialisations.", "All time values are normalised to RFC 3339 with seconds and an explicit offset; the originating local offset is preserved rather than silently converted to Z, because the offset carries jurisdictional meaning for deadlines.", "Coded values are canonicalised as scheme, code and scheme version together; a bare code is never canonical.", "Absent, null and empty are distinguished and preserved: an absent condition set is not an empty one, and an unknown decided-at is never defaulted to the recording time." ], "patch_rules": [ "Once status reaches decided, the outcome value, chosen option, decided-at instant, authority binding and signature bindings are immutable; any change is expressed as a revision entry or a superseding decision, never as an in-place edit.", "Pre-decision content (question, options, input package membership, participants) is patchable while status is proposed or under review, and each patch carries the acting party, a reason code and a recorded-at instant.", "Corrections of clerical error are a distinct patch class from substantive change and must state which is claimed; a substantive change after the decision requires a new decision occurrence.", "Deleting a condition or obligation from a recorded outcome is prohibited; obligations are closed, waived or superseded with an explicit act and reason." ], "compatibility_rules": [ "Adding optional elements or new alignment mappings is a minor change; changing the outcome vocabulary, tightening a cardinality, renaming a status or re-binding a referenced model is breaking.", "Alignment mappings are versioned independently of the model so that a target standard's new version does not force a model version bump.", "Consumers must tolerate unknown optional elements and must not infer meaning from element order.", "A breaking change requires a migration note stating how existing decided occurrences are re-expressed without altering their recorded outcome." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record for the decision, such as the resolution, case, authorization or approval reference held by the deciding body's register.", "Governed global identifier or IRI from a recognised registry or namespace where no master-system reference exists.", "UUID or ULID minted by the adopting Dimension, recorded together with the minting authority and the reason no higher-priority identifier was available.", "A decision date, meeting date, agenda position or sequence position is never an identifier, and no identifier may embed a date as its distinguishing part." ], "timestamp_rule": "All time values use RFC 3339 date-time with seconds and an explicit numeric offset or Z; a fractional-second precision, once chosen for a series, is kept stable. Event time and observation time are recorded separately whenever they differ: decided-at, started-at, ended-at, valid-from and valid-until are event times, while recorded-at and ingested-at are observation times, and recorded-at is never substituted for a missing decided-at. Where the instant is known in UTC but the local offset is genuinely unknown, -00:00 is used as RFC 3339 prescribes rather than Z.", "serial_naming_rule": "Serial artifacts (decision notices, deliberation minutes, contestation dossiers) are named as register code plus a zero-padded monotonic sequence assigned by the issuing register, optionally qualified by the register period; the sequence, not any date component, is the identifying part. Numbers are never reused, gaps are recorded with a reason, and a superseding item takes a new number and cites the prior one.", "integrity_rule": "Each artifact carries a content digest with its algorithm and the instant of computation over the canonical serialisation, and the input package digest covers its fixed member list. A signature manifestation must remain inseparably linked to the record it signs so that it cannot be excised, copied or transferred; this model stores the digest, algorithm and a reference to the verification result, while the cryptographic verification itself is performed by the referenced signature model." }, "policies": [ "Reference over restatement: where a concept belongs to a referenced model (party data, rule logic, audit records, retention schedules, enforcement state), this model carries a reference, a binding and subject-specific parameters only.", "No conformance without evidence: alignments to DMN, PROV-O, XACML, ODRL and RiC-O are declared as mappings with recorded caveats; a conformance claim requires a named test or profile and is otherwise prohibited.", "Record what happened, not what should have happened: participants, inputs, options and outcome are captured as observed facts with their times, and any normative expectation is expressed as a separate rule reference.", "Decision integrity before convenience: separation-of-duties and dual-authorization facts, recusals and emergency exceptions are recorded at the time of the act, never reconstructed afterwards without marking them as reconstructed.", "Explainability floor: a decision that significantly affects a person is not complete until a rationale sufficient for contestation and the required explanation obligation are recorded." ], "crud": { "read": [ "Read of the decision occurrence returns outcome, status, authority reference and validity by default; rationale, deliberation and personal data require an explicit scope.", "Reads are served consistently across projections: JSON, YAML, Markdown, Git, MCP or MongoDB representations must resolve to the same canonical values.", "Historical reads must be able to return the state as at a given instant, distinguishing decided-at from recorded-at." ], "create": [ "A decision occurrence is created only with a question, at least one subject reference and a decision-type code; identity follows the identity priority order.", "Creation asserts nothing about authority or outcome; those are added by their own functions with their own preconditions.", "Creating an outcome requires a resolvable authority binding and a chosen option from the recorded admissible set." ], "update": [ "Pre-decision updates are patches with actor, reason and recorded-at; post-decision changes are revisions or superseding decisions, never in-place edits of the outcome core.", "Status transitions are updates only through the declared transition set, each carrying the acting authority and an RFC 3339 instant.", "Updating an alignment mapping requires re-recording the target version and the checked-at instant." ], "delete": [ "This model performs no hard deletion of decision-context records. Disposition is executed by the referenced records-management model or, where none is adopted, by the adopting Dimension's retention policy; this model only asserts the retention class, the hold flag and the disposition reference.", "On disposition, a tombstone is retained containing the decision identifier and scheme, decision type, outcome class, decided-at, authority reference, disposition authority and disposition-executed-at, with substantive content, rationale and personal data removed.", "Erasure of personal data is requested through the adopting Dimension's privacy process; where an overriding legal obligation or the defence of legal claims applies, this model records a retention hold with its basis instead of erasing, and records the redaction actually applied.", "Destruction is blocked while the decision still confers rights or imposes undischarged obligations, or while a contestation is open; the block is released only by revocation, expiry or closure of the contestation.", "Deletion of a referenced audit record, party record or signature object is never performed or claimed here; those are governed entirely by their owning models." ] }, "roles": [ { "name": "Decision-context owner", "responsibilities": [ "Maintain the model package, its code lists, vocabularies and referenced-model bindings", "Approve breaking changes and publish migration notes", "Ensure organisational separation from the approvers whose decisions are recorded" ] }, { "name": "Deciding authority", "responsibilities": [ "Take the decision within the bounds of the conferring instrument and its limits", "Accept the risk and attach terms, conditions and validity to the outcome", "Trigger reauthorization, revocation or suspension when conditions change" ] }, { "name": "Decision recorder or secretariat", "responsibilities": [ "Capture sessions, attendance, tallies, dissent and declarations at the time of the act", "Issue serial-numbered notices and minutes and maintain the register sequence", "Fix the input package and record its digest and as-of times" ] }, { "name": "Assurance and review role", "responsibilities": [ "Run completeness validation against the bound profile and report gaps", "Check separation-of-duties, dual-authorization and recusal facts", "Verify that alignment mappings were checked against current target versions" ] }, { "name": "Records and privacy liaison", "responsibilities": [ "Assert retention classes and holds and coordinate disposition with the records model", "Handle erasure and access requests and record the redaction applied", "Coordinate mandatory disclosures to data subjects, auditors and supervisory authorities" ] } ], "access": { "default_rule": "Least privilege with role-scoped read. Existence, decision type, outcome class and validity window are readable by the affected and accountable parties; rationale, input package, deliberation, dissent and personal data are restricted to participants, the assurance role and holders of an explicit grant. Write access is limited to the role that owns the corresponding function.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "The affected person receives the rationale and the required explanation of an automated or significantly affecting decision, redacted only for third-party personal data and genuine confidentiality.", "Auditors, supervisory authorities and courts obtain access on a recorded legal basis that overrides the default restriction.", "Deliberation held in camera is sealed to participants and the assurance role, with a recorded unsealing authority and condition.", "Legal hold suspends both disposition and routine redaction until released.", "Emergency break-glass access is possible where an authorised grant path is unavailable, and is valid only with a recorded justification and mandatory post-hoc review." ], "audit_requirements": [ "Every state transition, outcome recording, supersession, revocation and override must be emitted as an event to the adopting Dimension's referenced audit-log model.", "Every read of restricted deliberation content, rationale or personal data, and every break-glass access, must be emitted to the same referenced audit-log model with the acting party and an RFC 3339 instant.", "This model states only which events must be logged and where the log reference resides; audit-record structure, immutability, storage, evaluation and retention are defined and owned by the referenced audit model and are out of scope here." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Owner or maintainer", "Model ID and registry entry" ], "read_order": [ "AGENTS.md first: read Name, Type, Model ID and the four URLs before any read or write, including when storage is MongoDB or access is through MCP.", "Specification URL: read scope, in-scope and out-of-scope lists and boundary notes, so that target-owned concepts are not recreated locally.", "Storage type URL: read the projection rules that map canonical semantics onto the concrete store or file layout.", "Interface URL: read the permitted operations, access scopes and exception paths before requesting data.", "Processes URL: read function preconditions and effects, and in particular the delete, retention and tombstone path, before any destructive request.", "Composition links last: resolve the party, authorization evaluation, rule logic, records, audit, signature and process models before creating decision instances." ] } }, "coverage": { "claim": "Single-provider (Claude) coverage of one decision or approval occurrence: identity and framing, authority, mandate and participation, inputs and applied criteria, option set and rationale, outcome with conditions and validity window, status lifecycle, oversight and contestation, and attribution, record, access and external alignment — 6 bundles, 12 layers, 25 findings, 100 questions, 6 artifacts and 10 functions grounded in 13 tier-1/tier-2 primary sources plus 1 tier-4 mirror. Coverage is claimed only against the consulted sources and only for the generic occurrence. Collective decision rules (quorum, thresholds, proxies, abstention counting) are a declared evidence gap; several coverage-checklist notes assert elements the structure does not actually carry; the applied rule-set pin, recusal, signature and retention/access setters have no function; and no second provider corroborated any element. No universal completeness and no domain-specific completeness (judicial, clinical, corporate-governance procedure) is claimed.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Master-system reference first, governed IRI second, minted UUID/ULID third; explicit prohibition on date-based identity and explicit separation from subject, notice and rule-set identifiers." }, { "dimension": "lifecycle", "status": "covered", "notes": "Status vocabulary, legal transitions, transition authority, supersession, revocation, suspension and reauthorization triggers, with immutability of the outcome core after the decided state." }, { "dimension": "relationships", "status": "covered", "notes": "Subject references, upstream and downstream decisions, containing process, participants and roles, supersession links and hand-over targets, all as references into owning models." }, { "dimension": "temporal", "status": "covered", "notes": "RFC 3339 with seconds and explicit offset; decided-at, started-at, ended-at, valid-from and valid-until as event times separated from recorded-at and ingested-at; input as-of times recorded per item." }, { "dimension": "provenance", "status": "covered", "notes": "PROV-style qualified association with role and plan, delegation chain, wasInformedBy and generation links, plus distinction between assertions by the deciding system and by third parties." }, { "dimension": "ownership", "status": "covered", "notes": "Authority-holding position distinct from the natural person, continuing accountability after the decision, rule-set owner, mapping owner and designated model owner in the service layers." }, { "dimension": "validation", "status": "covered", "notes": "Completeness validation against a bound profile that reports without enforcing; limit-check evidence, self-approval detection, signature verification referenced externally, conformance-evidence question." }, { "dimension": "access", "status": "covered", "notes": "Role-scoped default with content-level scopes, confidentiality markings, mandatory disclosure exceptions, sealed deliberation and break-glass with post-hoc review." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention class and hold asserted locally; disposition executed by the referenced records model or Dimension policy; explicit tombstone element list and destruction blocks while rights or contestations are live." }, { "dimension": "interoperability", "status": "covered", "notes": "Alignments to DMN, PROV-O, XACML, ODRL and RiC-O as versioned mappings with recorded loss cases and an explicit no-conformance-without-evidence policy." }, { "dimension": "authority and delegation", "status": "covered", "notes": "Conferring instrument with version and effective dates, holding position, delegation chain and validity period, reserved non-delegable act, competence limits and escalation." }, { "dimension": "evidence and rationale", "status": "covered", "notes": "Fixed input package with digests and as-of times, sufficiency and uncertainty treatment, rationale sufficient for contestation, and the explanation owed to affected parties." }, { "dimension": "collective decision rules", "status": "gap", "notes": "Quorum, majority thresholds, proxy and abstention counting have no normative support in any consulted primary source; the finding carries them as adopting-Dimension parameters and is explicitly declared a gap rather than canonical structure." }, { "dimension": "measurement", "status": "covered", "notes": "Materiality tiers against a named scale, authority limits as quantities with units or classes, and vote tallies as counted values; physical sensing is not applicable since measured quantities enter only as referenced inputs." }, { "dimension": "automated decision oversight", "status": "covered", "notes": "Modality classification, permitting basis for solely automated decisions, oversight assignment and competence, override and reversal events, and evidence that intervention was substantive." } ], "known_omissions": [ "Dissenting-opinion structure and minority-report handling are modelled from records practice; no consulted primary source defines them normatively.", "Jurisdiction and venue of the deciding authority are captured only as a limit class, not as a full spatial or legal-geography model.", "Cost, effort and decision-latency measures are not modelled; they belong to a process performance model.", "Group decision techniques (weighted scoring, multi-criteria analysis, consensus protocols) are referenced only as criteria, with no internal structure.", "Negotiated and conditional multi-party agreements where approval is mutual rather than unilateral are only partially served by the assigner-style role model.", "Machine-to-machine decision batches at high volume are addressable but no sampling or aggregation semantics are provided." ], "conflicts": [ "XACML's four decision values do not map one-to-one onto approval outcomes: conditional approval and deferral have no target value, and Indeterminate is an evaluator error state rather than a human inability to decide. Recorded as a mapping loss, not resolved.", "DMN's decisionMaker and decisionOwner are design-time model roles, whereas PROV association identifies the agent that actually decided an occurrence; conflating them is a common and material error, so both are carried separately.", "GDPR Article 22 and AI Act Article 14 have different triggers and different remedies: nominal human involvement may satisfy an oversight design duty while still failing the 'solely automated' test, so the two are modelled as distinct questions.", "21 CFR 11.50 requires the meaning of a signature to be displayed, while many general electronic-signature profiles carry only signer identity and time; meaning must therefore be modelled explicitly rather than inferred from a signature object.", "NIST's fixed authorization termination date competes with event-driven and ongoing authorization; the model supports both and requires the validity mode to be stated rather than assumed.", "RiC-O Mandate and DMN AuthorityRequirement both express 'authority' but at different layers — an archival mandate over an agent versus a modelling dependency on a knowledge source — and are aligned separately without merging." ], "regional_assumptions": [ "GDPR and the AI Act are EU instruments used here as structural evidence for contestation, explanation and oversight; other jurisdictions impose different or sectoral duties and the corresponding elements may be optional there.", "21 CFR Part 11 applies to FDA-regulated activity in the United States; its signature-meaning requirement is adopted here as good general practice, not as a universal legal requirement.", "NIST SP 800-37 and SP 800-53 describe US federal practice and are used as a worked normative pattern for formal approval and multi-party control, not as globally binding requirements.", "Quorum, board composition and written-procedure ratification follow local company, association or public law and are left entirely to the adopting Dimension.", "Local offsets are preserved because deadlines, validity windows and contest periods are frequently defined in local civil time rather than UTC." ], "adversarial_checks": [ "Tried to place policy evaluation, combining algorithms and obligation discharge inside the model because the outcome vocabulary aligns with XACML; rejected, since a reference to an evaluator confers no ownership of evaluation, and the concepts were moved to a REFERENCE link and boundary note.", "Tried to own an audit trail because decisions require accountability; rejected, and reduced to naming the events that must be emitted and where the log reference lives, with structure, immutability and log retention left to the audit model.", "Tested whether approval is merely authorization: counterexample of approving a manuscript, a design or a set of minutes, which grants no access right at all; the model therefore does not assume access-control semantics in its outcome vocabulary.", "Tested whether every decision has a human agent: counterexample of solely automated determinations under GDPR Article 22; agent kind is therefore a variable and human oversight is a separate, conditional finding rather than an assumption.", "Tested 'decision date plus committee' as an identity key; rejected under the identity priority rule, since a date is not an identifier and two decisions by the same body on the same day are routine.", "Tried to import DMN's design-time decision requirement structure as local content; rejected, because that model is authored and versioned elsewhere, leaving only a version pin and a deviation record locally.", "Tried to own retention scheduling because decisions must be kept for long periods; rejected, and reduced to an asserted retention class, a hold flag and a tombstone contract, with disposition executed by the records model or Dimension policy." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "event", "status": "deferred", "rationale": "The frozen registry record carries entry_kind 'standalone-mm' (a registry-entry axis) while the result declares 'event' (an ontological axis); the two are not comparable and neither was reconciled against the parent WM-ACT-002 or against the enumerated Vercy kind vocabulary, which is not in this pack and which a no-tools audit cannot resolve. The result's own scope statement ('in the PROV sense of an activity that occurred over a period'), the NAV.ACT.DEC path and ACT.DEC domain tag, the start/end activity times in q-attr-times, and the participation and plan structure all describe a period-bounded occurrence rather than an instantaneous event. The registry review_state is already 'boundary-review-required'. Carry 'event' forward unchanged so the draft remains publishable, but do not ratify it: the token must be resolved against the kind vocabulary and the parent record before this entry leaves candidate status." }, "decisions": [ { "concept": "Aggregate root: one bounded decision or approval occurrence", "disposition": "accepted with a required granularity rule", "rationale": "The root holds together — authority, inputs, choice, outcome and lifecycle all attach to a single occurrence and nothing in the structure needs a larger root. But q-subject-unit leaves the unit itself an open question (a single approval step, a whole chain, or one item in a multi-item session), so two adopters could model the same reality at different granularity and both claim conformance. Accept the root; require a stated default unit with chains represented as linked occurrences before the entry leaves candidate status." }, { "concept": "Entry kind 'event' against PROV activity framing and the registry's 'standalone-mm'", "disposition": "deferred to boundary review; token carried unchanged", "rationale": "Two different classification axes are in play and neither is reconciled in the pack. The scope statement, parent WM-ACT-002 Activity, ACT.DEC nav path and the explicit start/end activity times describe a perdurant over a period, which 'event' understates. A no-tools single-provider audit cannot ratify the token without the enumerated kind vocabulary and the parent record." }, { "concept": "af-authority-instrument declared as a locally owned artifact", "disposition": "rejected as owned artifact; demoted to referenced instrument", "rationale": "A board resolution, policy, standing order or delegation letter is a long-lived instrument authorising many decisions across time. Owning it on a single occurrence forks an authority register that this same model refuses to duplicate elsewhere: f-decision-rights-and-limits explicitly resolves limits against an external threshold register, and f-roles-and-participation explicitly refuses to fork party master data. The identical rule must apply to the conferring instrument." }, { "concept": "af-deliberation-minutes cardinality (one session evidences many decisions)", "disposition": "accepted only as a referenced or extracted artifact with an explicit N:1 rule", "rationale": "Minutes and voting records are session-level serials, and the model's own q-subject-unit admits that one occurrence may be one item within a multi-item session. A single minutes document therefore evidences many occurrences and cannot be exclusively owned by one. Publish it as a reference plus per-item extract, mirroring the 'resolution extract' form already accepted for the decision notice." }, { "concept": "af-contestation-dossier ownership versus the review as its own occurrence", "disposition": "reclassified: dossier belongs to the review occurrence; original keeps a typed link", "rationale": "A review determination has its own authority, participants, inputs, option set and outcome — it is another instance of this same model, related by the confirm/amend/replace/remit relation that q-con-outcome already names. Holding the appeal submission and the determination inside the original decision inflates the aggregate root and duplicates the outcome and notice surface that b-outcome already owns." }, { "concept": "af-signature-manifestation without a named host record", "disposition": "accepted with a mandatory host-record binding", "rationale": "The model denies the rationale its own artifact on the ground that it travels inside the decision notice, yet grants a free-floating signature block artifact with no declared carrier. Signatures are manifested on a carrier — notice, minutes or record — and each manifestation must name its host to stay consistent with q-sig-binding's non-excision and non-transfer requirement and with the model's own artifact-duplication rule." }, { "concept": "SRC-014, a tier-4 non-primary mirror of NIST SP 800-37 Appendix F", "disposition": "accepted as a corroborating pointer only; re-pin the citation to SRC-005", "rationale": "The mirror is cited in four load-bearing places (outcome value, conditions and validity, supersession, notice issuance) but never as sole support — the authoritative SRC-005 accompanies it every time, so this is not a sole-support defect. Even so, a non-primary third-party rendering must carry no normative weight; cite Appendix F through SRC-005 and retain the mirror only as a convenience locator." }, { "concept": "SRC-006 pinned to the CFR 2023 annual edition on a 2026-08-29 run", "disposition": "deferred pending a live re-pin of the edition", "rationale": "The 21 CFR Part 11 citation is fixed to an annual edition three years older than the run, and its signature-meaning requirement is load-bearing for f-signature-and-attestation and for the fourth declared conflict. A stale edition pin on a regulatory source is a concrete verification defect. This audit has no tools and cannot confirm the current edition, so the item is deferred to the live verification hold rather than resolved here." }, { "concept": "Decorative source_refs on the declared-gap finding f-collective-decision-rules", "disposition": "gap accepted; source_refs marked contextual rather than normative support", "rationale": "The finding honestly states that no consulted primary source normatively defines quorum, majority thresholds, proxies or abstention counting, yet it still carries SRC-011, SRC-012 and SRC-013, and fn-record-deliberation-and-votes carries the same three. Downstream validators read source_refs as support, which would silently promote a declared gap to grounded structure; the refs must be labelled contextual or removed." }, { "concept": "Coverage-checklist notes asserting elements absent from the structure", "disposition": "rejected as coverage evidence; checklist must be reduced to what the structure carries", "rationale": "The checklist marks dimensions 'covered' on the strength of an explicit tombstone element list, a prohibition on date-based identity, break-glass with post-hoc review, immutability of the outcome core after the decided state, and a designated model owner 'in the service layers'. No question, artifact or function carries any of these, the structure contains no service layer at all, and the identity prohibition exists only in the adversarial-check prose. Publishing those notes as coverage overstates the draft." }, { "concept": "Function coverage gaps against content the model declares locally owned", "disposition": "deferred; functions cannot be added in single-provider mode", "rationale": "No function pins the applied rule-set version or records a deviation, which is the only content f-criteria-and-rule-reference keeps locally; none records recusals, conflict declarations or separation-of-duties observations; none applies a signature with its declared meaning despite the 21 CFR 11.50 emphasis; and none sets the retention class, legal hold or access markings. The operation surface cannot write parts of the model it claims to own. add_functions must stay empty here, so this is logged for the next pass." }, { "concept": "Duplicate emergency-override and ratification questions across three bundles", "disposition": "accepted with a disambiguation requirement", "rationale": "q-limit-emergency (exceeding a competence limit and its after-the-fact ratification), q-con-emergency (emergency overrides and ratifications of the decision) and q-hov-intervention (an automated output disregarded, overridden or reversed) overlap enough that adopters may answer them with divergent facts about the same act. Keep all three but scope them explicitly to authority breach, outcome override and automation override, with cross-references." }, { "concept": "Empty frozen relationship contract against asserted REFERENCE links", "disposition": "deferred; relations_ref must be populated before boundary review closes", "rationale": "The adversarial checks claim that policy evaluation was 'moved to a REFERENCE link', and boundary_notes name seven neighbours, but the frozen relationship contract is empty and relations_ref, contains_ids and aligned_model_ids are all blank; only WM-ACT-002 is identified by model ID. The ownership boundary is therefore stated in prose and unverifiable against the registry." }, { "concept": "Provider-declared cross-vocabulary conflicts (XACML values, DMN versus PROV roles, GDPR 22 versus AI Act 14, signature meaning, fixed versus event-driven authorization, RiC-O Mandate versus DMN AuthorityRequirement)", "disposition": "accepted as recorded mapping losses; not escalated to critical conflicts", "rationale": "Each is carried as an explicit non-merge with both sides retained and the loss documented, which is the correct treatment for tension between external vocabularies. None contradicts another part of this result and none prevents a public reviewable draft, so critical_conflicts stays empty rather than being padded with the owner-authorized Grok waiver." }, { "concept": "Retention, disposition and access boundary", "disposition": "accepted", "rationale": "f-record-and-disposition-boundary keeps only the record reference, an asserted retention class and a hold flag while appraisal, scheduling and destruction execute in the records model or Dimension policy, and f-access-and-disclosure keeps access parameters and confidentiality markings while evaluation, enforcement and read logging stay with the referenced authorization and audit models. Both match the boundary notes and the refusal to own the audit trail; only the unrealised tombstone element list flagged in the checklist decision needs correction." } ], "publicationHolds": [ "LIVE SOURCE AND VERSION HOLD: every published artifact must state that all 14 source URLs and version pins are unverified by this audit and must be re-resolved live before publication — in particular DMN 1.5 and the DMN15.xsd 2023-03-24 namespace date, RiC-O 1.1 (2025-05-22) behind an ICA landing page, NIST SP 800-53 Rev. 5 upd1, SP 800-37 Rev. 2, XACML 3.0, ODRL 2.2, PROV-O, RFC 3339, the GDPR and AI Act OJ texts (original rather than consolidated), and SRC-006, which is pinned to the CFR 2023 annual edition on a 2026-08-29 run.", "SINGLE-PROVIDER HOLD: every published artifact must visibly state that Grok was waived by the repository owner at 2026-08-29T09:06:27Z after repeated structured-output failures, that no independent second-provider review corroborated any bundle, layer, finding, question, artifact or function, that the only cross-check is this no-tools adversarial audit of the same provider's output, and that the result therefore remains a reviewable draft rather than an accepted model.", "COVERAGE-CLAIM HOLD: the coverage checklist must be corrected before publication. The tombstone element list, the prohibition on date-based identity keys, break-glass access with post-hoc review, immutability of the outcome core after the decided state, and a model owner designated 'in the service layers' are asserted in checklist notes but appear in no question, artifact or function, and the structure has no service layer.", "REGISTRY RECONCILIATION HOLD: the entry_kind axis collision ('event' versus 'standalone-mm'), the empty relationship contract and blank relations_ref against seven prose-named neighbours, the placeholder owner_or_maintainer, the provenance field which records only Claude passes and not the owner waiver or this audit, and source_version_or_year 2026-08-22 predating the run must all be reconciled before the record leaves boundary-review-required.", "ARTIFACT OWNERSHIP HOLD: the authority or delegation instrument, the deliberation minutes and voting record, and the contestation dossier must not be published as artifacts owned by a single decision occurrence. They are respectively an externally governed instrument, a session-level serial evidencing many occurrences, and the record of a separate review occurrence; publish them as references, extracts or links pending restructuring.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Verify against WM-ACT-002's actual finding and question set that the generic activity surface (identity, temporal bounds, participation, status machinery) is genuinely not restated here; the 0.06 overlap factor and the parent boundary note are asserted, not demonstrated, and the parent record is not in this pack.", "Populate the relationship contract with model IDs and link types for the seven prose-named neighbours — audit trail / event log, records management and disposition, decision logic / DMN decision requirement graph, the subject of the decision, party and agent master data, the authorization PDP/PEP, and the electronic signature and seal model — and set relations_ref on the registry record.", "Close the function gaps identified in this audit: recording the applied rule-set version pin and any deviation, recording recusals, conflict declarations and separation-of-duties observations, applying a signature with its declared meaning, and setting the retention class, legal hold and access markings.", "Resolve the default granularity rule for one occurrence (single approval act by one authority instance versus a whole approval chain versus one item within a multi-item session) and specify how chains and multi-item sessions are represented as linked occurrences.", "Determine whether the RFC 3339 pin needs supplementing by a later IETF timestamp specification, and whether preserving local offsets requires an explicit rule for offset changes (daylight-saving or legal time changes) that fall inside a validity window or a contestation period.", "Consult at least one archival, records-management or administrative-decision standard from outside the EU and US to test the declared regional assumptions, which currently rest entirely on GDPR, the AI Act, 21 CFR Part 11, NIST SP 800-37/800-53 and RiC-O." ] }, "statistics": { "sources": 14, "bundles": 6, "layers": 12, "findings": 25, "questions": 100, "artifacts": 6, "functions": 10 } }