# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T15:27:31Z", "synthesisSha256": "2b8ec80a28db6679883f2ac1a4b6826378907b5c2dc913b4fbd776743c54f6e5", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-PER-005", "registryId": "vr.wm-per-005", "name": "Population Group", "version": "1.0.0", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Society, people and institutions", "industry": [ "Cross-industry" ], "domain": [ "SOC.PER.GRP" ], "tags": [ "population", "group", "soc.per.grp" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-per-005-population-group/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-per-005", "model": { "registry_id": "vr.wm-per-005", "model_id": "WM-PER-005", "name": "Population Group", "entry_kind": "entity", "purpose": "Describe an addressable human collective or defined human population with qualified membership, cohort evidence and optional representation.", "scope_statement": "One persistent population-group description with an explicit community, membership-group or statistical-cohort profile. Its identifier remains distinct from a classification concept, definition revision, person roster and statistical snapshot. A cohort can have no spokesperson, channel or enumerated member list. Statistical inclusion is not voluntary affiliation, consent or collective agency.", "in_scope": [ "Qualified collective identity, descriptions, classifications, temporal and geographic population boundaries", "Membership assertions or cohort criteria and independently identified snapshot references with counts and quality metadata", "Optional representation and channel references, stewardship, release assessment and local record continuity" ], "out_of_scope": [ "Person, household, organization, contact-point and social-norm master records and their lifecycles", "Biological species populations, arbitrary object populations, general statistical production pipelines and individual health or identity profiling", "Executing queries over personal data, inferring sensitive traits, appointing representatives, contacting groups or publishing member lists", "Determining legal personality, universal consent rules, an implemented disclosure-control algorithm or formal standards conformance" ], "boundary_notes": [ { "neighbor": "WM-PER-001 Person and WM-PER-004 Household / Family", "distinction": "References resolve externally. A household may be a statistical unit or contextual reference but its count is not a person count. Group membership never establishes family ties or person attributes.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "WM-ORG-001 Organization", "distinction": "An organized community can overlap an ORG organization even without formal legal status. This model owns its population description; organization structure and legal status stay external. Formalization is a qualified continuity link, not automatic identity replacement.", "source_refs": [ "SRC-002" ] }, { "neighbor": "WM-PER-010 Contact Point / Party Profile and WM-CIV-005 Social Norm", "distinction": "Carry optional qualified channel and norm references. No contact endpoint maintenance, delivery action, universal community norm, or representation authority is imported by a reference.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "neighbor": "Classification concept, cohort definition and observation dataset", "distinction": "The persistent group, defining predicate revision, materialized snapshot and category concept have separate identifiers. An empty or unknown population is valid. Snapshot counts cannot be projected into a roster or member attributes.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Generic Statistical Information Model version 2.0", "organization": "United Nations Economic Commission for Europe", "url": "https://unece.github.io/GSIM-2.0/", "version_or_date": "Version 2.0; online specification accessed 2026-10-06", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:25:32Z", "relevance": "Population, Unit, Unit Type and Represented Variable definitions support explicit population boundaries and counting units. Human-population restriction and snapshot packaging are authored design choices." }, { "id": "SRC-002", "title": "The Organization Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-org/", "version_or_date": "Recommendation 2014-01-16", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:25:32Z", "relevance": "Sections 2.1, 2.2, 5.2 and 5.3 support qualified membership and roles. ORG includes informal organizations; it is not applicable to every statistical cohort and cannot establish a representation mandate." }, { "id": "SRC-003", "title": "2030 Census Recommendations, Chapter 21: Ethnocultural characteristics", "organization": "United Nations Economic Commission for Europe", "url": "https://w3.unece.org/recs2030census/webpage24.html", "version_or_date": "2030 census round online recommendations; paragraphs 1334-1346 and 1362-1366 accessed 2026-10-06; exact release pin unresolved", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:25:32Z", "relevance": "Selected census guidance on self-identification, withholding sensitive responses, changing classifications, multiple responses and disclosure controls. Not a universal legal rule or a basis to infer individual identity." }, { "id": "SRC-004", "title": "The RDF Data Cube Vocabulary", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-data-cube/", "version_or_date": "Recommendation 2014-01-16", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:25:32Z", "relevance": "Sections 5 and 6 distinguish datasets, observations, dimensions, measures and attributes including units and provisional status. A cube slice is not the population itself." }, { "id": "SRC-005", "title": "De-Identifying Government Datasets: Techniques and Governance", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-188.pdf", "version_or_date": "SP 800-188, September 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:25:32Z", "relevance": "Abstract and sections 3 and 4 identify release risk, sharing models, review and de-identification controls. This draft proposes release assessment records, not an implemented anonymization method or a universal safe cell size." }, { "id": "SRC-006", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:25:32Z", "relevance": "Entity, activity, agent, derivation, attribution and revision concepts support traceable definitions and snapshots. Provenance does not certify truth, consent or authority." }, { "id": "SRC-007", "title": "SKOS Simple Knowledge Organization System Reference", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/skos-reference/", "version_or_date": "Recommendation 2009-08-18", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:25:32Z", "relevance": "Sections 3-10 support concept identifiers, scheme-qualified labels and mappings. A category concept is not a group instance or a roster; mapping does not prove population equivalence." }, { "id": "SRC-008", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "RFC 3339, July 2002, section 5.6", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T15:25:32Z", "relevance": "Timestamp syntax with seconds and explicit offset. Reference periods, imprecise dates and valid-time intervals remain separately typed authored fields." } ], "structure": { "bundles": [ { "id": "bundle-identity", "name": "Identity and population scope", "description": "Identify the collective and the population boundary independently of its roster.", "rationale": "Authored grouping of source-supported concepts; no cited standard prescribes this hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007" ], "layers": [ { "id": "layer-identity", "name": "Collective identity", "description": "Retain a namespace-qualified group identity across names and observations. Declare whether the group is self-described, externally described or statistical; do not infer common agency from a shared label.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "findings": [ { "id": "finding-identity", "name": "Persistent identity and profile", "description": "Retain a namespace-qualified group identity across names and observations. Declare whether the group is self-described, externally described or statistical; do not infer common agency from a shared label.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "questions": [ { "id": "q-identity-1", "text": "Which master identifier and profile distinguish this group from a label, person roster or statistical snapshot?", "kind": "identity", "answer_data": [ "identity: namespace, group_id, profile, revision, external_identifiers", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-identity-2", "text": "Who supplies the description and what shared basis is asserted without presuming unanimous agreement?", "kind": "definition", "answer_data": [ "description: text, language, attributed_actor, basis, dissent_status", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-identity-3", "text": "Which versioned classification concepts apply and which labels or mappings remain disputed?", "kind": "classification", "answer_data": [ "classification: scheme_uri, version, concept_uri, labels, mapping_status", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-identity-1", "name": "identity", "description": "Candidate field group: identity: namespace, group_id, profile, revision, external_identifiers. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "data-identity-2", "name": "description", "description": "Candidate field group: description: text, language, attributed_actor, basis, dissent_status. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "data-identity-3", "name": "classification", "description": "Candidate field group: classification: scheme_uri, version, concept_uri, labels, mapping_status. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-identity", "name": "Group identity record", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-boundary", "name": "Population boundaries", "description": "State the population unit, base, geographic scope and reference period. Preserve overlapping groups and uncertain boundaries. Subgroup links are qualified assertions and do not establish disjointness.", "source_refs": [ "SRC-001", "SRC-004" ], "findings": [ { "id": "finding-boundary", "name": "Unit and boundary definition", "description": "State the population unit, base, geographic scope and reference period. Preserve overlapping groups and uncertain boundaries. Subgroup links are qualified assertions and do not establish disjointness.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "q-boundary-1", "text": "What is the counting unit and base population, and how are household units distinguished from persons?", "kind": "composition", "answer_data": [ "unit: unit_type, base_population_ref, person_conversion_rule_or_not_applicable", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-boundary-2", "text": "Which geographic definition and reference period bound this population, including mobile or non-territorial groups?", "kind": "spatial", "answer_data": [ "boundary: geography_ref, geography_version, reference_period, residence_basis, nonterritorial_reason", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-boundary-3", "text": "Which subgroup, overlap or successor links are evidenced and may their counts safely be combined?", "kind": "relationship", "answer_data": [ "links: target_group, relation, evidence_ref, valid_interval, overlap_status, additivity_rule", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-boundary-1", "name": "unit", "description": "Candidate field group: unit: unit_type, base_population_ref, person_conversion_rule_or_not_applicable. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "data-boundary-2", "name": "boundary", "description": "Candidate field group: boundary: geography_ref, geography_version, reference_period, residence_basis, nonterritorial_reason. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "data-boundary-3", "name": "links", "description": "Candidate field group: links: target_group, relation, evidence_ref, valid_interval, overlap_status, additivity_rule. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-boundary", "name": "Population boundary register", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-belonging", "name": "Belonging and continuity", "description": "Qualify membership assertions and changes without assuming universal voluntary affiliation.", "rationale": "Authored grouping of source-supported concepts; no cited standard prescribes this hierarchy.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006" ], "layers": [ { "id": "layer-membership", "name": "Membership assertions", "description": "Keep voluntary affiliation, administrative inclusion and self-identification distinct. A statistical profile need not enumerate members. Multiple, disputed, ended and undisclosed affiliations remain representable without inferred sensitive traits.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ], "findings": [ { "id": "finding-membership", "name": "Qualified belonging and visibility", "description": "Keep voluntary affiliation, administrative inclusion and self-identification distinct. A statistical profile need not enumerate members. Multiple, disputed, ended and undisclosed affiliations remain representable without inferred sensitive traits.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ], "questions": [ { "id": "q-membership-1", "text": "What evidence and assertion type support a membership tie, or why is no individual roster maintained?", "kind": "relationship", "answer_data": [ "membership: person_ref, assertion_type, evidence_ref, roster_absence_reason, assessment_status", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-membership-2", "text": "When was the membership asserted and when did it apply, end or become disputed?", "kind": "temporal", "answer_data": [ "membership_time: valid_start, valid_end, recorded_at, precision, dispute_state", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-membership-3", "text": "What purpose, applicable authority and disclosure preference govern each membership view?", "kind": "privacy", "answer_data": [ "membership_access: purpose, authority_ref, preference, scope, restriction, exception_review", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-membership-1", "name": "membership", "description": "Candidate field group: membership: person_ref, assertion_type, evidence_ref, roster_absence_reason, assessment_status. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ] }, { "id": "data-membership-2", "name": "membership_time", "description": "Candidate field group: membership_time: valid_start, valid_end, recorded_at, precision, dispute_state. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ] }, { "id": "data-membership-3", "name": "membership_access", "description": "Candidate field group: membership_access: purpose, authority_ref, preference, scope, restriction, exception_review. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-membership", "name": "Restricted membership assertion register", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-change", "name": "Group change and contestation", "description": "Record formation, renaming, division, merger, cessation and corrections as supported assertions. Record retirement differs from group dissolution. Maintain conflicting accounts and lawful redress without indefinite retention of personal payloads.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "finding-change", "name": "Continuity and correction evidence", "description": "Record formation, renaming, division, merger, cessation and corrections as supported assertions. Record retirement differs from group dissolution. Maintain conflicting accounts and lawful redress without indefinite retention of personal payloads.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "questions": [ { "id": "q-change-1", "text": "Which event evidence establishes formation, cessation or continuing identity after a group change?", "kind": "lifecycle", "answer_data": [ "change: event_type, evidence_ref, predecessor_refs, successor_refs, continuity_decision", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-change-2", "text": "How do occurrence time, observation time and uncertain or conflicting accounts qualify the event?", "kind": "event", "answer_data": [ "event_time: occurred_at_or_period, observed_at, precision, conflicting_evidence, assessment", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-change-3", "text": "How can an affected party challenge a description or membership claim and how is the resolution recorded?", "kind": "exception", "answer_data": [ "challenge: case_ref, restricted_submitter_ref, contested_assertion, review_state, correction_ref", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-change-1", "name": "change", "description": "Candidate field group: change: event_type, evidence_ref, predecessor_refs, successor_refs, continuity_decision. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-change-2", "name": "event_time", "description": "Candidate field group: event_time: occurred_at_or_period, observed_at, precision, conflicting_evidence, assessment. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-change-3", "name": "challenge", "description": "Candidate field group: challenge: case_ref, restricted_submitter_ref, contested_assertion, review_state, correction_ref. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-change", "name": "Group continuity and correction journal", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-cohort", "name": "Cohort definition and snapshots", "description": "Separate a versioned predicate from the evidence of a materialization.", "rationale": "Authored grouping of source-supported concepts; no cited standard prescribes this hierarchy.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006", "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-criteria", "name": "Cohort definition", "description": "Define a cohort predicate against a stated base with reference time, variables and missing-data semantics. A classification change requires a new definition revision. This is a description, not an executable query or permission to process personal data.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ], "findings": [ { "id": "finding-criteria", "name": "Versioned inclusion and exclusion rules", "description": "Define a cohort predicate against a stated base with reference time, variables and missing-data semantics. A classification change requires a new definition revision. This is a description, not an executable query or permission to process personal data.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ], "questions": [ { "id": "q-criteria-1", "text": "Which inclusion and exclusion predicates, unit type and variable definitions identify the cohort revision?", "kind": "requirement", "answer_data": [ "criteria: definition_id, revision, base_ref, predicates, variable_refs, unit_type", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-criteria-2", "text": "How are missing, withheld, multiple or conflicting answers treated without fabricating sensitive membership?", "kind": "constraint", "answer_data": [ "missingness: unknown_rule, withheld_rule, multiple_response_rule, conflict_rule, exclusion_reporting", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-criteria-3", "text": "Who approved this cohort purpose and definition, with what review of affected groups and sensitive characteristics?", "kind": "authority", "answer_data": [ "definition_review: steward_role, purpose, review_ref, participation_evidence, authorization_ref", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-criteria-1", "name": "criteria", "description": "Candidate field group: criteria: definition_id, revision, base_ref, predicates, variable_refs, unit_type. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "data-criteria-2", "name": "missingness", "description": "Candidate field group: missingness: unknown_rule, withheld_rule, multiple_response_rule, conflict_rule, exclusion_reporting. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "data-criteria-3", "name": "definition_review", "description": "Candidate field group: definition_review: steward_role, purpose, review_ref, participation_evidence, authorization_ref. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-criteria", "name": "Cohort definition record", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-snapshot", "name": "Cohort materialization evidence", "description": "Reference a materialization produced by an authorized external processor. Keep immutable snapshot identity separate from its generation time; revised inputs or methods create a new revision. No microdata is required in this model.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-008" ], "findings": [ { "id": "finding-snapshot", "name": "Reproducible snapshot references", "description": "Reference a materialization produced by an authorized external processor. Keep immutable snapshot identity separate from its generation time; revised inputs or methods create a new revision. No microdata is required in this model.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-008" ], "questions": [ { "id": "q-snapshot-1", "text": "Which definition revision, source dataset revisions and processing record generated this snapshot?", "kind": "provenance", "answer_data": [ "lineage: snapshot_id, definition_ref, dataset_refs, process_ref, method_version, digest", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-snapshot-2", "text": "What reference period, extraction cutoff and generation time apply, and which earlier snapshot is superseded?", "kind": "temporal", "answer_data": [ "snapshot_time: reference_period, cutoff, generated_at, previous_snapshot_ref, revision_reason", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-snapshot-3", "text": "What completeness, duplicate-unit and unit-consistency checks were reported, and can authorized reviewers reproduce the result?", "kind": "validation", "answer_data": [ "snapshot_checks: validation_ref, duplicate_policy, coverage_status, reproducibility_status, access_limit", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-snapshot-1", "name": "lineage", "description": "Candidate field group: lineage: snapshot_id, definition_ref, dataset_refs, process_ref, method_version, digest. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-008" ] }, { "id": "data-snapshot-2", "name": "snapshot_time", "description": "Candidate field group: snapshot_time: reference_period, cutoff, generated_at, previous_snapshot_ref, revision_reason. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-008" ] }, { "id": "data-snapshot-3", "name": "snapshot_checks", "description": "Candidate field group: snapshot_checks: validation_ref, duplicate_policy, coverage_status, reproducibility_status, access_limit. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-snapshot", "name": "Snapshot provenance manifest", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-measures", "name": "Measures and disclosure", "description": "Interpret statistical observations and separately assess their release.", "rationale": "Authored grouping of source-supported concepts; no cited standard prescribes this hierarchy.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005" ], "layers": [ { "id": "layer-statistics", "name": "Counts and distributions", "description": "Distinguish enumerated counts, estimates, weighted totals, proportions and disclosure-adjusted outputs. Zero, missing, suppressed and not applicable are different states. Do not infer any individual characteristic from an aggregate.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-statistics", "name": "Qualified population measures", "description": "Distinguish enumerated counts, estimates, weighted totals, proportions and disclosure-adjusted outputs. Zero, missing, suppressed and not applicable are different states. Do not infer any individual characteristic from an aggregate.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "q-statistics-1", "text": "Which measure, unit, denominator and dimensions give each reported figure its meaning?", "kind": "measurement", "answer_data": [ "measure: concept_ref, value, unit, denominator_ref, dimensions, counting_basis", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-statistics-2", "text": "What method, uncertainty, coverage limitations and adjustment status qualify the measure?", "kind": "quality", "answer_data": [ "quality: method_ref, estimate_status, uncertainty, undercoverage, weighting_ref, disclosure_adjustment", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-statistics-3", "text": "Which changes in definition, geography, multiple-response treatment or method limit comparison and additivity?", "kind": "interoperability", "answer_data": [ "comparability: compared_snapshot_refs, breaks, overlap, mapping_ref, permitted_aggregation", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-statistics-1", "name": "measure", "description": "Candidate field group: measure: concept_ref, value, unit, denominator_ref, dimensions, counting_basis. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "data-statistics-2", "name": "quality", "description": "Candidate field group: quality: method_ref, estimate_status, uncertainty, undercoverage, weighting_ref, disclosure_adjustment. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "data-statistics-3", "name": "comparability", "description": "Candidate field group: comparability: compared_snapshot_refs, breaks, overlap, mapping_ref, permitted_aggregation. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-statistics", "name": "Population measure and quality table", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-release", "name": "Disclosure assessment", "description": "Aggregation and a minimum cell count do not by themselves establish safety. A separate accountable assessment must consider recipients, other releases, linkage and group harms. This model stores the decision evidence, not a disclosure-control engine.", "source_refs": [ "SRC-003", "SRC-005" ], "findings": [ { "id": "finding-release", "name": "Purpose-specific release decision", "description": "Aggregation and a minimum cell count do not by themselves establish safety. A separate accountable assessment must consider recipients, other releases, linkage and group harms. This model stores the decision evidence, not a disclosure-control engine.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "q-release-1", "text": "Which re-identification, linkage, repeated-release and group-harm risks were assessed for the intended recipient?", "kind": "security", "answer_data": [ "risk: assessment_ref, recipient_scope, release_history_refs, threat_assumptions, residual_risk", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-release-2", "text": "Which accountable reviewer accepted, restricted or refused release under which policy and validity period?", "kind": "decision", "answer_data": [ "release_decision: reviewer_role, policy_ref, decision, conditions, expires_at, review_evidence", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-release-3", "text": "Which fields, cells and metadata are authorized for this view and which restrictions must travel with it?", "kind": "access", "answer_data": [ "release_view: snapshot_revision, allowed_fields, suppression_markers, recipient, use_limits, authorization_ref", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-release-1", "name": "risk", "description": "Candidate field group: risk: assessment_ref, recipient_scope, release_history_refs, threat_assumptions, residual_risk. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "data-release-2", "name": "release_decision", "description": "Candidate field group: release_decision: reviewer_role, policy_ref, decision, conditions, expires_at, review_evidence. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "data-release-3", "name": "release_view", "description": "Candidate field group: release_view: snapshot_revision, allowed_fields, suppression_markers, recipient, use_limits, authorization_ref. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-release", "name": "Disclosure assessment and release manifest", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-addressability", "name": "Representation and addressability", "description": "Record optional mandate and channel evidence without manufacturing agency.", "rationale": "Authored grouping of source-supported concepts; no cited standard prescribes this hierarchy.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "layers": [ { "id": "layer-representation", "name": "Representation and mandate", "description": "A data steward, organization member or channel administrator is not automatically empowered to speak for a collective. Record the grant basis, constituency, limits and disputes of each representation claim; a cohort can have none.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "finding-representation", "name": "Optional scoped spokesperson assertion", "description": "A data steward, organization member or channel administrator is not automatically empowered to speak for a collective. Record the grant basis, constituency, limits and disputes of each representation claim; a cohort can have none.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "questions": [ { "id": "q-representation-1", "text": "What evidence identifies the constituency and basis for a representative to speak on a specified matter?", "kind": "authority", "answer_data": [ "mandate: holder_ref, constituency_ref, grant_basis, evidence_ref, matter_scope", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-representation-2", "text": "Is the representation claim active, disputed, expired or revoked for the relevant time and audience?", "kind": "state", "answer_data": [ "mandate_state: valid_interval, assessment_status, dispute_ref, revocation_evidence, audience_scope", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-representation-3", "text": "Which duties belong to the record steward and which require a separate representative mandate?", "kind": "ownership", "answer_data": [ "responsibility: steward_role, stewardship_scope, representation_limits, accountability_ref", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-representation-1", "name": "mandate", "description": "Candidate field group: mandate: holder_ref, constituency_ref, grant_basis, evidence_ref, matter_scope. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-representation-2", "name": "mandate_state", "description": "Candidate field group: mandate_state: valid_interval, assessment_status, dispute_ref, revocation_evidence, audience_scope. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-representation-3", "name": "responsibility", "description": "Candidate field group: responsibility: steward_role, stewardship_scope, representation_limits, accountability_ref. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-representation", "name": "Representation claim register", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-channel", "name": "Collective addressability", "description": "A collective may have a declared channel without every member receiving or endorsing its messages. Carry external contact references and usage restrictions. Addressability is optional and never grants permission to send.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "finding-channel", "name": "Optional controlled contact reference", "description": "A collective may have a declared channel without every member receiving or endorsing its messages. Carry external contact references and usage restrictions. Addressability is optional and never grants permission to send.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "questions": [ { "id": "q-channel-1", "text": "Which external contact-point reference is declared for the group and by whose evidence?", "kind": "relationship", "answer_data": [ "channel: contact_point_ref, declaring_actor_ref, evidence_ref, verification_status", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-channel-2", "text": "Which purpose, language, accessibility and authorization conditions govern use of the declared channel?", "kind": "requirement", "answer_data": [ "channel_use: purposes, languages, accessibility_ref, permission_ref, restrictions", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-channel-3", "text": "What happens when a channel is stale, contested, unavailable or reaches only part of the group?", "kind": "exception", "answer_data": [ "channel_limits: review_time, availability_status, coverage_limit, dispute_ref, fallback_policy", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-channel-1", "name": "channel", "description": "Candidate field group: channel: contact_point_ref, declaring_actor_ref, evidence_ref, verification_status. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-channel-2", "name": "channel_use", "description": "Candidate field group: channel_use: purposes, languages, accessibility_ref, permission_ref, restrictions. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-channel-3", "name": "channel_limits", "description": "Candidate field group: channel_limits: review_time, availability_status, coverage_limit, dispute_ref, fallback_policy. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-channel", "name": "Collective channel reference register", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-governance", "name": "Stewardship and interoperability", "description": "Govern local records and document the limits of projections.", "rationale": "Authored grouping of source-supported concepts; no cited standard prescribes this hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-stewardship", "name": "Record stewardship", "description": "Bind group records to accountable roles and adopting-Dimension policies. Keep sensitive membership payloads restricted; public descriptive views require approval. Retain only what the applicable purpose, retention rules and holds justify.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "findings": [ { "id": "finding-stewardship", "name": "Governed access and disposal", "description": "Bind group records to accountable roles and adopting-Dimension policies. Keep sensitive membership payloads restricted; public descriptive views require approval. Retain only what the applicable purpose, retention rules and holds justify.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-stewardship-1", "text": "Which accountable roles maintain identity, definitions, evidence and disclosure decisions for this profile?", "kind": "ownership", "answer_data": [ "stewardship: role_refs, responsibilities, namespace_authority, delegation_ref, review_interval", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-stewardship-2", "text": "Which retention schedule, hold and disposal authority apply to each local payload and referenced artifact?", "kind": "retention", "answer_data": [ "retention: artifact_ref, schedule_ref, trigger, hold_ref, disposal_authority, minimal_tombstone", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-stewardship-3", "text": "How are restricted membership, representative evidence and approved aggregate views separated and their use audited?", "kind": "access", "answer_data": [ "access_control: purpose, role, field_scope, policy_ref, audit_ref, exception_record", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-stewardship-1", "name": "stewardship", "description": "Candidate field group: stewardship: role_refs, responsibilities, namespace_authority, delegation_ref, review_interval. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] }, { "id": "data-stewardship-2", "name": "retention", "description": "Candidate field group: retention: artifact_ref, schedule_ref, trigger, hold_ref, disposal_authority, minimal_tombstone. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] }, { "id": "data-stewardship-3", "name": "access_control", "description": "Candidate field group: access_control: purpose, role, field_scope, policy_ref, audit_ref, exception_record. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-stewardship", "name": "Stewardship and retention profile", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-projection", "name": "Mappings and acceptance", "description": "Pin conceptual alignments and disclose mapping losses. ORG applies only where its organization semantics fit; SKOS categories and Data Cube observations cannot replace collective identity. Mappings and instance validation remain unimplemented proposals.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006", "SRC-007" ], "findings": [ { "id": "finding-projection", "name": "Bounded interoperable projections", "description": "Pin conceptual alignments and disclose mapping losses. ORG applies only where its organization semantics fit; SKOS categories and Data Cube observations cannot replace collective identity. Mappings and instance validation remain unimplemented proposals.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006", "SRC-007" ], "questions": [ { "id": "q-projection-1", "text": "Which target vocabulary and version can carry group identity, predicate revisions and statistical qualifiers without conflation?", "kind": "interoperability", "answer_data": [ "mapping: target_uri, version, field_map_ref, applicability, semantic_losses", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-projection-2", "text": "Which profile fixtures test empty cohorts, overlapping groups, disputed mandates and suppressed values before use?", "kind": "validation", "answer_data": [ "acceptance: profile_version, fixture_refs, expected_outcomes, results_ref, unresolved_gaps", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] }, { "id": "q-projection-3", "text": "What authorized revision and refusal report accompany an export that cannot preserve required provenance or restrictions?", "kind": "process", "answer_data": [ "export: source_revision, target_profile, authorization_ref, loss_report, refusal_reason", "Record assertion source, review status and an explicit unknown or not-applicable reason." ] } ], "data_elements": [ { "id": "data-projection-1", "name": "mapping", "description": "Candidate field group: mapping: target_uri, version, field_map_ref, applicability, semantic_losses. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006", "SRC-007" ] }, { "id": "data-projection-2", "name": "acceptance", "description": "Candidate field group: acceptance: profile_version, fixture_refs, expected_outcomes, results_ref, unresolved_gaps. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006", "SRC-007" ] }, { "id": "data-projection-3", "name": "export", "description": "Candidate field group: export: source_revision, target_profile, authorization_ref, loss_report, refusal_reason. A profile-specific nested schema must define field types, requiredness and constraints before operational use.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-projection", "name": "Mapping and acceptance manifest", "description": "Versioned local record of qualified assertions or external references; restricted payloads need separately authorized storage. It does not replace the referenced master.", "media_or_form": [ "structured record", "authorized document projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier with namespace and revision; otherwise governed IRI then local UUID. Opaque entry sequence beneath artifact ID; dates and personal names are not identifiers.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "resolve-group", "name": "Resolve a group reference", "description": "Proposed operation, not implemented. Resolve exact namespace and master ID; return ambiguous or unresolved status instead of merging on shared labels.", "inputs": [ "namespace", "group reference", "authorized purpose" ], "outputs": [ "resolved reference or ambiguity report" ], "preconditions": [ "Verified role, purpose and field-level access for every input", "Applicable profile and evidence references resolved; missing authority causes refusal", "Mutations require expected current revision and idempotency key; conflict causes refusal" ], "effects": [ "Read-only reference resolution" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "record-membership", "name": "Record an evidenced membership assertion", "description": "Proposed operation, not implemented. Append an authorized assertion with type and valid time. Never infer sensitive affiliation from cohort statistics or overwrite the person master.", "inputs": [ "group revision", "restricted person reference or roster-not-maintained status", "evidence and authority", "assertion type" ], "outputs": [ "membership revision or refusal report" ], "preconditions": [ "Verified role, purpose and field-level access for every input", "Applicable profile and evidence references resolved; missing authority causes refusal", "Mutations require expected current revision and idempotency key; conflict causes refusal" ], "effects": [ "Append local qualified evidence; no joining action or access expansion" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "revise-cohort", "name": "Record a reviewed cohort definition revision", "description": "Proposed operation, not implemented. Record a reviewed predicate and missing-data rules. A definition is not permission to run a query; preserve prior snapshot bindings.", "inputs": [ "definition revision", "review evidence", "predicate and variable references" ], "outputs": [ "new definition revision or refusal report" ], "preconditions": [ "Verified role, purpose and field-level access for every input", "Applicable profile and evidence references resolved; missing authority causes refusal", "Mutations require expected current revision and idempotency key; conflict causes refusal" ], "effects": [ "Create local revision and explicit comparability break where needed" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "link-snapshot", "name": "Link an externally produced snapshot", "description": "Proposed operation, not implemented. Link authorized processing evidence, definition and data revisions with quality qualifiers. Do not execute personal-data extraction or certify correctness.", "inputs": [ "snapshot master reference", "definition revision", "processing evidence and validation report" ], "outputs": [ "snapshot linkage or refusal report" ], "preconditions": [ "Verified role, purpose and field-level access for every input", "Applicable profile and evidence references resolved; missing authority causes refusal", "Mutations require expected current revision and idempotency key; conflict causes refusal" ], "effects": [ "Append provenance linkage; do not copy microdata" ], "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "record-mandate", "name": "Record a representation claim assessment", "description": "Proposed operation, not implemented. Record existing grant, expiry, revocation or dispute evidence. Do not appoint a representative or infer collective consent.", "inputs": [ "group reference", "holder and constituency references", "scope and mandate evidence" ], "outputs": [ "qualified mandate record or refusal report" ], "preconditions": [ "Verified role, purpose and field-level access for every input", "Applicable profile and evidence references resolved; missing authority causes refusal", "Mutations require expected current revision and idempotency key; conflict causes refusal" ], "effects": [ "Append local assessment without changing external rights" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "prepare-view", "name": "Prepare an authorized local projection", "description": "Proposed operation, not implemented. Check a recorded disclosure decision against recipient, revision and mapping. Refuse stale approval, missing qualifiers or a lossy sensitive projection. No transmission occurs.", "inputs": [ "approved release decision", "snapshot or group revision", "recipient scope and target profile" ], "outputs": [ "local permitted projection and loss report or refusal" ], "preconditions": [ "Verified role, purpose and field-level access for every input", "Applicable profile and evidence references resolved; missing authority causes refusal", "Mutations require expected current revision and idempotency key; conflict causes refusal" ], "effects": [ "Create local projection with audit reference; no external release" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007" ] } ], "composition": [ { "target": "WM-PER-001", "relation": "REFERENCE", "purpose": "Optional restricted person master reference; no roster required and no person lifecycle copied.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-PER-004", "relation": "REFERENCE", "purpose": "Household context or unit reference; household counts never silently become person counts.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "WM-ORG-001", "relation": "REFERENCE", "purpose": "Organization continuity or stewardship reference; organizational structure and legal personality remain externally mastered.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "WM-PER-010", "relation": "REFERENCE", "purpose": "Optional channel master reference; no delivery or endpoint management is performed here.", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] }, { "target": "WM-CIV-005", "relation": "REFERENCE", "purpose": "Optional attributed norm reference, with dissent and applicability qualifiers; no assumption that all members share it.", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] }, { "target": "https://unece.github.io/GSIM-2.0/", "relation": "ALIGN", "purpose": "Population and unit concepts only; human-population profile is narrower than GSIM.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "https://www.w3.org/ns/org#", "relation": "ALIGN", "purpose": "Membership and roles only when organization semantics apply; statistical cohorts are not automatically organizations.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "https://www.w3.org/2004/02/skos/core#", "relation": "ALIGN", "purpose": "Classification scheme and label references only; category identity is distinct from a collective.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "https://purl.org/linked-data/cube#", "relation": "ALIGN", "purpose": "Candidate statistical observation projection; full mapping and conformance tests remain deferred.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "https://www.w3.org/ns/prov#", "relation": "ALIGN", "purpose": "Candidate lineage vocabulary for definitions, assertions and snapshots; not proof of authority or truth.", "required": false, "source_refs": [ "SRC-006" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Group steward or statistical-definition custodian role with explicit namespace authority", "Applicable purpose, jurisdiction, privacy and disclosure-review profile", "Pinned references, retention schedule and accountable review and correction routes" ], "namespace_guidance": "Use a governed namespace plus master group ID. Distinguish group, definition, snapshot and artifact namespaces; never put personal names or sensitive labels in opaque identifiers.", "registry_links": [ "vr.wm-per-005", "Legacy H3 is migration evidence only; sibling bindings require version review" ] }, "canon_and_patch": { "canonicalization_rules": [ "Keep stable group IDs while versioning labels, criteria and assessments. Preserve original assertions and attribution subject to lawful retention.", "Do not normalize withheld, unknown, zero, suppressed and not-applicable values into one null state. Do not deduplicate groups by name or shared members." ], "patch_rules": [ "Require authorized actor, evidence, reason, base revision and idempotency key. Conflicts return a refusal or explicit reconciliation record.", "Changing a predicate, geography or counting unit creates a definition revision and comparability assessment; do not silently rewrite old snapshots." ], "compatibility_rules": [ "Preserve source namespaces and definition-to-snapshot bindings. Loss of required authority, unit, time or privacy qualifiers makes an export incompatible.", "Community and statistical profiles have conditional fields; representation, channels and individual rosters may be absent with reasons." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier plus namespace and revision", "Governed global identifier or IRI", "Dimension-assigned UUID or ULID with reconciliation status" ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and an explicit offset or Z. Record event time separately from observation and ingestion time; keep reference periods, date-only values, intervals and unknown precision separately typed.", "serial_naming_rule": "Use artifact ID and opaque stable entry sequence with a separate revision. No date-only identifiers or sensitive membership data in filenames.", "integrity_rule": "Store digest algorithm and byte scope for authorized artifacts plus derivation references. A digest proves byte consistency only; it does not prove membership, consent, truth or release safety." }, "policies": [ "This is a noncanonical reviewable draft with an owner-authorized single-provider waiver; independent review and source verification remain open.", "No sensitive individual membership inference, discrimination or targeting. Minimize collection and qualify any self-description or external classification.", "Statistical inclusion is not affiliation, membership is not consent, stewardship is not representation and aggregation is not anonymization.", "Sensitive cohort definitions, contested mandates and disclosure decisions require accountable profile review. No universal consent basis or minimum safe cell size is asserted.", "All proposed functions are local record operations; no query execution, communications, public release or exercise of authority is implemented." ], "crud": { "read": [ "Resolve role and purpose at bundle, layer, finding and artifact scopes, including field restrictions. Default-deny restricted membership and mandate evidence." ], "create": [ "Create only within an authorized namespace with declared profile, provenance, purpose and policy references. Empty cohorts and absent rosters are valid with explicit status." ], "update": [ "Append reviewed revisions with concurrency checks. Preserve contested evidence and supersession links subject to data minimization; never silently update a referenced master." ], "delete": [ "Retire local group descriptions separately from real-world dissolution. The adopting-Dimension retention custodian owns disposal execution under applicable holds and schedules.", "Lawfully erase restricted payloads when authorized and retain only minimal permitted tombstones. Provenance history does not require indefinite storage of personal data; reference retirement cannot delete external masters." ] }, "roles": [ { "name": "Group steward", "responsibilities": [ "Maintain group description and correction routing; this role grants no representative mandate." ] }, { "name": "Statistical-definition custodian", "responsibilities": [ "Review population units, definitions and comparability of snapshots." ] }, { "name": "Evidence curator", "responsibilities": [ "Maintain source references, revision bindings and uncertainty without certifying unsupported assertions." ] }, { "name": "Disclosure reviewer", "responsibilities": [ "Assess recipient-specific release evidence and approve, restrict or refuse projections." ] }, { "name": "Retention and access custodian", "responsibilities": [ "Apply purpose-limited access, retention, holds and authorized disposal." ] } ], "access": { "default_rule": "Deny access unless role, purpose, profile, recipient and field scope are authorized. Published descriptive or aggregate views require a separate recorded release decision.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Any exceptional disclosure requires documented applicable authority, narrow scope, reviewer and expiry; a spokesperson cannot authorize access to all members by default." ], "audit_requirements": [ "Reference the adopting-Dimension audit record for reads, revisions, decisions and exports without duplicating sensitive payloads in logs. Record actor role, purpose, scope, revision, time and refusal reason." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read AGENTS.md and adopting-Dimension authority and access policies", "Read spec.yaml, review holds and profile applicability", "Resolve master references and pinned evidence before answering or proposing a mutation" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one human population group with community, membership-group or statistical-cohort profiles. Separate frozen local no-tools self-audit completed. Source/version verification, applicable operational profiles, executable conformance and independent external review remain holds; this is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Separate group master, label, definition and snapshot IDs." }, { "dimension": "lifecycle", "status": "covered", "notes": "Formation and continuity assertions differ from record retirement and actual dissolution." }, { "dimension": "relationships", "status": "covered", "notes": "Qualified membership, overlap, subgroup and optional sibling references; no automatic inheritance." }, { "dimension": "temporal", "status": "covered", "notes": "Valid time, observed time, reference period and extraction cutoff are distinct." }, { "dimension": "provenance", "status": "covered", "notes": "Source and processing references preserve assertion lineage and revisions." }, { "dimension": "ownership", "status": "covered", "notes": "Role-based stewardship differs from representation authority." }, { "dimension": "validation", "status": "gap", "notes": "Research schema validation is available; executable nested instance schemas and profile fixtures are deferred." }, { "dimension": "access", "status": "covered", "notes": "Purpose and recipient-scoped access with separate disclosure evidence." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Local retirement, lawful payload disposal and minimal tombstones depend on the adopting policy." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual GSIM, ORG, SKOS, Data Cube and PROV alignment; no conformance claim." }, { "dimension": "direct properties", "status": "covered", "notes": "Group profile, names, status, boundaries and statistical measures; no intrinsic physical mass or geometry is required." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Attributed self-description, external definition, membership evidence and snapshots are separate observation routes." }, { "dimension": "capabilities and operations", "status": "covered", "notes": "Six proposed record operations with preconditions and refusal results; no implied collective agency." }, { "dimension": "measurement", "status": "covered", "notes": "Counting unit, denominator, missingness, overlap, uncertainty and adjustment status." }, { "dimension": "source verification", "status": "gap", "notes": "Eight primary browser documents accessed for selected claims. Direct HTTP status, content digests, current versions and profile applicability remain unverified." }, { "dimension": "independent review", "status": "gap", "notes": "Claude and Grok skipped under owner override; local no-tools self-audit cannot supply independent external review." } ], "known_omissions": [ "Executable nested field schemas, predicate language, privacy algorithms and statistical estimators are not implemented.", "Profile-specific law, consent or other authority, indigenous/community governance and detailed representation processes need qualified local review.", "Independent external review, pinned source versions, licenses and tested target mappings remain incomplete." ], "conflicts": [], "regional_assumptions": [ "GSIM is a conceptual statistical model; this profile is restricted to human population groups.", "UNECE census guidance is used for selected sensitive-data design considerations, not universal law. NIST guidance informs disclosure review, not a universal release threshold." ], "adversarial_checks": [ "Reject treating an empty cohort as invalid or an absent roster as proof of no members.", "Reject group-name matching as identity equivalence, subgroup totals as automatically additive, or a category concept as the collective.", "Reject inferring individual traits from aggregate measures or treating suppression as zero.", "Reject statistical inclusion as voluntary membership and steward status as a representation mandate.", "Reject claiming minimum cell size alone provides anonymity or a source digest proves substantive correctness.", "Reject keeping personal payloads forever solely to preserve history." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The root identifies one persistent population-group description with an explicit profile. Members, classification concepts, defining predicate revisions and snapshots retain separate identities. The registry standalone-mm value is a record-plane classification, not the research subject-kind enum." }, "decisions": [ { "concept": "Persistent collective boundary", "disposition": "accepted", "rationale": "The group is a persistent profile-qualified entity, distinct from its members, defining predicate, classification concept and snapshots. Multiple profile kinds do not require an aggregate root." }, { "concept": "Community and statistical profiles", "disposition": "qualified", "rationale": "A cohort need not have a roster, representative, shared purpose or channel. Statistical inclusion cannot establish voluntary affiliation or collective agency." }, { "concept": "Counting units and overlap", "disposition": "accepted", "rationale": "Household context remains a qualified unit reference. Person counts require their own basis; subgroup, overlapping and multiple-response totals cannot be assumed additive." }, { "concept": "Classification and identity", "disposition": "separated", "rationale": "Labels and scheme concepts cannot merge group identities. Changes in criteria and geography create explicit revisions and comparability questions." }, { "concept": "Membership and self-identification", "disposition": "qualified", "rationale": "Assertion type, evidence, valid time, authority, disclosure preference and dissent remain separate. Sensitive affiliations cannot be inferred from aggregates or missing responses." }, { "concept": "Continuity and formalization", "disposition": "qualified", "rationale": "Formation, cessation, correction and organizational continuity are evidenced claims. Retiring a local record does not dissolve a real collective or create legal personality." }, { "concept": "Cohort definition and snapshot identity", "disposition": "accepted", "rationale": "The definition revision and processing evidence bind each independently identified snapshot. Generation date is metadata, not the sole identity or proof of correctness." }, { "concept": "Statistical interpretation and disclosure", "disposition": "accepted with profile hold", "rationale": "Measures retain units, denominators, uncertainty and value status. Aggregation and minimum cell size do not establish release safety; accountable recipient-specific review is still required." }, { "concept": "Representation and channels", "disposition": "separated", "rationale": "Stewardship, membership and channel administration do not grant authority to speak for everyone. Mandates and channels can be absent, disputed, expired or limited." }, { "concept": "Sibling and standards mappings", "disposition": "qualified", "rationale": "The ledger has no model-specific edges. Proposed registry-confirmed neighbor references remain optional and need pinned boundary review. ORG is only applicable where organization semantics fit." }, { "concept": "Local functions and external action", "disposition": "accepted as proposed only", "rationale": "The six functions record or resolve local evidence and prepare authorized views. They do not perform selection queries, appoint representatives, contact groups or disclose data externally." }, { "concept": "Service rules and record disposal", "disposition": "accepted with policy dependency", "rationale": "Namespace, revision, role and field-level access rules preserve traceability. Retention qualifiers allow lawful payload erasure and minimal tombstones without deleting external masters." }, { "concept": "Source and legacy assurance", "disposition": "limited", "rationale": "Selected browser support is available for eight sources, but direct HTTP and byte checks were not run. Source-version, license and profile verification remain open; legacy conformance claims are not evidence." }, { "concept": "Instance validation and independent review", "disposition": "deferred", "rationale": "Candidate object groups and conceptual mappings do not implement nested schemas or acceptance fixtures. This separate local self-audit supplies no independent second-provider review." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; this separate local Codex self-audit is not an independent provider review.", "Source verification is incomplete. Eight primary browser documents were accessed for selected claims; direct HTTP requests were not attempted because of the declared sandbox restriction. Zero direct responses and zero HTTP 200 responses were measured. The coordinator must run check_sources.py outside the sandbox and review versions, content, licenses and exact census edition.", "Operational use requires qualified local review of statistical units and methods, privacy and lawful authority, sensitive cohort definitions, affected-group participation, representation mandates, retention and recipient-specific disclosure controls. No universal consent basis or safe cell-size threshold is asserted.", "Nested instance schemas, cohort predicate bindings, pinned neighbor versions, complete GSIM/ORG/SKOS/Data Cube/PROV mappings and adversarial acceptance fixtures are incomplete. No runtime, disclosure-safety or standards-conformance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Verify source byte identity, current editions, licenses and source-to-claim support externally, and restore independent provider review before canonical promotion.", "Develop profile-specific nested schemas and fixtures for empty populations, overlapping membership, household units, changing definitions, suppressed values, contested mandates and lawful erasure.", "Review local legal and community-governance applicability and test statistical comparability, disclosure assessments and target mappings with qualified accountable reviewers." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }