# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T12:14:13Z", "synthesisSha256": "33e4724330510bba66773257b1fb22482629d4e5f7617e511cf38b6ab577f472", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-REC-008", "registryId": "vr.wm-rec-008", "name": "Certificate / Credential Record", "version": "0.1.0-research.1", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.REC.CRT" ], "tags": [ "certificate", "credential", "record", "inf.rec.crt" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-rec-008-certificate-credential-record/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-rec-008", "model": { "registry_id": "vr.wm-rec-008", "model_id": "WM-REC-008", "name": "Certificate / Credential Record", "entry_kind": "entity", "purpose": "Describe the issued documentary representation of an attestation and its controlled local record context.", "scope_statement": "One identified documentary record representing an issued attestation, with payload variants, provenance and references to status and verification evidence. The root is a record entity, not the underlying grant, attestation lifecycle, presentation session or verification engine. Scanned and paper-derived representations are allowed as recorded evidence with explicitly unresolved authenticity.", "in_scope": [ "Record identity, documentary class, issuer and subject references, extracted claims and profile bindings", "Issued payload, copies, receipt, provenance, time assertions and observed status", "Verification-report references, disclosure references, correction lineage, retention and loss-aware projections" ], "out_of_scope": [ "Creation of substantive attestations or grants; issuer accreditation and identity master systems", "Issuing, renewing, suspending or revoking credentials; key management, proof generation and cryptographic verification execution", "Presentation-session ownership across credentials; wallet operation, authentication and relying-party authorization decisions", "Universal legal recognition, paper forensic authentication, sector certification and executable protocol conformance" ], "boundary_notes": [ { "neighbor": "WM-XCT-017 Attestation / Credential", "distinction": "Registry parent is a candidate semantic relationship. Reference the attestation and its status authority; this record model must not duplicate issuance, suspension, revocation or acceptance operations. Parent publication is a reviewable draft, not a pinned runtime dependency.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008" ] }, { "neighbor": "WM-POL-004 Permit / Authorization and WM-PER-013 Professional License / Credential", "distinction": "Optional references to the process or governed grant evidenced by the document. Possessing or deleting a copy does not grant or extinguish rights.", "source_refs": [ "SRC-001", "SRC-006" ] }, { "neighbor": "WM-XCT-006 Verification / ZK Attestation", "distinction": "Reference an external verification report and its method. Cryptographic algorithms and selective disclosure proof generation remain outside the local record.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Presentation session and identity masters", "distinction": "A presentation can combine multiple credentials and has independent identity. Holder, subject, custodian and issuer are distinct references; a local copy does not establish their equivalence.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "Recommendation 2025-05-15", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:13:08Z", "relevance": "Sections 1.1-1.2, 4.4-4.13 and 5.1: credential identity, roles, claims, time and validation distinction. Sections 8-9: privacy and security. Digital profile, not a universal certificate law." }, { "id": "SRC-002", "title": "Verifiable Credential Data Integrity 1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-integrity/", "version_or_date": "Recommendation 2025-05-15", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:13:08Z", "relevance": "Sections 2.1 and 3: proof metadata and verification context. Domain, challenge and proof purpose need profile-specific processing; no cryptographic implementation is supplied here." }, { "id": "SRC-003", "title": "Bitstring Status List v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-bitstring-status-list/", "version_or_date": "Recommendation 2025-05-15", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:13:08Z", "relevance": "Sections 2, 3 and 6: status purpose, referenced list entries, validation and correlation concerns. One status mechanism, not mandatory for all records." }, { "id": "SRC-004", "title": "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List Profile", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc5280", "version_or_date": "RFC 5280, May 2008; subsequent updates and errata not comprehensively verified", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:13:08Z", "relevance": "Sections 4.1, 4.2, 5 and 6: certificate fields, issuer-scoped serial, validity, extensions, revocation evidence and path-validation context. PKI-specific alignment only." }, { "id": "SRC-005", "title": "X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc6960", "version_or_date": "RFC 6960, June 2013; subsequent updates and errata not comprehensively verified", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:13:08Z", "relevance": "Sections 2.2-2.4 and 4.2: response states, freshness and response verification. A good status is not proof of issuance or universal acceptance." }, { "id": "SRC-006", "title": "Digital Identity Guidelines: Federation and Assertions", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/800-63-4/sp800-63c.html", "version_or_date": "SP 800-63C-4, 2025 edition; browser page timestamp 2025-08-26", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:13:08Z", "relevance": "Subscriber-controlled wallets, trust agreements, authentication and attribute disclosure, privacy and usability. Federation-specific guidance informs local disclosure questions, not universal credential requirements." }, { "id": "SRC-007", "title": "Open Badges Specification", "organization": "1EdTech Consortium", "url": "https://www.imsglobal.org/spec/ob/v3p0/", "version_or_date": "Specification 3.0, document 1.4.5, issued 2026-06-29 as displayed", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:13:08Z", "relevance": "Conceptual model and Criteria, Achievement, Evidence and credential classes support an education profile. Mutable version route and conformance mapping remain verification holds." }, { "id": "SRC-008", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:13:08Z", "relevance": "Entity attribution, generation, derivation and revision support documentary lineage. They do not establish authenticity or lawful retention." } ], "structure": { "bundles": [ { "id": "bundle-identity", "name": "Identity and roles", "description": "Establish the documentary root and independently governed parties.", "rationale": "Proposed documentary concern supported by the cited profiles; profile-specific obligations stay external.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-identity", "name": "Documentary identity", "description": "Maintain a local stable record key independently of issuer serials and public credential identifiers. Classify the representation and pin its profile before interpreting fields.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ], "findings": [ { "id": "finding-identity", "name": "Record identity and profile", "description": "Maintain a local stable record key independently of issuer serials and public credential identifiers. Classify the representation and pin its profile before interpreting fields.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ], "questions": [ { "id": "q-identity-1", "text": "Which master record and issuer-scoped identifiers distinguish this credential from its copies?", "kind": "identity", "answer_data": [ "master_record_ref, issuer_ref, issuer_serial, public_id, local_id, reconciliation_state", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-identity-2", "text": "Which credential class, representation type and schema revision govern this record?", "kind": "classification", "answer_data": [ "class_code, medium, schema_uri, schema_version, binding_status", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-identity-3", "text": "When an external identifier is absent or reused, which evidence prevents a false merge?", "kind": "constraint", "answer_data": [ "collision_evidence, matching_basis, unresolved_candidates, merge_authority", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-identity-1", "name": "Record identity and profile group 1", "description": "Candidate fields: master_record_ref, issuer_ref, issuer_serial, public_id, local_id, reconciliation_state. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] }, { "id": "data-identity-2", "name": "Record identity and profile group 2", "description": "Candidate fields: class_code, medium, schema_uri, schema_version, binding_status. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] }, { "id": "data-identity-3", "name": "Record identity and profile group 3", "description": "Candidate fields: collision_evidence, matching_basis, unresolved_candidates, merge_authority. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-identity", "name": "Record identity and profile evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-parties", "name": "Parties and authority references", "description": "Keep record stewardship distinct from issuing authority and possession. External role and authority evidence may be unresolved or contested.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "findings": [ { "id": "finding-parties", "name": "Issuer subject holder and custodian", "description": "Keep record stewardship distinct from issuing authority and possession. External role and authority evidence may be unresolved or contested.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "questions": [ { "id": "q-parties-1", "text": "Who is the issuer, who or what is each subject, and how does the holder relate to them?", "kind": "relationship", "answer_data": [ "issuer_ref, subject_refs, holder_ref, relationship_basis, unknown_roles", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-parties-2", "text": "Which external evidence supports the issuer or delegated signer for this claim type?", "kind": "authority", "answer_data": [ "authority_evidence_ref, delegation_ref, claim_scope, assessed_at, dispute_state", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-parties-3", "text": "Which custodian controls this local copy and which source remains authoritative for credential status?", "kind": "ownership", "answer_data": [ "custodian_ref, copy_role, source_master_ref, status_authority_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-parties-1", "name": "Issuer subject holder and custodian group 1", "description": "Candidate fields: issuer_ref, subject_refs, holder_ref, relationship_basis, unknown_roles. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "data-parties-2", "name": "Issuer subject holder and custodian group 2", "description": "Candidate fields: authority_evidence_ref, delegation_ref, claim_scope, assessed_at, dispute_state. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "data-parties-3", "name": "Issuer subject holder and custodian group 3", "description": "Candidate fields: custodian_ref, copy_role, source_master_ref, status_authority_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-parties", "name": "Issuer subject holder and custodian evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-content", "name": "Claims and evidence", "description": "Separate issued assertions, interpretations and supporting material.", "rationale": "Proposed documentary concern supported by the cited profiles; profile-specific obligations stay external.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-claims", "name": "Claims and qualifications", "description": "Store an attributed projection of the issued claim with qualifiers. A local interpretation or translation must remain distinguishable from signed source content.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ], "findings": [ { "id": "finding-claims", "name": "Claim projection and limitations", "description": "Store an attributed projection of the issued claim with qualifiers. A local interpretation or translation must remain distinguishable from signed source content.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ], "questions": [ { "id": "q-claims-1", "text": "What assertion is actually present in the issued payload and to which subject does it apply?", "kind": "definition", "answer_data": [ "claim_path, predicate, value, datatype, subject_ref, source_payload_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-claims-2", "text": "Which scheme, criteria or permitted-use restrictions qualify the assertion?", "kind": "requirement", "answer_data": [ "scheme_ref, criteria_revision, restriction_refs, scope, jurisdiction_assertion", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-claims-3", "text": "Which extraction, language or unsupported-extension issue could change the meaning of the claim?", "kind": "quality", "answer_data": [ "extraction_method, language, translation_ref, unresolved_extension, review_state", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-claims-1", "name": "Claim projection and limitations group 1", "description": "Candidate fields: claim_path, predicate, value, datatype, subject_ref, source_payload_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] }, { "id": "data-claims-2", "name": "Claim projection and limitations group 2", "description": "Candidate fields: scheme_ref, criteria_revision, restriction_refs, scope, jurisdiction_assertion. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] }, { "id": "data-claims-3", "name": "Claim projection and limitations group 3", "description": "Candidate fields: extraction_method, language, translation_ref, unresolved_extension, review_state. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-claims", "name": "Claim projection and limitations evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-evidence", "name": "Supporting context", "description": "Index cited support without re-performing the underlying assessment. Distinguish evidence supplied by an issuer from later local observations or disputed material.", "source_refs": [ "SRC-007", "SRC-008" ], "findings": [ { "id": "finding-evidence", "name": "Attestation and assessment evidence references", "description": "Index cited support without re-performing the underlying assessment. Distinguish evidence supplied by an issuer from later local observations or disputed material.", "source_refs": [ "SRC-007", "SRC-008" ], "questions": [ { "id": "q-evidence-1", "text": "Which cited assessment or achievement evidence supports each projected claim?", "kind": "evidence", "answer_data": [ "claim_ref, evidence_refs, criteria_ref, evidence_role", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-evidence-2", "text": "Who supplied or derived each evidence reference and when was the link recorded?", "kind": "provenance", "answer_data": [ "source_agent_ref, derivation_ref, link_event_time, observed_at", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-evidence-3", "text": "What missing, restricted or contradictory evidence prevents a substantiated interpretation?", "kind": "exception", "answer_data": [ "gap_reason, contrary_evidence_ref, access_constraint, escalation_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-evidence-1", "name": "Attestation and assessment evidence references group 1", "description": "Candidate fields: claim_ref, evidence_refs, criteria_ref, evidence_role. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "data-evidence-2", "name": "Attestation and assessment evidence references group 2", "description": "Candidate fields: source_agent_ref, derivation_ref, link_event_time, observed_at. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "data-evidence-3", "name": "Attestation and assessment evidence references group 3", "description": "Candidate fields: gap_reason, contrary_evidence_ref, access_constraint, escalation_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-evidence", "name": "Attestation and assessment evidence references evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-representation", "name": "Representation and receipt", "description": "Recognize what was received without asserting authenticity from appearance.", "rationale": "Proposed documentary concern supported by the cited profiles; profile-specific obligations stay external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-008" ], "layers": [ { "id": "layer-payload", "name": "Payload and copies", "description": "Retain permitted original bytes or an authoritative locator, and distinguish copies, scans, renderings and derived views. Visual appearance, a QR locator or a digest alone cannot establish authenticity.", "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ], "findings": [ { "id": "finding-payload", "name": "Representation integrity and recognition", "description": "Retain permitted original bytes or an authoritative locator, and distinguish copies, scans, renderings and derived views. Visual appearance, a QR locator or a digest alone cannot establish authenticity.", "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ], "questions": [ { "id": "q-payload-1", "text": "Which exact payload and companion proof or certificate-chain references constitute this representation?", "kind": "composition", "answer_data": [ "payload_ref, media_type, proof_refs, chain_refs, digest_algorithm, digest", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-payload-2", "text": "Which transformations separate the displayed or scanned copy from the issuer representation?", "kind": "validation", "answer_data": [ "original_ref, transformation_refs, rendering_version, missing_content, certification_claim", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-payload-3", "text": "Which untrusted embedded links or active content require isolated inspection before resolution?", "kind": "security", "answer_data": [ "link_inventory, resolver_policy_ref, content_risk, quarantine_state", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-payload-1", "name": "Representation integrity and recognition group 1", "description": "Candidate fields: payload_ref, media_type, proof_refs, chain_refs, digest_algorithm, digest. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] }, { "id": "data-payload-2", "name": "Representation integrity and recognition group 2", "description": "Candidate fields: original_ref, transformation_refs, rendering_version, missing_content, certification_claim. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] }, { "id": "data-payload-3", "name": "Representation integrity and recognition group 3", "description": "Candidate fields: link_inventory, resolver_policy_ref, content_risk, quarantine_state. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-payload", "name": "Representation integrity and recognition evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-receipt", "name": "Issue and custody evidence", "description": "Record evidence that a representation was issued or received; local registration is not an issuance operation. Repeated receipts do not create a new attestation.", "source_refs": [ "SRC-001", "SRC-008" ], "findings": [ { "id": "finding-receipt", "name": "Issuance assertions and local receipt", "description": "Record evidence that a representation was issued or received; local registration is not an issuance operation. Repeated receipts do not create a new attestation.", "source_refs": [ "SRC-001", "SRC-008" ], "questions": [ { "id": "q-receipt-1", "text": "Which external event or record establishes the asserted issuance of this document?", "kind": "event", "answer_data": [ "issuance_ref, asserted_issue_time, issuer_evidence_ref, uncertainty", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-receipt-2", "text": "When was this copy received and recorded, independently of the asserted issuance time?", "kind": "temporal", "answer_data": [ "receipt_time, recorded_at, time_precision, timezone_basis", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-receipt-3", "text": "How did custody or import transform this representation before local registration?", "kind": "provenance", "answer_data": [ "transfer_refs, importer_ref, transformations, prior_location_ref, duplicate_receipt_refs", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-receipt-1", "name": "Issuance assertions and local receipt group 1", "description": "Candidate fields: issuance_ref, asserted_issue_time, issuer_evidence_ref, uncertainty. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "data-receipt-2", "name": "Issuance assertions and local receipt group 2", "description": "Candidate fields: receipt_time, recorded_at, time_precision, timezone_basis. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "data-receipt-3", "name": "Issuance assertions and local receipt group 3", "description": "Candidate fields: transfer_refs, importer_ref, transformations, prior_location_ref, duplicate_receipt_refs. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-receipt", "name": "Issuance assertions and local receipt evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-001", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-applicability", "name": "Time and status", "description": "Capture bounded observations without a universal validity flag.", "rationale": "Proposed documentary concern supported by the cited profiles; profile-specific obligations stay external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005" ], "layers": [ { "id": "layer-term", "name": "Temporal applicability", "description": "Preserve source time syntax and profile semantics before mapping. Issue time, validity interval, assessment time and local observation time answer different questions.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-term", "name": "Validity intervals and time uncertainty", "description": "Preserve source time syntax and profile semantics before mapping. Issue time, validity interval, assessment time and local observation time answer different questions.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "q-term-1", "text": "What validity bounds are expressed and how does the pinned profile interpret their endpoints?", "kind": "temporal", "answer_data": [ "source_start, source_end, normalized_bounds, endpoint_rule, profile_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-term-2", "text": "At which stated assessment time was the interval applicable or indeterminate?", "kind": "state", "answer_data": [ "assessment_time, interval_result, clock_uncertainty, report_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-term-3", "text": "How are absent expiry, date-only precision or inconsistent timestamps represented without inventing certainty?", "kind": "exception", "answer_data": [ "missing_bound_reason, original_precision, inconsistency, unresolved_rule", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-term-1", "name": "Validity intervals and time uncertainty group 1", "description": "Candidate fields: source_start, source_end, normalized_bounds, endpoint_rule, profile_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "data-term-2", "name": "Validity intervals and time uncertainty group 2", "description": "Candidate fields: assessment_time, interval_result, clock_uncertainty, report_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "data-term-3", "name": "Validity intervals and time uncertainty group 3", "description": "Candidate fields: missing_bound_reason, original_precision, inconsistency, unresolved_rule. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-term", "name": "Validity intervals and time uncertainty evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-status", "name": "Status observations", "description": "Record purpose-specific observations with source and freshness. Credential status, signing-key status, expiry and record custody state must not collapse into one validity flag.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-status", "name": "Credential and key status evidence", "description": "Record purpose-specific observations with source and freshness. Credential status, signing-key status, expiry and record custody state must not collapse into one validity flag.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "questions": [ { "id": "q-status-1", "text": "Which credential status purpose and target are covered by the referenced observation?", "kind": "state", "answer_data": [ "target_ref, purpose, mechanism, status_value, response_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-status-2", "text": "What observation and freshness evidence limits reliance on that status response?", "kind": "temporal", "answer_data": [ "produced_at, this_update, next_update, fetched_at, freshness_policy_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-status-3", "text": "How are unavailable, unknown, stale or conflicting status results retained and escalated?", "kind": "exception", "answer_data": [ "failure_category, conflicting_refs, resolution_state, reviewer_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-status-1", "name": "Credential and key status evidence group 1", "description": "Candidate fields: target_ref, purpose, mechanism, status_value, response_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "id": "data-status-2", "name": "Credential and key status evidence group 2", "description": "Candidate fields: produced_at, this_update, next_update, fetched_at, freshness_policy_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "id": "data-status-3", "name": "Credential and key status evidence group 3", "description": "Candidate fields: failure_category, conflicting_refs, resolution_state, reviewer_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-status", "name": "Credential and key status evidence evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-use", "name": "Verification and disclosure", "description": "Bind external reports and cross-credential presentations to this record.", "rationale": "Proposed documentary concern supported by the cited profiles; profile-specific obligations stay external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "layer-verification", "name": "Verification evidence", "description": "Attach an external report to exact bytes, trust context and assessment time. Verification success does not establish truth, legal effect or acceptance for a purpose.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-verification", "name": "Bound verification reports and reliance", "description": "Attach an external report to exact bytes, trust context and assessment time. Verification success does not establish truth, legal effect or acceptance for a purpose.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ], "questions": [ { "id": "q-verification-1", "text": "Which external report checked this payload against which proof suite, trust anchors and policy revision?", "kind": "validation", "answer_data": [ "report_ref, payload_digest, suite_version, trust_context_ref, policy_revision", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-verification-2", "text": "Which proof-purpose, audience, challenge or key-authorization checks were applicable and recorded?", "kind": "security", "answer_data": [ "applicability_profile, proof_purpose, audience_ref, challenge_binding_ref, key_authorization_result", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-verification-3", "text": "Which separate relying-party decision accepted, rejected or deferred this record for the intended use?", "kind": "decision", "answer_data": [ "decision_ref, relying_party_ref, purpose, limitations, reason_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-verification-1", "name": "Bound verification reports and reliance group 1", "description": "Candidate fields: report_ref, payload_digest, suite_version, trust_context_ref, policy_revision. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "data-verification-2", "name": "Bound verification reports and reliance group 2", "description": "Candidate fields: applicability_profile, proof_purpose, audience_ref, challenge_binding_ref, key_authorization_result. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "data-verification-3", "name": "Bound verification reports and reliance group 3", "description": "Candidate fields: decision_ref, relying_party_ref, purpose, limitations, reason_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-verification", "name": "Bound verification reports and reliance evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-disclosure", "name": "Presentations and access", "description": "Reference a separately identified presentation or disclosure event and this record contribution. Selective disclosure requires a supporting mechanism; manual redaction is not automatically a valid derived proof.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "finding-disclosure", "name": "Disclosure references and minimization", "description": "Reference a separately identified presentation or disclosure event and this record contribution. Selective disclosure requires a supporting mechanism; manual redaction is not automatically a valid derived proof.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "questions": [ { "id": "q-disclosure-1", "text": "Which requested claims were approved for which recipient and purpose under the applicable disclosure basis?", "kind": "privacy", "answer_data": [ "request_ref, recipient_ref, purpose, disclosure_basis, approved_claim_paths", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-disclosure-2", "text": "Which independently identified presentation contains this record contribution and other credentials?", "kind": "relationship", "answer_data": [ "presentation_ref, contribution_ref, source_payload_ref, derived_proof_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-disclosure-3", "text": "What metadata, status query or evidence link could expose information beyond the approved view?", "kind": "access", "answer_data": [ "disclosed_metadata, correlation_risks, query_policy_ref, mitigation_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-disclosure-1", "name": "Disclosure references and minimization group 1", "description": "Candidate fields: request_ref, recipient_ref, purpose, disclosure_basis, approved_claim_paths. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-disclosure-2", "name": "Disclosure references and minimization group 2", "description": "Candidate fields: presentation_ref, contribution_ref, source_payload_ref, derived_proof_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-disclosure-3", "name": "Disclosure references and minimization group 3", "description": "Candidate fields: disclosed_metadata, correlation_risks, query_policy_ref, mitigation_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-disclosure", "name": "Disclosure references and minimization evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-continuity", "name": "Lineage and stewardship", "description": "Control local revision, retention and interoperability without changing rights.", "rationale": "Proposed documentary concern supported by the cited profiles; profile-specific obligations stay external.", "source_refs": [ "SRC-003", "SRC-006", "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-lineage", "name": "Correction and replacement", "description": "Correct local metadata through traceable revisions. A changed issued payload is a separately identified representation with authority evidence; replacement does not imply revocation of its predecessor.", "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ], "findings": [ { "id": "finding-lineage", "name": "Record revision and supersession links", "description": "Correct local metadata through traceable revisions. A changed issued payload is a separately identified representation with authority evidence; replacement does not imply revocation of its predecessor.", "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-lineage-1", "text": "Is the requested change a local metadata correction, a new copy or an issuer-authorized replacement?", "kind": "lifecycle", "answer_data": [ "change_class, authority_ref, predecessor_ref, successor_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-lineage-2", "text": "Which source payload and transformation support the revised or translated representation?", "kind": "provenance", "answer_data": [ "source_revision_ref, derivation_ref, translator_ref, payload_digest, assurance_limit", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-lineage-3", "text": "What prevents supersession or local deletion from being interpreted as revocation of the underlying credential?", "kind": "constraint", "answer_data": [ "link_semantics, status_authority_ref, independent_status_ref, invariant_check", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-lineage-1", "name": "Record revision and supersession links group 1", "description": "Candidate fields: change_class, authority_ref, predecessor_ref, successor_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ] }, { "id": "data-lineage-2", "name": "Record revision and supersession links group 2", "description": "Candidate fields: source_revision_ref, derivation_ref, translator_ref, payload_digest, assurance_limit. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ] }, { "id": "data-lineage-3", "name": "Record revision and supersession links group 3", "description": "Candidate fields: link_semantics, status_authority_ref, independent_status_ref, invariant_check. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-lineage", "name": "Record revision and supersession links evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-stewardship", "name": "Retention and portability", "description": "Apply an adopting-Dimension retention policy to payloads, reports and disclosure metadata separately. Export must expose projection losses and unresolved profile bindings.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ], "findings": [ { "id": "finding-stewardship", "name": "Governed record continuity", "description": "Apply an adopting-Dimension retention policy to payloads, reports and disclosure metadata separately. Export must expose projection losses and unresolved profile bindings.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-stewardship-1", "text": "Which retention trigger, lawful hold and authorized disposition apply to each stored artifact class?", "kind": "retention", "answer_data": [ "artifact_class, policy_ref, trigger, hold_refs, disposition_authority, due_state", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-stewardship-2", "text": "Which mapping preserves the credential profile and which claims or proofs are lost in an export?", "kind": "interoperability", "answer_data": [ "source_profile, target_profile, mapping_revision, loss_manifest, conformance_evidence_ref", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] }, { "id": "q-stewardship-3", "text": "Which adversarial fixtures must pass before this proposed record profile can support operational use?", "kind": "validation", "answer_data": [ "fixture_refs, expected_results, independent_review_ref, acceptance_status", "Source-qualified values; explicit unknown, disputed and not-applicable states." ] } ], "data_elements": [ { "id": "data-stewardship-1", "name": "Governed record continuity group 1", "description": "Candidate fields: artifact_class, policy_ref, trigger, hold_refs, disposition_authority, due_state. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "data-stewardship-2", "name": "Governed record continuity group 2", "description": "Candidate fields: source_profile, target_profile, mapping_revision, loss_manifest, conformance_evidence_ref. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "data-stewardship-3", "name": "Governed record continuity group 3", "description": "Candidate fields: fixture_refs, expected_results, independent_review_ref, acceptance_status. Proposed nested schema; not an executable instance contract.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-stewardship", "name": "Governed record continuity evidence index", "description": "Record-local versioned index of assertions and external evidence references; does not replace referenced masters.", "media_or_form": [ "structured record", "controlled human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and namespace first; otherwise governed IRI, then Dimension UUID or ULID. Record-local evidence entries use opaque entry IDs and revisions; preserve independent identifiers for external reports, payloads and presentations.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "function-register-copy", "name": "Register a received representation", "description": "Proposed local operation, not implemented. Create a local record or link a duplicate receipt; do not issue a credential.", "inputs": [ "payload or locator", "issuer identifiers", "receipt and provenance evidence" ], "outputs": [ "local record ID and copy binding" ], "preconditions": [ "Adopting-Dimension policy permits this actor, purpose and scope.", "Expected local revision matches; referenced evidence is available or explicitly marked unresolved.", "Reject authority, identity or integrity mismatch; never infer permission from possession." ], "effects": [ "Create a local record or link a duplicate receipt; do not issue a credential.", "Record minimal actor, time, evidence and revision metadata under retention policy." ], "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] }, { "id": "function-attach-report", "name": "Attach a verification report", "description": "Proposed local operation, not implemented. Store the report with its limits; do not execute cryptography or decide acceptance.", "inputs": [ "external report", "exact payload digest", "trust context", "assessment time" ], "outputs": [ "bound report reference or mismatch refusal" ], "preconditions": [ "Adopting-Dimension policy permits this actor, purpose and scope.", "Expected local revision matches; referenced evidence is available or explicitly marked unresolved.", "Reject authority, identity or integrity mismatch; never infer permission from possession." ], "effects": [ "Store the report with its limits; do not execute cryptography or decide acceptance.", "Record minimal actor, time, evidence and revision metadata under retention policy." ], "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "function-record-status", "name": "Record a status observation", "description": "Proposed local operation, not implemented. Append observation without overwriting history or commanding issuer status changes.", "inputs": [ "external status response", "target and purpose", "freshness evidence" ], "outputs": [ "purpose-specific observation or unresolved result" ], "preconditions": [ "Adopting-Dimension policy permits this actor, purpose and scope.", "Expected local revision matches; referenced evidence is available or explicitly marked unresolved.", "Reject authority, identity or integrity mismatch; never infer permission from possession." ], "effects": [ "Append observation without overwriting history or commanding issuer status changes.", "Record minimal actor, time, evidence and revision metadata under retention policy." ], "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "function-link-disclosure", "name": "Link an authorized disclosure", "description": "Proposed local operation, not implemented. Store only permitted metadata; do not generate a proof or send a presentation.", "inputs": [ "presentation ID", "contribution reference", "recipient purpose and authority" ], "outputs": [ "minimal disclosure index or authority refusal" ], "preconditions": [ "Adopting-Dimension policy permits this actor, purpose and scope.", "Expected local revision matches; referenced evidence is available or explicitly marked unresolved.", "Reject authority, identity or integrity mismatch; never infer permission from possession." ], "effects": [ "Store only permitted metadata; do not generate a proof or send a presentation.", "Record minimal actor, time, evidence and revision metadata under retention policy." ], "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "function-revise-metadata", "name": "Revise local metadata or link a replacement", "description": "Proposed local operation, not implemented. Preserve source bytes and predecessor linkage; do not revoke or reissue.", "inputs": [ "expected revision", "change class", "authority and derivation evidence" ], "outputs": [ "new metadata revision or replacement link", "conflict refusal" ], "preconditions": [ "Adopting-Dimension policy permits this actor, purpose and scope.", "Expected local revision matches; referenced evidence is available or explicitly marked unresolved.", "Reject authority, identity or integrity mismatch; never infer permission from possession." ], "effects": [ "Preserve source bytes and predecessor linkage; do not revoke or reissue.", "Record minimal actor, time, evidence and revision metadata under retention policy." ], "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "function-prepare-export", "name": "Prepare a controlled record export", "description": "Proposed local operation, not implemented. Produce only an authorized local projection, without asserting conformance or external delivery.", "inputs": [ "recipient scope", "mapping revision", "profile pins", "artifact selection" ], "outputs": [ "local export manifest with losses and unresolved checks" ], "preconditions": [ "Adopting-Dimension policy permits this actor, purpose and scope.", "Expected local revision matches; referenced evidence is available or explicitly marked unresolved.", "Reject authority, identity or integrity mismatch; never infer permission from possession." ], "effects": [ "Produce only an authorized local projection, without asserting conformance or external delivery.", "Record minimal actor, time, evidence and revision metadata under retention policy." ], "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] } ], "composition": [ { "target": "WM-XCT-017", "relation": "REFERENCE", "purpose": "Candidate binding to underlying attestation and issuer-controlled lifecycle; registry parent is not executable inheritance. Version and ownership agreement must be pinned before runtime use.", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-008" ] }, { "target": "WM-POL-004", "relation": "REFERENCE", "purpose": "Optional process or authorization context evidenced by a document; retain external process identity and authority.", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "target": "WM-PER-013", "relation": "REFERENCE", "purpose": "Optional professional grant reference; the record only preserves documentary evidence.", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "target": "WM-XCT-006", "relation": "REFERENCE", "purpose": "Optional external verification evidence binding; no verifier runtime or proof generation is owned here.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "W3C Verifiable Credentials Data Model 2.0", "relation": "ALIGN", "purpose": "Optional digital representation profile; pin vocabulary, schema, securing mechanism and status mechanism independently.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "target": "RFC 5280 and RFC 6960", "relation": "ALIGN", "purpose": "Optional PKI profile; its serials, time and status semantics do not apply universally.", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "target": "Open Badges 3.0", "relation": "ALIGN", "purpose": "Optional education profile; achievement definitions remain external and mappings require tests.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "PROV-O", "relation": "ALIGN", "purpose": "Conceptual lineage vocabulary only, without a conformance or truth claim.", "required": false, "source_refs": [ "SRC-008" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name the accountable record custodian and authorized issuer liaison by role, not brand.", "Declare namespace, master-system reconciliation, profile versions and data-classification policy.", "Pin retention, privacy, disclosure, trust and escalation policies before instance use." ], "namespace_guidance": "Keep record, payload, issuer serial, subject, proof, report and presentation namespaces distinct. Do not expose local identifiers in public exports by default.", "registry_links": [ "vr.wm-rec-008", "WM-XCT-017 candidate parent binding" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonical here means a governed local representation, not canonical research status. Preserve original signed bytes and separate parsed values, display renderings and authoritative references.", "Never rewrite signed content to normalize field order or punctuation; cryptographic canonicalization belongs to its pinned suite." ], "patch_rules": [ "Metadata changes require expected revision, authorized actor, purpose and evidence.", "A new issued payload uses a new representation identity and explicit derivation; do not overwrite it into an earlier signed object." ], "compatibility_rules": [ "Version vocabulary and mappings; unsupported extensions remain explicit.", "Changing profile, trust policy, status interpretation or field meaning requires compatibility review and new fixtures." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with namespace and issuer scope where applicable", "Governed global identifier or IRI with stated resolution policy", "Adopting-Dimension UUID or ULID with reconciliation status" ], "timestamp_rule": "Local timestamp metadata uses RFC 3339 with seconds and an explicit offset or Z. Keep event time separate from observation and ingestion time. Preserve original profile time syntax, date-only precision and unresolved timezone; never invent precision when normalizing.", "serial_naming_rule": "Use record ID, artifact kind, opaque entry ID and revision for local indexes. External presentation and verification-report IDs remain independent; no dates or personal names as identity.", "integrity_rule": "Hash retained payloads and record algorithm, media type and revision. A hash detects byte changes, not truth or authenticity. Reject mismatched report bindings; never store private keys or bearer secrets in the record." }, "policies": [ "These service rules are proposed local governance, not normative requirements from every cited source.", "Separate credential issuance and status authority from record custody, local access and relying-party acceptance.", "Minimize claim and presentation metadata; record applicable disclosure basis rather than assuming consent is always sufficient or required.", "Status fetches and evidence resolution need an approved resolver policy with privacy and untrusted-content controls.", "Dangerous or regulated contexts remain at policy and reference level; no operational handling instructions." ], "crud": { "read": [ "Authorize purpose and scope for each claim, payload and report; public certificate metadata does not make all supporting evidence public." ], "create": [ "Register a received representation with source and receipt evidence; mark unverified imports without issuing credentials." ], "update": [ "Use concurrency checks and append traceable metadata revisions or observations; external credential lifecycle changes are excluded." ], "delete": [ "The adopting-Dimension records policy and authorized custodian own retention and deletion execution. Check holds, minimize retained provenance and remove eligible payloads, replicas and caches under that policy.", "Keep only a policy-permitted minimal tombstone; never treat deletion of this local record as revocation or legal annulment of the referenced credential." ] }, "roles": [ { "name": "Record custodian", "responsibilities": [ "Maintains documentary identity and authorized record revisions." ] }, { "name": "Issuer liaison", "responsibilities": [ "Supplies or confirms external issuance and status evidence without acquiring authority from this record." ] }, { "name": "Subject or authorized holder", "responsibilities": [ "Requests permitted access and correction and controls disclosures where the profile assigns that role." ] }, { "name": "Evidence reviewer", "responsibilities": [ "Checks report bindings, conflicting observations and unsupported interpretations." ] }, { "name": "Policy steward", "responsibilities": [ "Approves retention, access, profile bindings and exception escalation." ] } ], "access": { "default_rule": "Deny access unless an actor has a documented purpose and permitted scope; apply the narrowest applicable rule to each artifact.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Document emergency or statutory disclosure basis, authorized reviewer, expiry and minimum data; never treat an exception as permanent public access.", "Permit manual review routes for missing electronic verification without treating the record as automatically authentic." ], "audit_requirements": [ "Record minimal read, export and mutation decisions with actor, purpose, scope, time and policy revision under a retention schedule.", "External audit systems own tamper-evident audit execution; local references must not leak claim values or reusable challenges." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md", "spec.yaml and visible research holds", "Adopting-Dimension policies and pinned profile bindings", "Authorized source payload and exact referenced reports" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one issued documentary record, with local custody and external attestation, status, verification and presentation references. Separate frozen local no-tools self-audit completed. Source verification, parent boundary agreement, profile validation and independent external review remain holds. This is a noncanonical reviewable draft, not an implemented credential system.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Local root, external identifiers and copy collision evidence." }, { "dimension": "lifecycle", "status": "covered", "notes": "Record receipt, revision and retirement; attestation lifecycle is external." }, { "dimension": "relationships", "status": "covered", "notes": "Issuer, subject, holder, parent attestation and independent presentation references." }, { "dimension": "temporal", "status": "covered", "notes": "Source intervals, local event time, assessment time and observation freshness." }, { "dimension": "provenance", "status": "covered", "notes": "Source payloads and attributed derivation indexes." }, { "dimension": "ownership", "status": "covered", "notes": "Custody is distinct from issuer and subject roles." }, { "dimension": "validation", "status": "gap", "notes": "Research schema gate only; executable report binding and profile fixtures remain pending." }, { "dimension": "access", "status": "covered", "notes": "Purpose and artifact scope, approved disclosure basis and exceptions." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Policy-dependent disposal, lawful holds and limited tombstones." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual alignments; tested versioned mappings remain absent." }, { "dimension": "direct properties", "status": "covered", "notes": "Class, representation, language, interval and claim qualifiers; physical dimensions belong to physical media profiles." }, { "dimension": "recognition", "status": "covered", "notes": "Byte and provenance evidence; visible appearance cannot establish authenticity." }, { "dimension": "capabilities", "status": "covered", "notes": "Proposed local record operations with refusal conditions and bounded effects." }, { "dimension": "regional applicability", "status": "gap", "notes": "Legal recognition, sector accreditation and jurisdiction rules require qualified profile review." }, { "dimension": "paper authentication", "status": "gap", "notes": "Scan provenance is expressible; forensic and certified-copy procedures are not researched." } ], "known_omissions": [ "Independent second-provider review is absent; this remains a reviewable draft.", "Live HTTP and exact source-version checks remain pending outside the sandbox.", "Nested data schemas, report schemas, cryptographic test vectors and versioned neighbor bindings are not implemented.", "Jurisdictional recognition, eIDAS, civil status, conformity certification and mobile-document licensed clauses need separate profiles.", "Paper authenticity, inaccessible-source remediation, archival proof renewal and offline presentation profiles require further evidence." ], "conflicts": [], "regional_assumptions": [ "The digital standards provide scoped technical examples, not global legal authority.", "NIST federation guidance is used within its stated context; local disclosure and retention rules require adopting-Dimension review." ], "adversarial_checks": [ "An authentic signature over a false claim must not produce a truth assertion.", "A good OCSP response, stale list or unreachable endpoint must not produce universal validity.", "Two issuers using the same serial and a credential with no public ID must remain representable.", "A multi-credential presentation must not become a child owned by one credential record.", "Replacement, metadata correction and local erasure must not silently revoke the underlying attestation.", "A redacted PDF cannot be labelled a selective disclosure proof without supporting evidence." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The root is a persistent documentary record with its own custody and revision identity. The registry standalone-mm value is a record-plane classification, not a subject-kind enum. Attestation lifecycle, grant, verification runtime and multi-credential presentation masters remain outside this root." }, "decisions": [ { "concept": "Documentary root", "disposition": "accepted", "rationale": "The record can have repeated receipts, renderings and revisions without becoming the underlying attestation or an issuance event. Stable local identity is supported by the proposed questions and service rules." }, { "concept": "Parent ownership overlap", "disposition": "qualified and held", "rationale": "The parent publication claims overlapping representation and disclosure scope. The current proposal confines ownership to documentary custody and local evidence indexes, uses optional references, and requires an agreed versioned split before runtime binding. No executable inheritance or shared edge is ratified." }, { "concept": "Identifiers and roles", "disposition": "accepted with profile limits", "rationale": "Issuer-scoped serials, optional public identifiers and local record keys are distinct. Holder, subject, custodian and issuer are separate role references; possession is not authority and does not merge identities." }, { "concept": "Claims and support", "disposition": "accepted as projections", "rationale": "Extracted claims retain source paths, qualifiers and uncertainty. Supporting and contrary evidence are references rather than local attestations of truth or re-performance of an assessment." }, { "concept": "Copy recognition and issue evidence", "disposition": "accepted", "rationale": "The payload and receipt findings distinguish appearance, digest, source bytes and issuance evidence. A scan, copied signature or local registration does not become a verified original or a newly issued credential." }, { "concept": "Time and status", "disposition": "accepted with uncertainty", "rationale": "Source interval semantics, event time, observation time and freshness are preserved separately. Expiry, issuer credential status, signing-key status and local custody are not reduced to a universal valid flag; unknown and stale results remain explicit." }, { "concept": "Verification and reliance", "disposition": "separated", "rationale": "The finding binds an external report to exact payload, trust context and policy. Proof verification neither proves truth nor supplies a relying-party acceptance decision, which remains a separate reference." }, { "concept": "Presentation ownership and privacy", "disposition": "accepted as external references", "rationale": "A presentation has independent identity and can contain several credentials. This root stores only the authorized contribution and minimal disclosure metadata. Redaction is not promoted to selective disclosure proof, and consent is not imposed as a universal disclosure basis." }, { "concept": "Corrections and replacement", "disposition": "accepted", "rationale": "Local metadata revision, new copy and issuer-authorized replacement are explicitly differentiated. A supersession link or local deletion cannot command revocation or annul an underlying grant." }, { "concept": "Operations and service governance", "disposition": "accepted as proposed only", "rationale": "All six operations are unimplemented local record actions with actor, purpose, revision and evidence preconditions and refusal outcomes. None issues, revokes, sends a presentation, executes cryptography or grants rights. Eight service sections cover the required governance surface." }, { "concept": "Retention and artifact identity", "disposition": "qualified", "rationale": "Local indexes have stable entry identifiers while referenced payloads, reports and presentations retain separate identities. History preservation is bounded by adopting-Dimension retention and disposal rules; the draft does not require indefinite personal-data storage." }, { "concept": "Coverage and supplement", "disposition": "limited", "rationale": "The proposed properties are informational rather than physical. The supplement's universal verification and identifier claims were rejected. Paper authentication, regional recognition, nested schemas and conformance are declared gaps, not implied by the eight-source technical evidence base." }, { "concept": "Provider and source assurance", "disposition": "waived and held", "rationale": "This is a local Codex self-audit of frozen authored evidence, not independent review. Eight pages yielded browser text but direct HTTP was not attempted under the sandbox constraint. Neither browser access nor zero measured 200 responses establishes a completed live-version gate." } ], "publicationHolds": [ "Independent external review is absent. Claude and Grok were explicitly skipped under the owner-authorized single-provider waiver; the separate local Codex no-tools self-audit is not a second-provider review.", "Source and version verification remains incomplete. Eight official pages yielded browser-readable text, but direct HTTP checks were not attempted due to the stated sandbox restriction: zero attempts and zero measured HTTP 200 responses. The coordinator must run check_sources.py outside the sandbox and separately verify claims, versions, redirects, updates and errata.", "WM-XCT-017 currently claims overlapping representation, report and disclosure scope and carries its own review holds. Agree documentary custody versus attestation ownership, resolve the presentation split and pin neighbor versions before runtime binding; all proposed links remain optional candidates.", "Jurisdictional recognition, issuer accreditation, disclosure basis, retention rules, paper authenticity, civil status, professional licensing and other sector profiles require qualified review. No universal legal validity, licensed mobile-document coverage or regulatory conformance is claimed.", "Candidate field groups are not nested executable instance schemas. Credential-profile mappings, report schemas, cryptographic fixtures, offline behavior, loss-aware exports and adversarial acceptance tests remain incomplete. No operational verifier or wallet implementation is supplied.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore independent external review and verify exact source versions, update chains and applicable licensing before promotion.", "Agree the WM-XCT-017 boundary and pin optional neighbor bindings without duplicating attestation or presentation ownership.", "Develop profile-specific schemas and fixtures for identifier collisions, unknown or stale status, mismatched reports, multiple credentials in one presentation, correction, replacement and lawful disposal.", "Research legal recognition, paper authenticity, mobile-document and offline profiles with appropriate primary evidence." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }