# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-07T11:55:32Z", "synthesisSha256": "50e7a5f03c063583dd672f6032b5cfdd931801bc1eb8c144dde8c155ab13e89c", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-MED-008", "registryId": "vr.wm-med-008", "name": "Content Provenance Credential", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.MED.PRV" ], "tags": [ "content", "provenance", "credential", "inf.med.prv" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-med-008-content-provenance-credential/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-med-008", "model": { "registry_id": "vr.wm-med-008", "model_id": "WM-MED-008", "name": "Content Provenance Credential", "entry_kind": "aggregate", "purpose": "Represent an issuer-attributable, integrity-protected and asset-bound set of provenance assertions with verifiable lineage, status, validation and disclosure context.", "scope_statement": "Owns content-provenance credential identity and revision; subject asset, rendition, segment and region scope; manifest, claim, assertion and attestation composition; hard and soft content bindings; action, ingredient and derivation references; signer, claim-generator, identity-provider, key, certificate, proof, timestamp and status evidence; embedded, external, repository and durable discovery bindings; validation component results and codes; trust-policy inputs and scoped decision references; human-facing disclosure; privacy, harms, lifecycle, preservation, access, retention, audit and loss-aware interoperability. Media assets, creative works, people, organizations, devices, software, keys, certificates, actions, repositories, rights instruments, evidence and trust decisions remain external masters.", "in_scope": [ "Credential identity, subject and region scope, assertions, manifests, claims, bindings, signatures, times and status", "Actions, ingredients, derivation, storage, discovery, recovery, validation, trust inputs and disclosure", "Privacy, harms, lifecycle, preservation, access, retention, audit and version-pinned interoperability" ], "out_of_scope": [ "Owning media-asset, creative-work, party, device, software, key, certificate, action, repository, rights, evidence or accountable trust-decision lifecycles", "Treating a hash, filename, URL, watermark, manifest, signature, certificate, trust-list entry, validation result or label as universal asset or credential identity", "Inferring factual truth, authorship, copyright, ownership, editorial endorsement, legality, safety or universal trust from provenance or cryptographic validity", "Signing, attesting identity, changing trust lists, disclosing protected provenance, revoking credentials or irreversibly deleting records without accountable authority" ], "boundary_notes": [ { "neighbor": "WM-MED-002 Media Asset / Rendition", "distinction": "The media model owns byte-bearing assets, renditions, technical formats and fixity. This model owns credentials and qualified bindings to those assets without importing media identity.", "source_refs": [ "SRC-001", "SRC-004", "SRC-022" ] }, { "neighbor": "WM-MED-001 Creative Work / Content", "distinction": "The work model owns intellectual content and authorship context. Provenance assertions may reference it but do not prove authorship, ownership or truth.", "source_refs": [ "SRC-001", "SRC-012", "SRC-017" ] }, { "neighbor": "C2PA manifest, claim, assertion and manifest store", "distinction": "These are profile-specific composition parts or containers. The logical credential record retains their identities and roles without requiring one serialization.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "neighbor": "Signer, issuer, human identity and organization", "distinction": "A signer controls a key, an issuer makes claims, and an optional identity provider attests a person or organization. None is inferred from an asset creator field alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-015" ] }, { "neighbor": "Validation result and trust decision", "distinction": "Validation establishes component outcomes under pinned rules. A verifier separately decides trust for a purpose and context; neither result proves assertion truth.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-012", "SRC-013" ] }, { "neighbor": "Copyright, rights and editorial policy", "distinction": "Credentials can carry or reference rights and editorial assertions, but legal ownership, permission and accountable publication decisions remain external.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-025" ] }, { "neighbor": "W3C Verifiable Credential", "distinction": "VC 2.0 supplies a broader issuer-holder-verifier claim model. C2PA and VC representations may be mapped only with explicit subject, proof, status and lifecycle semantics.", "source_refs": [ "SRC-012", "SRC-013", "SRC-014", "SRC-016" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Content Credentials: C2PA Technical Specification", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html", "version_or_date": "C2PA 2.4, April 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines assertions, claims, manifests, content bindings, signatures, trust, validation, actions, ingredients, redaction and supported embedding profiles." }, { "id": "SRC-002", "title": "Content Credentials JSON File Format", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.4/crJSON/crjson-format.html", "version_or_date": "C2PA 2.4, April 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines a JSON-LD derived view for evaluation and reporting while explicitly keeping the signed binary form authoritative." }, { "id": "SRC-003", "title": "Attestation in the C2PA Framework", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/1.4/attestations/attestation.html", "version_or_date": "Current official attestation document linked from C2PA 2.4", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines externally issued attestations, attestation manifests, credential holders and references to protected assertions." }, { "id": "SRC-004", "title": "C2PA Soft Binding API", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.4/softbinding/Decoupled.html", "version_or_date": "C2PA 2.4, April 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines fingerprint and watermark lookup, manifest repositories, recovery responses, confidence and durable credential discovery." }, { "id": "SRC-005", "title": "C2PA Implementation Guidance", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.2/guidance/Guidance.html", "version_or_date": "Current official guidance linked from C2PA 2.4", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Explains signer, trust-list, private credential, validation, capture and workflow implementation choices." }, { "id": "SRC-006", "title": "C2PA User Experience Guidance", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.2/ux/UX_Recommendations.html", "version_or_date": "Current official UX guidance linked from C2PA 2.4", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines progressive disclosure, provenance indicators, validation communication, accessibility and user interpretation concerns." }, { "id": "SRC-007", "title": "C2PA Security Considerations", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.4/security/Security_Considerations.html", "version_or_date": "C2PA 2.4, April 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines threat surfaces, signature and binding validation, ingredient verification, revocation, time and trust concerns." }, { "id": "SRC-008", "title": "C2PA Harms Modelling", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.4/security/Harms_Modelling.html", "version_or_date": "C2PA 2.4, April 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Covers privacy, surveillance, coercion, exclusion, false confidence, removal and harms to vulnerable creators and subjects." }, { "id": "SRC-009", "title": "Guidance for Artificial Intelligence and Machine Learning", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.3/ai-ml/ai_ml.html", "version_or_date": "Current official AI/ML guidance linked from C2PA 2.4", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines AI disclosure, digital source types, training data and model-related provenance considerations." }, { "id": "SRC-010", "title": "Human and Organizational Identity Recommendation", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.4/identity/identity.html", "version_or_date": "C2PA 2.4, April 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Separates signer credential identity from optional human or organizational identity assertions and identity providers." }, { "id": "SRC-011", "title": "C2PA Conformance Explorer", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/conformance-explorer/", "version_or_date": "Live conformance, signer trust and TSA trust registries, accessed 7 September 2026", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Publishes product conformance and current C2PA and TSA trust-list views used by validators." }, { "id": "SRC-012", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines issuer, holder, verifier, credential subject, claims, validity, status, evidence, schemas, presentations and trust boundaries." }, { "id": "SRC-013", "title": "Verifiable Credential Data Integrity 1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-integrity/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines data-integrity proofs, verification results, cryptographic suites, resource integrity and transformation concerns." }, { "id": "SRC-014", "title": "Securing Verifiable Credentials using JOSE and COSE", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-jose-cose/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines JOSE, COSE and selective-disclosure envelopes for credentials without making one proof format part of the logical model." }, { "id": "SRC-015", "title": "Controlled Identifiers v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/cid-1.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines controller documents, verification methods and relationships between controllers and cryptographic keys." }, { "id": "SRC-016", "title": "Bitstring Status List v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-bitstring-status-list/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines privacy-preserving credential revocation, suspension and refresh status publication and retrieval." }, { "id": "SRC-017", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines entities, activities, agents, generation, use, derivation, attribution, revision and invalidation." }, { "id": "SRC-018", "title": "Web Annotation Data Model", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/annotation-model/", "version_or_date": "W3C Recommendation, 23 February 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines bodies, targets, selectors, motivations and provenance for region- or segment-scoped assertions." }, { "id": "SRC-019", "title": "CBOR Object Signing and Encryption Structures", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9052.html", "version_or_date": "RFC 9052, August 2022; updated by RFC 9338", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines COSE protected and unprotected headers, payloads and signature structures used by C2PA and VC profiles." }, { "id": "SRC-020", "title": "Internet X.509 Public Key Infrastructure Certificate and CRL Profile", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc5280.html", "version_or_date": "RFC 5280, May 2008", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines certificate paths, extensions, validity, revocation lists, policies and certification path validation." }, { "id": "SRC-021", "title": "Internet X.509 Public Key Infrastructure Time-Stamp Protocol", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3161.html", "version_or_date": "RFC 3161, August 2001; updated by RFC 5816", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines trusted timestamp requests, tokens, message imprints, serial numbers and TSA evidence." }, { "id": "SRC-022", "title": "Digest Fields", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9530.html", "version_or_date": "RFC 9530, February 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines representation and content digests and algorithm identifiers for HTTP resources." }, { "id": "SRC-023", "title": "JSON Canonicalization Scheme", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc8785.html", "version_or_date": "RFC 8785, June 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines deterministic JSON canonicalization for repeatable digest and signature inputs where the selected profile uses JSON." }, { "id": "SRC-024", "title": "Date and Time on the Internet", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines interoperable timestamps with seconds and an explicit numeric offset or Z." }, { "id": "SRC-025", "title": "IPTC Photo Metadata User Guide", "organization": "International Press Telecommunications Council", "url": "https://www.iptc.org/std/photometadata/documentation/userguide/", "version_or_date": "Current guide, accessed 7 September 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Defines digital source type, creator, rights and image metadata guidance, including AI-generated and algorithmically altered sources." }, { "id": "SRC-026", "title": "Artificial Intelligence Risk Management Framework: Generative AI Profile", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf", "version_or_date": "NIST AI 600-1, July 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-07T11:45:00Z", "relevance": "Treats provenance, watermarking, metadata, content authentication and transparency as complementary risk controls rather than truth guarantees." } ], "structure": { "bundles": [ { "id": "credential-identity-scope-and-asset-binding", "name": "Credential identity, scope and asset binding", "description": "Groups the governed Resource Consumption concern for credential identity, scope and asset binding.", "rationale": "Establish the credential subject and exact protected relationship without turning a representation or locator into identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012", "SRC-013", "SRC-014", "SRC-004", "SRC-017", "SRC-018", "SRC-022" ], "layers": [ { "id": "credential-manifest-claim-and-assertion-boundary", "name": "Credential, manifest, claim and assertion boundary", "description": "Groups Resource Consumption context for credential, manifest, claim and assertion boundary without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012", "SRC-013", "SRC-014" ], "findings": [ { "id": "credential-identifier-namespace-version-issuer-holder-owner-and-master", "name": "Credential identifier, namespace, version, issuer, holder, owner and master system", "description": "Records credential identifier, namespace, version, issuer, holder, owner and master system as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012", "SRC-013", "SRC-014" ], "questions": [ { "id": "credential-identifier-namespace-version-issuer-holder-owner-and-master-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish credential identifier, namespace, version, issuer, holder, owner and master system?", "kind": "identity", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "credential-identifier-namespace-version-issuer-holder-owner-and-master-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews credential identifier, namespace, version, issuer, holder, owner and master system, and under which authority?", "kind": "provenance", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "credential-identifier-namespace-version-issuer-holder-owner-and-master-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify credential identifier, namespace, version, issuer, holder, owner and master system?", "kind": "measurement", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "credential-identifier-namespace-version-issuer-holder-owner-and-master-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to credential identifier, namespace, version, issuer, holder, owner and master system?", "kind": "access", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "credential-identifier-namespace-version-issuer-holder-owner-and-master-data", "name": "Credential identifier, namespace, version, issuer, holder, owner and master system data", "description": "Typed credential-scoped values and references required to answer the governed questions for credential identifier, namespace, version, issuer, holder, owner and master system.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012", "SRC-013", "SRC-014" ] } ], "artifacts": [ { "id": "credential-identifier-namespace-version-issuer-holder-owner-and-master-artifact", "name": "Credential identifier, namespace, version, issuer, holder, owner and master system evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting credential identifier, namespace, version, issuer, holder, owner and master system.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary", "name": "Manifest store, active manifest, claim, assertion, signature and presentation boundary", "description": "Records manifest store, active manifest, claim, assertion, signature and presentation boundary as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012", "SRC-013", "SRC-014" ], "questions": [ { "id": "manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish manifest store, active manifest, claim, assertion, signature and presentation boundary?", "kind": "composition", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews manifest store, active manifest, claim, assertion, signature and presentation boundary, and under which authority?", "kind": "ownership", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify manifest store, active manifest, claim, assertion, signature and presentation boundary?", "kind": "evidence", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to manifest store, active manifest, claim, assertion, signature and presentation boundary?", "kind": "exception", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-data", "name": "Manifest store, active manifest, claim, assertion, signature and presentation boundary data", "description": "Typed credential-scoped values and references required to answer the governed questions for manifest store, active manifest, claim, assertion, signature and presentation boundary.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012", "SRC-013", "SRC-014" ] } ], "artifacts": [ { "id": "manifest-store-active-manifest-claim-assertion-signature-and-presentation-boundary-artifact", "name": "Manifest store, active manifest, claim, assertion, signature and presentation boundary evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting manifest store, active manifest, claim, assertion, signature and presentation boundary.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null } ] }, { "id": "asset-subject-region-and-content-binding", "name": "Asset subject, region and content binding", "description": "Groups Resource Consumption context for asset subject, region and content binding without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-004", "SRC-017", "SRC-018", "SRC-022" ], "findings": [ { "id": "asset-rendition-segment-region-resource-and-credential-subject-binding", "name": "Asset, rendition, segment, region, resource and credential-subject binding", "description": "Records asset, rendition, segment, region, resource and credential-subject binding as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-004", "SRC-017", "SRC-018", "SRC-022" ], "questions": [ { "id": "asset-rendition-segment-region-resource-and-credential-subject-binding-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish asset, rendition, segment, region, resource and credential-subject binding?", "kind": "relationship", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "asset-rendition-segment-region-resource-and-credential-subject-binding-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews asset, rendition, segment, region, resource and credential-subject binding, and under which authority?", "kind": "authority", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "asset-rendition-segment-region-resource-and-credential-subject-binding-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify asset, rendition, segment, region, resource and credential-subject binding?", "kind": "quality", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "asset-rendition-segment-region-resource-and-credential-subject-binding-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to asset, rendition, segment, region, resource and credential-subject binding?", "kind": "interoperability", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "asset-rendition-segment-region-resource-and-credential-subject-binding-data", "name": "Asset, rendition, segment, region, resource and credential-subject binding data", "description": "Typed credential-scoped values and references required to answer the governed questions for asset, rendition, segment, region, resource and credential-subject binding.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-017", "SRC-018", "SRC-022" ] } ], "artifacts": [ { "id": "asset-rendition-segment-region-resource-and-credential-subject-binding-artifact", "name": "Asset, rendition, segment, region, resource and credential-subject binding evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting asset, rendition, segment, region, resource and credential-subject binding.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-004", "SRC-017", "SRC-018", "SRC-022" ] } ], "inline_only_rationale": null }, { "id": "hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery", "name": "Hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery", "description": "Records hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-004", "SRC-017", "SRC-018", "SRC-022" ], "questions": [ { "id": "hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery?", "kind": "evidence", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery, and under which authority?", "kind": "requirement", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery?", "kind": "validation", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery?", "kind": "decision", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-data", "name": "Hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery data", "description": "Typed credential-scoped values and references required to answer the governed questions for hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-017", "SRC-018", "SRC-022" ] } ], "artifacts": [ { "id": "hard-hash-soft-fingerprint-watermark-binding-algorithm-scope-and-recovery-artifact", "name": "Hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-004", "SRC-017", "SRC-018", "SRC-022" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "assertions-actions-ingredients-and-lineage", "name": "Assertions, actions, ingredients and lineage", "description": "Groups the governed Resource Consumption concern for assertions, actions, ingredients and lineage.", "rationale": "Represent what was asserted and how content changed while keeping source events, parties, tools and assets as external masters.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-017", "SRC-025", "SRC-007", "SRC-018", "SRC-026" ], "layers": [ { "id": "assertion-identity-payload-and-source", "name": "Assertion identity, payload and source", "description": "Groups Resource Consumption context for assertion identity, payload and source without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-017", "SRC-025" ], "findings": [ { "id": "assertion-label-version-instance-schema-format-source-and-claim-reference", "name": "Assertion label, version, instance, schema, format, source and claim reference", "description": "Records assertion label, version, instance, schema, format, source and claim reference as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-017", "SRC-025" ], "questions": [ { "id": "assertion-label-version-instance-schema-format-source-and-claim-reference-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish assertion label, version, instance, schema, format, source and claim reference?", "kind": "definition", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "assertion-label-version-instance-schema-format-source-and-claim-reference-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews assertion label, version, instance, schema, format, source and claim reference, and under which authority?", "kind": "constraint", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "assertion-label-version-instance-schema-format-source-and-claim-reference-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify assertion label, version, instance, schema, format, source and claim reference?", "kind": "security", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "assertion-label-version-instance-schema-format-source-and-claim-reference-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to assertion label, version, instance, schema, format, source and claim reference?", "kind": "identity", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "assertion-label-version-instance-schema-format-source-and-claim-reference-data", "name": "Assertion label, version, instance, schema, format, source and claim reference data", "description": "Typed credential-scoped values and references required to answer the governed questions for assertion label, version, instance, schema, format, source and claim reference.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-017", "SRC-025" ] } ], "artifacts": [ { "id": "assertion-label-version-instance-schema-format-source-and-claim-reference-artifact", "name": "Assertion label, version, instance, schema, format, source and claim reference evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting assertion label, version, instance, schema, format, source and claim reference.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-017", "SRC-025" ] } ], "inline_only_rationale": null }, { "id": "asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence", "name": "Asserted, gathered or attested metadata, digital source type, confidence and evidence", "description": "Records asserted, gathered or attested metadata, digital source type, confidence and evidence as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-017", "SRC-025" ], "questions": [ { "id": "asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish asserted, gathered or attested metadata, digital source type, confidence and evidence?", "kind": "provenance", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews asserted, gathered or attested metadata, digital source type, confidence and evidence, and under which authority?", "kind": "process", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify asserted, gathered or attested metadata, digital source type, confidence and evidence?", "kind": "privacy", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to asserted, gathered or attested metadata, digital source type, confidence and evidence?", "kind": "classification", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-data", "name": "Asserted, gathered or attested metadata, digital source type, confidence and evidence data", "description": "Typed credential-scoped values and references required to answer the governed questions for asserted, gathered or attested metadata, digital source type, confidence and evidence.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-017", "SRC-025" ] } ], "artifacts": [ { "id": "asserted-gathered-attested-metadata-digital-source-type-confidence-and-evidence-artifact", "name": "Asserted, gathered or attested metadata, digital source type, confidence and evidence evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting asserted, gathered or attested metadata, digital source type, confidence and evidence.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-017", "SRC-025" ] } ], "inline_only_rationale": null } ] }, { "id": "actions-ingredients-and-derivation-chain", "name": "Actions, ingredients and derivation chain", "description": "Groups Resource Consumption context for actions, ingredients and derivation chain without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-007", "SRC-009", "SRC-017", "SRC-018", "SRC-025", "SRC-026" ], "findings": [ { "id": "capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters", "name": "Capture, create, edit, generate, transform or publish action, actor, tool, time and parameters", "description": "Records capture, create, edit, generate, transform or publish action, actor, tool, time and parameters as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-007", "SRC-009", "SRC-017", "SRC-018", "SRC-025", "SRC-026" ], "questions": [ { "id": "capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish capture, create, edit, generate, transform or publish action, actor, tool, time and parameters?", "kind": "event", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews capture, create, edit, generate, transform or publish action, actor, tool, time and parameters, and under which authority?", "kind": "event", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify capture, create, edit, generate, transform or publish action, actor, tool, time and parameters?", "kind": "retention", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to capture, create, edit, generate, transform or publish action, actor, tool, time and parameters?", "kind": "composition", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-data", "name": "Capture, create, edit, generate, transform or publish action, actor, tool, time and parameters data", "description": "Typed credential-scoped values and references required to answer the governed questions for capture, create, edit, generate, transform or publish action, actor, tool, time and parameters.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-009", "SRC-017", "SRC-018", "SRC-025", "SRC-026" ] } ], "artifacts": [ { "id": "capture-create-edit-generate-transform-publish-action-actor-tool-time-and-parameters-artifact", "name": "Capture, create, edit, generate, transform or publish action, actor, tool, time and parameters evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting capture, create, edit, generate, transform or publish action, actor, tool, time and parameters.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-007", "SRC-009", "SRC-017", "SRC-018", "SRC-025", "SRC-026" ] } ], "inline_only_rationale": null }, { "id": "ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain", "name": "Ingredient, parent, derived, composed, rendition relationship, redaction and chain", "description": "Records ingredient, parent, derived, composed, rendition relationship, redaction and chain as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-007", "SRC-009", "SRC-017", "SRC-018", "SRC-025", "SRC-026" ], "questions": [ { "id": "ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish ingredient, parent, derived, composed, rendition relationship, redaction and chain?", "kind": "lifecycle", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews ingredient, parent, derived, composed, rendition relationship, redaction and chain, and under which authority?", "kind": "measurement", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify ingredient, parent, derived, composed, rendition relationship, redaction and chain?", "kind": "access", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to ingredient, parent, derived, composed, rendition relationship, redaction and chain?", "kind": "relationship", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-data", "name": "Ingredient, parent, derived, composed, rendition relationship, redaction and chain data", "description": "Typed credential-scoped values and references required to answer the governed questions for ingredient, parent, derived, composed, rendition relationship, redaction and chain.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-009", "SRC-017", "SRC-018", "SRC-025", "SRC-026" ] } ], "artifacts": [ { "id": "ingredient-parent-derived-composed-rendition-relationship-redaction-and-chain-artifact", "name": "Ingredient, parent, derived, composed, rendition relationship, redaction and chain evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting ingredient, parent, derived, composed, rendition relationship, redaction and chain.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-007", "SRC-009", "SRC-017", "SRC-018", "SRC-025", "SRC-026" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "signer-cryptography-time-and-credential-status", "name": "Signer, cryptography, time and credential status", "description": "Groups the governed Resource Consumption concern for signer, cryptography, time and credential status.", "rationale": "Preserve who controlled the signing key, what bytes were protected and when validation evidence applied.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020", "SRC-007", "SRC-011", "SRC-016", "SRC-021", "SRC-024" ], "layers": [ { "id": "signer-controller-key-and-signature", "name": "Signer, controller, key and signature", "description": "Groups Resource Consumption context for signer, controller, key and signature without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020" ], "findings": [ { "id": "signer-claim-generator-identity-provider-certificate-chain-policy-and-eku", "name": "Signer, claim generator, identity provider, certificate chain, policy and extended key usage", "description": "Records signer, claim generator, identity provider, certificate chain, policy and extended key usage as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020" ], "questions": [ { "id": "signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish signer, claim generator, identity provider, certificate chain, policy and extended key usage?", "kind": "authority", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews signer, claim generator, identity provider, certificate chain, policy and extended key usage, and under which authority?", "kind": "evidence", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify signer, claim generator, identity provider, certificate chain, policy and extended key usage?", "kind": "exception", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to signer, claim generator, identity provider, certificate chain, policy and extended key usage?", "kind": "state", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-data", "name": "Signer, claim generator, identity provider, certificate chain, policy and extended key usage data", "description": "Typed credential-scoped values and references required to answer the governed questions for signer, claim generator, identity provider, certificate chain, policy and extended key usage.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020" ] } ], "artifacts": [ { "id": "signer-claim-generator-identity-provider-certificate-chain-policy-and-eku-artifact", "name": "Signer, claim generator, identity provider, certificate chain, policy and extended key usage evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting signer, claim generator, identity provider, certificate chain, policy and extended key usage.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020" ] } ], "inline_only_rationale": null }, { "id": "signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest", "name": "Signature suite, algorithm, key ID, protected payload, canonicalization and digest", "description": "Records signature suite, algorithm, key id, protected payload, canonicalization and digest as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020" ], "questions": [ { "id": "signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish signature suite, algorithm, key id, protected payload, canonicalization and digest?", "kind": "security", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews signature suite, algorithm, key id, protected payload, canonicalization and digest, and under which authority?", "kind": "quality", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify signature suite, algorithm, key id, protected payload, canonicalization and digest?", "kind": "interoperability", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to signature suite, algorithm, key id, protected payload, canonicalization and digest?", "kind": "lifecycle", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-data", "name": "Signature suite, algorithm, key ID, protected payload, canonicalization and digest data", "description": "Typed credential-scoped values and references required to answer the governed questions for signature suite, algorithm, key id, protected payload, canonicalization and digest.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020" ] } ], "artifacts": [ { "id": "signature-suite-algorithm-key-id-protected-payload-canonicalization-and-digest-artifact", "name": "Signature suite, algorithm, key ID, protected payload, canonicalization and digest evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting signature suite, algorithm, key id, protected payload, canonicalization and digest.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020" ] } ], "inline_only_rationale": null } ] }, { "id": "trusted-time-status-and-algorithm-lifecycle", "name": "Trusted time, status and algorithm lifecycle", "description": "Groups Resource Consumption context for trusted time, status and algorithm lifecycle without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-007", "SRC-011", "SRC-016", "SRC-020", "SRC-021", "SRC-024" ], "findings": [ { "id": "claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks", "name": "Claimed signing time, trusted timestamp, validation, ingestion and observation clocks", "description": "Records claimed signing time, trusted timestamp, validation, ingestion and observation clocks as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-007", "SRC-011", "SRC-016", "SRC-020", "SRC-021", "SRC-024" ], "questions": [ { "id": "claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish claimed signing time, trusted timestamp, validation, ingestion and observation clocks?", "kind": "temporal", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews claimed signing time, trusted timestamp, validation, ingestion and observation clocks, and under which authority?", "kind": "validation", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify claimed signing time, trusted timestamp, validation, ingestion and observation clocks?", "kind": "decision", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to claimed signing time, trusted timestamp, validation, ingestion and observation clocks?", "kind": "temporal", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-data", "name": "Claimed signing time, trusted timestamp, validation, ingestion and observation clocks data", "description": "Typed credential-scoped values and references required to answer the governed questions for claimed signing time, trusted timestamp, validation, ingestion and observation clocks.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-011", "SRC-016", "SRC-020", "SRC-021", "SRC-024" ] } ], "artifacts": [ { "id": "claimed-signing-time-trusted-timestamp-validation-ingestion-and-observation-clocks-artifact", "name": "Claimed signing time, trusted timestamp, validation, ingestion and observation clocks evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting claimed signing time, trusted timestamp, validation, ingestion and observation clocks.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-007", "SRC-011", "SRC-016", "SRC-020", "SRC-021", "SRC-024" ] } ], "inline_only_rationale": null }, { "id": "certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility", "name": "Certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility", "description": "Records certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-007", "SRC-011", "SRC-016", "SRC-020", "SRC-021", "SRC-024" ], "questions": [ { "id": "certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility?", "kind": "lifecycle", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility, and under which authority?", "kind": "security", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility?", "kind": "identity", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility?", "kind": "spatial", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-data", "name": "Certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility data", "description": "Typed credential-scoped values and references required to answer the governed questions for certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-011", "SRC-016", "SRC-020", "SRC-021", "SRC-024" ] } ], "artifacts": [ { "id": "certificate-validity-revocation-suspension-refresh-trust-at-signing-and-algorithm-agility-artifact", "name": "Certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-007", "SRC-011", "SRC-016", "SRC-020", "SRC-021", "SRC-024" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "storage-discovery-versioning-and-preservation", "name": "Storage, discovery, versioning and preservation", "description": "Groups the governed Resource Consumption concern for storage, discovery, versioning and preservation.", "rationale": "Keep embedded, external and recovered credentials resolvable across edits, metadata loss and cryptographic change.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011", "SRC-022", "SRC-007", "SRC-016", "SRC-017", "SRC-020", "SRC-021" ], "layers": [ { "id": "manifest-store-location-and-durable-discovery", "name": "Manifest store location and durable discovery", "description": "Groups Resource Consumption context for manifest store location and durable discovery without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011", "SRC-022" ], "findings": [ { "id": "embedded-external-cloud-repository-location-active-selection-and-receipt", "name": "Embedded, external, cloud or repository location, active selection and receipt", "description": "Records embedded, external, cloud or repository location, active selection and receipt as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011", "SRC-022" ], "questions": [ { "id": "embedded-external-cloud-repository-location-active-selection-and-receipt-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish embedded, external, cloud or repository location, active selection and receipt?", "kind": "access", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "embedded-external-cloud-repository-location-active-selection-and-receipt-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews embedded, external, cloud or repository location, active selection and receipt, and under which authority?", "kind": "privacy", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "embedded-external-cloud-repository-location-active-selection-and-receipt-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify embedded, external, cloud or repository location, active selection and receipt?", "kind": "classification", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "embedded-external-cloud-repository-location-active-selection-and-receipt-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to embedded, external, cloud or repository location, active selection and receipt?", "kind": "provenance", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "embedded-external-cloud-repository-location-active-selection-and-receipt-data", "name": "Embedded, external, cloud or repository location, active selection and receipt data", "description": "Typed credential-scoped values and references required to answer the governed questions for embedded, external, cloud or repository location, active selection and receipt.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011", "SRC-022" ] } ], "artifacts": [ { "id": "embedded-external-cloud-repository-location-active-selection-and-receipt-artifact", "name": "Embedded, external, cloud or repository location, active selection and receipt evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting embedded, external, cloud or repository location, active selection and receipt.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011", "SRC-022" ] } ], "inline_only_rationale": null }, { "id": "soft-binding-query-repository-response-candidate-confidence-collision-and-recovery", "name": "Soft-binding query, repository response, candidate confidence, collision and recovery", "description": "Records soft-binding query, repository response, candidate confidence, collision and recovery as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011", "SRC-022" ], "questions": [ { "id": "soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish soft-binding query, repository response, candidate confidence, collision and recovery?", "kind": "process", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews soft-binding query, repository response, candidate confidence, collision and recovery, and under which authority?", "kind": "retention", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify soft-binding query, repository response, candidate confidence, collision and recovery?", "kind": "composition", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to soft-binding query, repository response, candidate confidence, collision and recovery?", "kind": "ownership", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-data", "name": "Soft-binding query, repository response, candidate confidence, collision and recovery data", "description": "Typed credential-scoped values and references required to answer the governed questions for soft-binding query, repository response, candidate confidence, collision and recovery.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011", "SRC-022" ] } ], "artifacts": [ { "id": "soft-binding-query-repository-response-candidate-confidence-collision-and-recovery-artifact", "name": "Soft-binding query, repository response, candidate confidence, collision and recovery evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting soft-binding query, repository response, candidate confidence, collision and recovery.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011", "SRC-022" ] } ], "inline_only_rationale": null } ] }, { "id": "manifest-lifecycle-preservation-and-failure", "name": "Manifest lifecycle, preservation and failure", "description": "Groups Resource Consumption context for manifest lifecycle, preservation and failure without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-016", "SRC-017", "SRC-020", "SRC-021", "SRC-022" ], "findings": [ { "id": "standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate", "name": "Standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate", "description": "Records standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-016", "SRC-017", "SRC-020", "SRC-021", "SRC-022" ], "questions": [ { "id": "standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate?", "kind": "lifecycle", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate, and under which authority?", "kind": "access", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate?", "kind": "relationship", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate?", "kind": "authority", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-data", "name": "Standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate data", "description": "Typed credential-scoped values and references required to answer the governed questions for standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-016", "SRC-017", "SRC-020", "SRC-021", "SRC-022" ] } ], "artifacts": [ { "id": "standard-update-attestation-manifest-predecessor-successor-active-orphan-and-duplicate-artifact", "name": "Standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-016", "SRC-017", "SRC-020", "SRC-021", "SRC-022" ] } ], "inline_only_rationale": null }, { "id": "removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state", "name": "Removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state", "description": "Records removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-016", "SRC-017", "SRC-020", "SRC-021", "SRC-022" ], "questions": [ { "id": "removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state?", "kind": "state", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state, and under which authority?", "kind": "exception", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state?", "kind": "state", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state?", "kind": "requirement", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-data", "name": "Removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state data", "description": "Typed credential-scoped values and references required to answer the governed questions for removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-016", "SRC-017", "SRC-020", "SRC-021", "SRC-022" ] } ], "artifacts": [ { "id": "removed-corrupt-unbound-redacted-revoked-expired-archived-tombstoned-and-revalidation-state-artifact", "name": "Removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-016", "SRC-017", "SRC-020", "SRC-021", "SRC-022" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "validation-trust-decision-and-human-interpretation", "name": "Validation, trust decision and human interpretation", "description": "Groups the governed Resource Consumption concern for validation, trust decision and human interpretation.", "rationale": "Return reproducible component evidence and communicate limits without converting technical validity into truth.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016", "SRC-019", "SRC-020", "SRC-021", "SRC-006", "SRC-008", "SRC-010", "SRC-026" ], "layers": [ { "id": "validation-result-and-trust-policy", "name": "Validation result and trust policy", "description": "Groups Resource Consumption context for validation result and trust policy without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016", "SRC-019", "SRC-020", "SRC-021" ], "findings": [ { "id": "well-formed-valid-component-status-code-failure-evidence-validator-and-profile", "name": "Well-formed or valid component, status code, failure evidence, validator and profile", "description": "Records well-formed or valid component, status code, failure evidence, validator and profile as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016", "SRC-019", "SRC-020", "SRC-021" ], "questions": [ { "id": "well-formed-valid-component-status-code-failure-evidence-validator-and-profile-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish well-formed or valid component, status code, failure evidence, validator and profile?", "kind": "validation", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "well-formed-valid-component-status-code-failure-evidence-validator-and-profile-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews well-formed or valid component, status code, failure evidence, validator and profile, and under which authority?", "kind": "interoperability", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "well-formed-valid-component-status-code-failure-evidence-validator-and-profile-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify well-formed or valid component, status code, failure evidence, validator and profile?", "kind": "lifecycle", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "well-formed-valid-component-status-code-failure-evidence-validator-and-profile-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to well-formed or valid component, status code, failure evidence, validator and profile?", "kind": "constraint", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "well-formed-valid-component-status-code-failure-evidence-validator-and-profile-data", "name": "Well-formed or valid component, status code, failure evidence, validator and profile data", "description": "Typed credential-scoped values and references required to answer the governed questions for well-formed or valid component, status code, failure evidence, validator and profile.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016", "SRC-019", "SRC-020", "SRC-021" ] } ], "artifacts": [ { "id": "well-formed-valid-component-status-code-failure-evidence-validator-and-profile-artifact", "name": "Well-formed or valid component, status code, failure evidence, validator and profile evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting well-formed or valid component, status code, failure evidence, validator and profile.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016", "SRC-019", "SRC-020", "SRC-021" ] } ], "inline_only_rationale": null }, { "id": "trust-list-anchor-private-store-policy-purpose-context-decision-and-review", "name": "Trust list, anchor, private store, policy, purpose, context, decision and review", "description": "Records trust list, anchor, private store, policy, purpose, context, decision and review as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016", "SRC-019", "SRC-020", "SRC-021" ], "questions": [ { "id": "trust-list-anchor-private-store-policy-purpose-context-decision-and-review-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish trust list, anchor, private store, policy, purpose, context, decision and review?", "kind": "decision", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "trust-list-anchor-private-store-policy-purpose-context-decision-and-review-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews trust list, anchor, private store, policy, purpose, context, decision and review, and under which authority?", "kind": "decision", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "trust-list-anchor-private-store-policy-purpose-context-decision-and-review-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify trust list, anchor, private store, policy, purpose, context, decision and review?", "kind": "temporal", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "trust-list-anchor-private-store-policy-purpose-context-decision-and-review-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to trust list, anchor, private store, policy, purpose, context, decision and review?", "kind": "process", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "trust-list-anchor-private-store-policy-purpose-context-decision-and-review-data", "name": "Trust list, anchor, private store, policy, purpose, context, decision and review data", "description": "Typed credential-scoped values and references required to answer the governed questions for trust list, anchor, private store, policy, purpose, context, decision and review.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016", "SRC-019", "SRC-020", "SRC-021" ] } ], "artifacts": [ { "id": "trust-list-anchor-private-store-policy-purpose-context-decision-and-review-artifact", "name": "Trust list, anchor, private store, policy, purpose, context, decision and review evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting trust list, anchor, private store, policy, purpose, context, decision and review.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-016", "SRC-019", "SRC-020", "SRC-021" ] } ], "inline_only_rationale": null } ] }, { "id": "meaning-disclosure-and-accessible-explanation", "name": "Meaning, disclosure and accessible explanation", "description": "Groups Resource Consumption context for meaning, disclosure and accessible explanation without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010", "SRC-012", "SRC-026" ], "findings": [ { "id": "integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction", "name": "Integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction", "description": "Records integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010", "SRC-012", "SRC-026" ], "questions": [ { "id": "integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction?", "kind": "classification", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction, and under which authority?", "kind": "identity", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction?", "kind": "spatial", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction?", "kind": "event", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-data", "name": "Integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction data", "description": "Typed credential-scoped values and references required to answer the governed questions for integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010", "SRC-012", "SRC-026" ] } ], "artifacts": [ { "id": "integrity-provenance-authenticity-identity-authorship-copyright-truth-and-endorsement-distinction-artifact", "name": "Integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010", "SRC-012", "SRC-026" ] } ], "inline_only_rationale": null }, { "id": "indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal", "name": "Indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal", "description": "Records indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010", "SRC-012", "SRC-026" ], "questions": [ { "id": "indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal?", "kind": "quality", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal, and under which authority?", "kind": "classification", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal?", "kind": "provenance", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal?", "kind": "measurement", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-data", "name": "Indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal data", "description": "Typed credential-scoped values and references required to answer the governed questions for indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010", "SRC-012", "SRC-026" ] } ], "artifacts": [ { "id": "indicator-disclosure-level-summary-detail-accessibility-localization-warning-and-appeal-artifact", "name": "Indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010", "SRC-012", "SRC-026" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "privacy-governance-and-interoperability", "name": "Privacy, governance and interoperability", "description": "Groups the governed Resource Consumption concern for privacy, governance and interoperability.", "rationale": "Control disclosure and extension while preserving verifiable meaning across standards and jurisdictions.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-016", "SRC-026", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-011", "SRC-013", "SRC-014", "SRC-015", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025" ], "layers": [ { "id": "privacy-safety-harms-and-access-control", "name": "Privacy, safety, harms and access control", "description": "Groups Resource Consumption context for privacy, safety, harms and access control without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-016", "SRC-026" ], "findings": [ { "id": "consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data", "name": "Consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data", "description": "Records consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-016", "SRC-026" ], "questions": [ { "id": "consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data?", "kind": "privacy", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data, and under which authority?", "kind": "composition", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data?", "kind": "ownership", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data?", "kind": "evidence", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-data", "name": "Consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data data", "description": "Typed credential-scoped values and references required to answer the governed questions for consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-016", "SRC-026" ] } ], "artifacts": [ { "id": "consent-data-minimization-selective-disclosure-redaction-sensitive-identity-location-and-device-data-artifact", "name": "Consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-016", "SRC-026" ] } ], "inline_only_rationale": null }, { "id": "surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy", "name": "Surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy", "description": "Records surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-016", "SRC-026" ], "questions": [ { "id": "surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy?", "kind": "exception", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy, and under which authority?", "kind": "relationship", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy?", "kind": "authority", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy?", "kind": "quality", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-data", "name": "Surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy data", "description": "Typed credential-scoped values and references required to answer the governed questions for surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-016", "SRC-026" ] } ], "artifacts": [ { "id": "surveillance-coercion-exclusion-spoofing-removal-reidentification-harm-review-and-remedy-artifact", "name": "Surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-016", "SRC-026" ] } ], "inline_only_rationale": null } ] }, { "id": "profiles-crosswalk-conformance-and-semantic-loss", "name": "Profiles, crosswalk, conformance and semantic loss", "description": "Groups Resource Consumption context for profiles, crosswalk, conformance and semantic loss without importing neighboring master lifecycles.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ], "findings": [ { "id": "c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk", "name": "C2PA, VC, Data Integrity, JOSE, COSE, X.509, PROV, Annotation and IPTC crosswalk", "description": "Records c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ], "questions": [ { "id": "c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk?", "kind": "interoperability", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk, and under which authority?", "kind": "state", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk?", "kind": "requirement", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk?", "kind": "validation", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-data", "name": "C2PA, VC, Data Integrity, JOSE, COSE, X.509, PROV, Annotation and IPTC crosswalk data", "description": "Typed credential-scoped values and references required to answer the governed questions for c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ] } ], "artifacts": [ { "id": "c2pa-vc-data-integrity-jose-cose-x509-prov-annotation-iptc-crosswalk-artifact", "name": "C2PA, VC, Data Integrity, JOSE, COSE, X.509, PROV, Annotation and IPTC crosswalk evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ] } ], "inline_only_rationale": null }, { "id": "profile-version-license-conformance-transformation-round-trip-and-semantic-loss", "name": "Profile, version, license, conformance, transformation, round trip and semantic loss", "description": "Records profile, version, license, conformance, transformation, round trip and semantic loss as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ], "questions": [ { "id": "profile-version-license-conformance-transformation-round-trip-and-semantic-loss-q01", "text": "Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish profile, version, license, conformance, transformation, round trip and semantic loss?", "kind": "requirement", "answer_data": [ "credential, manifest, claim, assertion, asset, rendition and region identifiers", "version, profile, schema, binding method, algorithm, scope and explicit unknowns", "subject, issuer, signer, holder, validator, source system and external-master references" ] }, { "id": "profile-version-license-conformance-transformation-round-trip-and-semantic-loss-q02", "text": "Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews profile, version, license, conformance, transformation, round trip and semantic loss, and under which authority?", "kind": "lifecycle", "answer_data": [ "issuer, signer, claim generator, identity provider, TSA, repository, validator, verifier and reviewer roles", "key control, certificate, trust anchor, policy, consent, purpose, access and review authority", "source, profile, jurisdiction, audience, recipient and accountable decision references" ] }, { "id": "profile-version-license-conformance-transformation-round-trip-and-semantic-loss-q03", "text": "Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify profile, version, license, conformance, transformation, round trip and semantic loss?", "kind": "constraint", "answer_data": [ "capture, create, edit, generate, transform, publish, redact, revoke and recover events", "ingredient, predecessor, successor, derivation, active manifest, signature, timestamp and status evidence", "validation codes, conflicts, uncertainty, limitations, harms, corrections and revalidation triggers" ] }, { "id": "profile-version-license-conformance-transformation-round-trip-and-semantic-loss-q04", "text": "Which security, privacy, retention, disclosure and interoperability checks apply to profile, version, license, conformance, transformation, round trip and semantic loss?", "kind": "security", "answer_data": [ "signature, digest, content binding, certificate path, revocation, timestamp and component validation", "minimization, consent, selective disclosure, redaction, access, retention, appeal and audit controls", "source and target versions, crosswalk, conformance, transformation, round-trip and semantic-loss report" ] } ], "data_elements": [ { "id": "profile-version-license-conformance-transformation-round-trip-and-semantic-loss-data", "name": "Profile, version, license, conformance, transformation, round trip and semantic loss data", "description": "Typed credential-scoped values and references required to answer the governed questions for profile, version, license, conformance, transformation, round trip and semantic loss.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ] } ], "artifacts": [ { "id": "profile-version-license-conformance-transformation-round-trip-and-semantic-loss-artifact", "name": "Profile, version, license, conformance, transformation, round trip and semantic loss evidence manifest", "description": "Digest-addressed manifest of credential identity, bindings, assertions, actors, clocks, cryptographic evidence, validation, policy, lifecycle and projection outcomes supporting profile, version, license, conformance, transformation, round trip and semantic loss.", "media_or_form": [ "application/c2pa", "application/json", "application/ld+json", "application/cbor", "application/yaml", "text/markdown", "external reference" ], "serial": true, "identity_strategy": "Authoritative credential or manifest identifier first, then issuer-qualified globally resolvable IRI, otherwise Dimension UUID or ULID; bind the target asset or region, immutable revision, proof profile and artifact digest separately.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-provenance-credential", "name": "Register provenance credential", "description": "Create one stable credential identity, subject scope and master authority without claiming media identity or truth.", "inputs": [ "credential proposal", "asset or subject reference", "issuer authority" ], "outputs": [ "credential identifier", "initial revision" ], "preconditions": [ "active Dimension", "identity boundary explicit" ], "effects": [ "identity, profile and unknowns are appended" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-012" ] }, { "id": "compose-credential-assertions", "name": "Compose credential assertions", "description": "Add typed assertions and claim references with explicit source, schema, instance, scope and evidence.", "inputs": [ "credential revision", "assertion payloads", "source metadata" ], "outputs": [ "versioned assertion set" ], "preconditions": [ "issuer and schema resolvable" ], "effects": [ "prior assertions remain immutable" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-012" ] }, { "id": "bind-credential-to-content", "name": "Bind credential to content", "description": "Create hard or soft bindings to an exact asset, rendition, segment or region.", "inputs": [ "credential", "target asset", "binding profile" ], "outputs": [ "qualified content binding" ], "preconditions": [ "target and algorithm explicit" ], "effects": [ "binding never replaces asset identity" ], "source_refs": [ "SRC-001", "SRC-004", "SRC-018", "SRC-022" ] }, { "id": "record-action-and-ingredient-lineage", "name": "Record action and ingredient lineage", "description": "Append capture, edit, generation, transformation and ingredient relationships without importing their external lifecycles.", "inputs": [ "credential", "actions", "ingredient references" ], "outputs": [ "qualified provenance chain" ], "preconditions": [ "actors, tools, times and inputs source-qualified" ], "effects": [ "derivation graph and redactions remain auditable" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-009", "SRC-017" ] }, { "id": "issue-and-sign-credential", "name": "Issue and sign credential", "description": "Protect a canonical claim with an authorized signing key and an explicitly pinned proof profile.", "inputs": [ "claim", "signing authority", "proof profile" ], "outputs": [ "signed credential", "signature evidence" ], "preconditions": [ "key control, certificate policy and algorithm acceptable" ], "effects": [ "unsigned claim and signature remain distinguishable" ], "source_refs": [ "SRC-001", "SRC-013", "SRC-014", "SRC-015", "SRC-019", "SRC-020" ] }, { "id": "timestamp-and-publish-status", "name": "Timestamp and publish status", "description": "Attach trusted-time evidence and publish applicable revocation, suspension or refresh information.", "inputs": [ "signed credential", "TSA or status authority", "policy" ], "outputs": [ "timestamp token", "status reference" ], "preconditions": [ "trust path and clocks explicit" ], "effects": [ "claimed time, trusted time and observation time stay distinct" ], "source_refs": [ "SRC-001", "SRC-011", "SRC-016", "SRC-021", "SRC-024" ] }, { "id": "store-embed-or-externalize", "name": "Store, embed or externalize credential", "description": "Place a manifest store in or outside an asset while preserving resolvability, receipts and integrity.", "inputs": [ "credential", "asset", "storage profile" ], "outputs": [ "embedded or external binding", "repository receipt" ], "preconditions": [ "location and retrieval policy valid" ], "effects": [ "storage location never becomes credential identity" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "recover-durable-credential", "name": "Recover durable credential", "description": "Use fingerprint or watermark evidence to query repositories and return ranked credential candidates.", "inputs": [ "asset observation", "soft binding", "repository endpoint" ], "outputs": [ "candidate set", "recovery evidence" ], "preconditions": [ "privacy and collision policy applied" ], "effects": [ "recovered candidate requires normal validation" ], "source_refs": [ "SRC-004", "SRC-007", "SRC-008" ] }, { "id": "validate-credential", "name": "Validate credential", "description": "Validate structure, claim, signature, time, status, assertions, ingredients and asset binding as separate components.", "inputs": [ "credential", "asset", "validation profile" ], "outputs": [ "component results", "validation report" ], "preconditions": [ "profile, algorithms and trust configuration pinned" ], "effects": [ "all failures and informational statuses remain attributable" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-011", "SRC-013", "SRC-019", "SRC-020" ] }, { "id": "evaluate-trust-and-disclose", "name": "Evaluate trust and disclose", "description": "Apply verifier purpose and trust policy, then present accessible provenance without implying factual truth.", "inputs": [ "validation report", "trust policy", "audience context" ], "outputs": [ "trust decision", "disclosure view" ], "preconditions": [ "decision scope and limitations explicit" ], "effects": [ "technical validity and human judgment remain separate" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-008", "SRC-012" ] }, { "id": "revise-redact-revoke-or-tombstone", "name": "Revise, redact, revoke or tombstone", "description": "Append an authorized lifecycle change while preserving prior credential and validation history.", "inputs": [ "credential revision", "change or status event", "authority" ], "outputs": [ "successor or status assertion", "notice" ], "preconditions": [ "retention and legal hold checked" ], "effects": [ "last-write-wins and silent deletion are rejected" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-016", "SRC-017" ] }, { "id": "validate-and-project-crosswalk", "name": "Validate and project crosswalk", "description": "Produce version-pinned C2PA, VC, PROV, IPTC or generic projections with explicit semantic loss.", "inputs": [ "credential revision", "target profile", "mapping" ], "outputs": [ "target projection", "validation and loss report" ], "preconditions": [ "source and target releases pinned" ], "effects": [ "canonical credential remains unchanged" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ] } ], "composition": [ { "target": "WM-MED-002 Media Asset / Rendition", "relation": "MIX-IN", "purpose": "Bind credentials to exact media assets, renditions, segments or regions while the media model retains identity and technical mastership.", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-022" ] }, { "target": "WM-MED-001 Creative Work / Content", "relation": "REFERENCE", "purpose": "Resolve intellectual work context without using provenance as proof of authorship, ownership or truth.", "required": false, "source_refs": [ "SRC-001", "SRC-012", "SRC-017" ] }, { "target": "Party, identity, device, software, key, certificate, action, repository, rights, evidence and decision masters", "relation": "REFERENCE", "purpose": "Resolve actors, mechanisms, events, custody, legal context and accountable decisions without importing their lifecycles.", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-010", "SRC-015", "SRC-017", "SRC-020" ] }, { "target": "C2PA 2.4 Content Credentials, crJSON, Attestations and Soft Binding API", "relation": "ALIGN", "purpose": "Project the principal content-provenance ecosystem while preserving format independence and exposing version-specific semantics.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] }, { "target": "C2PA implementation, UX, security, harms, AI/ML, identity and conformance guidance", "relation": "ALIGN", "purpose": "Project implementation and governance controls separately from normative credential structure.", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011" ] }, { "target": "W3C Verifiable Credentials 2.0, Data Integrity, VC JOSE/COSE, Controlled Identifiers and Bitstring Status", "relation": "ALIGN", "purpose": "Project generic credential, proof, controller and status semantics with explicit non-equivalence to C2PA roles.", "required": false, "source_refs": [ "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016" ] }, { "target": "PROV-O and Web Annotation", "relation": "ALIGN", "purpose": "Project derivation, activity, agent and region-scoped assertion graphs.", "required": false, "source_refs": [ "SRC-017", "SRC-018" ] }, { "target": "COSE, X.509 PKIX and Time-Stamp Protocol", "relation": "ALIGN", "purpose": "Project protected envelopes, certificate paths, revocation and trusted-time evidence without making one proof suite canonical.", "required": false, "source_refs": [ "SRC-019", "SRC-020", "SRC-021" ] }, { "target": "HTTP Digest Fields, JSON Canonicalization and RFC 3339", "relation": "ALIGN", "purpose": "Project digest, deterministic representation and unambiguous clock rules where adopted profiles require them.", "required": false, "source_refs": [ "SRC-022", "SRC-023", "SRC-024" ] }, { "target": "IPTC Photo Metadata and NIST Generative AI Profile", "relation": "ALIGN", "purpose": "Project digital-source vocabulary and complementary AI transparency and risk-control context.", "required": false, "source_refs": [ "SRC-025", "SRC-026" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Declare the Dimension owner, credential master, issuer authority, signer and key custodian, identity provider, TSA, repository operator, validator, trust-policy owner, privacy steward and independent reviewer.", "Register credential, manifest, assertion, action, ingredient, binding, signature, certificate, timestamp, status, validation and lifecycle vocabularies.", "Register media assets, creative works, parties, devices, software, keys, certificates, events, repositories, rights instruments, evidence and trust decisions separately.", "Pin C2PA, VC, cryptographic, identity, status, provenance, media-metadata, privacy, retention and jurisdictional profiles." ], "namespace_guidance": "Mint only Dimension-owned credential, manifest, assertion, binding, validation, disclosure and lifecycle identifiers locally; preserve asset, work, party, device, tool, key, certificate, event, repository, rights, evidence and decision identifiers as typed external references.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local credential, asset, assertion, identity, key, trust, status, validation, access, retention and provenance registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize by registry ID, model version, authoritative credential identifier, immutable revision, issuer, subject scope and proof profile; never by filename, URL, title, signature bytes, hash or timestamp alone.", "Keep asset, rendition, credential, manifest store, manifest, claim, assertion, attestation, signature, certificate, trust policy, validation result, trust decision and display label distinct." ], "patch_rules": [ "Additive extensions declare target node, namespace, issuer authority, source, schema and standards versions, access scope, validation behavior and interoperability impact.", "Breaking credential identity, subject, issuer, binding, claim, proof, trust, status or lifecycle changes require an immutable successor, migration and crosswalk map, compatibility declaration and continued resolution of prior versions." ], "compatibility_rules": [ "Consumers may ignore unknown additive fields only when credential identity, subject binding, issuer, claim, proof, validation, status, provenance, privacy and access meaning remain intact.", "C2PA, VC, Data Integrity, JOSE, COSE, X.509, PROV, Annotation and IPTC mappings pin releases and declare transformed, inferred, omitted, unverifiable or non-round-trippable values." ] }, "artifact_rules": { "identity_priority": [ "Authoritative credential or manifest identifier issued by the declared credential master.", "Issuer-qualified globally resolvable IRI whose subject and revision semantics match the credential.", "Adopting-Dimension UUID or ULID when no authoritative external identifier exists." ], "timestamp_rule": "Record event timestamps in RFC 3339 with seconds and an explicit numeric offset or Z; keep asset creation, claim generation, claimed signing, trusted timestamp, publication, validation, observation, revocation, recovery and ingestion times distinct.", "serial_naming_rule": "Name serial artifacts as {credential-id}--{artifact-kind}--{revision-or-event-id}; never use a filename, asset title, URL, hash, signer name or date alone as identity.", "integrity_rule": "Store credential and target identifiers, immutable revision, media type, byte length, digest and scope, proof and canonicalization profiles, issuer, signer, clocks, certificate and status evidence, validation outcome, privacy and access marking, retention and semantic-loss declaration." }, "policies": [ "The adopting Dimension declares who may issue, assert, gather, sign, timestamp, store, recover, validate, trust, disclose, redact, revoke and tombstone credentials.", "Every usable credential requires stable identity, subject scope, issuer, claim or assertion set, content binding when applicable, proof profile, lifecycle, provenance and applicable privacy and access context.", "Agents never infer factual truth, authorship, copyright, ownership, editorial endorsement, safety or universal trust from a valid signature, trusted signer, watermark, label or provenance chain alone.", "Media assets, works, parties, devices, software, keys, certificates, events, repositories, rights instruments, evidence and accountable trust decisions remain external masters.", "Agents may perform reversible discovery, extraction, validation and projection under delegation; signing, identity attestation, trust-list mutation, protected disclosure, revocation and destructive deletion require accountable authority." ], "crud": { "read": [ "Resolve active Dimension, purpose, role, credential identity and revision, target asset and region, validation horizon, trust policy, freshness, sensitivity, retention and access policy; return the minimum necessary credential and disclosure projection." ], "create": [ "Create stable credential identity with master authority, subject scope, issuer, assertion sources, binding profile, proof policy, lifecycle, privacy context and explicit unknowns before signing or publication." ], "update": [ "Append an immutable assertion, action, ingredient, binding, signature, timestamp, status, validation, trust or redaction revision with actor, authority, source, reason, RFC 3339 effective time and predecessor." ], "delete": [ "Apply privacy, rights, dispute, audit, preservation, retention and legal-hold policy; tombstone eligible credential-owned records or remove authorized projections while preserving material identity, revocation, validation, provenance and non-cascading external references." ] }, "roles": [ { "name": "Dimension owner", "responsibilities": [ "Own namespace, mastership, delegation, access, retention and federation rules." ] }, { "name": "Credential steward", "responsibilities": [ "Own credential identity, scope, schema, lifecycle, revision and interoperability policy." ] }, { "name": "Issuer or assertion authority", "responsibilities": [ "Own the meaning, source and authority of credential claims and assertions." ] }, { "name": "Signer and key custodian", "responsibilities": [ "Control approved signing credentials, proof profiles, rotation and compromise response." ] }, { "name": "Identity or attestation provider", "responsibilities": [ "Own separately scoped signer, human or organizational identity evidence." ] }, { "name": "Timestamp or status authority", "responsibilities": [ "Own trusted-time, revocation, suspension and refresh evidence." ] }, { "name": "Repository and preservation custodian", "responsibilities": [ "Own durable storage, recovery, receipts, retention and revalidation triggers." ] }, { "name": "Validator or verifier", "responsibilities": [ "Run pinned validation and trust policy, preserving component evidence and limitations." ] }, { "name": "Privacy and harm reviewer", "responsibilities": [ "Own minimization, consent, redaction, disclosure, misuse and remedy controls." ] }, { "name": "Independent auditor", "responsibilities": [ "Review identity, binding, proof, trust, validation, lifecycle and access without rewriting originals." ] } ], "access": { "default_rule": "Deny sensitive provenance disclosure and mutation unless active Dimension, role, purpose, consent or lawful basis, recipient, policy, time, retention and field controls grant the action; expose the minimum necessary projection.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency safety, incident response or legally compelled access must be grounded, time-limited, purpose-bound, attributable, independently reviewed and unable to erase immutable credential identity, revocation, validation or legal-hold evidence." ], "audit_requirements": [ "Log actor, role, purpose, credential and target identity, action, decision, policy, trust and standards versions, RFC 3339 timestamp with offset, affected assertions or projections, recipient, source evidence and outcome for privileged signing, trust, disclosure, revocation or deletion." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read the nearest Dimension-owner AGENTS.md and credential, identity, key, trust, privacy, access, retention, incident and jurisdiction policies.", "Read this model AGENTS.md, pinned spec.yaml and required asset, work, party, device, software, key, certificate, event, repository, rights, evidence and decision instructions before mutation." ] } }, "coverage": { "claim": "Source-grounded reviewable draft covering Content Provenance Credential identity, subject binding, assertions, actions, ingredients, derivation, signer and key evidence, trusted time, status, storage, recovery, validation, trust disclosure, privacy, harms, lifecycle, artifact identity rules, and interoperability with C2PA, VC, PROV and IPTC profiles. Confidence is medium because sole active provider (Codex) and single-provider mode require visible waiver and independent follow-up review; no claim of universal completeness or regional jurisdiction applicability.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Credential, manifest store, manifest, claim, assertion, attestation, signature, asset and validation identities remain distinct." }, { "dimension": "classification and definition", "status": "covered", "notes": "Standard, update, attestation and durable credentials plus assertion, binding and digital-source types are explicit." }, { "dimension": "direct properties", "status": "covered", "notes": "Issuer, subject, schema, version, assertions, profile, binding, signature, time, status and lifecycle are covered." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Hard hashes, fingerprints, watermarks, repository discovery and validator observations retain method and confidence." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Register, assert, bind, record lineage, sign, timestamp, store, recover, validate, disclose, revise and project functions declare authority and effects." }, { "dimension": "lifecycle", "status": "covered", "notes": "Draft, issued, active, superseded, redacted, revoked, expired, unbound, corrupt, archived and tombstoned states preserve history." }, { "dimension": "relationships", "status": "covered", "notes": "Assets, renditions, regions, ingredients, actors, tools, signers, certificates, repositories, validators and decisions use typed references." }, { "dimension": "temporal", "status": "covered", "notes": "Creation, action, claim, signing, trusted timestamp, publication, validation, observation, revocation, recovery and ingestion clocks remain distinct." }, { "dimension": "spatial", "status": "covered", "notes": "Asset regions, capture locations, processing locations, repository regions and applicable jurisdictions are separately scoped." }, { "dimension": "provenance", "status": "covered", "notes": "Assertions, actions, ingredients, sources, actors, tools, derivations, redactions, validators and revisions form attributable lineage." }, { "dimension": "ownership", "status": "covered", "notes": "Issuer, signer, holder, creator, subject, copyright holder, asset owner and trust-policy owner are not conflated." }, { "dimension": "validation", "status": "covered", "notes": "Structure, claim, signature, time, status, assertion, ingredient and binding checks produce separate evidence and codes." }, { "dimension": "security and privacy", "status": "covered", "notes": "Algorithm agility, key compromise, spoofing, removal, correlation, surveillance, minimization, consent and redaction are represented." }, { "dimension": "access", "status": "covered", "notes": "Purpose, recipient, disclosure level, role, consent or lawful basis, minimum projection, appeal and audit are explicit." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Repository preservation, revocation history, revalidation, archival, tombstone, projection removal and legal hold are distinguished." }, { "dimension": "interoperability", "status": "covered", "notes": "C2PA, VC, Data Integrity, JOSE, COSE, X.509, PROV, Annotation, HTTP digest and IPTC mappings disclose loss." } ], "known_omissions": [ "Image, video, audio, document, live-stream, model, sensor, news, legal, health and jurisdiction-specific profiles require specialist review.", "Media assets, creative works, parties, identities, devices, software, keys, certificates, actions, repositories, rights, evidence and trust decisions remain neighboring masters.", "Decentralized transparency logs, anonymous credentials, zero-knowledge proofs, post-quantum migration, biometric identity and forensic truth assessment remain future profiles." ], "conflicts": [ "C2PA Content Credential, W3C Verifiable Credential and generic provenance record have different subject, holder, proof and lifecycle semantics; crosswalks are projections, not identity equivalence.", "A cryptographically valid credential can carry false, incomplete, misleading or privacy-invasive assertions; validity, signer trust, assertion truth and asset trustworthiness remain separate results.", "Hard binding proves exact byte or region association while soft binding supports probabilistic recovery; neither is universal asset identity or proof of authorship.", "Revocation and trusted timestamps can preserve historical validity decisions, but current trust lists, current certificate status and trust at signing time are not interchangeable." ], "regional_assumptions": [ "Identity, electronic-signature, evidentiary, copyright, privacy, biometric, consumer-protection, records and disclosure duties depend on jurisdiction and purpose.", "C2PA trust lists and conformance results are ecosystem-specific signals and do not create universal legal or factual trust.", "IPTC digital-source terms are media-industry vocabulary and must not be treated as complete technical descriptions of AI generation or editing." ], "adversarial_checks": [ "Reject a credential without stable identity, revision, issuer, subject scope, master authority, profile, provenance and lifecycle.", "Reject an asset, rendition, manifest store, manifest, claim, assertion, signature, certificate, validation result or display label represented as the credential itself without an explicit profile rule.", "Reject a content binding without exact target scope, algorithm, digest or soft-binding evidence, profile and validation status.", "Reject a valid signature or trusted certificate as proof of factual truth, authorship, copyright, editorial approval, safety or universal asset authenticity.", "Reject claimed signing time as trusted time, current certificate status as historical status or a trust-list match as a context-free trust decision.", "Reject a recovered soft-binding candidate that bypasses normal signature, assertion, ingredient and asset validation.", "Reject redaction, update, revocation, metadata removal or destructive deletion that silently erases prior public lineage, validation evidence or legal hold.", "Reject disclosure of identity, location, device, biometric or behavioral data without purpose, minimum necessity, authority, recipient, retention and remedy controls.", "Reject crosswalk output that omits source and target releases, transformation trace, cryptographic verification limits and semantic-loss declaration." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "A Content Provenance Credential is a composite root entity that owns credential identity, namespace, version, revision, manifest store, manifest, claim, assertion, signature, timestamp, status, lifecycle, and artifact binding scopes. It composes manifest, claim, assertion, action, ingredient, signer, certificate, validation, and disclosure components while correctly delegating asset, rendition, media, creative work, party, device, software, key, certificate, event, repository, rights instrument, evidence, and accountable trust-decision lifecycles to external masters. This composition pattern matches the aggregate schema kind: it owns aggregate identity and revision while respecting neighboring model boundaries." }, "decisions": [ { "concept": "Entry kind: aggregate vs. alternatives", "disposition": "accepted", "rationale": "Content Provenance Credential owns credential identity, manifest composition, assertion sets, proof profile, lifecycle and artifact bindings. It composes typed parts (manifest, claim, assertion, signature, timestamp, status, validation, disclosure) whose identities and revisions it controls. This is the definition of an aggregate: a root entity whose identity and revision are minted once and whose parts are always accessed through the aggregate root. Alternative schema kinds (entity, event, relationship, classifier) are each defensible but narrower; aggregate is most defensible for a composite root with owned lifecycle." }, { "concept": "Source authority: C2PA 2.4, W3C VC 2.0, RFC primary tier", "disposition": "accepted", "rationale": "All 26 sources are standards-body or RFC outputs with stable, version-pinned references. C2PA 2.4 (April 2026) and W3C VC 2.0 (May 2025) are authoritative current specifications for their domains. RFC 5280 (X.509), RFC 3161 (TSP), RFC 9052 (CBOR), RFC 8785 (JCS) and others are stable foundational standards. No secondary sources needed for foundational schemas. Authority tier 1 is justified; live registry access (SRC-011) requires deferral to runtime verification." }, { "concept": "Boundary integrity: credential vs. media, work, party, decision", "disposition": "accepted", "rationale": "The model properly treats credential identity, manifest store, manifest, claim, assertion, signature, binding, timestamp, status, validation, disclosure and lifecycle as in-scope. Media assets, creative works, parties, identities, devices, software, keys, certificates, actions, events, repositories, rights instruments, evidence and accountable trust decisions are correctly treated as external masters whose identities and lifecycles remain outside this model. This orthogonality prevents scope creep, identity confusion and conflation of different authorities. Neighbor boundaries (WM-MED-002 media, WM-MED-001 creative work) and external masters are properly documented." }, { "concept": "Forensic truth distinction: signature validity, assertion truth, signer trust, asset authenticity", "disposition": "accepted", "rationale": "The model explicitly separates four independent validation and trust axes: (1) cryptographic validity of the signature under the declared algorithm, (2) semantic validity of assertions within the credential payload, (3) trust in the signer's authority to make those claims, and (4) factual truth, authorship, copyright, ownership, editorial endorsement, legality or safety of the claimed subject matter. These remain distinct results; the model enforces this separation in validation, trust policy, and disclosure layers and prevents conflation. This is foundational and correctly implemented." }, { "concept": "Crosswalk projections: C2PA, VC, PROV, IPTC mappings", "disposition": "deferred", "rationale": "The model correctly identifies that C2PA Content Credential, W3C Verifiable Credential and generic PROV provenance have different subject, holder, issuer, proof, status and lifecycle semantics. It declares that mappings are version-pinned projections, not identity equivalence, and that each transformation incurs semantic loss. Specific field-level transformation rules, dropped or inferred values, round-trip reversibility tests and confidence bounds remain deferred to specialist profile work and live crosswalk validators. The principle is sound; implementation is deferred." }, { "concept": "Algorithm agility and migration policy for deprecated or compromised algorithms", "disposition": "deferred", "rationale": "The model prescribes algorithm agility and requires pinned proof profiles and signature suite specifications. However, specific versioned migration policies for deprecated, weakened, or compromised algorithms (e.g., SHA-1, RSA-1024, deprecated X.509 key types) are not provided. This policy work remains deferred to the Dimension owner, trust-list custodian, and validator policy frameworks. Must be operationalized before production use." }, { "concept": "Jurisdiction-specific disclosure, signature and evidence duties", "disposition": "deferred", "rationale": "The model acknowledges that identity attestation, electronic-signature validity, evidentiary admissibility, copyright, privacy, biometric and consumer-protection duties depend on jurisdiction and purpose context. It does not model jurisdiction as a first-class scope dimension or provide compliance profiles for major regulatory regions (EU, UK, US, China, etc.). This specialist work remains deferred but should be completed before any production deployment claiming legal or evidence value." }, { "concept": "Soft-binding recovery: confidence thresholds and collision resolution", "disposition": "deferred", "rationale": "The model specifies soft-binding query, repository response, candidate ranking and recovery as functions but does not provide confidence thresholds, false-positive bounds, collision resolution policies or audit trails for ambiguous recovery cases. When a soft-binding query returns multiple candidate credentials with overlapping fingerprint evidence, the model does not specify how a verifier chooses the canonical credential. This operational detail remains deferred to repository and verifier implementations." } ], "publicationHolds": [ "Sole active provider: Codex. Claude and Grok waived due to timeouts on prior 1800-second, 900-second, 600-second and 300-second bounded attempts. Repository owner authorized completion without independent second-provider review.", "Single-provider mode: This result requires a separate no-tools adversarial audit (this audit) and remains reviewable-draft, not canonical, while independent second-provider review is waived.", "URL and version verification deferred: Live access verification of C2PA 2.4 specification URLs, W3C VC 2.0 recommendation URLs, RFC repository links and C2PA conformance explorer registry must be performed before archival publication.", "Crosswalk semantic loss: C2PA, VC, PROV and IPTC projections are declared lossy and version-pinned. Specific transformation rules, field drops and inference semantics remain deferred to specialist review before any production crosswalk is published.", "Algorithm migration and jurisdiction compliance policies deferred: No versioned algorithm deprecation path or regional compliance profiles (EU, UK, US, China) are specified. These must be completed before the model is used to support legal, evidentiary or jurisdictional claims.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Image, video, audio, document, live-stream, model, sensor, news, legal and health-domain specialist profiles for Content Provenance Credential assertions, bindings, validation and trust policies.", "Decentralized transparency logs, anonymous credentials, zero-knowledge proofs, post-quantum migration and biometric identity integration as future extensions.", "Versioned algorithm migration policies for deprecated or compromised cryptographic algorithms with specific timelines, validator update requirements and legacy credential revalidation paths.", "Jurisdiction-specific compliance profiles for EU (eIDAS, GDPR), UK (PSTI), US (state evidence rules, FTC Act), China (state control) and other major regulatory regions addressing electronic-signature validity, evidentiary admissibility, privacy and consent duties.", "Soft-binding recovery confidence thresholds, false-positive bounds, collision resolution policies and audit trails for ambiguous fingerprint matches with multiple candidate credentials.", "Operational credential revocation, suspension and refresh policies with specific time windows, repository consistency guarantees, offline verifier update mechanisms and legacy trust-anchor lifecycle.", "Harm review and remedy frameworks for surveillance, coercion, exclusion, spoofing, re-identification and removal scenarios with specific disclosure, escalation, audit and user-appeal procedures." ] }, "statistics": { "sources": 26, "bundles": 6, "layers": 12, "findings": 24, "questions": 96, "artifacts": 24, "functions": 12 } }