← Back to catalogue
Published

Non-human Agent

vr.wm-per-003 · wm-per-003-non-human-agent

Represent a persistent governed non-human actor with explicit identity, control, delegated authority, capabilities, operating state, attribution, oversight and lifecycle while remaining independent of storage and interface format.

World Models Society, people and institutions SOC.PER.AGT

Bundle → Layer → Finding → Questions Filled

7 bundles · 16 layers · 32 findings · 96 questions

Identity, kind and instance boundary Identifies the persistent governed agent and separates it from implementations, deployments, endpoints and sessions.

Persistent identity and lineage

Stable identifiers, aliases, versions and successor history for the governed actor.

Authoritative agent identifier and master system

The stable actor identifier, issuing authority, namespace, master system, resolution state and local bindings.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for authoritative agent identifier and master system? identity
  2. Which controller, operator, principal, authority, observation and evidence establishes authoritative agent identifier and master system, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may authoritative agent identifier and master system be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Aliases, version, specialization and successor lineage

Names, protocol identifiers, definition versions, specializations, replacements, merges and retirement lineage without identity collapse.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for aliases, version, specialization and successor lineage? lifecycle
  2. Which controller, operator, principal, authority, observation and evidence establishes aliases, version, specialization and successor lineage, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may aliases, version, specialization and successor lineage be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Kind, composition and boundary

Classification criteria and the distinction among actor, definition, deployment, endpoint, embodiment and session.

Non-human agent kind and classification criteria

Profile-qualified kind such as software, embodied, hybrid or collective machine actor, with observable criteria and prohibited subjecthood inferences.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for non-human agent kind and classification criteria? classification
  2. Which controller, operator, principal, authority, observation and evidence establishes non-human agent kind and classification criteria, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may non-human agent kind and classification criteria be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Agent, definition, deployment, endpoint, embodiment and session boundary

Typed component and realization references with separate identifiers, masters, versions and lifecycles.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for agent, definition, deployment, endpoint, embodiment and session boundary? composition
  2. Which controller, operator, principal, authority, observation and evidence establishes agent, definition, deployment, endpoint, embodiment and session boundary, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may agent, definition, deployment, endpoint, embodiment and session boundary be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Control, accountability and stakeholders Records who creates, controls, operates, benefits from and remains answerable for the agent.

Control and operating parties

Time-qualified bindings for parties with technical or organizational control.

Owner, controller, provider and deployer bindings

External party references, role basis, control surface, jurisdiction, validity and change history.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for owner, controller, provider and deployer bindings? relationship
  2. Which controller, operator, principal, authority, observation and evidence establishes owner, controller, provider and deployer bindings, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may owner, controller, provider and deployer bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Operator, beneficiary, customer and affected-party bindings

Operational, beneficiary, service-recipient and affected-party roles with scope, time and source.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for operator, beneficiary, customer and affected-party bindings? relationship
  2. Which controller, operator, principal, authority, observation and evidence establishes operator, beneficiary, customer and affected-party bindings, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may operator, beneficiary, customer and affected-party bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Accountability and responsibility

Answerability, escalation and the boundary between provenance responsibility and legal conclusions.

Accountable party, oversight owner and escalation contact

Who answers for deployment and use, receives escalation and has power to intervene, with delegated scope and availability.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for accountable party, oversight owner and escalation contact? authority
  2. Which controller, operator, principal, authority, observation and evidence establishes accountable party, oversight owner and escalation contact, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may accountable party, oversight owner and escalation contact be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Activity responsibility attribution versus liability and personhood

PROV responsibility claims and explicit non-inference of intention, consciousness, legal personality, rights, duties or liability.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for activity responsibility attribution versus liability and personhood? provenance
  2. Which controller, operator, principal, authority, observation and evidence establishes activity responsibility attribution versus liability and personhood, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may activity responsibility attribution versus liability and personhood be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Authority, mandate and delegation Defines the purpose-bound authority under which the agent may act.

Principal, mandate and delegation chain

The accountable principal, mandate, purpose and traceable chain of acting on behalf of another.

Principal, mandate, purpose, resource, jurisdiction and interval

The source authority, permitted purposes and targets, territorial or logical scope and validity interval.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for principal, mandate, purpose, resource, jurisdiction and interval? authority
  2. Which controller, operator, principal, authority, observation and evidence establishes principal, mandate, purpose, resource, jurisdiction and interval, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may principal, mandate, purpose, resource, jurisdiction and interval be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Delegation chain, subdelegation, conditions and revocation

Each delegator, delegate, allowed onward delegation, conditions, expiry, suspension and revocation effect.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for delegation chain, subdelegation, conditions and revocation? relationship
  2. Which controller, operator, principal, authority, observation and evidence establishes delegation chain, subdelegation, conditions and revocation, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may delegation chain, subdelegation, conditions and revocation be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Permission, credentials and policy

External policy and credential evidence that constrains actions at decision time.

Permission, prohibition, duty, constraint and approval gate

Referenced policy rules, actions, targets, conditions, duties, exceptions and human or organizational confirmation class.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for permission, prohibition, duty, constraint and approval gate? security
  2. Which controller, operator, principal, authority, observation and evidence establishes permission, prohibition, duty, constraint and approval gate, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may permission, prohibition, duty, constraint and approval gate be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Credential scope, audience, holder, validity and status

Credential references and observations with issuer, subject, audience, proof, expiry and status while secrets stay external.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for credential scope, audience, holder, validity and status? evidence
  2. Which controller, operator, principal, authority, observation and evidence establishes credential scope, audience, holder, validity and status, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may credential scope, audience, holder, validity and status be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Capability, behaviour, constraints and dependencies Describes what the agent can do, how it behaves and the envelope in which claims remain valid.

Capabilities, skills and interfaces

Declared and observed action surfaces plus machine-readable access bindings.

Declared, observed and verified capability surface

Actions, inputs, outputs, quality limits, confidence, evaluation basis and contexts in which the capability is available.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for declared, observed and verified capability surface? requirement
  2. Which controller, operator, principal, authority, observation and evidence establishes declared, observed and verified capability surface, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may declared, observed and verified capability surface be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Skill, protocol, interface, action, property and event bindings

Versioned A2A, WoT or domain binding references with authentication, media, schema and negotiation metadata.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for skill, protocol, interface, action, property and event bindings? interoperability
  2. Which controller, operator, principal, authority, observation and evidence establishes skill, protocol, interface, action, property and event bindings, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may skill, protocol, interface, action, property and event bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Behaviour, state and transition

Observable response patterns and governed operational states.

Behaviour policy, mode, trigger and observable signature

Expected responses under stated conditions, recognizable signatures, confidence, prohibited inference and drift indicators.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for behaviour policy, mode, trigger and observable signature? process
  2. Which controller, operator, principal, authority, observation and evidence establishes behaviour policy, mode, trigger and observable signature, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may behaviour policy, mode, trigger and observable signature be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Registered, configured, ready, active, paused, degraded and stopped state

Current state, allowed transitions, actor and authority, reason, event and valid times, safe-state target and history.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for registered, configured, ready, active, paused, degraded and stopped state? state
  2. Which controller, operator, principal, authority, observation and evidence establishes registered, configured, ready, active, paused, degraded and stopped state, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may registered, configured, ready, active, paused, degraded and stopped state be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Dependencies, envelope, hazards and failure

Conditions and components on which capability and safe behaviour depend.

Tool, model, memory, service and embodiment dependencies

Pinned external component references, trust state, version, availability, data boundary and degraded-mode effect.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for tool, model, memory, service and embodiment dependencies? composition
  2. Which controller, operator, principal, authority, observation and evidence establishes tool, model, memory, service and embodiment dependencies, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may tool, model, memory, service and embodiment dependencies be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Operating envelope, prohibition, hazard, failure and recovery

Resource, time, cost, environment and safety limits, forbidden actions, failure signatures, containment and recovery path.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for operating envelope, prohibition, hazard, failure and recovery? constraint
  2. Which controller, operator, principal, authority, observation and evidence establishes operating envelope, prohibition, hazard, failure and recovery, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may operating envelope, prohibition, hazard, failure and recovery be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Operation, attribution and oversight Connects agent state and execution context to activities, outputs and intervention controls.

Activation, deployment and session context

Which approved configuration is active where and how executions correlate to it.

Deployment, configuration, release and activation binding

Pinned external deployment and configuration references, approval, environment, activation authority and effective interval.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for deployment, configuration, release and activation binding? composition
  2. Which controller, operator, principal, authority, observation and evidence establishes deployment, configuration, release and activation binding, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may deployment, configuration, release and activation binding be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Session, run, correlation and temporal context

External session and run references, correlation identifiers and distinct event, valid, observation, knowledge and ingestion times.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for session, run, correlation and temporal context? temporal
  2. Which controller, operator, principal, authority, observation and evidence establishes session, run, correlation and temporal context, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may session, run, correlation and temporal context be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Activity and output attribution

Traceable associations among agent, activity, principal, plan, inputs and outputs.

Activity association, plan, role and delegation attribution

Which agent was associated with an activity, in which role, under which plan and on whose behalf.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for activity association, plan, role and delegation attribution? provenance
  2. Which controller, operator, principal, authority, observation and evidence establishes activity association, plan, role and delegation attribution, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may activity association, plan, role and delegation attribution be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Output entity generation, attribution and derivation

Generated or influenced output references, activity, sources, agent version and provenance bundle.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for output entity generation, attribution and derivation? provenance
  2. Which controller, operator, principal, authority, observation and evidence establishes output entity generation, attribution and derivation, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may output entity generation, attribution and derivation be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Oversight, intervention and safe state

Approval, monitoring, interruption, handoff and containment controls.

Human or organizational oversight, approval and intervention

Oversight role, competence reference, information supplied, approval gates, intervention controls and response evidence.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for human or organizational oversight, approval and intervention? authority
  2. Which controller, operator, principal, authority, observation and evidence establishes human or organizational oversight, approval and intervention, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may human or organizational oversight, approval and intervention be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Monitoring, alert, escalation, suspension, handoff and fail-safe

Signals, thresholds, accountable recipient, timeout, suspension authority, safe-state behavior and recovery confirmation.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for monitoring, alert, escalation, suspension, handoff and fail-safe? process
  2. Which controller, operator, principal, authority, observation and evidence establishes monitoring, alert, escalation, suspension, handoff and fail-safe, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may monitoring, alert, escalation, suspension, handoff and fail-safe be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Assurance, evidence, privacy and lifecycle Records bounded assurance claims, observations, incidents and durable lifecycle governance.

Assurance, monitoring and incidents

Risk, evaluation, limitation, telemetry and incident references.

Risk, evaluation, assurance, limitation and acceptance

External assessment references, test context, metrics, thresholds, residual risks, approver, validity and non-claims.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for risk, evaluation, assurance, limitation and acceptance? validation
  2. Which controller, operator, principal, authority, observation and evidence establishes risk, evaluation, assurance, limitation and acceptance, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may risk, evaluation, assurance, limitation and acceptance be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Monitoring, drift, anomaly, incident, impact and corrective action

Observed signals and externally mastered incident or corrective-action references with severity, scope and status.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for monitoring, drift, anomaly, incident, impact and corrective action? evidence
  2. Which controller, operator, principal, authority, observation and evidence establishes monitoring, drift, anomaly, incident, impact and corrective action, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may monitoring, drift, anomaly, incident, impact and corrective action be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Privacy, retention and agent lifecycle

Purpose-bound disclosure and governed suspension, retirement and tombstoning.

Data category, purpose, access, disclosure, retention and deletion

Field and artifact sensitivity, purpose, audience, access policy, retention class, legal hold and disposition evidence.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for data category, purpose, access, disclosure, retention and deletion? privacy
  2. Which controller, operator, principal, authority, observation and evidence establishes data category, purpose, access, disclosure, retention and deletion, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may data category, purpose, access, disclosure, retention and deletion be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Suspension, revocation, retirement, replacement and tombstone

Authorized lifecycle endings, surviving delegations and credentials, successor, endpoint withdrawal, retention and durable identity tombstone.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for suspension, revocation, retirement, replacement and tombstone? lifecycle
  2. Which controller, operator, principal, authority, observation and evidence establishes suspension, revocation, retirement, replacement and tombstone, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may suspension, revocation, retirement, replacement and tombstone be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Interoperability, governance and agent operations Controls projections, mapping loss and safe automated maintenance.

Profiles, projections and mapping loss

Versioned external representations and explicit non-equivalence.

PROV Agent, SoftwareAgent, association and delegation projection

Loss-aware mapping of agent identity, activity association, attribution and acted-on-behalf-of relations.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for prov agent, softwareagent, association and delegation projection? interoperability
  2. Which controller, operator, principal, authority, observation and evidence establishes prov agent, softwareagent, association and delegation projection, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may prov agent, softwareagent, association and delegation projection be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

A2A Agent Card, WoT description and credential projection

Versioned discovery, affordance and proof projections with authentication, disclosure, omission and round-trip limits.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for a2a agent card, wot description and credential projection? interoperability
  2. Which controller, operator, principal, authority, observation and evidence establishes a2a agent card, wot description and credential projection, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may a2a agent card, wot description and credential projection be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Safe agent control and validation

Authorized operations, invariants, concurrency and recovery.

Operation authority, purpose, preconditions, idempotency and evidence

Classifies each read, bind, delegate, activate, suspend, attribute, disclose and retire action with proof and effect.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for operation authority, purpose, preconditions, idempotency and evidence? security
  2. Which controller, operator, principal, authority, observation and evidence establishes operation authority, purpose, preconditions, idempotency and evidence, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may operation authority, purpose, preconditions, idempotency and evidence be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Pre-write and post-write validation, conflict, concurrency and recovery

Identity, boundary, authority, state, time, provenance, privacy, stale-head and rollback checks with immutable audit evidence.

  1. What exact values, references, qualifiers and explicit unknowns must be recorded for pre-write and post-write validation, conflict, concurrency and recovery? validation
  2. Which controller, operator, principal, authority, observation and evidence establishes pre-write and post-write validation, conflict, concurrency and recovery, at what event, valid and knowledge time, and with what confidence? evidence
  3. How may pre-write and post-write validation, conflict, concurrency and recovery be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation

Classifiers Filled

Family
World Models
Category
Society, people and institutions
Entry kind
entity
Navigation path
NAV.SOC.PER.AGT
Domain
SOC.PER.AGT
Industry
Cross-industry
Tags
nonhumanagentsoc.per.agt

What it is Filled

Owns the generic actor identity and kind, definition and instance boundary, control and accountable-party bindings, mandate and delegation envelope, capability and behavior assertions, dependency references, operating state, activity and output attribution, oversight, assurance references, privacy, lifecycle and loss-aware projections. External systems own persons, organizations, software, AI systems and models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence objects.

In scope

  • Persistent non-human agent identity, issuer, kind, aliases, versions, components and successor lineage
  • Controller, provider, deployer, operator, principal, beneficiary, affected-party and accountable-party bindings
  • Mandate, delegation, permission references, capabilities, behavior, dependencies, operating envelope, states, attribution, oversight, assurance, privacy, lifecycle and exchange

Out of scope

  • Human person, organization, software product, AI system, AI model, physical embodiment, task, activity, output, credential, policy, access decision, incident and evidence master lifecycles
  • Claims that the agent is conscious, sentient, intentional, a legal person, a rights-holder or itself legally liable
  • AI Agent details already owned by WM-AI-002, physical robotics semantics, universal authorization rules or deployment-specific compliance conclusions

Why it exists Filled

Represent a persistent governed non-human actor with explicit identity, control, delegated authority, capabilities, operating state, attribution, oversight and lifecycle while remaining independent of storage and interface format.

Distinguishing features Filled

  • Covers any non-human actor that acts, including software agents, robots and automated systems, not only AI agents.
  • Every agent is bound to a controlling and an accountable party.
  • Separates the agent definition from its running instances.
  • Makes no claim about consciousness, legal personhood or moral status.

What robots and AI may and may not do Filled

Must not

  • Act outside its delegated mandate.
  • Pretend to be a human or another agent.
  • Delegate authority it does not have.
  • Hide its accountable party when asked.
  • Claim rights, sentience or legal personhood.

Only with a human decision

  • Granting or extending mandates.
  • Deploying agents that act in the physical world or with financial effect.
  • Decommissioning an agent with ongoing obligations.

May

  • Declare its own identity, controller, mandate and capabilities.
  • Attribute its outputs and actions to itself in records.
  • Report its operating state and errors.
  • Refuse tasks outside its mandate.

Moral aspects Filled

  • People must know when they deal with a machine and who is responsible for it.
  • Accountability gaps appear when agents act through long delegation chains.
  • Claims about agent sentience can mislead and manipulate users.

Who is affected

  • People interacting with agents
  • Controllers and accountable parties
  • Third parties affected by agent actions

Owners Filled

Steward

Dimension identity, owner, agent registrar, delegation authority, oversight owner and namespace

Roles

Dimension owner
Own namespace, mastership, delegation, access, retention and federation rules.
Agent registrar
Maintain persistent identity, kind, boundary, aliases and successor lineage.
Controller or provider
Declare the controlled agent and maintain accurate configuration, capability and limitation references.
Deployer or operator
Operate only within current delegation and envelope and preserve activation, oversight and incident evidence.
Delegating principal
Grant, constrain, suspend and revoke purpose-bound authority within its own authority.
Accountable and oversight owner
Review consequential action, intervene, receive escalation and accept or reject residual risk.
Safety, privacy and access steward
Apply minimum disclosure, monitoring, incident, retention and security controls.
Independent auditor
Review identity, delegation, state, attribution, controls and evidence without rewriting source records.

Links to other meta-models Filled

child

  • WM-AI-002 AI Agent - Reuse the generic governed actor core while AI-specific model, memory, tool, protocol, evaluation and regulation semantics stay in the specialization.

references

  • Person, Organization, Software, AI System, AI Model, Embodiment, Task, Activity, Output, Policy, Credential, Incident and Evidence models - Connect the agent to externally mastered parties, components, executions, rules and evidence without identity or lifecycle duplication.

aligned

  • W3C PROV-DM and PROV-O - Project agent, SoftwareAgent, association, attribution, delegation, specialization and revision provenance.
  • A2A Protocol Specification - Publish an optional discovery and protocol projection through Agent Cards, skills, capabilities and interfaces.
  • ODRL Information Model 2.2 and Verifiable Credentials Data Model 2.0 - Represent purpose-bound authority policy and portable evidence without importing authorization or credential lifecycles.
  • Web of Things Thing Description 1.1 - Project optional properties, actions, events, forms and security metadata for networked or embodied agent interfaces.

neighbor

  • WM-AI-002 AI Agent - AI Agent is a specialization that owns AI-specific model, memory, tools, protocols, evaluation and regulatory context; this model supplies the common non-human actor identity, delegation, attribution and lifecycle core.
  • Software, AI System and AI Model - Software and models are components or implementations; the governed actor has its own persistent identity, controller, authority and state and may change components without silent identity replacement.
  • Robot, Device and Embodiment - A physical body owns geometry, material, pose, mechanics and safety details; this model records only the agent-to-embodiment binding and delegated physical operating envelope.
  • Session, Run, Task and Activity - These are bounded execution or work records; the agent is the durable actor referenced from each and keeps only correlation and attribution links.
  • Credential, Access and Policy - Credentials and policies provide evidence and authorization inputs; possession or technical ability does not establish current permission.
  • Legal or moral subject - Technical autonomy and provenance responsibility do not establish consciousness, intention, rights, duties, personhood or liability; those conclusions require external law, evidence and authority.

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative master-system identifier for the governed agent, qualified by issuer.
  • Governed globally resolvable agent IRI with explicit master-system binding.
  • Adopting-Dimension UUID or ULID when no authoritative external identifier exists.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • A non-human agent has an identifier, a kind, a controller, an accountable party and a mandate.
  • It is confused with the software product it runs on, with its human operator and with a service account.

Capabilities and actions required Filled

  • Register non-human agent: Create the persistent actor identity, kind, master binding and explicit boundaries.
  • Bind control and accountability parties: Append time-qualified owner, controller, provider, deployer, operator and accountable-party bindings.
  • Grant purpose-bound delegation: Attach an authorized mandate with principal, purpose, resources, interval, constraints and subdelegation rule.
  • Constrain, suspend or revoke delegation: Reduce or end delegated authority without erasing prior grants or activity provenance.
  • Declare capability and limits: Record declared, observed or verified ability with context, evidence, confidence and prohibitions.
  • Bind interface and dependency: Pin a protocol, skill, tool, model, memory, service or embodiment and state its trust and degraded-mode effect.
  • Transition operational state: Activate, pause, degrade, suspend, stop or recover the agent under a valid transition and authority.
  • Attribute activity or output: Link an external activity or entity to the exact agent, role, plan, delegation, version and execution context.
  • Request approval or escalate: Route an action, ambiguity, threshold breach or loss-of-control condition to the accountable authority.
  • Attach assurance or incident evidence: Reference an evaluation, limitation, risk acceptance, monitoring observation, incident or corrective action.
  • Project agent profile: Produce a purpose-bound PROV, A2A, WoT or credential view with explicit omissions and mapping loss.
  • Retire non-human agent: End authority and operation, withdraw discoverability, reconcile credentials and preserve a durable tombstone.

Hazards and failure modes required Filled

  • Actions beyond mandate through prompt injection or misconfiguration.
  • Impersonation of humans or other agents.
  • Unclear liability after harm.

Standards and interfaces required Filled

  • W3C Decentralized Identifiers (DIDs) 1.0.
  • OAuth 2.0 (RFC 6749) for delegated authorization.
  • ISO/IEC 42001 AI management systems.
  • Model Context Protocol (MCP).

Context of use required Filled

  • The EU AI Act supplies an EU AI-system profile and does not govern every non-human agent or create universal subject status.
  • PROV responsibility attribution is a provenance relation and does not decide legal accountability or liability in any jurisdiction.
  • A2A, WoT, ODRL and Verifiable Credentials are optional interoperability profiles, not mandatory storage or interface formats.

Sources Filled

  1. PROV-DM: The PROV Data Model - World Wide Web Consortium
  2. PROV-O: The PROV Ontology - World Wide Web Consortium
  3. AI Risk Management Framework: Audience - National Institute of Standards and Technology
  4. A2A Protocol Specification - A2A Project under the Linux Foundation
  5. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence - European Union
  6. ODRL Information Model 2.2 - World Wide Web Consortium
  7. Verifiable Credentials Data Model v2.0 - World Wide Web Consortium
  8. Time Ontology in OWL - World Wide Web Consortium
  9. Web of Things Thing Description 1.1 - World Wide Web Consortium
  10. Date and Time on the Internet: Timestamps - Internet Engineering Task Force

Open questions

  • Review the parent and child split with WM-AI-002 and approve exact field ownership, dependency direction and version compatibility.
  • Approve model identifiers and relation cardinalities for persons, organizations, software, AI systems, models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence.
  • Develop specialist profiles for software services, embodied robots, autonomous vehicles, swarms, animals and any future legally recognized electronic subject.
  • Create deterministic fixtures for identity replacement, controller changes, nested delegation, stale credentials, dependency loss, safe-state entry, disputed attribution and private-agent discovery.
  • Validate certified provenance, discovery, affordance, policy and credential projections with explicit disclosure, loss and round-trip tests.
  • No independent Claude or Grok result was available; this source-grounded Codex fallback requires later external review before canonical promotion.
  • WM-AI-002 AI Agent, software, AI system, model, robot or embodiment, task, activity, credential, access, incident and evidence models retain their own detailed semantics.
  • Animal, swarm, autonomous vehicle, industrial robot, legal electronic person and other jurisdiction or embodiment profiles require specialist review and must not be inferred from this common core.
  • The frozen relation ledger contains no approved WM-PER-003 dependency rows; composition targets remain descriptive holds until registry relations are reviewed.
  • Certified PROV, A2A, WoT, ODRL and credential crosswalks, conformance fixtures and round-trip tests remain future work.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-per-003-non-human-agent/spec.yaml, ver-cy/world-models/card-supplements/wm-per-003-non-human-agent.json