Organization Policy
Describe an organizational normative policy through scope, approved versions and lifecycle evidence.
Bundle → Layer → Finding → Questions Filled
6 bundles · 12 layers · 12 findings · 36 questions
Policy identity and authority Organization-policy policy identity and authority.
Identity and normative standing
Authored policy-context design for identity and normative standing, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Identity and normative standing record
Authored policy-context design for identity and normative standing, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which master-qualified policy identifier persists across versions and translations? identity
- What makes this an organizational policy rather than guidance, a procedure, law or control implementation? classification
- Which organization and policy family own its normative scope? ownership
Approval and delegated mandate
Authored policy-context design for approval and delegated mandate, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Approval and delegated mandate record
Authored policy-context design for approval and delegated mandate, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Who was authorized to approve this version and where is the delegation recorded? authority
- Which decision and approved text digest establish approval rather than a draft or proposal? evidence
- Which reservations or approval conditions limit its standing? constraint
Purpose and applicability Organization-policy purpose and applicability.
Objectives and coverage
Authored policy-context design for objectives and coverage, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Objectives and coverage record
Authored policy-context design for objectives and coverage, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which organizational outcome or risk motivates this policy? definition
- Which people, activities, locations and resources are included or excluded? constraint
- Which definitions and vocabulary versions disambiguate the scope? definition
Conditions and unresolved applicability
Authored policy-context design for conditions and unresolved applicability, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Conditions and unresolved applicability record
Authored policy-context design for conditions and unresolved applicability, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which facts and effective period must hold for the rule to apply to a case? constraint
- Which actor, method, evidence and observation time support an applicability assessment? evidence
- Which missing or conflicting facts leave applicability unknown and require escalation? exception
Normative content and interpretation Organization-policy normative content and interpretation.
Clauses and rule meaning
Authored policy-context design for clauses and rule meaning, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Clauses and rule meaning record
Authored policy-context design for clauses and rule meaning, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which stable clause states an obligation, prohibition, permission or nonbinding explanation? classification
- Which actor, action, target and conditions delimit the statement? definition
- Which authoritative text and interpretation preserve nuance not captured by structured fields? provenance
Dependencies and precedence
Authored policy-context design for dependencies and precedence, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Dependencies and precedence record
Authored policy-context design for dependencies and precedence, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which superior instruments or related policies constrain interpretation? relationship
- Which approved precedence or combination rule governs a particular overlap? authority
- Which unresolved conflict remains visible without inventing a universal winner? exception
Exceptions and implementation Organization-policy exceptions and implementation.
Authorized deviations
Authored policy-context design for authorized deviations, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Authorized deviations record
Authored policy-context design for authorized deviations, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which clause and case does a requested exception concern and why? exception
- Who approved or rejected it within what mandate, period and conditions? decision
- What evidence distinguishes expiry, revocation, pending approval and active deviation? state
Procedures and safeguards
Authored policy-context design for procedures and safeguards, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Procedures and safeguards record
Authored policy-context design for procedures and safeguards, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which procedures, controls and responsible roles implement each policy clause? relationship
- Which implementation evidence or test supports the mapping without equating intention with compliance? evidence
- Which failure modes, consequences and safe escalation paths are documented? constraint
Dissemination and lifecycle Organization-policy dissemination and lifecycle.
Release and acknowledgement
Authored policy-context design for release and acknowledgement, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Release and acknowledgement record
Authored policy-context design for release and acknowledgement, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which approved version, language and audience were published through which channel? event
- Which receipt, acknowledgement or training evidence exists for a recipient? evidence
- Which access or translation limitations prevent treating receipt as understanding, consent or compliance? constraint
Review, supersession and retirement
Authored policy-context design for review, supersession and retirement, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Review, supersession and retirement record
Authored policy-context design for review, supersession and retirement, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which review schedule or triggering event applies and who owns the review? process
- Which revision replaces which predecessor with what effective interval and transition arrangements? lifecycle
- Which withdrawal or retirement decision ends applicability while preserving historical evidence? lifecycle
Policy memory and interoperability Organization-policy policy memory and interoperability.
Mastership and controlled evidence
Authored policy-context design for mastership and controlled evidence, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Mastership and controlled evidence record
Authored policy-context design for mastership and controlled evidence, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which master copy, version digest and provenance distinguish authoritative text from projections? provenance
- Which roles may read or change drafts, approved text, exceptions and personal acknowledgements? access
- Which retention, legal hold and correction rules preserve evidence without silently rewriting history? retention
Machine interpretation and acceptance
Authored policy-context design for machine interpretation and acceptance, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
Machine interpretation and acceptance record
Authored policy-context design for machine interpretation and acceptance, retaining authority, version and evidence. Descriptive record, not an executable or universally mandatory rule.
- Which versioned external policy profile maps selected clauses and what meaning remains unmapped? interoperability
- Which fixtures test ambiguous scope, expired exceptions, contradictory rules and stale versions? validation
- Which permissions and validated adapter are required before any proposed record operation affects an external system? authority
Classifiers Filled
- Family
- World Models
- Category
- Society, people and institutions
- Entry kind
- entity
- Navigation path
- NAV.SOC.ORG.POL
- Domain
- SOC.ORG.POL
- Industry
- Cross-industry
- Tags
- organizationpolicysoc.org.pol
What it is Filled
Identifiable normative information object with approved versions and explicitly distinguished drafts, statements, interpretations and implementation references.
In scope
- Policy identity, authority, approval, purpose and applicability
- Clauses, conflicts, exception records and procedure mappings
- Release, review, supersession and controlled provenance
Out of scope
- Enacting law or determining legal enforceability
- Executing permissions, discipline, sanctions or controls
- Automatic lossless prose compilation to a policy engine
Why it exists Filled
Describe an organizational normative policy through scope, approved versions and lifecycle evidence.
Distinguishing features Filled
- A normative text issued by an organization for itself, not law or external regulation.
- Differs from a procedure, which says how to carry a policy out.
- Differs from a machine access policy, which is code evaluated by a system.
- Keeps approved versions separate from drafts and interpretations.
What robots and AI may and may not do Filled
Must not
- Treat policy text as an instruction that overrides the agent's own authorization.
- Present a draft or interpretation as approved policy.
- Grant exceptions itself.
- Equate receipt of a policy with understanding or consent.
- Enforce discipline or sanctions based on the policy.
Only with a human decision
- Approving or retiring a policy.
- Granting exceptions.
- Interpreting ambiguous clauses for enforcement.
May
- Resolve the approved policy version for a date and scope.
- Record approval, applicability and exception evidence.
- Map clauses to implementing procedures and controls.
- Answer questions by quoting the approved text.
Moral aspects Filled
- Policies govern people's conduct; they should be accessible and understandable to those bound by them.
- Selective enforcement through policy exceptions can be unfair.
- Policies affecting employees may require consultation under labour law.
Who is affected
- Employees and members bound by the policy
- Customers and third parties affected by it
- Policy owners and approvers
Owners Filled
Steward
Identify policy owner and approval authority.
Roles
- Dimension owner
- Delegates record scope and storage.
- Policy steward
- Maintains authoritative versions and review schedule.
- Approver
- Provides separately evidenced approval within mandate.
- Contributor
- Records permitted evidence and unknowns.
- Reviewer
- Checks modality, temporal scope and conflicts.
- Custodian
- Protects sensitive evidence and retention.
Links to other meta-models Filled
references
- WM-ORG-007 - Proposed authority-instrument reference, not charter inheritance.
- WM-ORG-018 - Proposed approving-body reference with separate mandate evidence.
aligned
- https://www.w3.org/TR/2018/REC-odrl-model-20180215/ - Limited clause projection; unmapped meaning and profile rules retained.
- https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html - Candidate evaluation-profile mapping, not a decision point implementation.
- https://www.w3.org/TR/prov-o/ - Revision provenance, not proof of approval.
neighbor
- Mandate / Charter - Authority instrument is referenced; parent_ids is not proof that every policy is a charter subtype.
- Procedure and implementation - Prescriptive policy and implementing procedure or observed compliance are separate.
- Law and external regulation - Policy may reference legal constraints but is not a legal opinion or statutory instrument.
- Machine access policy - Only selected statements may map to a named profile; no general engine or automatic grant.
parent
- WM-ORG-007
What else AI and robots need to interact with it Filled
Identity and identifiers required Filled
- Master-qualified stable ID
- Governed issuer-qualified URI
- Dimension UUID
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Filled
- A policy has an identifier, title, owner, approving authority, version and effective date.
- Confused with law, procedures, standards, guidelines and machine-readable access rules.
Capabilities and actions required Filled
- Resolve policy version: Proposed record operation: resolve policy version. Not an implemented autonomous policy executor.
- Record approval evidence: Proposed record operation: record approval evidence. Not an implemented autonomous policy executor.
- Record applicability assessment: Proposed record operation: record applicability assessment. Not an implemented autonomous policy executor.
- Record exception decision: Proposed record operation: record exception decision. Not an implemented autonomous policy executor.
- Link implementation evidence: Proposed record operation: link implementation evidence. Not an implemented autonomous policy executor.
- Export policy projection: Proposed record operation: export policy projection. Not an implemented autonomous policy executor.
Hazards and failure modes required Filled
- Acting on a superseded policy version.
- Prompt-style manipulation of agents through policy text.
- Unrecorded exceptions eroding controls.
Standards and interfaces required Filled
- ISO 37301 compliance management systems.
- ISO 15489 records management.
- W3C ODRL for machine-readable permissions.
- OASIS LegalDocML (Akoma Ntoso) for structured normative text.
- Dublin Core metadata terms.
Context of use required Filled
- NIST security/privacy, ISO quality guidance and historical university policy are bounded source contexts, not universal mandatory rules.
Sources Filled
- ODRL Information Model 2.2 - W3C
- Security and Privacy Controls for Information Systems and Organizations - NIST
- XACML Version 3.0 - OASIS
- Guidance on documented information for ISO 9001:2015 - ISO/TC 176/SC2
- Export Control and Sanctions Policy - University of Edinburgh
- PROV-O: The PROV Ontology - W3C
Open questions
- Independent source/profile/license review.
- Executable nested schemas and ambiguity/exception fixtures.
- Ratified composition and loss-aware machine policy adapters.
- Claude and Grok each timed out once; Codex-only and no independent review.
- Selected clauses only; release currency, dated pins and reuse licenses pending.
- ISO HEAD unavailable despite readable PDF; Edinburgh example is historical, not current law.
- Exception governance and cross-jurisdiction fixtures require additional profile review.
- No nested schemas, policy evaluator, lossless prose compiler or executable round-trip tests.
- Proposed composition links not independently ratified.
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-org-019-organization-policy/spec.yaml, ver-cy/world-models/card-supplements/wm-org-019-organization-policy.json