# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T10:56:43Z", "synthesisSha256": "746b6d5d280a90e2c869f7388fffad4c423dc0c847cbab38868b135f2b17c080", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ACT-053", "registryId": "vr.wm-act-053", "name": "Data Processing Job / Pipeline Run", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.DATA" ], "tags": [ "data", "processing", "job", "pipeline", "run", "act.data" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-053-data-processing-job-pipeline-run/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/publications/wm-act-053-data-processing-job-pipeline-run", "model": { "registry_id": "vr.wm-act-053", "model_id": "WM-ACT-053", "name": "Data Processing Job / Pipeline Run", "entry_kind": "aggregate", "purpose": "Represent one governed data-processing execution so agents can reconstruct what was requested, authorized, resolved, run, observed, produced and corrected without treating orchestration state as proof of data correctness or absorbing reusable definitions and data assets.", "scope_statement": "Owns one processing-run identity; immutable bindings to a parent pipeline or job definition, code, parameters, input versions, environment and effective data interval; trigger and execution authority; task, stage and attempt instances; state events; output materialization and lineage context; validation, quality and telemetry references; failure, retry, recovery, backfill, cancellation and correction lineage. Pipeline, job and workflow definitions, schedules, datasets, data products, schemas, contracts, code, packages, images, configurations, secrets, identities, compute resources, logs, metrics, traces, incidents, provenance, access audits and record masters remain external.", "in_scope": [ "Run identity and immutable execution bindings; trigger, request and authority; resolved graph, tasks, stages, attempts, resources, state and times", "Input consumption and output materialization links; lineage, validation, data quality and observability references; failure, retry, recovery, backfill, correction, access, retention and projections" ], "out_of_scope": [ "Creating or changing reusable pipeline, workflow, schedule, dataset, schema, code, package, image, secret, identity, compute, telemetry, incident or records masters", "Equating dispatch with start, process exit with correct output, materialization with publication, or success with data quality and downstream acceptance", "Autonomous execution, retry, cancellation, production mutation, secret retrieval, destructive cleanup or protected disclosure" ], "boundary_notes": [ { "neighbor": "WM-DAT-005 Data Pipeline", "distinction": "The candidate incoming CONTAINS relation may bind this execution to a parent pipeline and runnable graph. This aggregate cannot own, edit or cascade-delete the reusable pipeline definition.", "source_refs": [ "SRC-005", "SRC-008" ] }, { "neighbor": "Dataset, data product, schema and data contract models", "distinction": "External masters own data identity, content, schema, contract, publication and lifecycle. The run stores resolved version, partition, digest, role and source-qualified consumption or generation links.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005" ] }, { "neighbor": "Software, package, image, configuration, secret and compute models", "distinction": "External masters own artifacts, sensitive values and infrastructure lifecycle. The run binds immutable revisions, digests, entrypoints, secret references, resource observations and environment snapshots.", "source_refs": [ "SRC-008", "SRC-012", "SRC-013", "SRC-014" ] }, { "neighbor": "Logs, metrics, traces, quality results and incidents", "distinction": "Observability and quality systems own evidence content and lifecycle. The run records typed links, scope, sampling, times, integrity and bounded interpretations.", "source_refs": [ "SRC-004", "SRC-006", "SRC-011", "SRC-014" ] }, { "neighbor": "Run, task, stage, attempt and retry", "distinction": "The aggregate owns one run and its execution membership. Each task or stage instance and attempt has independent identity, sequence, environment, state events and outcome; retry never overwrites failure.", "source_refs": [ "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] }, { "neighbor": "OpenLineage, PROV, OTel, CloudEvents, CWL, WES, OGC Processes, Airflow, Kubernetes and OCI", "distinction": "These are versioned lineage, telemetry, event, workflow, API, orchestrator and runtime projections with different scopes. No mapping is assumed lossless or universally applicable.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ] } ] }, "sources": [ { "id": "SRC-001", "title": "PROV-DM: The PROV Data Model", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-dm/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines entities, activities, agents, generation, use, derivation, attribution, association, delegation, invalidation and temporal constraints for execution provenance." }, { "id": "SRC-002", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Provides interoperable RDF terms for execution, input, output, agent, revision and derivation provenance." }, { "id": "SRC-003", "title": "Data Catalog Vocabulary Version 3", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-dcat-3/", "version_or_date": "W3C Recommendation, 22 August 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines dataset, distribution, data service, version and catalog metadata used only as external data-asset projections." }, { "id": "SRC-004", "title": "Data on the Web Best Practices: Data Quality Vocabulary", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-dqv/", "version_or_date": "W3C Working Group Note, 15 December 2016", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Provides quality measurement, metric, annotation, certificate and policy terms for source-qualified quality-result projections." }, { "id": "SRC-005", "title": "OpenLineage Object Model", "organization": "OpenLineage Project", "url": "https://openlineage.io/docs/spec/object-model/", "version_or_date": "OpenLineage 1.53.0 at access", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Separates Job, Run and Dataset identities and represents runtime state updates, design-time metadata and extensible facets." }, { "id": "SRC-006", "title": "OpenTelemetry Specification", "organization": "Cloud Native Computing Foundation OpenTelemetry Project", "url": "https://opentelemetry.io/docs/specs/otel/", "version_or_date": "OpenTelemetry 1.60.0; semantic conventions 1.44.0 at access", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines traces, metrics, logs, resources, instrumentation scope, schema URLs and versioned telemetry used as external observability evidence." }, { "id": "SRC-007", "title": "CloudEvents Specification", "organization": "Cloud Native Computing Foundation", "url": "https://github.com/cloudevents/spec/tree/ce@v1.0.2", "version_or_date": "CloudEvents 1.0.2, released 6 February 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines interoperable event identity, source, type, subject, time, data schema and content type for trigger and lifecycle event projections." }, { "id": "SRC-008", "title": "Common Workflow Language Workflow Description", "organization": "Common Workflow Language Project", "url": "https://www.commonwl.org/v1.2/Workflow.html", "version_or_date": "CWL 1.2.1, approved 7 August 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines vendor-neutral workflow graphs, steps, inputs, outputs, requirements, hints and execution semantics for versioned workflow-definition bindings." }, { "id": "SRC-009", "title": "Workflow Execution Service API", "organization": "Global Alliance for Genomics and Health", "url": "https://ga4gh.github.io/workflow-execution-service-schemas/", "version_or_date": "WES 1.1.0, released 14 September 2023", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines a domain-specific API profile for submitting, monitoring, cancelling and obtaining logs and outputs from portable workflow runs." }, { "id": "SRC-010", "title": "OGC API - Processes - Part 1: Core", "organization": "Open Geospatial Consortium", "url": "https://docs.ogc.org/is/18-062r2/18-062r2.html", "version_or_date": "OGC 18-062r2, version 1.0.0, 20 December 2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines process execution, job identity, accepted, running, successful, failed and dismissed states, status times, results, exceptions and dismissal for a geospatial processing API profile." }, { "id": "SRC-011", "title": "Tasks", "organization": "Apache Software Foundation", "url": "https://airflow.apache.org/docs/apache-airflow/stable/core-concepts/tasks.html", "version_or_date": "Apache Airflow 3.3.x stable documentation at access", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Separates DAG runs, task instances, data intervals, dependencies, states, retries, rescheduling, deferral and heartbeat timeouts for an implementation profile." }, { "id": "SRC-012", "title": "Jobs", "organization": "Cloud Native Computing Foundation Kubernetes Project", "url": "https://kubernetes.io/docs/concepts/workloads/controllers/job/", "version_or_date": "Kubernetes documentation current at access", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines one-off task execution, completions, parallelism, retries, suspension and cleanup for a container-orchestration implementation profile." }, { "id": "SRC-013", "title": "OCI Image Format Specification", "organization": "Open Container Initiative", "url": "https://github.com/opencontainers/image-spec/tree/v1.1.1", "version_or_date": "OCI Image Specification 1.1.1, released 3 March 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines content-addressed image manifests, indexes, configurations, layers and descriptors for versioned runtime-image bindings." }, { "id": "SRC-014", "title": "Security and Privacy Controls for Information Systems and Organizations", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final", "version_or_date": "NIST SP 800-53 Rev. 5 Release 5.2.0, 27 August 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Provides configurable security, privacy, audit, access, integrity, contingency and system-use controls; deployment tailoring remains required." }, { "id": "SRC-015", "title": "Regulation (EU) 2016/679 General Data Protection Regulation", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj", "version_or_date": "27 April 2016; applicable from 25 May 2018", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Provides a European Union privacy and accountability profile for personal data in inputs, outputs, logs, traces and retained execution evidence." }, { "id": "SRC-016", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/info/rfc3339/", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Provides interoperable timestamps with seconds and explicit UTC relationship for scheduling, state transitions, observations and ingestion." }, { "id": "SRC-017", "title": "OpenAPI Specification 3.1.1", "organization": "OpenAPI Initiative", "url": "https://spec.openapis.org/oas/v3.1.1.html", "version_or_date": "OpenAPI 3.1.1, 24 October 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T11:05:00Z", "relevance": "Defines HTTP API descriptions, operations, parameters, request bodies, responses and schemas for version-pinned execution-service projections." } ], "structure": { "bundles": [ { "id": "run-identity-definition-trigger-and-authority", "name": "Run identity, definition, trigger and authority", "description": "Groups governed execution context for run identity, definition, trigger and authority.", "rationale": "One execution must bind stable identity, an immutable definition revision and accountable trigger without absorbing the reusable pipeline or scheduler masters.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-014" ], "layers": [ { "id": "run-root-definition-version-and-parent-pipeline", "name": "Run root, definition version and parent pipeline", "description": "Groups source-qualified execution context for run root, definition version and parent pipeline.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ], "findings": [ { "id": "processing-run-root-identity-namespace-owner-status-and-lineage-head", "name": "Processing run root identity, namespace, owner, status and lineage head", "description": "Records processing run root identity, namespace, owner, status and lineage head as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "processing-run-root-identity-namespace-owner-status-and-lineage-head-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish processing run root identity, namespace, owner, status and lineage head?", "kind": "identity", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "processing-run-root-identity-namespace-owner-status-and-lineage-head-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by processing run root identity, namespace, owner, status and lineage head, with which policy and limits?", "kind": "composition", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "processing-run-root-identity-namespace-owner-status-and-lineage-head-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to processing run root identity, namespace, owner, status and lineage head, and how is it corrected?", "kind": "privacy", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "processing-run-root-identity-namespace-owner-status-and-lineage-head-data", "name": "Processing run root identity, namespace, owner, status and lineage head data", "description": "Typed data for processing run root identity, namespace, owner, status and lineage head with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "processing-run-root-identity-namespace-owner-status-and-lineage-head-record", "name": "Processing run root identity, namespace, owner, status and lineage head record", "description": "Immutable or successor-versioned execution evidence for processing run root identity, namespace, owner, status and lineage head.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for processing-run-root-identity-namespace-owner-status-and-lineage-head; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "pipeline-job-workflow-definition-revision-code-location-and-parent-reference", "name": "Pipeline, job, workflow definition, revision, code location and parent reference", "description": "Records pipeline, job, workflow definition, revision, code location and parent reference as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "pipeline-job-workflow-definition-revision-code-location-and-parent-reference-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish pipeline, job, workflow definition, revision, code location and parent reference?", "kind": "relationship", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "pipeline-job-workflow-definition-revision-code-location-and-parent-reference-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by pipeline, job, workflow definition, revision, code location and parent reference, with which policy and limits?", "kind": "evidence", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "pipeline-job-workflow-definition-revision-code-location-and-parent-reference-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to pipeline, job, workflow definition, revision, code location and parent reference, and how is it corrected?", "kind": "lifecycle", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "pipeline-job-workflow-definition-revision-code-location-and-parent-reference-data", "name": "Pipeline, job, workflow definition, revision, code location and parent reference data", "description": "Typed data for pipeline, job, workflow definition, revision, code location and parent reference with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "pipeline-job-workflow-definition-revision-code-location-and-parent-reference-record", "name": "Pipeline, job, workflow definition, revision, code location and parent reference record", "description": "Immutable or successor-versioned execution evidence for pipeline, job, workflow definition, revision, code location and parent reference.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for pipeline-job-workflow-definition-revision-code-location-and-parent-reference; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "trigger-schedule-request-priority-and-execution-authority", "name": "Trigger, schedule, request, priority and execution authority", "description": "Groups source-qualified execution context for trigger, schedule, request, priority and execution authority.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-014" ], "findings": [ { "id": "trigger-kind-event-schedule-manual-request-source-correlation-and-deduplication", "name": "Trigger kind, event, schedule, manual request, source, correlation and deduplication", "description": "Records trigger kind, event, schedule, manual request, source, correlation and deduplication as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-014" ], "questions": [ { "id": "trigger-kind-event-schedule-manual-request-source-correlation-and-deduplication-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish trigger kind, event, schedule, manual request, source, correlation and deduplication?", "kind": "event", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "trigger-kind-event-schedule-manual-request-source-correlation-and-deduplication-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by trigger kind, event, schedule, manual request, source, correlation and deduplication, with which policy and limits?", "kind": "ownership", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "trigger-kind-event-schedule-manual-request-source-correlation-and-deduplication-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to trigger kind, event, schedule, manual request, source, correlation and deduplication, and how is it corrected?", "kind": "quality", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "trigger-kind-event-schedule-manual-request-source-correlation-and-deduplication-data", "name": "Trigger kind, event, schedule, manual request, source, correlation and deduplication data", "description": "Typed data for trigger kind, event, schedule, manual request, source, correlation and deduplication with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-014" ] } ], "artifacts": [ { "id": "trigger-kind-event-schedule-manual-request-source-correlation-and-deduplication-record", "name": "Trigger kind, event, schedule, manual request, source, correlation and deduplication record", "description": "Immutable or successor-versioned execution evidence for trigger kind, event, schedule, manual request, source, correlation and deduplication.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for trigger-kind-event-schedule-manual-request-source-correlation-and-deduplication; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "requester-operator-service-account-authorization-priority-policy-and-approval", "name": "Requester, operator, service account, authorization, priority, policy and approval", "description": "Records requester, operator, service account, authorization, priority, policy and approval as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-014" ], "questions": [ { "id": "requester-operator-service-account-authorization-priority-policy-and-approval-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish requester, operator, service account, authorization, priority, policy and approval?", "kind": "authority", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "requester-operator-service-account-authorization-priority-policy-and-approval-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by requester, operator, service account, authorization, priority, policy and approval, with which policy and limits?", "kind": "measurement", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "requester-operator-service-account-authorization-priority-policy-and-approval-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to requester, operator, service account, authorization, priority, policy and approval, and how is it corrected?", "kind": "security", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "requester-operator-service-account-authorization-priority-policy-and-approval-data", "name": "Requester, operator, service account, authorization, priority, policy and approval data", "description": "Typed data for requester, operator, service account, authorization, priority, policy and approval with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-014" ] } ], "artifacts": [ { "id": "requester-operator-service-account-authorization-priority-policy-and-approval-record", "name": "Requester, operator, service account, authorization, priority, policy and approval record", "description": "Immutable or successor-versioned execution evidence for requester, operator, service account, authorization, priority, policy and approval.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for requester-operator-service-account-authorization-priority-policy-and-approval; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "inputs-parameters-code-environment-and-effective-interval", "name": "Inputs, parameters, code, environment and effective interval", "description": "Groups governed execution context for inputs, parameters, code, environment and effective interval.", "rationale": "Reproducibility depends on resolved immutable bindings rather than mutable names or the latest available data.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016" ], "layers": [ { "id": "declared-resolved-and-consumed-inputs-parameters-and-secrets", "name": "Declared, resolved and consumed inputs, parameters and secrets", "description": "Groups source-qualified execution context for declared, resolved and consumed inputs, parameters and secrets.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-014" ], "findings": [ { "id": "declared-input-dataset-version-partition-schema-contract-and-availability", "name": "Declared input, dataset version, partition, schema, contract and availability", "description": "Records declared input, dataset version, partition, schema, contract and availability as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-014" ], "questions": [ { "id": "declared-input-dataset-version-partition-schema-contract-and-availability-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish declared input, dataset version, partition, schema, contract and availability?", "kind": "requirement", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "declared-input-dataset-version-partition-schema-contract-and-availability-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by declared input, dataset version, partition, schema, contract and availability, with which policy and limits?", "kind": "exception", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "declared-input-dataset-version-partition-schema-contract-and-availability-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to declared input, dataset version, partition, schema, contract and availability, and how is it corrected?", "kind": "retention", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "declared-input-dataset-version-partition-schema-contract-and-availability-data", "name": "Declared input, dataset version, partition, schema, contract and availability data", "description": "Typed data for declared input, dataset version, partition, schema, contract and availability with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-014" ] } ], "artifacts": [ { "id": "declared-input-dataset-version-partition-schema-contract-and-availability-record", "name": "Declared input, dataset version, partition, schema, contract and availability record", "description": "Immutable or successor-versioned execution evidence for declared input, dataset version, partition, schema, contract and availability.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for declared-input-dataset-version-partition-schema-contract-and-availability; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "resolved-parameter-configuration-secret-reference-consumed-value-and-redaction", "name": "Resolved parameter, configuration, secret reference, consumed value and redaction", "description": "Records resolved parameter, configuration, secret reference, consumed value and redaction as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-014" ], "questions": [ { "id": "resolved-parameter-configuration-secret-reference-consumed-value-and-redaction-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish resolved parameter, configuration, secret reference, consumed value and redaction?", "kind": "security", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "resolved-parameter-configuration-secret-reference-consumed-value-and-redaction-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by resolved parameter, configuration, secret reference, consumed value and redaction, with which policy and limits?", "kind": "provenance", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "resolved-parameter-configuration-secret-reference-consumed-value-and-redaction-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to resolved parameter, configuration, secret reference, consumed value and redaction, and how is it corrected?", "kind": "interoperability", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "resolved-parameter-configuration-secret-reference-consumed-value-and-redaction-data", "name": "Resolved parameter, configuration, secret reference, consumed value and redaction data", "description": "Typed data for resolved parameter, configuration, secret reference, consumed value and redaction with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-014" ] } ], "artifacts": [ { "id": "resolved-parameter-configuration-secret-reference-consumed-value-and-redaction-record", "name": "Resolved parameter, configuration, secret reference, consumed value and redaction record", "description": "Immutable or successor-versioned execution evidence for resolved parameter, configuration, secret reference, consumed value and redaction.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for resolved-parameter-configuration-secret-reference-consumed-value-and-redaction; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-014" ] } ], "inline_only_rationale": null } ] }, { "id": "code-package-image-runtime-environment-and-data-interval", "name": "Code, package, image, runtime environment and data interval", "description": "Groups source-qualified execution context for code, package, image, runtime environment and data interval.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ], "findings": [ { "id": "source-revision-build-package-image-digest-dependency-and-entrypoint", "name": "Source revision, build, package, image digest, dependency and entrypoint", "description": "Records source revision, build, package, image digest, dependency and entrypoint as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ], "questions": [ { "id": "source-revision-build-package-image-digest-dependency-and-entrypoint-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish source revision, build, package, image digest, dependency and entrypoint?", "kind": "provenance", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "source-revision-build-package-image-digest-dependency-and-entrypoint-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by source revision, build, package, image digest, dependency and entrypoint, with which policy and limits?", "kind": "process", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "source-revision-build-package-image-digest-dependency-and-entrypoint-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to source revision, build, package, image digest, dependency and entrypoint, and how is it corrected?", "kind": "decision", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "source-revision-build-package-image-digest-dependency-and-entrypoint-data", "name": "Source revision, build, package, image digest, dependency and entrypoint data", "description": "Typed data for source revision, build, package, image digest, dependency and entrypoint with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] } ], "artifacts": [ { "id": "source-revision-build-package-image-digest-dependency-and-entrypoint-record", "name": "Source revision, build, package, image digest, dependency and entrypoint record", "description": "Immutable or successor-versioned execution evidence for source revision, build, package, image digest, dependency and entrypoint.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for source-revision-build-package-image-digest-dependency-and-entrypoint; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "runtime-platform-environment-region-clock-locale-effective-data-interval-and-watermark", "name": "Runtime platform, environment, region, clock, locale, effective data interval and watermark", "description": "Records runtime platform, environment, region, clock, locale, effective data interval and watermark as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ], "questions": [ { "id": "runtime-platform-environment-region-clock-locale-effective-data-interval-and-watermark-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish runtime platform, environment, region, clock, locale, effective data interval and watermark?", "kind": "temporal", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "runtime-platform-environment-region-clock-locale-effective-data-interval-and-watermark-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by runtime platform, environment, region, clock, locale, effective data interval and watermark, with which policy and limits?", "kind": "validation", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "runtime-platform-environment-region-clock-locale-effective-data-interval-and-watermark-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to runtime platform, environment, region, clock, locale, effective data interval and watermark, and how is it corrected?", "kind": "state", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "runtime-platform-environment-region-clock-locale-effective-data-interval-and-watermark-data", "name": "Runtime platform, environment, region, clock, locale, effective data interval and watermark data", "description": "Typed data for runtime platform, environment, region, clock, locale, effective data interval and watermark with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] } ], "artifacts": [ { "id": "runtime-platform-environment-region-clock-locale-effective-data-interval-and-watermark-record", "name": "Runtime platform, environment, region, clock, locale, effective data interval and watermark record", "description": "Immutable or successor-versioned execution evidence for runtime platform, environment, region, clock, locale, effective data interval and watermark.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for runtime-platform-environment-region-clock-locale-effective-data-interval-and-watermark; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "graph-tasks-stages-attempts-resources-and-state", "name": "Graph, tasks, stages, attempts, resources and state", "description": "Groups governed execution context for graph, tasks, stages, attempts, resources and state.", "rationale": "Execution structure must preserve task and attempt identity, causal dependencies, resources and every state transition.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "layers": [ { "id": "task-stage-graph-dependencies-mapping-and-branching", "name": "Task, stage, graph, dependencies, mapping and branching", "description": "Groups source-qualified execution context for task, stage, graph, dependencies, mapping and branching.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-009", "SRC-011" ], "findings": [ { "id": "task-stage-instance-definition-binding-dependency-branch-map-index-and-order", "name": "Task, stage instance, definition binding, dependency, branch, map index and order", "description": "Records task, stage instance, definition binding, dependency, branch, map index and order as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-009", "SRC-011" ], "questions": [ { "id": "task-stage-instance-definition-binding-dependency-branch-map-index-and-order-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish task, stage instance, definition binding, dependency, branch, map index and order?", "kind": "composition", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "task-stage-instance-definition-binding-dependency-branch-map-index-and-order-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by task, stage instance, definition binding, dependency, branch, map index and order, with which policy and limits?", "kind": "privacy", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "task-stage-instance-definition-binding-dependency-branch-map-index-and-order-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to task, stage instance, definition binding, dependency, branch, map index and order, and how is it corrected?", "kind": "identity", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "task-stage-instance-definition-binding-dependency-branch-map-index-and-order-data", "name": "Task, stage instance, definition binding, dependency, branch, map index and order data", "description": "Typed data for task, stage instance, definition binding, dependency, branch, map index and order with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "task-stage-instance-definition-binding-dependency-branch-map-index-and-order-record", "name": "Task, stage instance, definition binding, dependency, branch, map index and order record", "description": "Immutable or successor-versioned execution evidence for task, stage instance, definition binding, dependency, branch, map index and order.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for task-stage-instance-definition-binding-dependency-branch-map-index-and-order; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "declared-graph-resolved-graph-dynamic-expansion-condition-skip-and-block", "name": "Declared graph, resolved graph, dynamic expansion, condition, skip and block", "description": "Records declared graph, resolved graph, dynamic expansion, condition, skip and block as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-009", "SRC-011" ], "questions": [ { "id": "declared-graph-resolved-graph-dynamic-expansion-condition-skip-and-block-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish declared graph, resolved graph, dynamic expansion, condition, skip and block?", "kind": "process", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "declared-graph-resolved-graph-dynamic-expansion-condition-skip-and-block-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by declared graph, resolved graph, dynamic expansion, condition, skip and block, with which policy and limits?", "kind": "lifecycle", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "declared-graph-resolved-graph-dynamic-expansion-condition-skip-and-block-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to declared graph, resolved graph, dynamic expansion, condition, skip and block, and how is it corrected?", "kind": "classification", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "declared-graph-resolved-graph-dynamic-expansion-condition-skip-and-block-data", "name": "Declared graph, resolved graph, dynamic expansion, condition, skip and block data", "description": "Typed data for declared graph, resolved graph, dynamic expansion, condition, skip and block with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "declared-graph-resolved-graph-dynamic-expansion-condition-skip-and-block-record", "name": "Declared graph, resolved graph, dynamic expansion, condition, skip and block record", "description": "Immutable or successor-versioned execution evidence for declared graph, resolved graph, dynamic expansion, condition, skip and block.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for declared-graph-resolved-graph-dynamic-expansion-condition-skip-and-block; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "attempt-dispatch-worker-compute-resource-and-state-transitions", "name": "Attempt, dispatch, worker, compute resource and state transitions", "description": "Groups source-qualified execution context for attempt, dispatch, worker, compute resource and state transitions.", "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "findings": [ { "id": "task-attempt-identity-sequence-dispatch-worker-host-container-resource-and-lease", "name": "Task attempt identity, sequence, dispatch, worker, host, container, resource and lease", "description": "Records task attempt identity, sequence, dispatch, worker, host, container, resource and lease as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "questions": [ { "id": "task-attempt-identity-sequence-dispatch-worker-host-container-resource-and-lease-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish task attempt identity, sequence, dispatch, worker, host, container, resource and lease?", "kind": "identity", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "task-attempt-identity-sequence-dispatch-worker-host-container-resource-and-lease-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by task attempt identity, sequence, dispatch, worker, host, container, resource and lease, with which policy and limits?", "kind": "quality", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "task-attempt-identity-sequence-dispatch-worker-host-container-resource-and-lease-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to task attempt identity, sequence, dispatch, worker, host, container, resource and lease, and how is it corrected?", "kind": "relationship", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "task-attempt-identity-sequence-dispatch-worker-host-container-resource-and-lease-data", "name": "Task attempt identity, sequence, dispatch, worker, host, container, resource and lease data", "description": "Typed data for task attempt identity, sequence, dispatch, worker, host, container, resource and lease with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "artifacts": [ { "id": "task-attempt-identity-sequence-dispatch-worker-host-container-resource-and-lease-record", "name": "Task attempt identity, sequence, dispatch, worker, host, container, resource and lease record", "description": "Immutable or successor-versioned execution evidence for task attempt identity, sequence, dispatch, worker, host, container, resource and lease.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for task-attempt-identity-sequence-dispatch-worker-host-container-resource-and-lease; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "requested-queued-started-running-heartbeat-succeeded-failed-cancelled-timed-out-and-unknown", "name": "Requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown", "description": "Records requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "questions": [ { "id": "requested-queued-started-running-heartbeat-succeeded-failed-cancelled-timed-out-and-unknown-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown?", "kind": "state", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "requested-queued-started-running-heartbeat-succeeded-failed-cancelled-timed-out-and-unknown-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown, with which policy and limits?", "kind": "security", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "requested-queued-started-running-heartbeat-succeeded-failed-cancelled-timed-out-and-unknown-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown, and how is it corrected?", "kind": "authority", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "requested-queued-started-running-heartbeat-succeeded-failed-cancelled-timed-out-and-unknown-data", "name": "Requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown data", "description": "Typed data for requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "artifacts": [ { "id": "requested-queued-started-running-heartbeat-succeeded-failed-cancelled-timed-out-and-unknown-record", "name": "Requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown record", "description": "Immutable or successor-versioned execution evidence for requested, queued, started, running, heartbeat, succeeded, failed, cancelled, timed out and unknown.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for requested-queued-started-running-heartbeat-succeeded-failed-cancelled-timed-out-and-unknown; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "outputs-lineage-validation-quality-and-observability", "name": "Outputs, lineage, validation, quality and observability", "description": "Groups governed execution context for outputs, lineage, validation, quality and observability.", "rationale": "A process outcome, output materialization, publication and data-quality assertion are separate claims supported by attributable evidence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-016" ], "layers": [ { "id": "declared-materialized-published-outputs-and-lineage", "name": "Declared, materialized, published outputs and lineage", "description": "Groups source-qualified execution context for declared, materialized, published outputs and lineage.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-008", "SRC-010" ], "findings": [ { "id": "declared-output-dataset-artifact-schema-partition-destination-and-contract", "name": "Declared output, dataset, artifact, schema, partition, destination and contract", "description": "Records declared output, dataset, artifact, schema, partition, destination and contract as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-008", "SRC-010" ], "questions": [ { "id": "declared-output-dataset-artifact-schema-partition-destination-and-contract-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish declared output, dataset, artifact, schema, partition, destination and contract?", "kind": "requirement", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "declared-output-dataset-artifact-schema-partition-destination-and-contract-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by declared output, dataset, artifact, schema, partition, destination and contract, with which policy and limits?", "kind": "retention", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "declared-output-dataset-artifact-schema-partition-destination-and-contract-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to declared output, dataset, artifact, schema, partition, destination and contract, and how is it corrected?", "kind": "requirement", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "declared-output-dataset-artifact-schema-partition-destination-and-contract-data", "name": "Declared output, dataset, artifact, schema, partition, destination and contract data", "description": "Typed data for declared output, dataset, artifact, schema, partition, destination and contract with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "declared-output-dataset-artifact-schema-partition-destination-and-contract-record", "name": "Declared output, dataset, artifact, schema, partition, destination and contract record", "description": "Immutable or successor-versioned execution evidence for declared output, dataset, artifact, schema, partition, destination and contract.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for declared-output-dataset-artifact-schema-partition-destination-and-contract; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "materialized-output-version-digest-size-row-count-publication-visibility-and-derivation", "name": "Materialized output, version, digest, size, row count, publication, visibility and derivation", "description": "Records materialized output, version, digest, size, row count, publication, visibility and derivation as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-008", "SRC-010" ], "questions": [ { "id": "materialized-output-version-digest-size-row-count-publication-visibility-and-derivation-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish materialized output, version, digest, size, row count, publication, visibility and derivation?", "kind": "provenance", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "materialized-output-version-digest-size-row-count-publication-visibility-and-derivation-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by materialized output, version, digest, size, row count, publication, visibility and derivation, with which policy and limits?", "kind": "interoperability", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "materialized-output-version-digest-size-row-count-publication-visibility-and-derivation-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to materialized output, version, digest, size, row count, publication, visibility and derivation, and how is it corrected?", "kind": "constraint", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "materialized-output-version-digest-size-row-count-publication-visibility-and-derivation-data", "name": "Materialized output, version, digest, size, row count, publication, visibility and derivation data", "description": "Typed data for materialized output, version, digest, size, row count, publication, visibility and derivation with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "materialized-output-version-digest-size-row-count-publication-visibility-and-derivation-record", "name": "Materialized output, version, digest, size, row count, publication, visibility and derivation record", "description": "Immutable or successor-versioned execution evidence for materialized output, version, digest, size, row count, publication, visibility and derivation.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for materialized-output-version-digest-size-row-count-publication-visibility-and-derivation; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "validation-data-quality-logs-metrics-traces-and-evidence", "name": "Validation, data quality, logs, metrics, traces and evidence", "description": "Groups source-qualified execution context for validation, data quality, logs, metrics, traces and evidence.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-016" ], "findings": [ { "id": "schema-contract-reconciliation-quality-rule-metric-threshold-result-and-waiver", "name": "Schema, contract, reconciliation, quality rule, metric, threshold, result and waiver", "description": "Records schema, contract, reconciliation, quality rule, metric, threshold, result and waiver as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-016" ], "questions": [ { "id": "schema-contract-reconciliation-quality-rule-metric-threshold-result-and-waiver-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish schema, contract, reconciliation, quality rule, metric, threshold, result and waiver?", "kind": "validation", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "schema-contract-reconciliation-quality-rule-metric-threshold-result-and-waiver-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by schema, contract, reconciliation, quality rule, metric, threshold, result and waiver, with which policy and limits?", "kind": "decision", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "schema-contract-reconciliation-quality-rule-metric-threshold-result-and-waiver-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to schema, contract, reconciliation, quality rule, metric, threshold, result and waiver, and how is it corrected?", "kind": "event", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "schema-contract-reconciliation-quality-rule-metric-threshold-result-and-waiver-data", "name": "Schema, contract, reconciliation, quality rule, metric, threshold, result and waiver data", "description": "Typed data for schema, contract, reconciliation, quality rule, metric, threshold, result and waiver with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-016" ] } ], "artifacts": [ { "id": "schema-contract-reconciliation-quality-rule-metric-threshold-result-and-waiver-record", "name": "Schema, contract, reconciliation, quality rule, metric, threshold, result and waiver record", "description": "Immutable or successor-versioned execution evidence for schema, contract, reconciliation, quality rule, metric, threshold, result and waiver.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for schema-contract-reconciliation-quality-rule-metric-threshold-result-and-waiver; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "log-metric-trace-span-event-evidence-source-scope-sampling-integrity-and-retention", "name": "Log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention", "description": "Records log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-016" ], "questions": [ { "id": "log-metric-trace-span-event-evidence-source-scope-sampling-integrity-and-retention-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention?", "kind": "evidence", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "log-metric-trace-span-event-evidence-source-scope-sampling-integrity-and-retention-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention, with which policy and limits?", "kind": "state", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "log-metric-trace-span-event-evidence-source-scope-sampling-integrity-and-retention-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention, and how is it corrected?", "kind": "temporal", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "log-metric-trace-span-event-evidence-source-scope-sampling-integrity-and-retention-data", "name": "Log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention data", "description": "Typed data for log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-016" ] } ], "artifacts": [ { "id": "log-metric-trace-span-event-evidence-source-scope-sampling-integrity-and-retention-record", "name": "Log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention record", "description": "Immutable or successor-versioned execution evidence for log, metric, trace, span, event, evidence source, scope, sampling, integrity and retention.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for log-metric-trace-span-event-evidence-source-scope-sampling-integrity-and-retention; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-016" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "failure-retry-recovery-backfill-replay-and-outcome", "name": "Failure, retry, recovery, backfill, replay and outcome", "description": "Groups governed execution context for failure, retry, recovery, backfill, replay and outcome.", "rationale": "Failure handling must preserve original attempts and distinguish rerun intent, data interval, side effects, compensation and final outcome.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014", "SRC-016" ], "layers": [ { "id": "error-failure-classification-retry-checkpoint-and-recovery", "name": "Error, failure classification, retry, checkpoint and recovery", "description": "Groups source-qualified execution context for error, failure classification, retry, checkpoint and recovery.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "findings": [ { "id": "error-exception-exit-status-failure-domain-root-cause-evidence-and-impact", "name": "Error, exception, exit status, failure domain, root cause, evidence and impact", "description": "Records error, exception, exit status, failure domain, root cause, evidence and impact as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "questions": [ { "id": "error-exception-exit-status-failure-domain-root-cause-evidence-and-impact-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish error, exception, exit status, failure domain, root cause, evidence and impact?", "kind": "exception", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "error-exception-exit-status-failure-domain-root-cause-evidence-and-impact-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by error, exception, exit status, failure domain, root cause, evidence and impact, with which policy and limits?", "kind": "identity", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "error-exception-exit-status-failure-domain-root-cause-evidence-and-impact-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to error, exception, exit status, failure domain, root cause, evidence and impact, and how is it corrected?", "kind": "composition", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "error-exception-exit-status-failure-domain-root-cause-evidence-and-impact-data", "name": "Error, exception, exit status, failure domain, root cause, evidence and impact data", "description": "Typed data for error, exception, exit status, failure domain, root cause, evidence and impact with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "artifacts": [ { "id": "error-exception-exit-status-failure-domain-root-cause-evidence-and-impact-record", "name": "Error, exception, exit status, failure domain, root cause, evidence and impact record", "description": "Immutable or successor-versioned execution evidence for error, exception, exit status, failure domain, root cause, evidence and impact.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for error-exception-exit-status-failure-domain-root-cause-evidence-and-impact; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "retry-policy-attempt-backoff-checkpoint-resume-idempotency-and-side-effect", "name": "Retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect", "description": "Records retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "questions": [ { "id": "retry-policy-attempt-backoff-checkpoint-resume-idempotency-and-side-effect-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect?", "kind": "lifecycle", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "retry-policy-attempt-backoff-checkpoint-resume-idempotency-and-side-effect-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect, with which policy and limits?", "kind": "classification", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "retry-policy-attempt-backoff-checkpoint-resume-idempotency-and-side-effect-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect, and how is it corrected?", "kind": "evidence", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "retry-policy-attempt-backoff-checkpoint-resume-idempotency-and-side-effect-data", "name": "Retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect data", "description": "Typed data for retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "artifacts": [ { "id": "retry-policy-attempt-backoff-checkpoint-resume-idempotency-and-side-effect-record", "name": "Retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect record", "description": "Immutable or successor-versioned execution evidence for retry policy, attempt, backoff, checkpoint, resume, idempotency and side effect.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for retry-policy-attempt-backoff-checkpoint-resume-idempotency-and-side-effect; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "inline_only_rationale": null } ] }, { "id": "backfill-replay-rerun-cancellation-compensation-and-outcome", "name": "Backfill, replay, rerun, cancellation, compensation and outcome", "description": "Groups source-qualified execution context for backfill, replay, rerun, cancellation, compensation and outcome.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-016" ], "findings": [ { "id": "backfill-replay-rerun-recovery-predecessor-successor-trigger-and-data-interval", "name": "Backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval", "description": "Records backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-016" ], "questions": [ { "id": "backfill-replay-rerun-recovery-predecessor-successor-trigger-and-data-interval-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval?", "kind": "provenance", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "backfill-replay-rerun-recovery-predecessor-successor-trigger-and-data-interval-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval, with which policy and limits?", "kind": "relationship", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "backfill-replay-rerun-recovery-predecessor-successor-trigger-and-data-interval-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval, and how is it corrected?", "kind": "ownership", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "backfill-replay-rerun-recovery-predecessor-successor-trigger-and-data-interval-data", "name": "Backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval data", "description": "Typed data for backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-016" ] } ], "artifacts": [ { "id": "backfill-replay-rerun-recovery-predecessor-successor-trigger-and-data-interval-record", "name": "Backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval record", "description": "Immutable or successor-versioned execution evidence for backfill, replay, rerun, recovery, predecessor, successor, trigger and data interval.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for backfill-replay-rerun-recovery-predecessor-successor-trigger-and-data-interval; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "cancel-timeout-cleanup-rollback-compensation-partial-result-final-outcome-and-closure", "name": "Cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure", "description": "Records cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-016" ], "questions": [ { "id": "cancel-timeout-cleanup-rollback-compensation-partial-result-final-outcome-and-closure-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure?", "kind": "lifecycle", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "cancel-timeout-cleanup-rollback-compensation-partial-result-final-outcome-and-closure-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure, with which policy and limits?", "kind": "authority", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "cancel-timeout-cleanup-rollback-compensation-partial-result-final-outcome-and-closure-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure, and how is it corrected?", "kind": "measurement", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "cancel-timeout-cleanup-rollback-compensation-partial-result-final-outcome-and-closure-data", "name": "Cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure data", "description": "Typed data for cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-016" ] } ], "artifacts": [ { "id": "cancel-timeout-cleanup-rollback-compensation-partial-result-final-outcome-and-closure-record", "name": "Cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure record", "description": "Immutable or successor-versioned execution evidence for cancel, timeout, cleanup, rollback, compensation, partial result, final outcome and closure.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for cancel-timeout-cleanup-rollback-compensation-partial-result-final-outcome-and-closure; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-016" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "governance-access-retention-correction-and-interoperability", "name": "Governance, access, retention, correction and interoperability", "description": "Groups governed execution context for governance, access, retention, correction and interoperability.", "rationale": "Safe agent use requires protected views, append-only corrections and profile-pinned projections that declare information loss.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "layers": [ { "id": "ownership-access-privacy-retention-legal-hold-and-disposition", "name": "Ownership, access, privacy, retention, legal hold and disposition", "description": "Groups source-qualified execution context for ownership, access, privacy, retention, legal hold and disposition.", "source_refs": [ "SRC-003", "SRC-006", "SRC-014", "SRC-015", "SRC-016" ], "findings": [ { "id": "owner-steward-operator-subject-purpose-access-redaction-disclosure-and-audit", "name": "Owner, steward, operator, subject, purpose, access, redaction, disclosure and audit", "description": "Records owner, steward, operator, subject, purpose, access, redaction, disclosure and audit as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-003", "SRC-006", "SRC-014", "SRC-015", "SRC-016" ], "questions": [ { "id": "owner-steward-operator-subject-purpose-access-redaction-disclosure-and-audit-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish owner, steward, operator, subject, purpose, access, redaction, disclosure and audit?", "kind": "privacy", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "owner-steward-operator-subject-purpose-access-redaction-disclosure-and-audit-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by owner, steward, operator, subject, purpose, access, redaction, disclosure and audit, with which policy and limits?", "kind": "requirement", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "owner-steward-operator-subject-purpose-access-redaction-disclosure-and-audit-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to owner, steward, operator, subject, purpose, access, redaction, disclosure and audit, and how is it corrected?", "kind": "exception", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "owner-steward-operator-subject-purpose-access-redaction-disclosure-and-audit-data", "name": "Owner, steward, operator, subject, purpose, access, redaction, disclosure and audit data", "description": "Typed data for owner, steward, operator, subject, purpose, access, redaction, disclosure and audit with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-006", "SRC-014", "SRC-015", "SRC-016" ] } ], "artifacts": [ { "id": "owner-steward-operator-subject-purpose-access-redaction-disclosure-and-audit-record", "name": "Owner, steward, operator, subject, purpose, access, redaction, disclosure and audit record", "description": "Immutable or successor-versioned execution evidence for owner, steward, operator, subject, purpose, access, redaction, disclosure and audit.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for owner-steward-operator-subject-purpose-access-redaction-disclosure-and-audit; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-003", "SRC-006", "SRC-014", "SRC-015", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "retention-class-legal-hold-tombstone-disposition-cleanup-and-external-record-policy", "name": "Retention class, legal hold, tombstone, disposition, cleanup and external record policy", "description": "Records retention class, legal hold, tombstone, disposition, cleanup and external record policy as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-003", "SRC-006", "SRC-014", "SRC-015", "SRC-016" ], "questions": [ { "id": "retention-class-legal-hold-tombstone-disposition-cleanup-and-external-record-policy-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish retention class, legal hold, tombstone, disposition, cleanup and external record policy?", "kind": "retention", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "retention-class-legal-hold-tombstone-disposition-cleanup-and-external-record-policy-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by retention class, legal hold, tombstone, disposition, cleanup and external record policy, with which policy and limits?", "kind": "constraint", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "retention-class-legal-hold-tombstone-disposition-cleanup-and-external-record-policy-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to retention class, legal hold, tombstone, disposition, cleanup and external record policy, and how is it corrected?", "kind": "provenance", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "retention-class-legal-hold-tombstone-disposition-cleanup-and-external-record-policy-data", "name": "Retention class, legal hold, tombstone, disposition, cleanup and external record policy data", "description": "Typed data for retention class, legal hold, tombstone, disposition, cleanup and external record policy with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-006", "SRC-014", "SRC-015", "SRC-016" ] } ], "artifacts": [ { "id": "retention-class-legal-hold-tombstone-disposition-cleanup-and-external-record-policy-record", "name": "Retention class, legal hold, tombstone, disposition, cleanup and external record policy record", "description": "Immutable or successor-versioned execution evidence for retention class, legal hold, tombstone, disposition, cleanup and external record policy.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for retention-class-legal-hold-tombstone-disposition-cleanup-and-external-record-policy; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-003", "SRC-006", "SRC-014", "SRC-015", "SRC-016" ] } ], "inline_only_rationale": null } ] }, { "id": "correction-projection-conformance-loss-and-agent-controls", "name": "Correction, projection, conformance, loss and agent controls", "description": "Groups source-qualified execution context for correction, projection, conformance, loss and agent controls.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-017" ], "findings": [ { "id": "amend-correct-invalidate-supersede-current-head-reason-authority-and-lineage", "name": "Amend, correct, invalidate, supersede, current head, reason, authority and lineage", "description": "Records amend, correct, invalidate, supersede, current head, reason, authority and lineage as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-017" ], "questions": [ { "id": "amend-correct-invalidate-supersede-current-head-reason-authority-and-lineage-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish amend, correct, invalidate, supersede, current head, reason, authority and lineage?", "kind": "provenance", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "amend-correct-invalidate-supersede-current-head-reason-authority-and-lineage-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by amend, correct, invalidate, supersede, current head, reason, authority and lineage, with which policy and limits?", "kind": "event", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "amend-correct-invalidate-supersede-current-head-reason-authority-and-lineage-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to amend, correct, invalidate, supersede, current head, reason, authority and lineage, and how is it corrected?", "kind": "process", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "amend-correct-invalidate-supersede-current-head-reason-authority-and-lineage-data", "name": "Amend, correct, invalidate, supersede, current head, reason, authority and lineage data", "description": "Typed data for amend, correct, invalidate, supersede, current head, reason, authority and lineage with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-017" ] } ], "artifacts": [ { "id": "amend-correct-invalidate-supersede-current-head-reason-authority-and-lineage-record", "name": "Amend, correct, invalidate, supersede, current head, reason, authority and lineage record", "description": "Immutable or successor-versioned execution evidence for amend, correct, invalidate, supersede, current head, reason, authority and lineage.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for amend-correct-invalidate-supersede-current-head-reason-authority-and-lineage; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "openlineage-prov-otel-cloudevents-cwl-wes-ogc-airflow-kubernetes-oci-projection-and-loss", "name": "OpenLineage, PROV, OTel, CloudEvents, CWL, WES, OGC, Airflow, Kubernetes, OCI projection and loss", "description": "Records openlineage, prov, otel, cloudevents, cwl, wes, ogc, airflow, kubernetes, oci projection and loss as source-qualified execution context while keeping reusable definitions, datasets, software, infrastructure, telemetry and records in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-017" ], "questions": [ { "id": "openlineage-prov-otel-cloudevents-cwl-wes-ogc-airflow-kubernetes-oci-projection-and-loss-q01", "text": "Which stable identities, execution scope, source-qualified values and explicit unknowns establish openlineage, prov, otel, cloudevents, cwl, wes, ogc, airflow, kubernetes, oci projection and loss?", "kind": "interoperability", "answer_data": [ "identifiers, class and execution scope", "source-qualified values and versions", "unknown and not-applicable states" ] }, { "id": "openlineage-prov-otel-cloudevents-cwl-wes-ogc-airflow-kubernetes-oci-projection-and-loss-q02", "text": "Who requests, authorizes, schedules, executes, owns, observes, validates or is affected by openlineage, prov, otel, cloudevents, cwl, wes, ogc, airflow, kubernetes, oci projection and loss, with which policy and limits?", "kind": "temporal", "answer_data": [ "actors, services and roles", "authority, policy and limits", "validation, review and exception path" ] }, { "id": "openlineage-prov-otel-cloudevents-cwl-wes-ogc-airflow-kubernetes-oci-projection-and-loss-q03", "text": "Which scheduled, requested, queued, dispatched, started, heartbeat, completed, observed, ingested and knowledge times apply to openlineage, prov, otel, cloudevents, cwl, wes, ogc, airflow, kubernetes, oci projection and loss, and how is it corrected?", "kind": "validation", "answer_data": [ "distinct execution and observation times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "openlineage-prov-otel-cloudevents-cwl-wes-ogc-airflow-kubernetes-oci-projection-and-loss-data", "name": "OpenLineage, PROV, OTel, CloudEvents, CWL, WES, OGC, Airflow, Kubernetes, OCI projection and loss data", "description": "Typed data for openlineage, prov, otel, cloudevents, cwl, wes, ogc, airflow, kubernetes, oci projection and loss with identity, execution scope, source, authority, state, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-017" ] } ], "artifacts": [ { "id": "openlineage-prov-otel-cloudevents-cwl-wes-ogc-airflow-kubernetes-oci-projection-and-loss-record", "name": "OpenLineage, PROV, OTel, CloudEvents, CWL, WES, OGC, Airflow, Kubernetes, OCI projection and loss record", "description": "Immutable or successor-versioned execution evidence for openlineage, prov, otel, cloudevents, cwl, wes, ogc, airflow, kubernetes, oci projection and loss.", "media_or_form": [ "logical processing-run assertion", "binding, task, attempt, state, input, output, validation, lineage, telemetry, failure, recovery or projection record" ], "serial": true, "identity_strategy": "Run ID plus independent task, attempt, input, output, validation, lineage, telemetry or assertion ID for openlineage-prov-otel-cloudevents-cwl-wes-ogc-airflow-kubernetes-oci-projection-and-loss; job name, dataset name, date, state and retry number never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-processing-run", "name": "Register processing run", "description": "Governed operation to register processing run without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "definition reference", "trigger", "requester", "owner mandate" ], "outputs": [ "run root and constituent slots" ], "preconditions": [ "stable identity, definition version, scope and authority pass" ], "effects": [ "one bounded execution is registered without starting it or asserting success" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010" ] }, { "id": "resolve-definition-inputs-and-environment", "name": "Resolve definition, inputs and environment", "description": "Governed operation to resolve definition, inputs and environment without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "run", "definition", "input selectors", "parameters", "runtime policy" ], "outputs": [ "immutable execution binding" ], "preconditions": [ "versions, digests, data interval, secret references and access pass" ], "effects": [ "the run can be reproduced without absorbing external master lifecycles" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-009", "SRC-013", "SRC-014" ] }, { "id": "authorize-and-dispatch", "name": "Authorize and dispatch", "description": "Governed operation to authorize and dispatch without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "resolved run", "operator", "compute target", "policy" ], "outputs": [ "authorization and dispatch event" ], "preconditions": [ "delegation, environment, quota, priority, access and idempotency pass" ], "effects": [ "dispatch is recorded without asserting start or execution" ], "source_refs": [ "SRC-007", "SRC-009", "SRC-010", "SRC-012", "SRC-014" ] }, { "id": "record-task-and-attempt-events", "name": "Record task and attempt events", "description": "Governed operation to record task and attempt events without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "run", "resolved graph", "task and attempt observations" ], "outputs": [ "task, stage, attempt and state history" ], "preconditions": [ "identity, dependency, sequence, worker, event time and source pass" ], "effects": [ "each attempt remains independently attributable and immutable" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-011", "SRC-012" ] }, { "id": "record-input-consumption-and-output-materialization", "name": "Record input consumption and output materialization", "description": "Governed operation to record input consumption and output materialization without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "attempt", "input observations", "output observations" ], "outputs": [ "consumption, generation and derivation links" ], "preconditions": [ "dataset versions, partitions, digests, schemas, times and visibility pass" ], "effects": [ "declared, consumed, materialized and published assets remain separate" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ] }, { "id": "record-validation-quality-and-observability", "name": "Record validation, quality and observability", "description": "Governed operation to record validation, quality and observability without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "run or attempt", "rules", "logs", "metrics", "traces" ], "outputs": [ "source-qualified evidence and results" ], "preconditions": [ "scope, method, metric, threshold, sampling, integrity and times pass" ], "effects": [ "process exit and data-quality assertions remain separate" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-014" ] }, { "id": "record-failure-and-retry", "name": "Record failure and retry", "description": "Governed operation to record failure and retry without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "failed attempt", "error evidence", "retry policy" ], "outputs": [ "failure classification and successor attempt" ], "preconditions": [ "policy, limit, backoff, idempotency, side effects and authority pass" ], "effects": [ "the failed attempt is preserved and never overwritten by retry" ], "source_refs": [ "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] }, { "id": "cancel-recover-resume-or-compensate", "name": "Cancel, recover, resume or compensate", "description": "Governed operation to cancel, recover, resume or compensate without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "active or failed run", "authorized action", "checkpoint and side effects" ], "outputs": [ "lifecycle event and resulting state" ], "preconditions": [ "authority, current state, checkpoint, impact, cleanup and evidence pass" ], "effects": [ "cancellation or cleanup does not cascade-delete external records" ], "source_refs": [ "SRC-001", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] }, { "id": "backfill-replay-rerun-and-close", "name": "Backfill, replay, rerun and close", "description": "Governed operation to backfill, replay, rerun and close without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "source run", "trigger", "data interval", "definition and input bindings" ], "outputs": [ "successor run and qualified outcome" ], "preconditions": [ "reason, predecessor, versions, interval, side effects and closure criteria pass" ], "effects": [ "original execution and evidence remain reconstructable" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-011", "SRC-016" ] }, { "id": "correct-project-retain-disclose-and-audit", "name": "Correct, project, retain, disclose and audit", "description": "Governed operation to correct, project, retain, disclose and audit without autonomous execution, production mutation, secret access or mutation of external masters.", "inputs": [ "run", "target profile", "access and records policy" ], "outputs": [ "successor, projection, disclosure, tombstone or disposition event" ], "preconditions": [ "mapping versions, loss, privacy, hold, authority and idempotency pass" ], "effects": [ "context stays protected, reconstructable and explicit about current head and loss" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "composition": [ { "target": "WM-DAT-005 Data Pipeline", "relation": "REFERENCE", "purpose": "Bind the candidate parent pipeline and runnable graph without owning definition lifecycle or cascade behavior.", "required": false, "source_refs": [ "SRC-005", "SRC-008" ] }, { "target": "Dataset, data product, schema, contract and source-record models", "relation": "REFERENCE", "purpose": "Resolve declared, consumed, generated and published data identities, versions and contracts without copying their lifecycles.", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005" ] }, { "target": "Software, package, image, configuration, secret, identity and compute models", "relation": "REFERENCE", "purpose": "Resolve immutable execution artifacts, authorization and environment while external systems retain control and sensitive values.", "required": true, "source_refs": [ "SRC-008", "SRC-012", "SRC-013", "SRC-014" ] }, { "target": "Log, metric, trace, quality, incident, provenance, access-audit and records models", "relation": "REFERENCE", "purpose": "Resolve evidence and governance records without absorbing observability, incident or retention execution.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006", "SRC-014", "SRC-015" ] }, { "target": "OpenLineage 1.53, PROV, OTel 1.60, CloudEvents 1.0.2, CWL 1.2, WES 1.1, OGC Processes 1.0, Airflow, Kubernetes Job, OCI Image and OpenAPI 3.1", "relation": "ALIGN", "purpose": "Project version-pinned lineage, telemetry, event, workflow, execution-service, orchestration, container and API views with scope and information-loss declarations.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-017" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension owner and data-processing mandate", "Authoritative pipeline, job, workflow, schedule, dataset, data product, schema, contract, code, package, image, configuration, secret, identity, compute, log, metric, trace, incident, provenance, audit and record registries", "Approved environment, authorization, data classification, quality, runtime, retry, backfill, privacy, retention and interoperability profiles", "Execution, publication, secret-use, cancellation, cleanup, compensation, disclosure and agent-operation policies" ], "namespace_guidance": "Mint run, task, stage, attempt, binding, state, validation, materialization, failure, recovery, correction, disclosure and event IDs; preserve authoritative external master and telemetry identifiers.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize each run and constituent by authoritative orchestrator or execution-system identifier, owning namespace and record kind; never by pipeline name, schedule, date, state or retry number alone.", "Keep reusable definition, run, task or stage instance, attempt, input binding, output materialization, quality result and telemetry evidence independently identifiable." ], "patch_rules": [ "Extensions declare processing domain, orchestrator, runtime, data, quality, observability, security, privacy, retention and interoperability effects.", "Released bindings, task and attempt events, materializations, validations, failures and outcomes are immutable; corrections create linked successors.", "Never silently change definition, code, input, parameter, secret reference, environment, data interval, state, result, output, error, authority or provenance." ], "compatibility_rules": [ "Ignore additive fields only when identity, execution scope, record kind, versions, source, authority, state, time, evidence and provenance survive.", "Every projection pins specification, orchestrator, workflow, runtime, schema, telemetry and code-list versions and declares information loss." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier for each run, task, attempt, binding, materialization, validation or execution event, qualified by owning execution system and record kind.", "Governed globally resolvable processing-run IRI.", "Dimension UUID or ULID when neither preceding identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; distinguish scheduled, requested, queued, dispatched, started, heartbeat, completed, cancelled, source event, output materialization, observation, ingestion and knowledge times whenever they differ.", "serial_naming_rule": "Use {run-id}--{task-attempt-binding-output-validation-or-assertion-id}--{artifact-kind}--{revision-id}.", "integrity_rule": "Store digest, media type, record kind, execution scope, definition and profile versions, actor, event and knowledge times, state, access marking and provenance." }, "policies": [ "The aggregate does not own Pipeline, Job Definition, Workflow Definition, Schedule, Dataset, Data Product, Schema, Data Contract, Code, Package, Image, Configuration, Secret, Identity, Compute Resource, Log, Metric, Trace, Incident, Provenance, Access Audit or Record masters.", "Requested, queued, dispatched, started, running, retrying, succeeded, failed, cancelled, timed out, skipped and unknown are source-qualified states with independent events.", "Successful process exit does not prove output publication, completeness, correctness, schema conformance, data quality, freshness or downstream use.", "Agents cannot execute, retry, cancel, publish, clean up, access secrets, disclose protected data or mutate production systems outside explicit delegated authority." ], "crud": { "read": [ "Resolve purpose, run head, definition and parent references, trigger, authority, immutable bindings, graph, tasks, attempts, states, resources, inputs, outputs, lineage, validations, telemetry, failures, recovery, holds and projection loss." ], "create": [ "Bind stable run and constituent identity, definition revision, trigger, requester, data interval, owner, source, state and event time before recording execution context." ], "update": [ "Append successor state, attempt, binding, materialization, validation, failure, recovery, outcome and correction events with reason, authority, expected revision, event time and knowledge time." ], "delete": [ "Apply data, privacy, security, observability, audit, legal-hold and adopting-Dimension retention policy; retire or tombstone only the run or named constituent without cascading to pipeline, dataset, software, infrastructure or telemetry masters, and let the external records policy execute physical disposition." ] }, "roles": [ { "name": "Data processing owner", "responsibilities": [ "Own execution purpose, service objectives, risk acceptance and accountable outcome interpretation." ] }, { "name": "Pipeline or workflow steward", "responsibilities": [ "Own reusable definitions, versions, dependencies and approved execution profiles." ] }, { "name": "Data owner or product steward", "responsibilities": [ "Own input and output assets, contracts, access, publication and retention decisions." ] }, { "name": "Execution operator or orchestrator", "responsibilities": [ "Own authorized dispatch, state observation, retry, cancellation and recovery within policy." ] }, { "name": "Platform and compute steward", "responsibilities": [ "Own runtime, capacity, isolation, resource and infrastructure evidence." ] }, { "name": "Data quality and validation steward", "responsibilities": [ "Own rules, metrics, thresholds, results, waivers and qualified acceptance." ] }, { "name": "Observability and incident steward", "responsibilities": [ "Own logs, metrics, traces, alerting, incident links, sampling and evidence integrity." ] }, { "name": "Security, privacy and records steward", "responsibilities": [ "Own identities, secret policy, protected views, disclosure, holds, retention and auditability." ] } ], "access": { "default_rule": "Deny inputs, outputs, parameters, secrets, logs and traces unless a purpose-bound policy permits the minimum necessary view.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Declared operator, recovery, incident, audit, subject-rights, legal or emergency access must cite authority, scope, purpose and time limit where applicable and must be logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, run and constituent, operation, authority, policy, RFC 3339 time, affected fields, source revision and outcome without duplicating secrets or protected data unnecessarily." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension execution, authorization, data, schema, quality, runtime, secret, privacy, access, correction, retention and agent policies.", "Read this aggregate and linked pipeline, workflow, dataset, software, compute, telemetry, incident, provenance and records models before mutation." ] } }, "coverage": { "claim": "WM-ACT-053 covers a source-qualified data-processing execution aggregate. It connects immutable definition, code, input, parameter, environment and effective-interval bindings; trigger and authority; graph, task, stage and attempt state; input consumption and output materialization; lineage, validation, quality and telemetry; failure, retry, recovery, cancellation, backfill, correction, protected use and projections. Candidate containment, domain and runtime profiles, release-pinned mappings and independent external review remain deferred.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identity is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "classification and definition", "status": "covered", "notes": "Classification and definition is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "direct properties", "status": "covered", "notes": "Direct properties is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Recognition and observation is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Capabilities and possible actions is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "composition", "status": "covered", "notes": "Composition is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "lifecycle", "status": "covered", "notes": "Lifecycle is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "relationships", "status": "covered", "notes": "Relationships is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "temporal", "status": "covered", "notes": "Temporal is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "spatial", "status": "covered", "notes": "Spatial is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "provenance", "status": "covered", "notes": "Provenance is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Ownership and stewardship is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "validation and quality", "status": "covered", "notes": "Validation and quality is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "access and privacy", "status": "covered", "notes": "Access and privacy is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention and deletion is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." }, { "dimension": "interoperability", "status": "covered", "notes": "Interoperability is explicit; candidate containment, runtime profiles, domain semantics, release-pinned mappings and independent review remain held where applicable." } ], "known_omissions": [ "Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.", "The only relation-ledger edge is candidate incoming WM-DAT-005 CONTAINS WM-ACT-053; it is not treated as approved composition or cascade authority.", "Batch, streaming, event, scientific, geospatial, machine-learning, ETL, ELT and transaction-processing executions require domain and runtime profiles.", "OpenLineage, OTel, Airflow, Kubernetes, OCI, WES and OGC materials have different technical or sector scopes and require release-pinned validation." ], "conflicts": [ "A reusable definition, run, task or stage instance, attempt, input binding, output materialization, validation result and telemetry observation are not interchangeable.", "Declared, resolved, consumed, materialized and published data states remain distinct.", "Successful process exit does not prove correct, complete, conformant, fresh, published or accepted output." ], "regional_assumptions": [ "Execution authority, data protection, cross-border processing, audit, retention and incident response depend on jurisdiction, organization and data classification.", "GDPR is a European Union legal profile, and NIST controls require deployment-specific tailoring.", "Orchestrator states, retry behavior, task identity, container semantics, quality rules, telemetry schemas and API behavior require versioned profiles." ], "adversarial_checks": [ "Reject a run or constituent without stable identity, definition revision, trigger, owner, source, state, event time and lineage head.", "Reject a retry or rerun that overwrites the original attempt, loses the effective data interval or silently changes code, inputs, parameters or environment.", "Reject a success claim inferred only from exit status when output materialization, publication, validation, quality and freshness remain unknown.", "Reject lineage that copies mutable dataset or software metadata without authoritative identifiers, versions, digests and source times.", "Reject autonomous execution, secret access, production mutation, destructive cleanup or protected disclosure outside explicit delegated authority." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The subject composes multiple independently identifiable task or stage instances, attempts, bindings, state events, materializations, validations and evidence records over one run. Aggregate is more accurate than event. The frozen record_plane world-model and catalogue entry_kind standalone-mm are separate axes from this subject-schema decision." }, "decisions": [ { "concept": "Run versus reusable definition", "disposition": "accepted", "rationale": "The aggregate owns one execution and immutable bindings. Pipeline, job and workflow definitions, schedules and code remain external masters." }, { "concept": "Input and output states", "disposition": "accepted", "rationale": "Declared, resolved and consumed inputs and declared, materialized and published outputs remain separate source-qualified assertions." }, { "concept": "Task, stage, attempt and retry", "disposition": "accepted", "rationale": "Each execution constituent has stable identity, causal membership, sequence, environment, states and times. Retry creates a successor attempt and never overwrites failure." }, { "concept": "Process outcome and data acceptance", "disposition": "accepted", "rationale": "Dispatch, start, process exit, output materialization, publication, schema validation, data quality, freshness and downstream acceptance are distinct outcomes." }, { "concept": "Lineage, telemetry and quality", "disposition": "accepted-external", "rationale": "External systems retain dataset, provenance, log, metric, trace and quality-result records. The run owns typed bindings, scope, times, integrity and bounded interpretation." }, { "concept": "Candidate containment", "disposition": "deferred", "rationale": "The incoming WM-DAT-005 CONTAINS WM-ACT-053 relation remains candidate. It supports a parent reference but grants no definition ownership, mutation or cascade behavior." }, { "concept": "Runtime and domain profiles", "disposition": "accepted-with-profile-hold", "rationale": "Batch, streaming, scientific, geospatial, ML, ETL, ELT and transactional systems differ. Airflow, Kubernetes, WES and OGC are bounded profiles, not universal semantics." }, { "concept": "Machine-readable projections", "disposition": "accepted-with-validation-hold", "rationale": "OpenLineage, PROV, OTel, CloudEvents, CWL, WES, OGC Processes, Airflow, Kubernetes, OCI and OpenAPI cover different surfaces. Every mapping must pin version, scope and loss." }, { "concept": "Single-provider waiver and no-tools audit", "disposition": "accepted-with-mandatory-hold", "rationale": "One Claude Sonnet and one Grok 4.6 research attempt each timed out after 120 seconds. Codex audited the frozen validated result and comparison locally without tools or new research facts. Confidence remains medium and assurance remains reviewable-draft." } ], "publicationHolds": [ "Absence-of-external-review hold: one Claude Sonnet and one Grok 4.6 research attempt for WM-ACT-053 each timed out after 120 seconds. No external research result was admitted.", "Relation hold: WM-DAT-005 CONTAINS WM-ACT-053 remains candidate and grants no ownership, mutation or cascade behavior.", "Domain and runtime hold: batch, streaming, event, scientific, geospatial, ML, ETL, ELT and transaction-processing executions require explicit domain, orchestrator and runtime profiles.", "Security and privacy hold: authorization, secrets, personal data, cross-border processing, logs, traces, cleanup and retention require adopting-Dimension and jurisdiction policies.", "Interoperability hold: all OpenLineage, PROV, OTel, CloudEvents, CWL, WES, OGC, Airflow, Kubernetes, OCI and OpenAPI projections require release-pinned mappings, scope constraints, loss declarations and validation.", "Outcome hold: successful process exit does not prove output publication, completeness, correctness, conformance, quality, freshness or downstream acceptance.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Approve or reject candidate containment by WM-DAT-005 and register any data, software, compute, telemetry, incident and records relations.", "Create execution profiles for batch, streaming, event-driven, scientific, geospatial, machine-learning, ETL, ELT and transactional workloads.", "Test release-pinned interoperability mappings with conformance, round-trip and information-loss evidence.", "Validate authorization, secret handling, resource, retry, side-effect, quality, observability, cleanup, privacy and retention policies for each deployment.", "Obtain supplemental independent external review and resolve any material challenge before canonical promotion." ] }, "statistics": { "sources": 17, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }