# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T11:50:58Z", "synthesisSha256": "fd67545505f9ee80a83ba426ab1f62f777fce0d3c461221585de6e78226b296e", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-AI-007", "registryId": "vr.wm-ai-007", "name": "AI Model Registry Entry", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "registry", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.AI.REG" ], "tags": [ "ai", "model", "registry", "entry", "inf.ai.reg" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-ai-007-ai-model-registry-entry/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/publications/wm-ai-007-ai-model-registry-entry", "model": { "registry_id": "vr.wm-ai-007", "model_id": "WM-AI-007", "name": "AI Model Registry Entry", "entry_kind": "registry", "purpose": "Represent one governed, discoverable registry record that binds an AI model family or version to artifacts, technical metadata, lineage, rights, evaluations, approvals, lifecycle and distribution views without absorbing their external masters.", "scope_statement": "Owns one registry-entry identity; owning registry, namespace, family and version bindings; catalog description, classifications and stewardship; artifact, technical-contract, lineage, rights, documentation, evaluation, risk, approval, lifecycle, promotion, deployment-observation, availability, access, correction, retention, audit and projection assertions. Model artifact, training run, dataset, source code, build, evaluation, deployment, endpoint, model card, policy, credential, provenance, audit and records masters remain external.", "in_scope": [ "Entry identity, registry scope, family and version bindings, aliases, discovery metadata, stewardship, artifact and technical-contract references, lineage, rights and transparency", "Evaluation, risk, safety, security, approvals, lifecycle, promotion, deployment observations, availability, access, correction, retention, audit and projections" ], "out_of_scope": [ "Creating or mutating external model artifact, training, dataset, code, build, evaluation, deployment, endpoint, policy, credential, provenance, audit or records masters", "Equating registry entry with model artifact, model card, approval or deployment, or equating digest, signature or popularity with quality and safety", "Autonomous approval, publication, signing, revocation, access expansion, disclosure, deployment or destructive cleanup" ], "boundary_notes": [ { "neighbor": "WM-SFT-004 ML Model Artifact", "distinction": "The unified parent_ids value is an unapproved boundary signal because no relation-ledger edge exists. The entry may reference immutable artifacts but cannot own or mutate their bytes, provenance or lifecycle.", "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014" ] }, { "neighbor": "WM-AI-006 Model Training / Fine-tuning Run", "distinction": "Training owns execution history. The registry entry stores source-qualified run, dataset, code and builder references and bounded lineage summaries.", "source_refs": [ "SRC-003", "SRC-006", "SRC-013", "SRC-016" ] }, { "neighbor": "AI Model Evaluation", "distinction": "External evaluation masters own datasets, procedures, measurements and conclusions. The entry stores versioned evidence bindings, summaries and approval use.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010" ] }, { "neighbor": "Deployment and endpoint", "distinction": "Deployment systems own environment, rollout, endpoint and observed runtime state. The registry records source-qualified references and observations without treating approval or publication as deployment.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-014" ] }, { "neighbor": "Model card, system card and technical documentation", "distinction": "These are versioned transparency artifacts or projections. The registry entry binds them and selected summaries but does not make every card the canonical record.", "source_refs": [ "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] }, { "neighbor": "DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage", "distinction": "These are catalog, registry, card, BOM, distribution, provenance, verification and lineage profiles with different scopes. No mapping is universally applicable or assumed lossless.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)", "organization": "National Institute of Standards and Technology", "url": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10", "version_or_date": "NIST AI 100-1, 26 January 2023; revision in progress at access", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Frames governed AI lifecycle risk, accountability, measurement and documentation." }, { "id": "SRC-002", "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf", "version_or_date": "NIST AI 600-1, July 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Adds training-data, privacy, security, provenance, pre-deployment testing, incident and environmental considerations for generative AI." }, { "id": "SRC-003", "title": "Secure Software Development Practices for Generative AI and Dual-Use Foundation Models", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218A.pdf", "version_or_date": "NIST SP 800-218A, July 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Extends secure development practices to model, data, component, provenance and release evidence." }, { "id": "SRC-004", "title": "Regulation (EU) 2024/1689 Artificial Intelligence Act", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj", "version_or_date": "13 June 2024 official journal text", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Provides an EU legal profile for technical documentation, records, transparency, risk and general-purpose AI obligations." }, { "id": "SRC-005", "title": "Regulation (EU) 2016/679 General Data Protection Regulation", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj", "version_or_date": "27 April 2016; applicable from 25 May 2018", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Provides an EU privacy profile for lawful processing, purpose, minimization, rights, security and accountability." }, { "id": "SRC-006", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines entities, activities, agents, attribution, association, derivation, revision and time for registry lineage." }, { "id": "SRC-007", "title": "Data Catalog Vocabulary (DCAT) Version 3", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-dcat-3/", "version_or_date": "W3C Recommendation 22 August 2024", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Separates a catalog record from the cataloged resource and defines discoverability, version, distribution, rights and qualified relations." }, { "id": "SRC-008", "title": "Model Registry Workflows", "organization": "MLflow", "url": "https://mlflow.org/docs/latest/ml/model-registry/workflow/", "version_or_date": "Latest first-party documentation at access; stages deprecated since 2.9.0", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines registered models, model versions, aliases, tags, source runs and access-controlled environments while deprecating fixed stages." }, { "id": "SRC-009", "title": "Model Cards", "organization": "Hugging Face", "url": "https://huggingface.co/docs/hub/model-cards", "version_or_date": "Hub documentation current at access", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines discoverable model-card metadata for task, library, language, license, datasets, base model, evaluation and newer-version links." }, { "id": "SRC-010", "title": "Model Cards for Model Reporting", "organization": "Google Research", "url": "https://research.google/pubs/model-cards-for-model-reporting/", "version_or_date": "2019 publication", "source_type": "scientific", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines transparent model reporting for intended use, limitations, evaluation conditions and relevant subgroups." }, { "id": "SRC-011", "title": "SPDX Specification AI Profile", "organization": "SPDX", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/AI/AI/", "version_or_date": "SPDX 3.0.1", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines an AI profile for model and system packages with licensing, provenance, metrics, limitations and sensitive-information metadata." }, { "id": "SRC-012", "title": "CycloneDX Bill of Materials Specification", "organization": "OWASP CycloneDX", "url": "https://github.com/CycloneDX/specification", "version_or_date": "CycloneDX 1.7, 21 October 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines ML-BOM component, model-card, dataset, dependency, distribution, license, provenance and cryptographic-assurance views." }, { "id": "SRC-013", "title": "SLSA Terminology", "organization": "Open Source Security Foundation", "url": "https://slsa.dev/spec/v1.1/terminology", "version_or_date": "SLSA 1.1", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines artifact, build, builder, dependency and provenance concepts for release integrity." }, { "id": "SRC-014", "title": "OCI Distribution Specification", "organization": "Open Container Initiative", "url": "https://github.com/opencontainers/distribution-spec/releases/tag/v1.1.1", "version_or_date": "OCI Distribution Specification 1.1.1", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines a content-addressed registry distribution API and release-pinned artifact discovery profile." }, { "id": "SRC-015", "title": "Verifying Signatures", "organization": "Sigstore", "url": "https://docs.sigstore.dev/cosign/verifying/verify/", "version_or_date": "Cosign first-party documentation current at access", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines bounded signature and identity verification for artifacts without equating a valid signature with model quality or safety." }, { "id": "SRC-016", "title": "OpenLineage Object Model", "organization": "OpenLineage", "url": "https://openlineage.io/docs/spec/object-model/", "version_or_date": "Specification 1.53.0 current at access", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Separates Job, Run, Dataset and RunEvent identities for source training and lineage references." }, { "id": "SRC-017", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/info/rfc3339/", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T14:55:00Z", "relevance": "Defines interoperable timestamps with seconds and an explicit UTC relationship." } ], "structure": { "bundles": [ { "id": "registry-identity-scope-ownership-and-discovery", "name": "Registry identity, scope, ownership and discovery", "description": "Groups governed registry context for registry identity, scope, ownership and discovery.", "rationale": "A registry entry has its own governed identity and registration provenance distinct from the cataloged model resource.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ], "layers": [ { "id": "entry-root-registry-scope-family-and-version", "name": "Entry root, registry scope, family and version", "description": "Groups source-qualified registry context for entry root, registry scope, family and version.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ], "findings": [ { "id": "entry-identity-registry-namespace-issuer-owner-revision-and-current-head", "name": "Entry identity, registry namespace, issuer, owner, revision and current head", "description": "Records entry identity, registry namespace, issuer, owner, revision and current head as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ], "questions": [ { "id": "entry-identity-registry-namespace-issuer-owner-revision-and-current-head-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish entry identity, registry namespace, issuer, owner, revision and current head?", "kind": "identity", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "entry-identity-registry-namespace-issuer-owner-revision-and-current-head-q02", "text": "Who may assert, review, approve, correct or rely on entry identity, registry namespace, issuer, owner, revision and current head, under which authority, purpose and limits?", "kind": "temporal", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "entry-identity-registry-namespace-issuer-owner-revision-and-current-head-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to entry identity, registry namespace, issuer, owner, revision and current head, and which evidence supports them?", "kind": "validation", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "entry-identity-registry-namespace-issuer-owner-revision-and-current-head-data", "name": "Entry identity, registry namespace, issuer, owner, revision and current head data", "description": "Typed data for entry identity, registry namespace, issuer, owner, revision and current head with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "entry-identity-registry-namespace-issuer-owner-revision-and-current-head-record", "name": "Entry identity, registry namespace, issuer, owner, revision and current head record", "description": "Immutable or successor-versioned registry evidence for entry identity, registry namespace, issuer, owner, revision and current head.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for entry-identity-registry-namespace-issuer-owner-revision-and-current-head; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "model-family-version-alias-canonical-uri-duplicate-and-equivalence", "name": "Model family, version, alias, canonical URI, duplicate and equivalence", "description": "Records model family, version, alias, canonical uri, duplicate and equivalence as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ], "questions": [ { "id": "model-family-version-alias-canonical-uri-duplicate-and-equivalence-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish model family, version, alias, canonical uri, duplicate and equivalence?", "kind": "relationship", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "model-family-version-alias-canonical-uri-duplicate-and-equivalence-q02", "text": "Who may assert, review, approve, correct or rely on model family, version, alias, canonical uri, duplicate and equivalence, under which authority, purpose and limits?", "kind": "composition", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "model-family-version-alias-canonical-uri-duplicate-and-equivalence-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to model family, version, alias, canonical uri, duplicate and equivalence, and which evidence supports them?", "kind": "privacy", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "model-family-version-alias-canonical-uri-duplicate-and-equivalence-data", "name": "Model family, version, alias, canonical URI, duplicate and equivalence data", "description": "Typed data for model family, version, alias, canonical uri, duplicate and equivalence with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "model-family-version-alias-canonical-uri-duplicate-and-equivalence-record", "name": "Model family, version, alias, canonical URI, duplicate and equivalence record", "description": "Immutable or successor-versioned registry evidence for model family, version, alias, canonical uri, duplicate and equivalence.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for model-family-version-alias-canonical-uri-duplicate-and-equivalence; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "catalog-description-classification-and-stewardship", "name": "Catalog description, classification and stewardship", "description": "Groups source-qualified registry context for catalog description, classification and stewardship.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ], "findings": [ { "id": "title-summary-keywords-task-modality-language-domain-and-search-facets", "name": "Title, summary, keywords, task, modality, language, domain and search facets", "description": "Records title, summary, keywords, task, modality, language, domain and search facets as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ], "questions": [ { "id": "title-summary-keywords-task-modality-language-domain-and-search-facets-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish title, summary, keywords, task, modality, language, domain and search facets?", "kind": "classification", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "title-summary-keywords-task-modality-language-domain-and-search-facets-q02", "text": "Who may assert, review, approve, correct or rely on title, summary, keywords, task, modality, language, domain and search facets, under which authority, purpose and limits?", "kind": "evidence", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "title-summary-keywords-task-modality-language-domain-and-search-facets-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to title, summary, keywords, task, modality, language, domain and search facets, and which evidence supports them?", "kind": "lifecycle", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "title-summary-keywords-task-modality-language-domain-and-search-facets-data", "name": "Title, summary, keywords, task, modality, language, domain and search facets data", "description": "Typed data for title, summary, keywords, task, modality, language, domain and search facets with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "title-summary-keywords-task-modality-language-domain-and-search-facets-record", "name": "Title, summary, keywords, task, modality, language, domain and search facets record", "description": "Immutable or successor-versioned registry evidence for title, summary, keywords, task, modality, language, domain and search facets.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for title-summary-keywords-task-modality-language-domain-and-search-facets; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "creator-provider-publisher-steward-contact-jurisdiction-and-attribution", "name": "Creator, provider, publisher, steward, contact, jurisdiction and attribution", "description": "Records creator, provider, publisher, steward, contact, jurisdiction and attribution as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ], "questions": [ { "id": "creator-provider-publisher-steward-contact-jurisdiction-and-attribution-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish creator, provider, publisher, steward, contact, jurisdiction and attribution?", "kind": "ownership", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "creator-provider-publisher-steward-contact-jurisdiction-and-attribution-q02", "text": "Who may assert, review, approve, correct or rely on creator, provider, publisher, steward, contact, jurisdiction and attribution, under which authority, purpose and limits?", "kind": "ownership", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "creator-provider-publisher-steward-contact-jurisdiction-and-attribution-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to creator, provider, publisher, steward, contact, jurisdiction and attribution, and which evidence supports them?", "kind": "quality", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "creator-provider-publisher-steward-contact-jurisdiction-and-attribution-data", "name": "Creator, provider, publisher, steward, contact, jurisdiction and attribution data", "description": "Typed data for creator, provider, publisher, steward, contact, jurisdiction and attribution with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "creator-provider-publisher-steward-contact-jurisdiction-and-attribution-record", "name": "Creator, provider, publisher, steward, contact, jurisdiction and attribution record", "description": "Immutable or successor-versioned registry evidence for creator, provider, publisher, steward, contact, jurisdiction and attribution.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for creator-provider-publisher-steward-contact-jurisdiction-and-attribution; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "model-artifact-technical-contract-and-compatibility", "name": "Model artifact, technical contract and compatibility", "description": "Groups governed registry context for model artifact, technical contract and compatibility.", "rationale": "The entry binds immutable artifacts and technical claims without becoming their master.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "layers": [ { "id": "artifact-release-packaging-and-integrity", "name": "Artifact release, packaging and integrity", "description": "Groups source-qualified registry context for artifact release, packaging and integrity.", "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "findings": [ { "id": "artifact-reference-version-format-distribution-digest-size-and-signature", "name": "Artifact reference, version, format, distribution, digest, size and signature", "description": "Records artifact reference, version, format, distribution, digest, size and signature as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "questions": [ { "id": "artifact-reference-version-format-distribution-digest-size-and-signature-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish artifact reference, version, format, distribution, digest, size and signature?", "kind": "evidence", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "artifact-reference-version-format-distribution-digest-size-and-signature-q02", "text": "Who may assert, review, approve, correct or rely on artifact reference, version, format, distribution, digest, size and signature, under which authority, purpose and limits?", "kind": "measurement", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "artifact-reference-version-format-distribution-digest-size-and-signature-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to artifact reference, version, format, distribution, digest, size and signature, and which evidence supports them?", "kind": "security", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "artifact-reference-version-format-distribution-digest-size-and-signature-data", "name": "Artifact reference, version, format, distribution, digest, size and signature data", "description": "Typed data for artifact reference, version, format, distribution, digest, size and signature with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "artifact-reference-version-format-distribution-digest-size-and-signature-record", "name": "Artifact reference, version, format, distribution, digest, size and signature record", "description": "Immutable or successor-versioned registry evidence for artifact reference, version, format, distribution, digest, size and signature.