# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "research-draft", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-24T12:14:40Z", "synthesisSha256": "9227cb167a395b6a4112af6aa82634d6e190aff92306aea5eec6ef7d5b236ac2", "providers": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-REC-001", "registryId": "vr.wm-rec-001", "name": "Document / Record", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.REC.DOC" ], "tags": [ "document", "record", "inf.rec.doc" ], "status": "research draft" }, "canonicalUrl": "https://ver.cy/models/wm-rec-001-document-record/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-rec-001", "model": { "registry_id": "vr.wm-rec-001", "model_id": "WM-REC-001", "name": "Document / Record", "entry_kind": "aggregate", "purpose": "Give agents one format-neutral vocabulary for treating a document as a governed record: a stable information object whose identity outlives any file, carried through immutable versions and multiple instantiations, made relyable by signatures, timestamps and custody evidence, and disposed of under an authorised retention regime.", "scope_statement": "Covers the record as an aggregate root over its versions, instantiations, signatures, provenance, events, retention assignments, holds and access decisions, from creation or capture through disposition. Excludes the semantics of what the record is about, the agents named in it, the aggregations that hold it, and any particular storage or interface technology.", "in_scope": [ "Record identity, designation and official reference numbers", "Documentary form/genre and business classification membership", "Content structure, components, attachments and significant properties", "Immutable version chain, supersession and amendment", "Instantiations: renditions, carriers, originals, duplicates, certified copies and extracts", "Format identification, rendering environment, fixity and preservation actions", "Authorship, approval, ownership, custody and stewardship roles as references", "Issuance under mandate and entry into custodial or public registers", "Signatures, seals, attestations, trusted timestamps and dated validation outcomes", "Provenance, derivation and unbroken chain of custody", "Status vocabulary, lifecycle events, audit trail and temporal anchors", "Retention classes, disposition authority, holds, disposition execution and surviving evidence", "Security marking, access decisions, rights, licensing and personal-data constraints", "Metadata alignment, exchange packaging and projections" ], "out_of_scope": [ "Subject-matter semantics of the record's content (contract obligations, clinical findings, financial postings)", "Attributes and identity of persons and organizations named as agents", "Archival arrangement and description of fonds, series and collections (WM-REC-015)", "Identifier scheme registration, syntax and resolution policy (naming model)", "Calendar systems, working-day arithmetic and duration algebra (time model)", "Message transport, delivery and receipt semantics (communication model)", "Byte storage, replication, tiering and infrastructure operations", "Workflow and case management beyond record-affecting events", "Full-text indexing, retrieval ranking and search relevance", "Statutory interpretation of exemptions; the model carries markings, not legal conclusions", "Cryptographic key generation and hardware security module operation" ], "boundary_notes": [ { "neighbor": "WM-REC-015 Archival fonds / collection", "distinction": "Aggregation levels, archival arrangement and multi-level description belong to WM-REC-015. RiC separates Record and RecordSet as distinct classes; this model instantiates the Record side and stores only membership references and the aggregate identifier at time of filing.", "source_refs": [ "SRC-008", "SRC-001" ] }, { "neighbor": "Agent models (person, organization)", "distinction": "PROV-O and RiC-O both keep Agent disjoint from the resource. This model stores role-qualified references (author, approver, signatory, custodian) and the basis of the role assertion, never agent attributes.", "source_refs": [ "SRC-003", "SRC-008" ] }, { "neighbor": "Identifier and naming scheme model", "distinction": "Scheme governance, syntax and resolution commitments (as in the DOI/ISO 26324 social infrastructure) live in the naming model; this model records scheme, value, assigning authority and granularity only.", "source_refs": [ "SRC-015" ] }, { "neighbor": "Time and calendar model", "distinction": "Calendar systems and period arithmetic live elsewhere; this model constrains time values to RFC 3339 instants with explicit offset and separates event time from observation time.", "source_refs": [ "SRC-004" ] }, { "neighbor": "Message and communication model", "distinction": "eIDAS treats an electronic registered delivery service as a distinct service from an electronic document. A message is a communication act; its attachment resolves to a record governed here.", "source_refs": [ "SRC-007" ] }, { "neighbor": "Dataset / data asset model", "distinction": "A dataset governed by a schema is not a record. It becomes a record here only when fixed as an instantiation with fixity, retention and access controls attached.", "source_refs": [ "SRC-006", "SRC-001" ] }, { "neighbor": "File / object storage model", "distinction": "PREMIS distinguishes File and Bitstream Objects from the Intellectual Entity. One record may span many files and one file may carry many records; storage location is a reference, not identity.", "source_refs": [ "SRC-006" ] } ] }, "sources": [ { "id": "SRC-001", "title": "ISO 15489-1:2016 Information and documentation — Records management — Part 1: Concepts and principles", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/62542.html", "version_or_date": "Edition 2, 2016-04", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:15:00Z", "relevance": "Normative frame for records, metadata for records, records systems, records processes and the characteristics of authoritative records (authenticity, reliability, integrity, usability). Catalogue record only; full text is paywalled and returned HTTP 403 on direct fetch." }, { "id": "SRC-002", "title": "DCMI Metadata Terms", "organization": "Dublin Core Metadata Initiative", "url": "https://www.dublincore.org/specifications/dublin-core/dcmi-terms/", "version_or_date": "DCMI Recommendation, 2020-01-20", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:16:00Z", "relevance": "Descriptive metadata facet: identifier, title, creator, issued, modified, valid, format, extent, medium, language, type, accessRights, license, provenance, isVersionOf/hasVersion, replaces/isReplacedBy, conformsTo." }, { "id": "SRC-003", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:16:00Z", "relevance": "Entity/Activity/Agent model plus wasGeneratedBy, wasDerivedFrom, wasAttributedTo, wasAssociatedWith, actedOnBehalfOf, Revision and Bundle — the derivation and responsibility layer of this model." }, { "id": "SRC-004", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:17:00Z", "relevance": "Mandates an explicit UTC relationship (Z or ±hh:mm) on every timestamp, defines the -00:00 unknown-local-offset convention, leap-second second value 60 and optional fractional seconds." }, { "id": "SRC-005", "title": "RFC 3161: Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP)", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3161", "version_or_date": "August 2001", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:17:00Z", "relevance": "Proof-of-existence token binding a message imprint hash, hash algorithm, TSA-allocated serial number, genTime, accuracy, TSA identity and optional nonce and ordering flag." }, { "id": "SRC-006", "title": "PREMIS Data Dictionary for Preservation Metadata, Version 3.0", "organization": "Library of Congress (PREMIS Editorial Committee)", "url": "https://www.loc.gov/standards/premis/v3/premis-3-0-final.pdf", "version_or_date": "Version 3.0, June 2015", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:18:00Z", "relevance": "Intellectual Entity / Representation / File / Bitstream object categories, plus Event, Agent and Rights entities and the fixity, format, significantProperties and storage semantic units. loc.gov returned HTTP 403 to direct fetch; content verified through indexed search extracts." }, { "id": "SRC-007", "title": "Regulation (EU) No 910/2014 (eIDAS), Article 3 — Definitions", "organization": "European Union (text as published by The National Archives, legislation.gov.uk)", "url": "https://www.legislation.gov.uk/eur/2014/910/article/3", "version_or_date": "Regulation of 23 July 2014; rendition retrieved 2026-08-24", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:19:00Z", "relevance": "Definitions of electronic document, electronic signature and its advanced/qualified tiers, electronic seal and its tiers, electronic time stamp and its qualified tier, validation, and electronic registered delivery service." }, { "id": "SRC-008", "title": "International Council on Archives Records in Contexts Ontology (ICA RiC-O) version 1.1", "organization": "International Council on Archives (EGAD)", "url": "https://www.ica.org/standards/RiC/RiC-O_1-1.html", "version_or_date": "Version 1.1, released 2025-05-22", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:20:00Z", "relevance": "Record, RecordPart, RecordSet, Instantiation, Agent, Activity, Mandate, Rule, CarrierType, DocumentaryFormType classes and partitive, provenance and instantiation relations; authority for separating record resource from instantiation." }, { "id": "SRC-009", "title": "Media Types registry", "organization": "Internet Assigned Numbers Authority", "url": "https://www.iana.org/assignments/media-types/media-types.xhtml", "version_or_date": "Registry last updated 2026-08-17", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:21:00Z", "relevance": "Normative value space for mediaType on instantiations and exchange packages; eleven top-level types; registration under RFC 6838 with Standards Tree and expert review procedures." }, { "id": "SRC-010", "title": "C2PA Technical Specification", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.1/specs/C2PA_Specification.html", "version_or_date": "Version 2.1, September 2024", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-24T10:22:00Z", "relevance": "Manifest, claim, claim signature, assertions, ingredients, hard and soft bindings, manifest store and validation/trust model; requires X.509 signing and recommends RFC 3161 time-stamping, with manifests expiring on credential revocation when untimestamped." }, { "id": "SRC-011", "title": "Universal Electronic Records Management (ERM) Requirements", "organization": "U.S. National Archives and Records Administration", "url": "https://www.archives.gov/records-mgmt/policy/universalermrequirements", "version_or_date": "Version 3, June 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:23:00Z", "relevance": "Lifecycle requirement grouping used to shape the operating surface: Capture, Maintenance and Use, Disposal, Transfer, Metadata and Reporting." }, { "id": "SRC-012", "title": "Metadata guidance tables for transfer of permanent electronic records (case file appendix)", "organization": "U.S. National Archives and Records Administration", "url": "https://www.archives.gov/records-mgmt/policy/transfer-guidance-tables.html", "version_or_date": "Current guidance, accessed 2026-08-24", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:24:00Z", "relevance": "Concrete mandatory element set for embedded case files: Identifier:FileName, MessageDigest, Title, CreationDate, ModifiedDate, AccessRestrictions — evidence that digest and restriction status are transfer-critical." }, { "id": "SRC-013", "title": "UNCITRAL Model Law on Electronic Commerce (1996) with additional article 5 bis (1998)", "organization": "United Nations Commission on International Trade Law", "url": "https://uncitral.un.org/en/texts/ecommerce/modellaw/electronic_commerce", "version_or_date": "Adopted 12 June 1996; article 5 bis added 1998", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:25:00Z", "relevance": "Functional-equivalence doctrine: criteria under which electronic communications satisfy paper concepts of writing, signature and original — the legal basis for treating an instantiation as an original of record." }, { "id": "SRC-014", "title": "PRONOM technical registry", "organization": "The National Archives (United Kingdom)", "url": "https://www.nationalarchives.gov.uk/PRONOM/Default.aspx", "version_or_date": "Live registry, accessed 2026-08-24", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T10:26:00Z", "relevance": "Registry of file formats, software products and technical components used for preservation, with DROID-based automatic identification; source of format identifiers finer-grained than media types." }, { "id": "SRC-015", "title": "What is a DOI? (DOI system and ISO 26324)", "organization": "DOI Foundation", "url": "https://www.doi.org/the-identifier/what-is-a-doi/", "version_or_date": "ISO 26324 approved 2010, revised 2022; page accessed 2026-08-24", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-24T10:27:00Z", "relevance": "Model of a governed global identifier: prefix/suffix syntax, Handle-based resolution, and persistence resting on organizational commitment rather than technology — the second tier of the identity priority." }, { "id": "SRC-016", "title": "MoReq2010: Modular Requirements for Records Systems, Volume 1 — Core Services & Plug-in Modules", "organization": "DLM Forum Foundation", "url": "https://moreq.info/files/moreq2010_vol1_v1_1_en.pdf", "version_or_date": "Version 1.1, December 2011", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-24T10:28:00Z", "relevance": "Core-service decomposition of a records system, including classification, records, metadata, disposal scheduling and disposal holding services, system-assigned entity identifiers and mandatory event history. Retrieved as PDF; content verified through indexed search extracts rather than direct text parsing." }, { "id": "SRC-017", "title": "ISO 23081 Metadata for records (ISO 23081-1:2017 principles; ISO 23081-2:2021 conceptual and implementation issues)", "organization": "ISO/TC 46/SC 11 Archives/records management", "url": "https://committee.iso.org/sites/tc46sc11/home/projects/published/iso-23081-metadata-for-records.html", "version_or_date": "ISO 23081-1:2017; ISO 23081-2:2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T00:00:00Z", "relevance": "Metadata must show that an object was managed as a record of events across its existence, supporting integrity, authenticity, reliability and usability in business context. Distinct from purely descriptive metadata." }, { "id": "SRC-018", "title": "PREMIS Data Dictionary for Preservation Metadata, Version 3.0 — Hierarchical Listing of Semantic Units", "organization": "Library of Congress / PREMIS Editorial Committee", "url": "https://www.loc.gov/standards/premis/v3/premis-hierarchical-3-0.html", "version_or_date": "Version 3.0, November 2015; listing page dated 2022-01-28", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T00:00:00Z", "relevance": "Entities: Intellectual Entity, Object (representation, file, bitstream), Event, Agent, Rights. Semantic units for identifiers, fixity, format, size, storage, signatureInformation, relationships and rights statements." }, { "id": "SRC-019", "title": "Records in Contexts – Conceptual Model (RiC-CM) Version 1.0", "organization": "International Council on Archives, Expert Group on Archival Description", "url": "https://www.ica.org/app/uploads/2023/12/RiC-CM-1.0.pdf", "version_or_date": "Version 1.0, November 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T00:00:00Z", "relevance": "Entities include Record Resource (Record Set, Record, Record Part) and Instantiation, plus Agent, Activity, Event, Rule, Mandate, Date, Place. Record is discrete inscribed information; Instantiation is the carrier inscription. Explicitly not a physical-management or exchange format. Notes relationship and remaining differences with ISO 23081." }, { "id": "SRC-020", "title": "ISO 14721:2025 Space Data System Practices — Reference model for an Open Archival Information System (OAIS)", "organization": "ISO / CCSDS", "url": "https://www.iso.org/standard/87471.html", "version_or_date": "2025-03, Edition 3", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T00:00:00Z", "relevance": "Information packages SIP, AIP, DIP; Content Information plus Preservation Description Information (reference, provenance, context, fixity, access rights); ingest, archival storage, data management, access, dissemination, preservation planning. Alignment for long-term packages, not this model's operational archive." }, { "id": "SRC-021", "title": "36 CFR § 1220.18 — Definitions applicable to Federal records management", "organization": "United States National Archives and Records Administration (as published in the e-CFR / LII)", "url": "https://www.law.cornell.edu/cfr/text/36/1220.18", "version_or_date": "74 FR 51014, 2009-10-02, as amended 87 FR 75931, 2022-12-12; implements 44 U.S.C. 3301", "source_type": "legislation", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-24T00:00:00Z", "relevance": "US Federal record, nonrecord, documentary materials, electronic record including required metadata, disposition, disposition authority, retention period, series, permanent, temporary, unscheduled (treat as permanent until scheduled), contingent records, personal files." }, { "id": "SRC-022", "title": "C2PA Technical Specification — Content Credentials", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html", "version_or_date": "Specification 2.4 (live spec site 2026)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T00:00:00Z", "relevance": "Signed manifest of assertions, claim and claim signature; hard binding (cryptographic hash of asset bytes) and optional soft binding (fingerprint or watermark). Emerging authenticity mechanism for digital assets; not a records-management standard." }, { "id": "SRC-023", "title": "JIS X 0902-1:2019 Information and documentation — Records management — Part 1: Concepts and principles (identical to ISO 15489-1:2016)", "organization": "Japanese Industrial Standards Committee", "url": "https://kikakurui.com/x0/X0902-1-2019-01.html", "version_or_date": "2019 (IDT ISO 15489-1:2016)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-24T00:00:00Z", "relevance": "Public identical adoption used to ground ISO 15489 clause 8 records controls (metadata schema, business classification, access/permission rules, disposition authority) and clause 9 processes, including capture assigning a unique identifier." }, { "id": "SRC-024", "title": "eSignature FAQ — eIDAS electronic signatures, seals and qualified timestamps", "organization": "European Commission", "url": "https://ec.europa.eu/digital-building-blocks/sites/spaces/DIGITAL/pages/880312429/eSignature+FAQ", "version_or_date": "Guidance on Regulation (EU) No 910/2014 (eIDAS); page observed 2026-02-02", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-24T00:00:00Z", "relevance": "Simple, advanced and qualified electronic signatures; qualified electronic seals; qualified electronic time stamps with presumption of date/time accuracy and integrity. Regional legal effect, not a global records model." } ], "structure": { "bundles": [ { "id": "identity-form-and-classification", "name": "Identity, documentary form and classification", "description": "What the record is, how it is named and referenced, what documentary genre it belongs to, and where it sits in a business classification scheme and archival aggregation.", "rationale": "ISO 15489 treats classification and identification as the controls from which every later recordkeeping decision derives, and RiC-O separates the record from the sets that contain it; an agent cannot apply retention, access or authenticity rules before these are fixed.", "source_refs": [ "SRC-001", "SRC-008", "SRC-002" ], "layers": [ { "id": "identity-and-designation", "name": "Identity and designation", "description": "The stable identifier of the record as an information object and the human-facing titles and reference numbers layered on top of it.", "source_refs": [ "SRC-002", "SRC-015", "SRC-016" ], "findings": [ { "id": "record-identity-anchor", "name": "Record identity anchor", "description": "The identifier that denotes the record independently of any file, version or rendition, its scheme, its granularity and its non-reuse guarantee.", "source_refs": [ "SRC-015", "SRC-016", "SRC-002", "SRC-006" ], "questions": [ { "id": "q-identity-master", "text": "Which system is the authoritative master for this record's identifier and from which registered scheme is the value drawn?", "kind": "identity", "answer_data": [ "master system reference", "identifier scheme name or IRI", "identifier value", "assigning authority reference" ] }, { "id": "q-identity-granularity", "text": "Does the identifier denote the record, one version, or one instantiation?", "kind": "definition", "answer_data": [ "granularity code (record | version | instantiation)", "version identifier pattern", "instantiation identifier pattern" ] }, { "id": "q-identity-persistence", "text": "What guarantees that the identifier is never reused after disposition or system migration?", "kind": "constraint", "answer_data": [ "non-reuse policy statement", "tombstone retention rule", "migration mapping table reference" ] }, { "id": "q-identity-alternates", "text": "Which legacy or alternate identifiers exist and on what basis are they asserted equivalent?", "kind": "interoperability", "answer_data": [ "alternate identifier list with scheme", "equivalence assertion basis", "assertion datetime" ] } ], "data_elements": [ { "id": "de-record-id", "name": "recordIdentifier", "description": "Primary identifier of the record, chosen by the identity priority rule.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-015" ] }, { "id": "de-record-id-scheme", "name": "identifierScheme", "description": "Registered scheme that governs the identifier's syntax and resolution.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] }, { "id": "de-identifier-granularity", "name": "identifierGranularity", "description": "Whether the identifier denotes the record, a version or an instantiation.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-008" ] }, { "id": "de-alternate-identifier", "name": "alternateIdentifier", "description": "Legacy or parallel identifiers with scheme and equivalence basis.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [], "inline_only_rationale": "Identifier values are inline reference data that must appear in every projection, including existence-level ones. The evidencing artifact for identifier assignment is the register entry produced under issuance and registration, so a separate artifact here would duplicate it." }, { "id": "designation-and-reference-numbers", "name": "Designation and reference numbers", "description": "Titles, alternative and translated titles, and the official reference numbers quoted on the face of the record, kept strictly distinct from identity.", "source_refs": [ "SRC-002", "SRC-008", "SRC-012" ], "questions": [ { "id": "q-designation-title", "text": "What is the official title of the record, in which language and script is it recorded, and who set it?", "kind": "definition", "answer_data": [ "title string", "language code", "script code", "title assigning agent" ] }, { "id": "q-designation-face-refs", "text": "Which reference numbers appear on the face of the record and which authority allocated each?", "kind": "identity", "answer_data": [ "reference number value", "allocating authority", "allocation context" ] }, { "id": "q-designation-drift", "text": "How are superseded or translated titles retained without ever being treated as identifiers?", "kind": "constraint", "answer_data": [ "alternative title list", "validity period per title", "identifier-vs-title separation rule" ] } ], "data_elements": [ { "id": "de-title", "name": "title", "description": "Official name given to the record.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-012" ] }, { "id": "de-alternative-title", "name": "alternativeTitle", "description": "Translated, short or superseded titles with their validity periods.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-title-language", "name": "titleLanguage", "description": "Language of the recorded title.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-face-reference-number", "name": "faceReferenceNumber", "description": "Reference numbers printed or displayed on the record itself.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "Designation is descriptive inline metadata carried on the record; no separate artifact is produced by titling, and treating a title list as an artifact would invite its use as an identifier, which the identity rule forbids." } ] }, { "id": "documentary-form-and-classification", "name": "Documentary form and classification", "description": "The genre of the record and its placement in a business classification scheme and archival aggregation, which drive the rules that later apply to it.", "source_refs": [ "SRC-001", "SRC-008", "SRC-016" ], "findings": [ { "id": "documentary-form", "name": "Documentary form and genre", "description": "The documentary form the record takes (contract, certificate, invoice, minutes, licence) typed against a controlled vocabulary, and the rules that follow from that form.", "source_refs": [ "SRC-008", "SRC-002", "SRC-001" ], "questions": [ { "id": "q-form-term", "text": "What documentary form does this record take and from which controlled vocabulary is the term drawn?", "kind": "classification", "answer_data": [ "documentary form term", "vocabulary IRI and version", "term notation" ] }, { "id": "q-form-consequences", "text": "Which obligations, signature requirements or retention consequences follow automatically from that form?", "kind": "requirement", "answer_data": [ "rule references triggered by form", "mandatory signature level", "default retention class" ] }, { "id": "q-form-multiplicity", "text": "Can one record carry more than one documentary form, such as a certificate inside a covering letter?", "kind": "composition", "answer_data": [ "primary form", "secondary form list", "component-to-form mapping" ] }, { "id": "q-form-governance", "text": "Who approves additions to the form vocabulary and how are retired terms handled?", "kind": "authority", "answer_data": [ "vocabulary owner", "approval process reference", "deprecation date and replacement term" ] } ], "data_elements": [ { "id": "de-documentary-form", "name": "documentaryForm", "description": "Controlled term for the record's genre.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-form-vocabulary", "name": "formVocabulary", "description": "Reference to the vocabulary and version supplying the term.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-resource-type", "name": "resourceType", "description": "Coarse resource type aligned to DCMI Type for cross-domain exchange.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-secondary-form", "name": "secondaryForm", "description": "Additional forms carried by components of a compound record.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [ { "id": "a-form-vocabulary", "name": "Documentary form vocabulary", "description": "The governed term list of documentary forms, with notations, definitions, deprecations and the rules each form triggers.", "media_or_form": [ "controlled vocabulary", "concept scheme", "code list" ], "serial": false, "identity_strategy": "Scheme IRI plus version tag; individual terms identified by scheme-scoped notation, never by display label.", "source_refs": [ "SRC-008", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "classification-and-aggregation", "name": "Business classification and aggregation membership", "description": "Filing of the record under a classification class and its membership in aggregations, with the boundary to the archival aggregation model held explicitly.", "source_refs": [ "SRC-001", "SRC-016", "SRC-008" ], "questions": [ { "id": "q-class-assignment", "text": "Under which classification class is the record filed and which version of the scheme was in force at filing?", "kind": "classification", "answer_data": [ "class notation", "scheme identifier and version", "filing datetime" ] }, { "id": "q-class-aggregations", "text": "Which aggregations does the record belong to and is membership exclusive?", "kind": "composition", "answer_data": [ "aggregation references", "membership exclusivity flag", "position within aggregation" ] }, { "id": "q-class-reorganisation", "text": "When the scheme is reorganised, is the historic class retained alongside the new one?", "kind": "temporal", "answer_data": [ "historic class with validity period", "reclassification event reference", "reclassifying agent" ] }, { "id": "q-class-precedence", "text": "If more than one class applies, which one determines retention and access?", "kind": "exception", "answer_data": [ "precedence rule statement", "prevailing class", "conflict resolution record" ] } ], "data_elements": [ { "id": "de-classification-class", "name": "classificationClass", "description": "Notation of the class under which the record is filed.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-016" ] }, { "id": "de-scheme-version", "name": "classificationSchemeVersion", "description": "Version of the classification scheme in force at filing.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-016" ] }, { "id": "de-aggregation-ref", "name": "aggregationMembership", "description": "References to the file, series, case or fonds containing the record.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-class-effective-from", "name": "classificationEffectiveFrom", "description": "Instant from which the class assignment applies.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "a-classification-scheme", "name": "Business classification scheme (file plan)", "description": "The hierarchical scheme of classes under which records are filed, with effective dates, retention linkage and superseded versions retained.", "media_or_form": [ "hierarchical scheme", "tabular file plan", "authority-issued instrument" ], "serial": false, "identity_strategy": "Scheme identifier issued by the owning organisation plus effective-from date; superseded versions kept and never overwritten.", "source_refs": [ "SRC-001", "SRC-016" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "content-versions-and-manifestations", "name": "Content, versions and manifestations", "description": "What the record says, the immutable states its content passes through, and the format-specific and carrier-specific realisations that make it readable.", "rationale": "PREMIS distinguishes Intellectual Entity, Representation, File and Bitstream, and RiC-O separates record resource from instantiation; collapsing these layers makes format migration indistinguishable from content change and destroys the evidentiary chain.", "source_refs": [ "SRC-006", "SRC-008", "SRC-002" ], "layers": [ { "id": "content-and-components", "name": "Content and components", "description": "The body of the record, its structural parts, attachments and the properties that must survive any transformation.", "source_refs": [ "SRC-006", "SRC-008", "SRC-016" ], "findings": [ { "id": "content-structure-and-components", "name": "Content structure, components and completeness", "description": "Which parts make up the complete record, which are essential to its meaning, and how completeness is verified at capture.", "source_refs": [ "SRC-006", "SRC-016", "SRC-002", "SRC-001" ], "questions": [ { "id": "q-content-components", "text": "Which components make up the complete record and which of them are essential rather than incidental?", "kind": "composition", "answer_data": [ "component list with roles", "essential flag per component", "ordering or structural map" ] }, { "id": "q-content-significant", "text": "Which significant properties must be preserved for the record to remain usable and understandable?", "kind": "quality", "answer_data": [ "significant property list", "measurement method", "acceptance threshold" ] }, { "id": "q-content-language", "text": "In which languages is the content expressed and which language version is authoritative for interpretation?", "kind": "definition", "answer_data": [ "content language codes", "authoritative language", "translation relationship references" ] }, { "id": "q-content-completeness", "text": "How is completeness verified before the record is declared captured?", "kind": "validation", "answer_data": [ "completeness check method", "checked-by agent", "check outcome and datetime" ] } ], "data_elements": [ { "id": "de-component", "name": "component", "description": "An addressable part of the record: body, annex, attachment or embedded object, with its role.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-016", "SRC-006" ] }, { "id": "de-significant-properties", "name": "significantProperties", "description": "Characteristics that must survive migration or rendition for the record to remain usable.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-content-language", "name": "contentLanguage", "description": "Languages in which the content is expressed.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-extent", "name": "extent", "description": "Size or duration of the content, such as page count, word count or playing time.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "a-component-manifest", "name": "Record component manifest", "description": "Itemised inventory of the components constituting one version of the record, with roles, order, essentiality and per-component digests.", "media_or_form": [ "itemised inventory", "structural map", "package listing" ], "serial": false, "identity_strategy": "Record identifier plus version identifier; exactly one manifest per version, regenerated only by issuing a new version.", "source_refs": [ "SRC-006", "SRC-016" ] } ], "inline_only_rationale": null } ] }, { "id": "versions-and-instantiations", "name": "Versions and instantiations", "description": "The immutable version chain of content states and the multiple physical or digital instantiations that realise each state.", "source_refs": [ "SRC-002", "SRC-008", "SRC-006" ], "findings": [ { "id": "version-chain-and-immutability", "name": "Version chain and immutability", "description": "How a content state is fixed, how versions supersede and amend one another, and the prohibition on editing an issued version in place.", "source_refs": [ "SRC-002", "SRC-008", "SRC-016", "SRC-001" ], "questions": [ { "id": "q-version-fixing", "text": "Which event fixes a version and makes it immutable, and who is competent to trigger it?", "kind": "event", "answer_data": [ "fixing event type", "triggering agent and authority", "event datetime" ] }, { "id": "q-version-authoritative", "text": "Which version is currently authoritative and which versions does it supersede or amend?", "kind": "state", "answer_data": [ "current version identifier", "supersession links", "amendment links" ] }, { "id": "q-version-draft", "text": "How are drafts distinguished from issued versions for retention and access purposes?", "kind": "lifecycle", "answer_data": [ "version state code", "draft retention rule", "draft access rule" ] }, { "id": "q-version-reason", "text": "What reason, authority and change description are recorded for each new version?", "kind": "provenance", "answer_data": [ "change note", "authorising agent", "change basis reference" ] } ], "data_elements": [ { "id": "de-version-id", "name": "versionIdentifier", "description": "Identifier of one immutable content state.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-016" ] }, { "id": "de-version-sequence", "name": "versionSequence", "description": "Monotonic sequence number of the version within the record.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-016" ] }, { "id": "de-version-state", "name": "versionState", "description": "Whether the version is draft, issued, superseded or withdrawn.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-supersedes-ref", "name": "supersedes", "description": "Reference to the version or record this one replaces.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-change-note", "name": "changeNote", "description": "Statement of what changed and why.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "a-version-history", "name": "Version history", "description": "Append-only chain of version entries with sequence, fixing event, issuing agent, change note and supersession links.", "media_or_form": [ "append-only log", "tabular history", "chained entries" ], "serial": true, "identity_strategy": "Record identifier plus zero-padded monotonic version sequence; sequences are never reused or renumbered.", "source_refs": [ "SRC-002", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "instantiation-copy-and-original-status", "name": "Instantiation, copy and original status", "description": "Format-specific and carrier-specific realisations of a version, and the legal distinction between the original of record, duplicates, certified copies and extracts.", "source_refs": [ "SRC-008", "SRC-006", "SRC-013", "SRC-007" ], "questions": [ { "id": "q-inst-original", "text": "Which instantiation is the original of record and where is it held?", "kind": "identity", "answer_data": [ "instantiation identifier", "original-of-record flag", "storage location reference", "holding agent" ] }, { "id": "q-inst-role", "text": "Is a given instantiation a faithful rendition, a derivative, a certified copy or an extract, and who attests it?", "kind": "evidence", "answer_data": [ "instantiation role code", "attesting authority", "attestation reference" ] }, { "id": "q-inst-surrogate", "text": "What criteria make a digitised surrogate acceptable in place of an analogue original?", "kind": "requirement", "answer_data": [ "integrity criterion statement", "capture specification", "authority permitting substitution" ] }, { "id": "q-inst-equivalence", "text": "How are two instantiations of the same version proven to carry the same content?", "kind": "validation", "answer_data": [ "comparison method", "significant-property comparison result", "verification datetime" ] } ], "data_elements": [ { "id": "de-instantiation-id", "name": "instantiationIdentifier", "description": "Identifier of one realisation of a version on a carrier or in a format.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-006" ] }, { "id": "de-instantiation-role", "name": "instantiationRole", "description": "Original of record, duplicate, certified copy, extract, rendition or preservation master.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-013" ] }, { "id": "de-carrier-type", "name": "carrierType", "description": "Physical or digital carrier on which the instantiation exists.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-storage-location", "name": "storageLocation", "description": "Reference to where the instantiation is held, resolved by the storage model.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "a-certified-copy-attestation", "name": "Certified copy or extract attestation", "description": "Statement by a competent authority that a named instantiation is a true copy or a faithful extract of a named source, with the scope of what was omitted.", "media_or_form": [ "signed statement", "endorsement applied to the copy", "separately issued certificate" ], "serial": true, "identity_strategy": "Attestation number allocated by the certifying authority plus RFC 3339 issue instant; the attestation references both source and copy identifiers.", "source_refs": [ "SRC-013", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "supersession-between-records", "name": "Supersession between records", "description": "Dublin Core replaces/isReplacedBy model a related resource that supplants another. A new record may supersede an older record (policy, specification, licence) without being a version of the same identity. Supersession does not by itself authorize destruction of the replaced record; disposition remains a separate control.", "source_refs": [ "SRC-002", "SRC-001" ], "data_elements": [ { "id": "supersession-between-records-data01", "name": "Supersedes record ref", "description": "Reference to an earlier record this record replaces.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "supersession-between-records-data02", "name": "Superseded-by record ref", "description": "Reference to the record that replaces this one.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "supersession-between-records-data03", "name": "Supersession datetime", "description": "RFC 3339 datetime from which supersession is effective.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "supersession-between-records-artifact01", "name": "Supersession link", "description": "Typed relation between two record identities with effective time.", "media_or_form": [ "typed relation" ], "serial": false, "identity_strategy": "Pair of record identifiers plus effective time.", "source_refs": [ "SRC-002" ] } ], "questions": [ { "id": "supersession-between-records-q01", "text": "Which earlier record(s) does this record replace, from when, and is the older identity retained?", "kind": "relationship", "answer_data": [ "Array of {record-ref, effective-at RFC 3339, older-identity-retained boolean}." ] }, { "id": "supersession-between-records-q02", "text": "Has this record been replaced, and is it still retained under its schedule?", "kind": "state", "answer_data": [ "superseded-by ref, effective-at, retention still in force boolean." ] }, { "id": "supersession-between-records-q03", "text": "Is the successor a new version of the same identity or a distinct record that replaces this one?", "kind": "definition", "answer_data": [ "Enum relation-kind: same-identity-version | distinct-record-replaces." ] } ], "inline_only_rationale": null } ] }, { "id": "format-fixity-and-preservation", "name": "Format, fixity and preservation", "description": "Technical identification of instantiations, the environment needed to render them, and the integrity and preservation controls applied over time.", "source_refs": [ "SRC-006", "SRC-009", "SRC-014" ], "findings": [ { "id": "format-identification-and-environment", "name": "Format identification and rendering environment", "description": "How each instantiation's format is identified against registries and what software and hardware environment is required to render it.", "source_refs": [ "SRC-009", "SRC-014", "SRC-006" ], "questions": [ { "id": "q-format-mediatype", "text": "Which registered media type and which format-registry identifier apply to this instantiation?", "kind": "measurement", "answer_data": [ "media type from the IANA registry", "format registry identifier such as a PRONOM PUID", "format version" ] }, { "id": "q-format-method", "text": "How was the format determined — declared by the producer or identified by a tool?", "kind": "provenance", "answer_data": [ "identification method", "tool name and version", "identification confidence" ] }, { "id": "q-format-environment", "text": "What environment is required to render the instantiation faithfully?", "kind": "requirement", "answer_data": [ "software dependency list with versions", "hardware or codec dependency", "font or external resource dependency" ] }, { "id": "q-format-obsolescence", "text": "What is the obsolescence risk for this format and what migration or emulation path is planned?", "kind": "decision", "answer_data": [ "risk assessment and date", "planned action", "action owner and review date" ] } ], "data_elements": [ { "id": "de-media-type", "name": "mediaType", "description": "IANA-registered media type of the instantiation.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "de-format-registry-id", "name": "formatRegistryIdentifier", "description": "Fine-grained format identifier from a technical registry, such as a PRONOM PUID.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "de-environment-dependency", "name": "environmentDependency", "description": "Software, hardware or resource dependencies needed to render the instantiation.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-byte-size", "name": "byteSize", "description": "Size of the instantiation in bytes.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-002" ] } ], "artifacts": [ { "id": "a-format-characterisation-report", "name": "Format characterisation report", "description": "Tool-produced technical description of an instantiation: identified format, version, validity, well-formedness, extracted properties and dependencies.", "media_or_form": [ "tool output report", "structured property set" ], "serial": true, "identity_strategy": "Instantiation identifier plus tool identifier, tool version and RFC 3339 run instant; reports are additive and earlier reports are retained.", "source_refs": [ "SRC-014", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "fixity-and-preservation-actions", "name": "Fixity and preservation actions", "description": "Baseline digests, verification history, declared preservation level and the actions applied to keep instantiations readable, including those that change bytes.", "source_refs": [ "SRC-006", "SRC-012", "SRC-011" ], "questions": [ { "id": "q-fixity-baseline", "text": "Which algorithm and digest value were recorded at capture, and by which agent?", "kind": "evidence", "answer_data": [ "algorithm name", "digest value", "computing agent", "computation datetime" ] }, { "id": "q-fixity-verification", "text": "When was fixity last verified, at what frequency, and what was the outcome?", "kind": "measurement", "answer_data": [ "last verification datetime", "verification schedule", "outcome code and detail" ] }, { "id": "q-fixity-actions", "text": "Which preservation actions have been applied and did any of them change the bytes?", "kind": "process", "answer_data": [ "action type and datetime", "input and output instantiation references", "byte-change flag" ] }, { "id": "q-fixity-failure", "text": "What happens when a fixity check fails, and who is notified?", "kind": "exception", "answer_data": [ "incident record reference", "recovery source", "notification recipients and deadline" ] } ], "data_elements": [ { "id": "de-fixity-algorithm", "name": "fixityAlgorithm", "description": "Named digest algorithm used; multiple algorithms may be recorded for agility.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-012" ] }, { "id": "de-fixity-value", "name": "fixityValue", "description": "Digest value bound to a specific instantiation and algorithm.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-012" ] }, { "id": "de-fixity-computed-at", "name": "fixityComputedAt", "description": "RFC 3339 instant at which the digest was computed.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "de-preservation-level", "name": "preservationLevel", "description": "Declared level of preservation commitment and replication for the instantiation.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-preservation-event-ref", "name": "preservationEvent", "description": "References to normalisation, migration, repair or replication events.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "a-fixity-manifest", "name": "Fixity manifest", "description": "Set of digests covering the instantiations and artifacts of a record or package, with algorithms, computation instants and the computing agent.", "media_or_form": [ "checksum list", "signed digest set", "package sidecar" ], "serial": true, "identity_strategy": "Record or package identifier plus algorithm set plus RFC 3339 computation instant; manifests accumulate and are never overwritten.", "source_refs": [ "SRC-006", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "agency-authority-and-issuance", "name": "Agency, authority and issuance", "description": "Who is responsible for the record, who owns and who keeps it, and the act of issuing it under a mandate and entering it into a register.", "rationale": "ISO 15489 makes assigned responsibility a precondition of trustworthy recordkeeping, RiC-O models Mandate and Agent as distinct contextual entities, and eIDAS makes the issuing legal person material to legal effect; ownership must be separable from custody.", "source_refs": [ "SRC-001", "SRC-008", "SRC-007" ], "layers": [ { "id": "agents-and-responsibility", "name": "Agents, ownership and custody", "description": "Role-qualified references to the agents who made, approved, own and keep the record.", "source_refs": [ "SRC-003", "SRC-008", "SRC-001" ], "findings": [ { "id": "authorship-and-responsibility-roles", "name": "Authorship and responsibility roles", "description": "Who authored, contributed to, approved and was addressed by the record, expressed as role-qualified references rather than embedded agent descriptions.", "source_refs": [ "SRC-003", "SRC-008", "SRC-002" ], "questions": [ { "id": "q-agent-author", "text": "Which agent is the author of record and which agents merely contributed?", "kind": "ownership", "answer_data": [ "author reference", "contributor references with contribution type", "attribution basis" ] }, { "id": "q-agent-approval", "text": "Who approved or authorised issue, and under what delegation of authority?", "kind": "authority", "answer_data": [ "approver reference", "delegation instrument reference", "approval datetime" ] }, { "id": "q-agent-addressee", "text": "Who are the intended addressees or recipients, and does that constrain access?", "kind": "relationship", "answer_data": [ "addressee references", "distribution list reference", "access consequence" ] }, { "id": "q-agent-unknown", "text": "How is a role recorded when the responsible agent cannot be identified?", "kind": "evidence", "answer_data": [ "unknown-agent placeholder policy", "evidence supporting the role assertion", "confidence statement" ] } ], "data_elements": [ { "id": "de-author-ref", "name": "author", "description": "Reference to the agent responsible for making the record.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "de-approver-ref", "name": "approver", "description": "Reference to the agent who authorised issue.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-addressee-ref", "name": "addressee", "description": "Reference to the intended recipient of the record.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-role-basis", "name": "roleAssertionBasis", "description": "Evidence on which a responsibility role is asserted.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Agent attributes are governed by the person and organization models; this finding stores only role-qualified references, and the artifacts that evidence responsibility are the signature object and the event history recorded in other findings." }, { "id": "ownership-custody-and-stewardship", "name": "Ownership, custody and stewardship", "description": "The separation between the record owner and the custodian or registrar acting on the owner's behalf, and the terms limiting custodial power.", "source_refs": [ "SRC-001", "SRC-008", "SRC-011" ], "questions": [ { "id": "q-own-who", "text": "Who owns the record and who currently has custody of it?", "kind": "ownership", "answer_data": [ "owner reference", "custodian reference", "custody start datetime" ] }, { "id": "q-own-limits", "text": "What may the custodian not do — can they widen access, migrate formats or dispose?", "kind": "authority", "answer_data": [ "permitted custodial actions", "prohibited actions", "escalation path to the owner" ] }, { "id": "q-own-transfer", "text": "How and when does ownership itself transfer, and what evidence is required?", "kind": "lifecycle", "answer_data": [ "ownership transfer event", "transferring and receiving parties", "instrument evidencing transfer" ] } ], "data_elements": [ { "id": "de-owner-ref", "name": "recordOwner", "description": "Reference to the author or issuing organization accountable for the record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-custodian-ref", "name": "custodian", "description": "Reference to the party currently holding the record on the owner's behalf.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-custody-terms", "name": "custodyTerms", "description": "Reference to the agreement or policy defining custodial powers and limits.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-ownership-transfer-event", "name": "ownershipTransferEvent", "description": "Events at which ownership, as distinct from custody, changed hands.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "a-custody-agreement", "name": "Custody or deposit agreement", "description": "Instrument setting out what the custodian may and may not do with the record, the service levels and the conditions for return or transfer.", "media_or_form": [ "signed agreement", "policy instrument", "deposit contract" ], "serial": false, "identity_strategy": "Agreement reference allocated by the owning party plus version; superseded versions retained for the period they governed.", "source_refs": [ "SRC-001", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "issuance-and-registration", "name": "Issuance and registration", "description": "The act of issuing the record under a mandate in a jurisdiction, and its entry into a custodial or public register.", "source_refs": [ "SRC-008", "SRC-007", "SRC-016" ], "findings": [ { "id": "issuance-mandate-and-registration", "name": "Issuance, mandate and register entry", "description": "The legal basis and jurisdiction under which the record was issued, and the register entry that anchors it in a custodial system.", "source_refs": [ "SRC-008", "SRC-007", "SRC-016", "SRC-001" ], "questions": [ { "id": "q-issue-mandate", "text": "Under which mandate, statute or delegated authority was the record issued?", "kind": "authority", "answer_data": [ "mandate reference", "issuing authority reference", "authority citation" ] }, { "id": "q-issue-jurisdiction", "text": "In which jurisdiction and at which place was it issued, and does that determine the applicable rules?", "kind": "spatial", "answer_data": [ "jurisdiction code", "place of issue reference", "governing law statement" ] }, { "id": "q-issue-register", "text": "Is the record registered, in which register, under what entry number, and at what instant?", "kind": "identity", "answer_data": [ "register reference", "entry number", "registration instant", "registering agent" ] }, { "id": "q-issue-publicity", "text": "Is the register public, and what is disclosed at existence level when content is withheld?", "kind": "access", "answer_data": [ "register publicity status", "existence-level field list", "withholding basis" ] } ], "data_elements": [ { "id": "de-issuing-authority", "name": "issuingAuthority", "description": "Reference to the legal person that issued the record.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "de-mandate-ref", "name": "mandate", "description": "Reference to the instrument authorising issue.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-jurisdiction", "name": "jurisdiction", "description": "Legal jurisdiction governing the record.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-register-entry-number", "name": "registerEntryNumber", "description": "Entry number allocated by the register authority.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-registered-at", "name": "registeredAt", "description": "RFC 3339 instant of registration.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "a-register-entry", "name": "Register entry or registration certificate", "description": "The custodial or public register line that anchors the record, with entry number, registering authority, registration instant and the existence-level fields disclosed.", "media_or_form": [ "register line entry", "issued certificate", "public register extract" ], "serial": true, "identity_strategy": "Register identifier plus entry number allocated by the register authority; entry numbers are monotonic per register and never reused.", "source_refs": [ "SRC-016", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "authenticity-and-evidentiary-value", "name": "Authenticity and evidentiary value", "description": "Why the record can be relied on: signatures and seals bound to fixed content, trusted timestamps, dated validation outcomes, derivation provenance and an unbroken chain of custody.", "rationale": "ISO 15489 makes authenticity and integrity defining characteristics of an authoritative record, eIDAS attaches legal effect to signature and timestamp tiers, and PROV-O and C2PA supply the derivation and binding structures; validity is time-dependent and must be recorded as evidence, not asserted as a flag.", "source_refs": [ "SRC-001", "SRC-007", "SRC-003", "SRC-010" ], "layers": [ { "id": "signatures-and-validation", "name": "Signatures, seals and validation evidence", "description": "Signature and seal objects bound to specific content, the timestamps that fix their moment, and the dated results of validating them.", "source_refs": [ "SRC-007", "SRC-005", "SRC-010" ], "findings": [ { "id": "signature-seal-and-attestation", "name": "Signature, seal and attestation", "description": "Signatures, seals and attestations applied to a version or instantiation, their assurance tier, their signatory and exactly what content each binds.", "source_refs": [ "SRC-007", "SRC-010", "SRC-013" ], "questions": [ { "id": "q-sig-type", "text": "What signature or seal type was applied and at which assurance tier?", "kind": "evidence", "answer_data": [ "signature type code", "assurance tier such as simple, advanced or qualified", "applicable legal regime" ] }, { "id": "q-sig-binding", "text": "Which exact content does each signature bind — a version, an instantiation, or a byte range?", "kind": "composition", "answer_data": [ "bound content reference", "bound digest and algorithm", "binding scope description" ] }, { "id": "q-sig-signatory", "text": "Who is the signatory or sealing legal person, and on which certificate or credential does the signature rest?", "kind": "identity", "answer_data": [ "signatory reference", "certificate identifier and issuer", "credential type" ] }, { "id": "q-sig-effect", "text": "What must hold for the signature to have legal effect in the governing jurisdiction?", "kind": "requirement", "answer_data": [ "required tier for the record type", "creation device requirement", "jurisdiction-specific condition" ] } ], "data_elements": [ { "id": "de-signature-id", "name": "signatureIdentifier", "description": "Identifier of the signature, seal or attestation object.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "de-signature-type", "name": "signatureType", "description": "Handwritten, electronic signature, advanced or qualified signature, electronic seal, or other attestation.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "de-signature-binding", "name": "signedContentBinding", "description": "Reference and digest of the exact content the signature binds.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-007" ] }, { "id": "de-claimed-signing-time", "name": "claimedSigningTime", "description": "Signing time asserted by the signatory, distinct from any trusted timestamp.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-certificate-ref", "name": "signingCertificate", "description": "Reference to the certificate or credential used.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "a-signature-object", "name": "Signature, seal or attestation object", "description": "The signature itself — detached or embedded — carrying the bound digest, the signing credential chain and the claimed signing time.", "media_or_form": [ "detached signature file", "embedded signature block", "physical seal or wet-ink endorsement" ], "serial": true, "identity_strategy": "Signature identifier plus the digest of the content it binds; a signature is never re-pointed to different content.", "source_refs": [ "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "timestamping-and-validation-evidence", "name": "Timestamping and validation evidence", "description": "Trusted time-stamp tokens proving existence at a time, validation outcomes recorded with their own validation instant and policy, and the renewal of evidence before algorithms weaken.", "source_refs": [ "SRC-005", "SRC-007", "SRC-010", "SRC-004" ], "questions": [ { "id": "q-ts-token", "text": "Is there a trusted time-stamp token binding the content to a time, and which authority issued it?", "kind": "evidence", "answer_data": [ "token reference", "issuing authority identity", "token serial number", "generation time and accuracy" ] }, { "id": "q-ts-validation", "text": "What was the validation outcome, at which validation instant, and under which validation policy?", "kind": "validation", "answer_data": [ "outcome code", "validation instant", "policy identifier", "revocation status checked" ] }, { "id": "q-ts-renewal", "text": "How is the evidence renewed before its algorithms or certificates weaken?", "kind": "temporal", "answer_data": [ "renewal schedule", "algorithm sunset date", "renewal event references" ] }, { "id": "q-ts-manifest", "text": "Which provenance manifest, if any, travels with the rendered asset, and does it survive rendition?", "kind": "interoperability", "answer_data": [ "manifest reference", "binding type (hard or soft)", "survival behaviour across renditions" ] } ], "data_elements": [ { "id": "de-timestamp-token", "name": "timeStampToken", "description": "Reference to the trusted token binding a digest to a time.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-timestamp-gentime", "name": "timeStampGenTime", "description": "Generation time asserted by the timestamping authority.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de-validation-outcome", "name": "validationOutcome", "description": "Result of validating a signature, seal or manifest at a specific moment.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-validated-at", "name": "validatedAt", "description": "RFC 3339 instant at which validation was performed.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-validation-policy", "name": "validationPolicy", "description": "Reference to the policy under which validation was performed.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "a-timestamp-token", "name": "Trusted time-stamp token", "description": "Proof-of-existence token binding a message imprint hash, algorithm, authority-allocated serial number and generation time with stated accuracy.", "media_or_form": [ "RFC 3161 token", "timestamped ledger entry" ], "serial": true, "identity_strategy": "Timestamping authority identity plus the serial number it allocated; serials are unique per authority.", "source_refs": [ "SRC-005" ] }, { "id": "a-validation-report", "name": "Signature validation report", "description": "Dated statement of the outcome of validating a signature, seal or provenance manifest, naming the policy, trust anchors and revocation data used.", "media_or_form": [ "structured validation result", "human-readable report" ], "serial": true, "identity_strategy": "Subject signature identifier plus RFC 3339 validation instant plus policy identifier; reports accumulate and earlier outcomes are never overwritten.", "source_refs": [ "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "authoritative-record-characteristics", "name": "Authoritative record characteristics", "description": "ISO 23081 states that metadata must support assertions of integrity, authenticity, reliability and usability over time in business context. ISO 15489 requires records to remain authoritative through those characteristics: authentic (what it purports to be, created or sent by the purported agent at the purported time), reliable (trusted full and accurate content of the transaction), integrity (complete and unaltered), usable (locatable, retrievable, presentable, interpretable). These are assessed properties with evidence, not decorative flags.", "source_refs": [ "SRC-001", "SRC-017" ], "data_elements": [ { "id": "authoritative-record-characteristics-data01", "name": "Authenticity assessment", "description": "Structured assessment that the record is what it purports to be, with evidence.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "authoritative-record-characteristics-data02", "name": "Reliability assessment", "description": "Structured assessment of full and accurate content of the transaction.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "authoritative-record-characteristics-data03", "name": "Integrity assessment", "description": "Structured assessment that the record is complete and unaltered.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "authoritative-record-characteristics-data04", "name": "Usability assessment", "description": "Structured assessment that the record is locatable, retrievable, presentable and interpretable.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017" ] } ], "artifacts": [ { "id": "authoritative-record-characteristics-artifact01", "name": "Authoritativeness assessment note", "description": "Recorded assessment with evidence refs (fixity, signature, custody, representation info) and assessment time. Pure assessment metadata may be inline if evidence artifacts live on related findings.", "media_or_form": [ "assessment note" ], "serial": false, "identity_strategy": "Record identity plus assessment time and evidence refs.", "source_refs": [ "SRC-001", "SRC-017" ] } ], "questions": [ { "id": "authoritative-record-characteristics-q01", "text": "Can this record be shown to be what it purports to be, created or sent by the purported agent at the purported time, and on what evidence?", "kind": "evidence", "answer_data": [ "Boolean plus evidence refs (signature, custody event, register entry, C2PA manifest) and assessed-at RFC 3339." ] }, { "id": "authoritative-record-characteristics-q02", "text": "Has integrity been maintained (complete, unaltered since capture), and what unauthorized change if any was detected?", "kind": "quality", "answer_data": [ "integrity-status; last-fixity-outcome; missing-rendition flags; incident refs." ] }, { "id": "authoritative-record-characteristics-q03", "text": "Can the record still be located, retrieved, presented and interpreted by the intended community?", "kind": "quality", "answer_data": [ "locatable boolean, retrievable boolean, presentable boolean, interpretable boolean, representation-info-gap notes." ] } ], "inline_only_rationale": null } ] }, { "id": "provenance-and-custody", "name": "Provenance and chain of custody", "description": "Where the record came from and who held it at every moment between creation and now.", "source_refs": [ "SRC-003", "SRC-002", "SRC-006" ], "findings": [ { "id": "derivation-and-provenance-graph", "name": "Derivation and provenance graph", "description": "The activities that generated the record, the sources it derives from, and the agents associated with each generating activity.", "source_refs": [ "SRC-003", "SRC-010", "SRC-002" ], "questions": [ { "id": "q-prov-generation", "text": "Which activity generated this record or version, and when did it start and end?", "kind": "provenance", "answer_data": [ "activity reference and type", "start instant", "end instant" ] }, { "id": "q-prov-derivation", "text": "Which prior records was it derived from, and is the derivation a revision, an extract or a quotation?", "kind": "relationship", "answer_data": [ "source record references", "derivation type", "derivation scope" ] }, { "id": "q-prov-attribution", "text": "Which agent was associated with each generating activity, and on whose behalf did they act?", "kind": "ownership", "answer_data": [ "associated agent reference", "delegation chain", "role in the activity" ] }, { "id": "q-prov-machine", "text": "Where a machine or model produced content, what tool, version and parameters are recorded?", "kind": "evidence", "answer_data": [ "software agent reference and version", "parameters or prompt reference", "human oversight statement" ] } ], "data_elements": [ { "id": "de-generating-activity", "name": "generatingActivity", "description": "Reference to the activity that produced the record or version.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-derived-from", "name": "derivedFrom", "description": "References to source entities from which this record was derived.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-002" ] }, { "id": "de-derivation-type", "name": "derivationType", "description": "Revision, extract, quotation, translation, redaction or format migration.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-generated-at", "name": "generatedAt", "description": "RFC 3339 instant at which generation completed.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-003" ] } ], "artifacts": [ { "id": "a-provenance-bundle", "name": "Provenance bundle or content credential manifest", "description": "A named set of provenance descriptions covering entities, activities, agents and derivations, or an asset-embedded manifest with assertions, ingredients and bindings.", "media_or_form": [ "provenance bundle", "content credential manifest store", "derivation graph" ], "serial": true, "identity_strategy": "Bundle identifier for provenance sets; asset-embedded manifests are identified by their claim signature and the hard binding they assert.", "source_refs": [ "SRC-003", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "chain-of-custody-and-transfer", "name": "Chain of custody and hand-over", "description": "The gapless sequence of custody intervals, hand-over receipts and integrity checks that allows the record to be relied on as evidence.", "source_refs": [ "SRC-002", "SRC-003", "SRC-011", "SRC-001" ], "questions": [ { "id": "q-coc-intervals", "text": "Who held the record over each interval and are there any unexplained gaps?", "kind": "temporal", "answer_data": [ "custody interval list with holder", "gap detection result", "explanation for each gap" ] }, { "id": "q-coc-receipt", "text": "What receipt or acknowledgement evidences each hand-over?", "kind": "evidence", "answer_data": [ "receipt reference", "acknowledging party", "receipt instant" ] }, { "id": "q-coc-integrity", "text": "Was integrity verified at dispatch and again at receipt, and by whom?", "kind": "validation", "answer_data": [ "pre-transfer digest and result", "post-transfer digest and result", "verifying agents" ] }, { "id": "q-coc-migration", "text": "How is the chain kept intact when a system migration rewrites storage or re-encodes content?", "kind": "exception", "answer_data": [ "migration event reference", "identifier mapping", "integrity re-baselining statement" ] } ], "data_elements": [ { "id": "de-custody-event", "name": "custodyEvent", "description": "An event at which responsibility for holding the record changed.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-002" ] }, { "id": "de-custody-from", "name": "custodyFrom", "description": "Party relinquishing custody.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-custody-to", "name": "custodyTo", "description": "Party receiving custody.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-custody-at", "name": "custodyChangedAt", "description": "RFC 3339 instant of the custody change.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "a-custody-transfer-receipt", "name": "Custody transfer receipt", "description": "Signed acknowledgement of hand-over naming both parties, the records covered, the integrity proof presented and the instant custody changed.", "media_or_form": [ "signed receipt", "acknowledgement message", "transfer register entry" ], "serial": true, "identity_strategy": "Transfer reference plus RFC 3339 hand-over instant; both parties retain matching copies bound to the same reference.", "source_refs": [ "SRC-011", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "state-time-and-recordkeeping-control", "name": "State, time and recordkeeping control", "description": "The status the record is in, the events that moved it there, the time anchors it carries, and the retention, hold and disposition regime that decides its end.", "rationale": "NARA's universal requirements organise records systems by lifecycle from capture through disposal and transfer, MoReq2010 requires an event history on every entity and separates disposal scheduling from disposal holding, and RFC 3339 makes explicit offsets mandatory; state, time and disposition are one control problem.", "source_refs": [ "SRC-011", "SRC-016", "SRC-004", "SRC-001" ], "layers": [ { "id": "status-lifecycle-and-time", "name": "Status, lifecycle events and time", "description": "Controlled status values, the append-only history of what happened, and the distinct time anchors the record carries.", "source_refs": [ "SRC-016", "SRC-006", "SRC-004" ], "findings": [ { "id": "record-status-and-transitions", "name": "Record status and permitted transitions", "description": "The controlled status vocabulary, which transitions are permitted from each state, who may authorise them, and how withdrawal differs from destruction.", "source_refs": [ "SRC-001", "SRC-016", "SRC-011" ], "questions": [ { "id": "q-status-current", "text": "What is the record's current status and since which instant has it held that status?", "kind": "state", "answer_data": [ "status code", "status-since instant", "status-setting agent" ] }, { "id": "q-status-transitions", "text": "Which transitions are permitted from the current status and who may authorise each?", "kind": "lifecycle", "answer_data": [ "permitted target statuses", "authorising role per transition", "required evidence per transition" ] }, { "id": "q-status-withdrawal", "text": "Is withdrawal or revocation distinct from destruction, and does a revoked record remain discoverable?", "kind": "exception", "answer_data": [ "withdrawal semantics statement", "discoverability rule for withdrawn records", "revocation notice reference" ] } ], "data_elements": [ { "id": "de-status", "name": "recordStatus", "description": "Current controlled status: draft, issued, effective, superseded, withdrawn, revoked, transferred or destroyed.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-016" ] }, { "id": "de-status-since", "name": "statusSince", "description": "RFC 3339 instant at which the current status took effect.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "de-transition-authority", "name": "transitionAuthority", "description": "Role or instrument authorising the transition into the current status.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] } ], "artifacts": [], "inline_only_rationale": "Status is inline state carried directly on the record and required in every projection including existence-level views; its evidence is the event history artifact in the adjacent finding, so a duplicate artifact would be a second source of truth." }, { "id": "lifecycle-events-and-audit-trail", "name": "Lifecycle events and audit trail", "description": "The append-only history of everything done to and with the record, using controlled event types with actor, outcome, event time and separately recorded observation time.", "source_refs": [ "SRC-006", "SRC-016", "SRC-011", "SRC-004" ], "questions": [ { "id": "q-event-vocab", "text": "Which event types are recorded and from which controlled vocabulary are they drawn?", "kind": "event", "answer_data": [ "event type vocabulary reference", "event type list in use", "mapping to external event vocabularies" ] }, { "id": "q-event-actor", "text": "Who performed each event, with what outcome and what detail?", "kind": "provenance", "answer_data": [ "event agent reference and role", "outcome code", "outcome detail note" ] }, { "id": "q-event-integrity", "text": "Is the trail append-only and how is its own integrity protected against tampering?", "kind": "security", "answer_data": [ "append-only enforcement mechanism", "trail digest or chaining scheme", "independent custody of the trail" ] }, { "id": "q-event-retention", "text": "How long is the audit trail retained relative to the record, and does disposition erase it?", "kind": "retention", "answer_data": [ "trail retention period", "survival-after-disposition rule", "separate storage location" ] } ], "data_elements": [ { "id": "de-event-id", "name": "eventIdentifier", "description": "Identifier of a single event entry.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-016" ] }, { "id": "de-event-type", "name": "eventType", "description": "Controlled type of the event, such as capture, migration, signing, hold or disposal.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-event-datetime", "name": "eventDateTime", "description": "RFC 3339 instant at which the event occurred.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-004" ] }, { "id": "de-event-recorded-at", "name": "eventRecordedAt", "description": "RFC 3339 instant at which the system learned of and recorded the event.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "de-event-outcome", "name": "eventOutcome", "description": "Outcome code and detail for the event.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "a-event-history", "name": "Event history and audit trail", "description": "Append-only sequence of event entries covering every action on the record, each with type, agent, outcome, event time and recording time.", "media_or_form": [ "append-only event log", "preservation event set", "chained audit entries" ], "serial": true, "identity_strategy": "Event identifier per entry, ordered by monotonic sequence within the record; entries are never edited, only superseded by correcting entries that cite the original.", "source_refs": [ "SRC-006", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "temporal-anchors-and-validity", "name": "Temporal anchors and validity periods", "description": "The distinct time anchors a record carries — created, issued, effective, expiry, received, observed — their precision, and the rule separating event time from ingestion time.", "source_refs": [ "SRC-004", "SRC-002", "SRC-012" ], "questions": [ { "id": "q-time-operative", "text": "Which datetime is the legally or operationally decisive one for this record type?", "kind": "temporal", "answer_data": [ "operative anchor name", "its value", "the rule making it decisive" ] }, { "id": "q-time-validity", "text": "Over what period is the record valid or effective, and may the period be open-ended?", "kind": "temporal", "answer_data": [ "effective-from instant", "effective-to instant or open-ended marker", "period basis" ] }, { "id": "q-time-observation", "text": "How are event time and observation or ingestion time kept distinct in every record of time?", "kind": "provenance", "answer_data": [ "event time field", "observation time field", "separation enforcement rule" ] }, { "id": "q-time-precision", "text": "How are dates of unknown precision or unknown local offset recorded?", "kind": "exception", "answer_data": [ "precision qualifier", "unknown-offset convention used", "uncertainty note" ] } ], "data_elements": [ { "id": "de-created-at", "name": "createdAt", "description": "RFC 3339 instant of creation of the content.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "de-issued-at", "name": "issuedAt", "description": "RFC 3339 instant of formal issuance.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "de-effective-from", "name": "effectiveFrom", "description": "Start of the period over which the record is valid or in force.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-effective-to", "name": "effectiveTo", "description": "End of the validity period, absent when open-ended.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-received-at", "name": "receivedAt", "description": "RFC 3339 instant at which the record was received or captured by the keeping system.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-011" ] }, { "id": "de-temporal-precision", "name": "temporalPrecision", "description": "Declared precision of a recorded time value where it is not instant-level.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "Time anchors are inline scalar values attached to the record, its versions and its events; the artifacts that carry temporal evidence are the trusted time-stamp token and the event history, both defined in other findings." }, { "id": "document-versus-record", "name": "Document versus captured record", "description": "ISO 15489 applies to records regardless of structure or form and treats capture into a records system as the act that places identified information under records controls. RiC-CM defines a Record as discrete information content formed and inscribed, at least once, on any persistent recoverable carrier by an agent in the course of activity. US 36 CFR 1220.18 / 44 U.S.C. 3301 additionally excludes extra copies kept only for reference, library or museum materials for exhibit, and personal files. This model stores a record-status on the object: document-not-captured, captured-record, nonrecord-copy, or jurisdiction-specific Federal-record, rather than splitting into two meta-models.", "source_refs": [ "SRC-001", "SRC-019", "SRC-021" ], "data_elements": [ { "id": "document-versus-record-data01", "name": "Record status", "description": "Enumerated status: document-not-captured, captured-record, nonrecord-copy or jurisdiction-specific Federal-record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-021" ] }, { "id": "document-versus-record-data02", "name": "Jurisdictional record determination", "description": "Structured determination that the object is a record under a named jurisdiction.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021" ] }, { "id": "document-versus-record-data03", "name": "Nonrecord or personal-file reason", "description": "Enumerated excluding criterion where the object is a nonrecord, extra copy or personal file.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021" ] } ], "artifacts": [ { "id": "document-versus-record-artifact01", "name": "Capture or nonrecord declaration", "description": "The decision record that this object is or is not managed as a record, with authority and time.", "media_or_form": [ "decision record" ], "serial": false, "identity_strategy": "Bound to the object identifier plus determination time and deciding authority.", "source_refs": [ "SRC-001", "SRC-021" ] } ], "questions": [ { "id": "document-versus-record-q01", "text": "Has this object been captured as a record, and under which jurisdiction or policy is that determination made?", "kind": "classification", "answer_data": [ "Enum record-status; optional jurisdiction code; policy or statute citation; determined-by agent ref; determined-at RFC 3339." ] }, { "id": "document-versus-record-q02", "text": "If it is a nonrecord, extra copy or personal file, what is the excluding criterion?", "kind": "classification", "answer_data": [ "Enum nonrecord-reason plus free-text justification and ownership (agency versus individual)." ] }, { "id": "document-versus-record-q03", "text": "Who has authority to determine record status when systems or staff disagree?", "kind": "authority", "answer_data": [ "Agent or role ref plus cited mandate. For US Federal records, NARA determination is binding per the Federal Records Act as reflected in 36 CFR." ] } ], "inline_only_rationale": null } ] }, { "id": "retention-disposition-and-holds", "name": "Retention, disposition and holds", "description": "The authorised schedule that decides the record's fate, the suspensions that override it, and the evidence that survives execution.", "source_refs": [ "SRC-001", "SRC-011", "SRC-016" ], "findings": [ { "id": "retention-schedule-and-authority", "name": "Retention class and disposition authority", "description": "The retention class assigned to the record, the instrument authorising it, the trigger that starts the clock and the action due at the end.", "source_refs": [ "SRC-001", "SRC-011", "SRC-016" ], "questions": [ { "id": "q-ret-authority", "text": "Which retention class applies and under which authority instrument and citation?", "kind": "authority", "answer_data": [ "retention class notation", "authority instrument reference", "citation string", "jurisdiction" ] }, { "id": "q-ret-trigger", "text": "What event triggers the retention clock and how is that trigger detected?", "kind": "event", "answer_data": [ "trigger event type", "trigger detection mechanism", "trigger occurrence instant" ] }, { "id": "q-ret-outcome", "text": "Is the record permanent or temporary, and what disposition action falls due at the end of the period?", "kind": "decision", "answer_data": [ "permanent or temporary flag", "retention period", "disposition action code", "computed due date" ] }, { "id": "q-ret-conflict", "text": "When two schedules apply to the same record, which one prevails?", "kind": "exception", "answer_data": [ "precedence rule", "prevailing schedule reference", "conflict resolution record" ] } ], "data_elements": [ { "id": "de-retention-class", "name": "retentionClass", "description": "Class assigning the record to a retention regime.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-016" ] }, { "id": "de-disposition-authority", "name": "dispositionAuthorityCitation", "description": "Citation of the instrument authorising the retention and disposition of the class.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-retention-trigger", "name": "retentionTriggerEvent", "description": "Event type that starts the retention period.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-retention-period", "name": "retentionPeriod", "description": "Duration for which the record must be kept after the trigger.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-disposition-due-at", "name": "dispositionDueAt", "description": "Computed date at which the disposition action becomes due.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "a-retention-schedule", "name": "Retention schedule or disposition authority instrument", "description": "The authorised schedule mapping classes to trigger events, periods, permanence and disposition actions, with its jurisdiction and period of force.", "media_or_form": [ "authority instrument", "schedule table", "approved records schedule" ], "serial": false, "identity_strategy": "Authority citation allocated by the competent archival or regulatory authority plus item number and version; superseded schedules are retained for records disposed of under them.", "source_refs": [ "SRC-011", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "holds-and-suspension", "name": "Holds and disposition suspension", "description": "Legal holds and other suspensions that override retention schedules until explicitly released, and the mechanism that prevents automated disposal of held records.", "source_refs": [ "SRC-016", "SRC-011", "SRC-001" ], "questions": [ { "id": "q-hold-scope", "text": "What is the scope of the hold — this record, its aggregation, or a query-defined set resolved at a moment in time?", "kind": "composition", "answer_data": [ "scope definition", "resolved record set with resolution instant", "scope re-evaluation rule" ] }, { "id": "q-hold-authority", "text": "Who placed the hold, under what proceeding or authority, and when?", "kind": "authority", "answer_data": [ "placing agent", "proceeding or authority reference", "placement instant" ] }, { "id": "q-hold-release", "text": "What must be true before the hold can be released and disposition resumed?", "kind": "constraint", "answer_data": [ "release conditions", "releasing authority", "release instant and evidence" ] }, { "id": "q-hold-enforcement", "text": "How is hold state surfaced so that no automated process can dispose of a held record?", "kind": "security", "answer_data": [ "enforcement point description", "hold check in the disposition function", "failure mode if the check is unavailable" ] } ], "data_elements": [ { "id": "de-hold-id", "name": "holdIdentifier", "description": "Identifier of the hold instrument.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-hold-basis", "name": "holdBasis", "description": "Proceeding, investigation or statutory basis for the hold.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-hold-placed-at", "name": "holdPlacedAt", "description": "RFC 3339 instant at which the hold took effect.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-hold-released-at", "name": "holdReleasedAt", "description": "RFC 3339 instant of release, absent while the hold is active.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-hold-active", "name": "holdActive", "description": "Whether any hold currently suspends disposition of this record.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-016" ] } ], "artifacts": [ { "id": "a-legal-hold-notice", "name": "Legal hold notice", "description": "Instrument placing or releasing a hold, naming the scope, the basis, the issuing authority and the instants of placement and release.", "media_or_form": [ "notice instrument", "hold record entry", "preservation order" ], "serial": true, "identity_strategy": "Hold identifier plus issuing authority reference; release is a new dated entry against the same hold identifier, never a deletion.", "source_refs": [ "SRC-016", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "disposition-execution-and-evidence", "name": "Disposition execution and surviving evidence", "description": "Carrying out destruction, transfer or permanent retention, and the evidence and tombstone that outlive the record itself.", "source_refs": [ "SRC-011", "SRC-001", "SRC-016", "SRC-012" ], "questions": [ { "id": "q-disp-authorisation", "text": "Who authorised the disposition and was the absence of any hold verified at that moment?", "kind": "authority", "answer_data": [ "authorising agents (at least two)", "hold check result and instant", "authority citation applied" ] }, { "id": "q-disp-method", "text": "What method was used and is it verifiable as irreversible for the carrier concerned?", "kind": "process", "answer_data": [ "destruction or transfer method", "verification method", "verifying agent" ] }, { "id": "q-disp-survivors", "text": "What evidence survives destruction and which metadata fields are kept as a tombstone?", "kind": "retention", "answer_data": [ "surviving evidence artifact references", "tombstone field list", "tombstone retention period" ] }, { "id": "q-disp-transfer", "text": "For transfer, what accession identifier and integrity proof did the receiving body return?", "kind": "interoperability", "answer_data": [ "accession identifier", "receiving body reference", "integrity proof returned", "acceptance instant" ] } ], "data_elements": [ { "id": "de-disposition-executed-at", "name": "dispositionExecutedAt", "description": "RFC 3339 instant at which the disposition action was carried out.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-011" ] }, { "id": "de-disposition-method", "name": "dispositionMethod", "description": "Method of destruction, transfer or permanent retention applied.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-tombstone-fields", "name": "tombstoneFields", "description": "Minimal metadata retained after the record body is gone.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-016" ] }, { "id": "de-accession-ref", "name": "accessionReference", "description": "Identifier allocated by the receiving archives on transfer.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "a-destruction-certificate", "name": "Disposition certificate", "description": "Signed evidence that a named set of records was destroyed under a named authority, listing identifiers, method, authorisers and the execution instant.", "media_or_form": [ "signed certificate", "disposal report", "destruction register entry" ], "serial": true, "identity_strategy": "Disposition run identifier plus record identifier; retained under its own schedule after the record itself no longer exists.", "source_refs": [ "SRC-011", "SRC-001" ] }, { "id": "a-transfer-accession-manifest", "name": "Transfer and accession manifest", "description": "Inventory of records transferred to another custodian or to permanent archives, with digests, counts, transfer instant and the accession returned.", "media_or_form": [ "transfer manifest", "accession record", "package inventory with digests" ], "serial": true, "identity_strategy": "Accession number allocated by the receiving archives plus the sending party's transfer identifier; both are retained on each side.", "source_refs": [ "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "access-rights-and-interoperability", "name": "Access, rights and interoperability", "description": "Who may see what, on what legal footing content may be reused, and how the record and its evidence move between systems without losing meaning.", "rationale": "NARA's transfer guidance makes access restriction status a mandatory transfer element, DCMI supplies accessRights, license and rightsHolder, and IANA and format registries govern the value space for exchange; access and interoperability are governed together because every projection is an access decision.", "source_refs": [ "SRC-012", "SRC-002", "SRC-009", "SRC-011" ], "layers": [ { "id": "access-and-rights", "name": "Access, security marking and rights", "description": "Markings and decisions controlling who may read the record, and the intellectual-property and personal-data constraints on reuse.", "source_refs": [ "SRC-012", "SRC-002", "SRC-001" ], "findings": [ { "id": "access-conditions-and-security-marking", "name": "Access conditions and security marking", "description": "The security marking and access restriction status carried by the record, the statutory regime behind them, and the recorded decisions on individual requests.", "source_refs": [ "SRC-012", "SRC-002", "SRC-001", "SRC-011" ], "questions": [ { "id": "q-acc-marking", "text": "What security marking and access restriction status does the record carry, and who set them?", "kind": "access", "answer_data": [ "security marking code", "access restriction status", "setting agent and instant" ] }, { "id": "q-acc-regime", "text": "Which statutory access or exemption regime applies, and for how long does the restriction run?", "kind": "authority", "answer_data": [ "regime reference", "exemption citation", "restriction review or expiry date" ] }, { "id": "q-acc-existence", "text": "What is disclosed at existence level when the content itself is withheld?", "kind": "privacy", "answer_data": [ "existence-level field list", "neither-confirm-nor-deny rule if any", "withholding basis" ] }, { "id": "q-acc-decisions", "text": "How are grants, denials and emergency access events recorded and reviewed?", "kind": "evidence", "answer_data": [ "decision record fields", "reviewing role", "notification obligations and deadlines" ] } ], "data_elements": [ { "id": "de-security-marking", "name": "securityMarking", "description": "Confidentiality or protective marking applied to the record.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-access-restriction-status", "name": "accessRestrictionStatus", "description": "Whether access is unrestricted, restricted or closed, and on what basis.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-002" ] }, { "id": "de-restriction-basis", "name": "restrictionBasis", "description": "Statutory or contractual basis for the restriction.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-restriction-review-at", "name": "restrictionReviewDate", "description": "Date on which the restriction must be reviewed or lapses.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "a-access-decision-record", "name": "Access decision record", "description": "Entry recording one access request: requester, purpose, requested scope, decision, decision-maker, reasons and the RFC 3339 decision instant.", "media_or_form": [ "decision log entry", "formal response letter", "authorisation token record" ], "serial": true, "identity_strategy": "Request identifier plus RFC 3339 decision instant; denials and break-glass events are recorded with the same fidelity as grants.", "source_refs": [ "SRC-011", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "rights-licensing-and-personal-data", "name": "Rights, licensing and personal data", "description": "Who holds rights in the content, under what licence it may be reused, and what personal data within it constrains processing and release.", "source_refs": [ "SRC-002", "SRC-001", "SRC-012" ], "questions": [ { "id": "q-rights-holder", "text": "Who holds rights in the content and under which licence may it be reused?", "kind": "ownership", "answer_data": [ "rights holder reference", "licence identifier or IRI", "permitted uses and restrictions" ] }, { "id": "q-rights-personal", "text": "Does the record contain personal or special-category data, and on what lawful basis is it processed?", "kind": "privacy", "answer_data": [ "personal data categories present", "lawful basis statement", "data subject rights applicable" ] }, { "id": "q-rights-redaction", "text": "What redactions produced the releasable derivative, and is the unredacted source preserved intact?", "kind": "process", "answer_data": [ "redaction scope and basis per passage", "derivative instantiation reference", "source preservation confirmation" ] } ], "data_elements": [ { "id": "de-rights-holder", "name": "rightsHolder", "description": "Reference to the person or organization owning or managing rights in the content.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-licence", "name": "license", "description": "Licence granting permission to use the content.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-personal-data-category", "name": "personalDataCategory", "description": "Categories of personal data present in the record.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-redaction-ref", "name": "redactionReference", "description": "Reference linking a redacted derivative to its source and to the basis for each redaction.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "a-rights-statement", "name": "Rights statement or licence instrument", "description": "Statement of rights held and the terms under which the content may be reused, redistributed or published.", "media_or_form": [ "licence text", "rights statement IRI", "assignment instrument" ], "serial": false, "identity_strategy": "Licence IRI where a published licence is used; otherwise the instrument reference of the granting party plus version.", "source_refs": [ "SRC-002" ] }, { "id": "a-redaction-log", "name": "Redaction and release log", "description": "Record of every redaction applied to produce a releasable derivative, with the passage affected, the basis and the approving agent.", "media_or_form": [ "redaction schedule", "annotated derivative", "release register entry" ], "serial": true, "identity_strategy": "Derivative instantiation identifier plus source instantiation identifier plus release instant; the derivative is a new instantiation and never overwrites the source.", "source_refs": [ "SRC-003", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "interoperability-and-exchange", "name": "Interoperability and exchange", "description": "Declared mappings to external metadata standards and the packaging and projection rules for moving records between systems.", "source_refs": [ "SRC-002", "SRC-006", "SRC-009", "SRC-011" ], "findings": [ { "id": "metadata-alignment-and-conformance", "name": "Metadata alignment and conformance evidence", "description": "Which external standards the record's metadata is mapped to, where mappings lose information, and what evidence is required before any conformance claim is made.", "source_refs": [ "SRC-002", "SRC-006", "SRC-008", "SRC-001" ], "questions": [ { "id": "q-map-targets", "text": "Which external standards is this metadata mapped to, and at which version of each?", "kind": "interoperability", "answer_data": [ "target standard identifiers", "target versions", "mapped element pairs" ] }, { "id": "q-map-loss", "text": "Where does a mapping lose information or contradict another target, and how is the loss recorded?", "kind": "quality", "answer_data": [ "lossy mapping list", "contradiction description", "mitigation or annotation applied" ] }, { "id": "q-map-conformance", "text": "What evidence supports any conformance claim, and who validated it?", "kind": "validation", "answer_data": [ "conformance claim text", "evidence artifact reference", "validating party and date" ] } ], "data_elements": [ { "id": "de-mapping-target", "name": "mappingTarget", "description": "External standard to which the metadata is mapped.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] }, { "id": "de-mapping-version", "name": "mappingTargetVersion", "description": "Version of the target standard covered by the mapping.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-mapping-lossiness", "name": "mappingLossiness", "description": "Statement of what the mapping cannot carry.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-conformance-claim", "name": "conformanceClaim", "description": "Any asserted conformance, permitted only with a cited evidence artifact.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-001" ] } ], "artifacts": [ { "id": "a-crosswalk-specification", "name": "Metadata crosswalk specification", "description": "Element-by-element mapping between this model and a named external standard version, marking lossy and unmappable elements.", "media_or_form": [ "mapping table", "transformation definition", "alignment document" ], "serial": false, "identity_strategy": "Mapping identifier plus source and target standard versions; a new target version requires a new mapping, not an edit.", "source_refs": [ "SRC-002", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "exchange-packaging-and-projections", "name": "Exchange packaging and projections", "description": "How a record and its evidence are packaged for transfer or publication, and how each projection deliberately omits parts without breaking reconstructability.", "source_refs": [ "SRC-006", "SRC-009", "SRC-011", "SRC-012" ], "questions": [ { "id": "q-pkg-structure", "text": "What package structure and manifest are used, and how is package integrity proven on arrival?", "kind": "interoperability", "answer_data": [ "package profile identifier", "manifest structure", "package-level digest and algorithm" ] }, { "id": "q-pkg-projection", "text": "Which projection is being served and which fields does it deliberately omit?", "kind": "access", "answer_data": [ "projection name", "included field list", "omitted field list and reason" ] }, { "id": "q-pkg-reconstruction", "text": "How does a receiving system reconstruct identity, version chain, fixity and events from the package alone?", "kind": "validation", "answer_data": [ "identity mapping in the package", "version chain representation", "fixity and event carriage" ] }, { "id": "q-pkg-encoding", "text": "Which media types, character encodings and normalisation rules apply to the payload?", "kind": "constraint", "answer_data": [ "media types used", "character encoding", "normalisation rules applied before hashing" ] } ], "data_elements": [ { "id": "de-package-id", "name": "packageIdentifier", "description": "Identifier of the exchange package.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-package-profile", "name": "packageProfile", "description": "Named packaging profile governing structure and required elements.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-011" ] }, { "id": "de-package-fixity", "name": "packageFixity", "description": "Digest covering the package as a whole.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-006" ] }, { "id": "de-projection-name", "name": "projectionName", "description": "Named subset served to a consumer, such as an existence-level listing, an evidentiary view or a disposition worklist.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "a-exchange-package-manifest", "name": "Exchange package manifest", "description": "Self-describing inventory of a submission, archival or dissemination package, listing records, versions, instantiations, digests, events and the profile in force.", "media_or_form": [ "package manifest", "inventory with digests", "transfer descriptor" ], "serial": true, "identity_strategy": "Package identifier plus the package-level digest; a re-generated package is a new package with a new identifier.", "source_refs": [ "SRC-006", "SRC-011", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-assign-record-identity", "name": "Assign record identity", "description": "Select and bind the identifier that will denote the record for its whole life, following the identity priority.", "inputs": [ "candidate master-system identifier", "identifier scheme reference", "minting agent", "granularity level" ], "outputs": [ "assigned record identifier", "identifier assignment event" ], "preconditions": [ "identity priority evaluated in order and the chosen tier recorded", "scheme is registered and its resolution commitment is known" ], "effects": [ "record becomes referenceable across projections", "identifier is reserved permanently and never reused, including after disposition" ], "source_refs": [ "SRC-015", "SRC-016", "SRC-002" ] }, { "id": "fn-capture-record", "name": "Capture or create record", "description": "Bring an authored or received information object under recordkeeping control.", "inputs": [ "content or received bytes", "documentary form", "classification class", "responsible agent", "receipt or creation instant" ], "outputs": [ "record with initial version", "capture event", "baseline fixity value" ], "preconditions": [ "identifier assigned", "documentary form and classification selected", "access restriction status determined" ], "effects": [ "received bytes preserved unaltered as the capture instantiation", "any normalisation recorded as a separate derivative with its own provenance" ], "source_refs": [ "SRC-001", "SRC-011", "SRC-006" ] }, { "id": "fn-issue-version", "name": "Issue version", "description": "Fix a new immutable content state and link it into the version chain.", "inputs": [ "draft content", "change note", "issuing authority" ], "outputs": [ "immutable version", "supersession link", "version issued event" ], "preconditions": [ "issuer authorised for the record's class", "prior version exists and is not blocked by a hold that forbids amendment" ], "effects": [ "prior version marked superseded and retained", "version sequence incremented and never renumbered" ], "source_refs": [ "SRC-002", "SRC-016", "SRC-008" ] }, { "id": "fn-produce-instantiation", "name": "Produce instantiation", "description": "Create a format-specific or carrier-specific realisation of an existing version.", "inputs": [ "source version", "target format profile", "producing agent" ], "outputs": [ "instantiation", "format characterisation report", "fixity value" ], "preconditions": [ "source version is fixed", "target format identifiable in a media type and format registry" ], "effects": [ "instantiation bound to exactly one version", "significant properties compared before and after and any loss recorded" ], "source_refs": [ "SRC-006", "SRC-009", "SRC-014" ] }, { "id": "fn-verify-fixity", "name": "Verify fixity", "description": "Recompute and compare digests for an instantiation or package against its baseline.", "inputs": [ "instantiation or package reference", "algorithm" ], "outputs": [ "fixity check result", "fixity check event" ], "preconditions": [ "a baseline fixity value with a named algorithm exists" ], "effects": [ "mismatches raise an integrity incident and trigger recovery from a verified replica", "failures are never silently repaired or overwritten" ], "source_refs": [ "SRC-006", "SRC-012" ] }, { "id": "fn-apply-signature-or-seal", "name": "Apply signature or seal", "description": "Bind a signature, seal or attestation to fixed content at a declared assurance tier.", "inputs": [ "version or instantiation reference", "signing credential", "signature policy" ], "outputs": [ "signature object", "signing event" ], "preconditions": [ "content is fixed and its digest computed", "credential valid at signing time and of the tier required for the documentary form" ], "effects": [ "signature binds a named digest; any later content change invalidates it rather than migrating with it" ], "source_refs": [ "SRC-007", "SRC-010" ] }, { "id": "fn-timestamp-and-validate", "name": "Timestamp and validate evidence", "description": "Obtain a trusted time-stamp token and record a dated validation outcome for a signature or manifest.", "inputs": [ "content or signature digest", "timestamping authority endpoint", "validation policy" ], "outputs": [ "time-stamp token", "signature validation report" ], "preconditions": [ "digest algorithm accepted by the validation policy", "trust anchors and revocation sources reachable" ], "effects": [ "validity recorded as a dated outcome under a named policy, never as a permanent flag", "renewal scheduled ahead of algorithm or certificate weakening" ], "source_refs": [ "SRC-005", "SRC-007", "SRC-010" ] }, { "id": "fn-record-custody-transfer", "name": "Record custody transfer", "description": "Move holding responsibility to another party without breaking the chain of custody.", "inputs": [ "record set", "transferring party", "receiving party", "pre-transfer integrity proof" ], "outputs": [ "custody transfer receipt", "custody events on both sides" ], "preconditions": [ "receiving party accepts the custody terms", "fixity verified before dispatch" ], "effects": [ "custody intervals remain gapless", "integrity re-verified on receipt and the result recorded on both sides" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-011" ] }, { "id": "fn-assign-retention", "name": "Assign retention", "description": "Bind the record to a retention class under a named authority and compute when disposition falls due.", "inputs": [ "record", "classification class", "authority instrument", "trigger event definition" ], "outputs": [ "retention assignment", "computed disposition due date" ], "preconditions": [ "authority instrument in force for the jurisdiction", "trigger event type detectable by the system" ], "effects": [ "disposition becomes schedulable", "schedule conflicts resolved by the declared precedence rule and the resolution recorded" ], "source_refs": [ "SRC-001", "SRC-011", "SRC-016" ] }, { "id": "fn-place-or-release-hold", "name": "Place or release hold", "description": "Suspend or resume disposition for a defined scope of records.", "inputs": [ "scope definition", "authority or proceeding reference", "reason", "placing or releasing agent" ], "outputs": [ "hold record", "hold event", "resolved affected record list" ], "preconditions": [ "scope resolvable at the moment of placement and the resolution instant recorded" ], "effects": [ "disposition blocked for every in-scope record until an explicit, separately authorised release", "release recorded as a new dated entry rather than by deleting the hold" ], "source_refs": [ "SRC-016", "SRC-011" ] }, { "id": "fn-execute-disposition", "name": "Execute disposition", "description": "Carry out destruction, transfer or permanent retention for records whose period has elapsed.", "inputs": [ "due record set", "authorisation from two parties", "method", "hold check result" ], "outputs": [ "disposition certificate or transfer manifest", "tombstone", "disposition events" ], "preconditions": [ "retention period elapsed", "no active hold at the moment of execution", "authority instrument still in force" ], "effects": [ "action is irreversible", "evidence artifact and tombstone survive the record and are retained under their own schedule" ], "source_refs": [ "SRC-011", "SRC-001", "SRC-016" ] }, { "id": "fn-issue-certified-copy", "name": "Issue certified copy or extract", "description": "Produce an attested copy or extract traceable to a named source version.", "inputs": [ "source version or instantiation", "certifying authority", "requester", "extract scope if partial" ], "outputs": [ "copy instantiation", "certified copy attestation", "issue event" ], "preconditions": [ "source integrity verified immediately before copying", "certifier competent in the governing jurisdiction" ], "effects": [ "copy is marked as a copy and never becomes the original of record", "omissions in an extract are stated explicitly in the attestation" ], "source_refs": [ "SRC-013", "SRC-007", "SRC-008" ] }, { "id": "fn-evaluate-access-request", "name": "Evaluate access request", "description": "Decide and record whether a requester may read a record or a projection of it.", "inputs": [ "requester identity", "stated purpose", "requested scope", "applicable regime" ], "outputs": [ "access decision record", "released projection or refusal with reasons" ], "preconditions": [ "security marking and access restriction status known", "statutory regime and exemptions identified" ], "effects": [ "decision, denial or emergency access logged with the decision instant", "break-glass access notifies the owner within the declared window" ], "source_refs": [ "SRC-012", "SRC-011", "SRC-001" ] }, { "id": "fn-export-exchange-package", "name": "Export exchange package", "description": "Assemble a self-describing package of records and their evidence for transfer or publication.", "inputs": [ "record set", "package profile", "projection", "target media types" ], "outputs": [ "exchange package", "package manifest with digests" ], "preconditions": [ "all referenced instantiations resolvable", "fixity current for every included instantiation" ], "effects": [ "receiver can reconstruct identity, version chain, fixity and event history from the package alone", "omitted fields are declared in the manifest rather than silently dropped" ], "source_refs": [ "SRC-006", "SRC-009", "SRC-011" ] }, { "id": "fn-classify-record", "name": "Assign classification and marking", "description": "Assign business class, documentary form, index terms and confidentiality or security marking from authorized schemes.", "inputs": [ "Authorized classification and marking schemes" ], "outputs": [ "Assigned business class, documentary form, index terms and confidentiality or security marking" ], "preconditions": [], "effects": [ "Assignments recorded against the record without authoring the scheme" ], "source_refs": [ "SRC-023", "SRC-002" ] }, { "id": "fn-register-record", "name": "Register in custodial register", "description": "Create an existence-level register entry with entry number, registered-at and custodian, without transferring ownership.", "inputs": [], "outputs": [ "Existence-level register entry with entry number, registered-at and custodian" ], "preconditions": [], "effects": [ "No transfer of ownership" ], "source_refs": [ "SRC-019", "SRC-002" ] }, { "id": "fn-migrate-or-convert", "name": "Migrate or convert", "description": "Create a successor instantiation in another format or medium, record the PREMIS/OAIS event, and keep the source instantiation unless disposition authorizes its destruction.", "inputs": [ "Source instantiation", "Target format or medium" ], "outputs": [ "Successor instantiation in another format or medium" ], "preconditions": [], "effects": [ "PREMIS/OAIS migration event recorded", "Source instantiation retained unless disposition authorizes its destruction" ], "source_refs": [ "SRC-018", "SRC-020", "SRC-023" ] }, { "id": "fn-assess-authoritativeness", "name": "Verify authenticity and integrity", "description": "Recompute fixity, validate signatures or content credentials, and record an assessment of authenticity, integrity and usability with observation time.", "inputs": [], "outputs": [ "Recomputed fixity result", "Signature or content-credential validation result", "Assessment of authenticity, integrity and usability" ], "preconditions": [], "effects": [ "Assessment recorded with observation time" ], "source_refs": [ "SRC-018", "SRC-022", "SRC-001" ] } ], "composition": [ { "target": "WM-REC-015 Archival fonds / collection", "relation": "CHILD", "purpose": "Records governed here are the members that archival aggregations contain; membership references are stored here, arrangement and multi-level description there.", "required": false, "source_refs": [ "SRC-008", "SRC-001" ] }, { "target": "Agent model — natural person", "relation": "REFERENCE", "purpose": "Authors, approvers, signatories and custodial officers are agents held disjoint from the resource in both PROV-O and RiC-O; only role-qualified references are stored here.", "required": true, "source_refs": [ "SRC-003", "SRC-008" ] }, { "target": "Agent model — organization / corporate body", "relation": "REFERENCE", "purpose": "Issuing organizations, custodians, registers and receiving archives are corporate bodies governed elsewhere; eIDAS attaches seals to legal persons, so the reference must be resolvable.", "required": true, "source_refs": [ "SRC-008", "SRC-007" ] }, { "target": "Identifier and naming scheme model", "relation": "REFERENCE", "purpose": "Scheme syntax, registration and resolution commitments, as modelled by the DOI system under ISO 26324, are governed outside this model; only scheme, value and assigning authority are carried here.", "required": true, "source_refs": [ "SRC-015", "SRC-016" ] }, { "target": "Time and calendar model", "relation": "REFERENCE", "purpose": "Retention triggers and validity periods anchor to calendar and working-day rules held elsewhere; this model constrains stored values to RFC 3339 instants with explicit offsets.", "required": true, "source_refs": [ "SRC-004" ] }, { "target": "Message and communication model", "relation": "COMPOSE", "purpose": "Message attachments resolve to records governed here; eIDAS keeps electronic registered delivery services distinct from electronic documents, so transport semantics stay in the communication model.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "Storage and object-store model", "relation": "REFERENCE", "purpose": "PREMIS separates File and Bitstream objects from the intellectual entity; byte storage, replication and tiering are referenced, not modelled here.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "DCMI Metadata Terms (2020-01-20)", "relation": "MIX-IN", "purpose": "Descriptive metadata facet applied to every record: title, creator, issued, modified, format, extent, language, accessRights, license, provenance and the version and replacement relations.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "ISO 15489-1:2016 Records management — Concepts and principles", "relation": "ALIGN", "purpose": "Vocabulary alignment for records, metadata for records, records systems, records processes and the characteristics of authoritative records; alignment only, no conformance claimed.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "PREMIS Data Dictionary for Preservation Metadata 3.0", "relation": "ALIGN", "purpose": "Alignment for object categories, fixity, format, significant properties, storage, and the Event, Agent and Rights entities used by the preservation and audit findings.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "ICA Records in Contexts Ontology 1.1", "relation": "ALIGN", "purpose": "Alignment for the record resource versus instantiation split, documentary form and carrier types, and the partitive and provenance relations.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "W3C PROV-O", "relation": "ALIGN", "purpose": "Alignment for derivation, generation, attribution, association and delegation, and for bundling provenance as an entity in its own right.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "Regulation (EU) No 910/2014 (eIDAS)", "relation": "ALIGN", "purpose": "Alignment for electronic document, signature and seal tiers, electronic time stamps and validation; the tier vocabulary is EU-specific and other jurisdictions map differently.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "UNCITRAL Model Law on Electronic Commerce (1996)", "relation": "ALIGN", "purpose": "Alignment for functional equivalence: the criteria under which an electronic instantiation satisfies paper concepts of writing, signature and original.", "required": false, "source_refs": [ "SRC-013" ] }, { "target": "C2PA Technical Specification 2.1", "relation": "ALIGN", "purpose": "Alignment for asset-level provenance manifests, hard and soft bindings, ingredients and validation, used where content credentials travel with a rendition.", "required": false, "source_refs": [ "SRC-010" ] }, { "target": "IANA Media Types registry", "relation": "REFERENCE", "purpose": "Normative value space for the mediaType element on instantiations and exchange packages.", "required": true, "source_refs": [ "SRC-009" ] }, { "target": "PRONOM technical registry", "relation": "REFERENCE", "purpose": "Value space for fine-grained format identifiers and rendering dependencies beyond what media types express.", "required": false, "source_refs": [ "SRC-014" ] }, { "target": "NARA Universal ERM Requirements v3 and MoReq2010 v1.1", "relation": "ALIGN", "purpose": "Alignment for the operating surface: capture, maintenance and use, disposal, transfer, metadata and reporting, plus disposal scheduling and disposal holding as separate services.", "required": false, "source_refs": [ "SRC-011", "SRC-016" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name one accountable record owner (the author or issuing organization) and, separately, any custodian; the package must state that custody never confers ownership and that a custodian cannot widen access or dispose.", "Declare every retention authority instrument the Dimension operates under, with its jurisdiction, period of force and precedence rule when two instruments collide.", "Publish the identifier schemes in use and the resolution endpoint for each before any record is registered, together with the non-reuse guarantee.", "Declare the accepted fixity algorithms, the minimum signature assurance tier per documentary form, and the algorithm sunset dates that trigger evidence renewal." ], "namespace_guidance": "Use a registry-rooted namespace such as vr.wm-rec-001 for model terms and a separate, resolvable namespace for instance identifiers. Never reuse an instance IRI for a different record, even after disposition; a disposed record keeps its IRI as a tombstone. Keep term IRIs stable across projections — JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are renderings of the same terms.", "registry_links": [ "IANA Media Types registry for every mediaType value (SRC-009)", "PRONOM for fine-grained format identification and rendering dependencies (SRC-014)", "DOI registration agencies under ISO 26324 where a citable persistent identifier is required (SRC-015)", "The competent archival authority's approved records schedules for retention classes and disposition authority citations (SRC-011)" ] }, "canon_and_patch": { "canonicalization_rules": [ "The canonical form is the ordered set of semantic fields, not any serialisation; storage and interface formats are projections and must round-trip the semantics.", "Normalise every timestamp to RFC 3339 with seconds and an explicit offset or Z before comparison or hashing; never normalise to local time.", "Canonicalise identifiers as scheme plus value; comparison is case-sensitive unless the governing scheme declares otherwise.", "Hash content and metadata under separate digests, so that a permitted metadata correction cannot invalidate a content fixity value." ], "patch_rules": [ "Issued versions are immutable: a correction is a new version with a supersession link and a change note, never an in-place edit.", "Descriptive and control metadata may be patched in place, but each patch writes an event entry carrying the previous value, the new value, the actor, the reason, the event time and the observation time.", "A patch must never change identity, retention class, recorded fixity values or a signature binding; each of those requires the corresponding governed function.", "Patches to a record under an active hold are rejected unless the hold instrument explicitly permits metadata correction, and the permission is cited in the event." ], "compatibility_rules": [ "Adding an optional field or a vocabulary term is a minor change; removing a field, tightening cardinality, or changing identifier granularity or semantics is breaking.", "External alignments may be added, re-versioned or withdrawn without a breaking change, but a conformance claim may never be added without a cited evidence artifact.", "Deprecated terms are retained with a deprecation date and a replacement pointer for at least one major version, and remain resolvable thereafter." ] }, "artifact_rules": { "identity_priority": [ "First: the authoritative master-system identifier issued by the system of record, such as a register entry number or an issuing organization's document number.", "Second: a governed global identifier or IRI, such as a DOI under ISO 26324, a Handle, an ARK or a registry-governed IRI with a published persistence commitment.", "Third: a UUID or ULID minted by the adopting Dimension, recorded together with the minting agent and the RFC 3339 minting instant.", "Never an identifier: a date, a title, a file name, a storage path or a content digest. A digest is a fixity value and is identical across duplicate copies, so it cannot denote a record." ], "timestamp_rule": "All time values use RFC 3339 date-time with seconds and an explicit UTC offset or Z; where the offset is genuinely unknown use the -00:00 convention rather than assuming Z. Event time (when it happened) and observation or ingestion time (when the system learned of it) are always stored as separate fields and neither is inferred from the other.", "serial_naming_rule": "Serial artifacts — versions, fixity manifests, format reports, validation reports, event entries, holds, receipts, disposition certificates and packages — are named //-. Sequences are monotonic per record and per kind, and are never reused or renumbered, including after an artifact body is deleted.", "integrity_rule": "Every artifact carries at least one fixity value with a named algorithm and its RFC 3339 computation instant. Artifacts with legal effect additionally carry a signature or seal and, where obtainable, a trusted time-stamp token so that their evidential value survives credential expiry or revocation. Integrity failures are recorded as events and recovered from a verified replica; they are never silently repaired." }, "policies": [ "No conformance to ISO 15489, PREMIS, RiC, eIDAS, C2PA, MoReq2010 or NARA requirements may be published without a cited evidence artifact naming the validating party and date; external standards are otherwise carried as alignments only.", "Disposition is irreversible and therefore requires an in-force authority instrument, an elapsed retention period, a hold check performed at the moment of execution, two-party authorisation, and a surviving evidence artifact plus tombstone.", "Access to record content is granted by the owner; a custodian may narrow but never widen access, and every grant, denial, exception and emergency access is logged with the same fidelity.", "Personal data within a record is processed only on a declared lawful basis; redaction produces a new derivative instantiation linked to its source and never overwrites the source.", "The audit trail, hold instruments and disposition evidence are stored so that disposing of the record does not erase them.", "Capture assigns a unique identifier before the object is treated as a record under controls.", "Content bytes of an issued version are replaced only by issuing a successor version.", "Default deny content access; metadata may be separately authorized; every content disclosure writes a use event.", "Retention assignment is mandatory for captured records; unscheduled US Federal records are ineligible for destruction.", "Legal and administrative holds overlay and block disposition until every applicable hold is released.", "Owner grants access; custodian or registrar may operate the store without acquiring ownership.", "Authenticity evidence (signature, seal, timestamp, C2PA, fixity) always names the signed version or instantiation.", "Certified copies bind to a named source version hash and do not overwrite the source identity." ], "crud": { "read": [ "Existence-level metadata — identifier, documentary form, classification, key dates, status — is readable by any authenticated agent unless the record carries a restriction that covers existence itself.", "Reading content requires an access decision recorded against the requester, the stated purpose, the scope and the RFC 3339 decision instant.", "Reads of records under an active hold are logged with the hold reference so that the reading is discoverable in proceedings." ], "create": [ "Creation requires an identifier assigned by the identity priority, a documentary form, a classification class, a responsible agent and an event time.", "Capture of an externally received record preserves the received bytes unaltered and records the receipt event before any normalisation, which is then recorded as a separate derivative." ], "update": [ "Only descriptive and control metadata may be updated in place; any change to content requires a new version.", "Every update writes an event entry with actor, reason, previous and new values, event time and observation time." ], "delete": [ "Logical withdrawal from active use is a distinct state from physical destruction and must never be conflated with it.", "Physical destruction executes only through the disposition function and always leaves a disposition certificate and a tombstone retaining identifier, form, classification, key dates and the authority applied.", "Deletion of provenance, audit-trail, hold or disposition-evidence artifacts is prohibited while the parent record exists, and those artifacts outlive the record under their own schedule." ] }, "roles": [ { "name": "Record owner (author or issuing organization)", "responsibilities": [ "Accountable for the record's existence, accuracy and classification", "Grants and revokes access to content and metadata", "Authorises issuance of new versions and approves disposition" ] }, { "name": "Custodian or registrar", "responsibilities": [ "Holds the record and maintains the register entry on the owner's behalf", "Maintains fixity, storage and the chain of custody without acquiring ownership", "Escalates to the owner any request that would widen access or alter content" ] }, { "name": "Records manager", "responsibilities": [ "Maintains the classification scheme and retention schedules and their authority citations", "Resolves schedule conflicts under the declared precedence rule", "Runs the disposition worklist and obtains the required authorisations" ] }, { "name": "Preservation engineer", "responsibilities": [ "Performs format identification, characterisation and fixity verification on schedule", "Plans and executes migration or emulation before format obsolescence", "Records every preservation action as an event with byte-change status" ] }, { "name": "Legal hold custodian", "responsibilities": [ "Places, scopes, monitors and releases holds under a named authority", "Verifies that no automated process can dispose of an in-scope record", "Retains hold instruments and release evidence independently of the records held" ] }, { "name": "Access and data protection officer", "responsibilities": [ "Applies security markings, statutory exemptions and restriction review dates", "Decides access requests and approves redacted derivatives for release", "Reviews break-glass events and notifies owners within the declared window" ] }, { "name": "Auditor", "responsibilities": [ "Reads holds, events, fixity artifacts and access logs without content access", "Tests that the audit trail is append-only and that disposition evidence survives", "Reports unexplained custody gaps and unverifiable conformance claims" ] } ], "access": { "default_rule": "Deny by default for record content. Existence-level metadata is readable by authenticated agents unless the record carries a restriction that extends to its existence; every content read requires a recorded decision.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Statutory access rights such as freedom-of-information and data-subject access override an owner's denial, subject to the declared exemptions and their review dates.", "Legal hold custodians and auditors receive read access to holds, event history, fixity artifacts and access logs without any right to content.", "Emergency break-glass access is available to named roles, is logged in full, and triggers notification to the owner within the declared window.", "Receiving archives obtain full read access to transferred records and their evidence at the moment custody transfers, under the transfer instrument.", "Court order, warrant or statutory disclosure duty", "Redacted dissemination DIP that omits exempt passages", "Privileged attorney-client or personnel content visible only to named roles", "Disability or accessibility reformatting that must not be treated as a new original", "Emergency vital-records retrieval logged after the fact within a defined SLA" ], "audit_requirements": [ "Log requester identity, stated purpose, requested scope, decision, decision-maker and the RFC 3339 decision instant for every access event.", "Retain access logs at least as long as the record's retention period and store them separately, so that disposition of the record does not erase the trail.", "Log denied and failed access attempts at the same fidelity as grants, and review break-glass events on a declared cycle.", "Record which projection was served, so that an omission can later be distinguished from an absence of data.", "Log capture, version issue, signature, register, classify, hold place/release, access decision, use, migration and disposition with agent, event time and ingestion time.", "Retain access and disposition logs at least as long as the record or as required by the audit schedule, whichever is longer.", "Fixity failures and signature invalidations raise integrity incidents linked to the object." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Owner", "Identifier scheme and resolution endpoint", "Retention authority instruments in force", "Default access rule", "Accepted fixity algorithms" ], "read_order": [ "AGENTS.md — model name, type and the four resolvable URLs, plus owner, identifier scheme and default access rule", "Specification URL — bundles, layers, findings, questions and data elements, and the boundaries to sibling models", "Storage type URL — how the chosen projection stores records, versions, instantiations, events and artifacts, and what it cannot express", "Interface URL — read, create, update and delete rules and the governed function endpoints", "Processes URL — capture, versioning, signing, validation, custody transfer, hold, disposition and export workflows", "Registry links — media types, format registry, identifier schemes and retention authorities in force for this Dimension" ] } }, "coverage": { "claim": "Merged model covers the governed-record decision and operating surface on the Claude base: identity and designation; documentary form and business classification; content, components and completeness; versions and instantiations including original/copy status; format identification, fixity and preservation; authorship, ownership, custody, issuance and registration; signatures, seals, trusted timestamps and dated validation evidence; provenance and chain of custody; status, lifecycle events and temporal anchors; retention, holds and disposition with surviving evidence; access, security marking, rights and personal data; and metadata alignment, exchange packaging and projections. Three Grok findings (capture threshold / record status, record-to-record supersession, authoritative-record characteristics) and four Grok operations (classify, register, migrate/convert, authoritativeness assessment) close real gaps in that surface. This is coverage of the stated surface only — not universal completeness, and no conformance to ISO, PREMIS, RiC, OAIS, eIDAS or C2PA is claimed.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Three-tier identity priority with explicit granularity (record, version, instantiation), non-reuse guarantee and tombstone rule; digests and titles explicitly excluded as identifiers. Grounded in DOI/ISO 26324 persistence model and MoReq2010 system identifiers." }, { "dimension": "lifecycle", "status": "covered", "notes": "Status vocabulary with permitted transitions and authorising roles, plus an append-only event history; capture, maintenance and use, disposal and transfer follow the NARA lifecycle grouping." }, { "dimension": "relationships", "status": "covered", "notes": "Supersession, amendment, derivation, aggregation membership, instantiation-of, signs, suspends and transfer relations are all carried, with the record/instantiation split taken from RiC-O and PREMIS." }, { "dimension": "temporal", "status": "covered", "notes": "RFC 3339 with explicit offset mandated everywhere; event time and observation time separated as a rule, not a convention; validity periods may be open-ended; unknown-offset convention -00:00 adopted." }, { "dimension": "provenance", "status": "covered", "notes": "PROV-O generation, derivation, attribution and delegation, plus chain of custody with gap detection and integrity checks at both dispatch and receipt; machine-generated content requires tool, version and parameters." }, { "dimension": "ownership", "status": "covered", "notes": "Owner and custodian separated with explicit custodial limits; ownership transfer modelled as its own evented act distinct from custody transfer; rights holder and licence held separately from ownership of the record." }, { "dimension": "validation", "status": "covered", "notes": "Validation outcomes are dated results under a named policy rather than static flags; fixity verification, completeness checks, format characterisation and conformance evidence each have explicit answer data." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default for content with existence-level metadata as the baseline projection; statutory override, auditor and hold-custodian carve-outs, break-glass with notification, and full logging of denials." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention class, authority citation, trigger, period and due date; holds override schedules and require separate release; disposition is two-party authorised, irreversible, and leaves certificate and tombstone. Actual periods are jurisdiction-specific and deliberately not asserted." }, { "dimension": "interoperability", "status": "covered", "notes": "Crosswalks declared with target versions and lossiness; media types from IANA and format identifiers from PRONOM; packages must let a receiver reconstruct identity, version chain, fixity and events unaided." }, { "dimension": "authenticity and evidentiary value", "status": "covered", "notes": "Signature and seal tiers from eIDAS, RFC 3161 tokens, C2PA manifests and evidence renewal before algorithm sunset; functional equivalence of writing, signature and original taken from UNCITRAL." }, { "dimension": "classification", "status": "covered", "notes": "Documentary form vocabulary and business classification scheme are separate findings, with scheme versioning, reclassification history and a precedence rule for multi-class filing." }, { "dimension": "security and privacy", "status": "covered", "notes": "Security markings, restriction status and review dates, personal-data categories with lawful basis, and redaction as a new derivative that never overwrites its source." }, { "dimension": "measurement", "status": "covered", "notes": "Extent, byte size, digests with named algorithms and computation instants, significant-property comparison, and verification frequency are all captured as measured values with method and time." }, { "dimension": "exception", "status": "covered", "notes": "Explicit exception questions for schedule conflicts, multi-class filing, custody gaps at migration, fixity failure, unknown temporal precision and neither-confirm-nor-deny disclosure." }, { "dimension": "jurisdiction and spatial", "status": "gap", "notes": "Jurisdiction, place of issue and governing law are carried as fields, but the model has no primary-sourced rule set for resolving conflict of laws when a record is created in one jurisdiction, held in a second and disclosed in a third. Marked as a gap rather than presented as canonical." }, { "dimension": "transferable records and control", "status": "gap", "notes": "Singularity and control of electronic transferable records (UNCITRAL MLETR) are not modelled; the retrieved MLEC page did not carry the article text and MLETR was not retrieved. Records that function as negotiable instruments need a sibling model." } ], "known_omissions": [ "Conservation treatment and environmental storage conditions for analogue carriers.", "Electronic transferable records: control, singularity and the guaranteed-uniqueness requirement.", "Cryptographic key lifecycle and hardware security module operation underpinning long-term signature preservation.", "Appraisal methodology (macro-appraisal, functional analysis) that produces retention schedules in the first place; the model consumes schedules but does not derive them.", "Vital-records designation and disaster-recovery prioritisation.", "Rendering fidelity and accessibility conformance of renditions.", "Full-text indexing, retrieval and relevance semantics.", "Cost, storage tiering and the economics of permanent retention.", "MoReq2010 / Modular Requirements for Records Systems not fetched as primary text.", "DoD 5015.02-STD Electronic Records Management Software Application Design Criteria not fetched.", "ISO 16175 (records in business systems), ISO 14641 (electronic archiving) and ISO 17068 (trusted third party repository) not fetched.", "ISO 19005 PDF/A, METS, BagIt (RFC 8493) and PRONOM/DROID as format-identification practice not modelled in depth.", "InterPARES authenticity requirements not fetched.", "EDRM / FRCP 37(e) litigation-hold primary texts not fetched; holds rest on ISO unauthorized-destruction protection plus 36 CFR unscheduled freeze.", "Vital records / business-continuity copies, encrypted or DRM-inhibited objects (PREMIS inhibitors) only lightly touched.", "Database, GIS and other dynamic system-of-record snapshots as records: in ISO 15489 scope by principle, under-specified here.", "Spoken, audiovisual and 3D records beyond Instantiation/format.", "National variants beyond US CFR, eIDAS and JIS identical adoption (e.g. Australian Archives Act, UK TNA, China GB/T 18894) not retrieved.", "Blockchain or distributed-register identity as an emerging identifier class not given primary support." ], "conflicts": [ "Three incompatible manifestation models coexist in the cited sources: PREMIS 3.0 makes Intellectual Entity a category of Object with Representation, File and Bitstream beneath it; RiC-O separates Record from Instantiation; DCMI keeps a single resource related by hasVersion/isVersionOf. This model normalises to record / version / instantiation and claims conformance to none of the three.", "The eIDAS text used was the rendition published by legislation.gov.uk because EUR-Lex returned no parseable content on repeated attempts. The EU consolidated text has since been amended by Regulation (EU) 2024/1183, which adds concepts such as electronic attestation of attributes and electronic ledgers that are not reflected here.", "NARA transfer guidance still specifies an MD5 checksum for embedded case files, while preservation and integrity practice requires SHA-2 or SHA-3. The model therefore permits multiple algorithms per instantiation and requires declared sunset dates rather than adopting either position.", "MoReq2010 requires a system-assigned unique identifier for every entity, which conflicts with the identity priority's preference for the authoritative master-system identifier whenever records migrate between systems; the model resolves this by recording the system identifier as an alternate identifier with an equivalence basis.", "C2PA hard bindings bind to the bytes of a specific rendered asset, so a manifest cannot survive a rendition change, whereas record identity must. Provenance manifests are therefore treated as per-instantiation evidence and never as record identity.", "'Record' in US federal practice is defined by agency business context and is narrower than the general information-object sense used here; NARA requirements are aligned, not adopted wholesale.", "ISO 15489-1:2016 full text is paywalled and returned HTTP 403; the characteristics of authoritative records and the records-process list were verified only from the ISO catalogue abstract and indexed extracts, so ISO-attributed claims are the weakest-evidenced in this model.", "ISO 15489 treats aggregations as records under the same principles; RiC-CM insists a Record Set is a different entity from a Record. This model sides with RiC for aggregations (WM-REC-015) and ISO for capture-as-record lifecycle.", "PREMIS Intellectual Entity versus RiC Record versus DCMI BibliographicResource versus OAIS Content Information are overlapping but not identical; mapped, not merged.", "US 44 U.S.C. 3301 record definition is jurisdiction-specific and excludes extra copies and exhibit materials; ISO 15489 has no such Federal-record test.", "eIDAS qualified signature legal effect does not automatically apply outside the EU; C2PA trust does not equal eIDAS qualification.", "Version (content change) versus rendition/format (hasFormat) versus Instantiation (carrier) are frequently collapsed in ECM products.", "Owner, custodian, rights holder and creator are often stored as a single 'author' field in implementations; standards distinguish them.", "Data-subject erasure (e.g. GDPR Art. 17, not fetched as primary here) can conflict with authorized retention; surfaced as an unresolved rights question rather than a default destroy.", "C2PA hard binding and PREMIS fixity both hash bytes but serve different trust frameworks and must not be treated as interchangeable certificates." ], "regional_assumptions": [ "Signature assurance tiers (simple, advanced, qualified) and seal semantics are eIDAS-specific to the EU and EEA; the US (ESIGN/UETA) and other jurisdictions use different tiering, and the model carries a tier code rather than asserting a universal ladder.", "Disposition authority, general records schedules, accession and transfer semantics are drawn from US federal practice and UK archival practice; other jurisdictions place these powers differently.", "PRONOM PUIDs are a de facto rather than universal format registry, originating with The National Archives (UK).", "Retention periods, hold triggers and destruction verification standards are jurisdiction- and sector-specific; no default period is asserted anywhere in the model.", "Access and exemption regimes vary by jurisdiction; the model carries markings, bases and review dates but never a statutory interpretation.", "Register publicity conventions differ sharply between civil-law public registers and common-law custodial registers; the model records publicity status as data.", "ISO 15489/23081 and RiC-CM are treated as the international backbone.", "US 36 CFR/44 U.S.C. definitions apply only when the adopting Dimension asserts US Federal jurisdiction.", "eIDAS signature levels apply when the adopting Dimension asserts EU/EEA trust-service law.", "C2PA is optional and currently most relevant to media and generated-content assets in adopting markets.", "Language of description defaults to the record's content language; multilingual titles are allowed via localized strings.", "RFC 3339 timestamps with explicit offset or Z are required even where local records law still uses date-only cutoffs; date-only values should be normalized with an explicit policy, not inferred." ], "adversarial_checks": [ "Tested whether version and instantiation can collapse into one concept: rejected. A format migration changes bytes and digests without changing content, and PREMIS and RiC-O both keep the layers apart; collapsing them would make every migration look like an amendment.", "Tested whether the archival aggregation belongs in this model: rejected. RiC-O models RecordSet as a distinct class and the registry already assigns aggregation to WM-REC-015; only membership references are retained here.", "Tested whether signature validity can be a static attribute: rejected. Validity depends on the validation moment, the policy, revocation data and algorithm strength, so it is recorded as a dated outcome with its own artifact, and untimestamped manifests are treated as expiring.", "Searched for counterexamples to 'every record has a version chain': born-final register entries, receipts and immutable ledger entries have exactly one version, so version cardinality is 1..n and a single-version record is normal rather than exceptional.", "Tested whether document equals file: rejected. One record can span many files and one file can carry many records (compound PDFs, mailboxes, case bundles), which is why storage location is a reference and identity is never a path or a digest.", "Tested whether retention can be modelled without holds: rejected. A hold must take precedence over an in-force schedule and requires its own separately authorised release, so disposal scheduling and disposal holding are modelled as distinct concerns, as MoReq2010 does.", "Tested whether an inline-only finding was being used to dodge the artifact requirement: each of the four inline-only findings (identity anchor, designation, responsibility roles, status, temporal anchors) points to the artifact elsewhere in the model that evidences it, rather than claiming no evidence exists.", "Checked whether disposition can erase its own evidence: rejected. Audit trail, holds and disposition certificates are stored under separate custody and outlive the record, otherwise destruction would be unauditable.", "Would a filename, object-storage key or 'document date' be accepted as the master identifier? The model forbids it; identity finding requires a typed scheme.", "Would converting PDF to PDF/A mint a new record identity or only a rendition? Format-of versus version-of is an explicit question; conversion is a migration event.", "Would deleting the last working copy while a preservation AIP remains be logged as record destruction? Last-copy and package-role questions block that collapse.", "Would a C2PA soft binding or watermark be used as the record id? Explicitly forbidden; soft bindings are lookup hints.", "Would releasing one of two overlapping holds authorize destruction? Remaining-active-hold-ids must be empty.", "Would a custodian's register rights be treated as ownership or as a right to grant public access? Stewardship and access default_rule keep owner as grantor.", "Would an unscheduled US Federal record appear on a destroy worklist? Unscheduled-treat-as-permanent is a first-class status.", "Would a certified extract that omits annexes keep the original record id? Certified-copy finding forces a same-identity versus new-extract choice." ] }, "researchAdjudication": { "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "Providers disagree (claude=aggregate, grok=entity) and the disagreement is resolved in favour of aggregate. Versions, instantiations, signatures, custody intervals, hold assignments and disposition evidence have no independent identity or lifecycle outside the record, and the model's hardest invariants are consistency boundaries that span them: a hold must block disposition across every instantiation, disposition must leave a tombstone that outlives the children, and identity must survive migration and rendition change. Grok's 'entity' reading is contradicted by its own last-copy and overlapping-hold checks, which are aggregate-scoped invariants. Aggregation into record sets stays outside the boundary and remains WM-REC-015, which both providers assert independently." }, "decisions": [ { "concept": "Base provider selection", "disposition": "claude as base", "rationale": "Claude's boundary notes name seven actual sibling models (WM-REC-015, agent, naming, time, communication, dataset, file/object storage) with a sourced distinction for each; Grok's notes are largely standards-alignment statements rather than model boundaries. Claude also carries the sibling-excluding out-of-scope list that a deterministic synthesizer needs. Size was not the deciding factor." }, { "concept": "Entry kind aggregate vs entity", "disposition": "aggregate accepted", "rationale": "Holds, last-copy destruction and tombstone survival are invariants that span versions, instantiations and evidence objects; only an aggregate root gives them a consistency boundary. Grok's own adversarial checks assume that boundary while its declared entry kind denies it." }, { "concept": "Capture threshold and record status (grok document-versus-record)", "disposition": "accepted into status-lifecycle-and-time", "rationale": "Materially absent from the base, which begins after the object is already a record. Supplies the nonrecord/extra-copy/personal-file exclusion tests and the competence-to-decide question, sourced to ISO 15489, RiC-CM and 36 CFR 1220.18." }, { "concept": "Record-to-record supersession (grok)", "disposition": "accepted into versions-and-instantiations", "rationale": "Base covers supersession only within one identity's version chain. Distinguishing a successor record from a new version, and denying that supersession authorises destruction, is an operative rule an agent needs and is DCMI-backed." }, { "concept": "Authoritative-record characteristics (grok)", "disposition": "accepted into signatures-and-validation", "rationale": "Adds the ISO 15489/23081 authentic-reliable-integral-usable property set as dated assessed evidence, and repairs the base's weakest-evidenced area where ISO text was unavailable behind HTTP 403, using an accessible identical national adoption." }, { "concept": "Master and public identifiers (grok)", "disposition": "rejected as duplicative", "rationale": "Base record-identity-anchor already carries scheme, granularity, non-reuse and alternate-identifier equivalence, and pins identity priority with DOI/ISO 26324 and MoReq2010 evidence. Grok adds no rule the base lacks." }, { "concept": "Descriptive metadata and classification assignment (grok)", "disposition": "rejected as duplicative", "rationale": "Split across three base findings — designation-and-reference-numbers, documentary-form and classification-and-aggregation — which additionally add scheme versioning, reclassification history and multi-class precedence that Grok lacks." }, { "concept": "Fixity and extent (grok)", "disposition": "rejected as duplicative", "rationale": "Base fixity-and-preservation-actions covers baseline digest, verification history, byte-changing actions and failure handling. Only declared-versus-measured extent is genuinely absent, and that is a question-level gap not worth importing a near-duplicate finding for; deferred instead." }, { "concept": "Record relationships / DCMI relation family (grok)", "disposition": "rejected as mostly duplicative", "rationale": "Part/whole, format-of, version-of, derivation and set membership are all already carried across base findings. Only requires/isRequiredBy dependency links are missing, so the residue is deferred as a question addition rather than importing overlapping structure." }, { "concept": "OAIS preservation package events / SIP-AIP-DIP (grok)", "disposition": "rejected, alignment deferred", "rationale": "Base exchange-packaging-and-projections already treats a package as a projection of one record and demands reconstructability, and format-identification-and-environment covers rendering environment. OAIS ISO 14721:2025 is absent from base sources, so the alignment is deferred rather than the structure imported." }, { "concept": "C2PA content-credentials binding (grok)", "disposition": "rejected as duplicative", "rationale": "Base already carries content-credential manifests as per-instantiation provenance evidence and records the hard-binding-cannot-be-identity resolution as an explicit conflict, which is the same rule Grok states." }, { "concept": "Legal and administrative holds (grok)", "disposition": "rejected as duplicative and weaker", "rationale": "Base holds-and-suspension carries scope, authority, release condition and anti-automation enforcement with retrieved MoReq2010 text; Grok itself records that its hold schemas rest on partial primary support with DoD 5015.02 and MoReq unretrieved." }, { "concept": "Disposition execution and last-copy rule (grok)", "disposition": "rejected as a finding; gap retained", "rationale": "Base disposition-execution-and-evidence duplicates authorisation, method, survivors and transfer. The one distinctive rule — destroying one instantiation is not destroying the record while another authoritative instantiation remains — is an unresolved aggregate-scope gap and is deferred rather than imported inside a duplicate finding." }, { "concept": "Rights and licences (grok)", "disposition": "rejected as duplicative", "rationale": "Base rights-licensing-and-personal-data covers rights holder, licence, personal-data lawful basis and redaction-as-derivative. The distinctive erasure-versus-retention conflict rests on GDPR text neither provider retrieved, so it is deferred rather than accepted." }, { "concept": "Certified copies and use events (grok)", "disposition": "rejected as duplicative", "rationale": "Certified copies are covered by base instantiation-copy-and-original-status with its attestation artifact and fn-issue-certified-copy; use logging is covered by lifecycle-events-and-audit-trail and access decision recording." }, { "concept": "Archival aggregation (fonds, series, record sets)", "disposition": "excluded to WM-REC-015", "rationale": "Both providers independently exclude it on RiC grounds, keeping only membership references and the aggregate identifier at filing time. The agreement is treated as settled and the boundary is carried into the merged model unchanged." }, { "concept": "Grok-only operations: classify, register, migrate, assess", "disposition": "accepted as functions", "rationale": "Each corresponds to a base finding that currently has no operation, so accepting them closes operating-surface gaps without introducing structure that competes with existing functions." }, { "concept": "Standards conformance language", "disposition": "suppressed in merged draft", "rationale": "Both providers normalise across three incompatible manifestation models (PREMIS, RiC, DCMI) and explicitly disclaim conformance; the merged draft must inherit that disclaimer rather than either provider's alignment wording." } ], "publicationHolds": [ "Source verification incomplete: re-verify every accepted source URL live and pin its version before publication. Claude's ISO 15489-1 source returned HTTP 403 and its ISO-attributed claims were read from catalogue abstracts and indexed extracts; re-verify them against Grok's JIS X 0902-1:2019 identical adoption or licensed ISO text before any ISO-derived statement is published.", "eIDAS evidence is second-hand on both sides: Claude used the legislation.gov.uk rendition of Article 3 and flags that Regulation (EU) 2024/1183 amendments are not reflected; Grok used a European Commission FAQ guidance page. Re-pin signature, seal and qualified-timestamp tiers to consolidated EU text before publishing the assurance-tier vocabulary.", "Instrument version drift must be reconciled to one pinned version each: RiC-O 1.1 (2025, Claude) versus RiC-CM 1.0 (2023, Grok), and C2PA 2.1 (Claude) versus C2PA 2.4 (Grok). Publish only after the record/instantiation split and the hard-binding rule are re-checked against the chosen versions.", "Multi-profile domain validation not yet complete: the merged model has been reasoned mainly against archival and government recordkeeping profiles. Validate against at least three materially different profiles — an EU qualified-signature commercial instrument, a US federal case file under 36 CFR, and a media or generated-content asset carrying content credentials — before publication.", "Confirm the WM-REC-015 boundary once that model exists, so aggregation-membership references and the record-set exclusion resolve to real structure rather than a placeholder neighbour.", "Strip any residual conformance-claim wording inherited from either provider; the published draft must state alignment and mapping only, with lossiness recorded." ], "deferredResearch": [ "Electronic transferable records under UNCITRAL MLETR: control, singularity and guaranteed uniqueness. Claude marks it a declared gap and Grok does not model it; likely a sibling model rather than an addition here.", "Conflict-of-laws rule set for records created in one jurisdiction, held in a second and disclosed in a third. Both providers carry jurisdiction as a field with no sourced resolution rule; keep marked as a gap, never as canonical.", "GDPR Article 17 erasure versus authorised retention duty: fetch the primary text and decide whether the conflict is carried as an unresolved question on the record or delegated to a rights/consent sibling model. Neither provider retrieved it.", "Last-copy and multi-instantiation destruction semantics: when destruction of one instantiation does or does not destroy the record identity, and how the tombstone reflects partial destruction. Grok raises it; the base has no rule.", "OAIS ISO 14721:2025 alignment: representation information for a designated community and SIP/AIP/DIP package roles — decide align-versus-reference against the base exchange-packaging finding rather than importing package structure.", "Legal-hold primary schemas not retrieved by either provider: DoD 5015.02-STD, the MoReq2010 hold module in detail, and FRCP 37(e). Needed before hold scope, overlapping holds and release semantics can be stated as sourced rather than pattern-based.", "Requires/isRequiredBy and references/isReferencedBy dependency relations between records (an annex, schema or referenced instrument needed to interpret the record) — evaluate as question-level additions to the content-and-components layer.", "Declared-versus-measured extent (bytes, pages, duration) as a validation check on an instantiation; currently implied by the base coverage checklist but present in no base question.", "InterPARES authenticity requirements and ISO 16175 / 14641 / 17068, none retrieved by either provider, as corroboration for the accepted authoritative-record-characteristics finding." ] }, "statistics": { "sources": 24, "bundles": 6, "layers": 13, "findings": 29, "questions": 108, "artifacts": 27, "functions": 18 } }