# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T01:44:47Z", "synthesisSha256": "7f9ee90e60284fdc12d4f2316f79b2798794916285a1bd6400efb132dbee7ccb", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-PER-003", "registryId": "vr.wm-per-003", "name": "Non-human Agent", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Society, people and institutions", "industry": [ "Cross-industry" ], "domain": [ "SOC.PER.AGT" ], "tags": [ "non", "human", "agent", "soc.per.agt" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-per-003-non-human-agent/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-per-003", "model": { "registry_id": "vr.wm-per-003", "model_id": "WM-PER-003", "name": "Non-human Agent", "entry_kind": "entity", "purpose": "Represent a persistent governed non-human actor with explicit identity, control, delegated authority, capabilities, operating state, attribution, oversight and lifecycle while remaining independent of storage and interface format.", "scope_statement": "Owns the generic actor identity and kind, definition and instance boundary, control and accountable-party bindings, mandate and delegation envelope, capability and behavior assertions, dependency references, operating state, activity and output attribution, oversight, assurance references, privacy, lifecycle and loss-aware projections. External systems own persons, organizations, software, AI systems and models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence objects.", "in_scope": [ "Persistent non-human agent identity, issuer, kind, aliases, versions, components and successor lineage", "Controller, provider, deployer, operator, principal, beneficiary, affected-party and accountable-party bindings", "Mandate, delegation, permission references, capabilities, behavior, dependencies, operating envelope, states, attribution, oversight, assurance, privacy, lifecycle and exchange" ], "out_of_scope": [ "Human person, organization, software product, AI system, AI model, physical embodiment, task, activity, output, credential, policy, access decision, incident and evidence master lifecycles", "Claims that the agent is conscious, sentient, intentional, a legal person, a rights-holder or itself legally liable", "AI Agent details already owned by WM-AI-002, physical robotics semantics, universal authorization rules or deployment-specific compliance conclusions" ], "boundary_notes": [ { "neighbor": "WM-AI-002 AI Agent", "distinction": "AI Agent is a specialization that owns AI-specific model, memory, tools, protocols, evaluation and regulatory context; this model supplies the common non-human actor identity, delegation, attribution and lifecycle core.", "source_refs": [ "SRC-003", "SRC-005" ] }, { "neighbor": "Software, AI System and AI Model", "distinction": "Software and models are components or implementations; the governed actor has its own persistent identity, controller, authority and state and may change components without silent identity replacement.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "neighbor": "Robot, Device and Embodiment", "distinction": "A physical body owns geometry, material, pose, mechanics and safety details; this model records only the agent-to-embodiment binding and delegated physical operating envelope.", "source_refs": [ "SRC-009" ] }, { "neighbor": "Session, Run, Task and Activity", "distinction": "These are bounded execution or work records; the agent is the durable actor referenced from each and keeps only correlation and attribution links.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "neighbor": "Credential, Access and Policy", "distinction": "Credentials and policies provide evidence and authorization inputs; possession or technical ability does not establish current permission.", "source_refs": [ "SRC-006", "SRC-007" ] }, { "neighbor": "Legal or moral subject", "distinction": "Technical autonomy and provenance responsibility do not establish consciousness, intention, rights, duties, personhood or liability; those conclusions require external law, evidence and authority.", "source_refs": [ "SRC-001", "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "PROV-DM: The PROV Data Model", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-dm/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Defines Agent, SoftwareAgent, attribution, association, delegation and responsibility for activities and entities without assigning legal personhood or liability." }, { "id": "SRC-002", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Provides machine-readable agent, software-agent, activity, entity, association, attribution, delegation, specialization and revision relations." }, { "id": "SRC-003", "title": "AI Risk Management Framework: Audience", "organization": "National Institute of Standards and Technology", "url": "https://airc.nist.gov/airmf-resources/airmf/2-sec-audience/", "version_or_date": "AI RMF 1.0 resource, accessed 6 September 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Separates AI lifecycle actors and responsibilities and supports explicit governance, oversight and accountability bindings for AI-related profiles." }, { "id": "SRC-004", "title": "A2A Protocol Specification", "organization": "A2A Project under the Linux Foundation", "url": "https://a2a-protocol.org/latest/specification/", "version_or_date": "Latest public specification, accessed 6 September 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Defines agent discovery through Agent Cards, skills, capabilities, interfaces, authentication and authorization, tasks, messages and artifacts for an optional protocol projection." }, { "id": "SRC-005", "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj", "version_or_date": "Regulation (EU) 2024/1689, 13 June 2024", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Supplies an EU AI profile for provider and deployer roles, record keeping, transparency, human oversight, robustness, cybersecurity and post-market duties without defining all non-human agents." }, { "id": "SRC-006", "title": "ODRL Information Model 2.2", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/odrl-model/", "version_or_date": "W3C Recommendation, 15 February 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Provides policies, permissions, prohibitions, duties, parties, actions and constraints for expressing referenced authority envelopes without turning capability into permission." }, { "id": "SRC-007", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Provides issuer, credential subject, validity, status, schema, evidence and terms-of-use patterns for portable agent or delegation attestations while credentials remain evidence." }, { "id": "SRC-008", "title": "Time Ontology in OWL", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/owl-time/", "version_or_date": "W3C Recommendation, 19 October 2017; current 15 November 2022 edition", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Provides instants, intervals, durations and temporal relations for identity, delegation, activation, observation and lifecycle validity." }, { "id": "SRC-009", "title": "Web of Things Thing Description 1.1", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/wot-thing-description11/", "version_or_date": "W3C Recommendation, 5 December 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Defines affordance-oriented descriptions of properties, actions, events, forms and security metadata useful for an optional embodied or networked agent interface projection." }, { "id": "SRC-010", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:38:00Z", "relevance": "Defines interoperable timestamps with seconds and explicit UTC relation for delegation, activation, attribution, observation and lifecycle events." } ], "structure": { "bundles": [ { "id": "identity-kind-and-instance-boundary", "name": "Identity, kind and instance boundary", "description": "Identifies the persistent governed agent and separates it from implementations, deployments, endpoints and sessions.", "rationale": "Attribution and governance fail when an agent name, executable, model, device, endpoint and run identifier are treated as one identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-008" ], "layers": [ { "id": "persistent-identity-and-lineage", "name": "Persistent identity and lineage", "description": "Stable identifiers, aliases, versions and successor history for the governed actor.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ], "findings": [ { "id": "authoritative-agent-identifier-and-master-system", "name": "Authoritative agent identifier and master system", "description": "The stable actor identifier, issuing authority, namespace, master system, resolution state and local bindings.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "authoritative-agent-identifier-and-master-system-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for authoritative agent identifier and master system?", "kind": "identity", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "authoritative-agent-identifier-and-master-system-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes authoritative agent identifier and master system, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "authoritative-agent-identifier-and-master-system-q03", "text": "How may authoritative agent identifier and master system be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "authoritative-agent-identifier-and-master-system-data", "name": "Authoritative agent identifier and master system data", "description": "Structured, source-qualified answer data for authoritative agent identifier and master system.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "authoritative-agent-identifier-and-master-system-record", "name": "Authoritative agent identifier and master system record", "description": "Versioned evidence-bearing record for authoritative agent identifier and master system with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus authoritative-agent-identifier-and-master-system assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "aliases-version-specialization-and-successor-lineage", "name": "Aliases, version, specialization and successor lineage", "description": "Names, protocol identifiers, definition versions, specializations, replacements, merges and retirement lineage without identity collapse.", "source_refs": [ "SRC-002", "SRC-004" ], "questions": [ { "id": "aliases-version-specialization-and-successor-lineage-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for aliases, version, specialization and successor lineage?", "kind": "lifecycle", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "aliases-version-specialization-and-successor-lineage-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes aliases, version, specialization and successor lineage, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "aliases-version-specialization-and-successor-lineage-q03", "text": "How may aliases, version, specialization and successor lineage be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "aliases-version-specialization-and-successor-lineage-data", "name": "Aliases, version, specialization and successor lineage data", "description": "Structured, source-qualified answer data for aliases, version, specialization and successor lineage.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "aliases-version-specialization-and-successor-lineage-record", "name": "Aliases, version, specialization and successor lineage record", "description": "Versioned evidence-bearing record for aliases, version, specialization and successor lineage with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus aliases-version-specialization-and-successor-lineage assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "kind-composition-and-boundary", "name": "Kind, composition and boundary", "description": "Classification criteria and the distinction among actor, definition, deployment, endpoint, embodiment and session.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009" ], "findings": [ { "id": "nonhuman-agent-kind-and-classification-criteria", "name": "Non-human agent kind and classification criteria", "description": "Profile-qualified kind such as software, embodied, hybrid or collective machine actor, with observable criteria and prohibited subjecthood inferences.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ], "questions": [ { "id": "nonhuman-agent-kind-and-classification-criteria-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for non-human agent kind and classification criteria?", "kind": "classification", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "nonhuman-agent-kind-and-classification-criteria-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes non-human agent kind and classification criteria, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "nonhuman-agent-kind-and-classification-criteria-q03", "text": "How may non-human agent kind and classification criteria be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "nonhuman-agent-kind-and-classification-criteria-data", "name": "Non-human agent kind and classification criteria data", "description": "Structured, source-qualified answer data for non-human agent kind and classification criteria.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] } ], "artifacts": [ { "id": "nonhuman-agent-kind-and-classification-criteria-record", "name": "Non-human agent kind and classification criteria record", "description": "Versioned evidence-bearing record for non-human agent kind and classification criteria with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus nonhuman-agent-kind-and-classification-criteria assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "agent-definition-deployment-endpoint-embodiment-session-boundary", "name": "Agent, definition, deployment, endpoint, embodiment and session boundary", "description": "Typed component and realization references with separate identifiers, masters, versions and lifecycles.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009" ], "questions": [ { "id": "agent-definition-deployment-endpoint-embodiment-session-boundary-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for agent, definition, deployment, endpoint, embodiment and session boundary?", "kind": "composition", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "agent-definition-deployment-endpoint-embodiment-session-boundary-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes agent, definition, deployment, endpoint, embodiment and session boundary, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "agent-definition-deployment-endpoint-embodiment-session-boundary-q03", "text": "How may agent, definition, deployment, endpoint, embodiment and session boundary be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "agent-definition-deployment-endpoint-embodiment-session-boundary-data", "name": "Agent, definition, deployment, endpoint, embodiment and session boundary data", "description": "Structured, source-qualified answer data for agent, definition, deployment, endpoint, embodiment and session boundary.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "agent-definition-deployment-endpoint-embodiment-session-boundary-record", "name": "Agent, definition, deployment, endpoint, embodiment and session boundary record", "description": "Versioned evidence-bearing record for agent, definition, deployment, endpoint, embodiment and session boundary with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus agent-definition-deployment-endpoint-embodiment-session-boundary assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "control-accountability-and-stakeholders", "name": "Control, accountability and stakeholders", "description": "Records who creates, controls, operates, benefits from and remains answerable for the agent.", "rationale": "Non-human agency must not hide the natural persons and organizations that configure, authorize, operate or benefit from it.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "layers": [ { "id": "control-and-operating-parties", "name": "Control and operating parties", "description": "Time-qualified bindings for parties with technical or organizational control.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "findings": [ { "id": "owner-controller-provider-and-deployer-bindings", "name": "Owner, controller, provider and deployer bindings", "description": "External party references, role basis, control surface, jurisdiction, validity and change history.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "owner-controller-provider-and-deployer-bindings-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for owner, controller, provider and deployer bindings?", "kind": "relationship", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "owner-controller-provider-and-deployer-bindings-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes owner, controller, provider and deployer bindings, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "owner-controller-provider-and-deployer-bindings-q03", "text": "How may owner, controller, provider and deployer bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "owner-controller-provider-and-deployer-bindings-data", "name": "Owner, controller, provider and deployer bindings data", "description": "Structured, source-qualified answer data for owner, controller, provider and deployer bindings.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "owner-controller-provider-and-deployer-bindings-record", "name": "Owner, controller, provider and deployer bindings record", "description": "Versioned evidence-bearing record for owner, controller, provider and deployer bindings with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus owner-controller-provider-and-deployer-bindings assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "operator-beneficiary-customer-and-affected-party-bindings", "name": "Operator, beneficiary, customer and affected-party bindings", "description": "Operational, beneficiary, service-recipient and affected-party roles with scope, time and source.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "operator-beneficiary-customer-and-affected-party-bindings-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for operator, beneficiary, customer and affected-party bindings?", "kind": "relationship", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "operator-beneficiary-customer-and-affected-party-bindings-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes operator, beneficiary, customer and affected-party bindings, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "operator-beneficiary-customer-and-affected-party-bindings-q03", "text": "How may operator, beneficiary, customer and affected-party bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "operator-beneficiary-customer-and-affected-party-bindings-data", "name": "Operator, beneficiary, customer and affected-party bindings data", "description": "Structured, source-qualified answer data for operator, beneficiary, customer and affected-party bindings.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "operator-beneficiary-customer-and-affected-party-bindings-record", "name": "Operator, beneficiary, customer and affected-party bindings record", "description": "Versioned evidence-bearing record for operator, beneficiary, customer and affected-party bindings with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus operator-beneficiary-customer-and-affected-party-bindings assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "accountability-and-responsibility", "name": "Accountability and responsibility", "description": "Answerability, escalation and the boundary between provenance responsibility and legal conclusions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ], "findings": [ { "id": "accountable-party-oversight-owner-and-escalation-contact", "name": "Accountable party, oversight owner and escalation contact", "description": "Who answers for deployment and use, receives escalation and has power to intervene, with delegated scope and availability.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "accountable-party-oversight-owner-and-escalation-contact-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for accountable party, oversight owner and escalation contact?", "kind": "authority", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "accountable-party-oversight-owner-and-escalation-contact-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes accountable party, oversight owner and escalation contact, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "accountable-party-oversight-owner-and-escalation-contact-q03", "text": "How may accountable party, oversight owner and escalation contact be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "accountable-party-oversight-owner-and-escalation-contact-data", "name": "Accountable party, oversight owner and escalation contact data", "description": "Structured, source-qualified answer data for accountable party, oversight owner and escalation contact.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "accountable-party-oversight-owner-and-escalation-contact-record", "name": "Accountable party, oversight owner and escalation contact record", "description": "Versioned evidence-bearing record for accountable party, oversight owner and escalation contact with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus accountable-party-oversight-owner-and-escalation-contact assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "activity-responsibility-attribution-versus-liability-and-personhood", "name": "Activity responsibility attribution versus liability and personhood", "description": "PROV responsibility claims and explicit non-inference of intention, consciousness, legal personality, rights, duties or liability.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "activity-responsibility-attribution-versus-liability-and-personhood-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for activity responsibility attribution versus liability and personhood?", "kind": "provenance", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "activity-responsibility-attribution-versus-liability-and-personhood-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes activity responsibility attribution versus liability and personhood, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "activity-responsibility-attribution-versus-liability-and-personhood-q03", "text": "How may activity responsibility attribution versus liability and personhood be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "activity-responsibility-attribution-versus-liability-and-personhood-data", "name": "Activity responsibility attribution versus liability and personhood data", "description": "Structured, source-qualified answer data for activity responsibility attribution versus liability and personhood.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "activity-responsibility-attribution-versus-liability-and-personhood-record", "name": "Activity responsibility attribution versus liability and personhood record", "description": "Versioned evidence-bearing record for activity responsibility attribution versus liability and personhood with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus activity-responsibility-attribution-versus-liability-and-personhood assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "authority-mandate-and-delegation", "name": "Authority, mandate and delegation", "description": "Defines the purpose-bound authority under which the agent may act.", "rationale": "A capability describes what an agent can do; only a current mandate, delegation and policy can establish what it may do.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007", "SRC-008" ], "layers": [ { "id": "principal-mandate-and-delegation-chain", "name": "Principal, mandate and delegation chain", "description": "The accountable principal, mandate, purpose and traceable chain of acting on behalf of another.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-008" ], "findings": [ { "id": "principal-mandate-purpose-resource-jurisdiction-and-interval", "name": "Principal, mandate, purpose, resource, jurisdiction and interval", "description": "The source authority, permitted purposes and targets, territorial or logical scope and validity interval.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008" ], "questions": [ { "id": "principal-mandate-purpose-resource-jurisdiction-and-interval-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for principal, mandate, purpose, resource, jurisdiction and interval?", "kind": "authority", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "principal-mandate-purpose-resource-jurisdiction-and-interval-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes principal, mandate, purpose, resource, jurisdiction and interval, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "principal-mandate-purpose-resource-jurisdiction-and-interval-q03", "text": "How may principal, mandate, purpose, resource, jurisdiction and interval be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "principal-mandate-purpose-resource-jurisdiction-and-interval-data", "name": "Principal, mandate, purpose, resource, jurisdiction and interval data", "description": "Structured, source-qualified answer data for principal, mandate, purpose, resource, jurisdiction and interval.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-008" ] } ], "artifacts": [ { "id": "principal-mandate-purpose-resource-jurisdiction-and-interval-record", "name": "Principal, mandate, purpose, resource, jurisdiction and interval record", "description": "Versioned evidence-bearing record for principal, mandate, purpose, resource, jurisdiction and interval with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus principal-mandate-purpose-resource-jurisdiction-and-interval assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "delegation-chain-subdelegation-conditions-and-revocation", "name": "Delegation chain, subdelegation, conditions and revocation", "description": "Each delegator, delegate, allowed onward delegation, conditions, expiry, suspension and revocation effect.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "questions": [ { "id": "delegation-chain-subdelegation-conditions-and-revocation-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for delegation chain, subdelegation, conditions and revocation?", "kind": "relationship", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "delegation-chain-subdelegation-conditions-and-revocation-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes delegation chain, subdelegation, conditions and revocation, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "delegation-chain-subdelegation-conditions-and-revocation-q03", "text": "How may delegation chain, subdelegation, conditions and revocation be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "delegation-chain-subdelegation-conditions-and-revocation-data", "name": "Delegation chain, subdelegation, conditions and revocation data", "description": "Structured, source-qualified answer data for delegation chain, subdelegation, conditions and revocation.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "artifacts": [ { "id": "delegation-chain-subdelegation-conditions-and-revocation-record", "name": "Delegation chain, subdelegation, conditions and revocation record", "description": "Versioned evidence-bearing record for delegation chain, subdelegation, conditions and revocation with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus delegation-chain-subdelegation-conditions-and-revocation assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "permission-credentials-and-policy", "name": "Permission, credentials and policy", "description": "External policy and credential evidence that constrains actions at decision time.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ], "findings": [ { "id": "permission-prohibition-duty-constraint-and-approval-gate", "name": "Permission, prohibition, duty, constraint and approval gate", "description": "Referenced policy rules, actions, targets, conditions, duties, exceptions and human or organizational confirmation class.", "source_refs": [ "SRC-006" ], "questions": [ { "id": "permission-prohibition-duty-constraint-and-approval-gate-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for permission, prohibition, duty, constraint and approval gate?", "kind": "security", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "permission-prohibition-duty-constraint-and-approval-gate-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes permission, prohibition, duty, constraint and approval gate, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "permission-prohibition-duty-constraint-and-approval-gate-q03", "text": "How may permission, prohibition, duty, constraint and approval gate be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "permission-prohibition-duty-constraint-and-approval-gate-data", "name": "Permission, prohibition, duty, constraint and approval gate data", "description": "Structured, source-qualified answer data for permission, prohibition, duty, constraint and approval gate.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "permission-prohibition-duty-constraint-and-approval-gate-record", "name": "Permission, prohibition, duty, constraint and approval gate record", "description": "Versioned evidence-bearing record for permission, prohibition, duty, constraint and approval gate with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus permission-prohibition-duty-constraint-and-approval-gate assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "credential-scope-audience-holder-validity-and-status", "name": "Credential scope, audience, holder, validity and status", "description": "Credential references and observations with issuer, subject, audience, proof, expiry and status while secrets stay external.", "source_refs": [ "SRC-007", "SRC-008" ], "questions": [ { "id": "credential-scope-audience-holder-validity-and-status-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for credential scope, audience, holder, validity and status?", "kind": "evidence", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "credential-scope-audience-holder-validity-and-status-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes credential scope, audience, holder, validity and status, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "credential-scope-audience-holder-validity-and-status-q03", "text": "How may credential scope, audience, holder, validity and status be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "credential-scope-audience-holder-validity-and-status-data", "name": "Credential scope, audience, holder, validity and status data", "description": "Structured, source-qualified answer data for credential scope, audience, holder, validity and status.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "credential-scope-audience-holder-validity-and-status-record", "name": "Credential scope, audience, holder, validity and status record", "description": "Versioned evidence-bearing record for credential scope, audience, holder, validity and status with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus credential-scope-audience-holder-validity-and-status assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "capability-behaviour-constraints-and-dependencies", "name": "Capability, behaviour, constraints and dependencies", "description": "Describes what the agent can do, how it behaves and the envelope in which claims remain valid.", "rationale": "Declarations, observations, permissions and safety claims are different evidence classes and must remain separately attributable.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-009" ], "layers": [ { "id": "capabilities-skills-and-interfaces", "name": "Capabilities, skills and interfaces", "description": "Declared and observed action surfaces plus machine-readable access bindings.", "source_refs": [ "SRC-004", "SRC-009" ], "findings": [ { "id": "declared-observed-and-verified-capability-surface", "name": "Declared, observed and verified capability surface", "description": "Actions, inputs, outputs, quality limits, confidence, evaluation basis and contexts in which the capability is available.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "questions": [ { "id": "declared-observed-and-verified-capability-surface-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for declared, observed and verified capability surface?", "kind": "requirement", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "declared-observed-and-verified-capability-surface-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes declared, observed and verified capability surface, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "declared-observed-and-verified-capability-surface-q03", "text": "How may declared, observed and verified capability surface be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "declared-observed-and-verified-capability-surface-data", "name": "Declared, observed and verified capability surface data", "description": "Structured, source-qualified answer data for declared, observed and verified capability surface.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "declared-observed-and-verified-capability-surface-record", "name": "Declared, observed and verified capability surface record", "description": "Versioned evidence-bearing record for declared, observed and verified capability surface with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus declared-observed-and-verified-capability-surface assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "skill-protocol-interface-action-property-and-event-bindings", "name": "Skill, protocol, interface, action, property and event bindings", "description": "Versioned A2A, WoT or domain binding references with authentication, media, schema and negotiation metadata.", "source_refs": [ "SRC-004", "SRC-009" ], "questions": [ { "id": "skill-protocol-interface-action-property-and-event-bindings-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for skill, protocol, interface, action, property and event bindings?", "kind": "interoperability", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "skill-protocol-interface-action-property-and-event-bindings-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes skill, protocol, interface, action, property and event bindings, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "skill-protocol-interface-action-property-and-event-bindings-q03", "text": "How may skill, protocol, interface, action, property and event bindings be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "skill-protocol-interface-action-property-and-event-bindings-data", "name": "Skill, protocol, interface, action, property and event bindings data", "description": "Structured, source-qualified answer data for skill, protocol, interface, action, property and event bindings.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "skill-protocol-interface-action-property-and-event-bindings-record", "name": "Skill, protocol, interface, action, property and event bindings record", "description": "Versioned evidence-bearing record for skill, protocol, interface, action, property and event bindings with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus skill-protocol-interface-action-property-and-event-bindings assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "behaviour-state-and-transition", "name": "Behaviour, state and transition", "description": "Observable response patterns and governed operational states.", "source_refs": [ "SRC-003", "SRC-004", "SRC-008" ], "findings": [ { "id": "behaviour-policy-mode-trigger-and-observable-signature", "name": "Behaviour policy, mode, trigger and observable signature", "description": "Expected responses under stated conditions, recognizable signatures, confidence, prohibited inference and drift indicators.", "source_refs": [ "SRC-003", "SRC-004" ], "questions": [ { "id": "behaviour-policy-mode-trigger-and-observable-signature-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for behaviour policy, mode, trigger and observable signature?", "kind": "process", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "behaviour-policy-mode-trigger-and-observable-signature-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes behaviour policy, mode, trigger and observable signature, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "behaviour-policy-mode-trigger-and-observable-signature-q03", "text": "How may behaviour policy, mode, trigger and observable signature be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "behaviour-policy-mode-trigger-and-observable-signature-data", "name": "Behaviour policy, mode, trigger and observable signature data", "description": "Structured, source-qualified answer data for behaviour policy, mode, trigger and observable signature.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "behaviour-policy-mode-trigger-and-observable-signature-record", "name": "Behaviour policy, mode, trigger and observable signature record", "description": "Versioned evidence-bearing record for behaviour policy, mode, trigger and observable signature with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus behaviour-policy-mode-trigger-and-observable-signature assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "registered-configured-ready-active-paused-degraded-and-stopped-state", "name": "Registered, configured, ready, active, paused, degraded and stopped state", "description": "Current state, allowed transitions, actor and authority, reason, event and valid times, safe-state target and history.", "source_refs": [ "SRC-003", "SRC-008" ], "questions": [ { "id": "registered-configured-ready-active-paused-degraded-and-stopped-state-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for registered, configured, ready, active, paused, degraded and stopped state?", "kind": "state", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "registered-configured-ready-active-paused-degraded-and-stopped-state-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes registered, configured, ready, active, paused, degraded and stopped state, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "registered-configured-ready-active-paused-degraded-and-stopped-state-q03", "text": "How may registered, configured, ready, active, paused, degraded and stopped state be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "registered-configured-ready-active-paused-degraded-and-stopped-state-data", "name": "Registered, configured, ready, active, paused, degraded and stopped state data", "description": "Structured, source-qualified answer data for registered, configured, ready, active, paused, degraded and stopped state.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-008" ] } ], "artifacts": [ { "id": "registered-configured-ready-active-paused-degraded-and-stopped-state-record", "name": "Registered, configured, ready, active, paused, degraded and stopped state record", "description": "Versioned evidence-bearing record for registered, configured, ready, active, paused, degraded and stopped state with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus registered-configured-ready-active-paused-degraded-and-stopped-state assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "dependencies-envelope-hazards-and-failure", "name": "Dependencies, envelope, hazards and failure", "description": "Conditions and components on which capability and safe behaviour depend.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009" ], "findings": [ { "id": "tool-model-memory-service-and-embodiment-dependencies", "name": "Tool, model, memory, service and embodiment dependencies", "description": "Pinned external component references, trust state, version, availability, data boundary and degraded-mode effect.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "questions": [ { "id": "tool-model-memory-service-and-embodiment-dependencies-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for tool, model, memory, service and embodiment dependencies?", "kind": "composition", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "tool-model-memory-service-and-embodiment-dependencies-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes tool, model, memory, service and embodiment dependencies, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "tool-model-memory-service-and-embodiment-dependencies-q03", "text": "How may tool, model, memory, service and embodiment dependencies be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "tool-model-memory-service-and-embodiment-dependencies-data", "name": "Tool, model, memory, service and embodiment dependencies data", "description": "Structured, source-qualified answer data for tool, model, memory, service and embodiment dependencies.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "tool-model-memory-service-and-embodiment-dependencies-record", "name": "Tool, model, memory, service and embodiment dependencies record", "description": "Versioned evidence-bearing record for tool, model, memory, service and embodiment dependencies with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus tool-model-memory-service-and-embodiment-dependencies assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "operating-envelope-prohibition-hazard-failure-and-recovery", "name": "Operating envelope, prohibition, hazard, failure and recovery", "description": "Resource, time, cost, environment and safety limits, forbidden actions, failure signatures, containment and recovery path.", "source_refs": [ "SRC-003", "SRC-005", "SRC-009" ], "questions": [ { "id": "operating-envelope-prohibition-hazard-failure-and-recovery-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for operating envelope, prohibition, hazard, failure and recovery?", "kind": "constraint", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "operating-envelope-prohibition-hazard-failure-and-recovery-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes operating envelope, prohibition, hazard, failure and recovery, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "operating-envelope-prohibition-hazard-failure-and-recovery-q03", "text": "How may operating envelope, prohibition, hazard, failure and recovery be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "operating-envelope-prohibition-hazard-failure-and-recovery-data", "name": "Operating envelope, prohibition, hazard, failure and recovery data", "description": "Structured, source-qualified answer data for operating envelope, prohibition, hazard, failure and recovery.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "operating-envelope-prohibition-hazard-failure-and-recovery-record", "name": "Operating envelope, prohibition, hazard, failure and recovery record", "description": "Versioned evidence-bearing record for operating envelope, prohibition, hazard, failure and recovery with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus operating-envelope-prohibition-hazard-failure-and-recovery assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "operation-attribution-and-oversight", "name": "Operation, attribution and oversight", "description": "Connects agent state and execution context to activities, outputs and intervention controls.", "rationale": "The durable actor must remain distinct from each run while activity and output provenance still resolves to the exact operational context.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-008" ], "layers": [ { "id": "activation-deployment-and-session-context", "name": "Activation, deployment and session context", "description": "Which approved configuration is active where and how executions correlate to it.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "findings": [ { "id": "deployment-configuration-release-and-activation-binding", "name": "Deployment, configuration, release and activation binding", "description": "Pinned external deployment and configuration references, approval, environment, activation authority and effective interval.", "source_refs": [ "SRC-003", "SRC-004", "SRC-008" ], "questions": [ { "id": "deployment-configuration-release-and-activation-binding-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for deployment, configuration, release and activation binding?", "kind": "composition", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "deployment-configuration-release-and-activation-binding-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes deployment, configuration, release and activation binding, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "deployment-configuration-release-and-activation-binding-q03", "text": "How may deployment, configuration, release and activation binding be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "deployment-configuration-release-and-activation-binding-data", "name": "Deployment, configuration, release and activation binding data", "description": "Structured, source-qualified answer data for deployment, configuration, release and activation binding.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-008" ] } ], "artifacts": [ { "id": "deployment-configuration-release-and-activation-binding-record", "name": "Deployment, configuration, release and activation binding record", "description": "Versioned evidence-bearing record for deployment, configuration, release and activation binding with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus deployment-configuration-release-and-activation-binding assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-004", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "session-run-correlation-and-temporal-context", "name": "Session, run, correlation and temporal context", "description": "External session and run references, correlation identifiers and distinct event, valid, observation, knowledge and ingestion times.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-010" ], "questions": [ { "id": "session-run-correlation-and-temporal-context-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for session, run, correlation and temporal context?", "kind": "temporal", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "session-run-correlation-and-temporal-context-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes session, run, correlation and temporal context, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "session-run-correlation-and-temporal-context-q03", "text": "How may session, run, correlation and temporal context be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "session-run-correlation-and-temporal-context-data", "name": "Session, run, correlation and temporal context data", "description": "Structured, source-qualified answer data for session, run, correlation and temporal context.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "session-run-correlation-and-temporal-context-record", "name": "Session, run, correlation and temporal context record", "description": "Versioned evidence-bearing record for session, run, correlation and temporal context with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus session-run-correlation-and-temporal-context assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "activity-and-output-attribution", "name": "Activity and output attribution", "description": "Traceable associations among agent, activity, principal, plan, inputs and outputs.", "source_refs": [ "SRC-001", "SRC-002" ], "findings": [ { "id": "activity-association-plan-role-and-delegation-attribution", "name": "Activity association, plan, role and delegation attribution", "description": "Which agent was associated with an activity, in which role, under which plan and on whose behalf.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "activity-association-plan-role-and-delegation-attribution-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for activity association, plan, role and delegation attribution?", "kind": "provenance", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "activity-association-plan-role-and-delegation-attribution-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes activity association, plan, role and delegation attribution, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "activity-association-plan-role-and-delegation-attribution-q03", "text": "How may activity association, plan, role and delegation attribution be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "activity-association-plan-role-and-delegation-attribution-data", "name": "Activity association, plan, role and delegation attribution data", "description": "Structured, source-qualified answer data for activity association, plan, role and delegation attribution.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "activity-association-plan-role-and-delegation-attribution-record", "name": "Activity association, plan, role and delegation attribution record", "description": "Versioned evidence-bearing record for activity association, plan, role and delegation attribution with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus activity-association-plan-role-and-delegation-attribution assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "output-entity-generation-attribution-and-derivation", "name": "Output entity generation, attribution and derivation", "description": "Generated or influenced output references, activity, sources, agent version and provenance bundle.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "output-entity-generation-attribution-and-derivation-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for output entity generation, attribution and derivation?", "kind": "provenance", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "output-entity-generation-attribution-and-derivation-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes output entity generation, attribution and derivation, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "output-entity-generation-attribution-and-derivation-q03", "text": "How may output entity generation, attribution and derivation be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "output-entity-generation-attribution-and-derivation-data", "name": "Output entity generation, attribution and derivation data", "description": "Structured, source-qualified answer data for output entity generation, attribution and derivation.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "output-entity-generation-attribution-and-derivation-record", "name": "Output entity generation, attribution and derivation record", "description": "Versioned evidence-bearing record for output entity generation, attribution and derivation with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus output-entity-generation-attribution-and-derivation assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "oversight-intervention-and-safe-state", "name": "Oversight, intervention and safe state", "description": "Approval, monitoring, interruption, handoff and containment controls.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "findings": [ { "id": "human-or-organizational-oversight-approval-and-intervention", "name": "Human or organizational oversight, approval and intervention", "description": "Oversight role, competence reference, information supplied, approval gates, intervention controls and response evidence.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "human-or-organizational-oversight-approval-and-intervention-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for human or organizational oversight, approval and intervention?", "kind": "authority", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "human-or-organizational-oversight-approval-and-intervention-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes human or organizational oversight, approval and intervention, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "human-or-organizational-oversight-approval-and-intervention-q03", "text": "How may human or organizational oversight, approval and intervention be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "human-or-organizational-oversight-approval-and-intervention-data", "name": "Human or organizational oversight, approval and intervention data", "description": "Structured, source-qualified answer data for human or organizational oversight, approval and intervention.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "human-or-organizational-oversight-approval-and-intervention-record", "name": "Human or organizational oversight, approval and intervention record", "description": "Versioned evidence-bearing record for human or organizational oversight, approval and intervention with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus human-or-organizational-oversight-approval-and-intervention assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "monitoring-alert-escalation-suspension-handoff-and-failsafe", "name": "Monitoring, alert, escalation, suspension, handoff and fail-safe", "description": "Signals, thresholds, accountable recipient, timeout, suspension authority, safe-state behavior and recovery confirmation.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "monitoring-alert-escalation-suspension-handoff-and-failsafe-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for monitoring, alert, escalation, suspension, handoff and fail-safe?", "kind": "process", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "monitoring-alert-escalation-suspension-handoff-and-failsafe-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes monitoring, alert, escalation, suspension, handoff and fail-safe, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "monitoring-alert-escalation-suspension-handoff-and-failsafe-q03", "text": "How may monitoring, alert, escalation, suspension, handoff and fail-safe be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "monitoring-alert-escalation-suspension-handoff-and-failsafe-data", "name": "Monitoring, alert, escalation, suspension, handoff and fail-safe data", "description": "Structured, source-qualified answer data for monitoring, alert, escalation, suspension, handoff and fail-safe.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "monitoring-alert-escalation-suspension-handoff-and-failsafe-record", "name": "Monitoring, alert, escalation, suspension, handoff and fail-safe record", "description": "Versioned evidence-bearing record for monitoring, alert, escalation, suspension, handoff and fail-safe with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus monitoring-alert-escalation-suspension-handoff-and-failsafe assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "assurance-evidence-privacy-and-lifecycle", "name": "Assurance, evidence, privacy and lifecycle", "description": "Records bounded assurance claims, observations, incidents and durable lifecycle governance.", "rationale": "Evaluation and credentials are evidence with scope and expiry, not proof of universal safety, authority, identity or legal compliance.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007", "SRC-008" ], "layers": [ { "id": "assurance-monitoring-and-incidents", "name": "Assurance, monitoring and incidents", "description": "Risk, evaluation, limitation, telemetry and incident references.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ], "findings": [ { "id": "risk-evaluation-assurance-limitation-and-acceptance", "name": "Risk, evaluation, assurance, limitation and acceptance", "description": "External assessment references, test context, metrics, thresholds, residual risks, approver, validity and non-claims.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "risk-evaluation-assurance-limitation-and-acceptance-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for risk, evaluation, assurance, limitation and acceptance?", "kind": "validation", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "risk-evaluation-assurance-limitation-and-acceptance-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes risk, evaluation, assurance, limitation and acceptance, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "risk-evaluation-assurance-limitation-and-acceptance-q03", "text": "How may risk, evaluation, assurance, limitation and acceptance be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "risk-evaluation-assurance-limitation-and-acceptance-data", "name": "Risk, evaluation, assurance, limitation and acceptance data", "description": "Structured, source-qualified answer data for risk, evaluation, assurance, limitation and acceptance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "risk-evaluation-assurance-limitation-and-acceptance-record", "name": "Risk, evaluation, assurance, limitation and acceptance record", "description": "Versioned evidence-bearing record for risk, evaluation, assurance, limitation and acceptance with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus risk-evaluation-assurance-limitation-and-acceptance assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "monitoring-drift-anomaly-incident-impact-and-corrective-action", "name": "Monitoring, drift, anomaly, incident, impact and corrective action", "description": "Observed signals and externally mastered incident or corrective-action references with severity, scope and status.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "monitoring-drift-anomaly-incident-impact-and-corrective-action-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for monitoring, drift, anomaly, incident, impact and corrective action?", "kind": "evidence", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "monitoring-drift-anomaly-incident-impact-and-corrective-action-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes monitoring, drift, anomaly, incident, impact and corrective action, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "monitoring-drift-anomaly-incident-impact-and-corrective-action-q03", "text": "How may monitoring, drift, anomaly, incident, impact and corrective action be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "monitoring-drift-anomaly-incident-impact-and-corrective-action-data", "name": "Monitoring, drift, anomaly, incident, impact and corrective action data", "description": "Structured, source-qualified answer data for monitoring, drift, anomaly, incident, impact and corrective action.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "monitoring-drift-anomaly-incident-impact-and-corrective-action-record", "name": "Monitoring, drift, anomaly, incident, impact and corrective action record", "description": "Versioned evidence-bearing record for monitoring, drift, anomaly, incident, impact and corrective action with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus monitoring-drift-anomaly-incident-impact-and-corrective-action assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "privacy-retention-and-agent-lifecycle", "name": "Privacy, retention and agent lifecycle", "description": "Purpose-bound disclosure and governed suspension, retirement and tombstoning.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007", "SRC-008" ], "findings": [ { "id": "data-category-purpose-access-disclosure-retention-and-deletion", "name": "Data category, purpose, access, disclosure, retention and deletion", "description": "Field and artifact sensitivity, purpose, audience, access policy, retention class, legal hold and disposition evidence.", "source_refs": [ "SRC-005", "SRC-007" ], "questions": [ { "id": "data-category-purpose-access-disclosure-retention-and-deletion-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for data category, purpose, access, disclosure, retention and deletion?", "kind": "privacy", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "data-category-purpose-access-disclosure-retention-and-deletion-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes data category, purpose, access, disclosure, retention and deletion, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "data-category-purpose-access-disclosure-retention-and-deletion-q03", "text": "How may data category, purpose, access, disclosure, retention and deletion be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "data-category-purpose-access-disclosure-retention-and-deletion-data", "name": "Data category, purpose, access, disclosure, retention and deletion data", "description": "Structured, source-qualified answer data for data category, purpose, access, disclosure, retention and deletion.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "data-category-purpose-access-disclosure-retention-and-deletion-record", "name": "Data category, purpose, access, disclosure, retention and deletion record", "description": "Versioned evidence-bearing record for data category, purpose, access, disclosure, retention and deletion with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus data-category-purpose-access-disclosure-retention-and-deletion assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "suspension-revocation-retirement-replacement-and-tombstone", "name": "Suspension, revocation, retirement, replacement and tombstone", "description": "Authorized lifecycle endings, surviving delegations and credentials, successor, endpoint withdrawal, retention and durable identity tombstone.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ], "questions": [ { "id": "suspension-revocation-retirement-replacement-and-tombstone-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for suspension, revocation, retirement, replacement and tombstone?", "kind": "lifecycle", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "suspension-revocation-retirement-replacement-and-tombstone-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes suspension, revocation, retirement, replacement and tombstone, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "suspension-revocation-retirement-replacement-and-tombstone-q03", "text": "How may suspension, revocation, retirement, replacement and tombstone be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "suspension-revocation-retirement-replacement-and-tombstone-data", "name": "Suspension, revocation, retirement, replacement and tombstone data", "description": "Structured, source-qualified answer data for suspension, revocation, retirement, replacement and tombstone.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "suspension-revocation-retirement-replacement-and-tombstone-record", "name": "Suspension, revocation, retirement, replacement and tombstone record", "description": "Versioned evidence-bearing record for suspension, revocation, retirement, replacement and tombstone with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus suspension-revocation-retirement-replacement-and-tombstone assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "interoperability-governance-and-agent-operations", "name": "Interoperability, governance and agent operations", "description": "Controls projections, mapping loss and safe automated maintenance.", "rationale": "Protocol cards and ontology projections are views of the governed actor and must never become the sole source of identity, authority or lifecycle truth.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006", "SRC-007", "SRC-009", "SRC-010" ], "layers": [ { "id": "profiles-projections-and-mapping-loss", "name": "Profiles, projections and mapping loss", "description": "Versioned external representations and explicit non-equivalence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-009" ], "findings": [ { "id": "prov-agent-softwareagent-association-and-delegation-projection", "name": "PROV Agent, SoftwareAgent, association and delegation projection", "description": "Loss-aware mapping of agent identity, activity association, attribution and acted-on-behalf-of relations.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "prov-agent-softwareagent-association-and-delegation-projection-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for prov agent, softwareagent, association and delegation projection?", "kind": "interoperability", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "prov-agent-softwareagent-association-and-delegation-projection-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes prov agent, softwareagent, association and delegation projection, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "prov-agent-softwareagent-association-and-delegation-projection-q03", "text": "How may prov agent, softwareagent, association and delegation projection be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "prov-agent-softwareagent-association-and-delegation-projection-data", "name": "PROV Agent, SoftwareAgent, association and delegation projection data", "description": "Structured, source-qualified answer data for prov agent, softwareagent, association and delegation projection.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "prov-agent-softwareagent-association-and-delegation-projection-record", "name": "PROV Agent, SoftwareAgent, association and delegation projection record", "description": "Versioned evidence-bearing record for prov agent, softwareagent, association and delegation projection with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus prov-agent-softwareagent-association-and-delegation-projection assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "a2a-agent-card-wot-description-and-credential-projection", "name": "A2A Agent Card, WoT description and credential projection", "description": "Versioned discovery, affordance and proof projections with authentication, disclosure, omission and round-trip limits.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ], "questions": [ { "id": "a2a-agent-card-wot-description-and-credential-projection-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for a2a agent card, wot description and credential projection?", "kind": "interoperability", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "a2a-agent-card-wot-description-and-credential-projection-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes a2a agent card, wot description and credential projection, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "a2a-agent-card-wot-description-and-credential-projection-q03", "text": "How may a2a agent card, wot description and credential projection be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "a2a-agent-card-wot-description-and-credential-projection-data", "name": "A2A Agent Card, WoT description and credential projection data", "description": "Structured, source-qualified answer data for a2a agent card, wot description and credential projection.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "a2a-agent-card-wot-description-and-credential-projection-record", "name": "A2A Agent Card, WoT description and credential projection record", "description": "Versioned evidence-bearing record for a2a agent card, wot description and credential projection with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus a2a-agent-card-wot-description-and-credential-projection assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "safe-agent-control-and-validation", "name": "Safe agent control and validation", "description": "Authorized operations, invariants, concurrency and recovery.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-010" ], "findings": [ { "id": "operation-authority-purpose-preconditions-idempotency-and-evidence", "name": "Operation authority, purpose, preconditions, idempotency and evidence", "description": "Classifies each read, bind, delegate, activate, suspend, attribute, disclose and retire action with proof and effect.", "source_refs": [ "SRC-003", "SRC-006" ], "questions": [ { "id": "operation-authority-purpose-preconditions-idempotency-and-evidence-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for operation authority, purpose, preconditions, idempotency and evidence?", "kind": "security", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "operation-authority-purpose-preconditions-idempotency-and-evidence-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes operation authority, purpose, preconditions, idempotency and evidence, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "operation-authority-purpose-preconditions-idempotency-and-evidence-q03", "text": "How may operation authority, purpose, preconditions, idempotency and evidence be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "operation-authority-purpose-preconditions-idempotency-and-evidence-data", "name": "Operation authority, purpose, preconditions, idempotency and evidence data", "description": "Structured, source-qualified answer data for operation authority, purpose, preconditions, idempotency and evidence.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "operation-authority-purpose-preconditions-idempotency-and-evidence-record", "name": "Operation authority, purpose, preconditions, idempotency and evidence record", "description": "Versioned evidence-bearing record for operation authority, purpose, preconditions, idempotency and evidence with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus operation-authority-purpose-preconditions-idempotency-and-evidence assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "prewrite-postwrite-validation-conflict-concurrency-and-recovery", "name": "Pre-write and post-write validation, conflict, concurrency and recovery", "description": "Identity, boundary, authority, state, time, provenance, privacy, stale-head and rollback checks with immutable audit evidence.", "source_refs": [ "SRC-002", "SRC-005", "SRC-010" ], "questions": [ { "id": "prewrite-postwrite-validation-conflict-concurrency-and-recovery-q01", "text": "What exact values, references, qualifiers and explicit unknowns must be recorded for pre-write and post-write validation, conflict, concurrency and recovery?", "kind": "validation", "answer_data": [ "value or typed reference", "profile and scope", "valid time", "explicit unknowns" ] }, { "id": "prewrite-postwrite-validation-conflict-concurrency-and-recovery-q02", "text": "Which controller, operator, principal, authority, observation and evidence establishes pre-write and post-write validation, conflict, concurrency and recovery, at what event, valid and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting actor", "authority and basis", "source and evidence", "times", "confidence" ] }, { "id": "prewrite-postwrite-validation-conflict-concurrency-and-recovery-q03", "text": "How may pre-write and post-write validation, conflict, concurrency and recovery be validated, challenged, changed, superseded, retained or disclosed without conflating capability with permission or importing a neighboring model lifecycle?", "kind": "validation", "answer_data": [ "validation rule", "challenge route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "prewrite-postwrite-validation-conflict-concurrency-and-recovery-data", "name": "Pre-write and post-write validation, conflict, concurrency and recovery data", "description": "Structured, source-qualified answer data for pre-write and post-write validation, conflict, concurrency and recovery.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005", "SRC-010" ] } ], "artifacts": [ { "id": "prewrite-postwrite-validation-conflict-concurrency-and-recovery-record", "name": "Pre-write and post-write validation, conflict, concurrency and recovery record", "description": "Versioned evidence-bearing record for pre-write and post-write validation, conflict, concurrency and recovery with authority, event, valid and knowledge time, provenance and access marking.", "media_or_form": [ "logical record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Agent identifier plus prewrite-postwrite-validation-conflict-concurrency-and-recovery assertion or event identifier; mutable names, endpoint URLs, dates, session identifiers and file hashes never identify the governed actor.", "source_refs": [ "SRC-002", "SRC-005", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-agent", "name": "Register non-human agent", "description": "Create the persistent actor identity, kind, master binding and explicit boundaries.", "inputs": [ "issuer", "agent kind", "master reference", "composition references" ], "outputs": [ "registered agent revision" ], "preconditions": [ "issuer has registration authority", "duplicate and boundary checks pass" ], "effects": [ "stable identity and provenance become resolvable" ], "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "bind-control-and-accountability", "name": "Bind control and accountability parties", "description": "Append time-qualified owner, controller, provider, deployer, operator and accountable-party bindings.", "inputs": [ "agent", "party references", "role basis", "interval" ], "outputs": [ "stakeholder binding revision" ], "preconditions": [ "parties resolve", "binding authority is recorded" ], "effects": [ "control and escalation responsibilities become explicit" ], "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "grant-delegation", "name": "Grant purpose-bound delegation", "description": "Attach an authorized mandate with principal, purpose, resources, interval, constraints and subdelegation rule.", "inputs": [ "agent", "principal", "mandate", "policy references" ], "outputs": [ "active delegation revision" ], "preconditions": [ "principal authority validates", "agent identity is active" ], "effects": [ "permitted action envelope becomes queryable" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] }, { "id": "constrain-or-revoke-delegation", "name": "Constrain, suspend or revoke delegation", "description": "Reduce or end delegated authority without erasing prior grants or activity provenance.", "inputs": [ "delegation", "authority", "reason", "effective time" ], "outputs": [ "delegation transition event" ], "preconditions": [ "actor may change delegation", "affected actions are identified" ], "effects": [ "future authorization sees the new state and history remains citable" ], "source_refs": [ "SRC-002", "SRC-006", "SRC-008" ] }, { "id": "declare-capability-and-limits", "name": "Declare capability and limits", "description": "Record declared, observed or verified ability with context, evidence, confidence and prohibitions.", "inputs": [ "agent", "capability profile", "evidence", "operating envelope" ], "outputs": [ "capability assertion" ], "preconditions": [ "source and evaluation context resolve" ], "effects": [ "ability is documented without implying permission" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] }, { "id": "bind-interface-and-dependency", "name": "Bind interface and dependency", "description": "Pin a protocol, skill, tool, model, memory, service or embodiment and state its trust and degraded-mode effect.", "inputs": [ "agent", "external component", "version", "binding profile" ], "outputs": [ "dependency binding revision" ], "preconditions": [ "component identity and version resolve", "access and data boundaries validate" ], "effects": [ "operational dependencies and failure effects become explicit" ], "source_refs": [ "SRC-004", "SRC-009" ] }, { "id": "transition-operational-state", "name": "Transition operational state", "description": "Activate, pause, degrade, suspend, stop or recover the agent under a valid transition and authority.", "inputs": [ "agent", "current head", "target state", "authority", "evidence" ], "outputs": [ "state transition event" ], "preconditions": [ "transition is allowed", "delegation and controls are current" ], "effects": [ "new state is effective without overwriting history" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-010" ] }, { "id": "attribute-activity-or-output", "name": "Attribute activity or output", "description": "Link an external activity or entity to the exact agent, role, plan, delegation, version and execution context.", "inputs": [ "agent", "activity or entity", "association or attribution evidence" ], "outputs": [ "PROV-compatible attribution revision" ], "preconditions": [ "identities and timestamps resolve", "claim authority is known" ], "effects": [ "responsibility provenance is queryable without inferring liability" ], "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "request-approval-or-escalate", "name": "Request approval or escalate", "description": "Route an action, ambiguity, threshold breach or loss-of-control condition to the accountable authority.", "inputs": [ "agent", "proposed action or signal", "policy", "deadline" ], "outputs": [ "approval request or escalation event" ], "preconditions": [ "recipient and fallback resolve" ], "effects": [ "operation waits, narrows or enters fail-safe according to policy" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] }, { "id": "attach-assurance-or-incident", "name": "Attach assurance or incident evidence", "description": "Reference an evaluation, limitation, risk acceptance, monitoring observation, incident or corrective action.", "inputs": [ "agent", "external record", "scope", "validity" ], "outputs": [ "assurance or incident binding" ], "preconditions": [ "record digest, issuer and scope validate" ], "effects": [ "bounded evidence is available without converting it to universal compliance" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-007" ] }, { "id": "project-agent-profile", "name": "Project agent profile", "description": "Produce a purpose-bound PROV, A2A, WoT or credential view with explicit omissions and mapping loss.", "inputs": [ "agent revision", "target profile", "requester and purpose" ], "outputs": [ "validated expiring projection" ], "preconditions": [ "versions, access and minimum disclosure validate" ], "effects": [ "projection is linked to source digest and cannot replace the master" ], "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-009" ] }, { "id": "retire-agent", "name": "Retire non-human agent", "description": "End authority and operation, withdraw discoverability, reconcile credentials and preserve a durable tombstone.", "inputs": [ "agent", "retirement authority", "successor", "retention decision" ], "outputs": [ "retirement event and tombstone" ], "preconditions": [ "agent is not active", "holds and dependent delegations are resolved" ], "effects": [ "new operation is blocked while prior identity and attribution remain resolvable" ], "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] } ], "composition": [ { "target": "WM-AI-002 AI Agent", "relation": "CHILD", "purpose": "Reuse the generic governed actor core while AI-specific model, memory, tool, protocol, evaluation and regulation semantics stay in the specialization.", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] }, { "target": "Person, Organization, Software, AI System, AI Model, Embodiment, Task, Activity, Output, Policy, Credential, Incident and Evidence models", "relation": "REFERENCE", "purpose": "Connect the agent to externally mastered parties, components, executions, rules and evidence without identity or lifecycle duplication.", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-009" ] }, { "target": "W3C PROV-DM and PROV-O", "relation": "ALIGN", "purpose": "Project agent, SoftwareAgent, association, attribution, delegation, specialization and revision provenance.", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "A2A Protocol Specification", "relation": "ALIGN", "purpose": "Publish an optional discovery and protocol projection through Agent Cards, skills, capabilities and interfaces.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "ODRL Information Model 2.2 and Verifiable Credentials Data Model 2.0", "relation": "ALIGN", "purpose": "Represent purpose-bound authority policy and portable evidence without importing authorization or credential lifecycles.", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] }, { "target": "Web of Things Thing Description 1.1", "relation": "ALIGN", "purpose": "Project optional properties, actions, events, forms and security metadata for networked or embodied agent interfaces.", "required": false, "source_refs": [ "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension identity, owner, agent registrar, delegation authority, oversight owner and namespace", "Person, organization, agent, software, AI system, model, embodiment, activity, policy, credential, incident and evidence registries", "Master-system mappings for agent, deployment, endpoint, session, delegation, activity, output and lifecycle-event identifiers", "Agent classification, delegation, approval, safety, privacy, retention, incident, federation and autonomous-operation policies" ], "namespace_guidance": "Mint governed agent and assertion identifiers in the adopting Dimension only when no authoritative master identifier exists; preserve parties, software, AI systems, models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence as typed external references.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local agent, delegation, capability, activation, attribution, assurance and lifecycle registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize by authoritative persistent agent identifier and issuer, never by display name, executable, model, device, endpoint, credential, session, date or content hash alone.", "Keep persistent agent, definition, deployment, endpoint, embodiment, session, task, activity and output identities and lifecycles distinct." ], "patch_rules": [ "Additive extensions declare target bundle, layer or finding, agent-kind profile, source, authority, safety, privacy and interoperability impact.", "Identity, boundary, controller, delegation, capability, state-transition or attribution semantic changes require a successor version, migration map, rollback path and continued resolution of prior records." ], "compatibility_rules": [ "Consumers may ignore unknown additive fields only when identity, kind, component boundary, control, authority, capability, state, attribution, oversight, access and lifecycle meaning remain intact.", "PROV, A2A, WoT, ODRL and credential projections pin source and target versions and disclose transformed, omitted, aggregated and non-round-trippable values." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier for the governed agent, qualified by issuer.", "Governed globally resolvable agent IRI with explicit master-system binding.", "Adopting-Dimension UUID or ULID when no authoritative external identifier exists." ], "timestamp_rule": "Record event timestamps in RFC 3339 with seconds and an explicit UTC offset or Z; keep event, decision, effective, observation, knowledge, issuance and ingestion times distinct.", "serial_naming_rule": "Name serial artifacts as {agent-id}--{artifact-kind}--{assertion-or-event-id}; never use an agent name, model name, endpoint, session, date, filename or hash alone as agent identity.", "integrity_rule": "Store digest, media type, byte length, issuer, source and profile versions, authority, valid and knowledge times, provenance, assurance, licence and access marking for every retained serial artifact." }, "policies": [ "The adopting Dimension declares who may register, classify, configure, delegate to, activate, suspend, attribute, disclose, replace and retire a non-human agent.", "Capability never implies permission, PROV responsibility never establishes liability, and technical autonomy never establishes consciousness, personhood, rights or moral agency.", "Controller, provider, deployer, operator, beneficiary and accountable party remain externally mastered, separately attributable and time-qualified.", "Software, AI system, model, embodiment, task, activity, output, credential, policy, incident and evidence lifecycles remain in their owning systems and are referenced.", "Automated agents may read, validate, index and append low-risk observations within policy; widening delegation, activation in a consequential scope, adverse suspension, public attestation and destructive disposition require accountable authority." ], "crud": { "read": [ "Resolve active Dimension, purpose, role, requested valid and knowledge time, delegation and evidence freshness; return the minimum permitted view without leaking private agent existence, capability or endpoint data." ], "create": [ "Create stable persistent identity, kind, master binding, controller and accountable-party references and explicit unknowns before capability, delegation or activation claims." ], "update": [ "Append an assertion, binding, event or successor revision with actor, authority, reason, RFC 3339 time, evidence and before-and-after validation; never overwrite a cited attribution, delegation or event." ], "delete": [ "Apply authority, incident, legal-hold, credential-status and retention policy; prefer retired state or tombstone, preserve identity and attribution history, and never cascade into referenced parties, software, models, embodiments, activities or evidence." ] }, "roles": [ { "name": "Dimension owner", "responsibilities": [ "Own namespace, mastership, delegation, access, retention and federation rules." ] }, { "name": "Agent registrar", "responsibilities": [ "Maintain persistent identity, kind, boundary, aliases and successor lineage." ] }, { "name": "Controller or provider", "responsibilities": [ "Declare the controlled agent and maintain accurate configuration, capability and limitation references." ] }, { "name": "Deployer or operator", "responsibilities": [ "Operate only within current delegation and envelope and preserve activation, oversight and incident evidence." ] }, { "name": "Delegating principal", "responsibilities": [ "Grant, constrain, suspend and revoke purpose-bound authority within its own authority." ] }, { "name": "Accountable and oversight owner", "responsibilities": [ "Review consequential action, intervene, receive escalation and accept or reject residual risk." ] }, { "name": "Safety, privacy and access steward", "responsibilities": [ "Apply minimum disclosure, monitoring, incident, retention and security controls." ] }, { "name": "Independent auditor", "responsibilities": [ "Review identity, delegation, state, attribution, controls and evidence without rewriting source records." ] } ], "access": { "default_rule": "Deny mutation and disclosure of private agent existence, endpoint, capability, delegation, state or evidence unless active Dimension, actor role, purpose and field policy grant it; expose the minimum necessary projection.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Statutory, judicial, safeguarding or emergency access must cite authority, be purpose-bound, attributable and reviewable, and must not erase original delegations, incidents, disputes or audit evidence." ], "audit_requirements": [ "Log actor, calling agent, role, purpose, agent and principal identities, action, policy, RFC 3339 timestamp with offset, requested and effective authority, affected scope, evidence and outcome." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read the nearest Dimension-owner AGENTS.md, agent mastership, delegation, oversight, safety, privacy, incident, retention and federation policies.", "Read this model AGENTS.md, pinned spec.yaml and required party, software, AI system, model, embodiment, activity, policy, credential, incident and evidence model instructions before mutation, activation or disclosure." ] } }, "coverage": { "claim": "A source-grounded reviewable draft for a persistent governed non-human actor across W3C provenance, policy, credential, time and Web of Things standards, NIST AI governance guidance, the A2A protocol, an EU AI-system profile and RFC 3339, without a claim of subjecthood, universal legal treatment, complete embodiment safety or certified crosswalk completeness.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Persistent agent identity, issuer, aliases, versions and successor lineage are explicit." }, { "dimension": "classification and definition", "status": "covered", "notes": "Software, embodied, hybrid and other profiled non-human kinds are allowed without subjecthood inference." }, { "dimension": "direct properties", "status": "covered", "notes": "Native computational, organizational and virtual properties are first-class; physical properties are delegated to an embodiment." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Identifiers, interface and behaviour signatures, methods, evidence, confidence, drift and confusing neighboring identities are covered." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Capabilities, behaviours, permissions, operations, affordances, constraints, hazards and failure modes remain distinct." }, { "dimension": "composition", "status": "covered", "notes": "Software, models, memory, tools, services and embodiment are pinned external references with separate masters." }, { "dimension": "lifecycle", "status": "covered", "notes": "Registration, configuration, activation, pause, degradation, suspension, recovery, retirement and tombstone preserve history." }, { "dimension": "relationships", "status": "covered", "notes": "Controllers, providers, deployers, operators, principals, beneficiaries, affected parties and accountable owners are time-qualified." }, { "dimension": "temporal", "status": "covered", "notes": "Event, decision, valid, observation, knowledge, issuance and ingestion times remain distinct and events use RFC 3339." }, { "dimension": "spatial", "status": "covered", "notes": "Physical, network, jurisdictional and logical operating scopes are referenced when the profile requires them." }, { "dimension": "provenance", "status": "covered", "notes": "Association, attribution, delegation, derivation, revision and conflicting assertions remain separately attributable." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Identity, control, data, components and evidence retain their owning master systems and stewards." }, { "dimension": "validation and quality", "status": "covered", "notes": "Duplicate identity, stale delegation, state transitions, dependency drift, boundary confusion and projection loss are checked." }, { "dimension": "access and privacy", "status": "covered", "notes": "Private existence, endpoint, capability, delegation, affected-party data and minimum disclosure are covered." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Per-artifact retention, legal hold, credential withdrawal, retirement and durable tombstone are explicit." }, { "dimension": "interoperability", "status": "covered", "notes": "PROV, A2A, WoT, ODRL and credential projections are versioned, purpose-bound and loss-aware." } ], "known_omissions": [ "No independent Claude or Grok result was available; this source-grounded Codex fallback requires later external review before canonical promotion.", "WM-AI-002 AI Agent, software, AI system, model, robot or embodiment, task, activity, credential, access, incident and evidence models retain their own detailed semantics.", "Animal, swarm, autonomous vehicle, industrial robot, legal electronic person and other jurisdiction or embodiment profiles require specialist review and must not be inferred from this common core.", "The frozen relation ledger contains no approved WM-PER-003 dependency rows; composition targets remain descriptive holds until registry relations are reviewed.", "Certified PROV, A2A, WoT, ODRL and credential crosswalks, conformance fixtures and round-trip tests remain future work." ], "conflicts": [ "W3C PROV uses Agent broadly for responsibility attribution, while this model narrows the subject to a persistently governed non-human actor and forbids legal or moral inferences.", "A2A Agent Cards describe discoverable protocol capabilities, while this model treats each card as a projection that may omit private controls, delegation, lifecycle and evidence.", "The generic Non-human Agent overlaps WM-AI-002 unless AI-specific model, memory, tool and regulatory semantics remain in that narrower specialization." ], "regional_assumptions": [ "The EU AI Act supplies an EU AI-system profile and does not govern every non-human agent or create universal subject status.", "PROV responsibility attribution is a provenance relation and does not decide legal accountability or liability in any jurisdiction.", "A2A, WoT, ODRL and Verifiable Credentials are optional interoperability profiles, not mandatory storage or interface formats." ], "adversarial_checks": [ "Reject any agent identifier derived only from name, executable, AI model, device, endpoint, credential, session or date.", "Reject permission inferred from capability, successful execution, credential possession or protocol advertisement alone.", "Reject consciousness, intention, personhood, rights, moral responsibility or liability inferred from autonomy or PROV classification.", "Reject activation when delegation, accountable party, required dependencies, oversight channel or safe-state behavior is absent or stale.", "Reject mutation, disclosure, subdelegation, attribution or retirement beyond actor authority, purpose, state preconditions and confirmation class." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted as a generic governed non-human actor", "rationale": "The model represents the durable actor identity and its control, delegation, capability, state, attribution, oversight and lifecycle. Human and organization identities, software, AI systems and models, embodiments, sessions, tasks, activities, outputs, credentials, policies, incidents and evidence remain distinct linked objects or records. WM-AI-002 remains the narrower AI Agent specialization." }, "decisions": [ { "concept": "Generic non-human agent boundary", "disposition": "accepted with explicit profile constraints", "rationale": "Software, embodied, hybrid and other machine-actor kinds may share persistent identity, control, delegation and attribution semantics, while kind-specific cognition, software, physical and legal details remain in child profiles." }, { "concept": "WM-AI-002 overlap", "disposition": "accepted as parent and specialization rather than duplicate", "rationale": "WM-PER-003 supplies a technology-neutral actor core; WM-AI-002 owns AI-specific model, memory, tool, protocol, evaluation and regulatory context." }, { "concept": "PROV Agent and SoftwareAgent", "disposition": "accepted as provenance projections", "rationale": "W3C PROV supports activity responsibility, association, attribution and delegation but does not establish a persistent master identity, legal personhood, intention or liability." }, { "concept": "Agent, component, deployment and session identity", "disposition": "accepted as separate identifiers and lifecycles", "rationale": "The governed actor can change software, model, embodiment, endpoint or deployment while sessions and runs remain bounded execution records referencing the durable actor." }, { "concept": "Control and accountability parties", "disposition": "accepted as time-qualified external bindings", "rationale": "Owner, controller, provider, deployer, operator, beneficiary, affected party and accountable owner may differ and must not be hidden behind the agent identity." }, { "concept": "Capability and permission", "disposition": "accepted as strictly non-equivalent", "rationale": "Declared, observed or verified technical ability never grants authority; permission requires a current purpose-bound mandate, delegation and policy decision." }, { "concept": "Delegation and credentials", "disposition": "accepted as bounded references and evidence", "rationale": "Delegation records principal, scope, purpose, interval, constraints and subdelegation, while credentials and policy engines retain independent authority and lifecycle." }, { "concept": "Behaviour, state and safety", "disposition": "accepted as observable and governed assertions", "rationale": "Operating modes, transition authority, dependencies, envelope, hazards, failure signatures, monitoring and safe-state behavior are recorded without claiming universal physical safety." }, { "concept": "Activity and output attribution", "disposition": "accepted without legal inference", "rationale": "Activities and outputs link to the exact agent, role, plan, delegation, version and execution context, while responsibility provenance remains distinct from legal or moral liability." }, { "concept": "Protocol and affordance descriptions", "disposition": "accepted as purpose-bound projections", "rationale": "A2A Agent Cards and WoT descriptions expose selected capabilities, skills, interfaces, actions, properties and events but cannot replace the governed master or prove hidden authority and controls." }, { "concept": "Subjecthood and personhood", "disposition": "explicitly rejected as an inference", "rationale": "Autonomy, learning, successful action, PROV responsibility or protocol classification do not establish consciousness, intention, moral agency, rights, duties, legal personality or liability." }, { "concept": "Approved registry composition", "disposition": "held pending relation governance", "rationale": "The approved relation ledger contains no WM-PER-003 rows, so proposed links to WM-AI-002 and party, software, model, embodiment, activity, policy, credential, incident and evidence models remain draft." } ], "publicationHolds": [ "Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.", "The generic Non-human Agent boundary and WM-AI-002 AI Agent specialization require later joint taxonomy review to prevent duplicated fields or conflicting lifecycle ownership.", "The approved relationship ledger contains no WM-PER-003 rows, so all proposed sibling and child composition remains draft.", "Animal, swarm, autonomous-vehicle, industrial-robot, legal electronic-person and other jurisdiction or embodiment profiles require specialist review and are not inferred from this core.", "Certified PROV, A2A, WoT, ODRL and Verifiable Credentials crosswalks, conformance fixtures, safety profiles and round-trip tests remain unverified.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Review the parent and child split with WM-AI-002 and approve exact field ownership, dependency direction and version compatibility.", "Approve model identifiers and relation cardinalities for persons, organizations, software, AI systems, models, embodiments, tasks, activities, outputs, policies, credentials, incidents and evidence.", "Develop specialist profiles for software services, embodied robots, autonomous vehicles, swarms, animals and any future legally recognized electronic subject.", "Create deterministic fixtures for identity replacement, controller changes, nested delegation, stale credentials, dependency loss, safe-state entry, disputed attribution and private-agent discovery.", "Validate certified provenance, discovery, affordance, policy and credential projections with explicit disclosure, loss and round-trip tests." ] }, "statistics": { "sources": 10, "bundles": 7, "layers": 16, "findings": 32, "questions": 96, "artifacts": 32, "functions": 12 } }