# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T22:10:00Z", "synthesisSha256": "883f0d6201568df55fdb1bff7cf7ba6f63acc13737bf9422bcb410cfc8871852", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-OBJ-008", "registryId": "vr.wm-obj-008", "name": "Device / Sensor / Compute HW", "version": "0.1.0-reviewable-draft", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Physical world and living systems", "industry": [ "Cross-industry" ], "domain": [ "PHY.OBJ.DEV" ], "tags": [ "device", "sensor", "compute", "hw", "phy.obj.dev" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-obj-008-device-sensor-compute-hw/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-obj-008", "model": { "registry_id": "vr.wm-obj-008", "model_id": "WM-OBJ-008", "name": "Device / Sensor / Compute HW", "entry_kind": "entity", "purpose": "Describe one physical device, sensing unit or computing hardware unit through governed identity, capabilities, state assertions and evidence links.", "scope_statement": "A physical unit with sensing, computing or connected-device functions, including unit-side component, firmware, configuration and interface assertions. Sensors, networking, mutable firmware and actuation are individually optional. All structure is proposed research, not an executable controller.", "in_scope": [ "Physical hardware identity specialization and recognition evidence", "Installed resource and component topology, conditional power and environmental properties", "Physical sensing capability and calibration evidence applicability", "Component firmware and configuration bindings, interface and stream references", "Scoped assurance, support and lifecycle evidence for the unit" ], "out_of_scope": [ "Product-type catalogue, fleet aggregate, virtual machine or purely virtual/human sensor root", "Observation payloads, stream ingestion, software release lifecycle and runtime scheduling", "External authority decisions, ownership transfers, maintenance execution, calibration execution and legal metrology certification", "Device commands, firmware installation, actuation, credential provisioning, sanitization and disposal execution", "Host vehicle or equipment lifecycle, incident response execution and global audit-trail semantics" ], "boundary_notes": [ { "neighbor": "WM-OBJ-001", "distinction": "Proposed successor binding for legacy M2. Reuse the physical-item master identity, ownership, custody and location references; only hardware-specific assertions are local. Pin an adopted revision before runtime use.", "source_refs": [ "SRC-001" ] }, { "neighbor": "WM-OBJ-006", "distinction": "Legacy M6 host equipment candidate. Store host reference and mount role; do not duplicate machinery condition, maintenance execution or lifecycle.", "source_refs": [ "SRC-002" ] }, { "neighbor": "WM-OBJ-007", "distinction": "Legacy M7 vehicle host candidate; store installation reference without vehicle operations or custody lifecycle.", "source_refs": [ "SRC-002" ] }, { "neighbor": "WM-MAT-008", "distinction": "Observation and calibration result records remain externally mastered; the device carries evidence references and applicability only.", "source_refs": [ "SRC-002", "SRC-008" ] }, { "neighbor": "WM-DAT-010", "distinction": "Observation collection payload, ingestion and retention remain external; keep only channel-to-collection bindings.", "source_refs": [ "SRC-005" ] }, { "neighbor": "WM-SFT-007", "distinction": "Installed firmware points to versioned software packages; release creation and distribution remain external.", "source_refs": [ "SRC-007" ] }, { "neighbor": "WM-SFT-011", "distinction": "Desired configuration profile is external; keep component binding and observed application evidence.", "source_refs": [ "SRC-004" ] }, { "neighbor": "WM-SFT-010", "distinction": "Runtime environments and virtual machines reference the physical host; do not treat them as this physical entity.", "source_refs": [ "SRC-009" ] }, { "neighbor": "WM-XCT-010", "distinction": "Use governed location and frame references; device-side placement does not own an address registry.", "source_refs": [ "SRC-002", "SRC-005" ] }, { "neighbor": "W3C SSN/SOSA 2017", "distinction": "Conceptual alignment for physical sensors and deployment only; broader virtual and human sensor semantics are not imported.", "source_refs": [ "SRC-002" ] }, { "neighbor": "W3C WoT Thing Description 1.1", "distinction": "Conceptual interface metadata mapping, without executing actions or claiming conformance.", "source_refs": [ "SRC-003" ] }, { "neighbor": "RFC 8348", "distinction": "Map qualified component identity and state assertions; do not equate a management server identifier with the physical master.", "source_refs": [ "SRC-001" ] }, { "neighbor": "OGC SensorThings 1.0", "distinction": "Historical pin for channel-to-stream concepts; endpoint implementation and conformance are deferred.", "source_refs": [ "SRC-005" ] }, { "neighbor": "DMTF ComputerSystem v1.24.0", "distinction": "Map physical-unit resources only after checking SystemType and scope; virtual and composed views are not identical roots.", "source_refs": [ "SRC-009" ] }, { "neighbor": "Legacy M8 and unreviewed card supplement", "distinction": "Legacy standalone-mm is a record-plane label; entity is the subject kind. Reject uniqueness of mutable software and mandatory data-stream output. Replace exactly-one-current-firmware with component and slot scoped assertions; legal metrology remains an applicability profile, not a disjoint device family.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-009" ] } ] }, "sources": [ { "id": "SRC-001", "title": "A YANG Data Model for Hardware Management", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc8348", "version_or_date": "RFC 8348, March 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "Sections 3 and 7: component identity, containment, revision and administrative versus operational state." }, { "id": "SRC-002", "title": "Semantic Sensor Network Ontology", "organization": "W3C", "url": "https://www.w3.org/TR/2017/REC-vocab-ssn-20171019/", "version_or_date": "Recommendation, 2017-10-19", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "Sections 4.2, 4.9 and 5.1: sensors, platforms, deployments and conditional capability; the hardware-only boundary is a local restriction." }, { "id": "SRC-003", "title": "Web of Things (WoT) Thing Description 1.1", "organization": "W3C", "url": "https://www.w3.org/TR/2023/REC-wot-thing-description11-20231205/", "version_or_date": "Recommendation, 2023-12-05", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "Sections 5.3 and 6: properties, actions, events, forms and security metadata; descriptions do not authorize invocation." }, { "id": "SRC-004", "title": "IoT Device Cybersecurity Capability Core Baseline", "organization": "NIST", "url": "https://doi.org/10.6028/NIST.IR.8259A", "version_or_date": "NISTIR 8259A, May 2020", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "Table 1: identification, configuration, data protection, logical interface access, software update and cybersecurity state awareness. Baseline guidance is not a certification." }, { "id": "SRC-005", "title": "OGC SensorThings API Part 1: Sensing", "organization": "OGC", "url": "https://docs.ogc.org/is/15-078r6/15-078r6.html", "version_or_date": "Version 1.0, OGC 15-078r6, 2016-07-26", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "Section 8.2: separate Thing, Location, Datastream, Sensor, ObservedProperty, Observation and FeatureOfInterest. Historical alignment pin, not a latest-version claim." }, { "id": "SRC-006", "title": "Remote ATtestation procedureS (RATS) Architecture", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc9334.html", "version_or_date": "RFC 9334, January 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "Sections 3, 7 and 8: separate evidence, verifier appraisal and relying-party decisions, with target binding and freshness." }, { "id": "SRC-007", "title": "Platform Firmware Resiliency Guidelines", "organization": "NIST", "url": "https://doi.org/10.6028/NIST.SP.800-193", "version_or_date": "SP 800-193, May 2018", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "Sections 3 and 4: protection, detection, recovery and policy-qualified update/recovery evidence; no implementation or safety certification inferred." }, { "id": "SRC-008", "title": "NIST Policy on Metrological Traceability", "organization": "NIST", "url": "https://www.nist.gov/calibrations/traceability", "version_or_date": "Page updated 2024-06-17", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "Policy statements 1, 3 and 5: documented calibration chain, result uncertainty, responsibility for claims and distinction from fitness for purpose." }, { "id": "SRC-009", "title": "Redfish ComputerSystem schema", "organization": "DMTF", "url": "https://redfish.dmtf.org/schemas/v1/ComputerSystem.v1_24_0.json", "version_or_date": "ComputerSystem v1.24.0, copyright 2014-2025", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T22:07:56Z", "relevance": "ComputerSystem, SystemType, ProcessorSummary and MemorySummary: hardware resource summaries and physical versus virtual representations; only qualified physical-unit mappings proposed." } ], "structure": { "bundles": [ { "id": "identity", "name": "Identity and recognition", "description": "Local device context for identity and recognition.", "rationale": "Group related unit-side assertions while preserving external masters and evidence.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "layers": [ { "id": "unit-identity-layer", "name": "Unit identity", "description": "Qualify unit identity for one physical unit and the relevant time interval.", "source_refs": [ "SRC-001", "SRC-004" ], "findings": [ { "id": "unit-identity", "name": "Unit identity", "description": "One persistent physical unit has a governed master reference and qualified aliases. Network addresses and manufacturer serials alone are insufficient for automatic record merging.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "unit-identity-q1", "text": "Which master record identifies this physical unit and qualifies its serial aliases?", "kind": "identity", "answer_data": [ "master reference", "issuer", "serial", "collision status" ] }, { "id": "unit-identity-q2", "text": "Which hardware class and product revision describe the unit?", "kind": "classification", "answer_data": [ "class code", "product reference", "hardware revision" ] }, { "id": "unit-identity-q3", "text": "Which owner, custodian and operator references apply for this interval?", "kind": "ownership", "answer_data": [ "role references", "effective interval", "authority evidence" ] }, { "id": "unit-identity-q4", "text": "What evidence resolves missing labels or conflicting identifiers without merging separate units?", "kind": "exception", "answer_data": [ "identity dispute", "evidence references", "steward decision" ] } ], "data_elements": [ { "id": "unit-identity-master-reference", "name": "Master reference", "description": "Authoritative unit identifier qualified by its master namespace.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "unit-identity-qualified-aliases", "name": "Qualified aliases", "description": "Issuer-scoped serials and address aliases with validity and collision status.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "unit-identity-role-bindings", "name": "Role bindings", "description": "Owner, custodian and operator references with independent authority and effective intervals.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "unit-identity-evidence-index", "name": "Unit identity evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "recognition-layer", "name": "Recognition evidence", "description": "Qualify recognition evidence for one physical unit and the relevant time interval.", "source_refs": [ "SRC-001", "SRC-006" ], "findings": [ { "id": "recognition", "name": "Recognition evidence", "description": "Labels, inventory observations and attestation references support a claimed unit match. Keep reported identity, authenticated endpoint and verified hardware association distinct.", "source_refs": [ "SRC-001", "SRC-006" ], "questions": [ { "id": "recognition-q1", "text": "Which label or inventory evidence supports the claimed hardware match?", "kind": "evidence", "answer_data": [ "evidence reference", "collection method", "observed time" ] }, { "id": "recognition-q2", "text": "Who collected recognition evidence and through which management path?", "kind": "provenance", "answer_data": [ "collector", "path", "provenance reference" ] }, { "id": "recognition-q3", "text": "Which component and evidence freshness constraints limit the identity assertion?", "kind": "validation", "answer_data": [ "target scope", "verifier reference", "expiry", "uncertainty" ] }, { "id": "recognition-q4", "text": "Which identifying evidence must be masked in public or shared views?", "kind": "privacy", "answer_data": [ "sensitive fields", "recipient scope", "redaction rule" ] } ], "data_elements": [ { "id": "recognition-recognition-evidence", "name": "Recognition evidence", "description": "References to label records, discovery snapshots or attestations.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "recognition-match-assessment", "name": "Match assessment", "description": "Claimed target, assessor, confidence, valid interval and unresolved mismatch.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] } ], "artifacts": [ { "id": "recognition-evidence-index", "name": "Recognition evidence evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "hardware", "name": "Physical properties and resources", "description": "Local device context for physical properties and resources.", "rationale": "Group related unit-side assertions while preserving external masters and evidence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "layers": [ { "id": "resources-layer", "name": "Installed resources", "description": "Qualify installed resources for one physical unit and the relevant time interval.", "source_refs": [ "SRC-009", "SRC-001" ], "findings": [ { "id": "resources", "name": "Installed resources", "description": "Capture installed processor, memory, storage and interface references for this unit. Capacity, allocation and measured workload are different assertions; virtual environments remain external.", "source_refs": [ "SRC-009", "SRC-001" ], "questions": [ { "id": "resources-q1", "text": "Which installed processors, memory, storage and interfaces belong to this unit?", "kind": "composition", "answer_data": [ "component references", "inventory scope", "inventory time" ] }, { "id": "resources-q2", "text": "What capacities and counts are reported with their units and evidence?", "kind": "measurement", "answer_data": [ "quantity", "unit", "method", "evidence", "uncertainty" ] }, { "id": "resources-q3", "text": "Which installed resources are unavailable, reserved or unsupported in this configuration?", "kind": "constraint", "answer_data": [ "resource reference", "availability", "reason", "effective interval" ] }, { "id": "resources-q4", "text": "How does each resource mapping distinguish physical hardware from logical or virtual views?", "kind": "interoperability", "answer_data": [ "mapping version", "source type", "physical target", "loss notes" ] } ], "data_elements": [ { "id": "resources-resource-inventory", "name": "Resource inventory", "description": "Component references, resource kind, physical scope and as-observed time.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-001" ] }, { "id": "resources-resource-quantities", "name": "Resource quantities", "description": "Reported counts or quantities with unit, basis and evidence; allocation references remain external.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-001" ] } ], "artifacts": [ { "id": "resources-evidence-index", "name": "Installed resources evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-009", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "limits-layer", "name": "Power and environmental envelope", "description": "Qualify power and environmental envelope for one physical unit and the relevant time interval.", "source_refs": [ "SRC-002", "SRC-009" ], "findings": [ { "id": "limits", "name": "Power and environmental envelope", "description": "Represent declared operating and survival conditions separately from measured conditions. Local fields can include dimensions, mass, electrical supply and thermal constraints when supported by unit-specific evidence.", "source_refs": [ "SRC-002", "SRC-009" ], "questions": [ { "id": "limits-q1", "text": "Which dimensions, mass and supply quantities are evidenced for this unit?", "kind": "measurement", "answer_data": [ "property", "quantity", "unit", "tolerance", "method", "conditions" ] }, { "id": "limits-q2", "text": "Which operating and survival envelopes apply to the installed revision?", "kind": "constraint", "answer_data": [ "envelope kind", "limits", "conditions", "revision", "source" ] }, { "id": "limits-q3", "text": "Which ratings are declared and which have been measured on the actual unit?", "kind": "quality", "answer_data": [ "assertion category", "evidence", "observation time", "uncertainty" ] }, { "id": "limits-q4", "text": "What policy limits use when required environmental or power evidence is missing?", "kind": "exception", "answer_data": [ "missing evidence", "policy reference", "restricted capability" ] } ], "data_elements": [ { "id": "limits-physical-properties", "name": "Physical properties", "description": "Quantity, unit, tolerance or uncertainty, method, conditions and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-009" ] }, { "id": "limits-conditional-envelopes", "name": "Conditional envelopes", "description": "Separate operating, storage or survival claims with applicability and evidence; no universal safe limits.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-009" ] } ], "artifacts": [ { "id": "limits-evidence-index", "name": "Power and environmental envelope evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-002", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "assembly", "name": "Components and placement", "description": "Local device context for components and placement.", "rationale": "Group related unit-side assertions while preserving external masters and evidence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-009" ], "layers": [ { "id": "components-layer", "name": "Component continuity", "description": "Qualify component continuity for one physical unit and the relevant time interval.", "source_refs": [ "SRC-001", "SRC-009" ], "findings": [ { "id": "components", "name": "Component continuity", "description": "Component membership is time-bounded. A replaceable module can retain its own identity after removal; a parent device record is not a fleet or procurement catalogue.", "source_refs": [ "SRC-001", "SRC-009" ], "questions": [ { "id": "components-q1", "text": "Which components are embedded, replaceable or separately mastered?", "kind": "composition", "answer_data": [ "component id", "role", "parent", "identity policy" ] }, { "id": "components-q2", "text": "During which interval was each component installed in this unit?", "kind": "temporal", "answer_data": [ "installed from", "removed at", "event reference" ] }, { "id": "components-q3", "text": "Which replacement changed component identity while preserving the parent unit?", "kind": "lifecycle", "answer_data": [ "old and new references", "continuity decision", "service evidence" ] }, { "id": "components-q4", "text": "How are containment cycles, duplicate active slots and ambiguous parents rejected?", "kind": "validation", "answer_data": [ "topology validation", "slot scope", "exception evidence" ] } ], "data_elements": [ { "id": "components-component-bindings", "name": "Component bindings", "description": "Child master reference or locally scoped subcomponent id, slot, role and membership interval.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "components-replacement-evidence", "name": "Replacement evidence", "description": "External maintenance records supporting component continuity decisions.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-009" ] } ], "artifacts": [ { "id": "components-evidence-index", "name": "Component continuity evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-001", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "placement-layer", "name": "Host and spatial binding", "description": "Qualify host and spatial binding for one physical unit and the relevant time interval.", "source_refs": [ "SRC-002", "SRC-005" ], "findings": [ { "id": "placement", "name": "Host and spatial binding", "description": "Record the unit-side relationship to a host, mounting frame or location reference over time. Physical mounting is distinct from network topology and from ownership of the host.", "source_refs": [ "SRC-002", "SRC-005" ], "questions": [ { "id": "placement-q1", "text": "Which host asset or platform is related to this installation?", "kind": "relationship", "answer_data": [ "host master reference", "relation role", "evidence" ] }, { "id": "placement-q2", "text": "Which coordinate frame, pose or named mount locates the unit on its host?", "kind": "spatial", "answer_data": [ "frame reference", "pose", "accuracy", "mount identifier" ] }, { "id": "placement-q3", "text": "When did the placement become valid and when was it observed?", "kind": "temporal", "answer_data": [ "valid interval", "observation time", "ingestion time" ] }, { "id": "placement-q4", "text": "How are mobile, unmounted or disputed installations represented?", "kind": "exception", "answer_data": [ "placement state", "alternatives", "authority", "uncertainty" ] } ], "data_elements": [ { "id": "placement-host-binding", "name": "Host binding", "description": "Host identity and relation role; simultaneous frames require an explicit profile.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "placement-placement-assertion", "name": "Placement assertion", "description": "Frame, pose or mount reference, evidence, uncertainty and validity interval.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] } ], "artifacts": [ { "id": "placement-evidence-index", "name": "Host and spatial binding evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-002", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "sensing", "name": "Sensing and metrology", "description": "Local device context for sensing and metrology.", "rationale": "Group related unit-side assertions while preserving external masters and evidence.", "source_refs": [ "SRC-002", "SRC-005", "SRC-008" ], "layers": [ { "id": "capability-layer", "name": "Sensing capability", "description": "Qualify sensing capability for one physical unit and the relevant time interval.", "source_refs": [ "SRC-002", "SRC-005" ], "findings": [ { "id": "capability", "name": "Sensing capability", "description": "A physical sensing channel links an observed property and procedure to conditional performance claims. Compute-only units can declare this layer not applicable; human and purely virtual sensors are outside the root.", "source_refs": [ "SRC-002", "SRC-005" ], "questions": [ { "id": "capability-q1", "text": "Which property and feature class can this physical channel observe?", "kind": "definition", "answer_data": [ "channel", "property reference", "feature class" ] }, { "id": "capability-q2", "text": "What range, resolution, frequency and uncertainty statements are evidenced under stated conditions?", "kind": "measurement", "answer_data": [ "performance property", "value", "unit", "conditions", "evidence" ] }, { "id": "capability-q3", "text": "Which procedure and sensor component support the capability claim?", "kind": "relationship", "answer_data": [ "procedure reference", "sensor component", "revision" ] }, { "id": "capability-q4", "text": "When is sensing absent, disabled or outside its supported envelope?", "kind": "exception", "answer_data": [ "applicability", "disabled reason", "envelope violation", "policy" ] } ], "data_elements": [ { "id": "capability-sensing-channels", "name": "Sensing channels", "description": "Physical channel and sensor references with property and procedure pins.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "capability-performance-claims", "name": "Performance claims", "description": "Conditional capability assertions; distinguish resolution, uncertainty and qualitative accuracy.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] } ], "artifacts": [ { "id": "capability-evidence-index", "name": "Sensing capability evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-002", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "calibration-layer", "name": "Calibration evidence and suitability", "description": "Qualify calibration evidence and suitability for one physical unit and the relevant time interval.", "source_refs": [ "SRC-008", "SRC-002" ], "findings": [ { "id": "calibration", "name": "Calibration evidence and suitability", "description": "Link calibration evidence for a specified channel, range and configuration. Traceability pertains to measurement results and does not itself guarantee suitability or legal verification.", "source_refs": [ "SRC-008", "SRC-002" ], "questions": [ { "id": "calibration-q1", "text": "Which calibration record identifies the channel, configuration and reference chain?", "kind": "evidence", "answer_data": [ "certificate reference", "channel", "configuration", "reference chain" ] }, { "id": "calibration-q2", "text": "What uncertainty and conditions constrain use of the calibration evidence?", "kind": "quality", "answer_data": [ "uncertainty", "unit", "conditions", "range", "result scope" ] }, { "id": "calibration-q3", "text": "Which policy determines the next review and invalidation triggers for this channel?", "kind": "temporal", "answer_data": [ "review policy", "due state", "change triggers", "assessment date" ] }, { "id": "calibration-q4", "text": "Who assessed fitness for the intended measurement purpose and with what criterion?", "kind": "decision", "answer_data": [ "assessor", "purpose", "acceptance criterion", "assessment reference" ] } ], "data_elements": [ { "id": "calibration-calibration-reference", "name": "Calibration reference", "description": "Calibration report identity and revision tied to a channel and configuration.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-002" ] }, { "id": "calibration-suitability-assessment", "name": "Suitability assessment", "description": "Assessment reference, uncertainty requirement, applicability and review state; not automatic certification.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-002" ] } ], "artifacts": [ { "id": "calibration-evidence-index", "name": "Calibration evidence and suitability evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-008", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "software-state", "name": "Installed software and configuration", "description": "Local device context for installed software and configuration.", "rationale": "Group related unit-side assertions while preserving external masters and evidence.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ], "layers": [ { "id": "firmware-layer", "name": "Component firmware state", "description": "Qualify component firmware state for one physical unit and the relevant time interval.", "source_refs": [ "SRC-007", "SRC-001" ], "findings": [ { "id": "firmware", "name": "Component firmware state", "description": "Each relevant component may expose active, staged, recovery or unknown firmware assertions. Installed versions reference external releases; this record does not execute updates or recovery.", "source_refs": [ "SRC-007", "SRC-001" ], "questions": [ { "id": "firmware-q1", "text": "Which firmware assertion is active, staged, recovery or unknown for each component?", "kind": "state", "answer_data": [ "component", "slot role", "release reference", "reported status" ] }, { "id": "firmware-q2", "text": "Which observation or deployment result supports the installed-version assertion?", "kind": "provenance", "answer_data": [ "evidence reference", "event time", "observed time", "collector" ] }, { "id": "firmware-q3", "text": "Which compatibility and rollback policies qualify a proposed firmware transition?", "kind": "constraint", "answer_data": [ "policy reference", "component dependencies", "recovery constraints" ] }, { "id": "firmware-q4", "text": "How are interrupted updates and conflicting version reports retained?", "kind": "event", "answer_data": [ "attempt reference", "partial outcome", "conflicting observations", "reconciliation" ] } ], "data_elements": [ { "id": "firmware-firmware-bindings", "name": "Firmware bindings", "description": "Component and slot scoped release references with distinct desired, reported and accepted state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "firmware-update-evidence", "name": "Update evidence", "description": "External change and recovery results; no executable payloads or signing secrets.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] } ], "artifacts": [ { "id": "firmware-evidence-index", "name": "Component firmware state evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-007", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "configuration-layer", "name": "Configuration binding", "description": "Qualify configuration binding for one physical unit and the relevant time interval.", "source_refs": [ "SRC-004", "SRC-007" ], "findings": [ { "id": "configuration", "name": "Configuration binding", "description": "Pin intended configuration and separately record observed application evidence. A successful request or configuration digest alone does not establish actual device state.", "source_refs": [ "SRC-004", "SRC-007" ], "questions": [ { "id": "configuration-q1", "text": "Which desired profile revision and observed configuration evidence apply?", "kind": "state", "answer_data": [ "desired reference", "observed reference", "difference state" ] }, { "id": "configuration-q2", "text": "Which operator grant authorizes assessment of the configuration binding?", "kind": "authority", "answer_data": [ "role", "grant reference", "purpose", "expiry" ] }, { "id": "configuration-q3", "text": "Which settings require protected references rather than stored plaintext values?", "kind": "security", "answer_data": [ "sensitivity", "secret reference", "disclosure rule" ] }, { "id": "configuration-q4", "text": "How is drift recorded and referred to an external change process?", "kind": "process", "answer_data": [ "drift evidence", "change reference", "local record revision" ] } ], "data_elements": [ { "id": "configuration-configuration-bindings", "name": "Configuration bindings", "description": "Versioned profile references scoped by component and validity interval.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "configuration-drift-evidence", "name": "Drift evidence", "description": "Observed revision or digest, assessment time, discrepancy and change-process reference; omit secret values.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] } ], "artifacts": [ { "id": "configuration-evidence-index", "name": "Configuration binding evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "interfaces", "name": "Interfaces and observation links", "description": "Local device context for interfaces and observation links.", "rationale": "Group related unit-side assertions while preserving external masters and evidence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ], "layers": [ { "id": "connectivity-layer", "name": "Interface and reachability assertions", "description": "Qualify interface and reachability assertions for one physical unit and the relevant time interval.", "source_refs": [ "SRC-003", "SRC-001" ], "findings": [ { "id": "connectivity", "name": "Interface and reachability assertions", "description": "Describe interaction affordances and endpoint bindings with time and scope. Reachability, power state, administrative state and operational health remain separate observations.", "source_refs": [ "SRC-003", "SRC-001" ], "questions": [ { "id": "connectivity-q1", "text": "Which interface description and protocol binding identify the available interactions?", "kind": "interoperability", "answer_data": [ "description revision", "form reference", "protocol", "content type" ] }, { "id": "connectivity-q2", "text": "What endpoint, power and health states were observed and from which vantage point?", "kind": "state", "answer_data": [ "endpoint", "state kind", "observation time", "observer", "expiry" ] }, { "id": "connectivity-q3", "text": "Which policy governs reading properties or invoking the described action?", "kind": "access", "answer_data": [ "policy reference", "role", "purpose", "security scheme" ] }, { "id": "connectivity-q4", "text": "What behavior is expected when the unit sleeps, disconnects or has stale reachability evidence?", "kind": "exception", "answer_data": [ "staleness threshold", "state unknown", "intermittent profile" ] } ], "data_elements": [ { "id": "connectivity-interface-bindings", "name": "Interface bindings", "description": "Interface and endpoint references with protocol and external access-policy pins.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "connectivity-status-assertions", "name": "Status assertions", "description": "State kind, value, vantage point, valid time, observed time and freshness threshold; unknown distinct from false.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] } ], "artifacts": [ { "id": "connectivity-evidence-index", "name": "Interface and reachability assertions evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-003", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "stream-binding-layer", "name": "Observation stream binding", "description": "Qualify observation stream binding for one physical unit and the relevant time interval.", "source_refs": [ "SRC-005", "SRC-002" ], "findings": [ { "id": "stream-binding", "name": "Observation stream binding", "description": "Bind a physical channel to external observation and collection masters. The binding can change over time without rewriting historical measurement provenance or owning the stream payload.", "source_refs": [ "SRC-005", "SRC-002" ], "questions": [ { "id": "stream-binding-q1", "text": "Which observation collection carries output from this channel during this interval?", "kind": "relationship", "answer_data": [ "channel", "collection reference", "binding interval" ] }, { "id": "stream-binding-q2", "text": "Which unit, property and result-shape mapping qualifies that output?", "kind": "measurement", "answer_data": [ "property reference", "unit mapping", "schema reference", "loss notes" ] }, { "id": "stream-binding-q3", "text": "How are phenomenon, result and ingestion times distinguished by the binding?", "kind": "temporal", "answer_data": [ "clock domain", "time fields", "synchronization evidence", "uncertainty" ] }, { "id": "stream-binding-q4", "text": "Which permitted purposes and recipient policies constrain the stream reference?", "kind": "privacy", "answer_data": [ "purpose policy", "access scope", "retention-policy reference" ] } ], "data_elements": [ { "id": "stream-binding-stream-bindings", "name": "Stream bindings", "description": "Channel, collection, schema, property and unit mapping references with start and end.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-002" ] }, { "id": "stream-binding-clock-binding", "name": "Clock binding", "description": "Clock source, synchronization evidence, time semantics and uncertainty; no fabricated timestamps.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-002" ] } ], "artifacts": [ { "id": "stream-binding-evidence-index", "name": "Observation stream binding evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-005", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "assurance", "name": "Assurance and lifecycle", "description": "Local device context for assurance and lifecycle.", "rationale": "Group related unit-side assertions while preserving external masters and evidence.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007", "SRC-009" ], "layers": [ { "id": "security-assessment-layer", "name": "Security evidence and review", "description": "Qualify security evidence and review for one physical unit and the relevant time interval.", "source_refs": [ "SRC-006", "SRC-004" ], "findings": [ { "id": "security-assessment", "name": "Security evidence and review", "description": "Retain scoped references to attestations, vulnerability applicability assessments and incident records. Evidence, verifier result and permission to operate are separate; a trusted boot claim does not establish sensor accuracy.", "source_refs": [ "SRC-006", "SRC-004" ], "questions": [ { "id": "security-assessment-q1", "text": "Which target and time interval does an attestation appraisal actually cover?", "kind": "evidence", "answer_data": [ "target environment", "evidence reference", "verifier", "freshness" ] }, { "id": "security-assessment-q2", "text": "What external assessment qualifies vulnerability applicability to this configuration?", "kind": "validation", "answer_data": [ "assessment reference", "affected component", "configuration", "uncertainty" ] }, { "id": "security-assessment-q3", "text": "Which relying-party policy decides whether the reported assurance is sufficient?", "kind": "authority", "answer_data": [ "policy pin", "decision reference", "decision maker" ] }, { "id": "security-assessment-q4", "text": "What restrictions govern incident evidence and compromised-unit status disclosures?", "kind": "security", "answer_data": [ "incident reference", "disclosure scope", "access policy", "review state" ] } ], "data_elements": [ { "id": "security-assessment-assurance-references", "name": "Assurance references", "description": "Evidence, appraisal and decision references with target scope, version and freshness.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-004" ] }, { "id": "security-assessment-security-review-state", "name": "Security review state", "description": "Qualified status and next review policy; no exploit details or universal trusted flag.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-004" ] } ], "artifacts": [ { "id": "security-assessment-evidence-index", "name": "Security evidence and review evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-006", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "lifecycle-evidence-layer", "name": "Support, service and retirement", "description": "Qualify support, service and retirement for one physical unit and the relevant time interval.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ], "findings": [ { "id": "lifecycle-evidence", "name": "Support, service and retirement", "description": "Unit records track commissioned, service-restricted and retired assertions using external evidence. Support expiry, decommissioning, sanitization and physical disposal are distinct facts; local deletion cannot perform them.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ], "questions": [ { "id": "lifecycle-evidence-q1", "text": "Which commissioning, maintenance or retirement evidence supports the recorded lifecycle state?", "kind": "lifecycle", "answer_data": [ "state", "event reference", "effective time", "approval" ] }, { "id": "lifecycle-evidence-q2", "text": "Which support horizon and unresolved failure modes restrict continued use?", "kind": "constraint", "answer_data": [ "support notice", "failure assessment", "constraint policy" ] }, { "id": "lifecycle-evidence-q3", "text": "Which policy governs retention or deletion of the unit record after retirement?", "kind": "retention", "answer_data": [ "retention schedule", "hold", "disposition authority", "tombstone" ] }, { "id": "lifecycle-evidence-q4", "text": "Which separate records attest sanitization, transfer and disposal without inferring completion?", "kind": "evidence", "answer_data": [ "sanitization reference", "transfer reference", "disposal reference", "unknown outcomes" ] } ], "data_elements": [ { "id": "lifecycle-evidence-lifecycle-assertions", "name": "Lifecycle assertions", "description": "State, evidence, effective interval and authority for commissioning, restriction and retirement.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] }, { "id": "lifecycle-evidence-disposition-references", "name": "Disposition references", "description": "Separate service, support, transfer, sanitization and disposal evidence links with retention class.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "lifecycle-evidence-evidence-index", "name": "Support, service and retirement evidence index", "description": "A local revisioned index of the named assertions and their external evidence references; source artifacts retain their master identities.", "media_or_form": [ "structured record", "human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system identifier, else governed IRI, else Dimension UUID or ULID; immutable revision and digest identify the rendition; dates are metadata.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-unit", "name": "Register a unit assertion", "description": "Proposed, unimplemented local record operation. Create the local hardware extension only after resolving the physical-item master.", "inputs": [ "master reference", "classification evidence", "qualified aliases" ], "outputs": [ "local unit revision or unresolved-identity refusal" ], "preconditions": [ "identity steward approval", "master namespace resolved", "Current record revision matches to prevent lost updates", "Purpose and access scope authorized" ], "effects": [ "Create a local record; do not transfer ownership", "Record actor, time, evidence and revision in the adopting audit service" ], "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "record-inventory", "name": "Record a component inventory", "description": "Proposed, unimplemented local record operation. Append a time-qualified resource and containment snapshot without altering hardware.", "inputs": [ "component references", "membership intervals", "resource evidence" ], "outputs": [ "inventory revision or topology conflict" ], "preconditions": [ "acyclic topology", "slot and component identities qualified", "Current record revision matches to prevent lost updates", "Purpose and access scope authorized" ], "effects": [ "Append accepted local assertions and preserve contradictory observations", "Record actor, time, evidence and revision in the adopting audit service" ], "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "link-calibration", "name": "Link calibration evidence", "description": "Proposed, unimplemented local record operation. Record an assessor-scoped applicability claim for an existing calibration result.", "inputs": [ "calibration reference", "channel scope", "configuration", "assessment" ], "outputs": [ "evidence binding or scope mismatch" ], "preconditions": [ "result revision resolved", "measurement purpose stated", "Current record revision matches to prevent lost updates", "Purpose and access scope authorized" ], "effects": [ "Add a local reference; do not calibrate or certify the unit", "Record actor, time, evidence and revision in the adopting audit service" ], "source_refs": [ "SRC-008", "SRC-002" ] }, { "id": "record-software-state", "name": "Record software state evidence", "description": "Proposed, unimplemented local record operation. Keep component-specific observed state separate from desired release or profile.", "inputs": [ "component and slot", "release and profile references", "observation evidence" ], "outputs": [ "state revision or unresolved discrepancy" ], "preconditions": [ "collection authority", "observation time and target known", "Current record revision matches to prevent lost updates", "Purpose and access scope authorized" ], "effects": [ "Append local state evidence; do not install, recover or configure", "Record actor, time, evidence and revision in the adopting audit service" ], "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "bind-interface-output", "name": "Bind interface and output references", "description": "Proposed, unimplemented local record operation. Record qualified links from the unit to interface descriptions and external observation collections.", "inputs": [ "description revision", "channel", "collection", "time and unit mappings" ], "outputs": [ "binding revision or mapping rejection" ], "preconditions": [ "reference access allowed", "binding interval validated", "Current record revision matches to prevent lost updates", "Purpose and access scope authorized" ], "effects": [ "Update local bindings only; no endpoint invocation or subscription", "Record actor, time, evidence and revision in the adopting audit service" ], "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "record-assurance-review", "name": "Record assurance review references", "description": "Proposed, unimplemented local record operation. Link evidence, external appraisal and relying-party decision without performing verification.", "inputs": [ "evidence target", "appraisal reference", "decision reference", "freshness" ], "outputs": [ "scoped review record or insufficient-evidence result" ], "preconditions": [ "security reviewer authority", "target and time scope match", "Current record revision matches to prevent lost updates", "Purpose and access scope authorized" ], "effects": [ "Preserve qualified assurance references; do not grant access or declare global trust", "Record actor, time, evidence and revision in the adopting audit service" ], "source_refs": [ "SRC-006", "SRC-004" ] }, { "id": "record-retirement", "name": "Record retirement evidence", "description": "Proposed, unimplemented local record operation. Record a unit lifecycle assertion and close local bindings when supported by authorized evidence.", "inputs": [ "retirement evidence", "binding list", "retention and hold policy" ], "outputs": [ "retirement revision or unresolved-disposition refusal" ], "preconditions": [ "lifecycle steward approval", "actual outcome distinguished from request", "Current record revision matches to prevent lost updates", "Purpose and access scope authorized" ], "effects": [ "Close eligible local bindings; never wipe, disable, dispose or delete external records", "Record actor, time, evidence and revision in the adopting audit service" ], "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] } ], "composition": [ { "target": "WM-OBJ-001", "relation": "EXTEND", "purpose": "Proposed successor binding for legacy M2. Reuse the physical-item master identity, ownership, custody and location references; only hardware-specific assertions are local. Pin an adopted revision before runtime use.", "required": true, "source_refs": [ "SRC-001" ] }, { "target": "WM-OBJ-006", "relation": "REFERENCE", "purpose": "Legacy M6 host equipment candidate. Store host reference and mount role; do not duplicate machinery condition, maintenance execution or lifecycle.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "WM-OBJ-007", "relation": "REFERENCE", "purpose": "Legacy M7 vehicle host candidate; store installation reference without vehicle operations or custody lifecycle.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "WM-MAT-008", "relation": "REFERENCE", "purpose": "Observation and calibration result records remain externally mastered; the device carries evidence references and applicability only.", "required": false, "source_refs": [ "SRC-002", "SRC-008" ] }, { "target": "WM-DAT-010", "relation": "REFERENCE", "purpose": "Observation collection payload, ingestion and retention remain external; keep only channel-to-collection bindings.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "WM-SFT-007", "relation": "REFERENCE", "purpose": "Installed firmware points to versioned software packages; release creation and distribution remain external.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "WM-SFT-011", "relation": "REFERENCE", "purpose": "Desired configuration profile is external; keep component binding and observed application evidence.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "WM-SFT-010", "relation": "REFERENCE", "purpose": "Runtime environments and virtual machines reference the physical host; do not treat them as this physical entity.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "WM-XCT-010", "relation": "REFERENCE", "purpose": "Use governed location and frame references; device-side placement does not own an address registry.", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "target": "W3C SSN/SOSA 2017", "relation": "ALIGN", "purpose": "Conceptual alignment for physical sensors and deployment only; broader virtual and human sensor semantics are not imported.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "W3C WoT Thing Description 1.1", "relation": "ALIGN", "purpose": "Conceptual interface metadata mapping, without executing actions or claiming conformance.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "RFC 8348", "relation": "ALIGN", "purpose": "Map qualified component identity and state assertions; do not equate a management server identifier with the physical master.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "OGC SensorThings 1.0", "relation": "ALIGN", "purpose": "Historical pin for channel-to-stream concepts; endpoint implementation and conformance are deferred.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "DMTF ComputerSystem v1.24.0", "relation": "ALIGN", "purpose": "Map physical-unit resources only after checking SystemType and scope; virtual and composed views are not identical roots.", "required": false, "source_refs": [ "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Resolve the accountable owner role, custodian and technical operator separately; no company or brand is a model owner.", "Pin the physical-item master and all required neighbor revisions, schema profiles and allowed purposes.", "Declare device sensitivity, safety applicability, retention, service authority and qualified reviewer roles before population." ], "namespace_guidance": "Use the adopting Dimension namespace for unit assertions and local extension IDs; preserve authoritative external identifiers and pin imported revisions.", "registry_links": [ "vr.wm-obj-008", "WM-OBJ-001", "research/provider-policy.json" ] }, "canon_and_patch": { "canonicalization_rules": [ "Preserve master identity through firmware changes; component replacement requires explicit identity continuity decisions.", "Keep desired, reported, assessed and unknown values separate with provenance and validity time; no last-write-wins truth rule." ], "patch_rules": [ "Require expected revision, actor, purpose, evidence and affected scope; preserve earlier claims through supersession.", "Record competing observations and loss of freshness; corrections never rewrite external measurement history." ], "compatibility_rules": [ "Changing root identity, meaning of a channel, unit, state or required reference is a versioned compatibility change.", "Bindings to older source editions remain explicit; no wildcard standard imports or automatic conformance claims." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier", "Governed global identifier or IRI", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Use RFC 3339 with seconds and explicit offset or Z. Distinguish event or phenomenon time, observation time and ingestion time; record clock uncertainty and unknown precision.", "serial_naming_rule": "Use stable artifact identity plus immutable revision; keep chronological display labels separate from identity.", "integrity_rule": "Record digest algorithm and bytes scope for each rendition, provenance and access policy. A digest establishes byte identity, not truth, authenticity or calibration validity." }, "policies": [ "This is a noncanonical reviewable draft under a single-provider waiver; independent external review and source/version verification remain open.", "Apply least privilege and purpose limitation to serials, precise locations, network paths, firmware state and telemetry references; never store credentials or private keys.", "Device, electrical, safety, privacy, radio, legal metrology and disposal rules require an adopted sector and jurisdiction profile; no legal compliance assertion follows from schema validity.", "Hazardous or controlled applications remain at policy and authorization level. A capability description grants no command authority.", "Maintenance, security verification, updates, calibration, actuation and disposal execute only in separately authorized systems." ], "crud": { "read": [ "Resolve scope and revision before reading; redact sensitive identifiers, paths and security evidence for the recipient." ], "create": [ "Resolve physical-item master identity, class and authority; preserve unknown optional facets rather than guessing values." ], "update": [ "Use revision checks and evidence-backed patches; local changes cannot silently mutate hardware, external releases or telemetry payloads." ], "delete": [ "Apply owner retention and disposition policy to local unit records and artifacts; block deletion under applicable holds.", "Retire eligible local assertions and retain minimal resolvable tombstones where permitted; lawfully erase sensitive payloads when due.", "Referenced masters own their deletion. Device sanitization and physical disposal are separate authorized processes, not effects of deleting this record." ] }, "roles": [ { "name": "Accountable owner", "responsibilities": [ "Approve intended purposes, access policy and retention for the device record." ] }, { "name": "Identity steward", "responsibilities": [ "Resolve physical master references, duplicate identities and component continuity." ] }, { "name": "Technical operator", "responsibilities": [ "Supply inventory and observed state evidence within a valid grant." ] }, { "name": "Metrology reviewer", "responsibilities": [ "Assess channel-specific calibration evidence and measurement suitability." ] }, { "name": "Security reviewer", "responsibilities": [ "Qualify assurance references, freshness, disclosure and applicability." ] }, { "name": "Records custodian", "responsibilities": [ "Apply revision, retention, hold and lawful disposition rules." ] } ], "access": { "default_rule": "Deny access unless role, purpose, unit and time scope are authorized; derived views cannot widen source-artifact access.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency access requires explicit adopting-policy authority, expiry and retrospective review; it does not permit arbitrary device control." ], "audit_requirements": [ "Record actor, purpose, grant, scope, before and after revision and evidence references in the adopting audit service.", "Do not copy secret values into audit or public evidence indexes." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Owner and Dimension policy", "AGENTS.md", "spec.yaml and publication holds", "Pinned neighbor models and source evidence", "Authorized instance records" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one physical device, sensing unit or compute hardware unit. A separate frozen local no-tools self-audit found no critical conflict. Source/version checks, sector profiles, pinned neighbor bindings, executable conformance and independent review remain holds. This is a noncanonical reviewable draft, not an operational controller or a certification.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Master unit identity and qualified aliases, with separate recognition confidence." }, { "dimension": "lifecycle", "status": "covered", "notes": "Unit-side state and support/disposition evidence; execution delegated." }, { "dimension": "relationships", "status": "covered", "notes": "Component, host, software, observation and stream references; candidate pins remain a hold." }, { "dimension": "temporal", "status": "covered", "notes": "Validity, event, observed and ingestion times plus stale/unknown state." }, { "dimension": "provenance", "status": "covered", "notes": "Evidence, actor, source revision and local assertion history." }, { "dimension": "ownership", "status": "covered", "notes": "Owner, custodian and operator references with external grants." }, { "dimension": "validation", "status": "covered", "notes": "Research schema and proposed semantic constraints; executable instance conformance deferred." }, { "dimension": "access", "status": "covered", "notes": "Role, purpose, scope, expiry and redaction." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Local retention, holds, erasure and tombstones; external disposition delegated." }, { "dimension": "interoperability", "status": "covered", "notes": "Qualified conceptual alignments without implementation conformance." }, { "dimension": "direct properties", "status": "covered", "notes": "Conditional quantities and installed resources with uncertainty and source evidence." }, { "dimension": "recognition", "status": "covered", "notes": "Label and reported identity evidence distinct from attestation and authority." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Sensing and interface affordances distinct from device command execution." }, { "dimension": "safety and regional profiles", "status": "gap", "notes": "Sector-specific hazards, radio and electrical certification, legal metrology and disposal rules require expert profile review." }, { "dimension": "executable fixtures", "status": "gap", "notes": "Nested schemas and adversarial instances not implemented." } ], "known_omissions": [ "No independent second-provider review; Claude and Grok skipped under owner override.", "Direct HTTP checks not attempted under the owner-reported sandbox block; browser content was reviewed, but status, redirect bodies and live hashes are unmeasured.", "Nested instance schemas, pinned neighbor releases, protocol adapters and adversarial acceptance fixtures remain incomplete.", "No electrical, functional safety, medical-device, radio, export, legal metrology or disposal certification; applicable profiles require qualified review.", "No guarantee of comprehensive failure-mode or supply-chain provenance coverage." ], "conflicts": [], "regional_assumptions": [ "NIST guidance is technical evidence, not universal legislation.", "W3C, IETF, OGC and DMTF alignments use specified editions; latest-version and errata checks remain open." ], "adversarial_checks": [ "Same address or serial cannot merge two physical units without namespace and evidence checks.", "Firmware update does not change unit identity; replaced components need continuity review and multiple firmware slots remain possible.", "Offline, asleep, administratively disabled, compromised and retired are distinct states.", "Virtual sensors and composed computer views do not silently expand the physical-unit root.", "Attestation freshness and trust do not establish calibration accuracy or authority to operate.", "Record retirement cannot prove sanitization, stream deletion or physical disposal." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The root is one persistent physical hardware unit with optional sensing, connectivity and mutable firmware. Virtual and composed management views are not automatically physical-unit identities. The registry standalone-mm value classifies the record plane; the legacy physical-item relationship remains a proposed, revision-pinned dependency." }, "decisions": [ { "concept": "Physical root and optional facets", "disposition": "accepted", "rationale": "The draft accommodates compute-only and intermittently connected hardware without requiring sensing, network reachability, actuation or exactly one firmware image." }, { "concept": "Legacy uniqueness and conformance claims", "disposition": "rejected", "rationale": "Mutable software and data-stream output are not treated as universal distinguishing properties; inherited conformance labels and wildcard imports do not become validated claims." }, { "concept": "Physical-item and host boundaries", "disposition": "qualified", "rationale": "The proposed physical-item extension reuses the master and generic ownership references. Equipment and vehicle hosts remain separately mastered, and adopted neighbor revisions remain unpinned." }, { "concept": "Identity and recognition", "disposition": "accepted", "rationale": "Unit identity requires a qualified master and collision handling. Labels, address aliases, observed identity and attestation are evidence with scope rather than automatic identity equivalence." }, { "concept": "Resources and physical properties", "disposition": "accepted as candidate fields", "rationale": "Installed quantities and conditional envelopes require actual evidence, units and uncertainty. Physical properties are local candidate data, not universal values supplied by the cited standards." }, { "concept": "Components and placement", "disposition": "accepted", "rationale": "Replacement continuity, membership intervals, topology constraints and spatial frame references preserve the parent unit without owning host asset lifecycles." }, { "concept": "Calibration and measurement suitability", "disposition": "separated", "rationale": "Channel and configuration scope constrain calibration evidence. Traceability, uncertainty and fitness for a stated purpose remain distinct; legal verification and calibration execution are excluded." }, { "concept": "Firmware and configuration state", "disposition": "accepted", "rationale": "Component and slot scoped firmware avoids the legacy single-image assumption. Desired, observed and assessed configuration are separate, and update/recovery execution remains external." }, { "concept": "Interfaces and stream bindings", "disposition": "qualified", "rationale": "Affordance descriptions do not grant invocation permission. Endpoint reachability, health and freshness are separate; collections and observation payloads remain outside the device root." }, { "concept": "Attestation and security decisions", "disposition": "separated", "rationale": "Evidence, verifier appraisal, vulnerability applicability and relying-party decisions are references with target and time scope; none is a global trust or calibration certificate." }, { "concept": "Local functions and retirement", "disposition": "accepted as proposed only", "rationale": "All seven unimplemented functions update local records under authority and revision preconditions. Retirement cannot itself wipe media, disable hardware, dispose of a unit or delete external data." }, { "concept": "Access, history and artifact identity", "disposition": "accepted", "rationale": "Evidence indexes preserve source masters and immutable revisions while retention policy permits lawful sensitive-payload erasure. Scoped grants, redaction and minimal tombstones avoid unlimited disclosure or retention." }, { "concept": "Source verification and conformance", "disposition": "deferred", "rationale": "Selected primary readings support conceptual design only. Direct HTTP statuses remain unmeasured, source currency and errata remain open, and research validation does not certify instance schemas or device safety." }, { "concept": "Independent external review", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the explicit owner override. This separate Codex no-tools self-audit does not supply an independent second-provider review." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; this separate local Codex no-tools self-audit is not independent review.", "Live source and version verification remains incomplete. Nine primary sources were reviewed through selected web-tool content. Direct HTTP checks were not attempted under the owner-reported sandbox block; zero statuses and zero HTTP 200 responses were measured. The coordinator checker is prepared. Current editions, errata, redirects, response hashes and complete claim support remain unverified.", "Sector and jurisdiction profiles for electrical and functional safety, radio, privacy, legal metrology, controlled applications, maintenance authority and disposal require qualified review. No certification or operational fitness is claimed.", "Pinned neighbor releases, nested instance schemas, state and quantity constraints, protocol mappings and adversarial conformance fixtures remain incomplete. Local functions are proposed only and perform no device control or external lifecycle execution.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Run the coordinator source checker outside the sandbox, then substantively review edition pins, errata, rights and complete claim support; HTTP success alone is insufficient.", "Pin physical-item and other neighbor revisions, implement nested instance schemas and test duplicate serials, replaced modules, virtual/composed views, sleeping devices, stale attestations, failed updates and conflicting observations.", "Validate sector-specific measurement suitability, safety, privacy and retirement/disposition profiles with qualified reviewers.", "Restore independent external review before any canonical or publishable-draft promotion." ] }, "statistics": { "sources": 9, "bundles": 7, "layers": 14, "findings": 14, "questions": 56, "artifacts": 14, "functions": 7 } }