# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-24T14:53:42Z", "synthesisSha256": "81cfa76550220c4fcf8ed3b29a98016a5318c7c5e3199a1c513d630ef6d4f8c7", "providerMode": "dual-provider", "providers": [ "Claude", "Grok" ], "waivedProviders": [] }, "metaModel": { "id": "WM-REC-010", "registryId": "vr.wm-rec-010", "name": "Decision / Approval Record", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.REC.DEC" ], "tags": [ "decision", "approval", "record", "inf.rec.dec" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-rec-010-decision-approval-record/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-rec-010", "model": { "registry_id": "vr.wm-rec-010", "model_id": "WM-REC-010", "name": "Decision / Approval Record", "entry_kind": "entity", "purpose": "Provide the format-neutral context an agent needs to identify, create, interpret, validate and operate an authoritative record of a decision or approval: what was decided, on what question, by whom under what authority, on what reasons and evidence, with what conditions, from when until when it is valid, and how it is superseded, challenged, disclosed and retained.", "scope_statement": "The model covers the record that constitutes or evidences a discrete decision or approval act and the act's decision-relevant attributes. It treats the decision act and the record of it as distinct but co-modelled: the act supplies authority, outcome, reasons and timing; the record supplies identity, versioned expression, integrity evidence, disclosure and disposition. It spans administrative decisions, judicial judgments, corporate and board resolutions, delegated sign-offs, gate/change approvals and retained machine authorization decisions. It excludes the deliberative occasion, the containing case or procedure, the norms applied, party master data and generic record custody mechanics, which belong to sibling or parent models.", "in_scope": [ "Decision identity, versioned expression identity and classification of decision or approval type", "Decided question, outcome/disposition, attached conditions, obligations and advice", "Statement of reasons, alternatives considered and rejected, evidence and findings of fact relied on", "Decision authority, legal or constitutional basis, delegation, approval limits, quorum and voting", "Approval participation acts, dissent, abstention, recusal and conflict-of-interest declarations", "Attestation evidence: signature, seal, trusted time-stamp token, hash and finality of the record", "Distinct decision-relevant times: taken, consented, issued, served, published, in force, recorded", "Validity window, retroactivity, conditions of validity, expiry and renewal", "Status model, finality, supersession, amendment, corrigendum, revocation and annulment", "Challenge, appeal, review outcome and suspensive effect", "Automated, assisted and solely automated decision modes with human oversight and contestability", "Publication, individual notification/service, access classification, redaction and anonymisation", "Decision-specific retention triggers, disposition and disposal/legal hold", "Alignment to external decision identifiers and vocabularies (ECLI, Akoma Ntoso, PROV, DCMI, XACML)" ], "out_of_scope": [ "The deliberative occasion itself — agenda, attendance, minutes as a whole (WM-ACT-025 Meeting)", "The containing administrative case, application or procedure lifecycle (WM-POL-017)", "Generic record custody, storage media, format migration and preservation mechanics (parent WM-REC-001)", "The normative content of the policy, statute, rule or standard being applied (policy/rule sibling model)", "Master data for persons, organisational units and positions holding decision roles (party/agent sibling model)", "Authoring and administration of machine access-control policies; only a retained decision result is in scope", "Contract or agreement terms that a decision may authorise (agreement sibling model)", "Workflow engine internals, task queues and routing logic that carry an approval request", "Downstream financial posting, permit issuance or benefit payment produced by a decision" ], "boundary_notes": [ { "neighbor": "WM-ACT-025 Meeting", "distinction": "A meeting is an occasion; a decision record is an outcome assertion. The relationship is optional in both directions: Delaware General Corporation Law §141(f) permits board action without any meeting by unanimous written or electronic consent, and delegated single-signature approvals never involve a meeting. Meeting attendance and agenda stay in the meeting model; only the linkage, the agenda item decided and the quorum/vote result attach to the decision record.", "source_refs": [ "SRC-010" ] }, { "neighbor": "WM-POL-017 Administrative case", "distinction": "A case is the procedural container and may hold many decisions — procedural, interim, partial and final. Case state transitions are driven by decisions but are not decisions. Ex parte communications belong to the case record and are referenced by the decision record only where a rule requires them to be placed on the record of decision.", "source_refs": [ "SRC-004" ] }, { "neighbor": "WM-REC-001 Record (parent)", "distinction": "The parent supplies generic record properties: authenticity, reliability, integrity and usability as record characteristics, custody, format and preservation. WM-REC-010 adds only what is decision-specific — authority, outcome, reasons, validity and supersession — and must not restate parent mechanics.", "source_refs": [ "SRC-002" ] }, { "neighbor": "Runtime authorization decision (XACML PDP result)", "distinction": "A PDP result has the same logical shape (decision value, status, obligations, advice, applicable policy identifiers) but is normally ephemeral and produced at log scale. The boundary is retention as a record: a PDP result becomes an instance of this model only when it is captured and managed as a record. XACML decision values are an alignment vocabulary, not the canonical outcome set.", "source_refs": [ "SRC-003" ] }, { "neighbor": "Judicial judgment / case law item", "distinction": "A judgment is a specialised decision record with a governed global identifier (ECLI) and a document structure of introduction, background, motivation and decision. That structure is judicial and must not be imposed on administrative or corporate decisions; court organisation, procedure and case-law citation networks are out of scope.", "source_refs": [ "SRC-006", "SRC-009" ] }, { "neighbor": "Electronic signature, seal and time-stamp evidence", "distinction": "Attestation evidence is referenced, not owned. The decision record holds pointers to signature/seal objects and time-stamp tokens plus a verification verdict and verification time; the cryptographic object model, trust lists and long-term validation data belong to a signature-evidence sibling model.", "source_refs": [ "SRC-012" ] }, { "neighbor": "Approval as an independent object", "distinction": "Boundary under review. In this model an approval is either an outcome value of a decision or a participation act within one, because the cited sources give approvals no independent identity. Standing authorisations such as licences and permits do have independent validity and holders, and may justify a separate sibling model; flagged rather than assumed.", "source_refs": [ "SRC-010", "SRC-003" ] }, { "neighbor": "Architecture decision record (ADR) practice", "distinction": "ISO/IEC/IEEE 42010:2022 treats an architecture decision as pertaining to concerns and affecting architecture description elements, with rationale covering alternatives not chosen. That is a design-governance specialisation of the same shape; the architecture description, viewpoints and models it affects are out of scope here.", "source_refs": [ "SRC-016" ] } ] }, "sources": [ { "id": "SRC-001", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013; namespace http://www.w3.org/ns/prov#", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:10:00Z", "relevance": "Normative model for attributing a decision activity to responsible agents (wasAssociatedWith), qualifying that association with a role and a plan (Association, hadRole, hadPlan), representing delegation (actedOnBehalfOf), derivation of a superseding decision (wasDerivedFrom), invalidation (wasInvalidatedBy) and separate activity/entity times." }, { "id": "SRC-002", "title": "ISO 15489-1:2016 Information and documentation — Records management — Part 1: Concepts and principles", "organization": "International Organization for Standardization (ISO)", "url": "https://www.iso.org/standard/62542.html", "version_or_date": "Second edition, published 2016-04", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:12:00Z", "relevance": "Defines records as evidence of business activity, the four characteristics that make a record authoritative (authenticity, reliability, integrity, usability), records metadata, appraisal, records controls and records processes. Anchors why a decision record must be fixed, attributable and disposed under authority. Full normative text is paywalled; iso.org returned HTTP 403 to automated retrieval, so claims are catalogue/abstract level." }, { "id": "SRC-003", "title": "eXtensible Access Control Markup Language (XACML) Version 3.0", "organization": "OASIS", "url": "https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html", "version_or_date": "OASIS Standard, 22 January 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:14:00Z", "relevance": "Normative four-valued decision vocabulary (Permit, Deny, NotApplicable, Indeterminate), the Result structure (Decision, Status, Obligations, AssociatedAdvice, PolicyIdentifierList), the binding distinction between obligations that must be discharged and advice that may be ignored, and the PDP/PEP/PAP/PIP role separation for machine-rendered decisions." }, { "id": "SRC-004", "title": "5 U.S.C. § 557 — Initial decisions; conclusiveness; review by agency; submissions by parties; contents of decisions; record", "organization": "United States Government Publishing Office (govinfo)", "url": "https://www.govinfo.gov/content/pkg/USCODE-2023-title5/html/USCODE-2023-title5-partI-chap5-subchapII-sec557.htm", "version_or_date": "United States Code, 2023 edition", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:16:00Z", "relevance": "Requires the record of a decision to show findings, conclusions and the reasons or basis therefor on all material issues of fact, law or discretion, plus the rule, order, sanction, relief or denial; distinguishes initial from agency decisions and recommended decisions by subordinate employees; requires prohibited ex parte communications to be placed on the public record." }, { "id": "SRC-005", "title": "RFC 3339 — Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "Proposed Standard, July 2002 (updated by RFC 9557)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:18:00Z", "relevance": "Normative timestamp profile: four-digit years, mandatory explicit relationship to UTC via numeric offset or 'Z', the distinct meaning of -00:00 as UTC with unknown local offset, optional fractional seconds and :60 for leap seconds. Governs every time value in this model." }, { "id": "SRC-006", "title": "European Case Law Identifier (ECLI)", "organization": "European Union — European e-Justice Portal", "url": "https://e-justice.europa.eu/topics/legislation-and-case-law/european-case-law-identifier-ecli_en", "version_or_date": "Council conclusions on ECLI, CELEX 52011XG0429(01) (OJ C 127, 29.4.2011)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:20:00Z", "relevance": "Governed global identifier for judicial decisions with five colon-separated components (literal 'ECLI', country code, court code, four-digit year the judgment was rendered, ordinal number up to 25 characters, letters/digits/dots only), plus a recommended Dublin Core-based minimum metadata set. Primary evidence for identity priority and for the rule that a year inside an identifier is not a date field." }, { "id": "SRC-007", "title": "Article 41 — Right to good administration, Charter of Fundamental Rights of the European Union", "organization": "European Union Agency for Fundamental Rights (FRA)", "url": "https://fra.europa.eu/en/eu-charter/article/41-right-good-administration", "version_or_date": "Charter as proclaimed, OJ C 303/17, 14.12.2007", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:22:00Z", "relevance": "Establishes the obligation of the administration to give reasons for its decisions (41(2)(c)), the right to be heard before an adverse individual measure (41(2)(a)) and the right of access to one's own file subject to confidentiality and business secrecy (41(2)(b)). Grounds the reasons, hearing and party-access findings." }, { "id": "SRC-008", "title": "DCMI Metadata Terms", "organization": "Dublin Core Metadata Initiative (DCMI)", "url": "https://www.dublincore.org/specifications/dublin-core/dcmi-terms/", "version_or_date": "2020-01-20; namespace http://purl.org/dc/terms/", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:24:00Z", "relevance": "Supplies distinct governed properties this model needs to keep separate: valid (date or range of validity), issued (formal issuance), created, modified, dateAccepted, replaces / isReplacedBy for supersession, provenance for custody changes, accessRights, rightsHolder, conformsTo and identifier. Also the metadata family ECLI recommends." }, { "id": "SRC-009", "title": "Akoma Ntoso Version 1.0. Part 1: XML Vocabulary", "organization": "OASIS", "url": "https://docs.oasis-open.org/legaldocml/akn-core/v1.0/os/part1-vocabulary/akn-core-v1.0-os-part1-vocabulary.html", "version_or_date": "OASIS Standard, 29 August 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:26:00Z", "relevance": "FRBR-based four-level identity for legal documents (Work, Expression, Manifestation, Item) expressed as IRIs, and the judgment document structure of introduction, background, motivation and decision. Primary support for separating the decision as an abstract work from its language versions, corrected versions and published formats." }, { "id": "SRC-010", "title": "Delaware General Corporation Law, Title 8, Chapter 1, Subchapter IV — Directors and Officers (§ 141)", "organization": "State of Delaware", "url": "https://delcode.delaware.gov/title8/c001/sc04/index.html", "version_or_date": "Delaware Code, current through the 2025 legislative session", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:28:00Z", "relevance": "Primary counterexample source for decision mechanics: quorum defaults and floors (§141(b), never less than one third), committee powers and their express limits (§141(c)), remote participation counting as presence in person (§141(i)), and action without a meeting by unanimous written or electronic consent filed with the minutes, optionally conditioned to take effect up to 60 days later (§141(f))." }, { "id": "SRC-011", "title": "Universal Electronic Records Management (ERM) Requirements", "organization": "U.S. National Archives and Records Administration (NARA)", "url": "https://www.archives.gov/records-mgmt/policy/universalermrequirements", "version_or_date": "Version 3, June 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:30:00Z", "relevance": "Lifecycle requirement groups (capture, maintenance and use, disposal, transfer, metadata, reporting) with Must Have / Should Have grading, and the program-versus-system requirement split. Grounds capture, disposition, transfer and metadata findings without importing a single national retention schedule." }, { "id": "SRC-012", "title": "RFC 3161 — Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc3161", "version_or_date": "Proposed Standard, August 2001 (updated by RFC 5816)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:32:00Z", "relevance": "Proof-of-existence semantics for attestation: TSTInfo fields version, policy, messageImprint, per-TSA unique serialNumber, genTime, accuracy, ordering, nonce and tsa. Supplies the evidentiary distinction between an asserted signing time and a third-party attested time." }, { "id": "SRC-013", "title": "AI Act — Regulatory framework for artificial intelligence", "organization": "European Commission (Directorate-General for Communications Networks, Content and Technology)", "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai", "version_or_date": "Regulation (EU) 2024/1689; in force 1 August 2024, general application from 2 August 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:34:00Z", "relevance": "Requires human oversight measures for high-risk AI systems, logging of activity to ensure traceability of results, and provider information duties toward deployers. Grounds the automation, oversight and system-attribution findings. Article-level text was not retrievable from EUR-Lex; obligations are cited at the level this official page states them." }, { "id": "SRC-014", "title": "Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679 (wp251rev.01)", "organization": "Article 29 Data Protection Working Party (endorsed by the European Data Protection Board)", "url": "https://ec.europa.eu/newsroom/article29/items/612053/en", "version_or_date": "wp251rev.01, last revised and adopted 2018", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:36:00Z", "relevance": "Official interpretation of when a decision is 'based solely on automated processing', what counts as legal or similarly significant effects, and what makes human intervention meaningful. Only the item metadata was retrievable at this URL; the substantive guidance sits in the linked PDF and is treated as an interpretive alignment, not a verified quotation." }, { "id": "SRC-015", "title": "Art. 22 GDPR — Automated individual decision-making, including profiling", "organization": "gdpr-info.eu (unofficial consolidated reproduction of Regulation (EU) 2016/679)", "url": "https://gdpr-info.eu/art-22-gdpr/", "version_or_date": "Regulation (EU) 2016/679; reproduction consulted 2026-08-24", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-08-24T09:38:00Z", "relevance": "Working text of the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, its three exceptions and the minimum safeguards of human intervention, expressing a point of view and contesting the decision. Used because EUR-Lex was not retrievable; must be re-verified against the Official Journal before any conformance claim." }, { "id": "SRC-016", "title": "ISO/IEC/IEEE 42010:2022 Software, systems and enterprise — Architecture description", "organization": "ISO / IEC / IEEE", "url": "https://www.iso.org/standard/74393.html", "version_or_date": "Second edition, published 2022-11", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T09:40:00Z", "relevance": "Normative treatment of architecture decision, architecture rationale, concern and stakeholder: a decision pertains to concerns and affects description elements, and rationale records justification including alternatives not chosen. Supports the reasons and options-considered findings as a general decision pattern. Full text paywalled; iso.org returned HTTP 403 to automated retrieval." }, { "id": "SRC-017", "title": "MoReq2010: Modular Requirements for Records Systems — Volume 1: Core Services & Plug-in Modules", "organization": "DLM Forum Foundation", "url": "https://www.dlmforum.eu/index.php/resources/moreq", "version_or_date": "MoReq2010, published 2011 (no further development pursued after 2018)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-24T09:42:00Z", "relevance": "Modular records-system requirement set built on core services with an explicit entity model covering records, aggregations, classes, disposal scheduling, disposal holding and an immutable event history. Supports the finality, event-history and hold findings. Development is discontinued, so it is treated as a stable reference rather than an evolving obligation." }, { "id": "SRC-018", "title": "ISO 23081 Metadata for records (ISO 23081-1:2017 principles; ISO 23081-2:2021 conceptual and implementation issues)", "organization": "ISO/TC 46/SC 11 Archives/records management", "url": "https://committee.iso.org/sites/tc46sc11/home/projects/published/iso-23081-metadata-for-records.html", "version_or_date": "ISO 23081-1:2017 and ISO 23081-2:2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T16:20:00Z", "relevance": "Primary statement that records metadata must support integrity, authenticity, reliability and usability, and must tell who did what to which digital object across the record's life." }, { "id": "SRC-019", "title": "PROV-DM: The PROV Data Model", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-dm/", "version_or_date": "W3C Recommendation 30 April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T16:15:00Z", "relevance": "Domain-agnostic provenance for the decision record as an entity: generation and invalidation times, usage of input entities, attribution and association of agents, delegation (actedOnBehalfOf), identifiers and derivation/revision." }, { "id": "SRC-020", "title": "Decision Model and Notation (DMN) Specification Version 1.5", "organization": "Object Management Group", "url": "https://www.omg.org/spec/DMN/1.5/About-DMN", "version_or_date": "formal/24-01-01, adopted August 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T16:18:00Z", "relevance": "Defines precise, often executable specification of repeatable business decisions. Used as an alignment boundary: DMN is decision logic, not the authorised instance record with approver and validity." }, { "id": "SRC-021", "title": "5 U.S.C. § 557 Initial decisions; conclusiveness; review by agency; submissions by parties; contents of decisions; record", "organization": "U.S. National Archives and Records Administration (Office of the Federal Register)", "url": "https://www.archives.gov/federal-register/laws/administrative-procedure/557.html", "version_or_date": "Administrative Procedure Act; page last reviewed 2016-08-15", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-24T16:12:00Z", "relevance": "Normative contents of an adjudicative decision record: findings, conclusions and reasons on material issues; the rule, order, sanction, relief or denial; initial, recommended and tentative grades; appeal and agency review; inclusion of all such decisions in the record; ex parte communication rules and docketing." }, { "id": "SRC-022", "title": "Markdown Architectural Decision Records (MADR)", "organization": "MADR project (adr.github.io)", "url": "https://adr.github.io/madr/", "version_or_date": "MADR 4.0.0, released 2024-09-17", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-08-24T16:25:00Z", "relevance": "Operational template for any important decision record: status vocabulary (proposed, rejected, accepted, deprecated, superseded), decision-makers, consulted and informed roles, context, drivers, options, outcome, consequences and confirmation." }, { "id": "SRC-023", "title": "Documenting Architecture Decisions", "organization": "Cognitect (Michael Nygard)", "url": "https://cognitect.com/blog/2011/11/15/documenting-architecture-decisions.html", "version_or_date": "2011-11-15", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-08-24T16:28:00Z", "relevance": "Canonical lightweight ADR: one decision per record; sequential identifiers not reused; Context, Decision, Status and Consequences; proposed/accepted/deprecated/superseded; keep superseded records rather than deleting them." }, { "id": "SRC-024", "title": "ISO 15489 (DCC Standards Watch briefing)", "organization": "Digital Curation Centre", "url": "https://www.dcc.ac.uk/guidance/briefing-papers/standards-watch-papers/iso-15489", "version_or_date": "July 2007 (describes ISO 15489:2001 and ISO 23081-1:2006)", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-08-24T16:30:00Z", "relevance": "Secondary exposition of record characteristics and the capture–registration–classification–access–disposition process chain. Used only to surface process detail; version predates ISO 15489-1:2016." } ], "structure": { "bundles": [ { "id": "identity-and-classification", "name": "Identity and classification", "description": "How a decision or approval record is uniquely designated, versioned as expressions and manifestations, typed, and bounded in subject matter and applicability.", "rationale": "An agent cannot cite, deduplicate, supersede or retrieve a decision without a stable identity separated from its versions, and cannot apply the right rules without knowing the decision type and its scope of effect. ECLI proves that decision identity is a governed concern in its own right, and Akoma Ntoso proves that the decision as a work differs from its language and format versions.", "source_refs": [ "SRC-006", "SRC-009", "SRC-008", "SRC-002" ], "layers": [ { "id": "l-identity-designation", "name": "Identity and designation", "description": "Identifier assignment for the decision act and its record, and the versioned expression structure that keeps corrections and translations distinct from the abstract decision.", "source_refs": [ "SRC-006", "SRC-009", "SRC-008" ], "findings": [ { "id": "f01-decision-identifier", "name": "Decision and record identifier assignment", "description": "The identifier that designates the decision, the authority that mints it, and the separation between the identifier of the decision act, the identifier of the record and any governed global identifier such as an ECLI.", "source_refs": [ "SRC-006", "SRC-008", "SRC-002" ], "questions": [ { "id": "q01-scheme", "text": "Which identifier scheme designates this decision, and which body governs and issues values in that scheme?", "kind": "identity", "answer_data": [ "Scheme name and governing authority", "Identifier value", "Scheme documentation URI", "Assignment date as RFC 3339 timestamp" ] }, { "id": "q01-act-vs-record", "text": "Does the identifier designate the decision act, the record documenting it, or both, and how is the other one identified?", "kind": "identity", "answer_data": [ "Referent type (act, record, or both)", "Companion identifier for the other referent", "Statement of the linkage rule" ] }, { "id": "q01-priority", "text": "When an authoritative master-system number, a governed global identifier and a locally minted UUID/ULID all exist, which is canonical for citation and which are aliases?", "kind": "identity", "answer_data": [ "Canonical identifier value and scheme", "Ordered list of alias identifiers with scheme and issuer", "Rationale for canonical selection" ] }, { "id": "q01-no-forum", "text": "How is an identifier minted for a decision taken without a meeting, a case number or a hearing — for example a delegated sign-off or unanimous written consent?", "kind": "identity", "answer_data": [ "Fallback minting rule", "Assigning system identifier", "Whether the identifier is sequential within a series" ] }, { "id": "q01-date-misuse", "text": "Are any date-bearing tokens inside the identifier being relied on as the decision date, and if so how is that dependency removed?", "kind": "constraint", "answer_data": [ "Identifier component breakdown", "Explicit statement that embedded years are not date fields", "Pointer to the authoritative date element" ] } ], "data_elements": [ { "id": "de01-decision-id", "name": "canonical_decision_identifier", "description": "The single canonical identifier used to cite this decision, expressed with its scheme.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-008" ] }, { "id": "de01-scheme", "name": "identifier_scheme", "description": "Governing scheme of the canonical identifier, for example an ECLI, a national register number or an internal case-management series.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de01-alias", "name": "alias_identifiers", "description": "Other identifiers denoting the same decision or its record, each with scheme, issuer and referent type.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de01-record-id", "name": "record_identifier", "description": "Identifier of the record object when it differs from the identifier of the decision act.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "art-identifier-register-entry", "name": "Identifier register entry", "description": "The register or minting-log entry that evidences assignment of the canonical identifier to this decision, including issuer, series and assignment time.", "media_or_form": [ "register entry", "structured record", "printed certificate of registration" ], "serial": true, "identity_strategy": "Identified by the register's own entry number issued by the minting authority; where the register is an ECLI coordinator's register, the ECLI itself is the entry key.", "source_refs": [ "SRC-006", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "f02-version-and-expression-identity", "name": "Version, expression and manifestation identity", "description": "How successive language versions, corrected texts, consolidated texts and published formats of the same decision are distinguished without fragmenting its identity.", "source_refs": [ "SRC-009", "SRC-008", "SRC-002" ], "questions": [ { "id": "q02-frbr", "text": "At which identity level does each stored item sit — abstract decision (work), a specific version or language (expression), a format (manifestation), or a single file (item)?", "kind": "composition", "answer_data": [ "Level assignment per stored object", "Work-level identifier", "Expression-level discriminators (language, version date)", "Manifestation format" ] }, { "id": "q02-authentic", "text": "Which expression is the authentic or authoritative text, and what governs divergence between language versions?", "kind": "authority", "answer_data": [ "Authentic expression identifier", "Language codes of all expressions", "Rule governing divergence" ] }, { "id": "q02-corrigendum", "text": "When a text is corrected, is a new expression created or is the existing one edited, and how is the superseded expression preserved?", "kind": "lifecycle", "answer_data": [ "Correction handling rule", "New expression identifier", "Retained prior expression reference", "Correction timestamp" ] }, { "id": "q02-published-variant", "text": "Does an anonymised or redacted published expression exist alongside a full internal expression, and are they explicitly linked?", "kind": "privacy", "answer_data": [ "Published expression identifier", "Internal expression identifier", "Redaction basis", "Linkage assertion" ] } ], "data_elements": [ { "id": "de02-work-id", "name": "work_identifier", "description": "Identifier of the abstract decision independent of version, language and format.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "de02-expression", "name": "expression_descriptor", "description": "Language, version label and version date that discriminate one expression of the decision from another.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009", "SRC-008" ] }, { "id": "de02-authentic-flag", "name": "is_authentic_expression", "description": "Whether this expression is the authoritative text for legal or evidential purposes.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-002" ] }, { "id": "de02-manifestation", "name": "manifestation_format", "description": "Concrete format in which an expression is rendered, for example a signed PDF/A file, an XML instance or a paper original.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [ { "id": "art-consolidated-text", "name": "Consolidated or corrected text", "description": "A distinct expression of the decision incorporating corrigenda or amendments, carrying its own expression identifier and a reference to the expressions it replaces.", "media_or_form": [ "XML document", "PDF/A document", "structured text with change annotations" ], "serial": false, "identity_strategy": "Work identifier plus expression discriminator (language and version date), following the FRBR-based IRI convention; never re-uses the identifier of the expression it replaces.", "source_refs": [ "SRC-009", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "f29-title-language-and-alternative-names", "name": "Title, language and alternative names", "description": "A short noun-phrase title representing the problem and chosen solution, plus language and any alternative citations. DCMI title and alternative apply; Nygard and MADR require a short representative heading.", "source_refs": [ "SRC-008", "SRC-022", "SRC-023" ], "questions": [ { "id": "f29-title-language-and-alternative-names-q01", "text": "What short title names this decision in terms of the problem solved and the outcome chosen?", "kind": "definition", "answer_data": [ "title", "title_language_tag" ] }, { "id": "f29-title-language-and-alternative-names-q02", "text": "In which language or languages is the authoritative text of the decision expressed?", "kind": "classification", "answer_data": [ "primary_language_tag", "additional_language_tags", "translation_record_ids" ] }, { "id": "f29-title-language-and-alternative-names-q03", "text": "What alternative names, docket numbers or popular citations should retrieve the same record without becoming identifiers?", "kind": "identity", "answer_data": [ "alternative_titles", "docket_or_citation_labels", "bibliographic_citation" ] } ], "data_elements": [ { "id": "f29-title-language-and-alternative-names-data01", "name": "Title", "description": "Short noun-phrase heading for the decision record.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-023" ] }, { "id": "f29-title-language-and-alternative-names-data02", "name": "Primary language", "description": "Language tag of the authoritative decision text.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "f29-title-language-and-alternative-names-data03", "name": "Alternative titles or citations", "description": "Other human labels that refer to the same record.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "Title and language are intrinsic descriptive metadata of the record, not a standalone artefact." } ] }, { "id": "l-classification-and-subject", "name": "Classification and subject matter", "description": "The type of decision or approval, its binding character, and the subject matter, jurisdiction and population to which it applies.", "source_refs": [ "SRC-003", "SRC-016", "SRC-002", "SRC-004" ], "findings": [ { "id": "f03-decision-type-classification", "name": "Decision type and binding character", "description": "Classification of the record along the axes that change how it must be handled: decision family, binding versus advisory, interim versus final, and positive versus negative outcome.", "source_refs": [ "SRC-003", "SRC-004", "SRC-016", "SRC-010" ], "questions": [ { "id": "q03-family", "text": "Which decision family does this record belong to — administrative decision, judicial judgment, corporate resolution, delegated approval, gate or change approval, or retained machine authorization decision?", "kind": "classification", "answer_data": [ "Decision family code", "Controlled vocabulary reference", "Family-specific handling rules triggered" ] }, { "id": "q03-binding", "text": "Is the instrument binding, or is it an opinion, recommendation or advice that does not itself dispose of the matter?", "kind": "classification", "answer_data": [ "Binding character code", "Basis for the classification", "Consequences for enforceability" ] }, { "id": "q03-finality-class", "text": "Is this an interim, partial, recommended or final decision, and if not final what does it leave undecided?", "kind": "state", "answer_data": [ "Procedural stage code", "Matters left undecided", "Reference to the anticipated final decision" ] }, { "id": "q03-vocab-collision", "text": "Where an external decision vocabulary is used, is it the canonical classification or an alignment, and what does not map?", "kind": "interoperability", "answer_data": [ "External vocabulary identifier", "Mapping table", "List of unmappable values" ] } ], "data_elements": [ { "id": "de03-family", "name": "decision_family", "description": "Coded decision family that selects the applicable handling, authority and retention rules.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "de03-binding", "name": "binding_character", "description": "Whether the instrument is binding, advisory or recommendatory.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-016" ] }, { "id": "de03-stage", "name": "procedural_stage", "description": "Interim, partial, recommended or final position of this decision in its procedure.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "Classification is a set of coded attributes of the decision record itself. It produces no separate deliverable object; the controlled vocabularies it draws on are governed by the Dimension's registry links rather than by an artifact of this finding." }, { "id": "f04-subject-matter-and-scope", "name": "Subject matter and scope of application", "description": "What the decision is about and how far its effect reaches — addressees only or a general class, which territory or jurisdiction, and which organisational or asset scope.", "source_refs": [ "SRC-004", "SRC-007", "SRC-006", "SRC-003" ], "questions": [ { "id": "q04-subject", "text": "What subject matter does the decision concern, and against which classification scheme is that subject expressed?", "kind": "classification", "answer_data": [ "Subject descriptors", "Classification scheme identifier", "Free-text matter summary" ] }, { "id": "q04-reach", "text": "Does the decision bind only named addressees, or does it apply generally to a class of persons, cases or objects?", "kind": "constraint", "answer_data": [ "Scope-of-effect code (individual or general)", "Class definition where general", "Named addressee references where individual" ] }, { "id": "q04-jurisdiction", "text": "Which jurisdiction, territory or organisational unit does the decision operate in, and is its effect limited to that boundary?", "kind": "spatial", "answer_data": [ "Jurisdiction identifier", "Territorial extent", "Organisational scope", "Statement of extraterritorial effect if any" ] }, { "id": "q04-precedent", "text": "Is the decision intended to have precedential or policy effect beyond the instant matter, and who may rely on it?", "kind": "authority", "answer_data": [ "Precedential status", "Reliance rule", "Publication requirement triggered by precedential status" ] } ], "data_elements": [ { "id": "de04-subject", "name": "subject_descriptors", "description": "Coded or textual descriptors of the matter decided.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-006" ] }, { "id": "de04-scope", "name": "scope_of_effect", "description": "Whether the decision has individual effect on named addressees or general effect on a defined class.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "de04-jurisdiction", "name": "jurisdiction", "description": "Jurisdiction or organisational domain within which the decision operates.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-007" ] }, { "id": "de04-territory", "name": "territorial_extent", "description": "Geographic extent of effect where the decision is territorially bounded.", "value_kind": "geometry", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Subject and scope are inline descriptive attributes and references to externally governed classification schemes and jurisdiction registers. Producing a separate artifact would duplicate those registers, which belong to sibling classification models." } ] } ] }, { "id": "substance-and-reasoning", "name": "Substance and reasoning", "description": "The decided question, the outcome and any attached conditions or obligations, together with the reasons, alternatives considered and evidence that support the outcome.", "rationale": "Substance and reasons are the part of a decision record that authorities most often make mandatory: 5 U.S.C. §557(c) requires findings, conclusions and reasons on all material issues, Charter Article 41(2)(c) imposes a duty to give reasons, and ISO/IEC/IEEE 42010 requires rationale that covers alternatives not chosen. Outcome vocabularies and the obligation/advice split are given normative shape by XACML.", "source_refs": [ "SRC-004", "SRC-007", "SRC-016", "SRC-003" ], "layers": [ { "id": "l-decision-substance", "name": "Decision substance", "description": "The question put, the disposition reached, and the conditions, obligations and implementation duties attached to it.", "source_refs": [ "SRC-004", "SRC-003", "SRC-016" ], "findings": [ { "id": "f05-matter-under-decision", "name": "Question put for decision", "description": "The precise question, proposal, motion or request the decision resolves, including how it was framed and by whom it was brought.", "source_refs": [ "SRC-004", "SRC-016", "SRC-010" ], "questions": [ { "id": "q05-question", "text": "What exact question, motion or proposal was put, and in what wording was it put to the deciding body?", "kind": "definition", "answer_data": [ "Verbatim question or motion text", "Wording source reference", "Language of the wording" ] }, { "id": "q05-trigger", "text": "What triggered the decision — an application, a referral, a statutory duty, a scheduled review or an own-initiative act — and who initiated it?", "kind": "process", "answer_data": [ "Trigger type code", "Initiating party reference", "Reference to the triggering request or instrument", "Trigger timestamp" ] }, { "id": "q05-concerns", "text": "Which stakeholder concerns, requirements or criteria was the decision required to address?", "kind": "requirement", "answer_data": [ "Concern or criterion identifiers", "Stakeholder references", "Mapping from concerns to the outcome" ] }, { "id": "q05-reframing", "text": "Was the question amended, split or reframed before decision, and is the final wording distinguishable from the original?", "kind": "lifecycle", "answer_data": [ "Original wording", "Amended wording", "Amendment timestamps", "Amendment authority" ] } ], "data_elements": [ { "id": "de05-question", "name": "question_text", "description": "Verbatim wording of the question, motion or proposal decided.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-010" ] }, { "id": "de05-trigger", "name": "trigger_reference", "description": "Reference to the application, referral, duty or scheduled review that caused the decision to be taken.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de05-concerns", "name": "addressed_concerns", "description": "Concerns, criteria or requirements the decision was required to resolve.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] } ], "artifacts": [ { "id": "art-proposal-or-application", "name": "Proposal, motion or application as submitted", "description": "The originating document that put the question — an application form, a submitted motion, a board paper or a referral — as received, before amendment.", "media_or_form": [ "submitted application", "board paper", "motion text", "referral letter", "structured request payload" ], "serial": false, "identity_strategy": "Identified by the submitting or receiving system's authoritative intake reference; falls back to a Dimension-assigned ULID when the submission arrived without a governed reference.", "source_refs": [ "SRC-004", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "f06-outcome-and-disposition", "name": "Outcome and disposition", "description": "The operative determination: the outcome value, the order or relief granted or refused, and any non-outcome such as deferral, withdrawal or inability to decide.", "source_refs": [ "SRC-003", "SRC-004", "SRC-010" ], "questions": [ { "id": "q06-outcome", "text": "What is the operative outcome value, and from which controlled vocabulary is it drawn?", "kind": "decision", "answer_data": [ "Outcome code", "Vocabulary identifier", "Verbatim operative wording" ] }, { "id": "q06-nonoutcome", "text": "How are non-dispositive results represented — deferral, adjournment, withdrawal, no quorum, tie, not applicable or unable to determine?", "kind": "exception", "answer_data": [ "Non-outcome code", "Reason for the non-outcome", "Whether the matter remains open", "Next scheduled step" ] }, { "id": "q06-operative-part", "text": "Which part of the record is the operative determination, and which parts are reasoning that does not bind?", "kind": "composition", "answer_data": [ "Pointer to the operative part", "Pointer to reasoning parts", "Rule distinguishing them" ] }, { "id": "q06-partial", "text": "Where the decision grants in part and refuses in part, how is each element of relief and refusal separately expressed?", "kind": "composition", "answer_data": [ "Itemised relief elements with per-item outcome", "Per-item reasons reference", "Aggregate outcome derivation rule" ] }, { "id": "q06-xacml-map", "text": "If an external four-valued authorization vocabulary is used, which administrative outcomes have no equivalent and how is that recorded?", "kind": "interoperability", "answer_data": [ "Mapping table to external decision values", "Unmapped outcome list", "Conflict note" ] } ], "data_elements": [ { "id": "de06-outcome", "name": "outcome_code", "description": "Coded operative outcome, for example granted, refused, granted with conditions, deferred, withdrawn, no decision or indeterminate.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de06-operative", "name": "operative_text", "description": "Verbatim operative part stating the rule, order, sanction, relief or denial.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "de06-items", "name": "outcome_items", "description": "Per-item outcomes where the decision disposes of several requests or heads of relief separately.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de06-status-detail", "name": "outcome_status_detail", "description": "Machine status detail explaining an indeterminate or not-applicable result, such as a missing attribute or an evaluation error.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "art-decision-instrument", "name": "Signed decision instrument", "description": "The issued instrument that carries the operative determination — the order, judgment, resolution, permit decision or notice of refusal — in its authentic expression.", "media_or_form": [ "signed PDF/A document", "XML legal document instance", "paper original with wet signature", "sealed electronic document" ], "serial": true, "identity_strategy": "Bears the canonical decision identifier from the issuing authority's decision series; where the authority participates in a governed global scheme the scheme identifier is carried on the face of the instrument.", "source_refs": [ "SRC-004", "SRC-009", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "f07-conditions-and-obligations", "name": "Conditions, obligations, advice and implementation duties", "description": "What must happen for the decision to take or keep effect, what the decision obliges parties to do, what is merely advisory, and which implementation and enforcement duties follow.", "source_refs": [ "SRC-003", "SRC-004", "SRC-010" ], "questions": [ { "id": "q07-conditions", "text": "Which conditions must be satisfied before the decision takes effect, and which conditions if breached end its effect?", "kind": "constraint", "answer_data": [ "Condition precedent list with due dates", "Condition subsequent list with breach consequences", "Verification responsibility per condition" ] }, { "id": "q07-oblig-vs-advice", "text": "Which attached requirements are binding obligations that must be discharged and which are advice that may be disregarded without invalidating the outcome?", "kind": "requirement", "answer_data": [ "Obligation list with obligor and deadline", "Advice list", "Rule for handling an obligation that cannot be discharged" ] }, { "id": "q07-enforcement", "text": "Who is responsible for implementing and enforcing the decision, and what happens if it is not implemented?", "kind": "process", "answer_data": [ "Implementing party reference", "Enforcement authority reference", "Non-compliance consequence", "Compliance monitoring interval" ] }, { "id": "q07-deferred-effect", "text": "Is effectiveness deliberately deferred to a later date or a future event, and is there a maximum permitted deferral?", "kind": "temporal", "answer_data": [ "Deferred effective date as RFC 3339 timestamp", "Triggering future event", "Maximum deferral rule and its source" ] } ], "data_elements": [ { "id": "de07-conditions", "name": "conditions", "description": "Conditions precedent and subsequent with type, due date, verifying party and current satisfaction state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-010" ] }, { "id": "de07-obligations", "name": "obligations", "description": "Binding obligations attached to the outcome, each with obligor, description and discharge deadline.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de07-advice", "name": "advisory_items", "description": "Non-binding advice attached to the outcome that may be disregarded without affecting validity.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de07-implementer", "name": "implementing_party", "description": "Party accountable for carrying the decision into effect.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "art-condition-compliance-evidence", "name": "Condition compliance evidence", "description": "Evidence lodged to show that a condition precedent or subsequent has been satisfied, such as a certificate, inspection report or payment confirmation.", "media_or_form": [ "certificate", "inspection report", "payment confirmation", "structured attestation" ], "serial": false, "identity_strategy": "Identified by the issuing body's own certificate or report number; otherwise a Dimension-assigned ULID linked to the condition identifier it discharges.", "source_refs": [ "SRC-004", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "l-reasoning-and-evidence", "name": "Reasoning and evidence", "description": "The stated reasons, the alternatives weighed and rejected, and the evidence and findings of fact on which the outcome rests.", "source_refs": [ "SRC-004", "SRC-007", "SRC-016", "SRC-001" ], "findings": [ { "id": "f08-statement-of-reasons", "name": "Statement of reasons", "description": "The reasoning that justifies the outcome, whether giving reasons is legally required for this decision, and whether the reasons form part of the operative instrument or a separate document.", "source_refs": [ "SRC-004", "SRC-007", "SRC-016" ], "questions": [ { "id": "q08-duty", "text": "Is there a legal or policy duty to give reasons for this decision, and what instrument imposes it?", "kind": "requirement", "answer_data": [ "Duty flag", "Citing instrument and provision", "Consequence of failing to give reasons" ] }, { "id": "q08-content", "text": "Do the reasons address all material issues of fact, law and discretion presented, and how is that completeness checked?", "kind": "validation", "answer_data": [ "Issue list with per-issue reasoning reference", "Completeness check outcome", "Checker identity and check timestamp" ] }, { "id": "q08-location", "text": "Are the reasons part of the operative instrument, an annexed statement, or a separately requestable document?", "kind": "composition", "answer_data": [ "Reasons location code", "Reference to the reasons document", "Rule on requesting reasons after the fact" ] }, { "id": "q08-abbrev", "text": "Where reasons are abbreviated, standardised or omitted, what justifies that and is a fuller statement available on request?", "kind": "exception", "answer_data": [ "Abbreviation basis", "Template identifier where standardised", "Availability of full reasons and how to obtain them" ] } ], "data_elements": [ { "id": "de08-reasons", "name": "reasons_text", "description": "The statement of findings, conclusions and the reasons or basis for them on the material issues.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "de08-duty", "name": "reasons_duty_basis", "description": "Instrument and provision imposing the duty to give reasons, where one applies.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "de08-issue-map", "name": "issue_to_reason_map", "description": "Mapping from each material issue raised to the passage of reasoning that resolves it.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "art-statement-of-reasons", "name": "Statement of reasons document", "description": "The document setting out findings, conclusions and reasons, whether embodied in the decision instrument or issued as a separate annexed or later-requested statement.", "media_or_form": [ "annex to the decision instrument", "separate reasons document", "structured reasoning object", "XML motivation section" ], "serial": false, "identity_strategy": "Inherits the decision's work identifier with a part or annex discriminator when embodied in the instrument; carries its own issuing reference when produced separately after request.", "source_refs": [ "SRC-004", "SRC-009", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "f09-options-considered", "name": "Options considered and rejected", "description": "The alternatives evaluated, the criteria and weights applied, and the recorded justification for rejecting each alternative not chosen.", "source_refs": [ "SRC-016", "SRC-004" ], "questions": [ { "id": "q09-alternatives", "text": "Which alternatives were formally considered, and is the list complete relative to what the deciding body was given?", "kind": "evidence", "answer_data": [ "Alternative identifiers and descriptions", "Source of each alternative", "Completeness attestation" ] }, { "id": "q09-criteria", "text": "Against which criteria and weights were the alternatives assessed, and were those criteria fixed before assessment?", "kind": "measurement", "answer_data": [ "Criterion list with weights", "Criteria fixing timestamp", "Scoring method" ] }, { "id": "q09-rejection", "text": "For each rejected alternative, what is the recorded reason for rejection?", "kind": "decision", "answer_data": [ "Per-alternative rejection reason", "Reference to supporting analysis", "Whether rejection was unanimous" ] }, { "id": "q09-do-nothing", "text": "Was the status quo or 'take no action' option explicitly assessed, and on what basis was it set aside?", "kind": "decision", "answer_data": [ "Status quo assessed flag", "Assessment summary", "Rejection basis" ] } ], "data_elements": [ { "id": "de09-options", "name": "considered_options", "description": "Alternatives assessed, each with description, assessment result and rejection reason where not chosen.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de09-criteria", "name": "assessment_criteria", "description": "Criteria and weights used to compare alternatives.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de09-scores", "name": "option_scores", "description": "Recorded scores or comparative assessments per option and criterion.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] } ], "artifacts": [ { "id": "art-options-appraisal", "name": "Options appraisal or comparative analysis", "description": "The analysis put before the deciding body comparing alternatives against criteria, including any scoring model and its assumptions.", "media_or_form": [ "appraisal report", "comparison matrix", "structured scoring dataset", "business case annex" ], "serial": false, "identity_strategy": "Identified by the authoring body's document reference; linked to the decision by the decision's canonical identifier plus a role qualifier marking it as an input relied upon.", "source_refs": [ "SRC-016", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "f10-evidence-and-findings", "name": "Evidence relied upon and findings of fact", "description": "The inputs the decision-maker used, the facts found from them, submissions received, and any communications that a rule requires to be placed on the record.", "source_refs": [ "SRC-004", "SRC-001", "SRC-007", "SRC-003" ], "questions": [ { "id": "q10-inputs", "text": "Which specific inputs did the decision-maker use, and are they retained and resolvable at the version actually relied upon?", "kind": "provenance", "answer_data": [ "Input references with version or hash", "Retention location", "Resolution status at decision time" ] }, { "id": "q10-facts", "text": "What facts were found, and which input supports each finding?", "kind": "evidence", "answer_data": [ "Finding statements", "Per-finding supporting input reference", "Standard of proof applied" ] }, { "id": "q10-hearing", "text": "Was the affected party heard before an adverse measure, and what submissions were received and considered?", "kind": "process", "answer_data": [ "Hearing offered flag and date", "Submissions received with dates", "Statement of how submissions were addressed" ] }, { "id": "q10-exparte", "text": "Were any prohibited or off-record communications received, and were they placed on the record as required?", "kind": "exception", "answer_data": [ "Communication log entries", "Disclosure timestamp", "Remedial action taken" ] }, { "id": "q10-attribute-sources", "text": "For machine-evaluated inputs, which attribute sources supplied values and were any required attributes missing?", "kind": "provenance", "answer_data": [ "Attribute source identifiers", "Attribute values or hashes", "Missing attribute list and effect on the outcome" ] } ], "data_elements": [ { "id": "de10-inputs", "name": "inputs_used", "description": "References to documents, data and testimony used in reaching the decision, each with a version or content hash.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "de10-findings", "name": "findings_of_fact", "description": "Facts found, each linked to its supporting input.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de10-submissions", "name": "party_submissions", "description": "Submissions, representations and proposed findings received from parties, with receipt timestamps.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "de10-exparte", "name": "disclosed_communications", "description": "Communications required to be placed on the record, with content reference and disclosure time.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "art-evidence-bundle", "name": "Evidence bundle or exhibit list", "description": "The enumerated set of inputs before the decision-maker, fixed at decision time, with per-item references and integrity digests.", "media_or_form": [ "exhibit list", "case bundle index", "manifest with content digests", "structured input manifest" ], "serial": false, "identity_strategy": "Identified by the case or matter reference plus a bundle sequence number from the managing system; each entry is keyed by the exhibit number assigned in the procedure.", "source_refs": [ "SRC-004", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "f31-completeness-of-rulings-and-implementation-confirmation", "name": "Completeness of rulings and confirmation of implementation", "description": "APA requires the record to show the ruling on each finding, conclusion or exception. MADR confirmation describes how implementation or compliance will be checked. Completeness is a quality property of the decision record; implementation evidence may live in sibling operational models.", "source_refs": [ "SRC-021", "SRC-022" ], "questions": [ { "id": "f31-completeness-of-rulings-and-implementation-confirmation-q01", "text": "Does the record contain a ruling on every material issue and every exception presented, and which items are missing?", "kind": "quality", "answer_data": [ "issues_requiring_ruling_count", "issues_with_ruling_count", "missing_issue_ids", "completeness_assessment" ] }, { "id": "f31-completeness-of-rulings-and-implementation-confirmation-q02", "text": "How will compliance with the decision be confirmed, and by whom?", "kind": "validation", "answer_data": [ "confirmation_method", "confirmation_agent_id", "confirmation_due_timestamp" ] }, { "id": "f31-completeness-of-rulings-and-implementation-confirmation-q03", "text": "Has implementation been confirmed, with what result and evidence?", "kind": "evidence", "answer_data": [ "confirmation_status_code", "confirmation_timestamp", "confirmation_evidence_refs" ] } ], "data_elements": [ { "id": "f31-completeness-of-rulings-and-implementation-confirmation-data01", "name": "Completeness assessment", "description": "Assessment that required rulings are present.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021" ] }, { "id": "f31-completeness-of-rulings-and-implementation-confirmation-data02", "name": "Confirmation", "description": "Method, due time, status and evidence of implementation or compliance checks.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-022" ] } ], "artifacts": [ { "id": "f31-completeness-of-rulings-and-implementation-confirmation-artifact01", "name": "Confirmation or compliance evidence", "description": "Review, test, audit or ArchUnit-style check that the chosen decision was implemented.", "media_or_form": [ "report", "log", "test-result" ], "serial": false, "identity_strategy": "Child artefact of the decision record or reference to an audit-workpaper sibling.", "source_refs": [ "SRC-022" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "authority-and-approval", "name": "Authority, approval and attestation", "description": "The competence under which the decision was taken, delegation and limits on it, the participation and voting that produced it, declared conflicts, and the evidence that fixes and attributes the record.", "rationale": "A decision that exceeds the decider's competence is voidable, so authority is not metadata but a validity condition. Delaware §141 supplies primary rules on quorum, committee limits, remote presence and action without a meeting; 5 U.S.C. §557 separates presiding, recommending and deciding roles; PROV-O supplies the qualified association and delegation pattern; RFC 3161 supplies third-party time attestation.", "source_refs": [ "SRC-010", "SRC-004", "SRC-001", "SRC-012", "SRC-002" ], "layers": [ { "id": "l-mandate-and-competence", "name": "Mandate and competence", "description": "The source of power to decide, and the delegation instruments and thresholds that bound it.", "source_refs": [ "SRC-010", "SRC-004", "SRC-007", "SRC-001" ], "findings": [ { "id": "f11-authority-and-legal-basis", "name": "Decision authority and legal basis", "description": "Which body or role held competence to take this decision, the instrument conferring that competence, and the rules of composition it had to satisfy.", "source_refs": [ "SRC-010", "SRC-004", "SRC-007", "SRC-001" ], "questions": [ { "id": "q11-who", "text": "Which body, office or role took the decision, as distinct from anyone who prepared, recommended or merely signed it?", "kind": "authority", "answer_data": [ "Deciding body or role reference", "Preparer reference", "Signatory reference", "Statement distinguishing the roles" ] }, { "id": "q11-basis", "text": "Which instrument and provision confer competence to take this decision, and was it in force at the decision time?", "kind": "authority", "answer_data": [ "Conferring instrument reference and provision", "In-force status at decision time", "Version of the instrument relied upon" ] }, { "id": "q11-composition", "text": "What composition, quorum or qualification rules applied to the deciding body, and what is their source?", "kind": "constraint", "answer_data": [ "Quorum rule and source provision", "Required qualifications", "Composition at the time of decision" ] }, { "id": "q11-ultra-vires", "text": "How is it verified that the decision falls within the conferred competence, and what happens if it does not?", "kind": "validation", "answer_data": [ "Competence check outcome and checker", "Check timestamp", "Consequence of an out-of-competence finding" ] } ], "data_elements": [ { "id": "de11-deciding-body", "name": "deciding_authority", "description": "Reference to the body, office or role that took the decision.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-004" ] }, { "id": "de11-basis", "name": "authority_basis", "description": "Instrument and provision conferring competence, with the version relied upon.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007", "SRC-010" ] }, { "id": "de11-role", "name": "agent_roles", "description": "Qualified roles of each agent associated with the decision activity, for example presiding, recommending, deciding, signing or advising.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "de11-quorum-rule", "name": "quorum_rule", "description": "Applicable quorum and majority requirement with its source provision.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [ { "id": "art-authority-instrument", "name": "Instrument conferring authority", "description": "The statute, charter, bylaw, terms of reference or standing order relied on as the source of competence, at the version in force when the decision was taken.", "media_or_form": [ "statutory provision", "corporate bylaw", "committee terms of reference", "standing order", "published mandate" ], "serial": false, "identity_strategy": "Referenced by the instrument's own governed identifier and point-in-time version identifier; never copied into the decision record, only cited with the version relied upon.", "source_refs": [ "SRC-010", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "f12-delegation-and-limits", "name": "Delegation, sub-delegation and approval limits", "description": "Where the decision was taken under delegated power, the delegation chain, its thresholds and exclusions, and its validity at the decision time.", "source_refs": [ "SRC-010", "SRC-001", "SRC-004" ], "questions": [ { "id": "q12-chain", "text": "Who delegated the power, to whom, and is there a sub-delegation chain back to the original holder of competence?", "kind": "authority", "answer_data": [ "Delegator and delegate references in order", "Delegation instrument references", "Sub-delegation permitted flag" ] }, { "id": "q12-limits", "text": "What monetary, categorical or risk thresholds bound the delegated power, and does this decision fall inside them?", "kind": "constraint", "answer_data": [ "Threshold definitions", "Decision value measured against each threshold", "Within-limit determination and who made it" ] }, { "id": "q12-exclusions", "text": "Which matters are expressly excluded from delegation and reserved to the delegating body?", "kind": "constraint", "answer_data": [ "Reserved matter list with source provision", "Applicability determination for this decision" ] }, { "id": "q12-validity", "text": "Was the delegation in force at the decision time, and had it been revoked, suspended or lapsed?", "kind": "temporal", "answer_data": [ "Delegation effective and expiry timestamps", "Revocation or suspension events", "Validity determination at decision time" ] } ], "data_elements": [ { "id": "de12-delegation", "name": "delegation_chain", "description": "Ordered chain of delegating and delegated agents with the instrument authorising each step.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "de12-threshold", "name": "applicable_thresholds", "description": "Thresholds bounding the delegated power and the measured value of this decision against them.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "de12-value", "name": "decision_magnitude", "description": "Quantified magnitude of the decision used to test delegation thresholds, with unit and currency where applicable.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [ { "id": "art-delegation-instrument", "name": "Delegation of authority instrument", "description": "The signed delegation, authority matrix entry or committee mandate under which the decider acted, at the version in force at decision time.", "media_or_form": [ "signed delegation letter", "authority matrix entry", "committee mandate", "structured entitlement record" ], "serial": false, "identity_strategy": "Identified by the issuing organisation's delegation register reference plus a version discriminator; where no register exists, a Dimension-assigned ULID bound to delegator, delegate and effective period.", "source_refs": [ "SRC-010", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "l-approval-acts", "name": "Approval acts, participation and objections", "description": "The individual acts of approval, participation, voting, dissent and recusal that constitute or evidence the decision.", "source_refs": [ "SRC-010", "SRC-004", "SRC-001" ], "findings": [ { "id": "f13-participation-quorum-and-vote", "name": "Participation, quorum and vote result", "description": "Who took part and how, whether quorum was met, how votes or consents were counted, and how decisions taken without a meeting are represented.", "source_refs": [ "SRC-010", "SRC-004", "SRC-001" ], "questions": [ { "id": "q13-quorum", "text": "Was quorum required and met, counted against which denominator, and who determined that?", "kind": "validation", "answer_data": [ "Quorum required flag", "Members present and total members", "Quorum determination and determiner", "Determination timestamp" ] }, { "id": "q13-tally", "text": "How were votes cast and counted — in favour, against, abstaining, absent — and what majority did the outcome require?", "kind": "measurement", "answer_data": [ "Per-member vote values", "Aggregate tally", "Required majority and its source", "Voting method" ] }, { "id": "q13-no-meeting", "text": "If the decision was taken without a meeting, how was consent collected, when did it become effective, and where is it filed?", "kind": "process", "answer_data": [ "Consent collection method", "Per-consenter consent timestamps", "Effectiveness rule applied", "Filing location with the minutes" ] }, { "id": "q13-remote", "text": "Did any participant attend by remote communication, and does the governing rule count that as presence?", "kind": "constraint", "answer_data": [ "Remote participant list", "Communication means used", "Governing provision on presence" ] }, { "id": "q13-sequence", "text": "Where approval is multi-step, were the steps sequential or parallel, and was any step skipped, escalated or auto-approved on timeout?", "kind": "process", "answer_data": [ "Approval step list with order and status", "Skip or escalation events with reason", "Timeout policy applied" ] } ], "data_elements": [ { "id": "de13-participants", "name": "participants", "description": "Agents who participated, each with role, presence mode and eligibility to vote.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-010", "SRC-001" ] }, { "id": "de13-tally", "name": "vote_tally", "description": "Counts in favour, against, abstaining and absent, with the required majority.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "de13-quorum-met", "name": "quorum_met", "description": "Whether the applicable quorum requirement was satisfied.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "de13-consents", "name": "written_consents", "description": "Individual written or electronic consents where the decision was taken without a meeting, each with consenter and consent timestamp.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [ { "id": "art-voting-record-or-consent", "name": "Voting record or unanimous written consent", "description": "The record of votes cast, or the set of individual written or electronic consents constituting action without a meeting, filed alongside the minutes.", "media_or_form": [ "voting sheet", "electronic ballot record", "signed consent set", "minute extract" ], "serial": true, "identity_strategy": "Identified by the governing body's sitting or resolution number and the decision's canonical identifier; individual consents are keyed by consenter identifier plus consent timestamp.", "source_refs": [ "SRC-010", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "f14-dissent-recusal-and-conflicts", "name": "Dissent, recusal and conflicts of interest", "description": "Recorded disagreement with the outcome, withdrawals from participation on interest grounds, and declared conflicts affecting the decision's soundness.", "source_refs": [ "SRC-004", "SRC-010", "SRC-007" ], "questions": [ { "id": "q14-dissent", "text": "Did any participant dissent or issue a separate opinion, and is that text part of the published record?", "kind": "evidence", "answer_data": [ "Dissenting participant references", "Dissent or separate opinion text reference", "Publication status of the dissent" ] }, { "id": "q14-recusal", "text": "Did any eligible participant recuse themselves, on what stated ground, and at what point in the process?", "kind": "process", "answer_data": [ "Recused participant references", "Recusal ground", "Recusal timestamp", "Effect on quorum and tally" ] }, { "id": "q14-conflict", "text": "What conflicts of interest were declared, by whom, and how were they managed?", "kind": "quality", "answer_data": [ "Declaration entries with declarant and interest description", "Declaration timestamp", "Management measure applied" ] }, { "id": "q14-undeclared", "text": "What control detects an undeclared conflict after the decision, and what remedy applies if one is found?", "kind": "exception", "answer_data": [ "Detection control description", "Remedy path (review, revocation, annulment)", "Responsible reviewer" ] } ], "data_elements": [ { "id": "de14-dissent", "name": "dissenting_opinions", "description": "Recorded dissents or separate opinions with author references and text location.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de14-recusal", "name": "recusals", "description": "Recusal events with participant, ground, timestamp and effect on quorum.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-007" ] }, { "id": "de14-conflict", "name": "conflict_declarations", "description": "Declared interests with declarant, interest description, declaration time and management measure.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "Dissents, recusals and conflict declarations are participation events attached to the decision and are normally captured inline in the decision record or in the meeting minutes owned by WM-ACT-025. Where a dissent is issued as a standalone opinion document it is carried as an additional expression under f02 rather than as an artifact unique to this finding." } ] }, { "id": "l-attestation-and-integrity", "name": "Attestation and record integrity", "description": "The evidence that fixes the record's content and attributes it to its signatories, and the point at which it becomes unalterable.", "source_refs": [ "SRC-012", "SRC-002", "SRC-011", "SRC-017" ], "findings": [ { "id": "f15-attestation-and-integrity-evidence", "name": "Signature, seal, time-stamp and integrity evidence", "description": "How the record is signed or sealed, how its content is fixed by digest and third-party time attestation, and how a later verifier can re-establish that it has not changed.", "source_refs": [ "SRC-012", "SRC-002", "SRC-011", "SRC-017" ], "questions": [ { "id": "q15-signature", "text": "Who signed or sealed the record, in what capacity, and with what kind of signature or seal?", "kind": "provenance", "answer_data": [ "Signatory references with capacity", "Signature or seal type", "Signature object reference", "Asserted signing time" ] }, { "id": "q15-timestamp", "text": "Is there a third-party attested time of existence for the record content, and how does it differ from the asserted signing time?", "kind": "evidence", "answer_data": [ "Time-stamp token reference", "Attested generation time", "Stated accuracy", "Issuing authority and policy identifier", "Difference from asserted signing time" ] }, { "id": "q15-digest", "text": "Which content was hashed, with which algorithm, and does the digest cover the reasons and annexes as well as the operative part?", "kind": "validation", "answer_data": [ "Digest algorithm identifier", "Digest value", "Precise coverage description", "Canonical form used before hashing" ] }, { "id": "q15-verify", "text": "When was verification last performed, by whom, with what verdict, and what is the re-verification interval?", "kind": "validation", "answer_data": [ "Verification verdict", "Verifier identity", "Verification timestamp", "Re-verification interval and next due date" ] }, { "id": "q15-fixity-point", "text": "At which lifecycle point does the record become unalterable, and what mechanism enforces that?", "kind": "lifecycle", "answer_data": [ "Fixity point definition", "Enforcement mechanism", "Permitted post-fixity operations", "Event-history entry recording the transition" ] } ], "data_elements": [ { "id": "de15-signature", "name": "signature_evidence", "description": "References to signature or seal objects with signatory, capacity, type and asserted signing time.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-002" ] }, { "id": "de15-tst", "name": "time_stamp_token", "description": "Third-party time-stamp token reference carrying attested generation time, accuracy, policy and issuer serial number.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de15-digest", "name": "content_digest", "description": "Digest algorithm, value and coverage statement fixing the record content.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-002" ] }, { "id": "de15-verification", "name": "last_verification", "description": "Most recent integrity and attestation verification with verdict, verifier and RFC 3339 verification timestamp.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "de15-fixed-at", "name": "fixed_at", "description": "Time at which the record became unalterable, recorded as an RFC 3339 timestamp with explicit offset or Z.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-017" ] } ], "artifacts": [ { "id": "art-timestamp-token", "name": "Trusted time-stamp token", "description": "A time-stamp token binding a digest of the record to an attested generation time, carrying the issuing authority's per-token serial number, policy identifier and stated accuracy.", "media_or_form": [ "detached token file", "embedded signature time-stamp", "archival time-stamp in a long-term signature container" ], "serial": true, "identity_strategy": "Identified by the issuing authority identifier plus the unique integer serial number that the authority assigns to each token; the token itself is not re-issued or renumbered.", "source_refs": [ "SRC-012" ] }, { "id": "art-event-history", "name": "Immutable event history entry", "description": "Append-only audit entry recording each action taken on the record — capture, approval, issuance, supersession, disposal — with actor, action and time.", "media_or_form": [ "append-only audit log entry", "system event record", "exported audit trail" ], "serial": true, "identity_strategy": "Sequential entry number within the record's event history, never reused; each entry additionally carries the record identifier and an RFC 3339 event timestamp.", "source_refs": [ "SRC-017", "SRC-011", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "time-validity-and-lifecycle", "name": "Time, validity and lifecycle", "description": "The distinct times attaching to a decision, the period during which it is valid, its status transitions and finality, and the ways it is superseded, revoked, challenged or annulled.", "rationale": "Decision records fail most often on time: a single 'decision date' cannot express that consent became effective when the last consent was delivered, that issuance and service differ, that validity is a range distinct from issuance, or that annulment operates retroactively. RFC 3339, DCMI Terms and Delaware §141(f) each supply primary support for separating these.", "source_refs": [ "SRC-005", "SRC-008", "SRC-010", "SRC-001", "SRC-002" ], "layers": [ { "id": "l-temporal-frame", "name": "Temporal frame", "description": "The set of separately recorded times around a decision, and the validity period distinct from any of them.", "source_refs": [ "SRC-005", "SRC-008", "SRC-010", "SRC-001" ], "findings": [ { "id": "f16-decision-event-timeline", "name": "Decision event timeline", "description": "The distinct, separately recorded moments in a decision's life — taken, consented, signed, issued, served, published, in force — plus the observation time at which each was recorded.", "source_refs": [ "SRC-005", "SRC-008", "SRC-001", "SRC-010" ], "questions": [ { "id": "q16-which-times", "text": "Which distinct times exist for this decision, and which one is the authoritative 'decision time' for citation and for computing deadlines?", "kind": "temporal", "answer_data": [ "Enumerated event times with labels", "Nominated authoritative decision time", "Rule selecting it", "Deadlines computed from it" ] }, { "id": "q16-event-vs-record", "text": "Are the time the event occurred and the time it was recorded or ingested stored separately, and how far apart are they?", "kind": "provenance", "answer_data": [ "Event timestamp", "Recording or ingestion timestamp", "Latency and its acceptable bound" ] }, { "id": "q16-offset", "text": "Does every stored time carry an explicit UTC offset or Z, and how is an unknown local offset represented?", "kind": "constraint", "answer_data": [ "Timestamp format rule", "Offset handling policy", "Representation used for unknown local offset" ] }, { "id": "q16-effective-consent", "text": "For action taken by consent rather than at a sitting, what rule fixes the moment the decision was taken?", "kind": "temporal", "answer_data": [ "Effectiveness rule and source provision", "Last consent delivery timestamp", "Any stated later effective date" ] }, { "id": "q16-service", "text": "When was the decision served on or notified to each addressee, and does that start a challenge period?", "kind": "temporal", "answer_data": [ "Per-addressee service timestamps", "Proof of service references", "Challenge period start and length" ] } ], "data_elements": [ { "id": "de16-decided-at", "name": "decided_at", "description": "Authoritative time the decision was taken, as an RFC 3339 timestamp with explicit offset or Z.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-010" ] }, { "id": "de16-issued-at", "name": "issued_at", "description": "Time of formal issuance of the decision instrument.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de16-recorded-at", "name": "recorded_at", "description": "Time the decision was captured into the records system, recorded separately from the event time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-001" ] }, { "id": "de16-served-at", "name": "served_at", "description": "Per-addressee service or notification times that start challenge periods.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-007" ] }, { "id": "de16-in-force-at", "name": "in_force_at", "description": "Time from which the decision produces legal or operational effect, where different from issuance.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "The timeline is a set of typed timestamp values on the decision record, each already evidenced by an artifact owned elsewhere in the model: proof of service under f25, the time-stamp token under f15 and the event-history entry under f15. Minting a separate timeline artifact would duplicate those without adding evidential weight." }, { "id": "f17-validity-window-and-applicability", "name": "Validity window, retroactivity and expiry", "description": "The period during which the decision is valid, whether effect reaches backwards in time, and how expiry, renewal and suspension of validity are represented.", "source_refs": [ "SRC-008", "SRC-010", "SRC-004" ], "questions": [ { "id": "q17-window", "text": "From when until when is the decision valid, and is the end open, fixed, conditional or event-driven?", "kind": "temporal", "answer_data": [ "Validity start timestamp", "Validity end timestamp or open-ended marker", "End-determination rule" ] }, { "id": "q17-retroactive", "text": "Does the decision take effect from a date earlier than it was taken, and what authorises that retroactivity?", "kind": "temporal", "answer_data": [ "Retroactive effect flag", "Retroactive effective date", "Authorising provision", "Affected prior acts" ] }, { "id": "q17-suspension", "text": "Can validity be suspended without being ended, and what events suspend and restore it?", "kind": "state", "answer_data": [ "Suspension events with start and end timestamps", "Suspending authority", "Effect of suspension on obligations" ] }, { "id": "q17-renewal", "text": "Is the decision renewable or subject to periodic review, and does renewal create a new decision or extend this one?", "kind": "lifecycle", "answer_data": [ "Renewal mechanism", "Review due date", "Whether renewal mints a new identifier" ] }, { "id": "q17-asof", "text": "How does a consumer ask whether the decision was valid at a specific past instant, and what does the answer depend on?", "kind": "validation", "answer_data": [ "As-of evaluation rule", "Inputs required (validity window, suspensions, revocations, annulments)", "Returned validity verdict with the instant evaluated" ] } ], "data_elements": [ { "id": "de17-valid-from", "name": "valid_from", "description": "Start of the period of validity, which may precede the decision time where retroactivity is authorised.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de17-valid-until", "name": "valid_until", "description": "End of the period of validity, absent where validity is open-ended.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de17-retro", "name": "retroactive_basis", "description": "Provision authorising effect earlier than the decision time, where claimed.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de17-suspensions", "name": "validity_suspensions", "description": "Suspension intervals during which the decision does not produce effect, each with authority and reason.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-010" ] }, { "id": "de17-review-due", "name": "review_due_date", "description": "Date on which the decision falls due for periodic review or renewal.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Validity is a temporal property of the decision expressed inline through a start, an end and suspension intervals. Where an authority issues a separate certificate of validity or currency, that is an outward-facing attestation carried by the notification artifact under f25, not a distinct object owned here." } ] }, { "id": "l-lifecycle-and-change", "name": "Lifecycle, change and challenge", "description": "Status transitions and the point of finality, the mechanisms by which a decision is amended, replaced or undone, and the routes by which it can be challenged.", "source_refs": [ "SRC-008", "SRC-002", "SRC-004", "SRC-017", "SRC-007" ], "findings": [ { "id": "f18-status-model-and-finality", "name": "Status model and finality", "description": "The permitted states of a decision record, the transitions between them, and the point at which the decision becomes final and the record unalterable.", "source_refs": [ "SRC-002", "SRC-017", "SRC-011", "SRC-004" ], "questions": [ { "id": "q18-states", "text": "What is the complete set of permitted states, and which are terminal?", "kind": "state", "answer_data": [ "State enumeration with definitions", "Terminal state list", "Initial state" ] }, { "id": "q18-transitions", "text": "Which transitions are permitted, who may trigger each, and what preconditions guard them?", "kind": "lifecycle", "answer_data": [ "Transition table with source and target states", "Authorised trigger role per transition", "Preconditions per transition" ] }, { "id": "q18-final", "text": "When does the decision become final in the substantive sense — no longer open to ordinary challenge — and is that different from the record becoming unalterable?", "kind": "lifecycle", "answer_data": [ "Substantive finality condition and date", "Record fixity point", "Statement distinguishing them" ] }, { "id": "q18-draft-boundary", "text": "At what point does a draft or proposed decision become a record subject to management, and how are pre-record drafts handled?", "kind": "lifecycle", "answer_data": [ "Capture threshold definition", "Draft handling and retention rule", "Capture timestamp" ] }, { "id": "q18-post-final", "text": "Which operations remain permitted after finality, and how is each recorded without altering the fixed content?", "kind": "constraint", "answer_data": [ "Permitted post-finality operation list", "Recording mechanism (event history, new expression)", "Prohibited operation list" ] } ], "data_elements": [ { "id": "de18-status", "name": "status", "description": "Current state of the decision record drawn from the governed state enumeration.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-017" ] }, { "id": "de18-transitions", "name": "status_history", "description": "Ordered history of state transitions with actor, reason and RFC 3339 transition timestamp.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-017", "SRC-011", "SRC-005" ] }, { "id": "de18-final-at", "name": "became_final_at", "description": "Time at which ordinary challenge routes were exhausted or expired.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "The status model is a governed enumeration and transition table applied to the record, with each transition already evidenced by the immutable event-history artifact defined under f15. Duplicating that evidence as a second artifact would create two competing audit trails." }, { "id": "f19-supersession-and-revocation", "name": "Supersession, amendment, corrigendum and revocation", "description": "How a later act changes or displaces this decision, distinguishing correction of the text from amendment of the substance and from withdrawal of the decision itself.", "source_refs": [ "SRC-008", "SRC-001", "SRC-009", "SRC-004" ], "questions": [ { "id": "q19-kind", "text": "Which change type applies — corrigendum to the text, amendment to the substance, replacement by a new decision, or revocation without replacement?", "kind": "lifecycle", "answer_data": [ "Change type code", "Justification for the classification", "Reference to the changing act" ] }, { "id": "q19-links", "text": "Which decision replaces this one and which does this one replace, expressed as explicit bidirectional links?", "kind": "relationship", "answer_data": [ "Replaced-by references", "Replaces references", "Link assertion timestamps" ] }, { "id": "q19-scope", "text": "Does the change affect the whole decision or only identified parts, and does the remainder stay in force?", "kind": "composition", "answer_data": [ "Affected part references", "Unaffected part statement", "Consolidated expression reference" ] }, { "id": "q19-who", "text": "Who is competent to revoke or amend this decision, and must it be the same or a higher authority?", "kind": "authority", "answer_data": [ "Competent revoking authority", "Source provision", "Any procedural precondition such as a hearing" ] }, { "id": "q19-effect", "text": "From when does the change take effect, and does it disturb acts already taken in reliance on the original?", "kind": "temporal", "answer_data": [ "Change effective timestamp", "Prospective or retroactive character", "Treatment of acts done in reliance" ] } ], "data_elements": [ { "id": "de19-change-type", "name": "change_type", "description": "Whether the change is a corrigendum, an amendment, a replacement or a revocation.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-004" ] }, { "id": "de19-replaced-by", "name": "is_replaced_by", "description": "Reference to the decision that supersedes this one.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de19-replaces", "name": "replaces", "description": "Reference to the decision or decisions this one supersedes.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de19-invalidated-at", "name": "invalidated_at", "description": "Time from which the decision ceased to be usable or effective as a result of the change.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "art-revoking-or-amending-act", "name": "Revoking, amending or correcting act", "description": "The later instrument that corrects, amends, replaces or revokes this decision, itself an instance of this model and linked bidirectionally.", "media_or_form": [ "revocation notice", "amending decision instrument", "published corrigendum", "structured supersession record" ], "serial": true, "identity_strategy": "Carries its own canonical decision identifier from the issuing authority's series and cites the identifier of the decision it changes; the changed decision's identifier is never reassigned.", "source_refs": [ "SRC-008", "SRC-009", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "f20-challenge-and-annulment", "name": "Challenge, appeal, review and annulment", "description": "The routes by which the decision can be contested, the time limits and suspensive effects that apply, and how the outcome of a challenge is recorded against the original.", "source_refs": [ "SRC-004", "SRC-007", "SRC-015", "SRC-006" ], "questions": [ { "id": "q20-routes", "text": "What challenge routes exist — internal review, administrative appeal, judicial review, ombudsman — and which apply to this decision?", "kind": "process", "answer_data": [ "Available route list with forum references", "Applicability determination", "Route stated in the decision notice" ] }, { "id": "q20-deadline", "text": "What is the time limit for challenge, from which event does it run, and can it be extended?", "kind": "temporal", "answer_data": [ "Limit duration", "Start event reference", "Computed deadline as an RFC 3339 timestamp", "Extension grounds" ] }, { "id": "q20-suspensive", "text": "Does lodging a challenge suspend the decision's effect, and if not can suspension be requested separately?", "kind": "state", "answer_data": [ "Suspensive effect flag", "Basis provision", "Interim relief mechanism and its status" ] }, { "id": "q20-outcome", "text": "How is the outcome of a challenge recorded — upheld, varied, quashed, remitted — and does it alter, replace or annul the original?", "kind": "lifecycle", "answer_data": [ "Challenge outcome code", "Reference to the reviewing decision", "Effect on the original record", "Effective timestamp of the outcome" ] }, { "id": "q20-annulment-effect", "text": "Where a decision is annulled, does the annulment operate from the original date or only from the annulment, and what happens to acts done meanwhile?", "kind": "temporal", "answer_data": [ "Annulment temporal character", "Affected intervening acts", "Restitution or remediation obligations" ] } ], "data_elements": [ { "id": "de20-routes", "name": "challenge_routes", "description": "Available contest routes with forum, deadline and suspensive effect.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "de20-deadline", "name": "challenge_deadline", "description": "Computed deadline by which a challenge must be lodged.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de20-challenges", "name": "challenges", "description": "Lodged challenges with challenger, forum, lodging date, current state and outcome.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-006" ] }, { "id": "de20-outcome-effect", "name": "review_outcome_effect", "description": "Effect of a review outcome on the original decision, such as upheld, varied, quashed or remitted.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "art-review-decision", "name": "Review or appeal decision", "description": "The decision of the reviewing body disposing of a challenge, linked to the original decision and itself an instance of this model.", "media_or_form": [ "appellate judgment", "internal review determination", "ombudsman finding", "structured review outcome" ], "serial": true, "identity_strategy": "Identified by the reviewing forum's own decision identifier, using the governed global scheme where the forum is a court that participates in one; cites the challenged decision's identifier.", "source_refs": [ "SRC-006", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "f30-adjudicative-grade-and-conclusiveness", "name": "Adjudicative grade and conclusiveness", "description": "In hearings under APA § 557, a presiding employee may issue an initial decision that becomes the agency decision unless appealed or reviewed; otherwise a recommended or tentative decision may be required, except where the agency finds on the record that due and timely execution of its functions imperatively and unavoidably requires omission.", "source_refs": [ "SRC-021" ], "questions": [ { "id": "f30-adjudicative-grade-and-conclusiveness-q01", "text": "Is this an initial, recommended, tentative or final agency decision, or does that grading not apply?", "kind": "classification", "answer_data": [ "decision_grade_code", "grade_applicable_flag", "becomes_final_unless_appealed_flag" ] }, { "id": "f30-adjudicative-grade-and-conclusiveness-q02", "text": "Did the deciding body preside at the reception of the evidence, and if not, who is the presiding or recommending employee?", "kind": "process", "answer_data": [ "presided_at_evidence_flag", "presiding_employee_id", "recommending_employee_id" ] }, { "id": "f30-adjudicative-grade-and-conclusiveness-q03", "text": "Was the recommended or tentative decision omitted because the agency found on the record that due and timely execution of its functions imperatively and unavoidably required it?", "kind": "exception", "answer_data": [ "recommended_decision_omitted_flag", "imperative_omission_finding_text", "omission_authority_clause" ] } ], "data_elements": [ { "id": "f30-adjudicative-grade-and-conclusiveness-data01", "name": "Decision grade", "description": "Initial, recommended, tentative, final, or not-applicable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-021" ] }, { "id": "f30-adjudicative-grade-and-conclusiveness-data02", "name": "Presided at evidence flag", "description": "Whether the deciding body received the evidence.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021" ] }, { "id": "f30-adjudicative-grade-and-conclusiveness-data03", "name": "Imperative omission flag", "description": "Whether a recommended or tentative decision was omitted under the APA emergency clause.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021" ] } ], "artifacts": [], "inline_only_rationale": "Grade and conclusiveness are legal-state fields of the record. The supporting finding of imperative omission, if any, is text on this record rather than a new artefact type." } ] } ] }, { "id": "relational-context", "name": "Relational context", "description": "The links that place a decision in its wider setting — the matter, occasion and prior decisions that produced it, and the parties and objects it acts upon.", "rationale": "A decision record with no outward links cannot be audited, aggregated or enforced. PROV-O supplies the generic derivation and association links, ECLI's metadata expectations imply citation links between decisions, and the registry's own CONTAINS and COMPOSE relations to the meeting and administrative-case models require explicit linkage semantics on this side.", "source_refs": [ "SRC-001", "SRC-006", "SRC-004", "SRC-010" ], "layers": [ { "id": "l-contextual-linkage", "name": "Contextual linkage", "description": "Typed relationships from the decision to its procedural context, related decisions, addressees and subject objects.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-010" ], "findings": [ { "id": "f21-contextual-relationships", "name": "Relationships to matter, occasion and other decisions", "description": "Typed links to the case or matter, the meeting or consent process that produced the decision, and prior, related, implementing and cited decisions.", "source_refs": [ "SRC-001", "SRC-004", "SRC-010", "SRC-006" ], "questions": [ { "id": "q21-container", "text": "Which case, matter, project or programme contains this decision, and is containment exclusive?", "kind": "relationship", "answer_data": [ "Container reference and type", "Exclusivity statement", "Position of the decision in the container's sequence" ] }, { "id": "q21-occasion", "text": "Was the decision produced at a meeting or by a consent process, and which agenda item or consent round does it correspond to?", "kind": "relationship", "answer_data": [ "Occasion reference or explicit absence", "Agenda item identifier", "Consent round identifier" ] }, { "id": "q21-relations", "text": "Which other decisions does this one implement, rely on, cite, contradict or depend on for its validity?", "kind": "relationship", "answer_data": [ "Typed relation entries with target identifiers", "Relation type vocabulary reference", "Direction and required flag per relation" ] }, { "id": "q21-dangling", "text": "What happens when a linked decision is revoked, annulled or destroyed under a retention rule — is this decision's validity affected?", "kind": "exception", "answer_data": [ "Dependency impact rule", "Notification mechanism", "Revalidation requirement" ] } ], "data_elements": [ { "id": "de21-container", "name": "container_reference", "description": "Reference to the case, matter or programme that contains the decision.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de21-occasion", "name": "occasion_reference", "description": "Reference to the meeting, sitting or consent round at which the decision was taken, absent where no occasion existed.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "de21-relations", "name": "decision_relations", "description": "Typed links to other decisions with relation type, target identifier and whether the relation is required for validity.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "These are typed references to objects owned by other models — the meeting by WM-ACT-025, the case by WM-POL-017, and other decisions by further instances of this model. Materialising them as an artifact would create a second, divergent copy of relationships that the referenced models already hold authoritatively." }, { "id": "f22-affected-parties-and-objects", "name": "Addressees, affected parties and subject objects", "description": "Who the decision is addressed to, who else it affects, and which concrete objects — assets, applications, permits, budgets, systems — it operates on.", "source_refs": [ "SRC-007", "SRC-004", "SRC-015", "SRC-001" ], "questions": [ { "id": "q22-addressee", "text": "Who are the formal addressees of the decision, and how are they identified authoritatively rather than by name alone?", "kind": "identity", "answer_data": [ "Addressee references with identifier scheme", "Role of each addressee", "Service address reference" ] }, { "id": "q22-affected", "text": "Which parties are affected without being addressees, and do they acquire procedural rights such as being heard or challenging?", "kind": "relationship", "answer_data": [ "Affected party references", "Nature of the effect", "Procedural rights acquired" ] }, { "id": "q22-objects", "text": "Which objects does the decision operate on, and are they identified at a specific version or state?", "kind": "relationship", "answer_data": [ "Object references with type", "Version or state at decision time", "Effect on each object" ] }, { "id": "q22-personal-data", "text": "Does the decision produce legal or similarly significant effects on a natural person, and does that trigger additional safeguards?", "kind": "privacy", "answer_data": [ "Significant effect determination and basis", "Affected natural person references", "Safeguards triggered", "Assessment reference" ] } ], "data_elements": [ { "id": "de22-addressees", "name": "addressees", "description": "Formal addressees of the decision with authoritative identifiers and service details.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "de22-affected", "name": "affected_parties", "description": "Parties affected by the decision without being addressees, with the nature of the effect.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "de22-objects", "name": "subject_objects", "description": "Objects the decision operates on, referenced at the version or state relied upon.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de22-significant-effect", "name": "significant_effect_flag", "description": "Whether the decision produces legal or similarly significant effects on a natural person.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015", "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "Addressees and subject objects are references into party, asset and application models that own their master data. This finding governs only the linkage and the effect characterisation; holding a local artifact would duplicate party master data and create an unmanaged personal-data copy." }, { "id": "f32-generating-activity-and-derivation-bundle", "name": "Generating activity, used entities and derivation", "description": "A decision record is a PROV entity generated by a deciding activity that used submissions, evidence, prior decisions, models or meeting records. Derivation and revision relate a later record to an earlier one without implying that usage alone is sufficient. Bundles support provenance of provenance.", "source_refs": [ "SRC-019", "SRC-008" ], "questions": [ { "id": "f32-generating-activity-and-derivation-bundle-q01", "text": "Which activity generated this decision record, and over what interval did that activity run?", "kind": "provenance", "answer_data": [ "generating_activity_id", "activity_type_code", "activity_start_timestamp", "activity_end_timestamp" ] }, { "id": "f32-generating-activity-and-derivation-bundle-q02", "text": "Which evidence, submissions, prior decisions, models or other entities were used in making the decision?", "kind": "provenance", "answer_data": [ "used_entity_ids", "usage_roles", "usage_timestamps" ] }, { "id": "f32-generating-activity-and-derivation-bundle-q03", "text": "From which prior records or drafts is this record derived or revised, and is a PROV bundle available for those assertions?", "kind": "provenance", "answer_data": [ "derived_from_ids", "revision_of_id", "prov_bundle_id", "provenance_statement" ] } ], "data_elements": [ { "id": "f32-generating-activity-and-derivation-bundle-data01", "name": "Generating activity", "description": "The PROV activity that produced the record.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-019" ] }, { "id": "f32-generating-activity-and-derivation-bundle-data02", "name": "Used entities", "description": "Inputs used by the deciding activity.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019" ] }, { "id": "f32-generating-activity-and-derivation-bundle-data03", "name": "Derived from", "description": "Prior entities from which this record is derived.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-008" ] } ], "artifacts": [ { "id": "f32-generating-activity-and-derivation-bundle-artifact01", "name": "Provenance bundle", "description": "Optional bundled provenance assertions about the decision record, enabling provenance of provenance.", "media_or_form": [ "prov-n", "rdf", "json" ], "serial": false, "identity_strategy": "PROV bundle identifier distinct from the decision entity identifier.", "source_refs": [ "SRC-019" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "automated-and-assisted-decisioning", "name": "Automated and assisted decisioning", "description": "How much of the decision was made by a machine, which system and configuration produced it, and what human oversight, explanation and contestability attach as a result.", "rationale": "Where a decision is taken wholly or partly by a system, additional and legally consequential context becomes mandatory: the system's identity and version, the logic applied, human oversight, and the affected person's right to intervention, to express a point of view and to contest. GDPR Article 22, the Article 29 Working Party guidance and the AI Act's oversight and logging duties all attach to this distinction, and XACML supplies the structure of a machine-rendered decision result.", "source_refs": [ "SRC-015", "SRC-014", "SRC-013", "SRC-003", "SRC-001" ], "layers": [ { "id": "l-automation-and-oversight", "name": "Automation, oversight and explanation", "description": "Decision mode and system attribution, and the oversight, explanation and contest mechanisms triggered by automation.", "source_refs": [ "SRC-015", "SRC-014", "SRC-013", "SRC-003" ], "findings": [ { "id": "f23-decision-mode-and-system-attribution", "name": "Decision mode and system attribution", "description": "Whether the decision was human, system-assisted or solely automated, and which system, model, policy version and inputs produced or shaped the result.", "source_refs": [ "SRC-015", "SRC-014", "SRC-013", "SRC-003", "SRC-001" ], "questions": [ { "id": "q23-mode", "text": "Was the decision human-made, system-assisted or based solely on automated processing, and who assessed that classification?", "kind": "classification", "answer_data": [ "Decision mode code", "Assessment basis and assessor", "Assessment timestamp", "Consequences triggered by the classification" ] }, { "id": "q23-system", "text": "Which system, model or rule engine produced or recommended the result, at which version and configuration?", "kind": "provenance", "answer_data": [ "System identifier", "Model or engine version", "Configuration or policy set identifier", "Deployment environment" ] }, { "id": "q23-policy-version", "text": "Which policy, rule set or decision logic was applied, and is that exact version retained and retrievable?", "kind": "provenance", "answer_data": [ "Applied policy identifiers", "Policy version or digest", "Retention location and retrieval method" ] }, { "id": "q23-logs", "text": "What execution logs were generated, what do they contain, and for how long are they kept?", "kind": "evidence", "answer_data": [ "Log record references", "Logged fields", "Log retention period and its basis" ] }, { "id": "q23-nominal-review", "text": "Where a human signed off a system-generated result, was that review substantive enough to displace 'solely automated' status?", "kind": "validation", "answer_data": [ "Reviewer identity, authority and competence", "Evidence of substantive consideration", "Time spent or material examined", "Resulting classification" ] } ], "data_elements": [ { "id": "de23-mode", "name": "decision_mode", "description": "Whether the decision was human, system-assisted or based solely on automated processing.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-015", "SRC-014" ] }, { "id": "de23-system", "name": "deciding_system", "description": "Reference to the system, model or engine that produced or recommended the result, with version.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-013" ] }, { "id": "de23-policy", "name": "applied_policy_identifiers", "description": "Identifiers and versions of the policies or rule sets evaluated in reaching the result.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de23-log", "name": "execution_log_reference", "description": "Reference to the execution log or trace generated when the decision was rendered.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-003" ] } ], "artifacts": [ { "id": "art-decision-log-entry", "name": "Machine decision log entry", "description": "The traceability record produced when a system renders a decision, capturing request attributes, applied policy identifiers, the decision value, status detail and any obligations returned.", "media_or_form": [ "structured log record", "authorization response payload", "AI system activity log" ], "serial": true, "identity_strategy": "Identified by the rendering system's identifier plus a monotonically increasing entry sequence and an RFC 3339 generation timestamp; correlated to the decision record by the canonical decision identifier where the result is retained as a record.", "source_refs": [ "SRC-003", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "f24-human-oversight-and-contestability", "name": "Human oversight, explanation and contestability", "description": "The oversight measures applied to an automated or assisted decision, the explanation owed to the affected person, and the mechanisms for intervention and contest.", "source_refs": [ "SRC-015", "SRC-014", "SRC-013", "SRC-007" ], "questions": [ { "id": "q24-oversight", "text": "What human oversight measures applied, who exercised them, and did the overseer have authority and competence to change the outcome?", "kind": "authority", "answer_data": [ "Oversight measure description", "Overseer reference", "Authority and competence evidence", "Whether the outcome could in fact be overridden" ] }, { "id": "q24-explanation", "text": "What explanation of the logic and of the significance and consequences is owed and provided to the affected person?", "kind": "requirement", "answer_data": [ "Explanation text or reference", "Explanation delivery timestamp", "Basis of the obligation", "Comprehensibility check" ] }, { "id": "q24-intervene", "text": "How can the affected person obtain human intervention, express a point of view and contest the decision, and what are the time limits?", "kind": "process", "answer_data": [ "Intervention request channel", "Point-of-view submission mechanism", "Contest route and deadline", "Handling service level" ] }, { "id": "q24-overrides", "text": "Were any overrides of the system result recorded, by whom and on what stated ground?", "kind": "event", "answer_data": [ "Override events with actor and ground", "Override timestamps", "Original and final outcome values" ] } ], "data_elements": [ { "id": "de24-oversight", "name": "oversight_measures", "description": "Human oversight measures applied, with overseer reference and evidence of authority and competence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-014" ] }, { "id": "de24-explanation", "name": "explanation_provided", "description": "Explanation of the logic involved and of the significance and envisaged consequences, with delivery time.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015", "SRC-014" ] }, { "id": "de24-contest", "name": "contest_mechanism", "description": "Channel, deadline and service level for requesting human intervention or contesting the decision.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015" ] }, { "id": "de24-overrides", "name": "override_events", "description": "Recorded overrides of a system-produced result with actor, ground and timestamp.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-001" ] } ], "artifacts": [ { "id": "art-explanation-statement", "name": "Explanation statement to the affected person", "description": "The statement issued to an affected person describing the logic involved, the significance and envisaged consequences of the decision, and how to obtain human intervention or contest it.", "media_or_form": [ "notice letter", "portal disclosure", "structured explanation payload", "accessible-format statement" ], "serial": false, "identity_strategy": "Identified by the decision's canonical identifier plus the recipient reference and the issuance timestamp; re-issued explanations increment a version discriminator rather than overwriting the prior statement.", "source_refs": [ "SRC-015", "SRC-014", "SRC-013" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "disclosure-retention-and-interoperability", "name": "Disclosure, retention and interoperability", "description": "How the decision is published or served, who may access which parts under what redactions, how long it is kept and how it is disposed of, and how it is expressed for exchange with external systems.", "rationale": "A decision that is not communicated may not take effect, and one that is over-disclosed breaches confidentiality and personal-data duties. Charter Article 41(2)(b) grants file access subject to confidentiality; NARA's ERM requirements and MoReq2010 supply disposal, transfer and hold mechanics; ECLI, Akoma Ntoso, DCMI and PROV supply the exchange vocabularies.", "source_refs": [ "SRC-007", "SRC-011", "SRC-017", "SRC-006", "SRC-009", "SRC-008", "SRC-001" ], "layers": [ { "id": "l-disclosure-and-access", "name": "Disclosure, notification and access", "description": "Proactive publication and individual service, access classification, redaction and anonymisation.", "source_refs": [ "SRC-007", "SRC-006", "SRC-008", "SRC-002" ], "findings": [ { "id": "f25-publication-and-notification", "name": "Publication, notification and service", "description": "How the decision is made known — published to a register or the public, and served on or notified to addressees — and the proof that communication occurred.", "source_refs": [ "SRC-007", "SRC-006", "SRC-008", "SRC-004" ], "questions": [ { "id": "q25-duty", "text": "Is there a duty to publish, a duty to notify addressees individually, or both, and what instrument imposes each?", "kind": "requirement", "answer_data": [ "Publication duty flag and basis", "Notification duty flag and basis", "Deadline for each" ] }, { "id": "q25-channel", "text": "Through which channel and register was the decision published or served, and in which language versions?", "kind": "process", "answer_data": [ "Channel or register identifier", "Publication reference or citation", "Language versions issued", "Publication timestamp" ] }, { "id": "q25-proof", "text": "What proof exists that each addressee received the decision, and what is the deemed-service rule where receipt is unproven?", "kind": "evidence", "answer_data": [ "Per-addressee proof references", "Delivery method", "Deemed service rule and computed date" ] }, { "id": "q25-failure", "text": "What happens if publication or notification fails or is late — does the decision still take effect, and does the challenge clock still run?", "kind": "exception", "answer_data": [ "Failure handling rule", "Effect on entry into force", "Effect on challenge deadlines", "Remedial reissue procedure" ] } ], "data_elements": [ { "id": "de25-publication", "name": "publication_reference", "description": "Register, gazette or portal reference under which the decision was published, with publication timestamp.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-008" ] }, { "id": "de25-notifications", "name": "notification_events", "description": "Per-addressee notification or service events with method, timestamp and proof reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "de25-deemed", "name": "deemed_service_date", "description": "Date on which service is deemed to have occurred where actual receipt is unproven.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "art-proof-of-service", "name": "Proof of service or delivery receipt", "description": "Evidence that the decision was delivered to an addressee — a signed receipt, registered-post confirmation, portal acknowledgement or electronic delivery evidence — used to start challenge periods.", "media_or_form": [ "signed receipt", "registered post confirmation", "portal acknowledgement", "electronic delivery evidence" ], "serial": true, "identity_strategy": "Identified by the delivery provider's own tracking or evidence identifier where one exists; otherwise by the decision identifier plus addressee reference plus delivery timestamp.", "source_refs": [ "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "f26-access-confidentiality-and-redaction", "name": "Access classification, confidentiality and redaction", "description": "Who may see which parts of the record, what must be withheld or anonymised, and how a party's right to access their own file is reconciled with confidentiality.", "source_refs": [ "SRC-007", "SRC-002", "SRC-008", "SRC-011" ], "questions": [ { "id": "q26-classification", "text": "What access classification applies to the record as a whole, and do any parts carry a stricter classification?", "kind": "access", "answer_data": [ "Record-level classification", "Part-level classification overrides", "Classifying authority and date", "Declassification trigger" ] }, { "id": "q26-party-access", "text": "How does an affected party exercise the right to access their own file, and what may legitimately be withheld from them?", "kind": "access", "answer_data": [ "Access request channel", "Withholding grounds with source provision", "Response deadline", "Partial-access mechanism" ] }, { "id": "q26-redaction", "text": "Which content must be redacted or anonymised before disclosure, on what basis, and who performs and approves the redaction?", "kind": "privacy", "answer_data": [ "Redaction rules with basis", "Redacted element list", "Redactor and approver identities", "Redaction timestamp" ] }, { "id": "q26-deliberative", "text": "Are deliberative materials — draft reasoning, internal advice, vote-level detail — withheld while the operative decision is disclosed, and under what rule?", "kind": "exception", "answer_data": [ "Withheld category list", "Governing exemption", "Duration of the withholding", "Review date" ] } ], "data_elements": [ { "id": "de26-classification", "name": "access_classification", "description": "Access or security classification applying to the record and to individual parts.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-008" ] }, { "id": "de26-redactions", "name": "redaction_actions", "description": "Redaction or anonymisation actions with basis, scope, actor and timestamp.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-011" ] }, { "id": "de26-withheld", "name": "withheld_elements", "description": "Elements withheld from disclosure with the exemption relied upon and any review date.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de26-access-log", "name": "access_events", "description": "Recorded accesses to the decision record with accessor, purpose, granted scope and RFC 3339 timestamp.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-017" ] } ], "artifacts": [ { "id": "art-redacted-public-version", "name": "Redacted or anonymised public version", "description": "A distinct disclosable expression of the decision with personal, commercially sensitive or exempt content removed or pseudonymised, published in place of the full internal text.", "media_or_form": [ "anonymised judgment text", "redacted PDF/A document", "public register entry" ], "serial": false, "identity_strategy": "Shares the decision's work identifier with an expression discriminator marking it as the redacted public expression; the full expression retains its own discriminator and is never overwritten.", "source_refs": [ "SRC-006", "SRC-009", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "l-retention-and-interoperability", "name": "Retention, disposition and external alignment", "description": "How long the decision record is kept and how it is disposed of or transferred, and how it is projected into external identifier schemes and vocabularies.", "source_refs": [ "SRC-011", "SRC-017", "SRC-002", "SRC-006", "SRC-009", "SRC-001", "SRC-003", "SRC-008" ], "findings": [ { "id": "f27-retention-disposition-and-hold", "name": "Retention trigger, disposition and disposal hold", "description": "The event that starts the retention clock for a decision, the authorised disposition outcome, and the holds that suspend disposal.", "source_refs": [ "SRC-011", "SRC-017", "SRC-002" ], "questions": [ { "id": "q27-trigger", "text": "Which event starts the retention period — creation, issuance, expiry of validity, exhaustion of challenge routes or closure of the containing case?", "kind": "retention", "answer_data": [ "Trigger event definition", "Trigger timestamp", "Retention duration", "Computed earliest disposal date" ] }, { "id": "q27-authority", "text": "Which disposition authority or schedule governs this record, and what disposition outcome does it prescribe?", "kind": "authority", "answer_data": [ "Disposition authority reference", "Schedule item identifier", "Prescribed outcome (destroy, transfer, retain permanently, review)", "Approving authority" ] }, { "id": "q27-hold", "text": "Is any disposal hold in force, who applied it, on what basis, and when is it reviewed?", "kind": "exception", "answer_data": [ "Hold entries with applier, basis and scope", "Hold start timestamp", "Review date", "Release conditions" ] }, { "id": "q27-execute", "text": "When disposal or transfer is executed, what evidence of it is retained after the record itself is gone?", "kind": "evidence", "answer_data": [ "Disposal or transfer certificate reference", "Retained metadata stub content", "Execution timestamp and executing actor" ] }, { "id": "q27-permanent", "text": "Does the decision have enduring evidential, precedential or historical value that requires permanent retention or archival transfer?", "kind": "quality", "answer_data": [ "Appraisal outcome and rationale", "Appraiser and appraisal date", "Transfer destination and format requirements" ] } ], "data_elements": [ { "id": "de27-trigger", "name": "retention_trigger", "description": "Event that starts the retention period, with its definition and the resolved trigger timestamp.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-002" ] }, { "id": "de27-schedule", "name": "disposition_authority_reference", "description": "Reference to the disposition authority or retention schedule item governing this record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-002" ] }, { "id": "de27-earliest", "name": "earliest_disposal_date", "description": "Computed earliest date on which disposal may lawfully occur.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-017" ] }, { "id": "de27-holds", "name": "disposal_holds", "description": "Active and released holds preventing disposal, with basis, applier, scope and review date.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017", "SRC-011" ] } ], "artifacts": [ { "id": "art-disposition-certificate", "name": "Disposition or transfer certificate", "description": "The record of executed disposal or archival transfer, retained after the decision record itself is destroyed or handed over, showing what was disposed of, under what authority and when.", "media_or_form": [ "destruction certificate", "transfer manifest", "archival accession record", "structured disposition event" ], "serial": true, "identity_strategy": "Identified by the disposal batch or accession number issued by the records-management authority or receiving archive, plus the disposed record's identifier retained as a metadata stub.", "source_refs": [ "SRC-011", "SRC-017", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "f28-external-alignment-and-identifiers", "name": "External alignment, identifiers and exchange projection", "description": "How the decision record maps to external identifier schemes and vocabularies for exchange, and which mappings are lossy, conflicting or unsupported.", "source_refs": [ "SRC-006", "SRC-009", "SRC-001", "SRC-003", "SRC-008" ], "questions": [ { "id": "q28-schemes", "text": "Which external identifier schemes apply to this decision, and is each one authoritative, an alias or merely advisory?", "kind": "interoperability", "answer_data": [ "Scheme list with values", "Authority status per scheme", "Issuing coordinator per scheme" ] }, { "id": "q28-vocab", "text": "Which external vocabularies is the record projected into for exchange, and which internal elements have no target?", "kind": "interoperability", "answer_data": [ "Target vocabulary identifiers and versions", "Element-level mapping table", "Unmapped element list" ] }, { "id": "q28-lossy", "text": "Which mappings are lossy or semantically inexact, and how is that recorded so a consumer is not misled?", "kind": "quality", "answer_data": [ "Lossy mapping entries with description of loss", "Conflict notes", "Warning conveyed to consumers" ] }, { "id": "q28-conformance", "text": "Is conformance to any external standard claimed, and what evidence supports the claim?", "kind": "validation", "answer_data": [ "Claimed conformance targets", "Evidence references", "Assessor identity", "Assessment date" ] }, { "id": "q28-roundtrip", "text": "Can an exported projection be re-imported without loss of identity, versioning or attestation, and what is lost if not?", "kind": "interoperability", "answer_data": [ "Round-trip test outcome", "Elements lost on round trip", "Mitigation or export profile constraint" ] } ], "data_elements": [ { "id": "de28-external-ids", "name": "external_identifiers", "description": "Identifiers of this decision in external governed schemes, each with scheme, value, issuer and authority status.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-008" ] }, { "id": "de28-mappings", "name": "vocabulary_mappings", "description": "Element-level mappings to external vocabularies with target term, version and lossiness note.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] }, { "id": "de28-conformance", "name": "conformance_claims", "description": "Conformance claims against named standards with supporting evidence, assessor and assessment date.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-002" ] } ], "artifacts": [ { "id": "art-exchange-projection", "name": "Exchange projection of the decision record", "description": "A serialised projection of the decision record into an external vocabulary for exchange, carrying its source record identifier, the target vocabulary version and a declaration of unmapped elements.", "media_or_form": [ "RDF graph", "XML legal-document instance", "structured interchange payload", "register export" ], "serial": false, "identity_strategy": "Carries the decision's canonical identifier as the subject of the projection plus the target vocabulary version and the projection timestamp; the projection is never treated as a second authoritative record.", "source_refs": [ "SRC-001", "SRC-009", "SRC-006", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-register-decision", "name": "Register decision record", "description": "Create a decision record and bind it to a canonical identifier following the identity priority, capturing both the event time and the ingestion time.", "inputs": [ "Decision family and binding character", "Question decided and outcome", "Deciding authority reference and authority basis", "Decision event time with explicit offset", "Available authoritative or governed identifiers" ], "outputs": [ "Persisted decision record in its initial state", "Canonical identifier assignment", "Alias identifier set", "Initial event-history entry" ], "preconditions": [ "The deciding authority reference resolves in the party model", "The authority basis instrument is resolvable at a stated version", "No existing record already carries the same authoritative identifier" ], "effects": [ "Record enters the governed state model", "Retention trigger candidates are computed but not yet resolved", "Identifier is reserved in the register and cannot be reassigned" ], "source_refs": [ "SRC-002", "SRC-006", "SRC-005", "SRC-011" ] }, { "id": "fn-record-approval-act", "name": "Record approval or consent act", "description": "Attach an individual approval, consent, vote, abstention or recusal to a decision record, preserving actor, capacity and time.", "inputs": [ "Decision record reference", "Participant reference and capacity", "Act type and value", "Act timestamp", "Presence mode where relevant" ], "outputs": [ "Persisted participation act", "Updated participant list", "Appended event-history entry" ], "preconditions": [ "The decision record is in a state that still accepts participation acts", "The participant is eligible under the applicable composition rule", "The participant has not already cast a conflicting act for the same question" ], "effects": [ "Vote tally and consent set are updated", "Quorum evaluation becomes re-computable", "Recusal adjusts the eligible denominator for quorum and majority" ], "source_refs": [ "SRC-010", "SRC-004", "SRC-001" ] }, { "id": "fn-evaluate-quorum-and-majority", "name": "Evaluate quorum and required majority", "description": "Determine whether the applicable quorum was satisfied and whether the recorded acts meet the required majority, including the no-meeting consent path.", "inputs": [ "Decision record reference", "Applicable quorum and majority rule with source provision", "Participation acts", "Eligible membership at the decision time" ], "outputs": [ "Quorum satisfaction verdict", "Majority satisfaction verdict", "Derived outcome or an explicit failure reason" ], "preconditions": [ "A quorum and majority rule is resolvable for the deciding body", "Eligible membership at the decision time is known", "Recusals and conflicts have been applied to the denominator" ], "effects": [ "A failed evaluation blocks transition to a decided state", "The verdict and the rule version used are recorded for audit", "Where consent replaces a sitting, effectiveness is derived from the last consent delivery or a stated later date" ], "source_refs": [ "SRC-010", "SRC-004" ] }, { "id": "fn-verify-authority", "name": "Verify competence and delegation limits", "description": "Check that the decider held competence at the decision time and that the decision falls within any delegated thresholds and outside reserved matters.", "inputs": [ "Decision record reference", "Authority basis and delegation chain", "Decision magnitude and category", "Decision time" ], "outputs": [ "Competence verdict with reasons", "List of breached thresholds or reserved matters", "Escalation target where competence is absent" ], "preconditions": [ "The delegation instruments are resolvable at their in-force versions", "The decision magnitude is expressed in a unit the thresholds use" ], "effects": [ "A negative verdict marks the record as requiring ratification or escalation", "The verdict, the instrument versions checked and the check time are recorded" ], "source_refs": [ "SRC-010", "SRC-001", "SRC-004" ] }, { "id": "fn-attest-and-fix", "name": "Attest, seal and fix the record", "description": "Apply signature or seal, compute a content digest over a declared canonical form, obtain a third-party attested time and mark the record unalterable.", "inputs": [ "Decision record reference", "Signatory references and capacities", "Canonicalisation profile identifier", "Digest algorithm identifier" ], "outputs": [ "Signature or seal evidence references", "Content digest with coverage statement", "Time-stamp token reference", "Fixity timestamp" ], "preconditions": [ "The record content is complete including reasons and annexes within the declared coverage", "Signatories hold the capacity asserted", "A canonical form is defined for the stored representation" ], "effects": [ "Record becomes unalterable; later changes require a new expression or a superseding decision", "Verification of integrity and attribution becomes possible without the originating system", "An event-history entry records the fixity transition" ], "source_refs": [ "SRC-012", "SRC-002", "SRC-017", "SRC-005" ] }, { "id": "fn-verify-integrity", "name": "Verify integrity and attestation", "description": "Recompute the digest over the declared canonical form and validate signature, seal and time-stamp evidence, returning a dated verdict.", "inputs": [ "Decision record reference", "Stored digest and coverage statement", "Signature, seal and time-stamp references", "Verification time" ], "outputs": [ "Integrity verdict", "Attestation validity verdict", "List of failed checks with reasons", "Next re-verification due date" ], "preconditions": [ "The canonical form used at fixity is reproducible", "Trust anchors needed to validate the attestation are available at verification time" ], "effects": [ "Verdict and verification time are appended to the record's verification history", "A failure raises a records-integrity exception to the records-management authority" ], "source_refs": [ "SRC-012", "SRC-002", "SRC-011" ] }, { "id": "fn-issue-and-notify", "name": "Issue, publish and serve", "description": "Formally issue the decision, publish it where a duty exists and serve it on addressees, capturing proof of service and starting any challenge period.", "inputs": [ "Decision record reference", "Publication and notification duties with their bases", "Addressee references and service addresses", "Language versions to issue" ], "outputs": [ "Issuance timestamp", "Publication reference", "Per-addressee service events with proof references", "Computed challenge deadlines" ], "preconditions": [ "The record is fixed and attested", "Any required redacted expression exists where publication is public", "Service addresses resolve for every addressee" ], "effects": [ "Challenge periods begin running from service or publication as the rule prescribes", "Entry into force may be triggered where it depends on notification", "Failed or late service is recorded as an exception with its remedial path" ], "source_refs": [ "SRC-007", "SRC-004", "SRC-006", "SRC-005" ] }, { "id": "fn-evaluate-validity-as-of", "name": "Evaluate validity at an instant", "description": "Answer whether the decision was valid, suspended, expired, revoked or annulled at a specified instant, returning the evidence used.", "inputs": [ "Decision record reference", "Instant to evaluate as an RFC 3339 timestamp", "Validity window, suspension intervals, supersession and annulment events" ], "outputs": [ "Validity verdict at the instant", "Governing event that determined the verdict", "Evidence references used" ], "preconditions": [ "All lifecycle events carry timestamps with explicit offsets", "Annulment temporal character is recorded where an annulment exists" ], "effects": [ "Verdict is returned without mutating the record", "The evaluation is logged where the answer is relied on for an enforcement action" ], "source_refs": [ "SRC-008", "SRC-005", "SRC-004" ] }, { "id": "fn-supersede-or-amend", "name": "Supersede, amend or correct", "description": "Link a later act to this decision as a corrigendum, amendment, replacement or revocation and create the resulting expression without altering fixed content.", "inputs": [ "Original decision record reference", "Change type", "Changing act reference", "Affected parts and change effective time" ], "outputs": [ "Bidirectional supersession links", "New consolidated or corrected expression", "Updated status of the original", "Event-history entries on both records" ], "preconditions": [ "The changing authority is competent to change this decision", "The original record's fixed content is preserved unmodified", "The change type is classified and justified" ], "effects": [ "Original moves to superseded, amended or revoked status as applicable", "Consumers resolving the original are directed to the current expression", "Invalidation time is recorded where effect ceases" ], "source_refs": [ "SRC-008", "SRC-001", "SRC-009", "SRC-004" ] }, { "id": "fn-record-challenge-outcome", "name": "Record challenge outcome", "description": "Register a lodged challenge and its disposal against the original decision, applying the outcome's effect on validity and finality.", "inputs": [ "Decision record reference", "Challenger reference and forum", "Lodging timestamp", "Outcome code and reviewing decision reference" ], "outputs": [ "Challenge entry with state", "Updated finality and validity of the original", "Link to the reviewing decision" ], "preconditions": [ "The challenge was lodged within the applicable deadline or an extension is recorded", "The forum is competent for this decision type" ], "effects": [ "Suspensive effect is applied where the rule provides it", "A quashing outcome invalidates the original with the recorded temporal character", "Finality date is set when routes are exhausted or expire" ], "source_refs": [ "SRC-004", "SRC-007", "SRC-006" ] }, { "id": "fn-produce-disclosable-expression", "name": "Produce disclosable expression", "description": "Generate a redacted or anonymised expression of the decision for publication or third-party access, recording the basis for every withholding.", "inputs": [ "Decision record reference", "Applicable redaction and exemption rules", "Target audience and disclosure purpose" ], "outputs": [ "Redacted expression with its own expression identifier", "Redaction action log with per-item basis", "Approval of the redaction" ], "preconditions": [ "Redaction rules are resolvable for the record's classification", "An approver distinct from the redactor is available where the policy requires separation" ], "effects": [ "Full expression remains unmodified and separately governed", "Published expression is linked to the full expression for internal traceability", "Withheld elements carry a review date" ], "source_refs": [ "SRC-007", "SRC-006", "SRC-009", "SRC-011" ] }, { "id": "fn-apply-disposition-or-hold", "name": "Apply disposition or disposal hold", "description": "Resolve the retention trigger, compute the earliest disposal date, apply or release holds, and execute the authorised disposition outcome.", "inputs": [ "Decision record reference", "Disposition authority reference", "Resolved retention trigger timestamp", "Hold instructions with basis and scope" ], "outputs": [ "Earliest disposal date", "Hold state", "Disposition or transfer certificate on execution", "Retained metadata stub" ], "preconditions": [ "A disposition authority covers this record family", "No unreleased hold is in force at execution time", "Appraisal for enduring value has been performed where the schedule requires it" ], "effects": [ "A hold suspends disposal and is itself auditable and reviewable", "Executed disposal removes the record but preserves evidence that disposal occurred under authority", "Archival transfer moves custody and records the accession" ], "source_refs": [ "SRC-011", "SRC-017", "SRC-002" ] }, { "id": "fn-export-projection", "name": "Export exchange projection", "description": "Serialise the decision record into a named external vocabulary at a stated version, declaring unmapped elements and lossy mappings.", "inputs": [ "Decision record reference", "Target vocabulary identifier and version", "Export profile constraints" ], "outputs": [ "Serialised projection", "Unmapped element declaration", "Lossy mapping notes", "Projection timestamp" ], "preconditions": [ "A mapping exists for the target vocabulary version", "The record is in a state that permits external disclosure at the requested scope" ], "effects": [ "Projection is marked non-authoritative relative to the source record", "Export is logged with requester, scope and time", "No conformance claim is emitted without recorded assessment evidence" ], "source_refs": [ "SRC-001", "SRC-009", "SRC-006", "SRC-003", "SRC-008" ] }, { "id": "fn-classify-decision-mode", "name": "Classify decision mode and oversight adequacy", "description": "Determine whether a decision was human, assisted or solely automated, and whether recorded human review was substantive enough to change that classification.", "inputs": [ "Decision record reference", "System attribution and execution log references", "Reviewer identity, authority and competence evidence", "Evidence of material considered during review" ], "outputs": [ "Decision mode classification", "Oversight adequacy verdict", "Triggered safeguard obligations" ], "preconditions": [ "Execution logs for the rendering system are retained and retrievable", "Reviewer authority to override the outcome is evidenced" ], "effects": [ "A solely-automated classification triggers explanation and contest obligations", "A nominal-review finding is recorded rather than silently upgrading the classification", "Classification and its basis are auditable" ], "source_refs": [ "SRC-015", "SRC-014", "SRC-013", "SRC-003" ] }, { "id": "fn-stay-or-invalidate-effect", "name": "Stay or invalidate effect", "description": "Stay, vacate or invalidate the effect of a decision without treating that act as deletion of the evidence record.", "inputs": [ "decision record", "stay or invalidation instrument", "reason code" ], "outputs": [ "updated in-force state", "invalidation or stay metadata" ], "preconditions": [ "The actor has authority to stay or invalidate." ], "effects": [ "Effect is suspended or ended.", "The record remains retrievable as evidence unless a separate disposition action applies." ], "source_refs": [ "SRC-019", "SRC-021" ] } ], "composition": [ { "target": "WM-REC-001", "relation": "EXTEND", "purpose": "WM-REC-010 is a specialisation of the generic record. The parent owns record characteristics, custody, format, preservation and baseline metadata; this model adds only decision-specific authority, outcome, reasons, validity and supersession semantics and must not restate parent mechanics.", "required": true, "source_refs": [ "SRC-002", "SRC-011" ] }, { "target": "WM-ACT-025", "relation": "REFERENCE", "purpose": "A meeting may produce decision records. The link is optional in both directions because Delaware §141(f) unanimous written consent and delegated sign-offs produce decisions with no meeting at all. Attendance, agenda and full minutes stay in the meeting model; only the occasion reference, agenda item and quorum/vote result attach here.", "required": false, "source_refs": [ "SRC-010", "SRC-004" ] }, { "target": "WM-POL-017", "relation": "COMPOSE", "purpose": "An administrative case ends or changes state through decisions. The case model owns the procedure and its state; this model owns each decision within it. One case may compose many decisions of different procedural stages, and one decision may close or alter several cases.", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "target": "Party / agent master-data model (sibling candidate, model ID not yet registered)", "relation": "REFERENCE", "purpose": "Deciders, approvers, dissenters, addressees and affected parties must resolve to governed party identifiers rather than being named inline, so that authority, delegation and conflicts can be verified against master data.", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] }, { "target": "Policy, rule and mandate model (sibling candidate, model ID not yet registered)", "relation": "REFERENCE", "purpose": "The authority basis, the rules applied and the machine policy sets evaluated are cited at a specific in-force version. Their normative content belongs to the policy model; this model records only which version was relied upon and to what effect.", "required": true, "source_refs": [ "SRC-003", "SRC-007", "SRC-010" ] }, { "target": "Electronic signature, seal and time-stamp evidence model (sibling candidate, model ID not yet registered)", "relation": "MIX-IN", "purpose": "Attestation evidence is mixed in rather than owned: this model holds references, coverage statements and verification verdicts, while the cryptographic object model, trust anchors and long-term validation material live in the evidence model.", "required": false, "source_refs": [ "SRC-012", "SRC-002" ] }, { "target": "Retention schedule and disposition authority model (sibling candidate, model ID not yet registered)", "relation": "REFERENCE", "purpose": "Retention periods, disposition outcomes and appraisal criteria are jurisdiction-specific and change independently of decisions. This model references a schedule item and records the resolved trigger, never embedding a period.", "required": true, "source_refs": [ "SRC-011", "SRC-017", "SRC-002" ] }, { "target": "W3C PROV-O (http://www.w3.org/ns/prov#)", "relation": "ALIGN", "purpose": "Alignment only. The decision act maps to prov:Activity, deciders and systems to prov:Agent, the record to prov:Entity, roles to a qualified prov:Association with prov:hadRole, delegation to prov:actedOnBehalfOf, supersession to prov:wasDerivedFrom and cessation of effect to prov:wasInvalidatedBy. PROV has no native concept of competence, quorum or validity window, so the alignment is partial.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "OASIS XACML 3.0 Result vocabulary", "relation": "ALIGN", "purpose": "Alignment only, for retained machine authorization decisions: Decision, Status, Obligations, AssociatedAdvice and PolicyIdentifierList map onto outcome, status detail, obligations, advisory items and applied policy identifiers. Permit/Deny must not be equated with a reasoned grant or refusal, and NotApplicable has no administrative equivalent.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "ECLI (European Case Law Identifier) and OASIS Akoma Ntoso v1.0", "relation": "ALIGN", "purpose": "Alignment for judicial and legislative decisions: ECLI supplies a governed global identifier for the decision as a work; Akoma Ntoso supplies the Work/Expression/Manifestation/Item identity levels and the judgment structure. Neither is imposed on administrative or corporate decisions.", "required": false, "source_refs": [ "SRC-006", "SRC-009" ] }, { "target": "DCMI Metadata Terms (http://purl.org/dc/terms/)", "relation": "ALIGN", "purpose": "Alignment for the temporal and supersession vocabulary: valid, issued, created, modified, dateAccepted, replaces, isReplacedBy, provenance, accessRights and conformsTo. Adopted because these terms keep validity, issuance and modification separate, which a single decision date collapses.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "ISO/IEC/IEEE 42010:2022 architecture decision and rationale", "relation": "ALIGN", "purpose": "Alignment for design-governance decisions, where a decision pertains to concerns, affects description elements and carries rationale covering alternatives not chosen. Used to justify the options-considered and reasons findings as a general pattern, not to import architecture description structure.", "required": false, "source_refs": [ "SRC-016" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension must name a single accountable record owner for each decision series and a records-management authority empowered to approve disposition; ownership of a decision record must not default to the system that stores it.", "The Dimension must publish, per decision family, the authority basis, the quorum and majority rules, the delegation thresholds and the disposition authority in force, each with an effective period, so that a decision can be validated against the rules that applied at its own decision time rather than today's rules.", "The Dimension must declare which identifier scheme is authoritative for each decision family, which governed global schemes it participates in, and the fallback minting rule, before any record is created.", "The Dimension must state which decision families are subject to a duty to give reasons, a duty to publish and a duty to serve, with the instrument imposing each, and must not assume these duties are universal.", "The Dimension must define the canonical form used for digest computation and the re-verification interval for attestation evidence." ], "namespace_guidance": "Use a stable, resolvable namespace under the Dimension's own authority for locally minted decision identifiers, distinct from the namespaces of any governed global scheme it also uses. Never mint values inside an external scheme's namespace. Keep the decision work identifier, the expression discriminator and the record object identifier in separate namespace segments so that corrections and translations never collide with the abstract decision. Do not encode dates, statuses or organisational names into identifier strings; where an inherited scheme already does so, treat those components as opaque and never parse them as data.", "registry_links": [ "Decision family vocabulary with per-family handling rules, maintained as a versioned registry entry", "Outcome and non-outcome vocabulary, including deferral, withdrawal, no quorum and unable-to-determine values", "Status enumeration and permitted transition table with per-transition authorised roles", "Authority basis register linking each decision family to its conferring instruments at versioned effective periods", "Delegation register with thresholds, reserved matters and effective periods", "Disposition authority register linking decision families to retention triggers and outcomes", "External scheme and vocabulary mapping registry with version, lossiness notes and conflict records" ] }, "canon_and_patch": { "canonicalization_rules": [ "Serialise all time values as RFC 3339 timestamps with seconds and an explicit numeric offset or Z; use -00:00 only to mean UTC with an unknown local offset, never as a synonym for Z.", "Normalise identifiers to their canonical scheme form, preserve case where the governing scheme is case-sensitive, and record aliases in a separate ordered list rather than rewriting the canonical value.", "Fix the element order and encoding of the canonical form before computing any digest, and record the canonicalisation profile identifier alongside the digest so a later verifier can reproduce it.", "Declare digest coverage explicitly: state whether reasons, annexes, evidence manifests and attachments are inside or outside the hashed content.", "Normalise references to external instruments as identifier plus version or point-in-time discriminator; a bare reference without a version is invalid for authority basis and applied policy elements." ], "patch_rules": [ "Content that has passed the fixity point is never patched in place. A correction creates a new expression under the same work identifier; a substantive change creates a superseding decision with its own identifier.", "Patches to management metadata — classification, holds, links, verification verdicts — are permitted after fixity and must each append an event-history entry with actor, action and RFC 3339 timestamp.", "A patch that changes outcome, reasons, authority basis or decision time is rejected and routed to the supersession function instead.", "Every patch records both the time the change occurred and the time it was ingested, and never overwrites an earlier recorded observation.", "Reversal of a patch is itself a patch with its own entry; the event history is append-only and entry numbers are never reused." ], "compatibility_rules": [ "Adding an optional element or a new vocabulary value is compatible. Removing an element, narrowing cardinality, or changing the meaning of an existing value is breaking and requires a new model version.", "Retiring a vocabulary value marks it deprecated with a replacement mapping and a retirement date; existing records retain the retired value and are not silently rewritten.", "External standard alignments may be revised without changing this model, but a revision that loses a previously supported mapping must be recorded as a conflict rather than presented as an upgrade.", "Conformance to an external standard is asserted only where recorded assessment evidence with an assessor and date exists; alignment tables alone never constitute conformance.", "Consumers must tolerate unknown optional elements and must not infer absence of an obligation from absence of an element." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record for the decision series, such as a case-management decision number or a resolution number from the governing body's own register.", "Governed global identifier or IRI issued under an external scheme the Dimension participates in, such as an ECLI for a judicial decision or a work-level IRI under a legal-document naming convention.", "UUID or ULID minted by the adopting Dimension, used only where neither of the above exists, and recorded together with the reason the higher-priority options were unavailable." ], "timestamp_rule": "All time values are recorded as RFC 3339 date-time values with seconds and an explicit numeric UTC offset or the Z designator; two-digit years are prohibited, -00:00 means UTC with unknown local offset and is not interchangeable with Z, and event time is stored separately from observation or ingestion time wherever the two can differ.", "serial_naming_rule": "Artifacts issued in a numbered series — decision instruments, voting records and consents, time-stamp tokens, event-history entries, machine decision log entries, proofs of service, disposition certificates and review decisions — take the series identifier of their issuing authority plus a monotonically increasing ordinal that is never reused, never back-filled and never re-sequenced after a gap; the ordinal is opaque and any year or code embedded in it is not a data field. Non-serial artifacts are identified by the decision's canonical identifier plus a role qualifier and, where several exist, the RFC 3339 creation timestamp.", "integrity_rule": "Every artifact that evidences the decision carries a digest computed over a declared canonical form with an explicit coverage statement, and, where it supports a legal or evidential claim, a third-party attested time of existence recorded separately from any asserted signing time. Verification produces a dated verdict with a named verifier; a failed verdict raises a records-integrity exception to the records-management authority and never silently re-fixes the record." }, "policies": [ "A decision record is not valid evidence of a decision unless the decider's competence at the decision time can be verified against the conferring instrument at the version then in force; competence is a validity condition, not descriptive metadata.", "Fixed decision content is immutable. Corrections produce new expressions and substantive changes produce superseding decisions; neither ever edits or deletes the content that was relied upon.", "Duties to give reasons, to publish and to serve are conditional and instrument-specific. The model must record, per decision family, whether each duty applies and its source, and must never assert a duty without a citation or suppress one by default.", "A decision must not be disposed of while any disposal hold is in force, and executed disposal must leave retained evidence that disposal occurred under a named authority at a recorded time.", "Where a decision produces legal or similarly significant effects on a natural person through solely automated processing, the record must carry the mode classification, the explanation provided and the contest route; a human sign-off is recorded as reviewed only where the reviewer's authority, competence and actual consideration are evidenced.", "Alignment to an external standard is recorded as a mapping with declared losses; conformance is claimed only with recorded assessment evidence.", "Treat accepted or final decision substance as immutable evidence; change effect through supersession, appeal, stay or invalidation, not overwrite.", "Separate decision event time from record capture time in every write path.", "Deny casual deletion; allow destruction or transfer only under a disposition authority and never while a legal hold is active.", "Default to least-privilege access, with audit of sensitive reads and with public-record placement only where the governing law or policy requires it.", "Do not claim ISO, DMN, PROV or DCMI conformance from mapping alone." ], "crud": { "read": [ "Reading the operative outcome, identity, authority basis, decision time and current status is available to any role with a legitimate purpose within the record's access classification.", "Reading reasons, evidence manifests, vote-level detail and dissent is scoped separately from the operative outcome and may be restricted where a deliberative or confidentiality exemption applies.", "An affected party may read their own file subject to lawful withholding, with each withholding recorded against a stated ground.", "Every read of a restricted scope is logged with accessor, purpose, granted scope and RFC 3339 timestamp." ], "create": [ "Creation requires a resolvable deciding authority, an authority basis at a stated version, the decided question, an outcome value and a decision time with an explicit offset.", "Identifier assignment follows the identity priority and is atomic with creation; a record is never persisted without a canonical identifier.", "Creation records the ingestion time separately from the decision time and opens the append-only event history.", "Bulk or migrated creation must carry the source system reference and preserve original identifiers as aliases rather than replacing them." ], "update": [ "Before fixity, substantive elements may be updated by the record owner with each change appended to the event history.", "After fixity, only management metadata — classification, holds, links, verification verdicts, disclosure state — may be updated; substantive elements are frozen.", "Supersession, amendment, revocation and challenge outcomes are recorded through their dedicated functions and never as direct field edits.", "No update may alter or remove a previously recorded observation time or event-history entry." ], "delete": [ "Deletion is permitted only as authorised disposition under a named disposition authority, never as an ordinary operation and never to correct an error.", "Disposal is blocked while any hold is in force, and hold state is evaluated at the moment of execution rather than at scheduling time.", "Executed disposal retains a metadata stub and a disposition certificate showing what was disposed of, under what authority, by whom and when.", "Erasure demanded on personal-data grounds is assessed against the record's legal retention basis and, where erasure is refused, the refusal is itself recorded as a decision under this model." ] }, "roles": [ { "name": "Record owner", "responsibilities": [ "Accountable for the completeness, accuracy and timely capture of decision records in an assigned series", "Nominates the authoritative identifier and confirms the authority basis version relied upon", "Approves creation and pre-fixity updates", "Refers competence failures for ratification or escalation" ] }, { "name": "Decision authority / approver", "responsibilities": [ "Takes the decision or casts an approval, consent, dissent or abstention within their competence", "Declares conflicts of interest and recuses where required", "Signs or seals the record in a stated capacity", "Confirms that the reasons address the material issues before issuance" ] }, { "name": "Records-management authority", "responsibilities": [ "Maintains the disposition authority and approves retention triggers and outcomes for each decision family", "Applies, reviews and releases disposal holds", "Authorises executed disposal and archival transfer and retains the resulting certificates", "Investigates records-integrity exceptions" ] }, { "name": "Access and privacy officer", "responsibilities": [ "Sets and reviews access classification at record and part level", "Approves redaction and anonymisation and records the ground for each withholding", "Handles party access requests and refusals, including refusals of erasure", "Oversees explanation and contest obligations for automated decisions" ] }, { "name": "Interoperability steward", "responsibilities": [ "Maintains mappings to external identifier schemes and vocabularies with versions and lossiness notes", "Records conflicts between external standards rather than resolving them silently", "Governs export profiles and blocks conformance claims that lack assessment evidence", "Verifies round-trip fidelity of projections" ] }, { "name": "System custodian", "responsibilities": [ "Operates the storage and interface projections without acquiring ownership of the records", "Preserves the append-only event history and prevents in-place modification after fixity", "Retains execution logs for machine-rendered decisions for the declared period", "Reproduces the canonical form on demand for verification" ] } ], "access": { "default_rule": "Deny by default. Access is granted per scope against a stated purpose, the record's access classification and the requester's role, and every grant on a restricted scope is logged. The operative outcome, reasons, evidence, vote-level detail and personal data are separately scoped: authorisation to read one never implies authorisation to read another.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "An affected party has a right of access to their own file that overrides ordinary internal restrictions, limited only by recorded grounds of confidentiality, professional or business secrecy or third-party personal data.", "Deliberative material — draft reasoning, internal advice and individual vote detail — may be withheld while the operative decision is disclosed, under a stated exemption with a duration and a review date.", "A published anonymised expression may be openly accessible while the full expression remains restricted; the two are linked internally but the linkage itself is not disclosed publicly.", "Emergency or break-glass access to a restricted decision is permitted only with a recorded justification, a named approver and mandatory post-hoc review.", "Records under a disposal hold remain readable to the holding authority and to legal counsel even where their ordinary retention period has expired.", "Public-record placement of ex parte communications and responses in APA-covered proceedings.", "Statutory withholding or redaction of legally privileged, personal or security-classified content.", "Oversight bodies that retain access even when public disclosure is withheld, including the APA rule that the ex parte subsection is not authority to withhold information from Congress.", "Emergency or sealed decisions whose existence may be known while substance remains restricted for a stated period." ], "audit_requirements": [ "Every access to a restricted scope is logged with accessor identity, purpose, granted scope and an RFC 3339 timestamp.", "Every change of access classification, every redaction and every withholding is logged with actor, ground and timestamp, and withholdings carry a review date.", "Break-glass access triggers a mandatory review by the access and privacy officer within a declared interval, and the review outcome is recorded.", "Export of any projection is logged with requester, target vocabulary version, scope and time.", "Audit entries are append-only, never reuse an entry number and are retained at least as long as the record they describe.", "Log create, status change, patch, read of restricted records, export, failed access and disposition.", "Retain access logs according to the same or a longer class than the decision record.", "Bind audit events to actor identity, event timestamp and ingestion timestamp." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Model ID and registry ID", "Owner and records-management authority", "Identifier scheme and identity priority in force", "Timestamp rule (RFC 3339 with explicit offset or Z)", "Access default rule and scope list", "Disposition authority reference", "Alignment and conflict register URL" ], "read_order": [ "Read AGENTS.md first and resolve Name, Type and Model ID before touching any stored data.", "Follow the Specification URL to obtain the model semantics, the state model, the identity priority and the vocabularies; treat the specification as authoritative over any storage schema.", "Follow the Storage type URL to learn how the semantics are projected into the concrete store, remembering that JSON, YAML, Markdown, Git, MongoDB and MCP are projections and never the semantics.", "Follow the Interface URL to learn the available operations, their preconditions and their audit obligations before attempting any read or write.", "Follow the Processes URL to learn the governed procedures for creation, approval, fixity, supersession, disclosure and disposition, and never invent a procedure that is not listed there.", "Consult the alignment and conflict register before emitting any external projection or conformance statement." ] } }, "coverage": { "claim": "The merged model gives a defensible, format-neutral context structure for authoritative decision and approval records across administrative, judicial, corporate, delegated and retained machine-authorization instances, using the Claude boundary (decision act and record co-modelled, generic record mechanics left to parent WM-REC-001) plus four evidence-backed additions from Grok grounded in 5 U.S.C. §557, DCMI Terms and PROV-DM. It is explicitly not complete: sector-specific approval regimes, non-EU/US and consensus-based decision traditions, the security and key-management dimension, access-event auditing, and the paywalled ISO normative texts are unverified, and the standing-authorisation and DMN boundaries are flagged rather than settled.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identity priority applied explicitly (master-system number, then governed global identifier such as ECLI, then Dimension-minted UUID/ULID). The decision act, the record object and the expression are separately identified using the FRBR-based levels from Akoma Ntoso. A rule forbids treating identifier-embedded years as date fields, which ECLI directly motivates since its year component is the year the judgment was rendered." }, { "dimension": "lifecycle", "status": "covered", "notes": "State enumeration, transition table with authorised triggers, the capture threshold for drafts, the fixity point, substantive finality distinguished from record immutability, and supersession, amendment, corrigendum, revocation, annulment and challenge outcomes each modelled with their temporal character." }, { "dimension": "relationships", "status": "covered", "notes": "Typed links to the containing case (WM-POL-017), the occasion (WM-ACT-025, explicitly optional), other decisions, addressees, affected parties and subject objects, plus a dependency-impact rule for when a linked decision is revoked or disposed of." }, { "dimension": "temporal", "status": "covered", "notes": "Multi-event timeline separating decided, consented, signed, issued, served, published, in force, fixed and recorded times, with RFC 3339 formatting, event time separated from ingestion time, validity window from DCMI valid, retroactivity, suspension intervals, and an as-of validity evaluation function." }, { "dimension": "provenance", "status": "covered", "notes": "PROV-O alignment for activity, agents, qualified association with role, delegation via actedOnBehalfOf, derivation for supersession and invalidation for cessation of effect; inputs relied upon captured at version or digest; attribute sources recorded for machine-evaluated inputs." }, { "dimension": "ownership", "status": "covered", "notes": "Record owner, decision authority, records-management authority, access and privacy officer, interoperability steward and system custodian are separated, with the explicit rule that ownership never defaults to the storing system and that the custodian holds no ownership." }, { "dimension": "validation", "status": "covered", "notes": "Competence and delegation-limit verification, quorum and majority evaluation, completeness of reasons against material issues, integrity and attestation verification with dated verdicts, oversight-adequacy assessment for automated decisions, and round-trip fidelity checks on projections." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default with four scopes, separate scoping of outcome versus reasons versus vote detail versus personal data, party access to their own file as an override with recorded withholding grounds, deliberative-material exemption with review dates, and break-glass with mandatory post-hoc review." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention trigger is modelled as a choice among creation, issuance, expiry of validity, exhaustion of challenge routes and case closure rather than assumed to be creation; disposition authority is referenced not embedded; holds block disposal evaluated at execution time; disposal leaves a certificate and metadata stub; refusal of an erasure request is itself recorded as a decision." }, { "dimension": "interoperability", "status": "covered", "notes": "Alignments to PROV-O, XACML, ECLI, Akoma Ntoso, DCMI and ISO/IEC/IEEE 42010 are recorded as mappings with declared losses and named conflicts; conformance requires recorded assessment evidence; export projections are marked non-authoritative." }, { "dimension": "authority and delegation", "status": "covered", "notes": "Treated as a validity condition rather than metadata: conferring instrument cited at its in-force version, delegation chain with thresholds and reserved matters, quorum floors and committee limits from Delaware §141, and the presiding/recommending/deciding role separation from 5 U.S.C. §557." }, { "dimension": "reasoning and evidence", "status": "covered", "notes": "Statement of reasons with an explicit conditional duty, issue-to-reason mapping, options considered including the status quo with per-option rejection reasons, evidence manifest fixed at decision time, and disclosure of communications that a rule requires to be placed on the record." }, { "dimension": "automation and explainability", "status": "covered", "notes": "Decision mode classification, system and policy-version attribution, execution logs with retention, oversight adequacy including the nominal-review problem, explanation of logic and consequences, and intervention and contest routes." }, { "dimension": "security", "status": "gap", "notes": "Signature, seal, digest and third-party time attestation are covered as evidential mechanisms, but key management, trust-anchor governance, cryptographic agility and long-term validation material are only referenced to a sibling evidence model. eIDAS-level assurance tiers could not be verified because EUR-Lex was not retrievable, so no signature-assurance vocabulary is asserted." }, { "dimension": "measurement", "status": "covered", "notes": "Decision magnitude for delegation thresholds, option scoring against pre-fixed criteria, vote tallies against required majorities, and service-level measures for contest handling." }, { "dimension": "spatial", "status": "covered", "notes": "Jurisdiction and territorial extent are modelled where a decision is territorially bounded, with a geometry-valued element, but spatial applicability is optional because most corporate and design-governance decisions have no territorial dimension." } ], "known_omissions": [ "The full normative texts of ISO 15489-1:2016, ISO/IEC/IEEE 42010:2022 and the ISO 23081 metadata series were not inspected; iso.org returned HTTP 403 to automated retrieval. Claims attributed to them are at catalogue, abstract and secondary-summary level and should be re-verified against purchased copies before any conformance statement.", "EUR-Lex could not be retrieved during this research. The eIDAS Regulation (EU) No 910/2014 was therefore not consulted at all, and the GDPR and the AI Act were consulted through an unofficial reproduction and an official Commission overview page rather than the Official Journal text. No electronic-signature assurance tier, seal semantics or article-level AI Act obligation is asserted on that basis.", "Sector-specific approval regimes — medicines and device authorisation, building and environmental permits, credit and underwriting decisions, research-ethics approvals, export licensing, clinical treatment decisions — are covered only by the generic structure. Each is likely to add mandatory elements this model does not name.", "Voting mechanics are modelled generically. Weighted voting, qualified majority with population thresholds, consensus and objection-based procedures, ranked and multi-round ballots, and proxy or alternate voting are not individually represented.", "Multilingual authentic-text divergence is handled only through expression identity; no rule is given for resolving substantive conflict between equally authentic language versions.", "Long-term preservation of validation data for attestation evidence — archival time-stamps, revocation information, cryptographic agility over decades — is referenced but not modelled.", "Group, class-action and collective decisions with many co-equal deciders across organisations are representable but were not stress-tested against a real instrument.", "No retention period, challenge deadline or quorum threshold is asserted as a value anywhere in the model; all are referenced to instruments that the adopting Dimension must supply.", "eIDAS/ETSI qualified electronic signatures and trust-service evidence profiles were not fetched and are not specified.", "GDPR Article 22 and other automated individual-decision rights regimes were not fetched; software-agent deciders are modelled only via PROV Agent.", "Corporate board-resolution statutes, company-law filing numbers and notarisation practices are not in the source set.", "Maker-checker or SOX/COSO dual-control is asked as a local policy question, not as a normative requirement.", "Akoma Ntoso, LegalDocML and judicial-opinion structure are excluded; court orders may still instantiate this record.", "ISO 9001 documented-information controls and ISO 30300 vocabulary were not fetched as primary texts.", "ISO 15489-1:2016 full clause text is paywalled; characteristics are taken from ISO 23081 TC46/SC11 and the official 2016 abstract, with DCC 2007 as secondary and version-lagged.", "Clinical, safety-case and financial-trade approval specialisations are not modelled." ], "conflicts": [ "XACML's four decision values do not map cleanly onto administrative or judicial outcomes. Deny is an enforcement result rather than a reasoned refusal, and NotApplicable has no administrative equivalent. Recorded as an alignment with declared loss; the model does not adopt the XACML vocabulary as canonical.", "ECLI's year component is the year the judgment was rendered, while DCMI issued is the date of formal issuance. These routinely differ. Treating the identifier as a source of dates would produce systematically wrong deadlines, so identifier components are declared opaque.", "Akoma Ntoso's judgment structure of introduction, background, motivation and decision is judicial. Administrative notices, board resolutions and machine authorization results do not share it and must not be forced into it; the model therefore adopts the FRBR identity levels but not the body structure.", "PROV-O can attribute an activity to responsible agents but has no concept of competence, quorum, majority or validity window. Provenance alignment alone cannot establish that a decision was validly taken.", "Delaware §141(f) makes action without a meeting effective when the last consent is delivered, or on a stated later date up to sixty days out. A model assuming decision time equals meeting date is wrong for this entire class, which is why decided_at is derived rather than copied from an occasion.", "GDPR Article 22 and the AI Act overlap without coinciding. Article 29 Working Party guidance indicates that nominal human sign-off does not necessarily remove solely-automated status, while AI Act human-oversight duties attach to system risk classification rather than to the individual decision. The model records mode and oversight adequacy separately rather than collapsing them.", "Records standards require records to be fixed and unalterable, yet decisions frequently need correction. The model resolves this by forbidding in-place edits and requiring a new expression or a superseding decision, but this conflicts with common practice in systems that silently overwrite approval records.", "Approval and decision are used interchangeably in practice but are not equivalent. Here an approval is either an outcome value or a participation act. Systems that treat a signature as constituting rather than evidencing the decision will disagree with this model about when the decision occurred.", "MADR documents a YYYY-MM-DD last-updated date, which is coarser than the required RFC 3339 event and ingestion timestamps and must be treated as a projection.", "Nygard/MADR practice treats accepted decisions as immutable and superseded rather than edited; some administrative systems amend orders in place. This model prefers succession and records in-place amendment as a compatibility exception.", "APA § 557 mandates findings, conclusions, reasons and rulings on exceptions for covered hearings; MADR treats drivers, confirmation and option trade-offs as optional. Neither profile is universal.", "OMG DMN models executable repeatable logic; ADR and APA model instance records. Merging them would falsify both.", "DCC briefing describes ISO 15489:2001 and DIRKS; ISO 15489-1:2016 is the current standard and de-emphasises that methodology. Process names from DCC are secondary only.", "APA public-record and Congressional-access rules are US-specific and conflict with a default need-to-know private-sector posture." ], "regional_assumptions": [ "ECLI applies to participating European jurisdictions and does not exist elsewhere; the identity priority degrades to master-system identifier then Dimension-minted identifier outside its scope.", "Charter of Fundamental Rights Article 41 binds Union institutions, bodies, offices and agencies. Member State authorities' duty to give reasons arises from national law and general principles, not directly from Article 41, so the duty must be cited per jurisdiction.", "5 U.S.C. §557 governs formal adjudication by United States federal agencies only. Its findings-and-reasons requirement is not a general rule of administrative law and is not assumed elsewhere.", "Delaware General Corporation Law §141 is the law of one United States state. Quorum floors, committee limits, remote-presence rules and the sixty-day consent window vary by jurisdiction and by corporate form and are cited as a verified counterexample source rather than as a default.", "NARA's Universal ERM Requirements apply to United States federal agencies. They are used as a lifecycle requirement pattern, not as a retention schedule for any other jurisdiction.", "MoReq2010 originates in a European context and its development was discontinued after 2018; it is treated as a stable reference rather than a current obligation.", "Qualified electronic signature and seal frameworks are assumed to be jurisdiction-specific. Because the eIDAS text was not retrievable, the model deliberately asserts no assurance-tier vocabulary and relies on RFC 3161 for the time-attestation semantics only.", "Non-Western and customary decision-making traditions, and consensus-based or non-adversarial procedures, were not researched; the model's quorum-and-majority orientation may be a poor fit for them.", "Adjudicative grades, ex parte docketing and emergency omission of recommended decisions are taken from US APA § 557 and do not automatically apply outside US formal adjudication.", "Public-records disclosure overlays (FOIA and analogues) are jurisdiction-specific; DCMI accessRights is the generic hook.", "ADR/MADR status vocabularies originate in software-engineering practice and are not legal status codes.", "ISO 15489/23081 are international but implementation instruments (retention schedules, classification schemes) are always local.", "Retroactive (nunc pro tunc) effect is treated as an exception requiring local authority, not as a default." ], "adversarial_checks": [ "Sought counterexamples to a required meeting. Delaware §141(f) unanimous written or electronic consent, and single-officer delegated sign-offs, produce valid decisions with no meeting and no vote. The occasion link was therefore made optional in both directions and decided_at was made a derived value with its own effectiveness rule rather than a copy of a meeting date.", "Sought counterexamples to a universal duty to give reasons. Many corporate resolutions, and effectively all machine authorization results, carry no statement of reasons, and Charter Article 41(2)(c) binds Union institutions rather than every decision-maker. The reasons element was therefore made conditional with a mandatory duty-basis citation, rather than required by default.", "Tested and rejected a single decision_date field. It cannot express delayed effectiveness under written consent, the gap between issuance and service that starts challenge clocks, retroactive effect, or the separation of event time from ingestion time required by RFC 3339 practice and PROV. It was replaced with an explicit multi-event timeline plus a separate validity window.", "Tested and rejected adopting XACML Permit/Deny/NotApplicable/Indeterminate as the canonical outcome vocabulary. It is attractive because it is normative and machine-clean, but it cannot express grant-with-conditions, partial grant, deferral or withdrawal, and NotApplicable has no administrative meaning. It was demoted to an alignment with a recorded conflict.", "Tested whether Approval deserves a separate sibling model. Rejected for now because the cited sources give approval acts no independent identity — they are outcome values or participation events. Flagged in the boundary notes because standing authorisations such as licences and permits do have independent holders and validity and may need their own model; this is recorded as an open boundary rather than resolved by assertion.", "Checked for duplication against the parent record model. Record characteristics, custody, format and preservation were removed from the findings and expressed only as an EXTEND link to WM-REC-001, so that the model adds decision-specific semantics rather than restating generic record mechanics.", "Probed whether a human sign-off on a machine result can be assumed to make a decision non-automated. Article 29 Working Party guidance indicates it cannot without evidence of authority, competence and actual consideration, so the model records a nominal-review finding rather than silently upgrading the classification.", "Probed the retention trigger assumption. Anchoring retention to record creation would destroy long-validity decisions such as permits while they are still in force, so the trigger was modelled as an explicit choice among creation, issuance, expiry of validity, exhaustion of challenge routes and case closure, with the resolved trigger timestamp stored.", "Checked whether any node lacks primary support. Every bundle, layer, finding, function and composition link carries at least one primary source reference except the two ISO-derived alignments and the security dimension, which are marked as evidence gaps in known_omissions and in the checklist rather than presented as canonical.", "Could this model be collapsed into WM-REC-001? No: parent recordhood is insufficient without outcome, rationale, approver and validity, which are the stated purpose of WM-REC-010.", "Could this model absorb DMN? No: DMN is reusable executable logic; this record is an authorised instance. Absorption would hide the approver and validity surface.", "Does unioning APA orders and lightweight ADRs over-claim a single type? The union is defensible at the instance-record layer (one outcome, reasons, agents, status, effect) if grades and mandatory findings remain optional-when-not-applicable rather than always required.", "Would treating minutes as the decision record lose citability? Yes; meetings may contain many motions. The decision record must be separable, which matches the WM-ACT-025 CONTAINS relation.", "Does allowing software agents as PROV Agents silently erase human accountability? The model requires explicit attribution of a responsible human or organisation when a system produced the outcome.", "Is oral-only approval a record? Not until captured; the oral-first flag records a completeness gap rather than inventing a contemporaneous instrument." ] }, "researchAdjudication": { "providerMode": "dual-provider", "activeProviders": [ "claude", "grok" ], "waivedProviders": [], "providerPolicy": {}, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "Both providers independently converge on entry_kind=entity for a single authoritative decision or approval instance, and both exclude the same neighbours (the meeting/occasion WM-ACT-025, the administrative case WM-POL-017, parent record mechanics WM-REC-001, and party/policy master data). The base draws the sharper internal line: the decision act supplies authority, outcome, reasons and timing while the record supplies identity, versioned expression, integrity evidence, disclosure and disposition, co-modelled but distinct. Approval is accepted as an outcome value or a participation act rather than an independent object, because neither source set gives approval acts independent identity. Two carve-outs are recorded rather than resolved: standing authorisations (licences, permits) with independent holders and validity may warrant a sibling model, and reusable executable decision logic (OMG DMN) is confirmed out of scope as a sibling. Neither carve-out changes the entry kind or blocks a research draft." }, "decisions": [ { "concept": "Base selection: Claude as structural base", "disposition": "accepted", "rationale": "Clearest complete boundaries, not size: eight boundary notes each with a stated distinction and source refs, an explicit act-versus-record separation, a nine-item out-of-scope list, and adversarial checks that actually tested the boundary (approval as a sibling model, duplication against the parent record model, rejection of a single decision_date). Grok's boundary work is sound but leans on tier-3 ADR practice for structural vocabulary and lacks the identity/expression and disclosure depth." }, { "concept": "Decision act and record of the act co-modelled but distinct", "disposition": "accepted from base", "rationale": "Both providers need the separation and only the base states it operationally: the act supplies authority, outcome, reasons and timing; the record supplies identity, versioned expression, integrity evidence, disclosure and disposition. This also settles the identifier question (which of the two an identifier designates) that both packs raise." }, { "concept": "Approval as an independent object with its own identity", "disposition": "deferred", "rationale": "Neither source set gives approval acts independent identity, so approval stays an outcome value or a participation act. Standing authorisations such as licences and permits do have independent holders and validity windows and may need a sibling model; this remains an open boundary flagged in the draft, not something resolved by assertion." }, { "concept": "OMG DMN boundary: reusable executable decision logic versus an instance record", "disposition": "accepted as a boundary note only, no node added", "rationale": "Grok's DMN distinction is the one boundary the base is missing, and it prevents a real failure mode where decision tables and FEEL logic get modelled as approval records, hiding the approver and validity surface. It belongs in boundary_notes with grok SRC-004 as the reference; it does not justify a finding, because base f03 q03-family already classifies the instance." }, { "concept": "ISO 23081 authenticity, integrity, reliability and usability as a finding here", "disposition": "rejected", "rationale": "The base explicitly assigns generic record characteristics, custody, format and preservation to parent WM-REC-001 and adds only decision-specific semantics. Importing Grok's authenticity-integrity finding would restate parent mechanics and create two owners for fixity. Decision-specific attestation stays with f15 (signature, seal, time-stamp, digest, verification verdict)." }, { "concept": "ADR status vocabulary (proposed, accepted, rejected, deprecated, superseded) as canonical", "disposition": "rejected as canonical; retained as an alignment", "rationale": "Grok itself notes these originate in software-engineering practice and are not legal status codes; they cannot express finality, annulment, stay or suspensive effect. The base's governed enumeration with a transition table and an explicit terminal-state question is more general and covers the ADR set as a profile." }, { "concept": "MADR decision drivers and recorded consequences", "disposition": "rejected", "rationale": "Drivers duplicate base f05 q05-concerns (stakeholder concerns, requirements and criteria the decision had to address) and f09 q09-criteria (criteria and weights fixed before assessment). Recorded consequences rest only on tier-3 practice sources and partly overlap f07 obligations and f21 relations to later decisions. Duplicate structure on weak support is worse than the gap." }, { "concept": "Ex parte start-of-ban timing and oral-then-memorialised capture gap", "disposition": "rejected as findings; flagged for question-level enrichment", "rationale": "Both are genuine primary-sourced details (§557(d) designation of when the prohibition begins; capture completeness where a decision is given orally and memorialised later) but the enclosing Grok findings duplicate base f14, f10 q10-exparte and f18 q18-draft-boundary. They should be added as questions under those findings during draft editing rather than as competing nodes." }, { "concept": "Grok approvers-and-roles (consulted/informed roles, non-human decider accountability)", "disposition": "rejected", "rationale": "Base q11-who already separates the decider from anyone who prepared, recommended or merely signed, and f23/f24 handle system attribution and residual human responsibility with stronger evidence (WP29 guidance, AI Act, XACML). The consulted/informed split is tier-3 RACI practice and adds no decision-relevant constraint." }, { "concept": "XACML four-valued outcome vocabulary as the canonical outcome set", "disposition": "rejected; retained as a declared-lossy alignment", "rationale": "Reaffirming the base's own adversarial finding: Permit/Deny/NotApplicable/Indeterminate cannot express grant-with-conditions, partial grant, deferral or withdrawal, and NotApplicable has no administrative meaning. The mapping stays recorded with its loss so a consumer is not misled." }, { "concept": "Retention trigger as an explicit choice rather than record creation", "disposition": "accepted from base", "rationale": "Anchoring retention to creation would destroy long-validity decisions such as permits while still in force. The base models the trigger as a choice among creation, issuance, expiry of validity, exhaustion of challenge routes and case closure, and stores the resolved trigger timestamp; Grok's retention finding is compatible and adds nothing beyond it." }, { "concept": "Access-event auditing and the wider security dimension", "disposition": "deferred", "rationale": "The base marks security as a gap (key management, trust anchors, cryptographic agility, long-term validation data), and Grok's only access-audit question (reads, exports, failed attempts) carries no primary requirement source in either pack. Adding a node now would assert a control neither provider evidenced; it is recorded as deferred research instead." }, { "concept": "Citation of record for 5 U.S.C. §557", "disposition": "reconciled to the base citation", "rationale": "Grok cites a NARA-hosted APA page last reviewed 2016-08-15; the base cites govinfo United States Code, 2023 edition. The imported §557-derived nodes (f30, f31) must carry the govinfo 2023 citation, with the NARA page demoted to a corroborating link, so no imported node rests on a stale reproduction." }, { "concept": "Machine authorization results as instances of this model", "disposition": "accepted from base with the retention test", "rationale": "A PDP result shares the logical shape but is ephemeral and produced at log scale. The base's rule — it becomes an instance only when captured and managed as a record — is the only workable boundary and keeps f23/f24 from swallowing runtime telemetry." } ], "publicationHolds": [ "Source and live-version verification is incomplete and remains a hold. Every accepted source URL, version pin and issuing-body status must be re-resolved live before publication, including the two Grok-derived citations imported with f29 and f32 (DCMI Terms 2020-01-20, PROV-DM W3C Recommendation 30 April 2013).", "Paywalled and unretrievable normative text: ISO 15489-1:2016, ISO/IEC/IEEE 42010:2022 and the ISO 23081 series were never read at clause level (iso.org returned HTTP 403 to both providers), so all claims attributed to them are catalogue, abstract or secondary-summary level. No conformance statement may be published until re-verified against purchased copies.", "EUR-Lex was not retrievable in either research run. GDPR Article 22 was consulted only through an unofficial reproduction (tier 3), the AI Act only through a Commission overview page, and eIDAS Regulation (EU) No 910/2014 not at all. The automation bundle (f23, f24) may be published as a research draft but no article-level obligation, signature-assurance tier or seal semantics may be asserted.", "Multi-profile domain validation is incomplete and remains a hold. The model has been exercised against US federal formal adjudication, Delaware corporate action, EU judicial identification, ADR practice and machine authorization only. It must be stress-tested against at least one sector approval regime (medicines or device authorisation, building or environmental permitting, credit underwriting, research ethics) and at least one non-EU/US legal tradition before any publication beyond a research draft.", "The two imported §557-derived nodes (f30-adjudicative-grade-and-conclusiveness, f31-completeness-of-rulings-and-implementation-confirmation) must be published as US formal-adjudication conditional, never as default grades or default completeness duties, and must carry the govinfo 2023 United States Code citation rather than the NARA reproduction." ], "deferredResearch": [ "Standing authorisations (licences, permits, accreditations) with independent holders, renewal cycles and their own validity: determine whether these require a sibling model or can remain outcome values of this one. This is the base's own flagged open boundary and the single largest structural risk in the model.", "Voting and consent mechanics beyond quorum-and-simple-majority: weighted voting, qualified majority with population thresholds, consensus and objection-based procedures, ranked and multi-round ballots, and proxy or alternate voting are representable but not individually modelled by either provider.", "Security dimension: key management, trust-anchor governance, cryptographic agility, long-term validation material for archival attestation, and access-event auditing (reads, exports, failed attempts). The base marks security as a gap and Grok's single access-audit question has no primary requirement source.", "Multilingual authentic-text divergence: no rule exists in either pack for resolving substantive conflict between equally authentic language versions; expression identity alone does not settle which text governs.", "Non-Western, customary and consensus-based decision traditions, and non-adversarial procedures, were researched by neither provider. The model's quorum-and-majority orientation may be a poor fit and should be tested before the coverage claim is widened.", "Question-level enrichment carried forward from rejected Grok nodes: the §557(d) designation of when ex parte prohibitions begin (under f10 or f14), and the oral-then-memorialised capture-completeness exception (under f18 q18-draft-boundary)." ] }, "statistics": { "sources": 24, "bundles": 7, "layers": 13, "findings": 32, "questions": 137, "artifacts": 23, "functions": 15 } }