← Back to catalogue
Published

Policy / Rule

vr.wm-knw-012 · wm-knw-012-policy-rule

Provide the format-neutral context an agent needs to identify, classify, compose, govern, version and interpret an executable or interpretable normative statement, while delegating condition expression, runtime evaluation, enforcement and governed-process semantics to referenced models.

World Models Information and virtual systems INF.KNW.POL

Bundle → Layer → Finding → Questions Filled

6 bundles · 13 layers · 24 findings · 101 questions

Normative identity and classification What the statement is, how it is durably identified and versioned, and what normative force it carries.

Identity and designation

Durable identification, naming, citation and version identity of the statement, independent of storage format.

Statement identifier and naming

How a normative statement and its contained rule slots are uniquely identified, titled and cited across systems.

  1. Which authoritative master-system identifier designates this statement, and which system issues it? identity
  2. Which governed global identifier or IRI resolves this statement for external citation? interoperability
  3. How are the statement container and its contained rule slots identified separately? composition
  4. Which official titles, short titles and citation forms are registered, and in which languages? definition

Version identity and point-in-time expression

Separation of the abstract work from its dated expressions and rendered manifestations, and the identity of each version.

  1. How is the abstract statement distinguished from its dated versions and its rendered manifestations? classification
  2. What version designator is assigned to each expression, and how is version ordering determined? identity
  3. Which expression is the current consolidated one, and which are historical point-in-time versions? state
  4. What must change on the record whenever the content of an expression changes? constraint

Normative classification

The force, modality, defeasibility and instrument genre of the statement.

Deontic modality, force and defeasibility

Which normative modality each rule slot carries, whether it can be violated, how severely, and whether it can be defeated.

  1. Which deontic modality does each rule slot carry: obligation, permission, prohibition or right? classification
  2. Is the statement an alethic necessity that cannot be violated, or a deontic obligation that can be? definition
  3. What enforcement level on the graded severity scale applies when the statement is violated? measurement
  4. Is the statement defeasible, and by which declared mechanism may it be defeated? constraint
  5. Does the statement express a strong permission acting as an explicit exception to a prohibition? exception

Instrument genre and binding form

What kind of instrument the statement is and how it binds, including whether it is a natural-language original or a derived machine-interpretable rendering.

  1. What instrument genre is this statement: legislation, regulation, standard, internal directive, contract or offer? classification
  2. Does the statement bind unilaterally, or does it require an identified counterparty to be in force? relationship
  3. Is this a natural-language original, a machine-interpretable statement, or a rendering derived from a natural-language original? interoperability
  4. Which taxonomy supplies the genre code, and who governs that taxonomy? authority
Authority and applicability Who issued the statement, under what mandate, who now owns the record, and over what it claims to apply.

Authority and accountability

Issuing authority and mandate at origin, and accountable ownership of the record afterwards.

Issuing authority and mandate

Which party issued the statement, under what legal or organisational competence, and by which recorded adoption decision.

  1. Which party issued the statement, and under what legal or organisational mandate? authority
  2. Which body formally adopted the statement, and by which recorded decision? decision
  3. Within what competence is the issuing authority empowered to bind? constraint
  4. What evidence supports the authority claim, and where does that evidence record live? evidence

Ownership, stewardship and roles

Accountable ownership of the statement record after issuance and the roles responsible for review, interpretation and succession.

  1. Who is the accountable owner of the statement record after issuance? ownership
  2. Which named roles are responsible for periodic review and for answering interpretation requests? process
  3. How are role assignments recorded so that a responsible party can be resolved for any past instant? temporal
  4. What happens to ownership when the issuing authority is reorganised or dissolved? lifecycle

Applicability scope

Where, to whom, to what and under which conditions the statement claims to apply.

Jurisdiction and territorial scope

The legal or organisational orders and territories over which the statement claims application, and how overlapping claims are declared.

  1. Over which jurisdictions or territories does the statement claim application? spatial
  2. Which connecting factor triggers application when a party, resource or activity sits outside the issuing territory? constraint
  3. Which subject-matter competence, as distinct from geography, bounds the statement? classification
  4. How are overlapping jurisdictional claims from different issuing authorities declared? relationship

Subject, target, action and context scope

The parties, resources, actions and contextual conditions that bring the statement into application, expressed as references into models that own those things.

  1. Which parties, roles or subject attributes fall within the statement's application? relationship
  2. Which resources or object classes are the target of each rule slot? composition
  3. Which actions or operations does each rule slot govern, and from which action vocabulary? interoperability
  4. Which environmental or contextual conditions must hold for the statement to be applicable? constraint
  5. Which processes, systems or datasets declare themselves governed by this statement? relationship
Normative content and composition The internal structure of the statement, how it composes into and inherits from larger statements, and how it binds to externally owned condition expressions and defined terms.

Rule structure and composition

Rule-slot inventory, atomicity, containment in policy sets and inheritance from parent statements.

Rule-slot inventory and atomicity

The complete set of rule slots a statement contains, whether each is atomic, and which duties, remedies or consequences attach to them.

  1. What is the complete inventory of rule slots the statement contains, and is each one atomic? composition
  2. Must the statement contain at least one rule slot to be valid? requirement
  3. How is a compact statement expanded into atomic rule slots without changing meaning? process
  4. Which duties, remedies or consequences attach to a given permission or prohibition slot? relationship

Policy-set containment and inheritance

How the statement nests inside larger policy sets and inherits rules or properties from parent statements without circularity.

  1. Is the statement contained in a larger policy set, and what is the containment path? composition
  2. From which parent statements does this one inherit rules or properties? relationship
  3. How is circularity in the inheritance graph prevented and detected? validation
  4. Which parent properties are explicitly not transferred to the child statement? constraint

Condition binding and interpretation

References to externally owned condition expressions, the parameter values this subject sets, and the vocabulary that fixes the meaning of terms.

Constraint expression binding

How each rule slot points at a constraint or rule expression owned by the referenced constraint model, and what binding metadata travels with the pointer.

  1. Which externally owned constraint or rule expression does each rule slot bind to? relationship
  2. At which binding point does the expression attach: rule condition, action refinement, or collection refinement? composition
  3. Which expression language and version is the referenced constraint written in? interoperability
  4. What happens to the statement when a referenced expression is unavailable or not understood? exception

Parameterisation and tailoring values

Parameters the statement exposes and the subject-specific values the adopting organisation sets, kept distinct from amendment of the statement itself.

  1. Which parameters does the statement expose, and what are their permitted value sets? definition
  2. Which parameter values has the adopting organisation set for this statement? decision
  3. Which unit and datatype governs each parameter value? measurement
  4. How is a tailoring change to a parameter distinguished from an amendment of the statement? lifecycle

Defined terms and vocabulary binding

Which governed vocabulary fixes the meaning of terms used in the statement, which terms are defined locally, and which profiles a processor must understand.

  1. Which controlled vocabulary supplies the meaning of terms used in the statement? definition
  2. Which locally defined terms override an otherwise applicable general definition, and within what scope? constraint
  3. Which profile identifiers must a consuming processor understand before interpreting the statement? interoperability
  4. How are term definitions versioned relative to the statement that uses them? temporal
Precedence, conflict and exceptions How the statement declares its precedence relative to other statements, how conflicts are named, and which derogations and open interpretations are on record.

Precedence and conflict declaration

Declared strategy identifiers and pairwise superiority relations that determine which statement prevails.

Combining and hit-policy declaration

The strategy identifier the statement declares for reconciling multiple applicable rule slots, and where the normative definition of that strategy lives.

  1. Which combining or hit-policy strategy identifier does the statement declare for its rule slots? decision
  2. Where is the normative definition of that strategy published, and who owns its execution? authority
  3. Is the declared strategy order-sensitive, and if so what fixes the order? constraint
  4. Which conflict term applies when a permission and a prohibition both match? exception

Override and superiority relations

Pairwise precedence between this statement and others, the ground on which precedence rests, and what is recorded when nothing resolves a conflict.

  1. Which other statements does this one override, and which override it? relationship
  2. On what declared ground does an override rest, such as specificity, recency or hierarchy of authority? authority
  3. Is the resulting precedence graph acyclic, and how is that checked? validation
  4. What is recorded when a conflict is detected but no superiority relation resolves it? exception

Exceptions and open interpretations

Registered derogations from the statement and formally recorded competing readings of it.

Derogation and waiver declaration

Registered exceptions, waivers and derogations from the statement, their granting authority, scope, period and compensating obligations.

  1. Which exceptions, waivers or derogations from this statement are currently registered? exception
  2. Which authority may grant a derogation, and is that authority distinct from the issuer? authority
  3. For which parties, resources or period does each derogation hold? temporal
  4. Which compensating obligation or remedy attaches to a granted derogation? requirement

Declared conflicts and alternative interpretations

Competing readings, known contradictions and semantic gaps recorded against the statement so that consumers are not misled into assuming settled meaning.

  1. Which competing interpretations of the statement are formally recorded as alternatives? quality
  2. Which contradictions with other statements are identified but not yet resolved? validation
  3. Which parts of the applicable standard's semantics are non-normative or incomplete for this statement? interoperability
  4. Who decides between recorded alternatives, and how is that decision captured? decision
Lifecycle, time and provenance How the statement record moves through its states, over which intervals it is in force and efficacious, and where its content came from.

Lifecycle and supersession

Permitted states of the statement record and the amendment, replacement and repeal relations between statements.

Statement lifecycle state model

The permitted lifecycle states of the statement record, the transitions between them, and which transitions depend on an external approval decision.

  1. What are the permitted lifecycle states of the statement record, from draft to repealed? lifecycle
  2. Which transitions are permitted, and which require an external approval decision? state
  3. How is suspension recorded, and what does it change about applicability while it lasts? process
  4. Which lifecycle events must carry a date, and which are merely recorded? event

Amendment, supersession and repeal

Which statements this one amends, replaces or repeals, at what provision granularity, and what a processor must do when replacement is declared.

  1. Which statements does this one amend, replace or repeal, and at which provision granularity? relationship
  2. Which amending instrument produced the current consolidated expression? provenance
  3. What must a processor do when the statement declares that it has been replaced? requirement
  4. How is a partial repeal distinguished from a full repeal in the record? classification

Temporal validity

The intervals over which the statement is in force, efficacious and applicable, and the separation of event time from record time.

Validity intervals and record time

Distinct in-force, efficacy and applicability intervals, expressed as RFC 3339 instants, with event time kept separate from observation or ingestion time.

  1. When does the statement enter into force, and is that distinct from when it was adopted? temporal
  2. Over which interval is the statement efficacious, and can efficacy begin after entry into force? state
  3. To which facts or periods does the statement apply, as distinct from when it is in force? constraint
  4. What is the observation or ingestion instant at which each dated occurrence was captured in the register? provenance
  5. How is an instant with an unknown local offset represented without falsely asserting UTC local time? requirement

Provenance and source mapping

Where the statement's content came from, who is accountable for it, and which authoritative provision each rule slot derives from.

Authoring, derivation and source mapping

The attribution and derivation chain of the expression, and the mapping from rule slots to authoritative source provisions including fidelity of any machine rendering.

  1. Which agents authored, revised or are otherwise accountable for the expression's content? provenance
  2. From which prior entity was this expression derived, and by which activity? process
  3. Which authoritative source provision does each rule slot derive from? composition
  4. Is the machine-interpretable statement a faithful rendering of a natural-language original, and who certified that? evidence
  5. Which primary source is cited, as distinct from an intermediate compilation or consolidation? quality
Assurance, disclosure and interoperability Declared alignments and structural conformance of the statement, its review status, and how the record itself is classified, disclosed and retained.

Assurance and alignment

Review status and recorded defects of the statement, and its declared structural conformance and standard alignments.

Statement quality and review status

Review cadence, recorded defects in the statement itself, and confidence in any machine-interpretable rendering.

  1. When was the statement last reviewed, and when is the next review due? quality
  2. Which recorded defects affect the statement, such as ambiguity, unreachable rule slots or missing definitions? validation
  3. What is the declared confidence in the machine-interpretable rendering of the statement? measurement
  4. Which review outcomes require the statement to be withdrawn from use? decision

Structural conformance and standard alignment

Which external standards or profiles the statement declares alignment with, which structural requirements make it well-formed, and how published manifestations are integrity-checked.

  1. Which external standards or profiles does the statement declare alignment with, and on what evidence? interoperability
  2. Which structural requirements must hold for the statement to be well-formed, independent of any runtime? requirement
  3. Which declared alignments are partial, and where do the semantics diverge? quality
  4. Which serialization bindings are published, and how is manifestation integrity verified? security

Disclosure and retention

Sensitivity classification and publication audience of the statement record, and retention and disposition of superseded expressions.

Record classification, access and retention

How the statement record itself is classified and published, and how long its superseded expressions are retained before a declared disposition.

  1. What sensitivity classification applies to the statement record itself, as distinct from what it governs? security
  2. Which statements are published openly, and which are restricted to named audiences? access
  3. Which parts of a statement may be redacted while leaving it citable? exception
  4. How long must superseded expressions be retained to support point-in-time reconstruction? retention
  5. Which disposition action applies at the end of retention, who executes it, and what tombstone remains resolvable? lifecycle

Classifiers Filled

Family
World Models
Category
Information and virtual systems
Entry kind
aggregate
Navigation path
NAV.INF.KNW.POL
Domain
INF.KNW.POL
Industry
Cross-industry
Tags
policyruleinf.knw.pol

What it is Filled

Describes an individual normative statement (policy, policy set, or atomic rule slot) as a governed record: identity and version identity, deontic or alethic force, issuing authority and mandate, applicability scope, rule-slot structure, declared precedence and conflict strategy, registered derogations, lifecycle and temporal validity, provenance and source-provision mapping, declared standard alignments, and record classification and retention. Storage- and interface-neutral: JSON, YAML, Markdown, XML, RDF, Git trees, MCP surfaces and document databases are manifestations of one record. Carries references and binding metadata for constraint expressions but never the expression grammar, and never renders, executes, enforces or logs a decision.

In scope

  • Identity, naming, citation forms and version identity, separated into abstract work, dated expression and rendered manifestation.
  • Deontic modality (obligation, permission, prohibition, right), alethic-versus-deontic classification, enforcement level and defeasibility.
  • Instrument genre and binding form: legislation, regulation, standard, internal directive, set, offer, agreement.
  • Issuing authority, mandate, adoption-decision reference, and post-issuance record ownership and stewardship roles.
  • Applicability scope: jurisdiction, territory, subject-matter competence, in-scope parties, target resources, governed actions and contextual conditions.
  • Rule-slot inventory, atomicity, policy-set containment and inheritance.
  • References and binding metadata for externally owned constraint or rule expressions, plus subject-specific parameter values and tailoring.
  • Declared precedence: combining or hit-policy strategy identifiers, conflict terms and pairwise superiority relations.
  • Registered exceptions, waivers and derogations, and recorded alternative interpretations and known contradictions.
  • Lifecycle states, amendment, supersession and repeal; in-force, efficacy and applicability intervals with event time and record time.
  • Provenance, derivation, attribution and mapping from rule slots to authoritative source provisions.
  • Declared standard alignments, structural well-formedness requirements, manifestation integrity, record classification, retention declaration and disposition class.

Out of scope

  • Constraint and rule expression grammar, operator and operand vocabularies, and logical composition semantics (WM-KNW-013).
  • Runtime policy evaluation, decision rendering, obligation discharge, enforcement actions and decision results (referenced decision or enforcement runtime).
  • Audit-trail entities, event streams and log storage for evaluation, enforcement or access.
  • Process, activity and task definitions and their execution state (WM-ACT-003).
  • Projection, disclosure and output-shape semantics of specialised disclosure policies (WM-XCT-003).
  • Party, organisation, resource and place master data.
  • Compliance risk assessment, control-effectiveness measurement and non-compliance case handling.
  • Sanction computation, penalty scales and litigation records.
  • Storage engines, serialization formats, access interfaces and repository mechanics.
  • Cryptographic signing ceremonies and PKI trust management.

Why it exists Filled

Provide the format-neutral context an agent needs to identify, classify, compose, govern, version and interpret an executable or interpretable normative statement, while delegating condition expression, runtime evaluation, enforcement and governed-process semantics to referenced models.

Distinguishing features Filled

  • A normative statement with authority, scope, version and precedence, not its runtime evaluation.
  • Delegates condition expressions to a constraint model and enforcement to referenced runtimes.
  • Unlike a process, it states what must or may happen, not the steps.
  • Unlike a disclosure policy, it is general rather than output-shape specific.

What robots and AI may and may not do Filled

Must not

  • Render permit or deny decisions within this model.
  • Publish a statement without issuing authority.
  • Treat alignment as conformance.
  • Change a published version in place.
  • Hide coverage gaps.

Only with a human decision

  • Enacting or repealing a policy.
  • Granting derogations.

May

  • Register a statement with its issuing authority and version.
  • Resolve which version applies at an instant.
  • Declare applicability scope and precedence.
  • Register derogations with their basis.

Moral aspects Filled

  • Rules govern people's rights and duties; clarity and accessibility of rules is a fairness matter.
  • Conflicts between rules can produce unjust outcomes if precedence is wrong.

Who is affected

  • People subject to the rules
  • Issuing authorities
  • Enforcing parties

Owners Filled

Steward

The adopting Dimension MUST name one accountable owner package for the policy/rule register and MUST NOT split identifier minting for a single statement work across packages.

Roles

Policy register owner
Own the register, the identifier-minting rule and the fallback justification record; Approve registration, supersession and disposition of statement records; Maintain the declared references to the constraint model and the decision runtime
Issuing authority representative
Assert the mandate under which a statement is issued; Confirm the adoption decision reference and the entry-into-force instant; Notify the register of reorganisation or dissolution affecting ownership
Normative editor
Draft and revise rule slots, modality, enforcement level and defeasibility declarations; Maintain provision anchors and the mapping from slots to authoritative source text; Record modification type and affected provisions on every amendment
Interpretation steward
Record alternative interpretations, known contradictions and semantic gaps; Maintain superiority relations and the acyclicity assertion of the precedence graph; Route unresolved conflicts to the deciding authority and record the outcome
Records and retention steward
Declare the governing retention schedule, retention period and disposition class; Ensure superseded expressions stay resolvable for the reconstruction window; Maintain tombstones after disposition executed by the retention authority
Interoperability steward
Maintain alignment declarations, divergence notes and required profile identifiers; Verify manifestation digests and reject mismatched manifestations; Review projections to external languages for recorded fidelity loss

Links to other meta-models Filled

child

  • WM-POL-001 - This model is the instance-level normative statement within the parent policy domain, which retains portfolio taxonomy and cross-policy programme governance.

references

  • WM-KNW-013 - Bind rule slots to constraint or rule expressions owned there. This model carries the reference, the binding point, the expression-language reference and subject-specific parameter values only, and reproduces neither the expression grammar nor that model's lifecycle or operational functions.
  • WM-ACT-003 - Carry applicability pointers to governed processes. The governance edge is authored by WM-ACT-003; no activity, task, sequence or execution state is modelled here.
  • Referenced decision or enforcement runtime (XACML PDP/PEP or ABAC access decision function) - Name the runtime that evaluates and enforces this statement. This model owns no evaluation, execution, enforcement or audit-trail semantics and stores no decision result or decision log.
  • Party / Agent model (adopting-Dimension registry target unresolved) - Resolve issuing authority, adopting body, assigner, assignee, bearer and responsible-party references; party master data is not held here.
  • Resource / Asset model (adopting-Dimension registry target unresolved) - Resolve rule-slot targets and target collections; resource master data is not held here.
  • Jurisdiction / Place model (adopting-Dimension registry target unresolved) - Resolve jurisdiction and territorial coverage references used by applicability scope.

extends

  • WM-XCT-003 - Incoming specialisation: projection and disclosure policies specialise this model with output-shape semantics. Generic identity, authority, lifecycle and conflict machinery is retained here per the relation rationale, and output-shape semantics are not modelled here.

aligned

  • ODRL Information Model 2.2 (W3C) - Alignment for policy and rule structure, action and target relations, constraint placement, conflict term, inheritFrom and profile conformance. Recorded as alignment, not conformance.
  • XACML 3.0 (OASIS) and LegalRuleML 1.0 (OASIS) - Alignment for policy-set containment, required identifiers and versions, combining algorithm declaration, deontic operators, superiority relations and temporal characteristics. Recorded as alignment, not conformance.
  • Akoma Ntoso 1.0 (OASIS) and European Legislation Identifier (Publications Office of the EU) - Alignment for FRBR work/expression/manifestation identity, IRI naming, dated lifecycle events and point-in-time consolidation.
  • PROV-O (W3C) - Alignment for attribution, derivation, revision, generation and invalidation of statement expressions.

composes

  • SBVR 1.5 (OMG) - Supplies the alethic-versus-deontic modality distinction, enforcement level as a graded severity scale, and the governed-vocabulary binding used to fix the meaning of terms.

neighbor

  • WM-KNW-013 Constraint / Rule expression - The condition itself (left operand, operator, right operand, logical operands, refinements) and its own lifecycle are owned there. This model carries only the reference, the binding point, the expression-language reference and subject-specific parameter values.
  • Referenced decision or enforcement runtime (XACML PDP/PEP, ABAC access decision function) - Evaluation, decision rendering, obligation discharge and decision logging are runtime concerns. This model declares which combining or hit-policy strategy applies and where its normative definition lives; it never evaluates or enforces.
  • WM-ACT-003 Process - Activities, tasks, sequence and execution state are owned there. The governance edge is authored by WM-ACT-003; this model only records applicability pointers to governed processes.
  • WM-XCT-003 Projection / disclosure policy - Output-shape, redaction-transform and disclosure-projection semantics are specialised there. Generic identity, authority, lifecycle and conflict machinery is retained here, as the relation rationale requires.
  • Compliance management system (obligations monitoring) - Compliance risk evaluation, monitoring, reporting and non-compliance handling sit in a compliance management model. This model holds the obligation statement and its governance metadata only.
  • Records and document management - Manifestation storage, format conversion, digital preservation and disposal execution belong to records management. This model holds work/expression identity, retention declaration, disposition class and tombstone.
  • WM-POL-001 parent policy domain - Domain grouping, portfolio taxonomy and cross-policy programme governance sit with the parent. This model describes one normative statement instance.

parent

  • WM-POL-001

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative master-system identifier issued by the system of record for the statement or artifact, such as the enacting or publishing authority's instrument identifier or the policy administration system's policy identifier.
  • Governed global identifier or IRI from a recognised scheme, such as an ELI legislation identifier, an Akoma Ntoso FRBR IRI, or an ODRL policy uid.
  • UUID or ULID minted by the adopting Dimension, stored together with the recorded reason that no higher-priority identifier was available.
  • A date, a title, a version designator alone, a digest alone or a file path is never an identifier and MUST NOT be promoted to one.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • A policy statement has an issuer, a version, a scope, effective dates and rule slots.
  • Often confused with a constraint expression, an access decision, a process and a guideline.

Capabilities and actions required Filled

  • Register a normative statement: Create a governed record for a normative statement with an identifier, an issuing authority, an instrument genre and at least one rule slot.
  • Issue a new version expression: Create a new dated expression of an existing statement work and link it to the expression it supersedes.
  • Declare applicability scope: Record the jurisdictions, parties, targets, actions and contextual conditions that bring the statement into application.
  • Bind a constraint expression reference: Attach a reference to an externally owned constraint or rule expression at a named binding point, with its expression language and unresolved-reference handling.
  • Declare precedence and conflict strategy: Record the combining or hit-policy strategy identifier, the conflict term, and pairwise superiority relations against other statements.
  • Record a lifecycle transition: Record a transition of the statement record such as approval, publication, entry into force, suspension, amendment or repeal.
  • Resolve the expression applicable at an instant: Given a work identifier and an instant, return the expression that was in force, efficacious or applicable at that instant.
  • Register a derogation: Record a waiver, exception or derogation from named rule slots, with its granting authority, beneficiaries, period and compensating obligations.
  • Declare a standard alignment: Record an alignment to an external standard or profile, with evidence, scope and any semantic divergence, without asserting conformance.

Hazards and failure modes required Filled

  • Wrong version applied.
  • Unresolved conflicts.
  • Unenforceable or ambiguous rules.

Standards and interfaces required Filled

  • OASIS XACML.
  • W3C ODRL.
  • OMG SBVR.
  • OASIS LegalRuleML.
  • Akoma Ntoso.

Context of use required Filled

  • Jurisdiction modelling assumes a state, sub-state or supranational legal order with an identifiable issuing authority; ELI and Akoma Ntoso reflect European and Commonwealth drafting practice and may need extension for federal-tribal, customary or religious orders.
  • ELI is a European scheme; adopting Dimensions outside the EU must name an equivalent governed legislation identifier or fall back to a locally minted IRI, recording the reason.
  • Retention periods, disposition classes and publication-audience categories are jurisdiction-specific and are always declared on the record rather than defaulted by this model.
  • Official titles are assumed multilingual and script-neutral; no Latin-script or single-authentic-language assumption is made, though authentic-version equivalence is left as a gap.
  • Personal-data handling assumes the adopting Dimension has its own privacy regime; no specific regional data-protection law is presumed.

Sources Filled

  1. ODRL Information Model 2.2 - World Wide Web Consortium (W3C)
  2. eXtensible Access Control Markup Language (XACML) Version 3.0 - OASIS
  3. LegalRuleML Core Specification Version 1.0 - OASIS
  4. Akoma Ntoso Version 1.0 Part 1: XML Vocabulary - OASIS
  5. Semantics of Business Vocabulary and Business Rules (SBVR), Version 1.5 - Object Management Group (OMG)
  6. Decision Model and Notation (DMN), Version 1.5 - Object Management Group (OMG)
  7. NIST SP 800-162, Guide to Attribute Based Access Control (ABAC) Definition and Considerations - National Institute of Standards and Technology (NIST)
  8. PROV-O: The PROV Ontology - World Wide Web Consortium (W3C)
  9. RFC 3339: Date and Time on the Internet: Timestamps - Internet Engineering Task Force (IETF)
  10. OSCAL Control Catalog Model concepts - National Institute of Standards and Technology (NIST)
  11. European Legislation Identifier (ELI) - Publications Office of the European Union
  12. ODRL Formal Semantics (Editor's Draft) - W3C ODRL Community Group
  13. ISO 37301:2021 Compliance management systems - Requirements with guidance for use - International Organization for Standardization (ISO)

Open questions

  • Multilingual authenticity: equivalence, precedence and divergence between authentic language versions of one statement, and the authority that certifies a translation. Declared as a gap with no cited source fixing the structure; needs a primary source before any structure is invented.
  • Delegation chains where an authority empowers a subordinate body to issue statements. Only a single mandate-basis reference is modelled, which cannot express multi-step delegated rule-making or the ultra vires consequences of a broken chain.
  • Retention floor when the applicability window is open-ended, and its interaction with the delegated privacy-erasure path where this model records only that a removal occurred. Needs a resolution rule that keeps point-in-time reconstruction reproducible without asserting unbounded retention.
  • Function-surface completion for record classification, retention declaration, parameter tailoring and defect or alternative-interpretation recording, each of which is required or distinguished by the service layers but has no function. Deferred because add_functions is barred in single-provider mode and inventing them here would be unsourced.
  • Customary, religious and indigenous normative orders whose authority structures do not resolve to an identifiable issuing body with a dated enactment, and the related regional assumption that ELI and Akoma Ntoso drafting practice generalises beyond European and Commonwealth orders.
  • Whether the access scope vocabulary should name subject-plane scopes (work, expression, rule slot, manifestation) or publish an explicit mapping onto the fixed record-plane scopes, and whether record-classification-access-and-retention should split into separate classification and retention findings at the next revision.
  • Equivalence, precedence and divergence between multiple authentic language versions of the same statement, and the authority that certifies a translation.
  • Customary, religious and indigenous normative orders whose authority structures do not map onto an identifiable issuing body with a dated enactment.
  • Negotiation and contract-formation workflow between an ODRL Offer and an Agreement; only the resulting genre and binding form are carried.
  • Cryptographic signature, seal and long-term validation of enacted instruments; only a content digest for manifestation integrity is modelled.
  • Sanction scales, penalty computation and enforcement outcomes beyond the ordinal enforcement level.
  • Machine-checkable semantics for cross-standard conflict resolution, because no cited normative source supplies one.
  • Delegation chains where an authority empowers another body to issue subordinate statements; only a single mandate basis reference is modelled.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-knw-012-policy-rule/spec.yaml, ver-cy/world-models/card-supplements/wm-knw-012-policy-rule.json