# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "research-draft", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-23T20:43:15Z", "synthesisSha256": "ffefc6ce9cf9d7c6b9661c80834009180840f8da0a23e7409434e4c49c9472b2", "providers": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-PER-001", "registryId": "vr.wm-per-001", "name": "Person", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Society, people and institutions", "industry": [ "Cross-industry" ], "domain": [ "SOC.PER.NAT" ], "tags": [ "person", "soc.per.nat" ], "status": "research draft" }, "canonicalUrl": "https://ver.cy/models/wm-per-001-person/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-per-001", "model": { "registry_id": "vr.wm-per-001", "model_id": "WM-PER-001", "name": "Person", "entry_kind": "entity", "purpose": "Model the natural person as a civil-identity anchor and life-course subject: a stable, referenceable identity that carries registered core attributes, scheme-qualified identifiers, evidence of identity, legal standing, life-event anchors and person-controlled personal-sphere data, so every other model can reference persons without copying them.", "scope_statement": "Format-neutral context structure for the natural person as a legally registered identity and data subject. Covers what an agent must know to establish, resolve, evidence, update, disclose, close and audit a person identity. Excludes the human as a biological organism, and excludes any concept that resolves in a composable sibling model (household, organization, address, vital-event record, qualification, authenticator).", "in_scope": [ "Person identity anchor, reference identifier and domain of applicability", "Registered core attributes: legal names over time, birth facts, administratively recorded sex and legal gender recognition", "Scheme-qualified identifier assignments, their validity, revocation and correlation properties", "Identity evidence: issued documents and electronic attestations, their status and holder binding", "Identity proofing outcome and assurance level, including biometric reference pointers", "Civil status, nationality and statelessness determination", "Legal capacity state and representation or support arrangements", "Anchors to vital and registered life events, with event time separated from registration and ingestion time", "Vital status and identity-record lifecycle states", "Person-controlled contact points, declared residence pointer and self-declared attributes", "Lawful basis, consent grants, subject rights, minimal disclosure, retention, erasure and disclosure audit", "Attribute accuracy, duplicate detection, record merge/split and external schema alignment" ], "out_of_scope": [ "The human biological organism: anatomy, physiology, genome, clinical findings and cause of death", "Household, family and kinship composition, including filiation ties as first-class objects", "Population, community and demographic group membership", "Educational, professional and occupational credentials as objects", "Organizations acting as issuers, employers or corporate guardians", "Address and place as spatial objects, geocoding and address validation", "The vital-event registration record itself and its statistical processing", "Party roles, employment, customer and account relationships", "Authenticators, sessions, keys and login security", "Cross-border private-international-law rules for recognising foreign status", "Behavioural profiling, scoring and inference about persons" ], "boundary_notes": [ { "neighbor": "Human biological organism / health subject model", "distinction": "This model treats the person as a civil identity, not an organism. HL7 FHIR Patient covers care-context demographics and explicitly permits several Patient records for one human; the anchor here is one per natural person and reconciles to Patient records by link, not by absorbing them.", "source_refs": [ "SRC-009", "SRC-002" ] }, { "neighbor": "Household and family model (legacy alias H2)", "distinction": "Kinship, filiation and household membership are separate registered acts and separate statistical units in UN civil-registration guidance. Person holds only typed pointers to them, never the tie itself.", "source_refs": [ "SRC-001", "SRC-017" ] }, { "neighbor": "Vital-event / civil-registration act model", "distinction": "The registration act, its informant, its statistical coding and its certificate are the event model's content. Person holds the anchor, the person's role in the event and the resulting status change only.", "source_refs": [ "SRC-001", "SRC-017" ] }, { "neighbor": "Address and place model", "distinction": "Residence is a pointer with a kind and a validity period. Address value shapes come from OASIS xAL and place resolution from the place model; usual residence as a statistical construct belongs to the census/statistics model.", "source_refs": [ "SRC-016", "SRC-004", "SRC-001" ] }, { "neighbor": "Organization model (legacy alias O1)", "distinction": "Registrars, issuing authorities, credential issuers and corporate guardians are organizations. Person references them; it does not define them.", "source_refs": [ "SRC-003", "SRC-004" ] }, { "neighbor": "Credential and authenticator security model", "distinction": "NIST separates identity proofing and enrollment from authenticator management. This model carries the proofing outcome and assurance level; authenticator binding, lifecycle and session security are out of scope.", "source_refs": [ "SRC-008" ] }, { "neighbor": "Consent and authorization service (legacy alias S1) and audit service (S4)", "distinction": "Person declares which data is subject-owned and what must be logged; the grant store, policy decision point and audit trail are service-layer components composed in, not duplicated here.", "source_refs": [ "SRC-011", "SRC-017" ] }, { "neighbor": "Publication vocabularies (schema.org Person)", "distinction": "schema.org Person is an open publication vocabulary with no validity periods, no issuing authority and no assurance semantics. It is a projection target only and must never be treated as an identity-assurance signal.", "source_refs": [ "SRC-010", "SRC-003" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Principles and Recommendations for a Vital Statistics System, Revision 3 (Series M No. 19/Rev.3)", "organization": "United Nations Department of Economic and Social Affairs, Statistics Division", "url": "https://unstats.un.org/unsd/demographic-social/Standards-and-Methods/files/Principles_and_Recommendations/CRVS/M19Rev3-E.pdf", "version_or_date": "Revision 3, 2014 (Sales No. 13.XVII.10)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Normative international basis for civil registration and vital events (live birth, death, fetal death, marriage, divorce), registration versus occurrence date and place, and the legal-instrument purpose of registration." }, { "id": "SRC-002", "title": "United Nations Strategy for Legal Identity for All (UN Legal Identity Agenda)", "organization": "United Nations Legal Identity Expert Group / UN Statistics Division", "url": "https://unstats.un.org/legal-identity-agenda/documents/UN-Strategy-for-LIA.pdf", "version_or_date": "2019 (UN LIA Strategy, endorsed 2020)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Defines legal identity as basic characteristics conferred through registration by an authorised civil registration authority, and ties civil registration, vital statistics, population registers and identity management from birth to death." }, { "id": "SRC-003", "title": "ISO/IEC 24760-1:2025 Information security, cybersecurity and privacy protection - A framework for identity management - Part 1: Core concepts and terminology", "organization": "ISO/IEC JTC 1/SC 27", "url": "https://www.iso.org/standard/24760-1", "version_or_date": "Edition published 2025 (supersedes ISO/IEC 24760-1:2019)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Authoritative vocabulary separating entity, identity, partial identity, attribute, identifier and reference identifier, plus identity register, identity information authority, relying party and the identity lifecycle. Full normative text is paywalled." }, { "id": "SRC-004", "title": "Core Person Vocabulary (CPV) 2.00", "organization": "European Commission, SEMIC / Interoperable Europe (formerly ISA2)", "url": "https://semiceu.github.io/Core-Person-Vocabulary/releases/2.00/", "version_or_date": "Version 2.00, 2022-04-01; namespace http://data.europa.eu/m8g", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Reference data model for people registers: name components including birth name, patronymic and matronymic, date and place of birth and death, gender, citizenship, domicile, plus Identifier with notation, scheme, issuing authority and issue date." }, { "id": "SRC-005", "title": "EUDI Wallet Architecture and Reference Framework, Annex 3.01 PID Rulebook", "organization": "European Commission, European Digital Identity Wallet consortium", "url": "https://eudi.dev/2.4.0/annexes/annex-3/annex-3.01-pid-rulebook/", "version_or_date": "ARF 2.4.0 (accessed 2026-08-23); earlier baseline ARF 1.2.0 / PID Rule Book 1.0.0, November 2023", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Concrete mandatory/optional person identification attribute set (family_name, given_name, birth_date, place_of_birth, nationality, expiry_date, issuing_authority, issuing_country mandatory; personal_administrative_number, portrait, sex, age_over_18, birth names optional) with issuer-defined identifier policy." }, { "id": "SRC-006", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Roles of issuer, holder, subject, verifier and verifiable data registry; credential properties including validFrom, validUntil, credentialStatus, credentialSchema and proof; warnings that subject identifiers increase correlatability." }, { "id": "SRC-007", "title": "Decentralized Identifiers (DIDs) v1.0", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/did-1.0/", "version_or_date": "W3C Recommendation, 19 July 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Governed global identifier option: DID syntax, DID subject versus DID controller, persistence and resolvability without a central registration authority, and documented DID correlation and privacy risks for persons." }, { "id": "SRC-008", "title": "NIST Special Publication 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment", "organization": "National Institute of Standards and Technology (NIST), U.S. Department of Commerce", "url": "https://csrc.nist.gov/pubs/sp/800/63/a/4/final", "version_or_date": "Revision 4, July 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Identity proofing and enrollment at three identity assurance levels, separating proofing from authenticator management, and framing evidence collection, validation and verification as recorded, assurance-bearing outcomes." }, { "id": "SRC-009", "title": "FHIR R5 Patient Resource", "organization": "Health Level Seven International (HL7)", "url": "https://hl7.org/fhir/patient.html", "version_or_date": "FHIR v5.0.0 (Release 5), Patient normative since R4", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Counterexample and boundary source: administrative demographics for care, explicit statement that one human may have several Patient records, and the link element (replaced-by, replaces, refer, seealso) as the deduplication mechanism instead of destructive merge." }, { "id": "SRC-010", "title": "schema.org Person", "organization": "schema.org (W3C Schema.org Community Group)", "url": "https://schema.org/Person", "version_or_date": "Version 30.0, 2026-03-19", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Widely deployed publication vocabulary for person data (name parts, birth/death date and place, gender, nationality, identifier, contact, relations). Used strictly as a lossy public projection target." }, { "id": "SRC-011", "title": "Regulation (EU) 2016/679 (General Data Protection Regulation)", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj", "version_or_date": "Regulation (EU) 2016/679 of 27 April 2016, OJ L 119, 4.5.2016", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Personal data and data subject definitions, accuracy and storage-limitation principles, special categories, and the rights of access, rectification, erasure, restriction, portability, objection and protection against solely automated decisions. EUR-Lex retrieval failed during this research; see SRC-012." }, { "id": "SRC-012", "title": "Art. 9 GDPR - Processing of special categories of personal data", "organization": "gdpr-info.eu (unofficial reproduction of Regulation (EU) 2016/679)", "url": "https://gdpr-info.eu/art-9-gdpr/", "version_or_date": "Reproduction of the 2016 consolidated text, accessed 2026-08-23", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Used only to verify the exact Article 9(1) special-category list after EUR-Lex retrieval failed. Not authoritative; the OJ text at SRC-011 governs." }, { "id": "SRC-013", "title": "ISO/IEC 5218:2022 Information technology - Codes for the representation of human sexes", "organization": "ISO/IEC JTC 1/SC 32", "url": "https://www.iso.org/standard/81682.html", "version_or_date": "Third edition, June 2022", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Code list 0 not known, 1 male, 2 female, 9 not applicable, with an explicit 2022 scope statement that human gender identities are not covered and no codes are provided for them." }, { "id": "SRC-014", "title": "Doc 9303, Machine Readable Travel Documents, Part 3: Specifications Common to all MRTDs", "organization": "International Civil Aviation Organization (ICAO)", "url": "https://store.icao.int/en/machine-readable-travel-documents-part-3-specifications-common-to-all-mrtds-doc-9303-3", "version_or_date": "Eighth Edition, 2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Machine-readable zone content, transliteration rules for names into the MRZ character set, truncation behaviour, and biometric image encoding referenced by identity documents. Full text is paywalled." }, { "id": "SRC-015", "title": "Convention on the Rights of Persons with Disabilities, Article 12 (Equal recognition before the law)", "organization": "United Nations / OHCHR", "url": "https://www.ohchr.org/en/instruments-mechanisms/instruments/convention-rights-persons-disabilities", "version_or_date": "Adopted 13 December 2006; in force 3 May 2008; General Comment No. 1 (2014)", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Requires recognition of legal capacity on an equal basis with others and a shift from substituted to supported decision-making respecting will and preferences, which constrains how capacity and guardianship may be modelled. Direct retrieval returned HTTP 403; Article 12(2) wording verified from quoting sources." }, { "id": "SRC-016", "title": "Customer Information Quality (CIQ) Specifications Version 3.0 - Name (xNL), Address (xAL) and Party (xPIL)", "organization": "OASIS Customer Information Quality Technical Committee", "url": "https://docs.oasis-open.org/ciq/v3.0/specs/ciq-specs-v3.html", "version_or_date": "Version 3.0, Committee Specification 02 (final release)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Reusable structured value shapes for person names and addresses designed for culture- and geography-specific formats, avoiding re-invention of name part and ordering semantics." }, { "id": "SRC-017", "title": "Guidelines on the Legislative Framework for Civil Registration, Vital Statistics and Identity Management Systems", "organization": "United Nations Department of Economic and Social Affairs, Statistics Division", "url": "https://digitallibrary.un.org/record/4010630", "version_or_date": "2023 (replaces the 1998 Handbook on Preparation of a Legal Framework)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T12:00:00Z", "relevance": "Legislative requirements for institutional arrangements, registrar authority, human-rights compliance, permanence of vital records, confidentiality, access control and quality procedures across civil registration and identity management." }, { "id": "SRC-018", "title": "Core Person Vocabulary (CPV) 2.1.2", "organization": "European Commission SEMIC / Interoperable Europe", "url": "https://semiceu.github.io/Core-Person-Vocabulary/releases/2.1.2/", "version_or_date": "2.1.2, SEMIC Recommendation, published 2026-05-12", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Defines Person as a non-imaginary natural person and a subclass of Agent, and supplies structured name, identifier, contact point, citizenship, domicile and residency properties while separating gender from biological sex." }, { "id": "SRC-019", "title": "United Nations Legal Identity Agenda — operational definition of legal identity", "organization": "United Nations Department of Economic and Social Affairs, Statistics Division", "url": "https://unstats.un.org/legal-identity-agenda/", "version_or_date": "UN LIA pages as retrieved 2026-08-23; definition used by UN Legal Identity Expert Group from 2018 onward", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Supplies the operational definition of legal identity, its conferral by birth registration or by a legally recognised identification authority linked to civil registration, its retirement by death registration, and the statelessness and refugee proof-of-identity cases." }, { "id": "SRC-020", "title": "Handbook on Civil Registration, Vital Statistics and Identity Management Systems: Communication for Development", "organization": "United Nations Statistics Division", "url": "https://unstats.un.org/unsd/demographic-social/Standards-and-Methods/files/Handbooks/crvs/CRVS-IdM-E.pdf", "version_or_date": "UN CRVS-IdM handbook aligned to Principles and Recommendations for a Vital Statistics System, Revision 3 (2014)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Frames civil registration as the continuous, permanent, compulsory and universal recording of vital events, the source of civil status and of vital statistics reuse." }, { "id": "SRC-021", "title": "ISO/IEC 24760-1:2019 IT Security and Privacy — A framework for identity management — Part 1: Terminology and concepts", "organization": "ISO/IEC JTC 1/SC 27", "url": "https://www.iso.org/obp/ui/#iso:std:iso-iec:24760:-1:ed-2:v1:en", "version_or_date": "ISO/IEC 24760-1:2019, second edition, May 2019, ISO standard 77582", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Supplies identity, attribute, identifier, principal and identity-proofing terminology, including its applicability to non-human principals, which bounds its use here to vocabulary alignment." }, { "id": "SRC-022", "title": "ICAO Doc 9303 Machine Readable Travel Documents, 8th edition", "organization": "International Civil Aviation Organization", "url": "https://www.icao.int/publications/doc-series/doc-9303", "version_or_date": "Doc 9303 8th edition; Part 3 common specifications and Part 4 TD3/MRP data elements, consolidated PDFs retrieved 2026-08-23", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Specifies travel-document evidence: MRZ and eMRTD data groups, primary and secondary name identifiers, Latin transliteration, the document sex field and nationality coding." }, { "id": "SRC-023", "title": "OASIS Customer Information Quality Specifications Version 3.0 — Name (xNL), Address (xAL), Name and Address (xNAL) and Party (xPIL)", "organization": "OASIS Customer Information Quality Technical Committee", "url": "https://docs.oasis-open.org/ciq/v3.0/cs02/specs/ciq-specs-v3-cs2.html", "version_or_date": "Committee Specification 02, 20 September 2008", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Supplies reusable structured name (xNL) and address (xAL) value shapes with customisable name-element semantics and a data-quality stance on unstructured name data." }, { "id": "SRC-024", "title": "Regulation (EU) No 910/2014 (eIDAS) as amended, and person identification data for European Digital Identity Wallets", "organization": "European Parliament and Council of the European Union; European Commission implementing acts on PID", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02014R0910-20241018", "version_or_date": "Consolidated eIDAS text 2024-10-18; CIR 2024/2977 PID attributes; eIDAS MDS family name, first name, date of birth, person identifier", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Supplies person identification data, the minimum data set, assurance levels, representation of a natural person and selective disclosure for electronic identification and the European Digital Identity Wallet." }, { "id": "SRC-025", "title": "UN Convention on the Rights of Persons with Disabilities, Article 12 — Equal recognition before the law", "organization": "United Nations Enable / UN DESA", "url": "https://www.un.org/development/desa/disabilities/convention-on-the-rights-of-persons-with-disabilities/article-12-equal-recognition-before-the-law.html", "version_or_date": "CRPD Article 12; Committee General Comment No. 1 (2014) CRPD/C/GC/1 used only to record the supported-decision-making interpretation conflict", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Supplies equal recognition before the law, legal capacity on an equal basis, access to support in exercising capacity and the safeguards that must be proportional, time-limited and independently reviewed." }, { "id": "SRC-026", "title": "Review — ISO/IEC 24760-1:2019", "organization": "IDPro Body of Knowledge", "url": "https://bok.idpro.org/article/id/18/print/", "version_or_date": "Scholefield, 2020, doi:10.55621/idpro.18; secondary reading of ISO/IEC 24760-1:2019 terms", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-08-23T00:00:00Z", "relevance": "Secondary reading of ISO/IEC 24760-1 terminology, used because the normative standard text is paywalled." } ], "structure": { "bundles": [ { "id": "civil-identity-core", "name": "Civil identity core", "description": "The registered identity itself: the anchor that other models reference, and the core attributes a registrar establishes and maintains about it.", "rationale": "UN guidance defines legal identity as basic characteristics conferred through registration; ISO/IEC 24760 separates the entity from the identity information held about it. The anchor plus its registered core attributes must therefore be one coherent, separately governed concern.", "source_refs": [ "SRC-002", "SRC-003", "SRC-001" ], "layers": [ { "id": "identity-anchor", "name": "Identity anchor and record identity", "description": "What the person entity is, how it is uniquely referenced within a domain, and how multiple records claiming the same person are reconciled.", "source_refs": [ "SRC-003", "SRC-009", "SRC-008" ], "findings": [ { "id": "person-identity-anchor", "name": "Person identity anchor", "description": "The natural person as a persistent entity distinct from any record, identifier, document or credential about them, carrying the reference identifier every other model points to.", "source_refs": [ "SRC-003", "SRC-002", "SRC-007" ], "questions": [ { "id": "q-anchor-reference-id", "text": "Which identifier is the reference identifier for this person, and which authority guarantees its persistence and non-reuse?", "kind": "identity", "answer_data": [ "reference identifier value pointer", "issuing authority reference", "persistence and non-reuse policy statement" ] }, { "id": "q-anchor-entity-vs-record", "text": "Does this record denote the natural person, or a registration record about the person?", "kind": "definition", "answer_data": [ "record subject kind code", "record-to-entity link", "registering system reference" ] }, { "id": "q-anchor-domain", "text": "Within which domain of applicability is this identity asserted unique and resolvable?", "kind": "classification", "answer_data": [ "domain of applicability name", "uniqueness assertion scope", "resolution endpoint or registry reference" ] }, { "id": "q-anchor-no-master-id", "text": "If no authoritative master-system identifier exists for this person, which fallback identifier is assigned, by whom, and why was the authoritative one unavailable?", "kind": "exception", "answer_data": [ "fallback identifier kind (governed IRI, UUID or ULID)", "assigning Dimension reference", "recorded reason the authoritative identifier is absent" ] } ], "data_elements": [ { "id": "de-person-reference-identifier", "name": "Person reference identifier", "description": "The single identifier that persistently references this person within the declared domain of applicability.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de-domain-of-applicability", "name": "Domain of applicability", "description": "The named domain within which the reference identifier is unique and the identity is meaningful.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-identifier-origin-class", "name": "Identifier origin class", "description": "Whether the reference identifier is an authoritative master-system identifier, a governed global identifier or a locally assigned surrogate.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] } ], "artifacts": [ { "id": "person-anchor-record", "name": "Person anchor record", "description": "The minimal governed record establishing the person as a referenceable entity, its reference identifier, origin class and domain of applicability.", "media_or_form": [ "structured record in the adopting store", "registry entry", "exported reference stub" ], "serial": false, "identity_strategy": "Keyed by the person reference identifier under identity priority: registrar identifier, then governed global identifier or IRI, then Dimension-assigned UUID or ULID.", "source_refs": [ "SRC-003", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "duplicate-detection-and-merge", "name": "Duplicate detection, merge and split", "description": "Several records may describe one person across systems; the model must express same-as links, merge, supersession and split without destroying history or silently unifying distinct people.", "source_refs": [ "SRC-009", "SRC-008", "SRC-017" ], "questions": [ { "id": "q-merge-link-type", "text": "Which other person records are asserted to denote the same natural person, and with what link type and direction?", "kind": "relationship", "answer_data": [ "linked record reference", "link type code (replaces, replaced-by, refer, see-also)", "asserting system reference" ] }, { "id": "q-merge-evidence", "text": "What evidence and matching threshold justified this merge, and which role authorised it?", "kind": "evidence", "answer_data": [ "matching attribute set and scores", "decision threshold applied", "authorising role and decision timestamp" ] }, { "id": "q-merge-reversal", "text": "How is an incorrect merge reversed, and what happens to identifiers and credentials issued under the superseded record?", "kind": "exception", "answer_data": [ "reversal procedure reference", "superseded identifier resolution policy", "downstream notification list" ] } ], "data_elements": [ { "id": "de-record-link", "name": "Person record link", "description": "A typed assertion that another person record denotes the same natural person, with direction and asserting system.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-match-confidence", "name": "Match confidence", "description": "Quantified confidence that two records denote the same person, with the algorithm or rule set version.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-surviving-record-ref", "name": "Surviving master record reference", "description": "The record that remains authoritative after a merge; the superseded record remains resolvable as a tombstone.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-017" ] } ], "artifacts": [ { "id": "record-linkage-decision", "name": "Record linkage decision record", "description": "Durable record of a merge, split or same-as assertion: inputs compared, confidence, threshold, authorising role, outcome and reversal path.", "media_or_form": [ "decision record", "audit trail entry" ], "serial": true, "identity_strategy": "Sequential decision identifier scoped to the registrar or operating authority, plus references to all affected person reference identifiers.", "source_refs": [ "SRC-009", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "alternative-registration-routes", "name": "Exceptional identity paths", "description": "UN LIA explicitly covers persons whose birth was not registered and refugees whose proof of legal identity may be issued by the host State or an internationally mandated authority. Statelessness is a named UN LIA concern. National CRVS practice also includes foundlings, unknown parentage, incomplete dates, delayed registration and, in some jurisdictions, presumed death and later identity restoration. Those last national cases are recorded here as operating needs with incomplete global normative detail.", "source_refs": [ "SRC-019", "SRC-020" ], "questions": [ { "id": "alternative-registration-routes-q01", "text": "Is proof of legal identity issued by a host State or by an internationally mandated authority for a refugee or similar status, and how does it link to this person?", "kind": "exception", "answer_data": [ "proof-issuer-kind (host-state | internationally-mandated-authority)", "issuer-id", "credential-type", "person-id", "issued-at (RFC 3339)", "national-law-recognition (boolean)" ] }, { "id": "alternative-registration-routes-q02", "text": "Was this identity opened for a foundling or person of unknown parentage, and which placeholder name and birth facts were assigned?", "kind": "exception", "answer_data": [ "foundling-or-unknown-parentage (boolean)", "assigned-name", "assigned-birth-date-or-estimate", "assigned-place", "legal-basis-ref", "later-rectification-id" ] }, { "id": "alternative-registration-routes-q03", "text": "Has legal identity been retired by presumed death or later restored, and what is the current vital status?", "kind": "lifecycle", "answer_data": [ "presumed-death-order-id", "presumed-death-at (RFC 3339)", "restored (boolean)", "restoration-order-id", "current-vital-status", "gap-flag (global-norm-incomplete)" ] } ], "data_elements": [ { "id": "alternative-registration-routes-data01", "name": "Proof of identity issuer kind", "description": "Host State versus internationally mandated authority for refugees.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019" ] }, { "id": "alternative-registration-routes-data02", "name": "Foundling or unknown parentage flag", "description": "Marks identities opened without ordinary parental birth facts.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "alternative-registration-routes-data03", "name": "Presumed-death order", "description": "National court or registrar instrument; global UN LIA text does not specify this path.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020" ] } ], "artifacts": [ { "id": "alternative-registration-routes-artifact01", "name": "Refugee or mandated identity credential", "description": "Proof of legal identity issued by a State or internationally mandated authority.", "media_or_form": [ "identity credential", "card or attestation" ], "serial": true, "identity_strategy": "Issuer-assigned credential number qualified by the host State or internationally mandated authority that issued it.", "source_refs": [ "SRC-019" ] } ], "inline_only_rationale": null } ] }, { "id": "registered-core-attributes", "name": "Registered core attributes", "description": "The attributes a civil registrar establishes and maintains: legal names over time, birth facts, and the administratively recorded sex or legally recognised gender.", "source_refs": [ "SRC-001", "SRC-004", "SRC-013" ], "findings": [ { "id": "legal-name-versioning", "name": "Legal name as a versioned structured fact", "description": "Legal name is a time-bounded, structured, script-bearing fact with an ordering convention, not a fixed string attribute of the person.", "source_refs": [ "SRC-004", "SRC-016", "SRC-001" ], "questions": [ { "id": "q-name-structure", "text": "What are the structured parts of this name and which cultural convention orders and formats them?", "kind": "composition", "answer_data": [ "name part values by role (given, family, patronymic, matronymic, prefix, suffix)", "ordering convention code", "formatted full-name rendering" ] }, { "id": "q-name-validity", "text": "Over which validity period was this the person's legal name, and which instrument changed it?", "kind": "temporal", "answer_data": [ "validity start date and end date", "name-change instrument reference", "registering authority reference" ] }, { "id": "q-name-role", "text": "Is this a birth name, current legal name, former name or alias, and who may assert each?", "kind": "classification", "answer_data": [ "name role code", "asserting party class", "registrar warranty flag" ] }, { "id": "q-name-script", "text": "In which script and encoding is the name recorded, and which transliteration is authoritative for machine-readable use?", "kind": "interoperability", "answer_data": [ "script code and character encoding", "authoritative transliteration value", "transliteration rule set reference" ] } ], "data_elements": [ { "id": "de-name-part", "name": "Name part", "description": "One structured component of a name with its role, value and sequence position under the declared ordering convention.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-016", "SRC-004" ] }, { "id": "de-name-role", "name": "Name role", "description": "Classifies the name as birth name, current legal name, former legal name or alias.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-name-validity-period", "name": "Name validity period", "description": "The period during which this name form was the person's legal name.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-name-script-code", "name": "Name script code", "description": "Writing system in which the name is recorded, distinguishing native-script and transliterated forms.", "value_kind": "code", "cardinality": "1..n", "required": false, "source_refs": [ "SRC-014", "SRC-016" ] } ], "artifacts": [ { "id": "name-change-instrument", "name": "Name change instrument reference", "description": "Reference to the registration act, court order or administrative decision that established a new legal name and its effective date.", "media_or_form": [ "registration act reference", "court or administrative decision reference", "certified extract" ], "serial": false, "identity_strategy": "Identified by the issuing authority's act identifier; never by the name value or the change date.", "source_refs": [ "SRC-001", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "birth-facts-record", "name": "Registered birth facts", "description": "Date, precision, place and, where recorded, time of birth as registered, plus multiple-birth order, distinguished from the place and date of registration.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "q-birth-date-precision", "text": "What is the registered date of birth and at what precision is it known?", "kind": "temporal", "answer_data": [ "birth date value", "precision code (day, month, year, estimated)", "estimation basis where the date is approximate" ] }, { "id": "q-birth-place", "text": "What is the registered place of birth, at which administrative granularity, and does it differ from the place of registration?", "kind": "spatial", "answer_data": [ "place of birth reference and granularity", "place of registration reference", "country code of occurrence" ] }, { "id": "q-birth-multiple", "text": "Was this birth part of a multiple birth, and what birth order was registered?", "kind": "measurement", "answer_data": [ "multiple birth indicator", "birth order number", "total births in the delivery where recorded" ] }, { "id": "q-birth-correction", "text": "Which registration act established these facts, and how must a correction to them be evidenced?", "kind": "provenance", "answer_data": [ "birth registration act reference", "registrar reference", "correction evidence requirement" ] } ], "data_elements": [ { "id": "de-birth-date", "name": "Date of birth", "description": "Registered day, month and year of birth, held as a date rather than a timestamp.", "value_kind": "date", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de-birth-date-precision", "name": "Birth date precision", "description": "Declared precision or estimation status of the birth date, required where full dates are unknown.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-birth-place-ref", "name": "Place of birth reference", "description": "Pointer to the place of birth resolved in the place model, with the recorded administrative granularity.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-001" ] }, { "id": "de-multiple-birth-order", "name": "Multiple birth order", "description": "Birth order within a multiple delivery, where registered.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-009" ] } ], "artifacts": [ { "id": "birth-registration-extract", "name": "Birth registration extract", "description": "Certified extract of the birth registration evidencing the registered birth facts and the registering authority.", "media_or_form": [ "certified extract", "registry record reference", "electronic attestation" ], "serial": true, "identity_strategy": "Identified by the civil register's act or entry number and the registering authority; the birth date is never the identifier.", "source_refs": [ "SRC-001", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "sex-and-gender-recording", "name": "Sex and gender recording", "description": "Administratively recorded sex, legal gender recognition and self-identified gender are three distinct values with different code lists, owners and disclosure rules.", "source_refs": [ "SRC-013", "SRC-005", "SRC-010" ], "questions": [ { "id": "q-sex-code-list", "text": "Which code list and version encodes the administratively recorded sex, and what does each value mean in that list?", "kind": "classification", "answer_data": [ "code list reference and version", "code value", "value meaning in the issuing jurisdiction" ] }, { "id": "q-gender-self-declared", "text": "Is a self-identified gender recorded separately from administrative sex, and who controls that value?", "kind": "ownership", "answer_data": [ "self-identified gender value", "controlling party", "registrar warranty flag (self-declared, not registered)" ] }, { "id": "q-gender-recognition", "text": "Has a legal gender recognition changed the registered value, and from which date does the change take effect?", "kind": "lifecycle", "answer_data": [ "prior and new registered value", "recognition decision reference", "effective date of the change" ] }, { "id": "q-gender-disclosure", "text": "Which of these values may be disclosed to which relying-party class, given the sensitivity of gender data?", "kind": "privacy", "answer_data": [ "per-value disclosure rule", "relying-party class", "lawful condition for release" ] } ], "data_elements": [ { "id": "de-administrative-sex-code", "name": "Administrative sex code", "description": "Coded sex as recorded by the register, always accompanied by the code list reference and version.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-005" ] }, { "id": "de-self-identified-gender", "name": "Self-identified gender", "description": "Gender as declared by the person, held in the personal sphere and carrying no registrar warranty.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-013" ] }, { "id": "de-gender-recognition-effective-date", "name": "Gender recognition effective date", "description": "Date from which a legally recognised change of registered sex or gender takes effect.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-017" ] } ], "artifacts": [ { "id": "gender-recognition-decision", "name": "Gender recognition decision reference", "description": "Reference to the administrative or judicial decision that changed the registered value, retained as evidence of the transition.", "media_or_form": [ "decision reference", "certified extract" ], "serial": false, "identity_strategy": "Identified by the deciding authority's case or act identifier.", "source_refs": [ "SRC-017", "SRC-001" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "identifiers-and-evidence", "name": "Identifiers and evidence", "description": "Scheme-qualified identifiers assigned to the person, the documents and attestations that evidence identity, and the assurance produced by proofing.", "rationale": "ISO/IEC 24760 separates identifier from identity; UN legal-identity guidance treats documents as proof of a registered identity rather than the identity itself; NIST separates the proofing outcome from the resulting credentials. These three must be modelled as evidence about the anchor, never as the anchor.", "source_refs": [ "SRC-003", "SRC-002", "SRC-008", "SRC-006" ], "layers": [ { "id": "identifier-schemes", "name": "Identifier schemes and correlation", "description": "How identifiers are assigned under named schemes with authorities and validity, and how their correlation properties are governed.", "source_refs": [ "SRC-004", "SRC-003", "SRC-007" ], "findings": [ { "id": "identifier-assignment", "name": "Scheme-qualified identifier assignment", "description": "An identifier attaches to the person under a named scheme with an assigning authority, validity period, format rule and reuse policy, without becoming the person.", "source_refs": [ "SRC-004", "SRC-003", "SRC-005" ], "questions": [ { "id": "q-ident-scheme", "text": "Under which named scheme was this identifier assigned, and by which authority?", "kind": "authority", "answer_data": [ "scheme name and version", "assigning authority reference", "scheme governing jurisdiction" ] }, { "id": "q-ident-validity", "text": "What is the identifier's validity period, and may it be revoked, reissued or reused for a different person?", "kind": "lifecycle", "answer_data": [ "validity start and end", "revocation state and reason", "reuse policy code" ] }, { "id": "q-ident-role", "text": "Is this identifier a reference identifier for the person or a scoped, derived or sector-limited identifier?", "kind": "classification", "answer_data": [ "identifier role code", "scope of applicability", "relationship to the reference identifier" ] }, { "id": "q-ident-validation", "text": "Which format, checksum or registry lookup validates this identifier value?", "kind": "validation", "answer_data": [ "format or pattern rule", "check-digit algorithm", "authoritative verification endpoint or procedure" ] } ], "data_elements": [ { "id": "de-identifier-scheme", "name": "Identifier scheme name", "description": "The named scheme under which the identifier was issued, qualified by its governing authority.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-003" ] }, { "id": "de-identifier-value-pointer", "name": "Identifier value pointer", "description": "Pointer to the identifier value, held so it can be withheld from projections that do not need it.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-006" ] }, { "id": "de-identifier-reuse-policy", "name": "Identifier reuse policy", "description": "Whether the scheme permits reassignment of a retired identifier value to another person.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "identifier-assignment-record", "name": "Identifier assignment record", "description": "Record of one identifier assignment: scheme, authority, value pointer, validity, revocation state and reuse policy.", "media_or_form": [ "structured record", "registry entry" ], "serial": true, "identity_strategy": "Composite of scheme name plus authority reference plus assignment sequence; the identifier value itself is a pointer, not the record key.", "source_refs": [ "SRC-004", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "identifier-correlation", "name": "Identifier correlation and pseudonymity", "description": "Cross-domain identifiers make a person correlatable across contexts; the model must record correlatability class and any pairwise or sector-specific pseudonym derivation.", "source_refs": [ "SRC-007", "SRC-006", "SRC-011" ], "questions": [ { "id": "q-corr-class", "text": "Which of this person's identifiers are correlatable across domains, and what harm follows from that linkage?", "kind": "privacy", "answer_data": [ "correlatability class per identifier", "known linkage surfaces", "assessed harm and mitigation" ] }, { "id": "q-corr-pseudonym", "text": "Where a pairwise or sector-specific pseudonym is required, how is it derived, scoped and rotated?", "kind": "security", "answer_data": [ "derivation method reference", "scope binding (relying party or sector)", "rotation trigger and period" ] }, { "id": "q-corr-omission", "text": "Which identifiers may be omitted entirely from a given presentation without breaking verification?", "kind": "access", "answer_data": [ "omissible identifier list per projection", "verification method that survives omission", "residual risk note" ] } ], "data_elements": [ { "id": "de-correlatability-class", "name": "Identifier correlatability class", "description": "Classifies an identifier as globally correlatable, sector-scoped, pairwise or single-use.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-006" ] }, { "id": "de-pseudonym-derivation", "name": "Pseudonym derivation method", "description": "Reference to the documented derivation and rotation method for scoped pseudonymous identifiers.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "pseudonymous-identifier-policy", "name": "Pseudonymous identifier policy statement", "description": "Published statement of which identifier classes are used for which relying-party classes, with derivation, scoping and rotation rules.", "media_or_form": [ "policy statement", "published specification section" ], "serial": false, "identity_strategy": "Identified by the owning Dimension's policy identifier and version.", "source_refs": [ "SRC-007", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "identity-evidence-and-assurance", "name": "Identity evidence and assurance", "description": "Issued documents and electronic attestations that evidence identity, and the proofing process that produces an assurance level.", "source_refs": [ "SRC-008", "SRC-006", "SRC-014", "SRC-005" ], "findings": [ { "id": "issued-identity-evidence", "name": "Issued identity evidence", "description": "Physical documents and electronic attestations evidence a registered identity and assert a subset of attributes; they never constitute the person and their revocation does not revoke the person.", "source_refs": [ "SRC-006", "SRC-014", "SRC-005", "SRC-002" ], "questions": [ { "id": "q-evid-type-issuer", "text": "What type of evidence is this, who issued it, and over which validity period?", "kind": "evidence", "answer_data": [ "evidence type code", "issuer reference", "validFrom and validUntil values" ] }, { "id": "q-evid-status", "text": "What is its current status: valid, expired, suspended, revoked, lost or stolen, and where is that status published?", "kind": "state", "answer_data": [ "status code and effective time", "status reason", "status list or revocation endpoint reference" ] }, { "id": "q-evid-attributes", "text": "Which person attributes does this evidence assert, and which of those are authoritative rather than copied from another source?", "kind": "provenance", "answer_data": [ "asserted attribute set", "per-attribute authoritativeness flag", "upstream source reference for copied attributes" ] }, { "id": "q-evid-binding", "text": "How is the evidence bound to the holder, cryptographically or physically?", "kind": "security", "answer_data": [ "holder binding method code", "binding proof reference", "binding strength assessment" ] } ], "data_elements": [ { "id": "de-evidence-type", "name": "Evidence type", "description": "Kind of identity evidence, such as travel document, national identity card, civil extract or electronic attestation.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-005" ] }, { "id": "de-evidence-status", "name": "Evidence status", "description": "Current lifecycle status of the evidence with its effective time and reason.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-asserted-attribute-set", "name": "Asserted attribute set", "description": "The person attributes this evidence carries, each flagged as authoritative or copied.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "de-holder-binding-method", "name": "Holder binding method", "description": "How the evidence is bound to the person presenting it, for example portrait, biometric match or key-bound proof.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-014" ] } ], "artifacts": [ { "id": "identity-document-record", "name": "Identity document record", "description": "Record of an issued physical identity document with issuer, number reference, validity, machine-readable form and status.", "media_or_form": [ "document record", "machine-readable zone data", "scanned image reference" ], "serial": true, "identity_strategy": "Composite of issuing authority plus document number plus issuance date; number alone is not unique across authorities.", "source_refs": [ "SRC-014", "SRC-005" ] }, { "id": "verifiable-attestation", "name": "Verifiable attestation", "description": "Electronic credential asserting person attributes, with issuer, validity window, status mechanism, schema reference and proof.", "media_or_form": [ "verifiable credential", "person identification data attestation" ], "serial": false, "identity_strategy": "Identified by the credential identifier assigned by the issuer, resolvable against the issuer's status list.", "source_refs": [ "SRC-006", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "identity-proofing-assurance", "name": "Identity proofing and assurance", "description": "The recorded outcome of resolving, validating and verifying a claimed identity against evidence, expressed as an assurance level with an expiry and an optional biometric reference.", "source_refs": [ "SRC-008", "SRC-003", "SRC-014" ], "questions": [ { "id": "q-proof-level", "text": "At which identity assurance level was this person proofed, and against which published criteria and version?", "kind": "quality", "answer_data": [ "assurance level value", "criteria document reference and version", "assessing party reference" ] }, { "id": "q-proof-steps", "text": "Which resolution, validation and verification steps were performed, and with what outcome for each?", "kind": "process", "answer_data": [ "step list with outcomes", "evidence items used per step", "failure or fallback notes" ] }, { "id": "q-proof-biometric", "text": "Which biometric reference, if any, was captured, in which encoding, and where is it stored?", "kind": "measurement", "answer_data": [ "biometric modality and encoding standard", "reference storage location or pointer", "capture quality score" ] }, { "id": "q-proof-expiry", "text": "When does this proofing outcome expire or require re-proofing, and what event forces early re-proofing?", "kind": "temporal", "answer_data": [ "proofing timestamp", "re-proofing due date", "re-proofing trigger events" ] } ], "data_elements": [ { "id": "de-assurance-level", "name": "Identity assurance level", "description": "Assurance level attained by the proofing process, qualified by the criteria set that defines it.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-proofing-step-outcome", "name": "Proofing step outcome", "description": "Per-step record of resolution, validation and verification with evidence used and result.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-biometric-reference-ref", "name": "Biometric reference pointer", "description": "Pointer to a stored biometric reference and its encoding standard; the biometric data itself is never inlined.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014", "SRC-011" ] } ], "artifacts": [ { "id": "proofing-assessment-record", "name": "Identity proofing assessment record", "description": "Durable record of a proofing event: criteria, evidence, steps, outcomes, assurance level, assessor and timestamps.", "media_or_form": [ "assessment record", "audit evidence package" ], "serial": true, "identity_strategy": "Sequential assessment identifier scoped to the credential service provider, linked to the person reference identifier.", "source_refs": [ "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "legal-standing", "name": "Legal standing", "description": "The person's status in law: civil status, nationality or statelessness, legal capacity and any representation or support arrangement.", "rationale": "UN vital-statistics guidance makes civil status a registered legal fact; legal identity and nationality are the basis for document issuance; the CRPD constrains how capacity and representation may be recorded. Each is a separately governed legal state, not a demographic attribute.", "source_refs": [ "SRC-001", "SRC-002", "SRC-015", "SRC-017" ], "layers": [ { "id": "civil-status", "name": "Civil status", "description": "The registered civil or marital status, its effective date, governing jurisdiction and causing act.", "source_refs": [ "SRC-001", "SRC-017" ], "findings": [ { "id": "civil-status-registration", "name": "Registered civil status", "description": "One current registered civil status per person with an effective date and governing jurisdiction; history is carried by the acts that changed it, not by overwriting the value.", "source_refs": [ "SRC-001", "SRC-017", "SRC-009" ], "questions": [ { "id": "q-status-current", "text": "What is the currently registered civil status, from which effective date, and under which jurisdiction's law?", "kind": "state", "answer_data": [ "civil status code and code list reference", "effective date", "governing jurisdiction code" ] }, { "id": "q-status-cause", "text": "Which registered act caused the most recent change of civil status?", "kind": "event", "answer_data": [ "causing act type (marriage, divorce, annulment, judicial separation, death of spouse)", "act reference in the vital-event model", "registering authority reference" ] }, { "id": "q-status-foreign", "text": "How is a civil status established under foreign law recognised here, and what evidence is required?", "kind": "exception", "answer_data": [ "recognition procedure reference", "required evidence set", "recognition decision and date" ] } ], "data_elements": [ { "id": "de-civil-status-code", "name": "Civil status code", "description": "Registered civil or marital status value, qualified by the national code list it comes from.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "de-civil-status-effective-date", "name": "Civil status effective date", "description": "Date from which the current civil status took legal effect, distinct from its registration date.", "value_kind": "date", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-civil-status-jurisdiction", "name": "Governing jurisdiction", "description": "Jurisdiction whose law governs the meaning and effects of the recorded status.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-017" ] } ], "artifacts": [ { "id": "civil-status-extract", "name": "Civil status extract", "description": "Certified extract evidencing the registered civil status, its effective date and the causing act.", "media_or_form": [ "certified extract", "registry record reference" ], "serial": true, "identity_strategy": "Identified by the register act or entry number plus the issuing registrar.", "source_refs": [ "SRC-001", "SRC-017" ] } ], "inline_only_rationale": null } ] }, { "id": "nationality-and-statelessness", "name": "Nationality and statelessness", "description": "Nationalities held, their basis and dates, and the distinct determination of statelessness or undetermined nationality.", "source_refs": [ "SRC-005", "SRC-004", "SRC-002" ], "findings": [ { "id": "nationality-holding", "name": "Nationality holding", "description": "Zero, one or several nationalities held by the person, each with a coding, acquisition basis, dates and conferring authority.", "source_refs": [ "SRC-005", "SRC-004", "SRC-010" ], "questions": [ { "id": "q-nat-codes", "text": "Which nationalities does the person hold, in which coding scheme, and from which dates?", "kind": "identity", "answer_data": [ "nationality country code and coding scheme", "acquisition date", "loss or renunciation date where applicable" ] }, { "id": "q-nat-authority", "text": "Which authority conferred or withdrew each nationality, and on what legal basis?", "kind": "authority", "answer_data": [ "conferring or withdrawing authority reference", "legal basis code (birth, descent, naturalisation, other)", "decision reference" ] }, { "id": "q-nat-governing", "text": "Where several nationalities are held, which one governs a given official interaction?", "kind": "decision", "answer_data": [ "governing nationality per interaction context", "selection rule reference", "evidence presented" ] } ], "data_elements": [ { "id": "de-nationality-code", "name": "Nationality code", "description": "Country code identifying a nationality held, with the coding scheme and version stated.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de-nationality-basis", "name": "Nationality acquisition basis", "description": "Legal ground on which the nationality was acquired or withdrawn.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-017" ] } ], "artifacts": [ { "id": "nationality-evidence-reference", "name": "Nationality evidence reference", "description": "Pointer to the naturalisation decision, passport issuance or civil-register entry evidencing a nationality.", "media_or_form": [ "decision reference", "document record reference" ], "serial": false, "identity_strategy": "Identified by the conferring authority's decision or document identifier.", "source_refs": [ "SRC-005", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "statelessness-determination", "name": "Statelessness and undetermined nationality", "description": "Determined statelessness, undetermined nationality and simply unrecorded nationality are three different states with different consequences for document issuance.", "source_refs": [ "SRC-002", "SRC-017", "SRC-005" ], "questions": [ { "id": "q-stateless-status", "text": "Is the person determined stateless, of undetermined nationality, or is nationality merely unrecorded?", "kind": "classification", "answer_data": [ "nationality determination status code", "basis for the classification", "date of assessment" ] }, { "id": "q-stateless-authority", "text": "Which authority made the determination, when, and under which procedure?", "kind": "authority", "answer_data": [ "determining authority reference", "procedure reference", "determination decision identifier and date" ] }, { "id": "q-stateless-substitute", "text": "Which substitute documents or registration routes establish legal identity where no nationality-based document exists?", "kind": "exception", "answer_data": [ "substitute document references", "alternative registration route", "validity and renewal conditions" ] } ], "data_elements": [ { "id": "de-nationality-determination-status", "name": "Nationality determination status", "description": "Explicit status distinguishing determined statelessness, undetermined nationality and unrecorded nationality.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-017" ] }, { "id": "de-substitute-document-ref", "name": "Substitute identity document reference", "description": "Pointer to a document issued in place of a nationality-based identity document.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-017" ] } ], "artifacts": [ { "id": "statelessness-determination-record", "name": "Statelessness determination record", "description": "Record of the determination procedure, evidence considered, outcome, authority and review date.", "media_or_form": [ "determination record", "decision reference" ], "serial": true, "identity_strategy": "Sequential case identifier scoped to the determining authority, linked to the person reference identifier.", "source_refs": [ "SRC-002", "SRC-017" ] } ], "inline_only_rationale": null } ] }, { "id": "capacity-and-representation", "name": "Legal capacity and representation", "description": "The person's legal capacity state and any arrangement by which another party supports or acts for them.", "source_refs": [ "SRC-015", "SRC-017" ], "findings": [ { "id": "legal-capacity-state", "name": "Legal capacity state", "description": "Capacity is a time-bounded, domain-scoped legal state established by a legal act, with equal recognition before the law as the default and restriction as the evidenced exception.", "source_refs": [ "SRC-015", "SRC-017", "SRC-001" ], "questions": [ { "id": "q-cap-state", "text": "What is the person's legal capacity state, over which effective period, and for which domains of action?", "kind": "state", "answer_data": [ "capacity class code", "effective period", "list of scoped domains affected" ] }, { "id": "q-cap-basis", "text": "Which legal act or judgment established, restricted or restored capacity?", "kind": "authority", "answer_data": [ "deciding authority reference", "act or judgment identifier", "legal basis cited" ] }, { "id": "q-cap-review", "text": "Is any restriction general or limited to specified matters, and when is it reviewed?", "kind": "constraint", "answer_data": [ "restriction scope (general or limited)", "enumerated restricted matters", "review due date and reviewing body" ] } ], "data_elements": [ { "id": "de-capacity-class", "name": "Capacity class", "description": "Coded legal capacity state, defaulting to full capacity where no restricting act exists.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] }, { "id": "de-capacity-scope", "name": "Capacity restriction scope", "description": "Enumerated domains of action to which a restriction applies; empty means unrestricted.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-017" ] }, { "id": "de-capacity-effective-period", "name": "Capacity effective period", "description": "Period during which the recorded capacity state applies, with review date where required.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] } ], "artifacts": [ { "id": "capacity-determination-record", "name": "Capacity determination record", "description": "Record of the act or judgment establishing, restricting or restoring legal capacity, with its scope and review terms.", "media_or_form": [ "judgment reference", "administrative decision record" ], "serial": true, "identity_strategy": "Identified by the deciding authority's case identifier; linked to the person reference identifier.", "source_refs": [ "SRC-015", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "representation-arrangement", "name": "Representation and support arrangement", "description": "An arrangement by which a person or organization supports or acts for the person, distinguishing supported from substituted decision-making and recording the person's own will and preferences.", "source_refs": [ "SRC-015", "SRC-017", "SRC-009" ], "questions": [ { "id": "q-rep-who", "text": "Who acts for or supports the person, in which capacity, and with what scope of authority?", "kind": "authority", "answer_data": [ "representative reference (person or organization)", "representation capacity code", "enumerated scope of authority" ] }, { "id": "q-rep-type", "text": "Is the arrangement supported decision-making or substituted decision-making, and how is that recorded?", "kind": "classification", "answer_data": [ "arrangement type code", "legal basis reference", "safeguards recorded" ] }, { "id": "q-rep-period", "text": "When does the arrangement start, end or require renewal, and who may terminate it?", "kind": "lifecycle", "answer_data": [ "start and end dates", "renewal condition", "parties entitled to terminate" ] }, { "id": "q-rep-will", "text": "How are the person's own expressed will and preferences recorded alongside the representative's acts?", "kind": "evidence", "answer_data": [ "will and preference statement reference", "date and method of capture", "conflict resolution note" ] } ], "data_elements": [ { "id": "de-representative-ref", "name": "Representative reference", "description": "Pointer to the representing or supporting party, resolved in the person or organization model.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-015", "SRC-009" ] }, { "id": "de-representation-type", "name": "Representation type", "description": "Whether the arrangement is supported or substituted decision-making.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] }, { "id": "de-authority-scope", "name": "Scope of representative authority", "description": "Enumerated matters over which the representative may act.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-015", "SRC-017" ] } ], "artifacts": [ { "id": "representation-mandate", "name": "Representation mandate record", "description": "The mandate, order or power of attorney establishing the arrangement, its scope, safeguards and duration.", "media_or_form": [ "mandate document reference", "court order reference", "registered power of attorney" ], "serial": true, "identity_strategy": "Identified by the issuing authority or notary reference plus mandate number.", "source_refs": [ "SRC-015", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "life-course", "name": "Life course", "description": "The person through time: anchors to registered life events, the separation of occurrence time from record time, vital status and the lifecycle of the identity record itself.", "rationale": "Civil registration is defined as continuous recording of vital events from birth to death, with occurrence and registration consistently distinguished; ISO/IEC 24760 frames identity as passing through lifecycle states. Time handling is therefore a first-class concern, not an implementation detail.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "layers": [ { "id": "life-event-anchoring", "name": "Life event anchoring and time", "description": "How registered life events attach to the person and how occurrence, registration and ingestion times are kept apart.", "source_refs": [ "SRC-001", "SRC-017" ], "findings": [ { "id": "life-event-anchor", "name": "Vital and registered life event anchor", "description": "The person carries typed anchors to life events resolved in the vital-event model, together with the role the person played in each event.", "source_refs": [ "SRC-001", "SRC-017", "SRC-002" ], "questions": [ { "id": "q-event-anchors", "text": "Which vital or registered life events anchor to this person, and in which model does each event resolve?", "kind": "relationship", "answer_data": [ "event anchor references", "event type codes", "resolving model reference per anchor" ] }, { "id": "q-event-role", "text": "What role does the person play in each anchored event: subject, parent, spouse, informant or declarant?", "kind": "classification", "answer_data": [ "role code per anchor", "role evidence reference", "role validity" ] }, { "id": "q-event-required", "text": "Which anchors are mandatory for a complete civil identity in this jurisdiction, and which are optional?", "kind": "requirement", "answer_data": [ "mandatory anchor list", "optional anchor list", "jurisdiction reference" ] } ], "data_elements": [ { "id": "de-event-anchor-ref", "name": "Life event anchor reference", "description": "Typed pointer to a registered event record held in the vital-event model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-person-role-in-event", "name": "Person role in event", "description": "The capacity in which the person participates in the anchored event.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-017" ] } ], "artifacts": [ { "id": "life-event-anchor-index", "name": "Life event anchor index", "description": "The person-side index of event anchors with types, roles and resolving model references, produced for navigation without copying event content.", "media_or_form": [ "index record", "navigation projection" ], "serial": false, "identity_strategy": "Keyed by the person reference identifier; each entry keyed by the external event identifier.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "event-time-versus-record-time", "name": "Occurrence time versus record time", "description": "Every person fact carries a time of occurrence, a time of registration and a time of ingestion; conflating them corrupts history and prevents lawful correction.", "source_refs": [ "SRC-001", "SRC-006", "SRC-017" ], "questions": [ { "id": "q-time-three", "text": "What are the occurrence time, the registration time and the ingestion time for this fact, and are they stored separately?", "kind": "temporal", "answer_data": [ "occurrence date or timestamp", "registration timestamp", "observation or ingestion timestamp" ] }, { "id": "q-time-format", "text": "Which values carry an explicit UTC offset or Z, and which are deliberately dates without a time zone?", "kind": "validation", "answer_data": [ "per-field temporal type", "offset or Z value where applicable", "precision declaration for date-only facts" ] }, { "id": "q-time-late", "text": "How are late, retroactive or back-dated registrations represented without rewriting existing history?", "kind": "provenance", "answer_data": [ "effective period of the new assertion", "superseded assertion reference", "reason for late registration" ] }, { "id": "q-time-conflict", "text": "Which time value governs when two sources disagree about when a fact took effect?", "kind": "decision", "answer_data": [ "precedence rule reference", "governing source", "recorded discrepancy note" ] } ], "data_elements": [ { "id": "de-occurrence-time", "name": "Occurrence time", "description": "When the fact actually happened, as a date or an RFC 3339 timestamp with explicit offset, with precision stated.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "de-registration-time", "name": "Registration time", "description": "When the authority registered the fact, as an RFC 3339 timestamp with explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-017" ] }, { "id": "de-ingestion-time", "name": "Observation or ingestion time", "description": "When this system observed or ingested the assertion, recorded separately from occurrence and registration.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-008" ] }, { "id": "de-effective-period", "name": "Assertion effective period", "description": "The period during which the asserted value is held to be true, enabling supersession without deletion.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-004" ] } ], "artifacts": [ { "id": "bitemporal-change-log-entry", "name": "Bitemporal change log entry", "description": "One entry recording a value change with occurrence, registration and ingestion times, the superseded assertion and the change reason.", "media_or_form": [ "change log entry", "audit trail record" ], "serial": true, "identity_strategy": "Monotonic sequence per person record, timestamped in RFC 3339 with explicit offset.", "source_refs": [ "SRC-001", "SRC-017" ] } ], "inline_only_rationale": null } ] }, { "id": "vital-status-and-record-lifecycle", "name": "Vital status and record lifecycle", "description": "Whether the person is living, deceased or presumed dead, and which lifecycle state the identity record itself occupies.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ], "findings": [ { "id": "vital-status-and-death", "name": "Vital status and death registration", "description": "Vital status is an evidenced state; registered death, judicially declared death and presumed death are distinct and must not be collapsed.", "source_refs": [ "SRC-001", "SRC-017", "SRC-009" ], "questions": [ { "id": "q-vital-status", "text": "What is the person's current vital status and what evidence supports it?", "kind": "state", "answer_data": [ "vital status code", "evidence reference", "status assertion timestamp" ] }, { "id": "q-death-facts", "text": "For a registered death, what are the date, time and place of death, and how do they differ from the date and place of registration?", "kind": "temporal", "answer_data": [ "date and time of death with precision", "place of death reference", "date and place of registration" ] }, { "id": "q-death-presumed", "text": "How is a presumed or judicially declared death represented differently from a registered death?", "kind": "exception", "answer_data": [ "determination basis code", "declaring authority and decision reference", "reversal procedure if the person is found living" ] }, { "id": "q-death-downstream", "text": "Which downstream references, identifiers and credentials must be notified or closed when death is registered?", "kind": "process", "answer_data": [ "notification target list", "credential and identifier closure actions", "closure completion evidence" ] } ], "data_elements": [ { "id": "de-vital-status-code", "name": "Vital status code", "description": "Living, deceased, presumed deceased or unknown, with the evidence basis recorded.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "de-death-date", "name": "Date of death", "description": "Registered date of death, held separately from the date of death registration.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "de-death-determination-basis", "name": "Death determination basis", "description": "Whether death was medically certified, judicially declared or presumed, with the deciding authority.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-017" ] } ], "artifacts": [ { "id": "death-registration-extract", "name": "Death registration extract", "description": "Certified extract evidencing the registered death, its date and place, and the registering authority; cause of death is excluded from this model.", "media_or_form": [ "certified extract", "registry record reference" ], "serial": true, "identity_strategy": "Identified by the death register act or entry number plus registering authority.", "source_refs": [ "SRC-001", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "identity-record-lifecycle", "name": "Identity record lifecycle state", "description": "The identity record moves through governed states such as established, active, suspended and archived; transitions carry an authority, a reason and a timestamp.", "source_refs": [ "SRC-003", "SRC-017", "SRC-009" ], "questions": [ { "id": "q-lifecycle-state", "text": "Which lifecycle state is the identity record in, and which published state vocabulary defines it?", "kind": "lifecycle", "answer_data": [ "current state value", "state vocabulary reference and version", "state entry timestamp" ] }, { "id": "q-lifecycle-authority", "text": "Who may suspend, reactivate or archive an identity record, and on which grounds?", "kind": "authority", "answer_data": [ "authorised role per transition", "permitted grounds", "approval evidence reference" ] }, { "id": "q-lifecycle-residue", "text": "After archiving, what remains resolvable and what is destroyed?", "kind": "retention", "answer_data": [ "retained element set", "destroyed element set", "tombstone resolution behaviour" ] } ], "data_elements": [ { "id": "de-record-lifecycle-state", "name": "Identity record lifecycle state", "description": "Current governed state of the identity record, bound to the adopting Dimension's published state vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-state-transition-authority", "name": "State transition authority", "description": "Role or authority that executed the most recent lifecycle transition, with the recorded reason.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-017" ] } ], "artifacts": [ { "id": "lifecycle-transition-log", "name": "Lifecycle transition log", "description": "Append-only log of identity record state transitions with authority, ground, evidence and RFC 3339 timestamps.", "media_or_form": [ "append-only log", "audit trail record" ], "serial": true, "identity_strategy": "Monotonic sequence per person record; entries are never rewritten.", "source_refs": [ "SRC-003", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "personal-sphere", "name": "Personal sphere", "description": "Data the person declares and controls: contact points, declared residence pointer, self-declared attributes and communication preferences.", "rationale": "UN legislative guidance and data-protection law both separate what an authority registers from what the person supplies about themselves. Mixing the two destroys the ownership boundary and misrepresents assurance.", "source_refs": [ "SRC-017", "SRC-011", "SRC-004" ], "layers": [ { "id": "contact-presence-and-declarations", "name": "Contact, presence and declarations", "description": "Person-controlled reachability, residence pointer and self-declared attributes, each explicitly flagged as unwarranted by any registrar.", "source_refs": [ "SRC-004", "SRC-009", "SRC-011" ], "findings": [ { "id": "person-controlled-contact-point", "name": "Person-controlled contact point", "description": "A channel through which the person can be reached, owned and revocable by the person, with a verification state and per-purpose usage limits.", "source_refs": [ "SRC-004", "SRC-009", "SRC-011" ], "questions": [ { "id": "q-contact-channel", "text": "What channel type and value does this contact point use, and has the value been verified?", "kind": "definition", "answer_data": [ "channel type code", "value pointer", "verification state and timestamp" ] }, { "id": "q-contact-control", "text": "Who controls this contact point and for which purposes may it be used?", "kind": "ownership", "answer_data": [ "controlling party", "permitted purposes", "purpose limitation basis" ] }, { "id": "q-contact-visibility", "text": "What visibility or disclosure setting applies, and can it differ per relying party?", "kind": "access", "answer_data": [ "visibility setting code", "per-relying-party overrides", "last change timestamp" ] } ], "data_elements": [ { "id": "de-channel-type", "name": "Contact channel type", "description": "The kind of channel, such as email, telephone, postal or messaging endpoint.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-009" ] }, { "id": "de-contact-verification-state", "name": "Contact verification state", "description": "Whether the contact value has been proven reachable and controlled by the person.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-contact-purpose-limitation", "name": "Contact purpose limitation", "description": "Enumerated purposes for which this contact point may be used.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "contact-verification-record", "name": "Contact point verification record", "description": "Record of a reachability or control check on a contact point, with method, outcome and timestamp.", "media_or_form": [ "verification record", "audit trail entry" ], "serial": true, "identity_strategy": "Sequential verification identifier scoped to the contact point reference.", "source_refs": [ "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "declared-residence-pointer", "name": "Declared residence pointer", "description": "A typed pointer to an address resolved in the place model, distinguishing legal domicile, registered residence and self-declared mailing address from statistical usual residence.", "source_refs": [ "SRC-004", "SRC-016", "SRC-001" ], "questions": [ { "id": "q-res-pointer", "text": "Which address does the person declare or stand registered at, and in which model does that address resolve?", "kind": "spatial", "answer_data": [ "address reference", "resolving model reference", "country and administrative area codes" ] }, { "id": "q-res-kind", "text": "Is this a legal domicile, a registered residence or a self-declared mailing address?", "kind": "classification", "answer_data": [ "residence kind code", "declaring or registering party", "warranty flag" ] }, { "id": "q-res-period", "text": "Over which period was it valid and who may change it?", "kind": "temporal", "answer_data": [ "validity start and end", "change authority", "last change timestamp" ] } ], "data_elements": [ { "id": "de-residence-address-ref", "name": "Residence address reference", "description": "Pointer to an address object held in the place or address model; address components are not duplicated here.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016", "SRC-004" ] }, { "id": "de-residence-kind", "name": "Residence kind", "description": "Legal domicile, registered residence or self-declared mailing address.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "residence-declaration-record", "name": "Residence declaration record", "description": "Record of a residence declaration or registration change, with declaring party, effective date and evidence reference.", "media_or_form": [ "declaration record", "registry entry reference" ], "serial": true, "identity_strategy": "Sequential declaration identifier scoped to the person reference identifier and the registering authority.", "source_refs": [ "SRC-017", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "self-declared-attributes", "name": "Self-declared attributes and preferences", "description": "Values supplied solely by the person, including communication and accessibility preferences, carrying no registrar warranty and always distinguishable from verified values in any projection.", "source_refs": [ "SRC-011", "SRC-009", "SRC-015" ], "questions": [ { "id": "q-self-scope", "text": "Which attributes are declared solely by the person and carry no authority warranty?", "kind": "provenance", "answer_data": [ "self-declared attribute list", "declaration timestamps", "assurance flag per attribute" ] }, { "id": "q-self-language", "text": "Which language and communication preferences apply, including accessible formats the person requires?", "kind": "quality", "answer_data": [ "preferred language codes with preference order", "accessible format needs", "interpretation or assistance requirement" ] }, { "id": "q-self-projection", "text": "How is a self-declared value distinguished from an authority-verified value in every projection that carries it?", "kind": "interoperability", "answer_data": [ "assurance marker representation", "projection rule reference", "behaviour when the target schema has no assurance field" ] }, { "id": "q-self-control", "text": "Which self-declared values may the person unilaterally change, hide or delete?", "kind": "ownership", "answer_data": [ "per-attribute change rights", "hide and delete rights", "propagation behaviour to prior recipients" ] } ], "data_elements": [ { "id": "de-self-declared-attribute", "name": "Self-declared attribute", "description": "A person-supplied name-value assertion with declaration time and no registrar warranty.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-010" ] }, { "id": "de-attribute-assurance-flag", "name": "Attribute assurance flag", "description": "Marks each attribute as self-declared, third-party asserted or authority-verified.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-006" ] }, { "id": "de-preferred-language-code", "name": "Preferred language code", "description": "Language the person prefers for communication, with preference ranking.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-accessible-format-need", "name": "Accessible format need", "description": "Format or assistance the person requires to receive and act on communications.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-009" ] } ], "artifacts": [ { "id": "self-declaration-statement", "name": "Self-declaration statement", "description": "The person's recorded declaration of attributes and preferences, timestamped and attributable to the person alone.", "media_or_form": [ "declaration record", "signed statement reference" ], "serial": true, "identity_strategy": "Sequential declaration identifier scoped to the person reference identifier, timestamped in RFC 3339.", "source_refs": [ "SRC-011", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "personal-data-governance", "name": "Personal data governance", "description": "Lawful basis and consent, subject-right execution, minimal disclosure, retention, erasure and disclosure audit over person data.", "rationale": "Person data is personal data by definition; UN legislative guidance requires confidentiality and access control over civil-registration records, and EU law defines subject rights, special categories and storage limitation. Governance is therefore inseparable from the model, not an optional overlay.", "source_refs": [ "SRC-011", "SRC-012", "SRC-017", "SRC-006" ], "layers": [ { "id": "lawful-basis-and-subject-rights", "name": "Lawful basis and subject rights", "description": "Why each processing purpose is permitted, how consent is scoped and withdrawn, and how subject-right requests are executed.", "source_refs": [ "SRC-011", "SRC-017" ], "findings": [ { "id": "lawful-basis-and-consent", "name": "Lawful basis and consent grant", "description": "Each processing purpose is bound to a lawful basis; consent-based purposes carry a scoped, withdrawable grant, while statutory registration processing is not consent-dependent.", "source_refs": [ "SRC-011", "SRC-017", "SRC-012" ], "questions": [ { "id": "q-basis-per-purpose", "text": "What is the lawful basis for each declared processing purpose over this person's data?", "kind": "authority", "answer_data": [ "purpose statement", "lawful basis code per purpose", "controller reference" ] }, { "id": "q-consent-scope", "text": "Where consent is the basis, what is its exact scope, and how are withdrawal and its propagation recorded?", "kind": "ownership", "answer_data": [ "granted attribute set and recipients", "grant validity period", "withdrawal timestamp and propagation outcome" ] }, { "id": "q-basis-statutory", "text": "Which processing is mandated by registration law and therefore cannot be refused by withdrawing consent?", "kind": "constraint", "answer_data": [ "statutory purpose list", "legal instrument reference", "person-facing explanation text" ] } ], "data_elements": [ { "id": "de-processing-purpose", "name": "Processing purpose", "description": "A declared, specific purpose for which person data is processed.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "de-lawful-basis-code", "name": "Lawful basis code", "description": "The legal ground permitting processing for a given purpose.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-011", "SRC-017" ] }, { "id": "de-consent-grant-ref", "name": "Consent grant reference", "description": "Pointer to a scoped grant held by the consent service, with validity and withdrawal state.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "consent-grant-record", "name": "Consent grant record", "description": "Durable record of a grant: granting person, scope, recipients, purpose, validity, and withdrawal with propagation results.", "media_or_form": [ "grant record", "audit trail entry" ], "serial": true, "identity_strategy": "Sequential grant identifier scoped to the person reference identifier and the controller.", "source_refs": [ "SRC-011", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "subject-rights-execution", "name": "Subject right execution", "description": "How access, rectification, erasure, restriction, portability and objection requests are received, decided, executed and evidenced, including lawful refusal.", "source_refs": [ "SRC-011", "SRC-012", "SRC-017" ], "questions": [ { "id": "q-right-request", "text": "Which right was exercised, when, by whom, and with what outcome?", "kind": "process", "answer_data": [ "right type code", "request and decision timestamps", "requesting party and verification of their identity" ] }, { "id": "q-right-authority", "text": "Which data can the person rectify directly and which requires a registrar act?", "kind": "authority", "answer_data": [ "directly rectifiable element list", "registrar-only element list", "escalation path" ] }, { "id": "q-right-portability", "text": "Which records are exportable in a portable form and which are excluded, and why?", "kind": "interoperability", "answer_data": [ "exportable element list and format", "excluded element list", "exclusion ground" ] }, { "id": "q-right-refusal", "text": "What lawful grounds justify refusing, restricting or deferring a request?", "kind": "exception", "answer_data": [ "refusal ground reference", "affected elements", "person-facing reason and appeal route" ] } ], "data_elements": [ { "id": "de-right-request-type", "name": "Subject right request type", "description": "Which right is being exercised over the person's data.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-012" ] }, { "id": "de-right-decision-outcome", "name": "Request decision outcome", "description": "Granted, partially granted, refused or deferred, with the ground recorded.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "de-requester-verification", "name": "Requester verification evidence", "description": "How the requesting party's entitlement to act was verified, including representative mandates.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-015" ] } ], "artifacts": [ { "id": "subject-right-case-file", "name": "Subject right request case file", "description": "Case record of a right request: intake, identity verification, decision, executed changes, evidence and communication to the person.", "media_or_form": [ "case record", "audit trail package" ], "serial": true, "identity_strategy": "Sequential case identifier scoped to the controller, linked to the person reference identifier.", "source_refs": [ "SRC-011", "SRC-017" ] } ], "inline_only_rationale": null } ] }, { "id": "disclosure-retention-and-audit", "name": "Disclosure, retention and audit", "description": "What is released to whom in what minimal form, how long data is kept, when it may be erased, and what is logged.", "source_refs": [ "SRC-006", "SRC-011", "SRC-017" ], "findings": [ { "id": "minimal-disclosure-projection", "name": "Minimal disclosure projection", "description": "Each relying party receives the narrowest projection satisfying its stated need, preferring a derived predicate over the underlying attribute, with special-category data excluded by default.", "source_refs": [ "SRC-006", "SRC-005", "SRC-011", "SRC-012" ], "questions": [ { "id": "q-disc-minimum", "text": "What is the minimum attribute set that satisfies this relying party's stated need?", "kind": "requirement", "answer_data": [ "requested attribute set", "approved minimum set", "justification for anything beyond the minimum" ] }, { "id": "q-disc-predicate", "text": "Can the need be met by a derived predicate instead of the underlying attribute?", "kind": "decision", "answer_data": [ "available predicate list", "predicate chosen", "attribute withheld as a result" ] }, { "id": "q-disc-special", "text": "Which requested attributes fall into a special category requiring a stricter condition before release?", "kind": "privacy", "answer_data": [ "special-category flag per attribute", "additional lawful condition", "approval evidence" ] }, { "id": "q-disc-public", "text": "Which projection is released for statutory public-record requests, and what does it deliberately omit?", "kind": "access", "answer_data": [ "public-record element list", "omitted element list", "legal basis for the public element list" ] } ], "data_elements": [ { "id": "de-released-attribute-set", "name": "Released attribute set", "description": "The attributes actually released in a disclosure, recorded per disclosure event.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-011" ] }, { "id": "de-predicate-assertion", "name": "Predicate assertion", "description": "A derived boolean claim released instead of an underlying attribute, such as an age threshold.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "de-special-category-flag", "name": "Special category flag", "description": "Marks an attribute as belonging to a legally defined special category of personal data.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "disclosure-projection-definition", "name": "Disclosure projection definition", "description": "Named, versioned definition of an attribute projection for a relying-party class, listing included attributes, predicates and omissions.", "media_or_form": [ "projection definition", "published specification section" ], "serial": false, "identity_strategy": "Identified by projection name plus version under the owning Dimension's namespace.", "source_refs": [ "SRC-006", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "retention-erasure-and-audit", "name": "Retention, erasure and disclosure audit", "description": "Retention classes and periods, the tension between permanent vital records and erasure rights, the method by which deletion is demonstrated, and what every disclosure must log.", "source_refs": [ "SRC-011", "SRC-017", "SRC-001" ], "questions": [ { "id": "q-ret-schedule", "text": "How long must each class of person data be retained, and under whose mandate?", "kind": "retention", "answer_data": [ "retention class and period per element group", "mandating instrument reference", "retention start trigger" ] }, { "id": "q-ret-exemption", "text": "Which data is subject to erasure on request and which is exempt because a legal obligation requires permanent retention?", "kind": "exception", "answer_data": [ "erasable element list", "exempt element list", "exempting legal ground" ] }, { "id": "q-ret-log", "text": "What is logged for every disclosure, and for how long is the log itself retained?", "kind": "evidence", "answer_data": [ "log field set", "log retention period", "log access rights" ] }, { "id": "q-ret-method", "text": "How is deletion demonstrated: physical destruction, cryptographic erasure or de-identification?", "kind": "validation", "answer_data": [ "deletion method code", "verification evidence", "residual tombstone description" ] } ], "data_elements": [ { "id": "de-retention-class", "name": "Retention class", "description": "Grouping of person data elements that share a retention rule and mandate.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-011", "SRC-017" ] }, { "id": "de-retention-period", "name": "Retention period", "description": "Duration for which a retention class must be kept, with the trigger that starts it.", "value_kind": "duration", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-011", "SRC-017" ] }, { "id": "de-deletion-method", "name": "Deletion method", "description": "How data was removed: destruction, cryptographic erasure or de-identification.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "disclosure-audit-log-entry", "name": "Disclosure audit log entry", "description": "Append-only entry recording requester, role, purpose, lawful basis, attribute set, decision and RFC 3339 timestamp for one access.", "media_or_form": [ "append-only log entry", "audit trail record" ], "serial": true, "identity_strategy": "Monotonic sequence per controller; entries are immutable and reference the person reference identifier.", "source_refs": [ "SRC-017", "SRC-011" ] }, { "id": "retention-schedule", "name": "Retention schedule", "description": "Published schedule mapping retention classes to periods, mandates, erasure eligibility and deletion methods.", "media_or_form": [ "schedule document", "published policy" ], "serial": false, "identity_strategy": "Identified by owning authority plus schedule version and effective date.", "source_refs": [ "SRC-017", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "quality-and-interoperability", "name": "Quality and interoperability", "description": "Attribute accuracy and correction, and disciplined alignment to external vocabularies including script and transliteration handling.", "rationale": "Accuracy is a legal principle for personal data and a quality requirement for civil registration; alignment to external standards must be recorded as mapping rather than claimed as conformance, and name transliteration is a documented interoperability hazard in travel documents.", "source_refs": [ "SRC-011", "SRC-001", "SRC-014", "SRC-004" ], "layers": [ { "id": "attribute-quality", "name": "Attribute quality and correction", "description": "Provenance and freshness of each attribute, the correction pathway, and the quality indicators measured over the person population.", "source_refs": [ "SRC-011", "SRC-001", "SRC-017" ], "findings": [ { "id": "attribute-accuracy-and-correction", "name": "Attribute accuracy and correction", "description": "Every core attribute carries a source and last-verified time; corrections supersede rather than overwrite, and population-level quality is measured.", "source_refs": [ "SRC-011", "SRC-001", "SRC-017", "SRC-008" ], "questions": [ { "id": "q-qual-source", "text": "What is the source and last-verified time of each core attribute?", "kind": "provenance", "answer_data": [ "source reference per attribute", "last verified timestamp", "verification method" ] }, { "id": "q-qual-correction", "text": "What triggers a correction, and which authority may make it in the register of record?", "kind": "process", "answer_data": [ "correction trigger list", "authorised correcting role", "required evidence and approval steps" ] }, { "id": "q-qual-history", "text": "How are erroneous historical values retained for audit while no longer being presented as current?", "kind": "temporal", "answer_data": [ "superseded assertion retention rule", "presentation suppression rule", "link from current to superseded value" ] }, { "id": "q-qual-indicators", "text": "Which quality indicators are measured over the person population and against what target?", "kind": "measurement", "answer_data": [ "indicator definitions (completeness, timeliness, duplication rate)", "measured values and measurement period", "target or threshold" ] } ], "data_elements": [ { "id": "de-attribute-source-ref", "name": "Attribute source reference", "description": "Pointer to the system or act that is the source of record for an attribute value.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-011", "SRC-001" ] }, { "id": "de-last-verified-time", "name": "Last verified time", "description": "RFC 3339 timestamp of the most recent verification of the attribute against its source.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-011" ] }, { "id": "de-quality-indicator", "name": "Population quality indicator", "description": "Measured indicator such as completeness, timeliness of registration or duplication rate.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-017" ] } ], "artifacts": [ { "id": "attribute-correction-record", "name": "Attribute correction record", "description": "Record of a correction: prior value, corrected value, evidence, authorising role, effective date and superseded assertion link.", "media_or_form": [ "correction record", "audit trail entry" ], "serial": true, "identity_strategy": "Sequential correction identifier scoped to the register of record and the person reference identifier.", "source_refs": [ "SRC-001", "SRC-017" ] } ], "inline_only_rationale": null } ] }, { "id": "external-alignment", "name": "External alignment and encoding", "description": "Versioned mappings to external vocabularies and credential schemas, and script, encoding and transliteration handling for names.", "source_refs": [ "SRC-004", "SRC-010", "SRC-014", "SRC-006" ], "findings": [ { "id": "external-schema-alignment", "name": "External schema alignment", "description": "Alignments to external vocabularies are versioned, explicitly lossy where relevant, and are mappings until conformance evidence exists.", "source_refs": [ "SRC-004", "SRC-010", "SRC-009", "SRC-006", "SRC-003" ], "questions": [ { "id": "q-align-target", "text": "Which external vocabulary or credential schema is this projection aligned to, at which version?", "kind": "interoperability", "answer_data": [ "target vocabulary or schema reference", "target version", "mapping document reference" ] }, { "id": "q-align-loss", "text": "Which parts of the alignment are lossy, and which fields have no counterpart in the target?", "kind": "constraint", "answer_data": [ "lossy field list with loss description", "unmapped field list", "compensating note or extension used" ] }, { "id": "q-align-conflict", "text": "Where two aligned standards conflict on the same concept, which one governs here and why?", "kind": "decision", "answer_data": [ "conflicting standards and concept", "governing choice", "recorded rationale" ] }, { "id": "q-align-conformance", "text": "Is this alignment a claim of conformance or only a mapping, and what evidence supports the claim?", "kind": "evidence", "answer_data": [ "claim type (mapping or conformance)", "conformance evidence reference", "test or certification result where any" ] } ], "data_elements": [ { "id": "de-alignment-target-ref", "name": "Alignment target reference", "description": "Identifies the external vocabulary, schema or code list this model is mapped to.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-010" ] }, { "id": "de-alignment-version", "name": "Alignment target version", "description": "Exact version or release date of the target that the mapping was made against.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-006" ] }, { "id": "de-conformance-claim-flag", "name": "Conformance claim flag", "description": "False by default; true only where retrievable conformance evidence exists.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "alignment-mapping-table", "name": "Alignment mapping table", "description": "Versioned table mapping this model's elements to a target vocabulary, marking lossy and unmapped fields and recording the governing choice on conflicts.", "media_or_form": [ "mapping table", "published specification annex" ], "serial": false, "identity_strategy": "Identified by source model identifier plus target reference plus mapping version.", "source_refs": [ "SRC-004", "SRC-010", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "script-and-transliteration", "name": "Script, encoding and transliteration", "description": "Names exist in native script, transliterated and machine-readable truncated forms; each form must be identified, rule-bound and reconcilable to the registered name.", "source_refs": [ "SRC-014", "SRC-016", "SRC-004" ], "questions": [ { "id": "q-script-forms", "text": "In which script and character encoding is each name form recorded, and which form is the registered original?", "kind": "interoperability", "answer_data": [ "script code and encoding per form", "registered original form marker", "derived form list" ] }, { "id": "q-script-rules", "text": "Which transliteration rule set produced the machine-readable form, and is the transformation reversible?", "kind": "validation", "answer_data": [ "transliteration rule set reference and version", "reversibility statement", "known ambiguity cases" ] }, { "id": "q-script-truncation", "text": "How are truncated machine-readable forms reconciled with the full registered name?", "kind": "exception", "answer_data": [ "truncation indicator", "full registered name reference", "reconciliation procedure for matching" ] } ], "data_elements": [ { "id": "de-name-form-script", "name": "Name form script and encoding", "description": "Script and character encoding of a specific recorded name form.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-014", "SRC-016" ] }, { "id": "de-transliteration-rule-ref", "name": "Transliteration rule set reference", "description": "The published rule set used to derive a transliterated or machine-readable name form.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "de-truncation-flag", "name": "Truncation flag", "description": "Indicates that a machine-readable name form was truncated to fit a fixed-length field.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [ { "id": "transliteration-mapping-record", "name": "Transliteration mapping record", "description": "Record linking a registered native-script name to its transliterated and machine-readable forms with the rule set applied.", "media_or_form": [ "mapping record", "document data extract" ], "serial": false, "identity_strategy": "Keyed by the name assertion identifier plus the target form code.", "source_refs": [ "SRC-014", "SRC-016" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "resolve-person-reference", "name": "Resolve person reference", "description": "Resolve a set of candidate identifiers and attributes to a single person reference identifier within a declared domain of applicability, or report non-resolution.", "inputs": [ "candidate identifiers with schemes", "candidate attribute bundle", "domain of applicability", "purpose and lawful basis" ], "outputs": [ "resolved person reference identifier or non-resolution reason", "match confidence and rule set version", "resolution attempt log entry" ], "preconditions": [ "a published matching policy and threshold exist", "requester purpose is bound to a lawful basis" ], "effects": [ "resolution attempt is logged with requester, purpose and RFC 3339 ingestion time", "no person record is created or modified" ], "source_refs": [ "SRC-003", "SRC-008", "SRC-009" ] }, { "id": "register-person-identity", "name": "Register person identity", "description": "Establish a new person anchor from a civil registration act, or from a recorded exception route where no registration act exists.", "inputs": [ "registration act reference or exception authorisation", "registered core attributes", "registrar reference" ], "outputs": [ "person anchor record with reference identifier", "initial lifecycle state", "registration evidence link" ], "preconditions": [ "registrar authority is established for the jurisdiction", "identity priority rule has been applied to choose the reference identifier" ], "effects": [ "person anchor becomes resolvable to other models", "registration time and ingestion time are recorded separately" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-017" ] }, { "id": "record-name-change", "name": "Record name change", "description": "Add a new time-bounded legal name assertion and close the validity of the prior one without deleting it.", "inputs": [ "structured name parts and ordering convention", "name-change instrument reference", "effective date" ], "outputs": [ "new name assertion with validity period", "superseded name assertion retained", "updated machine-readable name form" ], "preconditions": [ "a valid instrument evidences the change", "script and encoding are declared" ], "effects": [ "prior name remains queryable as a former name", "transliterated forms are regenerated under the recorded rule set" ], "source_refs": [ "SRC-004", "SRC-016", "SRC-014" ] }, { "id": "assign-scheme-identifier", "name": "Assign scheme-qualified identifier", "description": "Record an identifier issued to the person under a named scheme with authority, validity, reuse policy and correlatability class.", "inputs": [ "scheme name and version", "issuing authority reference", "identifier value pointer", "validity period" ], "outputs": [ "identifier assignment record", "correlatability classification", "validation result against the scheme format rule" ], "preconditions": [ "the scheme is registered in the owner package", "the issuing authority resolves in the organization model" ], "effects": [ "identifier becomes usable for lookups within its declared scope", "reference identifier is unchanged unless explicitly re-designated" ], "source_refs": [ "SRC-004", "SRC-003", "SRC-005" ] }, { "id": "record-identity-evidence", "name": "Record identity evidence", "description": "Register an issued document or electronic attestation as evidence about the person, with issuer, validity, asserted attributes, holder binding and status source.", "inputs": [ "evidence type and issuer reference", "validity window", "asserted attribute set", "holder binding method", "status endpoint or list reference" ], "outputs": [ "evidence record linked to the person anchor", "per-attribute authoritativeness flags", "status resolution pointer" ], "preconditions": [ "the person anchor exists", "the issuer is identifiable and its status mechanism is reachable or recorded as unavailable" ], "effects": [ "evidence is available for proofing and disclosure decisions", "evidence revocation never alters the person anchor" ], "source_refs": [ "SRC-006", "SRC-014", "SRC-005", "SRC-002" ] }, { "id": "assess-identity-assurance", "name": "Assess identity assurance", "description": "Run and record resolution, validation and verification against collected evidence and emit an assurance level with an expiry.", "inputs": [ "evidence records", "published criteria set and version", "optional biometric capture reference" ], "outputs": [ "assurance level", "per-step outcomes", "re-proofing due date" ], "preconditions": [ "criteria set is published and versioned", "biometric capture, if used, meets the declared encoding standard" ], "effects": [ "assurance record is retained as audit evidence", "downstream disclosure decisions may condition on the level" ], "source_refs": [ "SRC-008", "SRC-003", "SRC-014" ] }, { "id": "anchor-life-event", "name": "Anchor life event", "description": "Attach a typed anchor to a registered life event resolved in the vital-event model, recording the person's role and the three time values.", "inputs": [ "event identifier and type", "person role in event", "occurrence, registration and ingestion times" ], "outputs": [ "life event anchor entry", "any resulting status change proposal", "bitemporal change log entry" ], "preconditions": [ "the event resolves in the vital-event model", "occurrence and registration times are distinguishable" ], "effects": [ "person navigation index is updated", "no event content is copied into the person model" ], "source_refs": [ "SRC-001", "SRC-017" ] }, { "id": "record-legal-standing-change", "name": "Record legal standing change", "description": "Record a change of civil status, nationality, statelessness determination, legal capacity or representation arrangement with its authority and effective period.", "inputs": [ "standing type and new value", "deciding authority and act reference", "effective period and scope" ], "outputs": [ "new time-bounded standing assertion", "superseded assertion retained", "notification list for dependent systems" ], "preconditions": [ "the deciding authority is competent in the recorded jurisdiction", "for capacity restrictions, scope and review terms are stated" ], "effects": [ "prior standing remains auditable", "default of full legal capacity is only displaced by an evidenced act" ], "source_refs": [ "SRC-015", "SRC-001", "SRC-017", "SRC-002" ] }, { "id": "close-identity-on-death", "name": "Close identity on death", "description": "Record registered, judicially declared or presumed death, transition the identity record lifecycle state and drive downstream closure.", "inputs": [ "death determination basis and evidence", "date, time and place of death", "registration reference" ], "outputs": [ "updated vital status", "lifecycle state transition entry", "downstream closure and notification results" ], "preconditions": [ "determination basis is evidenced", "reversal procedure exists for presumed death" ], "effects": [ "dependent identifiers and credentials are marked for closure", "record remains retained under the retention schedule rather than deleted" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-017" ] }, { "id": "merge-or-split-person-records", "name": "Merge or split person records", "description": "Apply a same-as, merge or split decision across person records, preserving both records' histories and keeping superseded identifiers resolvable.", "inputs": [ "candidate record references", "matching evidence and confidence", "authorising role" ], "outputs": [ "linkage decision record", "surviving master designation", "tombstone resolution behaviour" ], "preconditions": [ "confidence meets the published threshold or a manual authorisation is recorded", "reversal path is defined" ], "effects": [ "no history is destroyed", "downstream holders of superseded identifiers are notified" ], "source_refs": [ "SRC-009", "SRC-008", "SRC-017" ] }, { "id": "emit-minimal-disclosure", "name": "Emit minimal disclosure projection", "description": "Produce the narrowest attribute projection or derived predicate that satisfies a relying party's stated need, and log the disclosure.", "inputs": [ "relying party identity and class", "stated purpose and lawful basis", "requested attribute set" ], "outputs": [ "released attribute set or predicate assertions", "withheld attribute list with reasons", "disclosure audit log entry" ], "preconditions": [ "a named projection definition exists for the relying-party class", "special-category attributes have an additional lawful condition if requested" ], "effects": [ "only approved attributes leave the boundary", "the person can see the disclosure in their own access log" ], "source_refs": [ "SRC-006", "SRC-005", "SRC-011" ] }, { "id": "execute-subject-right-request", "name": "Execute subject right request", "description": "Intake, verify, decide and execute an access, rectification, erasure, restriction, portability or objection request, including lawful refusal.", "inputs": [ "right type and requested scope", "requester identity and entitlement evidence", "controller policy references" ], "outputs": [ "decision with grounds", "executed changes or export package", "case file and person-facing response" ], "preconditions": [ "requester entitlement is verified, including any representation mandate", "retention obligations have been evaluated" ], "effects": [ "case file becomes durable evidence", "refusals record the exempting legal ground and appeal route" ], "source_refs": [ "SRC-011", "SRC-012", "SRC-015", "SRC-017" ] }, { "id": "apply-retention-decision", "name": "Apply retention or erasure decision", "description": "Evaluate a retention class against its schedule and legal obligations, then retain, suppress, de-identify or destroy, and evidence the outcome.", "inputs": [ "retention class and trigger date", "applicable legal obligations", "erasure request reference where relevant" ], "outputs": [ "retention or erasure decision with ground", "deletion method and verification evidence", "residual tombstone description" ], "preconditions": [ "a published retention schedule exists for the class", "permanent-record obligations have been checked" ], "effects": [ "outcome is logged immutably", "suppression is preferred to destruction where an obligation to retain exists" ], "source_refs": [ "SRC-011", "SRC-017", "SRC-001" ] }, { "id": "record-evidence-status-change", "name": "Revoke identity document", "description": "Invalidate a document before expiry and record revocation time, authority and reason.", "inputs": [ "Document identifier", "Revocation reason code", "Revoking authority identifier" ], "outputs": [ "Document state set to revoked with revocation time, authority and reason" ], "preconditions": [ "The document exists and has not already expired or been cancelled" ], "effects": [ "The document is no longer valid evidence of identity", "The revoked document remains historically recorded in a revoked state" ], "source_refs": [ "SRC-022" ] } ], "composition": [ { "target": "Household and family membership model (sibling; legacy alias H2)", "relation": "REFERENCE", "purpose": "Household membership, filiation and kinship ties are separate registered acts and separate statistical units; Person holds only typed pointers to them.", "required": false, "source_refs": [ "SRC-001", "SRC-017" ] }, { "target": "Population and community group model (sibling; legacy alias H3)", "relation": "REFERENCE", "purpose": "Group and community membership resolves against the person reference identifier and is never stored as a person attribute, particularly where it would reveal special-category data.", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "target": "Education and qualification model (sibling; legacy alias H4)", "relation": "REFERENCE", "purpose": "Earned credentials anchor to the person as holder; credential content and awarding rules live in the qualification model.", "required": false, "source_refs": [ "SRC-010", "SRC-006" ] }, { "target": "Organization model (sibling; legacy alias O1)", "relation": "REFERENCE", "purpose": "Registrars, issuing authorities, credential issuers, verifiers and corporate guardians must resolve as organizations rather than being described inside Person.", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-006" ] }, { "target": "Address and place model (sibling)", "relation": "REFERENCE", "purpose": "Places of birth, death and residence resolve as place or address objects; Person stores pointers plus a residence kind and validity period.", "required": true, "source_refs": [ "SRC-004", "SRC-001" ] }, { "target": "Vital event and civil registration act model (sibling)", "relation": "REFERENCE", "purpose": "The registration act, informant details, certificate issuance and statistical coding belong to the event model; Person keeps anchors, roles and resulting status changes.", "required": true, "source_refs": [ "SRC-001", "SRC-017" ] }, { "target": "Human biological organism and health subject model (sibling)", "relation": "REFERENCE", "purpose": "Explicit boundary: physiology, clinical findings, cause of death and genomic data are excluded here and must be reached only through a governed reference.", "required": false, "source_refs": [ "SRC-009", "SRC-011" ] }, { "target": "Consent and authorization service (legacy alias S1)", "relation": "COMPOSE", "purpose": "Grants, scopes, withdrawal and policy decisions over person data are executed by the consent service; Person declares what is subject-owned and which purposes exist.", "required": true, "source_refs": [ "SRC-011", "SRC-017" ] }, { "target": "Audit and evidence service (legacy alias S4)", "relation": "COMPOSE", "purpose": "Disclosure logs, lifecycle transition logs and correction records are written to the audit service so the person and oversight authorities can read them.", "required": true, "source_refs": [ "SRC-017", "SRC-011" ] }, { "target": "ISO/IEC 24760-1:2025 identity management framework", "relation": "ALIGN", "purpose": "Adopt the entity/identity/identifier/reference-identifier distinction and identity-register and relying-party roles as the model's conceptual vocabulary; the exact lifecycle state list must be bound to a published Dimension vocabulary.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "Core Person Vocabulary 2.00 (SEMIC)", "relation": "ALIGN", "purpose": "Map name components, birth and death facts, citizenship, domicile and the Identifier class with scheme, issuing authority and issue date.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "EUDI Wallet PID Rulebook (ARF Annex 3.01)", "relation": "ALIGN", "purpose": "Map the person identification data attribute set for wallet-based presentation, including predicate attributes such as age_over_18 and the issuer-defined personal administrative number policy.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "W3C Verifiable Credentials Data Model v2.0", "relation": "ALIGN", "purpose": "Express identity evidence as credentials with issuer, subject, validity window, status and proof, and use presentations for selective disclosure.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "W3C Decentralized Identifiers v1.0", "relation": "ALIGN", "purpose": "Provide the governed global identifier option at identity-priority level two, with documented correlation risk and controller-versus-subject separation.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "NIST SP 800-63A-4 identity proofing and enrollment", "relation": "ALIGN", "purpose": "Adopt resolution, validation and verification as recorded proofing steps producing an assurance level, while keeping authenticator management outside this model.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "HL7 FHIR R5 Patient", "relation": "ALIGN", "purpose": "Map to care-context demographics and reconcile the one-anchor-per-person rule with FHIR's multiple Patient records via link semantics rather than merge.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "schema.org Person", "relation": "ALIGN", "purpose": "Provide a lossy public publication projection only; no validity periods, authority or assurance semantics may be inferred from it.", "required": false, "source_refs": [ "SRC-010" ] }, { "target": "OASIS CIQ v3.0 xNL and xAL value shapes", "relation": "MIX-IN", "purpose": "Reuse structured, culture-aware name and address value shapes instead of re-inventing name part roles and ordering conventions.", "required": false, "source_refs": [ "SRC-016" ] }, { "target": "ISO/IEC 5218:2022 codes for the representation of human sexes", "relation": "ALIGN", "purpose": "Bind the administrative sex code list, noting the standard's explicit exclusion of gender identity, which forces separate modelling of self-identified gender.", "required": false, "source_refs": [ "SRC-013", "SRC-005" ] }, { "target": "ICAO Doc 9303 Part 3 (Eighth Edition, 2021)", "relation": "ALIGN", "purpose": "Bind machine-readable-zone name transliteration, truncation behaviour and biometric image encoding used by travel-document evidence.", "required": false, "source_refs": [ "SRC-014" ] }, { "target": "Regulation (EU) 2016/679 (GDPR)", "relation": "ALIGN", "purpose": "Regional legal alignment for lawful basis, special categories, accuracy, storage limitation and subject rights; other jurisdictions require their own binding.", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name a civil registrar or register of record that owns the registered-identity bundles, and a distinct controller relationship for the personal-sphere bundle owned by the person.", "Publish, before any person record is created, the identifier schemes recognised, their issuing authorities, format rules, reuse policies and correlatability classes.", "Publish jurisdiction bindings: civil status vocabulary, administrative sex code list and version, nationality coding scheme, identity-record lifecycle state vocabulary and the retention schedule.", "Register the disclosure projections available to each relying-party class, and the lawful basis attached to each declared processing purpose.", "Declare the escalation and reversal procedures for merges, splits, presumed-death reversal and refused subject-right requests." ], "namespace_guidance": "Use one stable logical namespace per Dimension, for example .person, with bundle-level sub-namespaces such as .civilIdentity, .identifiersEvidence, .legalStanding, .lifeCourse, .personalSphere, .dataGovernance and .qualityInterop. Namespaces are logical only and must not encode storage engine, file layout or access interface. Identifier scheme names are namespaced by issuing authority, never by consuming application. External code lists are referenced as namespaced, versioned registry entries rather than inlined literals.", "registry_links": [ "vr.wm-per-001 is the registry entry of record for WM-PER-001 and holds its status, review state and priority metadata.", "Sibling registry entries for household, organization, address/place, vital-event and qualification models must exist and be linked before Person records reference them.", "External alignment targets (ISO/IEC 24760-1, Core Person Vocabulary, EUDI PID Rulebook, W3C VC and DID, FHIR Patient, schema.org, ISO/IEC 5218, ICAO Doc 9303, OASIS CIQ) are registered as versioned references with their retrieval dates.", "Code lists for sex, civil status, nationality, capacity class and lifecycle state are registered as separately versioned registry entries owned by the adopting Dimension." ] }, "canon_and_patch": { "canonicalization_rules": [ "Serialise all recorded times as RFC 3339 with seconds and an explicit UTC offset or Z; keep date-only civil facts as dates with a stated precision and never widen them to timestamps.", "Order name parts by the declared ordering convention rather than by serialisation order, and always carry script and encoding alongside the value.", "Represent every coded value as a scheme reference plus version plus value; bare literals are non-canonical and must be rejected on ingest.", "Canonical person form is the reference identifier plus the set of scheme-qualified identifiers sorted by scheme name, then the current time-valid assertions sorted by element identifier.", "Store references to other models as model-qualified identifiers, never as embedded copies of the referenced object." ], "patch_rules": [ "An attribute change is a new time-bounded assertion that supersedes the prior one; in-place mutation of a prior value is prohibited.", "A correction carries a correction reason, the authorising role and the evidence reference, and links to the superseded assertion, which is retained.", "Merge, split and lifecycle transitions are record-level patches that never rewrite the superseded record's history and always leave a resolvable tombstone.", "Every patch records occurrence, registration and ingestion times separately, even when they coincide.", "Erasure executed under a subject right is a patch that records the deletion method and the residual tombstone, not a silent removal." ], "compatibility_rules": [ "Adding an optional finding, data element or code value is backward compatible; narrowing a code list, changing cardinality from optional to required, or repurposing an identifier scheme is breaking.", "Alignment mappings are versioned independently; a new version of an external standard does not implicitly change this model or its conformance posture.", "Removing a data element requires a deprecation period during which both the deprecated and replacement elements resolve.", "Changing the identity priority applied to an existing population is always breaking and requires a migration plan that keeps prior identifiers resolvable." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier: the civil register or population register entry identifier issued by the registrar of record for the jurisdiction.", "Governed global identifier or IRI: a resolvable identifier under a named, governed scheme such as a DID or registry IRI, used where no civil register identifier exists or where law forbids its use.", "UUID or ULID assigned by the adopting Dimension, used only as a local surrogate and never presented externally as a civil identifier.", "A date, a name, a name plus date-of-birth combination, a biometric template or any other demographic attribute set is not an identifier and must never be used as a key." ], "timestamp_rule": "All recorded times use RFC 3339 with seconds and an explicit UTC offset or Z. Occurrence time, registration time and observation/ingestion time are stored as separate fields and never collapsed. Date-only civil facts such as date of birth remain dates with an explicit precision code rather than being padded to midnight timestamps.", "serial_naming_rule": "Serial artifacts are named --, with the sequence scoped to the issuing authority and the artifact class. Sequence numbers are monotonic and are never reused after a merge, split, correction or erasure; gaps are permitted and must not be closed.", "integrity_rule": "Every artifact carries a content digest, the issuing or authoring authority reference and, where it evidences identity, a signature or equivalent authenticity proof. Digests are recomputed on each patch and the prior digest is retained in the change log, so that any artifact can be shown to be the one that was disclosed at a given logged time." }, "policies": [ "Documents, credentials and identifiers evidence identity; they never constitute it. Revoking a document or identifier does not revoke or close the person.", "Registered-identity data is owned by the registrar of record and personal-sphere data is owned by the person. No component may reclassify data between the two without a recorded decision.", "Disclosure defaults to the minimum attribute set or a derived predicate; releasing anything beyond the approved minimum requires a recorded justification.", "Special-category data is excluded from every default projection and requires an explicit additional lawful condition per disclosure.", "No conformance to an external standard may be claimed without retrievable evidence; every external link is a mapping until conformance is evidenced.", "Historical assertions are retained for audit even when superseded; erasure is a governed exception evaluated against retention obligations, never a default operation.", "Full legal capacity is the default and may be displaced only by an evidenced, scoped and reviewable act; representation arrangements must record the person's own will and preferences.", "Split stewardship: the civil registrar or identification authority owns registered identity, documents and civil status; the natural person owns personal-sphere data and consent over it.", "ISO/IEC 24760 alignment is vocabulary-only; non-human principals cannot be stored as Person.", "GDPR data minimisation, purpose limitation, accuracy, storage limitation and integrity apply to processing of person data, with the public-interest archiving exception for permanent civil registers.", "Identity verification and PID presentation use selective disclosure or confirmation-only answers.", "No silent overwrite of legal name, civil marker or civil status by self-declared attributes.", "Special-category data, including biometrics used to uniquely identify a person, require an Article 9 condition in addition to an Article 6 basis.", "Household, filiation and organisational roles must be referenced, not duplicated.", "Time values use RFC 3339 with seconds and an explicit offset or Z; incomplete civil dates use GenericDate precision." ], "crud": { "read": [ "Every read declares a purpose bound to a lawful basis and returns the narrowest projection satisfying it; unspecified-purpose reads are denied.", "Reads of registered-identity, evidence or special-category findings are logged with requester, role, purpose, attribute set and an RFC 3339 timestamp.", "The person may read every record and every access-log entry concerning them, including refusals and their grounds.", "Bulk or statistical reads are served only as aggregated or de-identified extracts, never as per-person projections." ], "create": [ "Creating the person anchor requires either a civil registration act reference or a recorded exception route with a named authorising role and reason.", "Creating an identifier assignment requires scheme, version, issuing authority, validity period, reuse policy and correlatability class.", "Creating an evidence record requires issuer, validity window, asserted attribute set, holder binding method and a status resolution pointer.", "Creating any assertion records occurrence, registration and ingestion times separately at creation." ], "update": [ "Registered-identity attributes are updated only by the registrar of record or under an approved correction decision.", "Self-declared attributes, contact points and preferences are updated by the person without registrar involvement, retaining their self-declared assurance flag.", "Every update writes a superseding time-bounded assertion with the change reason and authorising role; the prior assertion remains readable.", "Lifecycle state transitions are updates that require an authorised role, a permitted ground and an immutable log entry." ], "delete": [ "Physical deletion is prohibited by default; suppression is achieved by lifecycle state change and exclusion from projections.", "Erasure requests are evaluated against retention obligations, and refusals record the exempting legal ground and the appeal route.", "Where erasure is executed, the deletion method (destruction, cryptographic erasure or de-identification), its verification evidence and the residual tombstone are recorded.", "Audit and disclosure log entries are never deleted by an erasure operation; they are retained under their own retention rule." ] }, "roles": [ { "name": "Civil registrar of record", "responsibilities": [ "Establishes, corrects and closes the registered identity and its core attributes", "Authorises merges, splits, corrections and identity-record lifecycle transitions", "Publishes the register's code lists, retention schedule and public-record element list" ] }, { "name": "Data subject (the person)", "responsibilities": [ "Owns and controls personal-sphere data, self-declared attributes and contact points", "Grants, scopes and withdraws consent over their data", "Exercises access, rectification, erasure, restriction, portability and objection rights", "Reads their own complete record and their own access log" ] }, { "name": "Identity information provider or credential issuer", "responsibilities": [ "Issues identifiers, documents and attestations bound to the person", "Publishes and maintains evidence status (valid, suspended, revoked)", "Records the proofing evidence and resulting assurance level" ] }, { "name": "Relying party or verifier", "responsibilities": [ "States purpose, lawful basis and the minimum attribute set before requesting data", "Accepts derived predicates in place of raw attributes wherever they suffice", "Retains only what its stated purpose requires and honours withdrawal notifications" ] }, { "name": "Model steward", "responsibilities": [ "Maintains bundles, layers, findings, functions and their source citations", "Reviews conflicts between aligned standards and records the governing choice and rationale", "Approves breaking changes, deprecations and migrations of identity priority" ] }, { "name": "Data protection officer or oversight authority", "responsibilities": [ "Reviews lawful bases, special-category conditions and the retention schedule", "Audits disclosure logs, erasure decisions and refusals", "Handles complaints, escalations and cross-border transfer questions" ] } ], "access": { "default_rule": "Deny by default. Every read, presentation or export is scoped to a named purpose, a lawful basis and the narrowest approved projection for the requester's class. The person always retains full self-access to their own records and access logs.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Statutory public-record extracts defined by registration law may be released without the person's consent, limited strictly to the elements that law makes public.", "Vital statistics extracts are released to statistical authorities only in aggregated or de-identified form.", "Emergency, judicial or law-enforcement access follows a named legal instrument, is time-bounded, is minimised to the elements the instrument covers, and is always logged even when notification to the person is lawfully deferred.", "Guardians and legal representatives access only within their recorded scope of authority and only during the arrangement's validity period.", "Where an assurance level is insufficient for a requested attribute, access is refused rather than downgraded, and the refusal is logged with its ground.", "Parental responsibility or recorded representation for a child or supported person, limited to the arrangement scope and review period", "Court order or other legal obligation with expiry and audit identifier", "Vital-statistics production of anonymised aggregates", "Emergency vital-interests processing under GDPR Article 6(1)(d)", "Legally public civil-status extracts that exclude the personal sphere" ], "audit_requirements": [ "Log requester identity, role, purpose, lawful basis, requested and released attribute sets, decision and an RFC 3339 timestamp for every access to registered-identity, evidence or special-category data.", "Log every consent grant, scope change and withdrawal, together with the propagation outcome to each downstream recipient.", "Log every lifecycle transition, merge, split, correction, presumed-death reversal and erasure decision with the authorising role and evidence reference.", "Retain audit logs under their own retention rule, keep them append-only and immutable, and make them readable by the person and by the oversight authority.", "Record failed and refused access attempts with the same field set as successful ones.", "Record requester, purpose, projection type, attribute identifiers disclosed or withheld, lawful basis or exception, and decision time as RFC 3339", "Record corrections with prior value, new value, authority and evidence", "Record consent withdrawal and erasure decisions including permanent-register overrides", "Bind audit entries to the audit service rather than embedding an audit store in the person record" ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Registry ID and Model ID", "Owner or maintainer and register of record", "Access policy URL", "Source and alignment index URL", "Code list registry URL" ], "read_order": [ "AGENTS.md first: read Name, Type, Registry ID, Model ID and the four mandatory URLs before performing any read or write, regardless of whether storage is MongoDB, MCP, Git or files.", "Specification URL: scope, exclusions, boundary notes, bundle/layer/finding structure and the identity priority rule.", "Storage type URL: how the format-neutral model is projected into the chosen store, including canonicalisation, temporal field typing and tombstone behaviour.", "Interface URL: the access interface and its mandatory purpose and lawful-basis parameters, plus the available disclosure projections.", "Processes URL: registration, correction, merge and split, lifecycle transition, disclosure, retention and subject-right procedures with their authorising roles.", "Access policy URL and code list registry: confirm the jurisdiction bindings and projection entitlements before requesting any attribute.", "Only then read model content, beginning with the civil-identity-core bundle and its identity-anchor layer." ] } }, "coverage": { "claim": "Base is the Claude result (7 bundles, 14 layers, 28 findings, 13 functions) plus one grok-sourced finding and one renamed grok-sourced function, yielding 7 bundles, 14 layers, 29 findings and 14 functions. It covers the natural person as a civil-identity anchor and life-course subject across UN CRVS/LIA, ISO/IEC, EC SEMIC and eIDAS/EUDI PID, W3C, NIST, HL7 and OASIS anchors, with household, vital-event, place, organization, credential-security and consent/audit siblings referenced rather than absorbed. It is not complete in any universal sense: it is EU/UN-weighted, several normative texts were paywalled or not text-extractable, and named exception cases remain deferred.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Entity/identity/identifier separation, reference identifier, domain of applicability, identity priority with an explicit fallback route, and a rule that no attribute combination is an identifier. Grounded in ISO/IEC 24760-1, Core Person Vocabulary and W3C DID." }, { "dimension": "lifecycle", "status": "covered", "notes": "Identity record lifecycle states, evidence status lifecycle, name and standing supersession, death closure and presumed-death reversal are all modelled with authority, ground and timestamp. The exact state vocabulary is deliberately left bindable rather than asserted." }, { "dimension": "relationships", "status": "covered", "notes": "Kinship, household, organization, place, event and qualification relationships are all expressed as typed outbound references with a resolving model, never as embedded objects. Record-level same-as links follow FHIR link semantics." }, { "dimension": "temporal", "status": "covered", "notes": "Occurrence, registration and ingestion times are separated as required; RFC 3339 with explicit offset or Z is mandated for timestamps; date-only civil facts keep a precision code; supersession replaces mutation." }, { "dimension": "provenance", "status": "covered", "notes": "Per-attribute source of record, last-verified time, assurance flag distinguishing self-declared from authority-verified, and authoritative-versus-copied flags on credential-asserted attributes." }, { "dimension": "ownership", "status": "covered", "notes": "Two-owner split made explicit and enforced by policy: registrar of record owns registered identity, the person owns the personal sphere and all grants. Reclassification between them requires a recorded decision." }, { "dimension": "validation", "status": "covered", "notes": "Identifier format and check rules, proofing step outcomes and assurance levels, contact verification state, matching thresholds, deletion verification evidence, and canonicalisation rejecting bare code literals." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default with purpose and lawful basis on every read, four access scopes, named exceptions for public records, statistics, emergency/judicial access and representatives, and refusal instead of assurance downgrade." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention classes and periods, suppression preferred over destruction, explicit erasure-exemption route for permanently retained vital records, recorded deletion method and residual tombstone, audit logs exempt from erasure. Underlying legal conflict is recorded below." }, { "dimension": "interoperability", "status": "covered", "notes": "Versioned alignment mappings with lossy-field marking, a conformance-claim flag defaulting to false, an explicit governing-standard choice on conflict, and dedicated script, encoding, transliteration and truncation handling." }, { "dimension": "spatial", "status": "covered", "notes": "Places of birth, death and residence are pointers with granularity, kind and validity; address value shapes are mixed in from OASIS xAL; statistical usual residence is explicitly excluded to the census/statistics model." }, { "dimension": "authority", "status": "covered", "notes": "Registrar of record, issuing authority, deciding authority for standing changes, and authorising role for every lifecycle transition, correction, merge and erasure are all required fields rather than optional metadata." }, { "dimension": "evidence and assurance", "status": "covered", "notes": "Evidence is modelled as separate from identity, with issuer, validity, status source, holder binding and per-attribute authoritativeness; proofing outcomes carry an assurance level, criteria version and re-proofing due date." }, { "dimension": "privacy and special categories", "status": "covered", "notes": "Special-category flagging, exclusion from default projections, predicate-first disclosure, identifier correlatability classes and pseudonym derivation, and a caution that group membership can reveal special-category data." }, { "dimension": "measurement", "status": "covered", "notes": "Multiple-birth order, biometric capture quality and encoding standard, match confidence scores and population quality indicators (completeness, timeliness, duplication rate) are modelled as measured values with method references." }, { "dimension": "security", "status": "not-applicable", "notes": "Authenticators, keys, sessions and login security are deliberately out of scope and delegated to a sibling security model, following the NIST separation of proofing and enrollment from authenticator management. Only holder-binding method and artifact integrity are retained here." }, { "dimension": "identity record lifecycle state vocabulary", "status": "gap", "notes": "ISO/IEC 24760-1 is paywalled and its normative state list could not be retrieved; state names circulating in secondary summaries (unknown, established, active, suspended, archived) are not treated as canonical. The model requires the adopting Dimension to publish and bind its own vocabulary." }, { "dimension": "cross-border recognition of status", "status": "gap", "notes": "No single authoritative source governs recognition of foreign civil status, foreign gender recognition or foreign capacity decisions. Questions exist for the recognition procedure and evidence, but the decision rules must be supplied per jurisdiction." }, { "dimension": "exception handling", "status": "covered", "notes": "Explicit routes for missing authoritative identifiers, undocumented and stateless persons, presumed death and its reversal, incorrect merges, late and retroactive registration, refused subject-right requests, and truncated machine-readable names." } ], "known_omissions": [ "ISO/IEC 24760-1:2025 and ICAO Doc 9303 are paywalled; their catalogue and store pages were retrieved but the normative clause text was not. Definitions and lifecycle states from these standards are therefore treated as alignment targets to be bound, not reproduced as canonical.", "EUR-Lex retrieval of Regulation (EU) 2016/679 failed repeatedly during this research; the Article 9(1) special-category wording was verified against an unofficial reproduction (SRC-012). The OJ text remains governing and should be re-verified before implementation.", "OHCHR retrieval of the CRPD returned HTTP 403; Article 12(2) wording was verified from quoting sources rather than the treaty page itself.", "The UN Principles and Recommendations Rev. 3 PDF could not be text-extracted by the tooling; its publication metadata and the vital-event list were confirmed via the UNSD Standards and Methods catalogue page rather than the document body, so paragraph-level citations are not given.", "No dedicated source was consulted for indigenous, customary or non-state identity registration practices, nor for refugee and forced-displacement registration systems (for example UNHCR registration), which would likely add a finding on alternative registration routes.", "Biometric modality specifics (ISO/IEC 19794 and 39794 profiles), and the retention and template-protection rules that follow from them, are referenced only as pointers and not modelled.", "Child-specific protections beyond birth registration (right to preservation of identity, adoption record sealing and later access) are not given a dedicated finding; they were identified as a likely addition.", "Deceased-person data handling after death, where most data-protection regimes stop applying but registry obligations continue, is only partially covered by the retention finding.", "Machine-readable name matching across scripts is modelled structurally, but no normative matching algorithm or threshold is recommended, because none was found with sufficient authority.", "No extracted primary UN paragraph was located in this pass for foundlings, confidential birth (including accouchement sous X), intersex markers, or identity restoration after presumed death; those are recorded as likely operating cases, not as canonical UN rules.", "ISO/IEC 24760-1 normative text is paywalled; terms used here are those confirmed by the ISO abstract/OBP statement and the IDPro review.", "Religious personal-status systems and indigenous naming authorities beyond CIQ extensibility are not specified.", "Population-register (Nordic-style) versus event-register architectures are acknowledged by UN LIA interoperability language but not modelled as alternative masters.", "Posthumous personality, digital remains, nasciturus/unborn legal subjectivity, and biometric matching thresholds lack primary support in the sources used.", "World Bank ID4D, NIST SP 800-63 and W3C DID/VC were not fetched within the source budget; they are likely omissions for digital-identity assurance and self-sovereign identifiers.", "Hague conventions on protection of adults and apostille legalisation of civil documents were not fetched." ], "conflicts": [ "Sex and gender coding conflict: ISO/IEC 5218:2022 provides only 0/1/2/9 and explicitly excludes gender identity, the EUDI PID Rulebook extends the sex attribute with additional values, and schema.org accepts free text. No single interoperable code list exists; the model therefore separates administrative sex, legal gender recognition and self-identified gender into three governed values and requires each to carry its code list reference.", "Erasure versus permanence: EU law grants an erasure right, while UN civil-registration guidance treats vital records as permanent legal instruments. The legal-obligation exemption resolves the case in practice, but the defaults conflict, so the model requires an explicit exempt-element list rather than a global setting.", "Name stability: the Core Person Vocabulary presents the full name as a stable core label, whereas civil-registration practice and the PID/ICAO document world treat birth name and current name as separate, time-bounded values. This model follows the time-bounded reading and treats the CPV framing as a simplification.", "Cardinality of person records: FHIR explicitly permits several Patient records for one human and reconciles them with link, while this model asserts one anchor per natural person. Resolved by separating the record plane from the entity plane; no destructive merge is implied across systems.", "Identifier governance: W3C DIDs deliberately avoid a central registration authority, while civil registration presumes an authoritative registrar identifier. The identity priority rule resolves this in favour of the registrar identifier, with DIDs as the second-priority governed global identifier.", "Assurance signalling: schema.org Person carries person data with no assurance, authority or validity semantics, yet is the most widely deployed vocabulary. Treated as a publication projection only, and explicitly barred from being read as an assurance signal.", "CPV Person excludes imaginary people; schema.org Person includes fictional and undead characters.", "CPV 2.1.2 sex is defined as the organism's biological sex, which this civil-identity model must not own; UN LIA lists sex as a legal-identity characteristic; ICAO uses M/F/X.", "CPV domicile (Address: permanent home) and residency (Jurisdiction: dwelling) have overlapping usage notes versus classical domicile/habitual-residence law.", "CPV citizenship versus ICAO nationality are not the same legal concept.", "EU Publications Office country codes EL and UK versus ISO 3166-1 GR and GB.", "CRPD Article 12 and Committee General Comment No. 1 require supported rather than substitute decision-making; most national guardianship laws still substitute.", "GDPR erasure and storage limitation versus UN civil registration as continuous and permanent; GDPR generally concerns living natural persons, while death-retired records persist.", "eIDAS unique identifiers may be pairwise or derived and must not be treated as national personal numbers.", "ISO/IEC 24760 applies to non-human principals; this model does not.", "Anglo-American first/middle/last name semantics (default CIQ samples, schema.org comments, eIDAS given/family split) versus cultures without those parts." ], "regional_assumptions": [ "Data-subject rights, lawful bases and special-category rules are stated in EU terms (GDPR); other jurisdictions require their own binding and may lack an erasure or portability right entirely.", "The person identification data attribute set is EU-specific (EUDI ARF); other regions use different mandatory attribute sets, and the personal administrative number's uniqueness policy is issuer-defined rather than harmonised.", "CRPD Article 12's shift from substituted to supported decision-making is ratified unevenly and interpreted differently; many jurisdictions still operate plenary guardianship, so the model records arrangement type rather than assuming supported decision-making.", "Civil status vocabularies, name-part conventions, name-ordering rules and national personal identifier schemes are jurisdiction-specific and must be bound in the owner package.", "Alpha-2 country coding for nationality does not represent statelessness, undetermined nationality or contested territories well; the model therefore carries a separate nationality determination status.", "Legal gender recognition regimes vary from unavailable to self-declaration-based, which changes both the permitted values and who may change them.", "NIST assurance levels are a US federal framework; European and other schemes use different level definitions that are not one-to-one mappable.", "UN CRVSID is treated as the global operating frame: civil registration as identity factory, identity management as credentialing, vital statistics as reuse. Common-law splits between vital records and identity cards, and Nordic population registers, must be mapped into that frame rather than assumed identical.", "Age of majority is jurisdiction-specific; GDPR Article 8 child-consent ages vary by Member State.", "Latin MRZ transliteration is mandatory for ICAO documents even when the legal name is in another script.", "EU eIDAS PID and CPV are authoritative inside the Union and alignments elsewhere, not world law.", "Refugee identity may be issued by UNHCR or another mandated authority only where the host State so recognises." ], "adversarial_checks": [ "Tested whether Person should absorb household, family and kinship: rejected. UN civil-registration guidance treats household as a separate statistical unit and family ties as separately registered acts, so a candidate filiation finding was removed and replaced with a reference link and boundary note.", "Tested whether identity documents or credentials constitute identity: rejected. UN legal-identity guidance and ISO/IEC 24760 both treat documents as evidence of a registered identity, which is why evidence revocation is explicitly barred from closing the person anchor.", "Tested whether a national identifier can serve as the universal primary key: rejected. Stateless, undocumented and displaced persons often have none, so the identity priority rule mandates a fallback with a recorded reason, and a statelessness determination finding was added.", "Tested whether name plus date of birth is a usable identifier: rejected. A date is not an identifier and name/date collisions are common, which forced explicit match-confidence modelling and a linkage decision artifact rather than implicit deduplication.", "Tested whether schema.org Person could be the canonical shape: rejected. It lacks validity periods, issuing authority and assurance, so it is retained only as a lossy publication projection with a conformance-claim flag defaulting to false.", "Tested whether one gender field suffices: rejected. Three distinct governed values with different owners, code lists and disclosure rules were found once ISO/IEC 5218's explicit exclusion of gender identity was read against the EUDI and schema.org treatments.", "Searched for a counterexample to one-anchor-per-person and found one in FHIR, which permits multiple Patient records for a single human; rather than discarding the anchor rule, the model separates record plane from entity plane and adopts link semantics.", "Tested whether personal-sphere data could be governed by the same owner as the registered identity: rejected. UN legislative guidance and data-protection law separate registrar duties from subject control, so a policy bars silent reclassification between the two.", "Could a legal person, device, fictional character or FHIR Patient be stored as this Person? Rejected by CPV non-imaginary natural-person rule, GDPR natural-person definition, and explicit organism/health exclusion.", "Could a passport number or eIDAS UID be treated as the person? Rejected by ISO/IEC 24760 identifier-versus-identity distinction and eIDAS pairwise-identifier matching rules.", "Could household membership or parent/child links be copied into this model from schema.org? Rejected; those properties are sibling-model references only.", "Could self-declared gender overwrite the civil marker or ICAO document field without a civil event? Rejected by split ownership and marker-change as a registered event.", "Could death or an erasure request destroy the civil register? Rejected: death retires identity; the register is permanent; erasure applies to personal-sphere data unless law archives it.", "Could substitute guardianship be modelled as if CRPD had abolished it worldwide? Rejected: Article 12 text plus the documented Committee-versus-State conflict must both be representable." ] }, "researchAdjudication": { "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "Both providers independently resolved WM-PER-001 as an entity and both drew the same outer line: the natural person as a civil-identity subject, with the biological organism, household/filiation, organisational roles and location master data resolved in sibling models, and documents/identifiers treated as evidence rather than as the person. Claude's boundary is adopted because it names each neighbour with a stated distinction and source refs (FHIR Patient, household, vital-event act, address/place, organization, authenticator security, consent/audit services, schema.org projection) and separates the record plane from the entity plane. Grok's explicit exclusions of legal persons, devices and fictional/undead characters are folded into the base boundary prose as clarifying text, not as new structure." }, "decisions": [ { "concept": "Base provider selection", "disposition": "Claude as base", "rationale": "Chosen on boundary clarity, not size: eight neighbour-by-neighbour boundary notes with source refs, complete in/out-of-scope lists, an explicit record-plane versus entity-plane split, and adversarial checks that individually tested household absorption, document-as-identity, national-identifier-as-primary-key and schema.org-as-canonical. Grok's boundary is compatible but coarser and leaves quality, interoperability and disclosure concerns folded into a single governance bundle." }, { "concept": "Entry kind", "disposition": "Accepted as entity", "rationale": "Both providers independently returned entity with matching subject framing (a referenceable civil-identity subject other models point at), so no reclassification, split or merge of the registry entry is warranted before nodes are accepted." }, { "concept": "Alternative registration routes (refugee, host-State, mandated authority, delayed conferral)", "disposition": "Accepted into identity-anchor", "rationale": "The only grok finding that is materially absent from the base, evidence-backed in UN LIA and the UN CRVS-IdM handbook, and separable without restating an existing base finding. The base explicitly listed this as a likely missing finding." }, { "concept": "Evidence status change / document revocation operation", "disposition": "Accepted as a renamed function", "rationale": "Fills a real operational gap: the base models evidence status as a question but never transitions it. Renamed to keep issuance and revocation attributed to the issuing authority, consistent with the base's organization boundary note." }, { "concept": "Citizenship as a jurisdiction tie versus nationality as document encoding", "disposition": "Rejected as an addition, deferred as research", "rationale": "Grok's citizenship-ties would sit beside nationality-holding and statelessness-determination in the same layer while restating holding, conferring authority, dates and stateless/refugee status. The genuine delta is terminological (CPV citizenship as a Jurisdiction relationship versus ICAO nationality encoding), which belongs in the existing finding's text once primary wording is verified, not in a third overlapping node." }, { "concept": "Contact, domicile and residency as one finding", "disposition": "Rejected as an addition, residency delta deferred", "rationale": "Two thirds of grok's contact-domicile-residency duplicates the base findings person-controlled-contact-point and declared-residence-pointer. The only new content is residency as a tie to a jurisdiction (habitual residence) rather than a pointer to an address, which should extend the existing residence finding rather than create a duplicate node." }, { "concept": "Minority, age of majority and child consent", "disposition": "Rejected as an import, deferred as a dedicated finding", "rationale": "Grok carries GDPR Article 8 child consent and age-of-majority rules only inside a combined capacity-and-representation finding that duplicates the base's legal-capacity-state and representation-arrangement. The base separately flags child-specific protections as a likely addition, so this is queued as its own research task instead of imported as overlapping structure." }, { "concept": "Identity conferral and retirement as a distinct finding", "disposition": "Rejected as duplicative", "rationale": "Grok's identity-create-and-retire is covered by the base's birth-facts-record, vital-status-and-death, identity-record-lifecycle and the register-person-identity and close-identity-on-death functions. Its unique value is normative grounding (CRC Article 7, ICCPR Article 24(2), SDG 16.9), which is a citation improvement to existing nodes, not new structure." }, { "concept": "Document sex field versus civil-register marker", "disposition": "Rejected as duplicative", "rationale": "The base already governs three distinct values (administrative sex, legal gender recognition, self-identified gender) and handles document divergence generically through q-evid-attributes, which asks which evidence-asserted attributes are authoritative rather than copied. The ICAO M/F/X value set is a code-list binding for the existing finding." }, { "concept": "eIDAS pairwise identifier matching constraint", "disposition": "Rejected as an addition, retained as a constraint", "rationale": "The base's identifier-correlation covers pairwise and sector-specific pseudonym derivation and omission, and duplicate-detection-and-merge covers matching evidence and thresholds. Grok's rule that an eIDAS unique identifier must not be assumed equal to a national personal number tightens those existing nodes rather than justifying a new finding." }, { "concept": "Vital-statistics extract function", "disposition": "Rejected on boundary grounds", "rationale": "The base explicitly places the vital-event registration record and its statistical processing outside this model, and delegates usual residence as a statistical construct to the census/statistics model. Accepting produce-vital-statistics-extract would reopen a boundary the base closed deliberately; statutory public-record release stays covered by emit-minimal-disclosure and q-disc-public." }, { "concept": "Issue identity document function", "disposition": "Rejected as boundary-crossing and duplicative", "rationale": "Issuance is an act of the issuing authority, an organization the base references but does not define; the base already records the resulting artefact through record-identity-evidence with issuer, validity, asserted attributes and holder binding." }, { "concept": "Verify-identity and match-person-records functions", "disposition": "Rejected as duplicative", "rationale": "Covered by assess-identity-assurance (proofing outcome and assurance level), emit-minimal-disclosure (confirm only what was asked, with logging), resolve-person-reference and merge-or-split-person-records. Importing them would create two operations with the same trigger and outcome." }, { "concept": "Service-layer composition (consent, audit, disclosure ledgers)", "disposition": "Merged as composed service references", "rationale": "Both providers agree that grant stores, policy decision points and audit ledgers are sibling service components referenced from the person model, so the base's lawful-basis, disclosure and retention findings stay as declarations of what must be governed and logged, without duplicating the service structure." }, { "concept": "schema.org Person", "disposition": "Retained as a lossy publication projection only", "rationale": "Both providers reached the same conclusion from different angles (no validity periods, issuing authority or assurance semantics; admits fictional and undead characters), so it stays a projection target with a conformance-claim flag defaulting to false and is barred from being read as an assurance signal." } ], "publicationHolds": [ "Reconcile and re-pin the Core Person Vocabulary version before publication: base cites CPV 2.00 (2022-04-01), grok cites CPV 2.1.2 (2026-05-12). Properties grok relies on (Contact Point on Person, residency as Jurisdiction, the gender/sex split, GenericDate) must be confirmed against the live release actually pinned.", "Reconcile the ISO/IEC 24760-1 edition: base cites the 2025 edition, grok cites 2019. Both retrievals were catalogue-level only, so no definition, identifier taxonomy or identity-record state vocabulary may be published as canonical from this standard.", "Re-verify GDPR Article 9 special-category wording against the EUR-Lex OJ text; the base verified it from an unofficial reproduction (tier 3) after repeated EUR-Lex retrieval failure.", "Re-verify CRPD Article 12 and General Comment No. 1 wording against an official UN-hosted text; one provider recorded an HTTP 403 at OHCHR and quoted secondary sources.", "Verify every accepted source URL as live and version-pinned, including the two OASIS CIQ v3.0 URL variants, both ICAO Doc 9303 landing pages, and the UN Principles and Recommendations Rev.3 PDF whose body could not be text-extracted (paragraph-level citations are currently absent).", "Run domain-profile validation on at least one non-EU profile before publication: the model is EU/UN-weighted (GDPR, eIDAS/EUDI PID, CPV, NIST levels), and a common-law vital-records plus ID-card regime and a Nordic population-register architecture must be mapped into the frame rather than assumed equivalent.", "Correct the base coverage-claim counts: it states 7 bundles, 15 layers and 28 findings, but the base structure contains 14 layers; after the accepted addition the merged model is 7 bundles, 14 layers, 29 findings and 14 functions.", "Scope the imported alternative-registration-routes finding on publication: only the UN LIA and CRVS-IdM backed portion (host-State or internationally mandated issuance, conferral by an identification authority linked to civil registration, delayed registration) may be presented as sourced; foundling, unknown-parentage and presumed-death-restoration sub-cases must be marked as unsourced operating cases, and the overlap with q-stateless-substitute must be resolved." ], "deferredResearch": [ "Dedicated minority finding: age of majority and its jurisdictional variation, emancipation, and GDPR Article 8 child-consent thresholds, plus child-specific identity protections (preservation of identity, adoption record sealing and later access) that the base flagged as a likely addition.", "Citizenship as a legal tie to a jurisdiction versus nationality as encoded on travel documents: verify CPV and ICAO wording and decide whether the base nationality-holding finding is retitled or split, rather than adding a third overlapping node.", "Residency and habitual residence as a jurisdiction tie distinct from the address-typed domicile pointer, including which one governs applicable law; extend declared-residence-pointer rather than duplicating the contact layer.", "Foundlings, unknown parentage, confidential birth (including accouchement sous X), intersex civil markers, and identity restoration after a presumed or judicially declared death: no primary UN paragraph was located by either provider.", "Cross-border recognition of foreign civil status, foreign gender recognition and foreign capacity decisions, including the Hague Convention on the international protection of adults and apostille legalisation of civil documents, which neither provider fetched.", "Digital-identity assurance beyond the sources used: World Bank ID4D practice, and reconciliation of NIST SP 800-63A-4 assurance levels with eIDAS levels of assurance, which are not one-to-one mappable.", "Biometric modality profiles (ISO/IEC 19794 and 39794) and the template-protection, retention and matching-threshold rules that follow; both providers reference biometrics only as pointers and neither found an authoritative matching threshold for cross-script name matching.", "Deceased-person data handling after death and posthumous personality or digital remains, where most data-protection regimes stop applying while permanent registry obligations continue." ] }, "statistics": { "sources": 26, "bundles": 7, "layers": 14, "findings": 29, "questions": 103, "artifacts": 31, "functions": 14 } }