← Back to catalogue
Published

Passenger Mobility

vr.wm-flw-007 · wm-flw-007-passenger-mobility

Describe a governed passenger transport service context across network, service offers, operating assertions, fares and service evidence.

World Models Physical world and living systems PHY.FLW.MOB

Bundle → Layer → Finding → Questions Filled

7 bundles · 14 layers · 14 findings · 42 questions

Service context Persistent service scope and its accountable data releases.

Identity and accountability

Define which service context is being described, its modes and coverage, and who may attest each component. Names and logos are recognition aids rather than matching keys.

Governed service scope

Define which service context is being described, its modes and coverage, and who may attest each component. Names and logos are recognition aids rather than matching keys.

  1. Which authority-qualified service scope does this aggregate identify? identity
  2. Which passenger service modes and geographic coverage belong to this scope? classification
  3. Which accountable role can approve each component and its passenger-facing use? ownership

Release provenance

Keep release identity, derivation and effective coverage distinct from the continuing service context. Retired or corrected releases remain resolvable subject to data retention limits.

Versioned service release

Keep release identity, derivation and effective coverage distinct from the continuing service context. Retired or corrected releases remain resolvable subject to data retention limits.

  1. What release state and supersession link apply to this service description? lifecycle
  2. When is the release effective and when was its content issued and ingested? temporal
  3. Which source versions and transformations support the release? provenance
Passenger service network Boarding locations and recurring service patterns.

Boarding locations

Bind service stop points to the appropriate station, platform or boarding location. Spatial assertions carry coordinate reference and provenance; a nearby point or similar name does not establish equivalence.

Boarding-place binding

Bind service stop points to the appropriate station, platform or boarding location. Spatial assertions carry coordinate reference and provenance; a nearby point or similar name does not establish equivalence.

  1. Where is boarding offered and which station or platform hierarchy applies? spatial
  2. Which public code, sign or announcement helps a passenger recognize this boarding place? evidence
  3. What evidence supports merging or separating two candidate stop references? validation

Lines and patterns

Keep a marketed line, direction and ordered stop-pattern version distinct. Repeated stops and variants require occurrence-aware ordering; geometry remains a referenced path or evidenced service projection.

Service pattern

Keep a marketed line, direction and ordered stop-pattern version distinct. Repeated stops and variants require occurrence-aware ordering; geometry remains a referenced path or evidenced service projection.

  1. Which ordered stop occurrences define this service pattern variant? composition
  2. Which operator, direction and external path are associated with this pattern? relationship
  3. Which diversions or validity restrictions change this pattern without rewriting its historical version? constraint
Service availability Calendar, time and request conditions of the published offer.

Service days and frequency

Record scheduled or headway-based offers with service-day semantics. Preserve after-midnight offsets, date exceptions and time-zone conversion rules; do not coerce service-day times into civil-day instants.

Calendar-qualified offer

Record scheduled or headway-based offers with service-day semantics. Preserve after-midnight offsets, date exceptions and time-zone conversion rules; do not coerce service-day times into civil-day instants.

  1. Which service days, exceptions and local time basis govern this offer? temporal
  2. Is this offer scheduled or frequency-based and what timing precision is promised? classification
  3. How are midnight rollover and daylight-saving ambiguities resolved for a dated occurrence? validation

Demand-responsive conditions

Describe zones, pickup windows and request channels. A booking-rule description advertises how to request service; it is neither a reservation nor proof of vehicle availability.

Flexible service offer

Describe zones, pickup windows and request channels. A booking-rule description advertises how to request service; it is neither a reservation nor proof of vehicle availability.

  1. Which zones or location groups permit pickup and drop-off for this flexible offer? spatial
  2. What booking notice, contact channel and pickup window must a passenger consult? requirement
  3. Which eligibility or capacity uncertainties require an external booking confirmation? exception
Operating assertions Dated service status and passenger-facing disruptions.

Dated service realization

Bind a schedule occurrence to an external vehicle journey when known. Preserve the schedule relationship and separate predicted, measured and unconfirmed historical values. Cancellations and no-data conditions are explicit.

Service occurrence assertion

Bind a schedule occurrence to an external vehicle journey when known. Preserve the schedule relationship and separate predicted, measured and unconfirmed historical values. Cancellations and no-data conditions are explicit.

  1. Which service date and schedule selector identify the occurrence independently of feed message identity? identity
  2. What operating state is asserted and is its timing predicted, observed or unavailable? state
  3. How fresh and consistent is the assertion relative to its source and referenced schedule? quality

Disruption communication

Represent approved advisory content, affected entities, active periods and supersession. A record describes the asserted impact; recording or withdrawing it does not dispatch vehicles or prove service restoration.

Scoped service advisory

Represent approved advisory content, affected entities, active periods and supersession. A record describes the asserted impact; recording or withdrawing it does not dispatch vehicles or prove service restoration.

  1. Which interruption or change does this advisory report and which passengers or services are affected? event
  2. Who approved this advisory text and its active periods? authority
  3. What evidence supports updating, expiring or withdrawing this advisory? lifecycle
Passenger use context Accessible interchange and external journey bindings.

Accessibility and interchange

Record location access, vehicle accommodation and transfer constraints separately. Missing accessibility evidence remains unknown; a timetable connection or one positive flag cannot guarantee an accessible journey.

Qualified access path

Record location access, vehicle accommodation and transfer constraints separately. Missing accessibility evidence remains unknown; a timetable connection or one positive flag cannot guarantee an accessible journey.

  1. Which boarding, pathway and vehicle-accommodation conditions apply to this interchange? requirement
  2. What minimum transfer time and restrictions qualify this connection? constraint
  3. Which dated evidence or disruption qualifies the current accessibility statement? evidence

Journey references

Carry optional links between an external journey leg and a service occurrence or offer. The binding has its own purpose and access decision; no personal identity is needed for the public service description.

Passenger service-use binding

Carry optional links between an external journey leg and a service occurrence or offer. The binding has its own purpose and access decision; no personal identity is needed for the public service description.

  1. Which external journey leg refers to which service offer or occurrence? relationship
  2. What purpose and lawful authority justify retaining any passenger-linked service-use reference? privacy
  3. When must the service-use link expire or be erased while preserving permitted service statistics? retention
Fare descriptions Product offers and the conditions under which they may apply.

Fare offers

Version fare product descriptions with amount, currency, media and category qualifiers. Product, purchased entitlement, payment instrument and proof of eligibility are separate objects.

Fare product description

Version fare product descriptions with amount, currency, media and category qualifiers. Product, purchased entitlement, payment instrument and proof of eligibility are separate objects.

  1. Which fare product revision and media or rider-category variant is described? identity
  2. What decimal amount, currency and effective period qualify the published price? measurement
  3. Which tariff authority approved this offer and where is eligibility verification delegated? authority

Fare conditions

Describe service, zone, timeframe and transfer conditions without assuming all fares are zonal or all transfers are free. Displayed estimates require an explicitly selected profile; no ticket is issued by this draft.

Tariff applicability

Describe service, zone, timeframe and transfer conditions without assuming all fares are zonal or all transfers are free. Displayed estimates require an explicitly selected profile; no ticket is issued by this draft.

  1. Which service, area and time conditions determine the scope of this fare rule? constraint
  2. How are leg grouping and transfer conditions described for the selected tariff profile? process
  3. Which missing conditions, discounts or exclusions prevent a confirmed fare quote? exception
Service evidence and disclosure Qualified service measures and authorized aggregate release.

Service and ridership measures

Attach a measure to a declared scope, period, population and method. Boardings are not unique people or end-to-end journeys. Performance measures require explicit planned baselines and missing-data treatment.

Qualified service measure

Attach a measure to a declared scope, period, population and method. Boardings are not unique people or end-to-end journeys. Performance measures require explicit planned baselines and missing-data treatment.

  1. What quantity, unit and denominator does this service or ridership measure represent? measurement
  2. How was the value counted or estimated and which records support it? provenance
  3. How are transfers, missing observations and revised schedule baselines handled? quality

Disclosure assessment

A proposed release carries recipient-specific risk assessment and authorization. No fixed disclosure floor is claimed to guarantee anonymity; linkage and repeated releases can alter the risk.

Aggregate release decision

A proposed release carries recipient-specific risk assessment and authorization. No fixed disclosure floor is claimed to guarantee anonymity; linkage and repeated releases can alter the risk.

  1. Which linkage and singling-out risks affect the proposed spatial and temporal aggregation? security
  2. Which recipient and purpose are authorized for this specific release view? access
  3. What evidence supports release, suppression or withholding of the aggregate? decision

Classifiers Filled

Family
World Models
Category
Physical world and living systems
Entry kind
aggregate
Navigation path
NAV.PHY.FLW.MOB
Domain
PHY.FLW.MOB
Industry
Cross-industry
Tags
passengermobilityphy.flw.mob
Also called
F7

What it is Filled

One authority- or operator-governed passenger service context with a persistent scope key and independently versioned components. The aggregate connects service descriptions and passenger-facing operational assertions for scheduled, frequency-based and demand-responsive public/shared transport. It is not a single traveller journey, a physical fleet, or an execution engine. Multiple custodians retain authority over their components; aggregate stewardship does not transfer ownership.

In scope

  • Service scope, responsible roles, releases and provenance
  • Passenger-facing stop and pattern bindings, calendars, flexible service offers and operating-status assertions
  • Accessible interchange information, external journey references, fare descriptions and qualified service/ridership evidence

Out of scope

  • Individual person, vehicle, facility and organization master records
  • Generic Journey / Trip and Route / Itinerary lifecycle and route optimization
  • Ticket issuance, payment settlement, eligibility adjudication, booking execution, vehicle dispatch/control and safety certification
  • Freight consignment lifecycle, emission calculations, workforce rostering and unrestricted private movement histories

Why it exists Filled

Describe a governed passenger transport service context across network, service offers, operating assertions, fares and service evidence.

Distinguishing features Derived, awaiting review

  • Unlike WM-FLW-009 Journey / Trip: Registry parentage is a subject classification, not authority to own every journey. Keep generic passenger and vehicle movement identities and lifecycle externally mastered. This aggregate holds service-occurrence selectors, schedule realization links and scoped operational assertions, not a duplicate journey master.
  • Unlike WM-FLW-010 Route / Itinerary: Service lines and stop-pattern bindings describe the offered transit service. Traveller-selected itineraries and generic paths remain external. A line may have many patterns; route labels are not globally unique path identities.
  • Unlike WM-ECO-004 Money / Instrument: Fare descriptions may carry decimal amount and currency or a pinned money value binding; issuance, balances, transfer and settlement remain outside the aggregate. No mandatory runtime dependency is inferred from legacy F2.
  • Unlike WM-PER-001 Person: Optional restricted passenger reference only with an applicable purpose and lawful authority. Identity omission or an agreement alone does not prove anonymity or legal sufficiency. The legacy M1 person code is not retained as a current registry binding.
  • Unlike WM-FLW-004 Goods Movement / Logistics and WM-FLW-006 Emission: Shared location or activity-data references may support other models without importing consignment or emission-estimation semantics. Legacy F3 and F6 links remain optional candidates pending profile binding.
  • Unlike Physical stop, facility, vehicle and organization masters: Own service-facing identifiers, display assertions, boarding bindings and dated evidence only. Facility maintenance, vehicle engineering and legal-entity governance remain separately mastered.

Note: Derived from boundary notes against neighbouring models.

What robots and AI may and may not do Derived, awaiting review

Must not

  • Default to minimum data and deny personal-data disclosure without explicit applicable authority.
  • Deny restricted service-use and raw movement access unless recipient, purpose, scope and authority are established.

May

  • Stage a service release: Proposed, unimplemented local operation. Validate and stage a local candidate release with explicit effective coverage and source provenance.
  • Resolve an occurrence selector: Proposed, unimplemented local operation. Propose a service occurrence binding using the selected schedule and temporal profile.
  • Attach an operating assertion: Proposed, unimplemented local operation. Record a qualified prediction, observation or no-data status against a resolved occurrence.
  • Stage a passenger advisory: Proposed, unimplemented local operation. Prepare a scoped advisory revision for authorized review.
  • Inspect fare applicability: Proposed, unimplemented local operation. Describe conditions relevant to supplied service legs under one pinned tariff profile.
  • Bind an external journey leg: Proposed, unimplemented local operation. Record the minimum authorized relationship to an external journey leg.
  • Prepare a service evidence view: Proposed, unimplemented local operation. Assemble method-qualified measures and a disclosure assessment for review.

Note: Derived from functions, policies, CRUD and access rules; prohibitions were not authored for agents as such.

Moral aspects Derived, awaiting review

  • Changing stop identity, timing semantics, tariff interpretation, privacy scope or measure denominator requires compatibility review and migration evidence.
  • Privacy and records reviewer
  • Selected transit exchange concepts plus US metric and UK privacy guidance; local legal and specialist modal profiles remain open.
  • Nested data schemas, tariff/temporal engines, accessibility acceptance fixtures, privacy disclosure procedures and performance computations remain unimplemented.

Note: Sentences mentioning harm, privacy, consent or similar, collected from the specification.

Owners Filled

Steward

Declare the authority or operator role governing this service scope and each component custodian

Roles

Service authority
Approve service scope and component mandates
Operator data custodian
Maintain source-bound schedules and operating assertions
Passenger information reviewer
Review recognition, languages, accessibility qualifiers and advisories
Tariff steward
Approve descriptive fare revisions and delegate entitlement decisions
Privacy and records reviewer
Approve recipient views, risk assessments, retention and disposal
Service analyst
Maintain measure definitions, uncertainty and compatible baselines

Links to other meta-models Filled

references

  • WM-FLW-009 - Optional generic journey master binding for passenger legs and vehicle movements; service assertions do not acquire journey lifecycle ownership.
  • WM-FLW-010 - Optional itinerary or path reference; keep service-pattern version and traveller itinerary distinct.
  • WM-PER-001 - Optional purpose-limited passenger identity binding with separate authority and retention assessment; public service data needs no person link.
  • WM-FLW-004 - Optional shared corridor or terminal context only; freight records stay external.
  • WM-FLW-006 - Optional external consumer of qualified activity measures; no emission factors or calculation are asserted here.

composes

  • WM-ECO-004 - Optional profile-pinned money value representation for fare amount and currency only; no financial instrument lifecycle is imported.

aligned

  • GTFS Schedule and GTFS Realtime - Selected conceptual mapping for service data and operating assertions; immutable versions, feature profiles and round-trip tests required.
  • Transmodel, NeTEx and SIRI - Conceptual domain alignment from official explanatory material; normative parts, implementation mappings and certification remain unverified.
  • PROV-O - Candidate provenance mapping for assertion derivation and attribution; no truth or permission inference.

neighbor

  • WM-FLW-009 Journey / Trip - Registry parentage is a subject classification, not authority to own every journey. Keep generic passenger and vehicle movement identities and lifecycle externally mastered. This aggregate holds service-occurrence selectors, schedule realization links and scoped operational assertions, not a duplicate journey master.
  • WM-FLW-010 Route / Itinerary - Service lines and stop-pattern bindings describe the offered transit service. Traveller-selected itineraries and generic paths remain external. A line may have many patterns; route labels are not globally unique path identities.
  • WM-ECO-004 Money / Instrument - Fare descriptions may carry decimal amount and currency or a pinned money value binding; issuance, balances, transfer and settlement remain outside the aggregate. No mandatory runtime dependency is inferred from legacy F2.
  • WM-PER-001 Person - Optional restricted passenger reference only with an applicable purpose and lawful authority. Identity omission or an agreement alone does not prove anonymity or legal sufficiency. The legacy M1 person code is not retained as a current registry binding.
  • WM-FLW-004 Goods Movement / Logistics and WM-FLW-006 Emission - Shared location or activity-data references may support other models without importing consignment or emission-estimation semantics. Legacy F3 and F6 links remain optional candidates pending profile binding.
  • Physical stop, facility, vehicle and organization masters - Own service-facing identifiers, display assertions, boarding bindings and dated evidence only. Facility maintenance, vehicle engineering and legal-entity governance remain separately mastered.

What else AI and robots need to interact with it Incomplete

Identity and identifiers required Filled

  • Authoritative master-system identifier with namespace and revision
  • Governed global identifier or IRI
  • UUID or ULID assigned by the adopting Dimension

Direct properties required Missing, in the backlog

Not described yet. This gap is in the card backlog.

Recognition required Missing, in the backlog

Not described yet. This gap is in the card backlog.

Capabilities and actions required Filled

  • Stage a service release: Proposed, unimplemented local operation. Validate and stage a local candidate release with explicit effective coverage and source provenance.
  • Resolve an occurrence selector: Proposed, unimplemented local operation. Propose a service occurrence binding using the selected schedule and temporal profile.
  • Attach an operating assertion: Proposed, unimplemented local operation. Record a qualified prediction, observation or no-data status against a resolved occurrence.
  • Stage a passenger advisory: Proposed, unimplemented local operation. Prepare a scoped advisory revision for authorized review.
  • Inspect fare applicability: Proposed, unimplemented local operation. Describe conditions relevant to supplied service legs under one pinned tariff profile.
  • Bind an external journey leg: Proposed, unimplemented local operation. Record the minimum authorized relationship to an external journey leg.
  • Prepare a service evidence view: Proposed, unimplemented local operation. Assemble method-qualified measures and a disclosure assessment for review.

Hazards and failure modes required Missing, in the backlog

Not described yet. This gap is in the card backlog.

Standards and interfaces required Derived, awaiting review

  • PROV-O: The PROV Ontology

Context of use required Filled

  • GTFS concepts are used as exchange evidence, not as universal transport law.
  • Transmodel explanatory material supports conceptual distinctions only; broad domain coverage does not require importing every domain into this aggregate.
  • US transit metric definitions and UK anonymisation guidance are examples that need adoption review elsewhere.

Sources Filled

  1. GTFS Schedule Reference - MobilityData
  2. GTFS Realtime Reference - MobilityData
  3. Transmodel FAQ - CEN public transport data standards project
  4. GTFS Demand responsive services examples - MobilityData
  5. GTFS Fares feature guide - Introduction - MobilityData
  6. GTFS Accessibility features - MobilityData
  7. National Transit Database Glossary - Federal Transit Administration
  8. How do we ensure anonymisation is effective? - Information Commissioner's Office
  9. PROV-O: The PROV Ontology - World Wide Web Consortium
  10. Date and Time on the Internet: Timestamps - Internet Engineering Task Force

Open questions

  • Restore an independent external reviewer and verify immutable source revisions, normative standards and licensing before canonical promotion.
  • Develop and test adoption profiles with repeated stops, reused identifiers, midnight and daylight-saving transitions, missing realtime data, inaccessible transfers, unresolved booking requests and changing fare conditions.
  • Build nested schemas and reversible mappings with pinned journey, itinerary and money bindings; test corrections, conflicting sources and partial data without duplicating external masters.
  • Validate ridership definitions and recipient-specific disclosure assessment against linkage, repeated releases, suppression and lawful erasure; expand specialist modal and regional coverage separately.
  • Independent external review is waived; a separate local Codex self-audit does not replace it.
  • Direct HTTP checks are not attempted under the owner-reported sandbox restriction. Content access through the web tool does not prove measured URL status, immutable versions, licensing or current applicability.
  • Normative Transmodel, NeTEx and SIRI documents, mapping profiles and certification are not verified.
  • Full aviation, maritime, intercity ticketing, micromobility and informal-service profiles need additional research; private movement is outside this scope.
  • Nested data schemas, tariff/temporal engines, accessibility acceptance fixtures, privacy disclosure procedures and performance computations remain unimplemented.
  • Passenger compensation, statutory assistance, concession adjudication and emergency operations remain external policy dependencies.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-flw-007-passenger-mobility/spec.yaml