# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T17:27:04Z", "synthesisSha256": "c3cde53d5dcde20b30b974bf953e7afde15489e11eb0287791c10066f3ac2f5f", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-SFT-002", "registryId": "vr.wm-sft-002", "name": "Deployed System", "version": "1.0.0-reviewable-draft", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.SFT.SYS" ], "tags": [ "deployed", "system", "inf.sft.sys" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-sft-002-deployed-system/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-002", "model": { "registry_id": "vr.wm-sft-002", "model_id": "WM-SFT-002", "name": "Deployed System", "entry_kind": "entity", "purpose": "Describe one operator-governed logical software system, its organizational use and evidence-qualified operational context.", "scope_statement": "The queue label Deployed System refers to the persistent logical subject named Software System / Business Application in the current registry. One system identity persists across deployments, scaling and replacement instances. Planning and retirement records are allowed without a currently running instance. The owner archetype is the accountable operator, not necessarily the producer. This is proposed research structure, not an operational control plane.", "in_scope": [ "Logical system identity, purpose, capability limits and time-qualified operator and usage bindings", "System-specific membership, realization, environment, API and endpoint references", "Local lifecycle assertions, approved-context references, recognition evidence, assurance context and record continuity" ], "out_of_scope": [ "Product, component, release, license, SBOM, vulnerability, organization and authority master lifecycles", "Deployment execution, runtime orchestration, endpoint administration, configuration application, telemetry collection and reliability computation", "Business payload storage, credential storage, legal compliance determination and security enforcement" ], "boundary_notes": [ { "neighbor": "WM-SFT-001 Software Product", "distinction": "Product offering and producer lifecycle are externally mastered. A product or release name does not identify an operator system.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "WM-SFT-009 Deployment", "distinction": "Deployment occurrences and activation evidence are referenced; rollout, rollback and decommission execution are not owned here.", "source_refs": [ "SRC-002", "SRC-004" ] }, { "neighbor": "WM-SFT-010 Runtime / Compute Environment", "distinction": "Hosting topology and instance lifecycle remain runtime-owned. A system can span multiple environments and outlive instances.", "source_refs": [ "SRC-003", "SRC-004" ] }, { "neighbor": "WM-ORG-001 Organization", "distinction": "Organizations and their authority are separate masters; only system-specific role and usage bindings are recorded here.", "source_refs": [ "SRC-001", "SRC-006" ] }, { "neighbor": "WM-SFT-018 Network / Endpoint", "distinction": "Endpoints reference the exposed system; addresses, reachability and endpoint lifecycle remain endpoint-owned.", "source_refs": [ "SRC-001", "SRC-004" ] }, { "neighbor": "WM-SFT-007 Software Component / Package", "distinction": "Component identity and package metadata remain component-owned; logical membership alone is local context.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "WM-SFT-008 Build / Release", "distinction": "Release and build identity, provenance and distribution are external. Concurrent release references are permitted.", "source_refs": [ "SRC-002", "SRC-004" ] }, { "neighbor": "WM-SFT-003 API / Interface Contract", "distinction": "API definitions and interface lifecycle are external; system provider and consumer roles are local bindings.", "source_refs": [ "SRC-001" ] }, { "neighbor": "WM-SFT-011 Software Configuration", "distinction": "Configuration content, evaluation and application are external; baseline applicability and evidence references are local.", "source_refs": [ "SRC-002", "SRC-004" ] }, { "neighbor": "WM-SFT-016 Service Level Objective / Reliability Commitment", "distinction": "Commitment definitions, calculation and evaluation stay external; applicability is recorded here.", "source_refs": [ "SRC-002", "SRC-006" ] }, { "neighbor": "WM-SFT-017 Telemetry / Operational Signal", "distinction": "Observation payloads, signal collection and evaluation stay external; this system records qualified evidence links.", "source_refs": [ "SRC-003", "SRC-005" ] }, { "neighbor": "Shared legacy N4 and unreviewed legacy supplement", "distinction": "Split the combined product-and-system boundary. Preserve system purpose, operator and realization references; do not copy product publishing, dependency analysis, environment execution, broad conformance assertions or wildcard imports. Physical size and mass are inapplicable to the logical root; measured operational properties require metric context.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Descriptor Format of Catalog Entities", "organization": "Cloud Native Computing Foundation", "url": "https://backstage.io/docs/features/software-catalog/descriptor-format/", "version_or_date": "Living documentation, accessed 2026-10-06; System kind uses backstage.io/v1alpha1", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T17:25:42Z", "relevance": "System abstraction, component and API references, catalog identity and accountable ownership. Catalog owner metadata is not runtime authorization." }, { "id": "SRC-002", "title": "Guide for Security-Focused Configuration Management of Information Systems", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-128.pdf", "version_or_date": "SP 800-128, August 2011 with updates 2019-10-10", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T17:25:42Z", "relevance": "Sections 2.2-2.4 and 3.2-3.4 support system-specific responsibility, approved baseline references and evidence of configuration differences. US federal guidance is a qualified alignment." }, { "id": "SRC-003", "title": "Service semantic conventions", "organization": "Cloud Native Computing Foundation", "url": "https://opentelemetry.io/docs/specs/semconv/resource/service/", "version_or_date": "Living semantic conventions accessed 2026-10-06; pin release before implementation", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T17:25:42Z", "relevance": "Distinguishes logical service, service namespace and service instance identifiers; mapping to a whole system needs explicit scope and evidence." }, { "id": "SRC-004", "title": "Objects In Kubernetes", "organization": "Cloud Native Computing Foundation", "url": "https://kubernetes.io/docs/concepts/overview/working-with-objects/", "version_or_date": "Living documentation accessed 2026-10-06; target API versions require profile pinning", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T17:25:42Z", "relevance": "Object spec and status illustrate desired versus observed state. A controller-managed Deployment object is not this logical system or a deployment occurrence." }, { "id": "SRC-005", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T17:25:42Z", "relevance": "Entity, activity, attribution, derivation and revision relations support an evidence-qualified system record; provenance does not prove observation truth." }, { "id": "SRC-006", "title": "OSCAL System Security Plan Model v1.1.3 JSON Format Reference", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/OSCAL-Reference/models/v1.1.3/system-security-plan/json-reference/", "version_or_date": "OSCAL v1.1.3, selected version rather than a latest-version claim", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T17:25:42Z", "relevance": "System characteristics, identifiers, description, authorization boundary, information types and component status provide selected structural alignments. The research result is not an OSCAL security plan." }, { "id": "SRC-007", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "RFC 3339, July 2002; section 5.6", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T17:25:42Z", "relevance": "Timestamp syntax includes seconds and UTC designator or numeric offset; interval semantics and uncertainty are local profile decisions." } ], "structure": { "bundles": [ { "id": "bundle-identity", "name": "System identity", "description": "Persist a logical operator-governed system across replacement instances.", "rationale": "Proposed system-specific concern supported by the cited alignments; external masters remain separate.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "layers": [ { "id": "layer-identity", "name": "Continuity and names", "description": "An operator assigns one system identity with scoped aliases. Product names, catalog UIDs and runtime instance identifiers are not interchangeable masters.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "findings": [ { "id": "system-identity", "name": "Stable system identity", "description": "An operator assigns one system identity with scoped aliases. Product names, catalog UIDs and runtime instance identifiers are not interchangeable masters.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "questions": [ { "id": "system-identity-q01", "text": "Which authoritative inventory identifier and namespace identify this logical system?", "kind": "identity", "answer_data": [ "system-identity-system-id" ] }, { "id": "system-identity-q02", "text": "Which system class and business purpose distinguish it from a product or runtime instance?", "kind": "classification", "answer_data": [ "system-identity-system-class" ] }, { "id": "system-identity-q03", "text": "Which catalog and telemetry aliases map to this system, with what scope and ambiguity?", "kind": "interoperability", "answer_data": [ "system-identity-alias-bindings" ] }, { "id": "system-identity-q04", "text": "Which identity rule applies when this system is renamed, split, merged or transferred?", "kind": "lifecycle", "answer_data": [ "system-identity-continuity-rule" ] } ], "data_elements": [ { "id": "system-identity-system-id", "name": "system-id", "description": "Master identifier with issuer and namespace; mandatory when an instance is admitted.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "system-identity-system-class", "name": "system-class", "description": "Profile code, business purpose, accountable boundary and classification rationale.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "system-identity-alias-bindings", "name": "alias-bindings", "description": "Scheme, alias, namespace, target kind, validity interval, match evidence and unresolved collision status.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "system-identity-continuity-rule", "name": "continuity-rule", "description": "Continuity decision, authority reference, predecessor or successor IDs and effective time; no automatic identity merge.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "system-identity-artifact", "name": "System identity record", "description": "Versioned evidence carrier for stable system identity. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-boundary", "name": "Purpose and boundary", "description": "The local record states the system purpose and boundary. A business grouping, authorization boundary and hosting boundary can differ and must be related explicitly.", "source_refs": [ "SRC-001", "SRC-006" ], "findings": [ { "id": "system-boundary", "name": "Operational subject boundary", "description": "The local record states the system purpose and boundary. A business grouping, authorization boundary and hosting boundary can differ and must be related explicitly.", "source_refs": [ "SRC-001", "SRC-006" ], "questions": [ { "id": "system-boundary-q01", "text": "What capability does this system provide to its intended users?", "kind": "definition", "answer_data": [ "system-boundary-capability-context" ] }, { "id": "system-boundary-q02", "text": "Which externally mastered components belong to the system boundary at the stated time?", "kind": "composition", "answer_data": [ "system-boundary-membership-bindings" ] }, { "id": "system-boundary-q03", "text": "Where does the logical boundary differ from the security authorization boundary?", "kind": "constraint", "answer_data": [ "system-boundary-boundary-differences" ] }, { "id": "system-boundary-q04", "text": "How are shared services and outsourced parts represented without assigning their masters to this system?", "kind": "exception", "answer_data": [ "system-boundary-shared-part-rules" ] } ], "data_elements": [ { "id": "system-boundary-capability-context", "name": "capability-context", "description": "Purpose, intended outcomes, user classes and declared capability limits.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "system-boundary-membership-bindings", "name": "membership-bindings", "description": "Component reference, membership role, declared or observed basis and effective interval.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "system-boundary-boundary-differences", "name": "boundary-differences", "description": "Boundary reference, profile, included or excluded scope and responsible reviewer.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "system-boundary-shared-part-rules", "name": "shared-part-rules", "description": "External system or component reference, use role, responsibility boundary and unknown evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] } ], "artifacts": [ { "id": "system-boundary-artifact", "name": "System boundary statement", "description": "Versioned evidence carrier for operational subject boundary. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-governance", "name": "Accountability and usage", "description": "Separate accountability, authorization and organizational use.", "rationale": "Proposed system-specific concern supported by the cited alignments; external masters remain separate.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-responsibility", "name": "Accountability assignments", "description": "The accountable operator, custodian and decision authority are role references with scope and time. A catalog owner label alone grants no permission.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ], "findings": [ { "id": "system-accountability", "name": "Time-qualified accountability", "description": "The accountable operator, custodian and decision authority are role references with scope and time. A catalog owner label alone grants no permission.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ], "questions": [ { "id": "system-accountability-q01", "text": "Which role is accountable for the system during each effective interval?", "kind": "ownership", "answer_data": [ "system-accountability-accountability-assignments" ] }, { "id": "system-accountability-q02", "text": "Which authority reference permits approval of a system boundary or lifecycle assertion?", "kind": "authority", "answer_data": [ "system-accountability-authority-bindings" ] }, { "id": "system-accountability-q03", "text": "How are producer, operator, service custodian and using organization distinguished?", "kind": "relationship", "answer_data": [ "system-accountability-role-separation" ] }, { "id": "system-accountability-q04", "text": "What escalation applies when ownership is absent, overlapping or disputed?", "kind": "exception", "answer_data": [ "system-accountability-accountability-exceptions" ] } ], "data_elements": [ { "id": "system-accountability-accountability-assignments", "name": "accountability-assignments", "description": "Organization and role references, effective start and end, assignment authority and disputed or vacant state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] }, { "id": "system-accountability-authority-bindings", "name": "authority-bindings", "description": "Decision class, authority master reference, delegation limits and expiry; credentials excluded.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] }, { "id": "system-accountability-role-separation", "name": "role-separation", "description": "Typed organization references and responsibilities; one party can fill several explicitly separate roles.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] }, { "id": "system-accountability-accountability-exceptions", "name": "accountability-exceptions", "description": "Dispute reference, temporary contact, review due time and restriction on unapproved assertions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "system-accountability-artifact", "name": "Accountability assignment record", "description": "Versioned evidence carrier for time-qualified accountability. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-usage", "name": "Organizational usage", "description": "Usage assertions connect a logical system to organization, purpose and information categories. They neither authorize processing nor require a separate system per tenant.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ], "findings": [ { "id": "system-usage", "name": "Effective-dated use context", "description": "Usage assertions connect a logical system to organization, purpose and information categories. They neither authorize processing nor require a separate system per tenant.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ], "questions": [ { "id": "system-usage-q01", "text": "Which organizations or tenant scopes use this system for which purpose?", "kind": "relationship", "answer_data": [ "system-usage-usage-bindings" ] }, { "id": "system-usage-q02", "text": "When was a usage assertion effective and when was it recorded?", "kind": "temporal", "answer_data": [ "system-usage-usage-times" ] }, { "id": "system-usage-q03", "text": "Which information-category and data-governance references constrain this use?", "kind": "privacy", "answer_data": [ "system-usage-information-context" ] }, { "id": "system-usage-q04", "text": "What evidence distinguishes shared tenancy, a separate operator system and an unknown usage claim?", "kind": "exception", "answer_data": [ "system-usage-usage-evidence" ] } ], "data_elements": [ { "id": "system-usage-usage-bindings", "name": "usage-bindings", "description": "Organization reference, tenant scope token, use role and business purpose; no personal user list.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "system-usage-usage-times", "name": "usage-times", "description": "Effective interval, observation time, ingestion time, timezone offset and uncertainty.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "system-usage-information-context", "name": "information-context", "description": "Information category, dataset reference, handling policy reference and applicability; no business payload.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "system-usage-usage-evidence", "name": "usage-evidence", "description": "Assertion source, identity decision, scope exclusions and unresolved status.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "system-usage-artifact", "name": "Usage context register", "description": "Versioned evidence carrier for effective-dated use context. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-bindings", "name": "Composition and operation references", "description": "Bind external masters without importing their lifecycle or execution.", "rationale": "Proposed system-specific concern supported by the cited alignments; external masters remain separate.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006" ], "layers": [ { "id": "layer-realization", "name": "Product and release realization", "description": "A system can realize several products and releases, including custom software. Bindings separate intended, approved and observed realization and allow simultaneous versions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ], "findings": [ { "id": "system-realization", "name": "Realization references", "description": "A system can realize several products and releases, including custom software. Bindings separate intended, approved and observed realization and allow simultaneous versions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ], "questions": [ { "id": "system-realization-q01", "text": "Which product, component and release masters realize this system capability?", "kind": "composition", "answer_data": [ "system-realization-realization-bindings" ] }, { "id": "system-realization-q02", "text": "Which realization bindings are intended, approved, observed or no longer applicable?", "kind": "state", "answer_data": [ "system-realization-realization-state" ] }, { "id": "system-realization-q03", "text": "What deployment occurrence or inventory observation supports each running-version assertion?", "kind": "evidence", "answer_data": [ "system-realization-activation-evidence" ] }, { "id": "system-realization-q04", "text": "How are partial rollout, rollback and conflicting version observations retained?", "kind": "exception", "answer_data": [ "system-realization-realization-exceptions" ] } ], "data_elements": [ { "id": "system-realization-realization-bindings", "name": "realization-bindings", "description": "External master reference and version or digest, functional role, environment scope and custom or unknown state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "system-realization-realization-state", "name": "realization-state", "description": "Binding ID, assertion state, observation scope, evidence reference and effective interval.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "system-realization-activation-evidence", "name": "activation-evidence", "description": "Deployment or observation reference, source revision, recorded time and confidence; success does not imply current liveness.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "system-realization-realization-exceptions", "name": "realization-exceptions", "description": "Concurrent binding set, affected scope, disagreement evidence and review state; no automatic preferred value.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "system-realization-artifact", "name": "Realization binding register", "description": "Versioned evidence carrier for realization references. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-environment", "name": "Runtime and interface context", "description": "Runtime, endpoint and API references locate an operational realization. The local system neither controls orchestration nor owns network addresses or interface schemas.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006" ], "findings": [ { "id": "system-runtime-context", "name": "Runtime and exposure references", "description": "Runtime, endpoint and API references locate an operational realization. The local system neither controls orchestration nor owns network addresses or interface schemas.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006" ], "questions": [ { "id": "system-runtime-context-q01", "text": "Which runtime environment references and location claims apply to this system scope?", "kind": "spatial", "answer_data": [ "system-runtime-context-runtime-bindings" ] }, { "id": "system-runtime-context-q02", "text": "Which API and endpoint masters expose or connect this system?", "kind": "relationship", "answer_data": [ "system-runtime-context-interface-bindings" ] }, { "id": "system-runtime-context-q03", "text": "How are ephemeral runtime instances correlated without replacing the system master identifier?", "kind": "identity", "answer_data": [ "system-runtime-context-instance-correlation" ] }, { "id": "system-runtime-context-q04", "text": "Which placement or connectivity restrictions apply and where is compliance evaluated?", "kind": "constraint", "answer_data": [ "system-runtime-context-placement-constraints" ] } ], "data_elements": [ { "id": "system-runtime-context-runtime-bindings", "name": "runtime-bindings", "description": "Environment master reference, hosting role, region assertion source, interval and unknown location state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006" ] }, { "id": "system-runtime-context-interface-bindings", "name": "interface-bindings", "description": "API or endpoint reference, provider or consumer role, dependency direction and qualified scope.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006" ] }, { "id": "system-runtime-context-instance-correlation", "name": "instance-correlation", "description": "Instance master reference, telemetry alias tuple, observation window and mapping certainty.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006" ] }, { "id": "system-runtime-context-placement-constraints", "name": "placement-constraints", "description": "Policy reference, scope, external evaluation reference and unverified status; no enforcement operation.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "system-runtime-context-artifact", "name": "Runtime and interface map", "description": "Versioned evidence carrier for runtime and exposure references. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-lifecycle", "name": "Lifecycle and approved context", "description": "Keep local lifecycle assertions distinct from operational actions and baseline execution.", "rationale": "Proposed system-specific concern supported by the cited alignments; external masters remain separate.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "layer-state", "name": "System lifecycle assertions", "description": "The logical system can be planned, active, suspended or retired under an adopting profile. These are proposed local terms; shutdown, migration and reactivation are separate authorized processes.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-006" ], "findings": [ { "id": "system-lifecycle", "name": "Lifecycle evidence", "description": "The logical system can be planned, active, suspended or retired under an adopting profile. These are proposed local terms; shutdown, migration and reactivation are separate authorized processes.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-006" ], "questions": [ { "id": "system-lifecycle-q01", "text": "Which local lifecycle state is asserted and which profile defines it?", "kind": "state", "answer_data": [ "system-lifecycle-lifecycle-state" ] }, { "id": "system-lifecycle-q02", "text": "What approved decision and external operation evidence justify the stated transition?", "kind": "process", "answer_data": [ "system-lifecycle-transition-basis" ] }, { "id": "system-lifecycle-q03", "text": "How does retirement of the logical system relate to remaining runtime and consumer bindings?", "kind": "temporal", "answer_data": [ "system-lifecycle-retirement-context" ] }, { "id": "system-lifecycle-q04", "text": "When can a suspended or retired identity be resumed rather than replaced?", "kind": "exception", "answer_data": [ "system-lifecycle-resumption-rule" ] } ], "data_elements": [ { "id": "system-lifecycle-lifecycle-state", "name": "lifecycle-state", "description": "State code, profile version, effective time, assertion author and evidence reference.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-006" ] }, { "id": "system-lifecycle-transition-basis", "name": "transition-basis", "description": "Prior and proposed state, decision reference, operation reference and acceptance evidence; absence stays unknown.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-006" ] }, { "id": "system-lifecycle-retirement-context", "name": "retirement-context", "description": "Retirement effective time, residual runtime references, consumer migration status and unresolved obligations.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-006" ] }, { "id": "system-lifecycle-resumption-rule", "name": "resumption-rule", "description": "Profile identity rule, decision authority, continuity rationale and successor reference if replacement is required.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "system-lifecycle-artifact", "name": "Lifecycle assertion journal", "description": "Versioned evidence carrier for lifecycle evidence. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-baseline", "name": "Approved context and deviations", "description": "Approved system context is referenced by immutable revision. Detailed configurations and change requests remain externally mastered; differences are evidence claims rather than execution instructions.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ], "findings": [ { "id": "system-baseline", "name": "Baseline and deviation references", "description": "Approved system context is referenced by immutable revision. Detailed configurations and change requests remain externally mastered; differences are evidence claims rather than execution instructions.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ], "questions": [ { "id": "system-baseline-q01", "text": "Which approved configuration baseline revision applies to this system scope?", "kind": "requirement", "answer_data": [ "system-baseline-baseline-bindings" ] }, { "id": "system-baseline-q02", "text": "Which external comparison identifies a difference between the baseline and an observation?", "kind": "quality", "answer_data": [ "system-baseline-deviation-evidence" ] }, { "id": "system-baseline-q03", "text": "What exception decision qualifies acceptance of an identified deviation?", "kind": "authority", "answer_data": [ "system-baseline-deviation-disposition" ] }, { "id": "system-baseline-q04", "text": "What change-control reference supersedes a baseline without rewriting past observations?", "kind": "validation", "answer_data": [ "system-baseline-baseline-succession" ] } ], "data_elements": [ { "id": "system-baseline-baseline-bindings", "name": "baseline-bindings", "description": "Configuration master reference, approved revision or digest, applicability scope and approval reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "system-baseline-deviation-evidence", "name": "deviation-evidence", "description": "Evaluation reference, compared revisions, observed scope, result and unresolved or stale state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "system-baseline-deviation-disposition", "name": "deviation-disposition", "description": "Deviation reference, decision authority, expiry, condition and revocation reference; no implied risk acceptance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "system-baseline-baseline-succession", "name": "baseline-succession", "description": "Prior and successor baseline references, approved change reference, effective interval and compatibility note.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "system-baseline-artifact", "name": "Baseline applicability record", "description": "Versioned evidence carrier for baseline and deviation references. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance", "name": "Recognition and assurance context", "description": "Represent evidence and limits of operational assertions.", "rationale": "Proposed system-specific concern supported by the cited alignments; external masters remain separate.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-observation", "name": "Recognition and observation", "description": "Recognition uses explicit identity correlations and observation scope. An absent signal is not proof of absence; a health sample does not certify the entire system.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007" ], "findings": [ { "id": "system-observation", "name": "Evidence-qualified recognition", "description": "Recognition uses explicit identity correlations and observation scope. An absent signal is not proof of absence; a health sample does not certify the entire system.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007" ], "questions": [ { "id": "system-observation-q01", "text": "Which observer and source record produced this system-state assertion?", "kind": "provenance", "answer_data": [ "system-observation-observation-provenance" ] }, { "id": "system-observation-q02", "text": "Which metric definition, unit, window and population qualify the reported measurement?", "kind": "measurement", "answer_data": [ "system-observation-measurement-context" ] }, { "id": "system-observation-q03", "text": "When does an observation become stale or contradictory under the selected profile?", "kind": "quality", "answer_data": [ "system-observation-freshness-context" ] }, { "id": "system-observation-q04", "text": "What matching evidence prevents an unrelated instance from being attributed to this system?", "kind": "validation", "answer_data": [ "system-observation-recognition-check" ] } ], "data_elements": [ { "id": "system-observation-observation-provenance", "name": "observation-provenance", "description": "Observer reference, source artifact, derivation or method, source revision and collection authorization reference.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007" ] }, { "id": "system-observation-measurement-context", "name": "measurement-context", "description": "Telemetry and metric references, value if disclosed, unit, method, window, population, uncertainty and sample limits.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007" ] }, { "id": "system-observation-freshness-context", "name": "freshness-context", "description": "Observed and ingested times, freshness rule, clock uncertainty, contrary evidence references and review state.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007" ] }, { "id": "system-observation-recognition-check", "name": "recognition-check", "description": "Identity mapping evidence, namespace and tenant scope, ambiguity result and refusal to infer when unresolved.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "system-observation-artifact", "name": "System observation index", "description": "Versioned evidence carrier for evidence-qualified recognition. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-commitments", "name": "Impact and assurance references", "description": "Business criticality, reliability commitments and assurance decisions are separately scoped assertions. A designation or successful check does not establish overall safety, security or compliance.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "system-assurance", "name": "Criticality and assurance context", "description": "Business criticality, reliability commitments and assurance decisions are separately scoped assertions. A designation or successful check does not establish overall safety, security or compliance.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "questions": [ { "id": "system-assurance-q01", "text": "Which business impact or criticality assessment applies to this system?", "kind": "classification", "answer_data": [ "system-assurance-criticality-context" ] }, { "id": "system-assurance-q02", "text": "Which reliability commitment and recovery policy references apply to the stated use?", "kind": "requirement", "answer_data": [ "system-assurance-commitment-bindings" ] }, { "id": "system-assurance-q03", "text": "Which security assessment or unresolved advisory references affect this system context?", "kind": "security", "answer_data": [ "system-assurance-security-context" ] }, { "id": "system-assurance-q04", "text": "Who accepted a qualified assurance conclusion and what limits or expiry apply?", "kind": "decision", "answer_data": [ "system-assurance-assurance-decisions" ] } ], "data_elements": [ { "id": "system-assurance-criticality-context", "name": "criticality-context", "description": "Assessment reference, scale and version, business scope, assessor and review date; no universal criticality scale.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "system-assurance-commitment-bindings", "name": "commitment-bindings", "description": "Commitment or policy master reference, applicability period, consumer scope and explicit exclusions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "system-assurance-security-context", "name": "security-context", "description": "Assessment, risk or advisory reference, affected binding, review state and disclosure classification; no exploit detail.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "system-assurance-assurance-decisions", "name": "assurance-decisions", "description": "Decision reference, authority, conclusion scope, evidence set, conditions and expiry; authorization remains external.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "system-assurance-artifact", "name": "Assurance context index", "description": "Versioned evidence carrier for criticality and assurance context. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-continuity", "name": "Record continuity and interoperability", "description": "Preserve traceability and controlled exchange for this model records.", "rationale": "Proposed system-specific concern supported by the cited alignments; external masters remain separate.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-evidence", "name": "Record provenance and retention", "description": "Local assertions retain revisions and source links according to retention policy. Minimal lawful tombstones can preserve identity after payload disposal; retirement is not erasure.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ], "findings": [ { "id": "system-record-continuity", "name": "Evidence and disposition context", "description": "Local assertions retain revisions and source links according to retention policy. Minimal lawful tombstones can preserve identity after payload disposal; retirement is not erasure.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ], "questions": [ { "id": "system-record-continuity-q01", "text": "Which source and revision history support this system-record revision?", "kind": "provenance", "answer_data": [ "system-record-continuity-record-lineage" ] }, { "id": "system-record-continuity-q02", "text": "Which recipient view can disclose inventory, topology or assurance evidence?", "kind": "access", "answer_data": [ "system-record-continuity-disclosure-context" ] }, { "id": "system-record-continuity-q03", "text": "Which retention schedule and scoped holds govern this record and its artifacts?", "kind": "retention", "answer_data": [ "system-record-continuity-retention-context" ] }, { "id": "system-record-continuity-q04", "text": "What minimal continuity evidence remains after authorized record disposal?", "kind": "lifecycle", "answer_data": [ "system-record-continuity-disposal-context" ] } ], "data_elements": [ { "id": "system-record-continuity-record-lineage", "name": "record-lineage", "description": "Prior revision, author role, source reference, derivation and integrity digest; digest is not truth certification.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] }, { "id": "system-record-continuity-disclosure-context", "name": "disclosure-context", "description": "Classification, recipient role, purpose, policy decision reference and redaction or denial reason.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] }, { "id": "system-record-continuity-retention-context", "name": "retention-context", "description": "Policy reference, covered fields or artifacts, trigger, review date, hold reference and external disposition authority.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] }, { "id": "system-record-continuity-disposal-context", "name": "disposal-context", "description": "Disposition receipt reference, retained identifier, lawful tombstone scope and expiry; no deletion of referenced masters.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "system-record-continuity-artifact", "name": "Record continuity register", "description": "Versioned evidence carrier for evidence and disposition context. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-mapping", "name": "Profiles and interchange", "description": "Catalog, telemetry and security-plan projections use explicit versioned mappings. Similar labels are not identity equivalence, runtime permissions or conformance evidence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ], "findings": [ { "id": "system-interoperability", "name": "Versioned model bindings", "description": "Catalog, telemetry and security-plan projections use explicit versioned mappings. Similar labels are not identity equivalence, runtime permissions or conformance evidence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "system-interoperability-q01", "text": "Which profile maps this system record into a catalog or security-plan representation?", "kind": "interoperability", "answer_data": [ "system-interoperability-mapping-profile" ] }, { "id": "system-interoperability-q02", "text": "Which meanings or values are lost or narrowed in the selected projection?", "kind": "constraint", "answer_data": [ "system-interoperability-projection-losses" ] }, { "id": "system-interoperability-q03", "text": "Which conformance result and fixture set support this mapping version?", "kind": "validation", "answer_data": [ "system-interoperability-conformance-evidence" ] }, { "id": "system-interoperability-q04", "text": "How are unmapped legacy N4 fields and unresolved neighbor references handled?", "kind": "exception", "answer_data": [ "system-interoperability-migration-disposition" ] } ], "data_elements": [ { "id": "system-interoperability-mapping-profile", "name": "mapping-profile", "description": "Profile ID and version, target schema version, field mappings and extension policy.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ] }, { "id": "system-interoperability-projection-losses", "name": "projection-losses", "description": "Source field, target field, loss or aggregation rule, unknown handling and consumer warning.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ] }, { "id": "system-interoperability-conformance-evidence", "name": "conformance-evidence", "description": "External test result reference, fixture set revision, tested profile, failures and untested scope.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ] }, { "id": "system-interoperability-migration-disposition", "name": "migration-disposition", "description": "Legacy field, proposed target master, admitted or deferred decision, provenance and review state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "system-interoperability-artifact", "name": "Interoperability profile record", "description": "Versioned evidence carrier for versioned model bindings. Supports references and explicit unknowns; no automatic operational authority.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID; otherwise governed IRI; otherwise Dimension-assigned UUID or ULID. Revision is separate from stable identity; timestamp is not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-system", "name": "Register system context", "description": "Proposed, unimplemented local function. Create a proposed local system identity record after duplicate and boundary review.", "inputs": [ "Master ID and issuer", "Purpose and boundary", "Accountability evidence" ], "outputs": [ "New context revision or duplicate/boundary refusal" ], "preconditions": [ "Adopting-Dimension authorization for the stated local action and record scope", "Expected current revision matches; referenced identities and evidence are resolvable or explicitly unresolved", "Validate profile, purpose, classification and required input; refuse ambiguity rather than infer authority" ], "effects": [ "Create only a local record; no runtime is provisioned", "Preserve actor, input revision and evidence provenance; corrections create a new revision" ], "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "record-usage", "name": "Record usage assignment", "description": "Proposed, unimplemented local function. Record an effective-dated system usage or responsibility assertion.", "inputs": [ "System revision", "Organization and role references", "Effective interval and authority evidence" ], "outputs": [ "Qualified assignment revision or disputed/overlap refusal" ], "preconditions": [ "Adopting-Dimension authorization for the stated local action and record scope", "Expected current revision matches; referenced identities and evidence are resolvable or explicitly unresolved", "Validate profile, purpose, classification and required input; refuse ambiguity rather than infer authority" ], "effects": [ "Append a local binding; no access grant or organization update", "Preserve actor, input revision and evidence provenance; corrections create a new revision" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ] }, { "id": "bind-realization", "name": "Bind realization evidence", "description": "Proposed, unimplemented local function. Link externally mastered release, deployment and environment evidence to the system.", "inputs": [ "System revision", "External references and scope", "Observation or activation evidence" ], "outputs": [ "Qualified binding set or unresolved-reference refusal" ], "preconditions": [ "Adopting-Dimension authorization for the stated local action and record scope", "Expected current revision matches; referenced identities and evidence are resolvable or explicitly unresolved", "Validate profile, purpose, classification and required input; refuse ambiguity rather than infer authority" ], "effects": [ "Append a scoped local link; no release, deployment or runtime mutation", "Preserve actor, input revision and evidence provenance; corrections create a new revision" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "record-state", "name": "Record lifecycle assertion", "description": "Proposed, unimplemented local function. Record a justified system lifecycle assertion under an adopted profile.", "inputs": [ "Prior revision", "Profile and proposed state", "Decision and operation evidence" ], "outputs": [ "New state assertion or unsupported-transition refusal" ], "preconditions": [ "Adopting-Dimension authorization for the stated local action and record scope", "Expected current revision matches; referenced identities and evidence are resolvable or explicitly unresolved", "Validate profile, purpose, classification and required input; refuse ambiguity rather than infer authority" ], "effects": [ "Revise the local lifecycle assertion; no activation, shutdown, rollback or resource deletion", "Preserve actor, input revision and evidence provenance; corrections create a new revision" ], "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "attach-observation", "name": "Attach observation context", "description": "Proposed, unimplemented local function. Associate an evidence reference with a bounded system observation.", "inputs": [ "System identity mapping", "Telemetry reference", "Method, time, scope and uncertainty" ], "outputs": [ "Observation link with freshness status or ambiguous-identity refusal" ], "preconditions": [ "Adopting-Dimension authorization for the stated local action and record scope", "Expected current revision matches; referenced identities and evidence are resolvable or explicitly unresolved", "Validate profile, purpose, classification and required input; refuse ambiguity rather than infer authority" ], "effects": [ "Record evidence and contrary claims; no collection, metric evaluation or health certification", "Preserve actor, input revision and evidence provenance; corrections create a new revision" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-007" ] }, { "id": "project-context", "name": "Project permitted context", "description": "Proposed, unimplemented local function. Produce a permitted local view through a pinned mapping profile.", "inputs": [ "System revision", "Recipient and purpose", "Mapping profile and authorization decision" ], "outputs": [ "Redacted view and loss report or denied/unmapped refusal" ], "preconditions": [ "Adopting-Dimension authorization for the stated local action and record scope", "Expected current revision matches; referenced identities and evidence are resolvable or explicitly unresolved", "Validate profile, purpose, classification and required input; refuse ambiguity rather than infer authority" ], "effects": [ "Produce only a local derived artifact; no remote disclosure or source-master update", "Preserve actor, input revision and evidence provenance; corrections create a new revision" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] } ], "composition": [ { "target": "WM-SFT-001", "relation": "REFERENCE", "purpose": "Product offering and producer lifecycle are externally mastered. A product or release name does not identify an operator system. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-SFT-009", "relation": "REFERENCE", "purpose": "Deployment occurrences and activation evidence are referenced; rollout, rollback and decommission execution are not owned here. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "target": "WM-SFT-010", "relation": "REFERENCE", "purpose": "Hosting topology and instance lifecycle remain runtime-owned. A system can span multiple environments and outlive instances. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "target": "WM-ORG-001", "relation": "REFERENCE", "purpose": "Organizations and their authority are separate masters; only system-specific role and usage bindings are recorded here. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "target": "WM-SFT-018", "relation": "REFERENCE", "purpose": "Endpoints reference the exposed system; addresses, reachability and endpoint lifecycle remain endpoint-owned. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "target": "WM-SFT-007", "relation": "REFERENCE", "purpose": "Component identity and package metadata remain component-owned; logical membership alone is local context. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-SFT-008", "relation": "REFERENCE", "purpose": "Release and build identity, provenance and distribution are external. Concurrent release references are permitted. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "target": "WM-SFT-003", "relation": "REFERENCE", "purpose": "API definitions and interface lifecycle are external; system provider and consumer roles are local bindings. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "WM-SFT-011", "relation": "REFERENCE", "purpose": "Configuration content, evaluation and application are external; baseline applicability and evidence references are local. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "target": "WM-SFT-016", "relation": "REFERENCE", "purpose": "Commitment definitions, calculation and evaluation stay external; applicability is recorded here. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] }, { "target": "WM-SFT-017", "relation": "REFERENCE", "purpose": "Observation payloads, signal collection and evaluation stay external; this system records qualified evidence links. Registry edges are candidate bindings; added neighbors are proposed mappings needing version pinning.", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Accountable operator role and organizational authority references; no fixed company owner", "Adopted system-boundary, identity-continuity and lifecycle profile with pinned version", "Namespace issuer, retention and access policies and separately identified master systems", "Registry links and mapping versions for product, deployment, environment and organizational usage" ], "namespace_guidance": "Use an operator-governed namespace and stable system identifier. Keep external aliases, environment labels, runtime IDs and record revisions separate. Dates are not identities.", "registry_links": [ "vr.wm-sft-002", "WM-SFT-001", "WM-SFT-009", "WM-SFT-010", "WM-ORG-001" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize only under the selected profile; preserve original aliases, asserted values, unknowns and conflicting evidence.", "A declared realization is not an observed realization. Catalog presence does not establish system liveness or authorization." ], "patch_rules": [ "Require expected revision, actor, purpose and source evidence for local changes; append correction history and reject stale writes.", "Operator transfer or split/merge requires an explicit identity-continuity decision; never silently rewrite external references." ], "compatibility_rules": [ "Pin system profile and target schemas; record lossy mappings and reject silent field deletion.", "Local proposed states and roles are not universal enumerations; map them explicitly." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with issuer", "Governed global identifier or IRI", "Dimension-assigned UUID or ULID" ], "timestamp_rule": "Use RFC 3339 with seconds and an explicit offset or Z. Distinguish event or effective time from observation and ingestion time; preserve uncertainty and unknown times.", "serial_naming_rule": "Stable system/artifact ID plus independent revision or sequence; dates may label displays but cannot provide identity.", "integrity_rule": "Record source and payload digests when available, version and redaction lineage. A hash proves neither correctness nor authorization; retain payload only under policy." }, "policies": [ "Default deny for inventory and topology disclosure; recipient views follow purpose, classification and authoritative access decisions.", "Never store credentials, private keys, personal user lists or business payload in a system context record.", "A system owner label grants no runtime access, change authority or permission to publish.", "Retirement, deletion and decommissioning are distinct; local record changes do not operate external infrastructure.", "Restricted or dangerous applications are described only by policy, authority and risk references; no operational harmful guidance.", "Proposed design and conceptual alignments require implementation and qualified review before operational use." ], "crud": { "read": [ "Resolve selected record revision and recipient view; retain unknown and stale evidence markers." ], "create": [ "Verify local authority, stable identity, boundary, accountable operator and duplicate check; planned systems may have no deployment." ], "update": [ "Require revision precondition, evidence and scoped authority; preserve time-qualified bindings and conflicting observations." ], "delete": [ "Apply the adopting-Dimension retention schedule, scoped holds and approved disposition to this model local records and artifacts. Preserve minimal lawful tombstones and disposition references; history is not a mandate for perpetual payload retention.", "Actual erasure and decommission execution belong to the adopting-Dimension disposition service and deployment/runtime masters; never cascade-delete referenced products, environments or organizational records." ] }, "roles": [ { "name": "Accountable operator", "responsibilities": [ "Own the logical system boundary and assign accountable roles under organizational authority." ] }, { "name": "System record steward", "responsibilities": [ "Maintain local identity, mappings, revisions and explicit unknowns." ] }, { "name": "Evidence custodian", "responsibilities": [ "Resolve protected evidence references and retention rules without changing external findings." ] }, { "name": "Assurance reviewer", "responsibilities": [ "Review criticality, boundary and conclusion scope; do not infer authority from catalog ownership." ] }, { "name": "Authorized reader", "responsibilities": [ "Use only the permitted recipient view and preserve qualifications." ] } ], "access": { "default_rule": "Deny unless an authoritative policy decision permits the subject, action, purpose and recipient view; catalog ownership is metadata only.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Time-limited emergency access requires explicit external authority, purpose, scope, expiry and review evidence; it does not bypass source-master restrictions." ], "audit_requirements": [ "Record actor, action, decision reference, affected revision and artifact scope in the designated audit service; this model references receipts rather than implementing an audit master.", "Log denials, access expansion and exports without copying secrets or excessive personal data." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Model ID", "Owner role", "Profile version", "Publication holds" ], "read_order": [ "Nearest owner and Dimension policies", "AGENTS.md", "spec.yaml model boundary and research holds", "Pinned profile and reference masters", "Selected record revision and permitted evidence" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one persistent operator-governed logical system under the queue label Deployed System. The shared legacy product/system boundary is split through external references. Separate local no-tools self-audit completed; independent review, source verification, adoption profiles and executable conformance remain holds. This is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "System master identity, scoped aliases and continuity decisions." }, { "dimension": "lifecycle", "status": "covered", "notes": "Proposed logical lifecycle assertions and external transition evidence." }, { "dimension": "relationships", "status": "covered", "notes": "Time-qualified external master bindings and organizational use." }, { "dimension": "temporal", "status": "covered", "notes": "Effective, observed and ingestion time, uncertainty and stale evidence." }, { "dimension": "provenance", "status": "covered", "notes": "Attribution, derivation, revisions and evidence links." }, { "dimension": "ownership", "status": "covered", "notes": "Neutral accountable operator role; separate producer, user and authority." }, { "dimension": "validation", "status": "covered", "notes": "Research schema and local context rules; executable instance conformance is a gap." }, { "dimension": "access", "status": "covered", "notes": "Default deny, classified views and authority references." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Scoped holds, minimal lawful tombstones and external disposition execution." }, { "dimension": "interoperability", "status": "covered", "notes": "Versioned mappings and explicit losses; no conformance claim." }, { "dimension": "direct properties", "status": "covered", "notes": "Purpose, class, lifecycle, criticality and scoped operational measurements." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Identity correlation, observer, method, freshness and uncertainty." }, { "dimension": "capabilities and behavior", "status": "covered", "notes": "Declared business capability and limits; local record functions separated from external runtime behavior." }, { "dimension": "physical properties", "status": "not-applicable", "notes": "Logical system root has no mass or dimensions; hosting and physical location are referenced." }, { "dimension": "executable nested schemas", "status": "gap", "notes": "Candidate object groups are not complete instance schemas; bindings and fixtures need implementation." }, { "dimension": "independent external review", "status": "gap", "notes": "Claude and Grok skipped under the single-provider waiver; separate local self-audit cannot replace independent review." }, { "dimension": "live source verification", "status": "gap", "notes": "Browser text reviewed; direct HTTP unattempted under owner-reported sandbox restriction; moving documentation and target versions require pinning." } ], "known_omissions": [ "Executable nested schemas, API bindings and adversarial instance fixtures are incomplete.", "Cross-organization identity federation, outsourced-service contracts and sector-specific authority require adoption profiles.", "Current documentation release pins, licensing and independent source verification remain open.", "No independent external provider review." ], "conflicts": [], "regional_assumptions": [ "NIST examples are qualified US federal guidance and OSCAL structure, not universal legal requirements.", "Cloud-native sources illustrate selected implementations; non-container, on-premises and outsourced systems must map through an explicit profile." ], "adversarial_checks": [ "A replaced runtime instance does not automatically create a new logical system identity.", "Two operators using the same product do not automatically share a system master.", "Catalog owner metadata cannot grant access or operational authority.", "Declared deployment success is not current liveness; concurrent observed versions and unknown state are permitted.", "Legacy product release and runtime operations remain external masters.", "Retirement does not erase evidence, revoke authority or prove every runtime has stopped." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The frozen registry describes an operator-governed logical software system with organizational usage. Stable identity survives deployment and runtime replacement. The queue name Deployed System is retained with explicit reconciliation to Software System / Business Application; product, release, deployment, runtime and organization masters remain external." }, "decisions": [ { "concept": "Logical root and naming", "disposition": "accepted with explicit reconciliation", "rationale": "Queue and registry labels differ, but the proposal states the logical-system interpretation and allows planned or retired systems without conflating them with runtime instances. No shared name record is changed." }, { "concept": "Shared legacy N4 boundary", "disposition": "split through references", "rationale": "The legacy and unreviewed supplement are preparation inputs. Product publishing, release assembly, dependency analysis and runtime execution are excluded; only evidenced system-specific context is retained." }, { "concept": "Registry relation ownership", "disposition": "accepted", "rationale": "All four outgoing registry references retain external master ownership. Incoming runtime and endpoint links do not imply lifecycle control. Proposed additional references need explicit pinned adoption mappings." }, { "concept": "Product and release master resolution", "disposition": "qualified", "rationale": "Product and specialized release bindings remain external and cannot create competing local release masters. The adopting profile must select authoritative target records and retain unresolved conflicts as unknown references." }, { "concept": "System identity and component aggregation", "disposition": "accepted", "rationale": "Stable system identity, typed membership, scoped aliases and explicit continuity decisions support entity classification. Runtime or catalog-generated identity cannot silently replace the system master." }, { "concept": "Accountability and usage authority", "disposition": "separated", "rationale": "Accountable operator, producer, using organization and decision authority are distinct role bindings. Catalog owner metadata and usage assertions grant neither access nor processing permission." }, { "concept": "Desired and observed realization", "disposition": "separated", "rationale": "Concurrent versions, partial rollout, unknown placement and contradictory observations remain representable. A successful deployment occurrence cannot prove the current realization or continued liveness." }, { "concept": "Local lifecycle and external execution", "disposition": "accepted as proposed context", "rationale": "Local profile-defined state assertions can describe planning, suspension and retirement. Their recording never activates, rolls back or shuts down resources, and baseline references never apply configurations." }, { "concept": "Recognition and assurance limits", "disposition": "qualified", "rationale": "Measurement scope, observer, method, window, uncertainty and conclusion expiry are explicit. Telemetry aliases, evidence hashes and isolated checks cannot certify system-wide truth, security or compliance." }, { "concept": "Functions and service rules", "disposition": "accepted as unimplemented local design", "rationale": "Six functions operate only on local records or derived views with authority and revision preconditions and explicit refusal outputs. Eight service sections do not take ownership of referenced engines, signals or audit masters." }, { "concept": "Retention and sensitive disclosure", "disposition": "accepted with policy dependency", "rationale": "Access defaults to denial and inventory views require recipient-specific authority. Scoped holds, approved disposition and minimal lawful tombstones reconcile continuity with payload erasure; retirement is not deletion." }, { "concept": "Instance conformance and source verification", "disposition": "deferred", "rationale": "Valid candidate data structures and conceptual mappings are not executable instance schemas. Browser-selected evidence is useful but does not establish direct HTTP availability, complete claim support, current versions or operational fitness." }, { "concept": "Independent review", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the owner override. The separate frozen no-tools Codex self-audit provides a local adversarial phase but cannot count as an independent provider pass." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not independent second-provider review.", "Source and version verification remains incomplete. Selected primary-source sections were reviewed through browser retrieval. Direct HTTP checks were not attempted under the owner-reported sandbox block; no HTTP status was measured and zero HTTP 200 responses were measured. The coordinator checker is prepared. Moving documentation versions, full claim support and licensing require verification.", "Adoption profiles must resolve logical system identity, operator and tenant boundaries, product/release master bindings, lifecycle terms, delegated authority, retention and sector-specific security or legal applicability. NIST examples and cloud-native mappings are qualified alignments, not universal requirements.", "Executable nested instance schemas, pinned neighbor bindings, catalog/telemetry/security-plan mappings and adversarial conformance fixtures remain incomplete. Proposed functions are unimplemented local record operations; no runtime, security or compliance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Pin and verify source versions, claim support, licenses and target implementation schemas, then restore independent external provider review before canonical promotion.", "Build adoption profiles for shared tenancy, outsourced operation, identity split/merge, organizational transfer, ambiguous release masters, retirement with residual runtimes and lawful disposition.", "Implement nested schemas and test versioned mappings with concurrent versions, stale or conflicting observations, permission denial, unknown placement, redacted export and loss of reference resolution." ] }, "statistics": { "sources": 7, "bundles": 6, "layers": 12, "findings": 12, "questions": 48, "artifacts": 12, "functions": 6 } }