Non-human Agent
Represent a persistent governed non-human actor with explicit identity, control, delegated authority, capabilities, operating state, attribution, oversight and lifecycle while remaining independent of storage and interface format.
Bundle → Layer → Finding → Questions Filled
7 bundles · 16 layers · 32 findings · 96 questions
Identity, kind and instance boundary Identifies the persistent governed agent and separates it from implementations, deployments, endpoints and sessions.
Persistent identity and lineage
Stable identifiers, aliases, versions and successor history for the governed actor.
Authoritative agent identifier and master system
The stable actor identifier, issuing authority, namespace, master system, resolution state and local bindings.
- What exact values, references, qualifiers and explicit unknowns must be recorded for authoritative agent identifier and master system? identity
- Which controller, operator, principal, authority, observation and evidence establishes authoritative agent identifier and master system, at what event, valid and knowledge time, and with what confidence? evidence
- How may authoritative agent identifier and master system be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Aliases, version, specialization and successor lineage
Names, protocol identifiers, definition versions, specializations, replacements, merges and retirement lineage without identity collapse.
- What exact values, references, qualifiers and explicit unknowns must be recorded for aliases, version, specialization and successor lineage? lifecycle
- Which controller, operator, principal, authority, observation and evidence establishes aliases, version, specialization and successor lineage, at what event, valid and knowledge time, and with what confidence? evidence
- How may aliases, version, specialization and successor lineage be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Kind, composition and boundary
Classification criteria and the distinction among actor, definition, deployment, endpoint, embodiment and session.
Non-human agent kind and classification criteria
Profile-qualified kind such as software, embodied, hybrid or collective machine actor, with observable criteria and prohibited subjecthood inferences.
- What exact values, references, qualifiers and explicit unknowns must be recorded for non-human agent kind and classification criteria? classification
- Which controller, operator, principal, authority, observation and evidence establishes non-human agent kind and classification criteria, at what event, valid and knowledge time, and with what confidence? evidence
- How may non-human agent kind and classification criteria be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Agent, definition, deployment, endpoint, embodiment and session boundary
Typed component and realization references with separate identifiers, masters, versions and lifecycles.
- What exact values, references, qualifiers and explicit unknowns must be recorded for agent, definition, deployment, endpoint, embodiment and session boundary? composition
- Which controller, operator, principal, authority, observation and evidence establishes agent, definition, deployment, endpoint, embodiment and session boundary, at what event, valid and knowledge time, and with what confidence? evidence
- How may agent, definition, deployment, endpoint, embodiment and session boundary be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Control, accountability and stakeholders Records who creates, controls, operates, benefits from and remains answerable for the agent.
Control and operating parties
Time-qualified bindings for parties with technical or organizational control.
Owner, controller, provider and deployer bindings
External party references, role basis, control surface, jurisdiction, validity and change history.
- What exact values, references, qualifiers and explicit unknowns must be recorded for owner, controller, provider and deployer bindings? relationship
- Which controller, operator, principal, authority, observation and evidence establishes owner, controller, provider and deployer bindings, at what event, valid and knowledge time, and with what confidence? evidence
- How may owner, controller, provider and deployer bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Operator, beneficiary, customer and affected-party bindings
Operational, beneficiary, service-recipient and affected-party roles with scope, time and source.
- What exact values, references, qualifiers and explicit unknowns must be recorded for operator, beneficiary, customer and affected-party bindings? relationship
- Which controller, operator, principal, authority, observation and evidence establishes operator, beneficiary, customer and affected-party bindings, at what event, valid and knowledge time, and with what confidence? evidence
- How may operator, beneficiary, customer and affected-party bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Accountability and responsibility
Answerability, escalation and the boundary between provenance responsibility and legal conclusions.
Accountable party, oversight owner and escalation contact
Who answers for deployment and use, receives escalation and has power to intervene, with delegated scope and availability.
- What exact values, references, qualifiers and explicit unknowns must be recorded for accountable party, oversight owner and escalation contact? authority
- Which controller, operator, principal, authority, observation and evidence establishes accountable party, oversight owner and escalation contact, at what event, valid and knowledge time, and with what confidence? evidence
- How may accountable party, oversight owner and escalation contact be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Activity responsibility attribution versus liability and personhood
PROV responsibility claims and explicit non-inference of intention, consciousness, legal personality, rights, duties or liability.
- What exact values, references, qualifiers and explicit unknowns must be recorded for activity responsibility attribution versus liability and personhood? provenance
- Which controller, operator, principal, authority, observation and evidence establishes activity responsibility attribution versus liability and personhood, at what event, valid and knowledge time, and with what confidence? evidence
- How may activity responsibility attribution versus liability and personhood be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Authority, mandate and delegation Defines the purpose-bound authority under which the agent may act.
Principal, mandate and delegation chain
The accountable principal, mandate, purpose and traceable chain of acting on behalf of another.
Principal, mandate, purpose, resource, jurisdiction and interval
The source authority, permitted purposes and targets, territorial or logical scope and validity interval.
- What exact values, references, qualifiers and explicit unknowns must be recorded for principal, mandate, purpose, resource, jurisdiction and interval? authority
- Which controller, operator, principal, authority, observation and evidence establishes principal, mandate, purpose, resource, jurisdiction and interval, at what event, valid and knowledge time, and with what confidence? evidence
- How may principal, mandate, purpose, resource, jurisdiction and interval be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Delegation chain, subdelegation, conditions and revocation
Each delegator, delegate, allowed onward delegation, conditions, expiry, suspension and revocation effect.
- What exact values, references, qualifiers and explicit unknowns must be recorded for delegation chain, subdelegation, conditions and revocation? relationship
- Which controller, operator, principal, authority, observation and evidence establishes delegation chain, subdelegation, conditions and revocation, at what event, valid and knowledge time, and with what confidence? evidence
- How may delegation chain, subdelegation, conditions and revocation be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Permission, credentials and policy
External policy and credential evidence that constrains actions at decision time.
Permission, prohibition, duty, constraint and approval gate
Referenced policy rules, actions, targets, conditions, duties, exceptions and human or organizational confirmation class.
- What exact values, references, qualifiers and explicit unknowns must be recorded for permission, prohibition, duty, constraint and approval gate? security
- Which controller, operator, principal, authority, observation and evidence establishes permission, prohibition, duty, constraint and approval gate, at what event, valid and knowledge time, and with what confidence? evidence
- How may permission, prohibition, duty, constraint and approval gate be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Credential scope, audience, holder, validity and status
Credential references and observations with issuer, subject, audience, proof, expiry and status while secrets stay external.
- What exact values, references, qualifiers and explicit unknowns must be recorded for credential scope, audience, holder, validity and status? evidence
- Which controller, operator, principal, authority, observation and evidence establishes credential scope, audience, holder, validity and status, at what event, valid and knowledge time, and with what confidence? evidence
- How may credential scope, audience, holder, validity and status be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Capability, behaviour, constraints and dependencies Describes what the agent can do, how it behaves and the envelope in which claims remain valid.
Capabilities, skills and interfaces
Declared and observed action surfaces plus machine-readable access bindings.
Declared, observed and verified capability surface
Actions, inputs, outputs, quality limits, confidence, evaluation basis and contexts in which the capability is available.
- What exact values, references, qualifiers and explicit unknowns must be recorded for declared, observed and verified capability surface? requirement
- Which controller, operator, principal, authority, observation and evidence establishes declared, observed and verified capability surface, at what event, valid and knowledge time, and with what confidence? evidence
- How may declared, observed and verified capability surface be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Skill, protocol, interface, action, property and event bindings
Versioned A2A, WoT or domain binding references with authentication, media, schema and negotiation metadata.
- What exact values, references, qualifiers and explicit unknowns must be recorded for skill, protocol, interface, action, property and event bindings? interoperability
- Which controller, operator, principal, authority, observation and evidence establishes skill, protocol, interface, action, property and event bindings, at what event, valid and knowledge time, and with what confidence? evidence
- How may skill, protocol, interface, action, property and event bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Behaviour, state and transition
Observable response patterns and governed operational states.
Behaviour policy, mode, trigger and observable signature
Expected responses under stated conditions, recognizable signatures, confidence, prohibited inference and drift indicators.
- What exact values, references, qualifiers and explicit unknowns must be recorded for behaviour policy, mode, trigger and observable signature? process
- Which controller, operator, principal, authority, observation and evidence establishes behaviour policy, mode, trigger and observable signature, at what event, valid and knowledge time, and with what confidence? evidence
- How may behaviour policy, mode, trigger and observable signature be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Registered, configured, ready, active, paused, degraded and stopped state
Current state, allowed transitions, actor and authority, reason, event and valid times, safe-state target and history.
- What exact values, references, qualifiers and explicit unknowns must be recorded for registered, configured, ready, active, paused, degraded and stopped state? state
- Which controller, operator, principal, authority, observation and evidence establishes registered, configured, ready, active, paused, degraded and stopped state, at what event, valid and knowledge time, and with what confidence? evidence
- How may registered, configured, ready, active, paused, degraded and stopped state be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Dependencies, envelope, hazards and failure
Conditions and components on which capability and safe behaviour depend.
Tool, model, memory, service and embodiment dependencies
Pinned external component references, trust state, version, availability, data boundary and degraded-mode effect.
- What exact values, references, qualifiers and explicit unknowns must be recorded for tool, model, memory, service and embodiment dependencies? composition
- Which controller, operator, principal, authority, observation and evidence establishes tool, model, memory, service and embodiment dependencies, at what event, valid and knowledge time, and with what confidence? evidence
- How may tool, model, memory, service and embodiment dependencies be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Operating envelope, prohibition, hazard, failure and recovery
Resource, time, cost, environment and safety limits, forbidden actions, failure signatures, containment and recovery path.
- What exact values, references, qualifiers and explicit unknowns must be recorded for operating envelope, prohibition, hazard, failure and recovery? constraint
- Which controller, operator, principal, authority, observation and evidence establishes operating envelope, prohibition, hazard, failure and recovery, at what event, valid and knowledge time, and with what confidence? evidence
- How may operating envelope, prohibition, hazard, failure and recovery be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Operation, attribution and oversight Connects agent state and execution context to activities, outputs and intervention controls.
Activation, deployment and session context
Which approved configuration is active where and how executions correlate to it.
Deployment, configuration, release and activation binding
Pinned external deployment and configuration references, approval, environment, activation authority and effective interval.
- What exact values, references, qualifiers and explicit unknowns must be recorded for deployment, configuration, release and activation binding? composition
- Which controller, operator, principal, authority, observation and evidence establishes deployment, configuration, release and activation binding, at what event, valid and knowledge time, and with what confidence? evidence
- How may deployment, configuration, release and activation binding be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Session, run, correlation and temporal context
External session and run references, correlation identifiers and distinct event, valid, observation, knowledge and ingestion times.
- What exact values, references, qualifiers and explicit unknowns must be recorded for session, run, correlation and temporal context? temporal
- Which controller, operator, principal, authority, observation and evidence establishes session, run, correlation and temporal context, at what event, valid and knowledge time, and with what confidence? evidence
- How may session, run, correlation and temporal context be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Activity and output attribution
Traceable associations among agent, activity, principal, plan, inputs and outputs.
Activity association, plan, role and delegation attribution
Which agent was associated with an activity, in which role, under which plan and on whose behalf.
- What exact values, references, qualifiers and explicit unknowns must be recorded for activity association, plan, role and delegation attribution? provenance
- Which controller, operator, principal, authority, observation and evidence establishes activity association, plan, role and delegation attribution, at what event, valid and knowledge time, and with what confidence? evidence
- How may activity association, plan, role and delegation attribution be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Output entity generation, attribution and derivation
Generated or influenced output references, activity, sources, agent version and provenance bundle.
- What exact values, references, qualifiers and explicit unknowns must be recorded for output entity generation, attribution and derivation? provenance
- Which controller, operator, principal, authority, observation and evidence establishes output entity generation, attribution and derivation, at what event, valid and knowledge time, and with what confidence? evidence
- How may output entity generation, attribution and derivation be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Oversight, intervention and safe state
Approval, monitoring, interruption, handoff and containment controls.
Human or organizational oversight, approval and intervention
Oversight role, competence reference, information supplied, approval gates, intervention controls and response evidence.
- What exact values, references, qualifiers and explicit unknowns must be recorded for human or organizational oversight, approval and intervention? authority
- Which controller, operator, principal, authority, observation and evidence establishes human or organizational oversight, approval and intervention, at what event, valid and knowledge time, and with what confidence? evidence
- How may human or organizational oversight, approval and intervention be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Monitoring, alert, escalation, suspension, handoff and fail-safe
Signals, thresholds, accountable recipient, timeout, suspension authority, safe-state behavior and recovery confirmation.
- What exact values, references, qualifiers and explicit unknowns must be recorded for monitoring, alert, escalation, suspension, handoff and fail-safe? process
- Which controller, operator, principal, authority, observation and evidence establishes monitoring, alert, escalation, suspension, handoff and fail-safe, at what event, valid and knowledge time, and with what confidence? evidence
- How may monitoring, alert, escalation, suspension, handoff and fail-safe be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Assurance, evidence, privacy and lifecycle Records bounded assurance claims, observations, incidents and durable lifecycle governance.
Assurance, monitoring and incidents
Risk, evaluation, limitation, telemetry and incident references.
Risk, evaluation, assurance, limitation and acceptance
External assessment references, test context, metrics, thresholds, residual risks, approver, validity and non-claims.
- What exact values, references, qualifiers and explicit unknowns must be recorded for risk, evaluation, assurance, limitation and acceptance? validation
- Which controller, operator, principal, authority, observation and evidence establishes risk, evaluation, assurance, limitation and acceptance, at what event, valid and knowledge time, and with what confidence? evidence
- How may risk, evaluation, assurance, limitation and acceptance be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Monitoring, drift, anomaly, incident, impact and corrective action
Observed signals and externally mastered incident or corrective-action references with severity, scope and status.
- What exact values, references, qualifiers and explicit unknowns must be recorded for monitoring, drift, anomaly, incident, impact and corrective action? evidence
- Which controller, operator, principal, authority, observation and evidence establishes monitoring, drift, anomaly, incident, impact and corrective action, at what event, valid and knowledge time, and with what confidence? evidence
- How may monitoring, drift, anomaly, incident, impact and corrective action be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Privacy, retention and agent lifecycle
Purpose-bound disclosure and governed suspension, retirement and tombstoning.
Data category, purpose, access, disclosure, retention and deletion
Field and artifact sensitivity, purpose, audience, access policy, retention class, legal hold and disposition evidence.
- What exact values, references, qualifiers and explicit unknowns must be recorded for data category, purpose, access, disclosure, retention and deletion? privacy
- Which controller, operator, principal, authority, observation and evidence establishes data category, purpose, access, disclosure, retention and deletion, at what event, valid and knowledge time, and with what confidence? evidence
- How may data category, purpose, access, disclosure, retention and deletion be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Suspension, revocation, retirement, replacement and tombstone
Authorized lifecycle endings, surviving delegations and credentials, successor, endpoint withdrawal, retention and durable identity tombstone.
- What exact values, references, qualifiers and explicit unknowns must be recorded for suspension, revocation, retirement, replacement and tombstone? lifecycle
- Which controller, operator, principal, authority, observation and evidence establishes suspension, revocation, retirement, replacement and tombstone, at what event, valid and knowledge time, and with what confidence? evidence
- How may suspension, revocation, retirement, replacement and tombstone be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Interoperability, governance and agent operations Controls projections, mapping loss and safe automated maintenance.
Profiles, projections and mapping loss
Versioned external representations and explicit non-equivalence.
PROV Agent, SoftwareAgent, association and delegation projection
Loss-aware mapping of agent identity, activity association, attribution and acted-on-behalf-of relations.
- What exact values, references, qualifiers and explicit unknowns must be recorded for prov agent, softwareagent, association and delegation projection? interoperability
- Which controller, operator, principal, authority, observation and evidence establishes prov agent, softwareagent, association and delegation projection, at what event, valid and knowledge time, and with what confidence? evidence
- How may prov agent, softwareagent, association and delegation projection be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
A2A Agent Card, WoT description and credential projection
Versioned discovery, affordance and proof projections with authentication, disclosure, omission and round-trip limits.
- What exact values, references, qualifiers and explicit unknowns must be recorded for a2a agent card, wot description and credential projection? interoperability
- Which controller, operator, principal, authority, observation and evidence establishes a2a agent card, wot description and credential projection, at what event, valid and knowledge time, and with what confidence? evidence
- How may a2a agent card, wot description and credential projection be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Safe agent control and validation
Authorized operations, invariants, concurrency and recovery.
Operation authority, purpose, preconditions, idempotency and evidence
Classifies each read, bind, delegate, activate, suspend, attribute, disclose and retire action with proof and effect.
- What exact values, references, qualifiers and explicit unknowns must be recorded for operation authority, purpose, preconditions, idempotency and evidence? security
- Which controller, operator, principal, authority, observation and evidence establishes operation authority, purpose, preconditions, idempotency and evidence, at what event, valid and knowledge time, and with what confidence? evidence
- How may operation authority, purpose, preconditions, idempotency and evidence be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Pre-write and post-write validation, conflict, concurrency and recovery
Identity, boundary, authority, state, time, provenance, privacy, stale-head and rollback checks with immutable audit evidence.
- What exact values, references, qualifiers and explicit unknowns must be recorded for pre-write and post-write validation, conflict, concurrency and recovery? validation
- Which controller, operator, principal, authority, observation and evidence establishes pre-write and post-write validation, conflict, concurrency and recovery, at what event, valid and knowledge time, and with what confidence? evidence
- How may pre-write and post-write validation, conflict, concurrency and recovery be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle? validation
Classifiers Filled
- Family
- World Models
- Category
- Society, people and institutions
- Entry kind
- entity
- Navigation path
- NAV.SOC.PER.AGT
- Domain
- SOC.PER.AGT
- Industry
- Cross-industry
- Tags
- nonhumanagentsoc.per.agt
What it is Filled
Owns the generic actor identity and kind, definition and instance boundary, control and accountable-party bindings, mandate and delegation envelope, capability and behavior assertions, dependency references, operating state, activity and output attribution, oversight, assurance references, privacy, lifecycle and loss-aware projections. External systems own persons, organizations, software, AI systems and models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence objects.
In scope
- Persistent non-human agent identity, issuer, kind, aliases, versions, components and successor lineage
- Controller, provider, deployer, operator, principal, beneficiary, affected-party and accountable-party bindings
- Mandate, delegation, permission references, capabilities, behavior, dependencies, operating envelope, states, attribution, oversight, assurance, privacy, lifecycle and exchange
Out of scope
- Human person, organization, software product, AI system, AI model, physical embodiment, task, activity, output, credential, policy, access decision, incident and evidence master lifecycles
- Claims that the agent is conscious, sentient, intentional, a legal person, a rights-holder or itself legally liable
- AI Agent details already owned by WM-AI-002, physical robotics semantics, universal authorization rules or deployment-specific compliance conclusions
Why it exists Filled
Represent a persistent governed non-human actor with explicit identity, control, delegated authority, capabilities, operating state, attribution, oversight and lifecycle while remaining independent of storage and interface format.
Distinguishing features Filled
- Covers any non-human actor that acts, including software agents, robots and automated systems, not only AI agents.
- Every agent is bound to a controlling and an accountable party.
- Separates the agent definition from its running instances.
- Makes no claim about consciousness, legal personhood or moral status.
What robots and AI may and may not do Filled
Must not
- Act outside its delegated mandate.
- Pretend to be a human or another agent.
- Delegate authority it does not have.
- Hide its accountable party when asked.
- Claim rights, sentience or legal personhood.
Only with a human decision
- Granting or extending mandates.
- Deploying agents that act in the physical world or with financial effect.
- Decommissioning an agent with ongoing obligations.
May
- Declare its own identity, controller, mandate and capabilities.
- Attribute its outputs and actions to itself in records.
- Report its operating state and errors.
- Refuse tasks outside its mandate.
Moral aspects Filled
- People must know when they deal with a machine and who is responsible for it.
- Accountability gaps appear when agents act through long delegation chains.
- Claims about agent sentience can mislead and manipulate users.
Who is affected
- People interacting with agents
- Controllers and accountable parties
- Third parties affected by agent actions
Owners Filled
Steward
Dimension identity, owner, agent registrar, delegation authority, oversight owner and namespace
Roles
- Dimension owner
- Own namespace, mastership, delegation, access, retention and federation rules.
- Agent registrar
- Maintain persistent identity, kind, boundary, aliases and successor lineage.
- Controller or provider
- Declare the controlled agent and maintain accurate configuration, capability and limitation references.
- Deployer or operator
- Operate only within current delegation and envelope and preserve activation, oversight and incident evidence.
- Delegating principal
- Grant, constrain, suspend and revoke purpose-bound authority within its own authority.
- Accountable and oversight owner
- Review consequential action, intervene, receive escalation and accept or reject residual risk.
- Safety, privacy and access steward
- Apply minimum disclosure, monitoring, incident, retention and security controls.
- Independent auditor
- Review identity, delegation, state, attribution, controls and evidence without rewriting source records.
Links to other meta-models Filled
child
- WM-AI-002 AI Agent - Reuse the generic governed actor core while AI-specific model, memory, tool, protocol, evaluation and regulation semantics stay in the specialization.
references
- Person, Organization, Software, AI System, AI Model, Embodiment, Task, Activity, Output, Policy, Credential, Incident and Evidence models - Connect the agent to externally mastered parties, components, executions, rules and evidence without identity or lifecycle duplication.
aligned
- W3C PROV-DM and PROV-O - Project agent, SoftwareAgent, association, attribution, delegation, specialization and revision provenance.
- A2A Protocol Specification - Publish an optional discovery and protocol projection through Agent Cards, skills, capabilities and interfaces.
- ODRL Information Model 2.2 and Verifiable Credentials Data Model 2.0 - Represent purpose-bound authority policy and portable evidence without importing authorization or credential lifecycles.
- Web of Things Thing Description 1.1 - Project optional properties, actions, events, forms and security metadata for networked or embodied agent interfaces.
neighbor
- WM-AI-002 AI Agent - AI Agent is a specialization that owns AI-specific model, memory, tools, protocols, evaluation and regulatory context; this model supplies the common non-human actor identity, delegation, attribution and lifecycle core.
- Software, AI System and AI Model - Software and models are components or implementations; the governed actor has its own persistent identity, controller, authority and state and may change components without silent identity replacement.
- Robot, Device and Embodiment - A physical body owns geometry, material, pose, mechanics and safety details; this model records only the agent-to-embodiment binding and delegated physical operating envelope.
- Session, Run, Task and Activity - These are bounded execution or work records; the agent is the durable actor referenced from each and keeps only correlation and attribution links.
- Credential, Access and Policy - Credentials and policies provide evidence and authorization inputs; possession or technical ability does not establish current permission.
- Legal or moral subject - Technical autonomy and provenance responsibility do not establish consciousness, intention, rights, duties, personhood or liability; those conclusions require external law, evidence and authority.
What else AI and robots need to interact with it Filled
Identity and identifiers required Filled
- Authoritative master-system identifier for the governed agent, qualified by issuer.
- Governed globally resolvable agent IRI with explicit master-system binding.
- Adopting-Dimension UUID or ULID when no authoritative external identifier exists.
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Filled
- A non-human agent has an identifier, a kind, a controller, an accountable party and a mandate.
- It is confused with the software product it runs on, with its human operator and with a service account.
Capabilities and actions required Filled
- Register non-human agent: Create the persistent actor identity, kind, master binding and explicit boundaries.
- Bind control and accountability parties: Append time-qualified owner, controller, provider, deployer, operator and accountable-party bindings.
- Grant purpose-bound delegation: Attach an authorized mandate with principal, purpose, resources, interval, constraints and subdelegation rule.
- Constrain, suspend or revoke delegation: Reduce or end delegated authority without erasing prior grants or activity provenance.
- Declare capability and limits: Record declared, observed or verified ability with context, evidence, confidence and prohibitions.
- Bind interface and dependency: Pin a protocol, skill, tool, model, memory, service or embodiment and state its trust and degraded-mode effect.
- Transition operational state: Activate, pause, degrade, suspend, stop or recover the agent under a valid transition and authority.
- Attribute activity or output: Link an external activity or entity to the exact agent, role, plan, delegation, version and execution context.
- Request approval or escalate: Route an action, ambiguity, threshold breach or loss-of-control condition to the accountable authority.
- Attach assurance or incident evidence: Reference an evaluation, limitation, risk acceptance, monitoring observation, incident or corrective action.
- Project agent profile: Produce a purpose-bound PROV, A2A, WoT or credential view with explicit omissions and mapping loss.
- Retire non-human agent: End authority and operation, withdraw discoverability, reconcile credentials and preserve a durable tombstone.
Hazards and failure modes required Filled
- Actions beyond mandate through prompt injection or misconfiguration.
- Impersonation of humans or other agents.
- Unclear liability after harm.
Standards and interfaces required Filled
- W3C Decentralized Identifiers (DIDs) 1.0.
- OAuth 2.0 (RFC 6749) for delegated authorization.
- ISO/IEC 42001 AI management systems.
- Model Context Protocol (MCP).
Context of use required Filled
- The EU AI Act supplies an EU AI-system profile and does not govern every non-human agent or create universal subject status.
- PROV responsibility attribution is a provenance relation and does not decide legal accountability or liability in any jurisdiction.
- A2A, WoT, ODRL and Verifiable Credentials are optional interoperability profiles, not mandatory storage or interface formats.
Sources Filled
- PROV-DM: The PROV Data Model - World Wide Web Consortium
- PROV-O: The PROV Ontology - World Wide Web Consortium
- AI Risk Management Framework: Audience - National Institute of Standards and Technology
- A2A Protocol Specification - A2A Project under the Linux Foundation
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence - European Union
- ODRL Information Model 2.2 - World Wide Web Consortium
- Verifiable Credentials Data Model v2.0 - World Wide Web Consortium
- Time Ontology in OWL - World Wide Web Consortium
- Web of Things Thing Description 1.1 - World Wide Web Consortium
- Date and Time on the Internet: Timestamps - Internet Engineering Task Force
Open questions
- Review the parent and child split with WM-AI-002 and approve exact field ownership, dependency direction and version compatibility.
- Approve model identifiers and relation cardinalities for persons, organizations, software, AI systems, models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence.
- Develop specialist profiles for software services, embodied robots, autonomous vehicles, swarms, animals and any future legally recognized electronic subject.
- Create deterministic fixtures for identity replacement, controller changes, nested delegation, stale credentials, dependency loss, safe-state entry, disputed attribution and private-agent discovery.
- Validate certified provenance, discovery, affordance, policy and credential projections with explicit disclosure, loss and round-trip tests.
- No independent Claude or Grok result was available; this source-grounded Codex fallback requires later external review before canonical promotion.
- WM-AI-002 AI Agent, software, AI system, model, robot or embodiment, task, activity, credential, access, incident and evidence models retain their own detailed semantics.
- Animal, swarm, autonomous vehicle, industrial robot, legal electronic person and other jurisdiction or embodiment profiles require specialist review and must not be inferred from this common core.
- The frozen relation ledger contains no approved WM-PER-003 dependency rows; composition targets remain descriptive holds until registry relations are reviewed.
- Certified PROV, A2A, WoT, ODRL and credential crosswalks, conformance fixtures and round-trip tests remain future work.
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-per-003-non-human-agent/spec.yaml, ver-cy/world-models/card-supplements/wm-per-003-non-human-agent.json