Document / Record
Give agents one format-neutral vocabulary for treating a document as a governed record: a stable information object whose identity outlives any file, carried through immutable versions and multiple instantiations, made relyable by signatures, timestamps and custody evidence, and disposed of under an authorised retention regime.
Bundle → Layer → Finding → Questions Filled
6 bundles · 13 layers · 29 findings · 108 questions
Identity, documentary form and classification What the record is, how it is named and referenced, what documentary genre it belongs to, and where it sits in a business classification scheme and archival aggregation.
Identity and designation
The stable identifier of the record as an information object and the human-facing titles and reference numbers layered on top of it.
Record identity anchor
The identifier that denotes the record independently of any file, version or rendition, its scheme, its granularity and its non-reuse guarantee.
- Which system is the authoritative master for this record's identifier and from which registered scheme is the value drawn? identity
- Does the identifier denote the record, one version, or one instantiation? definition
- What guarantees that the identifier is never reused after disposition or system migration? constraint
- Which legacy or alternate identifiers exist and on what basis are they asserted equivalent? interoperability
Designation and reference numbers
Titles, alternative and translated titles, and the official reference numbers quoted on the face of the record, kept strictly distinct from identity.
- What is the official title of the record, in which language and script is it recorded, and who set it? definition
- Which reference numbers appear on the face of the record and which authority allocated each? identity
- How are superseded or translated titles retained without ever being treated as identifiers? constraint
Documentary form and classification
The genre of the record and its placement in a business classification scheme and archival aggregation, which drive the rules that later apply to it.
Documentary form and genre
The documentary form the record takes (contract, certificate, invoice, minutes, licence) typed against a controlled vocabulary, and the rules that follow from that form.
- What documentary form does this record take and from which controlled vocabulary is the term drawn? classification
- Which obligations, signature requirements or retention consequences follow automatically from that form? requirement
- Can one record carry more than one documentary form, such as a certificate inside a covering letter? composition
- Who approves additions to the form vocabulary and how are retired terms handled? authority
Business classification and aggregation membership
Filing of the record under a classification class and its membership in aggregations, with the boundary to the archival aggregation model held explicitly.
- Under which classification class is the record filed and which version of the scheme was in force at filing? classification
- Which aggregations does the record belong to and is membership exclusive? composition
- When the scheme is reorganised, is the historic class retained alongside the new one? temporal
- If more than one class applies, which one determines retention and access? exception
Content, versions and manifestations What the record says, the immutable states its content passes through, and the format-specific and carrier-specific realisations that make it readable.
Content and components
The body of the record, its structural parts, attachments and the properties that must survive any transformation.
Content structure, components and completeness
Which parts make up the complete record, which are essential to its meaning, and how completeness is verified at capture.
- Which components make up the complete record and which of them are essential rather than incidental? composition
- Which significant properties must be preserved for the record to remain usable and understandable? quality
- In which languages is the content expressed and which language version is authoritative for interpretation? definition
- How is completeness verified before the record is declared captured? validation
Versions and instantiations
The immutable version chain of content states and the multiple physical or digital instantiations that realise each state.
Version chain and immutability
How a content state is fixed, how versions supersede and amend one another, and the prohibition on editing an issued version in place.
- Which event fixes a version and makes it immutable, and who is competent to trigger it? event
- Which version is currently authoritative and which versions does it supersede or amend? state
- How are drafts distinguished from issued versions for retention and access purposes? lifecycle
- What reason, authority and change description are recorded for each new version? provenance
Instantiation, copy and original status
Format-specific and carrier-specific realisations of a version, and the legal distinction between the original of record, duplicates, certified copies and extracts.
- Which instantiation is the original of record and where is it held? identity
- Is a given instantiation a faithful rendition, a derivative, a certified copy or an extract, and who attests it? evidence
- What criteria make a digitised surrogate acceptable in place of an analogue original? requirement
- How are two instantiations of the same version proven to carry the same content? validation
Supersession between records
Dublin Core replaces/isReplacedBy model a related resource that supplants another. A new record may supersede an older record (policy, specification, licence) without being a version of the same identity. Supersession does not by itself authorize destruction of the replaced record; disposition remains a separate control.
- Which earlier record(s) does this record replace, from when, and is the older identity retained? relationship
- Has this record been replaced, and is it still retained under its schedule? state
- Is the successor a new version of the same identity or a distinct record that replaces this one? definition
Format, fixity and preservation
Technical identification of instantiations, the environment needed to render them, and the integrity and preservation controls applied over time.
Format identification and rendering environment
How each instantiation's format is identified against registries and what software and hardware environment is required to render it.
- Which registered media type and which format-registry identifier apply to this instantiation? measurement
- How was the format determined — declared by the producer or identified by a tool? provenance
- What environment is required to render the instantiation faithfully? requirement
- What is the obsolescence risk for this format and what migration or emulation path is planned? decision
Fixity and preservation actions
Baseline digests, verification history, declared preservation level and the actions applied to keep instantiations readable, including those that change bytes.
- Which algorithm and digest value were recorded at capture, and by which agent? evidence
- When was fixity last verified, at what frequency, and what was the outcome? measurement
- Which preservation actions have been applied and did any of them change the bytes? process
- What happens when a fixity check fails, and who is notified? exception
Agency, authority and issuance Who is responsible for the record, who owns and who keeps it, and the act of issuing it under a mandate and entering it into a register.
Agents, ownership and custody
Role-qualified references to the agents who made, approved, own and keep the record.
Authorship and responsibility roles
Who authored, contributed to, approved and was addressed by the record, expressed as role-qualified references rather than embedded agent descriptions.
- Which agent is the author of record and which agents merely contributed? ownership
- Who approved or authorised issue, and under what delegation of authority? authority
- Who are the intended addressees or recipients, and does that constrain access? relationship
- How is a role recorded when the responsible agent cannot be identified? evidence
Ownership, custody and stewardship
The separation between the record owner and the custodian or registrar acting on the owner's behalf, and the terms limiting custodial power.
- Who owns the record and who currently has custody of it? ownership
- What may the custodian not do — can they widen access, migrate formats or dispose? authority
- How and when does ownership itself transfer, and what evidence is required? lifecycle
Issuance and registration
The act of issuing the record under a mandate in a jurisdiction, and its entry into a custodial or public register.
Issuance, mandate and register entry
The legal basis and jurisdiction under which the record was issued, and the register entry that anchors it in a custodial system.
- Under which mandate, statute or delegated authority was the record issued? authority
- In which jurisdiction and at which place was it issued, and does that determine the applicable rules? spatial
- Is the record registered, in which register, under what entry number, and at what instant? identity
- Is the register public, and what is disclosed at existence level when content is withheld? access
Authenticity and evidentiary value Why the record can be relied on: signatures and seals bound to fixed content, trusted timestamps, dated validation outcomes, derivation provenance and an unbroken chain of custody.
Signatures, seals and validation evidence
Signature and seal objects bound to specific content, the timestamps that fix their moment, and the dated results of validating them.
Signature, seal and attestation
Signatures, seals and attestations applied to a version or instantiation, their assurance tier, their signatory and exactly what content each binds.
- What signature or seal type was applied and at which assurance tier? evidence
- Which exact content does each signature bind — a version, an instantiation, or a byte range? composition
- Who is the signatory or sealing legal person, and on which certificate or credential does the signature rest? identity
- What must hold for the signature to have legal effect in the governing jurisdiction? requirement
Timestamping and validation evidence
Trusted time-stamp tokens proving existence at a time, validation outcomes recorded with their own validation instant and policy, and the renewal of evidence before algorithms weaken.
- Is there a trusted time-stamp token binding the content to a time, and which authority issued it? evidence
- What was the validation outcome, at which validation instant, and under which validation policy? validation
- How is the evidence renewed before its algorithms or certificates weaken? temporal
- Which provenance manifest, if any, travels with the rendered asset, and does it survive rendition? interoperability
Authoritative record characteristics
ISO 23081 states that metadata must support assertions of integrity, authenticity, reliability and usability over time in business context. ISO 15489 requires records to remain authoritative through those characteristics: authentic (what it purports to be, created or sent by the purported agent at the purported time), reliable (trusted full and accurate content of the transaction), integrity (complete and unaltered), usable (locatable, retrievable, presentable, interpretable). These are assessed properties with evidence, not decorative flags.
- Can this record be shown to be what it purports to be, created or sent by the purported agent at the purported time, and on what evidence? evidence
- Has integrity been maintained (complete, unaltered since capture), and what unauthorized change if any was detected? quality
- Can the record still be located, retrieved, presented and interpreted by the intended community? quality
Provenance and chain of custody
Where the record came from and who held it at every moment between creation and now.
Derivation and provenance graph
The activities that generated the record, the sources it derives from, and the agents associated with each generating activity.
- Which activity generated this record or version, and when did it start and end? provenance
- Which prior records was it derived from, and is the derivation a revision, an extract or a quotation? relationship
- Which agent was associated with each generating activity, and on whose behalf did they act? ownership
- Where a machine or model produced content, what tool, version and parameters are recorded? evidence
Chain of custody and hand-over
The gapless sequence of custody intervals, hand-over receipts and integrity checks that allows the record to be relied on as evidence.
- Who held the record over each interval and are there any unexplained gaps? temporal
- What receipt or acknowledgement evidences each hand-over? evidence
- Was integrity verified at dispatch and again at receipt, and by whom? validation
- How is the chain kept intact when a system migration rewrites storage or re-encodes content? exception
State, time and recordkeeping control The status the record is in, the events that moved it there, the time anchors it carries, and the retention, hold and disposition regime that decides its end.
Status, lifecycle events and time
Controlled status values, the append-only history of what happened, and the distinct time anchors the record carries.
Record status and permitted transitions
The controlled status vocabulary, which transitions are permitted from each state, who may authorise them, and how withdrawal differs from destruction.
- What is the record's current status and since which instant has it held that status? state
- Which transitions are permitted from the current status and who may authorise each? lifecycle
- Is withdrawal or revocation distinct from destruction, and does a revoked record remain discoverable? exception
Lifecycle events and audit trail
The append-only history of everything done to and with the record, using controlled event types with actor, outcome, event time and separately recorded observation time.
- Which event types are recorded and from which controlled vocabulary are they drawn? event
- Who performed each event, with what outcome and what detail? provenance
- Is the trail append-only and how is its own integrity protected against tampering? security
- How long is the audit trail retained relative to the record, and does disposition erase it? retention
Temporal anchors and validity periods
The distinct time anchors a record carries — created, issued, effective, expiry, received, observed — their precision, and the rule separating event time from ingestion time.
- Which datetime is the legally or operationally decisive one for this record type? temporal
- Over what period is the record valid or effective, and may the period be open-ended? temporal
- How are event time and observation or ingestion time kept distinct in every record of time? provenance
- How are dates of unknown precision or unknown local offset recorded? exception
Document versus captured record
ISO 15489 applies to records regardless of structure or form and treats capture into a records system as the act that places identified information under records controls. RiC-CM defines a Record as discrete information content formed and inscribed, at least once, on any persistent recoverable carrier by an agent in the course of activity. US 36 CFR 1220.18 / 44 U.S.C. 3301 additionally excludes extra copies kept only for reference, library or museum materials for exhibit, and personal files. This model stores a record-status on the object: document-not-captured, captured-record, nonrecord-copy, or jurisdiction-specific Federal-record, rather than splitting into two meta-models.
- Has this object been captured as a record, and under which jurisdiction or policy is that determination made? classification
- If it is a nonrecord, extra copy or personal file, what is the excluding criterion? classification
- Who has authority to determine record status when systems or staff disagree? authority
Retention, disposition and holds
The authorised schedule that decides the record's fate, the suspensions that override it, and the evidence that survives execution.
Retention class and disposition authority
The retention class assigned to the record, the instrument authorising it, the trigger that starts the clock and the action due at the end.
- Which retention class applies and under which authority instrument and citation? authority
- What event triggers the retention clock and how is that trigger detected? event
- Is the record permanent or temporary, and what disposition action falls due at the end of the period? decision
- When two schedules apply to the same record, which one prevails? exception
Holds and disposition suspension
Legal holds and other suspensions that override retention schedules until explicitly released, and the mechanism that prevents automated disposal of held records.
- What is the scope of the hold — this record, its aggregation, or a query-defined set resolved at a moment in time? composition
- Who placed the hold, under what proceeding or authority, and when? authority
- What must be true before the hold can be released and disposition resumed? constraint
- How is hold state surfaced so that no automated process can dispose of a held record? security
Disposition execution and surviving evidence
Carrying out destruction, transfer or permanent retention, and the evidence and tombstone that outlive the record itself.
- Who authorised the disposition and was the absence of any hold verified at that moment? authority
- What method was used and is it verifiable as irreversible for the carrier concerned? process
- What evidence survives destruction and which metadata fields are kept as a tombstone? retention
- For transfer, what accession identifier and integrity proof did the receiving body return? interoperability
Access, rights and interoperability Who may see what, on what legal footing content may be reused, and how the record and its evidence move between systems without losing meaning.
Access, security marking and rights
Markings and decisions controlling who may read the record, and the intellectual-property and personal-data constraints on reuse.
Access conditions and security marking
The security marking and access restriction status carried by the record, the statutory regime behind them, and the recorded decisions on individual requests.
- What security marking and access restriction status does the record carry, and who set them? access
- Which statutory access or exemption regime applies, and for how long does the restriction run? authority
- What is disclosed at existence level when the content itself is withheld? privacy
- How are grants, denials and emergency access events recorded and reviewed? evidence
Rights, licensing and personal data
Who holds rights in the content, under what licence it may be reused, and what personal data within it constrains processing and release.
- Who holds rights in the content and under which licence may it be reused? ownership
- Does the record contain personal or special-category data, and on what lawful basis is it processed? privacy
- What redactions produced the releasable derivative, and is the unredacted source preserved intact? process
Interoperability and exchange
Declared mappings to external metadata standards and the packaging and projection rules for moving records between systems.
Metadata alignment and conformance evidence
Which external standards the record's metadata is mapped to, where mappings lose information, and what evidence is required before any conformance claim is made.
- Which external standards is this metadata mapped to, and at which version of each? interoperability
- Where does a mapping lose information or contradict another target, and how is the loss recorded? quality
- What evidence supports any conformance claim, and who validated it? validation
Exchange packaging and projections
How a record and its evidence are packaged for transfer or publication, and how each projection deliberately omits parts without breaking reconstructability.
- What package structure and manifest are used, and how is package integrity proven on arrival? interoperability
- Which projection is being served and which fields does it deliberately omit? access
- How does a receiving system reconstruct identity, version chain, fixity and events from the package alone? validation
- Which media types, character encodings and normalisation rules apply to the payload? constraint
Classifiers Filled
- Family
- World Models
- Category
- Information and virtual systems
- Entry kind
- aggregate
- Navigation path
- NAV.INF.REC.DOC
- Domain
- INF.REC.DOC
- Industry
- Cross-industry
- Tags
- documentrecordinf.rec.doc
- Also called
- N1
What it is Filled
Covers the record as an aggregate root over its versions, instantiations, signatures, provenance, events, retention assignments, holds and access decisions, from creation or capture through disposition. Excludes the semantics of what the record is about, the agents named in it, the aggregations that hold it, and any particular storage or interface technology.
In scope
- Record identity, designation and official reference numbers
- Documentary form/genre and business classification membership
- Content structure, components, attachments and significant properties
- Immutable version chain, supersession and amendment
- Instantiations: renditions, carriers, originals, duplicates, certified copies and extracts
- Format identification, rendering environment, fixity and preservation actions
- Authorship, approval, ownership, custody and stewardship roles as references
- Issuance under mandate and entry into custodial or public registers
- Signatures, seals, attestations, trusted timestamps and dated validation outcomes
- Provenance, derivation and unbroken chain of custody
- Status vocabulary, lifecycle events, audit trail and temporal anchors
- Retention classes, disposition authority, holds, disposition execution and surviving evidence
- Security marking, access decisions, rights, licensing and personal-data constraints
- Metadata alignment, exchange packaging and projections
Out of scope
- Subject-matter semantics of the record's content (contract obligations, clinical findings, financial postings)
- Attributes and identity of persons and organizations named as agents
- Archival arrangement and description of fonds, series and collections (WM-REC-015)
- Identifier scheme registration, syntax and resolution policy (naming model)
- Calendar systems, working-day arithmetic and duration algebra (time model)
- Message transport, delivery and receipt semantics (communication model)
- Byte storage, replication, tiering and infrastructure operations
- Workflow and case management beyond record-affecting events
- Full-text indexing, retrieval ranking and search relevance
- Statutory interpretation of exemptions; the model carries markings, not legal conclusions
- Cryptographic key generation and hardware security module operation
Why it exists Filled
Give agents one format-neutral vocabulary for treating a document as a governed record: a stable information object whose identity outlives any file, carried through immutable versions and multiple instantiations, made relyable by signatures, timestamps and custody evidence, and disposed of under an authorised retention regime.
Distinguishing features Filled
- A record is a document captured under controls as evidence of an activity, unlike a draft or working file.
- It differs from a dataset, which is structured data for reuse, and from a message, which is a communication event.
- It sits inside an archival fonds or collection (WM-REC-015) but is described and disposed of individually.
- Content of an issued version never changes; changes create a successor version.
What robots and AI may and may not do Filled
Must not
- Alter the content of an issued version.
- Dispose of a record under legal hold or before its retention period ends.
- Widen access beyond what the owner granted.
- Delete audit trail, hold or disposition evidence together with the record.
- Issue a certified copy without the issuing authority's procedure.
Only with a human decision
- Executing disposition of records.
- Placing or releasing a legal hold.
- Granting exceptional or emergency access to restricted content.
May
- Capture a document as a record with identifier, metadata and fixity value.
- Verify fixity and signatures and report the result.
- Assign a retention class from an in-force schedule.
- Produce a redacted derivative linked to its source.
Moral aspects Filled
- Records often hold personal data; access and redaction must protect the people named.
- Records are evidence of rights and duties; their loss or tampering harms people who rely on them.
- Early or hidden destruction can conceal wrongdoing and defeat accountability.
Who is affected
- People named in records
- Creating organization and its staff
- Courts, auditors and the public with access rights
Owners Filled
Steward
Name one accountable record owner (the author or issuing organization) and, separately, any custodian; the package must state that custody never confers ownership and that a custodian cannot widen access or dispose.
Roles
- Record owner (author or issuing organization)
- Accountable for the record's existence, accuracy and classification; Grants and revokes access to content and metadata; Authorises issuance of new versions and approves disposition
- Custodian or registrar
- Holds the record and maintains the register entry on the owner's behalf; Maintains fixity, storage and the chain of custody without acquiring ownership; Escalates to the owner any request that would widen access or alter content
- Records manager
- Maintains the classification scheme and retention schedules and their authority citations; Resolves schedule conflicts under the declared precedence rule; Runs the disposition worklist and obtains the required authorisations
- Preservation engineer
- Performs format identification, characterisation and fixity verification on schedule; Plans and executes migration or emulation before format obsolescence; Records every preservation action as an event with byte-change status
- Legal hold custodian
- Places, scopes, monitors and releases holds under a named authority; Verifies that no automated process can dispose of an in-scope record; Retains hold instruments and release evidence independently of the records held
- Access and data protection officer
- Applies security markings, statutory exemptions and restriction review dates; Decides access requests and approves redacted derivatives for release; Reviews break-glass events and notifies owners within the declared window
- Auditor
- Reads holds, events, fixity artifacts and access logs without content access; Tests that the audit trail is append-only and that disposition evidence survives; Reports unexplained custody gaps and unverifiable conformance claims
Links to other meta-models Filled
child
- WM-REC-015 Archival fonds / collection - Records governed here are the members that archival aggregations contain; membership references are stored here, arrangement and multi-level description there.
references
- Agent model — natural person - Authors, approvers, signatories and custodial officers are agents held disjoint from the resource in both PROV-O and RiC-O; only role-qualified references are stored here.
- Agent model — organization / corporate body - Issuing organizations, custodians, registers and receiving archives are corporate bodies governed elsewhere; eIDAS attaches seals to legal persons, so the reference must be resolvable.
- Identifier and naming scheme model - Scheme syntax, registration and resolution commitments, as modelled by the DOI system under ISO 26324, are governed outside this model; only scheme, value and assigning authority are carried here.
- Time and calendar model - Retention triggers and validity periods anchor to calendar and working-day rules held elsewhere; this model constrains stored values to RFC 3339 instants with explicit offsets.
- Storage and object-store model - PREMIS separates File and Bitstream objects from the intellectual entity; byte storage, replication and tiering are referenced, not modelled here.
- IANA Media Types registry - Normative value space for the mediaType element on instantiations and exchange packages.
- PRONOM technical registry - Value space for fine-grained format identifiers and rendering dependencies beyond what media types express.
composes
- Message and communication model - Message attachments resolve to records governed here; eIDAS keeps electronic registered delivery services distinct from electronic documents, so transport semantics stay in the communication model.
- DCMI Metadata Terms (2020-01-20) - Descriptive metadata facet applied to every record: title, creator, issued, modified, format, extent, language, accessRights, license, provenance and the version and replacement relations.
aligned
- ISO 15489-1:2016 Records management — Concepts and principles - Vocabulary alignment for records, metadata for records, records systems, records processes and the characteristics of authoritative records; alignment only, no conformance claimed.
- PREMIS Data Dictionary for Preservation Metadata 3.0 - Alignment for object categories, fixity, format, significant properties, storage, and the Event, Agent and Rights entities used by the preservation and audit findings.
- ICA Records in Contexts Ontology 1.1 - Alignment for the record resource versus instantiation split, documentary form and carrier types, and the partitive and provenance relations.
- W3C PROV-O - Alignment for derivation, generation, attribution, association and delegation, and for bundling provenance as an entity in its own right.
- Regulation (EU) No 910/2014 (eIDAS) - Alignment for electronic document, signature and seal tiers, electronic time stamps and validation; the tier vocabulary is EU-specific and other jurisdictions map differently.
- UNCITRAL Model Law on Electronic Commerce (1996) - Alignment for functional equivalence: the criteria under which an electronic instantiation satisfies paper concepts of writing, signature and original.
- C2PA Technical Specification 2.1 - Alignment for asset-level provenance manifests, hard and soft bindings, ingredients and validation, used where content credentials travel with a rendition.
- NARA Universal ERM Requirements v3 and MoReq2010 v1.1 - Alignment for the operating surface: capture, maintenance and use, disposal, transfer, metadata and reporting, plus disposal scheduling and disposal holding as separate services.
neighbor
- WM-REC-015 Archival fonds / collection - Aggregation levels, archival arrangement and multi-level description belong to WM-REC-015. RiC separates Record and RecordSet as distinct classes; this model instantiates the Record side and stores only membership references and the aggregate identifier at time of filing.
- Agent models (person, organization) - PROV-O and RiC-O both keep Agent disjoint from the resource. This model stores role-qualified references (author, approver, signatory, custodian) and the basis of the role assertion, never agent attributes.
- Identifier and naming scheme model - Scheme governance, syntax and resolution commitments (as in the DOI/ISO 26324 social infrastructure) live in the naming model; this model records scheme, value, assigning authority and granularity only.
- Time and calendar model - Calendar systems and period arithmetic live elsewhere; this model constrains time values to RFC 3339 instants with explicit offset and separates event time from observation time.
- Message and communication model - eIDAS treats an electronic registered delivery service as a distinct service from an electronic document. A message is a communication act; its attachment resolves to a record governed here.
- Dataset / data asset model - A dataset governed by a schema is not a record. It becomes a record here only when fixed as an instantiation with fixity, retention and access controls attached.
- File / object storage model - PREMIS distinguishes File and Bitstream Objects from the Intellectual Entity. One record may span many files and one file may carry many records; storage location is a reference, not identity.
What else AI and robots need to interact with it Filled
Identity and identifiers required Filled
- First: the authoritative master-system identifier issued by the system of record, such as a register entry number or an issuing organization's document number.
- Second: a governed global identifier or IRI, such as a DOI under ISO 26324, a Handle, an ARK or a registry-governed IRI with a published persistence commitment.
- Third: a UUID or ULID minted by the adopting Dimension, recorded together with the minting agent and the RFC 3339 minting instant.
- Never an identifier: a date, a title, a file name, a storage path or a content digest. A digest is a fixity value and is identical across duplicate copies, so it cannot denote a record.
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Filled
- A record has a unique identifier, a creator, a capture date, a classification and a retention class.
- Confused with a draft, a copy or rendition of the same record, a file in storage and the dataset or message it was derived from.
Capabilities and actions required Filled
- Assign record identity: Select and bind the identifier that will denote the record for its whole life, following the identity priority.
- Capture or create record: Bring an authored or received information object under recordkeeping control.
- Issue version: Fix a new immutable content state and link it into the version chain.
- Produce instantiation: Create a format-specific or carrier-specific realisation of an existing version.
- Verify fixity: Recompute and compare digests for an instantiation or package against its baseline.
- Apply signature or seal: Bind a signature, seal or attestation to fixed content at a declared assurance tier.
- Timestamp and validate evidence: Obtain a trusted time-stamp token and record a dated validation outcome for a signature or manifest.
- Record custody transfer: Move holding responsibility to another party without breaking the chain of custody.
- Assign retention: Bind the record to a retention class under a named authority and compute when disposition falls due.
- Place or release hold: Suspend or resume disposition for a defined scope of records.
- Execute disposition: Carry out destruction, transfer or permanent retention for records whose period has elapsed.
- Issue certified copy or extract: Produce an attested copy or extract traceable to a named source version.
- Evaluate access request: Decide and record whether a requester may read a record or a projection of it.
- Export exchange package: Assemble a self-describing package of records and their evidence for transfer or publication.
- Assign classification and marking: Assign business class, documentary form, index terms and confidentiality or security marking from authorized schemes.
- Register in custodial register: Create an existence-level register entry with entry number, registered-at and custodian, without transferring ownership.
- Migrate or convert: Create a successor instantiation in another format or medium, record the PREMIS/OAIS event, and keep the source instantiation unless disposition authorizes its destruction.
- Verify authenticity and integrity: Recompute fixity, validate signatures or content credentials, and record an assessment of authenticity, integrity and usability with observation time.
Hazards and failure modes required Filled
- Tampering or silent loss of evidential value.
- Unlawful disclosure of personal or confidential content.
- Irreversible disposition by error.
Standards and interfaces required Filled
- ISO 16175 records processes and functionality in software.
- ISO 14721 Open Archival Information System (OAIS).
- PREMIS Data Dictionary for preservation metadata.
- ICA Records in Contexts (RiC-CM and RiC-O).
Context of use required Filled
- Signature assurance tiers (simple, advanced, qualified) and seal semantics are eIDAS-specific to the EU and EEA; the US (ESIGN/UETA) and other jurisdictions use different tiering, and the model carries a tier code rather than asserting a universal ladder.
- Disposition authority, general records schedules, accession and transfer semantics are drawn from US federal practice and UK archival practice; other jurisdictions place these powers differently.
- PRONOM PUIDs are a de facto rather than universal format registry, originating with The National Archives (UK).
- Retention periods, hold triggers and destruction verification standards are jurisdiction- and sector-specific; no default period is asserted anywhere in the model.
- Access and exemption regimes vary by jurisdiction; the model carries markings, bases and review dates but never a statutory interpretation.
- Register publicity conventions differ sharply between civil-law public registers and common-law custodial registers; the model records publicity status as data.
- ISO 15489/23081 and RiC-CM are treated as the international backbone.
- US 36 CFR/44 U.S.C. definitions apply only when the adopting Dimension asserts US Federal jurisdiction.
- eIDAS signature levels apply when the adopting Dimension asserts EU/EEA trust-service law.
- C2PA is optional and currently most relevant to media and generated-content assets in adopting markets.
- Language of description defaults to the record's content language; multilingual titles are allowed via localized strings.
- RFC 3339 timestamps with explicit offset or Z are required even where local records law still uses date-only cutoffs; date-only values should be normalized with an explicit policy, not inferred.
Sources Filled
- ISO 15489-1:2016 Information and documentation — Records management — Part 1: Concepts and principles - International Organization for Standardization
- DCMI Metadata Terms - Dublin Core Metadata Initiative
- PROV-O: The PROV Ontology - World Wide Web Consortium
- RFC 3339: Date and Time on the Internet: Timestamps - Internet Engineering Task Force
- RFC 3161: Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) - Internet Engineering Task Force
- PREMIS Data Dictionary for Preservation Metadata, Version 3.0 - Library of Congress (PREMIS Editorial Committee)
- Regulation (EU) No 910/2014 (eIDAS), Article 3 — Definitions - European Union (text as published by The National Archives, legislation.gov.uk)
- International Council on Archives Records in Contexts Ontology (ICA RiC-O) version 1.1 - International Council on Archives (EGAD)
- Media Types registry - Internet Assigned Numbers Authority
- C2PA Technical Specification - Coalition for Content Provenance and Authenticity
- Universal Electronic Records Management (ERM) Requirements - U.S. National Archives and Records Administration
- Metadata guidance tables for transfer of permanent electronic records (case file appendix) - U.S. National Archives and Records Administration
- UNCITRAL Model Law on Electronic Commerce (1996) with additional article 5 bis (1998) - United Nations Commission on International Trade Law
- PRONOM technical registry - The National Archives (United Kingdom)
- What is a DOI? (DOI system and ISO 26324) - DOI Foundation
- MoReq2010: Modular Requirements for Records Systems, Volume 1 — Core Services & Plug-in Modules - DLM Forum Foundation
- ISO 23081 Metadata for records (ISO 23081-1:2017 principles; ISO 23081-2:2021 conceptual and implementation issues) - ISO/TC 46/SC 11 Archives/records management
- PREMIS Data Dictionary for Preservation Metadata, Version 3.0 — Hierarchical Listing of Semantic Units - Library of Congress / PREMIS Editorial Committee
- Records in Contexts – Conceptual Model (RiC-CM) Version 1.0 - International Council on Archives, Expert Group on Archival Description
- ISO 14721:2025 Space Data System Practices — Reference model for an Open Archival Information System (OAIS) - ISO / CCSDS
- 36 CFR § 1220.18 — Definitions applicable to Federal records management - United States National Archives and Records Administration (as published in the e-CFR / LII)
- C2PA Technical Specification — Content Credentials - Coalition for Content Provenance and Authenticity
- JIS X 0902-1:2019 Information and documentation — Records management — Part 1: Concepts and principles (identical to ISO 15489-1:2016) - Japanese Industrial Standards Committee
- eSignature FAQ — eIDAS electronic signatures, seals and qualified timestamps - European Commission
Open questions
- Electronic transferable records under UNCITRAL MLETR: control, singularity and guaranteed uniqueness. Claude marks it a declared gap and Grok does not model it; likely a sibling model rather than an addition here.
- Conflict-of-laws rule set for records created in one jurisdiction, held in a second and disclosed in a third. Both providers carry jurisdiction as a field with no sourced resolution rule; keep marked as a gap, never as canonical.
- GDPR Article 17 erasure versus authorised retention duty: fetch the primary text and decide whether the conflict is carried as an unresolved question on the record or delegated to a rights/consent sibling model. Neither provider retrieved it.
- Last-copy and multi-instantiation destruction semantics: when destruction of one instantiation does or does not destroy the record identity, and how the tombstone reflects partial destruction. Grok raises it; the base has no rule.
- OAIS ISO 14721:2025 alignment: representation information for a designated community and SIP/AIP/DIP package roles — decide align-versus-reference against the base exchange-packaging finding rather than importing package structure.
- Legal-hold primary schemas not retrieved by either provider: DoD 5015.02-STD, the MoReq2010 hold module in detail, and FRCP 37(e). Needed before hold scope, overlapping holds and release semantics can be stated as sourced rather than pattern-based.
- Requires/isRequiredBy and references/isReferencedBy dependency relations between records (an annex, schema or referenced instrument needed to interpret the record) — evaluate as question-level additions to the content-and-components layer.
- Declared-versus-measured extent (bytes, pages, duration) as a validation check on an instantiation; currently implied by the base coverage checklist but present in no base question.
- InterPARES authenticity requirements and ISO 16175 / 14641 / 17068, none retrieved by either provider, as corroboration for the accepted authoritative-record-characteristics finding.
- Conservation treatment and environmental storage conditions for analogue carriers.
- Electronic transferable records: control, singularity and the guaranteed-uniqueness requirement.
- Cryptographic key lifecycle and hardware security module operation underpinning long-term signature preservation.
- Appraisal methodology (macro-appraisal, functional analysis) that produces retention schedules in the first place; the model consumes schedules but does not derive them.
- Vital-records designation and disaster-recovery prioritisation.
- Rendering fidelity and accessibility conformance of renditions.
- Full-text indexing, retrieval and relevance semantics.
- Cost, storage tiering and the economics of permanent retention.
- MoReq2010 / Modular Requirements for Records Systems not fetched as primary text.
- DoD 5015.02-STD Electronic Records Management Software Application Design Criteria not fetched.
- ISO 16175 (records in business systems), ISO 14641 (electronic archiving) and ISO 17068 (trusted third party repository) not fetched.
- ISO 19005 PDF/A, METS, BagIt (RFC 8493) and PRONOM/DROID as format-identification practice not modelled in depth.
- InterPARES authenticity requirements not fetched.
- EDRM / FRCP 37(e) litigation-hold primary texts not fetched; holds rest on ISO unauthorized-destruction protection plus 36 CFR unscheduled freeze.
- Vital records / business-continuity copies, encrypted or DRM-inhibited objects (PREMIS inhibitors) only lightly touched.
- Database, GIS and other dynamic system-of-record snapshots as records: in ISO 15489 scope by principle, under-specified here.
- Spoken, audiovisual and 3D records beyond Instantiation/format.
- National variants beyond US CFR, eIDAS and JIS identical adoption (e.g. Australian Archives Act, UK TNA, China GB/T 18894) not retrieved.
- Blockchain or distributed-register identity as an emerging identifier class not given primary support.
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-rec-001-document-record/spec.yaml, ver-cy/world-models/card-supplements/wm-rec-001-document-record.json