# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T15:20:23Z", "synthesisSha256": "68d9c4aa452c73a6e83d32d6ee380dfa844063f0ef3bac992755ccee0ee0be76", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-PER-002", "registryId": "vr.wm-per-002", "name": "Digital Identity / Account", "version": "0.3.0-reviewable-draft", "previousVersions": [ { "version": "0.2.0-legacy", "url": "/models/world-r4-identity-register/" } ], "entryKind": "entity", "family": "World Models", "category": "Society, people and institutions", "industry": [ "Cross-industry" ], "domain": [ "SOC.PER.DIG" ], "tags": [ "digital", "identity", "account", "soc.per.dig" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-per-002-digital-identity-account/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-per-002", "model": { "registry_id": "vr.wm-per-002", "model_id": "WM-PER-002", "name": "Digital Identity / Account", "entry_kind": "entity", "purpose": "Describe one persistent digital identity record or subscriber account within a declared identity-service authority and namespace.", "scope_statement": "An identity-service record that binds scoped identifiers, subject assertions, authenticator references and assurance evidence over time. It is distinct from the represented person or organization, an identity register as a whole, and an application-specific online account. Federation is optional. Primary assurance coverage concerns natural persons; other subject kinds require separately justified profiles.", "in_scope": [ "Scoped identity and subject/controller distinctions, identifier bindings and explicit account linkage assertions", "Enrollment and proofing references, qualified assurance observations, authenticator and recovery metadata", "Identity-service lifecycle, federation bindings, restricted disclosure and retention evidence" ], "out_of_scope": [ "Population register operations, civil identity adjudication, person or organization master profiles, universal identity resolution", "Application-specific membership, purchases, content, subscriptions and virtual assets belonging to WM-VRT-005", "Private keys, passwords, recovery codes, bearer tokens, raw biometrics and source identity-document payloads", "Executing authentication, recovery, credential issuance, provisioning, authorization decisions, remote revocation or legal erasure" ], "boundary_notes": [ { "neighbor": "WM-XCT-016 Identity Register", "distinction": "The R4 legacy alias is shared. Register-wide indexing, registrar governance and population uniqueness belong to the register; this entity carries an optional register reference only. The legacy EXTEND world.registry and legal-effect claim are not inherited.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] }, { "neighbor": "WM-VRT-005 Online Account", "distinction": "The frozen inbound candidate REFERENCE lets an application account bind to this identity. Application lifecycle, entitlements and content remain there; no reciprocal containment or automatic synchronization is implied.", "source_refs": [ "SRC-003", "SRC-006" ] }, { "neighbor": "WM-PER-001 Person and external organization or thing master", "distinction": "The identity record describes assertions about a subject without owning that subject. A person can have several contextual identities; organization and thing profiles cannot inherit natural-person IAL requirements.", "source_refs": [ "SRC-001", "SRC-007" ] }, { "neighbor": "WM-XCT-017 Attestation / Credential and authenticator service", "distinction": "Credential assertions and authenticators have their own issuer, lifecycle and authority. This entity stores references, status observations and binding evidence, never secrets or credential issuance functions.", "source_refs": [ "SRC-002", "SRC-008" ] }, { "neighbor": "WM-XCT-002 Access Contract / Consent", "distinction": "Record purpose, policy and consent references. Identity proofing or successful authentication does not itself authorize access; policy masters and enforcement remain external.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "neighbor": "Authentication events and session services", "distinction": "Event and session references can qualify observations, but the persistent identity is neither a login event nor a session. Local closure is not proof that every remote session ended.", "source_refs": [ "SRC-002", "SRC-003" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Identity Proofing and Enrollment", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/800-63-4/sp800-63a.html", "version_or_date": "SP 800-63A-4, July 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "Sections 1, 3, 5 and 7: scoped enrollment, proofing evidence, subscriber records, closure and privacy; natural persons only." }, { "id": "SRC-002", "title": "Authentication and Authenticator Management", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/800-63-4/sp800-63b.html", "version_or_date": "SP 800-63B-4, July 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "Sections 2, 4 and 5: authenticator binding, recovery, notifications and session separation; no implementation or security certification." }, { "id": "SRC-003", "title": "Federation and Assertions", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/800-63-4/sp800-63c.html", "version_or_date": "SP 800-63C-4, July 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "Section 3.8: relying-party subscriber accounts, linking and removal; trust context and separate authorization boundary." }, { "id": "SRC-004", "title": "System for Cross-domain Identity Management: Core Schema", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc7643", "version_or_date": "RFC 7643, September 2015", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "Sections 3.1 and 4.1: scoped resource ID, administrative state and attribute metadata. Conceptual alignment only." }, { "id": "SRC-005", "title": "System for Cross-domain Identity Management: Protocol", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc7644.html", "version_or_date": "RFC 7644, September 2015", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "Sections 3.3, 3.5, 3.6 and 3.14: provisioning, updates, deletion and version controls. Deletion response is not erasure proof." }, { "id": "SRC-006", "title": "OpenID Connect Core 1.0 incorporating errata set 2", "organization": "OpenID Foundation", "url": "https://openid.net/specs/openid-connect-core-1_0.html", "version_or_date": "Final, errata set 2, 2023-12-15", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "Sections 2, 5.7 and 8: issuer-subject identity and pairwise identifiers. Email is not a stable account key." }, { "id": "SRC-007", "title": "Decentralized Identifiers v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/2022/REC-did-core-20220719/", "version_or_date": "Recommendation, 2022-07-19", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "Sections 2, 5, 7, 9 and 10: subject/controller separation, method-specific operations and privacy. Identifier control alone does not prove real-world identity." }, { "id": "SRC-008", "title": "Web Authentication: An API for accessing Public Key Credentials - Level 2", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/webauthn-2/", "version_or_date": "Recommendation, 2021-04-08", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "User handle definition, sections 5.4.3 and 14.6: account-scoped credential binding and privacy. Pinned Level 2, no latest-level claim." }, { "id": "SRC-009", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:18:38Z", "relevance": "Section 5.6 supports offset-bearing timestamp syntax; no implied clock accuracy or deadline semantics." } ], "structure": { "bundles": [ { "id": "per002-b-identity", "name": "Identity and naming", "description": "Root and externally scoped identifiers.", "rationale": "Keep root and externally scoped identifiers coherent while retaining separate external masters and evidence limits.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007" ], "layers": [ { "id": "per002-l-anchor", "name": "Scoped identity anchor", "description": "Context for scoped identity anchor. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "findings": [ { "id": "per002-f-anchor", "name": "Scoped identity anchor", "description": "The root is one identity-service record with a stable local key. Names and contact addresses remain changeable attributes, and identity does not imply legal personhood.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "questions": [ { "id": "per002-f-anchor-q1", "text": "Which authoritative namespace and master identifier distinguish this record?", "kind": "identity", "answer_data": [ "authority_ref", "namespace", "master_id" ] }, { "id": "per002-f-anchor-q2", "text": "Which subject kind and identity-service profile govern this anchor?", "kind": "classification", "answer_data": [ "subject_kind", "profile_ref" ] }, { "id": "per002-f-anchor-q3", "text": "What prevents reuse of a retired master identifier for a different record?", "kind": "constraint", "answer_data": [ "reuse_rule", "retirement_evidence" ] }, { "id": "per002-f-anchor-q4", "text": "Which subject reference is asserted, unknown or disputed?", "kind": "relationship", "answer_data": [ "subject_ref", "assertion_status" ] } ], "data_elements": [ { "id": "per002-f-anchor-data-master-id", "name": "Scoped master identifier", "description": "Scoped master identifier. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "per002-f-anchor-data-authority-ref", "name": "Identity-service authority reference", "description": "Identity-service authority reference. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "per002-f-anchor-data-subject-binding", "name": "Subject kind, optional master reference and assertion status", "description": "Subject kind, optional master reference and assertion status. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "per002-f-anchor-artifact", "name": "Scoped identity anchor record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "per002-l-identifier", "name": "Identifier bindings", "description": "Context for identifier bindings. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ], "findings": [ { "id": "per002-f-identifier", "name": "Identifier bindings", "description": "Bindings preserve issuer, scheme, audience and validity. Comparison uses profile-specific rules; matching labels or email addresses cannot silently merge identities.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ], "questions": [ { "id": "per002-f-identifier-q1", "text": "Which issuer, scheme and value identify each external binding?", "kind": "identity", "answer_data": [ "issuer", "scheme", "identifier_value" ] }, { "id": "per002-f-identifier-q2", "text": "During which interval is each identifier binding supported by evidence?", "kind": "temporal", "answer_data": [ "valid_from", "valid_until", "observed_at" ] }, { "id": "per002-f-identifier-q3", "text": "Which bindings are pairwise or restricted from correlation?", "kind": "privacy", "answer_data": [ "audience", "correlation_policy_ref" ] }, { "id": "per002-f-identifier-q4", "text": "Which case and normalization rules apply without changing identifier meaning?", "kind": "interoperability", "answer_data": [ "comparison_profile", "raw_value_ref", "normalization_rule" ] } ], "data_elements": [ { "id": "per002-f-identifier-data-bindings", "name": "Issuer-qualified binding descriptors and status", "description": "Issuer-qualified binding descriptors and status. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] }, { "id": "per002-f-identifier-data-comparison-profile", "name": "Identifier comparison profile reference", "description": "Identifier comparison profile reference. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] }, { "id": "per002-f-identifier-data-audience-rules", "name": "Audience and correlation restriction references", "description": "Audience and correlation restriction references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "per002-f-identifier-artifact", "name": "Identifier bindings record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-004", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "per002-b-assurance", "name": "Enrollment and assurance", "description": "Evidence and qualified confidence.", "rationale": "Keep evidence and qualified confidence coherent while retaining separate external masters and evidence limits.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "layers": [ { "id": "per002-l-enrollment", "name": "Enrollment and proofing record", "description": "Context for enrollment and proofing record. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-001" ], "findings": [ { "id": "per002-f-enrollment", "name": "Enrollment and proofing record", "description": "Enrollment records the chosen profile and evidence outcomes, including a declared unproofed state. Evidence pointers are purpose-limited; absence of a proofing result is not a successful result.", "source_refs": [ "SRC-001" ], "questions": [ { "id": "per002-f-enrollment-q1", "text": "Which enrollment route and approved exception path were used?", "kind": "process", "answer_data": [ "route", "exception_ref" ] }, { "id": "per002-f-enrollment-q2", "text": "Which proofing assessment and evidence references support enrollment?", "kind": "evidence", "answer_data": [ "assessment_ref", "evidence_refs", "assessor_ref" ] }, { "id": "per002-f-enrollment-q3", "text": "Is proofing unperformed, pending, completed, failed or disputed?", "kind": "state", "answer_data": [ "proofing_state", "outcome_reason" ] }, { "id": "per002-f-enrollment-q4", "text": "What unresolved mismatch or redress request qualifies the enrollment outcome?", "kind": "quality", "answer_data": [ "mismatch_refs", "redress_ref", "review_due" ] } ], "data_elements": [ { "id": "per002-f-enrollment-data-enrollment-record", "name": "Route, profile, outcome and assessor reference", "description": "Route, profile, outcome and assessor reference. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "per002-f-enrollment-data-proofing-evidence", "name": "Restricted evidence references without document or biometric payloads", "description": "Restricted evidence references without document or biometric payloads. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "per002-f-enrollment-data-exceptions", "name": "Exception and redress case references", "description": "Exception and redress case references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "per002-f-enrollment-artifact", "name": "Enrollment and proofing record record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "per002-l-assurance", "name": "Qualified assurance observations", "description": "Context for qualified assurance observations. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "findings": [ { "id": "per002-f-assurance", "name": "Qualified assurance observations", "description": "Assurance assertions identify framework, assessor, scope and time. Identity proofing, authentication strength and federation protections remain distinct; a historical maximum is not a current universal guarantee.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "questions": [ { "id": "per002-f-assurance-q1", "text": "Which framework and assurance dimension does each recorded level measure?", "kind": "measurement", "answer_data": [ "framework_version", "dimension", "level" ] }, { "id": "per002-f-assurance-q2", "text": "Who assessed the level and which evidence supports it?", "kind": "provenance", "answer_data": [ "assessor_ref", "assessment_ref" ] }, { "id": "per002-f-assurance-q3", "text": "When was assurance assessed and when must applicability be reviewed?", "kind": "temporal", "answer_data": [ "assessed_at", "review_due", "validity_rule" ] }, { "id": "per002-f-assurance-q4", "text": "Which evidence gap prevents interpreting an assurance claim as current?", "kind": "validation", "answer_data": [ "gap_reason", "evaluation_status" ] } ], "data_elements": [ { "id": "per002-f-assurance-data-assurance-claims", "name": "Dimension-specific claims with framework and evidence", "description": "Dimension-specific claims with framework and evidence. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "per002-f-assurance-data-review-rule", "name": "Assurance re-evaluation policy reference", "description": "Assurance re-evaluation policy reference. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "per002-f-assurance-data-assessment-status", "name": "Known, unknown, stale or disputed assessment status", "description": "Known, unknown, stale or disputed assessment status. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "artifacts": [ { "id": "per002-f-assurance-artifact", "name": "Qualified assurance observations record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "per002-b-control", "name": "Control and recovery", "description": "Authenticator bindings and recovery authority.", "rationale": "Keep authenticator bindings and recovery authority coherent while retaining separate external masters and evidence limits.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ], "layers": [ { "id": "per002-l-authenticator", "name": "Authenticator binding metadata", "description": "Context for authenticator binding metadata. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-002", "SRC-008" ], "findings": [ { "id": "per002-f-authenticator", "name": "Authenticator binding metadata", "description": "Bindings connect the identity to externally managed authenticators and public credential references. Binding, compromise and retirement observations are distinct from possession, successful authentication or identity proofing.", "source_refs": [ "SRC-002", "SRC-008" ], "questions": [ { "id": "per002-f-authenticator-q1", "text": "Which authenticator references and permitted purposes are bound?", "kind": "composition", "answer_data": [ "authenticator_refs", "binding_purpose" ] }, { "id": "per002-f-authenticator-q2", "text": "What authorized binding evidence links the authenticator to this identity?", "kind": "security", "answer_data": [ "binding_evidence", "approved_actor_ref" ] }, { "id": "per002-f-authenticator-q3", "text": "Which replacement, compromise or retirement event changes the binding state?", "kind": "lifecycle", "answer_data": [ "event_ref", "binding_state", "effective_at" ] }, { "id": "per002-f-authenticator-q4", "text": "How does the metadata projection exclude secret and reusable authentication material?", "kind": "constraint", "answer_data": [ "allowlist_profile", "rejection_reason" ] } ], "data_elements": [ { "id": "per002-f-authenticator-data-authenticator-bindings", "name": "Credential reference, account scope, purpose and state", "description": "Credential reference, account scope, purpose and state. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-008" ] }, { "id": "per002-f-authenticator-data-binding-evidence", "name": "Protected binding and retirement evidence references", "description": "Protected binding and retirement evidence references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-008" ] }, { "id": "per002-f-authenticator-data-projection-policy", "name": "Metadata-only field allowlist", "description": "Metadata-only field allowlist. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-008" ] } ], "artifacts": [ { "id": "per002-f-authenticator-artifact", "name": "Authenticator binding metadata record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-002", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "per002-l-recovery", "name": "Recovery and controller authority", "description": "Context for recovery and controller authority. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-002", "SRC-007" ], "findings": [ { "id": "per002-f-recovery", "name": "Recovery and controller authority", "description": "Recovery metadata records prerequisites, accountable actors and external outcomes. A controller or representative may differ from the subject; neither support access nor a changed contact address alone proves authority.", "source_refs": [ "SRC-002", "SRC-007" ], "questions": [ { "id": "per002-f-recovery-q1", "text": "Who may request or approve recovery under the applicable policy?", "kind": "authority", "answer_data": [ "requester_role", "approver_role", "authority_ref" ] }, { "id": "per002-f-recovery-q2", "text": "Which accepted evidence and notification obligations apply to the recovery route?", "kind": "requirement", "answer_data": [ "recovery_profile", "evidence_requirements", "notification_refs" ] }, { "id": "per002-f-recovery-q3", "text": "What assisted recovery or dispute route applies when normal prerequisites fail?", "kind": "exception", "answer_data": [ "exception_case_ref", "review_status" ] }, { "id": "per002-f-recovery-q4", "text": "Which confirmed external outcome permits a local recovery status change?", "kind": "event", "answer_data": [ "outcome_ref", "observed_at", "confirmation_state" ] } ], "data_elements": [ { "id": "per002-f-recovery-data-recovery-profile", "name": "Recovery policy reference without recovery codes", "description": "Recovery policy reference without recovery codes. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "per002-f-recovery-data-controller-authority", "name": "Subject/controller distinction and scoped delegation evidence", "description": "Subject/controller distinction and scoped delegation evidence. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "per002-f-recovery-data-recovery-observations", "name": "Outcome and notice references with unresolved states", "description": "Outcome and notice references with unresolved states. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "per002-f-recovery-artifact", "name": "Recovery and controller authority record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "per002-b-federation", "name": "Federation and linkage", "description": "Trust context and explicit cross-record assertions.", "rationale": "Keep trust context and explicit cross-record assertions coherent while retaining separate external masters and evidence limits.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "layers": [ { "id": "per002-l-federation", "name": "Federated identity context", "description": "Context for federated identity context. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-003", "SRC-006" ], "findings": [ { "id": "per002-f-federation", "name": "Federated identity context", "description": "Each federation binding retains identity-provider, issuer, subject and audience context. Token validation and federation execution are external; local metadata must not promote an unvalidated assertion into identity evidence.", "source_refs": [ "SRC-003", "SRC-006" ], "questions": [ { "id": "per002-f-federation-q1", "text": "Which issuer and subject pair identifies the federated identity?", "kind": "identity", "answer_data": [ "issuer", "subject_id" ] }, { "id": "per002-f-federation-q2", "text": "Which relying-party audience and trust agreement qualify the binding?", "kind": "relationship", "answer_data": [ "audience_ref", "trust_agreement_ref" ] }, { "id": "per002-f-federation-q3", "text": "Which external validation result supports acceptance of a federation observation?", "kind": "validation", "answer_data": [ "validation_result_ref", "validated_at", "result_status" ] }, { "id": "per002-f-federation-q4", "text": "Which expiry, stale trust or issuer mismatch blocks reuse of that observation?", "kind": "security", "answer_data": [ "expiry", "trust_state", "mismatch_reason" ] } ], "data_elements": [ { "id": "per002-f-federation-data-federation-bindings", "name": "Issuer, subject, audience and trust references", "description": "Issuer, subject, audience and trust references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] }, { "id": "per002-f-federation-data-validation-observations", "name": "External result references without token payloads", "description": "External result references without token payloads. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] }, { "id": "per002-f-federation-data-trust-profile", "name": "Federation trust profile reference", "description": "Federation trust profile reference. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "per002-f-federation-artifact", "name": "Federated identity context record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "per002-l-linkage", "name": "Explicit linkage and separation", "description": "Context for explicit linkage and separation. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "findings": [ { "id": "per002-f-linkage", "name": "Explicit linkage and separation", "description": "Linkage is a qualified assertion between contextual identities, not silent physical deduplication. Inbound application-account references preserve the separate online-account master and cannot transfer entitlements.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "questions": [ { "id": "per002-f-linkage-q1", "text": "Which identities are proposed as linked and for what limited purpose?", "kind": "relationship", "answer_data": [ "source_identity_ref", "target_identity_ref", "purpose" ] }, { "id": "per002-f-linkage-q2", "text": "Which authenticated request and approval evidence authorize a link?", "kind": "authority", "answer_data": [ "request_ref", "authentication_evidence_ref", "approval_ref" ] }, { "id": "per002-f-linkage-q3", "text": "How is a disputed or erroneous link corrected without merging histories?", "kind": "exception", "answer_data": [ "dispute_ref", "superseding_assertion_ref" ] }, { "id": "per002-f-linkage-q4", "text": "What evidence confirms unlinking and records any remaining access path?", "kind": "lifecycle", "answer_data": [ "unlink_result_ref", "remaining_binding_refs", "notice_ref" ] } ], "data_elements": [ { "id": "per002-f-linkage-data-linkage-assertions", "name": "Purpose, evidence, confidence and status of links", "description": "Purpose, evidence, confidence and status of links. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "per002-f-linkage-data-service-account-refs", "name": "Optional references to separate online-account records", "description": "Optional references to separate online-account records. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "per002-f-linkage-data-linkage-review", "name": "Reviewer decisions and correction references", "description": "Reviewer decisions and correction references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "per002-f-linkage-artifact", "name": "Explicit linkage and separation record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "per002-b-continuity", "name": "Lifecycle and synchronization", "description": "Local continuity with qualified external outcomes.", "rationale": "Keep local continuity with qualified external outcomes coherent while retaining separate external masters and evidence limits.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ], "layers": [ { "id": "per002-l-lifecycle", "name": "Identity-service state and continuity", "description": "Context for identity-service state and continuity. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "findings": [ { "id": "per002-f-lifecycle", "name": "Identity-service state and continuity", "description": "The profile defines admissible local states and transitions. Suspension, closure and identifier retirement are different decisions; death, inactivity or a provisioning response cannot independently prove closure or remote access revocation.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "per002-f-lifecycle-q1", "text": "Which local state is effective under the approved lifecycle profile?", "kind": "state", "answer_data": [ "state", "profile_ref", "effective_at" ] }, { "id": "per002-f-lifecycle-q2", "text": "Which actor and reason authorize the requested state transition?", "kind": "authority", "answer_data": [ "actor_ref", "reason_code", "approval_ref" ] }, { "id": "per002-f-lifecycle-q3", "text": "How are effective time and delayed observation time retained for a transition?", "kind": "temporal", "answer_data": [ "event_time", "observed_at", "sequence" ] }, { "id": "per002-f-lifecycle-q4", "text": "Which precondition or stale revision prevents applying the transition?", "kind": "constraint", "answer_data": [ "expected_revision", "precondition_status", "refusal_reason" ] } ], "data_elements": [ { "id": "per002-f-lifecycle-data-lifecycle-state", "name": "Current local state and effective time", "description": "Current local state and effective time. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "per002-f-lifecycle-data-transition-evidence", "name": "State decision and external outcome references", "description": "State decision and external outcome references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "per002-f-lifecycle-data-revision", "name": "Concurrency revision token", "description": "Concurrency revision token. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "per002-f-lifecycle-artifact", "name": "Identity-service state and continuity record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "per002-l-synchronization", "name": "Projection and remote outcome evidence", "description": "Context for projection and remote outcome evidence. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ], "findings": [ { "id": "per002-f-synchronization", "name": "Projection and remote outcome evidence", "description": "Provisioning and readback observations link this record to external resources without treating the protocol resource as the root. Pending, partial, failed and unknown results remain visible; session termination is separately evidenced.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ], "questions": [ { "id": "per002-f-synchronization-q1", "text": "Which external resource and mapping version correspond to this identity projection?", "kind": "interoperability", "answer_data": [ "external_resource_ref", "mapping_version" ] }, { "id": "per002-f-synchronization-q2", "text": "Which source system is authoritative for each mapped attribute?", "kind": "provenance", "answer_data": [ "field_authority_map", "observed_at" ] }, { "id": "per002-f-synchronization-q3", "text": "What outcome distinguishes a request from confirmed remote state?", "kind": "quality", "answer_data": [ "request_ref", "acknowledgement_ref", "readback_status" ] }, { "id": "per002-f-synchronization-q4", "text": "Which partial failure or unresolved session consequence requires reconciliation?", "kind": "exception", "answer_data": [ "failed_targets", "session_outcome_refs", "reconciliation_status" ] } ], "data_elements": [ { "id": "per002-f-synchronization-data-projection-bindings", "name": "External resource, field authority and mapping version", "description": "External resource, field authority and mapping version. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "per002-f-synchronization-data-remote-outcomes", "name": "Requests, acknowledgements and readback evidence references", "description": "Requests, acknowledgements and readback evidence references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "per002-f-synchronization-data-reconciliation-state", "name": "Pending, confirmed, partial, failed or unknown reconciliation state", "description": "Pending, confirmed, partial, failed or unknown reconciliation state. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "per002-f-synchronization-artifact", "name": "Projection and remote outcome evidence record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "per002-b-governance", "name": "Disclosure and disposition", "description": "Purpose-limited access and evidence-based retention.", "rationale": "Keep purpose-limited access and evidence-based retention coherent while retaining separate external masters and evidence limits.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ], "layers": [ { "id": "per002-l-disclosure", "name": "Purpose-limited identity views", "description": "Context for purpose-limited identity views. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008" ], "findings": [ { "id": "per002-f-disclosure", "name": "Purpose-limited identity views", "description": "Views separate subject, steward and relying-party access, minimizing identifiers and assurance evidence. Public resolution is never a default. A yes/no response can also disclose protected information.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008" ], "questions": [ { "id": "per002-f-disclosure-q1", "text": "Which authenticated recipient and purpose permit each identity view?", "kind": "access", "answer_data": [ "recipient_ref", "purpose", "policy_ref" ] }, { "id": "per002-f-disclosure-q2", "text": "Which attributes and correlation links must be omitted from this view?", "kind": "privacy", "answer_data": [ "field_allowlist", "redaction_rules" ] }, { "id": "per002-f-disclosure-q3", "text": "Which steward owns the record and which authority governs subject access requests?", "kind": "ownership", "answer_data": [ "steward_role", "subject_access_policy_ref" ] }, { "id": "per002-f-disclosure-q4", "text": "Which enumeration or correlation risk constrains lookup responses?", "kind": "security", "answer_data": [ "lookup_profile", "risk_review_ref", "response_rule" ] } ], "data_elements": [ { "id": "per002-f-disclosure-data-view-rules", "name": "Recipient, purpose and field-level policy references", "description": "Recipient, purpose and field-level policy references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "per002-f-disclosure-data-stewardship", "name": "Accountable role and subject-access routing", "description": "Accountable role and subject-access routing. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "per002-f-disclosure-data-disclosure-evidence", "name": "Minimized access-decision and disclosure references", "description": "Minimized access-decision and disclosure references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "per002-f-disclosure-artifact", "name": "Purpose-limited identity views record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "per002-l-retention", "name": "Retention and disposition evidence", "description": "Context for retention and disposition evidence. Proposed local organization informed by the cited sources.", "source_refs": [ "SRC-001", "SRC-005" ], "findings": [ { "id": "per002-f-retention", "name": "Retention and disposition evidence", "description": "Payload disposition follows adopted retention and exception rules. Closing an account, deleting a protocol resource and disposing of all retained copies have distinct evidence. Continuity metadata must be minimized rather than retained indefinitely.", "source_refs": [ "SRC-001", "SRC-005" ], "questions": [ { "id": "per002-f-retention-q1", "text": "Which retention schedule and trigger govern each category of identity data?", "kind": "retention", "answer_data": [ "data_category", "schedule_ref", "trigger" ] }, { "id": "per002-f-retention-q2", "text": "Which authorized hold postpones disposition for a defined scope?", "kind": "exception", "answer_data": [ "hold_ref", "scope", "review_due" ] }, { "id": "per002-f-retention-q3", "text": "Which disposal receipts and residual-copy inventory support a completion claim?", "kind": "evidence", "answer_data": [ "receipt_refs", "residual_copy_refs", "completion_state" ] }, { "id": "per002-f-retention-q4", "text": "What minimal tombstone or successor reference may remain under the adopted policy?", "kind": "lifecycle", "answer_data": [ "tombstone_fields", "policy_basis", "successor_ref" ] } ], "data_elements": [ { "id": "per002-f-retention-data-retention-rules", "name": "Category-specific schedule and trigger references", "description": "Category-specific schedule and trigger references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "per002-f-retention-data-disposition-evidence", "name": "Hold, execution receipt and residual-copy references", "description": "Hold, execution receipt and residual-copy references. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "per002-f-retention-data-continuity-record", "name": "Policy-limited tombstone or successor metadata", "description": "Policy-limited tombstone or successor metadata. Candidate field; nested instance constraints require an adopting profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "per002-f-retention-artifact", "name": "Retention and disposition evidence record", "description": "Restricted, versioned evidence view for this finding, containing metadata and resolvable references only. External originals retain their own authority and retention controls.", "media_or_form": [ "structured metadata record", "redacted evidence index" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Time is metadata, not identity. Distinct instances have distinct IDs; serial revisions retain an ordered revision token.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "per002-fn-record-enrollment", "name": "Record enrollment evidence", "description": "Proposed local operation, not implemented. Record an externally established enrollment outcome without performing proofing.", "inputs": [ "Scoped identity reference", "Enrollment outcome and evidence references", "Proofing profile" ], "outputs": [ "Enrollment observation revision", "Unresolved proofing or evidence gaps" ], "preconditions": [ "Authorized actor and purpose under the adopting Dimension policy", "Current identity reference, profile version and expected revision verified", "Evidence references are accessible to the reviewer and contain no secrets" ], "effects": [ "Append outcome metadata; preserve unproofed and disputed states" ], "source_refs": [ "SRC-001" ] }, { "id": "per002-fn-revise-binding", "name": "Revise identifier or authenticator binding metadata", "description": "Proposed local operation, not implemented. Record an approved binding change without creating credentials or handling secrets.", "inputs": [ "Binding reference", "Authorized change evidence", "Allowed metadata projection" ], "outputs": [ "Versioned binding observation", "Refusal for secret material or ambiguous namespace" ], "preconditions": [ "Authorized actor and purpose under the adopting Dimension policy", "Current identity reference, profile version and expected revision verified", "Evidence references are accessible to the reviewer and contain no secrets" ], "effects": [ "Record effective interval and superseding evidence; no remote binding operation" ], "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] }, { "id": "per002-fn-record-recovery", "name": "Record recovery outcome", "description": "Proposed local operation, not implemented. Attach verified external recovery and notice evidence to the local identity.", "inputs": [ "Recovery case reference", "External result reference", "Controller authority and notification evidence" ], "outputs": [ "Recovery outcome observation", "Pending or rejected outcome" ], "preconditions": [ "Authorized actor and purpose under the adopting Dimension policy", "Current identity reference, profile version and expected revision verified", "Evidence references are accessible to the reviewer and contain no secrets" ], "effects": [ "Update observation only after profile prerequisites are evidenced; no authenticator reset" ], "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "per002-fn-review-linkage", "name": "Record linkage disposition", "description": "Proposed local operation, not implemented. Preserve an authorized linkage, unlinkage or dispute disposition without merging roots.", "inputs": [ "Source and target references", "Authenticated request evidence", "Purpose and reviewer disposition" ], "outputs": [ "Versioned linkage assertion", "Unresolved authority or subject conflict" ], "preconditions": [ "Authorized actor and purpose under the adopting Dimension policy", "Current identity reference, profile version and expected revision verified", "Evidence references are accessible to the reviewer and contain no secrets" ], "effects": [ "Keep original histories and separate online-account authority; no entitlement transfer" ], "source_refs": [ "SRC-003", "SRC-006" ] }, { "id": "per002-fn-record-state", "name": "Record identity-state decision", "description": "Proposed local operation, not implemented. Apply a policy-authorized local state revision and attach external synchronization observations.", "inputs": [ "State decision reference", "Lifecycle profile", "Expected revision", "Remote result references" ], "outputs": [ "Local state revision", "Reconciliation gaps and refusal reasons" ], "preconditions": [ "Authorized actor and purpose under the adopting Dimension policy", "Current identity reference, profile version and expected revision verified", "Evidence references are accessible to the reviewer and contain no secrets" ], "effects": [ "Keep remote state unknown until confirmed; never infer all sessions revoked" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] }, { "id": "per002-fn-build-view", "name": "Build a minimized review view", "description": "Proposed local operation, not implemented. Propose a recipient-scoped local view including retention and evidence gaps.", "inputs": [ "Authenticated recipient context", "Purpose and policy references", "Field allowlist", "Retention and hold references" ], "outputs": [ "Redacted local view", "Denied fields and unresolved holds" ], "preconditions": [ "Authorized actor and purpose under the adopting Dimension policy", "Current identity reference, profile version and expected revision verified", "Evidence references are accessible to the reviewer and contain no secrets" ], "effects": [ "Record minimized disclosure evidence; no outbound transmission or disposal" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-008" ] } ], "composition": [ { "target": "WM-XCT-016", "relation": "REFERENCE", "purpose": "Candidate optional register membership reference. Register-wide indexing, uniqueness and resolution functions stay external.", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "target": "WM-PER-001", "relation": "REFERENCE", "purpose": "Candidate optional natural-person reference; profile and civil-status lifecycle remain external and pseudonymous identities need no person master link.", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "target": "WM-VRT-005", "relation": "REFERENCE", "purpose": "Optional navigational back-reference to the source of the frozen inbound candidate REFERENCE. Does not ratify reciprocal containment; application account state and assets remain target-owned.", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] }, { "target": "WM-XCT-017", "relation": "REFERENCE", "purpose": "Candidate credential evidence reference; issuer decisions and credential lifecycle are external.", "required": false, "source_refs": [ "SRC-002", "SRC-008" ] }, { "target": "WM-XCT-002", "relation": "REFERENCE", "purpose": "Candidate access and consent policy reference; no authorization enforcement owned here.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "RFC 7643 and RFC 7644", "relation": "ALIGN", "purpose": "Conceptual resource and provisioning mapping. Field authority, identifier scope and conformance fixtures remain to be specified.", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "target": "OpenID Connect Core 1.0", "relation": "ALIGN", "purpose": "Optional federation binding projection using issuer, subject and audience; no protocol execution.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "DID Core v1.0", "relation": "ALIGN", "purpose": "Optional identifier and controller reference; no mandatory DID, ledger or equivalence to a proofed natural person.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "Web Authentication Level 2", "relation": "ALIGN", "purpose": "Optional account-scoped credential reference projection; no ceremony execution or device trust certification.", "required": false, "source_refs": [ "SRC-008" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Declare an accountable identity steward role, authority namespace and immutable record key policy", "Declare permitted subject kinds, proofing profiles, federation roles and field authority map", "Declare recipient policies, lawful processing basis where applicable, retention schedules and redress routing", "Keep independent-review, live-source and executable-profile holds visible" ], "namespace_guidance": "Use a governed identity-service namespace and stable local identifiers. Preserve issuer and tenant context. Do not embed email, personal names or dates in stable keys.", "registry_links": [ "vr.wm-per-002", "Optional WM-XCT-016 register reference", "Frozen inbound WM-VRT-005 REFERENCE candidate" ] }, "canon_and_patch": { "canonicalization_rules": [ "The local master record and its revision define this identity projection, not universal truth about the subject", "Preserve identifier case and scope according to each scheme; never deduplicate by display name or email", "Derived current views retain the evidence and effective intervals on which they depend" ], "patch_rules": [ "Require authorized actor, purpose, expected revision, reason and evidence for every patch", "Separate correction from account linkage; record disputed assertions without destructive merging", "Reject secrets and raw proofing payloads; prevent privilege expansion through a metadata update" ], "compatibility_rules": [ "Version enum vocabularies, mappings and assurance frameworks explicitly", "Treat changes to identifier meaning, authority or subject binding as reviewed breaking changes", "Preserve minimal lawful continuity while permitting policy-authorized payload disposal; history is not an unlimited retention exception" ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier scoped to its authority", "Governed global identifier or IRI with issuer context", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Use RFC 3339 with seconds and explicit offset or Z. Distinguish event time, effective time and observation or ingestion time; record unknown precision without inventing an instant.", "serial_naming_rule": "Artifact master ID plus immutable revision or sequence; dates are optional display metadata, never sole identity.", "integrity_rule": "Record origin, access classification, version and permitted digest of retained evidence. A digest proves neither identity, correctness, authority nor safe disclosure." }, "policies": [ "Deny by default and release only fields needed for the documented recipient and purpose", "Never store passwords, private keys, bearer tokens, recovery codes or raw biometrics in this model", "Assurance, controller authority, identity evidence and permission to act are separate assertions", "Linking, recovery and destructive transitions require explicit profile authority and evidence; no automated name-based merges", "Reviewability is not conformance, legal compliance or independent review; natural-person guidance cannot certify nonhuman identities" ], "crud": { "read": [ "Authenticate the reader, evaluate purpose and current policy, then return a minimal view with unknown and disputed states", "Do not expose account existence, correlation links or audit details merely because an identifier is known" ], "create": [ "Create only an authorized scoped identity metadata record with profile, steward and provenance", "Allow unproofed enrollment where the adopted profile permits it; never fabricate evidence" ], "update": [ "Use expected revision and evidence-backed transitions; preserve prior assertion lineage subject to retention controls", "Record external recovery, provisioning and revocation outcomes as observed, pending or unknown" ], "delete": [ "Separate local closure, protocol deletion and payload disposal; require the relevant authority, retention and hold checks", "Record category-specific disposal outcomes and residual copies; retain only policy-permitted continuity metadata" ] }, "roles": [ { "name": "Identity steward", "responsibilities": [ "Own namespace, profile adoption and correction decisions" ] }, { "name": "Subject or authorized representative", "responsibilities": [ "Request review and recovery within evidenced authority; cannot self-certify assurance" ] }, { "name": "Evidence reviewer", "responsibilities": [ "Assess provenance and unresolved proofing or linkage evidence" ] }, { "name": "Security operator", "responsibilities": [ "Record external authenticator and recovery results without handling secrets in this model" ] }, { "name": "Privacy and records custodian", "responsibilities": [ "Approve scoped disclosure, retention exceptions and disposal evidence" ] }, { "name": "Relying-party reviewer", "responsibilities": [ "Consume only authorized identity views and evaluate external access policies" ] } ], "access": { "default_rule": "Deny by default; intersect role, purpose, subject scope, field restrictions and time validity. Subject access is policy-qualified, not unrestricted access to third-party evidence.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Document assisted access or emergency exceptions with authority, scope, expiry and subsequent review; never an implicit bypass" ], "audit_requirements": [ "Record actor reference, purpose, decision, affected record and revision without secret payloads", "Log denied and exceptional access with minimization and a retention schedule; the external audit master owns its lifecycle" ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Owner role", "Review state and holds" ], "read_order": [ "Read AGENTS.md and adopting Dimension policy", "Read spec.yaml boundary, assurance holds and composition references", "Resolve current record revision, profile and access authority before proposing changes" ] } }, "coverage": { "claim": "Source-grounded proposal for one persistent identity-service record with optional federation, scoped identifiers, qualified assurance and restricted evidence views. A separate local no-tools self-audit found no critical contradictions. The draft remains noncanonical with independent-review, source/version, adoption-profile and executable-conformance holds.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Scoped stable root and issuer-qualified bindings" }, { "dimension": "lifecycle", "status": "covered", "notes": "Profile-governed transitions and explicit continuity" }, { "dimension": "relationships", "status": "covered", "notes": "Subject, controller, credential and online-account references" }, { "dimension": "temporal", "status": "covered", "notes": "Effective, event and observation times kept distinct" }, { "dimension": "provenance", "status": "covered", "notes": "Evidence origin, reviewer and outcome references" }, { "dimension": "ownership", "status": "covered", "notes": "Accountable steward and separately evidenced controller authority" }, { "dimension": "validation", "status": "covered", "notes": "Unknown, stale and disputed evidence remains explicit" }, { "dimension": "access", "status": "covered", "notes": "Purpose- and field-limited recipient views" }, { "dimension": "retention and deletion", "status": "covered", "notes": "Category-level retention, holds, disposal and residual copies" }, { "dimension": "interoperability", "status": "covered", "notes": "Conceptual SCIM, OIDC, DID and WebAuthn mappings" }, { "dimension": "recovery", "status": "covered", "notes": "External outcome and notice evidence" }, { "dimension": "nonhuman assurance", "status": "gap", "notes": "Separate organization and thing assurance profiles not developed" }, { "dimension": "executable conformance", "status": "gap", "notes": "Nested schemas, protocol mappings and instance tests are deferred" } ], "known_omissions": [ "Independent external review is absent; local audit cannot replace it", "Direct HTTP and latest-version verification remain incomplete; browser reading is selected-section evidence", "Executable nested schemas, runtime bindings, protocol interoperability and adversarial instance fixtures are not implemented", "Nonhuman assurance, shared-account rules, guardianship, estate access, jurisdictional privacy rights and sector-specific identity requirements need qualified profiles" ], "conflicts": [], "regional_assumptions": [ "NIST assurance guidance is a selected US federal technical profile for natural persons, not a universal legal obligation", "No global one-person-one-account rule, legal identity effect or unconditional subject-access right is asserted", "Protocol versions are pinned examples; current amendment, errata and deployment applicability review remains open" ], "adversarial_checks": [ "Reject email collision as identity equivalence", "Reject successful authentication as proofing or authorization", "Reject DID controller equality with subject without evidence", "Reject local suspension as proof of remote session revocation", "Reject deletion acknowledgement as proof that all personal copies are erased", "Reject application-account lifecycle absorption from the inbound relation" ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The record has persistent identity across enrollment, binding and state observations. The registry standalone-mm value is a record-plane label, not a subject-kind enum. R4 register-wide functions stay in WM-XCT-016; the inbound WM-VRT-005 reference does not transfer application-account ownership." }, "decisions": [ { "concept": "Legacy register boundary", "disposition": "reconciled", "rationale": "The shared R4 legacy and unreviewed supplement describe a register. The entity explicitly rejects global uniqueness and legal effect, retains scoped metadata and keeps population governance external." }, { "concept": "Anchor identity and subject kind", "disposition": "accepted with profile limits", "rationale": "The root key identifies an identity-service record rather than the represented person. Unproofed and disputed subject assertions are allowed, while nonhuman assurance is a declared gap." }, { "concept": "Identifier correlation", "disposition": "accepted", "rationale": "Issuer, audience, validity and comparison rules qualify bindings. Email or display-name equality cannot silently establish same-subject identity or merge roots." }, { "concept": "Enrollment evidence", "disposition": "accepted", "rationale": "Enrollment route, evidence references, exception handling and redress are distinct from proofing success. The questions permit missing or disputed outcomes without fabricating a validated identity." }, { "concept": "Assurance dimensions", "disposition": "accepted", "rationale": "The proposal retains framework, dimension, assessor and observation time. It rejects interpreting a historical maximum or authentication strength as a universal current proofing guarantee." }, { "concept": "Authenticator and recovery ownership", "disposition": "limited to metadata", "rationale": "Binding and recovery functions record authorized external outcomes and notification references. They cannot handle secrets, reset authenticators or equate controller access with subject authority." }, { "concept": "Federation observation validity", "disposition": "accepted", "rationale": "Issuer-subject identity, relying-party audience and trust context qualify observations. Token execution is excluded, and stale or mismatched evidence must remain unusable for an accepted observation." }, { "concept": "Linkage and online-account relation", "disposition": "accepted with directional limit", "rationale": "The ledger supplies an inbound candidate reference only. The optional backlink is explicitly navigational; linking cannot merge histories, transfer entitlements or own WM-VRT-005 lifecycle." }, { "concept": "Local state and remote effect", "disposition": "separated", "rationale": "Lifecycle questions require authority, effective time and revision checks. Synchronization questions distinguish requests, acknowledgements, readback and unknown session consequences; closure never proves global revocation." }, { "concept": "Disclosure and subject access", "disposition": "qualified", "rationale": "Views require recipient, purpose and policy authority. Public lookup and unconditional self-access from the legacy input are rejected, and even yes/no responses remain disclosure-sensitive." }, { "concept": "Retention and artifact continuity", "disposition": "accepted with policy dependency", "rationale": "Serial artifact identity and correction lineage do not imply perpetual retention. Category-specific holds, residual copies and policy-limited tombstones distinguish closure, deletion and actual disposition." }, { "concept": "Local operations and service rules", "disposition": "accepted as proposed", "rationale": "All six functions are explicitly unimplemented local operations with actor, purpose, evidence and revision preconditions. The eight service sections preserve external authority and record refusals and evidence gaps." }, { "concept": "Executable schemas and mapping", "disposition": "deferred", "rationale": "Candidate collections and object fields do not define nested instance constraints, mapping behavior or protocol acceptance tests. These omissions are visible and prevent operational conformance claims, not review of the proposed structure." }, { "concept": "Source assurance", "disposition": "limited", "rationale": "Selected browser readings support conceptual alignments but do not establish complete latest-version, errata or deployment review. Direct HTTP was not attempted, and zero measured successes is not a measured failure rate." }, { "concept": "Independent review", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the owner override. This separate frozen assessment is a local Codex self-audit and cannot be described as independent external review." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not a second-provider review.", "Direct HTTP checks were not attempted under the owner-reported sandbox restriction: zero measured HTTP 200 responses. Selected browser source access is documented separately. Complete current-version, errata, licensing and claim-applicability verification remains open; the coordinator checker is prepared.", "Adopting profiles must qualify natural-person versus nonhuman assurance, controller and representative authority, recovery exceptions, shared identities, privacy rights, retention and sector or jurisdiction rules before operational use.", "Nested instance schemas, pinned neighbor bindings, SCIM/OIDC/DID/WebAuthn mappings, executable conformance and adversarial instance fixtures remain incomplete. No authentication, security or legal-compliance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Complete source/version and qualified adoption-profile review, including nonhuman and assisted-access cases.", "Specify and test instance constraints and external mappings against email reuse, incorrect linkage, lost authenticators, partial revocation, delayed provisioning and residual-copy disposal cases.", "Restore independent external review before any canonical or publishable-draft promotion." ] }, "statistics": { "sources": 9, "bundles": 6, "layers": 12, "findings": 12, "questions": 48, "artifacts": 12, "functions": 6 } }