# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T20:54:47Z", "synthesisSha256": "0e66367dfd85bd8b9e818052dc964c94c9ceed3b892874876c93cf80b64e2c1b", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-FLW-007", "registryId": "vr.wm-flw-007", "name": "Passenger Mobility", "version": "0.3.0-reviewable-draft", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Physical world and living systems", "industry": [ "Cross-industry" ], "domain": [ "PHY.FLW.MOB" ], "tags": [ "passenger", "mobility", "phy.flw.mob" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-flw-007-passenger-mobility/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-flw-007", "model": { "registry_id": "vr.wm-flw-007", "model_id": "WM-FLW-007", "name": "Passenger Mobility", "entry_kind": "aggregate", "purpose": "Describe a governed passenger transport service context across network, service offers, operating assertions, fares and service evidence.", "scope_statement": "One authority- or operator-governed passenger service context with a persistent scope key and independently versioned components. The aggregate connects service descriptions and passenger-facing operational assertions for scheduled, frequency-based and demand-responsive public/shared transport. It is not a single traveller journey, a physical fleet, or an execution engine. Multiple custodians retain authority over their components; aggregate stewardship does not transfer ownership.", "in_scope": [ "Service scope, responsible roles, releases and provenance", "Passenger-facing stop and pattern bindings, calendars, flexible service offers and operating-status assertions", "Accessible interchange information, external journey references, fare descriptions and qualified service/ridership evidence" ], "out_of_scope": [ "Individual person, vehicle, facility and organization master records", "Generic Journey / Trip and Route / Itinerary lifecycle and route optimization", "Ticket issuance, payment settlement, eligibility adjudication, booking execution, vehicle dispatch/control and safety certification", "Freight consignment lifecycle, emission calculations, workforce rostering and unrestricted private movement histories" ], "boundary_notes": [ { "neighbor": "WM-FLW-009 Journey / Trip", "distinction": "Registry parentage is a subject classification, not authority to own every journey. Keep generic passenger and vehicle movement identities and lifecycle externally mastered. This aggregate holds service-occurrence selectors, schedule realization links and scoped operational assertions, not a duplicate journey master.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "neighbor": "WM-FLW-010 Route / Itinerary", "distinction": "Service lines and stop-pattern bindings describe the offered transit service. Traveller-selected itineraries and generic paths remain external. A line may have many patterns; route labels are not globally unique path identities.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] }, { "neighbor": "WM-ECO-004 Money / Instrument", "distinction": "Fare descriptions may carry decimal amount and currency or a pinned money value binding; issuance, balances, transfer and settlement remain outside the aggregate. No mandatory runtime dependency is inferred from legacy F2.", "source_refs": [ "SRC-001", "SRC-005" ] }, { "neighbor": "WM-PER-001 Person", "distinction": "Optional restricted passenger reference only with an applicable purpose and lawful authority. Identity omission or an agreement alone does not prove anonymity or legal sufficiency. The legacy M1 person code is not retained as a current registry binding.", "source_refs": [ "SRC-008" ] }, { "neighbor": "WM-FLW-004 Goods Movement / Logistics and WM-FLW-006 Emission", "distinction": "Shared location or activity-data references may support other models without importing consignment or emission-estimation semantics. Legacy F3 and F6 links remain optional candidates pending profile binding.", "source_refs": [ "SRC-003", "SRC-007", "SRC-009" ] }, { "neighbor": "Physical stop, facility, vehicle and organization masters", "distinction": "Own service-facing identifiers, display assertions, boarding bindings and dated evidence only. Facility maintenance, vehicle engineering and legal-entity governance remain separately mastered.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] } ] }, "sources": [ { "id": "SRC-001", "title": "GTFS Schedule Reference", "organization": "MobilityData", "url": "https://gtfs.org/documentation/schedule/reference/", "version_or_date": "Page states revised April 27, 2026; rolling reference, immutable revision pin unresolved", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Selected definitions and fields: namespace-scoped identifiers, agency, stops, routes, trips, stop times, service calendars, frequencies and feed information. Service-day time can exceed 24 hours. These are exchange concepts, not an operational authorization." }, { "id": "SRC-002", "title": "GTFS Realtime Reference", "organization": "MobilityData", "url": "https://gtfs.org/documentation/realtime/reference/", "version_or_date": "Version 2.0 header semantics; rolling page read 2026-10-06, revision pin unresolved", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "FeedHeader, TripDescriptor, TripUpdate, StopTimeUpdate, VehiclePosition and Alert support schedule binding, prediction/observation distinctions, missing data and scoped alerts. Experimental fields are not assumed implemented." }, { "id": "SRC-003", "title": "Transmodel FAQ", "organization": "CEN public transport data standards project", "url": "https://transmodel-cen.eu/index.php/faq-transmodel/", "version_or_date": "Undated official explanatory page read 2026-10-06; normative EN 12896 parts not inspected", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Conceptual separation of lines, routes, journey patterns, vehicle journeys, fares, passenger information and statistics; NeTEx and SIRI are derived exchange standards. Supports conceptual alignment only." }, { "id": "SRC-004", "title": "GTFS Demand responsive services examples", "organization": "MobilityData", "url": "https://gtfs.org/documentation/schedule/examples/flex/", "version_or_date": "Rolling examples read 2026-10-06; page identifies March 2024 adoption", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Service zones, location groups, pickup/drop-off windows and booking-rule descriptions support discoverability of flexible services. Examples are not complete service contracts or booking transactions." }, { "id": "SRC-005", "title": "GTFS Fares feature guide - Introduction", "organization": "MobilityData", "url": "https://gtfs.org/resources/gtfs-schedule-feature-guides/fares/intro/", "version_or_date": "Fares v2 guide read 2026-10-06; rolling guide, immutable revision pin unresolved", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Fare products, media, rider categories, route networks, zones, timeframes and transfer conditions. Example prices and concession policies are not adopted as current or universal." }, { "id": "SRC-006", "title": "GTFS Accessibility features", "organization": "MobilityData", "url": "https://gtfs.org/getting-started/features/accessibility/", "version_or_date": "Rolling feature guide read 2026-10-06", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Boarding accessibility and trip/vehicle accommodation are distinct; text-to-speech names support passenger recognition. No end-to-end accessibility certification follows from one flag." }, { "id": "SRC-007", "title": "National Transit Database Glossary", "organization": "Federal Transit Administration", "url": "https://www.transit.dot.gov/ntd/national-transit-database-ntd-glossary", "version_or_date": "Selected live glossary entries read 2026-10-06; reporting-year applicability unpinned", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Unlinked passenger trips count boardings, including each boarding in a multi-vehicle journey; passenger distance and service output have separate definitions. US reporting examples, not global reporting mandates." }, { "id": "SRC-008", "title": "How do we ensure anonymisation is effective?", "organization": "Information Commissioner's Office", "url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/anonymisation/how-do-we-ensure-anonymisation-is-effective/", "version_or_date": "Selected official guidance read 2026-10-06; current legal applicability requires profile review", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Identifiability, singling out, linkability and inference depend on context. Removing direct identifiers does not by itself establish anonymity. Used for privacy risk design, not a universal legal opinion." }, { "id": "SRC-009", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Entity, activity, attribution, derivation and revision support traceable release and measurement assertions. Provenance does not certify correctness or authorize disclosure." }, { "id": "SRC-010", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "RFC 3339, July 2002, section 5.6", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T20:52:30Z", "relevance": "Syntax for instants with seconds and explicit offsets. Local service-day offsets and date-only calendar values require separate representations and conversion rules." } ], "structure": { "bundles": [ { "id": "b-governance", "name": "Service context", "description": "Persistent service scope and its accountable data releases.", "rationale": "A service aggregate needs a defined scope without claiming ownership of referenced masters.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ], "layers": [ { "id": "l-scope", "name": "Identity and accountability", "description": "Define which service context is being described, its modes and coverage, and who may attest each component. Names and logos are recognition aids rather than matching keys.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ], "findings": [ { "id": "f-scope", "name": "Governed service scope", "description": "Define which service context is being described, its modes and coverage, and who may attest each component. Names and logos are recognition aids rather than matching keys.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ], "questions": [ { "id": "q-scope-1", "text": "Which authority-qualified service scope does this aggregate identify?", "kind": "identity", "answer_data": [ "scope_id", "master_namespace", "aliases", "external_master_refs" ] }, { "id": "q-scope-2", "text": "Which passenger service modes and geographic coverage belong to this scope?", "kind": "classification", "answer_data": [ "mode_codes", "coverage_refs", "included_service_classes", "exclusions" ] }, { "id": "q-scope-3", "text": "Which accountable role can approve each component and its passenger-facing use?", "kind": "ownership", "answer_data": [ "custodian_roles", "component_mandates", "delegation_refs", "approval_scope" ] } ], "data_elements": [ { "id": "d-scope-1", "name": "Governed service scope - identity context", "description": "Candidate fields: scope_id, master_namespace, aliases, external_master_refs. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] }, { "id": "d-scope-2", "name": "Governed service scope - classification context", "description": "Candidate fields: mode_codes, coverage_refs, included_service_classes, exclusions. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] }, { "id": "d-scope-3", "name": "Governed service scope - ownership context", "description": "Candidate fields: custodian_roles, component_mandates, delegation_refs, approval_scope. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] } ], "artifacts": [ { "id": "a-scope", "name": "Service scope record", "description": "Versioned evidence for governed service scope within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "l-release", "name": "Release provenance", "description": "Keep release identity, derivation and effective coverage distinct from the continuing service context. Retired or corrected releases remain resolvable subject to data retention limits.", "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ], "findings": [ { "id": "f-release", "name": "Versioned service release", "description": "Keep release identity, derivation and effective coverage distinct from the continuing service context. Retired or corrected releases remain resolvable subject to data retention limits.", "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ], "questions": [ { "id": "q-release-1", "text": "What release state and supersession link apply to this service description?", "kind": "lifecycle", "answer_data": [ "release_id", "state", "supersedes_ref", "correction_reason" ] }, { "id": "q-release-2", "text": "When is the release effective and when was its content issued and ingested?", "kind": "temporal", "answer_data": [ "effective_interval", "issued_at", "ingested_at", "timezone_basis" ] }, { "id": "q-release-3", "text": "Which source versions and transformations support the release?", "kind": "provenance", "answer_data": [ "source_refs", "source_versions", "digest_algorithm", "digests", "transformation_refs" ] } ], "data_elements": [ { "id": "d-release-1", "name": "Versioned service release - lifecycle context", "description": "Candidate fields: release_id, state, supersedes_ref, correction_reason. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ] }, { "id": "d-release-2", "name": "Versioned service release - temporal context", "description": "Candidate fields: effective_interval, issued_at, ingested_at, timezone_basis. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ] }, { "id": "d-release-3", "name": "Versioned service release - provenance context", "description": "Candidate fields: source_refs, source_versions, digest_algorithm, digests, transformation_refs. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "a-release", "name": "Service release manifest", "description": "Versioned evidence for versioned service release within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-network", "name": "Passenger service network", "description": "Boarding locations and recurring service patterns.", "rationale": "Separate service topology and recognition from generic geography and physical asset ownership.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "layers": [ { "id": "l-boarding", "name": "Boarding locations", "description": "Bind service stop points to the appropriate station, platform or boarding location. Spatial assertions carry coordinate reference and provenance; a nearby point or similar name does not establish equivalence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "findings": [ { "id": "f-boarding", "name": "Boarding-place binding", "description": "Bind service stop points to the appropriate station, platform or boarding location. Spatial assertions carry coordinate reference and provenance; a nearby point or similar name does not establish equivalence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "questions": [ { "id": "q-boarding-1", "text": "Where is boarding offered and which station or platform hierarchy applies?", "kind": "spatial", "answer_data": [ "stop_ref", "location_type", "parent_ref", "coordinates", "coordinate_reference_system" ] }, { "id": "q-boarding-2", "text": "Which public code, sign or announcement helps a passenger recognize this boarding place?", "kind": "evidence", "answer_data": [ "public_code", "display_name", "language", "spoken_name", "observation_ref" ] }, { "id": "q-boarding-3", "text": "What evidence supports merging or separating two candidate stop references?", "kind": "validation", "answer_data": [ "candidate_refs", "equivalence_evidence", "effective_interval", "review_status" ] } ], "data_elements": [ { "id": "d-boarding-1", "name": "Boarding-place binding - spatial context", "description": "Candidate fields: stop_ref, location_type, parent_ref, coordinates, coordinate_reference_system. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "d-boarding-2", "name": "Boarding-place binding - evidence context", "description": "Candidate fields: public_code, display_name, language, spoken_name, observation_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "d-boarding-3", "name": "Boarding-place binding - validation context", "description": "Candidate fields: candidate_refs, equivalence_evidence, effective_interval, review_status. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "a-boarding", "name": "Boarding-place map", "description": "Versioned evidence for boarding-place binding within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "l-pattern", "name": "Lines and patterns", "description": "Keep a marketed line, direction and ordered stop-pattern version distinct. Repeated stops and variants require occurrence-aware ordering; geometry remains a referenced path or evidenced service projection.", "source_refs": [ "SRC-001", "SRC-003" ], "findings": [ { "id": "f-pattern", "name": "Service pattern", "description": "Keep a marketed line, direction and ordered stop-pattern version distinct. Repeated stops and variants require occurrence-aware ordering; geometry remains a referenced path or evidenced service projection.", "source_refs": [ "SRC-001", "SRC-003" ], "questions": [ { "id": "q-pattern-1", "text": "Which ordered stop occurrences define this service pattern variant?", "kind": "composition", "answer_data": [ "line_ref", "pattern_id", "ordered_stop_occurrences", "pickup_dropoff_rules" ] }, { "id": "q-pattern-2", "text": "Which operator, direction and external path are associated with this pattern?", "kind": "relationship", "answer_data": [ "operator_ref", "direction_label", "destination_display", "path_ref" ] }, { "id": "q-pattern-3", "text": "Which diversions or validity restrictions change this pattern without rewriting its historical version?", "kind": "constraint", "answer_data": [ "restriction_refs", "validity_interval", "replacement_pattern_ref", "change_authority" ] } ], "data_elements": [ { "id": "d-pattern-1", "name": "Service pattern - composition context", "description": "Candidate fields: line_ref, pattern_id, ordered_stop_occurrences, pickup_dropoff_rules. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "d-pattern-2", "name": "Service pattern - relationship context", "description": "Candidate fields: operator_ref, direction_label, destination_display, path_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "d-pattern-3", "name": "Service pattern - constraint context", "description": "Candidate fields: restriction_refs, validity_interval, replacement_pattern_ref, change_authority. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "a-pattern", "name": "Service pattern revision", "description": "Versioned evidence for service pattern within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-offer", "name": "Service availability", "description": "Calendar, time and request conditions of the published offer.", "rationale": "Published availability is distinct from confirmation that a service operated or a seat was reserved.", "source_refs": [ "SRC-001", "SRC-004", "SRC-010" ], "layers": [ { "id": "l-calendar", "name": "Service days and frequency", "description": "Record scheduled or headway-based offers with service-day semantics. Preserve after-midnight offsets, date exceptions and time-zone conversion rules; do not coerce service-day times into civil-day instants.", "source_refs": [ "SRC-001", "SRC-010" ], "findings": [ { "id": "f-calendar", "name": "Calendar-qualified offer", "description": "Record scheduled or headway-based offers with service-day semantics. Preserve after-midnight offsets, date exceptions and time-zone conversion rules; do not coerce service-day times into civil-day instants.", "source_refs": [ "SRC-001", "SRC-010" ], "questions": [ { "id": "q-calendar-1", "text": "Which service days, exceptions and local time basis govern this offer?", "kind": "temporal", "answer_data": [ "service_calendar_ref", "service_date", "exception_dates", "agency_timezone", "service_day_offsets" ] }, { "id": "q-calendar-2", "text": "Is this offer scheduled or frequency-based and what timing precision is promised?", "kind": "classification", "answer_data": [ "timing_mode", "headway_seconds", "operating_window", "exactness", "uncertainty" ] }, { "id": "q-calendar-3", "text": "How are midnight rollover and daylight-saving ambiguities resolved for a dated occurrence?", "kind": "validation", "answer_data": [ "conversion_profile", "source_time_values", "resolved_instants", "ambiguity_status" ] } ], "data_elements": [ { "id": "d-calendar-1", "name": "Calendar-qualified offer - temporal context", "description": "Candidate fields: service_calendar_ref, service_date, exception_dates, agency_timezone, service_day_offsets. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "d-calendar-2", "name": "Calendar-qualified offer - classification context", "description": "Candidate fields: timing_mode, headway_seconds, operating_window, exactness, uncertainty. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "d-calendar-3", "name": "Calendar-qualified offer - validation context", "description": "Candidate fields: conversion_profile, source_time_values, resolved_instants, ambiguity_status. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] } ], "artifacts": [ { "id": "a-calendar", "name": "Service availability profile", "description": "Versioned evidence for calendar-qualified offer within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-001", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "l-flex", "name": "Demand-responsive conditions", "description": "Describe zones, pickup windows and request channels. A booking-rule description advertises how to request service; it is neither a reservation nor proof of vehicle availability.", "source_refs": [ "SRC-004" ], "findings": [ { "id": "f-flex", "name": "Flexible service offer", "description": "Describe zones, pickup windows and request channels. A booking-rule description advertises how to request service; it is neither a reservation nor proof of vehicle availability.", "source_refs": [ "SRC-004" ], "questions": [ { "id": "q-flex-1", "text": "Which zones or location groups permit pickup and drop-off for this flexible offer?", "kind": "spatial", "answer_data": [ "zone_refs", "location_group_refs", "pickup_constraints", "dropoff_constraints" ] }, { "id": "q-flex-2", "text": "What booking notice, contact channel and pickup window must a passenger consult?", "kind": "requirement", "answer_data": [ "booking_rule_ref", "notice_rule", "request_channel_ref", "pickup_window" ] }, { "id": "q-flex-3", "text": "Which eligibility or capacity uncertainties require an external booking confirmation?", "kind": "exception", "answer_data": [ "eligibility_policy_ref", "capacity_status", "confirmation_system_ref", "unresolved_conditions" ] } ], "data_elements": [ { "id": "d-flex-1", "name": "Flexible service offer - spatial context", "description": "Candidate fields: zone_refs, location_group_refs, pickup_constraints, dropoff_constraints. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "d-flex-2", "name": "Flexible service offer - requirement context", "description": "Candidate fields: booking_rule_ref, notice_rule, request_channel_ref, pickup_window. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "d-flex-3", "name": "Flexible service offer - exception context", "description": "Candidate fields: eligibility_policy_ref, capacity_status, confirmation_system_ref, unresolved_conditions. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "a-flex", "name": "Flexible service conditions", "description": "Versioned evidence for flexible service offer within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-operations", "name": "Operating assertions", "description": "Dated service status and passenger-facing disruptions.", "rationale": "An operational assertion needs provenance and freshness; feed silence cannot establish that a service ran.", "source_refs": [ "SRC-002", "SRC-009", "SRC-010" ], "layers": [ { "id": "l-occurrence", "name": "Dated service realization", "description": "Bind a schedule occurrence to an external vehicle journey when known. Preserve the schedule relationship and separate predicted, measured and unconfirmed historical values. Cancellations and no-data conditions are explicit.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "findings": [ { "id": "f-occurrence", "name": "Service occurrence assertion", "description": "Bind a schedule occurrence to an external vehicle journey when known. Preserve the schedule relationship and separate predicted, measured and unconfirmed historical values. Cancellations and no-data conditions are explicit.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "questions": [ { "id": "q-occurrence-1", "text": "Which service date and schedule selector identify the occurrence independently of feed message identity?", "kind": "identity", "answer_data": [ "schedule_release_ref", "trip_selector", "service_date", "start_time_selector", "external_journey_ref" ] }, { "id": "q-occurrence-2", "text": "What operating state is asserted and is its timing predicted, observed or unavailable?", "kind": "state", "answer_data": [ "schedule_relationship", "operating_state", "time_assertions", "assertion_kind", "uncertainty" ] }, { "id": "q-occurrence-3", "text": "How fresh and consistent is the assertion relative to its source and referenced schedule?", "kind": "quality", "answer_data": [ "source_timestamp", "observed_at", "ingested_at", "freshness_policy", "conflicting_assertions" ] } ], "data_elements": [ { "id": "d-occurrence-1", "name": "Service occurrence assertion - identity context", "description": "Candidate fields: schedule_release_ref, trip_selector, service_date, start_time_selector, external_journey_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "id": "d-occurrence-2", "name": "Service occurrence assertion - state context", "description": "Candidate fields: schedule_relationship, operating_state, time_assertions, assertion_kind, uncertainty. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "id": "d-occurrence-3", "name": "Service occurrence assertion - quality context", "description": "Candidate fields: source_timestamp, observed_at, ingested_at, freshness_policy, conflicting_assertions. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "artifacts": [ { "id": "a-occurrence", "name": "Service occurrence evidence", "description": "Versioned evidence for service occurrence assertion within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "l-disruption", "name": "Disruption communication", "description": "Represent approved advisory content, affected entities, active periods and supersession. A record describes the asserted impact; recording or withdrawing it does not dispatch vehicles or prove service restoration.", "source_refs": [ "SRC-002", "SRC-009", "SRC-010" ], "findings": [ { "id": "f-disruption", "name": "Scoped service advisory", "description": "Represent approved advisory content, affected entities, active periods and supersession. A record describes the asserted impact; recording or withdrawing it does not dispatch vehicles or prove service restoration.", "source_refs": [ "SRC-002", "SRC-009", "SRC-010" ], "questions": [ { "id": "q-disruption-1", "text": "Which interruption or change does this advisory report and which passengers or services are affected?", "kind": "event", "answer_data": [ "advisory_id", "cause_code", "effect_code", "affected_selectors" ] }, { "id": "q-disruption-2", "text": "Who approved this advisory text and its active periods?", "kind": "authority", "answer_data": [ "approver_role", "approval_evidence", "active_periods", "language_versions" ] }, { "id": "q-disruption-3", "text": "What evidence supports updating, expiring or withdrawing this advisory?", "kind": "lifecycle", "answer_data": [ "revision", "supersession_ref", "withdrawal_reason", "restoration_evidence", "uncertain_end" ] } ], "data_elements": [ { "id": "d-disruption-1", "name": "Scoped service advisory - event context", "description": "Candidate fields: advisory_id, cause_code, effect_code, affected_selectors. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-009", "SRC-010" ] }, { "id": "d-disruption-2", "name": "Scoped service advisory - authority context", "description": "Candidate fields: approver_role, approval_evidence, active_periods, language_versions. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-009", "SRC-010" ] }, { "id": "d-disruption-3", "name": "Scoped service advisory - lifecycle context", "description": "Candidate fields: revision, supersession_ref, withdrawal_reason, restoration_evidence, uncertain_end. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "a-disruption", "name": "Service advisory revision", "description": "Versioned evidence for scoped service advisory within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-002", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-passenger", "name": "Passenger use context", "description": "Accessible interchange and external journey bindings.", "rationale": "Passenger information supports decisions while personal itineraries and master movement records remain external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-008" ], "layers": [ { "id": "l-interchange", "name": "Accessibility and interchange", "description": "Record location access, vehicle accommodation and transfer constraints separately. Missing accessibility evidence remains unknown; a timetable connection or one positive flag cannot guarantee an accessible journey.", "source_refs": [ "SRC-001", "SRC-006", "SRC-002" ], "findings": [ { "id": "f-interchange", "name": "Qualified access path", "description": "Record location access, vehicle accommodation and transfer constraints separately. Missing accessibility evidence remains unknown; a timetable connection or one positive flag cannot guarantee an accessible journey.", "source_refs": [ "SRC-001", "SRC-006", "SRC-002" ], "questions": [ { "id": "q-interchange-1", "text": "Which boarding, pathway and vehicle-accommodation conditions apply to this interchange?", "kind": "requirement", "answer_data": [ "boarding_access_status", "pathway_refs", "vehicle_accommodation", "assistance_policy_ref" ] }, { "id": "q-interchange-2", "text": "What minimum transfer time and restrictions qualify this connection?", "kind": "constraint", "answer_data": [ "from_occurrence_ref", "to_occurrence_ref", "transfer_duration", "restriction_basis", "guarantee_status" ] }, { "id": "q-interchange-3", "text": "Which dated evidence or disruption qualifies the current accessibility statement?", "kind": "evidence", "answer_data": [ "assessment_ref", "assessed_at", "facility_alert_ref", "unknown_features", "language_access" ] } ], "data_elements": [ { "id": "d-interchange-1", "name": "Qualified access path - requirement context", "description": "Candidate fields: boarding_access_status, pathway_refs, vehicle_accommodation, assistance_policy_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-002" ] }, { "id": "d-interchange-2", "name": "Qualified access path - constraint context", "description": "Candidate fields: from_occurrence_ref, to_occurrence_ref, transfer_duration, restriction_basis, guarantee_status. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-002" ] }, { "id": "d-interchange-3", "name": "Qualified access path - evidence context", "description": "Candidate fields: assessment_ref, assessed_at, facility_alert_ref, unknown_features, language_access. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-002" ] } ], "artifacts": [ { "id": "a-interchange", "name": "Interchange access assessment", "description": "Versioned evidence for qualified access path within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-001", "SRC-006", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "l-journey", "name": "Journey references", "description": "Carry optional links between an external journey leg and a service occurrence or offer. The binding has its own purpose and access decision; no personal identity is needed for the public service description.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008" ], "findings": [ { "id": "f-journey", "name": "Passenger service-use binding", "description": "Carry optional links between an external journey leg and a service occurrence or offer. The binding has its own purpose and access decision; no personal identity is needed for the public service description.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008" ], "questions": [ { "id": "q-journey-1", "text": "Which external journey leg refers to which service offer or occurrence?", "kind": "relationship", "answer_data": [ "external_journey_ref", "leg_ref", "service_ref", "binding_status" ] }, { "id": "q-journey-2", "text": "What purpose and lawful authority justify retaining any passenger-linked service-use reference?", "kind": "privacy", "answer_data": [ "purpose", "authority_ref", "linkability_assessment", "minimal_fields", "recipient_scope" ] }, { "id": "q-journey-3", "text": "When must the service-use link expire or be erased while preserving permitted service statistics?", "kind": "retention", "answer_data": [ "retention_profile", "expiry", "hold_basis", "disposal_evidence", "aggregate_lineage_policy" ] } ], "data_elements": [ { "id": "d-journey-1", "name": "Passenger service-use binding - relationship context", "description": "Candidate fields: external_journey_ref, leg_ref, service_ref, binding_status. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-008" ] }, { "id": "d-journey-2", "name": "Passenger service-use binding - privacy context", "description": "Candidate fields: purpose, authority_ref, linkability_assessment, minimal_fields, recipient_scope. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-008" ] }, { "id": "d-journey-3", "name": "Passenger service-use binding - retention context", "description": "Candidate fields: retention_profile, expiry, hold_basis, disposal_evidence, aggregate_lineage_policy. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-008" ] } ], "artifacts": [ { "id": "a-journey", "name": "Restricted service-use binding", "description": "Versioned evidence for passenger service-use binding within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-fares", "name": "Fare descriptions", "description": "Product offers and the conditions under which they may apply.", "rationale": "Fare information does not own payment, ticket validity adjudication or entitlement decisions.", "source_refs": [ "SRC-001", "SRC-005" ], "layers": [ { "id": "l-product", "name": "Fare offers", "description": "Version fare product descriptions with amount, currency, media and category qualifiers. Product, purchased entitlement, payment instrument and proof of eligibility are separate objects.", "source_refs": [ "SRC-001", "SRC-005" ], "findings": [ { "id": "f-product", "name": "Fare product description", "description": "Version fare product descriptions with amount, currency, media and category qualifiers. Product, purchased entitlement, payment instrument and proof of eligibility are separate objects.", "source_refs": [ "SRC-001", "SRC-005" ], "questions": [ { "id": "q-product-1", "text": "Which fare product revision and media or rider-category variant is described?", "kind": "identity", "answer_data": [ "product_ref", "revision", "media_ref", "rider_category_ref" ] }, { "id": "q-product-2", "text": "What decimal amount, currency and effective period qualify the published price?", "kind": "measurement", "answer_data": [ "decimal_amount", "currency_code", "price_role", "effective_interval", "source_tariff_ref" ] }, { "id": "q-product-3", "text": "Which tariff authority approved this offer and where is eligibility verification delegated?", "kind": "authority", "answer_data": [ "tariff_authority_role", "approval_ref", "eligibility_policy_ref", "external_verifier_ref" ] } ], "data_elements": [ { "id": "d-product-1", "name": "Fare product description - identity context", "description": "Candidate fields: product_ref, revision, media_ref, rider_category_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "d-product-2", "name": "Fare product description - measurement context", "description": "Candidate fields: decimal_amount, currency_code, price_role, effective_interval, source_tariff_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "d-product-3", "name": "Fare product description - authority context", "description": "Candidate fields: tariff_authority_role, approval_ref, eligibility_policy_ref, external_verifier_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "a-product", "name": "Fare product revision", "description": "Versioned evidence for fare product description within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "l-tariff", "name": "Fare conditions", "description": "Describe service, zone, timeframe and transfer conditions without assuming all fares are zonal or all transfers are free. Displayed estimates require an explicitly selected profile; no ticket is issued by this draft.", "source_refs": [ "SRC-005" ], "findings": [ { "id": "f-tariff", "name": "Tariff applicability", "description": "Describe service, zone, timeframe and transfer conditions without assuming all fares are zonal or all transfers are free. Displayed estimates require an explicitly selected profile; no ticket is issued by this draft.", "source_refs": [ "SRC-005" ], "questions": [ { "id": "q-tariff-1", "text": "Which service, area and time conditions determine the scope of this fare rule?", "kind": "constraint", "answer_data": [ "rule_id", "network_refs", "area_refs", "timeframe_refs", "effective_revision" ] }, { "id": "q-tariff-2", "text": "How are leg grouping and transfer conditions described for the selected tariff profile?", "kind": "process", "answer_data": [ "leg_group_refs", "transfer_rule_refs", "duration_basis", "precedence_profile" ] }, { "id": "q-tariff-3", "text": "Which missing conditions, discounts or exclusions prevent a confirmed fare quote?", "kind": "exception", "answer_data": [ "missing_inputs", "discount_refs", "excluded_cases", "estimate_status", "confirmation_ref" ] } ], "data_elements": [ { "id": "d-tariff-1", "name": "Tariff applicability - constraint context", "description": "Candidate fields: rule_id, network_refs, area_refs, timeframe_refs, effective_revision. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "d-tariff-2", "name": "Tariff applicability - process context", "description": "Candidate fields: leg_group_refs, transfer_rule_refs, duration_basis, precedence_profile. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "d-tariff-3", "name": "Tariff applicability - exception context", "description": "Candidate fields: missing_inputs, discount_refs, excluded_cases, estimate_status, confirmation_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [ { "id": "a-tariff", "name": "Tariff conditions record", "description": "Versioned evidence for tariff applicability within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-evidence", "name": "Service evidence and disclosure", "description": "Qualified service measures and authorized aggregate release.", "rationale": "Keep counting semantics and privacy review visible before deriving or disclosing performance assertions.", "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ], "layers": [ { "id": "l-measurement", "name": "Service and ridership measures", "description": "Attach a measure to a declared scope, period, population and method. Boardings are not unique people or end-to-end journeys. Performance measures require explicit planned baselines and missing-data treatment.", "source_refs": [ "SRC-007", "SRC-009" ], "findings": [ { "id": "f-measurement", "name": "Qualified service measure", "description": "Attach a measure to a declared scope, period, population and method. Boardings are not unique people or end-to-end journeys. Performance measures require explicit planned baselines and missing-data treatment.", "source_refs": [ "SRC-007", "SRC-009" ], "questions": [ { "id": "q-measurement-1", "text": "What quantity, unit and denominator does this service or ridership measure represent?", "kind": "measurement", "answer_data": [ "measure_definition", "value", "unit", "denominator", "scope", "period" ] }, { "id": "q-measurement-2", "text": "How was the value counted or estimated and which records support it?", "kind": "provenance", "answer_data": [ "method", "source_records", "sampling_basis", "uncertainty", "derivation_ref" ] }, { "id": "q-measurement-3", "text": "How are transfers, missing observations and revised schedule baselines handled?", "kind": "quality", "answer_data": [ "boarding_rule", "deduplication_scope", "missing_data_policy", "baseline_revision", "revision_status" ] } ], "data_elements": [ { "id": "d-measurement-1", "name": "Qualified service measure - measurement context", "description": "Candidate fields: measure_definition, value, unit, denominator, scope, period. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "d-measurement-2", "name": "Qualified service measure - provenance context", "description": "Candidate fields: method, source_records, sampling_basis, uncertainty, derivation_ref. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "d-measurement-3", "name": "Qualified service measure - quality context", "description": "Candidate fields: boarding_rule, deduplication_scope, missing_data_policy, baseline_revision, revision_status. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "a-measurement", "name": "Service measurement record", "description": "Versioned evidence for qualified service measure within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "l-disclosure", "name": "Disclosure assessment", "description": "A proposed release carries recipient-specific risk assessment and authorization. No fixed disclosure floor is claimed to guarantee anonymity; linkage and repeated releases can alter the risk.", "source_refs": [ "SRC-008", "SRC-009" ], "findings": [ { "id": "f-disclosure", "name": "Aggregate release decision", "description": "A proposed release carries recipient-specific risk assessment and authorization. No fixed disclosure floor is claimed to guarantee anonymity; linkage and repeated releases can alter the risk.", "source_refs": [ "SRC-008", "SRC-009" ], "questions": [ { "id": "q-disclosure-1", "text": "Which linkage and singling-out risks affect the proposed spatial and temporal aggregation?", "kind": "security", "answer_data": [ "risk_assessment_ref", "external_data_context", "granularity", "repeated_release_risk" ] }, { "id": "q-disclosure-2", "text": "Which recipient and purpose are authorized for this specific release view?", "kind": "access", "answer_data": [ "recipient_scope", "purpose", "release_view", "approval_ref", "use_restrictions" ] }, { "id": "q-disclosure-3", "text": "What evidence supports release, suppression or withholding of the aggregate?", "kind": "decision", "answer_data": [ "decision", "mitigation_refs", "residual_risk", "reviewer_role", "review_expiry" ] } ], "data_elements": [ { "id": "d-disclosure-1", "name": "Aggregate release decision - security context", "description": "Candidate fields: risk_assessment_ref, external_data_context, granularity, repeated_release_risk. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "d-disclosure-2", "name": "Aggregate release decision - access context", "description": "Candidate fields: recipient_scope, purpose, release_view, approval_ref, use_restrictions. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "d-disclosure-3", "name": "Aggregate release decision - decision context", "description": "Candidate fields: decision, mitigation_refs, residual_risk, reviewer_role, review_expiry. Nested schema and field constraints remain profile work; absent evidence stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "a-disclosure", "name": "Aggregate release assessment", "description": "Versioned evidence for aggregate release decision within the declared service scope; retain source and review qualifiers.", "media_or_form": [ "structured record", "human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier plus namespace and revision; otherwise governed IRI, then locally assigned UUID or ULID. A digest verifies content and does not replace identity.", "source_refs": [ "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-stage-release", "name": "Stage a service release", "description": "Proposed, unimplemented local operation. Validate and stage a local candidate release with explicit effective coverage and source provenance.", "inputs": [ "candidate release", "source version pins", "component approval references" ], "outputs": [ "candidate revision or refusal report" ], "preconditions": [ "Required component identities resolve within their namespaces", "Release authority and expected revision are verified", "Expected revision and role scope verified; otherwise refuse with reasons" ], "effects": [ "Creates a local candidate; does not publish a timetable or alter an external master" ], "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "fn-resolve-occurrence", "name": "Resolve an occurrence selector", "description": "Proposed, unimplemented local operation. Propose a service occurrence binding using the selected schedule and temporal profile.", "inputs": [ "schedule revision", "service date", "trip and start-time selectors", "timezone profile" ], "outputs": [ "binding with ambiguity status or refusal report" ], "preconditions": [ "Calendar and profile versions are pinned", "Input timing type is declared", "Expected revision and role scope verified; otherwise refuse with reasons" ], "effects": [ "Returns local linkage evidence; does not create or dispatch a journey" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-010" ] }, { "id": "fn-attach-assertion", "name": "Attach an operating assertion", "description": "Proposed, unimplemented local operation. Record a qualified prediction, observation or no-data status against a resolved occurrence.", "inputs": [ "occurrence reference", "source assertion", "observation and ingestion times" ], "outputs": [ "versioned assertion or conflict report" ], "preconditions": [ "Source and schedule match or mismatch is explicitly quarantined", "Actor may record evidence for this component", "Expected revision and role scope verified; otherwise refuse with reasons" ], "effects": [ "Appends local evidence and freshness status; no control action or inferred on-time guarantee" ], "source_refs": [ "SRC-002", "SRC-009" ] }, { "id": "fn-stage-advisory", "name": "Stage a passenger advisory", "description": "Proposed, unimplemented local operation. Prepare a scoped advisory revision for authorized review.", "inputs": [ "impact selectors", "active periods", "translated text", "approval reference" ], "outputs": [ "candidate advisory or refusal report" ], "preconditions": [ "Selectors are resolvable and ambiguity is visible", "Approval scope covers the proposed content", "Expected revision and role scope verified; otherwise refuse with reasons" ], "effects": [ "Stores a local draft; no message distribution, dispatch or service suspension" ], "source_refs": [ "SRC-002", "SRC-009" ] }, { "id": "fn-inspect-fare", "name": "Inspect fare applicability", "description": "Proposed, unimplemented local operation. Describe conditions relevant to supplied service legs under one pinned tariff profile.", "inputs": [ "fare revisions", "service-leg attributes", "tariff profile" ], "outputs": [ "qualified applicability explanation or unresolved-input report" ], "preconditions": [ "Tariff provenance and effective coverage are established", "Sensitive eligibility evidence stays with its external verifier", "Expected revision and role scope verified; otherwise refuse with reasons" ], "effects": [ "Produces a local explanation only; no binding quote, eligibility decision, payment or ticket issuance" ], "source_refs": [ "SRC-005" ] }, { "id": "fn-bind-service-use", "name": "Bind an external journey leg", "description": "Proposed, unimplemented local operation. Record the minimum authorized relationship to an external journey leg.", "inputs": [ "journey and leg reference", "service reference", "purpose and authorization", "expiry" ], "outputs": [ "restricted binding or refusal report" ], "preconditions": [ "External identity is resolvable without copying the journey master", "Retention and recipient rules are approved", "Expected revision and role scope verified; otherwise refuse with reasons" ], "effects": [ "Creates or revises a local relation; does not create a traveller profile or change the external journey" ], "source_refs": [ "SRC-003", "SRC-008", "SRC-009" ] }, { "id": "fn-prepare-measure", "name": "Prepare a service evidence view", "description": "Proposed, unimplemented local operation. Assemble method-qualified measures and a disclosure assessment for review.", "inputs": [ "approved observations", "measure definition", "scope and period", "recipient", "privacy assessment" ], "outputs": [ "candidate evidence view or withheld result" ], "preconditions": [ "Compatible units, periods and baselines are established", "Missing data and risk assessment are explicit", "Expected revision and role scope verified; otherwise refuse with reasons" ], "effects": [ "Creates a local candidate; external release requires the adopted authority workflow and is not performed" ], "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ] } ], "composition": [ { "target": "WM-FLW-009", "relation": "REFERENCE", "purpose": "Optional generic journey master binding for passenger legs and vehicle movements; service assertions do not acquire journey lifecycle ownership.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "target": "WM-FLW-010", "relation": "REFERENCE", "purpose": "Optional itinerary or path reference; keep service-pattern version and traveller itinerary distinct.", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] }, { "target": "WM-ECO-004", "relation": "COMPOSE", "purpose": "Optional profile-pinned money value representation for fare amount and currency only; no financial instrument lifecycle is imported.", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "target": "WM-PER-001", "relation": "REFERENCE", "purpose": "Optional purpose-limited passenger identity binding with separate authority and retention assessment; public service data needs no person link.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "WM-FLW-004", "relation": "REFERENCE", "purpose": "Optional shared corridor or terminal context only; freight records stay external.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "WM-FLW-006", "relation": "REFERENCE", "purpose": "Optional external consumer of qualified activity measures; no emission factors or calculation are asserted here.", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "target": "GTFS Schedule and GTFS Realtime", "relation": "ALIGN", "purpose": "Selected conceptual mapping for service data and operating assertions; immutable versions, feature profiles and round-trip tests required.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Transmodel, NeTEx and SIRI", "relation": "ALIGN", "purpose": "Conceptual domain alignment from official explanatory material; normative parts, implementation mappings and certification remain unverified.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "PROV-O", "relation": "ALIGN", "purpose": "Candidate provenance mapping for assertion derivation and attribution; no truth or permission inference.", "required": false, "source_refs": [ "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Declare the authority or operator role governing this service scope and each component custodian", "Pin namespace, service coverage, source releases and external master bindings", "Specify purpose, language, time-zone, tariff, access and retention profiles with responsible reviewers" ], "namespace_guidance": "Scope all source identifiers by issuing namespace and record type. Keep aggregate, component, feed message, schedule template, dated occurrence and external journey identities distinct; aliases require evidence.", "registry_links": [ "vr.wm-flw-007", "WM-FLW-009", "WM-FLW-010", "Adopting Dimension namespace and mandate registry" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalization is an adopted local record rule, not a claim that this research draft is canonical. Preserve source codes, decimals, units, unknowns and source precision.", "Keep service-day offsets and calendar dates separate from instants; preserve source timezone and conversion provenance." ], "patch_rules": [ "Require expected revision, actor scope, source evidence and reason. Version corrections and supersession; quarantine unresolved identity or schedule conflicts.", "Do not convert feed omission into cancellation or observed punctuality. Retire stale assertions from current views under the adopted freshness policy while preserving permitted evidence." ], "compatibility_rules": [ "Pin each import version, optional feature set and language/profile. Unknown or experimental features remain explicit rather than silently mapped.", "Changing stop identity, timing semantics, tariff interpretation, privacy scope or measure denominator requires compatibility review and migration evidence." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with namespace and revision", "Governed global identifier or IRI", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Instants use RFC 3339 with seconds and an explicit offset or Z. Keep effective, event, observation, source publication and ingestion times distinct. Preserve date-only calendar values and service-day offsets beyond 24 hours separately, with timezone and daylight-saving conversion policy; do not fabricate midnight instants.", "serial_naming_rule": "Use opaque service scope, artifact type and immutable sequence or revision. Keep personal identifiers out of filenames and public URLs.", "integrity_rule": "Record digest algorithm, content hash, origin and transformation chain when available. A digest does not prove source truth, authority, anonymity or safe operational use." }, "policies": [ "Reviewable draft under the single-provider waiver; independent external review and source/version checks remain open.", "Stewardship is assigned to authority, operator, data custodian and reviewer roles; no supplier or commercial brand owns the model by inference.", "Public service information and restricted movement evidence require distinct views. Default to minimum data and deny personal-data disclosure without explicit applicable authority.", "No function dispatches transport, issues tickets, completes bookings, charges fares, adjudicates concessions, changes safety controls or certifies accessibility.", "Jurisdictional rights, assistance duties, tariffs, licensing and disclosure obligations require a qualified adoption profile; no universal legal or numerical rule is supplied." ], "crud": { "read": [ "Return the authorized view with source, version, freshness, precision and uncertainty; public schedule access does not grant access to passenger links." ], "create": [ "Require governed scope, namespace, component authority, provenance and adopted profile; unresolved external references remain flagged." ], "update": [ "Record supported local revisions under concurrency control; keep contrary assertions and correction reasons without silently overwriting external masters." ], "delete": [ "Apply the approved retention schedule, legal holds and erasure duties separately to raw movement links, aggregates, copies and metadata. Retire service descriptions by supersession; erase personal payloads when required.", "Keep only a minimal non-identifying tombstone where lawful. History requirements do not authorize indefinite personal-data retention; local disposal does not delete external masters by implication." ] }, "roles": [ { "name": "Service authority", "responsibilities": [ "Approve service scope and component mandates" ] }, { "name": "Operator data custodian", "responsibilities": [ "Maintain source-bound schedules and operating assertions" ] }, { "name": "Passenger information reviewer", "responsibilities": [ "Review recognition, languages, accessibility qualifiers and advisories" ] }, { "name": "Tariff steward", "responsibilities": [ "Approve descriptive fare revisions and delegate entitlement decisions" ] }, { "name": "Privacy and records reviewer", "responsibilities": [ "Approve recipient views, risk assessments, retention and disposal" ] }, { "name": "Service analyst", "responsibilities": [ "Maintain measure definitions, uncertainty and compatible baselines" ] } ], "access": { "default_rule": "Deny restricted service-use and raw movement access unless recipient, purpose, scope and authority are established. Explicitly approved public descriptions are separate from restricted records.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency or statutory access requires a documented basis, bounded recipient and scope, responsible actor and subsequent review; no blanket bypass.", "Authority to edit a component does not imply authority to disclose all data in the aggregate." ], "audit_requirements": [ "Record minimal actor, purpose, scope, revision, decision and result for reads, edits, exports and disposal under an approved retention profile.", "Keep proof of disclosure assessment without copying sensitive raw journeys into public audit metadata." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md and the adopting Dimension authority/access policies", "spec.yaml and all publication holds", "Pinned service profiles, source releases and external master bindings" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one governed passenger service aggregate, with separate network, availability, operating assertions, passenger context, fares and service evidence. Legacy F7 is reconciled and generic journeys remain externally mastered. A separate frozen local no-tools self-audit found no critical conflicts. This is a noncanonical reviewable draft with independent-review, source/version, adoption-profile and executable-conformance holds.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Scope, release, stop, pattern, occurrence and external journey identities are distinct." }, { "dimension": "lifecycle", "status": "covered", "notes": "Local draft, effective, superseded and retired releases; assertion and advisory revision evidence." }, { "dimension": "relationships", "status": "covered", "notes": "Optional service-use, journey, itinerary, money and neighboring-domain references preserve external masters." }, { "dimension": "temporal", "status": "covered", "notes": "Calendar exceptions, service-day offsets, headways, time zones, prediction/observation and ingestion times." }, { "dimension": "provenance", "status": "covered", "notes": "Source releases, derivation, attribution and hashes; provenance is not truth." }, { "dimension": "ownership", "status": "covered", "notes": "Role-based authority per component; aggregate custody does not transfer legal rights." }, { "dimension": "validation", "status": "gap", "notes": "Research structure is validated; nested instance schemas, mapping fixtures and runtime conformance remain unfinished." }, { "dimension": "access", "status": "covered", "notes": "Public descriptions are separated from purpose-limited restricted service-use records." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Payload-specific disposal, legal holds and minimal lawful tombstones reconcile continuity and erasure." }, { "dimension": "interoperability", "status": "gap", "notes": "Selected GTFS and conceptual Transmodel-derived alignment; pinned feature mappings and round-trip tests deferred." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Codes, signs, spoken names and observation provenance do not substitute for identity." }, { "dimension": "direct properties", "status": "covered", "notes": "Modes, service area, pattern membership, headway, price and quantity carry scope and units where applicable." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Seven proposed local operations with prerequisites and refusal behavior; no dispatch or external release." }, { "dimension": "accessibility", "status": "covered", "notes": "Boarding, path and vehicle evidence are separately qualified, including unknowns." }, { "dimension": "regional applicability", "status": "gap", "notes": "Selected transit exchange concepts plus US metric and UK privacy guidance; local legal and specialist modal profiles remain open." } ], "known_omissions": [ "Independent external review is waived; a separate local Codex self-audit does not replace it.", "Direct HTTP checks are not attempted under the owner-reported sandbox restriction. Content access through the web tool does not prove measured URL status, immutable versions, licensing or current applicability.", "Normative Transmodel, NeTEx and SIRI documents, mapping profiles and certification are not verified.", "Full aviation, maritime, intercity ticketing, micromobility and informal-service profiles need additional research; private movement is outside this scope.", "Nested data schemas, tariff/temporal engines, accessibility acceptance fixtures, privacy disclosure procedures and performance computations remain unimplemented.", "Passenger compensation, statutory assistance, concession adjudication and emergency operations remain external policy dependencies." ], "conflicts": [], "regional_assumptions": [ "GTFS concepts are used as exchange evidence, not as universal transport law.", "Transmodel explanatory material supports conceptual distinctions only; broad domain coverage does not require importing every domain into this aggregate.", "US transit metric definitions and UK anonymisation guidance are examples that need adoption review elsewhere." ], "adversarial_checks": [ "A reused trip identifier across feeds or service days must not merge distinct occurrences.", "A departure beyond 24:00 and a daylight-saving transition must preserve service-day semantics.", "An absent realtime update cannot become evidence of on-time operation or cancellation.", "A station accessibility flag cannot establish an accessible interchange or vehicle accommodation.", "Boardings cannot be reported as unique passengers, and low counts cannot be declared anonymous using a fixed floor alone.", "Recording a fare condition or booking channel cannot issue a ticket, approve eligibility or reserve capacity.", "Retaining revision metadata must not defeat lawful erasure of passenger-linked payloads." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The root is one governed passenger service context whose independently versioned components have explicit custodians and external master references. It is neither the abstract field of all mobility nor one journey event. Registry standalone-mm is a record-plane classification. Registry parentage of WM-FLW-009 does not transfer ownership of generic person or vehicle journey lifecycle to this aggregate." }, "decisions": [ { "concept": "Governed aggregate root", "disposition": "accepted", "rationale": "Scope identity and component mandates make the root a bounded service context. The draft explicitly preserves independently mastered persons, vehicles, facilities and organizations rather than equating aggregate stewardship with universal ownership." }, { "concept": "Journey parentage and lifecycle", "disposition": "qualified", "rationale": "WM-FLW-009 parentage is retained in the frozen registry context. Service occurrence selectors and local assertions are permitted, while generic passenger and vehicle journey identity and lifecycle remain externally mastered. Service-use bindings do not create a second traveller history." }, { "concept": "Legacy route and stop equivalence", "disposition": "corrected", "rationale": "The admitted questions distinguish line, pattern variant, ordered stop occurrence, boarding hierarchy and external path. Similar signs, names or nearby coordinates cannot silently merge two stop masters." }, { "concept": "Source release continuity", "disposition": "accepted", "rationale": "The release finding separates continuing scope identity from effective coverage and derivation. Patch rules preserve supported corrections and uncertainty while retention rules limit personal payload history." }, { "concept": "Service-day and instant semantics", "disposition": "accepted with profile dependency", "rationale": "Questions and service rules preserve calendar dates, after-midnight offsets and timezone conversion separately from RFC 3339 instants. The occurrence function requires a pinned profile and reports ambiguity rather than inventing a daylight-saving resolution." }, { "concept": "Flexible availability and booking", "disposition": "separated", "rationale": "Zone and notice questions describe availability and request conditions only. Capacity and eligibility remain uncertain until an external process confirms them; no function promises or executes a reservation." }, { "concept": "Operating evidence and missing data", "disposition": "accepted", "rationale": "Occurrence questions distinguish predictions, observations and unavailable data, with source and schedule reconciliation. Feed silence cannot imply punctuality, completion or cancellation, and past predictions do not automatically become measurements." }, { "concept": "Advisory authority and effects", "disposition": "bounded", "rationale": "Advisory records require approval scope, affected selectors and revision evidence. Local draft storage neither distributes a message nor suspends service, dispatches vehicles or proves restoration." }, { "concept": "Accessible interchange", "disposition": "qualified", "rationale": "Boarding, pathway, vehicle and dated disruption evidence remain separate. Questions preserve unknowns and connection constraints without converting a positive location flag into an end-to-end accessibility guarantee." }, { "concept": "Fare and money boundaries", "disposition": "qualified", "rationale": "Fare descriptions and applicability explanations preserve tariff revisions, category/media qualifiers and missing inputs. The optional money composition is limited to a profile-pinned value representation; instrument, ticket, payment and eligibility lifecycle remain external." }, { "concept": "Ridership interpretation", "disposition": "accepted with definition dependency", "rationale": "Measures require quantity, denominator, method, period and source evidence. Boarding counts do not become unique passengers or end-to-end journeys. Missing-data treatment and revised baselines are required inputs to later implementations." }, { "concept": "Default anonymity and disclosure floor", "disposition": "rejected", "rationale": "The legacy and supplement shortcuts are not admitted. The structure requires contextual linkability, singling-out and repeated-release assessment, recipient-specific authorization and withholding when unresolved. No fixed count threshold establishes anonymity." }, { "concept": "Retention and lawful disposal", "disposition": "accepted with policy dependency", "rationale": "Restricted journey links have expiry and disposal questions. Service rules distinguish raw payloads, copies, aggregates and minimal lawful tombstones, so version continuity does not demand indefinite retention of identifiable movement data." }, { "concept": "Source support and executable conformance", "disposition": "limited and deferred", "rationale": "Selected official sources support transit concepts and the stated distinctions, not the authored hierarchy or an implemented system. Normative Transmodel-derived documents, immutable rolling-source pins, nested schemas, profile mappings and operational acceptance fixtures remain unverified." }, { "concept": "Independent review and source status", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the owner override. This assessment is a separate local Codex self-audit, not an independent provider pass. Web-tool text access cannot be promoted to direct HTTP measurements or complete current-version verification." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not an independent second-provider review.", "Live source and version verification remains incomplete. Selected content from all ten sources was read through the web research tool, but direct HTTP was not attempted under the owner-reported sandbox restriction and all statuses remain unmeasured. The coordinator checker is supplied. Rolling references, normative standard editions, licensing and current applicability require verification.", "Adoption profiles require qualified review of component mandates, local transport and privacy obligations, assistance and concession policies, temporal conversions, tariffs, metric definitions, mode coverage and recipient-specific disclosure risk. Selected US and UK guidance is not universal authority.", "Nested instance schemas, pinned neighbor bindings, GTFS/Transmodel-derived/PROV-O mappings, source reconciliation, privacy procedures and adversarial acceptance fixtures remain incomplete. All seven functions are proposed local operations; no runtime, safety, accessibility or legal-compliance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore an independent external reviewer and verify immutable source revisions, normative standards and licensing before canonical promotion.", "Develop and test adoption profiles with repeated stops, reused identifiers, midnight and daylight-saving transitions, missing realtime data, inaccessible transfers, unresolved booking requests and changing fare conditions.", "Build nested schemas and reversible mappings with pinned journey, itinerary and money bindings; test corrections, conflicting sources and partial data without duplicating external masters.", "Validate ridership definitions and recipient-specific disclosure assessment against linkage, repeated releases, suppression and lawful erasure; expand specialist modal and regional coverage separately." ] }, "statistics": { "sources": 10, "bundles": 7, "layers": 14, "findings": 14, "questions": 42, "artifacts": 14, "functions": 7 } }