# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T20:32:24Z", "synthesisSha256": "7ed8496e1e63ec13fb51a7b2c17aea46fafd7e90d294b2e2ffeeaced263fadff", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ECO-029", "registryId": "vr.wm-eco-029", "name": "Loyalty / Reward", "version": "0.1.0", "previousVersions": [], "entryKind": "relationship", "family": "World Models", "category": "Society, people and institutions", "industry": [ "Cross-industry" ], "domain": [ "SOC.ECO.LOY" ], "tags": [ "loyalty", "reward", "soc.eco.loy" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-eco-029-loyalty-reward/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-eco-029", "model": { "registry_id": "vr.wm-eco-029", "model_id": "WM-ECO-029", "name": "Loyalty / Reward", "entry_kind": "relationship", "purpose": "Represent one member relationship to one loyalty program, with evidenced benefit eligibility, reward activity and point balances where applicable.", "scope_statement": "The root is a persistent program membership relationship under an accountable operator namespace. It records member-specific terms bindings, status, benefit rights and reward-event evidence. Shared program definitions, party identities, customer relationships, purchases, fulfillment, payment and accounting retain separate masters. Local structures and safeguards are research proposals, not a universal source-mandated ontology or implemented reward engine.", "in_scope": [ "Membership identity and enrollment evidence with versioned terms bindings", "Member-specific earning, adjustments, balance observations and optional point lots", "Tier assignments and non-point benefits, redemption requests and outcome references", "Expiry, suspension, closure, disputes and recipient-scoped evidence continuity" ], "out_of_scope": [ "Design or operation of a shared program rule engine, campaign or reward catalog", "Party identity and full customer relationship lifecycle; customer profiles remain external", "Payment, gift-card stored value, currency issuance, securities, tax and general ledger accounting", "Purchase and fulfillment execution, marketing delivery, credit underwriting and general fraud detection", "One-off promotions without a program relationship; external offers can still be referenced", "Detailed coalition settlement, household pooling and transferable assets without an adopted profile" ], "boundary_notes": [ { "neighbor": "WM-ORG-014 Customer / Account Relationship", "distinction": "Registry parent candidate is retained as a reference, not inheritance. Loyalty membership does not own the general customer relationship, party identity or its lifecycle.", "source_refs": [ "SRC-002", "SRC-007" ] }, { "neighbor": "Shared program and tier definition", "distinction": "One program may serve many memberships. Pin the governing definition and effective version; do not duplicate program administration in each member record.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "neighbor": "Reward event and benefit fulfillment", "distinction": "Accrual and redemption events have their own IDs within the relationship history. A reservation, redemption acknowledgement and actual fulfillment are distinct observations.", "source_refs": [ "SRC-007", "SRC-009" ] }, { "neighbor": "Subscription and offer", "distinction": "Paid eligibility may coexist with loyalty. Neither a fee nor the absence of points removes membership from scope; subscription billing and offer lifecycle remain external.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "neighbor": "Accounting and stored value", "distinction": "A reward balance is not automatically money or an accounting liability. Refer specialist classification and valuation to separate financial masters; IFRIC 13 is historical.", "source_refs": [ "SRC-008" ] } ] }, "sources": [ { "id": "SRC-001", "title": "MemberProgram", "organization": "Schema.org", "url": "https://schema.org/MemberProgram", "version_or_date": "Development page displays V30.1, 2026-09-16; release pin pending", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "Distinguishes shared program from memberships and allows benefits without points." }, { "id": "SRC-002", "title": "ProgramMembership", "organization": "Schema.org", "url": "https://schema.org/ProgramMembership", "version_or_date": "Development page displays V30.1, 2026-09-16; release pin pending", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "Membership identifier, member, hosting organization, program and qualified point units." }, { "id": "SRC-003", "title": "MemberProgramTier", "organization": "Schema.org", "url": "https://schema.org/MemberProgramTier", "version_or_date": "Development page displays V30.1, 2026-09-16; release pin pending", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "Membership tiers with benefit and requirement definitions; fees are possible." }, { "id": "SRC-004", "title": "Customer loyalty schemes", "organization": "Australian Competition and Consumer Commission", "url": "https://www.accc.gov.au/business/advertising-and-promotions/customer-loyalty-schemes", "version_or_date": "Undated guidance retrieved 2026-10-06; discusses 2019 recommendations", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "Australian consumer issues: value, fees, expiry, notice, profiling and dispute escalation. Recommendations are not asserted as current universal law." }, { "id": "SRC-005", "title": "Regulation (EU) 2016/679", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng", "version_or_date": "Original act 2016-04-27; current consolidation and applicability not certified", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "Selected Articles 5, 6, 13, 17 and 21 support purpose-specific processing and qualified retention; consent is not the only lawful basis." }, { "id": "SRC-006", "title": "Loyalty Program", "organization": "Square developer documentation", "url": "https://developer.squareup.com/docs/loyalty/overview", "version_or_date": "Unversioned documentation retrieved 2026-10-06", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "One implementation distinguishes earning rules, reward price tiers and issued rewards; these are not universal state codes or membership ranks." }, { "id": "SRC-007", "title": "Loyalty API", "organization": "Square developer documentation", "url": "https://developer.squareup.com/docs/loyalty-api/overview", "version_or_date": "Unversioned documentation retrieved 2026-10-06; API binding not pinned", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "One implementation separates account, accrual, adjustments, reserved rewards, redemption and event history; proposed local safeguards are authored design." }, { "id": "SRC-008", "title": "IFRIC 13 Customer Loyalty Programmes - status and history", "organization": "IFRS Foundation", "url": "https://www.ifrs.org/issued-standards/list-of-standards/ifric-13-customer-loyalty-programmes/", "version_or_date": "Historical interpretation issued 2007; page states superseded by IFRS 15", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "Accounting is a separate boundary. Historical accounting treatment cannot establish a universal current liability or point-to-cash equivalence." }, { "id": "SRC-009", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:31:09Z", "relevance": "Attribution, derivation and revision links for evidence; provenance does not certify truth or authorization." } ], "structure": { "bundles": [ { "id": "foundation-bundle", "name": "Identity and governing terms", "description": "Identify the relationship and its applicable external rules.", "rationale": "Authored grouping of cited concerns; sources support the concepts, not this hierarchy or an executable profile.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-009" ], "layers": [ { "id": "identity-layer", "name": "Membership identity", "description": "Resolve the particular member-program relationship independently of a card, phone number or mutable display name.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "findings": [ { "id": "identity-finding", "name": "Membership identity", "description": "Resolve the particular member-program relationship independently of a card, phone number or mutable display name.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "questions": [ { "id": "identity-q1", "text": "Which master namespace and membership identifier distinguish this relationship?", "kind": "identity", "answer_data": [ "master_namespace", "membership_id", "aliases", "reconciliation_status" ] }, { "id": "identity-q2", "text": "Which program, member and operator references belong to this membership?", "kind": "relationship", "answer_data": [ "program_ref", "member_ref", "operator_ref", "customer_relationship_ref" ] }, { "id": "identity-q3", "text": "Which evidence distinguishes this membership from a customer account, gift card or standalone coupon?", "kind": "classification", "answer_data": [ "classification", "evidence_refs", "exclusions", "assessment_status" ] }, { "id": "identity-q4", "text": "Who is accountable for this membership record and under what stewardship mandate?", "kind": "ownership", "answer_data": [ "custodian_role", "mandate_ref", "responsibility_scope" ] } ], "data_elements": [ { "id": "identity-data-identity", "name": "Identity", "description": "Candidate object fields: master_namespace, membership_id, program_ref, member_ref, operator_ref. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "identity-data-recognition", "name": "Recognition", "description": "Candidate object fields: classification, aliases, evidence_refs, reconciliation_status. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "identity-artifact", "name": "Membership identity record", "description": "Versioned local record of membership identity assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "terms-layer", "name": "Applicable terms", "description": "Bind member-specific applicability to external program rule revisions, with notice evidence and unresolved effects kept explicit.", "source_refs": [ "SRC-001", "SRC-004", "SRC-009" ], "findings": [ { "id": "terms-finding", "name": "Applicable terms", "description": "Bind member-specific applicability to external program rule revisions, with notice evidence and unresolved effects kept explicit.", "source_refs": [ "SRC-001", "SRC-004", "SRC-009" ], "questions": [ { "id": "terms-q1", "text": "Which terms revision governs each benefit or activity in the disputed period?", "kind": "requirement", "answer_data": [ "terms_ref", "revision", "effective_interval", "applicability_basis" ] }, { "id": "terms-q2", "text": "When was a changed rule announced, effective and observed for this membership?", "kind": "temporal", "answer_data": [ "notice_ref", "announced_at", "effective_at", "observed_at", "timezone" ] }, { "id": "terms-q3", "text": "What supports the assertion that required notice or acceptance occurred?", "kind": "evidence", "answer_data": [ "notice_delivery_ref", "acceptance_evidence", "assessment_status" ] }, { "id": "terms-q4", "text": "Which grandfathered rights or disputed changes constrain use of the latest rule?", "kind": "exception", "answer_data": [ "exception_ref", "affected_lots", "dispute_ref", "reviewer", "unresolved_effect" ] } ], "data_elements": [ { "id": "terms-data-binding", "name": "Binding", "description": "Candidate object fields: terms_ref, revision, effective_interval, notice_refs. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-009" ] }, { "id": "terms-data-exceptions", "name": "Exceptions", "description": "Candidate object fields: grandfathering_basis, affected_rights, dispute_ref, assessment. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "terms-artifact", "name": "Terms applicability register", "description": "Versioned local record of applicable terms assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-001", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "participation-bundle", "name": "Participation and benefits", "description": "Describe enrollment, states and member-specific eligibility.", "rationale": "Authored grouping of cited concerns; sources support the concepts, not this hierarchy or an executable profile.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "enrollment-layer", "name": "Enrollment and status", "description": "Record supported joining, suspension, restoration and closure states without treating marketing permission as membership authority.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ], "findings": [ { "id": "enrollment-finding", "name": "Enrollment and status", "description": "Record supported joining, suspension, restoration and closure states without treating marketing permission as membership authority.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ], "questions": [ { "id": "enrollment-q1", "text": "What enrollment event established the relationship and its initial status?", "kind": "lifecycle", "answer_data": [ "enrollment_ref", "occurred_at", "channel", "status", "evidence_refs" ] }, { "id": "enrollment-q2", "text": "Which party or representative authorized enrollment and with what scope?", "kind": "authority", "answer_data": [ "actor_ref", "mandate_ref", "scope", "verification_status" ] }, { "id": "enrollment-q3", "text": "What current membership state is supported by the authoritative record?", "kind": "state", "answer_data": [ "state", "as_of", "source_revision", "restrictions", "evidence_refs" ] }, { "id": "enrollment-q4", "text": "Which purposes and lawful bases govern necessary membership processing separately from optional marketing?", "kind": "privacy", "answer_data": [ "purpose", "legal_basis", "notice_ref", "preference_ref", "withdrawal_effect" ] } ], "data_elements": [ { "id": "enrollment-data-enrollment", "name": "Enrollment", "description": "Candidate object fields: event_ref, actor_ref, mandate_ref, occurred_at, channel. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] }, { "id": "enrollment-data-status", "name": "Status", "description": "Candidate object fields: state, as_of, restriction_refs, purpose_basis_refs. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "enrollment-artifact", "name": "Enrollment and state journal", "description": "Versioned local record of enrollment and status assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "tier-layer", "name": "Tier and benefit eligibility", "description": "Keep member rank assignments distinct from reward price brackets, with point-free entitlements supported.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "findings": [ { "id": "tier-finding", "name": "Tier and benefit eligibility", "description": "Keep member rank assignments distinct from reward price brackets, with point-free entitlements supported.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "questions": [ { "id": "tier-q1", "text": "Does this label denote membership rank, a redemption price bracket or another scheme concept?", "kind": "classification", "answer_data": [ "source_label", "semantic_kind", "mapping_ref", "ambiguity" ] }, { "id": "tier-q2", "text": "Which qualifying metric and assessment window support the assigned membership tier?", "kind": "measurement", "answer_data": [ "metric", "unit", "window", "basis_ref", "assessed_value" ] }, { "id": "tier-q3", "text": "Which fees, thresholds or other conditions govern this member benefit?", "kind": "constraint", "answer_data": [ "benefit_ref", "eligibility_rule_ref", "fee_ref", "exclusions" ] }, { "id": "tier-q4", "text": "When does the tier assignment or benefit eligibility start, end or require reassessment?", "kind": "temporal", "answer_data": [ "assignment_ref", "valid_from", "valid_to", "reassessment_due", "evidence_refs" ] } ], "data_elements": [ { "id": "tier-data-assignment", "name": "Assignment", "description": "Candidate object fields: tier_ref, semantic_kind, assessment_ref, valid_interval. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "tier-data-benefits", "name": "Benefits", "description": "Candidate object fields: benefit_refs, eligibility_refs, conditions, fee_refs. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "tier-artifact", "name": "Tier assignment register", "description": "Versioned local record of tier and benefit eligibility assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "activity-bundle", "name": "Reward activity", "description": "Capture earning and corrective entries with attribution.", "rationale": "Authored grouping of cited concerns; sources support the concepts, not this hierarchy or an executable profile.", "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ], "layers": [ { "id": "earning-layer", "name": "Earned reward activity", "description": "Record qualified activity and attributed credit separately from estimates, using versioned rule evidence and source event identity.", "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ], "findings": [ { "id": "earning-finding", "name": "Earned reward activity", "description": "Record qualified activity and attributed credit separately from estimates, using versioned rule evidence and source event identity.", "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ], "questions": [ { "id": "earning-q1", "text": "Which source purchase or other qualifying activity supports this reward credit?", "kind": "event", "answer_data": [ "source_event_ref", "activity_type", "occurred_at", "evidence_refs" ] }, { "id": "earning-q2", "text": "What quantity and unit were credited under which earning rule and rounding policy?", "kind": "measurement", "answer_data": [ "quantity", "unit", "rule_revision", "rounding_policy", "input_basis" ] }, { "id": "earning-q3", "text": "How are duplicate, delayed or corrected earning events identified without repeating credits?", "kind": "validation", "answer_data": [ "event_key", "source_revision", "ingestion_time", "duplicate_status" ] }, { "id": "earning-q4", "text": "Is the award estimated, pending, posted, rejected or unresolved in its authoritative system?", "kind": "state", "answer_data": [ "award_status", "as_of", "authority_ref", "reason" ] } ], "data_elements": [ { "id": "earning-data-credit", "name": "Credit", "description": "Candidate object fields: event_key, source_event_ref, quantity, unit, rule_revision, status. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] }, { "id": "earning-data-basis", "name": "Basis", "description": "Candidate object fields: input_basis, rounding_policy, occurred_at, observed_at, source_revision. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "earning-artifact", "name": "Reward earning journal", "description": "Versioned local record of earned reward activity assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "adjustments-layer", "name": "Corrections and transfers", "description": "Preserve linked correction evidence rather than overwriting prior amounts; transfers and pooling require an explicit adopted profile.", "source_refs": [ "SRC-007", "SRC-009" ], "findings": [ { "id": "adjustments-finding", "name": "Corrections and transfers", "description": "Preserve linked correction evidence rather than overwriting prior amounts; transfers and pooling require an explicit adopted profile.", "source_refs": [ "SRC-007", "SRC-009" ], "questions": [ { "id": "adjustments-q1", "text": "Which original entry does this return, correction or reversal qualify?", "kind": "provenance", "answer_data": [ "original_entry_ref", "correction_ref", "reason", "source_evidence" ] }, { "id": "adjustments-q2", "text": "Who approved a manual adjustment and which limit or exception was applied?", "kind": "authority", "answer_data": [ "actor_ref", "approval_ref", "authority_limit", "exception_ref" ] }, { "id": "adjustments-q3", "text": "What rule governs insufficient available points after a refund or reversal?", "kind": "constraint", "answer_data": [ "rule_ref", "available_quantity", "negative_balance_policy", "unresolved_status" ] }, { "id": "adjustments-q4", "text": "If transfer or pooling is enabled, which paired records and conversion rules reconcile both sides?", "kind": "interoperability", "answer_data": [ "profile_ref", "source_entry_ref", "destination_entry_ref", "conversion", "rounding", "reconciliation_status" ] } ], "data_elements": [ { "id": "adjustments-data-adjustment", "name": "Adjustment", "description": "Candidate object fields: original_entry_ref, correction_ref, signed_quantity, unit, reason, approval_ref. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "adjustments-data-transfer", "name": "Transfer", "description": "Candidate object fields: profile_ref, paired_refs, conversion, rounding, reconciliation_status. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "adjustments-artifact", "name": "Adjustment linkage register", "description": "Versioned local record of corrections and transfers assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "value-bundle", "name": "Balances and expiry", "description": "Describe qualified quantities and changes in usable rights.", "rationale": "Authored grouping of cited concerns; sources support the concepts, not this hierarchy or an executable profile.", "source_refs": [ "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ], "layers": [ { "id": "balance-layer", "name": "Balance and reconciliation", "description": "Distinguish total, reserved, pending and available quantities by program unit and observation time. A local projection never overrides a master balance.", "source_refs": [ "SRC-002", "SRC-007", "SRC-009" ], "findings": [ { "id": "balance-finding", "name": "Balance and reconciliation", "description": "Distinguish total, reserved, pending and available quantities by program unit and observation time. A local projection never overrides a master balance.", "source_refs": [ "SRC-002", "SRC-007", "SRC-009" ], "questions": [ { "id": "balance-q1", "text": "Which balance quantities, units and inclusion rules describe this account snapshot?", "kind": "measurement", "answer_data": [ "unit", "posted_quantity", "reserved_quantity", "available_quantity", "pending_quantity", "inclusion_rule" ] }, { "id": "balance-q2", "text": "At what effective time and ingestion time was the snapshot observed?", "kind": "temporal", "answer_data": [ "effective_at", "observed_at", "source_revision", "precision", "timezone" ] }, { "id": "balance-q3", "text": "Which event sequence and reconciliation evidence support the displayed available amount?", "kind": "quality", "answer_data": [ "opening_ref", "event_refs", "closing_ref", "reconciliation_result", "unresolved_difference" ] }, { "id": "balance-q4", "text": "What prevents double counting of a reserved award when it is redeemed or released?", "kind": "validation", "answer_data": [ "reservation_ref", "state_mapping", "entry_refs", "invariant_result" ] } ], "data_elements": [ { "id": "balance-data-snapshot", "name": "Snapshot", "description": "Candidate object fields: unit, quantities, inclusion_rule, effective_at, observed_at, source_revision. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007", "SRC-009" ] }, { "id": "balance-data-reconciliation", "name": "Reconciliation", "description": "Candidate object fields: opening_ref, event_refs, closing_ref, difference, result. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "balance-artifact", "name": "Qualified balance snapshot", "description": "Versioned local record of balance and reconciliation assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-002", "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "expiry-layer", "name": "Expiry and value change", "description": "Track applicable lot or inactivity conditions, notification evidence and observed expiry separately from program change and accounting estimates.", "source_refs": [ "SRC-004", "SRC-007", "SRC-008" ], "findings": [ { "id": "expiry-finding", "name": "Expiry and value change", "description": "Track applicable lot or inactivity conditions, notification evidence and observed expiry separately from program change and accounting estimates.", "source_refs": [ "SRC-004", "SRC-007", "SRC-008" ], "questions": [ { "id": "expiry-q1", "text": "Which contractual expiry rule applies to each affected lot or account activity window?", "kind": "retention", "answer_data": [ "lot_ref", "rule_ref", "expiry_condition", "activity_window", "timezone" ] }, { "id": "expiry-q2", "text": "What notice and opportunity-to-use evidence exists for the affected balance?", "kind": "evidence", "answer_data": [ "notice_ref", "delivered_at", "delivery_status", "opportunity_basis" ] }, { "id": "expiry-q3", "text": "Which expiry, reinstatement or value-change event was actually recorded by the master?", "kind": "event", "answer_data": [ "event_ref", "event_kind", "quantity", "unit", "recorded_at", "rule_revision" ] }, { "id": "expiry-q4", "text": "What review separates member entitlement effects from accounting breakage or valuation estimates?", "kind": "constraint", "answer_data": [ "rights_assessment_ref", "accounting_assessment_ref", "reviewer", "unresolved_classification" ] } ], "data_elements": [ { "id": "expiry-data-expiry", "name": "Expiry", "description": "Candidate object fields: lot_ref, rule_ref, due_value, timezone, notice_refs, observed_event_ref. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-007", "SRC-008" ] }, { "id": "expiry-data-value-review", "name": "Value Review", "description": "Candidate object fields: change_ref, rights_assessment_ref, accounting_ref, unresolved_effect. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "expiry-artifact", "name": "Expiry and change assessment", "description": "Versioned local record of expiry and value change assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-004", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "claims-bundle", "name": "Benefit claims and outcomes", "description": "Trace instructions, reservations and delivered or disputed outcomes.", "rationale": "Authored grouping of cited concerns; sources support the concepts, not this hierarchy or an executable profile.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007", "SRC-009" ], "layers": [ { "id": "redemption-layer", "name": "Redemption intent and reservation", "description": "Keep a member instruction, eligibility assessment, reservation and external acceptance separate; pending outcomes remain unknown after timeouts.", "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ], "findings": [ { "id": "redemption-finding", "name": "Redemption intent and reservation", "description": "Keep a member instruction, eligibility assessment, reservation and external acceptance separate; pending outcomes remain unknown after timeouts.", "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ], "questions": [ { "id": "redemption-q1", "text": "What member instruction authorizes this particular benefit claim?", "kind": "authority", "answer_data": [ "instruction_ref", "actor_ref", "mandate_ref", "benefit_ref", "scope" ] }, { "id": "redemption-q2", "text": "Which benefit revision, point cost, fees, availability and exclusions were presented?", "kind": "constraint", "answer_data": [ "offer_ref", "revision", "point_cost", "unit", "fees", "availability_as_of", "exclusions" ] }, { "id": "redemption-q3", "text": "What reservation or claim acknowledgement links the request to the authoritative system?", "kind": "process", "answer_data": [ "request_key", "reservation_ref", "acknowledgement_ref", "source_state" ] }, { "id": "redemption-q4", "text": "How is an uncertain response resolved before any retry or release is proposed?", "kind": "exception", "answer_data": [ "correlation_key", "lookup_result", "timeout_at", "unresolved_status", "release_evidence" ] } ], "data_elements": [ { "id": "redemption-data-request", "name": "Request", "description": "Candidate object fields: request_key, instruction_ref, benefit_ref, cost, fees, presented_revision. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] }, { "id": "redemption-data-reservation", "name": "Reservation", "description": "Candidate object fields: reservation_ref, acknowledgement_ref, source_state, correlation_key. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "redemption-artifact", "name": "Redemption evidence record", "description": "Versioned local record of redemption intent and reservation assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "fulfillment-layer", "name": "Outcome and remediation", "description": "Link redemption outcomes to fulfillment evidence without assuming a recorded redemption delivered the promised benefit.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ], "findings": [ { "id": "fulfillment-finding", "name": "Outcome and remediation", "description": "Link redemption outcomes to fulfillment evidence without assuming a recorded redemption delivered the promised benefit.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ], "questions": [ { "id": "fulfillment-q1", "text": "Which authoritative outcome confirms redemption, rejection, cancellation or an unresolved claim?", "kind": "state", "answer_data": [ "outcome_ref", "source_state", "occurred_at", "evidence_refs" ] }, { "id": "fulfillment-q2", "text": "Which separate fulfillment or benefit-use evidence supports completion?", "kind": "evidence", "answer_data": [ "fulfillment_ref", "beneficiary_ref", "confirmation_status", "delivered_at" ] }, { "id": "fulfillment-q3", "text": "What release, refund or replacement was authorized after a failed or partial outcome?", "kind": "process", "answer_data": [ "remedy_ref", "approval_ref", "linked_entries", "residual_right" ] }, { "id": "fulfillment-q4", "text": "Which partner is responsible for the benefit and which external dispute record handles an unresolved failure?", "kind": "relationship", "answer_data": [ "partner_ref", "responsibility_ref", "dispute_ref", "escalation_route" ] } ], "data_elements": [ { "id": "fulfillment-data-outcome", "name": "Outcome", "description": "Candidate object fields: request_ref, outcome_ref, source_state, fulfillment_ref, status. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] }, { "id": "fulfillment-data-remedy", "name": "Remedy", "description": "Candidate object fields: remedy_ref, authorization_ref, linked_entries, residual_right, dispute_ref. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "fulfillment-artifact", "name": "Reward outcome register", "description": "Versioned local record of outcome and remediation assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "assurance-bundle", "name": "Protection and continuity", "description": "Govern access, review, closure and evidence exchange.", "rationale": "Authored grouping of cited concerns; sources support the concepts, not this hierarchy or an executable profile.", "source_refs": [ "SRC-004", "SRC-005", "SRC-008", "SRC-009" ], "layers": [ { "id": "protection-layer", "name": "Protection and contestability", "description": "Limit disclosure and record contested restrictions with evidence and review routes; suspicion is not proof of misuse.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009" ], "findings": [ { "id": "protection-finding", "name": "Protection and contestability", "description": "Limit disclosure and record contested restrictions with evidence and review routes; suspicion is not proof of misuse.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009" ], "questions": [ { "id": "protection-q1", "text": "Which recipient can inspect this membership, balance or reward artifact for which purpose?", "kind": "access", "answer_data": [ "recipient_role", "scope", "purpose", "permission_ref" ] }, { "id": "protection-q2", "text": "Which recorded security concern supports a limited restriction and who reviews it?", "kind": "security", "answer_data": [ "concern_ref", "evidence_ref", "restriction_scope", "review_role", "review_due" ] }, { "id": "protection-q3", "text": "How can the member contest a denied reward or suspended benefit without exposing unrelated data?", "kind": "decision", "answer_data": [ "decision_ref", "reasons_view", "complaint_ref", "review_route" ] }, { "id": "protection-q4", "text": "What controls prevent unnecessary profiling or partner disclosure beyond the applicable purpose and basis?", "kind": "privacy", "answer_data": [ "purpose_map", "partner_scope", "basis_ref", "minimization_rule", "marketing_objection_ref" ] } ], "data_elements": [ { "id": "protection-data-restriction", "name": "Restriction", "description": "Candidate object fields: concern_ref, evidence_ref, scope, reviewer, review_due. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-009" ] }, { "id": "protection-data-contest", "name": "Contest", "description": "Candidate object fields: decision_ref, reasons_view, dispute_ref, recipient_scope, purpose_basis. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "protection-artifact", "name": "Protection and review index", "description": "Versioned local record of protection and contestability assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-004", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "continuity-layer", "name": "Closure and controlled exchange", "description": "Preserve traceable local revisions and authorized projections while separating membership closure, financial disposition and lawful payload erasure.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ], "findings": [ { "id": "continuity-finding", "name": "Closure and controlled exchange", "description": "Preserve traceable local revisions and authorized projections while separating membership closure, financial disposition and lawful payload erasure.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ], "questions": [ { "id": "continuity-q1", "text": "What closure authority and outstanding rights determine the final membership state?", "kind": "lifecycle", "answer_data": [ "closure_ref", "authority_ref", "outstanding_claim_refs", "disposition_status" ] }, { "id": "continuity-q2", "text": "Which record-specific retention, hold and erasure decisions apply after closure?", "kind": "retention", "answer_data": [ "record_class", "schedule_ref", "hold_ref", "lawful_basis", "disposal_decision" ] }, { "id": "continuity-q3", "text": "Which mapping revision preserves units, terms, state and uncertainty in an exported projection?", "kind": "interoperability", "answer_data": [ "mapping_ref", "target_profile", "revision", "loss_report", "refusal_reason" ] }, { "id": "continuity-q4", "text": "Which source revisions, transformations and integrity checks support the exported evidence?", "kind": "provenance", "answer_data": [ "source_revision", "derivation_ref", "digest", "algorithm", "access_audit_ref" ] } ], "data_elements": [ { "id": "continuity-data-closure", "name": "Closure", "description": "Candidate object fields: closure_ref, authority_ref, outstanding_refs, disposition_status. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ] }, { "id": "continuity-data-exchange", "name": "Exchange", "description": "Candidate object fields: mapping_ref, source_revision, recipient_scope, loss_report, retention_refs. Unknown, unavailable and inapplicable values must be distinct; nested instance schema and profile constraints remain to be specified.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "continuity-artifact", "name": "Closure and projection register", "description": "Versioned local record of closure and controlled exchange assertions, evidence references and unresolved assessments. External master documents are referenced with access controls.", "media_or_form": [ "structured record", "authorized human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision first; otherwise governed IRI or local opaque UUID. Entry sequence is scoped by membership and artifact class. No personal identifiers in filenames.", "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "resolve-membership", "name": "Resolve membership identity", "description": "Proposed operation, not implemented. Resolve exact master namespace, membership ID and program binding; return ambiguity rather than merge records by phone number or similar names.", "inputs": [ "namespace", "membership ID", "authorized purpose" ], "outputs": [ "resolved reference or ambiguity report" ], "preconditions": [ "Verified actor role, purpose and record-level access", "Source and profile references resolve or the operation returns an explicit refusal or unknown result", "For local mutation, expected revision and idempotency key match; stale or conflicting inputs are refused" ], "effects": [ "Read-only resolution; no enrollment or identity merge" ], "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "record-reward-evidence", "name": "Record reward event evidence", "description": "Proposed operation, not implemented. Append a local assertion from an authoritative earning, adjustment or expiry event; never credit or remove live points.", "inputs": [ "membership reference", "event ID and source revision", "quantity and unit", "rule and evidence references" ], "outputs": [ "local event revision or refusal report" ], "preconditions": [ "Verified actor role, purpose and record-level access", "Source and profile references resolve or the operation returns an explicit refusal or unknown result", "For local mutation, expected revision and idempotency key match; stale or conflicting inputs are refused" ], "effects": [ "Append attributed evidence once per source event and revision; repeated keys return the recorded result" ], "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "reconcile-balance-view", "name": "Reconcile a balance view", "description": "Proposed operation, not implemented. Compare an opening snapshot and observed events to a closing snapshot using a pinned unit and inclusion profile. Unknown or incomplete sequences produce an unresolved difference.", "inputs": [ "snapshot revisions", "event sequence", "unit and state mapping profile" ], "outputs": [ "reconciliation report with residual and completeness status" ], "preconditions": [ "Verified actor role, purpose and record-level access", "Source and profile references resolve or the operation returns an explicit refusal or unknown result", "For local mutation, expected revision and idempotency key match; stale or conflicting inputs are refused" ], "effects": [ "Produce a local assessment; no repair of the authoritative balance" ], "source_refs": [ "SRC-002", "SRC-007", "SRC-009" ] }, { "id": "record-benefit-claim", "name": "Record benefit claim evidence", "description": "Proposed operation, not implemented. Record the member instruction, quoted terms and external reservation or outcome acknowledgement. A timeout stays unresolved until correlated evidence arrives.", "inputs": [ "member instruction reference", "benefit and terms revision", "request key", "external acknowledgement" ], "outputs": [ "local claim record or refusal report" ], "preconditions": [ "Verified actor role, purpose and record-level access", "Source and profile references resolve or the operation returns an explicit refusal or unknown result", "For local mutation, expected revision and idempotency key match; stale or conflicting inputs are refused" ], "effects": [ "Append claim evidence; do not reserve, redeem, cancel, transmit or fulfill rewards" ], "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] }, { "id": "assess-expiry-context", "name": "Assess expiry context", "description": "Proposed operation, not implemented. Prepare a local review of rule applicability, affected lots and notice evidence. Report unknown rules, disputes and clock precision; do not execute expiry.", "inputs": [ "lot or activity evidence", "applicable rule revision", "observation time", "notice and dispute references" ], "outputs": [ "expiry review with unresolved conditions" ], "preconditions": [ "Verified actor role, purpose and record-level access", "Source and profile references resolve or the operation returns an explicit refusal or unknown result", "For local mutation, expected revision and idempotency key match; stale or conflicting inputs are refused" ], "effects": [ "Create review artifact; no entitlement removal or legal determination" ], "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "export-member-view", "name": "Prepare authorized member view", "description": "Proposed operation, not implemented. Create a recipient-scoped local projection and loss report; refuse mappings that omit mandatory unit, authority, uncertainty or terms qualifiers.", "inputs": [ "recipient authorization", "membership revision", "mapping and retention profile" ], "outputs": [ "local projection and access record or refusal report" ], "preconditions": [ "Verified actor role, purpose and record-level access", "Source and profile references resolve or the operation returns an explicit refusal or unknown result", "For local mutation, expected revision and idempotency key match; stale or conflicting inputs are refused" ], "effects": [ "Create local export artifact without transmission or access expansion" ], "source_refs": [ "SRC-005", "SRC-009" ] } ], "composition": [ { "target": "WM-ORG-014", "relation": "REFERENCE", "purpose": "Candidate registry parent binding; customer relationship identity and lifecycle remain outside this membership. Pin the neighbor specification before integration.", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "target": "External program definition", "relation": "REFERENCE", "purpose": "Required semantic program reference with a versioned applicability binding; no mandatory implementation package or local program administration.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "External purchase and fulfillment records", "relation": "REFERENCE", "purpose": "Qualifying activity and benefit delivery retain external master identity; no payment or fulfillment operations are imported.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "External accounting assessment", "relation": "REFERENCE", "purpose": "Optional specialist classification and valuation reference; reward points and accounting amounts must not be conflated.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "Schema.org ProgramMembership and MemberProgram", "relation": "ALIGN", "purpose": "Conceptual membership and program separation only; public markup is not permission to disclose personal records.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "target": "PROV-O", "relation": "ALIGN", "purpose": "Selected attribution and derivation mapping only; no implemented ontology conformance or authenticity guarantee.", "required": false, "source_refs": [ "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Accountable program operator role and membership record custodian with mandate evidence", "Program and member master namespaces, terms applicability profile and jurisdiction scope", "Access, retention, review and financial-classification escalation policies" ], "namespace_guidance": "Membership IDs are scoped to operator and program. Maintain evidenced aliases, never a phone number or email as permanent identity. Owner roles contain no company assignments.", "registry_links": [ "vr.wm-eco-029", "WM-ORG-014 candidate reference; version pin required before integration" ] }, "canon_and_patch": { "canonicalization_rules": [ "Keep membership, program, tier definition, reward event and external purchase IDs separate.", "Quantities require program unit and observation scope; earned lifetime, posted, reserved and available values are not interchangeable." ], "patch_rules": [ "Use actor, purpose, expected revision, event key and evidence for local append or correction. Duplicate keys cannot create a second event.", "Link reversal and supersession records without inventing authoritative balance changes; restrict or erase payload where a lawful disposition requires it." ], "compatibility_rules": [ "Pin rule, mapping and API profiles. Refuse silent conversion of member tier to reward price bracket or points to currency.", "Program rule changes require explicit applicability review; latest text cannot silently rewrite earlier rights." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with namespace and revision", "Governed stable IRI with provenance and version", "Opaque local UUID with reconciliation status" ], "timestamp_rule": "Use RFC 3339 with seconds and an explicit UTC offset for instants. Separate occurrence, effective, observation and ingestion times. Preserve date-only expiry, local calendar, timezone, precision and unknowns rather than fabricate midnight instants.", "serial_naming_rule": "Use opaque membership key, artifact class and immutable sequence or revision; no member names, phone numbers or dates as sole identifiers.", "integrity_rule": "Record digest algorithm, content hash and derivation where available; integrity does not prove eligibility, truth, notice delivery or permission." }, "policies": [ "Single-provider reviewable draft; no independent external review or runtime conformance is claimed.", "Shared definitions, customer identity, purchases, fulfillment, payments and accounting remain separately mastered.", "Use applicable purposes and lawful bases. Enrollment is not blanket marketing consent; optional preferences are independently revocable where applicable.", "Only an adopted profile can authorize live credit, redemption, transfer, expiry or suspension; all functions here operate on local evidence.", "Escalate harmful changes, contested restrictions and financially material adjustments to accountable reviewers; suspicion alone is not proof." ], "crud": { "read": [ "Return only recipient-authorized membership fields with units, as-of time and uncertainty." ], "create": [ "Require a master-qualified membership reference, member/program bindings and enrollment evidence or explicitly pending verification." ], "update": [ "Append supported local assertions with optimistic concurrency and duplicate-event checks; preserve disputes and source references." ], "delete": [ "Apply per-record retention schedules, legal holds and lawful erasure decisions. Retire identity with a minimal non-identifying tombstone where lawful; do not retain personal audit payload indefinitely.", "Membership closure, erasure of local payload and forfeiture of outstanding rewards are separate decisions. Local deletion does not delete the authoritative account or extinguish claims." ] }, "roles": [ { "name": "Program steward", "responsibilities": [ "Maintain applicable rule references and accountable operator mandates" ] }, { "name": "Membership custodian", "responsibilities": [ "Maintain membership continuity and evidence quality" ] }, { "name": "Authorized member or representative", "responsibilities": [ "Inspect the permitted view and provide scoped benefit instructions" ] }, { "name": "Reward reviewer", "responsibilities": [ "Review disputed entries, harmful changes and exceptional adjustments" ] }, { "name": "Privacy and records officer", "responsibilities": [ "Govern access, purposes, retention, holds and erasure" ] } ], "access": { "default_rule": "Deny personal membership access unless actor, recipient, purpose and scope are authorized. Public program descriptions do not make balances public.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Statutory or incident access requires recorded authority, narrow scope and subsequent review; no blanket administrative bypass." ], "audit_requirements": [ "Record access, local edits, exports and disposition with actor, purpose, revision, scope and outcome under a minimal-data retention schedule." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md and owner access policies", "spec.yaml and publication holds", "Pinned terms, master records and recipient-specific profile" ] } }, "coverage": { "claim": "Source-grounded proposed context for one loyalty membership relationship and its benefit lifecycle. The hierarchy is authored research with selected primary evidence and explicit regional, implementation and source-verification limits; it is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Program-qualified persistent membership relationship with separate master references." }, { "dimension": "lifecycle", "status": "covered", "notes": "Enrollment, benefits, activity, claims, restriction and closure." }, { "dimension": "relationships", "status": "covered", "notes": "Program, customer, purchase, fulfillment and accounting masters are external." }, { "dimension": "temporal", "status": "covered", "notes": "Effective, event and observation times plus explicit expiry precision." }, { "dimension": "provenance", "status": "covered", "notes": "Attributed event evidence, correction and derivation links." }, { "dimension": "ownership", "status": "covered", "notes": "Generic accountable operator and custodian roles with mandates." }, { "dimension": "validation", "status": "gap", "notes": "Research gates only; nested profiles and executable fixtures pending." }, { "dimension": "access", "status": "covered", "notes": "Recipient, purpose and scope controls with contestability." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Closure and payload erasure separated; lawful holds and minimal tombstones." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual alignments and proposed loss reports; no implemented binding." }, { "dimension": "direct properties", "status": "covered", "notes": "Nonphysical properties include unit, status, eligibility and quantity; physical measurement of this relationship is inapplicable." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Evidence distinguishes membership, shared program, customer account and coupon." }, { "dimension": "capabilities and hazards", "status": "covered", "notes": "Six proposed local operations; duplicate credits, double spending, privacy loss and unfair forfeiture are explicit concerns." }, { "dimension": "context and evidence", "status": "covered", "notes": "Rule revisions, jurisdictions, records and assessments retained with unknown status." }, { "dimension": "regional and accounting profiles", "status": "gap", "notes": "Australian guidance and an EU privacy example do not establish universal law or accounting treatment." } ], "known_omissions": [ "Independent external review remains waived; local self-audit is not provider agreement.", "Direct HTTP status is unmeasured under the owner-reported sandbox block; current versions, source licensing and claim applicability need coordinator review.", "No executable nested instance schema, event ordering protocol, concurrency implementation or adversarial fixtures are delivered.", "Accounting classification, tax, unclaimed property, financial regulation, current consumer law and local privacy applicability require qualified profile work.", "Household pooling, coalition settlement, migration, transferable rewards and complex cross-border cases remain profile gaps.", "Schema.org development pages and vendor API docs require release pins and tested mappings before operational use." ], "conflicts": [], "regional_assumptions": [ "Australian loyalty guidance includes historical 2019 reform recommendations, not a verified statement of all current law.", "The EU original GDPR text is a selected privacy source, not a universal applicability determination.", "Vendor documentation is an implementation example; its phone mapping, country list, states and constraints are not universal requirements." ], "adversarial_checks": [ "Reject merging memberships by shared phone number or customer similarity.", "Reject equating member rank with reward price bracket.", "Reject assuming every program has points, every point is money or every paid program is outside scope.", "Reject counting reserved points twice or treating timeout as failure proof.", "Reject interpreting consent withdrawal as automatic forfeiture or closure as lawful erasure of every record.", "Reject current accounting advice from superseded IFRIC 13 or API conformance from descriptive source references." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "relationship", "status": "accepted", "rationale": "The stable root connects one member and one program across events and status changes. Relationship is defensible; shared program definitions and event identities remain separate. The registry standalone-mm label is not a subject-kind enum." }, "decisions": [ { "concept": "Membership boundary", "disposition": "accepted", "rationale": "The stable root connects one member and one program across events and status changes. Relationship is defensible; shared program definitions and event identities remain separate. The registry standalone-mm label is not a subject-kind enum." }, { "concept": "Customer relationship parent", "disposition": "qualified", "rationale": "The parent candidate is preserved as a reference to WM-ORG-014 without importing customer identity, lifecycle or functions. There is no explicit relation-ledger edge to override and no legacy alias to reconcile." }, { "concept": "Program reference requirement", "disposition": "accepted with distinction", "rationale": "A program reference is semantically necessary. Composition required=false indicates no mandatory runtime package dependency; it does not make program identity optional. This distinction is explicit in the composition purpose." }, { "concept": "Terms and enrollment authority", "disposition": "accepted", "rationale": "Applicable rule revision, notice, acceptance evidence and event time are distinguished. Enrollment does not imply optional marketing consent or a universal processing basis. Unknown legal effects remain unknown." }, { "concept": "Membership tiers and reward brackets", "disposition": "separated", "rationale": "Member rank is distinct from a vendor reward cost bracket. A paid tier or a program without points remains within the membership boundary. Shared definitions and billing remain external." }, { "concept": "Credits and corrections", "disposition": "accepted as evidence", "rationale": "Activity, source revision, quantity and unit are qualified. Corrections link original entries rather than replacing them. Transfer and pooling are elicitation concerns held for a profile, not assumed portable rights." }, { "concept": "Balance and reservation", "disposition": "accepted with conformance hold", "rationale": "Available, posted, reserved and pending values require a pinned inclusion profile. Duplicate-event and double-counting checks are proposed safeguards, not an implemented ledger or balance-repair engine." }, { "concept": "Expiry and financial value", "disposition": "qualified", "rationale": "Expiry and notice are reviewed under an applicable rule, without fixed universal periods. Member rights and accounting assessments remain separate; superseded IFRIC 13 cannot justify a current liability or cash-equivalence claim." }, { "concept": "Redemption and fulfillment", "disposition": "separated", "rationale": "Member instruction, reservation, acknowledgement, redemption and fulfillment evidence have distinct roles. Timeout remains unresolved, and a failed or partial outcome needs an evidenced remedy rather than automatic forfeiture or retry." }, { "concept": "Restriction and contestability", "disposition": "accepted", "rationale": "A concern or suspicion does not establish misuse. Limited restrictions, review roles, recipient-scoped reasons and external dispute references avoid importing fraud adjudication or a generic case lifecycle." }, { "concept": "Closure and privacy continuity", "disposition": "accepted with profile dependency", "rationale": "Closure, reward disposition and local erasure are distinct. Record-specific retention and minimal lawful tombstones reconcile audit continuity with erasure without requiring perpetual personal payload storage." }, { "concept": "Functions, artifacts and service layers", "disposition": "accepted as proposed", "rationale": "All six functions are unimplemented local evidence operations with access, evidence, revision and refusal preconditions. Artifact master identity, qualified times and all eight service sections are present; no function changes a live reward account or sends messages." }, { "concept": "Source scope and independent assurance", "disposition": "held", "rationale": "Nine primary pages were accessible through browser text, with selected concepts reviewed. Direct HTTP was not attempted and no status was measured. Release pins, current law, accounting applicability and independent external review remain open; this is a local Codex self-audit only." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not an independent second-provider review.", "Live source and version verification remains incomplete. Direct HTTP was not attempted under the owner-reported sandbox restriction; all statuses are unmeasured and zero HTTP 200 responses were measured. Browser text access is documented separately. The coordinator must run check_sources.py, verify content, release pins, current versions and licensing; HTTP success alone cannot close substantive review.", "Adopting program, jurisdiction, accounting, privacy and consumer-protection profiles require qualified review. Historical IFRIC 13 and 2019 recommendations are not current operational rules. Transfer, pooling, coalition settlement, migration and cross-border coverage remain incomplete.", "Nested instance schemas, exact numeric and state invariants, event ordering, concurrency, neighbor version pins, API and vocabulary mappings, and adversarial conformance fixtures are unimplemented. Structural validation is not runtime, accounting or legal certification.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore independent external review before any canonical or publishable-draft promotion.", "Verify current source releases, legal and accounting applicability and approved terms profiles; research pooled and coalition programs before extending scope.", "Develop nested schemas, pinned mappings and fixtures for duplicate events, reversed credits after redemption, concurrent claims, clock boundaries, failed fulfillment and lawful erasure." ] }, "statistics": { "sources": 9, "bundles": 6, "layers": 12, "findings": 12, "questions": 48, "artifacts": 12, "functions": 6 } }