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for artifact-reference-version-format-distribution-digest-size-and-signature; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies", "name": "Architecture, base model, tokenizer, framework, runtime, hardware and dependencies", "description": "Records architecture, base model, tokenizer, framework, runtime, hardware and dependencies as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "questions": [ { "id": "architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish architecture, base model, tokenizer, framework, runtime, hardware and dependencies?", "kind": "composition", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies-q02", "text": "Who may assert, review, approve, correct or rely on architecture, base model, tokenizer, framework, runtime, hardware and dependencies, under which authority, purpose and limits?", "kind": "exception", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to architecture, base model, tokenizer, framework, runtime, hardware and dependencies, and which evidence supports them?", "kind": "retention", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies-data", "name": "Architecture, base model, tokenizer, framework, runtime, hardware and dependencies data", "description": "Typed data for architecture, base model, tokenizer, framework, runtime, hardware and dependencies with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies-record", "name": "Architecture, base model, tokenizer, framework, runtime, hardware and dependencies record", "description": "Immutable or successor-versioned registry evidence for architecture, base model, tokenizer, framework, runtime, hardware and dependencies.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "interface-capability-intended-use-and-limits", "name": "Interface, capability, intended use and limits", "description": "Groups source-qualified registry context for interface, capability, intended use and limits.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "findings": [ { "id": "task-input-output-signature-modality-capability-and-behavior-contract", "name": "Task, input, output, signature, modality, capability and behavior contract", "description": "Records task, input, output, signature, modality, capability and behavior contract as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "questions": [ { "id": "task-input-output-signature-modality-capability-and-behavior-contract-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish task, input, output, signature, modality, capability and behavior contract?", "kind": "requirement", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "task-input-output-signature-modality-capability-and-behavior-contract-q02", "text": "Who may assert, review, approve, correct or rely on task, input, output, signature, modality, capability and behavior contract, under which authority, purpose and limits?", "kind": "provenance", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "task-input-output-signature-modality-capability-and-behavior-contract-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to task, input, output, signature, modality, capability and behavior contract, and which evidence supports them?", "kind": "interoperability", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "task-input-output-signature-modality-capability-and-behavior-contract-data", "name": "Task, input, output, signature, modality, capability and behavior contract data", "description": "Typed data for task, input, output, signature, modality, capability and behavior contract with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "task-input-output-signature-modality-capability-and-behavior-contract-record", "name": "Task, input, output, signature, modality, capability and behavior contract record", "description": "Immutable or successor-versioned registry evidence for task, input, output, signature, modality, capability and behavior contract.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for task-input-output-signature-modality-capability-and-behavior-contract; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes", "name": "Intended, supported, out-of-scope and prohibited use, limitations and failure modes", "description": "Records intended, supported, out-of-scope and prohibited use, limitations and failure modes as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "questions": [ { "id": "intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish intended, supported, out-of-scope and prohibited use, limitations and failure modes?", "kind": "constraint", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes-q02", "text": "Who may assert, review, approve, correct or rely on intended, supported, out-of-scope and prohibited use, limitations and failure modes, under which authority, purpose and limits?", "kind": "process", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to intended, supported, out-of-scope and prohibited use, limitations and failure modes, and which evidence supports them?", "kind": "decision", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes-data", "name": "Intended, supported, out-of-scope and prohibited use, limitations and failure modes data", "description": "Typed data for intended, supported, out-of-scope and prohibited use, limitations and failure modes with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes-record", "name": "Intended, supported, out-of-scope and prohibited use, limitations and failure modes record", "description": "Immutable or successor-versioned registry evidence for intended, supported, out-of-scope and prohibited use, limitations and failure modes.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "development-lineage-rights-and-transparency", "name": "Development lineage, rights and transparency", "description": "Groups governed registry context for development lineage, rights and transparency.", "rationale": "Development evidence, rights and transparency documents remain source-qualified bindings.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ], "layers": [ { "id": "training-data-code-build-and-supply-chain-lineage", "name": "Training, data, code, build and supply-chain lineage", "description": "Groups source-qualified registry context for training, data, code, build and supply-chain lineage.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ], "findings": [ { "id": "training-run-dataset-code-configuration-build-builder-and-provenance", "name": "Training run, dataset, code, configuration, build, builder and provenance", "description": "Records training run, dataset, code, configuration, build, builder and provenance as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ], "questions": [ { "id": "training-run-dataset-code-configuration-build-builder-and-provenance-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish training run, dataset, code, configuration, build, builder and provenance?", "kind": "provenance", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "training-run-dataset-code-configuration-build-builder-and-provenance-q02", "text": "Who may assert, review, approve, correct or rely on training run, dataset, code, configuration, build, builder and provenance, under which authority, purpose and limits?", "kind": "validation", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "training-run-dataset-code-configuration-build-builder-and-provenance-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to training run, dataset, code, configuration, build, builder and provenance, and which evidence supports them?", "kind": "state", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "training-run-dataset-code-configuration-build-builder-and-provenance-data", "name": "Training run, dataset, code, configuration, build, builder and provenance data", "description": "Typed data for training run, dataset, code, configuration, build, builder and provenance with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] } ], "artifacts": [ { "id": "training-run-dataset-code-configuration-build-builder-and-provenance-record", "name": "Training run, dataset, code, configuration, build, builder and provenance record", "description": "Immutable or successor-versioned registry evidence for training run, dataset, code, configuration, build, builder and provenance.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for training-run-dataset-code-configuration-build-builder-and-provenance; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "developers-funders-contributors-tools-environment-and-source-documentation", "name": "Developers, funders, contributors, tools, environment and source documentation", "description": "Records developers, funders, contributors, tools, environment and source documentation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ], "questions": [ { "id": "developers-funders-contributors-tools-environment-and-source-documentation-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish developers, funders, contributors, tools, environment and source documentation?", "kind": "ownership", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "developers-funders-contributors-tools-environment-and-source-documentation-q02", "text": "Who may assert, review, approve, correct or rely on developers, funders, contributors, tools, environment and source documentation, under which authority, purpose and limits?", "kind": "privacy", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "developers-funders-contributors-tools-environment-and-source-documentation-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to developers, funders, contributors, tools, environment and source documentation, and which evidence supports them?", "kind": "identity", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "developers-funders-contributors-tools-environment-and-source-documentation-data", "name": "Developers, funders, contributors, tools, environment and source documentation data", "description": "Typed data for developers, funders, contributors, tools, environment and source documentation with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] } ], "artifacts": [ { "id": "developers-funders-contributors-tools-environment-and-source-documentation-record", "name": "Developers, funders, contributors, tools, environment and source documentation record", "description": "Immutable or successor-versioned registry evidence for developers, funders, contributors, tools, environment and source documentation.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for developers-funders-contributors-tools-environment-and-source-documentation; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] } ], "inline_only_rationale": null } ] }, { "id": "license-rights-distribution-and-transparency-documents", "name": "License, rights, distribution and transparency documents", "description": "Groups source-qualified registry context for license, rights, distribution and transparency documents.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "findings": [ { "id": "license-copyright-ownership-ip-data-rights-export-and-use-terms", "name": "License, copyright, ownership, intellectual property, data rights, export and use terms", "description": "Records license, copyright, ownership, intellectual property, data rights, export and use terms as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "questions": [ { "id": "license-copyright-ownership-ip-data-rights-export-and-use-terms-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish license, copyright, ownership, intellectual property, data rights, export and use terms?", "kind": "authority", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "license-copyright-ownership-ip-data-rights-export-and-use-terms-q02", "text": "Who may assert, review, approve, correct or rely on license, copyright, ownership, intellectual property, data rights, export and use terms, under which authority, purpose and limits?", "kind": "lifecycle", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "license-copyright-ownership-ip-data-rights-export-and-use-terms-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to license, copyright, ownership, intellectual property, data rights, export and use terms, and which evidence supports them?", "kind": "classification", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "license-copyright-ownership-ip-data-rights-export-and-use-terms-data", "name": "License, copyright, ownership, intellectual property, data rights, export and use terms data", "description": "Typed data for license, copyright, ownership, intellectual property, data rights, export and use terms with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "license-copyright-ownership-ip-data-rights-export-and-use-terms-record", "name": "License, copyright, ownership, intellectual property, data rights, export and use terms record", "description": "Immutable or successor-versioned registry evidence for license, copyright, ownership, intellectual property, data rights, export and use terms.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for license-copyright-ownership-ip-data-rights-export-and-use-terms; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "model-card-system-card-technical-documentation-disclosure-and-version", "name": "Model card, system card, technical documentation, disclosure and version", "description": "Records model card, system card, technical documentation, disclosure and version as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "questions": [ { "id": "model-card-system-card-technical-documentation-disclosure-and-version-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish model card, system card, technical documentation, disclosure and version?", "kind": "evidence", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "model-card-system-card-technical-documentation-disclosure-and-version-q02", "text": "Who may assert, review, approve, correct or rely on model card, system card, technical documentation, disclosure and version, under which authority, purpose and limits?", "kind": "quality", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "model-card-system-card-technical-documentation-disclosure-and-version-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to model card, system card, technical documentation, disclosure and version, and which evidence supports them?", "kind": "relationship", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "model-card-system-card-technical-documentation-disclosure-and-version-data", "name": "Model card, system card, technical documentation, disclosure and version data", "description": "Typed data for model card, system card, technical documentation, disclosure and version with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "model-card-system-card-technical-documentation-disclosure-and-version-record", "name": "Model card, system card, technical documentation, disclosure and version record", "description": "Immutable or successor-versioned registry evidence for model card, system card, technical documentation, disclosure and version.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for model-card-system-card-technical-documentation-disclosure-and-version; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "evaluation-risk-safety-security-and-approval", "name": "Evaluation, risk, safety, security and approval", "description": "Groups governed registry context for evaluation, risk, safety, security and approval.", "rationale": "Measured evidence, risk assessment and accountable approval are distinct assertions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "layers": [ { "id": "evaluation-benchmark-quality-and-comparability", "name": "Evaluation, benchmark, quality and comparability", "description": "Groups source-qualified registry context for evaluation, benchmark, quality and comparability.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "findings": [ { "id": "evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result", "name": "Evaluation dataset, task, metric, threshold, subgroup, robustness and result", "description": "Records evaluation dataset, task, metric, threshold, subgroup, robustness and result as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "questions": [ { "id": "evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish evaluation dataset, task, metric, threshold, subgroup, robustness and result?", "kind": "measurement", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result-q02", "text": "Who may assert, review, approve, correct or rely on evaluation dataset, task, metric, threshold, subgroup, robustness and result, under which authority, purpose and limits?", "kind": "security", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to evaluation dataset, task, metric, threshold, subgroup, robustness and result, and which evidence supports them?", "kind": "authority", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result-data", "name": "Evaluation dataset, task, metric, threshold, subgroup, robustness and result data", "description": "Typed data for evaluation dataset, task, metric, threshold, subgroup, robustness and result with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result-record", "name": "Evaluation dataset, task, metric, threshold, subgroup, robustness and result record", "description": "Immutable or successor-versioned registry evidence for evaluation dataset, task, metric, threshold, subgroup, robustness and result.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "evidence-source-method-version-freshness-uncertainty-comparator-and-limit", "name": "Evidence source, method, version, freshness, uncertainty, comparator and limit", "description": "Records evidence source, method, version, freshness, uncertainty, comparator and limit as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "questions": [ { "id": "evidence-source-method-version-freshness-uncertainty-comparator-and-limit-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish evidence source, method, version, freshness, uncertainty, comparator and limit?", "kind": "quality", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "evidence-source-method-version-freshness-uncertainty-comparator-and-limit-q02", "text": "Who may assert, review, approve, correct or rely on evidence source, method, version, freshness, uncertainty, comparator and limit, under which authority, purpose and limits?", "kind": "retention", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "evidence-source-method-version-freshness-uncertainty-comparator-and-limit-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to evidence source, method, version, freshness, uncertainty, comparator and limit, and which evidence supports them?", "kind": "requirement", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "evidence-source-method-version-freshness-uncertainty-comparator-and-limit-data", "name": "Evidence source, method, version, freshness, uncertainty, comparator and limit data", "description": "Typed data for evidence source, method, version, freshness, uncertainty, comparator and limit with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "evidence-source-method-version-freshness-uncertainty-comparator-and-limit-record", "name": "Evidence source, method, version, freshness, uncertainty, comparator and limit record", "description": "Immutable or successor-versioned registry evidence for evidence source, method, version, freshness, uncertainty, comparator and limit.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for evidence-source-method-version-freshness-uncertainty-comparator-and-limit; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null } ] }, { "id": "risk-control-review-and-accountable-decision", "name": "Risk, control, review and accountable decision", "description": "Groups source-qualified registry context for risk, control, review and accountable decision.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010" ], "findings": [ { "id": "risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference", "name": "Risk, privacy, security, safety, bias, misuse, red-team and incident reference", "description": "Records risk, privacy, security, safety, bias, misuse, red-team and incident reference as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010" ], "questions": [ { "id": "risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish risk, privacy, security, safety, bias, misuse, red-team and incident reference?", "kind": "security", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference-q02", "text": "Who may assert, review, approve, correct or rely on risk, privacy, security, safety, bias, misuse, red-team and incident reference, under which authority, purpose and limits?", "kind": "interoperability", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to risk, privacy, security, safety, bias, misuse, red-team and incident reference, and which evidence supports them?", "kind": "constraint", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference-data", "name": "Risk, privacy, security, safety, bias, misuse, red-team and incident reference data", "description": "Typed data for risk, privacy, security, safety, bias, misuse, red-team and incident reference with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010" ] } ], "artifacts": [ { "id": "risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference-record", "name": "Risk, privacy, security, safety, bias, misuse, red-team and incident reference record", "description": "Immutable or successor-versioned registry evidence for risk, privacy, security, safety, bias, misuse, red-team and incident reference.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "reviewer-approval-rejection-exception-human-oversight-and-decision-evidence", "name": "Reviewer, approval, rejection, exception, human oversight and decision evidence", "description": "Records reviewer, approval, rejection, exception, human oversight and decision evidence as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010" ], "questions": [ { "id": "reviewer-approval-rejection-exception-human-oversight-and-decision-evidence-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish reviewer, approval, rejection, exception, human oversight and decision evidence?", "kind": "decision", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "reviewer-approval-rejection-exception-human-oversight-and-decision-evidence-q02", "text": "Who may assert, review, approve, correct or rely on reviewer, approval, rejection, exception, human oversight and decision evidence, under which authority, purpose and limits?", "kind": "decision", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "reviewer-approval-rejection-exception-human-oversight-and-decision-evidence-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to reviewer, approval, rejection, exception, human oversight and decision evidence, and which evidence supports them?", "kind": "event", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "reviewer-approval-rejection-exception-human-oversight-and-decision-evidence-data", "name": "Reviewer, approval, rejection, exception, human oversight and decision evidence data", "description": "Typed data for reviewer, approval, rejection, exception, human oversight and decision evidence with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010" ] } ], "artifacts": [ { "id": "reviewer-approval-rejection-exception-human-oversight-and-decision-evidence-record", "name": "Reviewer, approval, rejection, exception, human oversight and decision evidence record", "description": "Immutable or successor-versioned registry evidence for reviewer, approval, rejection, exception, human oversight and decision evidence.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for reviewer-approval-rejection-exception-human-oversight-and-decision-evidence; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "lifecycle-promotion-publication-and-deployment-bindings", "name": "Lifecycle, promotion, publication and deployment bindings", "description": "Groups governed registry context for lifecycle, promotion, publication and deployment bindings.", "rationale": "Registry lifecycle must not collapse publication, deployability and observed deployment into one status.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-014" ], "layers": [ { "id": "entry-state-events-correction-and-supersession", "name": "Entry state events, correction and supersession", "description": "Groups source-qualified registry context for entry state events, correction and supersession.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ], "findings": [ { "id": "candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked", "name": "Candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked", "description": "Records candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ], "questions": [ { "id": "candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked?", "kind": "lifecycle", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked-q02", "text": "Who may assert, review, approve, correct or rely on candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked, under which authority, purpose and limits?", "kind": "state", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked, and which evidence supports them?", "kind": "temporal", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked-data", "name": "Candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked data", "description": "Typed data for candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked-record", "name": "Candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked record", "description": "Immutable or successor-versioned registry evidence for candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "transition-event-reason-authority-time-correction-merge-split-and-supersession", "name": "Transition event, reason, authority, time, correction, merge, split and supersession", "description": "Records transition event, reason, authority, time, correction, merge, split and supersession as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ], "questions": [ { "id": "transition-event-reason-authority-time-correction-merge-split-and-supersession-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish transition event, reason, authority, time, correction, merge, split and supersession?", "kind": "event", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "transition-event-reason-authority-time-correction-merge-split-and-supersession-q02", "text": "Who may assert, review, approve, correct or rely on transition event, reason, authority, time, correction, merge, split and supersession, under which authority, purpose and limits?", "kind": "identity", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "transition-event-reason-authority-time-correction-merge-split-and-supersession-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to transition event, reason, authority, time, correction, merge, split and supersession, and which evidence supports them?", "kind": "composition", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "transition-event-reason-authority-time-correction-merge-split-and-supersession-data", "name": "Transition event, reason, authority, time, correction, merge, split and supersession data", "description": "Typed data for transition event, reason, authority, time, correction, merge, split and supersession with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "transition-event-reason-authority-time-correction-merge-split-and-supersession-record", "name": "Transition event, reason, authority, time, correction, merge, split and supersession record", "description": "Immutable or successor-versioned registry evidence for transition event, reason, authority, time, correction, merge, split and supersession.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for transition-event-reason-authority-time-correction-merge-split-and-supersession; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "promotion-alias-release-and-deployment-observation", "name": "Promotion, alias, release and deployment observation", "description": "Groups source-qualified registry context for promotion, alias, release and deployment observation.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-014" ], "findings": [ { "id": "promotion-gate-release-decision-alias-champion-channel-and-rollout-intent", "name": "Promotion gate, release decision, alias, champion, channel and rollout intent", "description": "Records promotion gate, release decision, alias, champion, channel and rollout intent as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-014" ], "questions": [ { "id": "promotion-gate-release-decision-alias-champion-channel-and-rollout-intent-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish promotion gate, release decision, alias, champion, channel and rollout intent?", "kind": "authority", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "promotion-gate-release-decision-alias-champion-channel-and-rollout-intent-q02", "text": "Who may assert, review, approve, correct or rely on promotion gate, release decision, alias, champion, channel and rollout intent, under which authority, purpose and limits?", "kind": "classification", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "promotion-gate-release-decision-alias-champion-channel-and-rollout-intent-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to promotion gate, release decision, alias, champion, channel and rollout intent, and which evidence supports them?", "kind": "evidence", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "promotion-gate-release-decision-alias-champion-channel-and-rollout-intent-data", "name": "Promotion gate, release decision, alias, champion, channel and rollout intent data", "description": "Typed data for promotion gate, release decision, alias, champion, channel and rollout intent with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-014" ] } ], "artifacts": [ { "id": "promotion-gate-release-decision-alias-champion-channel-and-rollout-intent-record", "name": "Promotion gate, release decision, alias, champion, channel and rollout intent record", "description": "Immutable or successor-versioned registry evidence for promotion gate, release decision, alias, champion, channel and rollout intent.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for promotion-gate-release-decision-alias-champion-channel-and-rollout-intent; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "deployable-deployed-active-environment-endpoint-compatibility-and-observation", "name": "Deployable, deployed, active, environment, endpoint, compatibility and observation", "description": "Records deployable, deployed, active, environment, endpoint, compatibility and observation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-014" ], "questions": [ { "id": "deployable-deployed-active-environment-endpoint-compatibility-and-observation-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish deployable, deployed, active, environment, endpoint, compatibility and observation?", "kind": "state", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "deployable-deployed-active-environment-endpoint-compatibility-and-observation-q02", "text": "Who may assert, review, approve, correct or rely on deployable, deployed, active, environment, endpoint, compatibility and observation, under which authority, purpose and limits?", "kind": "relationship", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "deployable-deployed-active-environment-endpoint-compatibility-and-observation-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to deployable, deployed, active, environment, endpoint, compatibility and observation, and which evidence supports them?", "kind": "ownership", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "deployable-deployed-active-environment-endpoint-compatibility-and-observation-data", "name": "Deployable, deployed, active, environment, endpoint, compatibility and observation data", "description": "Typed data for deployable, deployed, active, environment, endpoint, compatibility and observation with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-014" ] } ], "artifacts": [ { "id": "deployable-deployed-active-environment-endpoint-compatibility-and-observation-record", "name": "Deployable, deployed, active, environment, endpoint, compatibility and observation record", "description": "Immutable or successor-versioned registry evidence for deployable, deployed, active, environment, endpoint, compatibility and observation.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for deployable-deployed-active-environment-endpoint-compatibility-and-observation; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "distribution-access-retention-audit-and-projections", "name": "Distribution, access, retention, audit and projections", "description": "Groups governed registry context for distribution, access, retention, audit and projections.", "rationale": "Discovery and distribution require purpose-filtered views, auditability and version-pinned mappings.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "layers": [ { "id": "availability-distribution-access-and-use-signals", "name": "Availability, distribution, access and use signals", "description": "Groups source-qualified registry context for availability, distribution, access and use signals.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-014", "SRC-015" ], "findings": [ { "id": "landing-page-api-package-oci-location-mirror-availability-and-access-tier", "name": "Landing page, API, package, OCI location, mirror, availability and access tier", "description": "Records landing page, api, package, oci location, mirror, availability and access tier as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-014", "SRC-015" ], "questions": [ { "id": "landing-page-api-package-oci-location-mirror-availability-and-access-tier-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish landing page, api, package, oci location, mirror, availability and access tier?", "kind": "access", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "landing-page-api-package-oci-location-mirror-availability-and-access-tier-q02", "text": "Who may assert, review, approve, correct or rely on landing page, api, package, oci location, mirror, availability and access tier, under which authority, purpose and limits?", "kind": "authority", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "landing-page-api-package-oci-location-mirror-availability-and-access-tier-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to landing page, api, package, oci location, mirror, availability and access tier, and which evidence supports them?", "kind": "measurement", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "landing-page-api-package-oci-location-mirror-availability-and-access-tier-data", "name": "Landing page, API, package, OCI location, mirror, availability and access tier data", "description": "Typed data for landing page, api, package, oci location, mirror, availability and access tier with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "landing-page-api-package-oci-location-mirror-availability-and-access-tier-record", "name": "Landing page, API, package, OCI location, mirror, availability and access tier record", "description": "Immutable or successor-versioned registry evidence for landing page, api, package, oci location, mirror, availability and access tier.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for landing-page-api-package-oci-location-mirror-availability-and-access-tier; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "weight-availability-download-use-adoption-popularity-staleness-and-observation", "name": "Weight availability, download, use, adoption, popularity, staleness and observation", "description": "Records weight availability, download, use, adoption, popularity, staleness and observation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-014", "SRC-015" ], "questions": [ { "id": "weight-availability-download-use-adoption-popularity-staleness-and-observation-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish weight availability, download, use, adoption, popularity, staleness and observation?", "kind": "measurement", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "weight-availability-download-use-adoption-popularity-staleness-and-observation-q02", "text": "Who may assert, review, approve, correct or rely on weight availability, download, use, adoption, popularity, staleness and observation, under which authority, purpose and limits?", "kind": "requirement", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "weight-availability-download-use-adoption-popularity-staleness-and-observation-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to weight availability, download, use, adoption, popularity, staleness and observation, and which evidence supports them?", "kind": "exception", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "weight-availability-download-use-adoption-popularity-staleness-and-observation-data", "name": "Weight availability, download, use, adoption, popularity, staleness and observation data", "description": "Typed data for weight availability, download, use, adoption, popularity, staleness and observation with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "weight-availability-download-use-adoption-popularity-staleness-and-observation-record", "name": "Weight availability, download, use, adoption, popularity, staleness and observation record", "description": "Immutable or successor-versioned registry evidence for weight availability, download, use, adoption, popularity, staleness and observation.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for weight-availability-download-use-adoption-popularity-staleness-and-observation; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "governance-records-audit-and-interoperability", "name": "Governance, records, audit and interoperability", "description": "Groups source-qualified registry context for governance, records, audit and interoperability.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "findings": [ { "id": "role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof", "name": "Role, purpose, access, disclosure, audit, retention, hold, tombstone and proof", "description": "Records role, purpose, access, disclosure, audit, retention, hold, tombstone and proof as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "questions": [ { "id": "role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish role, purpose, access, disclosure, audit, retention, hold, tombstone and proof?", "kind": "retention", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof-q02", "text": "Who may assert, review, approve, correct or rely on role, purpose, access, disclosure, audit, retention, hold, tombstone and proof, under which authority, purpose and limits?", "kind": "constraint", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to role, purpose, access, disclosure, audit, retention, hold, tombstone and proof, and which evidence supports them?", "kind": "provenance", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof-data", "name": "Role, purpose, access, disclosure, audit, retention, hold, tombstone and proof data", "description": "Typed data for role, purpose, access, disclosure, audit, retention, hold, tombstone and proof with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "artifacts": [ { "id": "role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof-record", "name": "Role, purpose, access, disclosure, audit, retention, hold, tombstone and proof record", "description": "Immutable or successor-versioned registry evidence for role, purpose, access, disclosure, audit, retention, hold, tombstone and proof.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection", "name": "DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, PROV and OpenLineage projection", "description": "Records dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "questions": [ { "id": "dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection-q01", "text": "What stable identity, registry scope, version-qualified values and explicit unknowns establish dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection?", "kind": "interoperability", "answer_data": [ "entry, registry and model identifiers", "version-qualified values and classifications", "unknown and not-applicable states" ] }, { "id": "dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection-q02", "text": "Who may assert, review, approve, correct or rely on dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection, under which authority, purpose and limits?", "kind": "event", "answer_data": [ "creator, provider, publisher, steward and reviewer roles", "authority, policy, purpose and limits", "exception, contest and escalation path" ] }, { "id": "dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection-q03", "text": "Which event, effective, observed, recorded, ingested and knowledge times apply to dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection, and which evidence supports them?", "kind": "process", "answer_data": [ "distinct lifecycle and knowledge times", "evidence, provenance and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection-data", "name": "DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, PROV and OpenLineage projection data", "description": "Typed data for dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection with entry scope, source, authority, state, time, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "artifacts": [ { "id": "dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection-record", "name": "DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, PROV and OpenLineage projection record", "description": "Immutable or successor-versioned registry evidence for dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection.", "media_or_form": [ "logical AI model registry assertion", "identity, metadata, artifact, lineage, evaluation, approval, lifecycle, distribution or projection record" ], "serial": true, "identity_strategy": "Registry-entry ID plus independent assertion, decision, event or artifact ID for dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection; model name, alias, version label, timestamp, URL and digest never identify a registry assertion alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-model-entry", "name": "Register an AI model entry", "description": "Governed operation to register an ai model entry without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "owning registry", "model family or artifact reference", "owner and authority" ], "outputs": [ "stable registry entry" ], "preconditions": [ "namespace, scope, source, stewardship and duplicate checks pass" ], "effects": [ "a new entry head is created without copying or mutating the model artifact" ], "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "bind-family-version-and-artifacts", "name": "Bind family, version and artifacts", "description": "Governed operation to bind family, version and artifacts without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry", "model family", "model version", "artifact references" ], "outputs": [ "version-qualified model bindings" ], "preconditions": [ "identifiers, digests, formats, provenance and compatibility pass" ], "effects": [ "external artifacts remain independently identifiable and immutable" ], "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014" ] }, { "id": "describe-contract-use-and-limitations", "name": "Describe contract, use and limitations", "description": "Governed operation to describe contract, use and limitations without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry", "task", "input and output contract", "use assertions" ], "outputs": [ "discoverable capability and limitation profile" ], "preconditions": [ "source, author, scope, version and evidence pass" ], "effects": [ "supported and prohibited use remain explicit claims rather than inferred permissions" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-010" ] }, { "id": "attach-lineage-rights-and-transparency", "name": "Attach lineage, rights and transparency", "description": "Governed operation to attach lineage, rights and transparency without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry", "training and build references", "rights", "documentation" ], "outputs": [ "source-qualified lineage and disclosure bindings" ], "preconditions": [ "versions, issuers, legal scope, provenance and access pass" ], "effects": [ "the entry links evidence without replacing source masters or granting rights" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ] }, { "id": "attach-evaluation-risk-and-safety", "name": "Attach evaluation, risk and safety evidence", "description": "Governed operation to attach evaluation, risk and safety evidence without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry", "evaluation results", "risk and control references" ], "outputs": [ "bounded evidence profile" ], "preconditions": [ "method, dataset, metric, comparator, uncertainty, freshness and reviewer pass" ], "effects": [ "evidence is recorded without implying approval, publication or deployment" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-010" ] }, { "id": "review-approve-reject-or-except", "name": "Review, approve, reject or except", "description": "Governed operation to review, approve, reject or except without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry", "review packet", "accountable decision" ], "outputs": [ "immutable decision assertion" ], "preconditions": [ "decision authority, criteria, conflicts, conditions and evidence pass" ], "effects": [ "the registry records the decision and conditions without autonomously making a high-impact approval" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "publish-deprecate-withdraw-revoke-or-supersede", "name": "Publish, deprecate, withdraw, revoke or supersede", "description": "Governed operation to publish, deprecate, withdraw, revoke or supersede without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry", "authorized transition", "reason and successor" ], "outputs": [ "successor lifecycle state" ], "preconditions": [ "prior state, authority, effective time, notifications and retention pass" ], "effects": [ "discoverability changes without deleting artifact, evidence or prior history" ], "source_refs": [ "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-009" ] }, { "id": "bind-deployment-observations", "name": "Bind deployment observations", "description": "Governed operation to bind deployment observations without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry", "environment and deployment references", "observation" ], "outputs": [ "source-qualified deployment view" ], "preconditions": [ "deployment authority, source, environment, time and freshness pass" ], "effects": [ "deployed or active status remains external observation, not registry ownership" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008" ] }, { "id": "correct-merge-split-and-resolve-identity", "name": "Correct, merge, split and resolve identity", "description": "Governed operation to correct, merge, split and resolve identity without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry heads", "evidence", "authorized correction plan" ], "outputs": [ "successor entries and equivalence decisions" ], "preconditions": [ "expected revisions, affected assertions, redirects and audit pass" ], "effects": [ "prior assertions remain reconstructable and ambiguous equivalence stays contested" ], "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "query-project-disclose-retain-and-audit", "name": "Query, project, disclose, retain and audit", "description": "Governed operation to query, project, disclose, retain and audit without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.", "inputs": [ "entry", "query or target profile", "access and records policy" ], "outputs": [ "filtered result, projection, disclosure, tombstone or audit event" ], "preconditions": [ "purpose, access, mapping version, loss, hold and idempotency pass" ], "effects": [ "registry context remains purpose-filtered, reconstructable and explicit about current head and loss" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "composition": [ { "target": "WM-SFT-004 ML Model Artifact", "relation": "REFERENCE", "purpose": "Represent the unfrozen parent boundary as a non-owning artifact and version binding without composition, mutation, release or cascade authority.", "required": true, "source_refs": [ "SRC-003", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014" ] }, { "target": "WM-AI-006 Model Training / Fine-tuning Run and AI Model Evaluation", "relation": "REFERENCE", "purpose": "Resolve authoritative development lineage and evaluation evidence without absorbing execution or measurement masters.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-016" ] }, { "target": "Deployment, endpoint, dataset, code, build, policy, credential, provenance, audit and records models", "relation": "REFERENCE", "purpose": "Resolve authoritative lifecycle, control and evidence records without absorbing their ownership.", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006" ] }, { "target": "DCAT 3, MLflow, Hugging Face, SPDX 3.0.1 AI, CycloneDX 1.7, OCI 1.1.1, SLSA 1.1, Sigstore, PROV-O and OpenLineage 1.53.0", "relation": "ALIGN", "purpose": "Project release-pinned catalog, registry, card, BOM, distribution, provenance, verification and lineage views with information-loss declarations.", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension owner, registry mandate and accountable AI owner", "Authoritative model artifact, training, dataset, code, build, evaluation, deployment, endpoint, policy, credential, provenance, audit and records registries", "Approved model class, task, jurisdiction, data-rights, licensing, export, privacy, security, safety, quality, release, retention and interoperability profiles", "Role, delegation, approval, publication, revocation, incident, disclosure and agent-operation policies" ], "namespace_guidance": "Mint registry, entry, family-binding, version-binding, alias, metadata, artifact-binding, evidence, review, decision, transition, correction, disclosure and projection IDs; preserve external model and evidence identifiers.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize one registry entry by authoritative registry identifier and namespace; never by display name, alias, version label, digest, URL, task or lifecycle status alone.", "Keep registry, entry, model family, model version, artifact, training run, evaluation, decision, deployment, endpoint and documentation independently identifiable." ], "patch_rules": [ "Extensions declare model class, task, modality, jurisdiction, rights, privacy, security, safety, quality, release and interoperability effects.", "Released artifact, evidence, approval and lifecycle assertions are immutable; corrections create linked successors.", "Never silently change model binding, digest, intended use, limitation, license, approval, publication, revocation, access, retention or provenance." ], "compatibility_rules": [ "Ignore additive fields only when entry identity, model and artifact bindings, source, authority, state, time, rights, access and provenance survive.", "Every projection pins standard, implementation, schema, vocabulary, profile and mapping versions and declares information loss." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier for each registry entry, assertion, decision, event or projection, qualified by issuer, namespace and record kind.", "Governed globally resolvable registry-entry IRI.", "Dimension UUID or ULID when neither preceding identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; distinguish created, registered, reviewed, approved, published, deprecated, withdrawn, revoked, observed, recorded, ingested and knowledge times whenever they differ.", "serial_naming_rule": "Use {entry-id}--{assertion-decision-event-or-artifact-id}--{artifact-kind}--{revision-id}.", "integrity_rule": "Store digest, media type, record kind, registry and model scope, artifact and evidence versions, actor, event and knowledge times, access marking and provenance." }, "policies": [ "The entry does not own Model Artifact, Training Run, Dataset, Source Code, Build, Evaluation, Deployment, Endpoint, Model Card, Policy, Credential, Provenance, Access Audit or Records masters.", "Registered, reviewed, approved, published, deployable, deployed, active, deprecated, withdrawn and revoked are independent authority-qualified assertions.", "A digest or valid signature supports byte identity or signer evidence but does not prove safety, quality, ownership, authorization or fitness for use.", "Agents cannot approve, publish, sign, revoke, widen access, disclose restricted material, deploy or destroy records outside explicit delegated authority." ], "crud": { "read": [ "Resolve purpose, current head, family and version scope, artifact, contract, lineage, rights, evaluations, risk, approvals, lifecycle, deployment observations, access, retention and projection loss under the permitted view." ], "create": [ "Bind stable entry identity, owning registry, model family or artifact reference, owner, source, authority, initial state and registration time before catalog metadata." ], "update": [ "Append successor metadata, artifact, evidence, decision, lifecycle, deployment-observation, correction and disclosure assertions with reason, authority, expected revision, event time and knowledge time." ], "delete": [ "Apply rights, privacy, security, legal-hold and adopting-Dimension records policy; retire or tombstone only the registry entry without cascading to model, evidence or deployment masters, and let authoritative systems execute physical disposition." ] }, "roles": [ { "name": "AI system owner and accountable deployer", "responsibilities": [ "Own purpose, risk acceptance, release boundaries and accountable use of registered models." ] }, { "name": "Model provider or developer", "responsibilities": [ "Supply version-qualified artifacts, technical contract, lineage, rights, use and limitation claims." ] }, { "name": "Registry owner and steward", "responsibilities": [ "Own entry identity, duplicate resolution, metadata quality, lifecycle history, discoverability and projection integrity." ] }, { "name": "Independent evaluator, safety and security reviewer", "responsibilities": [ "Review evaluation, abuse, privacy, security, safety and red-team evidence without becoming the artifact owner." ] }, { "name": "Release and approval authority", "responsibilities": [ "Make attributable approval, exception, publication, withdrawal and revocation decisions within mandate." ] }, { "name": "Deployment and platform operator", "responsibilities": [ "Provide source-qualified environment, deployment, endpoint, compatibility and observed-state references." ] }, { "name": "Legal, privacy and records steward", "responsibilities": [ "Own license, data-rights, IP, export, disclosure, correction, hold, retention and disposition profiles." ] } ], "access": { "default_rule": "Deny restricted weights, training data, source code, personal data, secrets, security findings, unpublished evaluations and confidential approvals unless a purpose-bound policy permits the minimum necessary view.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Declared incident response, audit, legal, subject-rights, security, safety or emergency access must cite authority, scope, purpose and time limit where applicable and must be logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, registry and entry scope, operation, authority, policy, RFC 3339 time, affected fields, source revision and outcome without unnecessary secret or restricted-artifact duplication." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension AI, registry, release, data-rights, privacy, security, safety, access, retention and agent policies.", "Read this entry and linked model artifact, training, dataset, code, evaluation, deployment, endpoint, provenance and records models before mutation." ] } }, "coverage": { "claim": "WM-AI-007 covers one governed AI model registry entry from registration and model binding through discoverable technical metadata, lineage, rights, evaluations, risk, approvals, lifecycle, deployment observations, access, correction, retention and projection. Model class, task, jurisdiction, rights, provider-specific lifecycle, release-pinned mappings and independent external review remain deferred.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identity is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "classification and direct properties", "status": "covered", "notes": "Classification and direct properties is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Recognition and observation is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Capabilities and possible actions is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "composition", "status": "covered", "notes": "Composition is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "lifecycle", "status": "covered", "notes": "Lifecycle is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "relationships", "status": "covered", "notes": "Relationships is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "temporal", "status": "covered", "notes": "Temporal is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "spatial", "status": "covered", "notes": "Spatial is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "provenance", "status": "covered", "notes": "Provenance is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Ownership and stewardship is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "validation and quality", "status": "covered", "notes": "Validation and quality is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "access and privacy", "status": "covered", "notes": "Access and privacy is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention and deletion is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "interoperability", "status": "covered", "notes": "Interoperability is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." }, { "dimension": "authority and ethics", "status": "covered", "notes": "Authority and ethics is explicit; model class, task, jurisdiction, rights, release-pinned mappings, provider-specific lifecycle and independent review remain held where applicable." } ], "known_omissions": [ "Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.", "The unified row parent_ids WM-SFT-004 has no frozen relation-ledger edge and grants no composition, ownership, mutation, release or cascade authority.", "Model registries differ on family, version, alias, environment, approval, deletion and access semantics and require explicit profiles.", "NIST AI RMF 1.0 is under revision; this result pins the inspected 1.0 publication and does not predict the revision." ], "conflicts": [ "Registry entry, model family, version, immutable artifact, model card, evaluation, deployment and endpoint are not interchangeable identities.", "Registered, approved, published, deployable, deployed, active, deprecated, withdrawn and revoked are not one universal lifecycle axis.", "Digest, signature, provenance, license, approval, quality, safety and fitness-for-use establish different claims." ], "regional_assumptions": [ "Technical documentation, data rights, privacy, intellectual property, export, security, safety, disclosure, retention and high-risk AI obligations depend on jurisdiction, industry and use case.", "The EU AI Act and GDPR are European Union profiles; NIST publications are voluntary United States public-authority guidance unless adopted by policy or contract.", "DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage are versioned profiles, not universal lossless schemas." ], "adversarial_checks": [ "Reject an entry without stable registry identity, owning registry, model binding, owner, source, authority, lifecycle state, registration time and current head.", "Reject artifact identity based only on name, alias, URL or version label; require authoritative reference and digest where bytes are distributed.", "Reject safety, quality, ownership, authenticity or fitness claims inferred only from registration, popularity, digest, signature or deployment.", "Reject autonomous approval, publication, signature, revocation, access expansion, disclosure, deployment or destructive cleanup without delegated authority.", "Reject projection or import that collapses family, version, artifact, approval, publication and deployment states or hides information loss." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "registry", "status": "accepted", "rationale": "The root is a registry record with registration provenance, catalog metadata, lifecycle and governed bindings to external model resources. Registry is more accurate than model artifact, document, event or deployment. The frozen record_plane world-model and catalogue entry_kind standalone-mm are separate axes." }, "decisions": [ { "concept": "Registry entry versus model artifact", "disposition": "accepted", "rationale": "The entry owns registration identity, metadata and lifecycle assertions. Model family, version and artifact bytes remain external masters." }, { "concept": "Unified parent signal WM-SFT-004", "disposition": "accepted-as-unapproved-reference", "rationale": "The unified row has parent_ids WM-SFT-004 but the frozen relation ledger has no edge. The current result permits only a non-owning reference and grants no composition, mutation, release or cascade authority." }, { "concept": "Family, version, artifact and alias identity", "disposition": "accepted", "rationale": "Family, version, immutable artifact, digest, registry entry and mutable alias remain independently identifiable; aliases cannot replace canonical identity." }, { "concept": "Model card and technical documentation", "disposition": "accepted-external", "rationale": "Cards and disclosures are versioned source artifacts or projections. The registry binds them and selected summaries without claiming universal equivalence." }, { "concept": "Approval, publication and deployment", "disposition": "accepted", "rationale": "Registered, reviewed, approved, published, deployable, deployed and active are separate authority-qualified assertions and times." }, { "concept": "Digest and signature", "disposition": "accepted-with-bounded-claim", "rationale": "A digest supports byte identity and a successful signature verification supports signer evidence under a policy. Neither proves quality, safety, ownership, authorization or fitness." }, { "concept": "Popularity and adoption signals", "disposition": "accepted-as-observation", "rationale": "Downloads, use, adoption and popularity require method, interval, source and freshness and cannot substitute for evaluation or approval." }, { "concept": "Rights, privacy, security and jurisdiction", "disposition": "accepted-with-mandatory-hold", "rationale": "Weights, data, code, IP, license, export, privacy, security, disclosure, revocation and retention remain purpose-bound adopting-Dimension policies." }, { "concept": "Machine-readable projections", "disposition": "accepted-with-validation-hold", "rationale": "DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage cover different scopes. Every mapping must pin release, profile and information loss." }, { "concept": "Single-provider waiver and no-tools audit", "disposition": "accepted-with-mandatory-hold", "rationale": "One Claude Sonnet and one Grok 4.6 research attempt each timed out after 120 seconds. Codex separately audited the frozen validated result and comparison locally without tools or new research facts. Confidence remains medium and assurance remains reviewable-draft." } ], "publicationHolds": [ "Absence-of-external-review hold: one Claude Sonnet and one Grok 4.6 research attempt for WM-AI-007 each timed out after 120 seconds. No external research result was admitted.", "Relation hold: unified parent_ids WM-SFT-004 has no frozen relation-ledger edge and grants no composition, ownership, mutation, release or cascade behavior.", "Registry-profile hold: family, version, alias, environment, approval, deletion and access semantics differ by registry and require explicit profiles.", "Rights and jurisdiction hold: model and data rights, license, IP, export, privacy, security, safety, disclosure, revocation and retention require adopting-Dimension policies.", "Approval and deployment hold: registration, review, publication, deployability, deployment and active operation remain distinct and need accountable authorities.", "Interoperability hold: all DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage projections require release-pinned mappings and loss validation.", "Source-version hold: NIST AI RMF 1.0 is under revision; this specification pins the inspected 1.0 publication.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Approve or reject the WM-SFT-004 parent boundary and register training, evaluation, deployment, endpoint, dataset, code, policy, credential, provenance and records relations.", "Create registry profiles for model family and version semantics, aliasing, environments, approvals, publication, deprecation, withdrawal, revocation, deletion and access.", "Validate jurisdiction and organization-specific model and data rights, IP, license, export, privacy, security, safety, disclosure, retention and accountable-release policies.", "Test release-pinned DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage mappings with conformance, round-trip and information-loss evidence.", "Refresh the NIST AI RMF mapping after a new normative revision and obtain supplemental independent external review before canonical promotion." ] }, "statistics": { "sources": 17, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }