# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-02T20:58:47Z", "synthesisSha256": "724d40878d84b54cbe21e751d8e3e332b2f90f188d60e197b9359de545e045b1", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-KNW-014", "registryId": "vr.wm-knw-014", "name": "Issue / Problem", "version": "0.3.1-research.1", "previousVersions": [ { "version": "0.3.0-research.1", "url": "/models/wm-knw-014-issue-problem/versions/0.3.0-research.1/" } ], "entryKind": "aggregate", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.KNW.ISS" ], "tags": [ "issue", "problem", "inf.knw.iss" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-knw-014-issue-problem/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-knw-014", "model": { "registry_id": "vr.wm-knw-014", "model_id": "WM-KNW-014", "name": "Issue / Problem", "entry_kind": "aggregate", "purpose": "Give an agent the format-neutral context needed to recognize, record, classify, analyse, relate, govern and hand off a recognized discrepancy between an observed state and a required or expected state, without owning the work, change, enforcement or audit trail that resolves it.", "scope_statement": "An Issue / Problem record asserts that some observed state of a subject diverges from a stated expectation (requirement, specification, norm, target or design intent) and that the divergence is recognized as needing disposition. The model covers the discrepancy assertion itself, its identity, classification and grading, its recognition context in time and place, its evidence and provenance, its impact and causal analysis, its lifecycle states and disposition, its relationships to other issues and subjects, and the governance, confidentiality, assurance and retention context of the record. It deliberately stops at the boundary of the work: corrective and preventive actions, changes, incident response execution, verification execution, enforcement and audit trails are referenced, never reproduced. The model is storage- and interface-neutral: tracker rows, occurrence databases, nonconformance reports, SARIF results, Markdown files and MongoDB documents are projections of the same semantics.", "in_scope": [ "Assertion of a discrepancy: observed state, expected state and the reference norm or requirement against which the divergence is judged", "Identity of the issue record, duplicate resolution, merge/canonical selection and correspondence with identifiers in other systems", "Typology and grading: issue type, category codes, severity, priority, urgency and assessed impact", "Recognition context: who or what detected the discrepancy, through which channel, under which environment and configuration", "Separated time anchors for occurrence, detection, report submission and record ingestion", "Evidence set, reproducibility and the provenance and confidence of every asserted claim on the record", "Extent of impact, affected subjects, occurrence aggregation and recurrence semantics", "Causal analysis outcomes: hypothesis, proximate and root cause, contributing factors, and known-error designation", "Documented workaround and mitigation knowledge held as knowledge, not as executed work", "Lifecycle states, permitted transitions, triage acceptance, disposition categories and closure criteria", "Relationships between issues and to incidents, requirements, assets, tests, actions and changes", "Governance context: accountable roles, competent decision authority, waiver/concession reference, sensitivity, reporter protection, retention class and hold status", "Interoperability crosswalks to external issue, defect, nonconformance and occurrence vocabularies" ], "out_of_scope": [ "Execution, scheduling and tracking of corrective, preventive or containment actions, which belong to WM-ACT-021 and may be referenced without containment or lifecycle inheritance", "Change request implementation and release semantics, which belong to a change model aligned to OSLC Change Management", "Incident detection, triage and response operations, which belong to an incident/occurrence model", "Risk identification, analysis and treatment for events that have not been realized", "Runtime evaluation or enforcement of validation rules, routing rules or policy: this model declares constraints, an external evaluator or engine applies them", "Audit-trail generation and retention of who did what to the record, which belongs to the adopting Dimension's audit-log service", "Governance of classification schemes, taxonomies and code lists themselves (for example ADREP/ECCAIRS, CWE); this model binds to them", "Verification and validation execution proving an action was effective; only the reference and acceptance status are carried", "Physical or logical deletion execution and destruction certification, which belongs to a records retention and disposition model", "Party, organization and role master data", "Specification, requirement and norm authoring and versioning", "Security vulnerability enumeration, scoring and coordinated disclosure workflow, which is a specialized sibling model" ], "boundary_notes": [ { "neighbor": "Incident / occurrence event", "distinction": "An incident is an unplanned event or interruption that occurred at a point in time; an issue is the recognized discrepancy that one or more incidents may evidence. NIST SP 800-61r3 scopes incident response as an operational cycle inside cybersecurity risk management, and Regulation (EU) No 376/2014 treats an occurrence report as an event record with its own transmission deadlines. The issue record references occurrences; it does not carry their response lifecycle.", "source_refs": [ "SRC-006", "SRC-008" ] }, { "neighbor": "Risk register entry", "distinction": "A risk is an unrealized possibility carried for treatment; an issue is a recognized, already-observed divergence. Regulation (EU) No 376/2014 applies a safety risk classification to occurrences that have already happened, which shows risk scoring can be an attribute of an issue without making the issue a risk. Forward-looking likelihood modelling stays in the risk model.", "source_refs": [ "SRC-006", "SRC-008" ] }, { "neighbor": "Corrective and preventive action (CAPA)", "distinction": "21 CFR 820.100 separates investigating the cause of nonconformities from identifying, implementing and verifying the action. The issue owns the discrepancy, the investigation outcome and the disposition decision context; the action model owns action definition, execution and effectiveness verification. The issue carries only the reference and the acceptance status.", "source_refs": [ "SRC-007" ] }, { "neighbor": "Service case / work item reference (WM-ACT-021)", "distinction": "OSLC Change Management models ChangeRequest, Task and ReviewTask as trackable executable activities with their own state predicates. Assignment, effort, scheduling and workflow execution belong there. This model retains the discrepancy semantics and links to the change request rather than duplicating its workflow.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Requirement / specification / norm", "distinction": "The expected state that makes a discrepancy a discrepancy is authored and versioned elsewhere. The issue carries a resolvable reference to the norm clause and the norm version in force at recognition time, not the norm text.", "source_refs": [ "SRC-007", "SRC-009" ] }, { "neighbor": "Evidence, observation and measurement records", "distinction": "Tool runs, logs, samples, images and measurement results are entities with their own provenance. SARIF models a result inside a run with its own artifact and provenance objects. The issue references evidence and states its sufficiency; it does not become the evidence store.", "source_refs": [ "SRC-003", "SRC-004" ] }, { "neighbor": "Security vulnerability record", "distinction": "A vulnerability is a specialized weakness class with registry-governed identifiers, scoring systems and coordinated disclosure states. It behaves as a specialization of an issue but carries machinery this generic model must not absorb; SARIF keeps taxonomy membership in taxa references rather than in the result itself.", "source_refs": [ "SRC-003" ] }, { "neighbor": "Records retention and disposition policy", "distinction": "Regulation (EU) No 376/2014 places retention, de-identification and repository transfer duties on designated bodies. This model declares the retention class, hold state and tombstone marker on its own records but does not own destruction execution or certification.", "source_refs": [ "SRC-006", "SRC-012" ] }, { "neighbor": "Classification scheme / taxonomy registry", "distinction": "ADREP/ECCAIRS compatibility is mandated for aviation occurrence systems and SARIF results point at external taxa. Code list governance, versioning and deprecation stay in the classifier registry; the issue binds a code plus the scheme identifier and version.", "source_refs": [ "SRC-003", "SRC-006" ] }, { "neighbor": "Complaint or customer feedback record", "distinction": "21 CFR 820.100 lists complaints as one of several quality data sources analysed to detect nonconformities. A complaint is an intake channel artifact; it may cause an issue to be registered but is not itself the issue.", "source_refs": [ "SRC-007" ] } ] }, "sources": [ { "id": "SRC-001", "title": "OSLC Change Management Version 3.0. Part 2: Vocabulary (OASIS Standard)", "organization": "OASIS Open Projects — OSLC Open Project", "url": "https://docs.oasis-open-projects.org/oslc-op/cm/v3.0/os/change-mgt-vocab.html", "version_or_date": "Version 3.0, OASIS Standard, 26 May 2021", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Normative RDF vocabulary for ChangeRequest, Defect, Enhancement, Task, ReviewTask plus state predicates (closed, fixed, approved, reviewed, verified, inProgress), closeDate, priority, severity, parent, relatedChangeRequest and requirement/test linkage. Primary support for typology, grading, state, relationship and interoperability findings." }, { "id": "SRC-002", "title": "OSLC Change Management Version 3.0. Part 1: Specification (OASIS Standard)", "organization": "OASIS Open Projects — OSLC Open Project", "url": "https://docs.oasis-open-projects.org/oslc-op/cm/v3.0/os/change-mgt-spec.html", "version_or_date": "Version 3.0, OASIS Standard, 26 May 2021", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Defines ChangeRequest as a request for change covering enhancement, defect resolution or bug report, and marks oslc_cm:status archaic in favour of oslc_cm:state. Primary support for the boundary between the discrepancy record and the change request, and for state-vocabulary migration guidance." }, { "id": "SRC-003", "title": "Static Analysis Results Interchange Format (SARIF) Version 2.1.0 (OASIS Standard)", "organization": "OASIS", "url": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/sarif-v2.1.0-os.html", "version_or_date": "Version 2.1.0, OASIS Standard, 27 March 2020", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Normative model of a machine-detected result: guid and correlationGuid, fingerprints and partialFingerprints for stable identity across runs, baselineState (new/unchanged/updated/absent/renamed/moved), kind, level, rank as confidence, occurrenceCount, provenance with first/last detection times, taxa, suppressions and workItemUris. Primary support for identity, duplicate correlation, recurrence, confidence, evidence and cross-system linkage." }, { "id": "SRC-004", "title": "PROV-O: The PROV Ontology (W3C Recommendation)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Entity/Activity/Agent core with wasGeneratedBy, wasDerivedFrom, wasAttributedTo, wasAssociatedWith, startedAtTime, endedAtTime and the qualification pattern. Primary support for provenance, attribution, derivation of merged or superseded records and evidence lineage." }, { "id": "SRC-005", "title": "IEEE Std 1044-2009 — IEEE Standard Classification for Software Anomalies", "organization": "IEEE Standards Association", "url": "https://standards.ieee.org/ieee/1044/4607/", "version_or_date": "Published 7 January 2010; status Inactive-Reserved since 5 March 2020", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Uniform classification of software anomalies independent of where in the lifecycle they arise, distinguishing problem, failure, fault and defect, for defect causal analysis and process improvement. Supports typology and causal-analysis findings; its Inactive-Reserved status is recorded as an alignment caveat, not a conformance claim." }, { "id": "SRC-006", "title": "Regulation (EU) No 376/2014 on the reporting, analysis and follow-up of occurrences in civil aviation", "organization": "European Union (EUR-Lex)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0376", "version_or_date": "Regulation of 3 April 2014; consolidated version of 11 September 2018", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Binding requirements for mandatory and voluntary occurrence reporting: 72-hour reporting deadline, 30-day transfer to the European Central Repository, Annex I minimum data fields, endorsed safety risk classification, ADREP/ECCAIRS taxonomy compatibility, just-culture protection of reporters, removal of personal details and storage of disidentified information only. Primary support for temporal anchors, intake channels, classification binding, confidentiality and reporter protection." }, { "id": "SRC-007", "title": "21 CFR 820.100 — Corrective and preventive action", "organization": "U.S. Food and Drug Administration / U.S. Government Publishing Office", "url": "https://www.govinfo.gov/content/pkg/CFR-2023-title21-vol8/xml/CFR-2023-title21-vol8-sec820-100.xml", "version_or_date": "Code of Federal Regulations, 2023 edition, Title 21 Volume 8", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Requires analysing quality data sources (including complaints, audits, service and returned product) to detect nonconformities, investigating their cause, identifying corrective and preventive action, verifying or validating effectiveness, disseminating information to those responsible, submitting to management review, and documenting all activities and results. Primary support for the issue/action boundary, causal analysis, verification linkage and record completeness." }, { "id": "SRC-008", "title": "NIST SP 800-61 Rev. 3 — Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/61/r3/final", "version_or_date": "Revision 3, April 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Places incident response inside continuous cybersecurity risk management rather than treating it as a standalone record type. Primary support for the incident/issue and risk/issue boundary notes and for keeping response execution outside this model." }, { "id": "SRC-009", "title": "ECSS-Q-ST-10-09C Rev.1 — Space product assurance: Nonconformance control system", "organization": "European Cooperation for Space Standardization (ECSS Secretariat, ESA-ESTEC)", "url": "https://ecss.nl/standard/24183/", "version_or_date": "Rev.1, 1 March 2018", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Requirements for controlling nonconformances of deliverable products across the project lifecycle: the nonconformance report as the carrier of all relevant information, major/minor classification driving whether the customer Nonconformance Review Board is engaged, disposition categories (return to supplier, use as is, rework, repair, scrap), and NRB tasks including review of previous similar nonconformances and criticality assessment. Primary support for grading, disposition, decision authority and recurrence findings." }, { "id": "SRC-010", "title": "RFC 3339 — Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "Proposed Standard, July 2002 (updated by RFC 9557)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Normative date-time profile requiring full-date, seconds and an explicit time-offset or 'Z', with '-00:00' reserved for a known UTC instant whose local offset is unknown. Primary support for the timestamp rule and for separating occurrence, detection and ingestion times." }, { "id": "SRC-011", "title": "RFC 9562 — Universally Unique IDentifiers (UUIDs)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9562.html", "version_or_date": "Internet Standards Track, May 2024 (obsoletes RFC 4122)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Defines UUID versions 1-8, recommends UUIDv7 time-ordered identifiers over v1/v6, warns that UUIDs must not be assumed unguessable, and cautions against name-based UUIDs as primary keys because permanence assumptions often fail. Primary support for the third tier of the identity priority and for locally minted identifiers." }, { "id": "SRC-012", "title": "NPR 8621.1D — NASA Procedural Requirements for Mishap and Close Call Reporting, Investigating, and Recordkeeping", "organization": "National Aeronautics and Space Administration (NASA)", "url": "https://nodis3.gsfc.nasa.gov/displayDir.cfm?t=NPR&c=8621&s=1D", "version_or_date": "Effective 6 July 2020 (interim direction NID 8621.157 noted)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Public-authority procedural requirement establishing that reporting, investigation, corrective action and recordkeeping for mishaps and close calls are distinct governed stages with dedicated terms and definitions, investigation-process and recordkeeping chapters. Cited for the existence and separation of those obligations; the definitional appendix text was not retrievable in this session and is recorded as an evidence gap." }, { "id": "SRC-013", "title": "Problem Management in ITIL: Process & Implementation Guide", "organization": "Atlassian", "url": "https://www.atlassian.com/itsm/problem-management", "version_or_date": "Undated vendor guidance, accessed September 2026", "source_type": "secondary", "primary_source": false, "authority_tier": 4, "accessed_at": "2026-09-02T10:15:00Z", "relevance": "Secondary vendor description of common ITSM practice: a problem as the cause of one or more incidents, a known error as a problem with documented root cause and workaround, and the known error database. Used only to surface widespread terminology whose normative text (ITIL 4, ISO/IEC 20000-1:2018) is proprietary; not used to assert any normative requirement." } ], "structure": { "bundles": [ { "id": "issue-definition-and-identity", "name": "Discrepancy definition, identity and classification", "description": "Establishes what the record asserts, how it is uniquely and stably identified across systems and duplicates, and how it is typed and graded.", "rationale": "Every downstream use — triage, causal analysis, aggregation, exchange — depends on an unambiguous statement of the divergence and a stable identifier. Both OSLC CM and SARIF treat identity, type and severity/level as first-class, separable properties of the reporting item rather than derived text.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-011" ], "layers": [ { "id": "discrepancy-definition", "name": "Discrepancy assertion and record identity", "description": "The propositional content of the issue — observed versus expected against a named norm — and the identity apparatus that keeps the record addressable and de-duplicated.", "source_refs": [ "SRC-003", "SRC-007", "SRC-009", "SRC-011" ], "findings": [ { "id": "discrepancy-statement", "name": "Observed state, expected state and reference norm", "description": "The atomic assertion that makes something an issue: what was observed, what was required or expected, which authored norm or requirement establishes the expectation, and the version of that norm in force when the divergence was recognized.", "source_refs": [ "SRC-007", "SRC-009", "SRC-003" ], "questions": [ { "id": "q-ds-observed", "text": "What observed state or behaviour is asserted, and in what terms is it expressed?", "kind": "definition", "answer_data": [ "Observed-state description in controlled prose", "Measured or captured values with units where the divergence is quantitative" ] }, { "id": "q-ds-expected", "text": "What expected or required state is the observation being compared against?", "kind": "requirement", "answer_data": [ "Expected-state description", "Acceptance threshold or tolerance where applicable" ] }, { "id": "q-ds-norm", "text": "Which authored requirement, specification or norm clause establishes that expectation, and which version of it was in force at recognition?", "kind": "provenance", "answer_data": [ "Resolvable reference to the norm or requirement clause", "Norm version or edition identifier in force at recognition" ] }, { "id": "q-ds-divergence", "text": "Is the divergence asserted as a categorical failure to conform or as a quantified deviation?", "kind": "classification", "answer_data": [ "Divergence mode code (categorical or quantified)", "Deviation magnitude and direction when quantified" ] } ], "data_elements": [ { "id": "de-observed-state", "name": "observed_state", "description": "Description of the state or behaviour actually encountered.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-009" ] }, { "id": "de-expected-state", "name": "expected_state", "description": "Description of the state required by the referenced norm or design intent.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "de-norm-reference", "name": "reference_norm_ref", "description": "Resolvable reference to the requirement, specification or norm clause plus the version in force at recognition.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "de-deviation-magnitude", "name": "deviation_magnitude", "description": "Signed magnitude of the deviation with unit, present only for quantified divergences.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "The discrepancy assertion is structured inline data on the record: three short fields plus a reference. Materializing it as a separate document would fragment the atomic claim and duplicate the norm text, which is authored and versioned by the requirement model." }, { "id": "issue-record-identity", "name": "Issue identity, correlation and duplicate resolution", "description": "How the issue record is named, which identifier is authoritative, how correlation across runs and systems is achieved without conflating identity, and how duplicates are detected, merged and superseded.", "source_refs": [ "SRC-003", "SRC-011", "SRC-004", "SRC-001" ], "questions": [ { "id": "q-id-authoritative", "text": "Which system of record issues the authoritative identifier for this issue, and what is that identifier?", "kind": "identity", "answer_data": [ "Master-system identifier value", "Identifier-issuing system reference and namespace" ] }, { "id": "q-id-correlation", "text": "What stable correlation value lets the same discrepancy be recognized across repeated detections or tool runs?", "kind": "identity", "answer_data": [ "Correlation identifier or fingerprint value", "Fingerprint algorithm name and version" ] }, { "id": "q-id-duplicate", "text": "On what criteria is another record judged a duplicate rather than a related or recurring issue?", "kind": "constraint", "answer_data": [ "Duplicate-decision criteria set", "Comparison fields and matching tolerance" ] }, { "id": "q-id-merge", "text": "When records are merged, which record survives as canonical and how is the derivation of the retired record preserved?", "kind": "provenance", "answer_data": [ "Canonical record reference", "Derivation link from retired to canonical record and merge justification" ] } ], "data_elements": [ { "id": "de-issue-id", "name": "issue_identifier", "description": "Authoritative identifier of the issue record, qualified by the issuing system namespace.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-003" ] }, { "id": "de-correlation-id", "name": "correlation_identifier", "description": "Stable value used to recognize logically equivalent detections across runs or systems, modelled on SARIF correlationGuid and fingerprints.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-fingerprint", "name": "partial_fingerprints", "description": "Versioned named fingerprint values supporting more than one matching strategy.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-canonical-ref", "name": "canonical_issue_ref", "description": "Reference from a duplicate or merged record to the surviving canonical record, with a PROV-style derivation assertion.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Identity is a set of scalar values and references evaluated by matching logic; it has no document form. The fingerprint algorithms and matching engines are external tooling, so only the values and the algorithm names belong on the record." } ] }, { "id": "issue-classification", "name": "Typology and grading", "description": "Assignment of issue type and category codes from governed schemes, and of severity, priority, urgency and impact grades that drive routing and authority.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-009" ], "findings": [ { "id": "issue-typology", "name": "Issue type and category coding", "description": "The kind of discrepancy (defect, nonconformance, service problem, occurrence, enhancement gap, process deviation) and its category codes bound to externally governed classification schemes.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-ty-kind", "text": "What kind of discrepancy is this, and does the chosen kind change which lifecycle or authority applies?", "kind": "classification", "answer_data": [ "Issue type code", "Lifecycle or authority profile implied by the type" ] }, { "id": "q-ty-scheme", "text": "Which external classification scheme supplies the category codes, and at which scheme version were they assigned?", "kind": "interoperability", "answer_data": [ "Classification scheme identifier and version", "Assigned category code values" ] }, { "id": "q-ty-multi", "text": "May an issue carry codes from more than one scheme simultaneously, and how are conflicting codes reconciled?", "kind": "constraint", "answer_data": [ "Multi-scheme cardinality rule", "Conflict-reconciliation precedence rule" ] }, { "id": "q-ty-reclass", "text": "What evidence justifies reclassifying an issue after registration, and is the prior classification retained?", "kind": "decision", "answer_data": [ "Reclassification justification text and authority reference", "Superseded classification values with their validity interval" ] } ], "data_elements": [ { "id": "de-issue-type", "name": "issue_type", "description": "Primary type code distinguishing defect, nonconformance, service problem, occurrence, deviation or gap.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "de-category-code", "name": "category_code", "description": "Category value bound to an external scheme, carried with the scheme identifier and version, as ADREP/ECCAIRS compatibility and SARIF taxa both require.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-003" ] }, { "id": "de-classification-history", "name": "classification_history", "description": "Prior classification values with the interval during which each was asserted.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Type and category are coded values plus scheme bindings. The code lists themselves are governed by classifier registries referenced through composition, so reproducing them here as artifacts would claim ownership of taxonomy governance that this model does not hold." }, { "id": "severity-priority-and-impact-grading", "name": "Severity, priority, urgency and assessed impact", "description": "Independent grading axes: intrinsic seriousness of the discrepancy, the handling order assigned to it, and the assessed consequence, including the risk classification that determines which authority must review it.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-009" ], "questions": [ { "id": "q-sv-axes", "text": "Which grading axes are carried separately, and what is the permitted value set of each?", "kind": "measurement", "answer_data": [ "Severity value set and definitions", "Priority and urgency value sets and definitions" ] }, { "id": "q-sv-authority", "text": "Which grade threshold escalates the issue to a higher review authority or to an external body?", "kind": "authority", "answer_data": [ "Threshold value that triggers escalation", "Competent authority or board designated at that threshold" ] }, { "id": "q-sv-endorsement", "text": "Must an assigned risk or severity classification be reviewed and endorsed by a party other than the assigner?", "kind": "validation", "answer_data": [ "Endorsement requirement flag and endorsing party reference", "Endorsement decision timestamp" ] }, { "id": "q-sv-basis", "text": "On what stated basis was the grade derived, so that a later reader can challenge it?", "kind": "evidence", "answer_data": [ "Grading rationale text", "Grading scheme identifier and version applied" ] } ], "data_elements": [ { "id": "de-severity", "name": "severity", "description": "Intrinsic seriousness grade of the discrepancy, independent of handling order.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "de-priority", "name": "priority", "description": "Relative handling order assigned by the responsible party.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-major-minor", "name": "conformance_significance", "description": "Major/minor style significance grade that determines whether an internal or a customer-level review board is competent, per ECSS nonconformance control.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-risk-classification", "name": "risk_classification", "description": "Endorsed risk classification of the underlying occurrence where a common classification scheme is mandated.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Grades are coded scalars with a rationale string; the grading schemes and any scoring calculators are external. Holding them inline keeps a single mutable set of values whose history is captured by the record-versioning rules rather than by separate graded documents." } ] } ] }, { "id": "recognition-evidence-and-provenance", "name": "Recognition context, evidence and provenance", "description": "How, when, where and by whom the discrepancy came to be known, what evidence supports it, and how confident and attributable each assertion is.", "rationale": "Both Regulation (EU) No 376/2014 and SARIF make the detection context — reporter, channel, deadlines, run provenance, detection times, confidence rank — normative content rather than metadata, because disposition decisions are only defensible if the recognition circumstances are recoverable.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-010", "SRC-012" ], "layers": [ { "id": "recognition-context", "name": "Detection, time and situation", "description": "The circumstances of recognition: origin and channel, the separate time anchors that must not be collapsed, and the environment and configuration in which the divergence appeared.", "source_refs": [ "SRC-003", "SRC-006", "SRC-010" ], "findings": [ { "id": "detection-and-report-origin", "name": "Detector, reporting channel and obligation basis", "description": "Who or what recognized the discrepancy, through which intake channel it entered, and whether the report was made under a mandatory obligation or voluntarily.", "source_refs": [ "SRC-006", "SRC-003", "SRC-007" ], "questions": [ { "id": "q-dt-detector", "text": "Who or what detected the discrepancy — a person, an automated tool, an audit, a customer complaint or a monitoring service?", "kind": "provenance", "answer_data": [ "Detector reference with agent type", "Tool component name and version where automated" ] }, { "id": "q-dt-obligation", "text": "Was the report submitted under a mandatory reporting obligation or voluntarily, and which rule creates the obligation?", "kind": "authority", "answer_data": [ "Reporting basis code (mandatory or voluntary)", "Reference to the obligating rule or clause" ] }, { "id": "q-dt-channel", "text": "Through which intake channel did the report arrive, and what minimum data set did that channel require?", "kind": "process", "answer_data": [ "Intake channel identifier", "Minimum required field set for that channel" ] }, { "id": "q-dt-source-class", "text": "Which quality-data source category does the origin fall into for periodic source analysis?", "kind": "classification", "answer_data": [ "Source category code such as complaint, audit, service record, returned product or process monitoring", "Source system reference" ] } ], "data_elements": [ { "id": "de-detector-ref", "name": "detected_by_ref", "description": "Reference to the person, organization or automated component that recognized the discrepancy.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-003" ] }, { "id": "de-reporting-basis", "name": "reporting_basis", "description": "Whether the report is mandatory or voluntary, with the reference to the obligating provision.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-intake-channel", "name": "intake_channel", "description": "Identifier of the channel through which the report was received.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "af-intake-report", "name": "Intake report submission", "description": "The as-submitted report that caused the issue to be registered — an occurrence report satisfying a mandated minimum data set, a complaint, an audit finding sheet or a machine-generated analysis run output. Retained unaltered so that later edits to the issue record can be distinguished from what was originally asserted.", "media_or_form": [ "structured report record satisfying a mandated minimum-information set", "machine-generated analysis run log such as a SARIF run", "free-text or form-based human submission", "transcribed telephone or verbal report" ], "serial": true, "identity_strategy": "Identified by the submitting system's own submission identifier where one exists; otherwise a locally minted UUIDv7 qualified by the intake channel identifier, with a submission sequence number when a single issue accumulates multiple submissions.", "source_refs": [ "SRC-006", "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "temporal-anchors", "name": "Separated time anchors and reporting deadlines", "description": "The distinct instants that must be recorded independently — when the divergence occurred or began, when it was detected, when it was reported, when the record was ingested, and when onward transmission was due — together with their timezone discipline.", "source_refs": [ "SRC-010", "SRC-006", "SRC-003" ], "questions": [ { "id": "q-tm-anchors", "text": "Which distinct time anchors are recorded, and which of them are unknown rather than absent?", "kind": "temporal", "answer_data": [ "Occurrence, detection, report and ingestion timestamps", "Explicit unknown markers distinguishing unknown from not-applicable" ] }, { "id": "q-tm-interval", "text": "Is the divergence a point event or an interval, and if an interval, what bounds its start and end?", "kind": "temporal", "answer_data": [ "Interval start and end timestamps", "Boundedness qualifier for open-ended intervals" ] }, { "id": "q-tm-deadline", "text": "What externally imposed deadline applies to reporting or onward transmission of this record, and against which anchor is it measured?", "kind": "constraint", "answer_data": [ "Deadline duration and the anchor it is measured from", "Deadline satisfaction status and actual elapsed duration" ] }, { "id": "q-tm-offset", "text": "How is a timestamp represented when the instant is known in UTC but the local offset is not?", "kind": "interoperability", "answer_data": [ "Representation rule for unknown local offset", "Recorded local civil time and location where the offset matters analytically" ] } ], "data_elements": [ { "id": "de-occurrence-time", "name": "occurrence_time", "description": "RFC 3339 instant, or interval bounds, at which the divergent state occurred or began.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-006" ] }, { "id": "de-detection-time", "name": "detection_time", "description": "RFC 3339 instant at which the discrepancy was first recognized, corresponding to SARIF first-detection provenance.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-003" ] }, { "id": "de-ingestion-time", "name": "record_ingestion_time", "description": "RFC 3339 instant at which this record was created in the holding system, never inferred from occurrence or detection time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-010" ] }, { "id": "de-reporting-deadline", "name": "reporting_deadline", "description": "Externally imposed duration within which the report or its onward transmission is due, expressed with the anchor it runs from.", "value_kind": "duration", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Time anchors are scalar values on the record. Deadline monitoring, alerting and elapsed-time computation are performed by external scheduling or workflow services; this model only declares the anchors, the deadline duration and the anchor each deadline runs from." }, { "id": "situational-and-configuration-context", "name": "Location, environment and configuration at recognition", "description": "Where the divergence appeared — physical or organizational location, operating environment, and the configuration or version state of the affected subject at the moment of recognition.", "source_refs": [ "SRC-003", "SRC-006", "SRC-009" ], "questions": [ { "id": "q-sc-location", "text": "At what physical, organizational or logical location was the divergence observed?", "kind": "spatial", "answer_data": [ "Location reference with the location scheme used", "Coordinates or facility/site identifier where the discrepancy is physically situated" ] }, { "id": "q-sc-configuration", "text": "What configuration, build, batch or serial state of the affected subject was in force when the divergence appeared?", "kind": "state", "answer_data": [ "Configuration or version identifier of the affected subject", "Batch, lot or serial number for physical items" ] }, { "id": "q-sc-environment", "text": "What operating or process conditions were present that a reproduction attempt would need to recreate?", "kind": "composition", "answer_data": [ "Named environment or process-condition set", "Parameter values distinguishing this environment from others" ] } ], "data_elements": [ { "id": "de-location-ref", "name": "observation_location", "description": "Reference to the site, facility, organizational unit or logical location of observation, with the scheme identifier.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-configuration-state", "name": "subject_configuration_state", "description": "Configuration, build, version, batch or serial designation of the affected subject at recognition.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-003" ] }, { "id": "de-environment-descriptor", "name": "environment_descriptor", "description": "Named set of operating or process conditions in force at recognition.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Situational context is a set of references and short descriptors pointing at configuration, asset and location records held in their own master systems. Copying those records here would create a second, drifting source of configuration truth." } ] }, { "id": "evidence-and-provenance", "name": "Evidence, reproducibility and provenance", "description": "The supporting material for the assertion, whether the divergence can be reproduced or re-observed, and the attribution, derivation and confidence of every claim carried.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-012" ], "findings": [ { "id": "evidence-set-and-reproducibility", "name": "Evidence set, sufficiency and reproduction", "description": "Which evidence items support the discrepancy assertion, whether they are sufficient for the disposition sought, and whether and how the divergence can be reproduced or re-observed on demand.", "source_refs": [ "SRC-003", "SRC-007", "SRC-009" ], "questions": [ { "id": "q-ev-items", "text": "What evidence items are relied on, and where does each authoritatively reside?", "kind": "evidence", "answer_data": [ "Evidence item references with type and custodian", "Resolvable location or repository identifier for each item" ] }, { "id": "q-ev-sufficiency", "text": "Is the evidence sufficient for the disposition sought, and if not, what is missing?", "kind": "quality", "answer_data": [ "Sufficiency assessment with assessing party reference", "Enumerated evidence gaps blocking the sought disposition" ] }, { "id": "q-ev-reproduce", "text": "Can the divergence be reproduced or re-observed, and under what stated preconditions?", "kind": "validation", "answer_data": [ "Reproducibility status code", "Preconditions and steps required for reproduction, with observed reproduction rate" ] }, { "id": "q-ev-integrity", "text": "How is each evidence item shown to be unaltered since capture?", "kind": "security", "answer_data": [ "Content digest with algorithm identifier", "Capture timestamp and capturing agent reference" ] } ], "data_elements": [ { "id": "de-evidence-ref", "name": "evidence_item_ref", "description": "Reference to an evidence item with its type, custodian and content digest.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "de-reproducibility-status", "name": "reproducibility_status", "description": "Whether the divergence is reproducible, intermittent, single-observation or not reproducible.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-evidence-sufficiency", "name": "evidence_sufficiency", "description": "Assessed adequacy of the evidence for the disposition being sought.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "af-evidence-item", "name": "Evidence item", "description": "A captured item relied on to support the discrepancy assertion: log extract, measurement record, image, physical sample reference, tool output fragment or witness statement. Each is referenced with a content digest so that alteration after capture is detectable.", "media_or_form": [ "log or trace extract", "measurement or test result record", "image, video or scan", "physical sample or specimen reference", "tool output fragment", "witness or operator statement" ], "serial": true, "identity_strategy": "Identified by the capturing system's evidence identifier where one exists; otherwise a locally minted UUIDv7 bound to the issue identifier, with a capture sequence number and a content digest as the integrity anchor rather than as identity.", "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "af-reproduction-procedure", "name": "Reproduction procedure", "description": "The stated preconditions, steps and expected divergent outcome that allow an independent party to re-observe the discrepancy, together with the observed reproduction rate.", "media_or_form": [ "ordered step sequence with preconditions and expected outcome", "executable or scripted reproduction case", "test configuration and input data reference" ], "serial": true, "identity_strategy": "Identified by a locally minted UUIDv7 bound to the issue identifier plus a revision ordinal, because reproduction procedures are refined as understanding improves and earlier revisions must remain citable.", "source_refs": [ "SRC-003", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "provenance-attribution-and-confidence", "name": "Attribution, derivation and confidence of assertions", "description": "For each substantive claim on the record — the observation, the classification, the causal conclusion — who asserted it, from what it was derived, and how confident or contested it is.", "source_refs": [ "SRC-004", "SRC-003", "SRC-005" ], "questions": [ { "id": "q-pv-attribution", "text": "Which agent asserted each substantive claim on the record, and in what capacity?", "kind": "provenance", "answer_data": [ "Agent reference per claim with role at time of assertion", "Assertion timestamp" ] }, { "id": "q-pv-derivation", "text": "From which prior record, report or analysis was this claim derived?", "kind": "relationship", "answer_data": [ "Derivation references to source records or analyses", "Derivation type such as transcription, aggregation, merge or restatement" ] }, { "id": "q-pv-confidence", "text": "What confidence is attached to the assertion, and on what scale is it expressed?", "kind": "measurement", "answer_data": [ "Confidence value and the scale or rank definition used", "Basis for the confidence assignment" ] }, { "id": "q-pv-dispute", "text": "Is any claim contested, and how is the competing position recorded without overwriting the original?", "kind": "exception", "answer_data": [ "Dispute marker with disputing party reference", "Competing assertion retained alongside the original with its own attribution" ] } ], "data_elements": [ { "id": "de-assertion-attribution", "name": "assertion_attribution", "description": "Per-claim attribution linking a claim to the agent that asserted it and the instant of assertion, following the PROV attribution pattern.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-derived-from", "name": "derived_from_ref", "description": "Reference to a prior entity from which this record or claim was derived.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-confidence-rank", "name": "confidence_rank", "description": "Confidence in the validity of the assertion, expressed on a declared scale such as the SARIF 0.0-100.0 rank.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-dispute-marker", "name": "contested_claim", "description": "Marker identifying a claim as contested, with the competing assertion and its attribution retained.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Provenance here is a graph of attributions and derivation links attached to individual claims, best expressed as inline structured relations aligned to PROV-O. It is deliberately not an audit trail: who edited the stored record is generated and held by the adopting Dimension's audit-log service, which this model only references." } ] } ] }, { "id": "impact-and-causal-analysis", "name": "Impact, recurrence and causal analysis", "description": "What the discrepancy affects and how widely, how repeated observations aggregate onto one record, and what the investigation concluded about cause and available mitigation knowledge.", "rationale": "21 CFR 820.100 requires investigating the cause of nonconformities as an activity distinct from acting on them, ECSS requires the review board to consider previous similar nonconformances and item criticality, and ITSM practice designates a diagnosed problem with a documented workaround as a known error. Impact, recurrence and cause are therefore recorded knowledge, separate from the work.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-013" ], "layers": [ { "id": "impact-and-extent", "name": "Impact extent and occurrence aggregation", "description": "The affected population and consequence of the divergence, and the rules by which multiple observations are counted as one issue or as several.", "source_refs": [ "SRC-003", "SRC-006", "SRC-009" ], "findings": [ { "id": "affected-subjects-and-extent", "name": "Affected subjects, consequence and extent of spread", "description": "Which subjects are affected, what consequence is assessed, and how far the divergence is believed to have spread across items, services, populations or time.", "source_refs": [ "SRC-009", "SRC-006", "SRC-003" ], "questions": [ { "id": "q-im-subjects", "text": "Which subjects — items, services, processes, data sets or populations — are affected, and which are only suspected?", "kind": "composition", "answer_data": [ "Affected subject references with confirmed or suspected qualifier", "Subject type per reference" ] }, { "id": "q-im-consequence", "text": "What consequence is assessed, and is it actual, potential or both?", "kind": "measurement", "answer_data": [ "Consequence description with modality qualifier", "Quantified consequence measures such as affected count, downtime or loss where available" ] }, { "id": "q-im-spread", "text": "Could the same divergence extend to items already delivered, in process or not yet examined?", "kind": "constraint", "answer_data": [ "Extent-of-spread assessment across delivered, in-process and unexamined populations", "Bounding rationale limiting the affected population" ] }, { "id": "q-im-criticality", "text": "Is any affected subject designated critical, and does that designation change the required review path?", "kind": "authority", "answer_data": [ "Criticality designation per affected subject", "Review path implied by the designation" ] } ], "data_elements": [ { "id": "de-affected-subject", "name": "affected_subject_ref", "description": "Reference to an affected subject with a confirmed or suspected qualifier.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-003" ] }, { "id": "de-consequence-assessment", "name": "consequence_assessment", "description": "Assessed actual or potential consequence, with quantified measures where available.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-009" ] }, { "id": "de-extent-of-spread", "name": "extent_of_spread", "description": "Assessment of applicability to delivered, in-process and unexamined populations.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Impact is a set of references and assessed values that must stay attached to the issue record so that grading and authority routing remain re-derivable. Detailed impact studies, when they exist, are evidence items referenced from the evidence finding rather than duplicated here." }, { "id": "occurrence-aggregation-and-recurrence", "name": "Occurrence aggregation, recurrence and baseline state", "description": "The rule deciding whether a repeated observation increments an existing issue or creates a new one, how occurrence counts are maintained, and how the record's state relative to a previous baseline is expressed.", "source_refs": [ "SRC-003", "SRC-009", "SRC-013" ], "questions": [ { "id": "q-oc-aggregation", "text": "Does a repeated observation increment an existing issue or create a new record, and what rule decides?", "kind": "constraint", "answer_data": [ "Aggregation rule statement", "Fields compared to decide sameness and their tolerance" ] }, { "id": "q-oc-count", "text": "How many times has the condition been observed, and over what interval?", "kind": "measurement", "answer_data": [ "Occurrence count", "First and most recent observation timestamps" ] }, { "id": "q-oc-baseline", "text": "Relative to a previous assessment baseline, is this condition new, unchanged, updated, absent, renamed or moved?", "kind": "state", "answer_data": [ "Baseline state value", "Baseline run or assessment reference" ] }, { "id": "q-oc-priorsimilar", "text": "Have previous similar or identical discrepancies been recorded, and what did their disposition conclude?", "kind": "relationship", "answer_data": [ "References to prior similar records", "Summary of their dispositions and whether recurrence after closure occurred" ] } ], "data_elements": [ { "id": "de-occurrence-count", "name": "occurrence_count", "description": "Number of times the condition has been observed against this record.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-baseline-state", "name": "baseline_state", "description": "State of the condition relative to a named prior baseline, using a declared value set such as new, unchanged, updated, absent, renamed or moved.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-prior-similar-ref", "name": "prior_similar_ref", "description": "References to previously recorded similar or identical discrepancies considered during review.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Aggregation is a counting and matching semantic expressed as a rule statement plus counters and references. The matching engines and baseline comparison runs live in detection tooling outside this model, so only the resulting values and the declared rule belong on the record." } ] }, { "id": "causal-analysis", "name": "Causal analysis and mitigation knowledge", "description": "Recorded outcomes of investigation into why the divergence exists, and the documented workaround or containment knowledge that follows from a diagnosed cause.", "source_refs": [ "SRC-005", "SRC-007", "SRC-012", "SRC-013" ], "findings": [ { "id": "causal-hypothesis-and-root-cause", "name": "Hypothesis, proximate cause, root cause and contributing factors", "description": "The investigation outcome recorded on the issue: candidate hypotheses, the immediate cause of the divergence, the underlying cause whose removal prevents recurrence, and contributing factors, each with its evidential basis and status.", "source_refs": [ "SRC-007", "SRC-005", "SRC-012", "SRC-009" ], "questions": [ { "id": "q-ca-hypothesis", "text": "What candidate causes were considered, and on what evidence was each accepted or eliminated?", "kind": "evidence", "answer_data": [ "Candidate cause statements with status", "Eliminating or confirming evidence reference per candidate" ] }, { "id": "q-ca-levels", "text": "Which cause is asserted as immediate and which as underlying, and are contributing factors distinguished from both?", "kind": "classification", "answer_data": [ "Proximate cause statement", "Root cause statement and contributing factor statements, each separately typed" ] }, { "id": "q-ca-method", "text": "Which analysis method produced the conclusion, and who performed it?", "kind": "process", "answer_data": [ "Analysis method name and version", "Analyst or investigating body reference and completion timestamp" ] }, { "id": "q-ca-status", "text": "Is the causal conclusion provisional or confirmed, and what would be needed to confirm it?", "kind": "quality", "answer_data": [ "Causal conclusion status code", "Outstanding confirmation conditions" ] }, { "id": "q-ca-nocause", "text": "If no cause could be determined, how is that outcome recorded so it is not mistaken for an unfinished investigation?", "kind": "exception", "answer_data": [ "Undetermined-cause outcome code with justification", "Conditions under which the investigation would be reopened" ] } ], "data_elements": [ { "id": "de-proximate-cause", "name": "proximate_cause", "description": "Statement of the immediate cause of the observed divergence.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-007" ] }, { "id": "de-root-cause", "name": "root_cause", "description": "Statement of the underlying cause whose removal is expected to prevent recurrence.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-005" ] }, { "id": "de-contributing-factor", "name": "contributing_factor", "description": "Condition that increased the likelihood or severity of the divergence without being its cause.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-causal-status", "name": "causal_conclusion_status", "description": "Whether the causal conclusion is hypothesised, provisional, confirmed or formally undetermined.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-005" ] } ], "artifacts": [ { "id": "af-causal-analysis-report", "name": "Causal analysis report", "description": "The structured record of the investigation supporting the causal conclusion — the method applied, data examined, hypotheses eliminated and the reasoning that reaches the stated cause. Required wherever the governing rule obliges the cause of a nonconformity to be investigated and the investigation documented.", "media_or_form": [ "structured investigation report with method, data, elimination reasoning and conclusion", "fault tree, cause-and-effect or event-and-causal-factor representation", "structured problem-solving worksheet", "investigation board findings record" ], "serial": true, "identity_strategy": "Identified by the investigating body's own report identifier where one is issued; otherwise a locally minted UUIDv7 bound to the issue identifier plus a revision ordinal, so that superseded analyses remain citable when a conclusion is revised.", "source_refs": [ "SRC-007", "SRC-012", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "known-error-and-workaround-knowledge", "name": "Known-error designation and workaround knowledge", "description": "The knowledge state reached when a cause is documented and a means of avoiding or reducing the impact exists, expressed as reusable knowledge rather than as executed work.", "source_refs": [ "SRC-013", "SRC-007", "SRC-009" ], "questions": [ { "id": "q-ke-designation", "text": "On what conditions is the issue designated a known error, and what must be documented before that designation holds?", "kind": "definition", "answer_data": [ "Known-error designation criteria", "Required documented elements, minimally a cause and a means of avoidance" ] }, { "id": "q-ke-workaround", "text": "What documented means exists to avoid or reduce the impact without removing the cause, and what are its limits and side effects?", "kind": "requirement", "answer_data": [ "Workaround description with applicability conditions", "Stated limitations, residual impact and side effects" ] }, { "id": "q-ke-validity", "text": "Under which configurations, versions or populations is the documented workaround valid, and when does it expire?", "kind": "constraint", "answer_data": [ "Applicability scope by configuration, version or population", "Validity end condition or review date" ] }, { "id": "q-ke-supersede", "text": "When a permanent removal of the cause is achieved, how is the known-error knowledge retired without losing its history?", "kind": "lifecycle", "answer_data": [ "Retirement status of the known-error entry", "Reference to what supersedes it and the retirement justification" ] } ], "data_elements": [ { "id": "de-known-error-flag", "name": "known_error_designation", "description": "Whether the issue currently holds a known-error designation, with the instant the designation was made.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "de-workaround-scope", "name": "workaround_applicability", "description": "Configurations, versions or populations for which the documented workaround is valid.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-009" ] }, { "id": "de-knowledge-retirement", "name": "knowledge_retirement_status", "description": "Whether the known-error knowledge is current, superseded or retired, with the superseding reference.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [ { "id": "af-known-error-entry", "name": "Known-error knowledge entry", "description": "The reusable knowledge record stating the documented cause, current status of a permanent removal, and the conditions under which the entry applies. Distinct from the issue record because it is consumed by parties handling unrelated incidents who never touch the issue itself.", "media_or_form": [ "structured knowledge-base entry", "symptom-to-cause reference record", "published advisory or bulletin" ], "serial": false, "identity_strategy": "Identified by the knowledge-base system's own entry identifier where one exists; otherwise a locally minted UUIDv7 bound to the issue identifier. One current entry per issue, with revisions versioned in place rather than serialized.", "source_refs": [ "SRC-013" ] }, { "id": "af-workaround-instruction", "name": "Workaround instruction", "description": "The stated means of avoiding or reducing impact while the cause remains present, with preconditions, steps, applicability scope and residual risk. Held as instruction content; performing it is work owned by the action model.", "media_or_form": [ "ordered instruction sequence with preconditions and residual risk", "configuration or parameter change description", "operational restriction or avoidance notice" ], "serial": true, "identity_strategy": "Identified by a locally minted UUIDv7 bound to the issue identifier plus a revision ordinal, since workarounds are revised as scope narrows or widens and superseded revisions must stay citable from incidents that applied them.", "source_refs": [ "SRC-013", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "lifecycle-and-disposition", "name": "Lifecycle, triage and disposition", "description": "The permitted states of the issue record, the triage decision that accepts or rejects it, the disposition categories that conclude it, and the references by which resolution and its verification are linked without being owned.", "rationale": "OSLC CM models state through explicit predicates and a closeDate, ECSS fixes a closed disposition set decided by a competent review board, and 21 CFR 820.100 separates identifying and implementing action from verifying or validating its effectiveness. The issue therefore owns state and disposition context but only references the work and its verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-009" ], "layers": [ { "id": "state-and-progression", "name": "State model and triage", "description": "The declared state set with permitted transitions and their conditions, and the triage decision determining whether the asserted discrepancy is accepted for handling.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "findings": [ { "id": "lifecycle-state-model", "name": "State set, permitted transitions and reopening", "description": "The declared lifecycle states of the issue record, the conditions and competent party for each transition, terminal versus non-terminal states, and how reopening after a terminal state is represented.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "questions": [ { "id": "q-lc-states", "text": "What is the declared state set, and which states are terminal?", "kind": "state", "answer_data": [ "Enumerated state values with definitions", "Terminality flag per state" ] }, { "id": "q-lc-transitions", "text": "Which transitions are permitted, and what condition must hold for each?", "kind": "lifecycle", "answer_data": [ "Permitted transition pairs", "Guard condition and competent party per transition" ] }, { "id": "q-lc-predicates", "text": "Are independent progress predicates such as in-progress, fixed, reviewed, verified and closed carried alongside the state value, and how do they relate to it?", "kind": "interoperability", "answer_data": [ "Predicate set carried with their boolean values", "Mapping rule between predicates and the state value" ] }, { "id": "q-lc-reopen", "text": "On what grounds may a terminal state be reopened, and does reopening reuse the record or create a successor?", "kind": "exception", "answer_data": [ "Reopening grounds and competent party", "Rule choosing between reuse of the record and creation of a successor record" ] } ], "data_elements": [ { "id": "de-state", "name": "state", "description": "Current lifecycle state of the issue record from the declared state set.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "de-state-predicates", "name": "progress_predicates", "description": "Independent boolean progress indicators such as in-progress, fixed, approved, reviewed, verified and closed, carried for interoperability with OSLC-style consumers.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-transition-record", "name": "state_transition", "description": "A recorded transition with prior state, new state, transition timestamp, competent party reference and stated reason.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "de-reopen-count", "name": "reopen_count", "description": "Number of times the record has re-entered a non-terminal state after reaching a terminal one.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "The state model is a declared value set and transition table plus the record's current values. Transition evaluation, guard enforcement and workflow routing are performed by an external workflow engine; declaring the states here does not confer ownership of their execution." }, { "id": "triage-and-acceptance-decision", "name": "Triage, acceptance and rejection of the assertion", "description": "The first substantive decision on a registered issue: whether the asserted discrepancy is accepted as a genuine, in-scope divergence, deferred, or rejected — and the grounds recorded for that determination.", "source_refs": [ "SRC-003", "SRC-009", "SRC-007" ], "questions": [ { "id": "q-tr-outcome", "text": "What triage outcome was reached — accepted, deferred, rejected, redirected or merged into another record?", "kind": "decision", "answer_data": [ "Triage outcome code", "Outcome timestamp and deciding party reference" ] }, { "id": "q-tr-grounds", "text": "On what grounds was a rejection or deferral made, and is the assertion preserved rather than deleted?", "kind": "exception", "answer_data": [ "Rejection or deferral ground code with justification text", "Preservation status of the rejected assertion" ] }, { "id": "q-tr-suppression", "text": "Where a detected condition is intentionally suppressed rather than rejected, how is the suppression recorded and reviewed?", "kind": "access", "answer_data": [ "Suppression kind and justification", "Suppressing party reference and suppression review date" ] }, { "id": "q-tr-completeness", "text": "What minimum information must be present before triage may conclude?", "kind": "validation", "answer_data": [ "Required field set for triage completion", "Missing-information handling rule" ] } ], "data_elements": [ { "id": "de-triage-outcome", "name": "triage_outcome", "description": "Outcome of the acceptance determination on the asserted discrepancy.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-003" ] }, { "id": "de-triage-grounds", "name": "triage_grounds", "description": "Recorded justification for a rejection, deferral or redirection.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "de-suppression", "name": "suppression", "description": "Record that a detected condition is intentionally suppressed, with kind, justification and suppressing party, modelled on SARIF suppressions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Triage produces a coded outcome, a justification string and a party reference on the record. Where the adopting Dimension requires a formal decision record with its own governance, that record belongs to a decision model and is referenced, not reproduced here." } ] }, { "id": "disposition-and-resolution-linkage", "name": "Disposition, closure and resolution linkage", "description": "How the issue concludes: the disposition category selected by the competent authority, the criteria that must be satisfied to close, and the references to externally owned resolution work and its effectiveness verification.", "source_refs": [ "SRC-007", "SRC-009", "SRC-001" ], "findings": [ { "id": "disposition-and-closure-criteria", "name": "Disposition category and closure criteria", "description": "The declared disposition outcome for the discrepancy, the closed value set from which it is drawn, the conditions that must be satisfied before closure, and the closure instant.", "source_refs": [ "SRC-009", "SRC-001", "SRC-007" ], "questions": [ { "id": "q-dp-category", "text": "Which disposition category was selected from the declared closed value set, and by which competent body?", "kind": "decision", "answer_data": [ "Disposition category value", "Deciding body reference and decision timestamp" ] }, { "id": "q-dp-criteria", "text": "What criteria must be satisfied before closure is permitted, and is each recorded as met?", "kind": "requirement", "answer_data": [ "Enumerated closure criteria", "Per-criterion satisfaction status with supporting reference" ] }, { "id": "q-dp-feasibility", "text": "What assessments were made before selecting the disposition — feasibility, effect on the agreement, effect on intended use and applicability to in-process items?", "kind": "process", "answer_data": [ "Assessment outcomes per required dimension", "Applicability determination for existing and in-process items" ] }, { "id": "q-dp-close", "text": "At what instant did the record close, and what distinguishes closure from resolution?", "kind": "temporal", "answer_data": [ "Closure timestamp", "Statement of the distinction between resolution achieved and record closed" ] } ], "data_elements": [ { "id": "de-disposition", "name": "disposition_category", "description": "Selected disposition from a declared closed value set, such as return to supplier, use as is, rework, repair, scrap, permanent removal of cause, or no action with justification.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-closure-criteria", "name": "closure_criteria", "description": "Enumerated conditions required before closure, each with a satisfaction status and supporting reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "de-close-date", "name": "close_timestamp", "description": "Instant at which work on the issue record was declared ended.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "af-disposition-record", "name": "Disposition record", "description": "The formal record of the disposition decision: the category selected, the assessments performed, the conditions attached, the concurring parties and any limits placed on the disposition. Held as an artifact because it is the evidentiary output the competent body signs and because it is frequently exchanged with a customer or regulator independently of the issue record.", "media_or_form": [ "review board disposition minute or decision sheet", "signed nonconformance report disposition block", "structured closure statement with attached conditions" ], "serial": false, "identity_strategy": "Identified by the deciding body's own decision identifier where one is issued; otherwise a locally minted UUIDv7 bound to the issue identifier. A single current disposition per issue, with any change captured as a superseding decision that references the prior one.", "source_refs": [ "SRC-009", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "resolution-reference-and-verification-linkage", "name": "Resolution and effectiveness-verification references", "description": "The references from the issue to the corrective, preventive or change work undertaken elsewhere and to the verification or validation of that work's effectiveness, together with the acceptance status the issue carries as a result.", "source_refs": [ "SRC-007", "SRC-001", "SRC-009" ], "questions": [ { "id": "q-rv-actions", "text": "Which action, change or task records address this issue, and which model owns each of them?", "kind": "relationship", "answer_data": [ "References to action, change and task records with owning model identifier", "Role of each reference such as correction, corrective action or preventive action" ] }, { "id": "q-rv-effectiveness", "text": "What verification or validation of effectiveness is required, and where is its result held?", "kind": "validation", "answer_data": [ "Required verification or validation type", "Resolvable reference to the result record and its owning system" ] }, { "id": "q-rv-acceptance", "text": "What acceptance status does the issue carry as a consequence of that externally produced result?", "kind": "state", "answer_data": [ "Acceptance status code carried on the issue", "Timestamp and accepting party reference" ] }, { "id": "q-rv-dissemination", "text": "Which parties must be informed of the outcome, and how is the fact of dissemination recorded without owning the notification?", "kind": "process", "answer_data": [ "Recipient party references with the ground for their inclusion", "Dissemination confirmation reference produced by the notifying service" ] } ], "data_elements": [ { "id": "de-resolution-ref", "name": "resolution_action_ref", "description": "Reference to an action, change or task record that addresses the issue, qualified by its role and owning model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "de-verification-ref", "name": "effectiveness_verification_ref", "description": "Reference to the externally produced verification or validation result establishing that the action was effective.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-acceptance-status", "name": "resolution_acceptance_status", "description": "Status the issue carries in consequence of the referenced verification result.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "This finding is deliberately reference-only. Action definition, execution and the verification or validation that proves effectiveness are owned by the action and verification models; reproducing their content here would duplicate the target models' lifecycle and operational semantics. The issue carries the pointers and the consequent acceptance status, nothing more." } ] } ] }, { "id": "relationships-and-interoperability", "name": "Relationships and interoperability", "description": "How issues relate to one another and to other subjects, and how the record is mapped, exchanged and reconciled across systems and vocabularies.", "rationale": "OSLC CM defines explicit parent, related, affects and tracks predicates for exactly these purposes, and SARIF carries workItemUris and taxa to bind results to external trackers and taxonomies. Cross-system correspondence is a persistent operational concern because the same discrepancy is typically registered in more than one system.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ], "layers": [ { "id": "relationship-structure", "name": "Issue-to-issue and issue-to-subject relations", "description": "The typed link structure among issues and from issues to the subjects, requirements, tests and events they concern.", "source_refs": [ "SRC-001", "SRC-003" ], "findings": [ { "id": "issue-to-issue-relations", "name": "Typed relations between issue records", "description": "The link types among issues — parent/child decomposition, duplicate-of, caused-by, blocks, related-to, supersedes — their directionality, cardinality and cycle rules.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ], "questions": [ { "id": "q-rl-types", "text": "What typed relations may hold between two issue records, and is each directed or symmetric?", "kind": "relationship", "answer_data": [ "Relation type vocabulary with definitions", "Directionality and inverse name per relation type" ] }, { "id": "q-rl-hierarchy", "text": "Does a parent/child decomposition exist, and what does closing a parent imply for its children?", "kind": "composition", "answer_data": [ "Hierarchy cardinality rule", "Closure propagation rule between parent and children" ] }, { "id": "q-rl-causal-link", "text": "How is a causal link between issues distinguished from a merely correlated one?", "kind": "constraint", "answer_data": [ "Causal versus correlated link criteria", "Evidence reference required to assert a causal link" ] }, { "id": "q-rl-cycles", "text": "Are cycles permitted in any relation type, and what is the resolution rule if one is detected?", "kind": "validation", "answer_data": [ "Per-relation-type cycle permissibility", "Detection and resolution rule for detected cycles" ] } ], "data_elements": [ { "id": "de-issue-relation", "name": "issue_relation", "description": "A typed, directed link from this issue to another issue record, with relation type and assertion provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "de-parent-issue", "name": "parent_issue_ref", "description": "Reference to a parent issue where a decomposition hierarchy is in use.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Relations are typed links carrying at most a type, a direction and an assertion provenance. They are inherently graph data with no document form, and traversal, cycle detection and propagation are executed by the storage projection rather than by this model." }, { "id": "external-subject-linkage", "name": "Links to incidents, requirements, assets, tests and changes", "description": "The outward links from an issue to the events it explains, the requirements it violates or affects, the assets and configurations it concerns, the tests that detect or are blocked by it, and the changes that address it.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-008" ], "questions": [ { "id": "q-el-incidents", "text": "Which incident or occurrence records does this issue explain, and does explaining them alter their own lifecycle?", "kind": "relationship", "answer_data": [ "Occurrence or incident references with explanatory role", "Explicit statement that the referenced record's lifecycle stays with its owning model" ] }, { "id": "q-el-requirements", "text": "Which requirements does the issue affect, track or arise from, and with what link semantics?", "kind": "composition", "answer_data": [ "Requirement references with link predicate", "Predicate vocabulary used for the linkage" ] }, { "id": "q-el-tests", "text": "Which tests, checks or monitors detect this issue or are blocked by it?", "kind": "evidence", "answer_data": [ "Test, check or monitor references with detection or blocking role", "Detecting rule identifier where the detection is automated" ] }, { "id": "q-el-integrity", "text": "What happens to an outward link when the target record is retired, merged or made inaccessible?", "kind": "quality", "answer_data": [ "Dangling-reference handling rule", "Retained target identifier and last-known-state snapshot" ] } ], "data_elements": [ { "id": "de-explains-occurrence", "name": "explains_occurrence_ref", "description": "Reference to an incident or occurrence record for which this issue is asserted to be a cause or contributing condition.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-006" ] }, { "id": "de-requirement-link", "name": "requirement_link", "description": "Link to a requirement with an explicit predicate such as affects, tracks or arises-from.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-detecting-rule", "name": "detecting_rule_ref", "description": "Identifier of the rule, check or test that produced the detection, together with the tool component and version.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Outward linkage is reference data by definition. The referenced incidents, requirements, assets, tests and changes are governed by their own models; the issue holds only the pointer, the predicate and, where a target may become unreachable, a last-known-state snapshot for forensic legibility." } ] }, { "id": "interoperability-and-exchange", "name": "Vocabulary alignment and cross-system correspondence", "description": "Mapping this model onto external issue, defect, nonconformance and occurrence vocabularies, and reconciling the same discrepancy held in several systems at once.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ], "findings": [ { "id": "vocabulary-crosswalks-and-conflicts", "name": "Crosswalks to external vocabularies and recorded conflicts", "description": "Declared mappings from this model's elements to external vocabularies, the lossy or contested points in each mapping, and the explicit refusal to claim conformance without evidence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-iv-targets", "text": "Which external vocabularies is this model mapped to, at which version of each?", "kind": "interoperability", "answer_data": [ "Target vocabulary identifiers with version or edition", "Mapping direction and coverage per target" ] }, { "id": "q-iv-lossy", "text": "Which mappings are lossy or one-way, and what information is lost in each direction?", "kind": "quality", "answer_data": [ "Per-mapping lossiness statement", "Enumerated elements without a target counterpart" ] }, { "id": "q-iv-conflict", "text": "Where do two external vocabularies define the same term incompatibly, and how is the conflict recorded rather than silently resolved?", "kind": "constraint", "answer_data": [ "Conflicting term pairs with each source definition", "Recorded non-resolution or declared local precedence" ] }, { "id": "q-iv-conformance", "text": "What evidence would be required before a conformance claim to any target could be asserted?", "kind": "validation", "answer_data": [ "Conformance evidence requirements per target", "Current claim status, defaulting to alignment rather than conformance" ] } ], "data_elements": [ { "id": "de-crosswalk-entry", "name": "crosswalk_entry", "description": "A mapping from a local element to a target vocabulary term with direction, exactness and any loss note.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "de-alignment-status", "name": "alignment_status", "description": "Declared relationship to a target standard: aligned, partially aligned or not aligned; never conformant absent evidence.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "af-vocabulary-crosswalk", "name": "Vocabulary crosswalk table", "description": "The maintained mapping between this model's elements and the terms of an external issue, defect, nonconformance or occurrence vocabulary, recording direction, exactness, loss and unresolved conflicts. Held as an artifact because it is versioned against the target standard's release cycle rather than against any individual issue.", "media_or_form": [ "element-to-term mapping table with direction and exactness", "machine-readable mapping expressed in an ontology mapping vocabulary", "annotated conflict register accompanying the mapping" ], "serial": true, "identity_strategy": "Identified by the target vocabulary's namespace identifier plus the target version, combined with a locally minted UUIDv7 for the mapping edition; one serial edition per target version so that historical mappings remain resolvable.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "cross-system-correspondence", "name": "Correspondence of one discrepancy across several systems", "description": "How the same real discrepancy registered in a detection tool, a tracker, a quality system and a regulator repository is reconciled: which holder is authoritative for which field, and how divergence between copies is detected and expressed.", "source_refs": [ "SRC-003", "SRC-006", "SRC-001" ], "questions": [ { "id": "q-cs-holders", "text": "Which systems hold a representation of this same discrepancy, and what identifier does each assign?", "kind": "identity", "answer_data": [ "Holding system references with their local identifiers", "Representation role such as originating, master, mirror or repository copy" ] }, { "id": "q-cs-authority", "text": "Which holder is authoritative for which field, when several hold overlapping values?", "kind": "ownership", "answer_data": [ "Field-level authoritative-holder assignment", "Precedence rule applied when authority is unassigned" ] }, { "id": "q-cs-divergence", "text": "How is divergence between copies detected, and is reconciliation recorded as a change or as a disagreement?", "kind": "quality", "answer_data": [ "Divergence detection basis and last reconciliation timestamp", "Disagreement record retaining both values with their holders" ] }, { "id": "q-cs-onward", "text": "Is onward transmission to an external repository required, and what is its due interval and confirmation?", "kind": "requirement", "answer_data": [ "Onward transmission obligation with due interval", "Transmission confirmation reference and status" ] } ], "data_elements": [ { "id": "de-external-identifier", "name": "external_identifier", "description": "Identifier assigned to this discrepancy by another holding system, qualified by that system's namespace and the representation role.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "de-field-authority", "name": "field_authority_map", "description": "Assignment of authoritative holder per field where several systems carry overlapping values.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-transmission-status", "name": "onward_transmission_status", "description": "Status and confirmation reference of any required transmission to an external or central repository.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Correspondence is a set of identifiers, roles and authority assignments held inline so that a reader of any single copy can locate the others. The transmission itself and the receiving repository's processing are operations of the systems concerned, which this model references but does not perform." } ] } ] }, { "id": "governance-assurance-and-retention", "name": "Ownership, authority, assurance, confidentiality and retention", "description": "Who is accountable for the record, who is competent to decide on it, how record quality and completeness are declared, and how confidentiality, reporter protection and retention govern its life and end.", "rationale": "Regulation (EU) No 376/2014 makes reporter protection and de-identification binding conditions of the reporting system rather than optional practice; ECSS makes disposition authority board-level and dependent on significance; 21 CFR 820.100 requires that all activities and their results be documented. Governance is therefore part of the record's meaning, not an administrative wrapper.", "source_refs": [ "SRC-006", "SRC-007", "SRC-009", "SRC-012" ], "layers": [ { "id": "ownership-and-authority", "name": "Accountability and competent authority", "description": "Which parties are accountable for the record and which are competent to make each determination on it, including waiver and concession routes.", "source_refs": [ "SRC-007", "SRC-009", "SRC-006" ], "findings": [ { "id": "accountable-roles-and-custody", "name": "Accountable roles and record custody", "description": "The named accountabilities attached to the issue record — who owns it, who holds custody of its data, who is answerable for the affected subject — as distinct from who performs the resolving work.", "source_refs": [ "SRC-007", "SRC-009", "SRC-006" ], "questions": [ { "id": "q-ow-owner", "text": "Which party is accountable for the issue record itself, and how does that differ from accountability for the affected subject?", "kind": "ownership", "answer_data": [ "Record owner reference", "Affected-subject owner reference and the distinction between the two roles" ] }, { "id": "q-ow-custody", "text": "Which organization holds custody of the record and its evidence, and under whose jurisdiction?", "kind": "authority", "answer_data": [ "Custodian organization reference", "Governing jurisdiction and applicable regime" ] }, { "id": "q-ow-handover", "text": "How is accountability transferred when the owner changes, and is the prior accountability period preserved?", "kind": "provenance", "answer_data": [ "Handover timestamp and accepting party reference", "Prior owner with the interval of their accountability" ] }, { "id": "q-ow-informed", "text": "Which parties are directly responsible for the affected area and must therefore receive information about the issue?", "kind": "requirement", "answer_data": [ "Responsible-party references with the ground for inclusion", "Information scope each is entitled to receive" ] } ], "data_elements": [ { "id": "de-record-owner", "name": "record_owner_ref", "description": "Party accountable for the completeness and correctness of the issue record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "de-custodian", "name": "custodian_ref", "description": "Organization holding the record and its evidence, with the governing jurisdiction.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-accountability-interval", "name": "accountability_interval", "description": "Owner references with the interval over which each held accountability.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "Accountability is expressed as party references with validity intervals. Party master data, role definitions and organizational structure belong to the party model; duplicating them here would create a competing directory that drifts from the authoritative one." }, { "id": "decision-authority-and-waiver", "name": "Competent decision authority, escalation path and waiver reference", "description": "Which body or role is competent to accept, grade, dispose of, waive or close the issue at each significance level, the declared escalation path, and the reference to any concession, waiver or deviation permitting the divergence to stand.", "source_refs": [ "SRC-009", "SRC-006", "SRC-007" ], "questions": [ { "id": "q-au-competence", "text": "Which body or role is competent to make each determination, and does significance change that competence?", "kind": "authority", "answer_data": [ "Determination-to-authority mapping", "Significance thresholds that shift competence to a higher or external body" ] }, { "id": "q-au-escalation", "text": "What escalation path is declared when the competent authority cannot or will not decide within the applicable interval?", "kind": "process", "answer_data": [ "Ordered escalation path with the triggering condition", "Interval after which escalation applies" ] }, { "id": "q-au-waiver", "text": "Where a divergence is permitted to stand, which concession, waiver or deviation authorises it and under what limits?", "kind": "exception", "answer_data": [ "Waiver, concession or deviation reference with issuing authority", "Scope, conditions and expiry attached to the authorisation" ] }, { "id": "q-au-independence", "text": "Must the deciding party be independent of the party that caused or reported the divergence?", "kind": "constraint", "answer_data": [ "Independence requirement statement", "Conflict-of-interest declaration and its resolution" ] } ], "data_elements": [ { "id": "de-competent-authority", "name": "competent_authority_ref", "description": "Body or role competent for a given determination at the record's current significance level.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-006" ] }, { "id": "de-waiver-ref", "name": "authorisation_to_deviate_ref", "description": "Reference to a concession, waiver or deviation authorising the divergence to stand, with its scope and expiry.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-escalation-path", "name": "escalation_path", "description": "Declared ordered escalation path with the condition that triggers each step.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Authority is carried as references and a declared path. The waiver or concession instrument itself is a governed document owned by the authorising body's own model, and escalation routing and notification are executed by workflow services; this model declares who is competent and records which authorisation applies." } ] }, { "id": "assurance-confidentiality-and-retention", "name": "Record assurance, confidentiality and retention", "description": "Declared completeness and quality constraints on the record, the confidentiality and reporter-protection regime governing its disclosure, and the retention, hold and disposition context of the record itself.", "source_refs": [ "SRC-006", "SRC-007", "SRC-003", "SRC-012" ], "findings": [ { "id": "record-completeness-and-validation", "name": "Minimum information, completeness and declared validation constraints", "description": "The minimum data set the record must carry to be usable at each lifecycle stage, the declared consistency constraints, and the explicit statement that evaluation and enforcement of those constraints are performed elsewhere.", "source_refs": [ "SRC-006", "SRC-007", "SRC-003" ], "questions": [ { "id": "q-va-minimum", "text": "What minimum information must a record carry to be admissible, and does that minimum grow at later lifecycle stages?", "kind": "requirement", "answer_data": [ "Minimum field set per lifecycle stage", "Admissibility rule for records below the minimum" ] }, { "id": "q-va-consistency", "text": "Which cross-field consistency constraints must hold, such as detection time not preceding occurrence time?", "kind": "validation", "answer_data": [ "Enumerated cross-field constraints with severity of breach", "Constraint identifier and version" ] }, { "id": "q-va-quality", "text": "How is the quality of a record measured, and what threshold makes it fit for the decision being taken on it?", "kind": "quality", "answer_data": [ "Quality dimensions assessed with their measures", "Fitness threshold per decision type" ] }, { "id": "q-va-evaluation", "text": "Which component evaluates these constraints, and what does this model record about the outcome?", "kind": "process", "answer_data": [ "Evaluating component reference held outside this model", "Recorded validation outcome, constraint version and evaluation timestamp" ] } ], "data_elements": [ { "id": "de-minimum-set", "name": "minimum_information_set", "description": "Declared minimum field set required for admissibility, indexed by lifecycle stage.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] }, { "id": "de-validation-outcome", "name": "validation_outcome", "description": "Recorded outcome of an external evaluation, with the constraint set identifier, version and evaluation timestamp.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-quality-score", "name": "record_quality_indicator", "description": "Assessed quality of the record against declared dimensions such as completeness, specificity and evidential support.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "af-record-conformance-profile", "name": "Issue record conformance profile", "description": "The declarative profile stating the minimum information set, cardinalities, permitted value sets and cross-field constraints an issue record must satisfy in a given adopting context. It is a declaration of what must hold; it is not an evaluator, and it confers no enforcement authority.", "media_or_form": [ "declarative constraint profile with cardinalities and value-set bindings", "minimum-information annex enumerating mandatory fields", "documented consistency-rule register" ], "serial": true, "identity_strategy": "Identified by the profile namespace plus a semantic version; profile editions are serial so that a recorded validation outcome always names the exact profile version it was evaluated against.", "source_refs": [ "SRC-006", "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "confidentiality-and-reporter-protection", "name": "Sensitivity, reporter protection and disclosure control", "description": "The sensitivity classification of the record, the protections owed to the reporter and to persons named in it, and the de-identification and redaction conditions under which the record or a derived extract may be disclosed.", "source_refs": [ "SRC-006", "SRC-012" ], "questions": [ { "id": "q-cf-sensitivity", "text": "What sensitivity classification applies to the record and to its evidence, and can they differ?", "kind": "privacy", "answer_data": [ "Sensitivity classification per record component", "Classifying authority reference and classification timestamp" ] }, { "id": "q-cf-reporter", "text": "What protection is owed to the reporter and to persons named, and which narrow exceptions remove it?", "kind": "security", "answer_data": [ "Protection regime statement", "Enumerated exceptions such as wilful misconduct or manifest severe disregard of an obvious risk" ] }, { "id": "q-cf-deidentify", "text": "Which personal details must be removed before storage or dissemination, and at what point in the flow?", "kind": "privacy", "answer_data": [ "Fields subject to removal or de-identification", "Stage in the flow at which removal occurs and who performs it" ] }, { "id": "q-cf-release", "text": "On what basis may a party outside the holding organization obtain the record or a derived extract?", "kind": "access", "answer_data": [ "Requester categories with their entitlement basis", "Extract scope and any conditions attached to release" ] } ], "data_elements": [ { "id": "de-sensitivity-class", "name": "sensitivity_classification", "description": "Classification governing handling and disclosure of the record and, separately, of its evidence.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-deidentification-state", "name": "deidentification_state", "description": "Whether the stored representation retains personal details, is disidentified, or is a redacted derivative.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-protection-exception", "name": "protection_exception", "description": "Recorded invocation of a narrow exception removing reporter protection, with the deciding authority and grounds.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "af-disidentified-extract", "name": "Disidentified disclosure extract", "description": "A derived representation of the issue with personal details removed or masked, produced for storage in a shared repository or for release to an entitled requester. Held as a distinct artifact because the extract, not the source record, is what circulates, and its derivation must remain traceable to the source without exposing it.", "media_or_form": [ "masked or redacted structured record", "aggregate or statistical extract", "repository submission payload carrying only disidentified fields" ], "serial": true, "identity_strategy": "Identified by a locally minted UUIDv7 plus a release ordinal, carrying a derivation link to the source issue identifier that is resolvable only by parties entitled to the source; the extract identifier must not encode any protected personal detail.", "source_refs": [ "SRC-006", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "retention-hold-and-record-disposition", "name": "Retention class, legal hold and record disposition context", "description": "How long the issue record and its evidence must be kept, what suspends normal disposal, and how the end of the record's life is represented — while destruction execution stays with the records model or adopting Dimension.", "source_refs": [ "SRC-006", "SRC-012", "SRC-007" ], "questions": [ { "id": "q-rt-class", "text": "What retention class applies to the record and to its evidence, and from which anchor does the period run?", "kind": "retention", "answer_data": [ "Retention class with minimum period", "Anchor event from which the period is computed" ] }, { "id": "q-rt-hold", "text": "What conditions suspend disposal, and who may place or lift a hold?", "kind": "authority", "answer_data": [ "Hold reason codes with placing and lifting authority", "Hold placement and expected review timestamps" ] }, { "id": "q-rt-tombstone", "text": "When a record is disposed of, what tombstone remains so that inbound references do not silently break?", "kind": "lifecycle", "answer_data": [ "Tombstone content specification", "Retained identifier, disposition outcome and disposal timestamp" ] }, { "id": "q-rt-execution", "text": "Which model or policy actually executes disposal, and what does this model record about it?", "kind": "ownership", "answer_data": [ "Owning retention policy or model reference", "Recorded disposal authorisation reference and confirmation status" ] } ], "data_elements": [ { "id": "de-retention-class", "name": "retention_class", "description": "Retention classification with the minimum period and the anchor event from which it runs.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-012" ] }, { "id": "de-hold-status", "name": "disposal_hold", "description": "Active hold suspending disposal, with reason, placing authority and review date.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-tombstone", "name": "tombstone", "description": "Minimal surviving record after disposal, retaining the identifier, disposal outcome, disposal timestamp and authorising reference.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "Retention is declared as a class, an anchor and a hold state on the record, plus a tombstone shape. The retention schedule itself, the disposal authorisation and the destruction or de-identification execution are owned by the records retention and disposition model or by the adopting Dimension's policy; this model must not reproduce that lifecycle." } ] } ] } ] }, "functions": [ { "id": "fn-register-issue", "name": "Register issue from an intake submission", "description": "Create an issue record from an intake submission, binding the observed and expected state, the reference norm, the intake channel and the separated time anchors, and assigning the authoritative identifier.", "inputs": [ "Intake report submission", "Detector or reporter reference", "Reference norm or requirement reference", "Detection and ingestion timestamps" ], "outputs": [ "Issue record with authoritative identifier", "Preserved link to the as-submitted intake artifact", "Initial state value" ], "preconditions": [ "The minimum information set for the intake channel is satisfied or the record is marked incomplete", "An identifier-issuing system of record is designated" ], "effects": [ "A new issue record exists in its initial state", "The as-submitted intake artifact is retained unaltered and referenced", "Ingestion time is recorded separately from detection and occurrence time" ], "source_refs": [ "SRC-006", "SRC-007", "SRC-010", "SRC-011" ] }, { "id": "fn-state-discrepancy", "name": "State or restate the discrepancy", "description": "Record or revise the observed state, expected state, reference norm and norm version in force, retaining the superseded statement with its attribution.", "inputs": [ "Observed-state description", "Expected-state description", "Norm reference and version" ], "outputs": [ "Current discrepancy statement", "Superseded statement with validity interval" ], "preconditions": [ "The issue record exists", "The asserting agent is identified" ], "effects": [ "The discrepancy statement is current and attributed", "Prior statements remain citable rather than overwritten" ], "source_refs": [ "SRC-007", "SRC-009", "SRC-004" ] }, { "id": "fn-classify-and-grade", "name": "Classify and grade the issue", "description": "Assign type, external category codes with scheme and version, and the severity, priority and significance grades, recording the grading basis and any required endorsement.", "inputs": [ "Issue record reference", "Classification scheme identifiers and versions", "Grading scheme and assessed inputs" ], "outputs": [ "Type and category code assignments", "Severity, priority and significance values with rationale", "Endorsement status where required" ], "preconditions": [ "The referenced classification and grading schemes are resolvable at a stated version", "The assigning party is competent for the grade being applied" ], "effects": [ "Grades and codes are current with their prior values retained", "Any threshold shifting competent authority is made explicit on the record" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-009" ] }, { "id": "fn-resolve-identity", "name": "Resolve identity, duplicates and cross-system correspondence", "description": "Determine whether an incoming assertion is the same discrepancy as an existing record, select the canonical record on a merge, and register identifiers held by other systems with their authority assignment.", "inputs": [ "Candidate record or incoming assertion", "Correlation identifiers and fingerprint values", "Declared duplicate-decision criteria" ], "outputs": [ "Duplicate determination with justification", "Canonical record reference and derivation link from the retired record", "External identifier registrations with representation roles" ], "preconditions": [ "Duplicate-decision criteria and the fingerprint algorithm version are declared", "No record already merged into a different canonical record without a recorded supersession" ], "effects": [ "At most one canonical record represents the discrepancy", "Retired records remain resolvable and carry a derivation link to the canonical record" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-011" ] }, { "id": "fn-attach-evidence", "name": "Attach evidence and reproduction context", "description": "Associate evidence items and any reproduction procedure with the issue, recording custodian, capture time, content digest and the resulting sufficiency assessment.", "inputs": [ "Evidence item references with digests", "Reproduction preconditions and steps", "Capturing agent reference" ], "outputs": [ "Evidence set attached to the issue", "Reproducibility status", "Sufficiency assessment with named gaps" ], "preconditions": [ "Each evidence item has a resolvable custodian and a content digest", "Evidence sensitivity is classified before attachment" ], "effects": [ "The evidential basis of the assertion is inspectable", "Evidence gaps blocking a sought disposition are made explicit" ], "source_refs": [ "SRC-003", "SRC-007", "SRC-009" ] }, { "id": "fn-record-causal-outcome", "name": "Record causal analysis outcome", "description": "Record the investigation outcome on the issue — hypotheses considered and eliminated, proximate cause, root cause, contributing factors, method, analyst and conclusion status — and any resulting known-error designation.", "inputs": [ "Causal analysis report reference", "Candidate causes with eliminating evidence", "Analysis method and analyst reference" ], "outputs": [ "Typed causal statements with conclusion status", "Known-error designation where its criteria are met", "Reference to the supporting analysis report" ], "preconditions": [ "The investigation is complete or is explicitly recorded as provisional", "Evidence supporting each retained cause is referenced" ], "effects": [ "The causal conclusion and its status are separable from the actions that follow", "A formally undetermined outcome is distinguishable from an unfinished investigation" ], "source_refs": [ "SRC-007", "SRC-005", "SRC-012", "SRC-013" ] }, { "id": "fn-transition-state", "name": "Apply a lifecycle transition to the issue record", "description": "Move the record between declared states, recording prior state, new state, transition instant, competent party and reason, and updating any interoperability progress predicates consistently.", "inputs": [ "Target state", "Competent party reference", "Transition reason" ], "outputs": [ "Updated state value and progress predicates", "Appended transition record" ], "preconditions": [ "The transition is in the declared permitted set and its guard condition is satisfied", "The acting party is competent for the transition at the record's current significance" ], "effects": [ "The record's state history is complete and attributable", "Predicate values remain consistent with the state value per the declared mapping" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "id": "fn-record-disposition", "name": "Record disposition and closure", "description": "Record the disposition category selected by the competent body, the assessments performed, the closure criteria and their satisfaction, and the closure instant.", "inputs": [ "Disposition category from the declared closed value set", "Deciding body reference and assessment outcomes", "Closure criteria with satisfaction evidence references" ], "outputs": [ "Disposition record artifact reference", "Closure criteria satisfaction status", "Closure timestamp" ], "preconditions": [ "The deciding body is competent at the record's significance level", "Each closure criterion is either satisfied with a reference or explicitly waived by an authorisation" ], "effects": [ "The disposition and its justification are inspectable independently of the issue narrative", "Closure of the record is distinguishable from resolution of the discrepancy" ], "source_refs": [ "SRC-009", "SRC-007", "SRC-001" ] }, { "id": "fn-link-resolution-reference", "name": "Link resolution work and effectiveness verification", "description": "Attach references to the action, change or task records addressing the issue and to the externally produced effectiveness verification results, and set the acceptance status the issue carries in consequence.", "inputs": [ "Action, change or task record references with roles", "Effectiveness verification result references", "Accepting party reference" ], "outputs": [ "Resolution reference set", "Acceptance status with timestamp" ], "preconditions": [ "Each reference resolves in its owning model", "The verification result exists in the verification model before acceptance is set" ], "effects": [ "The issue carries pointers and a consequent status only", "No action definition, execution state or verification result is copied into this model" ], "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "fn-produce-disclosure-extract", "name": "Produce a disclosure extract under confidentiality constraints", "description": "Derive a disidentified or redacted representation of the issue for a stated requester entitlement, retaining a derivation link to the source that only entitled parties can resolve.", "inputs": [ "Source issue record", "Requester entitlement basis", "Fields designated for removal or masking" ], "outputs": [ "Disidentified disclosure extract", "Derivation link to the source record", "Release conditions attached to the extract" ], "preconditions": [ "Sensitivity classification and reporter-protection regime are recorded on the source", "The requester's entitlement basis is stated and the release scope is bounded" ], "effects": [ "Only the extract circulates outside the holding organization", "The extract identifier encodes no protected personal detail" ], "source_refs": [ "SRC-006", "SRC-004" ] }, { "id": "fn-project-for-exchange", "name": "Project the issue into an external vocabulary", "description": "Emit a representation of the issue in a target vocabulary at a stated version using the maintained crosswalk, annotating elements lost in the projection and declaring alignment rather than conformance.", "inputs": [ "Issue record", "Target vocabulary identifier and version", "Crosswalk edition" ], "outputs": [ "Projected representation in the target vocabulary", "Loss annotation listing unmapped elements", "Alignment declaration" ], "preconditions": [ "A crosswalk edition exists for the target version", "Any conflicting term definitions are recorded rather than silently resolved" ], "effects": [ "Consumers receive an explicitly lossy, versioned projection", "No conformance claim is asserted without recorded evidence" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] }, { "id": "fn-set-retention-status", "name": "Set retention class, hold and tombstone marker", "description": "Record the retention class and anchor, place or lift a disposal hold with its authority, and, once disposal is authorised and executed elsewhere, replace the record with the declared tombstone.", "inputs": [ "Retention class and anchor event", "Hold reason and placing or lifting authority", "Disposal authorisation reference" ], "outputs": [ "Retention status on the record", "Hold state with review date", "Tombstone once disposal is confirmed" ], "preconditions": [ "The owning retention policy or records model is identified", "No active hold is in force when disposal is recorded as authorised" ], "effects": [ "Retention state and hold state are inspectable on the record", "A tombstone preserves the identifier and disposal outcome so inbound references do not break; destruction execution and certification remain with the owning retention model" ], "source_refs": [ "SRC-006", "SRC-012", "SRC-007" ] } ], "composition": [ { "target": "WM-ACT-021", "relation": "REFERENCE", "purpose": "Optional non-owning reference to a service case that exposed or tracks the issue. The issue/problem retains its own identity, causal analysis and disposition lifecycle; WM-ACT-021 retains case identity, requester interaction, assignment, scheduling and closure. Neither lifecycle contains or inherits from the other.", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] }, { "target": "Incident / occurrence event model", "relation": "REFERENCE", "purpose": "Carry references to the occurrences an issue explains, with the explanatory role and, where required, the onward-transmission obligation. The occurrence record's own detection, response and closure lifecycle stays entirely in that model.", "required": false, "source_refs": [ "SRC-006", "SRC-008" ] }, { "target": "Risk model (risk register entry)", "relation": "REFERENCE", "purpose": "Bind a realized risk to the issue it became, and carry an endorsed risk classification value assigned to the discrepancy. Likelihood modelling, treatment planning and risk-appetite evaluation remain with the risk model.", "required": false, "source_refs": [ "SRC-006", "SRC-008" ] }, { "target": "Requirement / specification / norm model", "relation": "REFERENCE", "purpose": "Resolve the expected state against an authored requirement clause at the version in force at recognition. Requirement authoring, versioning and baseline control stay with that model.", "required": true, "source_refs": [ "SRC-007", "SRC-009" ] }, { "target": "Corrective and preventive action model", "relation": "REFERENCE", "purpose": "Reference corrections, corrective actions and preventive actions with their roles, and the effectiveness verification or validation results they produce. Action execution and the verification activity itself are owned there; this model carries only the reference and the resulting acceptance status.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "Change request model aligned to OSLC Change Management 3.0", "relation": "ALIGN", "purpose": "Align state, priority, severity, parent and related-request semantics to the oslc_cm vocabulary for exchange, using oslc_cm:state in preference to the archaic oslc_cm:status. Alignment only: no conformance is claimed and change workflow is not reproduced.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Evidence, observation and measurement model", "relation": "REFERENCE", "purpose": "Reference evidence items with custodian, capture time and content digest, and reproduction procedures. Evidence capture, storage and integrity verification remain with that model.", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] }, { "target": "Provenance model aligned to W3C PROV-O", "relation": "ALIGN", "purpose": "Express per-claim attribution, derivation of merged and superseded records, and assertion intervals using the PROV Entity/Activity/Agent pattern and its qualification classes.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "Classification scheme and taxonomy registry", "relation": "REFERENCE", "purpose": "Bind category codes to externally governed schemes with an explicit scheme identifier and version, as ADREP/ECCAIRS compatibility and SARIF taxa references both require. Code list governance, deprecation and versioning stay in the registry.", "required": true, "source_refs": [ "SRC-006", "SRC-003" ] }, { "target": "Party, organization and role model", "relation": "REFERENCE", "purpose": "Resolve reporter, owner, custodian, analyst, competent authority and recipient references. Party master data, role definitions and competence assertions are owned there.", "required": true, "source_refs": [ "SRC-006", "SRC-009" ] }, { "target": "Records retention and disposition policy model", "relation": "REFERENCE", "purpose": "Bind the retention class, anchor and hold authority, and receive the disposal authorisation reference. Schedule authoring, destruction execution and disposal certification are owned by that model or by the adopting Dimension's policy.", "required": true, "source_refs": [ "SRC-006", "SRC-012" ] }, { "target": "Audit log service of the adopting Dimension", "relation": "REFERENCE", "purpose": "Reference the externally generated audit trail of who read or modified the issue record. This model declares what must be logged; generation, immutability and retention of the audit trail are owned entirely by that service and are not audit semantics of this model.", "required": true, "source_refs": [ "SRC-007", "SRC-006" ] }, { "target": "Security vulnerability record model", "relation": "REFERENCE", "purpose": "Reference specialized weakness records that behave as issues but carry registry-governed identifiers, scoring systems and coordinated disclosure states. Those states and scoring machinery are not reproduced here.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "Sensitivity and disclosure classification mix-in", "relation": "MIX-IN", "purpose": "Apply a shared sensitivity, de-identification and release-condition vocabulary to the issue record, its evidence and its derived extracts, so that classification semantics are common across record types rather than redefined per model.", "required": false, "source_refs": [ "SRC-006" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name an accountable issue-record owner and a custodian organization, with the governing jurisdiction, before any issue record may be registered.", "Declare the permitted state set, transitions, guard conditions and the disposition value set, plus the competent authority for each determination and the significance thresholds that shift it.", "Bind a retention class with its anchor event and name the retention policy or records model that owns disposal execution, together with the hold-placing authority.", "Declare the sensitivity classification scheme, the reporter-protection regime and its narrow exceptions, and the de-identification point in the intake flow.", "Declare the minimum information set per lifecycle stage and name the external component that evaluates the conformance profile; this model does not evaluate or enforce it.", "Register the classification and grading schemes used, each with an identifier and version, and the crosswalk editions maintained for external exchange." ], "namespace_guidance": "Use a single Dimension-governed namespace for locally minted issue identifiers, distinct from the namespaces of any originating tracker, detection tool or regulator repository. Never mint an identifier in a namespace the Dimension does not control, and never reuse a retired identifier. External identifiers are always carried qualified by their issuing system's namespace and a representation role, so a reader can tell a master identifier from a mirror copy. Artifact identifiers live in artifact-type sub-namespaces so that an evidence item, a disposition record and a disclosure extract can never collide.", "registry_links": [ "vr.wm-knw-014 is the registry entry for this model; nav path NAV.INF.KNW.ISS and domain tag INF.KNW.ISS locate it in the knowledge plane.", "Candidate registry relation WM-KNW-014 REFERENCE WM-ACT-021 links a problem to a service case that exposes or tracks it; neither side owns the other's identity or lifecycle.", "Classification scheme registries (for example ADREP/ECCAIRS-compatible taxonomies and static-analysis taxa) are linked by identifier and version, not embedded." ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonical form carries the authoritative master-system identifier first; locally minted identifiers appear only when no master-system or governed global identifier exists.", "All timestamps are normalized to RFC 3339 with explicit seconds and an explicit numeric offset or 'Z'; a known instant with an unknown local offset uses '-00:00' and is never silently rewritten to 'Z'.", "Coded values are canonicalized as a triple of scheme identifier, scheme version and code, never as bare display labels.", "References are canonicalized to resolvable identifiers with the owning system's namespace; display names accompany but never replace them.", "Free-text fields are canonicalized by trimming and normalizing whitespace only; no semantic rewriting, summarization or translation is performed during canonicalization.", "Collections that carry no inherent order (evidence items, relations, category codes) are serialized in a declared deterministic order so that byte-level comparison of two canonical forms is meaningful." ], "patch_rules": [ "Patches address individual fields by stable path; whole-record replacement is not a permitted patch form.", "A patch that changes a discrepancy statement, classification, grade, causal conclusion or disposition must retain the superseded value with its assertion interval and attribution rather than overwriting it.", "A patch may not alter the authoritative identifier, the record ingestion timestamp or any preserved as-submitted intake artifact.", "Merging two records is expressed as a supersession patch on the retired record plus a derivation link on the canonical record, never as deletion of the retired record.", "Every patch carries the acting agent, the RFC 3339 instant of the change and a reason; the patch itself is not the audit trail, which is generated by the referenced audit log service." ], "compatibility_rules": [ "Adding an optional field, an optional relation type or a new code value within an existing scheme is a minor change; consumers must ignore unknown optional fields rather than reject the record.", "Removing a field, narrowing a cardinality, removing a permitted state or transition, or changing the meaning of an existing code is a breaking change requiring a new major profile version.", "Crosswalk editions are versioned against the target vocabulary version; a target's new release never silently rebinds an existing crosswalk edition.", "State-vocabulary migration follows the OSLC precedent of retaining an archaic property while promoting its successor, so consumers can transition without loss.", "Alignment declarations may be strengthened only with recorded evidence; a conformance claim may never be introduced by a compatibility change." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record that owns the issue — the tracker, quality management system, nonconformance system or occurrence database designated as master for this record.", "Governed global identifier or IRI from a recognized registry or namespace, such as an OSLC resource IRI or a taxonomy-governed occurrence identifier.", "UUID or ULID minted by the adopting Dimension when no master-system or governed global identifier exists; UUIDv7 is preferred per RFC 9562 for time-ordered locality, and UUIDs must not be assumed unguessable or treated as an access control.", "Never use a date, a title, a reporter name, a severity value or a file path as an identifier. Content fingerprints and correlation values (for example SARIF fingerprints and correlationGuid) are matching aids for recognizing the same condition across runs and must never be promoted to record identity." ], "timestamp_rule": "All time values are RFC 3339 date-time strings that include explicit seconds and an explicit numeric UTC offset or 'Z'; the '-00:00' form is used only when the UTC instant is known but the local offset is not. Occurrence or event time, detection or observation time, report submission time and record ingestion time are recorded as separate fields whenever they differ, and none is ever derived from another. Interval-valued divergences carry separate start and end instants with an explicit open-ended qualifier. Where local civil time is analytically significant, it is carried in addition to, not instead of, the offset-qualified instant.", "serial_naming_rule": "Artifacts that accumulate over the life of one issue — intake submissions, evidence items, reproduction procedures, causal analysis revisions, workaround revisions, disclosure extracts and conformance profile editions — are named by the owning issue identifier, the artifact type sub-namespace and a monotonically increasing, zero-padded ordinal that is never reused after retraction. Ordinals express sequence only and carry no date component; the RFC 3339 capture or issue instant is a separate field. Single-instance artifacts such as the known-error entry and the current disposition record take no ordinal and are revised in place with supersession links.", "integrity_rule": "Every artifact carries a content digest with a named algorithm and its capture instant, so that alteration after capture is detectable without relying on storage-layer guarantees. As-submitted intake artifacts and evidence items are immutable once registered; corrections are additive artifacts that supersede rather than replace, and the superseded artifact remains resolvable for as long as its retention class requires. A disclosure extract carries a derivation link to its source that only entitled parties can resolve, and its identifier encodes no protected personal detail. Digest verification and storage-integrity enforcement are performed by the storage projection and the referenced audit log service, not by this model." }, "policies": [ "Assertion preservation: a discrepancy statement, classification, grade, causal conclusion or disposition is superseded with its interval and attribution retained, never overwritten, because later readers must be able to reconstruct what was believed when a decision was taken.", "Boundary discipline: this model records references and consequent statuses for work, change, verification, enforcement and audit performed elsewhere; it never reproduces the target model's lifecycle, execution state or audit trail.", "Alignment over conformance: external standards are recorded as alignments with explicit lossiness and conflict notes; no conformance is claimed without recorded evidence, and an inactive or withdrawn standard is cited with its status.", "Reporter protection by default: personal details are removed or masked at the declared point in the intake flow, only disidentified representations circulate outside the holding organization, and protection is removed only through an explicitly recorded narrow exception decided by a named authority.", "Time separation: occurrence, detection, submission and ingestion instants are captured independently and an unknown value is marked unknown rather than defaulted, because deadline compliance and causal ordering both depend on the distinction.", "Identity stability: a duplicate or merged record is retired with a derivation link and remains resolvable; identifiers are never reused and never encode dates, names or grades.", "Declared-not-enforced: constraint sets, state transitions, escalation paths and retention schedules are declared here and evaluated or executed by external components; declaring them confers no evaluation, enforcement or disposal authority." ], "crud": { "read": [ "Reading an issue record returns the current values plus the supersession history needed to reconstruct prior assertions; a reader may not be served a current value without access to its assertion attribution.", "Read scope is filtered by the record's sensitivity classification and the reader's entitlement basis; where entitlement is partial, a disidentified extract is served rather than a silently truncated record whose omissions are invisible.", "Evidence items are read through their custodian system with the issue supplying only the reference and digest, so that evidence access control is not duplicated or weakened here.", "Read access to a tombstoned record returns the tombstone — identifier, disposition outcome, disposal instant and authorising reference — rather than a not-found response." ], "create": [ "A record is created only from an intake submission that satisfies the declared minimum information set for its channel, or is explicitly marked incomplete with the missing fields enumerated.", "Creation assigns the authoritative identifier per the identity priority and records the ingestion instant separately from the detection and occurrence instants.", "The as-submitted intake artifact is retained unaltered at creation and referenced immutably, so later edits are distinguishable from what was originally asserted.", "Creation of a record that duplicates an existing canonical record is permitted but must be resolved by the identity function into a supersession, never by silent discard." ], "update": [ "Updates are field-level patches carrying the acting agent, an RFC 3339 instant and a reason; whole-record replacement is not permitted.", "Updates to substantive assertions retain the superseded value with its interval and attribution; the identifier, ingestion instant and preserved intake artifact are immutable.", "A state change is applied only through a declared permitted transition by a party competent at the record's current significance level; the guard evaluation is performed by the external workflow component and its outcome is recorded here.", "Reclassification and regrading record the prior values, the justification and the endorsing party where endorsement is required." ], "delete": [ "Issue records are not deleted on request. Disposal occurs only when the retention period computed from the declared anchor has elapsed and no disposal hold is active, and it is authorised by the authority named in the adopting Dimension's retention policy.", "On disposal, the record is replaced by a tombstone retaining the authoritative identifier, the disposition outcome, the disposal instant and the disposal authorisation reference, so that inbound references from incidents, actions and knowledge entries do not silently break.", "Execution of destruction, de-identification of stored copies and any disposal certification are owned by the referenced records retention and disposition model or by the adopting Dimension's policy; this model records only the retention class, hold state, authorisation reference and resulting tombstone and holds no disposal authority of its own.", "A legal, regulatory or investigative hold suspends disposal indefinitely until lifted by the recorded hold authority; a held record may be neither tombstoned nor purged, and the hold reason and review date remain readable to entitled parties.", "Where a confidentiality regime requires removal of personal details rather than removal of the record, de-identification is applied in place and recorded as a de-identification state change, not as a deletion, so that safety and quality analysis of the disidentified content survives.", "Retracted duplicates are never hard-deleted: they are superseded with a derivation link to the canonical record and follow the canonical record's retention class." ] }, "roles": [ { "name": "Issue registrar", "responsibilities": [ "Register records from intake submissions and verify the minimum information set for the channel", "Assign the authoritative identifier per the identity priority and record ingestion time separately", "Preserve the as-submitted intake artifact unaltered and reference it immutably" ] }, { "name": "Issue record owner", "responsibilities": [ "Hold accountability for completeness, correctness and currency of the record", "Maintain the discrepancy statement, classification and grading with attribution", "Ensure resolution and verification references are attached and their consequent acceptance status is current" ] }, { "name": "Competent review authority", "responsibilities": [ "Decide triage acceptance, significance grading endorsement, disposition category and closure", "Assess feasibility, effect on the agreement, effect on intended use and applicability to in-process items before disposition", "Declare and resolve conflicts of interest where independence from the reporting or causing party is required" ] }, { "name": "Investigating analyst", "responsibilities": [ "Record hypotheses considered with their eliminating or confirming evidence", "Record proximate cause, root cause and contributing factors as separately typed statements with a conclusion status", "Produce and version the causal analysis report and any known-error and workaround knowledge" ] }, { "name": "Records and disclosure custodian", "responsibilities": [ "Apply the sensitivity classification, de-identification point and reporter-protection regime", "Produce disclosure extracts with resolvable derivation links and bounded release conditions", "Maintain retention class, hold state and tombstone, and route disposal authorisation to the owning retention policy" ] }, { "name": "Interoperability steward", "responsibilities": [ "Maintain crosswalk editions against target vocabulary versions with loss and conflict annotations", "Register external identifiers with representation roles and field-level authority assignments", "Keep alignment declarations honest and block unevidenced conformance claims" ] } ], "access": { "default_rule": "Deny by default. Read, write and export are granted per record on the basis of the record's sensitivity classification and the requester's stated entitlement, evaluated by the adopting Dimension's access control component; this model declares the classification and the entitlement bases but performs no evaluation or enforcement.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Reporter identity and personal details of persons named are withheld from all scopes by default and released only under a recorded narrow exception decided by a named authority, such as wilful misconduct or manifest severe disregard of an obvious risk.", "Entities entrusted with regulating the relevant domain may hold broader access to disidentified content than the originating organization grants to other requesters, on the entitlement basis recorded against the request.", "Evidence artifacts may carry a stricter classification than the issue record and are accessed through their custodian system; a grant on the issue never implies a grant on its evidence.", "Disposal-held records remain readable to entitled parties for the duration of the hold even where the normal retention period has elapsed.", "Emergency safety disclosure to parties directly responsible for an affected area may proceed on a disidentified extract before full entitlement review, with the basis and scope recorded at the time of release." ], "audit_requirements": [ "Every read, patch, state transition, disposition decision, extract release and hold change must be logged with the acting agent, the RFC 3339 instant with explicit offset, the affected scope and the entitlement basis relied on.", "Extract releases must log the derivation link, the release scope and the conditions attached, so a circulated extract can be traced to its authorising request.", "Invocations of a reporter-protection exception must be logged with the deciding authority and grounds and be separately reviewable.", "The audit trail is generated, made immutable and retained by the referenced audit log service of the adopting Dimension; this model states what must be logged and holds no ownership of audit-trail generation, storage, immutability or review semantics." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Registry ID and Model ID (vr.wm-knw-014 / WM-KNW-014)", "Identity priority and timestamp rule summary", "Sensitivity, reporter-protection and retention entry points", "Known-relation ledger with the candidate WM-KNW-014 REFERENCE WM-ACT-021 link and its non-containment boundary" ], "read_order": [ "AGENTS.md — resolve Name, Type, Specification URL, Storage type URL, Interface URL and Processes URL before touching any record, including when storage is MongoDB or access is via MCP.", "Specification URL — model scope, exclusions and boundary notes, so that target-owned concepts are not modelled or written locally.", "Storage type URL — the projection in use and its canonicalization, ordering and immutability characteristics.", "Interface URL — read, create, update and disposal operations, entitlement bases and error semantics.", "Processes URL — registration, triage, causal recording, disposition, disclosure and retention procedures with their competent authorities.", "Known-relation ledger and composition links — confirm which referenced model owns action execution, verification, enforcement, audit trail and disposal before performing any operation." ] } }, "coverage": { "claim": "This audit covers the whole active-provider result for WM-KNW-014 — all 6 bundles, 12 layers, 26 findings, 104 questions, 10 artifacts, 12 functions, 13 sources and the complete service-layer block — read against the frozen registry record, the empty relationship contract, the absent legacy source and the declared omissions. It is not a completeness claim for the Issue/Problem domain: ITSM problem-management structure, OH&S and clinical patient-safety specialization remain declared gaps; live URL and version verification was impossible in this no-tools audit; and no independent second-provider review exists because Grok is owner-waived. The result is publishable only as a reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identity priority names the authoritative master-system identifier first, then governed global identifier or IRI, then Dimension-minted UUIDv7 or ULID per RFC 9562. Correlation values and fingerprints are explicitly demoted to matching aids. Duplicate detection, canonical selection, supersession and cross-system identifier registration with representation roles are all modelled." }, { "dimension": "lifecycle", "status": "covered", "notes": "Declared state set with terminality, permitted transitions with guards and competent parties, OSLC-style progress predicates, triage acceptance, disposition value set drawn from ECSS practice, closure criteria, reopening rules and supersession. Transition evaluation and workflow routing are explicitly left to external components." }, { "dimension": "relationships", "status": "covered", "notes": "Typed issue-to-issue relations with directionality, cardinality and cycle rules; outward links to occurrences, requirements, assets, tests, actions and changes with explicit predicates; dangling-reference handling with last-known-state snapshots. Referenced records' lifecycles remain with their owning models." }, { "dimension": "temporal", "status": "covered", "notes": "Occurrence, detection, submission and ingestion instants are separated and never derived from one another; interval divergences carry bounds; externally imposed reporting and transmission deadlines are carried with the anchor they run from. RFC 3339 with seconds and explicit offset or 'Z' is mandated, including the '-00:00' unknown-local-offset convention." }, { "dimension": "provenance", "status": "covered", "notes": "Per-claim attribution, derivation links for merges and supersessions, assertion intervals and confidence rank, aligned to PROV-O Entity/Activity/Agent and the qualification pattern. Explicitly distinguished from the audit trail, which is owned by the referenced audit log service." }, { "dimension": "ownership", "status": "covered", "notes": "Record owner, custodian organization and jurisdiction, accountability intervals and handover; competent decision authority per determination with significance-driven shifts; field-level authoritative-holder assignment where several systems carry overlapping values." }, { "dimension": "validation", "status": "covered", "notes": "Minimum information set per lifecycle stage, cross-field consistency constraints, record quality indicators and fitness thresholds, expressed as a versioned declarative conformance profile. The model states explicitly that an external component performs evaluation and that declaring constraints confers no enforcement authority." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default rule with the four required scopes, entitlement bases, sensitivity-driven filtering, disidentified extracts for partial entitlement, stricter evidence classification, and five named exception paths including emergency safety disclosure and regulator access to disidentified content." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention class with anchor, disposal holds with placing and lifting authority, tombstone specification preserving identifier and disposal outcome, de-identification-in-place as an alternative to deletion, and an explicit statement that destruction execution and certification are owned by the referenced retention model or the adopting Dimension's policy." }, { "dimension": "interoperability", "status": "covered", "notes": "Versioned crosswalks with lossiness and conflict annotation, alignment-not-conformance policy, external identifier registration with representation roles, onward transmission obligations, and OSLC state-vocabulary migration precedent for compatible evolution." }, { "dimension": "classification", "status": "covered", "notes": "Type and category coding bound to external schemes with identifier and version, multi-scheme cardinality and precedence, reclassification with history retention, and separated severity, priority and significance grading axes with endorsement where mandated." }, { "dimension": "causality", "status": "covered", "notes": "Hypotheses with eliminating evidence, separately typed proximate cause, root cause and contributing factors, method and analyst attribution, conclusion status, and a formal undetermined-cause outcome distinguishable from an unfinished investigation." }, { "dimension": "evidence and quality", "status": "covered", "notes": "Evidence set with custodian, capture time and content digest; sufficiency assessment naming gaps that block a sought disposition; reproducibility status and versioned reproduction procedures; contested-claim handling that preserves both positions." }, { "dimension": "measurement", "status": "covered", "notes": "Occurrence counts, baseline state relative to a prior assessment, deviation magnitude with units, quantified consequence measures, confidence rank on a declared scale, and record quality indicators. Aggregate analytics and dashboards are external consumers, not part of this model." }, { "dimension": "spatial and environmental context", "status": "covered", "notes": "Observation location with scheme, configuration, build, batch and serial state of the affected subject at recognition, and named environment or process-condition sets sufficient for a reproduction attempt." }, { "dimension": "privacy and reporter protection", "status": "covered", "notes": "Sensitivity classification separable between record and evidence, de-identification point in the intake flow, disidentified-only circulation, and narrowly enumerated protection exceptions grounded in Regulation (EU) No 376/2014." }, { "dimension": "authority and exceptions", "status": "covered", "notes": "Competence mapping per determination, escalation path with triggering conditions and intervals, independence requirements with conflict-of-interest resolution, and waiver, concession or deviation references with scope and expiry." }, { "dimension": "enforcement and audit-trail semantics", "status": "not-applicable", "notes": "Deliberately excluded. Runtime evaluation, policy enforcement and audit-trail generation, immutability and review belong to the referenced evaluator, workflow and audit log services; the model declares requirements and records outcomes only, and holds no ownership of these semantics." }, { "dimension": "cost, effort and scheduling of resolution", "status": "not-applicable", "notes": "Effort estimation, scheduling, capacity and cost of resolution work belong to WM-ACT-021 and are reached only through the non-owning reference." }, { "dimension": "domain-specific ITSM structure", "status": "gap", "notes": "Problem-versus-incident structure, known error database semantics and ITIL 4 practice terminology could only be sourced from a tier-4 vendor page because ITIL 4 and ISO/IEC 20000-1:2018 are proprietary. The known-error finding is therefore modelled generically and is marked as lacking primary support for its ITSM-specific naming." }, { "dimension": "safety and health incident specialization", "status": "gap", "notes": "Aviation occurrence reporting is well supported by Regulation (EU) No 376/2014, but occupational health and safety incident structure (ISO 45001) and clinical patient-safety reporting were not verified against primary sources in this session and may require a specializing sibling model." } ], "known_omissions": [ "ITSM problem management structure derived from ITIL 4 and ISO/IEC 20000-1:2018 is unverifiable at primary level because both are proprietary; the known-error and workaround finding rests on a tier-4 secondary source for its terminology and is marked as a gap.", "ISO/IEC/IEEE 24765 and ISO 9000:2015 term definitions for problem, defect, anomaly, nonconformity and root cause could not be retrieved — the ISO Online Browsing Platform returned 403 — so definitional boundaries rest on IEEE 1044-2009, ECSS-Q-ST-10-09C and 21 CFR 820.100 instead.", "IEEE Std 1044-2009 was verified as published but is Inactive-Reserved since 5 March 2020; its detailed classification attribute set is behind a paywall and was not read, so typology structure draws on its stated scope rather than its clause text.", "The definitional appendix of NASA NPR 8621.1D was not retrievable in a readable form; the source supports the separation of reporting, investigation, corrective action and recordkeeping stages, not the specific wording of proximate cause, root cause or contributing factor.", "Quantitative severity and priority scales are deliberately not fixed. No cross-domain normative scale exists, and imposing one would be unsupported structure; the model requires a declared scheme with version instead.", "Escalation timing thresholds, ageing bands and service-level targets are left to the adopting Dimension; no primary source establishes cross-domain values.", "Multilingual and translation semantics for discrepancy statements circulating across jurisdictions are not modelled.", "Statistical aggregation, trend detection and predictive analytics over issue populations are treated as external consumption, not as model content." ], "conflicts": [ "State representation conflicts across sources: OSLC CM 3.0 carries both an enumerated oslc_cm:state and independent boolean predicates (closed, fixed, verified) and marks oslc_cm:status archaic, while SARIF expresses status as baselineState relative to a prior run and separately as suppressions. These are not reconcilable into one field; the model carries state, predicates and baseline state as distinct elements and records the mapping as lossy rather than collapsing them.", "Identity conflicts: SARIF treats fingerprints as the stable cross-run identity of a result, whereas RFC 9562 warns against treating derived or name-based values as durable primary keys. The model resolves this by ranking master-system and governed identifiers above minted UUIDs and by demoting fingerprints to correlation aids, which will lose some SARIF round-trip fidelity for tools that key on fingerprints alone.", "Disposition vocabulary conflicts: ECSS fixes a closed set (return to supplier, use as is, rework, repair, scrap) appropriate to physical deliverables, while software and service domains need outcomes such as permanent removal of cause, not-reproducible and no action with justification. No single normative disposition set exists across domains, so the model requires a declared closed set per adopting Dimension rather than asserting one.", "Terminology conflict on 'problem': IEEE 1044-2009 distinguishes problem, failure, fault and defect within software anomaly classification, while ITSM practice uses 'problem' specifically for the cause of one or more incidents. The model uses 'discrepancy' as the neutral primitive and records both readings as alignments rather than choosing one.", "Cause-terminology conflict: aviation and aerospace practice separates proximate cause, root cause and contributing factor, while 21 CFR 820.100 speaks only of investigating 'the cause' of nonconformities. The model carries the finer distinction as optional typed statements so that a regulated single-cause record remains valid.", "Retention conflict: Regulation (EU) No 376/2014 requires removal of personal details and storage of disidentified information only, while quality regimes require retention of records evidencing the nature of nonconformities and the results of corrective action. The model resolves this as de-identification-in-place rather than deletion, but the resolution is an interpretation and is flagged as such." ], "regional_assumptions": [ "Reporter protection and de-identification requirements are modelled from the EU civil aviation regime, which is binding only in that sector and jurisdiction. Other regions and sectors have weaker, absent or differently scoped protections; the model treats the regime as a declared per-Dimension parameter, not as a universal default.", "Corrective and preventive action structure is modelled from US FDA device regulation as it stood in the 2023 CFR edition. That part has been undergoing harmonization toward ISO 13485-based requirements; adopters in that sector must confirm the currently effective text before relying on clause-level structure.", "Nonconformance disposition and review board structure is modelled from European space product assurance practice and is contractual within that supply chain rather than generally binding.", "Reporting deadlines of 72 hours for submission and 30 days for onward transmission are aviation-specific and must not be generalized to other domains.", "Time representation assumes RFC 3339 with explicit offsets; deployments that store only local civil time or only naive UTC will lose the occurrence-versus-ingestion distinction the model depends on.", "Language is assumed to be a single working language per adopting Dimension; cross-border exchange of free-text discrepancy statements may require translation semantics this model does not provide." ], "adversarial_checks": [ "Boundary sweep against the known-relation ledger: the registered ledger is empty, so every bundle, layer, finding and function was instead checked against each composition link's rationale and against the registry parent WM-ACT-021. Three candidate findings were removed or converted during drafting — a resolution-work-planning finding, an escalation-execution finding and an audit-trail finding — because each would have owned a target model's operational semantics. What remains are reference-only findings: resolution and verification are pointers plus a consequent acceptance status; escalation is a declared path, not a routing engine; audit is a stated logging requirement discharged by the referenced audit log service.", "Enforcement trap test: the record-completeness finding declares constraints and a versioned conformance profile but explicitly names an external evaluator and states that declaration confers no enforcement authority. The same test was applied to the state model, the escalation path and the retention schedule — each declares and records, none evaluates, routes or destroys.", "Attractive-but-unsupported structure rejected: a numeric cross-domain severity scale, a canonical universal state machine, a fixed disposition enumeration and a built-in root-cause taxonomy were all considered and rejected because no primary source establishes any of them across domains. Each is instead a declared, versioned, per-Dimension binding.", "Counterexample search on identity: a discrepancy detected by a scanner has no master-system identifier at detection time, only a fingerprint. The identity priority handles this by permitting a Dimension-minted UUIDv7 while keeping the fingerprint as a correlation aid, and the cross-system correspondence finding lets a later master-system identifier be registered without invalidating the original — verified against the RFC 9562 warning about permanence assumptions.", "Counterexample search on aggregation: a condition observed 10,000 times by a monitor would flood a one-record-per-observation model. Occurrence aggregation with a declared sameness rule, occurrence count and baseline state absorbs this, while the duplicate-versus-recurrence distinction prevents the opposite failure of merging genuinely distinct discrepancies.", "Deletion-request stress test: a request to erase a record containing personal details was traced through the delete rules. The model refuses hard deletion, applies de-identification in place, preserves the safety- and quality-relevant content, and routes any actual disposal to the owning retention policy with a tombstone preserving inbound references — while acknowledging in the conflicts list that this reconciliation of privacy and record-keeping duties is an interpretation.", "Inversion test on evidence: an attempt to make the issue record the evidence store was rejected. Evidence stays with its custodian and is referenced with a digest, so that access control and integrity are not silently re-implemented at weaker strength inside this model." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "aggregate", "status": "reclassified", "rationale": "Two axes must be kept apart. On the record plane the frozen registry value 'standalone-mm' asserts only that vr.wm-knw-014 is a self-contained mega-model record rather than a component of another record; it classifies the registry entry, is not a member of the schema enum, and must never be carried into boundary_decision. On the subject-model axis the provider's 'entity' understates what was actually built. Ten artifact types (intake submission, evidence item, reproduction procedure, causal analysis report, known-error entry, workaround instruction, disposition record, crosswalk edition, conformance profile, disclosure extract) are identified by binding to the owning issue identifier plus ordinals; the CRUD and retention rules define a single consistency boundary over that whole cluster (tombstone preserves the root identifier so inbound references survive, retracted duplicates inherit the canonical record's retention class, evidence is reachable only through the root's reference and digest); and no contained artifact is independently addressable in the model's own namespace scheme. That is an aggregate root, not a flat entity. 'aggregate' is therefore the most defensible schema kind. The reclassification sharpens the provider's own structure rather than contradicting it, and leaves the record-plane value untouched." }, "decisions": [ { "concept": "Entry kind on the subject-model axis", "disposition": "reclassified from entity to aggregate", "rationale": "Artifact identity, serial ordinals, retention inheritance and tombstone behaviour all bind ten artifact types to one root issue identifier, which is aggregate-root behaviour rather than flat-entity behaviour; the frozen registry 'standalone-mm' value is a record-plane classifier and is deliberately not reused here." }, { "concept": "Aggregate root: issue record versus the real-world discrepancy it asserts", "disposition": "accepted with mandatory disclosure", "rationale": "identity_priority ranks record-level master-system identifiers first and explicitly demotes SARIF fingerprints and correlationGuid to matching aids, so the underlying discrepancy referent has no first-class identity across systems; cross-system-correspondence carries that burden by correlation alone. Record-as-root is the defensible choice for a storage-neutral model, but the draft must state plainly that the referent is unidentified, not silently imply otherwise." }, { "concept": "WM-KNW-014 relation to WM-ACT-021", "disposition": "accepted-as-candidate-reference", "rationale": "The prior parent/CHILD direction contradicted both models: a service case may expose or track an issue, while the issue keeps independent identity, causal analysis and disposition. The registry source now removes WM-ACT-021 from parent_ids and records the candidate edge WM-KNW-014 REFERENCE WM-ACT-021. EM-COM-04 independent provider review reached the same boundary: problem lifecycle remains separate from case lifecycle." }, { "concept": "Coverage-claim assertion that excluded concerns are 'bound through a composition link'", "disposition": "superseded by registered candidate relation", "rationale": "The relation ledger now records candidate WM-KNW-014 REFERENCE WM-ACT-021. Publication language must call it a candidate non-owning reference until canonical relation approval, without implying containment or a completed governance chain." }, { "concept": "Primary-source arithmetic in the coverage claim", "disposition": "rejected; correct eleven to twelve", "rationale": "SRC-001 through SRC-012 all carry primary_source true, giving twelve primary sources, while the coverage claim states eleven; only SRC-013 is non-primary. The nine-organizations figure holds only if the two OASIS entries are merged, which should be stated explicitly rather than left implicit." }, { "concept": "Serial artifact naming scope", "disposition": "split into record-scoped and model-scoped serial classes", "rationale": "serial_naming_rule keys every serial artifact to the owning issue identifier plus a zero-padded ordinal, but af-vocabulary-crosswalk is keyed by target namespace and target version and af-record-conformance-profile by profile namespace and semantic version. Both are marked serial:true yet are model-scoped editions with no owning issue, so the rule as written cannot govern them." }, { "concept": "Disclosure-extract identifier minted as UUIDv7", "disposition": "rejected for this artifact; require a non-time-ordered identifier", "rationale": "af-disidentified-extract requires that the identifier encode no protected personal detail, yet UUIDv7 deliberately encodes a time-ordered creation instant. Release timing correlated with a small occurrence population is a re-identification vector that undercuts the reporter-protection-by-default policy; a random identifier serves the same resolution purpose without the leak." }, { "concept": "Hard-deletion refusal phrased as a model-held authority", "disposition": "accepted with required rewording", "rationale": "'Issue records are not deleted on request' reads as enforcement while the declared-not-enforced policy and the retention finding both disclaim any disposal authority. Restate it as a constraint the adopting Dimension must implement, so the model's stated powerlessness and its stated prohibition stop contradicting each other." }, { "concept": "De-identification-in-place as the answer to an erasure request", "disposition": "deferred pending a data-protection source", "rationale": "The deletion-request stress test traces an erasure demand for personal details, but no data-protection instrument appears anywhere in SRC-001 to SRC-013; the resolution currently rests only on EU 376/2014 reporter protection plus quality-retention duties. The conflicts list already flags it as an interpretation, and that flag must survive into publication." }, { "concept": "Emergency safety disclosure exception in the access model", "disposition": "accepted with a required post-hoc review duty", "rationale": "Reporter-protection exceptions must be 'separately reviewable', but emergency release before entitlement review is only logged. That asymmetry leaves the widest bypass in a deny-by-default model without the review obligation attached to the narrower one." }, { "concept": "Question kind assigned to q-tr-suppression", "disposition": "re-kind from access to exception", "rationale": "Recording and reviewing an intentionally suppressed detection is a triage and exception semantic drawn from SARIF suppressions, not an access-control question. The miskinding also inflates the already thin access kind count of two and understates exception coverage." }, { "concept": "Verb of fn-transition-state", "disposition": "accepted with rewording to record an applied transition", "rationale": "The function says it moves the record between states, while the update rules place guard evaluation and workflow routing in an external component whose outcome is only recorded here. The imperative wording is the one place where the boundary-discipline policy leaks." }, { "concept": "Function coverage for triage outcome, occurrence aggregation and typed issue-to-issue relations", "disposition": "deferred as a named gap", "rationale": "triage-and-acceptance-decision, occurrence-aggregation-and-recurrence and issue-to-issue-relations carry no corresponding function; fn-resolve-identity covers duplicates and cross-system identifiers but not increment-versus-new-record, baseline state or relation assertion. add_functions must stay empty in single-provider mode, so this is recorded for the next revision rather than patched here." }, { "concept": "Model name 'Issue / Problem' against the discrepancy primitive", "disposition": "accepted with a visible naming note", "rationale": "The name imports the ITSM sense of 'problem' as the cause of one or more incidents, which the coverage checklist marks as a tier-4-only gap and the conflicts list resolves by adopting 'discrepancy' as the neutral primitive. Keep the registry name for continuity, but state in the published draft which reading is modelled." }, { "concept": "Tier-4 sole-support test on SRC-013", "disposition": "accepted", "rationale": "Checked every citation of the Atlassian page: known-error-and-workaround-knowledge also cites SRC-007 and SRC-009, occurrence-aggregation-and-recurrence also cites SRC-003 and SRC-009, and fn-record-causal-outcome also cites SRC-007, SRC-005 and SRC-012. No finding or function rests on the tier-4 source alone, so the declared gap is honestly bounded." }, { "concept": "Blocking-conflict assessment", "disposition": "no critical conflict recorded", "rationale": "Every contradiction found — candidate relation approval, source-count arithmetic, serial-scope mismatch — is disclosed or correctable within the draft and none prevents a public reviewable draft. The waiver of Grok is an authorized absence of review, not a contradiction, and is handled as a publication hold rather than manufactured into a conflict." } ], "publicationHolds": [ "Live source and version verification is outstanding: this audit had no tools, so none of the thirteen URLs or version pins were confirmed against the live web. SRC-005 Inactive-Reserved status, the SRC-007 2023 CFR edition against any superseding QMSR text, the SRC-012 interim-direction note and the undated SRC-013 access date must each be re-verified before publication.", "Independent second-provider review is absent by explicit repository-owner authorization dated 2026-08-29T09:06:27Z after repeated Grok structured-output failures. Every publication artifact must carry a visible single-provider banner and the result stays a reviewable draft, not a validated model.", "The corrected WM-KNW-014 REFERENCE WM-ACT-021 row remains candidate until canonical relation-ledger approval; publication must not describe containment, parenthood or lifecycle inheritance.", "Coverage-claim corrections must land before publication: eleven primary sources must become twelve, the nine-organizations count must state that the two OASIS entries are merged, and relation language must identify the candidate non-owning reference.", "The registry entry_kind reconciliation must be visible in the published artifact: record-plane 'standalone-mm' and subject-model kind 'aggregate' are two different axes and both must appear, so no reader treats the frozen registry value as the model kind.", "The af-disidentified-extract identifier scheme must be changed off UUIDv7 to a non-time-ordered identifier, or the reporter-protection claim that the extract identifier encodes no protected personal detail must be withdrawn.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Acquire licensed access to ITIL 4 and ISO/IEC 20000-1:2018 to replace the tier-4 Atlassian basis for problem-versus-incident structure, known-error-database semantics and workaround terminology.", "Retrieve ISO/IEC/IEEE 24765 and ISO 9000:2015 definitions for problem, defect, anomaly, nonconformity and root cause; the ISO Online Browsing Platform returned 403 in the source session and the definitional boundary currently rests on IEEE 1044-2009, ECSS-Q-ST-10-09C and 21 CFR 820.100.", "Identify a primary data-protection instrument covering the erasure-versus-record-keeping tension so that de-identification-in-place stops resting on an aviation reporter-protection regime plus quality-retention duties alone.", "Verify the currently effective US FDA text for corrective and preventive action, since the model is built on the 2023 CFR 820.100 edition during an ongoing harmonization toward ISO 13485-based requirements.", "Source ISO 45001 occupational health and safety incident structure and clinical patient-safety reporting to decide whether a specializing sibling model is required rather than stretching this aggregate.", "Obtain IEEE 1044-2009 clause text or its successor disposition so that typology structure draws on the classification attribute set rather than only the standard's stated scope.", "Register the ten neighbour models referenced in the boundary notes — action, change, incident, risk, records retention, party, requirement, classifier registry, audit-log service and the vulnerability specialization sibling — so the relationship contract stops being empty and the boundary discipline becomes checkable.", "Design and add functions for triage outcome recording, occurrence aggregation with baseline state, and assertion of typed issue-to-issue and external-subject relations, all of which have findings but no corresponding function." ] }, "statistics": { "sources": 13, "bundles": 6, "layers": 12, "findings": 26, "questions": 104, "artifacts": 10, "functions": 12 } }