# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T12:29:09Z", "synthesisSha256": "f73987c0135bb453d11922fef09622fd99070c93d48379f8c986f4687ab2f9d7", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-SFT-011", "registryId": "vr.wm-sft-011", "name": "Software Configuration", "version": "0.1.0", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.SFT.CFG" ], "tags": [ "software", "configuration", "inf.sft.cfg" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-sft-011-software-configuration/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-011", "model": { "registry_id": "vr.wm-sft-011", "model_id": "WM-SFT-011", "name": "Software Configuration", "entry_kind": "entity", "purpose": "Describe a governed software configuration and its revisions, desired settings, references and version scope, with evidence of validation and adoption.", "scope_statement": "One logical desired-configuration entity with stable master identity and separately identified revisions. It can be draft, approved, superseded or retired. Its declared content, resolved projection and externally observed application are distinct assertions. The proposed model records evidence and local review operations; it does not apply settings to a running system.", "in_scope": [ "Configuration identity, target/version/environment scope and typed setting declarations", "Resolution provenance, external resource and secret references, and optional dynamic flag bindings", "Revision lineage, approval and validation references, consumption expectations, drift assessment and retirement of configuration records" ], "out_of_scope": [ "Software source, package, release, deployment, runtime and telemetry master records", "Secret payload storage, secret retrieval, credential rotation and permission grants", "Production changes, remote evaluation, rollout execution, runtime remediation and automatic rollback", "A universal configuration management database, executable template language or full security baseline catalogue" ], "boundary_notes": [ { "neighbor": "WM-SFT-002 Software System / Business Application", "distinction": "Registry parent identifies the target domain. Configuration references a separately mastered system; the parent does not imply that configuration inherits its business lifecycle.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "WM-SFT-007 Software Component / Package and WM-SFT-008 Build / Release", "distinction": "Version selectors and pinned release references constrain applicability. Configuration content is not executable code, a build or a release manifest.", "source_refs": [ "SRC-002", "SRC-003" ] }, { "neighbor": "WM-SFT-009 Deployment and WM-SFT-010 Runtime / Compute Environment", "distinction": "Deployment owns application attempts and runtime owns environment identity. A local approved revision cannot establish activation or full adoption.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "neighbor": "WM-SFT-013 Software Change / Pull Request and WM-SFT-015 Test Case / Test Result", "distinction": "Reference change authorization and test evidence without copying workflow or test execution semantics into configuration.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "neighbor": "WM-SFT-017 Telemetry / Operational Signal and external secret or flag services", "distinction": "Configuration stores scoped evidence links and protected bindings. Observation, secret lifecycle and flag evaluation retain separate authorities.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Guide for Security-Focused Configuration Management of Information Systems", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-128.pdf", "version_or_date": "SP 800-128, August 2011, updates 2019-10-10", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:24Z", "relevance": "Sections 2.3.7, 2.3.8 and 3.3-3.4 inform baseline approval, controlled changes and monitoring. Federal security guidance is an alignment, not a universal software configuration schema." }, { "id": "SRC-002", "title": "ConfigMaps", "organization": "Kubernetes project", "url": "https://kubernetes.io/docs/concepts/configuration/configmap/", "version_or_date": "Rolling documentation accessed 2026-10-06; release pin unresolved", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:27:24Z", "relevance": "Motivation, consumption methods and mounted update sections demonstrate code/configuration separation and differing propagation behavior. Kubernetes details are profile examples only." }, { "id": "SRC-003", "title": "JSON Schema Validation: A Vocabulary for Structural Validation of JSON", "organization": "JSON Schema project", "url": "https://json-schema.org/draft/2020-12/json-schema-validation", "version_or_date": "Draft 2020-12", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:27:24Z", "relevance": "Sections 3, 6, 7 and 9 distinguish assertions, types, annotations and default metadata. A validation result is bounded by schema and vocabulary; it cannot establish operational safety." }, { "id": "SRC-004", "title": "Network Configuration Protocol (NETCONF)", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc6241", "version_or_date": "RFC 6241, June 2011", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:24Z", "relevance": "Sections 8.3-8.4 distinguish candidate editing, commit, concurrency and capability-dependent confirmed commit. These are network protocol examples, not universal transaction guarantees." }, { "id": "SRC-005", "title": "Network Management Datastore Architecture (NMDA)", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc8342.html", "version_or_date": "RFC 8342, March 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:24Z", "relevance": "Sections 3 and 5 distinguish intended, transformed, dynamic and operational configuration. Conceptual alignment informs provenance and observation boundaries, not a claim to implement NMDA." }, { "id": "SRC-006", "title": "Flag Evaluation API", "organization": "OpenFeature project", "url": "https://openfeature.dev/specification/sections/flag-evaluation/", "version_or_date": "Rolling specification accessed 2026-10-06; immutable release pin unresolved", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:27:24Z", "relevance": "Sections 1.3-1.4 distinguish typed evaluation, fallback defaults, evaluation context and best-effort details. This model references flag behavior and evidence; it does not own the evaluator." }, { "id": "SRC-007", "title": "Secrets", "organization": "Kubernetes project", "url": "https://kubernetes.io/docs/concepts/configuration/secret/", "version_or_date": "Rolling documentation accessed 2026-10-06; release pin unresolved", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:27:24Z", "relevance": "Introductory cautions and access recommendations support separate confidential storage and least privilege. A secret reference does not prove encryption or authorize retrieval." }, { "id": "SRC-008", "title": "JavaScript Object Notation (JSON) Patch", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc6902.html", "version_or_date": "RFC 6902, April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:27:24Z", "relevance": "Sections 3-5 define ordered edits, explicit operations and failure behavior for one JSON representation. Semantic configuration merging and external transactionality require separate profiles." } ], "structure": { "bundles": [ { "id": "bundle-scope", "name": "Identity and scope", "description": "Identify the logical configuration and bound software applicability.", "rationale": "This concern has distinct evidence and decisions within the desired-configuration boundary.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "layers": [ { "id": "layer-identity", "name": "Configuration identity", "description": "A logical configuration retains identity across revisions; paths and display names are aliases scoped to an authoritative namespace.", "source_refs": [ "SRC-001", "SRC-002" ], "findings": [ { "id": "finding-identity", "name": "Configuration identity", "description": "A logical configuration retains identity across revisions; paths and display names are aliases scoped to an authoritative namespace.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "question-identity-1", "text": "Which master identifier distinguishes this configuration from similarly named configurations?", "kind": "identity", "answer_data": [ "master system", "namespace", "configuration identifier", "aliases" ] }, { "id": "question-identity-2", "text": "Is this record a reusable declaration, a target-specific revision or a resolved projection?", "kind": "classification", "answer_data": [ "representation kind", "logical parent", "revision reference" ] }, { "id": "question-identity-3", "text": "Which role maintains the authoritative declaration and resolves competing copies?", "kind": "ownership", "answer_data": [ "steward role", "authority policy reference", "conflict route" ] } ], "data_elements": [ { "id": "data-identity-master-reference", "name": "Master reference", "value_kind": "identifier", "cardinality": "1", "required": true, "description": "Authority namespace and stable configuration identity; never a date or display name alone.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "data-identity-revision-reference", "name": "Revision reference", "value_kind": "reference", "cardinality": "0..1", "required": false, "description": "Explicit revision binding; absent for an unversioned logical envelope.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "artifact-identity", "name": "Identity and alias record", "description": "Proposed evidence artifact for configuration identity. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-scope", "name": "Target and applicability", "description": "Each revision declares a target selector and compatibility scope. Environment labels alone do not identify a runtime, and an untested version range remains an assertion.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "findings": [ { "id": "finding-scope", "name": "Target and applicability", "description": "Each revision declares a target selector and compatibility scope. Environment labels alone do not identify a runtime, and an untested version range remains an assertion.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "questions": [ { "id": "question-scope-1", "text": "Which software or component identities and version selectors does this revision target?", "kind": "relationship", "answer_data": [ "target references", "selector syntax", "resolved version pins" ] }, { "id": "question-scope-2", "text": "Which environment, tenant or region constraints limit applicability?", "kind": "spatial", "answer_data": [ "environment master reference", "tenant scope", "logical region selector", "exclusions" ] }, { "id": "question-scope-3", "text": "What evidence supports the declared compatibility range and its exceptions?", "kind": "constraint", "answer_data": [ "compatibility evidence reference", "tested versions", "unknown ranges", "exception basis" ] } ], "data_elements": [ { "id": "data-scope-target-bindings", "name": "Target bindings", "value_kind": "collection", "cardinality": "1..n", "required": true, "description": "Master references with version selector syntax, environment and exclusions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "data-scope-compatibility-evidence", "name": "Compatibility evidence", "value_kind": "reference", "cardinality": "0..n", "required": false, "description": "Evidence records supporting each scope claim, with uncertainty retained.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-scope", "name": "Applicability manifest", "description": "Proposed evidence artifact for target and applicability. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-content", "name": "Content and resolution", "description": "Declare setting semantics and the provenance of derived projections.", "rationale": "This concern has distinct evidence and decisions within the desired-configuration boundary.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-008" ], "layers": [ { "id": "layer-values", "name": "Typed setting declarations", "description": "Settings preserve typed values and the distinctions between absence, explicit null, empty content and defaults. Constraints are profile-defined; a schema default is not proof of a runtime value.", "source_refs": [ "SRC-002", "SRC-003" ], "findings": [ { "id": "finding-values", "name": "Typed setting declarations", "description": "Settings preserve typed values and the distinctions between absence, explicit null, empty content and defaults. Constraints are profile-defined; a schema default is not proof of a runtime value.", "source_refs": [ "SRC-002", "SRC-003" ], "questions": [ { "id": "question-values-1", "text": "Which setting keys, types and semantic units does this revision declare?", "kind": "definition", "answer_data": [ "key path", "value type", "allowed unit", "meaning", "sensitivity" ] }, { "id": "question-values-2", "text": "Which keys are required and which constraints or cross-field rules apply?", "kind": "requirement", "answer_data": [ "schema identifier", "dialect", "required keys", "bounds", "dependent constraints" ] }, { "id": "question-values-3", "text": "How are absent, null, empty and defaulted values distinguished in this profile?", "kind": "state", "answer_data": [ "presence marker", "explicit value", "default source", "consumer interpretation" ] } ], "data_elements": [ { "id": "data-values-setting-entries", "name": "Setting entries", "value_kind": "collection", "cardinality": "0..n", "required": false, "description": "Key, typed value or protected reference, presence marker, semantic unit and sensitivity; empty declarations are allowed if meaningful.", "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "data-values-schema-binding", "name": "Schema binding", "value_kind": "reference", "cardinality": "0..1", "required": false, "description": "Pinned schema and dialect; missing schema means validation is incomplete.", "source_refs": [ "SRC-002", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-values", "name": "Setting declaration", "description": "Proposed evidence artifact for typed setting declarations. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-002", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-resolution", "name": "Resolution and precedence", "description": "A derived projection records ordered inputs, declared precedence and transformation provenance. No universal merge order is inferred; executable templates are delegated to an authorized external engine.", "source_refs": [ "SRC-005", "SRC-008" ], "findings": [ { "id": "finding-resolution", "name": "Resolution and precedence", "description": "A derived projection records ordered inputs, declared precedence and transformation provenance. No universal merge order is inferred; executable templates are delegated to an authorized external engine.", "source_refs": [ "SRC-005", "SRC-008" ], "questions": [ { "id": "question-resolution-1", "text": "Which pinned inputs contribute to the resolved configuration?", "kind": "composition", "answer_data": [ "base revision", "overlays", "includes", "input digests", "resolver reference" ] }, { "id": "question-resolution-2", "text": "What explicit precedence and merge rules select each winning value?", "kind": "process", "answer_data": [ "ordered inputs", "key provenance", "array behavior", "conflict policy" ] }, { "id": "question-resolution-3", "text": "How are cycles, unresolved references and conflicting transformations reported?", "kind": "exception", "answer_data": [ "resolution status", "cycle path", "unresolved key", "conflict evidence", "refusal reason" ] } ], "data_elements": [ { "id": "data-resolution-resolution-inputs", "name": "Resolution inputs", "value_kind": "collection", "cardinality": "0..n", "required": false, "description": "Ordered pinned inputs and resolver version; distinguish replace, merge and delete.", "source_refs": [ "SRC-005", "SRC-008" ] }, { "id": "data-resolution-resolution-result", "name": "Resolution result", "value_kind": "object", "cardinality": "0..1", "required": false, "description": "Projection reference, per-key origin, completeness and unresolved conflicts; no embedded executable code.", "source_refs": [ "SRC-005", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-resolution", "name": "Resolution provenance report", "description": "Proposed evidence artifact for resolution and precedence. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-005", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-bindings", "name": "Protected and dynamic bindings", "description": "Control external references and optional feature-setting context.", "rationale": "This concern has distinct evidence and decisions within the desired-configuration boundary.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-references", "name": "Protected resource references", "description": "Confidential payloads remain in separate authorities. This model records protected identifiers and binding requirements; a reference does not confer access and can itself be sensitive.", "source_refs": [ "SRC-002", "SRC-007" ], "findings": [ { "id": "finding-references", "name": "Protected resource references", "description": "Confidential payloads remain in separate authorities. This model records protected identifiers and binding requirements; a reference does not confer access and can itself be sensitive.", "source_refs": [ "SRC-002", "SRC-007" ], "questions": [ { "id": "question-references-1", "text": "Which settings require protected references instead of inline confidential values?", "kind": "security", "answer_data": [ "key classification", "external store identifier", "redaction policy" ] }, { "id": "question-references-2", "text": "Which subject is authorized to resolve each reference for the intended target?", "kind": "access", "answer_data": [ "principal reference", "policy reference", "environment scope", "no secret payload" ] }, { "id": "question-references-3", "text": "How are mutable references, rotation and expiry reflected in reproducibility evidence?", "kind": "temporal", "answer_data": [ "version selector", "resolution observation time", "expiry metadata", "unknown binding state" ] } ], "data_elements": [ { "id": "data-references-resource-references", "name": "Resource references", "value_kind": "collection", "cardinality": "0..n", "required": false, "description": "External resource identity, target binding and optional immutable version, with protected metadata.", "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "data-references-resolution-authority", "name": "Resolution authority", "value_kind": "reference", "cardinality": "0..n", "required": false, "description": "Policy and principal references only; never credentials or access grants.", "source_refs": [ "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-references", "name": "Redacted binding manifest", "description": "Proposed evidence artifact for protected resource references. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-flags", "name": "Dynamic feature settings", "description": "Optional flag bindings describe evaluation inputs and fallbacks. A stored flag declaration is not a universal boolean outcome; evaluator behavior and individual results remain external.", "source_refs": [ "SRC-006" ], "findings": [ { "id": "finding-flags", "name": "Dynamic feature settings", "description": "Optional flag bindings describe evaluation inputs and fallbacks. A stored flag declaration is not a universal boolean outcome; evaluator behavior and individual results remain external.", "source_refs": [ "SRC-006" ], "questions": [ { "id": "question-flags-1", "text": "Which flag keys, value types and fallback values are bound to this configuration?", "kind": "definition", "answer_data": [ "flag key", "expected type", "fallback", "provider reference" ] }, { "id": "question-flags-2", "text": "Which evaluation context categories are necessary and how are personal values minimized?", "kind": "privacy", "answer_data": [ "context schema reference", "permitted categories", "retention policy", "redaction rules" ] }, { "id": "question-flags-3", "text": "What evidence distinguishes a configured fallback from a successful evaluated result?", "kind": "evidence", "answer_data": [ "result reference", "evaluation reason if available", "error state", "observation time", "unknown metadata" ] } ], "data_elements": [ { "id": "data-flags-flag-bindings", "name": "Flag bindings", "value_kind": "collection", "cardinality": "0..n", "required": false, "description": "Flag keys, expected types, fallback values and external evaluator reference.", "source_refs": [ "SRC-006" ] }, { "id": "data-flags-context-policy", "name": "Context policy", "value_kind": "reference", "cardinality": "0..1", "required": false, "description": "Permitted context categories and privacy policy; no individual targeting records are required here.", "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "artifact-flags", "name": "Flag binding profile", "description": "Proposed evidence artifact for dynamic feature settings. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance", "name": "Revision assurance", "description": "Separate change authority from evidence of validation.", "rationale": "This concern has distinct evidence and decisions within the desired-configuration boundary.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008" ], "layers": [ { "id": "layer-revisions", "name": "Revisions and change authority", "description": "Local revisions preserve predecessor and review evidence. Approval, change authorization and activation are separate states, and concurrent changes require an explicit base revision.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "findings": [ { "id": "finding-revisions", "name": "Revisions and change authority", "description": "Local revisions preserve predecessor and review evidence. Approval, change authorization and activation are separate states, and concurrent changes require an explicit base revision.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ], "questions": [ { "id": "question-revisions-1", "text": "Which predecessor, author role and change record explain this revision?", "kind": "provenance", "answer_data": [ "predecessor reference", "author role", "change reference", "reason", "content digest" ] }, { "id": "question-revisions-2", "text": "What approval scope and evidence authorize this revision for its intended use?", "kind": "authority", "answer_data": [ "approval reference", "approving role", "target scope", "expiry", "pending or rejected state" ] }, { "id": "question-revisions-3", "text": "Which base revision and conflict result were recorded when edits were proposed?", "kind": "event", "answer_data": [ "expected base", "observed base", "patch reference", "conflict status", "proposal time" ] } ], "data_elements": [ { "id": "data-revisions-revision-lineage", "name": "Revision lineage", "value_kind": "object", "cardinality": "1", "required": true, "description": "Stable revision identity, predecessor and content digest with author and change provenance.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] }, { "id": "data-revisions-approval-evidence", "name": "Approval evidence", "value_kind": "reference", "cardinality": "0..n", "required": false, "description": "Separately mastered review or approval records; absence never implies approval.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-revisions", "name": "Revision and review record", "description": "Proposed evidence artifact for revisions and change authority. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-001", "SRC-004", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-validation", "name": "Validation evidence", "description": "Validation is scoped to the exact revision, schema, profile and validator. Syntactic success cannot prove safe behavior, compatibility, security or deployment success.", "source_refs": [ "SRC-001", "SRC-003" ], "findings": [ { "id": "finding-validation", "name": "Validation evidence", "description": "Validation is scoped to the exact revision, schema, profile and validator. Syntactic success cannot prove safe behavior, compatibility, security or deployment success.", "source_refs": [ "SRC-001", "SRC-003" ], "questions": [ { "id": "question-validation-1", "text": "Which schema, dialect, validator and profile were used for this revision?", "kind": "validation", "answer_data": [ "revision digest", "schema pin", "dialect", "validator version", "assertion options" ] }, { "id": "question-validation-2", "text": "Which checks passed, failed, were skipped or remain unknown?", "kind": "quality", "answer_data": [ "check identifier", "result state", "diagnostics", "test evidence reference", "limitations" ] }, { "id": "question-validation-3", "text": "What security-impact review covers access, logging and data-handling changes?", "kind": "security", "answer_data": [ "impact review reference", "affected controls", "reviewer role", "exception expiry" ] } ], "data_elements": [ { "id": "data-validation-validation-evidence", "name": "Validation evidence", "value_kind": "collection", "cardinality": "0..n", "required": false, "description": "Immutable result references bound to revision and tool profile; skipped and unknown states remain explicit.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "data-validation-impact-review", "name": "Impact review", "value_kind": "reference", "cardinality": "0..n", "required": false, "description": "External safety and security review records; this model does not certify compliance.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-validation", "name": "Configuration validation report", "description": "Proposed evidence artifact for validation evidence. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-adoption", "name": "Adoption evidence", "description": "Distinguish intended consumption from scoped observations.", "rationale": "This concern has distinct evidence and decisions within the desired-configuration boundary.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ], "layers": [ { "id": "layer-consumption", "name": "Consumption and activation expectations", "description": "The revision declares how a target is expected to consume it. Actual application is an external event; update, delivery, reload and use must not be collapsed.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-consumption", "name": "Consumption and activation expectations", "description": "The revision declares how a target is expected to consume it. Actual application is an external event; update, delivery, reload and use must not be collapsed.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ], "questions": [ { "id": "question-consumption-1", "text": "How is each target expected to consume the revision and notice changes?", "kind": "process", "answer_data": [ "binding method", "reload or restart requirement", "propagation expectation", "capability reference" ] }, { "id": "question-consumption-2", "text": "Which intended effective interval and external application evidence are associated with this revision?", "kind": "temporal", "answer_data": [ "intended start and end", "deployment reference", "acknowledgement time", "observation time" ] }, { "id": "question-consumption-3", "text": "What partial-application or rejection states must remain visible?", "kind": "exception", "answer_data": [ "target subset", "failed keys", "failure evidence", "pending propagation", "unknown adoption" ] } ], "data_elements": [ { "id": "data-consumption-consumption-profile", "name": "Consumption profile", "value_kind": "object", "cardinality": "0..1", "required": false, "description": "Delivery binding, reload semantics and capability assumptions; no deployment instructions.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "id": "data-consumption-application-evidence", "name": "Application evidence", "value_kind": "reference", "cardinality": "0..n", "required": false, "description": "External application acknowledgements and failures, qualified by target and revision.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-consumption", "name": "Consumption and adoption record", "description": "Proposed evidence artifact for consumption and activation expectations. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-drift", "name": "Observed differences", "description": "A drift assessment compares a specified intended projection with a scoped observation. Stale or partial data, hidden keys and legitimate dynamic values prevent an unconditional equality claim.", "source_refs": [ "SRC-001", "SRC-005" ], "findings": [ { "id": "finding-drift", "name": "Observed differences", "description": "A drift assessment compares a specified intended projection with a scoped observation. Stale or partial data, hidden keys and legitimate dynamic values prevent an unconditional equality claim.", "source_refs": [ "SRC-001", "SRC-005" ], "questions": [ { "id": "question-drift-1", "text": "Which intended projection and observed target snapshot were compared?", "kind": "measurement", "answer_data": [ "projection digest", "snapshot reference", "target identity", "comparison scope" ] }, { "id": "question-drift-2", "text": "How fresh and complete is the observation for the claimed comparison interval?", "kind": "temporal", "answer_data": [ "observed at", "ingested at", "freshness limit", "missing or redacted keys" ] }, { "id": "question-drift-3", "text": "How are differences classified and assigned for review without automatic remediation?", "kind": "decision", "answer_data": [ "difference paths", "origin", "approved deviation reference", "unknown reason", "responsible role" ] } ], "data_elements": [ { "id": "data-drift-comparison-basis", "name": "Comparison basis", "value_kind": "object", "cardinality": "0..1", "required": false, "description": "Pinned intended and observed references, comparison method and completeness.", "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "data-drift-difference-summary", "name": "Difference summary", "value_kind": "collection", "cardinality": "0..n", "required": false, "description": "Redacted differences and interpretation states; observation masters remain external.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-drift", "name": "Drift assessment", "description": "Proposed evidence artifact for observed differences. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-continuity", "name": "Continuity and exchange", "description": "Retire records safely and qualify representation mappings.", "rationale": "This concern has distinct evidence and decisions within the desired-configuration boundary.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-continuity", "name": "Supersession and retirement", "description": "A configuration record can be superseded or retired without changing a running system. Reusing old content requires new compatibility and authority checks; recoverability is not guaranteed.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ], "findings": [ { "id": "finding-continuity", "name": "Supersession and retirement", "description": "A configuration record can be superseded or retired without changing a running system. Reusing old content requires new compatibility and authority checks; recoverability is not guaranteed.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ], "questions": [ { "id": "question-continuity-1", "text": "What state and successor identify whether this revision remains available for new use?", "kind": "lifecycle", "answer_data": [ "draft or approved or superseded or retired", "successor", "reason", "state evidence" ] }, { "id": "question-continuity-2", "text": "Which dependencies and changed references limit reuse of an earlier revision?", "kind": "constraint", "answer_data": [ "target compatibility", "external binding versions", "rollback prerequisites", "unavailable dependencies" ] }, { "id": "question-continuity-3", "text": "Which retention, hold and disposal rules govern configuration evidence and sensitive payloads?", "kind": "retention", "answer_data": [ "retention schedule", "hold reference", "disposal authority", "tombstone", "redaction evidence" ] } ], "data_elements": [ { "id": "data-continuity-continuity-state", "name": "Continuity state", "value_kind": "object", "cardinality": "1", "required": true, "description": "Lifecycle state, successor and retirement evidence independent of operational activation.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] }, { "id": "data-continuity-retention-policy", "name": "Retention policy", "value_kind": "reference", "cardinality": "0..1", "required": false, "description": "Adopting authority rules for history, legal holds and controlled deletion.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-continuity", "name": "Supersession and disposition record", "description": "Proposed evidence artifact for supersession and retirement. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-projection", "name": "Interoperable projections", "description": "Storage syntax is a projection of the subject. Mappings must preserve types, presence, references and intended-versus-observed status; lossy conversion requires an explicit report.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-008" ], "findings": [ { "id": "finding-projection", "name": "Interoperable projections", "description": "Storage syntax is a projection of the subject. Mappings must preserve types, presence, references and intended-versus-observed status; lossy conversion requires an explicit report.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-008" ], "questions": [ { "id": "question-projection-1", "text": "Which mapping profile binds this model to the target representation?", "kind": "interoperability", "answer_data": [ "format and version", "mapping profile", "schema dialect", "external identifiers" ] }, { "id": "question-projection-2", "text": "What round-trip evidence detects lost types, ordering or presence semantics?", "kind": "validation", "answer_data": [ "fixture references", "semantic comparison", "precision handling", "unsupported fields" ] }, { "id": "question-projection-3", "text": "Which limits or losses prevent a projection from being safely accepted?", "kind": "constraint", "answer_data": [ "size or encoding limit", "duplicate keys", "unsupported operation", "loss report", "rejection status" ] } ], "data_elements": [ { "id": "data-projection-mapping-profile", "name": "Mapping profile", "value_kind": "reference", "cardinality": "0..n", "required": false, "description": "Pinned representation bindings and declared loss rules.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-008" ] }, { "id": "data-projection-conversion-evidence", "name": "Conversion evidence", "value_kind": "reference", "cardinality": "0..n", "required": false, "description": "External test and conversion evidence linked to exact revision and profile.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-projection", "name": "Mapping and loss report", "description": "Proposed evidence artifact for interoperable projections. Bind the configuration and revision, scope, author role and evidence references; redact sensitive content.", "media_or_form": [ "Structured record", "Human-readable view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact identifier plus revision; otherwise governed IRI, then owner-assigned UUID or ULID. Digests identify exact bytes, not semantic identity; dates are metadata.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "function-propose-revision", "name": "Propose a local revision", "description": "Create a reviewable local candidate from an identified base; never apply it to a target. This is an unimplemented research-level function contract.", "inputs": [ "Base revision", "Typed proposed changes", "Change reason and author role" ], "outputs": [ "Candidate revision or conflict report" ], "preconditions": [ "Editor authority", "Expected base equals current base", "Payload sensitivity screening" ], "effects": [ "Record predecessor and changed paths", "Keep approval pending" ], "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "function-validate-candidate", "name": "Validate a candidate profile", "description": "Proposed local validation against an explicitly pinned schema and approved checks; no untrusted code execution. This is an unimplemented research-level function contract.", "inputs": [ "Candidate digest", "Pinned schema and validator profile" ], "outputs": [ "Validation report with pass, fail, skipped or unknown checks" ], "preconditions": [ "Read authority", "Trusted offline validator and resolved schema", "No secret dereferencing" ], "effects": [ "Bind evidence to exact inputs", "Leave runtime safety and adoption unproven" ], "source_refs": [ "SRC-003" ] }, { "id": "function-resolve-projection", "name": "Resolve a declarative projection", "description": "Proposed local processing of a bounded non-executable merge profile; executable templates require an external authorized resolver. This is an unimplemented research-level function contract.", "inputs": [ "Pinned inputs", "Declared precedence", "Bounded merge profile" ], "outputs": [ "Resolved projection and origin map or refusal report" ], "preconditions": [ "All inputs locally authorized", "Cycle and unresolved-reference checks", "No network or secret resolution" ], "effects": [ "Record winning and shadowed origins", "Refuse ambiguous rules and preserve the base" ], "source_refs": [ "SRC-005", "SRC-008" ] }, { "id": "function-link-review", "name": "Link approval evidence", "description": "Associate an existing approval with the exact revision and scope; this operation cannot create approval authority. This is an unimplemented research-level function contract.", "inputs": [ "Approval master reference", "Revision digest", "Target scope" ], "outputs": [ "Qualified approval binding or mismatch report" ], "preconditions": [ "Evidence readable by caller", "Approving role and scope verified", "Approval not expired or revoked" ], "effects": [ "Record local evidence link", "Keep mismatched or missing evidence pending" ], "source_refs": [ "SRC-001" ] }, { "id": "function-assess-drift", "name": "Assess supplied observation", "description": "Compare supplied authorized intended and observed records locally, without querying or changing live systems. This is an unimplemented research-level function contract.", "inputs": [ "Intended projection", "Redacted observation reference and supplied snapshot", "Comparison profile" ], "outputs": [ "Scoped differences or indeterminate assessment" ], "preconditions": [ "Same target and compatible representations", "Freshness and coverage declared", "Sensitive keys suppressed" ], "effects": [ "Record method and unknowns", "Refer differences to review without remediation" ], "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "function-propose-reuse", "name": "Assess earlier revision reuse", "description": "Propose reuse of older content as a new candidate, conditioned on current compatibility and authorization. This is an unimplemented research-level function contract.", "inputs": [ "Earlier revision", "Current target scope", "Dependency metadata", "Review policy" ], "outputs": [ "Reuse candidate or unresolved-preconditions report" ], "preconditions": [ "Historical content accessible under retention policy", "References and compatibility rechecked", "No claim that rollback is guaranteed" ], "effects": [ "Retain original history", "Require fresh approval and external deployment process" ], "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ] } ], "composition": [ { "target": "WM-SFT-002", "relation": "REFERENCE", "purpose": "Identify the target system. Registry parent is reconciled as a target relationship, without inheriting application operations. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-SFT-007", "relation": "REFERENCE", "purpose": "Bind component identity and compatibility without owning package content. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-002", "SRC-003" ] }, { "target": "WM-SFT-008", "relation": "REFERENCE", "purpose": "Pin release versions when needed; releases retain their own evidence and lifecycle. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-SFT-009", "relation": "REFERENCE", "purpose": "Link external application attempts, acknowledgements and failures; configuration never executes deployment. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "target": "WM-SFT-010", "relation": "REFERENCE", "purpose": "Bind independently mastered environments and target selectors. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "target": "WM-SFT-013", "relation": "REFERENCE", "purpose": "Link change proposals and authorization evidence; change workflow remains external. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "WM-SFT-015", "relation": "REFERENCE", "purpose": "Link compatibility and behavior test results without executing tests here. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "WM-SFT-017", "relation": "REFERENCE", "purpose": "Reference observed state with time, source and coverage; preserve telemetry master identity. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "External secret authority", "relation": "REFERENCE", "purpose": "Keep credentials outside this model; resolve bindings only under separately authorized processes. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "External feature evaluation service", "relation": "REFERENCE", "purpose": "Delegate flag evaluation and context processing; retain bindings and qualified result references only. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "JSON Schema Draft 2020-12", "relation": "ALIGN", "purpose": "Optional validation vocabulary alignment, not universal instance-schema conformance. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "RFC 8342 NMDA", "relation": "ALIGN", "purpose": "Conceptual intended/operational separation only; no protocol conformance claimed. Candidate binding requires an adopting profile and version pin.", "required": false, "source_refs": [ "SRC-005" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Declare the adopting software/service owner role and configuration steward; no company or product brand is an owner", "Bind authoritative configuration, environment, approval and secret-reference namespaces", "Specify access, change authority, retention, exception and incident policies before instance use" ], "namespace_guidance": "Use owner-governed stable namespaces. Separate logical configuration IDs, revision IDs, artifact IDs and external target references; never use an environment label or timestamp as identity.", "registry_links": [ "vr.wm-sft-011", "WM-SFT-002", "WM-SFT-009", "WM-SFT-010" ] }, "canon_and_patch": { "canonicalization_rules": [ "Preserve value types, presence and unit semantics. Define format-specific byte normalization separately from semantic equality. Reject duplicate keys if ambiguous.", "Keep original protected evidence and derived redacted views separately identified under retention policy; a digest alone proves neither source authority nor safety." ], "patch_rules": [ "Require exact base revision and editor authority; generate a new revision and record conflicts instead of silent last-write-wins.", "Use explicit ordered patch semantics only under a pinned profile. Do not infer array merge, null deletion or external atomicity from serialization." ], "compatibility_rules": [ "Pin schema, resolver and consumer versions. Classify changes to key meaning, defaults, type or scope for impact review.", "An old revision can be incompatible after dependencies or secret references change; require fresh evidence for reuse." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with artifact revision", "Governed global identifier or IRI", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Use RFC 3339 with seconds and an explicit offset or Z. Distinguish declared effective time, approval time, application event time, observation time and ingestion time; preserve unknowns.", "serial_naming_rule": "Use stable artifact identity plus explicit revision and sequence. Human labels and filenames may change; dates and digests do not replace master identity.", "integrity_rule": "Record digest algorithm and digest of exact bytes, provenance, redaction scope and input references. Protect low-entropy sensitive values from disclosure through hashes; do not hash secret payloads into public evidence." }, "policies": [ "This is a noncanonical reviewable draft under a single-provider waiver; local research functions are proposals, not deployed capabilities.", "Default to secret references and least privilege. Never reveal payloads, dereference secrets or execute configuration-supplied code as a side effect of reading.", "Production application, security-control changes and rollback require the adopting authority and external processes; no local evidence operation authorizes them.", "Retain revision history according to the applicable schedule and holds, with controlled redaction and disposal rather than indefinite sensitive-data retention." ], "crud": { "read": [ "Read only authorized scopes and redact sensitive settings, reference metadata and evaluation context. Report stale evidence and unresolved bindings." ], "create": [ "Assign stable identity, target scope, proposed state and source provenance. Refuse inline secrets in this proposed model profile." ], "update": [ "Create a new content revision with optimistic concurrency and a review reference. Supersede evidence links explicitly; never treat local approval as activation." ], "delete": [ "Retire or supersede first. Check retention schedules, holds and dependent references before authorized payload deletion; preserve a minimal permissible tombstone.", "The adopting records authority executes local disposal. Deleting this record neither removes running settings nor revokes or rotates external secrets." ] }, "roles": [ { "name": "Configuration steward", "responsibilities": [ "Maintain identity, namespace and target scope" ] }, { "name": "Configuration editor", "responsibilities": [ "Propose typed changes with provenance and exact base" ] }, { "name": "Change approver", "responsibilities": [ "Review impact and authorize only the declared revision and scope" ] }, { "name": "Evidence reviewer", "responsibilities": [ "Assess validation, freshness and drift limitations" ] }, { "name": "Records custodian", "responsibilities": [ "Apply retention, access and approved disposal rules" ] } ], "access": { "default_rule": "Deny unless a role has purpose-bound access to the target environment and sensitivity class; metadata and derived artifacts inherit restrictions.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency access requires time-bounded authority, reason, review and audit; never treat emergency state as approval to expose credentials." ], "audit_requirements": [ "Record actor role, purpose, target, base and result revision, accessed scope and decision without secret values.", "Link external audit authority records and preserve redaction history; this model does not replace the audit system." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md", "spec.yaml and visible research holds", "Adopting Dimension access and change policies", "Pinned target, schema and reference profiles", "Exact revision evidence before any proposed change" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one desired software configuration with distinct revisions, resolved projections and adoption evidence. A separate frozen local no-tools self-audit found no critical contradiction. Source/version verification, adopting profiles, executable conformance and independent external review remain holds; this is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Logical and revision identity plus artifact master priority." }, { "dimension": "lifecycle", "status": "covered", "notes": "Draft, approved, superseded and retired records remain separate from activation." }, { "dimension": "relationships", "status": "covered", "notes": "Target, release, deployment, environment, change, test and observation references." }, { "dimension": "temporal", "status": "covered", "notes": "Effective, approval, application and observation times are distinct." }, { "dimension": "provenance", "status": "covered", "notes": "Revision lineage and resolved per-key origins." }, { "dimension": "ownership", "status": "covered", "notes": "Owner roles and separately mastered dependencies." }, { "dimension": "validation", "status": "covered", "notes": "Scoped schema and impact evidence, with failure and unknown states." }, { "dimension": "access", "status": "covered", "notes": "Protected bindings, least privilege and redacted views." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Policy-bound history, holds and minimal tombstones." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual mappings only; executable round-trip profiles remain unbuilt." }, { "dimension": "direct properties", "status": "covered", "notes": "Typed settings, presence, compatibility scope and lifecycle are direct nonphysical properties." }, { "dimension": "physical measurements", "status": "not-applicable", "notes": "The configuration is informational; setting units are semantic attributes, not measurements of the record." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Declarations, resolved projections and scoped runtime evidence are distinct." }, { "dimension": "capabilities and behavior", "status": "covered", "notes": "Proposed local functions specify refusal, authority and effects; external behavior remains delegated." }, { "dimension": "independent review", "status": "gap", "notes": "Codex is the sole active provider; separate local audit cannot supply independent review." }, { "dimension": "live source verification", "status": "gap", "notes": "Browser content reviewed; direct HTTP checks not run under the stated sandbox restriction and immutable rolling-document pins unresolved." } ], "known_omissions": [ "Nested instance schemas, concrete resolver implementations and acceptance fixtures", "Pinned adopting profiles, consumer-specific key catalogues and universal merge semantics", "Independent external review and complete current-version source verification", "Specialized regulated or safety-critical deployment assurance; requires separate qualified profiles" ], "conflicts": [], "regional_assumptions": [ "NIST guidance is a US federal security example, not a mandate for every adopter.", "Technology documents illustrate bounded behavior; jurisdictional privacy, retention and operating authority must be supplied by the adopting Dimension." ], "adversarial_checks": [ "An approved but never applied revision remains valid as a configuration record.", "Missing or redacted observation data cannot establish no drift.", "A secret reference grants no access, and reference metadata may itself be confidential.", "A changed default, mutable input or expired approval can invalidate historical reuse.", "Duplicate keys, unresolved inputs, cycles and concurrent edits require explicit rejection or unknown results.", "A feature fallback cannot be recorded as successful policy evaluation." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The root is a logically identified desired configuration whose revisions and evidence remain distinguishable. It is neither the application, a deployment event nor the runtime observation. Registry standalone-mm identifies the record plane, not the subject-kind enum. A settings collection does not alone require aggregate classification." }, "decisions": [ { "concept": "Logical root and revision identity", "disposition": "accepted", "rationale": "The scope and identity rules preserve logical continuity while separately identifying revisions and derived artifacts. Paths, labels, dates and digests cannot silently replace the authoritative identity." }, { "concept": "Registry parent and neighbor ownership", "disposition": "qualified", "rationale": "The frozen ledger has no explicit WM-SFT-011 edges. The registry parent is reconciled as a target reference, while proposed neighbor bindings remain optional and require profile pins. Deployment, runtime, change, test and telemetry masters remain separate." }, { "concept": "Supplement authority", "disposition": "rejected as evidence", "rationale": "The supplement supplied leads only. Its no-properties statement is rejected in favor of typed nonphysical settings and scope. Its path identity and rollback claims are qualified; the frozen record has no legacy successor alias." }, { "concept": "Declared, resolved and observed content", "disposition": "separated", "rationale": "The scope, resolution and drift findings preserve representation kind and origins. Declared approval, successful resolution and an external observation are different evidence states, so none can imply universal runtime adoption." }, { "concept": "Missing values and schema defaults", "disposition": "accepted with profile dependency", "rationale": "The value finding distinguishes absence, null, empty and default metadata. Required keys and cross-field constraints must be supplied by a pinned instance profile rather than inferred from the research schema." }, { "concept": "Merge and patch semantics", "disposition": "qualified", "rationale": "The resolver function is limited to an explicit bounded non-executable profile and records cycles, ambiguity and unresolved inputs. Protocol and JSON patch examples do not grant universal precedence or cross-system atomicity." }, { "concept": "Secret and resource bindings", "disposition": "accepted as a local profile", "rationale": "The reference-only policy is explicitly proposed, rather than a claim about every real-world configuration. It preserves confidentiality of metadata, prohibits secret retrieval and does not treat references or digests as encryption or permission evidence." }, { "concept": "Feature flag outcomes", "disposition": "separated", "rationale": "Optional typed bindings and fallback expectations are configuration-owned. Evaluation, individual context processing and result masters stay external; unavailable details and fallback outcomes remain qualified." }, { "concept": "Approval, validation and activation", "disposition": "separated", "rationale": "Revision review and exact-input validation are distinct from consumer adoption. The local link function records existing approval evidence only, and validation explicitly leaves security, behavioral compatibility and runtime application unproven." }, { "concept": "Propagation and drift", "disposition": "accepted with uncertainty", "rationale": "Consumption and drift questions retain target subset, freshness, missing keys and partial application. A stored update or an incomplete observation cannot establish full adoption or zero drift; comparison effects stop at review evidence." }, { "concept": "Historical reuse and disposal", "disposition": "qualified", "rationale": "The reuse function creates a new candidate after current checks and cannot execute rollback. Local retirement does not remove running settings or revoke secrets. Retention schedules and authorized disposal qualify history preservation." }, { "concept": "Artifact integrity and service rules", "disposition": "accepted", "rationale": "Artifacts retain master identifiers, separate revisions, scoped provenance and timestamps. The eight service sections restrict access, concurrent edits and sensitive evidence without assigning ownership to a product or company." }, { "concept": "Source breadth and live checks", "disposition": "limited", "rationale": "Eight primary sources support selected concepts across security guidance, schemas and protocol examples. Browser readings are not direct HTTP measurements. The report records zero attempts under the stated restriction, and rolling release pins and comprehensive errata checks remain unresolved." }, { "concept": "Executable implementation and independent review", "disposition": "deferred", "rationale": "Candidate data groups, optional bindings and six unimplemented functions support a reviewable design but not executable conformance. No waived provider contributes nodes or agreement. This is a separate Codex self-audit, not independent external review." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not a second-provider review.", "Live source and version verification remains incomplete. Browser content was reviewed, but direct HTTP checks were not attempted under the stated sandbox restriction: zero attempts and zero measured HTTP 200 responses. The coordinator must run check_sources.py outside the sandbox and review current versions, rolling-document pins and errata; HTTP success alone is insufficient.", "Nested instance schemas, pinned neighbor and resolver bindings, representation mappings, executable conformance and adversarial round-trip fixtures remain incomplete. The six local functions are unimplemented research contracts, not deployed operations.", "Adopting software, environment, security, privacy, retention, change-authority and regulated-use profiles require qualified review. No universal compatibility, runtime adoption, rollback guarantee or compliance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Complete coordinator-side source checks and immutable document pins, then review supported claims and errata against the adopting versions.", "Build instance profiles and fixtures for absent versus null values, duplicate keys, conflicting overlays, concurrent edits, mutable references, partial adoption, stale observations and lossy conversion.", "Validate adopting authority, consumer capabilities and retention requirements, and restore independent external review before any canonical promotion." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }