# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T06:37:07Z", "synthesisSha256": "d26622f855fc2f579fb897114d51b872ce8bf8ab92338203c11cc7b28ab4e4c7", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ACT-035", "registryId": "vr.wm-act-035", "name": "Test Execution", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "event", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.TST" ], "tags": [ "test", "execution", "act.tst" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-035-test-execution/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-035", "model": { "registry_id": "vr.wm-act-035", "model_id": "WM-ACT-035", "name": "Test Execution", "entry_kind": "event", "purpose": "Represent one attributable occurrence of running a versioned test procedure against identified subjects in a declared context, producing preserved observations, evidence and bounded result assertions.", "scope_statement": "Owns execution identity and lineage, source-qualified classification, immutable bindings to test definition, criterion, expected result and oracle, run-specific subject and configuration snapshots, inputs and samples, environment, equipment and tools, actor and automation assignments, authorization and safety envelope, lifecycle and step events, source observations, evidence pointers, comparison and verdict assertions, anomalies, rerun and review lineage, projections, access and retention. Test case, requirement, subject, product, configuration, sample, environment, resource, instrument, dataset, observation, artifact, defect, incident, risk, assessment, verification or validation claim and generic audit masters remain external.", "in_scope": [ "Execution identity, attempt and lineage, procedure and criterion revisions, expected results, oracle, subject configuration, inputs, environment, tools, resources, actors and authority", "Lifecycle and step occurrences, deviations, observations, measurements, evidence, comparisons, outcomes, verdicts, confidence, anomalies and external issue links", "Rerun, reproducibility, review, invalidation, correction, supersession, interoperability, access, retention and safe agent operations" ], "out_of_scope": [ "Test case, requirement, subject, product, configuration, sample, environment, instrument, dataset, observation, artifact, defect, incident, risk, assessment, verification or validation claim or audit-log master lifecycle", "Treating completion as pass, pass as compliance, failure as a defect, one run as reproducibility, or a rerun as a mutable revision of the first execution", "Implementing a test runner, laboratory information system, observability backend, issue tracker, certification scheme or universal legal compliance and claiming full ISO conformance from public abstracts" ], "boundary_notes": [ { "neighbor": "Test Case / Procedure / Requirement / Criterion", "distinction": "Reusable intent and acceptance logic are external versioned definitions. The execution binds the exact revision and records what actually occurred.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009" ] }, { "neighbor": "Subject / Sample / Environment / Instrument", "distinction": "The execution owns source-qualified snapshots and usage assertions while external masters keep identity, lifecycle and authority.", "source_refs": [ "SRC-003", "SRC-005", "SRC-007", "SRC-010" ] }, { "neighbor": "Observation / Measurement / Evidence Artifact", "distinction": "The execution organizes run-scoped observations and pointers, but source observation and artifact masters retain method, integrity and custody provenance.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-008" ] }, { "neighbor": "Assessment / Verification / Validation / Certification", "distinction": "A test execution may supply evidence to a broader assessment or assurance claim. Its bounded verdict does not itself establish system compliance, fitness or certification.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-010" ] }, { "neighbor": "Defect / Incident / Risk / Nonconformity", "distinction": "A failed or anomalous run can link to external issue masters through source-qualified correlation or causality assertions; it does not create or control them automatically.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ] } ] }, "sources": [ { "id": "SRC-001", "title": "ISO/IEC/IEEE 29119 series: Software and systems engineering, Software testing", "organization": "International Organization for Standardization", "url": "https://committee.iso.org/sites/jtc1sc7/home/projects/flagship-standards/isoiecieee-29119-series.html", "version_or_date": "Official ISO/IEC JTC 1/SC 7 series overview, accessed 2026-09-06", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "States that the series covers organizational, management and dynamic test processes, with process outputs documented by Part 3 and test design techniques in Part 4." }, { "id": "SRC-002", "title": "ISO/IEC/IEEE 29119-3:2021 Software testing, Part 3: Test documentation", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/79429.html", "version_or_date": "ISO/IEC/IEEE 29119-3:2021, Edition 2; official catalogue abstract only", "source_type": "standard", "primary_source": false, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Identifies test documentation as outputs of test processes and establishes the neighboring documentation standard; public abstract does not support clause-level conformance." }, { "id": "SRC-003", "title": "ISO/IEC 17025:2017 General requirements for the competence of testing and calibration laboratories", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/66912.html", "version_or_date": "ISO/IEC 17025:2017, Edition 3; confirmed 2023; official catalogue summary", "source_type": "standard", "primary_source": false, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Establishes competence, impartiality and consistent laboratory operation as result-confidence concerns, without exposing clause-level requirements in the public page." }, { "id": "SRC-004", "title": "Evaluation and Report Language (EARL) 1.0 Schema", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/EARL10-Schema/", "version_or_date": "W3C Working Group Note, 2 February 2017", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Defines assertions that bind assertor, test subject, test criterion, result and test mode; distinguishes pass, fail, cannot tell, inapplicable and untested outcomes." }, { "id": "SRC-005", "title": "OSCAL Assessment Layer: Assessment Results Model", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-results/", "version_or_date": "OSCAL assessment results documentation, updated 3 March 2025", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Defines plan-linked assessment results with subjects, assets, performed actions, observations, evidence, findings, risks, attestations and back matter." }, { "id": "SRC-006", "title": "OSCAL Assessment Results Model v1.2.0 XML Format Reference", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/OSCAL-Reference/models/v1.2.0/assessment-results/xml-reference/", "version_or_date": "OSCAL 1.2.0 XML reference", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Provides machine identities and structured assessment-result semantics used for a version-pinned, loss-aware security-assessment projection." }, { "id": "SRC-007", "title": "Observations, Measurements, and Samples", "organization": "Open Geospatial Consortium", "url": "https://www.ogc.org/standards/om/", "version_or_date": "OGC Abstract Specification Topic 20, OGC 20-082r4 and ISO 19156:2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Defines conceptual exchange semantics for observation acts, their results, observed features, procedures and sampling features across scientific and technical communities." }, { "id": "SRC-008", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Defines entities, activities, agents, plans, usage, generation, association, delegation, derivation, revision and invalidation needed for attributable test evidence." }, { "id": "SRC-009", "title": "Robot Framework User Guide", "organization": "Robot Framework Foundation", "url": "https://robotframework.org/robotframework/7.4.2/RobotFrameworkUserGuide.html", "version_or_date": "Robot Framework 7.4.2 user guide", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Documents executable test suites and cases, setup and teardown, status, messages, machine-readable output.xml and its result.xsd schema, with versioned output compatibility concerns." }, { "id": "SRC-010", "title": "NASA Systems Engineering Handbook, Appendix I: Verification and Validation Plan Outline", "organization": "National Aeronautics and Space Administration", "url": "https://www.nasa.gov/reference/system-engineering-handbook-appendix/", "version_or_date": "NASA/SP-2016-6105 Rev2 appendix, official web projection", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Distinguishes test, analysis, inspection and demonstration, and calls for test-article pedigree, support equipment, implementation flow, results and certification evidence." }, { "id": "SRC-011", "title": "OpenTelemetry Test Attributes", "organization": "OpenTelemetry", "url": "https://opentelemetry.io/docs/specs/semconv/registry/attributes/test/", "version_or_date": "Semantic Conventions 1.44.0 test attribute registry, development stability", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Defines development-stage software-test attributes for case name, case result status, suite name and suite-run status including aborted, timed out and in progress." }, { "id": "SRC-012", "title": "NIST Privacy Framework", "organization": "National Institute of Standards and Technology", "url": "https://www.nist.gov/privacy-framework", "version_or_date": "Privacy Framework 1.0; 1.1 initial public draft available", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Grounds purpose-aware privacy risk governance across data collection, processing, sharing, retention and disposal." }, { "id": "SRC-013", "title": "Disposing of records", "organization": "The National Archives, United Kingdom", "url": "https://www.nationalarchives.gov.uk/information-management/manage-information/policy-process/disposal/", "version_or_date": "Official records-management guidance, accessed 2026-09-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Grounds retention and responsible disposition based on business, legal, accountability and historical requirements." }, { "id": "SRC-014", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002, updated by RFC 9557", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T06:22:00Z", "relevance": "Defines seconds and explicit-offset timestamps for execution, step, observation, evidence and knowledge events." } ], "structure": { "bundles": [ { "id": "execution-identity-definition-and-procedure", "name": "Execution identity, definition and procedure", "description": "Defines the event root and binds it to reusable test intent without copying the test specification.", "rationale": "A test execution is an occurrence with its own identity. The case, procedure, criterion and requirement are versioned external definitions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-008" ], "layers": [ { "id": "execution-definition-identity-and-lineage", "name": "Execution definition, identity and lineage", "description": "Pins the event boundary, source profile, identity and attempt lineage.", "source_refs": [ "SRC-004", "SRC-008", "SRC-011", "SRC-014" ], "findings": [ { "id": "test-execution-definition-profile-classification-and-neighbor-boundary", "name": "Test execution definition, profile, classification and neighbor boundary", "description": "Source-qualified execution type, domain profile, inclusion and exclusion rules, and distinctions from test case, assessment, experiment, inspection, monitoring and verification claim.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-007", "SRC-010" ], "questions": [ { "id": "test-execution-definition-profile-classification-and-neighbor-boundary-q01", "text": "What identities, types, roles, scope, versions and explicit values define test execution definition, profile, classification and neighbor boundary?", "kind": "classification", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "test-execution-definition-profile-classification-and-neighbor-boundary-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support test execution definition, profile, classification and neighbor boundary?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "test-execution-definition-profile-classification-and-neighbor-boundary-q03", "text": "How is test execution definition, profile, classification and neighbor boundary validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "test-execution-definition-profile-classification-and-neighbor-boundary-data", "name": "Test execution definition, profile, classification and neighbor boundary data", "description": "Structured test-execution data for test execution definition, profile, classification and neighbor boundary.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "test-execution-definition-profile-classification-and-neighbor-boundary-record", "name": "Test execution definition, profile, classification and neighbor boundary record", "description": "Versioned evidence-bearing test-execution record for test execution definition, profile, classification and neighbor boundary with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus test-execution-definition-profile-classification-and-neighbor-boundary assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "execution-identifier-name-attempt-version-source-predecessor-rerun-and-lineage", "name": "Execution identifier, name, attempt, version, source, predecessor, rerun and lineage", "description": "Stable execution identity, source run ID, attempt number, schema and profile version, prior execution link, rerun reason and correction or supersession lineage.", "source_refs": [ "SRC-006", "SRC-008", "SRC-009", "SRC-011" ], "questions": [ { "id": "execution-identifier-name-attempt-version-source-predecessor-rerun-and-lineage-q01", "text": "What identities, types, roles, scope, versions and explicit values define execution identifier, name, attempt, version, source, predecessor, rerun and lineage?", "kind": "identity", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "execution-identifier-name-attempt-version-source-predecessor-rerun-and-lineage-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support execution identifier, name, attempt, version, source, predecessor, rerun and lineage?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "execution-identifier-name-attempt-version-source-predecessor-rerun-and-lineage-q03", "text": "How is execution identifier, name, attempt, version, source, predecessor, rerun and lineage validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "execution-identifier-name-attempt-version-source-predecessor-rerun-and-lineage-data", "name": "Execution identifier, name, attempt, version, source, predecessor, rerun and lineage data", "description": "Structured test-execution data for execution identifier, name, attempt, version, source, predecessor, rerun and lineage.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-008", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "execution-identifier-name-attempt-version-source-predecessor-rerun-and-lineage-record", "name": "Execution identifier, name, attempt, version, source, predecessor, rerun and lineage record", "description": "Versioned evidence-bearing test-execution record for execution identifier, name, attempt, version, source, predecessor, rerun and lineage with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus execution-identifier-name-attempt-version-source-predecessor-rerun-and-lineage assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-006", "SRC-008", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "test-definition-criterion-procedure-expectation-and-oracle", "name": "Test definition, criterion, procedure, expectation and oracle", "description": "Binds the occurrence to the exact reusable definitions used at run time.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009" ], "findings": [ { "id": "test-case-procedure-method-revision-step-plan-parameter-and-applicability-binding", "name": "Test case, procedure, method, revision, step plan, parameter and applicability binding", "description": "External test definition and procedure IDs, immutable revision or digest, method, ordered planned steps, parameters, applicability and permitted variation.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009" ], "questions": [ { "id": "test-case-procedure-method-revision-step-plan-parameter-and-applicability-binding-q01", "text": "What identities, types, roles, scope, versions and explicit values define test case, procedure, method, revision, step plan, parameter and applicability binding?", "kind": "requirement", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "test-case-procedure-method-revision-step-plan-parameter-and-applicability-binding-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support test case, procedure, method, revision, step plan, parameter and applicability binding?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "test-case-procedure-method-revision-step-plan-parameter-and-applicability-binding-q03", "text": "How is test case, procedure, method, revision, step plan, parameter and applicability binding validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "test-case-procedure-method-revision-step-plan-parameter-and-applicability-binding-data", "name": "Test case, procedure, method, revision, step plan, parameter and applicability binding data", "description": "Structured test-execution data for test case, procedure, method, revision, step plan, parameter and applicability binding.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "test-case-procedure-method-revision-step-plan-parameter-and-applicability-binding-record", "name": "Test case, procedure, method, revision, step plan, parameter and applicability binding record", "description": "Versioned evidence-bearing test-execution record for test case, procedure, method, revision, step plan, parameter and applicability binding with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus test-case-procedure-method-revision-step-plan-parameter-and-applicability-binding assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "requirement-criterion-expected-result-acceptance-rule-tolerance-and-oracle", "name": "Requirement, criterion, expected result, acceptance rule, tolerance and oracle", "description": "External requirement and test criterion, expected value or behavior, acceptance rule, tolerance, oracle type, comparator revision and ambiguity handling.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ], "questions": [ { "id": "requirement-criterion-expected-result-acceptance-rule-tolerance-and-oracle-q01", "text": "What identities, types, roles, scope, versions and explicit values define requirement, criterion, expected result, acceptance rule, tolerance and oracle?", "kind": "requirement", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "requirement-criterion-expected-result-acceptance-rule-tolerance-and-oracle-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support requirement, criterion, expected result, acceptance rule, tolerance and oracle?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "requirement-criterion-expected-result-acceptance-rule-tolerance-and-oracle-q03", "text": "How is requirement, criterion, expected result, acceptance rule, tolerance and oracle validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "requirement-criterion-expected-result-acceptance-rule-tolerance-and-oracle-data", "name": "Requirement, criterion, expected result, acceptance rule, tolerance and oracle data", "description": "Structured test-execution data for requirement, criterion, expected result, acceptance rule, tolerance and oracle.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "requirement-criterion-expected-result-acceptance-rule-tolerance-and-oracle-record", "name": "Requirement, criterion, expected result, acceptance rule, tolerance and oracle record", "description": "Versioned evidence-bearing test-execution record for requirement, criterion, expected result, acceptance rule, tolerance and oracle with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus requirement-criterion-expected-result-acceptance-rule-tolerance-and-oracle assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "subject-configuration-environment-and-resources", "name": "Subject, configuration, environment and resources", "description": "Freezes what was tested and the conditions and means of the run.", "rationale": "A result is uninterpretable when subject revision, sampled portion, environment, dependencies, tools or measurement traceability are missing.", "source_refs": [ "SRC-003", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ], "layers": [ { "id": "subject-sample-input-and-configuration", "name": "Subject, sample, input and configuration", "description": "Identifies the tested thing and its run-specific state without taking ownership of the subject master.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-010" ], "findings": [ { "id": "subject-identity-type-version-build-pedigree-configuration-state-and-scope", "name": "Subject identity, type, version, build, pedigree, configuration, state and scope", "description": "External subject ID and type, version or build, provenance or test-article pedigree, frozen configuration, initial state, tested boundary and excluded portions.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-010" ], "questions": [ { "id": "subject-identity-type-version-build-pedigree-configuration-state-and-scope-q01", "text": "What identities, types, roles, scope, versions and explicit values define subject identity, type, version, build, pedigree, configuration, state and scope?", "kind": "identity", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "subject-identity-type-version-build-pedigree-configuration-state-and-scope-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support subject identity, type, version, build, pedigree, configuration, state and scope?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "subject-identity-type-version-build-pedigree-configuration-state-and-scope-q03", "text": "How is subject identity, type, version, build, pedigree, configuration, state and scope validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "subject-identity-type-version-build-pedigree-configuration-state-and-scope-data", "name": "Subject identity, type, version, build, pedigree, configuration, state and scope data", "description": "Structured test-execution data for subject identity, type, version, build, pedigree, configuration, state and scope.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "subject-identity-type-version-build-pedigree-configuration-state-and-scope-record", "name": "Subject identity, type, version, build, pedigree, configuration, state and scope record", "description": "Versioned evidence-bearing test-execution record for subject identity, type, version, build, pedigree, configuration, state and scope with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus subject-identity-type-version-build-pedigree-configuration-state-and-scope assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "sample-specimen-dataset-input-fixture-precondition-and-chain-of-custody", "name": "Sample, specimen, dataset, input, fixture, precondition and chain of custody", "description": "External sample or dataset identity, selection and preparation, fixture input, preconditions, custody, integrity, representativeness and consumption state.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-010" ], "questions": [ { "id": "sample-specimen-dataset-input-fixture-precondition-and-chain-of-custody-q01", "text": "What identities, types, roles, scope, versions and explicit values define sample, specimen, dataset, input, fixture, precondition and chain of custody?", "kind": "evidence", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "sample-specimen-dataset-input-fixture-precondition-and-chain-of-custody-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support sample, specimen, dataset, input, fixture, precondition and chain of custody?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "sample-specimen-dataset-input-fixture-precondition-and-chain-of-custody-q03", "text": "How is sample, specimen, dataset, input, fixture, precondition and chain of custody validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "sample-specimen-dataset-input-fixture-precondition-and-chain-of-custody-data", "name": "Sample, specimen, dataset, input, fixture, precondition and chain of custody data", "description": "Structured test-execution data for sample, specimen, dataset, input, fixture, precondition and chain of custody.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "sample-specimen-dataset-input-fixture-precondition-and-chain-of-custody-record", "name": "Sample, specimen, dataset, input, fixture, precondition and chain of custody record", "description": "Versioned evidence-bearing test-execution record for sample, specimen, dataset, input, fixture, precondition and chain of custody with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus sample-specimen-dataset-input-fixture-precondition-and-chain-of-custody assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "environment-equipment-instruments-and-dependencies", "name": "Environment, equipment, instruments and dependencies", "description": "Records execution conditions and the resources capable of influencing results.", "source_refs": [ "SRC-003", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ], "findings": [ { "id": "environment-location-time-platform-network-ambient-condition-and-dependency-snapshot", "name": "Environment, location, time, platform, network, ambient condition and dependency snapshot", "description": "Physical or virtual location, environment profile, platform, operating system, network, dependencies, ambient conditions, clock basis and run-time snapshots.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-014" ], "questions": [ { "id": "environment-location-time-platform-network-ambient-condition-and-dependency-snapshot-q01", "text": "What identities, types, roles, scope, versions and explicit values define environment, location, time, platform, network, ambient condition and dependency snapshot?", "kind": "spatial", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "environment-location-time-platform-network-ambient-condition-and-dependency-snapshot-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support environment, location, time, platform, network, ambient condition and dependency snapshot?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "environment-location-time-platform-network-ambient-condition-and-dependency-snapshot-q03", "text": "How is environment, location, time, platform, network, ambient condition and dependency snapshot validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "environment-location-time-platform-network-ambient-condition-and-dependency-snapshot-data", "name": "Environment, location, time, platform, network, ambient condition and dependency snapshot data", "description": "Structured test-execution data for environment, location, time, platform, network, ambient condition and dependency snapshot.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-014" ] } ], "artifacts": [ { "id": "environment-location-time-platform-network-ambient-condition-and-dependency-snapshot-record", "name": "Environment, location, time, platform, network, ambient condition and dependency snapshot record", "description": "Versioned evidence-bearing test-execution record for environment, location, time, platform, network, ambient condition and dependency snapshot with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus environment-location-time-platform-network-ambient-condition-and-dependency-snapshot assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "equipment-instrument-tool-version-calibration-reference-material-and-fixture", "name": "Equipment, instrument, tool, version, calibration, reference material and fixture", "description": "External resource IDs, tool versions, calibration or validation status, reference materials, fixtures, uncertainty contribution, suitability and availability.", "source_refs": [ "SRC-003", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ], "questions": [ { "id": "equipment-instrument-tool-version-calibration-reference-material-and-fixture-q01", "text": "What identities, types, roles, scope, versions and explicit values define equipment, instrument, tool, version, calibration, reference material and fixture?", "kind": "measurement", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "equipment-instrument-tool-version-calibration-reference-material-and-fixture-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support equipment, instrument, tool, version, calibration, reference material and fixture?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "equipment-instrument-tool-version-calibration-reference-material-and-fixture-q03", "text": "How is equipment, instrument, tool, version, calibration, reference material and fixture validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "equipment-instrument-tool-version-calibration-reference-material-and-fixture-data", "name": "Equipment, instrument, tool, version, calibration, reference material and fixture data", "description": "Structured test-execution data for equipment, instrument, tool, version, calibration, reference material and fixture.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "equipment-instrument-tool-version-calibration-reference-material-and-fixture-record", "name": "Equipment, instrument, tool, version, calibration, reference material and fixture record", "description": "Versioned evidence-bearing test-execution record for equipment, instrument, tool, version, calibration, reference material and fixture with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus equipment-instrument-tool-version-calibration-reference-material-and-fixture assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-003", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "authorization-conduct-steps-and-timing", "name": "Authorization, conduct, steps and timing", "description": "Records who or what performed the run, under which authority, and what actually occurred.", "rationale": "Planned steps and actual step occurrences are separate. Execution completion does not itself imply pass, validity or authorization.", "source_refs": [ "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-010", "SRC-014" ], "layers": [ { "id": "roles-authorization-mode-and-safety", "name": "Roles, authorization, mode and safety", "description": "Makes responsibility, automation and guardrails explicit.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-008", "SRC-010" ], "findings": [ { "id": "executor-observer-owner-reviewer-agent-delegation-authorization-and-segregation", "name": "Executor, observer, owner, reviewer, agent, delegation, authorization and segregation", "description": "External actors or agents, run roles, delegated authority, competence assertion, approval boundaries, independence and segregation of duties.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-008", "SRC-010" ], "questions": [ { "id": "executor-observer-owner-reviewer-agent-delegation-authorization-and-segregation-q01", "text": "What identities, types, roles, scope, versions and explicit values define executor, observer, owner, reviewer, agent, delegation, authorization and segregation?", "kind": "authority", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "executor-observer-owner-reviewer-agent-delegation-authorization-and-segregation-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support executor, observer, owner, reviewer, agent, delegation, authorization and segregation?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "executor-observer-owner-reviewer-agent-delegation-authorization-and-segregation-q03", "text": "How is executor, observer, owner, reviewer, agent, delegation, authorization and segregation validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "executor-observer-owner-reviewer-agent-delegation-authorization-and-segregation-data", "name": "Executor, observer, owner, reviewer, agent, delegation, authorization and segregation data", "description": "Structured test-execution data for executor, observer, owner, reviewer, agent, delegation, authorization and segregation.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "executor-observer-owner-reviewer-agent-delegation-authorization-and-segregation-record", "name": "Executor, observer, owner, reviewer, agent, delegation, authorization and segregation record", "description": "Versioned evidence-bearing test-execution record for executor, observer, owner, reviewer, agent, delegation, authorization and segregation with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus executor-observer-owner-reviewer-agent-delegation-authorization-and-segregation assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "manual-automatic-semiautomatic-mode-tool-control-safety-privacy-and-stop-rule", "name": "Manual, automatic, semiautomatic mode, tool control, safety, privacy and stop rule", "description": "Execution mode, automation tool and controller, human intervention points, safety envelope, privacy constraints, abort triggers and emergency authority.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012" ], "questions": [ { "id": "manual-automatic-semiautomatic-mode-tool-control-safety-privacy-and-stop-rule-q01", "text": "What identities, types, roles, scope, versions and explicit values define manual, automatic, semiautomatic mode, tool control, safety, privacy and stop rule?", "kind": "constraint", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "manual-automatic-semiautomatic-mode-tool-control-safety-privacy-and-stop-rule-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support manual, automatic, semiautomatic mode, tool control, safety, privacy and stop rule?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "manual-automatic-semiautomatic-mode-tool-control-safety-privacy-and-stop-rule-q03", "text": "How is manual, automatic, semiautomatic mode, tool control, safety, privacy and stop rule validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "manual-automatic-semiautomatic-mode-tool-control-safety-privacy-and-stop-rule-data", "name": "Manual, automatic, semiautomatic mode, tool control, safety, privacy and stop rule data", "description": "Structured test-execution data for manual, automatic, semiautomatic mode, tool control, safety, privacy and stop rule.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012" ] } ], "artifacts": [ { "id": "manual-automatic-semiautomatic-mode-tool-control-safety-privacy-and-stop-rule-record", "name": "Manual, automatic, semiautomatic mode, tool control, safety, privacy and stop rule record", "description": "Versioned evidence-bearing test-execution record for manual, automatic, semiautomatic mode, tool control, safety, privacy and stop rule with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus manual-automatic-semiautomatic-mode-tool-control-safety-privacy-and-stop-rule assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012" ] } ], "inline_only_rationale": null } ] }, { "id": "execution-lifecycle-step-occurrences-and-deviations", "name": "Execution lifecycle, step occurrences and deviations", "description": "Captures the append-only event history and actual ordered conduct.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-014" ], "findings": [ { "id": "plan-prepare-start-pause-resume-block-abort-complete-time-and-state-event", "name": "Plan, prepare, start, pause, resume, block, abort, complete, time and state event", "description": "Typed lifecycle event, prior and next state, actor or agent, authority, rationale, event time with seconds and offset, observed time and evidence.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-014" ], "questions": [ { "id": "plan-prepare-start-pause-resume-block-abort-complete-time-and-state-event-q01", "text": "What identities, types, roles, scope, versions and explicit values define plan, prepare, start, pause, resume, block, abort, complete, time and state event?", "kind": "lifecycle", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "plan-prepare-start-pause-resume-block-abort-complete-time-and-state-event-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support plan, prepare, start, pause, resume, block, abort, complete, time and state event?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "plan-prepare-start-pause-resume-block-abort-complete-time-and-state-event-q03", "text": "How is plan, prepare, start, pause, resume, block, abort, complete, time and state event validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "plan-prepare-start-pause-resume-block-abort-complete-time-and-state-event-data", "name": "Plan, prepare, start, pause, resume, block, abort, complete, time and state event data", "description": "Structured test-execution data for plan, prepare, start, pause, resume, block, abort, complete, time and state event.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-014" ] } ], "artifacts": [ { "id": "plan-prepare-start-pause-resume-block-abort-complete-time-and-state-event-record", "name": "Plan, prepare, start, pause, resume, block, abort, complete, time and state event record", "description": "Versioned evidence-bearing test-execution record for plan, prepare, start, pause, resume, block, abort, complete, time and state event with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus plan-prepare-start-pause-resume-block-abort-complete-time-and-state-event assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "step-occurrence-sequence-input-action-output-duration-log-message-deviation-and-recovery", "name": "Step occurrence, sequence, input, action, output, duration, log, message, deviation and recovery", "description": "Actual step ID, planned-step link, order and concurrency, inputs, action, outputs, timestamps, messages, deviation, recovery and continuation decision.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-010", "SRC-014" ], "questions": [ { "id": "step-occurrence-sequence-input-action-output-duration-log-message-deviation-and-recovery-q01", "text": "What identities, types, roles, scope, versions and explicit values define step occurrence, sequence, input, action, output, duration, log, message, deviation and recovery?", "kind": "lifecycle", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "step-occurrence-sequence-input-action-output-duration-log-message-deviation-and-recovery-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support step occurrence, sequence, input, action, output, duration, log, message, deviation and recovery?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "step-occurrence-sequence-input-action-output-duration-log-message-deviation-and-recovery-q03", "text": "How is step occurrence, sequence, input, action, output, duration, log, message, deviation and recovery validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "step-occurrence-sequence-input-action-output-duration-log-message-deviation-and-recovery-data", "name": "Step occurrence, sequence, input, action, output, duration, log, message, deviation and recovery data", "description": "Structured test-execution data for step occurrence, sequence, input, action, output, duration, log, message, deviation and recovery.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-010", "SRC-014" ] } ], "artifacts": [ { "id": "step-occurrence-sequence-input-action-output-duration-log-message-deviation-and-recovery-record", "name": "Step occurrence, sequence, input, action, output, duration, log, message, deviation and recovery record", "description": "Versioned evidence-bearing test-execution record for step occurrence, sequence, input, action, output, duration, log, message, deviation and recovery with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus step-occurrence-sequence-input-action-output-duration-log-message-deviation-and-recovery assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-010", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "observations-measurements-evidence-and-results", "name": "Observations, measurements, evidence and results", "description": "Separates raw observation from interpretation, verdict and broader assurance claim.", "rationale": "Expected result, observed value, comparison, verdict, confidence and compliance conclusion are different assertions with their own sources.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ], "layers": [ { "id": "observations-measurements-and-evidence", "name": "Observations, measurements and evidence", "description": "Preserves source observations and evidence before conclusion.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-008", "SRC-010" ], "findings": [ { "id": "observation-property-value-unit-scale-time-location-method-quality-and-uncertainty", "name": "Observation, property, value, unit, scale, time, location, method, quality and uncertainty", "description": "Observed property, value or category, unit and scale, phenomenon and result time, location, procedure, sensor or observer, quality flag, detection limit and uncertainty.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-014" ], "questions": [ { "id": "observation-property-value-unit-scale-time-location-method-quality-and-uncertainty-q01", "text": "What identities, types, roles, scope, versions and explicit values define observation, property, value, unit, scale, time, location, method, quality and uncertainty?", "kind": "measurement", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "observation-property-value-unit-scale-time-location-method-quality-and-uncertainty-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support observation, property, value, unit, scale, time, location, method, quality and uncertainty?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "observation-property-value-unit-scale-time-location-method-quality-and-uncertainty-q03", "text": "How is observation, property, value, unit, scale, time, location, method, quality and uncertainty validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "observation-property-value-unit-scale-time-location-method-quality-and-uncertainty-data", "name": "Observation, property, value, unit, scale, time, location, method, quality and uncertainty data", "description": "Structured test-execution data for observation, property, value, unit, scale, time, location, method, quality and uncertainty.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-014" ] } ], "artifacts": [ { "id": "observation-property-value-unit-scale-time-location-method-quality-and-uncertainty-record", "name": "Observation, property, value, unit, scale, time, location, method, quality and uncertainty record", "description": "Versioned evidence-bearing test-execution record for observation, property, value, unit, scale, time, location, method, quality and uncertainty with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus observation-property-value-unit-scale-time-location-method-quality-and-uncertainty assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "evidence-artifact-pointer-log-trace-image-record-integrity-digest-and-custody", "name": "Evidence artifact, pointer, log, trace, image, record, integrity, digest and custody", "description": "External artifact identity, relevant pointer, media type, capture event, generating tool or agent, digest, signature, storage, access marking and custody lineage.", "source_refs": [ "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "evidence-artifact-pointer-log-trace-image-record-integrity-digest-and-custody-q01", "text": "What identities, types, roles, scope, versions and explicit values define evidence artifact, pointer, log, trace, image, record, integrity, digest and custody?", "kind": "evidence", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "evidence-artifact-pointer-log-trace-image-record-integrity-digest-and-custody-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support evidence artifact, pointer, log, trace, image, record, integrity, digest and custody?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "evidence-artifact-pointer-log-trace-image-record-integrity-digest-and-custody-q03", "text": "How is evidence artifact, pointer, log, trace, image, record, integrity, digest and custody validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "evidence-artifact-pointer-log-trace-image-record-integrity-digest-and-custody-data", "name": "Evidence artifact, pointer, log, trace, image, record, integrity, digest and custody data", "description": "Structured test-execution data for evidence artifact, pointer, log, trace, image, record, integrity, digest and custody.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "evidence-artifact-pointer-log-trace-image-record-integrity-digest-and-custody-record", "name": "Evidence artifact, pointer, log, trace, image, record, integrity, digest and custody record", "description": "Versioned evidence-bearing test-execution record for evidence artifact, pointer, log, trace, image, record, integrity, digest and custody with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus evidence-artifact-pointer-log-trace-image-record-integrity-digest-and-custody assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "comparison-verdict-confidence-and-review", "name": "Comparison, verdict, confidence and review", "description": "Builds bounded result assertions without converting them into unearned compliance claims.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-011" ], "findings": [ { "id": "expected-actual-comparator-difference-tolerance-outcome-verdict-and-rationale", "name": "Expected, actual, comparator, difference, tolerance, outcome, verdict and rationale", "description": "Expected and actual references, comparator and version, difference, tolerance evaluation, outcome vocabulary, verdict issuer, rationale and affected scope.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-011" ], "questions": [ { "id": "expected-actual-comparator-difference-tolerance-outcome-verdict-and-rationale-q01", "text": "What identities, types, roles, scope, versions and explicit values define expected, actual, comparator, difference, tolerance, outcome, verdict and rationale?", "kind": "validation", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "expected-actual-comparator-difference-tolerance-outcome-verdict-and-rationale-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support expected, actual, comparator, difference, tolerance, outcome, verdict and rationale?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "expected-actual-comparator-difference-tolerance-outcome-verdict-and-rationale-q03", "text": "How is expected, actual, comparator, difference, tolerance, outcome, verdict and rationale validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "expected-actual-comparator-difference-tolerance-outcome-verdict-and-rationale-data", "name": "Expected, actual, comparator, difference, tolerance, outcome, verdict and rationale data", "description": "Structured test-execution data for expected, actual, comparator, difference, tolerance, outcome, verdict and rationale.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "expected-actual-comparator-difference-tolerance-outcome-verdict-and-rationale-record", "name": "Expected, actual, comparator, difference, tolerance, outcome, verdict and rationale record", "description": "Versioned evidence-bearing test-execution record for expected, actual, comparator, difference, tolerance, outcome, verdict and rationale with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus expected-actual-comparator-difference-tolerance-outcome-verdict-and-rationale assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "validity-confidence-coverage-review-attestation-signoff-and-compliance-boundary", "name": "Validity, confidence, coverage, review, attestation, signoff and compliance boundary", "description": "Run validity, confidence, coverage and limitations, reviewer and attestation, signoff authority, disputes and explicit separation from system-level compliance or certification.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-010" ], "questions": [ { "id": "validity-confidence-coverage-review-attestation-signoff-and-compliance-boundary-q01", "text": "What identities, types, roles, scope, versions and explicit values define validity, confidence, coverage, review, attestation, signoff and compliance boundary?", "kind": "validation", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "validity-confidence-coverage-review-attestation-signoff-and-compliance-boundary-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support validity, confidence, coverage, review, attestation, signoff and compliance boundary?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "validity-confidence-coverage-review-attestation-signoff-and-compliance-boundary-q03", "text": "How is validity, confidence, coverage, review, attestation, signoff and compliance boundary validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "validity-confidence-coverage-review-attestation-signoff-and-compliance-boundary-data", "name": "Validity, confidence, coverage, review, attestation, signoff and compliance boundary data", "description": "Structured test-execution data for validity, confidence, coverage, review, attestation, signoff and compliance boundary.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-010" ] } ], "artifacts": [ { "id": "validity-confidence-coverage-review-attestation-signoff-and-compliance-boundary-record", "name": "Validity, confidence, coverage, review, attestation, signoff and compliance boundary record", "description": "Versioned evidence-bearing test-execution record for validity, confidence, coverage, review, attestation, signoff and compliance boundary with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus validity-confidence-coverage-review-attestation-signoff-and-compliance-boundary assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "anomalies-reruns-review-and-lifecycle", "name": "Anomalies, reruns, review and lifecycle", "description": "Preserves failed and inconclusive evidence while linking external issue masters and later attempts.", "rationale": "A failed result is not automatically a defect. A rerun never overwrites the earlier execution and one run does not prove reproducibility.", "source_refs": [ "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-011" ], "layers": [ { "id": "anomaly-failure-incident-defect-and-impact-links", "name": "Anomaly, failure, incident, defect and impact links", "description": "Records run-local symptoms and source-qualified links to separately governed issue records.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-011" ], "findings": [ { "id": "anomaly-failure-error-timeout-inconclusive-blocked-symptom-and-triage", "name": "Anomaly, failure, error, timeout, inconclusive, blocked, symptom and triage", "description": "Observed anomaly or symptom, failure mode, error and timeout, inconclusive or blocked reason, affected step or subject scope, severity hypothesis and triage state.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-011" ], "questions": [ { "id": "anomaly-failure-error-timeout-inconclusive-blocked-symptom-and-triage-q01", "text": "What identities, types, roles, scope, versions and explicit values define anomaly, failure, error, timeout, inconclusive, blocked, symptom and triage?", "kind": "evidence", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "anomaly-failure-error-timeout-inconclusive-blocked-symptom-and-triage-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support anomaly, failure, error, timeout, inconclusive, blocked, symptom and triage?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "anomaly-failure-error-timeout-inconclusive-blocked-symptom-and-triage-q03", "text": "How is anomaly, failure, error, timeout, inconclusive, blocked, symptom and triage validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "anomaly-failure-error-timeout-inconclusive-blocked-symptom-and-triage-data", "name": "Anomaly, failure, error, timeout, inconclusive, blocked, symptom and triage data", "description": "Structured test-execution data for anomaly, failure, error, timeout, inconclusive, blocked, symptom and triage.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "anomaly-failure-error-timeout-inconclusive-blocked-symptom-and-triage-record", "name": "Anomaly, failure, error, timeout, inconclusive, blocked, symptom and triage record", "description": "Versioned evidence-bearing test-execution record for anomaly, failure, error, timeout, inconclusive, blocked, symptom and triage with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus anomaly-failure-error-timeout-inconclusive-blocked-symptom-and-triage assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "defect-incident-risk-nonconformity-link-correlation-causality-status-and-owner", "name": "Defect, incident, risk, nonconformity link, correlation, causality, status and owner", "description": "External issue IDs, typed relation, correlation evidence, unconfirmed or confirmed causality, source status, owner, disposition and no-cascade rule.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "defect-incident-risk-nonconformity-link-correlation-causality-status-and-owner-q01", "text": "What identities, types, roles, scope, versions and explicit values define defect, incident, risk, nonconformity link, correlation, causality, status and owner?", "kind": "relationship", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "defect-incident-risk-nonconformity-link-correlation-causality-status-and-owner-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support defect, incident, risk, nonconformity link, correlation, causality, status and owner?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "defect-incident-risk-nonconformity-link-correlation-causality-status-and-owner-q03", "text": "How is defect, incident, risk, nonconformity link, correlation, causality, status and owner validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "defect-incident-risk-nonconformity-link-correlation-causality-status-and-owner-data", "name": "Defect, incident, risk, nonconformity link, correlation, causality, status and owner data", "description": "Structured test-execution data for defect, incident, risk, nonconformity link, correlation, causality, status and owner.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "defect-incident-risk-nonconformity-link-correlation-causality-status-and-owner-record", "name": "Defect, incident, risk, nonconformity link, correlation, causality, status and owner record", "description": "Versioned evidence-bearing test-execution record for defect, incident, risk, nonconformity link, correlation, causality, status and owner with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus defect-incident-risk-nonconformity-link-correlation-causality-status-and-owner assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "rerun-reproducibility-review-correction-and-supersession", "name": "Rerun, reproducibility, review, correction and supersession", "description": "Relates attempts and protects released evidence from silent mutation.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ], "findings": [ { "id": "retry-rerun-repeat-reproduction-replication-delta-and-comparability", "name": "Retry, rerun, repeat, reproduction, replication, delta and comparability", "description": "New execution ID, predecessor link, reason, controlled and changed factors, procedure and subject equivalence, result delta and bounded reproducibility assessment.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "retry-rerun-repeat-reproduction-replication-delta-and-comparability-q01", "text": "What identities, types, roles, scope, versions and explicit values define retry, rerun, repeat, reproduction, replication, delta and comparability?", "kind": "lifecycle", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "retry-rerun-repeat-reproduction-replication-delta-and-comparability-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support retry, rerun, repeat, reproduction, replication, delta and comparability?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "retry-rerun-repeat-reproduction-replication-delta-and-comparability-q03", "text": "How is retry, rerun, repeat, reproduction, replication, delta and comparability validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "retry-rerun-repeat-reproduction-replication-delta-and-comparability-data", "name": "Retry, rerun, repeat, reproduction, replication, delta and comparability data", "description": "Structured test-execution data for retry, rerun, repeat, reproduction, replication, delta and comparability.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "retry-rerun-repeat-reproduction-replication-delta-and-comparability-record", "name": "Retry, rerun, repeat, reproduction, replication, delta and comparability record", "description": "Versioned evidence-bearing test-execution record for retry, rerun, repeat, reproduction, replication, delta and comparability with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus retry-rerun-repeat-reproduction-replication-delta-and-comparability assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "review-dispute-invalidate-correct-amend-supersede-release-and-tombstone", "name": "Review, dispute, invalidate, correct, amend, supersede, release and tombstone", "description": "Review and dispute events, invalidation reason, correction successor, release state, supersession link, residual validity and minimum tombstone.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-013" ], "questions": [ { "id": "review-dispute-invalidate-correct-amend-supersede-release-and-tombstone-q01", "text": "What identities, types, roles, scope, versions and explicit values define review, dispute, invalidate, correct, amend, supersede, release and tombstone?", "kind": "lifecycle", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "review-dispute-invalidate-correct-amend-supersede-release-and-tombstone-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support review, dispute, invalidate, correct, amend, supersede, release and tombstone?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "review-dispute-invalidate-correct-amend-supersede-release-and-tombstone-q03", "text": "How is review, dispute, invalidate, correct, amend, supersede, release and tombstone validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "review-dispute-invalidate-correct-amend-supersede-release-and-tombstone-data", "name": "Review, dispute, invalidate, correct, amend, supersede, release and tombstone data", "description": "Structured test-execution data for review, dispute, invalidate, correct, amend, supersede, release and tombstone.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-013" ] } ], "artifacts": [ { "id": "review-dispute-invalidate-correct-amend-supersede-release-and-tombstone-record", "name": "Review, dispute, invalidate, correct, amend, supersede, release and tombstone record", "description": "Versioned evidence-bearing test-execution record for review, dispute, invalidate, correct, amend, supersede, release and tombstone with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus review-dispute-invalidate-correct-amend-supersede-release-and-tombstone assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-013" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "provenance-interoperability-access-retention-and-agent-operation", "name": "Provenance, interoperability, access, retention and agent operation", "description": "Supports attributable exchange and safe management of sensitive test evidence.", "rationale": "Mappings are version-pinned and loss-aware. Agent execution, signoff, disclosure and disposition require policy and delegated authority.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014" ], "layers": [ { "id": "source-provenance-and-interoperability", "name": "Source, provenance and interoperability", "description": "Keeps origin and semantic loss visible across projections.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011" ], "findings": [ { "id": "source-assertion-agent-activity-plan-usage-generation-revision-invalidation-and-contradiction", "name": "Source assertion, agent, activity, plan, usage, generation, revision, invalidation and contradiction", "description": "Assertion identity and source, responsible agent, execution activity and plan, used and generated entities, revision, invalidation, confidence and supporting or contradicting claims.", "source_refs": [ "SRC-004", "SRC-005", "SRC-008" ], "questions": [ { "id": "source-assertion-agent-activity-plan-usage-generation-revision-invalidation-and-contradiction-q01", "text": "What identities, types, roles, scope, versions and explicit values define source assertion, agent, activity, plan, usage, generation, revision, invalidation and contradiction?", "kind": "provenance", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "source-assertion-agent-activity-plan-usage-generation-revision-invalidation-and-contradiction-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support source assertion, agent, activity, plan, usage, generation, revision, invalidation and contradiction?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "source-assertion-agent-activity-plan-usage-generation-revision-invalidation-and-contradiction-q03", "text": "How is source assertion, agent, activity, plan, usage, generation, revision, invalidation and contradiction validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "source-assertion-agent-activity-plan-usage-generation-revision-invalidation-and-contradiction-data", "name": "Source assertion, agent, activity, plan, usage, generation, revision, invalidation and contradiction data", "description": "Structured test-execution data for source assertion, agent, activity, plan, usage, generation, revision, invalidation and contradiction.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-008" ] } ], "artifacts": [ { "id": "source-assertion-agent-activity-plan-usage-generation-revision-invalidation-and-contradiction-record", "name": "Source assertion, agent, activity, plan, usage, generation, revision, invalidation and contradiction record", "description": "Versioned evidence-bearing test-execution record for source assertion, agent, activity, plan, usage, generation, revision, invalidation and contradiction with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus source-assertion-agent-activity-plan-usage-generation-revision-invalidation-and-contradiction assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "earl-oscal-oms-prov-robot-opentelemetry-and-domain-crosswalk", "name": "EARL, OSCAL, OMS, PROV, Robot, OpenTelemetry and domain crosswalk", "description": "Pinned source and target versions, identity, subject, criterion, action, observation, evidence, status and result mappings, omissions, semantic conflicts and round-trip classification.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011" ], "questions": [ { "id": "earl-oscal-oms-prov-robot-opentelemetry-and-domain-crosswalk-q01", "text": "What identities, types, roles, scope, versions and explicit values define earl, oscal, oms, prov, robot, opentelemetry and domain crosswalk?", "kind": "interoperability", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "earl-oscal-oms-prov-robot-opentelemetry-and-domain-crosswalk-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support earl, oscal, oms, prov, robot, opentelemetry and domain crosswalk?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "earl-oscal-oms-prov-robot-opentelemetry-and-domain-crosswalk-q03", "text": "How is earl, oscal, oms, prov, robot, opentelemetry and domain crosswalk validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "earl-oscal-oms-prov-robot-opentelemetry-and-domain-crosswalk-data", "name": "EARL, OSCAL, OMS, PROV, Robot, OpenTelemetry and domain crosswalk data", "description": "Structured test-execution data for earl, oscal, oms, prov, robot, opentelemetry and domain crosswalk.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "earl-oscal-oms-prov-robot-opentelemetry-and-domain-crosswalk-record", "name": "EARL, OSCAL, OMS, PROV, Robot, OpenTelemetry and domain crosswalk record", "description": "Versioned evidence-bearing test-execution record for earl, oscal, oms, prov, robot, opentelemetry and domain crosswalk with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus earl-oscal-oms-prov-robot-opentelemetry-and-domain-crosswalk assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "access-privacy-retention-and-safe-automation", "name": "Access, privacy, retention and safe automation", "description": "Controls reading, execution, correction and disposition for humans and agents.", "source_refs": [ "SRC-008", "SRC-012", "SRC-013", "SRC-014" ], "findings": [ { "id": "role-view-purpose-access-disclosure-redaction-exception-and-audit", "name": "Role view, purpose, access, disclosure, redaction, exception and audit", "description": "Purpose-bound role views, field-redacted projections, disclosure rules, exception authority, expiry and tamper-evident access events.", "source_refs": [ "SRC-005", "SRC-008", "SRC-012", "SRC-014" ], "questions": [ { "id": "role-view-purpose-access-disclosure-redaction-exception-and-audit-q01", "text": "What identities, types, roles, scope, versions and explicit values define role view, purpose, access, disclosure, redaction, exception and audit?", "kind": "access", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "role-view-purpose-access-disclosure-redaction-exception-and-audit-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support role view, purpose, access, disclosure, redaction, exception and audit?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "role-view-purpose-access-disclosure-redaction-exception-and-audit-q03", "text": "How is role view, purpose, access, disclosure, redaction, exception and audit validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "role-view-purpose-access-disclosure-redaction-exception-and-audit-data", "name": "Role view, purpose, access, disclosure, redaction, exception and audit data", "description": "Structured test-execution data for role view, purpose, access, disclosure, redaction, exception and audit.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-012", "SRC-014" ] } ], "artifacts": [ { "id": "role-view-purpose-access-disclosure-redaction-exception-and-audit-record", "name": "Role view, purpose, access, disclosure, redaction, exception and audit record", "description": "Versioned evidence-bearing test-execution record for role view, purpose, access, disclosure, redaction, exception and audit with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus role-view-purpose-access-disclosure-redaction-exception-and-audit assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-005", "SRC-008", "SRC-012", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "retention-trigger-legal-hold-disposition-tombstone-agent-authority-idempotency-and-post-check", "name": "Retention trigger, legal hold, disposition, tombstone, agent authority, idempotency and post-check", "description": "Retention class and trigger, hold, deletion eligibility, tombstone, delegated agent scope, preconditions, dry run, idempotency key, expected revision and post-check.", "source_refs": [ "SRC-008", "SRC-012", "SRC-013", "SRC-014" ], "questions": [ { "id": "retention-trigger-legal-hold-disposition-tombstone-agent-authority-idempotency-and-post-check-q01", "text": "What identities, types, roles, scope, versions and explicit values define retention trigger, legal hold, disposition, tombstone, agent authority, idempotency and post-check?", "kind": "retention", "answer_data": [ "identifiers and classifications", "roles and scope", "versions and validity", "values and explicit unknowns" ] }, { "id": "retention-trigger-legal-hold-disposition-tombstone-agent-authority-idempotency-and-post-check-q02", "text": "Which authority, source, method, evidence, event time and knowledge time support retention trigger, legal hold, disposition, tombstone, agent authority, idempotency and post-check?", "kind": "provenance", "answer_data": [ "authority", "source and method", "supporting and contradicting evidence", "event and knowledge time", "confidence and uncertainty" ] }, { "id": "retention-trigger-legal-hold-disposition-tombstone-agent-authority-idempotency-and-post-check-q03", "text": "How is retention trigger, legal hold, disposition, tombstone, agent authority, idempotency and post-check validated, accessed, changed, contested, corrected and retained?", "kind": "validation", "answer_data": [ "validation and profile rules", "access and disclosure", "change and dispute", "lineage", "retention and disposition" ] } ], "data_elements": [ { "id": "retention-trigger-legal-hold-disposition-tombstone-agent-authority-idempotency-and-post-check-data", "name": "Retention trigger, legal hold, disposition, tombstone, agent authority, idempotency and post-check data", "description": "Structured test-execution data for retention trigger, legal hold, disposition, tombstone, agent authority, idempotency and post-check.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-012", "SRC-013", "SRC-014" ] } ], "artifacts": [ { "id": "retention-trigger-legal-hold-disposition-tombstone-agent-authority-idempotency-and-post-check-record", "name": "Retention trigger, legal hold, disposition, tombstone, agent authority, idempotency and post-check record", "description": "Versioned evidence-bearing test-execution record for retention trigger, legal hold, disposition, tombstone, agent authority, idempotency and post-check with authority, time, provenance and access marking.", "media_or_form": [ "logical test-execution assertion", "plan, configuration, event, observation, result, evidence or review reference" ], "serial": true, "identity_strategy": "Execution identifier plus retention-trigger-legal-hold-disposition-tombstone-agent-authority-idempotency-and-post-check assertion, artifact or event identifier; name, date, timestamp and digest never identify the execution alone.", "source_refs": [ "SRC-008", "SRC-012", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-test-execution", "name": "Register test execution", "description": "Create a stable event identity and classify the source and domain profile.", "inputs": [ "test request", "source authority", "profile" ], "outputs": [ "versioned execution root" ], "preconditions": [ "identity, duplicate, profile and boundary checks pass" ], "effects": [ "a test occurrence exists without copying the reusable test case" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-008" ] }, { "id": "bind-procedure-criteria-and-oracles", "name": "Bind procedure, criteria and oracles", "description": "Freeze the exact definitions against which the run is conducted and interpreted.", "inputs": [ "execution root", "test case", "procedure revision", "criteria" ], "outputs": [ "definition-binding release" ], "preconditions": [ "versions, digests, applicability, expected results, tolerances and oracle rules validate" ], "effects": [ "the run can be interpreted against immutable intent" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009" ] }, { "id": "freeze-subject-input-and-environment", "name": "Freeze subject, input and environment", "description": "Record the tested subject, configuration, inputs and influential conditions.", "inputs": [ "execution", "subject", "inputs", "environment profile" ], "outputs": [ "run-context release" ], "preconditions": [ "subject identity, configuration, sample custody, platform, dependencies and condition checks pass" ], "effects": [ "later result comparison has a stable context" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010" ] }, { "id": "qualify-resources-and-authorization", "name": "Qualify resources and authorization", "description": "Bind actors, automation, instruments, delegated authority and safety controls.", "inputs": [ "run context", "actors", "tools", "equipment", "policies" ], "outputs": [ "authorization and resource release" ], "preconditions": [ "competence, calibration, tool version, delegation, privacy and stop rules validate" ], "effects": [ "execution can begin within an explicit control envelope" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012" ] }, { "id": "execute-and-log-steps", "name": "Execute and log steps", "description": "Append actual lifecycle and step occurrences without rewriting the plan.", "inputs": [ "authorized execution", "procedure", "inputs" ], "outputs": [ "state and step event stream" ], "preconditions": [ "preconditions, order, timing, deviation, abort and evidence rules validate" ], "effects": [ "the occurrence history becomes attributable and reproducible enough to inspect" ], "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-010", "SRC-014" ] }, { "id": "capture-observations-and-evidence", "name": "Capture observations and evidence", "description": "Record raw observations, measurements and integrity-protected artifacts before verdict.", "inputs": [ "running execution", "observed subject", "instruments" ], "outputs": [ "observation and evidence release" ], "preconditions": [ "property, unit, method, time, quality, uncertainty, pointer, digest and custody validate" ], "effects": [ "source evidence remains distinguishable from interpretation" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-008", "SRC-010" ] }, { "id": "evaluate-and-assert-results", "name": "Evaluate and assert results", "description": "Compare observed and expected states through a pinned oracle and issue bounded verdicts.", "inputs": [ "observations", "expected results", "comparator", "criteria" ], "outputs": [ "result assertion release" ], "preconditions": [ "expected and actual links, comparator version, tolerance, outcome, rationale, scope and confidence validate" ], "effects": [ "a source-qualified run result exists without asserting broader compliance" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-009", "SRC-011" ] }, { "id": "link-anomalies-and-external-issues", "name": "Link anomalies and external issues", "description": "Connect run-local symptoms to separately governed defects, incidents, risks or nonconformities.", "inputs": [ "execution result", "anomaly evidence", "external issue references" ], "outputs": [ "typed issue-link release" ], "preconditions": [ "relation, correlation, causality status, owner, source status and no-cascade checks pass" ], "effects": [ "triage remains traceable without turning every failed test into a defect" ], "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] }, { "id": "review-invalidate-correct-and-rerun", "name": "Review, invalidate, correct and rerun", "description": "Preserve an immutable attempt while creating reviewed successors or new execution identities.", "inputs": [ "released execution", "review or dispute", "rerun intent" ], "outputs": [ "review event, correction successor or new execution root" ], "preconditions": [ "authority, reason, controlled deltas, lineage, residual validity and expected revision validate" ], "effects": [ "later learning cannot erase the original evidence" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-013" ] }, { "id": "project-disclose-retain-and-audit", "name": "Project, disclose, retain and audit", "description": "Create governed crosswalk views and perform controlled information-lifecycle operations.", "inputs": [ "execution revision", "target profile", "purpose", "policy" ], "outputs": [ "projection, disclosure, correction, disposition or audit event" ], "preconditions": [ "version pin, mapping loss, access, legal hold, tombstone, idempotency and post-checks validate" ], "effects": [ "test evidence remains interpretable, protected and accountable" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014" ] } ], "composition": [ { "target": "Test Case, Test Procedure, Requirement, Criterion and Oracle models", "relation": "REFERENCE", "purpose": "Resolve immutable test intent and acceptance logic while keeping the execution occurrence separate.", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009" ] }, { "target": "Subject, Product, Configuration, Sample, Dataset, Environment, Resource and Instrument models", "relation": "REFERENCE", "purpose": "Bind run-specific snapshots and usage without copying external master lifecycles.", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-007", "SRC-010" ] }, { "target": "Observation, Measurement, Artifact, Defect, Incident, Risk, Assessment and Audit models", "relation": "REFERENCE", "purpose": "Link source evidence, issues and broader assurance records while preserving source identity and authority.", "required": false, "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-010" ] }, { "target": "EARL 1.0 and OSCAL Assessment Results 1.2.0", "relation": "ALIGN", "purpose": "Project assertions, subjects, criteria, results, actions, observations, evidence and findings with explicit non-equivalence and loss rules.", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ] }, { "target": "OGC OMS, W3C PROV-O, Robot Framework 7.4.2 and OpenTelemetry Semantic Conventions 1.44.0", "relation": "ALIGN", "purpose": "Project observations, provenance, software-run artifacts and telemetry status through version-pinned profiles with declared semantic loss.", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-009", "SRC-011" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension identity, owner, testing authority, quality, safety, privacy and records stewards", "Test type, procedure, subject, environment, instrument, result, lifecycle, interoperability, access and retention registries", "Master mappings for test cases, requirements, subjects, configurations, samples, resources, observations, artifacts, defects, incidents, risks, assessments and audit logs", "Execution authorization, environment qualification, evidence, result, review, disclosure, retention and agent-operation policies" ], "namespace_guidance": "Mint stable IDs for execution roots, releases, attempt links, bindings, step events, observations, result assertions, evidence pointers, reviews and lifecycle events. Preserve authoritative external test-case, subject, instrument, observation and issue identities; never use a test name, date or digest as execution identity.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local test-definition, execution, subject, evidence and policy registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize by authoritative source plus execution identifier and lineage head, not by test-case name, subject, timestamp, outcome or digest.", "Keep test definition, expected result, source observation, comparison, verdict, confidence, issue link, assessment finding and compliance conclusion as distinct assertion classes." ], "patch_rules": [ "Extensions declare target domain profile and finding, semantics, authority, lifecycle, measurement, safety, privacy and interoperability impact.", "Released bindings, events, observations, evidence and results are immutable. Corrections create successors and reruns create new execution identities.", "Patching an execution must never silently change procedure revision, subject configuration, environment, oracle or original evidence." ], "compatibility_rules": [ "Unknown additive fields may be ignored only when execution identity, definition binding, subject, environment, conduct, observations, verdict, lifecycle and provenance remain intact.", "EARL, OSCAL, OMS, PROV, Robot Framework, OpenTelemetry and domain mappings pin versions and declare omissions, semantic conflicts and round-trip limits." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system test-management or laboratory execution identifier qualified by source and execution class.", "Governed globally resolvable execution IRI under a controlled namespace.", "Dimension UUID when no authoritative or governed global identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; separate planned, event, observation, result, ingestion and knowledge times and preserve source precision.", "serial_naming_rule": "Use {execution-id}--{step-or-root}--{artifact-kind}--{assertion-or-event-id}; never use test name, date, timestamp or digest alone.", "integrity_rule": "Store digest, media type, execution and release binding, source and profile versions, procedure and subject revisions, generating actor or tool, event and knowledge times, access marking and provenance." }, "policies": [ "A Test Execution is not the reusable Test Case, broader Assessment, Experiment, Inspection, Monitoring stream, Defect, Incident or Verification or Validation claim.", "Expected result, actual observation, comparison, verdict, confidence and compliance conclusion remain separate source-qualified assertions.", "Execution ownership does not transfer ownership of test definition, requirement, subject, product, configuration, environment, instrument, dataset, observation, artifact, defect, incident, risk, assessment or audit masters. Execution invalidation or disposition never cascades to linked masters.", "Agents may validate, link and project allowlisted data, but physical or destructive testing, unsafe automation, signoff, compliance assertion, protected disclosure and disposition require delegated authority and policy controls." ], "crud": { "read": [ "Resolve Dimension policy, execution identity and lineage, definition binding, subject and context, actors and resources, event stream, observations, results, reviews, provenance and access purpose." ], "create": [ "Record execution identity, procedure and criterion revisions, expected result and oracle, subject configuration, environment, resources, authority and provenance before starting the run." ], "update": [ "Append state, step, observation, result, anomaly, review, correction, invalidation, rerun-link or supersession events with actor, authority, rationale, event and knowledge time and expected revision; never overwrite released history." ], "delete": [ "Apply retention, legal-hold and audit policy; cancel or invalidate execution separately from deleting eligible working copies, preserve required evidence lineage and minimum tombstone, and never cascade deletion to linked masters." ] }, "roles": [ { "name": "Test owner or accountable authority", "responsibilities": [ "Own execution purpose, authorization, acceptance boundaries and accountable disposition." ] }, { "name": "Test designer or procedure steward", "responsibilities": [ "Own reusable case, method, criteria, expected results, oracle and permitted variation." ] }, { "name": "Executor or automation operator", "responsibilities": [ "Perform authorized steps, record deviations and protect source evidence." ] }, { "name": "Subject, sample or configuration custodian", "responsibilities": [ "Own subject identity, pedigree, configuration, sample handling and custody assertions." ] }, { "name": "Environment, equipment and metrology steward", "responsibilities": [ "Own condition, tool, instrument, calibration, reference-material and uncertainty evidence." ] }, { "name": "Reviewer or assurance authority", "responsibilities": [ "Review validity, independence, evidence sufficiency, verdict scope and signoff without rewriting the run." ] }, { "name": "Data, privacy, safety and records steward", "responsibilities": [ "Control protected views, safe execution, retention, holds, disposition and auditability." ] } ], "access": { "default_rule": "Deny sensitive subject data, credentials, personal or health observations, security findings, hazardous procedures, proprietary inputs and raw evidence; disclose purpose-bound minimum views under Dimension policy. Field redaction is a governed projection, not a separate access scope.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Test owner, executor, subject custodian, safety responder, reviewer, auditor, regulator or court access cites authority and remains minimum-necessary, time-limited and separately logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, execution, operation, policy, RFC 3339 time, release or affected fields, source revision and outcome without copying protected source data unnecessarily." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension testing, safety, privacy, access, retention and agent-operation policies.", "Read this model and linked test-definition, requirement, subject, sample, environment, instrument, observation, artifact, defect, incident, assessment and audit models before mutation." ] } }, "coverage": { "claim": "Covers a cross-domain Test Execution event kernel spanning immutable intent binding, source-qualified subject and environment snapshots, authorized conduct with step-level logging, captured observations and measurements, bounded verdicts with confidence and evidence, anomaly and external-issue links, reruns with lineage, invalidation and review cycles, and governed access, privacy, retention and audit operations. Execution identity, procedure revision, subject configuration, environment, resource qualification, observations, result assertions, lifecycle events, provenance and interoperability mappings are first-class. Gaps exist in external master authorization (relation registry rows not approved), sector-specific governance (laboratory, clinical, security, safety-critical), OpenTelemetry alignment (development-status semantic conventions), and full-text ISO/IEC source validation.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Execution, release, attempt, binding, step, observation, result, evidence and review identities are distinct." }, { "dimension": "classification and definition", "status": "covered", "notes": "Cross-domain profiles and test-case, assessment, experiment, inspection, monitoring and assurance boundaries are explicit." }, { "dimension": "direct properties", "status": "covered", "notes": "Procedure binding, subject, context, authority, conduct, observations, verdict, anomalies, reruns and review are first-class." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Observed property, value, unit, method, result time, quality and uncertainty are source-qualified." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Register, bind, freeze, authorize, execute, observe, evaluate, link, review, rerun, project and retain are governed." }, { "dimension": "composition", "status": "gap", "notes": "Test case, requirement, subject, resource, observation, artifact, issue, assessment and audit masters remain external. Proposed relations or mapping versions remain held for review." }, { "dimension": "lifecycle", "status": "covered", "notes": "Planning, preparation, start, pause, resume, block, abort, completion, invalidation, correction, review and supersession preserve history." }, { "dimension": "relationships", "status": "covered", "notes": "Bindings, step plans, usage, generation, reruns, evidence, issue links and crosswalks use typed relations." }, { "dimension": "temporal", "status": "covered", "notes": "Planned, event, observation, result, ingestion and knowledge times remain distinct." }, { "dimension": "spatial", "status": "covered", "notes": "Physical or virtual location, environment and observed-feature location remain source-qualified." }, { "dimension": "provenance", "status": "covered", "notes": "Plans, agents, used and generated entities, observations, results, revisions and invalidations preserve provenance." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Test, procedure, subject, resource, review, safety, privacy and records duties are separated." }, { "dimension": "validation and quality", "status": "covered", "notes": "Identity, revision, context, calibration, timing, oracle, evidence, outcome and stale-head checks are explicit." }, { "dimension": "access and privacy", "status": "covered", "notes": "Purpose-bound views, protected evidence, field-redacted projections and deny-by-default sensitive content are explicit." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Abort or invalidation, working-copy deletion, retained evidence, holds and minimum tombstones are distinguished." }, { "dimension": "interoperability", "status": "gap", "notes": "EARL, OSCAL, OMS, PROV, Robot and OpenTelemetry projections are versioned and loss-aware. Proposed relations or mapping versions remain held for review." } ], "known_omissions": [ "No successful independent Claude or Grok result was available; laboratory, software, manufacturing, clinical, security, safety-critical, regional and legal review is required before canonical promotion.", "Test Execution has no single universal cross-domain vocabulary. This package defines a shared occurrence kernel and requires profile-specific procedures, outcome vocabularies and authority rules.", "No approved relation rows were supplied; the registry Assessment / Evaluation parent link and proposed test-definition, subject, observation, evidence, issue and audit relations remain holds.", "The ISO/IEC/IEEE 29119-3 and ISO/IEC 17025 pages are public abstracts or summaries, not licensed clause text, so no ISO conformance claim is made.", "OpenTelemetry test attributes are development status and currently much narrower than the Vercy cross-domain model.", "Sector profiles need their own competence, accreditation, safety, ethics, custody, uncertainty, privacy, retention and signoff rules." ], "conflicts": [ "Some systems call a test-case result the execution itself, while others separate run, case attempt, step, observation and assertion. Vercy preserves separate identities and source mappings.", "Pass, success, completion, conformance, compliance, certification and validation are not equivalent and can conflict across sources.", "Evidence completeness, privacy minimization, reproducibility, operational speed and safety controls can conflict." ], "regional_assumptions": [ "Accreditation, admissibility, product compliance, clinical or research ethics, workplace safety, privacy, records and disclosure depend on jurisdiction and sector.", "NASA guidance informs systems-engineering verification and validation but does not define a universal test execution lifecycle.", "OSCAL is a security-assessment profile; EARL is rooted in accessibility and quality reporting; Robot and OpenTelemetry are software-oriented interoperability profiles." ], "adversarial_checks": [ "Reject an execution without stable identity, exact procedure and criterion binding, subject configuration, environment and accountable authority.", "Reject success, pass, compliance or defect identity inferred only from process completion, an exit code, a single comparison or a linked issue.", "Reject a rerun that overwrites an earlier execution or silently changes procedure, subject, environment, oracle or source observations.", "Reject raw observations, evidence and verdicts that lack source, time, method, scope, integrity and uncertainty or validity context.", "Reject agent execution, signoff, protected disclosure or disposition outside delegated authority, safety controls, retention policy and post-checks." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "event", "status": "accepted", "rationale": "Test Execution is a bounded, time-scoped occurrence with stable identity, attempt lineage, and immutable history of planning, conduct, observations, verdicts, reviews, and supersessions. It is not a persistent entity (test case definition), structural relationship (connection between external masters), or cross-cutting mixin (quality facet applied retroactively). The event archetype correctly separates the run instance from reusable definitions and enables independent master stewardship, causality chains, reruns with new identities, and forensic audit trails. Frozen registry record-plane type (standalone-mm) classifies the data-governance plane; subject-model kind (event) is the defensible semantic class." }, "decisions": [ { "concept": "Entry kind and archetype (event vs. entity vs. aggregate root)", "disposition": "accepted", "rationale": "Test Execution is fundamentally an occurrence in time with identity, lineage, and state-transition events (plan, start, step, complete, review, invalidate, supersede). This matches the event archetype. It is not a persistent master (entity), collection (aggregate), or structural connector (relationship). The execution owns its own lifecycle and verdicts but not the reusable test case, requirement, subject, product, instrument, or defect masters." }, { "concept": "Ownership boundary and steward separation", "disposition": "accepted", "rationale": "The model correctly scopes out test case, requirement, subject, product, configuration, environment, sample, instrument, dataset, observation, artifact, defect, incident, risk, assessment and audit master lifecycle. Execution owns only the instance identity, procedure revision binding, subject/environment snapshots, captured observations, issued verdicts, and review lineage. This prevents circular dependencies, enables independent master stewardship, and blocks cascading invalidation on rerun or review." }, { "concept": "Source authority and abstractness (ISO, W3C, NIST, NASA, UK-NA, OGC, RFC, OTel)", "disposition": "deferred", "rationale": "Fourteen sources are cited. SRC-002 and SRC-003 are ISO catalogue abstracts or summaries, not full normative clause text; SRC-001 is an official series overview. SRC-004, SRC-005 and SRC-006 are official W3C and NIST technical documentation and still require version-pinned crosswalk verification. SRC-011 is development-status OpenTelemetry material. SRC-013 is jurisdiction-scoped records guidance. Full ISO text review and jurisdiction-specific analysis remain necessary before canonical conformance claims." }, { "concept": "Relation registry rows and external master binding", "disposition": "split", "rationale": "No approved registry rows exist between Test Execution and test-definition, subject, observation, evidence, issue, or audit masters. Service-layer notes declare proposed source-qualified bindings and explicit no-cascade semantics, but these remain held for stakeholder review. The model is internally consistent; proposed relations must pass external master steward review before registry authorization. This deferral is correct, not a model flaw." }, { "concept": "Interoperability and semantic crosswalk validation", "disposition": "deferred", "rationale": "EARL, OSCAL, OMS, PROV, Robot Framework, and OpenTelemetry crosswalks (finding earl-oscal-oms-prov-robot-opentelemetry-and-domain-crosswalk) declare version pins, identity/criterion/action/observation/status mappings, acknowledged omissions and semantic conflicts, and round-trip classification limits. However, these remain unvalidated in independent audit. OpenTelemetry test attributes are development-status and narrower than the cross-domain model. Sector-specific validation (security assessment, clinical, manufacturing) is required before canonical alignment claims." }, { "concept": "Validity, confidence, and compliance boundary", "disposition": "accepted", "rationale": "The model strictly separates execution verdict (bounded, source-qualified, scoped to a run) from system compliance, certification, or fitness claim. Confidence depends on procedure revision, oracle, evidence quality and reviewer authority, not inferred from outcome, exit code or linked-issue status. Assessment or assurance layer remains external. This boundary prevents pass-to-defect-to-compliance confusion and supports auditable risk escalation." }, { "concept": "Access, privacy, redaction, and protected-view governance", "disposition": "accepted", "rationale": "The model enforces deny-by-default for sensitive subject data, credentials, personal or health observations, proprietary inputs, security findings, and hazardous procedures. Purpose-bound role views, field-redacted projections, and tamper-evident access events are declared. Agent operation requires delegated authority, pre-conditions, dry-run, and post-checks. This supports NIST Privacy Framework 1.0 and OSCAL assessment confidentiality controls without requiring the security auditor to define sector-specific rules." }, { "concept": "Immutability, rerun lineage, and no-cascade rule", "disposition": "accepted", "rationale": "The model enforces append-only step and observation logs, separate review/invalidation/supersession events that do not overwrite released history, predecessor and rerun links, and explicit no-cascade semantics: an invalidated execution does not automatically delete external masters or linked issues. Execution invalidation never cascades to test case, subject, or issue lifecycle. This preserves forensic completeness and enables dispute resolution." }, { "concept": "Retention, legal hold, and disposition governance", "disposition": "deferred", "rationale": "The model declares retention trigger, legal hold, deletion eligibility, minimum tombstone, agent authority scope, preconditions, dry-run, idempotency and post-check semantics. Sector-specific retention schedules are not embedded and depend on jurisdictional and Dimension policy. Laboratory, clinical, manufacturing, aerospace, security and financial profiles therefore remain deferred rather than being inferred from uncited standards." }, { "concept": "Anomaly, failure, and issue linking without automatic creation", "disposition": "accepted", "rationale": "The model permits execution to link to external defect, incident, risk, and nonconformity masters through source-qualified correlation or causality assertions. Linking never automatically creates or reopens issues. A failed execution is evidence; issue creation and triage remain separate authorities. This prevents noise from run-local anomalies and preserves issue-steward autonomy." }, { "concept": "Timestamp precision and temporal distinctness (event, observation, result, ingestion, knowledge time)", "disposition": "accepted", "rationale": "The model requires RFC 3339 timestamps with seconds and explicit offset or Z, and preserves distinct time slots: planned, event (when state changed), observation (when phenomenon occurred), result (when comparison concluded), ingestion (when stored), and knowledge time (when asserted). This supports reproducibility debugging, clock-skew analysis, and time-series forensics." } ], "publicationHolds": [ "No successful independent Claude or Grok research result was available. A separate no-tools audit was completed, but it is not an independent evidence pass. Repository owner authorized Codex-only completion per single-provider-waiver policy. This result remains reviewable-draft pending independent second-provider review.", "ISO/IEC/IEEE 29119-3 and ISO/IEC 17025 are cited through public catalogue abstracts or summaries rather than full normative clause text. NIST OSCAL is cited through official technical documentation. Full ISO document review and cross-reference validation are required for canonical standards-conformance claims.", "No approved relation registry rows exist between Test Execution and test-definition, subject, observation, evidence, issue, or audit masters. Proposed source-qualified bindings and no-cascade semantics remain held for test-case steward, subject steward, observation steward, and issue-tracking steward review and acceptance.", "EARL, OSCAL, OMS, PROV, Robot Framework, and OpenTelemetry interoperability crosswalks remain unvalidated in independent audit. OpenTelemetry test semantic conventions are development-status. Sector-specific validation (security assessment, clinical research, manufacturing, aerospace, supply chain) required before canonical alignment and round-trip loss-limit claims.", "Laboratory competence, software test governance, clinical and safety-critical assurance, manufacturing, aerospace, financial and regional privacy and retention authority review are deferred. Canonical promotion requires jurisdiction and sector governance alignment.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Full-text review of ISO/IEC/IEEE 29119-3:2021 and ISO/IEC 17025:2017 to bind normative test-execution requirements, competence scopes and domain-specific artifact and retention rules.", "OpenTelemetry Semantic Conventions maturity and test-attribute expansion roadmap: current development-status test registry is narrower than Vercy cross-domain model; determine stability timeline and compatibility-breaking gates.", "Sector-specific validation across accredited laboratories, software, security assessment, clinical research, manufacturing, aerospace and financial services, using newly verified primary standards for each profile rather than importing uncited requirements into this draft.", "Relation registry rows for external masters: work with test-case steward, subject steward (product lifecycle, configuration management), observation steward (metrology, sensor calibration), evidence steward (artifact custody, integrity verification), issue steward (defect/incident/risk/nonconformity lifecycle), and assessment steward to define source-qualified binding semantics, approval gates, and cascade policies.", "Governed agent operation and automation authority: define delegation scope, safety controls, preconditions, dry-run mode, idempotency keys, expected-revision checks, post-execution validation, and audit-event immutability for unattended test runners, continuous integration systems, and autonomous laboratory information systems in regulated environments.", "Redundancy and conflict resolution: clarify Vercy semantics when a single physical test execution is independently reported in Robot Framework output, OSCAL assessment result, EARL accessibility report, OpenTelemetry spans, proprietary LMS export, and ISO/IEC 17025 test record. Define canonical vs. projection identity semantics and round-trip loss-acceptable boundaries." ] }, "statistics": { "sources": 14, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }