# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-26T13:49:24Z", "synthesisSha256": "bfaebc341dbb5ba8357ec6ab90ade4f75f864f22691e924cd6da759186b4856c", "providerMode": "dual-provider", "providers": [ "Claude", "Grok" ], "waivedProviders": [] }, "metaModel": { "id": "WM-AI-005", "registryId": "vr.wm-ai-005", "name": "Prompt / Agent Configuration", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.AI.PRM" ], "tags": [ "prompt", "agent", "configuration", "inf.ai.prm" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-ai-005-prompt-agent-configuration/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-ai-005", "model": { "registry_id": "vr.wm-ai-005", "model_id": "WM-AI-005", "name": "Prompt / Agent Configuration", "entry_kind": "aggregate", "purpose": "Describe, as a format-neutral aggregate, the versioned operational instruction set and tool configuration that governs how an AI model or agent behaves, so that an agent can identify, compose, validate, release, deploy, audit and retire a configuration revision reproducibly.", "scope_statement": "A Prompt / Agent Configuration is an immutable, versioned, content-addressable specification of agent behaviour. It aggregates instruction blocks (system, developer, template), template arguments and rendering rules, instruction authority levels and trust boundaries, model selection and decoding parameters, output contracts, tool and context/resource grants with risk annotations, server and authorization-scope bindings, safety constraints and human-oversight gates, autonomy and resource budgets, evaluation and adversarial evidence, provenance and release attestation, deployment bindings, and governance metadata (ownership, regulatory classification, access, retention). The model covers the configuration artifact and its lifecycle, not the actor that executes it and not the executions themselves.", "in_scope": [ "Identity, namespacing and content-addressed revision integrity of a configuration", "Instruction blocks, prompt templates, arguments and rendering/escaping rules", "Instruction authority hierarchy and untrusted-content trust boundaries", "Model selection, decoding parameters and declared output contract", "Tool grants, schema bindings, behaviour annotations and confirmation gates", "Context, root, resource and persistent-memory grants", "Server bindings, requested authorization scopes and secret referencing by handle", "Behavioural constraints, refusal policy and enforcement points outside the model", "Human oversight gates, autonomy caps and per-run resource budgets", "Evaluation suites, acceptance thresholds and adversarial-test evidence tied to a digest", "Authorship provenance, release attestation, signing and dependency inventory", "Version scheme, compatibility rules, lifecycle states and change control", "Environment binding, rollout, rollback and immediate-disable mechanisms", "Ownership, regulatory classification, confidentiality, access and retention" ], "out_of_scope": [ "The foundation model itself: weights, training data, fine-tuning and adapter artifacts", "The deployed agent as an actor, its persona in the world, and its runtime process", "Agent run/execution records, transcripts, traces and conversation content", "Tool and API implementations, their internal service contracts and hosting", "Identity and access management principals, credential issuance and secret storage", "Retrieval corpora, vector index construction and knowledge-base content", "Multi-agent orchestration topology and inter-agent negotiation protocols", "Serving infrastructure, hardware, autoscaling and cost accounting systems", "Content credentials or watermarking applied to generated outputs" ], "boundary_notes": [ { "neighbor": "WM-AI-002 AI Agent (deployed actor)", "distinction": "This model is the versioned instruction artifact; the agent model is the actor that loads it. The agent references a configuration revision; the configuration never contains agent runtime state, health or persona-in-world facts. One configuration may be referenced by many agents and one agent may swap configurations over time.", "source_refs": [ "SRC-016", "SRC-005" ] }, { "neighbor": "WM-AI-004 Agent Run / execution record", "distinction": "A run records the exact configuration revision identifier and digest for reproducibility. Only linkage fields (revision reference, telemetry attribute keys, conversation identifier) belong here; prompts, tool call payloads, outputs and timings of a specific execution belong to the run model.", "source_refs": [ "SRC-016", "SRC-011" ] }, { "neighbor": "WM-KNW-005 parent knowledge model", "distinction": "The configuration is a governed knowledge artifact and inherits identity, provenance and retention semantics, but adds executable operational semantics: authority levels, capability grants and enforcement points that a passive knowledge asset does not have.", "source_refs": [ "SRC-007", "SRC-013" ] }, { "neighbor": "Foundation model / model card artifact", "distinction": "The configuration records which model it is pinned to and which decoding parameters it sets; it does not describe training data, architecture, quantitative model-level analysis or model licensing. Those belong to a model-card style sibling aligned with CycloneDX ML-BOM.", "source_refs": [ "SRC-012", "SRC-005" ] }, { "neighbor": "Tool / MCP server definition", "distinction": "The configuration records the grant (which tool name, from which server, bound to which schema digest, with which confirmation gate). The tool's own definition, implementation, availability and versioning are owned by the server and its registry entry. Tool annotations are copied as untrusted claims, not as authoritative classification.", "source_refs": [ "SRC-001", "SRC-017", "SRC-004" ] }, { "neighbor": "Credential and secret management model", "distinction": "The configuration holds only opaque secret handles and requested authorization scopes. Secret values, rotation, vault policy and token issuance are out of scope; embedding a secret in instruction text is prohibited by policy rather than modelled here.", "source_refs": [ "SRC-018", "SRC-004" ] }, { "neighbor": "Software build / release artifact", "distinction": "The configuration borrows release semantics (immutability, semantic versioning, in-toto/SLSA attestation) but is not a code build: its externalParameters are instruction text and grants, and its correctness evidence is behavioural evaluation rather than compilation.", "source_refs": [ "SRC-009", "SRC-011" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Model Context Protocol Specification — Tools", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2026-07-28/server/tools", "version_or_date": "Protocol revision 2026-07-28", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Normative tool definition fields (name, title, description, inputSchema, outputSchema, annotations, icons), tool name constraints, untrusted-annotation warning, human-in-the-loop guidance, and server security duties." }, { "id": "SRC-002", "title": "Model Context Protocol Specification — Prompts", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2025-06-18/server/prompts", "version_or_date": "Protocol revision 2025-06-18", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Prompt template data type: name, title, description, arguments with required flag, PromptMessage roles and content types, argument validation and injection warnings." }, { "id": "SRC-003", "title": "Model Context Protocol — Versioning", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/versioning", "version_or_date": "Current revision 2026-07-28; date-based YYYY-MM-DD scheme", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Interface-revision versioning distinct from artifact versioning, per-request version declaration, feature deprecation policy and minimum deprecation windows." }, { "id": "SRC-004", "title": "Model Context Protocol — Security Best Practices", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2026-07-28/basic/security_best_practices", "version_or_date": "Protocol revision 2026-07-28", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Scope minimisation and least privilege, token audience rules, per-client consent, local server compromise and pre-execution consent, state handle hijacking, and audit/correlation requirements." }, { "id": "SRC-005", "title": "Model Context Protocol Specification — Sampling", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2026-07-28/client/sampling", "version_or_date": "Protocol revision 2026-07-28 (feature marked Deprecated)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Evidence that model preferences (hints, costPriority, speedPriority, intelligencePriority), systemPrompt, temperature, maxTokens, stopSequences, includeContext, tools and toolChoice are distinct configuration facets; also iteration-limit and human-approval guidance." }, { "id": "SRC-006", "title": "OpenAI Model Spec", "organization": "OpenAI", "url": "https://model-spec.openai.com/2025-10-27.html", "version_or_date": "2025-10-27", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Chain of command: root, system, developer, user and guideline authority levels; higher authority overrides lower; tool outputs, quoted text and attachments carry no authority by default." }, { "id": "SRC-007", "title": "NIST AI Risk Management Framework Playbook — GOVERN", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://airc.nist.gov/AI_RMF_Knowledge_Base/Playbook/Govern", "version_or_date": "AI RMF 1.0 Playbook, accessed 2026-08-26", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "GOVERN 1.2 change management and validation policy, GOVERN 1.6 AI system inventory as an organised database of artifacts, GOVERN 2.1 roles and separation of development from testing, GOVERN 4.2 documented risks, GOVERN 6.1 third-party and supply-chain policy." }, { "id": "SRC-008", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013; namespace http://www.w3.org/ns/prov#", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Entity/Activity/Agent model with wasGeneratedBy, wasDerivedFrom, wasAttributedTo, wasAssociatedWith, actedOnBehalfOf, used, startedAtTime/endedAtTime/generatedAtTime, Revision and specializationOf — the provenance vocabulary for configuration authorship." }, { "id": "SRC-009", "title": "Semantic Versioning 2.0.0", "organization": "Semantic Versioning project", "url": "https://semver.org/", "version_or_date": "2.0.0", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "MAJOR for incompatible changes, MINOR for backward-compatible additions, PATCH for fixes; released version contents MUST NOT be modified; pre-release and build-metadata syntax and precedence." }, { "id": "SRC-010", "title": "RFC 3339 — Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Fully qualified timestamps with seconds and an explicit UTC relationship expressed as Z or a numeric +/-hh:mm offset; basis for the model's timestamp rule." }, { "id": "SRC-011", "title": "SLSA Provenance (predicate specification)", "organization": "OpenSSF / SLSA project", "url": "https://slsa.dev/spec/v1.1/provenance", "version_or_date": "v1.1 (retired in favour of v1.2); predicate type https://slsa.dev/provenance/v1", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "in-toto Statement subject with resourceUri and digest; buildDefinition (buildType, externalParameters, internalParameters, resolvedDependencies) and runDetails (builder, invocationId, startedOn, finishedOn, byproducts) as the attestation shape for a released configuration revision." }, { "id": "SRC-012", "title": "CycloneDX Machine Learning Bill of Materials (ML-BOM)", "organization": "OWASP Foundation / CycloneDX (ECMA-424)", "url": "https://cyclonedx.org/capabilities/mlbom/", "version_or_date": "ECMA-424, accessed 2026-08-26", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Standardised inventory of datasets, models and configurations for AI systems, including model parameters, considerations and risk data — the alignment target for a configuration's dependency inventory." }, { "id": "SRC-013", "title": "AGENTS.md — an open format for guiding coding agents", "organization": "AGENTS.md community project", "url": "https://agents.md/", "version_or_date": "Accessed 2026-08-26", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Nested configuration precedence — the closest AGENTS.md to the edited file wins — plus plain-Markdown format with no required fields; basis for composition/overlay precedence and for the bootstrap contract." }, { "id": "SRC-014", "title": "Regulatory framework for AI (Regulation (EU) 2024/1689)", "organization": "European Commission, Directorate-General for Communications Networks, Content and Technology", "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai", "version_or_date": "Regulation (EU) 2024/1689; in force 1 August 2024, generally applicable 2 August 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Risk classes and high-risk obligations: risk management, technical documentation, activity logging for traceability, information to deployers, human oversight, robustness/accuracy/cybersecurity; GPAI transparency duties and phased application dates." }, { "id": "SRC-015", "title": "EU AI Act Article 13 — Transparency and provision of information to deployers", "organization": "Future of Life Institute (AI Act Explorer reproduction)", "url": "https://artificialintelligenceact.eu/article/13/", "version_or_date": "Reproduction of the Official Journal text of 13 June 2024", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Article-level detail on instructions for use, declared characteristics/capabilities/limitations and human-oversight measures. Used only to locate obligations; the authoritative text is the Official Journal version." }, { "id": "SRC-016", "title": "OpenTelemetry Semantic Conventions — GenAI attribute registry", "organization": "OpenTelemetry (Cloud Native Computing Foundation)", "url": "https://opentelemetry.io/docs/specs/semconv/registry/attributes/gen-ai/", "version_or_date": "Semantic Conventions 1.41.0; GenAI attributes at Development stability and relocated to the semantic-conventions-genai repository", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Attribute keys that carry configuration facets into telemetry: gen_ai.request.model, temperature, top_p, max_tokens, seed, stop_sequences, provider.name, operation.name, agent.id/name, tool.name, conversation.id, system_instructions, output.type." }, { "id": "SRC-017", "title": "MCP Registry — generic server.json reference", "organization": "Model Context Protocol project", "url": "https://raw.githubusercontent.com/modelcontextprotocol/registry/main/docs/reference/server-json/generic-server-json.md", "version_or_date": "Schema https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Reverse-DNS namespaced name as the ownership-bearing identifier, semantic version field, repository and packages/remotes declaration, and publisher-provided _meta under a reverse-DNS key." }, { "id": "SRC-018", "title": "OWASP Top 10 for Large Language Model Applications", "organization": "OWASP Foundation", "url": "https://owasp.org/www-project-top-10-for-large-language-model-applications/", "version_or_date": "Project page: v1.1 (2023) archived; active development moved to the OWASP GenAI Security Project", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Risk taxonomy underpinning the safety layers: prompt injection, insecure plugin/tool design, excessive agency, sensitive information disclosure and supply-chain risk. The 2025 revision was not directly verified in this session (see known omissions)." }, { "id": "SRC-019", "title": "JSON Schema 2020-12 release notes", "organization": "JSON Schema organisation", "url": "https://json-schema.org/draft/2020-12/release-notes", "version_or_date": "Draft 2020-12", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Dialect and vocabulary mechanics, $schema/$id/$dynamicRef and compound schema bundling — the validation dialect assumed by MCP tool input/output schemas and by configuration output contracts." }, { "id": "SRC-020", "title": "ISO/IEC 22989:2022/DAmd 1 Information technology — Artificial intelligence — Concepts and terminology — Amendment 1: Generative AI", "organization": "ISO/IEC JTC 1/SC 42", "url": "https://www.iso.org/obp/ui?iso:std:iso-iec:22989:dis:ed-1:v1:amd:1:v1:en", "version_or_date": "ISO/IEC 22989:2022/DAmd 1, term 3.6.19 prompt (public excerpt)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "Normative terminology for prompt as overarching generative-AI instructions, including that a prompt may be fixed or editable and may carry formatting and output controls." }, { "id": "SRC-021", "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf", "version_or_date": "NIST AI 600-1, July 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "GAI risks and suggested actions for AI configuration, human-AI configuration, prompt injection, jailbreaking, documentation, roles, red-teaming, and content filters that constrain instructions and tool use." }, { "id": "SRC-022", "title": "Semantic conventions for generative client AI spans", "organization": "OpenTelemetry / CNCF", "url": "https://raw.githubusercontent.com/open-telemetry/semantic-conventions-genai/main/docs/gen-ai/gen-ai-spans.md", "version_or_date": "Development status, semantic-conventions-genai main, accessed 2026-08-26", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "Observability identifiers for named prompt templates and versions, generation request parameters, conversation identifiers, and privacy-sensitive capture of instructions, inputs, and outputs." }, { "id": "SRC-023", "title": "Model Context Protocol — Tools", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2025-06-18/server/tools", "version_or_date": "Protocol revision 2025-06-18", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "Canonical tool definition (name, title, description, inputSchema, outputSchema, annotations), model-controlled invocation, listChanged, human-in-the-loop SHOULD, and security rules for validation, rate limits, and audit." }, { "id": "SRC-024", "title": "Agent Skills Specification", "organization": "Agent Skills (open standard originated by Anthropic)", "url": "https://agentskills.io/specification", "version_or_date": "Specification page accessed 2026-08-26", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "Skill package identity, SKILL.md frontmatter, progressive disclosure, compatibility, experimental allowed-tools, and validation of instruction packages." }, { "id": "SRC-025", "title": "Agent2Agent (A2A) Protocol Specification, Version 1.0", "organization": "A2A Project, Linux Foundation", "url": "https://a2a-protocol.org/latest/llms.txt", "version_or_date": "A2A 1.0.0 (Protobuf normative; docs specification.md 1.0.0)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "Agent Card identity, version, skills, modalities, security schemes, and extended authenticated card; distinguishes public discovery from operational instructions." }, { "id": "SRC-026", "title": "OpenAI Model Spec", "organization": "OpenAI", "url": "https://raw.githubusercontent.com/openai/model_spec/main/model_spec.md", "version_or_date": "Model Spec main branch, accessed 2026-08-26 (CC0 1.0)", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "Instruction authority chain (root, system, developer, user, guideline), override rules, and the requirement to follow applicable instructions without collapsing provider and developer layers." }, { "id": "SRC-027", "title": "OpenAI API — Agent definitions and stored prompts", "organization": "OpenAI", "url": "https://developers.openai.com/api/docs/guides/agents/define-agents", "version_or_date": "Agent definitions guide, accessed 2026-08-26", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "Agent configuration surface: name, instructions (static or dynamic), model and modelSettings, tools, handoffs, guardrails, MCP servers, structured outputs, and stored prompt id/version/variables with local override." }, { "id": "SRC-028", "title": "OWASP Top 10 for LLM Applications 2025", "organization": "OWASP Foundation", "url": "https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf", "version_or_date": "Version 2025, 2024-11-18", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "LLM01 prompt injection, LLM06 excessive agency via tools/skills/plugins, and LLM07 system prompt leakage: instructions are not secrets or security controls and must not contain credentials." }, { "id": "SRC-029", "title": "Safety system messages — Azure OpenAI in Azure AI Foundry Models", "organization": "Microsoft", "url": "https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/system-message", "version_or_date": "Azure AI Foundry documentation, accessed 2026-08-26", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "System message as scenario profile, capabilities, limitations, tone, safety guidelines, and tool-use instructions; concision because instructions consume the context window." }, { "id": "SRC-030", "title": "Agent Registry JSON schemas (A2A Agent Card and MCP tool schema)", "organization": "Google Cloud", "url": "https://docs.cloud.google.com/agent-registry/json-schemas", "version_or_date": "Documentation dated 2026-08-11; A2A Agent Card versions 0.3 and 1.0", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "Governed Agent Card and MCP tool payloads including skills, modalities, and tool annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint)." }, { "id": "SRC-031", "title": "ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system", "organization": "ISO/IEC JTC 1/SC 42", "url": "https://www.iso.org/standard/81230.html", "version_or_date": "ISO/IEC 42001:2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "AIMS requirements to document AI system design, development, operation, roles, and continual improvement; operational instruction configuration is a documented operational artefact, not the management system itself." }, { "id": "SRC-032", "title": "Model Context Protocol schema — Tool and ToolAnnotations", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2026-07-28/schema.md", "version_or_date": "Specification 2026-07-28", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T16:00:00Z", "relevance": "ToolAnnotations as untrusted hints (title, readOnlyHint, destructiveHint, idempotentHint, openWorldHint) with documented defaults and the rule that clients must not trust annotations from untrusted servers." } ], "structure": { "bundles": [ { "id": "identity-and-release-control", "name": "Identity and Release Control", "description": "How a configuration is named, uniquely addressed, digested, versioned and moved through controlled lifecycle states.", "rationale": "Without a stable identifier and an immutable, content-addressed revision, no downstream claim about behaviour, evidence or compliance can be attached to anything. Release immutability and version semantics are normative in SemVer and presumed by attestation formats.", "source_refs": [ "SRC-009", "SRC-011", "SRC-017", "SRC-007" ], "layers": [ { "id": "identity-and-addressing", "name": "Identity and Addressing", "description": "Names, namespaces, aliases and the digest that makes a revision comparable across stores.", "source_refs": [ "SRC-017", "SRC-001", "SRC-011" ], "findings": [ { "id": "configuration-identity", "name": "Configuration identity and addressing", "description": "The identifiers by which this configuration is known: the master-system identifier of record, an ownership-bearing namespaced name, and any unstable display aliases. MCP names are unique only within a server, so they are not global identifiers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-017" ], "questions": [ { "id": "q-master-identifier", "text": "Which authoritative master system issues the identifier for this configuration, and what is that identifier?", "kind": "identity", "answer_data": [ "Master system name and base IRI", "Identifier string as issued", "Whether the Dimension is the system of record or a replica" ] }, { "id": "q-global-namespace", "text": "What governed namespace or reverse-DNS name distinguishes this configuration from a same-named configuration published by someone else?", "kind": "interoperability", "answer_data": [ "Reverse-DNS namespace and local name", "Evidence of namespace ownership (DNS, repository or registry verification)" ] }, { "id": "q-configuration-kind", "text": "Is this a system instruction, a parameterised prompt template, an agent definition, a tool-grant set, or a composite of these?", "kind": "classification", "answer_data": [ "Configuration kind code", "Whether the kind changes the required fields", "Composite part list if applicable" ] }, { "id": "q-stable-aliases", "text": "Which display titles, slugs or aliases resolve to this configuration, and which of them are guaranteed stable?", "kind": "definition", "answer_data": [ "Alias values with stability flag", "Locale of each display title", "Resolution precedence among aliases" ] } ], "data_elements": [ { "id": "configuration-identifier", "name": "Configuration identifier", "description": "Identifier issued by the master system of record for the configuration as a whole, stable across all revisions.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-017", "SRC-007" ] }, { "id": "configuration-namespace-name", "name": "Namespaced configuration name", "description": "Reverse-DNS namespaced name asserting publisher ownership, for example com.example.agents/support-triage.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017" ] }, { "id": "configuration-kind-code", "name": "Configuration kind", "description": "Coded kind: system instruction, prompt template, agent definition, tool-grant set, or composite.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-001" ] }, { "id": "configuration-alias", "name": "Alias or display title", "description": "Human-facing label with an explicit stability flag and locale; never used as an identifier.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "configuration-identity-record", "name": "Configuration identity record", "description": "The registry or manifest header that binds the master identifier, namespaced name, kind and aliases to the configuration.", "media_or_form": [ "registry entry", "manifest header", "resolvable IRI" ], "serial": false, "identity_strategy": "Authoritative master-system identifier from the configuration registry of record; failing that a governed reverse-DNS namespaced name; failing that a UUID or ULID minted by the adopting Dimension.", "source_refs": [ "SRC-017", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "revision-integrity-and-content-address", "name": "Revision integrity and content address", "description": "Each released revision is an immutable snapshot identified by an algorithm-qualified digest over a canonical serialisation, with run-time-resolved regions explicitly excluded.", "source_refs": [ "SRC-011", "SRC-009", "SRC-001" ], "questions": [ { "id": "q-revision-digest", "text": "What algorithm-qualified digest identifies the exact content of this configuration revision?", "kind": "evidence", "answer_data": [ "Digest algorithm identifier", "Digest value", "Digest scope description" ] }, { "id": "q-canonical-form", "text": "Which canonical serialisation was digested so the same logical configuration yields the same digest in any store?", "kind": "validation", "answer_data": [ "Canonicalisation profile reference", "Key ordering, encoding and line-ending rules", "Round-trip test result" ] }, { "id": "q-digest-exclusions", "text": "Which regions are excluded from the digest because they resolve only at run time?", "kind": "composition", "answer_data": [ "Excluded field paths", "Reason for each exclusion", "How excluded values are recorded at run time instead" ] } ], "data_elements": [ { "id": "revision-identifier", "name": "Revision identifier", "description": "Identifier of one immutable revision of the configuration, issued by the master system.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-009" ] }, { "id": "revision-content-digest", "name": "Revision content digest", "description": "Algorithm-qualified digest over the canonical serialisation of the revision; the equality test for two stored copies.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "canonical-form-reference", "name": "Canonicalisation profile reference", "description": "Reference to the canonicalisation rules applied before digesting.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "digest-excluded-region", "name": "Digest-excluded region", "description": "Field paths deliberately outside the digest because they are resolved at run time, such as secret handles or resolved model build identifiers.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-004" ] } ], "artifacts": [ { "id": "configuration-revision-snapshot", "name": "Configuration revision snapshot", "description": "The frozen, digestible bundle containing instruction blocks, parameters, grants and policy bindings for one revision.", "media_or_form": [ "immutable manifest", "signed bundle", "content-addressed blob" ], "serial": true, "identity_strategy": "Master-system revision identifier as the primary key, with the algorithm-qualified content digest as the authoritative tie-breaker for byte equality.", "source_refs": [ "SRC-011", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "configuration-kind-and-intended-use", "name": "Configuration kind and intended use", "description": "Configurations are not one kind. ISO 22989 treats prompt as overarching generative-AI instructions that may be fixed or editable. MCP treats prompts as user-selected templates and tools as model-controlled functions. OpenAI packages instructions, tools, model settings, guardrails, and handoffs as an agent. Agent Skills packages task expertise separately from the host agent. Classification must record kind, intended task, and whether the payload is public discovery or operational instruction.", "source_refs": [ "SRC-020", "SRC-002", "SRC-024", "SRC-027" ], "questions": [ { "id": "configuration-kind-and-intended-use-q01", "text": "Is this payload an instruction stack, a user-selectable prompt template, a skill package, a tool catalog binding, a stored-prompt reference, or a composite agent configuration?", "kind": "classification", "answer_data": [ "config_kind_code", "kind_scheme", "is_composite" ] }, { "id": "configuration-kind-and-intended-use-q02", "text": "What intended purpose, user population, and prohibited uses bound this configuration?", "kind": "definition", "answer_data": [ "intended_purpose", "user_population", "prohibited_uses", "refusal_domains" ] }, { "id": "configuration-kind-and-intended-use-q03", "text": "Is the prompt fixed by the deployer, editable by operators, or dynamically generated per request, and who may edit it?", "kind": "state", "answer_data": [ "mutability_code", "dynamic_instruction_flag", "editor_roles" ] }, { "id": "configuration-kind-and-intended-use-q04", "text": "Which fields may appear on a public discovery card versus remaining in the operational instruction body?", "kind": "classification", "answer_data": [ "public_fields", "authenticated_extended_fields", "operational_only_fields" ] } ], "data_elements": [ { "id": "configuration-kind-and-intended-use-data01", "name": "Configuration kind", "description": "Code for instruction-stack, prompt-template, skill-package, tool-binding, stored-prompt, or composite-agent-config.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-002", "SRC-024", "SRC-027" ] }, { "id": "configuration-kind-and-intended-use-data02", "name": "Intended purpose", "description": "Human-defined objective the configuration is designed to serve, aligned to ISO AI-system objectives and Agent Card description.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-025", "SRC-031" ] }, { "id": "configuration-kind-and-intended-use-data03", "name": "Mutability", "description": "Whether instruction text is fixed, operator-editable, or dynamically composed at request time.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-027" ] } ], "artifacts": [ { "id": "configuration-kind-and-intended-use-artifact01", "name": "Configuration kind and intended-use statement", "description": "Classified kind, purpose, audience, and public-versus-operational field map for one configuration.", "media_or_form": [ "application/json", "text/markdown" ], "serial": true, "identity_strategy": "Same master-system identifier as the configuration version", "source_refs": [ "SRC-020", "SRC-025", "SRC-031" ] } ], "inline_only_rationale": null } ] }, { "id": "versioning-and-lifecycle", "name": "Versioning and Lifecycle", "description": "Version semantics, compatibility declarations, lifecycle states and the change-control record behind each transition.", "source_refs": [ "SRC-009", "SRC-003", "SRC-007" ], "findings": [ { "id": "version-scheme-and-compatibility", "name": "Version scheme and compatibility", "description": "Which version scheme applies, which change classes are breaking for a configuration (authority, grants, output contract, safety constraints), and which interface revisions are declared compatible. Interface revision and artifact version are separate axes.", "source_refs": [ "SRC-009", "SRC-003", "SRC-017" ], "questions": [ { "id": "q-version-scheme", "text": "Which version scheme governs this configuration and what change classes force a major increment?", "kind": "classification", "answer_data": [ "Version string", "Scheme identifier", "Breaking-change class list" ] }, { "id": "q-consumer-pinning", "text": "Which consumers pin this configuration by exact revision rather than by a version range?", "kind": "relationship", "answer_data": [ "Consumer references", "Pinning mode per consumer", "Upgrade notification path" ] }, { "id": "q-protocol-compatibility", "text": "Which protocol or interface revisions does this configuration declare itself compatible with?", "kind": "interoperability", "answer_data": [ "Declared protocol revision identifiers", "Known-incompatible revisions", "Behaviour on negotiation failure" ] }, { "id": "q-release-immutability", "text": "May a released version be edited in place, and if not, how are corrections issued?", "kind": "constraint", "answer_data": [ "Immutability rule statement", "Correction procedure", "Supersedes link to the corrected revision" ] } ], "data_elements": [ { "id": "version-string", "name": "Version string", "description": "Version of the configuration artifact, ordered by the declared scheme.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "version-scheme-code", "name": "Version scheme", "description": "Coded scheme, for example semantic versioning 2.0.0 or a date-based interface revision scheme.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-003" ] }, { "id": "compatible-protocol-revision", "name": "Compatible interface revision", "description": "Interface or protocol revision identifiers this configuration is declared to work against, recorded separately from its own version.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "supersedes-revision-reference", "name": "Supersedes revision", "description": "Reference to the revision this one replaces.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-008" ] } ], "artifacts": [ { "id": "version-manifest", "name": "Version and compatibility manifest", "description": "Declaration of version, scheme, breaking-change class and compatible interface revisions, published with the revision.", "media_or_form": [ "manifest", "release note", "registry record" ], "serial": true, "identity_strategy": "Namespaced configuration name plus version string; the revision digest disambiguates rebuilds of the same version string.", "source_refs": [ "SRC-009", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "lifecycle-states-and-change-control", "name": "Lifecycle states and change control", "description": "The state a revision occupies, the transitions permitted, the approval evidence required to promote it, and the separately recorded instants of authoring, approval, release and withdrawal.", "source_refs": [ "SRC-007", "SRC-003", "SRC-010" ], "questions": [ { "id": "q-current-state", "text": "What lifecycle state is this revision in and which states are reachable from it?", "kind": "state", "answer_data": [ "Current state code", "Permitted next states", "Guard conditions per transition" ] }, { "id": "q-promotion-authority", "text": "Who must approve promotion to production and on what evidence?", "kind": "decision", "answer_data": [ "Approver identity and role", "Required evidence set", "Recorded decision and rationale" ] }, { "id": "q-lifecycle-timestamps", "text": "When was this revision authored, approved, released and withdrawn, each recorded as a separate instant?", "kind": "temporal", "answer_data": [ "Authored-at, approved-at, released-at, withdrawn-at timestamps", "Ingestion timestamp where it differs from the event instant" ] }, { "id": "q-deprecation-notice", "text": "What notice period applies before this configuration is withdrawn from service?", "kind": "lifecycle", "answer_data": [ "Notice period duration", "Migration path or statement that none is required", "Notification channel and recipients" ] } ], "data_elements": [ { "id": "lifecycle-state-code", "name": "Lifecycle state", "description": "Coded state such as draft, candidate, approved, released, deprecated or withdrawn.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "authored-at-time", "name": "Authored at", "description": "Event time at which the revision content was completed, RFC 3339 with seconds and explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-008" ] }, { "id": "released-at-time", "name": "Released at", "description": "Event time at which the revision became immutable and available for binding.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-009" ] }, { "id": "withdrawn-at-time", "name": "Withdrawn at", "description": "Event time at which the revision ceased to be available for new bindings.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-003" ] }, { "id": "approver-reference", "name": "Approver reference", "description": "Reference to the agent or body that approved promotion, with the recorded rationale.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "deprecation-window", "name": "Deprecation notice period", "description": "Minimum duration between deprecation announcement and eligibility for removal.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "change-control-record", "name": "Change control record", "description": "Approval and transition log for one revision, linking evidence, approver, rationale and timestamps.", "media_or_form": [ "approval record", "change ticket", "signed tag" ], "serial": true, "identity_strategy": "Revision identifier plus transition sequence number issued by the change-control system of record.", "source_refs": [ "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "external-schema-alignment", "name": "External schema alignment and conflicts", "description": "This model aligns to ISO 22989 prompt, MCP tools and prompts, A2A AgentSkill, Agent Skills, OpenTelemetry gen_ai.prompt.* and generation attributes, and vendor agent objects. Alignments are not conformance claims. Known conflicts include MCP user-controlled prompts versus developer system instructions, OpenAI provider-system versus industry system-message, OTel date-like version examples, and OpenAI migration away from hosted prompt objects.", "source_refs": [ "SRC-020", "SRC-022", "SRC-023", "SRC-002", "SRC-024", "SRC-025", "SRC-027" ], "questions": [ { "id": "external-schema-alignment-q01", "text": "Which external schemas is this configuration mapped to, and with what field-level mapping evidence?", "kind": "interoperability", "answer_data": [ "alignment_targets", "field_map", "mapping_evidence" ] }, { "id": "external-schema-alignment-q02", "text": "Is any conformance to MCP, A2A, Agent Skills, or OTel actually claimed, and what test evidence supports it?", "kind": "evidence", "answer_data": [ "conformance_claims", "test_harness", "failed_constraints" ] }, { "id": "external-schema-alignment-q03", "text": "Which recorded conflicts (prompt control, system-layer meaning, version-as-date, hosted versus repo prompts) affect this instance?", "kind": "decision", "answer_data": [ "applicable_conflicts", "chosen_interpretation", "rationale" ] }, { "id": "external-schema-alignment-q04", "text": "Which storage or interface projection carries this instance, without treating that projection as the semantic model?", "kind": "interoperability", "answer_data": [ "projection_type", "interface_url", "not_semantic_flag" ] } ], "data_elements": [ { "id": "external-schema-alignment-data01", "name": "Alignment targets", "description": "External schemas this instance is mapped to.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-020", "SRC-022", "SRC-023", "SRC-025" ] }, { "id": "external-schema-alignment-data02", "name": "Conformance claims", "description": "Optional explicit conformance statements with evidence; empty means alignment only.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-025" ] }, { "id": "external-schema-alignment-data03", "name": "Recorded conflicts", "description": "Conflicts among aligned standards that apply to this instance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-026", "SRC-027" ] }, { "id": "external-schema-alignment-data04", "name": "Projection type", "description": "Storage or interface used, such as repo files, hosted prompt object, MCP server, or Agent Card.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-025", "SRC-027" ] } ], "artifacts": [ { "id": "external-schema-alignment-artifact01", "name": "External schema alignment map", "description": "Field mappings, optional conformance evidence, and recorded conflicts for one configuration family.", "media_or_form": [ "application/json", "text/markdown" ], "serial": true, "identity_strategy": "Alignment-map identifier plus configuration-family identifier", "source_refs": [ "SRC-020", "SRC-022", "SRC-023", "SRC-025" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "instruction-content-and-authority", "name": "Instruction Content and Authority", "description": "What the configuration actually says, how it is parameterised and rendered, what authority each part carries, and how untrusted content is kept out of the instruction channel.", "rationale": "Instruction content is the substance of the artifact, but its operational meaning depends entirely on authority level and trust boundary: the same sentence in a developer block and in a retrieved document must be treated differently.", "source_refs": [ "SRC-006", "SRC-002", "SRC-004", "SRC-013" ], "layers": [ { "id": "instruction-content", "name": "Instruction Content and Composition", "description": "The instruction blocks themselves, their templating surface, and how configurations layer over one another.", "source_refs": [ "SRC-002", "SRC-013", "SRC-019" ], "findings": [ { "id": "instruction-blocks-and-templating", "name": "Instruction blocks, arguments and rendering", "description": "The discrete blocks that make up the instruction payload, their roles and ordering, the named arguments a template accepts, the substitution step that produces final messages, and the escaping that keeps argument values from being read as instructions.", "source_refs": [ "SRC-002", "SRC-004", "SRC-019", "SRC-016" ], "questions": [ { "id": "q-block-inventory", "text": "Which discrete instruction blocks make up this configuration and what role does each carry?", "kind": "composition", "answer_data": [ "Block identifiers with role codes", "Ordering index", "Per-block token estimate" ] }, { "id": "q-primary-system-block", "text": "Which block is delivered to the model as the system or developer instruction before any user input?", "kind": "definition", "answer_data": [ "Block identifier", "Verbatim block body or its digest", "Delivery channel or API field used" ] }, { "id": "q-template-arguments", "text": "Which named arguments does this template accept and which of them are required?", "kind": "requirement", "answer_data": [ "Argument names", "Required flag per argument", "Per-argument value schema" ] }, { "id": "q-render-pipeline", "text": "What rendering or substitution step turns the template plus arguments into the final message sequence?", "kind": "process", "answer_data": [ "Rendering engine and version", "Deterministic output guarantee", "Rendered message role sequence" ] }, { "id": "q-argument-failure", "text": "What happens when a required argument is missing or fails schema validation?", "kind": "exception", "answer_data": [ "Error code or failure mode", "Whether the call is refused or degraded", "Operator-visible message" ] } ], "data_elements": [ { "id": "instruction-block-body", "name": "Instruction block body", "description": "The literal instruction text or multimodal content of one block.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-016" ] }, { "id": "instruction-block-role", "name": "Instruction block role", "description": "Coded role of the block: system, developer, user-facing example, assistant seed, or reference material.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-006" ] }, { "id": "instruction-block-language", "name": "Instruction block language", "description": "Language tag of the block content, where the configuration is localised.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "template-argument-name", "name": "Template argument name", "description": "Name of a substitutable argument accepted by the template.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "template-argument-required", "name": "Template argument required flag", "description": "Whether the argument must be supplied for the template to render.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "template-argument-schema", "name": "Template argument schema", "description": "Schema constraining permitted argument values, expressed in a declared dialect.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-002" ] }, { "id": "argument-escaping-rule", "name": "Argument escaping rule", "description": "Rule describing how substituted values are delimited or escaped so they cannot be interpreted as instructions.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "prompt-template-definition", "name": "Prompt template definition", "description": "The template body plus its argument declarations and rendering rules, addressable independently of any single rendering.", "media_or_form": [ "template file", "argument schema document", "message array definition" ], "serial": false, "identity_strategy": "Configuration revision identifier plus block identifier; the block body digest resolves duplicates across formats.", "source_refs": [ "SRC-002", "SRC-019" ] } ], "inline_only_rationale": null }, { "id": "configuration-composition-and-precedence", "name": "Composition, overlays and precedence", "description": "How this configuration imports or overrides bases, which file wins when several apply to the same working scope, which fragments are shared with other configurations, and how locale or tenant variants are selected.", "source_refs": [ "SRC-013", "SRC-006", "SRC-017" ], "questions": [ { "id": "q-base-imports", "text": "Which parent or base configurations does this revision import, extend or override?", "kind": "composition", "answer_data": [ "Base revision references", "Override mode per import", "Resulting effective field list" ] }, { "id": "q-file-precedence", "text": "When more than one configuration applies to the same working scope, which one wins?", "kind": "constraint", "answer_data": [ "Precedence rule statement", "Scope path of each candidate", "Deterministic tie-break" ] }, { "id": "q-shared-fragments", "text": "Which fragments are shared with other configurations and therefore change together?", "kind": "relationship", "answer_data": [ "Shared fragment references", "Dependent configuration references", "Blast-radius estimate on change" ] }, { "id": "q-variant-selection", "text": "Which locale, tenant or channel variants exist and how is one selected at run time?", "kind": "classification", "answer_data": [ "Variant keys and selectors", "Fallback variant", "Selection evaluation order" ] } ], "data_elements": [ { "id": "base-configuration-reference", "name": "Base configuration reference", "description": "Reference to a parent revision that this configuration extends or overrides.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "overlay-scope-path", "name": "Overlay scope", "description": "The working scope (directory, tenant, product surface) over which this configuration takes effect.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "precedence-rule-statement", "name": "Precedence rule", "description": "Declared rule resolving which configuration wins when scopes overlap, for example nearest-scope-wins.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "shared-fragment-reference", "name": "Shared fragment reference", "description": "Reference to an instruction fragment reused by more than one configuration.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-017" ] }, { "id": "variant-selector", "name": "Variant selector", "description": "Selector expression choosing a locale, tenant or channel variant.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [ { "id": "composition-graph", "name": "Composition and precedence graph", "description": "Resolved graph of bases, overlays, shared fragments and variants, with the precedence trace that produced the effective configuration.", "media_or_form": [ "dependency graph", "include list", "nested file tree", "precedence trace" ], "serial": false, "identity_strategy": "Effective-configuration digest of the resolved graph, keyed by the root revision identifier and the scope selector.", "source_refs": [ "SRC-013", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "skill-package-bindings", "name": "Skill packages and progressive disclosure", "description": "A skill is a directory with SKILL.md frontmatter (name, description, optional license, compatibility, metadata, experimental allowed-tools) plus optional scripts, references, and assets. Agents load name and description first, then the instruction body on activation, then referenced files on demand. Name must match the directory. This is operational instruction packaging, not the knowledge corpus of the references themselves.", "source_refs": [ "SRC-024", "SRC-025" ], "questions": [ { "id": "skill-package-bindings-q01", "text": "What skill name, description, license, compatibility, and directory identity uniquely identify each bound skill version?", "kind": "identity", "answer_data": [ "skill_name", "skill_description", "license", "compatibility", "directory_name" ] }, { "id": "skill-package-bindings-q02", "text": "Under what conditions is a skill activated, and which instruction body, scripts, and references may then load?", "kind": "process", "answer_data": [ "activation_trigger", "instruction_body_ref", "scripts", "references", "assets" ] }, { "id": "skill-package-bindings-q03", "text": "Does the skill declare experimental allowed-tools, and how is that reconciled with the host configuration allowlist?", "kind": "constraint", "answer_data": [ "allowed_tools_string", "host_allowlist", "reconciliation_rule" ] }, { "id": "skill-package-bindings-q04", "text": "Was the skill validated against naming and frontmatter rules, and what validator and result apply?", "kind": "validation", "answer_data": [ "validator_name", "validation_result", "violations" ] } ], "data_elements": [ { "id": "skill-package-bindings-data01", "name": "Skill name", "description": "Lowercase hyphenated identifier matching the skill directory, max 64 characters.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-024" ] }, { "id": "skill-package-bindings-data02", "name": "Skill description", "description": "What the skill does and when to use it; loaded at startup for routing.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-024" ] }, { "id": "skill-package-bindings-data03", "name": "Compatibility", "description": "Environment or product requirements for the skill.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-024" ] }, { "id": "skill-package-bindings-data04", "name": "Skill allowed-tools", "description": "Experimental space-separated pre-approved tools the skill may use.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-024" ] }, { "id": "skill-package-bindings-data05", "name": "Skill bundled resources", "description": "References to scripts, references, and assets loaded on demand.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-024" ] } ], "artifacts": [ { "id": "skill-package-bindings-artifact01", "name": "Skill package", "description": "SKILL.md plus optional scripts, references, and assets for one skill version.", "media_or_form": [ "text/markdown", "application/zip", "inode/directory" ], "serial": true, "identity_strategy": "Skill name matching directory plus package digest; metadata.version if present is a label only", "source_refs": [ "SRC-024" ] } ], "inline_only_rationale": null } ] }, { "id": "authority-and-trust-boundaries", "name": "Authority and Trust Boundaries", "description": "The precedence of instructions against platform, developer and user levels, and the declared boundary between instructions and untrusted content.", "source_refs": [ "SRC-006", "SRC-004", "SRC-018" ], "findings": [ { "id": "instruction-authority-hierarchy", "name": "Instruction authority hierarchy", "description": "The authority level each block occupies relative to platform, developer and user instructions, which instructions an end user may override, and how equal-authority conflicts resolve. Higher authority overrides lower; developer configuration cannot override platform-level rules.", "source_refs": [ "SRC-006", "SRC-002", "SRC-014" ], "questions": [ { "id": "q-authority-level", "text": "At which authority level does each instruction block sit relative to platform, developer and user instructions?", "kind": "authority", "answer_data": [ "Authority level code per block", "Platform rules that remain non-overridable", "Delegation statements that grant authority downward" ] }, { "id": "q-user-overridable", "text": "Which instructions may an end user override and which are non-negotiable for this deployment?", "kind": "constraint", "answer_data": [ "Overridable instruction list", "Non-negotiable instruction list", "Override recording requirement" ] }, { "id": "q-peer-conflict", "text": "How is a conflict between two instructions of equal authority resolved?", "kind": "decision", "answer_data": [ "Tie-break rule (order, specificity or explicit precedence)", "Worked conflict example", "Fallback when no rule applies" ] } ], "data_elements": [ { "id": "instruction-authority-level", "name": "Instruction authority level", "description": "Coded authority level assigned to a block, ordered against platform, developer, user and guideline levels.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "user-override-permission", "name": "User override permission", "description": "Whether and how an end user may override a given instruction.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "authority-conflict-rule", "name": "Authority conflict rule", "description": "Declared resolution rule for equal-authority conflicts.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Authority level is an annotation carried on each instruction block and reproduced in the runtime message envelope; it has no separately addressable, separately retained representation. Extracting it into a standalone artifact would create a second source of truth that could drift from the digested revision, which is precisely the failure the content-address rule exists to prevent. It is therefore modelled as inline data on the revision snapshot and as reference data in the precedence trace produced by effective-configuration resolution." }, { "id": "untrusted-content-and-injection-defence", "name": "Untrusted content boundary and injection defence", "description": "Which inbound channels carry no instruction authority, how such content is delimited, what injection testing evidence exists for this revision, and what the runtime does on detection. Tool outputs, retrieved documents and attachments have no authority by default.", "source_refs": [ "SRC-006", "SRC-004", "SRC-018" ], "questions": [ { "id": "q-untrusted-channels", "text": "Which inbound content channels are declared untrusted and stripped of instruction authority?", "kind": "security", "answer_data": [ "Channel list (tool results, retrieved documents, attachments, quoted text)", "Any channel explicitly granted authority and by whom" ] }, { "id": "q-content-delimiters", "text": "What structural markers separate retrieved or tool-returned content from configuration instructions?", "kind": "constraint", "answer_data": [ "Delimiter or envelope convention", "Behaviour when the delimiter appears in the content itself" ] }, { "id": "q-injection-evidence", "text": "What evidence shows this revision was tested against direct and indirect prompt injection?", "kind": "evidence", "answer_data": [ "Test suite reference and run date", "Revision digest tested", "Pass rate and unresolved cases" ] }, { "id": "q-escalation-on-detection", "text": "What does the runtime do when injected instructions are detected mid-run?", "kind": "event", "answer_data": [ "Detection signal source", "Automatic action (halt, quarantine, escalate)", "Notification target and record written" ] } ], "data_elements": [ { "id": "untrusted-channel-declaration", "name": "Untrusted channel declaration", "description": "Enumerated inbound channels whose content must not be executed as instructions.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-004" ] }, { "id": "content-delimiter-convention", "name": "Content delimiter convention", "description": "Structural convention marking untrusted content within the assembled context.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "injection-test-reference", "name": "Injection test reference", "description": "Reference to injection test runs executed against this revision digest.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-007" ] }, { "id": "injection-detection-action", "name": "Injection detection action", "description": "Coded runtime action taken when injection is detected.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-018" ] } ], "artifacts": [ { "id": "trust-boundary-declaration", "name": "Trust boundary declaration", "description": "Document declaring untrusted channels, delimiting conventions, detection signals and escalation behaviour for this configuration.", "media_or_form": [ "policy section", "threat model document", "runtime guard configuration" ], "serial": false, "identity_strategy": "Configuration revision identifier plus declaration section identifier; superseded whenever the revision digest changes.", "source_refs": [ "SRC-004", "SRC-018" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "capability-and-binding-surface", "name": "Capability and Binding Surface", "description": "What the configuration lets the model do: which model it invokes and how, what it may output, which tools and context it may reach, and which servers, scopes and credentials it binds.", "rationale": "Capability grants are the part of a configuration with direct security and cost consequences, and they are the part most likely to drift after release because tool lists, servers and model builds change underneath a pinned artifact.", "source_refs": [ "SRC-001", "SRC-005", "SRC-004", "SRC-016", "SRC-019" ], "layers": [ { "id": "model-invocation-parameters", "name": "Model Invocation Parameters", "description": "Model pinning and preferences, decoding parameters and the declared output contract.", "source_refs": [ "SRC-005", "SRC-016", "SRC-019" ], "findings": [ { "id": "model-selection-and-preferences", "name": "Model selection and preferences", "description": "Which model and provider the configuration is pinned to, or the abstract capability priorities and hints used when no exact model is pinned, and what must be re-validated when the model changes beneath a pinned configuration.", "source_refs": [ "SRC-005", "SRC-016", "SRC-006" ], "questions": [ { "id": "q-pinned-model", "text": "Which model and provider is this configuration pinned to, if any?", "kind": "identity", "answer_data": [ "Model identifier and build", "Provider name", "Whether the pin is exact or family-level" ] }, { "id": "q-selection-preferences", "text": "If no exact model is pinned, which capability priorities and hints drive selection?", "kind": "decision", "answer_data": [ "Cost, speed and intelligence priority values", "Ordered model hints", "Whether hints are advisory or binding" ] }, { "id": "q-model-drift", "text": "What must be re-validated when the underlying model changes beneath a pinned configuration?", "kind": "validation", "answer_data": [ "Re-validation trigger list", "Evaluation subset to rerun", "Blocking versus advisory outcome" ] } ], "data_elements": [ { "id": "target-model-identifier", "name": "Target model identifier", "description": "Identifier of the model the configuration invokes, matching the telemetry request-model attribute.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016", "SRC-005" ] }, { "id": "model-provider-name", "name": "Model provider name", "description": "Coded provider supplying the model.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "model-selection-hint", "name": "Model selection hint", "description": "Ordered advisory hints naming preferred models or model families.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "capability-priority-set", "name": "Capability priority set", "description": "Normalised cost, speed and intelligence priorities used when no exact model is pinned.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "model-revalidation-trigger", "name": "Model re-validation trigger", "description": "Conditions on the underlying model that require evaluation evidence to be refreshed.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "Model binding is a small set of scalar fields and an advisory hint list that live inside the digested revision manifest and are mirrored into telemetry attributes at run time. They have no independent custody, lifecycle or retention: a pinned model identifier is meaningless outside the revision that pins it, and the resolved build is a run-time fact belonging to the agent-run model. Promoting this to a separate artifact would duplicate the manifest without adding an addressable object." }, { "id": "generation-parameters-and-output-contract", "name": "Generation parameters and output contract", "description": "The decoding parameters the configuration sets, which of them a runtime may silently ignore or clamp, the required output shape, and the schema dialect that governs it.", "source_refs": [ "SRC-005", "SRC-016", "SRC-019", "SRC-001" ], "questions": [ { "id": "q-decoding-values", "text": "Which decoding parameters are set and what value does each take?", "kind": "measurement", "answer_data": [ "Temperature, top-p, max tokens, stop sequences, seed", "Provider-specific extra parameters", "Units and permitted ranges" ] }, { "id": "q-ignored-parameters", "text": "Which of these parameters may the runtime silently ignore, clamp or reject?", "kind": "exception", "answer_data": [ "Parameters the client may modify or drop", "Parameters the client must respect", "Observed clamping behaviour per provider" ] }, { "id": "q-output-contract", "text": "What output format does this configuration require and is it enforced by a schema?", "kind": "requirement", "answer_data": [ "Output type code", "Output schema document or digest", "Enforcement point and failure action" ] }, { "id": "q-schema-dialect", "text": "Which schema dialect governs the declared output structure?", "kind": "interoperability", "answer_data": [ "Dialect IRI or default assumption", "Reference resolution rules applied", "Validator implementation used" ] } ], "data_elements": [ { "id": "decoding-temperature", "name": "Temperature", "description": "Randomness control for generation; range depends on the provider.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-016" ] }, { "id": "decoding-top-p", "name": "Top-p", "description": "Nucleus sampling parameter.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "decoding-max-tokens", "name": "Maximum output tokens", "description": "Upper bound on generated tokens; treated as binding on the runtime.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-016" ] }, { "id": "decoding-stop-sequence", "name": "Stop sequences", "description": "Sequences that terminate generation.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-016" ] }, { "id": "decoding-seed", "name": "Generation seed", "description": "Seed value supporting reproducible generation where the provider honours it.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "output-type-code", "name": "Output type", "description": "Coded output modality or format expected from the model.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "output-schema-definition", "name": "Output schema", "description": "Schema constraining structured output, with an explicit dialect.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-001" ] }, { "id": "schema-validation-failure-action", "name": "Schema validation failure action", "description": "Declared behaviour when generated output fails validation against the output schema.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-019" ] } ], "artifacts": [ { "id": "output-schema-document", "name": "Output schema document", "description": "The schema document defining the required output structure, addressable and versionable independently of the prose instructions.", "media_or_form": [ "JSON Schema document", "response format declaration" ], "serial": false, "identity_strategy": "Schema $id IRI where present, otherwise the configuration revision identifier plus schema digest.", "source_refs": [ "SRC-019", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "modalities-and-handoff-bindings", "name": "Structured outputs, modalities and handoffs", "description": "A2A Agent Cards declare default input and output MIME types and skills with examples. OpenAI agents add structured outputs and handoffs with handoffDescription. Configuration must state the output contract and which specialist configurations may be delegated to, without absorbing those specialists' identities.", "source_refs": [ "SRC-025", "SRC-027", "SRC-030" ], "questions": [ { "id": "modalities-and-handoff-bindings-q01", "text": "What structured-output schema or MIME types must responses satisfy, and what happens on violation?", "kind": "constraint", "answer_data": [ "output_schema", "output_mime_types", "on_violation" ] }, { "id": "modalities-and-handoff-bindings-q02", "text": "Which default input and output modalities are enabled, and which are overridden per skill?", "kind": "classification", "answer_data": [ "default_input_modes", "default_output_modes", "per_skill_overrides" ] }, { "id": "modalities-and-handoff-bindings-q03", "text": "Which other configurations or agents may be handed off to, with what descriptions and constraints?", "kind": "relationship", "answer_data": [ "handoff_targets", "handoff_description", "handoff_constraints" ] }, { "id": "modalities-and-handoff-bindings-q04", "text": "Which skills are advertised on a discovery card versus only available inside this operational configuration?", "kind": "interoperability", "answer_data": [ "advertised_skill_ids", "internal_only_skill_ids", "examples" ] } ], "data_elements": [ { "id": "modalities-and-handoff-bindings-data01", "name": "Structured output schema", "description": "Schema the model output is constrained to when structured outputs are enabled.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-027" ] }, { "id": "modalities-and-handoff-bindings-data02", "name": "Default input modes", "description": "MIME types accepted as default inputs.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-025" ] }, { "id": "modalities-and-handoff-bindings-data03", "name": "Default output modes", "description": "MIME types produced as default outputs.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-025" ] }, { "id": "modalities-and-handoff-bindings-data04", "name": "Handoff targets", "description": "References to other agent or configuration identities this specialist may delegate to.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-027" ] } ], "artifacts": [ { "id": "modalities-and-handoff-bindings-artifact01", "name": "Output, modality and handoff contract", "description": "Structured-output schema, modality lists, advertised skills, and handoff bindings for one configuration version.", "media_or_form": [ "application/json" ], "serial": true, "identity_strategy": "Configuration version identifier plus contract digest", "source_refs": [ "SRC-025", "SRC-027" ] } ], "inline_only_rationale": null } ] }, { "id": "tool-and-context-grants", "name": "Tool and Context Grants", "description": "Which tools the configuration may call, how risky each is declared to be, and what context, roots and memory it may read or write.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "findings": [ { "id": "tool-grant-and-schema-binding", "name": "Tool grants and schema binding", "description": "The named tools the configuration may call, the server each comes from, the input and output schema digests bound at release, disambiguation of colliding names across servers, and explicit denials.", "source_refs": [ "SRC-001", "SRC-004", "SRC-019" ], "questions": [ { "id": "q-granted-tools", "text": "Which named tools may this configuration call and from which server does each come?", "kind": "access", "answer_data": [ "Tool names with server references", "Grant basis per tool", "Whether the grant is allowlist or inherited" ] }, { "id": "q-schema-binding", "text": "Which input and output schemas were bound to each granted tool at release time?", "kind": "composition", "answer_data": [ "Input schema digest per tool", "Output schema digest per tool", "Behaviour when the live schema no longer matches" ] }, { "id": "q-name-collisions", "text": "How are collisions between identically named tools from different servers disambiguated?", "kind": "interoperability", "answer_data": [ "Disambiguation strategy and prefix", "Why the server name alone is insufficient", "Resolved fully qualified names" ] }, { "id": "q-explicit-denials", "text": "Which tools are explicitly denied even when the runtime offers them?", "kind": "constraint", "answer_data": [ "Denylist entries", "Reason per denial", "Enforcement point for the denial" ] } ], "data_elements": [ { "id": "granted-tool-name", "name": "Granted tool name", "description": "Name of a tool the configuration is permitted to invoke, unique only within its serving server.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "granting-server-reference", "name": "Granting server reference", "description": "Reference to the server that exposes the granted tool.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-017" ] }, { "id": "tool-input-schema-digest", "name": "Tool input schema digest", "description": "Digest of the tool input schema as observed at release, used to detect post-release drift.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-011" ] }, { "id": "tool-output-schema-digest", "name": "Tool output schema digest", "description": "Digest of the tool output schema as observed at release.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-011" ] }, { "id": "tool-denylist-entry", "name": "Tool denylist entry", "description": "Tool explicitly forbidden to this configuration regardless of runtime availability.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-018" ] }, { "id": "tool-disambiguation-prefix", "name": "Tool disambiguation prefix", "description": "Prefix applied by an aggregating client to make tool names unique across servers.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "tool-grant-manifest", "name": "Tool grant manifest", "description": "Frozen allowlist and denylist of tools with server references and schema digests captured at release.", "media_or_form": [ "allowlist manifest", "tool descriptor set", "policy attachment" ], "serial": false, "identity_strategy": "Configuration revision identifier plus manifest digest; each tool entry keyed by server reference plus tool name.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "tool-risk-annotation-and-confirmation", "name": "Tool risk annotations and confirmation gates", "description": "The behaviour hints attached to granted tools, the basis on which the supplying server is trusted, which calls require human confirmation, and per-tool invocation limits. Annotations must be treated as untrusted unless the server is trusted.", "source_refs": [ "SRC-001", "SRC-004", "SRC-018" ], "questions": [ { "id": "q-behaviour-hints", "text": "Which granted tools are annotated read-only, destructive, idempotent or open-world?", "kind": "classification", "answer_data": [ "Annotation values per tool", "Missing-annotation handling", "Locally assigned risk class where annotations are absent" ] }, { "id": "q-annotation-trust", "text": "On what basis is the server supplying those annotations treated as trusted?", "kind": "quality", "answer_data": [ "Trust basis statement", "Verification performed", "Default treatment when trust is not established" ] }, { "id": "q-confirmation-gates", "text": "Which tool calls require explicit human confirmation before execution?", "kind": "authority", "answer_data": [ "Tools requiring confirmation", "What is shown to the approver", "Whether inputs are displayed before the call" ] }, { "id": "q-invocation-limits", "text": "What invocation or rate limits apply per tool under this configuration?", "kind": "measurement", "answer_data": [ "Rate limit values and windows", "Per-run invocation cap", "Behaviour on limit breach" ] } ], "data_elements": [ { "id": "tool-read-only-hint", "name": "Read-only hint", "description": "Claim that the tool does not modify its environment.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "tool-destructive-hint", "name": "Destructive hint", "description": "Claim that the tool may perform destructive updates.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "tool-idempotent-hint", "name": "Idempotent hint", "description": "Claim that repeated calls with the same arguments have no additional effect.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "tool-open-world-hint", "name": "Open-world hint", "description": "Claim that the tool interacts with an open, external world.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "annotation-trust-basis", "name": "Annotation trust basis", "description": "Recorded reason the annotation source is or is not trusted.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "tool-confirmation-required", "name": "Confirmation required flag", "description": "Whether a human must approve the call before execution.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "tool-invocation-limit", "name": "Tool invocation limit", "description": "Rate or count limit applied to a granted tool.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "tool-risk-register", "name": "Tool risk register", "description": "Reviewed risk table recording each granted tool, its annotations, the locally assigned risk class, trust basis, confirmation gate and limits.", "media_or_form": [ "risk table", "annotation review record", "security sign-off" ], "serial": false, "identity_strategy": "Configuration revision identifier plus review sequence issued by the security review function.", "source_refs": [ "SRC-001", "SRC-004", "SRC-018" ] } ], "inline_only_rationale": null }, { "id": "context-resource-and-memory-grants", "name": "Context, resource and memory grants", "description": "Which resources, roots and knowledge collections may enter context, what context-inclusion mode applies and whether the runtime may narrow it for privacy, and which persistent memory stores the configuration may write to.", "source_refs": [ "SRC-005", "SRC-004", "SRC-002" ], "questions": [ { "id": "q-resource-grants", "text": "Which resources, roots or knowledge collections may be read into context?", "kind": "access", "answer_data": [ "Resource URIs or root paths granted", "Grant scope and recursion rules", "Explicitly excluded locations" ] }, { "id": "q-context-inclusion", "text": "What context-inclusion mode applies and may the runtime narrow it for privacy reasons?", "kind": "privacy", "answer_data": [ "Inclusion mode value", "Whether the client may unilaterally narrow it", "Categories of data never included" ] }, { "id": "q-memory-writes", "text": "Which persistent memory stores may this configuration write to and with what scope?", "kind": "retention", "answer_data": [ "Memory store references", "Write scope (user, tenant, global)", "Retention and expiry of written memory" ] } ], "data_elements": [ { "id": "context-resource-grant", "name": "Context resource grant", "description": "Resource, root or collection the configuration may read into context.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "context-inclusion-mode", "name": "Context inclusion mode", "description": "Coded scope of automatic context inclusion, defaulting to none.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "memory-store-reference", "name": "Memory store reference", "description": "Reference to a persistent store the configuration may write to.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "memory-write-scope", "name": "Memory write scope", "description": "Coded scope within which written memory is visible and retained.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-014" ] } ], "artifacts": [ { "id": "context-grant-manifest", "name": "Context grant manifest", "description": "Declaration of readable resources and roots, inclusion mode and permitted memory writes with their scopes.", "media_or_form": [ "resource allowlist", "root declaration", "memory policy attachment" ], "serial": false, "identity_strategy": "Configuration revision identifier plus manifest digest; individual grants keyed by resource URI or root path.", "source_refs": [ "SRC-005", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "server-and-credential-bindings", "name": "Server and Credential Bindings", "description": "The external servers a configuration connects to, the authorization scopes it requests and how credentials are referenced.", "source_refs": [ "SRC-004", "SRC-017", "SRC-001" ], "findings": [ { "id": "server-binding-and-authorization-scope", "name": "Server bindings and authorization scope", "description": "Which servers the configuration binds to and over which transport, which scopes it requests and what justifies each, how credentials are referenced without being embedded, and what happens when a bound server changes its tool list after release.", "source_refs": [ "SRC-004", "SRC-017", "SRC-001" ], "questions": [ { "id": "q-bound-servers", "text": "Which servers does this configuration bind to, at what endpoint and over which transport?", "kind": "relationship", "answer_data": [ "Server references and registry entries", "Endpoint URLs", "Transport kind and whether the server runs locally" ] }, { "id": "q-scope-justification", "text": "Which authorization scopes are requested and which declared capability justifies each one?", "kind": "authority", "answer_data": [ "Requested scope list", "Justification per scope", "Baseline versus step-up scopes" ] }, { "id": "q-secret-referencing", "text": "How are credentials referenced without being embedded in instruction text?", "kind": "security", "answer_data": [ "Secret handle format and resolver", "Proof that no secret value is in the digested content", "Rotation impact on the revision" ] }, { "id": "q-server-drift", "text": "What happens when a bound server changes its tool list after this revision was released?", "kind": "event", "answer_data": [ "Drift detection mechanism", "Automatic action on detection", "Whether a new revision is required before continued use" ] } ], "data_elements": [ { "id": "bound-server-reference", "name": "Bound server reference", "description": "Reference to a server the configuration connects to, ideally its registry entry.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017", "SRC-001" ] }, { "id": "server-transport-kind", "name": "Server transport kind", "description": "Coded transport used to reach the server, for example local standard input/output or streamable HTTP.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-017" ] }, { "id": "requested-authorization-scope", "name": "Requested authorization scope", "description": "Scope requested for the binding, subject to least privilege and progressive elevation.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "scope-justification-note", "name": "Scope justification", "description": "Recorded justification linking each requested scope to a declared capability.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "secret-handle-reference", "name": "Secret handle reference", "description": "Opaque handle resolving to a credential held outside the configuration.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-018" ] }, { "id": "server-drift-detection-rule", "name": "Server drift detection rule", "description": "Rule describing how post-release changes to a bound server's tool list are detected and handled.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "server-binding-manifest", "name": "Server binding manifest", "description": "Frozen record of bound servers, endpoints, transports, requested scopes and secret handles for the revision.", "media_or_form": [ "binding manifest", "registry server record reference", "connection profile" ], "serial": false, "identity_strategy": "Configuration revision identifier plus the reverse-DNS server name from the server registry entry.", "source_refs": [ "SRC-017", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "safety-policy-and-oversight", "name": "Safety, Policy and Human Oversight", "description": "The behavioural constraints the configuration asserts, where they are actually enforced, the secrecy posture of the instruction text, and the human gates and budgets that bound autonomous operation.", "rationale": "Instruction text is a weak control: guidance written in natural language is exposed and evadable, so the model separates what the configuration says from where it is enforced, and requires an oversight and budget envelope independent of the prompt.", "source_refs": [ "SRC-018", "SRC-006", "SRC-004", "SRC-014" ], "layers": [ { "id": "behavioural-policy", "name": "Behavioural Policy and Secrecy Posture", "description": "Declared constraints, refusal behaviour, enforcement points, and the consequences of instruction text being disclosed.", "source_refs": [ "SRC-006", "SRC-018", "SRC-007" ], "findings": [ { "id": "behavioural-constraints-and-refusals", "name": "Behavioural constraints, enforcement and refusals", "description": "The behaviours the configuration requires, forbids or conditions; which of them are enforced outside the model at the application or policy layer; and the specified refusal or safe-completion behaviour for out-of-scope requests.", "source_refs": [ "SRC-006", "SRC-018", "SRC-007" ], "questions": [ { "id": "q-declared-constraints", "text": "Which behaviours does this configuration require, forbid or make conditional?", "kind": "constraint", "answer_data": [ "Constraint statements", "Conditioning triggers", "Priority against other instructions" ] }, { "id": "q-enforcement-point", "text": "Which of those constraints are enforced outside the model rather than by instruction text alone?", "kind": "requirement", "answer_data": [ "Enforcement point per constraint", "Constraints with no external enforcement", "Residual risk note for prompt-only constraints" ] }, { "id": "q-refusal-behaviour", "text": "What refusal or safe-completion behaviour is specified for out-of-scope requests?", "kind": "process", "answer_data": [ "Refusal wording or template reference", "Escalation or handoff path", "Whether the refusal is logged" ] } ], "data_elements": [ { "id": "behavioural-constraint-statement", "name": "Behavioural constraint statement", "description": "One declared requirement, prohibition or conditional rule on model behaviour.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-018" ] }, { "id": "constraint-enforcement-point", "name": "Constraint enforcement point", "description": "Coded location where the constraint is actually enforced: prompt only, application layer, policy engine, or downstream output inspection.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018" ] }, { "id": "refusal-policy-statement", "name": "Refusal policy", "description": "Specified behaviour when a request falls outside declared scope.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "residual-risk-note", "name": "Residual risk note", "description": "Recorded residual risk for constraints that have no enforcement outside the model.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-018" ] } ], "artifacts": [ { "id": "behavioural-policy-annex", "name": "Behavioural policy annex", "description": "Document listing constraints with their enforcement points, refusal policy and residual risk statements for the revision.", "media_or_form": [ "policy document", "guardrail configuration", "risk annex" ], "serial": false, "identity_strategy": "Configuration revision identifier plus annex section identifier; reissued whenever the revision digest changes.", "source_refs": [ "SRC-007", "SRC-018" ] } ], "inline_only_rationale": null }, { "id": "secret-hygiene-and-prompt-leakage", "name": "Secret hygiene and prompt leakage exposure", "description": "Whether any instruction block contains a secret, the declared impact of full instruction disclosure, and the independent output inspection that verifies compliance instead of relying on the prompt.", "source_refs": [ "SRC-018", "SRC-004", "SRC-006" ], "questions": [ { "id": "q-secrets-in-text", "text": "Does any instruction block contain a secret, credential or connection string?", "kind": "security", "answer_data": [ "Boolean finding with scan evidence", "Offending block references if any", "Remediation status" ] }, { "id": "q-disclosure-impact", "text": "What is the declared impact if the full instruction text is disclosed to an end user?", "kind": "privacy", "answer_data": [ "Impact class", "Controls that would be defeated by disclosure", "Compensating controls outside the prompt" ] }, { "id": "q-independent-inspection", "text": "Which independent output inspection verifies compliance instead of relying on the prompt?", "kind": "validation", "answer_data": [ "Inspection component reference", "Checks performed and their coverage", "Action on non-compliant output" ] } ], "data_elements": [ { "id": "secret-present-in-prompt", "name": "Secret present in prompt", "description": "Whether any digested instruction content contains secret material; policy requires this to be false.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-004" ] }, { "id": "leakage-impact-class", "name": "Leakage impact class", "description": "Coded impact if the instruction text becomes known to an end user or attacker.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018" ] }, { "id": "output-inspection-control", "name": "Output inspection control", "description": "Independent check inspecting model output for compliance rather than trusting instruction adherence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018" ] } ], "artifacts": [ { "id": "prompt-leakage-assessment", "name": "Prompt leakage assessment", "description": "Security assessment recording secret scanning results, disclosure impact and the independent controls compensating for prompt exposure.", "media_or_form": [ "assessment record", "security review sign-off" ], "serial": true, "identity_strategy": "Configuration revision digest plus assessment sequence number issued by the security review function.", "source_refs": [ "SRC-018", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "human-oversight-and-autonomy", "name": "Human Oversight and Autonomy Envelope", "description": "Where a human can intervene, what they must be shown, and the hard limits on autonomous operation.", "source_refs": [ "SRC-001", "SRC-014", "SRC-005" ], "findings": [ { "id": "human-oversight-and-approval-gates", "name": "Human oversight and approval gates", "description": "Actions requiring a human able to deny them, the information the reviewer must be shown before deciding, the competence and empowerment of the intervening role, and how overrides and denials are recorded.", "source_refs": [ "SRC-001", "SRC-014", "SRC-015" ], "questions": [ { "id": "q-oversight-gates", "text": "Which actions require a human in the loop able to deny them?", "kind": "authority", "answer_data": [ "Gated action list", "Gate trigger conditions", "Default behaviour when no reviewer is available" ] }, { "id": "q-reviewer-information", "text": "What must be shown to the reviewer before an approval decision is taken?", "kind": "requirement", "answer_data": [ "Disclosed fields including tool inputs", "Truncation rules and prohibitions", "Time allowed for the decision" ] }, { "id": "q-competent-role", "text": "Which role is competent and empowered to intervene, and how is that competence assured?", "kind": "ownership", "answer_data": [ "Reviewer role definition", "Competence or training evidence", "Authority to stop or reverse the action" ] }, { "id": "q-override-record", "text": "How is an override, edit or denial recorded?", "kind": "event", "answer_data": [ "Record fields including actor, decision and rationale", "Timestamp with explicit offset", "Linkage to the affected run" ] } ], "data_elements": [ { "id": "oversight-gate-definition", "name": "Oversight gate definition", "description": "One action or action class that requires human approval before proceeding.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-014" ] }, { "id": "reviewer-role-code", "name": "Reviewer role", "description": "Coded role authorised to approve or deny at a gate.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-007" ] }, { "id": "reviewer-disclosure-field", "name": "Reviewer disclosure field", "description": "Field that must be displayed to the reviewer before a decision, such as untruncated tool inputs.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "oversight-decision-record", "name": "Oversight decision record reference", "description": "Reference to the recorded approval, edit or denial.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-007" ] } ], "artifacts": [ { "id": "oversight-plan", "name": "Human oversight plan", "description": "Procedure defining gates, reviewer roles, disclosure requirements and recording obligations for the configuration.", "media_or_form": [ "oversight procedure", "approval policy", "deployer instruction extract" ], "serial": false, "identity_strategy": "Configuration identifier plus plan version; bound to specific revisions by explicit revision references.", "source_refs": [ "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "autonomy-limits-and-resource-budgets", "name": "Autonomy limits and resource budgets", "description": "The maximum autonomous steps or tool-loop iterations, the token, cost and wall-clock budget bounding a single run, and what terminates an over-budget run and in what state.", "source_refs": [ "SRC-005", "SRC-004", "SRC-018" ], "questions": [ { "id": "q-iteration-cap", "text": "What is the maximum number of autonomous steps or tool-loop iterations permitted?", "kind": "constraint", "answer_data": [ "Iteration cap value", "Whether the cap is enforced by client or server", "Behaviour on the final iteration" ] }, { "id": "q-run-budget", "text": "What token, cost and wall-clock budget bounds a single run under this configuration?", "kind": "measurement", "answer_data": [ "Token budget with unit", "Cost budget with currency", "Wall-clock budget as a duration" ] }, { "id": "q-budget-exhaustion", "text": "What terminates a run that exceeds its budget and what state is left behind?", "kind": "state", "answer_data": [ "Termination mechanism", "Partial-result handling", "Cleanup of state handles and open transactions" ] } ], "data_elements": [ { "id": "autonomy-iteration-cap", "name": "Autonomy iteration cap", "description": "Maximum number of tool-loop iterations or autonomous steps in one run.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "run-token-budget", "name": "Run token budget", "description": "Upper bound on tokens consumed by a single run.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-016" ] }, { "id": "run-cost-budget", "name": "Run cost budget", "description": "Upper bound on monetary cost of a single run.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "run-wallclock-budget", "name": "Run wall-clock budget", "description": "Maximum elapsed time for a single run before termination.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "budget-termination-behaviour", "name": "Budget termination behaviour", "description": "Declared behaviour and cleanup when a budget is exhausted.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Autonomy caps and budgets are scalar limits carried inside the digested revision and mirrored into runtime enforcement configuration. They are not independently retained, approved or disclosed: they change only when the revision changes, and their observed consumption belongs to the agent-run model rather than to the configuration. Materialising them as an artifact would create a mutable second copy that could diverge from the digest, weakening the reproducibility guarantee that the revision snapshot provides." } ] } ] }, { "id": "assurance-and-provenance", "name": "Assurance, Evidence and Provenance", "description": "The evidence that a specific revision behaves acceptably, and the verifiable record of who produced it, from what, and with which dependencies.", "rationale": "Evidence and provenance are only meaningful when bound to an exact digest. Attaching evaluation results or attestations to a mutable name is the most common way assurance claims become false after a change.", "source_refs": [ "SRC-007", "SRC-011", "SRC-008", "SRC-012", "SRC-018" ], "layers": [ { "id": "evaluation-evidence", "name": "Evaluation Evidence", "description": "Functional and adversarial evidence produced against a named revision digest, with thresholds and expiry.", "source_refs": [ "SRC-007", "SRC-014", "SRC-018" ], "findings": [ { "id": "evaluation-suite-and-acceptance-criteria", "name": "Evaluation suites and acceptance criteria", "description": "Which suites were run against the exact revision digest, what thresholds gated release, which model build and runtime were used, and how long the evidence stays valid.", "source_refs": [ "SRC-007", "SRC-014", "SRC-016" ], "questions": [ { "id": "q-suites-run", "text": "Which evaluation suites were run against this exact revision digest?", "kind": "evidence", "answer_data": [ "Suite identifiers and versions", "Revision digest under test", "Run identifiers and dates" ] }, { "id": "q-acceptance-thresholds", "text": "What acceptance thresholds had to be met before release was permitted?", "kind": "measurement", "answer_data": [ "Metric names with units", "Threshold values and comparison operators", "Observed values and pass or fail" ] }, { "id": "q-evaluation-environment", "text": "Which model build and runtime version were used during evaluation?", "kind": "provenance", "answer_data": [ "Model build identifier", "Runtime and library versions", "Decoding parameters in force during evaluation" ] }, { "id": "q-evidence-expiry", "text": "How long does this evaluation evidence remain valid before it must be repeated?", "kind": "temporal", "answer_data": [ "Validity period or expiry instant", "Events that invalidate evidence early", "Owner responsible for refresh" ] } ], "data_elements": [ { "id": "evaluation-run-reference", "name": "Evaluation run reference", "description": "Reference to an evaluation execution tied to the revision digest.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "evaluation-metric-name", "name": "Evaluation metric name", "description": "Coded metric reported by the suite.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-014" ] }, { "id": "evaluation-metric-value", "name": "Evaluation metric value", "description": "Observed value of a reported metric.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "evaluation-acceptance-threshold", "name": "Acceptance threshold", "description": "Threshold that had to be met for release.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-014" ] }, { "id": "evaluation-model-build", "name": "Evaluated model build", "description": "Model build identifier in force during evaluation.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "evidence-valid-until", "name": "Evidence valid until", "description": "Instant after which the evaluation evidence is considered stale.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-007" ] } ], "artifacts": [ { "id": "evaluation-report", "name": "Evaluation report", "description": "Report binding suite, thresholds, observed metrics, environment and verdict to a specific revision digest.", "media_or_form": [ "evaluation report", "scorecard", "test result set" ], "serial": true, "identity_strategy": "Revision digest plus suite identifier plus run sequence, issued by the evaluation system of record.", "source_refs": [ "SRC-007", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "adversarial-testing-evidence", "name": "Adversarial testing evidence", "description": "Red-team and adversarial testing performed against the configuration, the attack classes explicitly excluded, and the open findings with their accepted residual risk.", "source_refs": [ "SRC-018", "SRC-007", "SRC-004" ], "questions": [ { "id": "q-redteam-scope", "text": "What adversarial or red-team testing was performed against this configuration?", "kind": "evidence", "answer_data": [ "Exercise references and dates", "Testers and independence status", "Revision digest exercised" ] }, { "id": "q-attack-exclusions", "text": "Which attack classes were explicitly out of scope for that testing?", "kind": "exception", "answer_data": [ "Excluded attack classes", "Reason for each exclusion", "Compensating assurance if any" ] }, { "id": "q-residual-acceptance", "text": "Which findings remain open at release and who accepted the residual risk?", "kind": "decision", "answer_data": [ "Open finding references and severity", "Risk acceptor identity and role", "Acceptance expiry or review date" ] } ], "data_elements": [ { "id": "adversarial-exercise-reference", "name": "Adversarial exercise reference", "description": "Reference to a red-team or adversarial test exercise.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-007" ] }, { "id": "attack-class-covered", "name": "Attack class covered", "description": "Attack class exercised during testing, such as direct or indirect prompt injection or excessive agency.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018" ] }, { "id": "attack-class-excluded", "name": "Attack class excluded", "description": "Attack class deliberately out of scope, recorded to keep the assurance claim falsifiable.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-007" ] }, { "id": "open-adversarial-finding", "name": "Open adversarial finding", "description": "Unresolved finding carried into release with its severity.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-018" ] }, { "id": "residual-risk-acceptor", "name": "Residual risk acceptor", "description": "Reference to the accountable party who accepted the open findings.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-014" ] } ], "artifacts": [ { "id": "adversarial-test-record", "name": "Adversarial test record", "description": "Record of the exercise, its scope, exclusions, findings and risk acceptance, bound to a revision digest.", "media_or_form": [ "red-team report", "penetration test log", "risk acceptance memo" ], "serial": true, "identity_strategy": "Revision digest plus exercise identifier issued by the testing function; independent testers keep their own identifiers as aliases.", "source_refs": [ "SRC-018", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "provenance-and-supply-chain", "name": "Provenance and Supply Chain", "description": "Who and what produced the revision, and the signed record that lets a consumer verify it before loading.", "source_refs": [ "SRC-008", "SRC-011", "SRC-012" ], "findings": [ { "id": "authorship-and-provenance-chain", "name": "Authorship and provenance chain", "description": "The agents that authored or revised the configuration and on whose behalf they acted, the generating activity and prior entity it derived from, whether any part was machine-generated, and the separation of activity time from record ingestion time.", "source_refs": [ "SRC-008", "SRC-011", "SRC-007" ], "questions": [ { "id": "q-authoring-agents", "text": "Which agents authored or revised this configuration and on whose behalf did they act?", "kind": "provenance", "answer_data": [ "Agent references", "Delegation chain (acted on behalf of)", "Role of each agent in the activity" ] }, { "id": "q-derivation-link", "text": "Which activity generated this revision and from which prior entity was it derived?", "kind": "relationship", "answer_data": [ "Generating activity reference", "Derived-from entity references", "Whether the relation is a revision or a quotation" ] }, { "id": "q-machine-generation", "text": "Was any part of this configuration machine-generated, and by which system?", "kind": "quality", "answer_data": [ "Machine-generated regions", "Generating system and its configuration reference", "Human review status of generated content" ] }, { "id": "q-activity-vs-record-time", "text": "When did the authoring activity start and end, as distinct from when the record was ingested?", "kind": "temporal", "answer_data": [ "Activity start and end instants", "Record ingestion instant", "Explanation where the two diverge materially" ] } ], "data_elements": [ { "id": "authoring-agent-reference", "name": "Authoring agent reference", "description": "Reference to a human or software agent responsible for the revision content.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "acted-on-behalf-of-reference", "name": "Acted on behalf of", "description": "Reference to the principal on whose behalf the authoring agent acted.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "generating-activity-reference", "name": "Generating activity reference", "description": "Reference to the activity that produced this revision.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "derived-from-reference", "name": "Derived from", "description": "Reference to the prior entity from which this revision was derived.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "activity-started-at", "name": "Activity started at", "description": "Event time at which the authoring activity began.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-010" ] }, { "id": "record-ingested-at", "name": "Record ingested at", "description": "Observation time at which the Dimension recorded the provenance fact, kept separate from the event time.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-008" ] } ], "artifacts": [ { "id": "provenance-record", "name": "Provenance record", "description": "Graph or log expressing generation, derivation, attribution and delegation for the revision.", "media_or_form": [ "provenance graph", "commit and review history", "attribution log" ], "serial": true, "identity_strategy": "Revision identifier as the entity key, with provenance statements addressed by the generating activity identifier; IRIs used where a governed provenance namespace exists.", "source_refs": [ "SRC-008", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "release-attestation-and-dependency-inventory", "name": "Release attestation and dependency inventory", "description": "The signed statement binding a builder identity to the revision digest, the external parameters and resolved dependencies that produced it, the inventory of models, datasets, tools and third-party prompt components, and the consumer-side verification procedure.", "source_refs": [ "SRC-011", "SRC-012", "SRC-007" ], "questions": [ { "id": "q-attestation-binding", "text": "Which signed attestation binds a builder identity to this revision digest?", "kind": "evidence", "answer_data": [ "Attestation predicate type and location", "Builder identity and version", "Subject digest matching the revision" ] }, { "id": "q-build-parameters", "text": "Which external parameters and resolved dependencies produced the released artifact?", "kind": "composition", "answer_data": [ "External parameters (source revision, template inputs)", "Internal parameters", "Resolved dependency digests" ] }, { "id": "q-component-inventory", "text": "Which models, datasets, tools and third-party prompt components does this configuration depend on?", "kind": "interoperability", "answer_data": [ "Component list with versions and digests", "Licence and origin per component", "Bill-of-materials document reference" ] }, { "id": "q-verification-procedure", "text": "How does a consumer verify the attestation before loading the configuration?", "kind": "validation", "answer_data": [ "Trust anchors and expected builder identities", "Verification steps and tooling", "Action when verification fails" ] } ], "data_elements": [ { "id": "release-attestation-reference", "name": "Release attestation reference", "description": "Reference to the signed provenance statement for the revision.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "builder-identity", "name": "Builder identity", "description": "Identity of the platform or process that produced the released revision.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "build-external-parameters", "name": "Build external parameters", "description": "User-controlled inputs to the release process, which downstream verifiers must check.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "resolved-dependency-entry", "name": "Resolved dependency", "description": "Dependency resolved during release, recorded with a digest.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "id": "component-inventory-reference", "name": "Component inventory reference", "description": "Reference to the machine-readable bill of materials covering models, datasets, tools and prompt components.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "signature-verification-rule", "name": "Signature verification rule", "description": "Rule stating which signatures must verify against which trust anchors before load.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-004" ] } ], "artifacts": [ { "id": "release-attestation", "name": "Release attestation and bill of materials", "description": "Signed statement over the revision digest plus the accompanying component inventory.", "media_or_form": [ "in-toto statement", "provenance predicate document", "machine-readable bill of materials" ], "serial": true, "identity_strategy": "Subject digest of the attested revision plus predicate type; the attestation store's own identifier is a secondary alias.", "source_refs": [ "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "deployment-and-observability", "name": "Deployment and Observability", "description": "Where a revision is actually in force, how exposure is controlled and reversed, and how a run can be traced back to the exact configuration that produced it.", "rationale": "A released configuration only has effect through a binding. Regulated logging duties and reproducibility both require the binding window and the run-to-revision link to be first-class, separately timestamped facts.", "source_refs": [ "SRC-007", "SRC-014", "SRC-016", "SRC-003" ], "layers": [ { "id": "deployment-binding", "name": "Deployment Binding and Reversal", "description": "Active environments, rollout exposure, effective windows, rollback target and immediate-disable mechanism.", "source_refs": [ "SRC-007", "SRC-014", "SRC-003" ], "findings": [ { "id": "environment-binding-rollout-and-rollback", "name": "Environment binding, rollout and rollback", "description": "Which environments and tenants run this revision, the rollout strategy and traffic share, the effective-from and effective-to window per environment, the designated rollback target, and the mechanism that disables the configuration immediately without a redeploy.", "source_refs": [ "SRC-007", "SRC-014", "SRC-004", "SRC-003" ], "questions": [ { "id": "q-active-environments", "text": "In which environments and tenants is this revision currently active?", "kind": "state", "answer_data": [ "Environment codes", "Tenant references", "Activation status per binding" ] }, { "id": "q-rollout-strategy", "text": "What rollout strategy governs exposure and what share of traffic sees this revision?", "kind": "process", "answer_data": [ "Strategy code (canary, staged, full)", "Traffic share value", "Promotion criteria between stages" ] }, { "id": "q-effective-window", "text": "From when until when was this revision effective in each environment?", "kind": "temporal", "answer_data": [ "Effective-from instant per binding", "Effective-to instant or open-ended marker", "Overlap handling between successive bindings" ] }, { "id": "q-rollback-target", "text": "Which prior revision is the designated rollback target?", "kind": "decision", "answer_data": [ "Rollback target revision and digest", "Verification that the target is still retained", "Known regressions in the target" ] }, { "id": "q-immediate-disable", "text": "What mechanism disables this configuration immediately without a redeploy?", "kind": "exception", "answer_data": [ "Disable mechanism description", "Authorised operators", "Expected time to take effect" ] } ], "data_elements": [ { "id": "deployment-environment-code", "name": "Deployment environment", "description": "Coded environment in which the revision is bound.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "deployment-tenant-reference", "name": "Deployment tenant reference", "description": "Reference to the tenant or customer scope of the binding.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "rollout-strategy-code", "name": "Rollout strategy", "description": "Coded exposure strategy governing the binding.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "rollout-traffic-share", "name": "Rollout traffic share", "description": "Proportion of eligible traffic routed to this revision.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "binding-effective-from", "name": "Binding effective from", "description": "Event time from which the binding is in force.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-014" ] }, { "id": "binding-effective-to", "name": "Binding effective to", "description": "Event time at which the binding ceased to be in force.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-014" ] }, { "id": "rollback-target-reference", "name": "Rollback target reference", "description": "Reference to the revision designated for rollback.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "immediate-disable-mechanism", "name": "Immediate disable mechanism", "description": "Description of the control that withdraws the configuration without a redeploy.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] } ], "artifacts": [ { "id": "deployment-binding-record", "name": "Deployment binding record", "description": "Record of one revision bound to one environment or tenant, with strategy, exposure and effective window, closed rather than overwritten on change.", "media_or_form": [ "deployment record", "release channel entry", "runbook attachment" ], "serial": true, "identity_strategy": "Environment plus tenant plus revision identifier, with a monotonically increasing binding sequence; closed bindings retain their identifiers permanently.", "source_refs": [ "SRC-007", "SRC-014" ] } ], "inline_only_rationale": null } ] }, { "id": "observability-and-run-linkage", "name": "Observability and Run Linkage", "description": "The telemetry contract that makes a run attributable to an exact configuration revision, and the privacy rules on capturing instruction text.", "source_refs": [ "SRC-016", "SRC-014", "SRC-007" ], "findings": [ { "id": "run-linkage-and-telemetry", "name": "Run linkage and telemetry contract", "description": "Which telemetry attribute carries the exact revision used by a run, whether instruction text is captured and under what opt-in and redaction rules, and how long run records are kept so the link survives.", "source_refs": [ "SRC-016", "SRC-014", "SRC-007" ], "questions": [ { "id": "q-telemetry-key", "text": "Which telemetry attribute carries the exact configuration revision used by a run?", "kind": "interoperability", "answer_data": [ "Attribute key and value format", "Stability level of the attribute", "Fallback correlation identifier" ] }, { "id": "q-instruction-capture", "text": "Are instruction texts recorded in telemetry, and under what opt-in and redaction rules?", "kind": "privacy", "answer_data": [ "Capture mode (off, hashed, full)", "Opt-in mechanism and default", "Redaction rules applied before storage" ] }, { "id": "q-trace-retention", "text": "How long are run records kept so a run can still be traced back to its configuration?", "kind": "retention", "answer_data": [ "Retention period for run records", "Alignment with configuration retention", "Consequence when run records outlive the revision record" ] } ], "data_elements": [ { "id": "telemetry-attribute-key", "name": "Telemetry attribute key", "description": "Attribute key used to carry configuration identity and parameters into traces, aligned with generative-AI semantic conventions.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "linked-run-reference", "name": "Linked run reference", "description": "Reference to an execution that used this revision; linkage only, with run payloads held elsewhere.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "conversation-identifier", "name": "Conversation identifier", "description": "Identifier correlating related exchanges that used this configuration.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "instruction-capture-mode", "name": "Instruction capture mode", "description": "Coded rule for whether and how instruction text is recorded in telemetry.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016", "SRC-018" ] }, { "id": "run-record-retention-period", "name": "Run record retention period", "description": "Duration for which run records preserving the configuration link are kept.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014", "SRC-007" ] } ], "artifacts": [ { "id": "telemetry-mapping", "name": "Telemetry attribute mapping", "description": "Mapping table from configuration fields to telemetry attribute keys, with capture and redaction rules and the stability caveat for development-stage attributes.", "media_or_form": [ "attribute mapping table", "semantic convention profile", "observability configuration" ], "serial": false, "identity_strategy": "Configuration identifier plus semantic convention version; superseded when the convention version changes.", "source_refs": [ "SRC-016" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "governance-compliance-and-retention", "name": "Governance, Compliance and Retention", "description": "Who is accountable, which regulatory duties attach, who may see the configuration, and how long revisions survive.", "rationale": "Accountability, documentation duties, confidentiality and retention are the facts most often missing when a prompt is treated as a source file rather than a governed artifact; each is separately required by inventory, transparency and record-keeping obligations.", "source_refs": [ "SRC-007", "SRC-014", "SRC-015", "SRC-018" ], "layers": [ { "id": "accountability-and-regulatory-duties", "name": "Accountability and Regulatory Duties", "description": "Ownership, inventory linkage, segregation of duties, risk classification and documentation obligations.", "source_refs": [ "SRC-007", "SRC-014", "SRC-015" ], "findings": [ { "id": "ownership-and-accountable-roles", "name": "Ownership and accountable roles", "description": "Who owns the configuration, who is the accountable deployer, which organisational AI inventory entry records it, and how authoring and approval duties are separated.", "source_refs": [ "SRC-007", "SRC-014", "SRC-015" ], "questions": [ { "id": "q-owner-and-deployer", "text": "Who owns this configuration and who is the accountable deployer?", "kind": "ownership", "answer_data": [ "Owner reference and role", "Accountable deployer reference", "Escalation contact" ] }, { "id": "q-inventory-entry", "text": "Which entry in the organisational AI system inventory records this configuration?", "kind": "identity", "answer_data": [ "Inventory entry identifier", "Inventory system reference", "Date of last inventory reconciliation" ] }, { "id": "q-segregation-of-duties", "text": "Which duties are separated so that the author is not the sole approver?", "kind": "authority", "answer_data": [ "Separated duty pairs", "Enforcement mechanism", "Documented exceptions and who granted them" ] } ], "data_elements": [ { "id": "configuration-owner-reference", "name": "Configuration owner reference", "description": "Reference to the accountable owner of the configuration.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-014" ] }, { "id": "accountable-deployer-reference", "name": "Accountable deployer reference", "description": "Reference to the party accountable for deployment and use in a given jurisdiction.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014", "SRC-015" ] }, { "id": "inventory-entry-reference", "name": "AI inventory entry reference", "description": "Reference to the organisational inventory record covering this configuration.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "duty-segregation-rule", "name": "Duty segregation rule", "description": "Rule preventing the same party from authoring and solely approving a revision.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "ownership-record", "name": "Ownership and inventory record", "description": "Record linking the configuration to its owner, accountable deployer, stewards and inventory entry.", "media_or_form": [ "inventory entry", "responsibility assignment table", "governance register row" ], "serial": false, "identity_strategy": "Inventory system identifier as the master key, with the configuration identifier as the cross-reference.", "source_refs": [ "SRC-007", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "regulatory-classification-and-documentation", "name": "Regulatory classification and documentation duties", "description": "Whether the system driven by this configuration falls into a regulated risk class, which technical-documentation elements must record the key design choices captured here, and which jurisdictions and effective dates apply.", "source_refs": [ "SRC-014", "SRC-015", "SRC-007" ], "questions": [ { "id": "q-risk-class", "text": "Does the system driven by this configuration fall into a regulated risk class in any applicable jurisdiction?", "kind": "classification", "answer_data": [ "Risk class code per jurisdiction", "Basis for the classification", "Who made and approved the determination" ] }, { "id": "q-documentation-duties", "text": "Which technical-documentation elements must record the key design choices captured here?", "kind": "requirement", "answer_data": [ "Documentation element list", "Mapping from configuration fields to elements", "Gaps still to be filled" ] }, { "id": "q-jurisdiction-and-dates", "text": "Which jurisdictions and effective dates apply to those duties?", "kind": "spatial", "answer_data": [ "Jurisdiction codes", "Obligation start dates", "Placement or use assumptions underlying the analysis" ] } ], "data_elements": [ { "id": "regulatory-risk-class", "name": "Regulatory risk class", "description": "Coded risk class assigned under an applicable regime.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "applicable-jurisdiction-code", "name": "Applicable jurisdiction", "description": "Jurisdiction in which the configuration's system is placed on the market or used.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "documentation-obligation-entry", "name": "Documentation obligation", "description": "Documentation element the configuration must feed, such as design specifications and key design choices.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-015" ] }, { "id": "obligation-effective-date", "name": "Obligation effective date", "description": "Date from which a documentation or transparency obligation applies.", "value_kind": "date", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "conformity-evidence-reference", "name": "Conformity evidence reference", "description": "Reference to evidence supporting a conformity or transparency claim; conformance is never asserted without it.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-007" ] } ], "artifacts": [ { "id": "regulatory-dossier-extract", "name": "Regulatory dossier extract", "description": "Extract mapping configuration fields to required technical-documentation and instructions-for-use elements for a jurisdiction.", "media_or_form": [ "technical documentation annex", "instructions for use extract", "conformity file section" ], "serial": false, "identity_strategy": "Configuration revision identifier plus jurisdiction code plus dossier section reference issued by the compliance system of record.", "source_refs": [ "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "access-retention-and-disclosure", "name": "Access, Retention and Disclosure", "description": "Confidentiality classification, principal rights, redaction for disclosure, and the retention and deletion regime for revisions.", "source_refs": [ "SRC-018", "SRC-004", "SRC-014" ], "findings": [ { "id": "configuration-confidentiality-and-access", "name": "Confidentiality classification and access rights", "description": "The confidentiality class of the instruction text, which principals may read, propose, approve or publish, which fields must be redacted before disclosure, and what is logged on read or export. Confidentiality is a handling class, never a security control.", "source_refs": [ "SRC-018", "SRC-004", "SRC-007" ], "questions": [ { "id": "q-confidentiality-class", "text": "What confidentiality class applies to the instruction text of this configuration?", "kind": "access", "answer_data": [ "Class value and definition", "Basis for the classification", "Explicit statement that the class is not relied on as a control" ] }, { "id": "q-principal-rights", "text": "Which principals may read, propose, approve or publish revisions of it?", "kind": "authority", "answer_data": [ "Principal or group per right", "Grant basis and expiry", "Separation between read and publish rights" ] }, { "id": "q-redaction-rules", "text": "Which fields must be redacted before the configuration is shared with a deployer or auditor?", "kind": "privacy", "answer_data": [ "Redaction rule set", "Fields always redacted", "How digest linkage is preserved after redaction" ] }, { "id": "q-read-logging", "text": "What is logged whenever the configuration is read or exported?", "kind": "security", "answer_data": [ "Logged fields including principal and purpose", "Timestamp format with explicit offset", "Log retention and review cadence" ] } ], "data_elements": [ { "id": "confidentiality-class-code", "name": "Confidentiality class", "description": "Coded handling class for the instruction text.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-007" ] }, { "id": "read-principal-grant", "name": "Read principal grant", "description": "Principal or group permitted to read the configuration.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "publish-principal-grant", "name": "Publish principal grant", "description": "Principal or group permitted to release or bind revisions, held separately from read rights.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "disclosure-redaction-rule", "name": "Disclosure redaction rule", "description": "Rule removing or masking fields before external disclosure.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-015" ] }, { "id": "access-log-reference", "name": "Access log reference", "description": "Reference to the log capturing reads and exports of the configuration.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-014" ] } ], "artifacts": [ { "id": "access-policy-record", "name": "Access policy and classification record", "description": "Classification label plus access control list and redaction rules governing the configuration.", "media_or_form": [ "access control list", "classification label", "redaction ruleset" ], "serial": false, "identity_strategy": "Configuration identifier plus policy version issued by the access governance system; applies across revisions unless a revision overrides it.", "source_refs": [ "SRC-004", "SRC-018" ] } ], "inline_only_rationale": null }, { "id": "retention-deletion-and-legal-hold", "name": "Retention, deletion and legal hold", "description": "How long superseded revisions must be retained for audit and reproducibility, what deletion does and what tombstone survives it, and which holds override the normal period.", "source_refs": [ "SRC-014", "SRC-007", "SRC-011" ], "questions": [ { "id": "q-retention-period", "text": "How long must superseded revisions be retained to support audit and reproducibility?", "kind": "retention", "answer_data": [ "Retention period with unit", "Retention basis (regulatory, contractual, internal)", "Alignment with run record retention" ] }, { "id": "q-deletion-and-tombstone", "text": "What deletes a revision and what tombstone survives deletion?", "kind": "lifecycle", "answer_data": [ "Deletion method and authoriser", "Tombstone fields retained (identifier, digest, dates)", "Effect on referencing runs and attestations" ] }, { "id": "q-hold-override", "text": "Which legal hold or regulatory minimum overrides the normal retention period?", "kind": "exception", "answer_data": [ "Hold identifier and scope", "Authority imposing the hold", "Release condition and reviewer" ] } ], "data_elements": [ { "id": "revision-retention-period", "name": "Revision retention period", "description": "Minimum duration for which a superseded revision must be retained.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014", "SRC-007" ] }, { "id": "retention-basis-statement", "name": "Retention basis", "description": "Stated legal, contractual or operational basis for the retention period.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "deletion-method-code", "name": "Deletion method", "description": "Coded disposition method applied at end of retention.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "revision-tombstone", "name": "Revision tombstone", "description": "Minimal surviving record after deletion: identifier, digest, lifecycle dates and disposition reference.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-007" ] }, { "id": "legal-hold-flag", "name": "Legal hold flag", "description": "Whether a hold currently suspends deletion of the revision.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [ { "id": "retention-schedule-entry", "name": "Retention schedule entry", "description": "Schedule row binding the configuration class to a retention period, disposition method, hold status and tombstone requirement.", "media_or_form": [ "retention schedule", "disposition record", "legal hold notice" ], "serial": false, "identity_strategy": "Records management system identifier for the schedule row, cross-referenced to the configuration identifier and revision digests it covers.", "source_refs": [ "SRC-014", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "resolve-effective-configuration", "name": "Resolve effective configuration", "description": "Combine a base revision with its overlays, variants and scope-specific configurations into a single effective view, emitting the precedence trace that justifies every resolved field.", "inputs": [ "Base revision reference", "Overlay and variant references", "Working scope path", "Tenant, locale and channel selectors" ], "outputs": [ "Effective configuration document", "Precedence trace listing the winning source of each field", "Effective-configuration digest" ], "preconditions": [ "Every referenced revision resolves and its integrity has been verified", "A deterministic precedence rule is declared for overlapping scopes" ], "effects": [ "Produces a read-only derived view; mutates no stored revision", "Makes the resolution reproducible by digesting the resolved result" ], "source_refs": [ "SRC-013", "SRC-006", "SRC-011" ] }, { "id": "render-prompt-from-template", "name": "Render prompt from template", "description": "Substitute validated argument values into a prompt template to produce the final message sequence, applying escaping so that values cannot be read as instructions.", "inputs": [ "Template block reference", "Argument name and value pairs", "Rendering engine version" ], "outputs": [ "Rendered message sequence with roles", "Render trace recording substitutions", "Validation errors where arguments fail" ], "preconditions": [ "All arguments marked required are present", "Each value validates against its declared argument schema" ], "effects": [ "Substituted values are delimited and carry no instruction authority", "Rendering fails closed when a required argument is missing" ], "source_refs": [ "SRC-002", "SRC-004", "SRC-019" ] }, { "id": "validate-configuration", "name": "Validate configuration revision", "description": "Check a candidate revision against its structural schema, declared policy rules and internal consistency, including that no secret appears in instruction text and that every requested scope has a justification.", "inputs": [ "Candidate revision snapshot", "Schema dialect reference", "Policy ruleset" ], "outputs": [ "Validation report", "Pass or fail verdict", "Ordered violation list with severities" ], "preconditions": [ "The schema dialect resolves and reference resolution rules are applied", "The policy ruleset version is recorded with the report" ], "effects": [ "Blocks promotion of the revision while any blocking violation is open", "Records the verdict against the candidate content digest" ], "source_refs": [ "SRC-019", "SRC-001", "SRC-007", "SRC-018" ] }, { "id": "release-configuration-revision", "name": "Release configuration revision", "description": "Freeze an approved candidate into an immutable revision, mint its canonical digest, assign a version according to the declared change class, and emit the release event.", "inputs": [ "Approved candidate snapshot", "Change class (major, minor or patch)", "Approval decision record" ], "outputs": [ "Immutable revision with content digest", "Version string", "Release event with an RFC 3339 timestamp" ], "preconditions": [ "Validation passed and approval is recorded by a party other than the sole author", "The version string is not already in use for a different digest" ], "effects": [ "Released content becomes immutable; corrections require a new version", "Supersedes and derived-from links are written to the prior revision" ], "source_refs": [ "SRC-009", "SRC-007", "SRC-008", "SRC-010" ] }, { "id": "attest-and-sign-revision", "name": "Attest and sign revision", "description": "Produce a signed provenance statement binding the builder identity, external parameters and resolved dependencies to the released revision digest, together with a component inventory.", "inputs": [ "Revision digest", "Builder identity and version", "Resolved dependency set", "Component inventory" ], "outputs": [ "Signed attestation over the revision digest", "Bill-of-materials reference", "Public verification instructions" ], "preconditions": [ "The release environment and its trust anchors are identified", "The digest to be attested matches the stored revision" ], "effects": [ "Enables downstream verification before load", "Creates the supply-chain record used for dependency impact analysis" ], "source_refs": [ "SRC-011", "SRC-012" ] }, { "id": "verify-configuration-before-load", "name": "Verify configuration before load", "description": "Verify digest and signature against declared trust anchors before a runtime loads a configuration, and classify accompanying tool annotations as trusted or untrusted based on the verification result.", "inputs": [ "Revision reference", "Attestation", "Trust anchor set and trust policy" ], "outputs": [ "Verification verdict", "Trusted or untrusted classification for tool annotations", "Rejection reason where verification fails" ], "preconditions": [ "Trust anchors are configured out of band", "The attestation subject digest is recomputed locally, not taken on trust" ], "effects": [ "Refuses to load unverified or mismatched revisions", "Downgrades tool annotations to untrusted when the source is not verified" ], "source_refs": [ "SRC-011", "SRC-001", "SRC-004" ] }, { "id": "evaluate-configuration-revision", "name": "Evaluate configuration revision", "description": "Run functional and adversarial evaluation suites against a specific revision digest under a pinned model build, compare results with acceptance thresholds and attach the evidence with an expiry.", "inputs": [ "Revision reference and digest", "Evaluation suite references and versions", "Pinned model build and runtime versions" ], "outputs": [ "Metric results with units", "Acceptance verdict per threshold", "Evidence record with validity period" ], "preconditions": [ "Suites are versioned and the run environment is recorded", "The digest under test equals the digest that will be released" ], "effects": [ "Attaches evidence to the revision rather than to a mutable name", "Sets an expiry that forces re-evaluation on model or runtime change" ], "source_refs": [ "SRC-007", "SRC-014", "SRC-018" ] }, { "id": "bind-and-roll-out", "name": "Bind revision and control rollout", "description": "Activate a verified revision in a named environment or tenant under a declared rollout strategy, opening a new binding record and closing the previous one with an effective-to instant.", "inputs": [ "Revision reference", "Environment and tenant", "Rollout strategy and traffic share" ], "outputs": [ "Deployment binding record", "Effective-from instant", "Closed prior binding with effective-to instant" ], "preconditions": [ "Verification and evaluation have passed and evidence is unexpired", "A rollback target is designated and still retained" ], "effects": [ "Makes the revision operative for matching traffic", "Preserves an auditable, non-overlapping history of effective windows" ], "source_refs": [ "SRC-007", "SRC-014", "SRC-003" ] }, { "id": "rollback-or-disable-configuration", "name": "Roll back or disable configuration", "description": "Withdraw an active revision immediately, either by reverting to the designated rollback target or by disabling the configuration without a redeploy, and link the action to an incident record.", "inputs": [ "Active binding reference", "Rollback target reference or disable instruction", "Incident reference" ], "outputs": [ "Closed binding with effective-to instant", "Restored binding or disabled state", "Incident linkage record" ], "preconditions": [ "The rollback target is retained and passes integrity verification", "The operator is authorised to act on the affected environment" ], "effects": [ "Removes the revision from service without deleting its record", "Creates the audit trail linking withdrawal to its triggering incident" ], "source_refs": [ "SRC-007", "SRC-014", "SRC-004" ] }, { "id": "redact-configuration-for-disclosure", "name": "Redact configuration for disclosure", "description": "Produce an audience-appropriate disclosure package from a revision, applying the declared redaction rules while preserving verifiable linkage to the original digest.", "inputs": [ "Revision snapshot", "Audience class (deployer, auditor, regulator, end user)", "Redaction ruleset" ], "outputs": [ "Redacted disclosure package", "Redaction manifest naming every removed field", "Reference to the source revision digest" ], "preconditions": [ "A confidentiality class is assigned to the revision", "The audience class maps to a defined disclosure scope" ], "effects": [ "Removes secrets and restricted fields without breaking digest traceability", "Writes an access log entry recording principal, purpose and timestamp" ], "source_refs": [ "SRC-018", "SRC-015", "SRC-014", "SRC-004" ] }, { "id": "bind-tools-and-skills", "name": "Bind tools and skills", "description": "Attach a pinned tool catalog and skill packages, reconcile experimental allowed-tools with the host allowlist, and record independent risk classes.", "inputs": [ "configuration version", "tool definitions", "skill packages", "host allowlist and approval policy" ], "outputs": [ "pinned catalog digest", "reconciled allowlist", "untrusted annotation flags" ], "preconditions": [ "Tool input schemas are valid JSON Schema objects", "Skill names match directories and frontmatter" ], "effects": [ "The configuration version references a frozen or explicitly live catalog", "Annotations are stored as hints only" ], "source_refs": [ "SRC-023", "SRC-024", "SRC-028", "SRC-032" ] }, { "id": "emit-run-pin", "name": "Pin configuration for a run", "description": "Emit the pin tuple a run must store so later inspection can recover the exact instruction and tool package.", "inputs": [ "configuration version or stored prompt reference", "effective stack digest if already composed", "content-capture policy" ], "outputs": [ "pin tuple", "optional redacted instruction snapshot according to capture policy" ], "preconditions": [ "Version exists and is not hard-deleted", "Capture policy is known" ], "effects": [ "A run can be related to WM-AI-005 without depending on a latest pointer" ], "source_refs": [ "SRC-022", "SRC-027" ] } ], "composition": [ { "target": "WM-AI-002 AI Agent", "relation": "REFERENCE", "purpose": "The deployed agent references the exact configuration revision it operates under; agent identity, persona and runtime health remain in the agent model while instruction content, grants and parameters remain here.", "required": true, "source_refs": [ "SRC-016", "SRC-005" ] }, { "target": "WM-AI-004 Agent Run / execution record", "relation": "REFERENCE", "purpose": "Each run records the configuration revision identifier and content digest so that behaviour can be reproduced and attributed; only linkage fields cross the boundary.", "required": true, "source_refs": [ "SRC-016", "SRC-011" ] }, { "target": "WM-KNW-005 parent knowledge model", "relation": "CHILD", "purpose": "Inherits identity, provenance, access and retention semantics for a governed knowledge artifact, and adds executable operational semantics that a passive knowledge asset does not carry.", "required": true, "source_refs": [ "SRC-007", "SRC-013" ] }, { "target": "Model Context Protocol tool and prompt definitions", "relation": "ALIGN", "purpose": "Field-level alignment for prompt arguments, tool name, input and output schema, behaviour annotations and capability declaration; alignment only, no conformance claimed.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "MCP server registry entry (server.json)", "relation": "REFERENCE", "purpose": "Bound servers are referenced by their reverse-DNS registry name and version rather than restated, keeping server packaging and availability outside this model.", "required": false, "source_refs": [ "SRC-017" ] }, { "target": "Semantic Versioning 2.0.0", "relation": "ALIGN", "purpose": "Supplies the version precedence and release-immutability rules used for configuration revisions; the breaking-change classes are model-specific and are not part of the standard.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "W3C PROV-O", "relation": "ALIGN", "purpose": "Provides the vocabulary for authorship, delegation, generation and derivation of configuration revisions, including the separation of activity time from record time.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "SLSA Provenance / in-toto attestation", "relation": "ALIGN", "purpose": "Supplies the attestation shape binding builder identity, external parameters and resolved dependencies to a subject digest for released configuration revisions.", "required": false, "source_refs": [ "SRC-011" ] }, { "target": "CycloneDX ML-BOM (ECMA-424)", "relation": "ALIGN", "purpose": "Target format for the configuration's dependency inventory of models, datasets, tools and third-party prompt components.", "required": false, "source_refs": [ "SRC-012" ] }, { "target": "OpenTelemetry generative-AI semantic conventions", "relation": "ALIGN", "purpose": "Maps configuration facets to telemetry attribute keys so runs can be attributed to a revision; attributes are at development stability, so the alignment is explicitly provisional.", "required": false, "source_refs": [ "SRC-016" ] }, { "target": "AGENTS.md bootstrap convention", "relation": "EXTEND", "purpose": "Extends the plain-Markdown, nearest-file-wins convention with the mandatory Vercy bootstrap fields, so an agent can discover the specification, storage, interface and process endpoints from the package root.", "required": true, "source_refs": [ "SRC-013" ] }, { "target": "OpenAI Model Spec chain of command", "relation": "ALIGN", "purpose": "Supplies the authority ordering and the default rule that tool output, quoted text and attachments carry no instruction authority; adopted as an alignment, not a conformance claim.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "Regulation (EU) 2024/1689 technical documentation and transparency duties", "relation": "ALIGN", "purpose": "Maps configuration fields to documentation, logging, information-to-deployer and human-oversight obligations where the driven system falls into a regulated class; applicability is asserted per deployment, never by default.", "required": false, "source_refs": [ "SRC-014", "SRC-015" ] }, { "target": "NIST AI RMF AI system inventory and change management", "relation": "ALIGN", "purpose": "Links each configuration to an organisational inventory entry and to documented change-management, testing and third-party policy expectations.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "Credential and secret management model (sibling, not yet registered)", "relation": "REFERENCE", "purpose": "Secret values, vaults, rotation and token issuance are referenced by opaque handle only; embedding secret material in instruction text is prohibited rather than modelled.", "required": true, "source_refs": [ "SRC-004", "SRC-018" ] }, { "target": "Foundation model / model card model (sibling)", "relation": "REFERENCE", "purpose": "The pinned model is referenced by identifier and build; training data, architecture, model-level quantitative analysis and model licensing stay with the model card sibling.", "required": false, "source_refs": [ "SRC-012", "SRC-016" ] }, { "target": "Evaluation suite and benchmark model (sibling)", "relation": "REFERENCE", "purpose": "Suite definitions, task sets and scoring methodology are referenced; only the binding of results to a revision digest, thresholds and expiry belongs here.", "required": false, "source_refs": [ "SRC-007", "SRC-018" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension MUST nominate exactly one authoritative master system for configuration and revision identifiers and publish its base IRI; every other identifier held for the same configuration is recorded as an alias with an explicit stability flag.", "The owner package MUST publish an AGENTS.md bootstrap at the package root resolving to the specification, storage type, interface and processes URLs, and MUST keep the nearest-file-wins precedence rule explicit where nested packages exist.", "The owner package MUST name an accountable owner and an accountable deployer, and MUST enforce segregation of duties so the author of a revision is never its sole approver.", "The owner package MUST declare retention periods for superseded revisions and for the run records that reference them, and MUST state the tombstone fields that survive deletion.", "The owner package MUST declare which external standards it aligns to and MUST NOT record a conformance claim without a stored conformity evidence reference." ], "namespace_guidance": "Use reverse-DNS namespaces owned by the publisher for globally visible configuration names, for example com.example.agents/support-triage, mirroring MCP registry practice where namespace ownership is verifiable. Tool names and prompt names are unique only within their serving server and MUST NOT be treated as global identifiers; aggregating clients apply a documented disambiguation prefix. The lower-kebab-case identifiers used inside this model are Dimension-internal structural keys and are never published as global identifiers.", "registry_links": [ "Vercy world-model registry entry vr.wm-ai-005", "Organisational AI system inventory maintained under NIST AI RMF GOVERN 1.6", "MCP server registry entries for every bound server, referenced by reverse-DNS name and version", "Attestation transparency log or artifact store holding signed provenance for each released revision" ] }, "canon_and_patch": { "canonicalization_rules": [ "Serialise the revision to a deterministic canonical form before digesting: lexicographically sorted object keys, UTF-8 in Normalization Form C, LF line endings, no insignificant whitespace, and explicit null versus absent distinction.", "Normalise every time value to RFC 3339 with seconds and an explicit offset before canonicalisation, so that identical instants written in different local offsets do not produce different digests.", "Exclude declared run-time-resolved regions such as secret handles and resolved model build identifiers from the digest, and list every excluded field path in the manifest so exclusion is auditable.", "Canonicalise embedded schemas by their declared dialect; where no $schema is present, record the assumed default dialect explicitly rather than leaving it implicit." ], "patch_rules": [ "Released revisions are immutable. Corrections are issued as new revisions carrying supersedes and derived-from links to the corrected revision; the defective revision is deprecated, never edited.", "A patch is expressed as a structured diff against a named base revision digest and MUST be rejected if the stored base digest does not match the digest the diff was computed against.", "Adding, widening or removing a tool grant, raising an authority level, changing the output contract, relaxing an oversight gate or raising an autonomy budget is a breaking change and cannot be delivered as a patch-level correction.", "Metadata that is not part of the digested content may be appended as a dated annotation with its own observation timestamp; it never rewrites the revision record." ], "compatibility_rules": [ "Increment the major component for changes to instruction authority, tool or context grants, output contract, safety constraints or oversight gates; the minor component for additive, backward-compatible behaviour; the patch component only for wording changes that evaluation evidence shows to be behaviour-neutral.", "Record the supported interface or protocol revisions separately from the configuration's own version, because interface revisions use an independent date-based scheme and change for unrelated reasons.", "Consumers that pin by exact revision digest MUST NOT be silently upgraded; a pinned consumer is notified and re-verified rather than migrated automatically.", "Deprecated features referenced by a configuration MUST record their announced removal window so that dependent revisions can be scheduled for migration before removal." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the configuration registry of record, that is, the system that owns the configuration's lifecycle and is the single source of truth for its identity.", "Governed global identifier or IRI, such as a reverse-DNS namespaced configuration name whose namespace ownership is verifiable and which resolves to a published manifest.", "UUID or ULID minted by the adopting Dimension, used only when neither a master-system identifier nor a governed global identifier exists, and recorded as Dimension-local." ], "timestamp_rule": "All time values are recorded using RFC 3339 with explicit seconds and either the literal 'Z' or a numeric UTC offset of the form +hh:mm or -hh:mm; a bare date is never accepted as an identifier and a local time without an offset is never stored. Event time (authored at, approved at, released at, effective from, withdrawn at, activity started and ended) is recorded separately from observation or ingestion time (when the Dimension harvested or recorded the fact), and both are retained whenever they differ, so that late-arriving or back-filled records remain distinguishable from the events they describe.", "serial_naming_rule": "Revision artifacts are named @+. The revision series is strictly increasing per configuration, gaps are never reused, and a version string may never be re-pointed at a different digest. Subordinate serialised records use //, where record kind is one of evaluation, adversarial-test, attestation, binding or change-control, and the sequence is monotonic per revision and per kind.", "integrity_rule": "Every stored revision carries an algorithm-qualified content digest over its canonical form and, once released, a signed attestation binding a builder identity to that digest. Consumers MUST recompute the digest locally and verify the signature against configured trust anchors before loading a revision; a revision whose digest or signature fails verification MUST be refused, and any tool behaviour annotations arriving with an unverified revision MUST be treated as untrusted claims rather than as authoritative risk classification." }, "policies": [ "No secret, credential, API key or connection string may appear in instruction text or any other digested region; configurations reference credentials by opaque handle only, and secret scanning is a blocking validation check.", "Instruction text is guidance, not a security control. Every constraint whose violation would cause material harm MUST also be enforced outside the model, at the application layer, in a policy engine or through independent output inspection, and any constraint enforced by prompt alone MUST carry a written residual risk note.", "Every production revision MUST carry unexpired functional evaluation evidence and adversarial-test evidence produced against that exact content digest; evidence attached to a mutable name is not accepted.", "Every tool grant annotated as destructive or open-world MUST have a human-in-the-loop denial capability, and the reviewer MUST be shown the untruncated tool inputs before the call proceeds.", "Authorization scopes follow least privilege and progressive elevation: a configuration requests the minimum baseline scope set and escalates on demand rather than requesting an entire scope catalogue up front.", "Segregation of duties applies to every promotion: the author of a revision may not be its sole approver, and publish rights are held separately from read rights.", "No conformance to an external standard or regulation is asserted without a stored conformity evidence reference; external standards are recorded as alignments and known conflicts are recorded rather than reconciled silently.", "Production changes to instructions, guardrails, or tool lists require named owners, an approval record, and an audit event proportional to risk (NIST AI 600-1 AI configuration and ISO/IEC 42001 operational control).", "Instruction text is not a secret and not a security control; credentials and connection strings are forbidden in prompts (OWASP LLM07).", "Tool annotations are untrusted hints; destructive or open-world tools require independent risk classification and default to human confirmation (MCP tools and ToolAnnotations).", "Telemetry capture of instruction content is opt-in and redacted according to the Dimension privacy policy (OpenTelemetry GenAI content capture)." ], "crud": { "read": [ "Resolve a configuration by master identifier or namespaced name and return the effective revision for a given environment, tenant and working scope, together with the precedence trace.", "Return the exact revision snapshot and content digest that a recorded run referenced, so past behaviour can be reconstructed.", "List the revision history with lifecycle state, version, digest, effective-from and effective-to per environment.", "Return the redacted disclosure package for a stated audience class rather than raw instruction text when the requester is external." ], "create": [ "Draft a candidate revision from a named base revision, recording the authoring agent, the principal on whose behalf it acted, and the authoring activity start instant.", "Mint the canonical digest and release record once validation has passed and an approval decision by a party other than the sole author has been captured.", "Register the configuration in the organisational AI system inventory on first release and link the inventory entry back to the configuration identifier.", "Create evaluation, adversarial-test, attestation and binding records as new serialised children of the revision rather than as fields on it." ], "update": [ "Only draft and candidate revisions are mutable; a released revision is changed only by releasing a superseding revision that carries supersedes and derived-from links.", "Lifecycle transitions, deployment bindings, evidence attachments and oversight decisions are appended as new records; existing records are closed with an effective-to instant, never overwritten.", "Corrections to non-digested metadata are recorded as dated annotations carrying their own observation timestamp and author, leaving the digest and the original assertion intact.", "Access, retention and classification policies may be updated independently of revisions, but each update is versioned and the version in force at any past instant remains reconstructable." ], "delete": [ "Withdrawal removes a revision from service and closes its bindings but preserves the revision record, digest and lifecycle timestamps in full.", "Hard deletion requires an explicit, authorised disposition decision, is blocked while any legal hold is active, and always leaves a tombstone carrying the identifier, digest, lifecycle dates and disposition reference.", "Deleting a revision that is still referenced by retained run records, attestations or open regulatory obligations is prohibited; redaction of restricted fields is used instead.", "Deletion of subordinate evidence records is governed by the retention schedule for their own record kind and does not implicitly delete the revision they attest to." ] }, "roles": [ { "name": "Configuration author", "responsibilities": [ "Draft instruction blocks, templates and argument schemas", "Declare tool, context and memory grants with a justification for each", "Propose the change class and record the rationale for the version increment", "Record derivation from prior revisions and disclose any machine-generated content" ] }, { "name": "Release approver", "responsibilities": [ "Verify that validation, evaluation and adversarial evidence are complete and unexpired for the exact candidate digest", "Approve or reject promotion and record the decision with rationale and timestamp", "Confirm segregation of duties, refusing approval where the approver authored the revision", "Confirm that a retained, verifiable rollback target exists before production release" ] }, { "name": "Accountable deployer", "responsibilities": [ "Determine and record the regulatory risk classification and applicable jurisdictions", "Maintain instructions for use and other deployer-facing disclosure extracts", "Staff and empower the human oversight function and assure reviewer competence", "Own incident response, withdrawal decisions and post-market monitoring linkage" ] }, { "name": "Security reviewer", "responsibilities": [ "Assess prompt injection and leakage exposure and sign off the trust boundary declaration", "Review scope minimisation, secret-handle hygiene and server binding trust", "Maintain the tool risk register and decide whether supplier annotations may be trusted", "Set and review confirmation gates and per-tool invocation limits" ] }, { "name": "Evaluation owner", "responsibilities": [ "Maintain versioned evaluation and adversarial suites and their acceptance thresholds", "Bind every result set to a revision digest and a pinned model build", "Set evidence validity periods and trigger re-evaluation on model or runtime change", "Publish coverage and exclusions so that assurance claims remain falsifiable" ] }, { "name": "Registry steward", "responsibilities": [ "Maintain identifiers, namespaces, aliases and inventory linkage for every configuration", "Enforce canonicalisation, digest and serial naming rules across storage projections", "Operate the retention schedule, legal holds, tombstones and disposition records", "Reconcile the model's alignments when an external standard publishes a new revision" ] } ], "access": { "default_rule": "Deny by default. Read access to instruction text is granted per confidentiality class to named principals or groups with a recorded grant basis and expiry; propose, approve and publish rights are granted separately from read rights and are never bundled into a single omnibus permission.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Auditors and regulators receive a redacted disclosure package with a redaction manifest that preserves verifiable linkage to the source revision digest, rather than raw instruction text.", "Incident responders may obtain time-boxed break-glass read access to a withdrawn or restricted revision; the grant is logged, notified to the owner and expires automatically.", "Deployers receive only the instructions-for-use extract required to exercise oversight and to understand capabilities and limitations, not the full configuration.", "Automated verification and evaluation services may read revision digests, attestations and schemas without read access to instruction bodies, using digest-only scopes.", "A configuration under legal hold is readable by the holding authority's nominated custodian regardless of its normal confidentiality class.", "Incident responders may read frozen versions under audit", "Extended A2A Agent Cards may reveal additional capability metadata after authentication without revealing instruction bodies", "Redacted eval corpora may include instruction excerpts when required to reproduce a finding" ], "audit_requirements": [ "Log every read, export and redaction of instruction text with the principal, stated purpose, revision digest and an RFC 3339 timestamp carrying seconds and an explicit offset.", "Log every lifecycle transition, approval, rejection, binding, rollback and withdrawal with actor, rationale and correlation identifiers to affected runs.", "Log every change to tool grants, requested scopes or oversight gates, including the prior and new values, and retain those entries for at least the revision retention period.", "Log break-glass grants and their expiry separately and review them on a defined cadence.", "Retain access logs at least as long as the run records that reference the configuration, so that a past decision remains attributable.", "Record read of classified instruction bodies and every create, activate, freeze, rollback, and delete event with RFC 3339 event time", "Record tool-policy changes and human denials of tool invocation at the configuration-policy level" ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md at the package root, then the AGENTS.md nearest to the current working scope, which takes precedence on conflict.", "Specification URL, for the model contract, field semantics and identity rules.", "Storage type URL, for the concrete projection in use, whether files, Git, MongoDB, an object store or a registry API.", "Interface URL, for the access protocol in use, whether HTTP, MCP or a local library.", "Processes URL, for release, evaluation, rollout, rollback, redaction and retention procedures.", "The effective configuration revision and its attestation, verified before any tool is invoked or any instruction is loaded." ] } }, "coverage": { "claim": "Claude's seven-bundle structure carries the model: identity and release control, instruction content and authority, capability and binding surface, safety and oversight, assurance and provenance, deployment and observability, and governance/retention, with an explicit out-of-scope list and seven sourced boundary notes. Four Grok findings are grafted in to close real gaps (skill packaging, kind/intended-use, modality and handoff bindings, external alignment mapping) plus two functions. This is defensible coverage of a versioned prompt/agent configuration, not universal completeness: internationalisation, guardrail fail-modes, prompt experimentation and ISO clause-level anchoring remain open.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Master-system identifier first, then governed reverse-DNS name, then Dimension-minted UUID or ULID; revision equality resolved by canonical content digest. MCP prompt and tool names are explicitly rejected as global identifiers because their uniqueness is only per-server." }, { "dimension": "lifecycle", "status": "covered", "notes": "Draft through candidate, approved, released, deprecated and withdrawn, with guarded transitions, approval evidence, deprecation notice windows and tombstones surviving deletion. Release immutability follows Semantic Versioning 2.0.0." }, { "dimension": "relationships", "status": "covered", "notes": "Composition and precedence between base, overlay and variant configurations; references to agent, run, model, server, credential and evaluation siblings; supersedes and derived-from links between revisions." }, { "dimension": "temporal", "status": "covered", "notes": "Authored, approved, released, withdrawn, activity start and end, binding effective-from and effective-to, and evidence expiry, all RFC 3339 with seconds and explicit offset, with event time held separately from ingestion time." }, { "dimension": "provenance", "status": "covered", "notes": "PROV-O attribution, association, delegation, generation and derivation, plus SLSA-style signed attestation binding builder identity, external parameters and resolved dependencies to the subject digest." }, { "dimension": "ownership", "status": "covered", "notes": "Owner, accountable deployer, stewards, inventory linkage and segregation of duties, aligned with NIST AI RMF GOVERN 1.6 inventory and GOVERN 2.1 role expectations." }, { "dimension": "validation", "status": "covered", "notes": "Structural validation against a declared schema dialect, policy validation including secret scanning and scope justification, output-contract validation, evaluation thresholds and pre-load digest and signature verification." }, { "dimension": "access", "status": "covered", "notes": "Deny by default, confidentiality classification, separated read and publish rights, digest-only scopes for automated verifiers, break-glass and redacted-disclosure exceptions, and mandatory access logging." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention periods with a stated basis, disposition methods, tombstone fields, legal hold override, prohibition on deleting revisions still referenced by retained runs, and alignment between configuration and run record retention." }, { "dimension": "interoperability", "status": "covered", "notes": "Alignments recorded to MCP, Semantic Versioning, PROV-O, SLSA, CycloneDX ML-BOM, OpenTelemetry generative-AI conventions, JSON Schema 2020-12 and AGENTS.md, with tool-name disambiguation and interface-revision declaration handled explicitly." }, { "dimension": "authority and precedence", "status": "covered", "notes": "Platform, developer, user and guideline ordering from the OpenAI Model Spec; equal-authority tie-breaks; nearest-scope-wins overlay precedence from the AGENTS.md convention; tool output and quoted content carry no authority by default." }, { "dimension": "security", "status": "covered", "notes": "Untrusted content boundary, injection defence and evidence, secret-handle referencing, least-privilege scope elevation, untrusted tool annotations, local server execution consent and state handle hijacking, all from MCP security best practices and the OWASP LLM risk taxonomy." }, { "dimension": "measurement and evaluation", "status": "covered", "notes": "Metric names, units, thresholds, observed values, evaluated model build, evidence expiry, adversarial coverage and explicit attack-class exclusions to keep assurance claims falsifiable." }, { "dimension": "cost and resource limits", "status": "covered", "notes": "Token, cost and wall-clock budgets, autonomy iteration caps, per-tool invocation limits and declared termination behaviour on budget exhaustion." }, { "dimension": "spatial", "status": "not-applicable", "notes": "A configuration has no physical location. The only spatial dimension that applies is jurisdiction, which is modelled under regulatory classification. Data residency of stored revisions is delegated to the storage projection and to the deployment model." }, { "dimension": "internationalisation", "status": "gap", "notes": "Locale and variant selection is modelled structurally, but no authoritative source was found governing translation equivalence, review of localised instruction text, or how evaluation evidence for one locale transfers to another. Treated as an open gap, not as canonical structure." } ], "known_omissions": [ "Model weights, fine-tuning runs, adapters and distillation artifacts, which belong to a model-card sibling.", "Retrieval corpus construction, chunking and vector index configuration beyond the grant reference.", "Multi-agent orchestration topology, delegation graphs and inter-agent protocols.", "Internal design of guardrail classifiers and output inspection models.", "Commercial licensing, pricing and intellectual property terms attaching to prompt assets.", "Content credentials or watermarking applied to generated outputs.", "Accessibility and human-factors requirements for the oversight review interface.", "ISO/IEC 42001 Annex A control mapping: iso.org returned HTTP 403 during this session, so no ISO control identifiers are cited and no ISO alignment is asserted.", "NIST AI 600-1 Generative AI Profile action identifiers: the published PDF could not be parsed to text in this session, so only the NIST AI RMF Playbook GOVERN subcategories are cited.", "OWASP Top 10 for LLM Applications 2025 entry text: the 2025 PDF exceeded the fetch size limit, so only the OWASP project page and its archived 2023 list were directly verified and the 2025 entry numbering is not asserted.", "EU AI Act Annex IV mapping of prompts as high-risk technical documentation was not fetched as a primary source and is a likely regional omission.", "Prompt A/B experimentation, canary traffic splitting, and automatic prompt optimization (DSPy and similar) lack a primary standard and are not modeled as first-class objects.", "IEEE or other SDO prompt-markup languages (PromptML, POML) were not located as adopted standards in this pass.", "MCP specification has moved beyond 2025-06-18 (schema 2026-07-28 observed); hosts may implement later prompt or tool fields not fully decomposed here.", "Provider-specific cache breakpoints, prompt-caching billing, and multimodal system-prompt part inventories beyond MCP image/audio examples are incomplete.", "National adoptions of ISO/IEC 42001 (for example documented operational-instruction lists) were seen only in translation and are not treated as ISO-canonical clause text.", "LangChain Hub, PromptLayer, and other commercial prompt registries are vendor implementations, not semantic sources." ], "conflicts": [ "MCP describes a prompt or tool name as a unique identifier, but uniqueness is scoped to a single server and the specification itself warns that the server name is not a reliable disambiguator. The MCP registry adds reverse-DNS namespacing. This model therefore refuses to treat bare MCP names as global identifiers.", "MCP sampling, the clearest normative source for model preferences, system prompt and decoding parameters as a configuration surface, is marked Deprecated as of protocol revision 2026-07-28 with migration to direct provider APIs. Those field names are used as evidence that the facets exist, not as a durable interface contract.", "OpenTelemetry generative-AI attributes are at Development stability and have been relocated to a separate repository, so attribute keys used for run linkage may be renamed. The telemetry alignment is provisional and versioned against semantic conventions 1.41.0.", "Semantic Versioning requires that released contents never change, while common practice keeps prompts in a mutable branch file with no released version at all. This model takes the standards-led position and treats a mutable prompt file as an unreleased draft.", "OWASP guidance holds that a system prompt must not be treated as a secret or relied on as a control, while commercial practice classifies system prompts as confidential intellectual property. The model records a confidentiality class for handling purposes while forbidding reliance on it as a security control.", "MCP requires clients to treat tool behaviour annotations as untrusted unless the server is trusted, which conflicts with using those annotations directly as a risk classification. The model resolves this by recording an annotation trust basis and a locally assigned risk class alongside the supplier's claims.", "EU AI Act obligations depend on risk class, role and phased application dates, so a single configuration may be in scope for some duties and not others. The model records classification and applicability per deployment and never assumes them.", "MCP prompts are specified as user-controlled templates; OpenAI/Azure system or developer instructions are deployer-controlled; ISO 22989 'prompt' is overarching instructions. This model keeps all three as kinds rather than forcing one control plane.", "OpenAI Model Spec 'system' is provider-only and above developer; industry 'system message' is usually developer text. Collapsing those layers is a mapping error.", "OWASP: system prompts are not secrets. A2A/ADK practice: public Agent Cards must not carry instruction bodies. Both stand: do not rely on obscurity; still withhold operational text from unauthenticated discovery.", "OpenTelemetry examples allow date-like gen_ai.prompt.version values; this meta-model forbids dates as identifiers and treats such strings as labels only.", "OpenAI documents hosted prompt objects with id/version/variables and also a migration path that moves prompts into application source. Hosted versus repo storage is a projection conflict, not two semantics.", "ToolAnnotations defaults (destructiveHint true, openWorldHint true, readOnlyHint false) conflict with authors who omit annotations intending 'safe'; clients must assume the spec defaults, not author intent.", "OTel GenAI conventions remain Development status; field names may change before stability." ], "regional_assumptions": [ "Regulatory structure is drawn from Regulation (EU) 2024/1689 as described by the European Commission and assumes placement on the market or use within the European Union; dates cited are the Commission's published timeline.", "No obligations from United States federal or state law, United Kingdom, Chinese, Japanese, Indian, Brazilian or sector-specific regimes are asserted; adopters in those jurisdictions must add their own documentation and record-keeping duties.", "NIST AI RMF is treated as voluntary guidance, not as a legal requirement in any jurisdiction.", "Language and locale variants are assumed optional; a monolingual configuration is valid under this model.", "Data residency and cross-border transfer constraints on stored revisions and access logs are delegated to the storage projection and are not modelled here.", "NIST AI 600-1 is voluntary US federal guidance; it is used for risk actions, not as a global legal duty.", "ISO/IEC 22989 prompt text cited here is from Amendment 1 draft excerpt (DAmd 1), not proven as already in ISO/IEC 22989:2022 without the amendment.", "OpenAI Model Spec localization and legal-compliance variants imply some deployments will have locale-specific provider-system layers.", "EU, UK, and other high-risk AI documentation duties may require retaining instruction versions even when this model would otherwise allow deletion; treat as a hold overlay until a primary mapping is added." ], "adversarial_checks": [ "Single-vendor dependence: model selection preferences and system-prompt fields rest largely on the MCP sampling feature, which is deprecated, and on OpenTelemetry attributes at development stability. Both are flagged in conflicts, and the finding that depends most heavily on them is marked inline-only rather than presented as an independently governed artifact.", "Duplication with the agent-run model: run identifiers, conversation identifiers and telemetry keys appear only as linkage fields. No prompt text, tool call payload, output or latency measurement of a specific execution is modelled here, so the boundary with WM-AI-004 holds.", "Storage-format independence: every identity, ordering and integrity rule is expressed over canonical content and digests rather than file paths, so the model survives projection to Git, MongoDB, an object store or an MCP interface. The nearest-file-wins precedence rule is stated as a scope rule, not a filesystem rule.", "Prompt versus agent conflation: boundary notes separate the configuration artifact from the deployed actor, the tool implementation and the foundation model. A configuration with no agent bound to it is still a valid instance, which is the discriminating test.", "Opinion versus fact: findings whose answers are policy choices rather than lookups, namely authority hierarchy, autonomy budgets, refusal policy and confidentiality class, require a declared decision with a named accountable owner and a recorded rationale, so they remain auditable rather than assertive.", "Unearned conformance: no bundle, layer or function claims conformance to any standard or regulation. Every external standard is recorded as an alignment, two alignments are flagged as unstable, and three evidence gaps are declared where sources could not be retrieved.", "Falsifiability of the identity rule: if an adopting Dimension has no registry of record, the priority chain forces an explicit fallback to a verifiable reverse-DNS name and then to a Dimension-local UUID or ULID. A date is explicitly rejected as an identifier, so a configuration keyed only by its release date fails the rule rather than passing silently.", "Evidence decay: attaching evaluation results to a mutable name is rejected, evidence carries an expiry, and model or runtime change is a declared re-validation trigger, so a stale assurance claim becomes visibly stale rather than remaining nominally valid.", "Checked that agent identity (WM-AI-002) and run traces (WM-AI-004) are referenced rather than duplicated as configuration fields.", "Checked that MCP/A2A/Git/JSON are treated as projections, with tool and prompt payloads remaining the semantic objects.", "Checked that ISO 22989:2022 is not claimed to contain the prompt term without the generative-AI amendment excerpt.", "Checked that system prompts are not modeled as secrets or as access-control mechanisms, matching OWASP LLM07.", "Checked that OTel date-like version examples are recorded as a conflict rather than copied into identity rules.", "Checked that skill references/ knowledge files are bounded to WM-KNW-005 rather than absorbed as instruction identity.", "Checked that 'latest' stored-prompt pointers cannot satisfy run pinning." ] }, "researchAdjudication": { "providerMode": "dual-provider", "activeProviders": [ "claude", "grok" ], "waivedProviders": [], "providerPolicy": {}, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "Providers disagree (Claude aggregate, Grok entity) and the aggregate reading wins. The parts this model governs — instruction blocks, template arguments, tool and context grants, guardrail bindings, autonomy caps — have no identity, lifecycle or retention outside the revision that contains them, and the revision digest is the consistency boundary that makes them reproducible. Grok's motivation for 'entity' is that a run must pin one version; an aggregate root has exactly that pin-able identity, so nothing is lost. The model boundary stays: the configuration artifact and its lifecycle, not the agent actor (WM-AI-002), not a single execution (WM-AI-004), not model weights or knowledge corpora (WM-KNW-005)." }, "decisions": [ { "concept": "Base provider selection", "disposition": "Claude as base", "rationale": "Claude carries a complete out-of-scope list, seven boundary notes each with source refs, explicit inline-only rationales where a facet must not become a second source of truth, and three bundles Grok lacks entirely (assurance/provenance, deployment/observability, governance/retention). Grok is smaller but not narrower in ambition; the decisive factor is boundary completeness, not the 28-versus-16 finding count." }, { "concept": "Entry kind aggregate versus entity", "disposition": "Accept aggregate", "rationale": "The revision is the immutability and consistency boundary for parts that have no independent identity or retention; Grok's pin-ability requirement is satisfied by the aggregate root's revision identity, so the disagreement resolves without loss of either provider's semantics." }, { "concept": "Skill packages and progressive disclosure", "disposition": "Accepted from Grok", "rationale": "A genuine hole in the base: an entire configuration packaging convention with a primary specification behind it and direct consequences for tool allowlists and instruction loading order." }, { "concept": "Configuration kind and intended use", "disposition": "Accepted from Grok", "rationale": "Intended purpose, user population, prohibited uses and the fixed/editable/dynamic state are decision-bearing facts that the base only gestures at through a single classification question." }, { "concept": "External schema alignment map", "disposition": "Accepted from Grok", "rationale": "Turns the base model's non-conformance stance into per-instance, falsifiable data (mapping evidence, conformance claim, projection used) instead of a prose disclaimer in coverage notes." }, { "concept": "Default modalities and handoff bindings", "disposition": "Accepted from Grok, narrowed", "rationale": "Modalities are missing from the base outright; handoff bindings are admitted only as declared references to other configurations, keeping the base's exclusion of orchestration topology and inter-agent protocols intact." }, { "concept": "Grok tool-definitions finding", "disposition": "Rejected as duplicative", "rationale": "Claude's tool-grant-and-schema-binding already covers names, sources, schema binding at release and explicit denials, and its q-server-drift covers post-release catalog change, which is the listChanged concern under a different name." }, { "concept": "Grok injection-leakage-access finding", "disposition": "Rejected as duplicative", "rationale": "Fully covered across the base by untrusted-content-and-injection-defence, secret-hygiene-and-prompt-leakage, and configuration-confidentiality-and-access, including the OWASP position that a system prompt is not a security control." }, { "concept": "Grok pinning-observability-retention finding", "disposition": "Rejected as duplicative", "rationale": "Run-linkage-and-telemetry plus retention-deletion-and-legal-hold already cover the pin attribute, opt-in content capture, retention window and tombstones; the base checklist also forbids deleting revisions still referenced by retained runs." }, { "concept": "Grok role-separated-instructions and parameterized-templates", "disposition": "Rejected as duplicative", "rationale": "Both restate Claude's instruction-blocks-and-templating. Their genuinely new sub-questions — request-time computed instructions, static-instruction token budget, vendor stored-prompt objects, untrusted variable provenance — are recorded as deferred research rather than imported as overlapping findings." }, { "concept": "Grok guardrails-and-refusals finding", "disposition": "Rejected; one sub-question deferred", "rationale": "Behavioural-constraints-and-refusals plus the evaluation-evidence layer cover refusal criteria, external enforcement points and re-validation after change. Only guardrail fail-mode (fail-closed, fail-open, escalate) is genuinely absent, and it lacks a primary-source anchor beyond vendor documentation." }, { "concept": "Grok instruction-composition finding", "disposition": "Rejected; two sub-questions deferred", "rationale": "Merge order and precedence are held by configuration-composition-and-precedence and the resolve-effective-configuration function. Post-substitution effective-stack digest and context-budget truncation policy are the only additive parts and are deferred pending a primary source." }, { "concept": "Claude inline-only findings", "disposition": "Retained as inline-only", "rationale": "Authority level, model binding and autonomy budgets stay inline on the revision snapshot. Materialising them as separately governed artifacts would create a mutable second copy able to drift from the digest, defeating the reproducibility rule the model is built on." }, { "concept": "Provider-system versus developer system-message layers", "disposition": "Keep both layers distinct", "rationale": "Both providers independently flag collapsing them as a mapping error; the base already separates platform, developer, user and guideline authority, so no adjudication conflict remains." }, { "concept": "Grok functions fn-register-version, fn-compose-stack, fn-validate-config, fn-activate-rollback, fn-redact-secrets", "disposition": "Rejected as duplicative", "rationale": "Each maps onto an existing base function (release-configuration-revision, resolve-effective-configuration plus render-prompt-from-template, validate-configuration, bind-and-roll-out plus rollback-or-disable, redact-configuration-for-disclosure) with no additional operation." }, { "concept": "ISO/IEC 22989 DAmd 1 and ISO/IEC 42001 as normative anchors", "disposition": "Downgraded to publication hold", "rationale": "Grok cites a draft-amendment public excerpt and a standard landing page; Claude reported iso.org returning HTTP 403 in the same window. Neither establishes clause text, so imported findings keep their conceptual grounding but no ISO clause identifier may be asserted." } ], "publicationHolds": [ "Verify every accepted source URL live and re-pin versions before publication, notably the MCP 2026-07-28 revisions, the MCP registry server.json schema, and the relocated OpenTelemetry GenAI semantic conventions at 1.41.0.", "MCP sampling (Claude SRC-005) is marked Deprecated and OTel GenAI attributes are at Development stability; every alignment resting on them must be labelled provisional and dated, and no durable interface contract may be claimed.", "ISO/IEC 22989 DAmd 1 and ISO/IEC 42001 clause text remain unverified (draft excerpt and landing page only, with a 403 recorded against iso.org). No ISO clause identifier or conformance statement may appear in the published draft.", "Imported Grok findings carry Grok source identifiers that collide with Claude's SRC numbering; the synthesizer must remap and re-resolve each source reference, and a human must confirm no finding ends up citing the wrong document.", "Multi-profile domain validation has not been performed. The model has been exercised against agent-platform and MCP-style profiles only; validate against at least a regulated-deployment profile and a vendor-hosted stored-prompt profile before publishing beyond a research draft.", "OWASP Top 10 for LLM Applications 2025 entry numbering is asserted only by Grok's PDF fetch while Claude recorded a fetch failure; confirm LLM01, LLM06 and LLM07 identifiers against the published document before citing them.", "Internationalisation remains a declared gap: locale and variant selection is structural only, with no source governing translation equivalence or transfer of evaluation evidence across locales." ], "deferredResearch": [ "Guardrail fail-mode semantics: whether a bound guardrail fails closed, fails open or escalates to a human, and whether that decision is logged — currently only vendor documentation supports it.", "Effective-stack digest after substitution as distinct from the unevaluated template digest, and the context-budget truncation policy that decides what is dropped first and whether the drop is recorded.", "Vendor-hosted stored-prompt objects (id, version, variables) and the migration path toward application-owned source, to confirm this is a storage projection rather than a second semantics.", "Request-time computed instructions: which function, inputs and non-model local context may shape instruction text, and how a dynamically computed stack is pinned for replay.", "Static-instruction token or character budgeting so instructions do not starve task context, and whether any primary source governs it.", "EU AI Act Annex IV mapping of prompt and configuration artifacts as high-risk technical documentation, fetched as a primary source rather than via a reproduction site.", "Prompt A/B experimentation, canary traffic splitting and automatic prompt optimisation (DSPy and similar) — currently no primary standard, so generated text is treated as a versioned payload only.", "Determinism: how a sampling seed is combined with the configuration digest for reproducible runs without the seed ever becoming part of identity.", "Internationalisation governance: translation equivalence, review of localised instruction text, and whether evaluation evidence for one locale transfers to another." ] }, "statistics": { "sources": 32, "bundles": 7, "layers": 15, "findings": 32, "questions": 118, "artifacts": 29, "functions": 12 } }