# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T12:26:52Z", "synthesisSha256": "70f75f1e956ba9d5e87114443bacf4875bcc8c208178dd815801d4fe11abd3c7", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-REC-014", "registryId": "vr.wm-rec-014", "name": "Configuration Record", "version": "0.1.0", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.REC.CFG" ], "tags": [ "configuration", "record", "inf.rec.cfg" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-rec-014-configuration-record/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-rec-014", "model": { "registry_id": "vr.wm-rec-014", "model_id": "WM-REC-014", "name": "Configuration Record", "entry_kind": "entity", "purpose": "Preserve a versioned declaration of intended configuration with identity, applicability and accountable evidence, distinct from observed runtime state.", "scope_statement": "One governed configuration record with separately addressable declaration revisions. Own the documentary assertion, revision lineage, designation metadata and evidence links. Parameter semantics, configured targets, runtime observation, enforcement and deployment remain external masters. The hierarchy and functions are research proposals, not implemented operations.", "in_scope": [ "Stable record identity, revision identity and target applicability binding", "Declared content references, schema binding and transformation lineage", "Change and approval references, validation evidence and scoped designations", "External application and comparison evidence links, disclosure, integrity and retention" ], "out_of_scope": [ "Software parameter definitions and executable configuration engines", "Target asset, software product, service or sellable product-variant master lifecycle", "Runtime telemetry collection, drift evaluator, deployment, rollback execution and security enforcement", "Secret-store lifecycle, legal authorization and universal sector compliance", "Generic records-management or audit-event engine implementation" ], "boundary_notes": [ { "neighbor": "WM-REC-001 Document / Record", "distinction": "Registry parent is a conceptual specialization candidate. Reuse its generic record contract through a pinned adopting profile; this model specializes declaration-specific context and does not implement a second generic record engine.", "source_refs": [ "SRC-004", "SRC-005" ] }, { "neighbor": "WM-SFT-011 Software Configuration", "distinction": "That sibling owns software-specific desired settings and version scope. This record attests to a declaration revision and can reference those semantics; a record revision is not automatically a software release.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] }, { "neighbor": "WM-REC-013 Operational Log / Trace", "distinction": "Events and observations remain separately mastered evidence. Application receipts and comparison reports are links, not a runtime state master.", "source_refs": [ "SRC-001", "SRC-004" ] }, { "neighbor": "WM-OBJ-017 Product Configuration / Variant", "distinction": "A sellable product variant is not this governed declaration. A target or variant reference does not transfer product-family constraints into this record.", "source_refs": [ "SRC-005" ] }, { "neighbor": "Deployment and target operations", "distinction": "Record designation, syntactic validity and stored approval do not execute, authorize or prove successful target mutation. External operators own application and restoration.", "source_refs": [ "SRC-002", "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "RFC 8342: Network Management Datastore Architecture (NMDA)", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc8342", "version_or_date": "March 2018; update chain unresolved", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:25:05Z", "relevance": "Sections 2, 3 and 5 distinguish configuration stages and operational state. Network-specific semantics are an alignment, not a universal implementation requirement." }, { "id": "SRC-002", "title": "RFC 6241: Network Configuration Protocol (NETCONF)", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc6241", "version_or_date": "June 2011; later updates unresolved", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:25:05Z", "relevance": "Sections 2.2, 7 and 8 ground access, candidate validation and conditional commit capabilities; they do not establish deployment authority for this model." }, { "id": "SRC-003", "title": "RFC 6902: JavaScript Object Notation (JSON) Patch", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc6902", "version_or_date": "April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:25:05Z", "relevance": "Sections 3-5 ground ordered patch interpretation, test operations and error handling for a declared JSON projection." }, { "id": "SRC-004", "title": "PROV-O: The PROV Ontology", "organization": "W3C", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:25:05Z", "relevance": "Entity, activity, attribution, derivation and revision relations support evidence linkage without certifying truth or authorization." }, { "id": "SRC-005", "title": "Guide for Security-Focused Configuration Management of Information Systems, NIST SP 800-128", "organization": "NIST", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-128.pdf", "version_or_date": "August 2011, updates 10 October 2019", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:25:05Z", "relevance": "Sections 2.3, 3.2-3.4 and Appendix D support baseline identification, controlled change, monitoring and governed record retention. Federal guidance is not universal law." }, { "id": "SRC-006", "title": "JSON Schema: A Media Type for Describing JSON Documents", "organization": "JSON Schema project", "url": "https://json-schema.org/draft/2020-12/json-schema-core", "version_or_date": "Draft 2020-12, published 16 June 2022", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:25:05Z", "relevance": "Core vocabulary, dialect, schema-resource identity and reference mechanisms support pinned validation bindings, not a complete configuration instance schema." }, { "id": "SRC-007", "title": "RFC 8785: JSON Canonicalization Scheme (JCS)", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc8785", "version_or_date": "June 2020; Informational", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:25:05Z", "relevance": "Section 3 supports an optional JSON canonicalization binding with duplicate-name, numeric and Unicode limits. A digest does not certify meaning or authority." } ], "structure": { "bundles": [ { "id": "bundle-record-boundary", "name": "Record boundary", "description": "Identify the governed declaration and its external subject.", "rationale": "Proposed organization of record-owned context; cited sources motivate distinctions, not this exact hierarchy.", "source_refs": [ "SRC-004", "SRC-005", "SRC-001" ], "layers": [ { "id": "layer-identity", "name": "Record identity context", "description": "A declaration has a stable record identity and independently addressable revisions. The record is distinct from the target and from any source file path. This is a proposed local entity boundary.", "source_refs": [ "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-identity", "name": "Record identity", "description": "A declaration has a stable record identity and independently addressable revisions. The record is distinct from the target and from any source file path. This is a proposed local entity boundary.", "source_refs": [ "SRC-004", "SRC-005" ], "questions": [ { "id": "question-identity-1", "text": "Which master identifier identifies the record independently of its revision and storage location?", "kind": "identity", "answer_data": [ "data-record-identity" ] }, { "id": "question-identity-2", "text": "Which revision identifiers and derivation links distinguish this declaration from its predecessors or branches?", "kind": "provenance", "answer_data": [ "data-revision-lineage" ] }, { "id": "question-identity-3", "text": "Which accountable role maintains the record and resolves conflicting master-system claims?", "kind": "ownership", "answer_data": [ "data-mastership" ] } ], "data_elements": [ { "id": "data-record-identity", "name": "Record identity", "description": "Master system namespace and immutable record identifier; aliases are recorded separately. Candidate field group; nested executable constraints require a profile.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "data-revision-lineage", "name": "Revision lineage", "description": "Revision ID, parent revision references, branch or derivation kind, author reference and recorded time. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "data-mastership", "name": "Mastership", "description": "Record custodian role, authoritative repository reference, competing identifiers and resolution evidence. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-identity", "name": "Record identity evidence", "description": "Versioned evidence or manifest for record identity. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-target", "name": "Target and applicability context", "description": "The declaration binds to an external target within an explicit environment and applicability scope. A path or label is insufficient recognition evidence; records may describe manual or automated settings.", "source_refs": [ "SRC-001", "SRC-005" ], "findings": [ { "id": "finding-target", "name": "Target and applicability", "description": "The declaration binds to an external target within an explicit environment and applicability scope. A path or label is insufficient recognition evidence; records may describe manual or automated settings.", "source_refs": [ "SRC-001", "SRC-005" ], "questions": [ { "id": "question-target-1", "text": "Which target master reference and environment does this revision address?", "kind": "relationship", "answer_data": [ "data-target-binding" ] }, { "id": "question-target-2", "text": "Which target versions, features and location or tenant restrictions limit applicability?", "kind": "constraint", "answer_data": [ "data-applicability" ] }, { "id": "question-target-3", "text": "What makes this material a declaration rather than an observation, template or product variant?", "kind": "classification", "answer_data": [ "data-recognition" ] } ], "data_elements": [ { "id": "data-target-binding", "name": "Target binding", "description": "Target namespace and identifier, environment identity and independently mastered target type. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "data-applicability", "name": "Applicability", "description": "Version range or pinned version, required capabilities, tenant boundary and applicable site restrictions. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "data-recognition", "name": "Recognition", "description": "Record kind, declaration stage, inspection evidence and unresolved classification ambiguity. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-target", "name": "Target and applicability evidence", "description": "Versioned evidence or manifest for target and applicability. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-declared-content", "name": "Declared content", "description": "Preserve interpreted content and its resolution lineage.", "rationale": "Proposed organization of record-owned context; cited sources motivate distinctions, not this exact hierarchy.", "source_refs": [ "SRC-001", "SRC-006", "SRC-004" ], "layers": [ { "id": "layer-payload", "name": "Declared content context", "description": "A revision preserves its declared content and interpretation binding. Native format, absent values, null values, explicit removal and defaults need a declared profile; the record does not invent target parameter semantics.", "source_refs": [ "SRC-001", "SRC-006" ], "findings": [ { "id": "finding-payload", "name": "Declared content", "description": "A revision preserves its declared content and interpretation binding. Native format, absent values, null values, explicit removal and defaults need a declared profile; the record does not invent target parameter semantics.", "source_refs": [ "SRC-001", "SRC-006" ], "questions": [ { "id": "question-payload-1", "text": "Which declared fields or content artifacts belong to this revision and which remain external references?", "kind": "composition", "answer_data": [ "data-content-manifest" ] }, { "id": "question-payload-2", "text": "Which pinned schema and dialect define types, units, allowed values and required fields?", "kind": "definition", "answer_data": [ "data-schema-binding" ] }, { "id": "question-payload-3", "text": "How does the profile distinguish omission, null, removal, unknown and defaulted settings?", "kind": "exception", "answer_data": [ "data-value-semantics" ] } ], "data_elements": [ { "id": "data-content-manifest", "name": "Content manifest", "description": "Artifact identifiers and revisions, field paths, sensitivity labels and external subject references. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "data-schema-binding", "name": "Schema binding", "description": "Schema identity, revision or digest, dialect, vocabulary support and external domain semantics reference. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "data-value-semantics", "name": "Value semantics", "description": "Declared absence and default rules, provenance of defaults, unresolved values and profile-specific deletion markers. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-payload", "name": "Declared content evidence", "description": "Versioned evidence or manifest for declared content. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-derivation", "name": "Resolved declaration lineage context", "description": "Templates, overlays and dependency references can produce a resolved declaration. Preserve the inputs and interpretation evidence so an authoring artifact is not mislabeled as the final intended content.", "source_refs": [ "SRC-001", "SRC-004" ], "findings": [ { "id": "finding-derivation", "name": "Resolved declaration lineage", "description": "Templates, overlays and dependency references can produce a resolved declaration. Preserve the inputs and interpretation evidence so an authoring artifact is not mislabeled as the final intended content.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "question-derivation-1", "text": "Which ordered inputs and transformation versions produced the resolved declaration?", "kind": "process", "answer_data": [ "data-resolution-inputs" ] }, { "id": "question-derivation-2", "text": "Which unresolved references, conflicting overlays or cycles prevent a reproducible resolution?", "kind": "validation", "answer_data": [ "data-resolution-issues" ] }, { "id": "question-derivation-3", "text": "Which sensitive values are represented by protected references and what rotation policy affects reproducibility?", "kind": "security", "answer_data": [ "data-secret-bindings" ] } ], "data_elements": [ { "id": "data-resolution-inputs", "name": "Resolution inputs", "description": "Pinned templates, overlay revisions, precedence order, resolver identity and resulting artifact reference. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "data-resolution-issues", "name": "Resolution issues", "description": "Dependency identity, failure class, affected fields and resolution or refusal evidence. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "data-secret-bindings", "name": "Secret bindings", "description": "Opaque secret reference, version or rotation policy, authorized resolver role and masked availability status; never secret material. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-derivation", "name": "Resolved declaration lineage evidence", "description": "Versioned evidence or manifest for resolved declaration lineage. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-controlled-revisions", "name": "Controlled revisions", "description": "Record change proposals and scoped approval evidence.", "rationale": "Proposed organization of record-owned context; cited sources motivate distinctions, not this exact hierarchy.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "layers": [ { "id": "layer-revision", "name": "Revision change proposal context", "description": "A change is a proposed new declaration against identified base content. Patch interpretation and conflict policy are explicit; a syntactically valid patch does not authorize a change to any target.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-revision", "name": "Revision change proposal", "description": "A change is a proposed new declaration against identified base content. Patch interpretation and conflict policy are explicit; a syntactically valid patch does not authorize a change to any target.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "questions": [ { "id": "question-revision-1", "text": "Which base revision and reason does the proposed change supersede or branch from?", "kind": "lifecycle", "answer_data": [ "data-change-basis" ] }, { "id": "question-revision-2", "text": "Which ordered patch operations or full replacement content express the change?", "kind": "constraint", "answer_data": [ "data-change-expression" ] }, { "id": "question-revision-3", "text": "What happens if a precondition fails or another writer changes the base before acceptance?", "kind": "exception", "answer_data": [ "data-concurrency" ] } ], "data_elements": [ { "id": "data-change-basis", "name": "Change basis", "description": "Base revision, proposed revision, change request reference, reason and lineage disposition. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "id": "data-change-expression", "name": "Change expression", "description": "Patch format and version, ordered operations, base digest and candidate content artifact. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "id": "data-concurrency", "name": "Concurrency", "description": "Expected revision token, comparison result, conflict disposition and refusal without partial accepted mutation. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-revision", "name": "Revision change proposal evidence", "description": "Versioned evidence or manifest for revision change proposal. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-approval", "name": "Approval and designation context", "description": "The adopting policy distinguishes draft, reviewed, approved, rejected, superseded and retired record designations. A baseline is a scoped designation backed by authority; approval does not prove application.", "source_refs": [ "SRC-005", "SRC-004" ], "findings": [ { "id": "finding-approval", "name": "Approval and designation", "description": "The adopting policy distinguishes draft, reviewed, approved, rejected, superseded and retired record designations. A baseline is a scoped designation backed by authority; approval does not prove application.", "source_refs": [ "SRC-005", "SRC-004" ], "questions": [ { "id": "question-approval-1", "text": "Which decision and role authorize this exact revision for its stated use?", "kind": "authority", "answer_data": [ "data-approval-binding" ] }, { "id": "question-approval-2", "text": "When does the baseline designation apply and how are overlapping or expired designations resolved?", "kind": "temporal", "answer_data": [ "data-designation-time" ] }, { "id": "question-approval-3", "text": "Which emergency or rejected change evidence must remain visible without implying retrospective approval?", "kind": "exception", "answer_data": [ "data-exception-decision" ] } ], "data_elements": [ { "id": "data-approval-binding", "name": "Approval binding", "description": "Approval record reference, signer or role reference, revision digest, decision scope and validity interval. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "data-designation-time", "name": "Designation time", "description": "Effective start and end, recorded time, target scope, precedence rule and overlap issue. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "data-exception-decision", "name": "Exception decision", "description": "Exception authority reference, reason, review deadline, rejected decision and unresolved status. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-approval", "name": "Approval and designation evidence", "description": "Versioned evidence or manifest for approval and designation. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-005", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance-and-use", "name": "Assurance and use evidence", "description": "Separate validation conclusions from externally reported application.", "rationale": "Proposed organization of record-owned context; cited sources motivate distinctions, not this exact hierarchy.", "source_refs": [ "SRC-005", "SRC-006", "SRC-001", "SRC-002" ], "layers": [ { "id": "layer-assurance", "name": "Validation evidence context", "description": "The record indexes validation evidence for a pinned revision and profile. Syntax, schema validity, dependency resolution, policy assessment and operational safety are distinct conclusions.", "source_refs": [ "SRC-005", "SRC-006" ], "findings": [ { "id": "finding-assurance", "name": "Validation evidence", "description": "The record indexes validation evidence for a pinned revision and profile. Syntax, schema validity, dependency resolution, policy assessment and operational safety are distinct conclusions.", "source_refs": [ "SRC-005", "SRC-006" ], "questions": [ { "id": "question-assurance-1", "text": "Which checks ran against which revision, schema dialect and validator version?", "kind": "validation", "answer_data": [ "data-validation-context" ] }, { "id": "question-assurance-2", "text": "Which results are pass, fail, indeterminate or not evaluated, and what coverage was excluded?", "kind": "quality", "answer_data": [ "data-validation-results" ] }, { "id": "question-assurance-3", "text": "Which additional review or safety authority is required before any external use of the declaration?", "kind": "requirement", "answer_data": [ "data-use-gates" ] } ], "data_elements": [ { "id": "data-validation-context", "name": "Validation context", "description": "Input digest, schema pin, validator identifier and version, check scope and execution evidence reference. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "data-validation-results", "name": "Validation results", "description": "Check identifier, result, diagnostic reference, exclusions and evidence time. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "data-use-gates", "name": "Use gates", "description": "Applicable policy references, unresolved gate, accountable reviewer and permitted-use restrictions. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-assurance", "name": "Validation evidence evidence", "description": "Versioned evidence or manifest for validation evidence. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-application", "name": "Application evidence links context", "description": "Externally produced receipts can report acceptance, rejection or partial application. Preserve stage, target and revision linkage without turning a receipt into proof that all desired settings are in use.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ], "findings": [ { "id": "finding-application", "name": "Application evidence links", "description": "Externally produced receipts can report acceptance, rejection or partial application. Preserve stage, target and revision linkage without turning a receipt into proof that all desired settings are in use.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ], "questions": [ { "id": "question-application-1", "text": "Which external attempt reports use of this revision on which target and at what stage?", "kind": "event", "answer_data": [ "data-application-link" ] }, { "id": "question-application-2", "text": "What evidence distinguishes queued, accepted, applied, rejected, partial and unknown outcomes?", "kind": "state", "answer_data": [ "data-application-outcome" ] }, { "id": "question-application-3", "text": "Which capabilities and persistence assumptions qualify the reported outcome across restart or rollback?", "kind": "constraint", "answer_data": [ "data-application-limits" ] } ], "data_elements": [ { "id": "data-application-link", "name": "Application link", "description": "Attempt or deployment reference, target identity, revision digest, stage and event time. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] }, { "id": "data-application-outcome", "name": "Application outcome", "description": "Reported status, reporter, evidence reference, affected scope and observation time. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] }, { "id": "data-application-limits", "name": "Application limits", "description": "External protocol capability evidence, restart persistence, rollback conditions and unsupported guarantees. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-application", "name": "Application evidence links evidence", "description": "Versioned evidence or manifest for application evidence links. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-comparison-and-continuity", "name": "Comparison and continuity", "description": "Link observation comparisons and govern supersession or disposal.", "rationale": "Proposed organization of record-owned context; cited sources motivate distinctions, not this exact hierarchy.", "source_refs": [ "SRC-001", "SRC-005", "SRC-002", "SRC-004" ], "layers": [ { "id": "layer-comparison", "name": "Observation comparison evidence context", "description": "The record may link a comparison between declared intent and a separately mastered observation. A difference requires interpretation; missing or stale observations do not prove agreement or unauthorized drift.", "source_refs": [ "SRC-001", "SRC-005" ], "findings": [ { "id": "finding-comparison", "name": "Observation comparison evidence", "description": "The record may link a comparison between declared intent and a separately mastered observation. A difference requires interpretation; missing or stale observations do not prove agreement or unauthorized drift.", "source_refs": [ "SRC-001", "SRC-005" ], "questions": [ { "id": "question-comparison-1", "text": "Which observation and declaration revision were compared under the same target and environment scope?", "kind": "evidence", "answer_data": [ "data-comparison-inputs" ] }, { "id": "question-comparison-2", "text": "Which normalized paths differ and which exclusions, defaults or tolerances affect the comparison?", "kind": "measurement", "answer_data": [ "data-comparison-result" ] }, { "id": "question-comparison-3", "text": "How fresh and complete is the observation, and what unresolved interpretation limits the drift claim?", "kind": "temporal", "answer_data": [ "data-observation-quality" ] } ], "data_elements": [ { "id": "data-comparison-inputs", "name": "Comparison inputs", "description": "Observation master reference, declaration revision, target binding and coverage alignment. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "data-comparison-result", "name": "Comparison result", "description": "Comparator profile and version, difference paths, excluded scope, units or tolerances where meaningful and result reference. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "data-observation-quality", "name": "Observation quality", "description": "Observed time, ingested time, collection scope, inaccessible fields and stale or indeterminate disposition. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-comparison", "name": "Observation comparison evidence evidence", "description": "Versioned evidence or manifest for observation comparison evidence. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-continuity", "name": "Retirement and restoration references context", "description": "Record retirement ends a local designation without deconfiguring the target. Earlier declarations can inform a restoration proposal, but current dependencies, revoked secrets and authority must be checked again.", "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ], "findings": [ { "id": "finding-continuity", "name": "Retirement and restoration references", "description": "Record retirement ends a local designation without deconfiguring the target. Earlier declarations can inform a restoration proposal, but current dependencies, revoked secrets and authority must be checked again.", "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ], "questions": [ { "id": "question-continuity-1", "text": "Which supersession or retirement decision ends use of this revision while keeping references resolvable?", "kind": "lifecycle", "answer_data": [ "data-retirement" ] }, { "id": "question-continuity-2", "text": "Which compatibility, dependency and authorization checks qualify a proposed restoration from an earlier revision?", "kind": "requirement", "answer_data": [ "data-restoration-gates" ] }, { "id": "question-continuity-3", "text": "Which schedule, hold or disposal decision governs the payload, history and minimal tombstone?", "kind": "retention", "answer_data": [ "data-disposition" ] } ], "data_elements": [ { "id": "data-retirement", "name": "Retirement", "description": "Retired revision, successor if any, effective time, reason and authorized decision reference. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ] }, { "id": "data-restoration-gates", "name": "Restoration gates", "description": "Selected earlier revision, present target profile, external restoration plan reference and unresolved safety or permission gates. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ] }, { "id": "data-disposition", "name": "Disposition", "description": "Retention authority, hold scope, payload deletion evidence, remaining identifiers and disposition time; retention is not indefinite by default. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-continuity", "name": "Retirement and restoration references evidence", "description": "Versioned evidence or manifest for retirement and restoration references. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-protection-and-exchange", "name": "Protection and exchange", "description": "Control disclosure and preserve explicit projection integrity.", "rationale": "Proposed organization of record-owned context; cited sources motivate distinctions, not this exact hierarchy.", "source_refs": [ "SRC-005", "SRC-002", "SRC-004", "SRC-003", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-protection", "name": "Controlled disclosure context", "description": "Content and metadata may expose credentials, topology or personal information. The proposed profile uses least privilege, protected references and recipient-specific projections without treating redaction as an unchanged original.", "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ], "findings": [ { "id": "finding-protection", "name": "Controlled disclosure", "description": "Content and metadata may expose credentials, topology or personal information. The proposed profile uses least privilege, protected references and recipient-specific projections without treating redaction as an unchanged original.", "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ], "questions": [ { "id": "question-protection-1", "text": "Which roles can read declaration metadata, sensitive fields and artifacts in the current purpose and tenant scope?", "kind": "access", "answer_data": [ "data-access-binding" ] }, { "id": "question-protection-2", "text": "Which information must be masked or omitted from a recipient view and how is the view related to its source?", "kind": "privacy", "answer_data": [ "data-disclosure-view" ] }, { "id": "question-protection-3", "text": "What authorized response records accidental secret inclusion without propagating it through logs or exports?", "kind": "security", "answer_data": [ "data-exposure-response" ] } ], "data_elements": [ { "id": "data-access-binding", "name": "Access binding", "description": "Policy reference, recipient role, purpose, tenant, field or artifact scope and decision evidence. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ] }, { "id": "data-disclosure-view", "name": "Disclosure view", "description": "Redaction profile, source revision, derived view identity, omitted paths and permitted explanation. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ] }, { "id": "data-exposure-response", "name": "Exposure response", "description": "Restricted incident reference, quarantine state, revocation owner, payload disposition and sanitized evidence; no secret values. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-protection", "name": "Controlled disclosure evidence", "description": "Versioned evidence or manifest for controlled disclosure. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-005", "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-exchange", "name": "Exchange and integrity context", "description": "Each projection declares its mapping and loss. Content hashes identify bytes under a specified scheme; provenance and signatures require separate verification and never establish configuration correctness by themselves.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ], "findings": [ { "id": "finding-exchange", "name": "Exchange and integrity", "description": "Each projection declares its mapping and loss. Content hashes identify bytes under a specified scheme; provenance and signatures require separate verification and never establish configuration correctness by themselves.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ], "questions": [ { "id": "question-exchange-1", "text": "Which mapping preserves identity, revisions and value distinctions across the selected exchange formats?", "kind": "interoperability", "answer_data": [ "data-exchange-binding" ] }, { "id": "question-exchange-2", "text": "Which exact bytes or declared canonicalization profile are covered by integrity evidence?", "kind": "evidence", "answer_data": [ "data-integrity-binding" ] }, { "id": "question-exchange-3", "text": "Which round-trip differences or unsupported constructs prevent a lossless conformance claim?", "kind": "quality", "answer_data": [ "data-exchange-loss" ] } ], "data_elements": [ { "id": "data-exchange-binding", "name": "Exchange binding", "description": "Format and profile versions, mapping identity, source and target representation references and known loss. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ] }, { "id": "data-integrity-binding", "name": "Integrity binding", "description": "Artifact identifier, media type, digest algorithm, byte digest or canonical profile, signature reference and verification outcome. Candidate field group; nested executable constraints require a profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ] }, { "id": "data-exchange-loss", "name": "Exchange loss", "description": "Fixture reference, unsupported fields, numeric or Unicode limitations, semantic differences and acceptance decision. Candidate field group; nested executable constraints require a profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-exchange", "name": "Exchange and integrity evidence", "description": "Versioned evidence or manifest for exchange and integrity. May be a controlled reference to an externally mastered artifact; materialization is profile-dependent.", "media_or_form": [ "structured record", "controlled document reference" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier first, then governed IRI, then Dimension-assigned UUID or ULID. Keep revision and representation distinct; date and digest alone are not logical identity.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "function-register-declaration", "name": "Register declaration revision", "description": "Record a new immutable declaration revision locally. Proposed and unimplemented.", "inputs": [ "Master record and target identifiers", "Candidate content manifest and schema binding", "Author evidence and classification" ], "outputs": [ "Revision reference and validation issues" ], "preconditions": [ "Resolve the master and environment; refuse ambiguous target binding", "Authorized record writer and no conflicting revision identifier" ], "effects": [ "Create local draft revision or return refusal; no target changes" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-006" ] }, { "id": "function-propose-revision", "name": "Propose revision change", "description": "Construct a reviewable local candidate against a pinned base. Proposed and unimplemented.", "inputs": [ "Base revision and concurrency token", "Ordered patch or replacement", "Reason and request reference" ], "outputs": [ "Candidate revision or conflict report" ], "preconditions": [ "Authorized writer and matching base token", "Supported patch semantics and secret-handling checks" ], "effects": [ "Preserve base revision; reject failed preconditions without accepting partial content" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "id": "function-attach-validation", "name": "Attach validation evidence", "description": "Index externally produced checks without expanding their conclusion. Proposed and unimplemented.", "inputs": [ "Revision digest", "Validator and profile pins", "Result and coverage report" ], "outputs": [ "Bound validation evidence or rejection" ], "preconditions": [ "Authorized evidence recorder", "Exact input match; refuse unbound result or unsupported pass assertion" ], "effects": [ "Append local evidence association; no safety, deployment or conformance certification" ], "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "function-record-designation", "name": "Record scoped designation", "description": "Bind an existing approval or retirement decision to a revision. Proposed and unimplemented.", "inputs": [ "Decision reference", "Revision digest", "Scope and effective interval" ], "outputs": [ "Designation record or unresolved conflict" ], "preconditions": [ "Authorized custodian and verifiable decision scope", "No unresolved overlapping designation; refuse expired or mismatched authority" ], "effects": [ "Update local designation with history; no external approval issuance or target action" ], "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "function-link-use-evidence", "name": "Link use and comparison evidence", "description": "Associate an external receipt or comparison with its exact inputs. Proposed and unimplemented.", "inputs": [ "Evidence master reference", "Revision and target binding", "Stage, time and coverage" ], "outputs": [ "Qualified evidence link or mismatch report" ], "preconditions": [ "Read authorization for all linked subjects", "Refuse wrong target, wrong revision or unsupported conversion of unknown to success" ], "effects": [ "Record qualified local association; no monitoring, drift correction or runtime mutation" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "function-prepare-projection", "name": "Prepare controlled projection", "description": "Propose a recipient view with explicit mapping, redaction and integrity evidence. Proposed and unimplemented.", "inputs": [ "Revision manifest", "Recipient access decision", "Pinned mapping and integrity profile" ], "outputs": [ "Local derived view and loss report or refusal" ], "preconditions": [ "Authorized recipient and purpose; no secret dereferencing", "Supported mapping and no concealed semantic loss" ], "effects": [ "Create separate local view identity; refuse inaccessible fields; no external transmission or changed original" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007" ] } ], "composition": [ { "target": "WM-REC-001", "relation": "EXTEND", "purpose": "Candidate specialization of governed records; pin the generic identity and custody contract before implementation. No mandatory runtime dependency asserted.", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "target": "WM-SFT-011", "relation": "REFERENCE", "purpose": "Optional software-specific configuration semantics and revision scope; do not duplicate its domain model.", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "target": "WM-REC-013", "relation": "REFERENCE", "purpose": "Optional external application and observation event evidence; preserve the log master.", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "target": "WM-OBJ-017", "relation": "REFERENCE", "purpose": "Optional configured product variant target; do not absorb variant definition or feasibility rules.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "RFC 8342", "relation": "ALIGN", "purpose": "Conceptual stage distinction for network profiles; not every record uses these datastores.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "PROV-O", "relation": "ALIGN", "purpose": "Proposed derivation, revision and attribution crosswalk; no tested RDF conformance claimed.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "JSON Schema Draft 2020-12", "relation": "ALIGN", "purpose": "Optional schema-resource and dialect binding for a JSON projection; complete nested schemas remain deferred.", "required": false, "source_refs": [ "SRC-006" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name a record custodian role and authoritative master system, separate from target operation authority", "Bind the adopting namespace, tenant, profile version, target identity scheme and external record contract", "Provide retention, access, approval and secret-reference policies with accountable reviewers" ], "namespace_guidance": "Use a governed Dimension namespace for record identity, revision identity, artifact identity and extension terms. Names, paths, timestamps and content digests are not interchangeable identifiers.", "registry_links": [ "vr.wm-rec-014", "WM-REC-001 candidate specialization", "WM-SFT-011 optional semantic reference" ] }, "canon_and_patch": { "canonicalization_rules": [ "Preserve original bytes and semantic profile separately. Any normalized view receives its own representation identity and mapping evidence.", "RFC 8785 is an optional JSON binding only. Reject unsupported numeric or duplicate-key input; do not silently normalize strings or claim it canonicalizes all formats." ], "patch_rules": [ "Pin base revision and profile; preserve ordered operations and test preconditions. Commit a new local revision atomically or report refusal.", "Record ancestry for branches and merges; do not overwrite approved content or apply a patch directly to a target." ], "compatibility_rules": [ "Require migration and loss reports when schemas, dialects, target versions or secret-reference policies change.", "Old content availability does not prove operational rollback compatibility. Unknown extensions remain explicit and cannot receive a silent pass." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier", "Governed global identifier or IRI", "Dimension-assigned UUID or ULID" ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z. Separate authored, approved, effective, observed and ingested times; an unknown instant stays unknown.", "serial_naming_rule": "Name serial artifacts by stable record, artifact and revision identifiers; human-readable sequence labels are secondary and dates never replace identity.", "integrity_rule": "Record exact-byte digest algorithm and value or an explicitly pinned canonical profile. Preserve originals and view lineage; integrity verification does not prove truth, authority or safe configuration." }, "policies": [ "These are proposed adopting-profile requirements informed by the cited sources, not universal normative obligations.", "Keep declaration, validation, approval, application and observation assertions distinct; never infer authorization or runtime truth from a file.", "Use opaque protected secret references; restrict topology and personal-data metadata, including logs and diagnostics.", "For safety-sensitive or controlled domains, retain policy and authority references only; operational procedures require separately reviewed profiles." ], "crud": { "read": [ "Check recipient, purpose, tenant and field/artifact permissions; unresolved access returns denial or a qualified view." ], "create": [ "Require master identity, target applicability, profile binding and custodian authority; create a draft without changing targets." ], "update": [ "Compare expected base revision, validate content and preserve revision lineage. Scope every designation change to its decision evidence." ], "delete": [ "Retire or supersede local declarations first; apply the adopting records policy for retention, holds and authorized payload deletion.", "Keep only a permitted minimal tombstone and disposition evidence; confidentiality or lawful erasure can require payload removal. Generic records services execute disposal, and target deconfiguration remains externally owned." ] }, "roles": [ { "name": "Record custodian", "responsibilities": [ "Maintain master identity, revision lineage and retention bindings" ] }, { "name": "Declaration author", "responsibilities": [ "Propose scoped changes and explain unresolved values" ] }, { "name": "Approving authority", "responsibilities": [ "Decide permitted use for exact revisions and scopes under adopting policy" ] }, { "name": "Evidence reviewer", "responsibilities": [ "Assess source, coverage and qualification of validation and use evidence" ] }, { "name": "Access steward", "responsibilities": [ "Govern disclosure, secret references and incident restriction" ] } ], "access": { "default_rule": "Deny by default; authorize by tenant, purpose, role and sensitivity across metadata and payload.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency access needs time-bounded authority and restricted evidence; it does not approve a target change.", "Derived views may omit sensitive fields with an explicit incompleteness marker; do not fabricate absent content." ], "audit_requirements": [ "Reference externally governed access and mutation audit events with actor, purpose, target record, revision, decision and time.", "Do not log secrets; keep restricted incident references and separately authorized retention for audit metadata." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read AGENTS.md and the adopting Dimension authority, access and retention policies", "Read spec.yaml, publication holds, pinned generic record contract and target profile", "Resolve master identities and evidence before proposing any local mutation" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one governed configuration declaration record with distinct revision, target and evidence identities. A separate frozen local no-tools self-audit found no critical conflicts. Independent review, source/version verification, executable mappings and adopting-sector profiles remain open; this is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Separate master record, revision, target and representation identities." }, { "dimension": "lifecycle", "status": "covered", "notes": "Proposal, designation, supersession and retirement are local documentary states." }, { "dimension": "relationships", "status": "covered", "notes": "Optional candidate neighbor bindings preserve target masters." }, { "dimension": "temporal", "status": "covered", "notes": "Separate effective, event, observation and ingestion times." }, { "dimension": "provenance", "status": "covered", "notes": "Revision ancestry, resolution inputs and evidence attribution." }, { "dimension": "ownership", "status": "covered", "notes": "Custodian and approval roles are independent of execution authority." }, { "dimension": "validation", "status": "covered", "notes": "Pin schema, validator, input and coverage; record unknown outcomes." }, { "dimension": "access", "status": "covered", "notes": "Purpose and tenant restrictions include fields and metadata." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Policy-bound payload disposal and minimal permitted tombstones." }, { "dimension": "interoperability", "status": "gap", "notes": "Candidate mappings and integrity bindings lack executable fixtures." }, { "dimension": "direct properties", "status": "covered", "notes": "Content, stage, profile, sensitivity and applicability are nonphysical properties; physical dimensions of the record itself are inapplicable." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Classify declarations separately from templates and runtime evidence." }, { "dimension": "capabilities and hazards", "status": "covered", "notes": "Six proposed local operations with refusal conditions; target mutation is delegated." }, { "dimension": "context and evidence", "status": "covered", "notes": "Source scope and exact input bindings limit each assertion." }, { "dimension": "sector breadth", "status": "gap", "notes": "Physical device and manual configuration profiles need additional domain evidence." } ], "known_omissions": [ "Independent external review remains absent under the owner-authorized provider waiver.", "Direct HTTP status is unmeasured in this sandbox; live version, errata and update-chain review is incomplete.", "Executable nested instance schemas, pinned neighbor contracts, transformation and comparison mappings and adversarial fixtures remain incomplete.", "Sector-specific physical equipment, offline/manual procedures, jurisdiction, retention schedules and licensing need adopting-profile review." ], "conflicts": [], "regional_assumptions": [ "NIST information-system guidance is used as a scoped example, not a universal legal mandate.", "Network datastore concepts and JSON projections do not prescribe a storage format or architecture for all targets." ], "adversarial_checks": [ "Reject stored approval or successful schema validation as proof of deployment or safe use.", "Reject stale or unavailable observation as proof of no drift.", "Reject retained old content as a guarantee of safe restoration with current dependencies or rotated secrets.", "Reject filename, digest, clock time or target identity as the complete record identity.", "Reject a redacted view as unchanged original content and reject automatic secret resolution." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The root is a persistent governed record with separately addressable revisions, not the configured target, a runtime datastore or a deployment event. Revision collections do not by themselves require aggregate classification. The registry standalone-mm value classifies the record plane, while entity is the defensible subject kind." }, "decisions": [ { "concept": "Record and revision identity", "disposition": "accepted", "rationale": "Master record, revision, target and artifact identities stay distinct. A path, timestamp or digest cannot silently replace the stable logical record identity." }, { "concept": "Generic parent and software sibling", "disposition": "qualified", "rationale": "The registry parent is represented as a candidate specialization with a required future profile pin, not an implemented dependency. Software-specific parameter semantics stay with the sibling; local fields bind record evidence only." }, { "concept": "Universal machine application", "disposition": "rejected", "rationale": "The supplement's machine-application restriction is not required by the frozen registry purpose. Manual declarations can fit the proposed boundary, with sector-specific detail retained as an evidence gap." }, { "concept": "Nonphysical record properties", "disposition": "accepted", "rationale": "The record has declared content, stage, profile, applicability and sensitivity properties. Physical dimensions of the record itself are inapplicable; the supplement's broader no-properties assertion is not adopted." }, { "concept": "Resolved content and secret references", "disposition": "accepted as proposed profile", "rationale": "The derivation questions retain ordered inputs, resolver version, unresolved references and secret rotation policy. They do not claim a universal resolution algorithm or permit secret material in artifacts." }, { "concept": "Concurrent patch acceptance", "disposition": "accepted", "rationale": "Pinned base content and explicit preconditions prevent silent overwrite. Local candidate acceptance is all-or-refusal; that rule is a proposed storage requirement and not a guarantee about external targets." }, { "concept": "Approval and runtime effect", "disposition": "separated", "rationale": "Designation binds an existing decision to exact content, scope and time. It neither issues approval nor proves application, persistence across restart or safety." }, { "concept": "Validation and application evidence", "disposition": "qualified", "rationale": "All evidence is input-bound and reports scope and unknown outcomes. Schema validity is distinct from operational safety; protocol capabilities and application outcomes remain externally mastered." }, { "concept": "Observation comparison ownership", "disposition": "accepted", "rationale": "The comparison finding indexes external observations and comparator results. It does not operate a monitoring engine or correct drift; stale, missing and inaccessible values cannot become an agreement assertion." }, { "concept": "Restoration and retention", "disposition": "qualified", "rationale": "Old revisions inform proposals but do not guarantee safe restoration with current dependencies or rotated secrets. Non-overwriting revision history is subject to explicit retention, holds and lawful payload disposal, with only permitted tombstone data remaining." }, { "concept": "Local function scope", "disposition": "accepted as unimplemented", "rationale": "All six proposed functions have authority and evidence preconditions and refusal outputs. Their effects are local records or views; deployment, rollback, secret resolution and transmission are excluded." }, { "concept": "Source and conformance assurance", "disposition": "deferred", "rationale": "Selected primary-source sections support conceptual distinctions. Readable web-tool content is not measured direct HTTP or complete update-chain review; candidate field groups and mappings are not executable conformance schemas." }, { "concept": "Independent provider agreement", "disposition": "waived and held", "rationale": "No Claude or Grok result was requested or admitted. This separate frozen Codex semantic assessment is a self-audit, not an independent external review, and cannot close that hold." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped; the separate frozen local Codex no-tools self-audit is not a second-provider review.", "Live source/version verification remains incomplete. Seven sources were readable through the web research tool, but direct HTTP requests were not attempted under the stated sandbox restriction: zero measured responses. The coordinator must run check_sources.py; current update chains, errata, applicability and licensing still require substantive review.", "Executable nested instance schemas, pinned neighbor contracts, transformation and comparison mappings, protocol bindings and adversarial acceptance fixtures remain incomplete. No runtime, safe-deployment or standards-conformance certification is claimed.", "Sector-specific device and manual configuration profiles, target compatibility, authority, confidentiality, retention and disposal rules require adopting-profile review before operational use. Information-system and network examples are not universal mandates.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Run the deferred direct HTTP checker and review source update chains, errata, licensing and profile applicability without equating reachability with claim verification.", "Pin neighbor contracts and develop nested schemas and fixtures for concurrent writes, failed patch tests, unresolved dependencies, rotating secrets, partial application, stale observations and lossy projections.", "Review physical-device, manual and sector-specific authority, retention and confidentiality profiles, and restore independent external review before canonical promotion." ] }, "statistics": { "sources": 7, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }