# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T20:38:19Z", "synthesisSha256": "31401bf00325f51a00b710c841cc1dfc7e378cd2ac474d10e134ebc8301768b8", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-FLW-002", "registryId": "vr.wm-flw-002", "name": "Water Supply", "version": "0.1.0", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Physical world and living systems", "industry": [ "Cross-industry" ], "domain": [ "PHY.FLW.H2O" ], "tags": [ "water", "supply", "phy.flw.h2o" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-flw-002-water-supply/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-flw-002", "model": { "registry_id": "vr.wm-flw-002", "model_id": "WM-FLW-002", "name": "Water Supply", "entry_kind": "aggregate", "purpose": "Describe a governed water supply system and its evidence of source, treatment, delivery, quality and continuity.", "scope_statement": "One declared supply-system aggregate links independently mastered sources, facilities, zones and delivery points across an effective period. Drinking-water service is the core profile; nonpotable use must carry an explicit separate profile. The aggregate owns supply-specific assertions and evidence references, not the assets, water bodies, regulator, laboratory or physical controls.", "in_scope": [ "System identity, service area, intended use, accountable roles and responsibility interfaces", "Source and abstraction evidence, treatment assurance, monitoring and quality assessment references", "Time-qualified distribution, storage, supply quantity, continuity and authorized communication records" ], "out_of_scope": [ "Food production, agricultural lots, food processing, cold chains and food recalls belong to WM-FLW-003", "Water body hydrology, land and asset master lifecycles, energy dispatch, generic consignment custody, wastewater and residuals processing", "Engineering design, treatment dosing, network actuation, emergency command, public notice issuance, billing and legal compliance certification" ], "boundary_notes": [ { "neighbor": "Legacy F4 and WM-FLW-003 Food Supply Chain", "distinction": "F4 mixed water and food. Retain only water supply concerns. Do not require a batch for continuous flow or retain agriculture and cold-chain layers. The unreviewed supplement repeats this scope leakage and is not evidence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] }, { "neighbor": "WM-PLC-003 Water Body and WM-PLC-002 Land Parcel", "distinction": "Reference catchments, water bodies and locations; keep hydrologic behavior, rights registers and parcel identity externally mastered.", "source_refs": [ "SRC-003" ] }, { "neighbor": "WM-FLW-004 Goods Movement / Logistics and WM-FLW-001 Energy", "distinction": "Optional delivery and energy dependency references do not imply generic logistics inheritance for a continuous pipe network.", "source_refs": [ "SRC-003", "SRC-005" ] }, { "neighbor": "Premise plumbing, wastewater and treatment assets", "distinction": "Record the point of supply separately from the compliance point and consumer tap. Link premise responsibilities and residual handoffs without taking ownership of those systems.", "source_refs": [ "SRC-003", "SRC-004" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Water safety plan manual, second edition", "organization": "World Health Organization", "url": "https://www.who.int/publications/i/item/9789240067691", "version_or_date": "2023-03-01; ISBN 9789240067691", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:35:53Z", "relevance": "Official overview and module index support risk planning, monitoring, management, climate resilience and equity. Full manual and corrigendum not reviewed." }, { "id": "SRC-002", "title": "Guidelines for drinking-water quality, fourth edition incorporating the first and second addenda", "organization": "World Health Organization", "url": "https://www.who.int/publications/i/item/9789240045064", "version_or_date": "2022-03-21; ISBN 9789240045064; historical pinned overview, not a latest-edition claim", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:35:53Z", "relevance": "Overview supports health-based targets, catchment-to-consumer planning and independent surveillance. Numeric limits are not imported; later addenda and corrigenda require verification." }, { "id": "SRC-003", "title": "Directive (EU) 2020/2184 on the quality of water intended for human consumption", "organization": "European Union", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A32020L2184", "version_or_date": "Original Official Journal text, 2020-12-23; current consolidation and national implementation unverified", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:35:53Z", "relevance": "Selected Articles 5-9 and 14 support profile-specific standards, supply/compliance boundaries, risk management and authorized remedial communication. EU example only." }, { "id": "SRC-004", "title": "Drinking Water Distribution System Tools and Resources", "organization": "United States Environmental Protection Agency", "url": "https://www.epa.gov/dwreginfo/drinking-water-distribution-system-tools-and-resources", "version_or_date": "Official resource page accessed 2026-10-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:35:53Z", "relevance": "Topic index supports distribution integrity, pressure, water age, storage, losses and backflow concerns. Linked technical papers not all reviewed; no universal operating limits inferred." }, { "id": "SRC-005", "title": "EPANET", "organization": "United States Environmental Protection Agency", "url": "https://www.epa.gov/water-research/epanet", "version_or_date": "Official overview of EPANET 2.2; page updated 2026-09-09", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:35:53Z", "relevance": "Capabilities section supports time-dependent network topology, hydraulic quantities, storage, mixing and source-fraction simulation. Simulation is not an observation or safety certificate." }, { "id": "SRC-006", "title": "OGC SensorThings API Part 1: Sensing Version 1.1", "organization": "Open Geospatial Consortium", "url": "https://docs.ogc.org/is/18-088/18-088.html", "version_or_date": "1.1; 18-088; 2021-08-04", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:35:53Z", "relevance": "Section 8.2 supplies conceptual observation, sensor, observed property, feature of interest, time and unit distinctions. No API implementation conformance claimed." }, { "id": "SRC-007", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:35:53Z", "relevance": "Entity, activity, attribution and derivation concepts support evidence lineage. Provenance does not establish truth, ownership or authority." }, { "id": "SRC-008", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "RFC 3339; July 2002; section 5.6", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:35:53Z", "relevance": "Timestamp syntax supports seconds and explicit offsets. Interval conventions, clock uncertainty and ingestion distinctions are proposed local profile rules." } ], "structure": { "bundles": [ { "id": "bundle-boundary", "name": "Supply identity and responsibility", "description": "Define the system, use profile and accountable interfaces.", "rationale": "Groups supply-specific decisions with explicit evidence and external ownership boundaries.", "source_refs": [ "SRC-001", "SRC-003" ], "layers": [ { "id": "layer-identity", "name": "System identity and service boundary", "description": "Proposed aggregate boundary ties a service area and intended use to time-qualified member references; membership does not transfer asset ownership.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ], "findings": [ { "id": "finding-identity", "name": "System identity and service boundary", "description": "Proposed aggregate boundary ties a service area and intended use to time-qualified member references; membership does not transfer asset ownership.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ], "questions": [ { "id": "q-identity-1", "text": "Which master identifier and aliases identify this supply system across renaming or operator change?", "kind": "identity", "answer_data": [ "system_master_id", "aliases", "predecessor_successor_refs" ] }, { "id": "q-identity-2", "text": "Which intended uses and delivery modes define the service profile and its exclusions?", "kind": "classification", "answer_data": [ "intended_use", "piped_or_delivered", "profile_version", "exclusions" ] }, { "id": "q-identity-3", "text": "What service-area geometry and effective dates determine the included zones and delivery points?", "kind": "spatial", "answer_data": [ "service_area", "crs", "zone_refs", "valid_from", "valid_to" ] } ], "data_elements": [ { "id": "data-identity-1", "name": "identity_profile", "description": "Master identifier, aliases, use class, delivery mode and succession references.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "data-identity-2", "name": "service_boundary", "description": "Geometry with CRS, membership references and effective interval; unknown coverage remains explicit.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-identity", "name": "Supply boundary register", "description": "Versioned evidence for system identity and service boundary, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-authority", "name": "Responsibility and applicable profile", "description": "Responsibility, regulatory applicability and data stewardship are distinct assertions. A supplier handoff need not coincide with a legal compliance location.", "source_refs": [ "SRC-003", "SRC-007" ], "findings": [ { "id": "finding-authority", "name": "Responsibility and applicable profile", "description": "Responsibility, regulatory applicability and data stewardship are distinct assertions. A supplier handoff need not coincide with a legal compliance location.", "source_refs": [ "SRC-003", "SRC-007" ], "questions": [ { "id": "q-authority-1", "text": "Which role stewards each segment and evidence record without assuming ownership of every linked asset?", "kind": "ownership", "answer_data": [ "segment_ref", "steward_role", "master_system", "delegation_ref" ] }, { "id": "q-authority-2", "text": "Which jurisdiction, competent authority and versioned rules govern this use and supply size?", "kind": "authority", "answer_data": [ "jurisdiction", "authority_ref", "rule_version", "applicability", "exemption_basis" ] }, { "id": "q-authority-3", "text": "Where do supplier responsibility, premise responsibility and compliance-point boundaries differ?", "kind": "relationship", "answer_data": [ "point_of_supply", "compliance_point", "premise_steward_ref", "interface_agreement" ] } ], "data_elements": [ { "id": "data-authority-1", "name": "responsibility_map", "description": "Segment, steward role, competence basis and effective period.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "data-authority-2", "name": "applicable_profile", "description": "Rule references and versions, applicability decision, compliance points and supported exceptions.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-authority", "name": "Responsibility and profile record", "description": "Versioned evidence for responsibility and applicable profile, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-source", "name": "Sources and resource availability", "description": "Connect source context to recorded abstractions and supply availability.", "rationale": "Groups supply-specific decisions with explicit evidence and external ownership boundaries.", "source_refs": [ "SRC-001", "SRC-003" ], "layers": [ { "id": "layer-origin", "name": "Source context and protection", "description": "Source context references catchment and raw-water risk evidence. This model does not calculate hydrology or grant abstraction rights.", "source_refs": [ "SRC-001", "SRC-003" ], "findings": [ { "id": "finding-origin", "name": "Source context and protection", "description": "Source context references catchment and raw-water risk evidence. This model does not calculate hydrology or grant abstraction rights.", "source_refs": [ "SRC-001", "SRC-003" ], "questions": [ { "id": "q-origin-1", "text": "Which water bodies, intakes or bulk suppliers contribute to this system and during which periods?", "kind": "composition", "answer_data": [ "source_ref", "intake_ref", "bulk_supplier_ref", "effective_interval" ] }, { "id": "q-origin-2", "text": "Which catchment assessment and protection records support the identified source risks?", "kind": "evidence", "answer_data": [ "assessment_ref", "protection_zone_ref", "risk_review_date", "unknowns" ] }, { "id": "q-origin-3", "text": "How are source substitution and blending changes recorded when provenance is incomplete?", "kind": "exception", "answer_data": [ "source_change_event", "known_contributors", "unknown_fraction", "review_state" ] } ], "data_elements": [ { "id": "data-origin-1", "name": "source_bindings", "description": "Externally mastered origin and intake references with participation intervals.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "data-origin-2", "name": "source_risk_context", "description": "Assessment and protection references, review time, uncertainty and accountable role.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-origin", "name": "Source context dossier", "description": "Versioned evidence for source context and protection, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-quantity", "name": "Abstraction and availability evidence", "description": "Record permitted, measured and estimated quantities distinctly. A capacity figure does not establish sustainable yield or a right to abstract.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "findings": [ { "id": "finding-quantity", "name": "Abstraction and availability evidence", "description": "Record permitted, measured and estimated quantities distinctly. A capacity figure does not establish sustainable yield or a right to abstract.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-quantity-1", "text": "Which permit or supply agreement, if applicable, constrains abstraction for the recorded interval?", "kind": "requirement", "answer_data": [ "authorization_ref", "effective_interval", "quantity_basis", "exception_basis" ] }, { "id": "q-quantity-2", "text": "What volume or flow was measured or estimated at each intake with units and uncertainty?", "kind": "measurement", "answer_data": [ "intake_ref", "quantity", "unit", "method", "uncertainty", "interval", "quality_flag" ] }, { "id": "q-quantity-3", "text": "Which seasonal, drought or dependency assumptions limit the stated available capacity?", "kind": "constraint", "answer_data": [ "availability_estimate", "scenario_ref", "assumptions", "confidence", "validity" ] } ], "data_elements": [ { "id": "data-quantity-1", "name": "abstraction_authority", "description": "Reference to the applicable rights or contract master; local legal verification required.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] }, { "id": "data-quantity-2", "name": "quantity_observations", "description": "Value, unit, interval, method, uncertainty, quality status and measured or estimated discriminator.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-quantity", "name": "Abstraction and availability statement", "description": "Versioned evidence for abstraction and availability evidence, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance", "name": "Treatment and risk assurance", "description": "Separate preventive assurance plans from evidence of actual control performance.", "rationale": "Groups supply-specific decisions with explicit evidence and external ownership boundaries.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "layers": [ { "id": "layer-risk", "name": "Risk and improvement context", "description": "Maintain local links between hazards, control evidence, review decisions and improvement actions; no technical threat procedures or universal scoring scheme.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "findings": [ { "id": "finding-risk", "name": "Risk and improvement context", "description": "Maintain local links between hazards, control evidence, review decisions and improvement actions; no technical threat procedures or universal scoring scheme.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "questions": [ { "id": "q-risk-1", "text": "Which hazard categories and hazardous events are covered by the current supply risk assessment?", "kind": "quality", "answer_data": [ "assessment_ref", "hazard_category", "affected_segment", "scope_gaps" ] }, { "id": "q-risk-2", "text": "Who accepted the residual-risk assessment and prioritized improvements using which method?", "kind": "decision", "answer_data": [ "reviewer_role", "risk_method", "decision_ref", "priority", "uncertainty" ] }, { "id": "q-risk-3", "text": "What changes or review triggers require the safety plan and improvement register to be reconsidered?", "kind": "lifecycle", "answer_data": [ "plan_version", "review_trigger", "action_owner_role", "due_date", "closure_evidence" ] } ], "data_elements": [ { "id": "data-risk-1", "name": "risk_register", "description": "Hazard category, assessment reference, control linkage, residual uncertainty and review state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "data-risk-2", "name": "improvement_refs", "description": "Action references with accountable roles, review triggers and closure evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-risk", "name": "Supply safety assessment", "description": "Versioned evidence for risk and improvement context, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-treatment", "name": "Treatment assurance and operational monitoring", "description": "Link externally mastered treatment stages and their authorized operating envelopes to monitoring records. Monitoring completion does not certify all delivered water.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "findings": [ { "id": "finding-treatment", "name": "Treatment assurance and operational monitoring", "description": "Link externally mastered treatment stages and their authorized operating envelopes to monitoring records. Monitoring completion does not certify all delivered water.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "questions": [ { "id": "q-treatment-1", "text": "Which treatment stages and control measures apply to this water stream or identified delivered lot?", "kind": "process", "answer_data": [ "stage_refs", "stream_or_lot_ref", "process_version", "bypass_state" ] }, { "id": "q-treatment-2", "text": "What evidence validates each claimed control measure under its stated conditions?", "kind": "validation", "answer_data": [ "validation_evidence_ref", "conditions", "performance_claim", "reviewer_role" ] }, { "id": "q-treatment-3", "text": "Which operational deviations were observed and which authorized corrective-action records address them?", "kind": "event", "answer_data": [ "monitoring_ref", "deviation_event", "action_ref", "event_time", "closure_evidence" ] } ], "data_elements": [ { "id": "data-treatment-1", "name": "treatment_bindings", "description": "Stage and control-plan references, applicability, conditions and version.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "data-treatment-2", "name": "control_evidence", "description": "Monitoring observations, validation references, deviation flags and corrective-action links; no actuator commands.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-treatment", "name": "Treatment assurance record", "description": "Versioned evidence for treatment assurance and operational monitoring, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-quality", "name": "Observations and quality interpretation", "description": "Preserve sampling provenance and constrain what a quality assessment can establish.", "rationale": "Groups supply-specific decisions with explicit evidence and external ownership boundaries.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "layers": [ { "id": "layer-observation", "name": "Sampling and observation context", "description": "Observation identity and target must survive correction. A sample applies to its declared location, time and method, not automatically the entire supply.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007", "SRC-008" ], "findings": [ { "id": "finding-observation", "name": "Sampling and observation context", "description": "Observation identity and target must survive correction. A sample applies to its declared location, time and method, not automatically the entire supply.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-observation-1", "text": "Which sample or sensor observation, collection method and laboratory or instrument produced this result?", "kind": "provenance", "answer_data": [ "sample_id", "observation_id", "method_ref", "laboratory_ref", "sensor_ref", "custody_ref" ] }, { "id": "q-observation-2", "text": "How do collection time, phenomenon interval, result time and ingestion time differ?", "kind": "temporal", "answer_data": [ "collection_time", "phenomenon_interval", "result_time", "ingested_at", "clock_uncertainty" ] }, { "id": "q-observation-3", "text": "Which property, location, value, unit, detection qualifier and uncertainty describe the result?", "kind": "measurement", "answer_data": [ "observed_property", "feature_of_interest", "value", "unit", "detection_qualifier", "uncertainty", "quality_flag" ] } ], "data_elements": [ { "id": "data-observation-1", "name": "observation_binding", "description": "Master observation/sample ID, target, method, attribution and distinct time fields.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "data-observation-2", "name": "qualified_result", "description": "Value, unit, method-specific detection/quantification qualifiers, uncertainty and quality flags; missing is not zero.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-006", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-observation", "name": "Qualified observation record", "description": "Versioned evidence for sampling and observation context, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-assessment", "name": "Quality assessment and limits", "description": "An authored assessment links observations to the applicable versioned rule and comparison method. Unknown, pending and invalid inputs cannot silently become passing results.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "finding-assessment", "name": "Quality assessment and limits", "description": "An authored assessment links observations to the applicable versioned rule and comparison method. Unknown, pending and invalid inputs cannot silently become passing results.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "questions": [ { "id": "q-assessment-1", "text": "Which parameter rule, sampling plan and compliance location apply to this assessment?", "kind": "requirement", "answer_data": [ "parameter_rule_ref", "version", "sampling_plan_ref", "compliance_location", "applicability" ] }, { "id": "q-assessment-2", "text": "Were units, method suitability, sample coverage and censored results sufficient for the stated comparison?", "kind": "validation", "answer_data": [ "unit_check", "method_check", "coverage_check", "censoring_rule", "unresolved_inputs" ] }, { "id": "q-assessment-3", "text": "What assessment status and competent review evidence distinguish an exceedance flag from a safety determination?", "kind": "state", "answer_data": [ "status", "comparison_ref", "reviewer_role", "determination_ref", "reassessment_trigger" ] } ], "data_elements": [ { "id": "data-assessment-1", "name": "assessment_context", "description": "Rule pin, sampling scope, method and comparison basis; no universal numerical limits.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-assessment-2", "name": "assessment_outcome", "description": "Pass, fail, pending, unknown or invalid with reasons and authoritative determination reference where present.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-assessment", "name": "Scoped quality assessment", "description": "Versioned evidence for quality assessment and limits, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-delivery", "name": "Distribution and storage", "description": "Time-qualified network and storage assertions describe delivery without inventing complete physical traceability.", "rationale": "Groups supply-specific decisions with explicit evidence and external ownership boundaries.", "source_refs": [ "SRC-004", "SRC-005" ], "layers": [ { "id": "layer-network", "name": "Network connectivity and delivery context", "description": "Topology, pressure and delivery evidence have separate time and confidence. Continuous-flow mixing makes exact lot-to-tap attribution an unsupported default.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ], "findings": [ { "id": "finding-network", "name": "Network connectivity and delivery context", "description": "Topology, pressure and delivery evidence have separate time and confidence. Continuous-flow mixing makes exact lot-to-tap attribution an unsupported default.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-network-1", "text": "Which active network links, bulk interfaces and endpoints define the delivery path for the interval?", "kind": "relationship", "answer_data": [ "network_revision", "link_refs", "bulk_interface_refs", "endpoint_refs", "effective_interval" ] }, { "id": "q-network-2", "text": "Which pressure, flow and delivered-volume observations support the claimed service state?", "kind": "measurement", "answer_data": [ "observation_refs", "units", "interval", "measurement_conditions", "uncertainty" ] }, { "id": "q-network-3", "text": "Which simulated source fractions or water-age estimates are used and how are assumptions and calibration identified?", "kind": "interoperability", "answer_data": [ "simulation_ref", "engine_version", "input_revision", "calibration_ref", "estimate_interval", "confidence" ] } ], "data_elements": [ { "id": "data-network-1", "name": "network_snapshot", "description": "Pinned topology and endpoint references with validity and observation links.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ] }, { "id": "data-network-2", "name": "delivery_estimates", "description": "Measured or simulated discriminator, quantity and units, model inputs and uncertainty; no inferred exact consumer exposure.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-network", "name": "Distribution evidence snapshot", "description": "Versioned evidence for network connectivity and delivery context, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-storage", "name": "Storage and distribution integrity", "description": "Quantity and quality availability are separate. Reserve volume can be unavailable for supply because of restrictions or uncertain quality.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ], "findings": [ { "id": "finding-storage", "name": "Storage and distribution integrity", "description": "Quantity and quality availability are separate. Reserve volume can be unavailable for supply because of restrictions or uncertain quality.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-storage-1", "text": "What observed storage level and usable volume are supported by tank geometry, units and observation time?", "kind": "measurement", "answer_data": [ "tank_ref", "level", "volume", "geometry_ref", "units", "observed_at", "uncertainty" ] }, { "id": "q-storage-2", "text": "Which inspection, maintenance and distribution-integrity records qualify the storage or network state?", "kind": "quality", "answer_data": [ "inspection_refs", "maintenance_refs", "integrity_issue", "water_age_evidence", "review_state" ] }, { "id": "q-storage-3", "text": "Which reserve, isolation or quality restrictions limit the amount considered available for delivery?", "kind": "constraint", "answer_data": [ "restriction_ref", "available_volume", "demand_basis", "validity_interval", "unknowns" ] } ], "data_elements": [ { "id": "data-storage-1", "name": "storage_status", "description": "Tank reference, level/volume observations, geometry basis, available versus total amount and time.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ] }, { "id": "data-storage-2", "name": "integrity_context", "description": "Restricted inspection and maintenance evidence, loss/backflow concern categories and authorized response references.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-storage", "name": "Storage and integrity statement", "description": "Versioned evidence for storage and distribution integrity, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-continuity", "name": "Continuity and communication", "description": "Describe service disruption and approved communication with privacy and safety controls.", "rationale": "Groups supply-specific decisions with explicit evidence and external ownership boundaries.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "layers": [ { "id": "layer-continuity", "name": "Disruptions and recovery evidence", "description": "Record interruption scope and resilience dependencies at policy level. Local record state cannot restart a system or authorize an allocation.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "findings": [ { "id": "finding-continuity", "name": "Disruptions and recovery evidence", "description": "Record interruption scope and resilience dependencies at policy level. Local record state cannot restart a system or authorize an allocation.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "questions": [ { "id": "q-continuity-1", "text": "Which planned or unplanned interruption affected which service area and interval?", "kind": "event", "answer_data": [ "incident_ref", "affected_area", "start_time", "end_time", "planned_flag", "cause_category" ] }, { "id": "q-continuity-2", "text": "What demand, reserve, power and alternative-supply assumptions support the continuity estimate?", "kind": "constraint", "answer_data": [ "scenario_ref", "demand_basis", "dependency_refs", "alternative_supply_ref", "uncertainty" ] }, { "id": "q-continuity-3", "text": "Which authorized recovery decision and verification evidence distinguish restored service from a closed work order?", "kind": "lifecycle", "answer_data": [ "recovery_decision_ref", "verification_refs", "service_state", "effective_time", "remaining_restrictions" ] } ], "data_elements": [ { "id": "data-continuity-1", "name": "service_event", "description": "Disruption and recovery event references, affected area, times and evidence state.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] }, { "id": "data-continuity-2", "name": "continuity_scenario", "description": "Demand, usable reserve and dependencies with assumptions; equity impacts and approvals remain explicit.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-continuity", "name": "Continuity and recovery record", "description": "Versioned evidence for disruptions and recovery evidence, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-communication", "name": "Notices, access and record continuity", "description": "Link approved advisories and their scope without autonomously issuing them. Preserve correction lineage while obeying adopted retention and privacy rules.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008" ], "findings": [ { "id": "finding-communication", "name": "Notices, access and record continuity", "description": "Link approved advisories and their scope without autonomously issuing them. Preserve correction lineage while obeying adopted retention and privacy rules.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-communication-1", "text": "Which competent role approved the notice, restriction or lifting decision for the affected area?", "kind": "authority", "answer_data": [ "notice_master_id", "approval_ref", "area", "effective_interval", "supersedes_ref" ] }, { "id": "q-communication-2", "text": "Which public summary and restricted evidence views serve recipients without disclosing sensitive network or household details?", "kind": "access", "answer_data": [ "view_policy", "recipient_scope", "redaction_basis", "public_notice_ref", "access_audit_ref" ] }, { "id": "q-communication-3", "text": "Which record schedule and hold govern correction, archival transfer or lawful payload disposal?", "kind": "retention", "answer_data": [ "record_class", "retention_policy_ref", "hold_ref", "disposition_authority", "tombstone_ref" ] } ], "data_elements": [ { "id": "data-communication-1", "name": "notice_binding", "description": "Approved external notice identity, scope, versions and delivery evidence references; receipt and issue are distinct.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008" ] }, { "id": "data-communication-2", "name": "record_governance", "description": "View policy, retention schedule, holds, correction lineage and authorized disposal references.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-communication", "name": "Notice and record-governance index", "description": "Versioned evidence for notices, access and record continuity, carrying subject and time scope, author, review state, access policy and source links.", "media_or_form": [ "Structured record", "Document reference" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; owner-issued UUID or ULID last. Stable artifact identity plus distinct revision identifier; timestamp or digest alone is not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "function-register", "name": "Register supply boundary", "description": "Proposed local operation records a versioned system boundary and external master references.", "inputs": [ "system master ID", "use profile", "area and member refs", "effective interval" ], "outputs": [ "new boundary revision or refusal with unresolved references" ], "preconditions": [ "Authorized steward role, purpose and scoped access are established.", "Expected revision and referenced master identities resolve; missing authority causes refusal." ], "effects": [ "Append an attributable local record revision and validation outcome only.", "No physical actuation, rights change, external master mutation, public communication or safety certification." ], "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "function-link-observation", "name": "Link qualified observation", "description": "Proposed local operation attaches evidence without changing a laboratory or sensor master record.", "inputs": [ "observation master ID", "target", "method and result qualifiers", "time fields" ], "outputs": [ "qualified evidence link or refusal for ambiguous identity or missing qualifiers" ], "preconditions": [ "Authorized steward role, purpose and scoped access are established.", "Expected revision and referenced master identities resolve; missing authority causes refusal." ], "effects": [ "Append an attributable local record revision and validation outcome only.", "No physical actuation, rights change, external master mutation, public communication or safety certification." ], "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "function-record-assessment", "name": "Record scoped assessment", "description": "Proposed local operation records a reviewed comparison and flags unknown inputs; it does not determine potability.", "inputs": [ "observation refs", "rule version", "comparison method", "competent review reference" ], "outputs": [ "assessment record with explicit status or refusal for incompatible units or scope" ], "preconditions": [ "Authorized steward role, purpose and scoped access are established.", "Expected revision and referenced master identities resolve; missing authority causes refusal." ], "effects": [ "Append an attributable local record revision and validation outcome only.", "No physical actuation, rights change, external master mutation, public communication or safety certification." ], "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "function-record-scenario", "name": "Record delivery scenario", "description": "Proposed local operation links a supplied simulation result; it does not run hydraulic calculations or operate equipment.", "inputs": [ "network revision", "scenario output ref", "engine version", "calibration and assumptions" ], "outputs": [ "time-qualified estimate reference with uncertainty or refusal for missing input provenance" ], "preconditions": [ "Authorized steward role, purpose and scoped access are established.", "Expected revision and referenced master identities resolve; missing authority causes refusal." ], "effects": [ "Append an attributable local record revision and validation outcome only.", "No physical actuation, rights change, external master mutation, public communication or safety certification." ], "source_refs": [ "SRC-005", "SRC-007" ] }, { "id": "function-record-event", "name": "Record continuity event", "description": "Proposed local operation links interruption and recovery evidence without executing response actions.", "inputs": [ "incident reference", "affected service area", "event times", "approved recovery evidence if present" ], "outputs": [ "continuity record or unresolved recovery state" ], "preconditions": [ "Authorized steward role, purpose and scoped access are established.", "Expected revision and referenced master identities resolve; missing authority causes refusal." ], "effects": [ "Append an attributable local record revision and validation outcome only.", "No physical actuation, rights change, external master mutation, public communication or safety certification." ], "source_refs": [ "SRC-001", "SRC-003", "SRC-008" ] }, { "id": "function-project-view", "name": "Prepare authorized evidence view", "description": "Proposed local operation prepares a locally reviewable summary with approved notice links; it does not send or publish a notice.", "inputs": [ "approved view policy", "recipient scope", "selected evidence", "redaction rules" ], "outputs": [ "local view and provenance manifest or access refusal" ], "preconditions": [ "Authorized steward role, purpose and scoped access are established.", "Expected revision and referenced master identities resolve; missing authority causes refusal." ], "effects": [ "Append an attributable local record revision and validation outcome only.", "No physical actuation, rights change, external master mutation, public communication or safety certification." ], "source_refs": [ "SRC-003", "SRC-007" ] } ], "composition": [ { "target": "WM-FLW-003", "relation": "REFERENCE", "purpose": "Food supply is a separate successor to F4. Link water supplied to a food facility without copying food lots or safety processes.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "WM-PLC-003", "relation": "REFERENCE", "purpose": "Water body and catchment context remains externally mastered.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "WM-PLC-002", "relation": "REFERENCE", "purpose": "Use location and parcel references without parcel lifecycle ownership.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "WM-FLW-004", "relation": "REFERENCE", "purpose": "Optional tanker or packaged-water consignment linkage; custody remains in logistics.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "WM-FLW-001", "relation": "REFERENCE", "purpose": "Record pumping or treatment energy dependency references without dispatch control.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "OGC SensorThings API Part 1: Sensing 1.1", "relation": "ALIGN", "purpose": "Conceptual observation mapping only; executable bindings and conformance tests deferred.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "PROV-O", "relation": "ALIGN", "purpose": "Conceptual evidence attribution and derivation mapping; no ownership inference.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "EPANET 2.2", "relation": "ALIGN", "purpose": "Optional simulation evidence interface, not a required runtime or sensor source.", "required": false, "source_refs": [ "SRC-005" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "A generic supply-system steward role owns local assertion namespaces and declares external master systems.", "The adopting Dimension supplies intended use, jurisdiction, responsible roles, rule pins, units, CRS, time policy and access matrix.", "The adopting Dimension supplies retention schedules, lawful disposal authority, instance schemas and approved process bindings before operational use." ], "namespace_guidance": "Use a governed owner namespace and stable lower-kebab-case local IDs. Separate system, sample, asset, event and artifact identifiers; do not encode dates as identity.", "registry_links": [ "vr.wm-flw-002", "Candidate neighbor bindings require version pins before operational integration." ] }, "canon_and_patch": { "canonicalization_rules": [ "Preserve original evidence values and units; normalized projections record conversion and source version.", "Distinguish observed, estimated, simulated, asserted, unknown and disputed values. A missing result never means compliant." ], "patch_rules": [ "Require expected revision, authority, reason, attribution and affected time interval. Corrections supersede assertions without silently rewriting external masters.", "Changes to intended use, zone boundary, rule version or sampling context trigger impact review and new assessment references." ], "compatibility_rules": [ "Breaking identity, unit, time or boundary changes require explicit migration and a version change.", "Legacy F4 imports must remove food-only fields and preserve continuous-flow context; no wildcard standard imports or inherited conformance claims." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier", "Governed global identifier or IRI", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z. Distinguish event, collection, phenomenon, result and ingestion times. Preserve clock uncertainty; date-only values remain dates and intervals retain start/end semantics.", "serial_naming_rule": "Stable artifact identifier plus separate revision and optional sequence; a timestamp is descriptive metadata, not the sole key.", "integrity_rule": "Hash retained evidence bytes where available, record algorithm and custody/derivation links, and verify references. A digest proves neither truth nor regulatory acceptance." }, "policies": [ "Treat public health restrictions and control changes as externally authorized decisions; local functions cannot issue notices or actuate systems.", "Use minimum necessary personal data, scoped infrastructure access and approved public views. Commercial confidentiality does not override applicable disclosure duties.", "Use profile-specific quality rules and competent review; this research draft supplies no universal numerical thresholds or engineering instructions.", "Independent review, current source verification, regional applicability and executable conformance remain holds." ], "crud": { "read": [ "Resolve master identities and permissions before reading; default to restricted detailed evidence and approved public summaries." ], "create": [ "Create supply-specific assertion records with identity, scope, provenance and time; mark missing or disputed information explicitly." ], "update": [ "Append attributable revisions under concurrency control; preserve correction links and propagate stale-assessment warnings." ], "delete": [ "Apply the adopting Dimension retention schedule and legal/safety holds before retiring local records. Authorized records processes execute disposal; do not delete referenced masters.", "Preserve a minimal lawful tombstone and disposition evidence when permitted, while erasing eligible payloads and derived views as required. Version history is not a mandate for perpetual personal-data retention." ] }, "roles": [ { "name": "Supply-system steward", "responsibilities": [ "Own local assertion quality, namespace and interface references." ] }, { "name": "Water quality reviewer", "responsibilities": [ "Review sampling context, rule applicability and assessment limits." ] }, { "name": "Authorized operator", "responsibilities": [ "Supply evidence of treatment and service events; physical controls stay in separately authorized systems." ] }, { "name": "Competent oversight role", "responsibilities": [ "Provide applicable decisions, review duties and authorized notice references." ] }, { "name": "Records and access custodian", "responsibilities": [ "Maintain scoped access, lawful retention and disposal evidence." ] } ], "access": { "default_rule": "Deny detailed infrastructure and personal-data access unless authorized by purpose and role; release only approved public views.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency access must be policy-authorized, time-limited and audited; it does not grant actuation or notice authority.", "Legally required public information uses an approved view with necessary safety information and justified redactions." ], "audit_requirements": [ "Record actor role, purpose, object, time, policy version and decision for access or mutation.", "Delegate audit-trail storage and enforcement to the adopting owner service; preserve evidence links without duplicating its lifecycle." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md and adopting Dimension owner policies", "spec.yaml and publication holds", "Pinned profile and external master bindings", "Relevant evidence and authorized process before any mutation" ] } }, "coverage": { "claim": "Source-grounded proposed Water Supply aggregate with water-only legacy reconciliation and a separate local no-tools self-audit. Selected source readings support the conceptual structure; independent review, source/version checks, regional applicability and executable conformance remain holds. This is a reviewable draft, not operational or regulatory certification.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Stable system identity and member/master distinctions." }, { "dimension": "lifecycle", "status": "covered", "notes": "Boundary revisions, risk reviews, interruption and recovery records." }, { "dimension": "relationships", "status": "covered", "notes": "Candidate references preserve neighbor ownership; no known ledger edges found." }, { "dimension": "temporal", "status": "covered", "notes": "Effective intervals and distinct observation/result/ingestion times." }, { "dimension": "provenance", "status": "covered", "notes": "Attribution, qualified results, corrections and derivation references." }, { "dimension": "ownership", "status": "covered", "notes": "Generic steward, operator, reviewer and authority roles." }, { "dimension": "validation", "status": "gap", "notes": "Research schema is testable; nested instance schemas and operational acceptance tests are deferred." }, { "dimension": "access", "status": "covered", "notes": "Restricted detail, approved public views and delegated audit." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Policy-owned schedules, holds, disposal and minimal lawful tombstones." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual OGC, PROV-O and simulation alignments only." }, { "dimension": "physical quantities", "status": "covered", "notes": "Units, measurement context, uncertainty and simulation distinction." }, { "dimension": "regional applicability", "status": "gap", "notes": "EU example and global guidance do not establish a jurisdiction-specific compliance profile." }, { "dimension": "independent review", "status": "gap", "notes": "Only Codex evidence is admitted under the owner waiver." } ], "known_omissions": [ "Independent external review and complete live source/version verification.", "Nested instance schemas, unit/CRS code lists, profile fixtures, binding implementations and conformance tests.", "Small private supplies, rainwater, desalination, reuse, nonpotable service, bottled-water trade and emergency delivery require specialized profiles.", "Tariffs, billing, asset engineering, process design, hydrology, detailed leakage accounting and wastewater operations are delegated." ], "conflicts": [ "Legacy registry purpose and F4 supplement still mix food with water; this local water-only successor reconciles that mismatch without changing shared records." ], "regional_assumptions": [ "WHO material is guidance; the 2022 overview is a pinned historical source, and later addenda/corrigenda are not incorporated.", "The original EU directive is an illustrative framework, not verified current national law. No numerical limit, deadline or exemption is generalized." ], "adversarial_checks": [ "A single passing sample cannot prove all water safe across a service area and time.", "A continuous mixed network cannot promise exact batch-to-consumer lineage.", "A restored work order or simulation cannot establish safe recovery.", "A data steward is not automatically a legally competent authority.", "A public notice reference cannot authorize this model to publish one.", "A source-access timestamp does not prove current legal or technical applicability." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The root joins independently mastered source, facility, zone and delivery references within one governed supply context and effective period. It owns supply-specific assertions, not component masters. The registry standalone-mm classification describes the record plane rather than the subject-kind enum." }, "decisions": [ { "concept": "Supply aggregate boundary", "disposition": "accepted", "rationale": "The model explicitly coordinates separately mastered members and supply evidence without claiming component ownership or universal asset lifecycle control." }, { "concept": "Legacy food scope", "disposition": "rejected", "rationale": "The food layers and cold-chain operations in F4 and its supplement contradict the water-only successor. The result excludes them and keeps WM-FLW-003 as an optional reference." }, { "concept": "Mandatory batch identity", "disposition": "rejected", "rationale": "Continuous mixing is represented through source, time and network context. Lot identity remains conditional and simulated fractions cannot establish exact consumer exposure." }, { "concept": "Responsibility and compliance location", "disposition": "accepted", "rationale": "The questions distinguish system stewardship, legal competence, point of supply, premise responsibility and compliance point rather than treating them as a single boundary." }, { "concept": "Source rights and availability", "disposition": "qualified", "rationale": "The proposed quantity record asks for the actual permit or agreement where applicable and separates measurements and estimates. It grants no abstraction right or sustainable-yield certification." }, { "concept": "Treatment and risk assurance", "disposition": "qualified", "rationale": "Risk methods, control conditions and validation evidence remain profile-specific. The structure contains no universal thresholds or actionable control instructions." }, { "concept": "Sampling and assessment", "disposition": "accepted", "rationale": "Observation identity, method, scope, units and time qualify each result. Missing, invalid and censored inputs cannot silently become compliant outcomes or system-wide safety claims." }, { "concept": "Delivery and storage quantities", "disposition": "accepted", "rationale": "The draft separates topology snapshots, measurements, simulation estimates, total stored water and usable supply, with explicit assumptions and uncertainty." }, { "concept": "Recovery and notice authority", "disposition": "separated", "rationale": "Work-order closure is distinct from restored service. Notice approval and lifting decisions are externally mastered; local records and views do not issue public advice." }, { "concept": "Local functions and neighbor bindings", "disposition": "accepted as proposed", "rationale": "All six functions record or project local evidence with authority and revision preconditions. Optional links preserve external master lifecycles and no waived-provider nodes are added." }, { "concept": "Artifact identity access and retention", "disposition": "accepted with policy dependency", "rationale": "Master-first identity, separate revisions and scoped views support accountable corrections. Adopted schedules and holds govern lawful disposal without imposing perpetual payload retention." }, { "concept": "Source strength and currency", "disposition": "limited", "rationale": "Selected primary readings support a proposed conceptual draft. Full manuals, later addenda, current legal consolidation and regional applicability are unresolved; direct HTTP checks were not attempted." }, { "concept": "Operational conformance", "disposition": "deferred", "rationale": "Optional candidate groups and conceptual mappings do not constitute nested instance schemas, executable bindings or tested operational acceptance criteria." }, { "concept": "Independent review", "disposition": "waived and held", "rationale": "Claude and Grok were explicitly skipped. This separate Codex self-audit is not independent external review and cannot establish provider agreement or canonical completeness." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped; the separate local Codex no-tools self-audit is not an independent second-provider review.", "Source and version verification remains incomplete. Eight admitted URLs have selected browser evidence, but direct HTTP checks were not attempted under the sandbox restriction: zero measured HTTP 200 responses. The coordinator must run check_sources.py outside the sandbox. Full WHO documents, later addenda/corrigenda, standards errata, licenses and current legal consolidation require review.", "Qualified jurisdiction and water-domain review is required before operational adoption, including intended use, supply size, local rights, limits, sampling, premise responsibility, retention, equitable continuity and competent notice/recovery authority. No engineering or legal-compliance certification is claimed.", "Nested instance schemas, required profile fields, unit/CRS vocabularies, pinned neighbor bindings, SensorThings/PROV-O/simulation mappings and adversarial operational fixtures remain incomplete. The six functions are unimplemented local operation proposals.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Verify source availability, current editions, corrigenda, legal applicability and specialized water-supply profiles without promoting HTTP success into substantive verification.", "Develop nested schemas and test mixed sources, stale/censored observations, incompatible units, boundary handoffs, unavailable reserves, unauthorized recovery and lawful disposal.", "Restore independent external review before canonical or publishable-draft promotion." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }