# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T15:22:40Z", "synthesisSha256": "529f05a220936cf7e05a451ebcfb02932fa03aa57994f1947bfce34e6e78a375", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-PER-004", "registryId": "vr.wm-per-004", "name": "Household / Family", "version": "0.3.0", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Society, people and institutions", "industry": [ "Cross-industry" ], "domain": [ "SOC.PER.HH" ], "tags": [ "household", "family", "soc.per.hh" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-per-004-household-family/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-per-004", "model": { "registry_id": "vr.wm-per-004", "model_id": "WM-PER-004", "name": "Household / Family", "entry_kind": "aggregate", "purpose": "Represent a bounded household or family context with qualified membership, relationship, residence and care assertions, without treating social, legal and statistical definitions as identical.", "scope_statement": "One governed context aggregate has an opaque context identifier and an explicit context_kind: household or family-network. Household instances bind a declared membership rule; family-network instances bind an explicit participant and relationship scope and may link multiple households. Different kinds have separate identities and are never merged by shared people or addresses. Statistical family groups are derived profile-qualified views, not universal family identities. This hierarchy and family-network envelope are authored proposals, not structures prescribed by the sources.", "in_scope": [ "Context identity and purpose, definition profiles, qualified person membership and family relationship assertions", "Residence references, shared-living observations, care and dependency context, external authority references", "Evidence, disputes, changes, restricted views, retention and qualified statistical projections" ], "out_of_scope": [ "Person identity masters, civil registration, parentage determination, marriage or adoption registration, custody and guardianship decisions", "Dwelling geometry, title and tenancy masters; tax units, benefits eligibility, bank accounts, payments and clinical care plans", "General genealogy, population enumeration systems, disclosure-control algorithms, emergency response execution and institutional operations" ], "boundary_notes": [ { "neighbor": "WM-PER-001 Person", "distinction": "Reference people using their master namespaces; a context entry cannot establish identity, legal capacity or demographic facts from co-residence.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ] }, { "neighbor": "WM-PER-005 Population Group", "distinction": "Statistical cohorts and estimates have separate definitions. An authorized context projection supplies qualified observations, not a complete population or guaranteed anonymous dataset.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "neighbor": "Dwelling and built-environment masters", "distinction": "Residence and shared-facility observations reference a dwelling or location; neither address equality nor tenancy proves common household membership. No unverified legacy U binding is treated as a runtime dependency.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Civil registrar and family-law decision records", "distinction": "Registered relations and mandates retain source authority and jurisdiction. Local statements or profile classifications cannot create or dissolve legal relationships.", "source_refs": [ "SRC-005", "SRC-007" ] }, { "neighbor": "Consumer unit, tax unit and financial records", "distinction": "A shared expense group is purpose-specific and may differ from household membership. Tax and benefit definitions and all transactions are delegated.", "source_refs": [ "SRC-002", "SRC-004" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Measuring Population and Housing: Practices of UNECE Countries in the 2020 Round of Censuses, Chapter 22", "organization": "United Nations Economic Commission for Europe", "url": "https://w3.unece.org/pub/censuspractices2020/webpage25.html", "version_or_date": "2020 round retrospective; displayed chapter accessed 2026-10-06; exact publication version pending", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:21:08Z", "relevance": "Sections 22.2-22.6: competing household concepts, family nuclei, membership and housing links. Descriptive census practice, not a universal household law." }, { "id": "SRC-002", "title": "Families and households, UK quality and methods guide", "organization": "Office for National Statistics", "url": "https://www.ons.gov.uk/peoplepopulationandcommunity/birthsdeathsandmarriages/families/methodologies/familiesandhouseholdsqmi", "version_or_date": "Last revised 2026-04-17", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:21:08Z", "relevance": "Sections 4-5 and glossary: profile-specific residence, family and household concepts, classification and statistical uncertainty. UK survey scope only." }, { "id": "SRC-003", "title": "Current Population Survey: Subject Definitions", "organization": "United States Census Bureau", "url": "https://www.census.gov/programs-surveys/cps/technical-documentation/subject-definitions.html", "version_or_date": "Living reference page accessed 2026-10-06; mixed historical definitions, release pin unresolved", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:21:08Z", "relevance": "Family, family group, family household and household entries demonstrate distinct counting units; historical details must not be assumed current." }, { "id": "SRC-004", "title": "Consumer Expenditure Surveys: Glossary", "organization": "United States Bureau of Labor Statistics", "url": "https://www.bls.gov/cex/csxgloss.htm", "version_or_date": "Living glossary accessed 2026-10-06; release pin pending", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:21:08Z", "relevance": "Consumer unit and reference person entries support separation of expense-sharing groups from household identity. No financial authority or tax entitlement follows." }, { "id": "SRC-005", "title": "Convention on the Rights of the Child text", "organization": "United Nations Children's Fund", "url": "https://www.unicef.org/child-rights-convention/convention-text", "version_or_date": "Convention adopted 1989-11-20; selected articles 3, 5, 8, 12, 16, 18 and 19", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:21:08Z", "relevance": "Child participation, family identity, privacy and care principles. Treaty applicability, reservations and domestic implementation require profile review." }, { "id": "SRC-006", "title": "Regulation (EU) 2016/679", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679", "version_or_date": "2016-04-27 original act; current consolidation unverified; indexed excerpts only", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:21:08Z", "relevance": "Selected indexed Articles 5, 17 and 25 support minimisation, qualified erasure and privacy by design. Full text retrieval returned a challenge, not verified legislation." }, { "id": "SRC-007", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:21:08Z", "relevance": "Attribution, derivation and revision vocabulary for assertions and projections; not proof of truth, kinship or authority." } ], "structure": { "bundles": [ { "id": "bundle-boundary", "name": "Context identity and definitions", "description": "Explicit scope and profile guard against conflating household and family.", "rationale": "Authored grouping of the cited concepts; the sources do not mandate this hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ], "layers": [ { "id": "layer-identity", "name": "Context identity", "description": "Identify one household or family-network context; avoid a universal family ID. A move, membership change or shared surname does not by itself merge contexts.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "findings": [ { "id": "finding-identity", "name": "Typed context and continuity", "description": "Identify one household or family-network context; avoid a universal family ID. A move, membership change or shared surname does not by itself merge contexts.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "questions": [ { "id": "q-identity-1", "text": "Which master namespace, context identifier and context kind identify this bounded unit?", "kind": "identity", "answer_data": [ "identity: namespace, context_id, context_kind, aliases, reconciliation_state", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-identity-2", "text": "Which participant boundary distinguishes this family network from its linked households or statistical family groups?", "kind": "composition", "answer_data": [ "scope: inclusion_rule, participant_refs, linked_context_refs, excluded_scope, purpose", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-identity-3", "text": "What evidence supports continuity, closure or successor links after the unit splits or combines?", "kind": "lifecycle", "answer_data": [ "continuity: predecessor_refs, successor_refs, event_basis, effective_period, assessment", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-identity-1", "name": "identity", "description": "Candidate nested field group: identity: namespace, context_id, context_kind, aliases, reconciliation_state. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "data-identity-2", "name": "scope", "description": "Candidate nested field group: scope: inclusion_rule, participant_refs, linked_context_refs, excluded_scope, purpose. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "data-identity-3", "name": "continuity", "description": "Candidate nested field group: continuity: predecessor_refs, successor_refs, event_basis, effective_period, assessment. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-identity", "name": "Context identity register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-profile", "name": "Definition profiles", "description": "Retain independent social, administrative and statistical readings, including disagreements. The cited sources demonstrate definitional variation; no source classification is universally required.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "findings": [ { "id": "finding-profile", "name": "Purpose-qualified classification", "description": "Retain independent social, administrative and statistical readings, including disagreements. The cited sources demonstrate definitional variation; no source classification is universally required.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "questions": [ { "id": "q-profile-1", "text": "Which definition, jurisdiction, release and reference date govern each household or family classification?", "kind": "classification", "answer_data": [ "profile: issuer, definition_uri, version, jurisdiction, purpose, reference_date, code", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-profile-2", "text": "How does the selected profile treat single-person units, unrelated residents and multiple family groups?", "kind": "constraint", "answer_data": [ "classification: rule_refs, included_members, group_refs, exception_codes, unknown_reason", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-profile-3", "text": "Which conflicting classifications must remain separate when a profile or destination cannot express the source meaning?", "kind": "interoperability", "answer_data": [ "mapping: source_profile, target_profile, version, loss_report, conflict_refs, refusal_reason", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-profile-1", "name": "profile", "description": "Candidate nested field group: profile: issuer, definition_uri, version, jurisdiction, purpose, reference_date, code. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "data-profile-2", "name": "classification", "description": "Candidate nested field group: classification: rule_refs, included_members, group_refs, exception_codes, unknown_reason. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "data-profile-3", "name": "mapping", "description": "Candidate nested field group: mapping: source_profile, target_profile, version, loss_report, conflict_refs, refusal_reason. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-profile", "name": "Definition profiles register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-people", "name": "Membership and relationships", "description": "People are referenced; membership and kinship remain distinct assertions.", "rationale": "Authored grouping of the cited concepts; the sources do not mandate this hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-007" ], "layers": [ { "id": "layer-membership", "name": "Membership and roles", "description": "Membership assertions are time-bounded and profile-specific. A reference person is a reporting anchor, not the owner of people or their data. Provisional and contested entries remain visible only to authorized readers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ], "findings": [ { "id": "finding-membership", "name": "Qualified inclusion and reference roles", "description": "Membership assertions are time-bounded and profile-specific. A reference person is a reporting anchor, not the owner of people or their data. Provisional and contested entries remain visible only to authorized readers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ], "questions": [ { "id": "q-membership-1", "text": "Which person reference is included under which membership basis and effective interval?", "kind": "relationship", "answer_data": [ "membership: person_ref, context_ref, basis, valid_from, valid_to, status", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-membership-2", "text": "What evidence permits a respondent or representative to supply information about each other person?", "kind": "authority", "answer_data": [ "mandate: actor_ref, subject_ref, authority_basis, allowed_fields, expiry, verification", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-membership-3", "text": "How are visitor, temporary absence, shared residence and disputed membership assertions retained without forcing a single answer?", "kind": "exception", "answer_data": [ "exception: asserted_status, profile_ref, source_ref, competing_assertions, review_state", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-membership-1", "name": "membership", "description": "Candidate nested field group: membership: person_ref, context_ref, basis, valid_from, valid_to, status. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ] }, { "id": "data-membership-2", "name": "mandate", "description": "Candidate nested field group: mandate: actor_ref, subject_ref, authority_basis, allowed_fields, expiry, verification. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ] }, { "id": "data-membership-3", "name": "exception", "description": "Candidate nested field group: exception: asserted_status, profile_ref, source_ref, competing_assertions, review_state. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-membership", "name": "Membership and roles register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-kinship", "name": "Family relationships", "description": "Separate a reported relationship, its asserted legal status and any source record. Links can cross households; a social description need not satisfy a census family definition. Do not infer kinship from names, age, address or a reference-person label.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-007" ], "findings": [ { "id": "finding-kinship", "name": "Declared and registered relationship assertions", "description": "Separate a reported relationship, its asserted legal status and any source record. Links can cross households; a social description need not satisfy a census family definition. Do not infer kinship from names, age, address or a reference-person label.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-007" ], "questions": [ { "id": "q-kinship-1", "text": "Which people are connected by the asserted relationship and what vocabulary defines its type and direction?", "kind": "relationship", "answer_data": [ "relation: subject_ref, object_ref, relation_type, vocabulary_version, scope, effective_period", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-kinship-2", "text": "Which declaration or authoritative record supports the relationship and its separate registration status?", "kind": "evidence", "answer_data": [ "support: declarant_ref, record_ref, issuer, jurisdiction, registration_status, verification_state", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-kinship-3", "text": "How are disputed, corrected, ended or confidential relationships represented without treating a local edit as a legal act?", "kind": "state", "answer_data": [ "state: assertion_status, contrary_refs, supersedes, asserted_effective_time, restriction_ref", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-kinship-1", "name": "relation", "description": "Candidate nested field group: relation: subject_ref, object_ref, relation_type, vocabulary_version, scope, effective_period. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-007" ] }, { "id": "data-kinship-2", "name": "support", "description": "Candidate nested field group: support: declarant_ref, record_ref, issuer, jurisdiction, registration_status, verification_state. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-007" ] }, { "id": "data-kinship-3", "name": "state", "description": "Candidate nested field group: state: assertion_status, contrary_refs, supersedes, asserted_effective_time, restriction_ref. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-kinship", "name": "Family relationships register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-place-time", "name": "Residence and change", "description": "Location observations and time-qualified changes do not imply legal domicile.", "rationale": "Authored grouping of the cited concepts; the sources do not mandate this hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "layers": [ { "id": "layer-residence", "name": "Residence and shared living", "description": "Keep actual, reported, registered and profile-defined usual residence distinct. Dwelling identity and legal domicile are external. Protected or unknown locations use restricted references or explicit unknowns, not fabricated addresses.", "source_refs": [ "SRC-001", "SRC-002" ], "findings": [ { "id": "finding-residence", "name": "Qualified dwelling and location links", "description": "Keep actual, reported, registered and profile-defined usual residence distinct. Dwelling identity and legal domicile are external. Protected or unknown locations use restricted references or explicit unknowns, not fabricated addresses.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "q-residence-1", "text": "Which dwelling or location references describe actual, declared and registered residence for this period?", "kind": "spatial", "answer_data": [ "location: place_ref, residence_kind, period, precision, source, restricted_reference", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-residence-2", "text": "Which observations about shared accommodation and facilities support the selected household definition?", "kind": "evidence", "answer_data": [ "living: observation_id, facility_sharing, observation_time, method, profile_rule, uncertainty", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-residence-3", "text": "How does the profile handle multiple residences, no fixed address or an institutional setting without silently assigning a private household?", "kind": "exception", "answer_data": [ "residence_exception: case_type, inclusion_rule, alternative_context_refs, unknown_reason, review", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-residence-1", "name": "location", "description": "Candidate nested field group: location: place_ref, residence_kind, period, precision, source, restricted_reference. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "data-residence-2", "name": "living", "description": "Candidate nested field group: living: observation_id, facility_sharing, observation_time, method, profile_rule, uncertainty. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "data-residence-3", "name": "residence_exception", "description": "Candidate nested field group: residence_exception: case_type, inclusion_rule, alternative_context_refs, unknown_reason, review. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "artifact-residence", "name": "Residence and shared living register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-change", "name": "Changes and observation time", "description": "Record observed transitions separately from administrative recording. A corrected historical roster is a new assertion revision; absence of a person in one snapshot is not proof of departure or death.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "findings": [ { "id": "finding-change", "name": "Membership and residence event assertions", "description": "Record observed transitions separately from administrative recording. A corrected historical roster is a new assertion revision; absence of a person in one snapshot is not proof of departure or death.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "questions": [ { "id": "q-change-1", "text": "What observed join, departure, move, formation or closure event supports a proposed context revision?", "kind": "event", "answer_data": [ "event: type, affected_refs, evidence_ref, actor_ref, change_reason", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-change-2", "text": "What are the distinct effective, observed and recorded times and their precision or uncertainty?", "kind": "temporal", "answer_data": [ "times: effective_period, observed_at, recorded_at, timezone, precision, uncertainty", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-change-3", "text": "Which stale, overlapping or contradictory intervals need review before a roster can be used for a specified date?", "kind": "quality", "answer_data": [ "temporal_quality: conflict_refs, stale_after_rule, as_of, unresolved_intervals, reviewer", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-change-1", "name": "event", "description": "Candidate nested field group: event: type, affected_refs, evidence_ref, actor_ref, change_reason. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "data-change-2", "name": "times", "description": "Candidate nested field group: times: effective_period, observed_at, recorded_at, timezone, precision, uncertainty. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "data-change-3", "name": "temporal_quality", "description": "Candidate nested field group: temporal_quality: conflict_refs, stale_after_rule, as_of, unresolved_intervals, reviewer. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-change", "name": "Changes and observation time register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-support", "name": "Care and shared resources", "description": "Separate support, responsibility and economic sharing without deciding legal rights.", "rationale": "Authored grouping of the cited concepts; the sources do not mandate this hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-007" ], "layers": [ { "id": "layer-care", "name": "Care and dependency", "description": "Distinguish a statistical dependant, practical support recipient and legal responsibility. Care context records limited purpose and participants; clinical detail and custody or guardianship decisions remain external.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ], "findings": [ { "id": "finding-care", "name": "Care context and external mandates", "description": "Distinguish a statistical dependant, practical support recipient and legal responsibility. Care context records limited purpose and participants; clinical detail and custody or guardianship decisions remain external.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ], "questions": [ { "id": "q-care-1", "text": "What kind of dependency is asserted and which purpose-specific rule supports it?", "kind": "classification", "answer_data": [ "dependency: person_ref, dependency_kind, profile_ref, period, evidence, unknown_reason", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-care-2", "text": "Which caregiver or representative has which verified scope of responsibility and external mandate?", "kind": "authority", "answer_data": [ "care: caregiver_ref, recipient_ref, scope, informal_or_formal, mandate_ref, validity, disputed_status", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-care-3", "text": "How are the affected child's views, evolving capacity and protection needs considered by the responsible reviewer?", "kind": "requirement", "answer_data": [ "participation: review_ref, appropriate_view_record_ref, capacity_basis, restrictions, escalation_role", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-care-1", "name": "dependency", "description": "Candidate nested field group: dependency: person_ref, dependency_kind, profile_ref, period, evidence, unknown_reason. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] }, { "id": "data-care-2", "name": "care", "description": "Candidate nested field group: care: caregiver_ref, recipient_ref, scope, informal_or_formal, mandate_ref, validity, disputed_status. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] }, { "id": "data-care-3", "name": "participation", "description": "Candidate nested field group: participation: review_ref, appropriate_view_record_ref, capacity_basis, restrictions, escalation_role. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-care", "name": "Care and dependency register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-resources", "name": "Shared resources", "description": "Describe whether a purpose-specific group shares resources and obligations without assuming common income, equal access or joint liability. A consumer unit is not automatically the household. Financial ledgers and entitlement calculations are external.", "source_refs": [ "SRC-001", "SRC-004" ], "findings": [ { "id": "finding-resources", "name": "Expense-sharing context without financial ownership", "description": "Describe whether a purpose-specific group shares resources and obligations without assuming common income, equal access or joint liability. A consumer unit is not automatically the household. Financial ledgers and entitlement calculations are external.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "q-resources-1", "text": "Which people participate in the stated expense-sharing arrangement and how does that set differ from the household roster?", "kind": "composition", "answer_data": [ "resource_group: participant_refs, purpose, definition_ref, excluded_members, period", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-resources-2", "text": "Which external agreement supports the stated responsibility without inferring asset ownership or authority to spend?", "kind": "ownership", "answer_data": [ "responsibility: actor_refs, agreement_ref, responsibility_type, limits, verification_state", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-resources-3", "text": "If an aggregate resource measure is needed, what period, currency or unit, coverage and uncertainty qualify it?", "kind": "measurement", "answer_data": [ "measure: external_measure_ref, unit, currency, period, included_population, method, uncertainty", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-resources-1", "name": "resource_group", "description": "Candidate nested field group: resource_group: participant_refs, purpose, definition_ref, excluded_members, period. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "data-resources-2", "name": "responsibility", "description": "Candidate nested field group: responsibility: actor_refs, agreement_ref, responsibility_type, limits, verification_state. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "data-resources-3", "name": "measure", "description": "Candidate nested field group: measure: external_measure_ref, unit, currency, period, included_population, method, uncertainty. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-resources", "name": "Shared resources register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance", "name": "Evidence and restricted views", "description": "Trace claims and enforce purpose-specific access.", "rationale": "Authored grouping of the cited concepts; the sources do not mandate this hierarchy.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-evidence", "name": "Evidence and disputes", "description": "Retain provenance and review state for each permitted assertion. Reported, inferred, verified and disputed are different states. Model operations cannot determine parentage, truth or legal admissibility.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ], "findings": [ { "id": "finding-evidence", "name": "Attribution and conflicting assertions", "description": "Retain provenance and review state for each permitted assertion. Reported, inferred, verified and disputed are different states. Model operations cannot determine parentage, truth or legal admissibility.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ], "questions": [ { "id": "q-evidence-1", "text": "Who asserted or derived this observation from which record and transformation?", "kind": "provenance", "answer_data": [ "provenance: assertion_id, source_ref, actor_ref, method, derived_from, recorded_at", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-evidence-2", "text": "What authorized evidence check was performed and what exactly remains unverified?", "kind": "validation", "answer_data": [ "assessment: reviewer_ref, procedure_ref, checked_fields, result, limits, review_date", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-evidence-3", "text": "How can an affected person contest an assertion and obtain a restricted correction trail without exposing another person's protected data?", "kind": "process", "answer_data": [ "dispute: request_ref, contested_assertion, permitted_view, decision_ref, supersession, review_status", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-evidence-1", "name": "provenance", "description": "Candidate nested field group: provenance: assertion_id, source_ref, actor_ref, method, derived_from, recorded_at. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "data-evidence-2", "name": "assessment", "description": "Candidate nested field group: assessment: reviewer_ref, procedure_ref, checked_fields, result, limits, review_date. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "data-evidence-3", "name": "dispute", "description": "Candidate nested field group: dispute: request_ref, contested_assertion, permitted_view, decision_ref, supersession, review_status. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-evidence", "name": "Evidence and disputes register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-privacy", "name": "Restricted views and stewardship", "description": "Govern each subject and field separately. Household membership, kinship, majority vote and infrastructure control grant no blanket access. Exact protected locations and relationship details require a narrowly authorized view.", "source_refs": [ "SRC-005", "SRC-006" ], "findings": [ { "id": "finding-privacy", "name": "Purpose and recipient-specific permissions", "description": "Govern each subject and field separately. Household membership, kinship, majority vote and infrastructure control grant no blanket access. Exact protected locations and relationship details require a narrowly authorized view.", "source_refs": [ "SRC-005", "SRC-006" ], "questions": [ { "id": "q-privacy-1", "text": "Which recipient, purpose and lawful basis authorize this exact view of membership, relations and location?", "kind": "access", "answer_data": [ "access: recipient_ref, purpose, basis_ref, field_scope, subject_scope, expiry, decision_ref", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-privacy-2", "text": "Which fields and indirect clues must be withheld to avoid revealing a protected residence or sensitive relationship?", "kind": "privacy", "answer_data": [ "protection: restricted_fields, derived_disclosure_risks, safe_contact_ref, reviewer, approved_view", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-privacy-3", "text": "What policy and accountable reviewer govern an exceptional disclosure or conflicting representation claim?", "kind": "security", "answer_data": [ "exception_access: policy_ref, authority_evidence, minimum_scope, review_ref, audit_ref, refusal_reason", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-privacy-1", "name": "access", "description": "Candidate nested field group: access: recipient_ref, purpose, basis_ref, field_scope, subject_scope, expiry, decision_ref. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "data-privacy-2", "name": "protection", "description": "Candidate nested field group: protection: restricted_fields, derived_disclosure_risks, safe_contact_ref, reviewer, approved_view. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "data-privacy-3", "name": "exception_access", "description": "Candidate nested field group: exception_access: policy_ref, authority_evidence, minimum_scope, review_ref, audit_ref, refusal_reason. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-privacy", "name": "Restricted views and stewardship register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-continuity", "name": "Continuity and interchange", "description": "Preserve qualified history and export only defensible projections.", "rationale": "Authored grouping of the cited concepts; the sources do not mandate this hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-retention", "name": "Retention and record continuity", "description": "Keep useful revision links without requiring indefinite personal data retention. Custodian policy controls erasure, lawful preservation and external-master coordination. Closing a context neither deletes people nor dissolves a legal relationship.", "source_refs": [ "SRC-006", "SRC-007" ], "findings": [ { "id": "finding-retention", "name": "Purpose-bound preservation and disposition", "description": "Keep useful revision links without requiring indefinite personal data retention. Custodian policy controls erasure, lawful preservation and external-master coordination. Closing a context neither deletes people nor dissolves a legal relationship.", "source_refs": [ "SRC-006", "SRC-007" ], "questions": [ { "id": "q-retention-1", "text": "Which retention purpose, trigger, schedule and preservation hold apply to each local payload and copy?", "kind": "retention", "answer_data": [ "retention: payload_ref, purpose, schedule_ref, trigger, hold_ref, review_due", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-retention-2", "text": "What approved disposition can erase or restrict personal payload while retaining only a lawful minimal continuity marker?", "kind": "lifecycle", "answer_data": [ "disposition: authorization_ref, action, affected_copies, completion_evidence, minimal_tombstone", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-retention-3", "text": "Which custodian controls this context revision and which independent authority controls each referenced master record?", "kind": "ownership", "answer_data": [ "custody: local_custodian, authority_basis, master_owner_role, coordination_ref, limits", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-retention-1", "name": "retention", "description": "Candidate nested field group: retention: payload_ref, purpose, schedule_ref, trigger, hold_ref, review_due. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] }, { "id": "data-retention-2", "name": "disposition", "description": "Candidate nested field group: disposition: authorization_ref, action, affected_copies, completion_evidence, minimal_tombstone. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] }, { "id": "data-retention-3", "name": "custody", "description": "Candidate nested field group: custody: local_custodian, authority_basis, master_owner_role, coordination_ref, limits. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-retention", "name": "Retention and record continuity register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-projection", "name": "Interchange and acceptance", "description": "Map observations to a named destination with reference date, rule and loss report. Pseudonyms and removing names do not establish anonymity. Population estimation, disclosure-control execution and production conformance remain delegated and unimplemented.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ], "findings": [ { "id": "finding-projection", "name": "Qualified projections and failure cases", "description": "Map observations to a named destination with reference date, rule and loss report. Pseudonyms and removing names do not establish anonymity. Population estimation, disclosure-control execution and production conformance remain delegated and unimplemented.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ], "questions": [ { "id": "q-projection-1", "text": "Which pinned mapping preserves context kind, person references, profile and uncertainty in the destination?", "kind": "interoperability", "answer_data": [ "projection: target_schema, mapping_version, context_revision, preserved_fields, loss_report", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-projection-2", "text": "What counting unit and as-of roster support a household-size or family-group projection without double counting overlapping views?", "kind": "measurement", "answer_data": [ "count: unit_type, profile_ref, as_of, selected_members, deduplication_rule, uncertainty, derivation_ref", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] }, { "id": "q-projection-3", "text": "Which acceptance examples demonstrate refusal for lost authority qualifiers, unsafe disclosure and unresolved membership?", "kind": "validation", "answer_data": [ "acceptance: fixture_refs, expected_outcomes, observed_results, unresolved_gaps, reviewer", "Explicit unknown, not-applicable or disputed state with supporting assertion reference" ] } ], "data_elements": [ { "id": "data-projection-1", "name": "projection", "description": "Candidate nested field group: projection: target_schema, mapping_version, context_revision, preserved_fields, loss_report. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "data-projection-2", "name": "count", "description": "Candidate nested field group: count: unit_type, profile_ref, as_of, selected_members, deduplication_rule, uncertainty, derivation_ref. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "data-projection-3", "name": "acceptance", "description": "Candidate nested field group: acceptance: fixture_refs, expected_outcomes, observed_results, unresolved_gaps, reviewer. A profile-specific instance schema is still required.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-projection", "name": "Interchange and acceptance register", "description": "Context-local versioned assertion register or reference index; retain only authorized content and do not replace external masters.", "media_or_form": [ "structured assertion register", "restricted document projection" ], "serial": true, "identity_strategy": "Authoritative master-system namespace and record identifier plus revision first; otherwise governed IRI or locally assigned opaque UUID. Stable context reference and entry sequence; dates and names are not identifiers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "resolve-context", "name": "Resolve a typed context reference", "description": "Proposed local operation, not implemented. Resolve exact namespace and kind without merging by address, surname or overlapping participants.", "inputs": [ "namespace", "context ID", "context kind" ], "outputs": [ "qualified context reference or ambiguity report" ], "preconditions": [ "Verified actor, purpose and per-person field access; kinship and reference-person status are insufficient", "Applicable definition and source evidence supplied; unknown authority or unsafe disclosure requires refusal", "For any mutation, expected revision and idempotency key must match" ], "effects": [ "Read-only resolution; no identity merge" ], "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "record-membership", "name": "Record a qualified membership assertion", "description": "Proposed local operation, not implemented. Append reported inclusion or departure evidence under a named definition; do not decide residence rights.", "inputs": [ "context revision", "person reference", "membership evidence", "profile and effective interval" ], "outputs": [ "membership revision or refusal report" ], "preconditions": [ "Verified actor, purpose and per-person field access; kinship and reference-person status are insufficient", "Applicable definition and source evidence supplied; unknown authority or unsafe disclosure requires refusal", "For any mutation, expected revision and idempotency key must match" ], "effects": [ "Append local assertion and provenance only" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "link-relation", "name": "Link relationship evidence", "description": "Proposed local operation, not implemented. Record a declaration or an existing authoritative relation reference with its status; do not register or dissolve relationships.", "inputs": [ "context revision", "person pair", "relationship vocabulary", "source evidence and restrictions" ], "outputs": [ "relationship assertion or refusal report" ], "preconditions": [ "Verified actor, purpose and per-person field access; kinship and reference-person status are insufficient", "Applicable definition and source evidence supplied; unknown authority or unsafe disclosure requires refusal", "For any mutation, expected revision and idempotency key must match" ], "effects": [ "Append a qualified link; external legal status unchanged" ], "source_refs": [ "SRC-005", "SRC-007" ] }, { "id": "record-change", "name": "Record an observed context change", "description": "Proposed local operation, not implemented. Append observed residence or roster changes with time precision and conflicting evidence.", "inputs": [ "context revision", "event evidence", "effective and observation times" ], "outputs": [ "change revision or unresolved review report" ], "preconditions": [ "Verified actor, purpose and per-person field access; kinship and reference-person status are insufficient", "Applicable definition and source evidence supplied; unknown authority or unsafe disclosure requires refusal", "For any mutation, expected revision and idempotency key must match" ], "effects": [ "Append local observation; do not infer death, abandonment, custody or automatic closure" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "prepare-view", "name": "Prepare a recipient-scoped view", "description": "Proposed local operation, not implemented. Prepare a local projection after field and inference-risk review; refuse unsupported anonymisation claims and unsafe location exposure.", "inputs": [ "context revision", "recipient and purpose", "authorization", "pinned mapping" ], "outputs": [ "restricted local artifact and loss report or refusal" ], "preconditions": [ "Verified actor, purpose and per-person field access; kinship and reference-person status are insufficient", "Applicable definition and source evidence supplied; unknown authority or unsafe disclosure requires refusal", "For any mutation, expected revision and idempotency key must match" ], "effects": [ "Create local view and access record; no transmission" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "assess-profile-fit", "name": "Assess proposed profile fit", "description": "Proposed local operation, not implemented. Compare a recorded roster with an explicitly supplied definition and report ambiguity; no tax, benefit or legal eligibility determination.", "inputs": [ "profile version", "as-of roster", "classification rule", "source assertions" ], "outputs": [ "proposed classification with evidence and unresolved cases" ], "preconditions": [ "Verified actor, purpose and per-person field access; kinship and reference-person status are insufficient", "Applicable definition and source evidence supplied; unknown authority or unsafe disclosure requires refusal", "For any mutation, expected revision and idempotency key must match" ], "effects": [ "Read-only assessment; no civil record or entitlement change" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "composition": [ { "target": "WM-PER-001", "relation": "REFERENCE", "purpose": "Candidate person master binding; pin before operational use. No local person master or legal-capacity authority.", "required": false, "source_refs": [ "SRC-005", "SRC-007" ] }, { "target": "WM-PER-005", "relation": "REFERENCE", "purpose": "Candidate population-group binding for definitions and qualified observations; no cohort master or estimation engine here.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Dwelling master (binding unresolved)", "relation": "REFERENCE", "purpose": "Residence target retains separate identity. Legacy U is not an exact current dwelling binding; verify before integration.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Civil registration and authority records (jurisdiction binding unresolved)", "relation": "REFERENCE", "purpose": "Reference existing legal relationship and mandate evidence; all effective registration and adjudication stay external.", "required": false, "source_refs": [ "SRC-005", "SRC-007" ] }, { "target": "Consumer Expenditure consumer-unit definition", "relation": "ALIGN", "purpose": "Example of economic grouping that may differ from the household; no automatic membership or financial mapping.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "UNECE, ONS and CPS household/family definitions", "relation": "ALIGN", "purpose": "Separate optional, versioned statistical profiles; not interchangeable vocabularies or a universal legal rule.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "target": "PROV-O 2013-04-30", "relation": "ALIGN", "purpose": "Conceptual assertion attribution and derivation only; executable mapping and conformance are deferred.", "required": false, "source_refs": [ "SRC-007" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Named accountable context custodian and evidenced mandate, distinct from member and registrar roles", "Declared context kind, membership or network scope, applicable purpose and jurisdiction profile", "Master namespaces, field access policy, retention schedule and escalation contacts" ], "namespace_guidance": "Use opaque context IDs qualified by custodian namespace and kind. Do not use names, addresses or dates as identity; keep family and household IDs separate.", "registry_links": [ "vr.wm-per-004", "Candidate person and population bindings require pinned reviewed specifications" ] }, "canon_and_patch": { "canonicalization_rules": [ "Normalize exact references within verified namespaces; do not infer kinship, merge households or force profiles into agreement.", "Keep legal, reported, observed and statistical status separate; preserve unknown and contested assertions." ], "patch_rules": [ "Require expected revision, actor, purpose, supporting evidence and idempotency key for changes.", "Corrections supersede assertions; authorized payload erasure can remove personal content without inventing history." ], "compatibility_rules": [ "Version context-kind rules and profile mappings. Refuse migration that loses authority, uncertainty, protected-location restrictions or provenance." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with namespace and revision", "Governed global identifier or IRI with version", "Opaque local UUID with reconciliation state" ], "timestamp_rule": "Use RFC 3339 with seconds and explicit offset or Z for recording instants. Keep effective time, observation time and ingestion time separate. Preserve date-only values, partial intervals, timezone and uncertainty; do not manufacture midnight precision.", "serial_naming_rule": "Use opaque context key, artifact type and immutable sequence or revision. Personal names and addresses must not appear in filenames.", "integrity_rule": "Record permitted source digest and transformation provenance. A digest proves byte continuity only, not kinship, truth, registration or authority." }, "policies": [ "This Codex-only result is a reviewable draft; independent external review, source/version checks, local legal profiles and executable conformance remain holds.", "Apply minimisation, purpose limitation and per-person restrictions. Neither household membership nor a reference-person role grants blanket access or consent authority.", "Protect location and family relationship information, including derived clues; require child-appropriate participation and a qualified human review of contested mandates.", "No proposed operation registers relationships, decides parentage, custody or benefits, makes payments, discloses externally or certifies an extract." ], "crud": { "read": [ "Authorize recipient, purpose, subject and field scope; return a restricted view with uncertainty and source qualifiers." ], "create": [ "Require context kind, identifier, scope, custodian mandate and definition reference; draft unknown facts explicitly." ], "update": [ "Append evidenced assertions with revision checks; route disputes and authority conflicts to qualified review." ], "delete": [ "Apply payload-specific retention, erasure and legal-hold policy. Approved custodians execute local disposition and coordinate independent external-master owners; no operation deletes people or dissolves legal relations.", "Retain only a lawful minimal tombstone and necessary provenance; no perpetual personal-data audit log requirement. Review copies and derived projections." ] }, "roles": [ { "name": "Context custodian", "responsibilities": [ "Maintain scoped record integrity under a verified mandate, not ownership of members" ] }, { "name": "Member or authorized respondent", "responsibilities": [ "Supply permitted assertions and seek correction without gaining blanket access" ] }, { "name": "Registrar or mandate verifier", "responsibilities": [ "Verify external authority references within jurisdiction; retain external master responsibility" ] }, { "name": "Privacy and safeguarding reviewer", "responsibilities": [ "Approve recipient scope, protected location treatment and contested representation handling" ] }, { "name": "Records steward", "responsibilities": [ "Apply retention, holds, disposal and projection continuity" ] } ], "access": { "default_rule": "Deny by default at subject and field level; grant only evidenced purpose-specific views. A family relationship or shared address is not authorization.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency or statutory requests need a documented basis, minimum scope and accountable review; no blanket override.", "A member view can require third-party redactions and protected-address suppression even where the record concerns that member." ], "audit_requirements": [ "Record access, corrections, exports and disposition with actor, purpose, scope, revision and outcome under a minimal-data retention policy. Do not leak protected values into audit metadata." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read AGENTS.md and applicable custodian Dimension policy", "Read spec.yaml and all review holds", "Resolve context kind, profile, permissions and source evidence before any operation" ] } }, "coverage": { "claim": "Source-grounded proposed household and bounded family-network context structure, reviewed in a separate frozen local Codex no-tools self-audit. Selected statistical definitions and child/privacy principles inform the design without prescribing this hierarchy. Independent review, current source versions, local legal profiles and executable conformance remain holds. This is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Typed context scope and master-qualified references; no universal family identifier" }, { "dimension": "lifecycle", "status": "covered", "notes": "Formation, revisions, closure, split and successor assertions" }, { "dimension": "relationships", "status": "covered", "notes": "Membership, kinship, care and resource-group links remain distinct" }, { "dimension": "temporal", "status": "covered", "notes": "Effective, observed and recorded times plus uncertain intervals" }, { "dimension": "provenance", "status": "covered", "notes": "Source attribution, derivation, contrary evidence and assessment state" }, { "dimension": "ownership", "status": "covered", "notes": "Mandated custodian and independent master authorities, no ownership of people" }, { "dimension": "validation", "status": "gap", "notes": "Repository research validation is available; nested instance schemas and executable acceptance cases are not" }, { "dimension": "access", "status": "covered", "notes": "Per-person and field views, child privacy and protected-location review" }, { "dimension": "retention and deletion", "status": "covered", "notes": "Purpose-specific holds, erasure and minimal lawful tombstones" }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual alignments only; current neighbor pins and executable mappings unresolved" }, { "dimension": "direct properties", "status": "covered", "notes": "Context kind, scope, profile, size observations and status; physical dimensions delegated to dwelling" }, { "dimension": "recognition and observation", "status": "covered", "notes": "Source-qualified membership and residence observations, no inference from surname" }, { "dimension": "capabilities and behaviour", "status": "covered", "notes": "Six proposed local operations with authority, revision and refusal preconditions" }, { "dimension": "regional coverage", "status": "gap", "notes": "Selected UNECE, UK, US and treaty/EU examples; local legal implementation and diverse social definitions require review" } ], "known_omissions": [ "Independent external provider review is absent.", "Direct HTTP requests were not attempted because the owner reports sandbox blocking; all source HTTP statuses remain unmeasured pending coordinator execution of check_sources.py.", "Current consolidated GDPR, source release pins, treaty applicability and domestic family/privacy rules need verification.", "Family-network scope is a proposed representation; no universal kinship ontology or complete cultural taxonomy is provided.", "Institutional households and no-fixed-address cases are classified or referred by profile; institutional operations and full enumeration coverage are not modelled.", "Nested instance schemas, executable disclosure control, adult-care law, financial calculations and end-to-end fixtures remain outside this research draft." ], "conflicts": [], "regional_assumptions": [ "Statistical family and household definitions differ by programme and date; do not apply a UK LFS rule to a US CPS or local administrative record.", "Treaty principles and EU privacy examples do not establish applicability or a lawful processing basis for a specific instance.", "A family-network can link several households; a source-defined statistical family may require co-residence and is only a projection." ], "adversarial_checks": [ "One person can form a household without a family group; unrelated residents are not inferred relatives.", "Two households at one address or several family groups in one household must not be merged automatically.", "Shared parenting, temporary absence and cross-household kinship keep profile-specific inclusion and independent relation assertions.", "An estranged relative or reference person cannot reveal a protected address through a member view, count or audit log.", "A corrected declaration cannot create parentage, dissolve a marriage or change custody.", "A closed empty historical context is not counted as an active household; incomplete draft membership remains unknown.", "Dropping names or replacing IDs does not certify statistical anonymity." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The subject is a bounded context aggregate of qualified membership, relationship, residence and care assertions. Explicit household versus family-network kinds have separate identities; statistical family groups are profile-qualified views. This is an authored design, not a universal family identity. The registry standalone-mm value describes the record plane, not the subject-kind enum." }, "decisions": [ { "concept": "Typed context root", "disposition": "accepted with qualification", "rationale": "The kind discriminator and scope question prevent a household, family network and statistical family from silently sharing identity. A cross-household family network is explicitly proposed, not attributed to a census standard." }, { "concept": "Legacy definition coherence", "disposition": "rejected", "rationale": "The legacy expectation that social, administrative and statistical readings agree is replaced by independent purpose, version and date qualifiers. Conflicting profile classifications remain representable." }, { "concept": "Composition ownership", "disposition": "accepted as candidate references", "rationale": "There are no frozen current relation-ledger rows. Person and population bindings reconcile legacy H1 and H3 without claiming conformance. The unresolved dwelling binding does not silently inherit legacy U or take over built-environment identity." }, { "concept": "Householder authority", "disposition": "rejected", "rationale": "Membership and reference-person roles do not authorize another person's data access, declarations or consent. The mandate question and per-person access policy correctly separate reporting roles from authority." }, { "concept": "Kinship and legal effect", "disposition": "separated", "rationale": "The relation finding and link operation retain declarations, registered evidence and status independently. No operation infers kinship from names or address or creates, corrects or dissolves a civil master by local editing." }, { "concept": "Residence and continuity", "disposition": "accepted", "rationale": "Actual, registered and profile-defined residence remain distinct. Unknown locations, shared residence, temporary absence and institutional classification do not force a private household or an automatic identity merge." }, { "concept": "Time and state", "disposition": "accepted", "rationale": "Effective, observed and recorded times are separate, and event evidence is required. An absent snapshot member is not declared dead or departed. Closed historical contexts are excluded from active counting in the adversarial checks." }, { "concept": "Care and dependency", "disposition": "accepted with profile hold", "rationale": "Statistical dependency, practical care and legal responsibility are distinguished, with external mandates and child participation. Adult-care law and domestic authority rules remain explicit gaps rather than invented legal criteria." }, { "concept": "Resource sharing", "disposition": "accepted with delegation", "rationale": "The consumer-unit example motivates a separate participant set. Questions reference agreements and externally qualified measures; they neither imply joint ownership nor introduce financial ledgers, payment or eligibility operations." }, { "concept": "Member self-view and statistical release", "disposition": "legacy privileges rejected", "rationale": "A member view may need third-party redaction and location protection. Local view preparation is not certified extract issuance or transmission. Pseudonymisation and counts do not establish anonymity, and disclosure-control execution stays external." }, { "concept": "Provenance and correction", "disposition": "accepted", "rationale": "Evidence attribution and revision links support review but do not certify truth or authority. Correction requests are scoped, and retained history is reconciled with lawful erasure rather than indefinite personal payload retention." }, { "concept": "Source verification", "disposition": "limited and held", "rationale": "Six sources were readable through the web tool; GDPR support was official indexed excerpts only. All direct HTTP statuses are unmeasured because no local requests were attempted under the owner-reported block. Neither source currency nor legal applicability is proven." }, { "concept": "Runtime conformance", "disposition": "deferred", "rationale": "Candidate object groups and six proposed functions provide a research surface but no nested instance validator, executable mapping, access engine or tested acceptance fixtures. Those omissions do not contradict publication as a reviewable research draft." }, { "concept": "Provider independence", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the owner instruction. This separate Codex no-tools assessment is a self-audit, not independent second-provider agreement, and cannot close the external-review hold." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped; the separate local Codex no-tools self-audit is not an independent provider review.", "Live source and version verification remains incomplete. All seven direct HTTP statuses are unmeasured, with zero requests attempted under the owner-reported sandbox block. Six documents were readable through the web tool; GDPR was limited to official indexed excerpts. The coordinator must run check_sources.py and review content, versions and applicability separately.", "Local household definitions, family-network scope, treaty applicability, privacy basis, protected-location handling, child and adult representation, civil registration, care and retention rules require qualified jurisdiction and safeguarding review before operational use.", "Nested instance schemas, exact neighbor bindings, executable mappings, disclosure controls and adversarial acceptance fixtures remain incomplete. No implementation, anonymity guarantee or conformance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Verify source bodies, exact editions, current legal consolidations, applicability and licensing; retain the distinction between HTTP transport checks and substantive evidence review.", "Validate culturally and jurisdictionally appropriate family-network boundaries, adult-care authority and child-protective access with qualified reviewers.", "Develop nested schemas and fixtures for one-person households, unrelated residents, multiple family groups, shared parenting, protected addresses, disputes, split/merge continuity and lawful erasure.", "Restore independent provider review before canonical or publishable-draft promotion." ] }, "statistics": { "sources": 7, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }