World Models · public research draft

Document / Record

Give agents one format-neutral vocabulary for treating a document as a governed record: a stable information object whose identity outlives any file, carried through immutable versions and multiple instantiations, made relyable by signatures, timestamps and custody evidence, and disposed of under an authorised retention regime.

AI YAMLAGENTS.mdResearch evidence
Research draft. The Claude + Grok synthesis is public for review and use with caution. It passed structural validation but is not yet a canonical Vercy release because the source and coverage holds below remain open.
Catalogue IDWM-REC-001
Version0.3.0-research.1
Previous version-
Typeaggregate
ValidationPassed
Synthesis digestsha256:9227cb167a395b6a…
24Sources
6Bundles
13Layers
29Findings
108Questions
27Artifacts
Format-independent logical structure

Bundles → Layers → Findings → Questions + Artifacts

identity-form-and-classificationIdentity, documentary form and classification2 layers

What the record is, how it is named and referenced, what documentary genre it belongs to, and where it sits in a business classification scheme and archival aggregation.

identity-and-designationIdentity and designation2 findings

The stable identifier of the record as an information object and the human-facing titles and reference numbers layered on top of it.

record-identity-anchor

Record identity anchor

The identifier that denotes the record independently of any file, version or rendition, its scheme, its granularity and its non-reuse guarantee.

Questions
  1. Which system is the authoritative master for this record's identifier and from which registered scheme is the value drawn?identity
    Expected answer
    • master system reference
    • identifier scheme name or IRI
    • identifier value
    • assigning authority reference
  2. Does the identifier denote the record, one version, or one instantiation?definition
    Expected answer
    • granularity code (record | version | instantiation)
    • version identifier pattern
    • instantiation identifier pattern
  3. What guarantees that the identifier is never reused after disposition or system migration?constraint
    Expected answer
    • non-reuse policy statement
    • tombstone retention rule
    • migration mapping table reference
  4. Which legacy or alternate identifiers exist and on what basis are they asserted equivalent?interoperability
    Expected answer
    • alternate identifier list with scheme
    • equivalence assertion basis
    • assertion datetime
designation-and-reference-numbers

Designation and reference numbers

Titles, alternative and translated titles, and the official reference numbers quoted on the face of the record, kept strictly distinct from identity.

Questions
  1. What is the official title of the record, in which language and script is it recorded, and who set it?definition
    Expected answer
    • title string
    • language code
    • script code
    • title assigning agent
  2. Which reference numbers appear on the face of the record and which authority allocated each?identity
    Expected answer
    • reference number value
    • allocating authority
    • allocation context
  3. How are superseded or translated titles retained without ever being treated as identifiers?constraint
    Expected answer
    • alternative title list
    • validity period per title
    • identifier-vs-title separation rule
documentary-form-and-classificationDocumentary form and classification2 findings

The genre of the record and its placement in a business classification scheme and archival aggregation, which drive the rules that later apply to it.

documentary-form

Documentary form and genre

The documentary form the record takes (contract, certificate, invoice, minutes, licence) typed against a controlled vocabulary, and the rules that follow from that form.

Questions
  1. What documentary form does this record take and from which controlled vocabulary is the term drawn?classification
    Expected answer
    • documentary form term
    • vocabulary IRI and version
    • term notation
  2. Which obligations, signature requirements or retention consequences follow automatically from that form?requirement
    Expected answer
    • rule references triggered by form
    • mandatory signature level
    • default retention class
  3. Can one record carry more than one documentary form, such as a certificate inside a covering letter?composition
    Expected answer
    • primary form
    • secondary form list
    • component-to-form mapping
  4. Who approves additions to the form vocabulary and how are retired terms handled?authority
    Expected answer
    • vocabulary owner
    • approval process reference
    • deprecation date and replacement term
Artifacts
  • Documentary form vocabularyThe governed term list of documentary forms, with notations, definitions, deprecations and the rules each form triggers.
classification-and-aggregation

Business classification and aggregation membership

Filing of the record under a classification class and its membership in aggregations, with the boundary to the archival aggregation model held explicitly.

Questions
  1. Under which classification class is the record filed and which version of the scheme was in force at filing?classification
    Expected answer
    • class notation
    • scheme identifier and version
    • filing datetime
  2. Which aggregations does the record belong to and is membership exclusive?composition
    Expected answer
    • aggregation references
    • membership exclusivity flag
    • position within aggregation
  3. When the scheme is reorganised, is the historic class retained alongside the new one?temporal
    Expected answer
    • historic class with validity period
    • reclassification event reference
    • reclassifying agent
  4. If more than one class applies, which one determines retention and access?exception
    Expected answer
    • precedence rule statement
    • prevailing class
    • conflict resolution record
Artifacts
  • Business classification scheme (file plan)The hierarchical scheme of classes under which records are filed, with effective dates, retention linkage and superseded versions retained.
content-versions-and-manifestationsContent, versions and manifestations3 layers

What the record says, the immutable states its content passes through, and the format-specific and carrier-specific realisations that make it readable.

content-and-componentsContent and components1 findings

The body of the record, its structural parts, attachments and the properties that must survive any transformation.

content-structure-and-components

Content structure, components and completeness

Which parts make up the complete record, which are essential to its meaning, and how completeness is verified at capture.

Questions
  1. Which components make up the complete record and which of them are essential rather than incidental?composition
    Expected answer
    • component list with roles
    • essential flag per component
    • ordering or structural map
  2. Which significant properties must be preserved for the record to remain usable and understandable?quality
    Expected answer
    • significant property list
    • measurement method
    • acceptance threshold
  3. In which languages is the content expressed and which language version is authoritative for interpretation?definition
    Expected answer
    • content language codes
    • authoritative language
    • translation relationship references
  4. How is completeness verified before the record is declared captured?validation
    Expected answer
    • completeness check method
    • checked-by agent
    • check outcome and datetime
Artifacts
  • Record component manifestItemised inventory of the components constituting one version of the record, with roles, order, essentiality and per-component digests.
versions-and-instantiationsVersions and instantiations3 findings

The immutable version chain of content states and the multiple physical or digital instantiations that realise each state.

version-chain-and-immutability

Version chain and immutability

How a content state is fixed, how versions supersede and amend one another, and the prohibition on editing an issued version in place.

Questions
  1. Which event fixes a version and makes it immutable, and who is competent to trigger it?event
    Expected answer
    • fixing event type
    • triggering agent and authority
    • event datetime
  2. Which version is currently authoritative and which versions does it supersede or amend?state
    Expected answer
    • current version identifier
    • supersession links
    • amendment links
  3. How are drafts distinguished from issued versions for retention and access purposes?lifecycle
    Expected answer
    • version state code
    • draft retention rule
    • draft access rule
  4. What reason, authority and change description are recorded for each new version?provenance
    Expected answer
    • change note
    • authorising agent
    • change basis reference
Artifacts
  • Version historyAppend-only chain of version entries with sequence, fixing event, issuing agent, change note and supersession links.
instantiation-copy-and-original-status

Instantiation, copy and original status

Format-specific and carrier-specific realisations of a version, and the legal distinction between the original of record, duplicates, certified copies and extracts.

Questions
  1. Which instantiation is the original of record and where is it held?identity
    Expected answer
    • instantiation identifier
    • original-of-record flag
    • storage location reference
    • holding agent
  2. Is a given instantiation a faithful rendition, a derivative, a certified copy or an extract, and who attests it?evidence
    Expected answer
    • instantiation role code
    • attesting authority
    • attestation reference
  3. What criteria make a digitised surrogate acceptable in place of an analogue original?requirement
    Expected answer
    • integrity criterion statement
    • capture specification
    • authority permitting substitution
  4. How are two instantiations of the same version proven to carry the same content?validation
    Expected answer
    • comparison method
    • significant-property comparison result
    • verification datetime
Artifacts
  • Certified copy or extract attestationStatement by a competent authority that a named instantiation is a true copy or a faithful extract of a named source, with the scope of what was omitted.
supersession-between-records

Supersession between records

Dublin Core replaces/isReplacedBy model a related resource that supplants another. A new record may supersede an older record (policy, specification, licence) without being a version of the same identity. Supersession does not by itself authorize destruction of the replaced record; disposition remains a separate control.

Questions
  1. Which earlier record(s) does this record replace, from when, and is the older identity retained?relationship
    Expected answer
    • Array of {record-ref, effective-at RFC 3339, older-identity-retained boolean}.
  2. Has this record been replaced, and is it still retained under its schedule?state
    Expected answer
    • superseded-by ref, effective-at, retention still in force boolean.
  3. Is the successor a new version of the same identity or a distinct record that replaces this one?definition
    Expected answer
    • Enum relation-kind: same-identity-version | distinct-record-replaces.
Artifacts
  • Supersession linkTyped relation between two record identities with effective time.
format-fixity-and-preservationFormat, fixity and preservation2 findings

Technical identification of instantiations, the environment needed to render them, and the integrity and preservation controls applied over time.

format-identification-and-environment

Format identification and rendering environment

How each instantiation's format is identified against registries and what software and hardware environment is required to render it.

Questions
  1. Which registered media type and which format-registry identifier apply to this instantiation?measurement
    Expected answer
    • media type from the IANA registry
    • format registry identifier such as a PRONOM PUID
    • format version
  2. How was the format determined — declared by the producer or identified by a tool?provenance
    Expected answer
    • identification method
    • tool name and version
    • identification confidence
  3. What environment is required to render the instantiation faithfully?requirement
    Expected answer
    • software dependency list with versions
    • hardware or codec dependency
    • font or external resource dependency
  4. What is the obsolescence risk for this format and what migration or emulation path is planned?decision
    Expected answer
    • risk assessment and date
    • planned action
    • action owner and review date
Artifacts
  • Format characterisation reportTool-produced technical description of an instantiation: identified format, version, validity, well-formedness, extracted properties and dependencies.
fixity-and-preservation-actions

Fixity and preservation actions

Baseline digests, verification history, declared preservation level and the actions applied to keep instantiations readable, including those that change bytes.

Questions
  1. Which algorithm and digest value were recorded at capture, and by which agent?evidence
    Expected answer
    • algorithm name
    • digest value
    • computing agent
    • computation datetime
  2. When was fixity last verified, at what frequency, and what was the outcome?measurement
    Expected answer
    • last verification datetime
    • verification schedule
    • outcome code and detail
  3. Which preservation actions have been applied and did any of them change the bytes?process
    Expected answer
    • action type and datetime
    • input and output instantiation references
    • byte-change flag
  4. What happens when a fixity check fails, and who is notified?exception
    Expected answer
    • incident record reference
    • recovery source
    • notification recipients and deadline
Artifacts
  • Fixity manifestSet of digests covering the instantiations and artifacts of a record or package, with algorithms, computation instants and the computing agent.
agency-authority-and-issuanceAgency, authority and issuance2 layers

Who is responsible for the record, who owns and who keeps it, and the act of issuing it under a mandate and entering it into a register.

agents-and-responsibilityAgents, ownership and custody2 findings

Role-qualified references to the agents who made, approved, own and keep the record.

authorship-and-responsibility-roles

Authorship and responsibility roles

Who authored, contributed to, approved and was addressed by the record, expressed as role-qualified references rather than embedded agent descriptions.

Questions
  1. Which agent is the author of record and which agents merely contributed?ownership
    Expected answer
    • author reference
    • contributor references with contribution type
    • attribution basis
  2. Who approved or authorised issue, and under what delegation of authority?authority
    Expected answer
    • approver reference
    • delegation instrument reference
    • approval datetime
  3. Who are the intended addressees or recipients, and does that constrain access?relationship
    Expected answer
    • addressee references
    • distribution list reference
    • access consequence
  4. How is a role recorded when the responsible agent cannot be identified?evidence
    Expected answer
    • unknown-agent placeholder policy
    • evidence supporting the role assertion
    • confidence statement
ownership-custody-and-stewardship

Ownership, custody and stewardship

The separation between the record owner and the custodian or registrar acting on the owner's behalf, and the terms limiting custodial power.

Questions
  1. Who owns the record and who currently has custody of it?ownership
    Expected answer
    • owner reference
    • custodian reference
    • custody start datetime
  2. What may the custodian not do — can they widen access, migrate formats or dispose?authority
    Expected answer
    • permitted custodial actions
    • prohibited actions
    • escalation path to the owner
  3. How and when does ownership itself transfer, and what evidence is required?lifecycle
    Expected answer
    • ownership transfer event
    • transferring and receiving parties
    • instrument evidencing transfer
Artifacts
  • Custody or deposit agreementInstrument setting out what the custodian may and may not do with the record, the service levels and the conditions for return or transfer.
issuance-and-registrationIssuance and registration1 findings

The act of issuing the record under a mandate in a jurisdiction, and its entry into a custodial or public register.

issuance-mandate-and-registration

Issuance, mandate and register entry

The legal basis and jurisdiction under which the record was issued, and the register entry that anchors it in a custodial system.

Questions
  1. Under which mandate, statute or delegated authority was the record issued?authority
    Expected answer
    • mandate reference
    • issuing authority reference
    • authority citation
  2. In which jurisdiction and at which place was it issued, and does that determine the applicable rules?spatial
    Expected answer
    • jurisdiction code
    • place of issue reference
    • governing law statement
  3. Is the record registered, in which register, under what entry number, and at what instant?identity
    Expected answer
    • register reference
    • entry number
    • registration instant
    • registering agent
  4. Is the register public, and what is disclosed at existence level when content is withheld?access
    Expected answer
    • register publicity status
    • existence-level field list
    • withholding basis
Artifacts
  • Register entry or registration certificateThe custodial or public register line that anchors the record, with entry number, registering authority, registration instant and the existence-level fields disclosed.
authenticity-and-evidentiary-valueAuthenticity and evidentiary value2 layers

Why the record can be relied on: signatures and seals bound to fixed content, trusted timestamps, dated validation outcomes, derivation provenance and an unbroken chain of custody.

signatures-and-validationSignatures, seals and validation evidence3 findings

Signature and seal objects bound to specific content, the timestamps that fix their moment, and the dated results of validating them.

signature-seal-and-attestation

Signature, seal and attestation

Signatures, seals and attestations applied to a version or instantiation, their assurance tier, their signatory and exactly what content each binds.

Questions
  1. What signature or seal type was applied and at which assurance tier?evidence
    Expected answer
    • signature type code
    • assurance tier such as simple, advanced or qualified
    • applicable legal regime
  2. Which exact content does each signature bind — a version, an instantiation, or a byte range?composition
    Expected answer
    • bound content reference
    • bound digest and algorithm
    • binding scope description
  3. Who is the signatory or sealing legal person, and on which certificate or credential does the signature rest?identity
    Expected answer
    • signatory reference
    • certificate identifier and issuer
    • credential type
  4. What must hold for the signature to have legal effect in the governing jurisdiction?requirement
    Expected answer
    • required tier for the record type
    • creation device requirement
    • jurisdiction-specific condition
Artifacts
  • Signature, seal or attestation objectThe signature itself — detached or embedded — carrying the bound digest, the signing credential chain and the claimed signing time.
timestamping-and-validation-evidence

Timestamping and validation evidence

Trusted time-stamp tokens proving existence at a time, validation outcomes recorded with their own validation instant and policy, and the renewal of evidence before algorithms weaken.

Questions
  1. Is there a trusted time-stamp token binding the content to a time, and which authority issued it?evidence
    Expected answer
    • token reference
    • issuing authority identity
    • token serial number
    • generation time and accuracy
  2. What was the validation outcome, at which validation instant, and under which validation policy?validation
    Expected answer
    • outcome code
    • validation instant
    • policy identifier
    • revocation status checked
  3. How is the evidence renewed before its algorithms or certificates weaken?temporal
    Expected answer
    • renewal schedule
    • algorithm sunset date
    • renewal event references
  4. Which provenance manifest, if any, travels with the rendered asset, and does it survive rendition?interoperability
    Expected answer
    • manifest reference
    • binding type (hard or soft)
    • survival behaviour across renditions
Artifacts
  • Trusted time-stamp tokenProof-of-existence token binding a message imprint hash, algorithm, authority-allocated serial number and generation time with stated accuracy.
  • Signature validation reportDated statement of the outcome of validating a signature, seal or provenance manifest, naming the policy, trust anchors and revocation data used.
authoritative-record-characteristics

Authoritative record characteristics

ISO 23081 states that metadata must support assertions of integrity, authenticity, reliability and usability over time in business context. ISO 15489 requires records to remain authoritative through those characteristics: authentic (what it purports to be, created or sent by the purported agent at the purported time), reliable (trusted full and accurate content of the transaction), integrity (complete and unaltered), usable (locatable, retrievable, presentable, interpretable). These are assessed properties with evidence, not decorative flags.

Questions
  1. Can this record be shown to be what it purports to be, created or sent by the purported agent at the purported time, and on what evidence?evidence
    Expected answer
    • Boolean plus evidence refs (signature, custody event, register entry, C2PA manifest) and assessed-at RFC 3339.
  2. Has integrity been maintained (complete, unaltered since capture), and what unauthorized change if any was detected?quality
    Expected answer
    • integrity-status; last-fixity-outcome; missing-rendition flags; incident refs.
  3. Can the record still be located, retrieved, presented and interpreted by the intended community?quality
    Expected answer
    • locatable boolean, retrievable boolean, presentable boolean, interpretable boolean, representation-info-gap notes.
Artifacts
  • Authoritativeness assessment noteRecorded assessment with evidence refs (fixity, signature, custody, representation info) and assessment time. Pure assessment metadata may be inline if evidence artifacts live on related findings.
provenance-and-custodyProvenance and chain of custody2 findings

Where the record came from and who held it at every moment between creation and now.

derivation-and-provenance-graph

Derivation and provenance graph

The activities that generated the record, the sources it derives from, and the agents associated with each generating activity.

Questions
  1. Which activity generated this record or version, and when did it start and end?provenance
    Expected answer
    • activity reference and type
    • start instant
    • end instant
  2. Which prior records was it derived from, and is the derivation a revision, an extract or a quotation?relationship
    Expected answer
    • source record references
    • derivation type
    • derivation scope
  3. Which agent was associated with each generating activity, and on whose behalf did they act?ownership
    Expected answer
    • associated agent reference
    • delegation chain
    • role in the activity
  4. Where a machine or model produced content, what tool, version and parameters are recorded?evidence
    Expected answer
    • software agent reference and version
    • parameters or prompt reference
    • human oversight statement
Artifacts
  • Provenance bundle or content credential manifestA named set of provenance descriptions covering entities, activities, agents and derivations, or an asset-embedded manifest with assertions, ingredients and bindings.
chain-of-custody-and-transfer

Chain of custody and hand-over

The gapless sequence of custody intervals, hand-over receipts and integrity checks that allows the record to be relied on as evidence.

Questions
  1. Who held the record over each interval and are there any unexplained gaps?temporal
    Expected answer
    • custody interval list with holder
    • gap detection result
    • explanation for each gap
  2. What receipt or acknowledgement evidences each hand-over?evidence
    Expected answer
    • receipt reference
    • acknowledging party
    • receipt instant
  3. Was integrity verified at dispatch and again at receipt, and by whom?validation
    Expected answer
    • pre-transfer digest and result
    • post-transfer digest and result
    • verifying agents
  4. How is the chain kept intact when a system migration rewrites storage or re-encodes content?exception
    Expected answer
    • migration event reference
    • identifier mapping
    • integrity re-baselining statement
Artifacts
  • Custody transfer receiptSigned acknowledgement of hand-over naming both parties, the records covered, the integrity proof presented and the instant custody changed.
state-time-and-recordkeeping-controlState, time and recordkeeping control2 layers

The status the record is in, the events that moved it there, the time anchors it carries, and the retention, hold and disposition regime that decides its end.

status-lifecycle-and-timeStatus, lifecycle events and time4 findings

Controlled status values, the append-only history of what happened, and the distinct time anchors the record carries.

record-status-and-transitions

Record status and permitted transitions

The controlled status vocabulary, which transitions are permitted from each state, who may authorise them, and how withdrawal differs from destruction.

Questions
  1. What is the record's current status and since which instant has it held that status?state
    Expected answer
    • status code
    • status-since instant
    • status-setting agent
  2. Which transitions are permitted from the current status and who may authorise each?lifecycle
    Expected answer
    • permitted target statuses
    • authorising role per transition
    • required evidence per transition
  3. Is withdrawal or revocation distinct from destruction, and does a revoked record remain discoverable?exception
    Expected answer
    • withdrawal semantics statement
    • discoverability rule for withdrawn records
    • revocation notice reference
lifecycle-events-and-audit-trail

Lifecycle events and audit trail

The append-only history of everything done to and with the record, using controlled event types with actor, outcome, event time and separately recorded observation time.

Questions
  1. Which event types are recorded and from which controlled vocabulary are they drawn?event
    Expected answer
    • event type vocabulary reference
    • event type list in use
    • mapping to external event vocabularies
  2. Who performed each event, with what outcome and what detail?provenance
    Expected answer
    • event agent reference and role
    • outcome code
    • outcome detail note
  3. Is the trail append-only and how is its own integrity protected against tampering?security
    Expected answer
    • append-only enforcement mechanism
    • trail digest or chaining scheme
    • independent custody of the trail
  4. How long is the audit trail retained relative to the record, and does disposition erase it?retention
    Expected answer
    • trail retention period
    • survival-after-disposition rule
    • separate storage location
Artifacts
  • Event history and audit trailAppend-only sequence of event entries covering every action on the record, each with type, agent, outcome, event time and recording time.
temporal-anchors-and-validity

Temporal anchors and validity periods

The distinct time anchors a record carries — created, issued, effective, expiry, received, observed — their precision, and the rule separating event time from ingestion time.

Questions
  1. Which datetime is the legally or operationally decisive one for this record type?temporal
    Expected answer
    • operative anchor name
    • its value
    • the rule making it decisive
  2. Over what period is the record valid or effective, and may the period be open-ended?temporal
    Expected answer
    • effective-from instant
    • effective-to instant or open-ended marker
    • period basis
  3. How are event time and observation or ingestion time kept distinct in every record of time?provenance
    Expected answer
    • event time field
    • observation time field
    • separation enforcement rule
  4. How are dates of unknown precision or unknown local offset recorded?exception
    Expected answer
    • precision qualifier
    • unknown-offset convention used
    • uncertainty note
document-versus-record

Document versus captured record

ISO 15489 applies to records regardless of structure or form and treats capture into a records system as the act that places identified information under records controls. RiC-CM defines a Record as discrete information content formed and inscribed, at least once, on any persistent recoverable carrier by an agent in the course of activity. US 36 CFR 1220.18 / 44 U.S.C. 3301 additionally excludes extra copies kept only for reference, library or museum materials for exhibit, and personal files. This model stores a record-status on the object: document-not-captured, captured-record, nonrecord-copy, or jurisdiction-specific Federal-record, rather than splitting into two meta-models.

Questions
  1. Has this object been captured as a record, and under which jurisdiction or policy is that determination made?classification
    Expected answer
    • Enum record-status; optional jurisdiction code; policy or statute citation; determined-by agent ref; determined-at RFC 3339.
  2. If it is a nonrecord, extra copy or personal file, what is the excluding criterion?classification
    Expected answer
    • Enum nonrecord-reason plus free-text justification and ownership (agency versus individual).
  3. Who has authority to determine record status when systems or staff disagree?authority
    Expected answer
    • Agent or role ref plus cited mandate. For US Federal records, NARA determination is binding per the Federal Records Act as reflected in 36 CFR.
Artifacts
  • Capture or nonrecord declarationThe decision record that this object is or is not managed as a record, with authority and time.
retention-disposition-and-holdsRetention, disposition and holds3 findings

The authorised schedule that decides the record's fate, the suspensions that override it, and the evidence that survives execution.

retention-schedule-and-authority

Retention class and disposition authority

The retention class assigned to the record, the instrument authorising it, the trigger that starts the clock and the action due at the end.

Questions
  1. Which retention class applies and under which authority instrument and citation?authority
    Expected answer
    • retention class notation
    • authority instrument reference
    • citation string
    • jurisdiction
  2. What event triggers the retention clock and how is that trigger detected?event
    Expected answer
    • trigger event type
    • trigger detection mechanism
    • trigger occurrence instant
  3. Is the record permanent or temporary, and what disposition action falls due at the end of the period?decision
    Expected answer
    • permanent or temporary flag
    • retention period
    • disposition action code
    • computed due date
  4. When two schedules apply to the same record, which one prevails?exception
    Expected answer
    • precedence rule
    • prevailing schedule reference
    • conflict resolution record
Artifacts
  • Retention schedule or disposition authority instrumentThe authorised schedule mapping classes to trigger events, periods, permanence and disposition actions, with its jurisdiction and period of force.
holds-and-suspension

Holds and disposition suspension

Legal holds and other suspensions that override retention schedules until explicitly released, and the mechanism that prevents automated disposal of held records.

Questions
  1. What is the scope of the hold — this record, its aggregation, or a query-defined set resolved at a moment in time?composition
    Expected answer
    • scope definition
    • resolved record set with resolution instant
    • scope re-evaluation rule
  2. Who placed the hold, under what proceeding or authority, and when?authority
    Expected answer
    • placing agent
    • proceeding or authority reference
    • placement instant
  3. What must be true before the hold can be released and disposition resumed?constraint
    Expected answer
    • release conditions
    • releasing authority
    • release instant and evidence
  4. How is hold state surfaced so that no automated process can dispose of a held record?security
    Expected answer
    • enforcement point description
    • hold check in the disposition function
    • failure mode if the check is unavailable
Artifacts
  • Legal hold noticeInstrument placing or releasing a hold, naming the scope, the basis, the issuing authority and the instants of placement and release.
disposition-execution-and-evidence

Disposition execution and surviving evidence

Carrying out destruction, transfer or permanent retention, and the evidence and tombstone that outlive the record itself.

Questions
  1. Who authorised the disposition and was the absence of any hold verified at that moment?authority
    Expected answer
    • authorising agents (at least two)
    • hold check result and instant
    • authority citation applied
  2. What method was used and is it verifiable as irreversible for the carrier concerned?process
    Expected answer
    • destruction or transfer method
    • verification method
    • verifying agent
  3. What evidence survives destruction and which metadata fields are kept as a tombstone?retention
    Expected answer
    • surviving evidence artifact references
    • tombstone field list
    • tombstone retention period
  4. For transfer, what accession identifier and integrity proof did the receiving body return?interoperability
    Expected answer
    • accession identifier
    • receiving body reference
    • integrity proof returned
    • acceptance instant
Artifacts
  • Disposition certificateSigned evidence that a named set of records was destroyed under a named authority, listing identifiers, method, authorisers and the execution instant.
  • Transfer and accession manifestInventory of records transferred to another custodian or to permanent archives, with digests, counts, transfer instant and the accession returned.
access-rights-and-interoperabilityAccess, rights and interoperability2 layers

Who may see what, on what legal footing content may be reused, and how the record and its evidence move between systems without losing meaning.

access-and-rightsAccess, security marking and rights2 findings

Markings and decisions controlling who may read the record, and the intellectual-property and personal-data constraints on reuse.

access-conditions-and-security-marking

Access conditions and security marking

The security marking and access restriction status carried by the record, the statutory regime behind them, and the recorded decisions on individual requests.

Questions
  1. What security marking and access restriction status does the record carry, and who set them?access
    Expected answer
    • security marking code
    • access restriction status
    • setting agent and instant
  2. Which statutory access or exemption regime applies, and for how long does the restriction run?authority
    Expected answer
    • regime reference
    • exemption citation
    • restriction review or expiry date
  3. What is disclosed at existence level when the content itself is withheld?privacy
    Expected answer
    • existence-level field list
    • neither-confirm-nor-deny rule if any
    • withholding basis
  4. How are grants, denials and emergency access events recorded and reviewed?evidence
    Expected answer
    • decision record fields
    • reviewing role
    • notification obligations and deadlines
Artifacts
  • Access decision recordEntry recording one access request: requester, purpose, requested scope, decision, decision-maker, reasons and the RFC 3339 decision instant.
rights-licensing-and-personal-data

Rights, licensing and personal data

Who holds rights in the content, under what licence it may be reused, and what personal data within it constrains processing and release.

Questions
  1. Who holds rights in the content and under which licence may it be reused?ownership
    Expected answer
    • rights holder reference
    • licence identifier or IRI
    • permitted uses and restrictions
  2. Does the record contain personal or special-category data, and on what lawful basis is it processed?privacy
    Expected answer
    • personal data categories present
    • lawful basis statement
    • data subject rights applicable
  3. What redactions produced the releasable derivative, and is the unredacted source preserved intact?process
    Expected answer
    • redaction scope and basis per passage
    • derivative instantiation reference
    • source preservation confirmation
Artifacts
  • Rights statement or licence instrumentStatement of rights held and the terms under which the content may be reused, redistributed or published.
  • Redaction and release logRecord of every redaction applied to produce a releasable derivative, with the passage affected, the basis and the approving agent.
interoperability-and-exchangeInteroperability and exchange2 findings

Declared mappings to external metadata standards and the packaging and projection rules for moving records between systems.

metadata-alignment-and-conformance

Metadata alignment and conformance evidence

Which external standards the record's metadata is mapped to, where mappings lose information, and what evidence is required before any conformance claim is made.

Questions
  1. Which external standards is this metadata mapped to, and at which version of each?interoperability
    Expected answer
    • target standard identifiers
    • target versions
    • mapped element pairs
  2. Where does a mapping lose information or contradict another target, and how is the loss recorded?quality
    Expected answer
    • lossy mapping list
    • contradiction description
    • mitigation or annotation applied
  3. What evidence supports any conformance claim, and who validated it?validation
    Expected answer
    • conformance claim text
    • evidence artifact reference
    • validating party and date
Artifacts
  • Metadata crosswalk specificationElement-by-element mapping between this model and a named external standard version, marking lossy and unmappable elements.
exchange-packaging-and-projections

Exchange packaging and projections

How a record and its evidence are packaged for transfer or publication, and how each projection deliberately omits parts without breaking reconstructability.

Questions
  1. What package structure and manifest are used, and how is package integrity proven on arrival?interoperability
    Expected answer
    • package profile identifier
    • manifest structure
    • package-level digest and algorithm
  2. Which projection is being served and which fields does it deliberately omit?access
    Expected answer
    • projection name
    • included field list
    • omitted field list and reason
  3. How does a receiving system reconstruct identity, version chain, fixity and events from the package alone?validation
    Expected answer
    • identity mapping in the package
    • version chain representation
    • fixity and event carriage
  4. Which media types, character encodings and normalisation rules apply to the payload?constraint
    Expected answer
    • media types used
    • character encoding
    • normalisation rules applied before hashing
Artifacts
  • Exchange package manifestSelf-describing inventory of a submission, archival or dissemination package, listing records, versions, instantiations, digests, events and the profile in force.

Publication holds

  • Source verification incomplete: re-verify every accepted source URL live and pin its version before publication. Claude's ISO 15489-1 source returned HTTP 403 and its ISO-attributed claims were read from catalogue abstracts and indexed extracts; re-verify them against Grok's JIS X 0902-1:2019 identical adoption or licensed ISO text before any ISO-derived statement is published.
  • eIDAS evidence is second-hand on both sides: Claude used the legislation.gov.uk rendition of Article 3 and flags that Regulation (EU) 2024/1183 amendments are not reflected; Grok used a European Commission FAQ guidance page. Re-pin signature, seal and qualified-timestamp tiers to consolidated EU text before publishing the assurance-tier vocabulary.
  • Instrument version drift must be reconciled to one pinned version each: RiC-O 1.1 (2025, Claude) versus RiC-CM 1.0 (2023, Grok), and C2PA 2.1 (Claude) versus C2PA 2.4 (Grok). Publish only after the record/instantiation split and the hard-binding rule are re-checked against the chosen versions.
  • Multi-profile domain validation not yet complete: the merged model has been reasoned mainly against archival and government recordkeeping profiles. Validate against at least three materially different profiles — an EU qualified-signature commercial instrument, a US federal case file under 36 CFR, and a media or generated-content asset carrying content credentials — before publication.
  • Confirm the WM-REC-015 boundary once that model exists, so aggregation-membership references and the record-set exclusion resolve to real structure rather than a placeholder neighbour.
  • Strip any residual conformance-claim wording inherited from either provider; the published draft must state alignment and mapping only, with lossiness recorded.

Deferred research

  • Electronic transferable records under UNCITRAL MLETR: control, singularity and guaranteed uniqueness. Claude marks it a declared gap and Grok does not model it; likely a sibling model rather than an addition here.
  • Conflict-of-laws rule set for records created in one jurisdiction, held in a second and disclosed in a third. Both providers carry jurisdiction as a field with no sourced resolution rule; keep marked as a gap, never as canonical.
  • GDPR Article 17 erasure versus authorised retention duty: fetch the primary text and decide whether the conflict is carried as an unresolved question on the record or delegated to a rights/consent sibling model. Neither provider retrieved it.
  • Last-copy and multi-instantiation destruction semantics: when destruction of one instantiation does or does not destroy the record identity, and how the tombstone reflects partial destruction. Grok raises it; the base has no rule.
  • OAIS ISO 14721:2025 alignment: representation information for a designated community and SIP/AIP/DIP package roles — decide align-versus-reference against the base exchange-packaging finding rather than importing package structure.
  • Legal-hold primary schemas not retrieved by either provider: DoD 5015.02-STD, the MoReq2010 hold module in detail, and FRCP 37(e). Needed before hold scope, overlapping holds and release semantics can be stated as sourced rather than pattern-based.
  • Requires/isRequiredBy and references/isReferencedBy dependency relations between records (an annex, schema or referenced instrument needed to interpret the record) — evaluate as question-level additions to the content-and-components layer.
  • Declared-versus-measured extent (bytes, pages, duration) as a validation check on an instantiation; currently implied by the base coverage checklist but present in no base question.
  • InterPARES authenticity requirements and ISO 16175 / 14641 / 17068, none retrieved by either provider, as corroboration for the accepted authoritative-record-characteristics finding.