# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T12:29:33Z", "synthesisSha256": "2f8751dac69dc6e587f1c67166e4b852e905e70d7534adf5a827ae9123f173c7", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-SFT-010", "registryId": "vr.wm-sft-010", "name": "Runtime / Compute Environment", "version": "1.0.0", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.SFT.RUN" ], "tags": [ "runtime", "compute", "environment", "inf.sft.run" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-sft-010-runtime-compute-environment/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-010", "model": { "registry_id": "vr.wm-sft-010", "model_id": "WM-SFT-010", "name": "Runtime / Compute Environment", "entry_kind": "entity", "purpose": "Describe a managed runtime environment, its resources, dependent occupants and configuration evidence across time without duplicating software, deployment or physical-asset masters.", "scope_statement": "One identity-bearing execution context at declared granularity, including resource references, temporal topology assertions, dependent runtime occupancy, capacities, capabilities, configuration-control designations and governed evidence. The root is an entity; dependent records do not turn it into a universal infrastructure graph or an execution engine.", "in_scope": [ "Environment identity, classification, accountability and resource topology", "Capacity and execution capability assertions with evidence and uncertainty", "Dependent occupant bindings and observed lifecycle or health facts", "Configuration designations, baselines, drift and maintenance evidence", "Isolation, action-authority references, provenance, projections and record continuity" ], "out_of_scope": [ "Software and application masters, product lifecycle, source code and release ownership", "Deployment orchestration, change approval execution and workload scheduling or execution", "Managed-service tenant mastership, impact propagation, general audit and enforcement engines", "Physical asset identity, custody, procurement and disposal", "Secret payloads, workload business data, billing, energy accounting and complete platform security certification" ], "boundary_notes": [ { "neighbor": "WM-SFT-002", "distinction": "Reference logical software and application identity, ownership and product lifecycle; occupant records never become independent software masters.", "source_refs": [ "SRC-002", "SRC-005" ] }, { "neighbor": "WM-SFT-009", "distinction": "Reference deployment occurrences for creation or change evidence; deployment plan, approval, execution and outcome remain deployment-owned.", "source_refs": [ "SRC-002", "SRC-007" ] }, { "neighbor": "WM-XCT-039", "distinction": "Reference tenant mastership and bounded impact projections; this model records runtime topology assertions, not managed-service graph evaluation or cross-tenant impact propagation.", "source_refs": [ "SRC-003", "SRC-010" ] }, { "neighbor": "WM-OBJ-001", "distinction": "Reference underlying physical item when applicable; runtime resource identity and CI designation do not duplicate physical identity, custody, ownership or asset lifecycle.", "source_refs": [ "SRC-003", "SRC-007" ] }, { "neighbor": "WM-SFT-018", "distinction": "Incoming hosting links can identify this runtime context; endpoint identity, contract and endpoint lifecycle remain external.", "source_refs": [ "SRC-003", "SRC-010" ] }, { "neighbor": "WM-SFT-015", "distinction": "Incoming execution links identify where an execution occurred; task execution state, scheduling and execution effects remain external.", "source_refs": [ "SRC-002", "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "The NIST Definition of Cloud Computing", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/145/final", "version_or_date": "SP 800-145, September 2011; official abstract reviewed", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Resource pooling and service/deployment models frame cloud profiles only; local and edge environments need not be cloud services." }, { "id": "SRC-002", "title": "Open Container Initiative Runtime Specification - Runtime and Lifecycle", "organization": "Open Container Initiative", "url": "https://github.com/opencontainers/runtime-spec/blob/v1.2.0/runtime.md", "version_or_date": "v1.2.0, runtime.md", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Container identity has host scope and can be reused after deletion. Runtime states and operations motivate incarnation-aware occupancy and lifecycle evidence; not a universal environment state machine." }, { "id": "SRC-003", "title": "Nodes", "organization": "Kubernetes project", "url": "https://kubernetes.io/docs/concepts/architecture/nodes/", "version_or_date": "Rolling documentation retrieved 2026-10-06; deployed-version pin unresolved", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Node representation, physical/virtual hosting, name reuse, capacity and allocatable fields, conditions and heartbeats support resource topology and recognition." }, { "id": "SRC-004", "title": "Resource SDK", "organization": "OpenTelemetry project", "url": "https://opentelemetry.io/docs/specs/otel/resource/sdk/", "version_or_date": "Rolling specification retrieved 2026-10-06; stable core reviewed, development entity behavior excluded", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Telemetry resource attributes, schema URLs and immutable resource values motivate attributed snapshots and explicit mapping conflicts, not authoritative inventory identity." }, { "id": "SRC-005", "title": "Pod Lifecycle", "organization": "Kubernetes project", "url": "https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/", "version_or_date": "Rolling documentation retrieved 2026-10-06; deployed-version pin unresolved", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Ephemeral UID-bound Pods, one-time node binding, container restarts, phase and readiness distinctions inform dependent occupancy records and health evidence." }, { "id": "SRC-006", "title": "Resource Management for Pods and Containers", "organization": "Kubernetes project", "url": "https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/", "version_or_date": "Rolling documentation retrieved 2026-10-06; selected requests, limits and units sections", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Requests, limits and consumption have different meanings. Units and resource scope must survive a projection; version-specific resize and feature behavior is not adopted." }, { "id": "SRC-007", "title": "Guide for Security-Focused Configuration Management of Information Systems", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-128.pdf", "version_or_date": "SP 800-128, August 2011 with 2019-10-10 updates; sections 2.3, 3.2-3.4", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "CI designation, approved baselines, controlled change and monitoring motivate separate configuration facts and decisions. Federal guidance is not asserted as universal obligation." }, { "id": "SRC-008", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 2013-04-30; sections 3 and 4 selected terms", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Entity, activity, agent, derivation, attribution and revision support provenance references. Provenance does not establish truth or grant authority." }, { "id": "SRC-009", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "July 2002; section 5.6 timestamp syntax", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Timestamp syntax supports seconds and explicit offsets; interval semantics, clock uncertainty and retention are local design choices." }, { "id": "SRC-010", "title": "Multi-tenancy", "organization": "Kubernetes project", "url": "https://kubernetes.io/docs/concepts/security/multi-tenancy/", "version_or_date": "Rolling documentation retrieved 2026-10-06; tenancy and isolation sections", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:22Z", "relevance": "Tenancy has several meanings and isolation spans control and data planes. Namespace or node placement is not sufficient evidence of tenant isolation." } ], "structure": { "bundles": [ { "id": "bundle-identity-topology", "name": "Identity and resource topology", "description": "Identify one environment and its time-varying resource membership.", "rationale": "Proposed format-neutral grouping derived from the cited evidence and the frozen relationship contract; not a source-prescribed hierarchy.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008" ], "layers": [ { "id": "layer-environment", "name": "Environment identity and accountability", "description": "Context for environment identity and accountability with explicit evidence and authority limits.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ], "findings": [ { "id": "finding-environment", "name": "Environment identity and accountability", "description": "A persistent managed execution context with explicit granularity, authority and classification. Resource replacement need not replace the environment, but a new authority scope must not silently reuse it.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ], "questions": [ { "id": "question-environment-1", "text": "Which master identifier, authority scope and incarnation distinguish this environment from another with the same label?", "kind": "identity", "answer_data": [ "environment_id", "master_authority", "tenant_or_account_scope", "incarnation", "aliases" ] }, { "id": "question-environment-2", "text": "Is this context a host, cluster, resource pool or managed execution service, and what boundary does its profile assert?", "kind": "classification", "answer_data": [ "environment_kind", "boundary_definition", "profile_version", "deployment_model_if_applicable" ] }, { "id": "question-environment-3", "text": "Which accountable roles maintain its record, operate the context and approve its configuration?", "kind": "ownership", "answer_data": [ "steward_role_ref", "operator_role_ref", "approver_role_ref", "effective_interval" ] }, { "id": "question-environment-4", "text": "Which observations corroborate the environment identity, and which apparent matches remain ambiguous?", "kind": "evidence", "answer_data": [ "recognition_evidence_refs", "observed_identifiers", "matching_method", "unresolved_collisions" ] } ], "data_elements": [ { "id": "data-environment-1", "name": "Environment key", "description": "Scoped master ID plus incarnation; labels and addresses are aliases.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "data-environment-2", "name": "Environment profile", "description": "Kind, purpose, classification and boundary rule; production status is an assertion with effectivity.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "data-environment-3", "name": "Accountability assignments", "description": "Role references and time-bounded authority; no company is named as owner.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "data-environment-4", "name": "Recognition assertions", "description": "Evidence and confidence for identity reconciliation; ambiguity is not automatic equivalence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-environment", "name": "Environment identity record", "description": "Proposed revisioned evidence view for environment identity and accountability; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-topology", "name": "Resources and temporal topology", "description": "Context for resources and temporal topology with explicit evidence and authority limits.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ], "findings": [ { "id": "finding-topology", "name": "Resources and temporal topology", "description": "Record infrastructure resource identities and typed, time-bounded hosting, membership and attachment assertions. A resource may be shared. Physical asset and managed-service graph masters remain external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ], "questions": [ { "id": "question-topology-1", "text": "Which compute, storage and network resources belong to this environment at the requested time?", "kind": "composition", "answer_data": [ "resource_refs", "membership_kind", "valid_from", "valid_to", "observed_at" ] }, { "id": "question-topology-2", "text": "Which hosting or attachment edges are asserted, and are they desired, observed or inferred?", "kind": "relationship", "answer_data": [ "edge_type", "source_ref", "target_ref", "assertion_class", "evidence_ref" ] }, { "id": "question-topology-3", "text": "Which location or failure-domain references are known, and which placement details are concealed or unknown?", "kind": "spatial", "answer_data": [ "site_ref", "zone_ref", "failure_domain_ref", "visibility_state", "evidence_time" ] }, { "id": "question-topology-4", "text": "How are replacement resources and overlapping shared membership represented without rewriting earlier topology?", "kind": "temporal", "answer_data": [ "resource_incarnation", "supersedes_ref", "membership_intervals", "conflict_state" ] } ], "data_elements": [ { "id": "data-topology-1", "name": "Resource references", "description": "Scoped resource master identities and kinds, including virtual resources; no physical custody duplication.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] }, { "id": "data-topology-2", "name": "Topology assertions", "description": "Typed edges with endpoints, effective interval, observation time and evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] }, { "id": "data-topology-3", "name": "Placement references", "description": "Site, zone and failure-domain references; region labels alone do not prove data residency.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] }, { "id": "data-topology-4", "name": "Topology revision", "description": "Revision and predecessor reference for an as-of view; unknown intervals remain open-ended, not infinite guarantees.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-topology", "name": "Temporal resource topology", "description": "Proposed revisioned evidence view for resources and temporal topology; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-capacity-capability", "name": "Capacity and execution capabilities", "description": "Distinguish quantitative resource constraints from evidenced execution support.", "rationale": "Proposed format-neutral grouping derived from the cited evidence and the frozen relationship contract; not a source-prescribed hierarchy.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "layers": [ { "id": "layer-capacity", "name": "Capacity, reservations and observed use", "description": "Context for capacity, reservations and observed use with explicit evidence and authority limits.", "source_refs": [ "SRC-003", "SRC-006" ], "findings": [ { "id": "finding-capacity", "name": "Capacity, reservations and observed use", "description": "Separate nominal capacity, allocatable capacity, request, limit, quota and measured consumption. Computed headroom is a profile-bound estimate, never a universal scheduling guarantee.", "source_refs": [ "SRC-003", "SRC-006" ], "questions": [ { "id": "question-capacity-1", "text": "Which resource quantity is recorded, with what unit, scope and capacity or consumption meaning?", "kind": "measurement", "answer_data": [ "quantity_kind", "value", "unit", "resource_ref", "quantity_semantics" ] }, { "id": "question-capacity-2", "text": "Which reservations, limits or quotas constrain this resource pool independently of its nominal capacity?", "kind": "constraint", "answer_data": [ "reservation_refs", "request_values", "limit_values", "quota_scope", "effective_time" ] }, { "id": "question-capacity-3", "text": "What sampling window, collector, aggregation method and uncertainty qualify the usage observation?", "kind": "quality", "answer_data": [ "window_start", "window_end", "collector_ref", "aggregation", "uncertainty_or_unknown" ] }, { "id": "question-capacity-4", "text": "Which exhaustion, throttling or eviction evidence limits the interpretation of apparently available capacity?", "kind": "exception", "answer_data": [ "condition_ref", "affected_scope", "observed_time", "competing_load", "assessment_state" ] } ], "data_elements": [ { "id": "data-capacity-1", "name": "Resource quantities", "description": "Typed quantities with units and nominal, allocatable, reserved, limit or usage meaning.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] }, { "id": "data-capacity-2", "name": "Constraints", "description": "Time-bounded quota and allocation references; missing limits are unknown unless explicitly unbounded by profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] }, { "id": "data-capacity-3", "name": "Measurement context", "description": "Sampling conditions, duration, source, aggregation and precision; no cross-scope addition without reconciliation.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] }, { "id": "data-capacity-4", "name": "Capacity exceptions", "description": "External controller reports and unresolved observations; no scheduler implementation.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-capacity", "name": "Capacity evidence sheet", "description": "Proposed revisioned evidence view for capacity, reservations and observed use; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-capability", "name": "Execution capability and compatibility", "description": "Context for execution capability and compatibility with explicit evidence and authority limits.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "finding-capability", "name": "Execution capability and compatibility", "description": "Describe declared and observed execution support and its preconditions. Compatibility belongs to a named platform profile and evidence set; no generic claim that every workload can run here.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ], "questions": [ { "id": "question-capability-1", "text": "Which operating system, architecture, runtime implementation and interface versions characterize the execution context?", "kind": "classification", "answer_data": [ "os_ref", "architecture", "runtime_ref", "interface_version", "observation_time" ] }, { "id": "question-capability-2", "text": "Which workload requirements have been compared with those capabilities and which remain untested?", "kind": "requirement", "answer_data": [ "workload_ref", "requirement_refs", "tested_capabilities", "unsupported_or_unknown" ] }, { "id": "question-capability-3", "text": "Which resource, permission or platform preconditions limit a declared execution capability?", "kind": "constraint", "answer_data": [ "capability", "prerequisite_refs", "resource_bounds", "privilege_constraints", "profile_version" ] }, { "id": "question-capability-4", "text": "What scoped evidence supports compatibility and where would portability lose semantics?", "kind": "interoperability", "answer_data": [ "test_or_attestation_refs", "source_profile", "target_profile", "unsupported_features", "loss_notes" ] } ], "data_elements": [ { "id": "data-capability-1", "name": "Execution profile", "description": "OS, architecture, runtime and interface identifiers with versions; secrets excluded.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-capability-2", "name": "Capability assertions", "description": "Capability, prerequisites and declared versus observed status.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-capability-3", "name": "Compatibility evidence", "description": "Requirement and result references; a version string is not conformance evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "data-capability-4", "name": "Portability limitations", "description": "Unsupported features and untested platform combinations.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-capability", "name": "Execution capability profile", "description": "Proposed revisioned evidence view for execution capability and compatibility; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-occupancy-lifecycle", "name": "Occupancy and runtime lifecycle", "description": "Track dependent occupants and subject-specific state without taking over software or deployment masters.", "rationale": "Proposed format-neutral grouping derived from the cited evidence and the frozen relationship contract; not a source-prescribed hierarchy.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ], "layers": [ { "id": "layer-occupancy", "name": "Dependent runtime occupants", "description": "Context for dependent runtime occupants with explicit evidence and authority limits.", "source_refs": [ "SRC-002", "SRC-005", "SRC-009" ], "findings": [ { "id": "finding-occupancy", "name": "Dependent runtime occupants", "description": "An occupant is a dependent record of a software reference in an environment and resource incarnation over an interval. It is not a second software, deployment or execution master.", "source_refs": [ "SRC-002", "SRC-005", "SRC-009" ], "questions": [ { "id": "question-occupancy-1", "text": "Which logical software reference, runtime identifier and incarnation does this occupancy assertion bind?", "kind": "identity", "answer_data": [ "software_ref", "environment_ref", "runtime_id", "authority_scope", "incarnation" ] }, { "id": "question-occupancy-2", "text": "Which resource placement was actually observed, separately from requested or merely scheduled placement?", "kind": "state", "answer_data": [ "resource_ref", "desired_placement", "scheduled_placement", "observed_placement", "evidence_ref" ] }, { "id": "question-occupancy-3", "text": "What start and end bounds are supported, including never-started, unknown-end and late-arriving evidence?", "kind": "temporal", "answer_data": [ "valid_from", "valid_to", "bound_precision", "observation_time", "interval_state" ] }, { "id": "question-occupancy-4", "text": "Which deployment or execution references explain the occupancy, and how are restarts and replacements distinguished?", "kind": "relationship", "answer_data": [ "deployment_ref_or_unknown", "execution_ref_or_unknown", "parent_occupant_ref", "restart_sequence", "replacement_ref" ] } ], "data_elements": [ { "id": "data-occupancy-1", "name": "Occupancy binding", "description": "Environment-scoped dependent identity with software, resource and incarnation references; software resolution may be pending.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-009" ] }, { "id": "data-occupancy-2", "name": "Placement assertions", "description": "Desired, scheduled and observed placement kept separate.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-009" ] }, { "id": "data-occupancy-3", "name": "Occupancy interval", "description": "Evidence-qualified interval with unknown bounds; timestamps alone never identify an occupant.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-009" ] }, { "id": "data-occupancy-4", "name": "Continuity links", "description": "Restart, replacement, deployment and execution references; no execution control or deployment approval.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-occupancy", "name": "Occupancy interval ledger", "description": "Proposed revisioned evidence view for dependent runtime occupants; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-002", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-state", "name": "Lifecycle state and health observations", "description": "Context for lifecycle state and health observations with explicit evidence and authority limits.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ], "findings": [ { "id": "finding-state", "name": "Lifecycle state and health observations", "description": "Keep environment lifecycle, resource state and occupant state distinct. Health, readiness and reachability are time-sensitive observations. A stale heartbeat does not establish destruction.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ], "questions": [ { "id": "question-state-1", "text": "Which entity and profile define the reported lifecycle state rather than borrowing a state from a child resource?", "kind": "state", "answer_data": [ "subject_ref", "lifecycle_profile", "state_code", "reported_at", "source_ref" ] }, { "id": "question-state-2", "text": "Which evidence supports a state transition and what ordering uncertainty remains?", "kind": "event", "answer_data": [ "before_state", "after_state", "transition_evidence_ref", "event_time", "ingestion_time", "clock_uncertainty" ] }, { "id": "question-state-3", "text": "Do readiness, liveness and reachability observations agree, and when do they become stale?", "kind": "quality", "answer_data": [ "probe_kind", "result", "scope", "freshness_threshold", "last_observed_at", "disagreement" ] }, { "id": "question-state-4", "text": "How are unreachable, failed, stopped and retired states distinguished when a controller loses contact?", "kind": "exception", "answer_data": [ "controller_view", "reported_state", "inferred_state", "unknown_reason", "recovery_evidence_ref" ] } ], "data_elements": [ { "id": "data-state-1", "name": "State assertions", "description": "Subject-scoped profile codes with asserted, observed or inferred status.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ] }, { "id": "data-state-2", "name": "Transition evidence", "description": "External event references, ordering and conflicting reports; no deployment or execution state-machine ownership.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ] }, { "id": "data-state-3", "name": "Health evidence", "description": "Observation method, freshness, readiness/liveness distinction and source.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ] }, { "id": "data-state-4", "name": "State uncertainty", "description": "Unreachable and stale are evidence conditions, not deletion proofs.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-state", "name": "Runtime state timeline", "description": "Proposed revisioned evidence view for lifecycle state and health observations; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-configuration", "name": "Configuration control evidence", "description": "Separate control designation, baseline authority, observations and maintenance evidence.", "rationale": "Proposed format-neutral grouping derived from the cited evidence and the frozen relationship contract; not a source-prescribed hierarchy.", "source_refs": [ "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-baseline", "name": "Configuration designation and baseline", "description": "Context for configuration designation and baseline with explicit evidence and authority limits.", "source_refs": [ "SRC-007", "SRC-008" ], "findings": [ { "id": "finding-baseline", "name": "Configuration designation and baseline", "description": "A configuration-item designation scopes control over selected environment facts. It does not create a new physical or software master. Approved baseline, desired configuration and observed snapshot remain separate.", "source_refs": [ "SRC-007", "SRC-008" ], "questions": [ { "id": "question-baseline-1", "text": "Which environment or resource facts are designated for configuration control and under whose effective authority?", "kind": "authority", "answer_data": [ "designation_id", "subject_refs", "controlled_paths", "authority_ref", "effective_interval" ] }, { "id": "question-baseline-2", "text": "Which baseline revision and approval evidence govern the controlled facts at the comparison time?", "kind": "requirement", "answer_data": [ "baseline_ref", "revision", "approval_ref", "effective_from", "effective_to" ] }, { "id": "question-baseline-3", "text": "Which desired declarations differ from the approved baseline or from an observed runtime snapshot?", "kind": "state", "answer_data": [ "desired_ref", "baseline_ref", "snapshot_ref", "differing_paths", "unknown_paths" ] }, { "id": "question-baseline-4", "text": "How are inherited baselines, scoped exceptions and superseded designations distinguished?", "kind": "classification", "answer_data": [ "inheritance_ref", "exception_ref", "designated_scope", "supersedes_ref", "profile_rule" ] } ], "data_elements": [ { "id": "data-baseline-1", "name": "CI designation", "description": "Local control designation referencing existing subjects and authority; neither mandatory for every resource nor a gold-copy master.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "data-baseline-2", "name": "Baseline binding", "description": "Approved version and effective scope; approval evidence stays with its source authority.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "data-baseline-3", "name": "Configuration views", "description": "Desired, approved and observed references with digest and redaction metadata.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "data-baseline-4", "name": "Baseline exceptions", "description": "Scoped deviations and expiration; a declared desired state is not automatically approved.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-baseline", "name": "Configuration baseline register", "description": "Proposed revisioned evidence view for configuration designation and baseline; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-drift", "name": "Drift and maintenance evidence", "description": "Context for drift and maintenance evidence with explicit evidence and authority limits.", "source_refs": [ "SRC-007", "SRC-003" ], "findings": [ { "id": "finding-drift", "name": "Drift and maintenance evidence", "description": "Record evidence-qualified configuration differences and maintenance status. Difference detection is not a breach verdict, change authorization or automatic remediation; support deadlines need version-specific evidence.", "source_refs": [ "SRC-007", "SRC-003" ], "questions": [ { "id": "question-drift-1", "text": "Which exact snapshot and baseline revisions were compared by which method?", "kind": "provenance", "answer_data": [ "snapshot_ref", "baseline_ref", "comparator_version", "compared_at", "covered_paths" ] }, { "id": "question-drift-2", "text": "Which differences are confirmed, excepted or unresolved because data was unavailable or redacted?", "kind": "validation", "answer_data": [ "difference_paths", "comparison_status", "exception_ref", "missing_paths", "reviewer_ref" ] }, { "id": "question-drift-3", "text": "Which observed component versions have maintenance or support evidence, and when was that evidence checked?", "kind": "evidence", "answer_data": [ "component_ref", "observed_version", "advisory_or_support_ref", "applicable_profile", "checked_at", "unknown_status" ] }, { "id": "question-drift-4", "text": "Which authorized change or deployment record explains a difference, and what remains unexplained?", "kind": "relationship", "answer_data": [ "difference_ref", "change_ref", "deployment_ref", "explanation_state", "follow_up_role" ] } ], "data_elements": [ { "id": "data-drift-1", "name": "Comparison record", "description": "Input revisions, method, coverage and time; this draft proposes a local comparison contract only.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-003" ] }, { "id": "data-drift-2", "name": "Drift assertions", "description": "Differences and evidence state; do not infer unauthorized change solely from mismatch.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-003" ] }, { "id": "data-drift-3", "name": "Maintenance evidence", "description": "External advisory and support references, observed version and applicability uncertainty.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-003" ] }, { "id": "data-drift-4", "name": "Change associations", "description": "Reference-only association to authorized changes; no patching or deployment execution.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-drift", "name": "Drift and maintenance report", "description": "Proposed revisioned evidence view for drift and maintenance evidence; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-007", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-isolation-authority", "name": "Isolation and operator authority", "description": "Bound shared use, disclosure and action authority with external enforcement references.", "rationale": "Proposed format-neutral grouping derived from the cited evidence and the frozen relationship contract; not a source-prescribed hierarchy.", "source_refs": [ "SRC-007", "SRC-010" ], "layers": [ { "id": "layer-isolation", "name": "Tenancy and isolation boundaries", "description": "Context for tenancy and isolation boundaries with explicit evidence and authority limits.", "source_refs": [ "SRC-010", "SRC-001" ], "findings": [ { "id": "finding-isolation", "name": "Tenancy and isolation boundaries", "description": "Record tenancy scope and isolation requirements with evidence for control-plane, network, storage and execution boundaries. Labels, namespaces and shared-node placement do not by themselves demonstrate isolation.", "source_refs": [ "SRC-010", "SRC-001" ], "questions": [ { "id": "question-isolation-1", "text": "Which tenant definition and trust assumptions apply to the environment and each shared resource?", "kind": "definition", "answer_data": [ "tenant_profile_ref", "tenant_scope_ref", "trust_assumptions", "shared_resource_refs" ] }, { "id": "question-isolation-2", "text": "Which isolation requirements and control references apply to each execution or data boundary?", "kind": "security", "answer_data": [ "boundary_kind", "requirement_refs", "control_refs", "enforcement_point_refs" ] }, { "id": "question-isolation-3", "text": "Which observations or assessments support effective isolation and which are only configuration intent?", "kind": "evidence", "answer_data": [ "assessment_refs", "desired_controls", "observed_controls", "assessment_scope", "unresolved_gaps" ] }, { "id": "question-isolation-4", "text": "What cross-tenant exposure is permitted by an approved exception and when does that exception expire?", "kind": "exception", "answer_data": [ "exception_ref", "permitted_scope", "approval_ref", "expiry", "review_status" ] } ], "data_elements": [ { "id": "data-isolation-1", "name": "Tenancy binding", "description": "Tenant definition and scope remain mastered by the adopting Dimension or managed-service graph.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] }, { "id": "data-isolation-2", "name": "Isolation declarations", "description": "Execution, control-plane, storage and network requirements; no firewall or policy-engine execution.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] }, { "id": "data-isolation-3", "name": "Isolation evidence", "description": "Assessment result references and evidence times; no certification claim.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] }, { "id": "data-isolation-4", "name": "Isolation exceptions", "description": "Approved scope, expiry and compensating-control references.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] } ], "artifacts": [ { "id": "artifact-isolation", "name": "Isolation assurance record", "description": "Proposed revisioned evidence view for tenancy and isolation boundaries; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-010", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-authority", "name": "Operator access and action boundaries", "description": "Context for operator access and action boundaries with explicit evidence and authority limits.", "source_refs": [ "SRC-007", "SRC-010" ], "findings": [ { "id": "finding-authority", "name": "Operator access and action boundaries", "description": "Record who may read runtime context or request actions and which external controller owns each effect. Capability, permission and approval are separate. Configuration and telemetry may expose secrets or internal topology.", "source_refs": [ "SRC-007", "SRC-010" ], "questions": [ { "id": "question-authority-1", "text": "Which role may read which runtime facts and artifacts for the stated purpose?", "kind": "access", "answer_data": [ "role_ref", "purpose", "record_scope", "sensitivity", "policy_ref" ] }, { "id": "question-authority-2", "text": "Which authority is required to request provisioning, scaling, patching or retirement, separately from technical capability?", "kind": "authority", "answer_data": [ "action_kind", "subject_scope", "authority_ref", "approval_ref", "validity_interval" ] }, { "id": "question-authority-3", "text": "Which secret values, internal endpoints or tenant identifiers must be omitted or masked in a projection?", "kind": "privacy", "answer_data": [ "field_paths", "classification", "redaction_rule", "recipient_scope", "retained_reference" ] }, { "id": "question-authority-4", "text": "How are emergency access, revocation and denied requests evidenced without treating this record as the enforcement engine?", "kind": "process", "answer_data": [ "external_decision_ref", "emergency_basis", "expiry", "revocation_ref", "refusal_reason" ] } ], "data_elements": [ { "id": "data-authority-1", "name": "Access policy references", "description": "Role and purpose scoped rules for local runtime records.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] }, { "id": "data-authority-2", "name": "Action authority references", "description": "Permission and approval evidence; local functions never provision or terminate workloads.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] }, { "id": "data-authority-3", "name": "Disclosure rules", "description": "Field-level exclusions and masked views; secret payloads prohibited.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] }, { "id": "data-authority-4", "name": "External decisions", "description": "Time-limited emergency or denial references; general audit and enforcement semantics stay external.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "artifact-authority", "name": "Runtime authority matrix", "description": "Proposed revisioned evidence view for operator access and action boundaries; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-evidence-projection", "name": "Evidence and interoperability", "description": "Preserve source uncertainty and identify loss in platform projections.", "rationale": "Proposed format-neutral grouping derived from the cited evidence and the frozen relationship contract; not a source-prescribed hierarchy.", "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ], "layers": [ { "id": "layer-observation", "name": "Observation lineage and uncertainty", "description": "Context for observation lineage and uncertainty with explicit evidence and authority limits.", "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ], "findings": [ { "id": "finding-observation", "name": "Observation lineage and uncertainty", "description": "Attach observations to exact environment, resource or occupant subjects. Preserve evidence lineage, collector context and time. Telemetry attributes identify a reported source but need reconciliation with the authority that masters identity.", "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ], "questions": [ { "id": "question-observation-1", "text": "Which collector and source record produced this runtime assertion and by what transformation?", "kind": "provenance", "answer_data": [ "collector_ref", "source_record_ref", "transformation_version", "evidence_digest", "attribution_ref" ] }, { "id": "question-observation-2", "text": "What event, observation and ingestion times apply, with what clock offset and uncertainty?", "kind": "temporal", "answer_data": [ "event_time", "observed_at", "ingested_at", "clock_offset", "uncertainty", "timezone_offset" ] }, { "id": "question-observation-3", "text": "What evidence distinguishes an absent resource from a collection gap, access denial or stale sample?", "kind": "quality", "answer_data": [ "collection_scope", "completeness_state", "access_result", "last_success", "absence_evidence" ] }, { "id": "question-observation-4", "text": "How are conflicting measurements or schema versions retained without silently selecting a new master identity?", "kind": "validation", "answer_data": [ "assertion_refs", "schema_url", "conflict_type", "resolution_ref", "unresolved_state" ] } ], "data_elements": [ { "id": "data-observation-1", "name": "Observation provenance", "description": "Collector, source, transformation and attribution references; digest is integrity evidence only.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ] }, { "id": "data-observation-2", "name": "Observation times", "description": "RFC 3339 times with seconds and offset; unknown event time stays unknown.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ] }, { "id": "data-observation-3", "name": "Coverage assessment", "description": "Source scope, gaps, denial and freshness; no inference from missing to zero.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ] }, { "id": "data-observation-4", "name": "Conflicting assertions", "description": "Retain alternate facts and schema versions until an authorized resolution.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-observation", "name": "Runtime observation provenance", "description": "Proposed revisioned evidence view for observation lineage and uncertainty; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-projection", "name": "Loss-aware interoperability projections", "description": "Context for loss-aware interoperability projections with explicit evidence and authority limits.", "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ], "findings": [ { "id": "finding-projection", "name": "Loss-aware interoperability projections", "description": "Project records through named, versioned mappings to external runtime and telemetry vocabularies. A successful serialization does not establish semantic equivalence or platform conformance.", "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ], "questions": [ { "id": "question-projection-1", "text": "Which source and target profiles define the mapping for this environment view?", "kind": "interoperability", "answer_data": [ "source_profile", "target_profile", "mapping_version", "subject_scope" ] }, { "id": "question-projection-2", "text": "Which identities, states, quantities or topology edges lack an equivalent target representation?", "kind": "constraint", "answer_data": [ "unmapped_fields", "lossy_conversions", "unit_changes", "unresolved_references" ] }, { "id": "question-projection-3", "text": "Which fixtures demonstrate that round-trip or one-way projection preserves the required distinctions?", "kind": "validation", "answer_data": [ "fixture_refs", "comparison_method", "tested_invariants", "failures", "untested_cases" ] }, { "id": "question-projection-4", "text": "Which external consumers received which revision and disclosure scope?", "kind": "provenance", "answer_data": [ "consumer_role_ref", "source_revision", "projection_revision", "policy_ref", "export_evidence_ref" ] } ], "data_elements": [ { "id": "data-projection-1", "name": "Mapping declaration", "description": "Versioned conceptual alignment; executable mapping remains a hold.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] }, { "id": "data-projection-2", "name": "Loss report", "description": "Lost values, precision, identity scope and state semantics.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] }, { "id": "data-projection-3", "name": "Conformance evidence references", "description": "Explicit fixtures and actual result refs; no implementation or certification is supplied.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] }, { "id": "data-projection-4", "name": "Projection provenance", "description": "Input revision and access-filter context; the operation does not transmit externally.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-projection", "name": "Interoperability loss register", "description": "Proposed revisioned evidence view for loss-aware interoperability projections; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-retirement-history", "name": "Retirement and governed history", "description": "Separate runtime effects from local records and preserve authorized continuity.", "rationale": "Proposed format-neutral grouping derived from the cited evidence and the frozen relationship contract; not a source-prescribed hierarchy.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008", "SRC-009" ], "layers": [ { "id": "layer-retirement", "name": "Retirement and resource continuity", "description": "Context for retirement and resource continuity with explicit evidence and authority limits.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007" ], "findings": [ { "id": "finding-retirement", "name": "Retirement and resource continuity", "description": "Record decommissioning intent and external completion evidence separately. Environment record retirement, workload termination, infrastructure destruction and underlying data disposal are different effects.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007" ], "questions": [ { "id": "question-retirement-1", "text": "Which environment or resource is proposed for retirement and which dependents or shared attachments remain unresolved?", "kind": "lifecycle", "answer_data": [ "subject_ref", "proposed_status", "dependent_refs", "shared_resource_refs", "unresolved_bindings" ] }, { "id": "question-retirement-2", "text": "Which accountable authority approved the retirement and which controller evidence confirms its actual effects?", "kind": "authority", "answer_data": [ "approval_ref", "controller_ref", "completion_evidence_ref", "actual_effects", "unknown_effects" ] }, { "id": "question-retirement-3", "text": "Which successor, replacement or recovery reference preserves continuity without reusing the retired incarnation?", "kind": "relationship", "answer_data": [ "successor_ref", "replacement_ref", "recovery_evidence_ref", "identity_rule" ] }, { "id": "question-retirement-4", "text": "What proves an occupant ended rather than merely disappearing from the latest inventory?", "kind": "evidence", "answer_data": [ "termination_evidence_ref", "observation_gap", "last_seen", "confirmed_end_or_unknown" ] } ], "data_elements": [ { "id": "data-retirement-1", "name": "Retirement proposal", "description": "Scope and unresolved dependent references; no controller action performed.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007" ] }, { "id": "data-retirement-2", "name": "Retirement evidence", "description": "External approval and completion references; resource deletion is never inferred from local deletion.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007" ] }, { "id": "data-retirement-3", "name": "Continuity references", "description": "Replacement, successor and tested recovery evidence with distinct incarnations.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007" ] }, { "id": "data-retirement-4", "name": "Unresolved effects", "description": "Potential active occupants, shared attachments and unknown outcomes.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-retirement", "name": "Retirement evidence record", "description": "Proposed revisioned evidence view for retirement and resource continuity; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-retention", "name": "Record retention and historical reconstruction", "description": "Context for record retention and historical reconstruction with explicit evidence and authority limits.", "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ], "findings": [ { "id": "finding-retention", "name": "Record retention and historical reconstruction", "description": "Retain only authorized runtime history needed for a defined purpose, with evidence and disclosure limits. Snapshot retention is not workload data backup, and lawful erasure can limit later reconstruction.", "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ], "questions": [ { "id": "question-retention-1", "text": "Which retention policy governs environment snapshots, occupancy history and sensitive topology evidence?", "kind": "retention", "answer_data": [ "record_class", "policy_ref", "purpose", "retention_trigger", "period", "hold_ref" ] }, { "id": "question-retention-2", "text": "Which records may be disposed of and what minimal tombstone preserves permitted reference continuity?", "kind": "decision", "answer_data": [ "record_refs", "disposal_authority_ref", "required_tombstone_fields", "approved_disposal_time" ] }, { "id": "question-retention-3", "text": "What can an as-of reconstruction establish after gaps, corrections or authorized erasure?", "kind": "quality", "answer_data": [ "requested_time", "available_revisions", "missing_intervals", "redactions", "reconstruction_limits" ] }, { "id": "question-retention-4", "text": "How do record corrections preserve lineage without recreating deleted secret or personal payloads?", "kind": "privacy", "answer_data": [ "supersedes_ref", "correction_reason", "evidence_pointer", "payload_disposal_state", "access_scope" ] } ], "data_elements": [ { "id": "data-retention-1", "name": "Retention binding", "description": "Adopting-Dimension policy, purpose and holds; no universal period is asserted.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ] }, { "id": "data-retention-2", "name": "Disposition record", "description": "Authorized local-record deletion and minimal tombstone; physical resource and workload data disposal stay external.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ] }, { "id": "data-retention-3", "name": "Historical view limitations", "description": "Gaps, source expiration, redaction and lawful disposal limitations.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ] }, { "id": "data-retention-4", "name": "Correction lineage", "description": "Revision links and reasons; history does not justify indefinite sensitive-payload storage.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-retention", "name": "Runtime record disposition schedule", "description": "Proposed revisioned evidence view for record retention and historical reconstruction; retain source references, unknowns, redaction status and profile version.", "media_or_form": [ "Structured record", "Human-readable report" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI, then Dimension-assigned UUID or ULID. Revisions retain parent identity and digest; timestamps and filenames are not identity.", "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "function-register-context", "name": "Register an environment record", "description": "Create a local identity record after authority and alias reconciliation. Proposed contract only; not implemented by this research package.", "inputs": [ "Scoped master identifier", "Environment boundary and operator-role references" ], "outputs": [ "Registered environment revision or collision report" ], "preconditions": [ "Authorized local role, purpose, tenant scope and current record revision are validated.", "Resolve referenced identities and evidence availability; refuse on ambiguous incarnation, denied scope or stale concurrency token.", "Applicable profile and retention rules are supplied; secrets are excluded and unknowns remain explicit." ], "effects": [ "Adds only a local record; creates no compute resource.", "Preserve prior permitted revisions, input provenance and refusal reason. General audit-trail storage remains external." ], "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "function-attach-observation", "name": "Attach a runtime observation", "description": "Bind supplied evidence to an environment, resource or occupant without inventing a missing identity. Proposed contract only; not implemented by this research package.", "inputs": [ "Evidence pointer and collector reference", "Scoped subject and event/observation times" ], "outputs": [ "Versioned observation or unresolved binding report" ], "preconditions": [ "Authorized local role, purpose, tenant scope and current record revision are validated.", "Resolve referenced identities and evidence availability; refuse on ambiguous incarnation, denied scope or stale concurrency token.", "Applicable profile and retention rules are supplied; secrets are excluded and unknowns remain explicit." ], "effects": [ "Appends a local assertion; performs no discovery scan or telemetry collection.", "Preserve prior permitted revisions, input provenance and refusal reason. General audit-trail storage remains external." ], "source_refs": [ "SRC-004", "SRC-008", "SRC-009" ] }, { "id": "function-record-occupancy", "name": "Record an occupancy interval", "description": "Represent a supplied placement and incarnation claim, retaining gaps and conflicts. Proposed contract only; not implemented by this research package.", "inputs": [ "Environment and software references", "Runtime incarnation, placement and interval evidence" ], "outputs": [ "Dependent occupancy revision or conflict report" ], "preconditions": [ "Authorized local role, purpose, tenant scope and current record revision are validated.", "Resolve referenced identities and evidence availability; refuse on ambiguous incarnation, denied scope or stale concurrency token.", "Applicable profile and retention rules are supplied; secrets are excluded and unknowns remain explicit." ], "effects": [ "Writes a dependent record; starts, moves or stops no workload.", "Preserve prior permitted revisions, input provenance and refusal reason. General audit-trail storage remains external." ], "source_refs": [ "SRC-002", "SRC-005", "SRC-009" ] }, { "id": "function-compare-configuration", "name": "Compare supplied configuration views", "description": "Proposed local comparison of supplied revisions with explicit covered and unknown paths. Proposed contract only; not implemented by this research package.", "inputs": [ "Baseline and observed snapshot revisions", "Comparator profile, redaction map and authority references" ], "outputs": [ "Scoped difference report with unknown paths or refusal" ], "preconditions": [ "Authorized local role, purpose, tenant scope and current record revision are validated.", "Resolve referenced identities and evidence availability; refuse on ambiguous incarnation, denied scope or stale concurrency token.", "Applicable profile and retention rules are supplied; secrets are excluded and unknowns remain explicit." ], "effects": [ "Produces a proposed local report; approves, patches and remediates nothing.", "Preserve prior permitted revisions, input provenance and refusal reason. General audit-trail storage remains external." ], "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "function-prepare-projection", "name": "Prepare a scoped projection", "description": "Propose a local export using a named mapping and recipient disclosure policy. Proposed contract only; not implemented by this research package.", "inputs": [ "Runtime record revision", "Mapping profile and permitted recipient scope" ], "outputs": [ "Local projected view and loss report or refusal" ], "preconditions": [ "Authorized local role, purpose, tenant scope and current record revision are validated.", "Resolve referenced identities and evidence availability; refuse on ambiguous incarnation, denied scope or stale concurrency token.", "Applicable profile and retention rules are supplied; secrets are excluded and unknowns remain explicit." ], "effects": [ "Creates a local artifact only; no external transmission or target mutation.", "Preserve prior permitted revisions, input provenance and refusal reason. General audit-trail storage remains external." ], "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] }, { "id": "function-record-retirement", "name": "Record retirement evidence", "description": "Distinguish intent from externally evidenced completion and retain unknown effects. Proposed contract only; not implemented by this research package.", "inputs": [ "Subject incarnation and approval reference", "Completion evidence, dependent references and retention policy" ], "outputs": [ "Retirement evidence revision or unresolved-effects report" ], "preconditions": [ "Authorized local role, purpose, tenant scope and current record revision are validated.", "Resolve referenced identities and evidence availability; refuse on ambiguous incarnation, denied scope or stale concurrency token.", "Applicable profile and retention rules are supplied; secrets are excluded and unknowns remain explicit." ], "effects": [ "Changes only local evidence state; destroys no resource and terminates no execution.", "Preserve prior permitted revisions, input provenance and refusal reason. General audit-trail storage remains external." ], "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] }, { "id": "function-prepare-history", "name": "Reconstruct a bounded historical view", "description": "Propose an as-of view from permitted revisions and explicitly report missing evidence. Proposed contract only; not implemented by this research package.", "inputs": [ "Environment identity and requested interval", "Authorized revision set and disclosure policy" ], "outputs": [ "Local historical view with gaps and uncertainty or refusal" ], "preconditions": [ "Authorized local role, purpose, tenant scope and current record revision are validated.", "Resolve referenced identities and evidence availability; refuse on ambiguous incarnation, denied scope or stale concurrency token.", "Applicable profile and retention rules are supplied; secrets are excluded and unknowns remain explicit." ], "effects": [ "Reads permitted records and emits a local view; does not recover erased payloads or claim a complete past.", "Preserve prior permitted revisions, input provenance and refusal reason. General audit-trail storage remains external." ], "source_refs": [ "SRC-008", "SRC-009" ] } ], "composition": [ { "target": "WM-SFT-002", "relation": "REFERENCE", "purpose": "Reference logical software and application identity, ownership and product lifecycle; occupant records never become independent software masters. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "target": "WM-SFT-009", "relation": "REFERENCE", "purpose": "Reference deployment occurrences for creation or change evidence; deployment plan, approval, execution and outcome remain deployment-owned. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "target": "WM-XCT-039", "relation": "REFERENCE", "purpose": "Reference tenant mastership and bounded impact projections; this model records runtime topology assertions, not managed-service graph evaluation or cross-tenant impact propagation. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.", "required": false, "source_refs": [ "SRC-003", "SRC-010" ] }, { "target": "WM-OBJ-001", "relation": "REFERENCE", "purpose": "Reference underlying physical item when applicable; runtime resource identity and CI designation do not duplicate physical identity, custody, ownership or asset lifecycle. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] }, { "target": "WM-SFT-018", "relation": "REFERENCE", "purpose": "Incoming hosting links can identify this runtime context; endpoint identity, contract and endpoint lifecycle remain external. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.", "required": false, "source_refs": [ "SRC-003", "SRC-010" ] }, { "target": "WM-SFT-015", "relation": "REFERENCE", "purpose": "Incoming execution links identify where an execution occurred; task execution state, scheduling and execution effects remain external. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "target": "https://github.com/opencontainers/runtime-spec/blob/v1.2.0/runtime.md", "relation": "ALIGN", "purpose": "Container-profile state and ID alignment only; no universal lifecycle or conformance claim.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "https://opentelemetry.io/docs/specs/otel/resource/sdk/", "relation": "ALIGN", "purpose": "Telemetry resource projection only; schema URLs and conflict/loss reports are required.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "https://www.w3.org/TR/prov-o/", "relation": "ALIGN", "purpose": "Attribution and revision vocabulary alignment; no truth or authority inference.", "required": false, "source_refs": [ "SRC-008" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "An adopting Dimension assigns environment steward, runtime operator, configuration approver and evidence reviewer roles using role references.", "Declare master authorities, environment granularity, tenant scope and resource/occupant incarnation rules before merging records.", "Supply access, evidence freshness, retention, exception and external controller policies; source standards do not substitute for local authority.", "Pin lifecycle, quantity, topology and projection profiles with neighbor model versions." ], "namespace_guidance": "Use an adopting-Dimension namespace plus scoped master IDs. Separate environment, resource, occupancy and CI-designation types; do not merge by hostname, address, label or timestamp.", "registry_links": [ "vr.wm-sft-010", "WM-SFT-002", "WM-SFT-009", "WM-XCT-039", "WM-OBJ-001", "WM-SFT-015", "WM-SFT-018" ] }, "canon_and_patch": { "canonicalization_rules": [ "Normalize references and quantity units with loss reporting; preserve source values, authority and observation times.", "Separate desired, approved, observed and inferred assertions. Conflicting scope or incarnation remains unresolved.", "This package is reviewable-draft and noncanonical; local normalization does not promote its assurance state." ], "patch_rules": [ "Use explicit base revision, author role, changed paths, evidence and reason; reject concurrent stale writes.", "Append corrections and supersession links. Rebaseline only with external approval evidence; retain prior approved versions subject to retention." ], "compatibility_rules": [ "Namespace or incarnation changes require explicit migration, never silent relabeling.", "Breaking field, state or quantity mappings require a new profile version and fixture review. Optional object groups are not executable nested instance schemas." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier scoped to authority and incarnation", "Governed global identifier or IRI", "Dimension-assigned UUID or ULID" ], "timestamp_rule": "Use RFC 3339 with seconds and an explicit offset or Z. Distinguish event time, observation time and ingestion time; keep uncertainty and unknown values, and never use a date as identity.", "serial_naming_rule": "A serial artifact name includes subject ID, artifact kind and revision; a timestamp may assist discovery but cannot replace stable identity.", "integrity_rule": "Record digest, media type, provenance and access scope. A matching digest proves byte consistency, not identity truth, security or completeness; never hash and publish secret payloads as a substitute for redaction." }, "policies": [ "No secret values, credentials or workload business payloads are admitted to runtime evidence; use governed references and restricted views.", "Tenant separation, field disclosure and freshness rules apply to every read and projection, including derived views.", "Compute provisioning, scaling, patching, termination, deployment approval and access enforcement require the external authority and controller; this package implements none of them.", "Unknown is distinct from zero, absent, stopped, unrestricted, unsupported and noncompliant. Absence in an incomplete inventory is not deletion evidence.", "Hardware measurements, workload data protection, sector regulation, residency and service guarantees require qualified profiles and external evidence." ], "crud": { "read": [ "Authorize tenant, purpose and field scope; show revision, evidence freshness, unresolved identities and disclosure omissions.", "Do not turn an as-of view into a complete historical claim when observations or retained records are missing." ], "create": [ "Require scoped environment identity, granularity and source authority; create dependent occupant records only within an identified context.", "Local record creation does not provision resources or confer operating authority." ], "update": [ "Use revision preconditions and typed patches with evidence. Preserve conflicts and old permitted views; do not overwrite master-owned neighbor facts.", "A baseline update requires the external approval reference and effective interval; desired state alone is insufficient." ], "delete": [ "Retire local records with a reason, policy, authority and minimal permitted tombstone; apply retention periods, legal holds and approved payload deletion.", "Adopting-Dimension records policy owns local disposition execution. Runtime controllers own compute destruction and occupant termination; physical-item and data masters own their own disposal.", "Retain reference continuity only where authorized. Do not recreate erased sensitive values from historical artifacts." ] }, "roles": [ { "name": "Environment steward", "responsibilities": [ "Resolve scoped master identities, granularity and record quality." ] }, { "name": "Runtime operator", "responsibilities": [ "Supply controller evidence and resource observations under delegated authority." ] }, { "name": "Configuration approver", "responsibilities": [ "Provide approved baseline and exception references; local records cannot grant this authority." ] }, { "name": "Evidence reviewer", "responsibilities": [ "Challenge stale observations, ambiguity, mapping loss and unsupported conformance." ] }, { "name": "Records custodian", "responsibilities": [ "Apply disclosure, retention, erasure and tombstone rules to local evidence." ] } ], "access": { "default_rule": "Deny unless a scoped role and purpose authorize the tenant, subject and field. Redact sensitive topology and external pointers whose disclosure is restricted.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency access requires an externally authorized, time-limited exception and subsequent review; it cannot silently broaden all tenant scopes." ], "audit_requirements": [ "Reference the external access or change decision with role, purpose, subject, revision, time, result and policy; this model does not own a general audit engine.", "Log disclosure and denied projection outcomes without recording secret payloads." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read adopting-Dimension authority and AGENTS.md", "Read spec.yaml and all review holds", "Resolve scoped master identities and pinned neighbor profiles", "Inspect evidence, freshness and access before proposing local changes" ] } }, "coverage": { "claim": "Source-grounded proposed core for one managed runtime environment, its resource references, dependent occupancy and configuration evidence. Separate local no-tools self-audit completed with no critical conflict. Independent review, direct source and version verification, specialist platform profiles and executable conformance remain holds; this is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Scoped environment identity and resource/occupant incarnations; aliases cannot merge masters." }, { "dimension": "lifecycle", "status": "covered", "notes": "Separate subject states, observations, retirement intent and external completion." }, { "dimension": "relationships", "status": "covered", "notes": "All frozen ledger boundaries reconciled; incoming endpoint/execution references preserve external masters." }, { "dimension": "temporal", "status": "covered", "notes": "Occupancy and topology intervals separate event, observation and ingestion times." }, { "dimension": "provenance", "status": "covered", "notes": "Attribution, evidence pointers, digests, corrections and conflicting assertions." }, { "dimension": "ownership", "status": "covered", "notes": "Accountable roles and authority references; no named company owner." }, { "dimension": "validation", "status": "covered", "notes": "Research structure validation only; nested instance and platform conformance remain gaps." }, { "dimension": "access", "status": "covered", "notes": "Tenant, purpose and field scope with secret exclusion and exceptional authority references." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Policy-based local record disposition separate from compute or data destruction." }, { "dimension": "interoperability", "status": "covered", "notes": "Conceptual OCI, telemetry and provenance mappings with explicit loss; executable mappings pending." }, { "dimension": "direct properties", "status": "covered", "notes": "Compute capacity and configuration are meaningful; physical asset measurements are delegated." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Evidence-based identity correlation and stale or incomplete inventory handling." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Declared support, preconditions, observed evidence and external-effect limits are separate." }, { "dimension": "specialist platforms", "status": "gap", "notes": "Detailed VM, serverless, accelerator, edge and embedded platform schemas and fixtures remain unresearched." }, { "dimension": "security assurance", "status": "gap", "notes": "Isolation and maintenance evidence are structured; no penetration test, certification or current support-status verification." }, { "dimension": "independent review", "status": "gap", "notes": "Codex only; external providers skipped by owner override and no second-provider agreement claimed." } ], "known_omissions": [ "Nested executable instance schemas, interval overlap rules and unit-aware acceptance fixtures are not implemented.", "Virtual-machine, serverless, accelerators, edge and embedded profiles need deeper primary research and integration tests.", "Runtime disaster recovery, billing and energy accounting are external concerns; only recovery evidence references are represented.", "Direct source HTTP status and body hashes are unmeasured locally; rolling source versions and deployed-platform applicability require coordinator review.", "Independent external review is absent under the owner-authorized waiver." ], "conflicts": [], "regional_assumptions": [ "No universal legal or residency requirement is inferred. NIST guidance retains its stated federal context; adopting environments must supply applicable local policies.", "Container documentation supplies examples and distinctions, not mandatory semantics for every compute platform." ], "adversarial_checks": [ "Reused host or container IDs must create new incarnation bindings rather than inherit prior occupants.", "Missing telemetry must not become zero usage, deletion, successful isolation or a stopped workload.", "A desired baseline or scheduled placement must not be promoted to approved or observed state.", "A namespace, label or shared-node boundary must not be treated as isolation proof.", "Local record retirement must not imply resource destruction, tenant graph propagation or workload-data erasure.", "An unreviewed supplement, source digest or local self-audit must not be described as independent validation." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The root retains environment identity at an explicit granularity across resource and occupant changes. Resource references, time-bounded memberships and dependent occupant records do not require an aggregate or universal service-graph root. The registry standalone-mm value classifies the registry record plane, while its REFERENCE ledger preserves neighboring masters." }, "decisions": [ { "concept": "Environment granularity and identity", "disposition": "accepted with profile requirement", "rationale": "Host, cluster, pool and managed-service contexts require explicit granularity and authority. The identity finding prevents silent alias merges and distinguishes resource replacement from environment continuity." }, { "concept": "Resource and physical-item boundary", "disposition": "accepted", "rationale": "Temporal resource membership and runtime identity are local facts; physical custody, ownership and asset lifecycle remain with the referenced physical-item master. CI designation does not create an underlying object master." }, { "concept": "Software and dependent occupants", "disposition": "accepted", "rationale": "Occupancy binds environment, resource and runtime incarnation to software references. Missing software identity stays unresolved instead of becoming an invented master. Requested, scheduled and observed placement remain separate." }, { "concept": "Runtime identifier reuse and continuity", "disposition": "accepted", "rationale": "The scoped identity and incarnation contract prevents reused IDs or names from inheriting earlier occupants. Restarts, replacements, unknown end times and never-started placement remain distinguishable." }, { "concept": "State and health assertions", "disposition": "accepted", "rationale": "Subject-scoped lifecycle states are not conflated with readiness, liveness or reachability. Stale heartbeats and collection gaps cannot establish termination or destruction." }, { "concept": "Capacity and direct properties", "disposition": "supplement claim rejected", "rationale": "The supplement's blanket not-applicable property claim is too broad. Compute quantities and configuration are meaningful properties, with units, scope and evidence. Physical measurements remain delegated; estimated headroom is not a scheduling guarantee." }, { "concept": "Baseline, drift and maintenance", "disposition": "qualified", "rationale": "Approved baseline, desired declarations and observations are separate. A difference is not an unauthorized-change verdict, and a component version is not proof of patch adequacy or support status. Version-specific evidence is required." }, { "concept": "Tenancy and managed-service projection ownership", "disposition": "accepted", "rationale": "Isolation declarations require evidence and preserve control-plane and data-plane distinctions. Runtime topology assertions do not take over tenant mastership, graph evaluation, impact propagation or enforcement." }, { "concept": "Direction of candidate integration links", "disposition": "qualified", "rationale": "Outgoing ledger references preserve all target-owned concepts. Optional references back to execution and endpoint context document local integration needs only; the boundary memo explicitly does not ratify reciprocal registry edges or alter the frozen ledger." }, { "concept": "Proposed local operations and authority", "disposition": "accepted as unimplemented contracts", "rationale": "All seven functions declare role, scope, revision and evidence preconditions and refusal outcomes. Their effects are limited to local records and views. No provisioning, deployment, scheduling, scanning, external transmission or resource destruction occurs." }, { "concept": "Observation and telemetry provenance", "disposition": "accepted with limits", "rationale": "Telemetry attributes and schema URLs support evidence reconciliation, not authoritative master selection. SDK resource immutability is not environment immutability. Digests, attribution and local validation cannot establish factual truth or security certification." }, { "concept": "Retirement and retained history", "disposition": "accepted with policy dependency", "rationale": "Local record retirement, actual compute effects and underlying data disposal remain distinct. Retention and authorized erasure limit historical reconstruction, so lineage is not a justification for perpetual sensitive-payload storage." }, { "concept": "Candidate fields and executable conformance", "disposition": "deferred", "rationale": "Optional candidate field groups express research context but cannot enforce complete instances, interval rules, unit semantics or platform mappings. Fixtures and nested schemas remain explicit holds, not completed implementation." }, { "concept": "Source access and platform coverage", "disposition": "limited", "rationale": "The pack records ten browser text readings and selected primary sections, including an abstract-only cloud source. Direct HTTP checks were not attempted and no status was measured. Rolling versions, licenses and deployed-platform applicability remain unresolved; specialist platforms are acknowledged gaps." }, { "concept": "Provider waiver and local audit assurance", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the explicit owner override. This separate no-tools phase is a Codex self-audit of frozen evidence; it is not independent external review or provider agreement." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not a second-provider review.", "Direct source HTTP and immutable body verification are pending. No direct requests were attempted in the blocked sandbox and no HTTP status was measured. Ten source pages yielded browser text; selected-section access, rolling version pins, licensing and deployed-platform applicability need coordinator verification using check_sources.py and substantive source review.", "Specialist virtual-machine, serverless, accelerator, edge and embedded profiles, support and maintenance applicability, isolation assurance, data residency and sector policy require qualified primary-source review before operational use.", "Nested instance schemas, pinned neighbor bindings, interval and quantity constraints, executable runtime and telemetry mappings, and adversarial fixtures remain incomplete. All seven local functions are proposed contracts only; no runtime, security or interoperability certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Run the coordinator source checker outside the sandbox, pin applicable source versions and record source-to-claim and license dispositions without treating HTTP success as semantic verification.", "Develop nested instance profiles and fixtures covering reused IDs, overlapping occupancy, unknown bounds, stale telemetry, conflicting baselines, shared resources, tenant isolation and lawful erasure.", "Research specialist compute platforms and test loss-aware mappings against actual deployed versions and pinned neighbor models.", "Restore independent external review before any canonical or publishable-draft promotion." ] }, "statistics": { "sources": 10, "bundles": 7, "layers": 14, "findings": 14, "questions": 56, "artifacts": 14, "functions": 7 } }