# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T20:24:35Z", "synthesisSha256": "f7459dfe5bd33a5f0830fc9cb402e5f6f844b810c2fc9f6df2f6bfde35ee6b40", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-DAT-012", "registryId": "vr.wm-dat-012", "name": "Synthetic Data Product", "version": "0.1.0", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.DAT.SYN" ], "tags": [ "synthetic", "data", "product", "inf.dat.syn" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-dat-012-synthetic-data-product/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-dat-012", "model": { "registry_id": "vr.wm-dat-012", "model_id": "WM-DAT-012", "name": "Synthetic Data Product", "entry_kind": "entity", "purpose": "Describe a governed generated-data product through release-specific lineage, fitness evidence, privacy claims and distribution conditions.", "scope_statement": "One persistent synthetic data product identity with individually identified release versions and evidence revisions. The product record indexes generated content and its claims; source datasets, generator assets, pipeline runs, evaluation execution and distribution services remain external masters. This proposed model supports incomplete or rejected release candidates without implying permission to share them.", "in_scope": [ "Product identity and synthetic classification with explicit generated, retained-real or mixed component boundaries", "Release-pinned generation basis, intended use, schema constraints, utility and privacy evidence references", "Local claim status, release decision references, distribution bindings and withdrawal or reassessment notices" ], "out_of_scope": [ "Running generators, training models, executing attacks or computing quality and privacy assessments", "Owning source data, generic data catalog operations, schema definitions, lineage graphs or evaluator lifecycles", "Automatic anonymisation certification, legal conclusions, universal utility thresholds, real-world observations inferred from generated records", "Operational generation or use of dangerous-subject data; any such domain extension remains policy-level and separately reviewed" ], "boundary_notes": [ { "neighbor": "WM-DAT-008 Data Product / Product Catalog Record", "distinction": "Registry parent is candidate semantic specialization. Bind its product master identity and generic terms; local content supplies synthetic-specific claims and evidence. Executable inheritance is not ratified.", "source_refs": [ "SRC-001", "SRC-006" ] }, { "neighbor": "WM-DAT-001 Dataset and WM-DAT-004 Data Schema / Data Contract", "distinction": "Content snapshots and schemas are version-pinned references. A product is not each byte file, source dataset or schema; distributions and format conversions do not automatically create a new product.", "source_refs": [ "SRC-001" ] }, { "neighbor": "WM-DAT-005 Data Pipeline and WM-DAT-006 Data Lineage", "distinction": "Reference generation runs and provenance records. This model records which run supports a release and never orchestrates training, execution or the full lineage lifecycle.", "source_refs": [ "SRC-002" ] }, { "neighbor": "WM-DAT-007 Data Quality Evaluation", "distinction": "Reference assessments and retain a product-specific interpretation. Evaluators own test execution and measurement records; a utility observation is not universal approval.", "source_refs": [ "SRC-003", "SRC-004" ] }, { "neighbor": "Masked data, simulation outputs and mixed products", "distinction": "Masking or sampling real rows alone does not establish synthetic origin. Rule-based generation can qualify with a declared target and use. Partially generated products must label retained real components; classification alone implies no privacy guarantee.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Data Catalog Vocabulary (DCAT) - Version 3", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-dcat-3/", "version_or_date": "Recommendation, 22 August 2024; errata not independently checked", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:23:02Z", "relevance": "Sections 6.4, 6.6, 6.8 and 11 support dataset, distribution, version, rights and status distinctions. Alignment only." }, { "id": "SRC-002", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:23:02Z", "relevance": "Entity, activity, agent, derivation, generation and qualified influence support lineage references, not proof of correctness." }, { "id": "SRC-003", "title": "Data on the Web Best Practices: Data Quality Vocabulary", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-dqv/", "version_or_date": "Working Group Note; retrieved 2026-10-06, exact dated edition pin pending", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T20:23:02Z", "relevance": "Sections 4.1-4.7 support metric, measured resource, value, unit, annotation and policy references. This is a Note, not a conformance certification." }, { "id": "SRC-004", "title": "Guidelines for Evaluating Differential Privacy Guarantees", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-226.pdf", "version_or_date": "SP 800-226, March 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:23:02Z", "relevance": "Sections 2 and 3.6 support qualified privacy claims, composition, privacy unit, utility limitations and synthetic-data disclosure risk. Selected sections reviewed." }, { "id": "SRC-005", "title": "De-Identifying Government Datasets: Techniques and Governance", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/188/final", "version_or_date": "SP 800-188, September 2023; official abstract reviewed", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:23:02Z", "relevance": "Official abstract supports sharing-model choices, disclosure review and measurable risk assessment. Full report was not read and is not claimed as verified." }, { "id": "SRC-006", "title": "Synthetic data policy", "organization": "Office for National Statistics", "url": "https://www.ons.gov.uk/aboutus/transparencyandgovernance/datastrategy/datapolicies/syntheticdatapolicy", "version_or_date": "Official policy page accessed 2026-10-06; exact revision pin unresolved", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:23:02Z", "relevance": "Sections 2-5 support purpose-specific suitability, generation documentation, disclosure review and qualified sharing. Institutional example, not universal law." }, { "id": "SRC-007", "title": "Introduction to anonymisation", "organization": "Information Commissioner's Office", "url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/anonymisation/introduction-to-anonymisation/", "version_or_date": "Official UK guidance accessed 2026-10-06; legal currency and applicability unresolved", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:23:02Z", "relevance": "Anonymous information, anonymisation as processing and pseudonymisation sections support separation of input processing authority and output identifiability. UK example only." } ], "structure": { "bundles": [ { "id": "dat012-b-designation", "name": "Product designation", "description": "Persistent product identity and the kind of generated content claimed.", "rationale": "Keep this product concern separately reviewable and bound to release-specific evidence without absorbing external master operations.", "source_refs": [ "SRC-001", "SRC-006" ], "layers": [ { "id": "dat012-l-identity", "name": "Product and release identity", "description": "A proposed identity view separates the product, release, content snapshot and metadata revision. Evidence targets exact releases, including unreleased candidates.", "source_refs": [ "SRC-001", "SRC-002" ], "findings": [ { "id": "dat012-f-identity", "name": "Release identity binding", "description": "A proposed identity view separates the product, release, content snapshot and metadata revision. Evidence targets exact releases, including unreleased candidates.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "dat012-f-identity-q01", "kind": "identity", "text": "Which product master and release identifiers distinguish this candidate from other versions?", "answer_data": [ "product_master_id", "release_id", "metadata_revision" ] }, { "id": "dat012-f-identity-q02", "kind": "relationship", "text": "Which predecessor and successor links concern content changes rather than metadata corrections?", "answer_data": [ "previous_release_ref", "successor_ref", "change_kind" ] }, { "id": "dat012-f-identity-q03", "kind": "ownership", "text": "Which accountable steward maintains the synthetic-specific product claims?", "answer_data": [ "steward_role_ref", "delegation_ref", "effective_period" ] }, { "id": "dat012-f-identity-q04", "kind": "temporal", "text": "What generation, release-decision and evidence-observation times apply to this version?", "answer_data": [ "generation_time", "decision_time", "observed_at", "time_precision" ] } ], "data_elements": [ { "id": "dat012-f-identity-data01", "name": "Product master", "description": "Reference to the governed product identity.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "dat012-f-identity-data02", "name": "Release binding", "description": "Version, content snapshot, metadata revision and predecessor references.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "dat012-f-identity-artifact", "name": "Synthetic product release manifest", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "dat012-l-classification", "name": "Synthetic classification", "description": "Declare whether content is generated, partially generated or mixed and identify untouched real components. Synthetic origin is distinct from anonymisation and observed-world truth.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ], "findings": [ { "id": "dat012-f-classification", "name": "Generation and mixture declaration", "description": "Declare whether content is generated, partially generated or mixed and identify untouched real components. Synthetic origin is distinct from anonymisation and observed-world truth.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ], "questions": [ { "id": "dat012-f-classification-q01", "kind": "classification", "text": "Which components are generated, retained from real data or of unknown origin?", "answer_data": [ "component_refs", "origin_class", "unknown_reason" ] }, { "id": "dat012-f-classification-q02", "kind": "definition", "text": "What target population, scenario or data shape is this product intended to represent?", "answer_data": [ "target_definition", "coverage", "simulation_assumptions" ] }, { "id": "dat012-f-classification-q03", "kind": "evidence", "text": "What evidence distinguishes generation from masked or sampled real records?", "answer_data": [ "generation_evidence_ref", "classification_review" ] }, { "id": "dat012-f-classification-q04", "kind": "constraint", "text": "How are synthetic labels preserved when components are joined or exported?", "answer_data": [ "component_labels", "export_label_policy", "mixed_product_warning" ] } ], "data_elements": [ { "id": "dat012-f-classification-data01", "name": "Origin declaration", "description": "Component-level origin class and rationale; unknown origin blocks an unqualified synthetic label.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] }, { "id": "dat012-f-classification-data02", "name": "Target context", "description": "Population or scenario, period and geography semantics; no assertion that records are real observations.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "dat012-f-classification-artifact", "name": "Origin and labelling declaration", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dat012-b-generation", "name": "Generation basis", "description": "Product-specific bindings to inputs, generation configuration and authority evidence.", "rationale": "Keep this product concern separately reviewable and bound to release-specific evidence without absorbing external master operations.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007" ], "layers": [ { "id": "dat012-l-inputs", "name": "Input basis", "description": "Reference versioned inputs, their use roles and permission evidence. Generation may use rules or public assumptions without confidential training rows; a claimed absence needs a rationale.", "source_refs": [ "SRC-002", "SRC-007" ], "findings": [ { "id": "dat012-f-inputs", "name": "Source and authority binding", "description": "Reference versioned inputs, their use roles and permission evidence. Generation may use rules or public assumptions without confidential training rows; a claimed absence needs a rationale.", "source_refs": [ "SRC-002", "SRC-007" ], "questions": [ { "id": "dat012-f-inputs-q01", "kind": "provenance", "text": "Which input snapshots, public parameters or rules supported this release?", "answer_data": [ "input_refs", "versions", "input_roles", "no_real_data_rationale" ] }, { "id": "dat012-f-inputs-q02", "kind": "authority", "text": "Which recorded authority and purpose permit each source use in generation?", "answer_data": [ "authority_evidence_ref", "permitted_purpose", "restrictions" ] }, { "id": "dat012-f-inputs-q03", "kind": "privacy", "text": "Which input categories or linkage keys require restricted handling?", "answer_data": [ "sensitivity_classes", "linkage_key_policy", "authorized_view" ] }, { "id": "dat012-f-inputs-q04", "kind": "exception", "text": "Which missing or disputed input permissions prevent reliance on the release?", "answer_data": [ "permission_gaps", "dispute_ref", "claim_status" ] } ], "data_elements": [ { "id": "dat012-f-inputs-data01", "name": "Input bindings", "description": "Typed input references with version, role and access classification.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "dat012-f-inputs-data02", "name": "Use authority assessment", "description": "Authority references or explicit not-applicable rationale, limitations and unresolved items.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "dat012-f-inputs-artifact", "name": "Input use evidence index", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "dat012-l-run", "name": "Generation trace", "description": "Bind a release to an externally managed generator and run, including transformations and known reproducibility limits. Recording a run does not execute it or prove its claims.", "source_refs": [ "SRC-002", "SRC-004" ], "findings": [ { "id": "dat012-f-run", "name": "Generation run attestation", "description": "Bind a release to an externally managed generator and run, including transformations and known reproducibility limits. Recording a run does not execute it or prove its claims.", "source_refs": [ "SRC-002", "SRC-004" ], "questions": [ { "id": "dat012-f-run-q01", "kind": "provenance", "text": "Which generator artifact, configuration and run produced the admitted snapshot?", "answer_data": [ "generator_ref", "artifact_version", "configuration_ref", "run_ref" ] }, { "id": "dat012-f-run-q02", "kind": "process", "text": "Which filtering, conditioning or post-processing steps changed the generated output?", "answer_data": [ "transformation_refs", "order", "additional_input_refs" ] }, { "id": "dat012-f-run-q03", "kind": "validation", "text": "What reproducibility claim is supported by the retained environment and randomness evidence?", "answer_data": [ "environment_ref", "randomness_policy", "replay_evidence", "reproducibility_limit" ] }, { "id": "dat012-f-run-q04", "kind": "security", "text": "Which run details must be withheld because they expose source records or secret randomness?", "answer_data": [ "restricted_fields", "access_policy", "redaction_reason" ] } ], "data_elements": [ { "id": "dat012-f-run-data01", "name": "Run binding", "description": "External run and configuration references pinned to the content digest.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "dat012-f-run-data02", "name": "Reproduction limits", "description": "Known nondeterminism, omitted environment details and permitted replay conditions.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "dat012-f-run-artifact", "name": "Release generation attestation", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dat012-b-fitness", "name": "Fitness for declared use", "description": "Schema and purpose-specific evidence about useful and misleading behavior.", "rationale": "Keep this product concern separately reviewable and bound to release-specific evidence without absorbing external master operations.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "layers": [ { "id": "dat012-l-contract", "name": "Shape and constraints", "description": "Point to content schema and constraint checks. Shape compatibility and deliberate anomalies are distinct from semantic fidelity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "findings": [ { "id": "dat012-f-contract", "name": "Content contract binding", "description": "Point to content schema and constraint checks. Shape compatibility and deliberate anomalies are distinct from semantic fidelity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "questions": [ { "id": "dat012-f-contract-q01", "kind": "composition", "text": "Which datasets, partitions and schema versions make up this release?", "answer_data": [ "content_refs", "partition_refs", "schema_version_refs" ] }, { "id": "dat012-f-contract-q02", "kind": "constraint", "text": "Which referential, range and temporal constraints are required for the intended use?", "answer_data": [ "constraint_refs", "scope", "profile_version" ] }, { "id": "dat012-f-contract-q03", "kind": "exception", "text": "Which invalid or missing values are deliberately introduced as test cases?", "answer_data": [ "deliberate_anomalies", "scenario_refs", "labels" ] }, { "id": "dat012-f-contract-q04", "kind": "validation", "text": "Which exact snapshot passed or failed the linked content checks?", "answer_data": [ "evaluation_refs", "tested_digest", "check_status", "unexecuted_checks" ] } ], "data_elements": [ { "id": "dat012-f-contract-data01", "name": "Contract references", "description": "Schemas and constraints remain externally defined with pinned versions.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "dat012-f-contract-data02", "name": "Conformance view", "description": "Linked check results and intentional exceptions; absent tests are unknown.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "dat012-f-contract-artifact", "name": "Content contract evidence view", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "dat012-l-utility", "name": "Use suitability", "description": "Record suitability for stated tasks through externally produced metrics and reviewer interpretation. Similarity in one statistic does not establish general fitness, fairness or causal validity.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006" ], "findings": [ { "id": "dat012-f-utility", "name": "Utility and subgroup evidence", "description": "Record suitability for stated tasks through externally produced metrics and reviewer interpretation. Similarity in one statistic does not establish general fitness, fairness or causal validity.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006" ], "questions": [ { "id": "dat012-f-utility-q01", "kind": "requirement", "text": "Which intended uses and acceptance criteria were defined before evaluating this release?", "answer_data": [ "use_cases", "criteria_refs", "threshold_rationale", "excluded_uses" ] }, { "id": "dat012-f-utility-q02", "kind": "measurement", "text": "Which task and distribution metrics support each suitability claim?", "answer_data": [ "metric_refs", "values", "units", "baseline_refs", "uncertainty", "evaluation_ref" ] }, { "id": "dat012-f-utility-q03", "kind": "quality", "text": "How do minority groups, rare events and missingness differ within the evaluated scope?", "answer_data": [ "subgroup_refs", "coverage_limits", "error_bounds", "unevaluated_groups" ] }, { "id": "dat012-f-utility-q04", "kind": "decision", "text": "Which uses were accepted, rejected or left unassessed by the responsible reviewer?", "answer_data": [ "use_decisions", "reviewer_role", "rationale", "validity_period" ] } ], "data_elements": [ { "id": "dat012-f-utility-data01", "name": "Suitability claims", "description": "Use-specific decisions with baseline, metric, units, uncertainty and exceptions.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-006" ] }, { "id": "dat012-f-utility-data02", "name": "Assessment bindings", "description": "External evaluation versions and exact target snapshots; prevent train/test contamination claims without evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "dat012-f-utility-artifact", "name": "Use suitability evidence matrix", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dat012-b-protection", "name": "Privacy and disclosure claims", "description": "Separate empirical disclosure assessment from formal mechanism guarantees.", "rationale": "Keep this product concern separately reviewable and bound to release-specific evidence without absorbing external master operations.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ], "layers": [ { "id": "dat012-l-disclosure", "name": "Disclosure assessment", "description": "Reference a threat-scoped assessment of release content and accompanying metadata. Passing a finite set of tests is not proof of anonymity or absence of future attacks.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ], "findings": [ { "id": "dat012-f-disclosure", "name": "Residual disclosure evidence", "description": "Reference a threat-scoped assessment of release content and accompanying metadata. Passing a finite set of tests is not proof of anonymity or absence of future attacks.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ], "questions": [ { "id": "dat012-f-disclosure-q01", "kind": "privacy", "text": "Which protected subjects, auxiliary information and recipient assumptions define the disclosure assessment?", "answer_data": [ "protected_unit", "threat_model_ref", "recipient_context", "auxiliary_data_scope" ] }, { "id": "dat012-f-disclosure-q02", "kind": "evidence", "text": "What authorized assessments considered copying, membership or attribute disclosure?", "answer_data": [ "assessment_refs", "test_families", "target_digest", "findings", "untested_threats" ] }, { "id": "dat012-f-disclosure-q03", "kind": "security", "text": "Could released examples, reports or lineage metadata expose protected input information?", "answer_data": [ "metadata_review_ref", "sensitive_outputs", "redactions" ] }, { "id": "dat012-f-disclosure-q04", "kind": "decision", "text": "Who accepted the residual risk for the stated audience and until what reassessment trigger?", "answer_data": [ "risk_acceptance_ref", "approver_role", "audience", "review_trigger" ] } ], "data_elements": [ { "id": "dat012-f-disclosure-data01", "name": "Disclosure assessment binding", "description": "Threat context, authorized assessment reference, findings and uncertainty; no attack execution here.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] }, { "id": "dat012-f-disclosure-data02", "name": "Residual claim status", "description": "Unassessed, qualified, rejected or accepted for a specified context; not a legal guarantee.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "dat012-f-disclosure-artifact", "name": "Disclosure claim evidence view", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "dat012-l-guarantee", "name": "Formal privacy qualification", "description": "Formal privacy is optional. A claim requires mechanism-specific evidence and a cumulative accounting reference; absent evidence stays unverified and never defaults to zero privacy loss.", "source_refs": [ "SRC-004" ], "findings": [ { "id": "dat012-f-guarantee", "name": "Mechanism guarantee binding", "description": "Formal privacy is optional. A claim requires mechanism-specific evidence and a cumulative accounting reference; absent evidence stays unverified and never defaults to zero privacy loss.", "source_refs": [ "SRC-004" ], "questions": [ { "id": "dat012-f-guarantee-q01", "kind": "classification", "text": "Is a formal privacy guarantee claimed, absent, unverified or not applicable for this release?", "answer_data": [ "guarantee_state", "rationale", "scope" ] }, { "id": "dat012-f-guarantee-q02", "kind": "requirement", "text": "Which mechanism, privacy unit, adjacency and trust assumptions define the claimed guarantee?", "answer_data": [ "mechanism_ref", "privacy_unit", "adjacency", "trust_model", "proof_ref" ] }, { "id": "dat012-f-guarantee-q03", "kind": "measurement", "text": "Which privacy definition, parameters and accountant support the cumulative release claim?", "answer_data": [ "definition_variant", "epsilon", "delta_if_applicable", "accountant_ref", "cumulative_bound", "related_releases" ] }, { "id": "dat012-f-guarantee-q04", "kind": "exception", "text": "Which extra data accesses or implementation deviations fall outside the proved mechanism?", "answer_data": [ "deviation_refs", "additional_accesses", "composition_review", "claim_limitations" ] } ], "data_elements": [ { "id": "dat012-f-guarantee-data01", "name": "Guarantee state", "description": "Explicit state; a product may exist without a differential privacy claim.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "dat012-f-guarantee-data02", "name": "Formal claim evidence", "description": "Mechanism, parameters, implementation assurance and accountant bindings required only when a formal claim is made.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "dat012-f-guarantee-artifact", "name": "Formal privacy claim record", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dat012-b-release", "name": "Release and consumption", "description": "Qualified approval and distribution metadata tied to exact evidence.", "rationale": "Keep this product concern separately reviewable and bound to release-specific evidence without absorbing external master operations.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ], "layers": [ { "id": "dat012-l-decision", "name": "Release qualification", "description": "A local product record stores a reference to an authorized release decision and its scope. Evidence completeness, legal status, permitted audience and product state remain separate.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ], "findings": [ { "id": "dat012-f-decision", "name": "Audience-specific release decision", "description": "A local product record stores a reference to an authorized release decision and its scope. Evidence completeness, legal status, permitted audience and product state remain separate.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ], "questions": [ { "id": "dat012-f-decision-q01", "kind": "authority", "text": "Which decision authority approved or refused this snapshot for the specified audience?", "answer_data": [ "decision_ref", "authority_role", "audience", "snapshot_digest" ] }, { "id": "dat012-f-decision-q02", "kind": "requirement", "text": "Which licence, purpose and source-agreement conditions constrain this release?", "answer_data": [ "licence_ref", "purpose_restrictions", "agreement_refs", "jurisdiction_profile" ] }, { "id": "dat012-f-decision-q03", "kind": "state", "text": "Is the release proposed, under review, approved for a scope, refused or withdrawn?", "answer_data": [ "release_state", "effective_at", "decision_basis" ] }, { "id": "dat012-f-decision-q04", "kind": "access", "text": "Which evidence can each reviewer or recipient see without exposing restricted material?", "answer_data": [ "recipient_scope", "evidence_view_policy", "restriction_reason" ] } ], "data_elements": [ { "id": "dat012-f-decision-data01", "name": "Release decision binding", "description": "External decision reference with snapshot and audience; not permission inferred from a status string.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "dat012-f-decision-data02", "name": "Release claim state", "description": "Local projection of decision evidence with unknown and refusal states.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "dat012-f-decision-artifact", "name": "Release qualification record", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "dat012-l-distribution", "name": "Consumer binding", "description": "Each distribution identifies format, snapshot and permitted use, with synthetic labels and known limitations. A downloadable URL is not an access grant or a quality guarantee.", "source_refs": [ "SRC-001", "SRC-006" ], "findings": [ { "id": "dat012-f-distribution", "name": "Distribution and disclosure notice", "description": "Each distribution identifies format, snapshot and permitted use, with synthetic labels and known limitations. A downloadable URL is not an access grant or a quality guarantee.", "source_refs": [ "SRC-001", "SRC-006" ], "questions": [ { "id": "dat012-f-distribution-q01", "kind": "interoperability", "text": "Which distribution metadata maps to catalogue terms and which local extensions remain unmapped?", "answer_data": [ "mapping_profile_ref", "distribution_refs", "unmapped_fields", "loss_report" ] }, { "id": "dat012-f-distribution-q02", "kind": "identity", "text": "Which checksum and snapshot identify the content delivered by each distribution?", "answer_data": [ "distribution_id", "snapshot_ref", "digest_algorithm", "digest_value" ] }, { "id": "dat012-f-distribution-q03", "kind": "access", "text": "What access route and recipient conditions apply to each delivery option?", "answer_data": [ "service_ref", "access_policy_ref", "recipient_conditions" ] }, { "id": "dat012-f-distribution-q04", "kind": "constraint", "text": "Which synthetic notice and unsuitable-use warnings accompany every consumer view?", "answer_data": [ "notice_ref", "synthetic_label", "use_limits", "contact_role" ] } ], "data_elements": [ { "id": "dat012-f-distribution-data01", "name": "Distribution bindings", "description": "Delivery references, format, content integrity and applicable conditions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "dat012-f-distribution-data02", "name": "Consumer notice", "description": "Clear origin label, tested uses, limitations and accountable contact role.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006" ] } ], "artifacts": [ { "id": "dat012-f-distribution-artifact", "name": "Distribution notice manifest", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dat012-b-continuity", "name": "Evidence continuity", "description": "Reassessment and scoped retirement without rewriting prior claims.", "rationale": "Keep this product concern separately reviewable and bound to release-specific evidence without absorbing external master operations.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ], "layers": [ { "id": "dat012-l-reassessment", "name": "Review continuity", "description": "New evidence or changed context creates a new claim revision. A claim update does not alter already released bytes or silently renew a release decision.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "findings": [ { "id": "dat012-f-reassessment", "name": "Claim reassessment and supersession", "description": "New evidence or changed context creates a new claim revision. A claim update does not alter already released bytes or silently renew a release decision.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "questions": [ { "id": "dat012-f-reassessment-q01", "kind": "event", "text": "Which incident, new assessment or changed use invalidates reliance on earlier evidence?", "answer_data": [ "trigger_ref", "affected_claims", "affected_release_refs" ] }, { "id": "dat012-f-reassessment-q02", "kind": "lifecycle", "text": "Which claim or release supersedes this one and which prior conclusions remain disputed?", "answer_data": [ "supersession_refs", "dispute_status", "affected_audiences" ] }, { "id": "dat012-f-reassessment-q03", "kind": "temporal", "text": "When did the changed evidence become effective and when was it recorded?", "answer_data": [ "effective_at", "observed_at", "recorded_at", "valid_until" ] }, { "id": "dat012-f-reassessment-q04", "kind": "process", "text": "Which notices and reevaluation requests were recorded for affected consumers?", "answer_data": [ "notice_refs", "assessment_request_refs", "delivery_evidence", "unreachable_consumers" ] } ], "data_elements": [ { "id": "dat012-f-reassessment-data01", "name": "Reassessment entry", "description": "Trigger, affected immutable evidence revision, successor and recorded notices.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "dat012-f-reassessment-data02", "name": "Evidence currency", "description": "Evidence validity period and unresolved reassessment status.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "dat012-f-reassessment-artifact", "name": "Claim reassessment register", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "dat012-l-retirement", "name": "Retirement and records", "description": "Retirement marks local reliance and distribution status without claiming deletion of all copies. Sensitive retained evidence remains subject to separately governed retention and erasure.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ], "findings": [ { "id": "dat012-f-retirement", "name": "Withdrawal and retention binding", "description": "Retirement marks local reliance and distribution status without claiming deletion of all copies. Sensitive retained evidence remains subject to separately governed retention and erasure.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ], "questions": [ { "id": "dat012-f-retirement-q01", "kind": "retention", "text": "Which retention schedules and holds apply separately to product metadata, reports and payloads?", "answer_data": [ "retention_policy_refs", "record_classes", "hold_refs", "disposition_dates" ] }, { "id": "dat012-f-retirement-q02", "kind": "lifecycle", "text": "Which authority requested withdrawal and which distributions are affected?", "answer_data": [ "withdrawal_decision_ref", "distribution_refs", "withdrawal_state" ] }, { "id": "dat012-f-retirement-q03", "kind": "evidence", "text": "Which acknowledgements distinguish requested withdrawal from confirmed local removal?", "answer_data": [ "acknowledgement_refs", "deletion_attestations", "uncontrolled_copies" ] }, { "id": "dat012-f-retirement-q04", "kind": "exception", "text": "What minimum lawful tombstone preserves references when restricted evidence is erased?", "answer_data": [ "tombstone_fields", "legal_basis_ref", "redaction_policy", "unresolved_references" ] } ], "data_elements": [ { "id": "dat012-f-retirement-data01", "name": "Disposition binding", "description": "Retention and withdrawal instructions remain policy references with scoped acknowledgements.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "dat012-f-retirement-data02", "name": "Uncontrolled copies", "description": "Known inability to recall third-party copies; never claim universal erasure.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "dat012-f-retirement-artifact", "name": "Withdrawal and disposition evidence view", "description": "Versioned product evidence view with author, status, release target and restricted underlying evidence references. Not a substitute for the external master record.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID, else governed IRI, else Dimension UUID or ULID; preserve product ID, release ID and evidence revision separately. Timestamp and digest are not identity.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "dat012-fn-register", "name": "Register a synthetic release candidate", "description": "Proposed local operation, not implemented. Create a local synthetic-specific candidate linked to an existing product master.", "inputs": [ "Product master reference", "Release and origin declarations" ], "outputs": [ "Candidate evidence view", "Refusal with unresolved bindings" ], "preconditions": [ "Steward role is authorized", "Product identity resolves", "Origin classification is supported or explicitly unknown", "Expected metadata revision matches current revision" ], "effects": [ "Record candidate state without granting distribution access" ], "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "dat012-fn-bind-lineage", "name": "Bind generation evidence", "description": "Proposed local operation, not implemented. Attach verified references to input and run records without copying source rows.", "inputs": [ "Release ID and expected revision", "Input and run attestations" ], "outputs": [ "Versioned lineage binding", "Mismatch or access refusal" ], "preconditions": [ "Reference access allowed", "Run output digest matches candidate", "Use authority state recorded", "Expected metadata revision matches current revision" ], "effects": [ "Add evidence revision; do not run a pipeline or expose protected configuration" ], "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "dat012-fn-record-fitness", "name": "Record a suitability interpretation", "description": "Proposed local operation, not implemented. Bind external assessment outputs to use-specific claims.", "inputs": [ "Release digest", "Assessment references", "Criteria and reviewer interpretation" ], "outputs": [ "Qualified suitability matrix", "Untested or unsupported result" ], "preconditions": [ "Reviewer authorized", "Assessment targets this snapshot", "Units, baselines and limits recorded", "Expected metadata revision matches current revision" ], "effects": [ "Record accepted, rejected or unknown use claims without executing evaluation" ], "source_refs": [ "SRC-003", "SRC-006" ] }, { "id": "dat012-fn-record-privacy", "name": "Record a privacy claim", "description": "Proposed local operation, not implemented. Attach empirical or formal claim evidence with distinct states.", "inputs": [ "Disclosure assessment reference", "Optional formal guarantee evidence", "Related release accounting reference" ], "outputs": [ "Qualified privacy claim view", "Incomplete evidence refusal" ], "preconditions": [ "Privacy reviewer authorized", "Target and audience match", "No inferred zero budget or unproved guarantee", "Expected metadata revision matches current revision" ], "effects": [ "Record claim revision; never calculate attacks, certify anonymity or allocate external budgets" ], "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "dat012-fn-bind-decision", "name": "Bind release decision", "description": "Proposed local operation, not implemented. Record the externally authorized decision for a precise audience and snapshot.", "inputs": [ "Decision reference", "Snapshot digest", "Audience and conditions" ], "outputs": [ "Release qualification projection", "Refusal for missing or stale authority" ], "preconditions": [ "Decision authority verified", "Required evidence available", "No unresolved blocking local policy condition", "Expected metadata revision matches current revision" ], "effects": [ "Update local release claim state only; no upload, access expansion or publication action" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "dat012-fn-record-withdrawal", "name": "Record reassessment or withdrawal", "description": "Proposed local operation, not implemented. Record changed evidence and referenced withdrawal instructions.", "inputs": [ "Affected release and expected revision", "Trigger and authority references", "Acknowledgement references" ], "outputs": [ "Supersession or withdrawal view", "Unresolved copy and retention list" ], "preconditions": [ "Record steward authorized", "Target versions resolved", "Retention and erasure constraints checked", "Expected metadata revision matches current revision" ], "effects": [ "Mark local claims and distributions for review; do not delete remote data or promise recall" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "composition": [ { "target": "WM-DAT-008 Data Product / Product Catalog Record", "relation": "EXTEND", "purpose": "Candidate registry parent specialization: bind one product master and generic product policy; add only synthetic-specific claims. No executable inheritance is certified.", "required": true, "source_refs": [ "SRC-001", "SRC-006" ] }, { "target": "WM-DAT-001 Dataset", "relation": "REFERENCE", "purpose": "Bind generated output snapshots and optional input datasets without owning their lifecycle.", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-DAT-004 Data Schema / Data Contract", "relation": "REFERENCE", "purpose": "Pin schemas and constraints used to interpret generated content; definitions stay external.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "WM-DAT-005 Data Pipeline", "relation": "REFERENCE", "purpose": "Reference generation runs if a pipeline is used; no execution or scheduling ownership.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "WM-DAT-006 Data Lineage", "relation": "REFERENCE", "purpose": "Bind external lineage evidence; local run selection is not a full lineage graph.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "WM-DAT-007 Data Quality Evaluation", "relation": "REFERENCE", "purpose": "Bind assessment results with product-specific interpretations; no evaluation execution.", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "target": "W3C DCAT 3, PROV-O and DQV", "relation": "ALIGN", "purpose": "Conceptual catalogue, provenance and quality mappings; implementer must pin and test a profile before claiming conformance.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name the accountable product steward and adopting Dimension without a fixed company owner", "Bind product master, namespace, release policy and source-use authority roles", "Pin privacy, evidence access, retention and interoperability profiles before operational adoption" ], "namespace_guidance": "Stable lower-kebab-case IDs in the adopting Dimension namespace; keep product, release, content and evidence revision identities distinct.", "registry_links": [ "vr.wm-dat-012", "WM-DAT-008 candidate parent", "WM-DAT-001, WM-DAT-004, WM-DAT-005, WM-DAT-006 and WM-DAT-007 reference bindings" ] }, "canon_and_patch": { "canonicalization_rules": [ "This is a noncanonical reviewable draft. Canonicalization here means deterministic record handling, not promotion of research assurance.", "Normalize identifiers without merging product versions, distributions or real and generated components; retain origin and evidence status." ], "patch_rules": [ "Require role, purpose, expected revision, change reason and evidence reference; append a new metadata revision.", "Changed content receives a new release snapshot; corrected metadata can retain content identity with a distinct revision." ], "compatibility_rules": [ "Do not silently widen audience, redefine the privacy unit or carry evidence across changed snapshots.", "Schema, intended-use, input or mechanism changes require compatibility and claim review under the adopting profile." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier", "Governed global identifier or IRI", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and an explicit offset or Z. Distinguish event time, effective time and observation or ingestion time; preserve uncertainty without inventing precision.", "serial_naming_rule": "Keep stable artifact identity and separate monotonically governed revision labels. Dates and checksums are attributes, never sole identifiers.", "integrity_rule": "Record digest algorithm, digest, target release and evidence provenance. Restrict raw exemplars and seeds. Integrity checks establish byte continuity, not fidelity, privacy or authority." }, "policies": [ "Proposed model policies are design choices grounded in cited evidence; sources do not prescribe these field names or state codes.", "Synthetic origin, empirical disclosure testing, formal privacy, lawful use and release permission are separate claims. Unknown never means safe.", "Keep generated labels with every distribution; preserve mixed-origin component notices and negative suitability findings.", "Only authorized local evidence changes are proposed functions. External generation, testing, sharing and deletion require separately governed systems and authority.", "A valid research schema is not a usable instance schema, privacy proof, standards conformance or independent review." ], "crud": { "read": [ "Enforce purpose and recipient-specific access at every scope; public catalogue visibility does not expose restricted reports or source links." ], "create": [ "Bind existing product identity, candidate release and declared origin; require authority to store each evidence field. Missing assessment can be stored as unknown but cannot support approval." ], "update": [ "Use revision checks and explicit claim provenance; stale evidence must not silently remain valid for a changed release." ], "delete": [ "Retire local claims and preserve only lawful minimal tombstones. Apply retention schedules, erasure obligations and holds separately to metadata, reports and payloads.", "Adopting-Dimension storage policy and external dataset masters own physical deletion; this model records acknowledgements and does not delete source data or guarantee recall of public copies." ] }, "roles": [ { "name": "Product steward", "responsibilities": [ "Maintain synthetic classification, use context and accountable references" ] }, { "name": "Generation custodian", "responsibilities": [ "Attest externally produced run and configuration bindings without exposing restricted inputs" ] }, { "name": "Utility reviewer", "responsibilities": [ "Interpret release-specific fitness evidence and rejected uses" ] }, { "name": "Privacy reviewer", "responsibilities": [ "Qualify disclosure and formal privacy evidence with explicit uncertainty" ] }, { "name": "Release authority", "responsibilities": [ "Approve audience and conditions through an external decision record" ] }, { "name": "Records custodian", "responsibilities": [ "Apply scoped retention and withdrawal policy through authorized systems" ] } ], "access": { "default_rule": "Deny access to restricted evidence and payloads unless purpose, role and release scope permit it; reviewable research metadata does not authorize dataset access.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Any exceptional access needs an authorized, time-limited decision with purpose and minimum necessary view.", "Public sanitized summaries may omit source locations and sensitive metrics; retain an access-controlled mapping and an explicit omission notice." ], "audit_requirements": [ "Record actor role, purpose, target release, expected revision, decision basis and outcome in the adopting audit system.", "Do not copy confidential example rows, credentials, raw seeds or attack outputs into public evidence views." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Nearest owner and Dimension policies", "AGENTS.md and spec.yaml with visible holds", "Product release binding and applicable evidence/access profile", "Referenced masters and qualified evidence before any local claim change" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one persistent synthetic data product and release-specific evidence. Separate local no-tools self-audit completed. Independent review, source/version verification, adoption profiles and executable conformance remain holds. This reviewable draft does not certify privacy, fitness, legal compliance or universal modality coverage.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Product master, release, snapshot and evidence revision are separate." }, { "dimension": "lifecycle", "status": "covered", "notes": "Local candidate, decision, supersession and withdrawal claims reference external authority." }, { "dimension": "relationships", "status": "covered", "notes": "Candidate parent and optional neighbors preserve their master operations." }, { "dimension": "temporal", "status": "covered", "notes": "Generation, effective, observation and record times are separate." }, { "dimension": "provenance", "status": "covered", "notes": "Input, generator, run and transformations are pinned through references." }, { "dimension": "ownership", "status": "covered", "notes": "Role-based stewardship and authority; no fixed company owner." }, { "dimension": "validation", "status": "covered", "notes": "Release-specific evidence and negative results; execution delegated." }, { "dimension": "access", "status": "covered", "notes": "Recipient and evidence scopes are distinct from catalogue visibility." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Scoped retention, erasure, holds and incomplete recall are explicit." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual vocabulary links present; executable mappings and pinned neighbor profiles pending." }, { "dimension": "direct properties", "status": "covered", "notes": "Origin class, schema, scope, distribution integrity, utility and privacy claim states are nonphysical properties." }, { "dimension": "recognition", "status": "covered", "notes": "Generation evidence and labels support recognition without assuming perfect anonymity." }, { "dimension": "capabilities and failure", "status": "covered", "notes": "Six proposed local operations have preconditions, refusals and limited effects." }, { "dimension": "spatial", "status": "covered", "notes": "Target geography and synthetic coordinates describe represented scope, not verified observed locations." }, { "dimension": "privacy", "status": "covered", "notes": "Empirical risk and optional formal guarantees remain separate." }, { "dimension": "modality coverage", "status": "gap", "notes": "Tabular and statistical examples dominate evidence; multimodal and complex relational profiles need further review." } ], "known_omissions": [ "No executable nested instance schemas, external adapters, thresholds or benchmark fixtures are supplied.", "No generator is run, dataset evaluated, formal privacy accountant implemented or source licence adjudicated.", "Modality-specific text, image, longitudinal, graph, simulation and multi-table evaluation requirements remain deferred.", "No independent external review or direct HTTP status measurement in this sandbox." ], "conflicts": [], "regional_assumptions": [ "NIST material is technical government guidance, not a universal legal standard.", "ONS and ICO examples are institution- or UK-specific; local law, source rights and sector obligations need qualified review." ], "adversarial_checks": [ "Challenge synthetic labels when real records are retained or memorized.", "Reject general fitness inferred from one distribution metric or an untested subgroup.", "Reject an epsilon-only privacy claim with no unit, mechanism, assumptions or cumulative context.", "Distinguish identical-copy redistribution and post-processing from fresh private-data access; defer formal accounting to its external evidence.", "Reject public availability inferred from catalogue registration and complete deletion inferred from a withdrawal notice.", "Challenge claims copied to a new release without matching content digest." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "A governed product persists across separately identified releases, distributions and evidence revisions. The registry standalone-mm value describes the record plane, not the subject kind. Dataset, generator, pipeline, lineage, evaluator and decision masters remain external; the parent is a candidate specialization without certified executable inheritance." }, "decisions": [ { "concept": "Persistent product boundary", "disposition": "accepted", "rationale": "Product, release, snapshot and evidence revisions are separate. The root remains identifiable across changes without becoming a pipeline run or one file." }, { "concept": "Parent and neighboring ownership", "disposition": "qualified", "rationale": "The candidate EXTEND binds the generic product master. Reference links delegate schemas, lineage and evaluation execution; proposed operations change only synthetic-specific local evidence views." }, { "concept": "Generated origin and mixed records", "disposition": "accepted with qualification", "rationale": "Origin declarations label retained real components. The result rejects both automatic anonymity and the supplement's guarantee that generated rows cannot correspond to real subjects." }, { "concept": "Input basis and authority", "disposition": "accepted", "rationale": "Rules and public parameters can replace confidential training inputs. Input authority is recorded separately from output privacy and unresolved permission cannot support reliance." }, { "concept": "Generation and replay", "disposition": "limited", "rationale": "Run attestations bind versions and transformations without executing generators. Restricted configuration, randomness and source evidence are not made public for reproducibility." }, { "concept": "Utility and content contract", "disposition": "accepted", "rationale": "Schema compatibility and deliberate anomalies are distinct from use-specific fitness. Metrics, groups and uncertainty qualify claims, with execution left to the external evaluator." }, { "concept": "Empirical disclosure testing", "disposition": "qualified", "rationale": "The threat context, recipient and metadata are assessed explicitly. Passing finite tests never proves anonymity or eliminates future disclosure risk." }, { "concept": "Formal privacy claim", "disposition": "optional and qualified", "rationale": "Mechanism, unit, adjacency, trust, definition, parameters and cumulative accounting references are required to substantiate a claim. Absence is not zero privacy loss, and external accounting remains authoritative." }, { "concept": "Release permission", "disposition": "separated", "rationale": "An audience-specific external decision must target the snapshot. Catalogue visibility, local status and a privacy claim do not grant permission to distribute." }, { "concept": "Claim revision and withdrawal", "disposition": "accepted", "rationale": "Reassessment preserves prior claim identity without silently renewing evidence. Withdrawal is scoped and does not assert control over all released copies." }, { "concept": "Retention and access", "disposition": "accepted with policy dependency", "rationale": "Restricted evidence uses recipient views, retention schedules and lawful erasure. Reference continuity uses minimal lawful tombstones rather than indefinite sensitive history." }, { "concept": "Properties and modality", "disposition": "qualified", "rationale": "Origin, schema, scope, integrity and evidence states are direct nonphysical properties. Broader multimodal and complex relational validation remains deferred." }, { "concept": "Sources and independent review", "disposition": "limited and held", "rationale": "Selected web content supports the draft, but HTTP statuses are unmeasured, some version pins unresolved and SP 800-188 use limited to its official abstract. This local self-audit is not independent external review." }, { "concept": "Executable instance and conformance", "disposition": "deferred", "rationale": "Candidate fields do not provide complete instance schemas, operational thresholds or mappings. Adopting profiles must define unknown-value handling, conditional requirements and release-blocking fixtures." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts. This separate Codex no-tools self-audit is not an independent second-provider review.", "Live source and version verification remains incomplete. Seven official sources were accessed through selected web-tool content; direct HTTP checks were not attempted under the owner-reported sandbox block, so statuses and HTTP 200 count are unmeasured. The coordinator checker is prepared. Exact guidance revisions, errata and substantive independent verification remain open; SP 800-188 review covered only its official abstract.", "Adoption profiles require qualified review of source rights, processing authority, recipient context, jurisdiction, sector, utility criteria, disclosure risk and any formal privacy claim. Statistical evidence does not establish universal multimodal suitability, anonymisation or legal compliance.", "Executable nested instance schemas, unknown-value rules, pinned neighbor bindings, catalogue/provenance/quality mappings, operational mechanisms and adversarial conformance fixtures remain incomplete. No generator, evaluator, privacy accountant or deployment was implemented.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Pin source editions and errata, run the coordinator HTTP checker, and independently verify claim support and regional legal applicability.", "Define adopting instance schemas and negative fixtures for mixed origin, stale digests, incomplete claims, audience expansion and incomplete withdrawal.", "Review multimodal, longitudinal, graph and multi-table profiles with purpose-specific utility and qualified privacy evidence.", "Restore independent external review before any canonical or publishable-draft promotion." ] }, "statistics": { "sources": 7, "bundles": 6, "layers": 12, "findings": 12, "questions": 48, "artifacts": 12, "functions": 6 } }