# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T12:36:57Z", "synthesisSha256": "90bb7ec6caa08dfa1465075ad561b1cb0f9f94774ce76c07fd18606911fc8870", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-SFT-017", "registryId": "vr.wm-sft-017", "name": "Telemetry / Operational Signal", "version": "0.1.0", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.SFT.TEL" ], "tags": [ "telemetry", "operational", "signal", "inf.sft.tel" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-sft-017-telemetry-operational-signal/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-017", "model": { "registry_id": "vr.wm-sft-017", "model_id": "WM-SFT-017", "name": "Telemetry / Operational Signal", "entry_kind": "entity", "purpose": "Describe a typed operational signal record with source attribution, interpretation, collection qualifications and governed evidence use.", "scope_statement": "One information entity representing a metric point, log occurrence or span observation tied to runtime context. The root is the record, not the real-world event, metric stream, whole distributed trace, collector or monitoring platform. Signal-specific profiles supply conditional payload constraints.", "in_scope": [ "Record identity and typed metric/log/span interpretation", "Source resource and time evidence, sampling and delivery qualifications", "Local derivation, consumer references, access and disposition evidence" ], "out_of_scope": [ "Runtime, deployment, network endpoint, service commitment and incident master lifecycles", "Production collection, sampling configuration, export, alert routing, objective evaluation and response execution", "Physical sensor/device master models and legally evidential archive systems", "Full profiling payloads, continuous trace aggregates, universal telemetry ontology and executable protocol conformance" ], "boundary_notes": [ { "neighbor": "WM-MAT-008 Observation / Measurement Record", "distinction": "Registry parent is reconciled as a candidate alignment. This root is an information entity with typed software operational evidence, not a physical measurement process.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ] }, { "neighbor": "WM-SFT-018 Network / Endpoint", "distinction": "The ledger has an inbound consumer reference to telemetry. Traffic and reachability evidence do not transfer endpoint lifecycle, exposure policy or authentication ownership here.", "source_refs": [ "SRC-006", "SRC-008" ] }, { "neighbor": "Runtime, deployment and reliability commitment", "distinction": "Bind external masters with observation-time evidence. No local operation changes runtime or evaluates objective compliance.", "source_refs": [ "SRC-007", "SRC-001", "SRC-008" ] }, { "neighbor": "Operational log and evidential archive", "distinction": "A log occurrence is a supported signal class. Evidential preservation may reference it separately; near-real-time use does not impose a universal short retention period.", "source_refs": [ "SRC-002", "SRC-004", "SRC-008" ] }, { "neighbor": "Profiles and physical sensors", "distinction": "The registry purpose bounds this draft to metrics, logs and traces. Profiles are deferred. Physical observations may be referenced but device mastery and physical measurement procedures remain external.", "source_refs": [ "SRC-001", "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Metrics Data Model", "organization": "OpenTelemetry project", "url": "https://opentelemetry.io/docs/specs/otel/metrics/data-model/", "version_or_date": "Documentation displaying 1.61.0, accessed 2026-10-06; immutable revision unverified", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Model Details and Metric Points: type, unit, temporality, resource/scope identity and aggregation limitations." }, { "id": "SRC-002", "title": "Logs Data Model", "organization": "OpenTelemetry project", "url": "https://opentelemetry.io/docs/specs/otel/logs/data-model/", "version_or_date": "Documentation displaying 1.61.0, accessed 2026-10-06; immutable revision unverified", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Field descriptions: source and observed time, body, severity and optional trace correlation." }, { "id": "SRC-003", "title": "Trace Context", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/trace-context/", "version_or_date": "Recommendation 23 November 2021; selected browser text", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Traceparent and tracestate; privacy and security sections. Propagation identity is not authentication or a universal signal key." }, { "id": "SRC-004", "title": "The Syslog Protocol", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc5424.html", "version_or_date": "RFC 5424, March 2009; current errata review pending", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Sections 4, 6, 7.1 and 8: message structure, source clock quality, replay and transport limitations." }, { "id": "SRC-005", "title": "Tracing API", "organization": "OpenTelemetry project", "url": "https://opentelemetry.io/docs/specs/otel/trace/api/", "version_or_date": "Documentation displaying 1.61.0, accessed 2026-10-06; immutable revision unverified", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Span context, span lifetime, parent, links, events, status and time representation." }, { "id": "SRC-006", "title": "OTLP Specification", "organization": "OpenTelemetry project", "url": "https://opentelemetry.io/docs/specs/otlp/", "version_or_date": "Page displays 1.11.0, accessed 2026-10-06; immutable revision unverified", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Protocol responses: accepted data, partial rejection, warning-only responses and retry distinctions." }, { "id": "SRC-007", "title": "Resource SDK", "organization": "OpenTelemetry project", "url": "https://opentelemetry.io/docs/specs/otel/resource/sdk/", "version_or_date": "Documentation displaying 1.61.0, accessed 2026-10-06; immutable revision unverified", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Resource creation, detection and immutability; source metadata does not prove a runtime master binding." }, { "id": "SRC-008", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 30 April 2013; selected browser text", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Starting Point terms for entities, generating activities, derivation and attribution; conceptual mapping only." }, { "id": "SRC-009", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002; current updates and errata review pending", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Section 5.6 timestamp grammar supports seconds, fractional seconds and offsets; it does not establish clock accuracy." }, { "id": "SRC-010", "title": "Handling sensitive data", "organization": "OpenTelemetry project", "url": "https://opentelemetry.io/docs/security/handling-sensitive-data/", "version_or_date": "Living guidance, accessed 2026-10-06; page says modified 14 January 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:35:20Z", "relevance": "Context-dependent sensitivity, minimization, removal and hashing limitations; guidance is not a legal compliance determination." } ], "structure": { "bundles": [ { "id": "signal-context", "name": "Signal identity and context", "description": "Identify an operational record without owning the emitting infrastructure.", "rationale": "Type and resource attribution must precede interpretation.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007", "SRC-008" ], "layers": [ { "id": "signal-identity-layer", "name": "Record identity and signal class", "description": "One locally governed record represents one metric point, log occurrence or span observation. A stream definition and a trace group are references, not interchangeable root identities.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008" ], "findings": [ { "id": "signal-identity", "name": "Record identity and signal class", "description": "One locally governed record represents one metric point, log occurrence or span observation. A stream definition and a trace group are references, not interchangeable root identities.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008" ], "questions": [ { "id": "signal-identity-q1", "text": "Which authoritative record key and source identity distinguish this occurrence from a replay?", "kind": "identity", "answer_data": [ "master system", "record key", "source key", "deduplication basis" ] }, { "id": "signal-identity-q2", "text": "Which signal class and versioned interpretation profile apply to this record?", "kind": "classification", "answer_data": [ "metric-point or log or span", "profile reference", "profile version" ] }, { "id": "signal-identity-q3", "text": "How is a correction linked without overwriting the original observation?", "kind": "lifecycle", "answer_data": [ "revision", "supersedes reference", "correction reason", "responsible role" ] } ], "data_elements": [ { "id": "signal-identity-d1", "name": "Record key", "description": "Locally assigned stable key with source namespace, not a timestamp or metric name alone.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008" ] }, { "id": "signal-identity-d2", "name": "Signal class", "description": "Discriminator for metric-point, log or span; unknown types are quarantined pending profile review.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008" ] }, { "id": "signal-identity-d3", "name": "Source identity and revision", "description": "Original key if supplied, source namespace, local revision and correction links.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008" ] } ], "artifacts": [ { "id": "signal-identity-artifact", "name": "Signal identity register", "description": "Proposed governed evidence view for record identity and signal class. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "resource-binding-layer", "name": "Resource and instrumentation attribution", "description": "Keep the emitter description at observation time separate from collector enrichment and current runtime state. Unknown, ephemeral or conflicting resource bindings remain explicit.", "source_refs": [ "SRC-007", "SRC-002", "SRC-005" ], "findings": [ { "id": "resource-binding", "name": "Resource and instrumentation attribution", "description": "Keep the emitter description at observation time separate from collector enrichment and current runtime state. Unknown, ephemeral or conflicting resource bindings remain explicit.", "source_refs": [ "SRC-007", "SRC-002", "SRC-005" ], "questions": [ { "id": "resource-binding-q1", "text": "Which runtime and deployment references identify the observed resource at capture time?", "kind": "relationship", "answer_data": [ "runtime reference", "deployment reference", "effective time", "unresolved binding reason" ] }, { "id": "resource-binding-q2", "text": "Which instrumentation scope and schema version produced the signal?", "kind": "provenance", "answer_data": [ "scope name", "scope version", "schema URL", "detector or supplied origin" ] }, { "id": "resource-binding-q3", "text": "Who is accountable for resolving resource collisions across tenants or reused instance names?", "kind": "ownership", "answer_data": [ "service steward role", "tenant namespace", "collision state", "resolution evidence" ] } ], "data_elements": [ { "id": "resource-binding-d1", "name": "Resource snapshot", "description": "Source resource attributes plus provenance of any separate enrichment; never rewrite source attribution silently.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-002", "SRC-005" ] }, { "id": "resource-binding-d2", "name": "Runtime binding", "description": "Candidate master reference, effective interval and unresolved/conflicting state.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-002", "SRC-005" ] }, { "id": "resource-binding-d3", "name": "Instrumentation", "description": "Scope and schema metadata, preserving absent values.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-002", "SRC-005" ] } ], "artifacts": [ { "id": "resource-binding-artifact", "name": "Resource attribution snapshot", "description": "Proposed governed evidence view for resource and instrumentation attribution. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-007", "SRC-002", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "value-meaning", "name": "Metric and log meaning", "description": "Preserve signal-specific payload semantics.", "rationale": "A numerical series and a log occurrence require different interpretation profiles.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ], "layers": [ { "id": "metric-semantics-layer", "name": "Metric point interpretation", "description": "For metric records preserve value representation, unit, point type and temporal semantics. Derived conversions require a new evidence version; gauges are not automatically additive.", "source_refs": [ "SRC-001" ], "findings": [ { "id": "metric-semantics", "name": "Metric point interpretation", "description": "For metric records preserve value representation, unit, point type and temporal semantics. Derived conversions require a new evidence version; gauges are not automatically additive.", "source_refs": [ "SRC-001" ], "questions": [ { "id": "metric-semantics-q1", "text": "Which unit, point type and value representation make this metric point interpretable?", "kind": "measurement", "answer_data": [ "unit", "point type", "numeric or distribution representation" ] }, { "id": "metric-semantics-q2", "text": "Which interval, aggregation temporality and reset evidence apply to this point?", "kind": "temporal", "answer_data": [ "start and end", "delta or cumulative or not applicable", "monotonic flag", "reset evidence" ] }, { "id": "metric-semantics-q3", "text": "Which compatibility check prevents combining incompatible metric points?", "kind": "validation", "answer_data": [ "resource and scope", "attribute set", "type and unit check", "bucket or scale compatibility", "rejection reason" ] } ], "data_elements": [ { "id": "metric-semantics-d1", "name": "Metric descriptor", "description": "Conditional metric profile: name, resource/scope binding, unit and point type.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "metric-semantics-d2", "name": "Point payload", "description": "Conditional typed value or distribution with attributes, interval and applicable temporality. Required by a metric profile, not by log/span profiles.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "metric-semantics-artifact", "name": "Metric interpretation sheet", "description": "Proposed governed evidence view for metric point interpretation. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "log-semantics-layer", "name": "Log occurrence and source severity", "description": "Represent a log body and source severity without requiring a trace association. Protocol conversion retains the original meaning and records losses.", "source_refs": [ "SRC-002", "SRC-004" ], "findings": [ { "id": "log-semantics", "name": "Log occurrence and source severity", "description": "Represent a log body and source severity without requiring a trace association. Protocol conversion retains the original meaning and records losses.", "source_refs": [ "SRC-002", "SRC-004" ], "questions": [ { "id": "log-semantics-q1", "text": "What body representation and source severity were recorded for this log occurrence?", "kind": "definition", "answer_data": [ "body or protected body reference", "body type", "severity text and value", "source vocabulary" ] }, { "id": "log-semantics-q2", "text": "Which optional trace association is supported rather than inferred from nearby timestamps?", "kind": "evidence", "answer_data": [ "trace and span references", "association origin", "unknown or conflict state" ] }, { "id": "log-semantics-q3", "text": "What was lost or changed when the source log format was normalized?", "kind": "interoperability", "answer_data": [ "source format", "mapping version", "unmapped fields", "truncation", "conversion loss" ] } ], "data_elements": [ { "id": "log-semantics-d1", "name": "Log content", "description": "Conditional log body/reference and original severity with mapped severity kept separately.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "log-semantics-d2", "name": "Log conversion", "description": "Source message metadata and mapping report, including unsupported values.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "log-semantics-artifact", "name": "Log interpretation record", "description": "Proposed governed evidence view for log occurrence and source severity. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "operation-time", "name": "Operation and time evidence", "description": "Qualify span context and temporal assertions.", "rationale": "Correlation and timestamps have distinct trust and precision limits.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-009" ], "layers": [ { "id": "span-context-layer", "name": "Span observation and causal context", "description": "A span observation describes an operation interval and its supplied relationships. A parent, link or propagated identifier is an assertion, not proof of causal truth or caller authority.", "source_refs": [ "SRC-003", "SRC-005" ], "findings": [ { "id": "span-context", "name": "Span observation and causal context", "description": "A span observation describes an operation interval and its supplied relationships. A parent, link or propagated identifier is an assertion, not proof of causal truth or caller authority.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "span-context-q1", "text": "Which trace and span identifiers, parent and links describe this observed operation?", "kind": "composition", "answer_data": [ "trace ID", "span ID", "parent reference", "links", "origin and trust boundary" ] }, { "id": "span-context-q2", "text": "Which operation kind, events and status were observed before the span ended?", "kind": "event", "answer_data": [ "operation name", "span kind", "event references", "status", "end state" ] }, { "id": "span-context-q3", "text": "How is invalid or untrusted incoming trace context represented without granting access?", "kind": "security", "answer_data": [ "validation result", "trust boundary", "rejected fields", "correlation-only limitation" ] } ], "data_elements": [ { "id": "span-context-d1", "name": "Span payload", "description": "Conditional span identifiers, operation, interval, kind, status, events and links.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "span-context-d2", "name": "Context assessment", "description": "Validation and trust qualification; context never serves as an authorization credential.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "span-context-artifact", "name": "Span context assessment", "description": "Proposed governed evidence view for span observation and causal context. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "time-quality-layer", "name": "Observation time and clock quality", "description": "Record source, observed and ingestion times separately where known. Ordering assumptions and precision losses must be visible; unknown source time is not synthesized from arrival time.", "source_refs": [ "SRC-002", "SRC-004", "SRC-009" ], "findings": [ { "id": "time-quality", "name": "Observation time and clock quality", "description": "Record source, observed and ingestion times separately where known. Ordering assumptions and precision losses must be visible; unknown source time is not synthesized from arrival time.", "source_refs": [ "SRC-002", "SRC-004", "SRC-009" ], "questions": [ { "id": "time-quality-q1", "text": "Which source, observation and ingestion times are known and which clock supplied each?", "kind": "temporal", "answer_data": [ "source time", "observed time", "ingestion time", "clock origin", "unknown reason" ] }, { "id": "time-quality-q2", "text": "What clock uncertainty or synchronization evidence limits ordering and duration claims?", "kind": "quality", "answer_data": [ "synchronization state", "uncertainty", "measurement method", "negative-duration flag" ] }, { "id": "time-quality-q3", "text": "How are original epoch precision and offset semantics preserved in a normalized timestamp?", "kind": "interoperability", "answer_data": [ "original representation", "precision", "RFC 3339 value", "offset state", "rounding loss" ] } ], "data_elements": [ { "id": "time-quality-d1", "name": "Time evidence", "description": "Named timestamps, original epoch values, clock sources and precision. Never require a fabricated event timestamp.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-009" ] }, { "id": "time-quality-d2", "name": "Clock quality", "description": "Uncertainty and synchronization evidence, or explicit unknown state.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "time-quality-artifact", "name": "Time quality record", "description": "Proposed governed evidence view for observation time and clock quality. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-002", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "collection-quality", "name": "Collection quality", "description": "Describe selection and delivery qualifications.", "rationale": "A retained signal cannot establish collection completeness.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "selection-coverage-layer", "name": "Sampling and observation coverage", "description": "Record the selection policy and known observation gaps. Sampling decisions, truncation and collection failure are distinct; absence of a record does not establish a healthy system.", "source_refs": [ "SRC-003", "SRC-005", "SRC-001" ], "findings": [ { "id": "selection-coverage", "name": "Sampling and observation coverage", "description": "Record the selection policy and known observation gaps. Sampling decisions, truncation and collection failure are distinct; absence of a record does not establish a healthy system.", "source_refs": [ "SRC-003", "SRC-005", "SRC-001" ], "questions": [ { "id": "selection-coverage-q1", "text": "Which selection rule and decision evidence explain why this signal was retained?", "kind": "process", "answer_data": [ "policy reference and version", "decision stage", "sampling evidence", "unknown selection state" ] }, { "id": "selection-coverage-q2", "text": "Which observation gaps prevent this record from representing the whole workload?", "kind": "quality", "answer_data": [ "coverage window", "known gaps", "selection bias", "missing population information" ] }, { "id": "selection-coverage-q3", "text": "What authorization is required before changing the referenced sampling configuration?", "kind": "authority", "answer_data": [ "configuration owner role", "approval reference", "scope", "production change boundary" ] } ], "data_elements": [ { "id": "selection-coverage-d1", "name": "Selection evidence", "description": "Referenced selection policy and observed decision; no universal scalar sampling probability is assumed.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-001" ] }, { "id": "selection-coverage-d2", "name": "Coverage qualification", "description": "Known gaps, uncertainty and permitted analytical use of the retained signal.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-001" ] } ], "artifacts": [ { "id": "selection-coverage-artifact", "name": "Selection and coverage note", "description": "Proposed governed evidence view for sampling and observation coverage. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-003", "SRC-005", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "delivery-evidence-layer", "name": "Collection and delivery outcome", "description": "A delivery receipt is distinct from the signal occurrence and from persistence at every destination. Retries may duplicate data; protocol-level partial success must not be collapsed into full acceptance.", "source_refs": [ "SRC-006", "SRC-004" ], "findings": [ { "id": "delivery-evidence", "name": "Collection and delivery outcome", "description": "A delivery receipt is distinct from the signal occurrence and from persistence at every destination. Retries may duplicate data; protocol-level partial success must not be collapsed into full acceptance.", "source_refs": [ "SRC-006", "SRC-004" ], "questions": [ { "id": "delivery-evidence-q1", "text": "Which collector path and destination-specific receipts qualify delivery of this signal?", "kind": "provenance", "answer_data": [ "collector references", "destination", "receipt reference", "acceptance scope" ] }, { "id": "delivery-evidence-q2", "text": "What rejection, warning, delay or truncation was reported for the relevant export?", "kind": "exception", "answer_data": [ "batch reference", "rejected count", "warning", "signal-level attribution limit", "delay" ] }, { "id": "delivery-evidence-q3", "text": "How does the selected transport profile handle retries without claiming exactly-once delivery?", "kind": "constraint", "answer_data": [ "transport and version", "retry classification", "partial-success handling", "duplicate evidence" ] } ], "data_elements": [ { "id": "delivery-evidence-d1", "name": "Delivery references", "description": "Batch and destination receipts linked without treating batch counts as per-record proof.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-004" ] }, { "id": "delivery-evidence-d2", "name": "Delivery qualification", "description": "Accepted, rejected, partial, unknown or warning-only outcome with protocol context.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-004" ] } ], "artifacts": [ { "id": "delivery-evidence-artifact", "name": "Delivery qualification record", "description": "Proposed governed evidence view for collection and delivery outcome. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-006", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "evidence-use", "name": "Evidence lineage and use", "description": "Track derived views and external consumers.", "rationale": "Transformation provenance and consumer ownership prevent silent semantic expansion.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010" ], "layers": [ { "id": "derivation-lineage-layer", "name": "Transformations and evidence lineage", "description": "Any local normalization, redaction or aggregation yields a separately identified derived view with links to permitted inputs. A digest checks bytes, not observational truth.", "source_refs": [ "SRC-008", "SRC-010" ], "findings": [ { "id": "derivation-lineage", "name": "Transformations and evidence lineage", "description": "Any local normalization, redaction or aggregation yields a separately identified derived view with links to permitted inputs. A digest checks bytes, not observational truth.", "source_refs": [ "SRC-008", "SRC-010" ], "questions": [ { "id": "derivation-lineage-q1", "text": "Which source records and transformation activity generated this derived representation?", "kind": "provenance", "answer_data": [ "input references", "activity ID", "mapping version", "responsible role" ] }, { "id": "derivation-lineage-q2", "text": "Which changed fields and information losses limit reversal or comparison?", "kind": "constraint", "answer_data": [ "changed paths", "loss report", "reversibility", "retained source availability" ] }, { "id": "derivation-lineage-q3", "text": "What evidence supports integrity while keeping sensitive input payloads out of the lineage index?", "kind": "evidence", "answer_data": [ "digest and algorithm", "protected input locator", "access policy", "integrity verification state" ] } ], "data_elements": [ { "id": "derivation-lineage-d1", "name": "Derivation graph", "description": "References to inputs, processing activity and output revision; no payload duplication required.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-010" ] }, { "id": "derivation-lineage-d2", "name": "Transformation assessment", "description": "Local change, loss and integrity evidence with explicit verification limits.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "derivation-lineage-artifact", "name": "Transformation provenance record", "description": "Proposed governed evidence view for transformations and evidence lineage. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "consumer-binding-layer", "name": "Operational consumers and evidential limits", "description": "Signals may be cited by endpoint, incident or reliability records. Local consumer bindings do not define exposure policy, compute compliance, trigger alerts or master an incident.", "source_refs": [ "SRC-008", "SRC-001", "SRC-006" ], "findings": [ { "id": "consumer-binding", "name": "Operational consumers and evidential limits", "description": "Signals may be cited by endpoint, incident or reliability records. Local consumer bindings do not define exposure policy, compute compliance, trigger alerts or master an incident.", "source_refs": [ "SRC-008", "SRC-001", "SRC-006" ], "questions": [ { "id": "consumer-binding-q1", "text": "Which externally mastered endpoint, incident or reliability records cite this signal?", "kind": "relationship", "answer_data": [ "consumer reference", "consumer type", "binding version", "use purpose" ] }, { "id": "consumer-binding-q2", "text": "Which query window and interpretation version make a downstream use reproducible?", "kind": "requirement", "answer_data": [ "query or selection reference", "window", "interpretation version", "input revision" ] }, { "id": "consumer-binding-q3", "text": "What uncertainty prevents observed traffic or silence from proving declared reachability or an objective outcome?", "kind": "decision", "answer_data": [ "coverage limits", "unresolved evidence", "external decision owner", "prohibited inference" ] } ], "data_elements": [ { "id": "consumer-binding-d1", "name": "Consumer references", "description": "Optional links; the inbound WM-SFT-018 reference does not make endpoint records telemetry children.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-001", "SRC-006" ] }, { "id": "consumer-binding-d2", "name": "Use qualification", "description": "Permitted purpose, evidence window and known limitations supplied to the consumer.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-001", "SRC-006" ] } ], "artifacts": [ { "id": "consumer-binding-artifact", "name": "Consumer evidence binding", "description": "Proposed governed evidence view for operational consumers and evidential limits. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-008", "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "record-governance", "name": "Record governance", "description": "Protect content and govern local continuity.", "rationale": "Operational utility does not remove access and retention responsibilities.", "source_refs": [ "SRC-003", "SRC-004", "SRC-008", "SRC-010" ], "layers": [ { "id": "content-controls-layer", "name": "Sensitive content and scoped access", "description": "The adopting Dimension must classify payloads and attributes, minimize collection and restrict derived views. Correlation can reveal personal behavior; hashing alone is not proof of anonymity.", "source_refs": [ "SRC-010", "SRC-003" ], "findings": [ { "id": "content-controls", "name": "Sensitive content and scoped access", "description": "The adopting Dimension must classify payloads and attributes, minimize collection and restrict derived views. Correlation can reveal personal behavior; hashing alone is not proof of anonymity.", "source_refs": [ "SRC-010", "SRC-003" ], "questions": [ { "id": "content-controls-q1", "text": "Which fields require removal, masking or restricted viewing for the declared observability purpose?", "kind": "privacy", "answer_data": [ "field classification", "purpose", "minimization decision", "approved transformation" ] }, { "id": "content-controls-q2", "text": "Which tenant, role and artifact scopes govern access to this record and its correlations?", "kind": "access", "answer_data": [ "tenant boundary", "role", "allowed fields", "artifact scope", "correlation permission" ] }, { "id": "content-controls-q3", "text": "How is an exceptional disclosure approved and recorded without copying sensitive values into its audit entry?", "kind": "authority", "answer_data": [ "approver role", "purpose", "recipient", "expiry", "minimal audit reference" ] } ], "data_elements": [ { "id": "content-controls-d1", "name": "Content classification", "description": "Context-specific field classes and permitted uses; secrets are excluded from ordinary evidence views.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-003" ] }, { "id": "content-controls-d2", "name": "Access binding", "description": "Owner policy reference, tenant and recipient-specific view rules.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-003" ] } ], "artifacts": [ { "id": "content-controls-artifact", "name": "Content access assessment", "description": "Proposed governed evidence view for sensitive content and scoped access. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-010", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "record-continuity-layer", "name": "Retention, correction and retirement", "description": "Govern the local signal record lifecycle under an explicit owner policy. Preserve only lawful minimal continuity when payloads expire; an external evidential record has its own retention authority.", "source_refs": [ "SRC-008", "SRC-010", "SRC-004" ], "findings": [ { "id": "record-continuity", "name": "Retention, correction and retirement", "description": "Govern the local signal record lifecycle under an explicit owner policy. Preserve only lawful minimal continuity when payloads expire; an external evidential record has its own retention authority.", "source_refs": [ "SRC-008", "SRC-010", "SRC-004" ], "questions": [ { "id": "record-continuity-q1", "text": "Which retention trigger, duration and exception policy apply to each raw or derived signal artifact?", "kind": "retention", "answer_data": [ "artifact class", "trigger", "duration", "hold reference", "policy version" ] }, { "id": "record-continuity-q2", "text": "How are correction, supersession and expiry represented without reusing a retired identity?", "kind": "lifecycle", "answer_data": [ "state", "superseding reference", "retirement reason", "tombstone scope" ] }, { "id": "record-continuity-q3", "text": "Who authorizes deletion and verifies disposition across the recorded copies and external evidence references?", "kind": "authority", "answer_data": [ "records steward role", "deletion decision", "copy inventory", "verification evidence", "external handoff" ] } ], "data_elements": [ { "id": "record-continuity-d1", "name": "Disposition policy", "description": "Applicable schedule, hold and scope references; no universal period is prescribed.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-010", "SRC-004" ] }, { "id": "record-continuity-d2", "name": "Continuity state", "description": "Active, corrected, superseded or retired local state with minimal permitted linkage.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-010", "SRC-004" ] } ], "artifacts": [ { "id": "record-continuity-artifact", "name": "Signal disposition record", "description": "Proposed governed evidence view for retention, correction and retirement. It references the signal record and revision; it is not a separately authoritative master.", "media_or_form": [ "Structured record", "Human-readable evidence view" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID and revision; otherwise governed IRI; otherwise Dimension UUID or ULID. Link signal ID and evidence revision. Time and content digest are not sole identity.", "source_refs": [ "SRC-008", "SRC-010", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-signal", "name": "Register a signal record", "description": "Proposed local operation, not implemented. Validate an authorized supplied observation and assign a local record identity.", "inputs": [ "Supplied signal envelope", "Source namespace and profile" ], "outputs": [ "Registered record or quarantine report" ], "preconditions": [ "Authorized role and tenant scope; pinned profile; expected record revision.", "Class-specific required fields and duplicate criteria resolved." ], "effects": [ "Creates a local evidence record; does not collect from or configure a production runtime." ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] }, { "id": "assess-interpretation", "name": "Assess interpretation compatibility", "description": "Proposed local operation, not implemented. Check a proposed representation against its signal profile.", "inputs": [ "Signal revision", "Unit/type/time mapping" ], "outputs": [ "Compatibility and loss report" ], "preconditions": [ "Authorized role and tenant scope; pinned profile; expected record revision.", "Original representation available or explicitly absent." ], "effects": [ "Records assessment only; does not silently alter values or certify conformance." ], "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "id": "link-context", "name": "Link attributed context", "description": "Proposed local operation, not implemented. Attach qualified external bindings.", "inputs": [ "Runtime or consumer reference", "Binding evidence" ], "outputs": [ "Versioned binding or unresolved-reference report" ], "preconditions": [ "Authorized role and tenant scope; pinned profile; expected record revision.", "External master identity and permitted purpose checked." ], "effects": [ "Changes local references only; does not change endpoint policy or runtime state." ], "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "record-delivery", "name": "Record delivery qualification", "description": "Proposed local operation, not implemented. Associate supplied transport receipts with a local record.", "inputs": [ "Receipt reference", "Batch and destination scope" ], "outputs": [ "Qualified delivery view" ], "preconditions": [ "Authorized role and tenant scope; pinned profile; expected record revision.", "Attribution uncertainty and transport response profile retained." ], "effects": [ "Records observed acceptance or uncertainty; performs no export or retry." ], "source_refs": [ "SRC-006", "SRC-004" ] }, { "id": "derive-view", "name": "Create a governed derived view", "description": "Proposed local operation, not implemented. Produce a local redacted or normalized representation with provenance.", "inputs": [ "Input revision", "Approved transformation and recipient scope" ], "outputs": [ "Derived artifact and loss report or refusal" ], "preconditions": [ "Authorized role and tenant scope; pinned profile; expected record revision.", "Sensitive fields and reversible transformations reviewed." ], "effects": [ "Creates a separate local view and lineage; no external disclosure or raw overwrite." ], "source_refs": [ "SRC-008", "SRC-010" ] }, { "id": "retire-record", "name": "Record retirement decision", "description": "Proposed local operation, not implemented. Mark a local record retired after authorized disposition evidence.", "inputs": [ "Disposition decision", "Hold and copy checks" ], "outputs": [ "Retirement marker or refusal report" ], "preconditions": [ "Authorized role and tenant scope; pinned profile; expected record revision.", "Retention policy, active holds and deletion authority resolved." ], "effects": [ "Updates minimal permitted local continuity; payload deletion is performed only by the separately authorized custodian workflow." ], "source_refs": [ "SRC-008", "SRC-010" ] } ], "composition": [ { "target": "WM-MAT-008", "relation": "ALIGN", "purpose": "Candidate registry parent: generic observation concepts align, but typed signal payload and operational occurrence identity remain local.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ] }, { "target": "WM-SFT-010", "relation": "REFERENCE", "purpose": "Runtime identity is externally mastered; keep a time-qualified binding, including unresolved state.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "WM-SFT-009", "relation": "REFERENCE", "purpose": "Deployment identity and lifecycle remain external; no deployment execution belongs here.", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "target": "WM-SFT-018", "relation": "REFERENCE", "purpose": "Optional backlink to a consumer of traffic evidence. Preserve the ledger direction WM-SFT-018 REFERENCE WM-SFT-017; no required reverse containment or exposure authority.", "required": false, "source_refs": [ "SRC-008", "SRC-006" ] }, { "target": "WM-SFT-016", "relation": "REFERENCE", "purpose": "Reliability commitment and evaluator remain external; record only qualified evidence bindings.", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "target": "WM-ACT-042", "relation": "REFERENCE", "purpose": "Incident response may consume signal evidence; triage, paging and response execution stay external.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "OpenTelemetry signal data models and OTLP", "relation": "ALIGN", "purpose": "Selected conceptual and protocol mappings require pinned schemas and tested adapters before conformance claims.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007" ] }, { "target": "W3C Trace Context and PROV-O", "relation": "ALIGN", "purpose": "Use correlation and provenance concepts without claiming authentication, truth or executable ontology conformance.", "required": false, "source_refs": [ "SRC-003", "SRC-008" ] }, { "target": "RFC 5424 and RFC 3339", "relation": "ALIGN", "purpose": "Preserve protocol-specific source semantics and timestamp representation; no universal transport guarantee.", "required": false, "source_refs": [ "SRC-004", "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name accountable service steward and telemetry custodian roles with tenant namespace and authorized purposes.", "Pin signal profiles, source protocol versions, master systems and authority for classification and corrections.", "Declare retention, access, export and evidence-handoff policies, resource budgets and delegated operations." ], "namespace_guidance": "Separate source namespace, tenant, signal record ID, stream descriptor and local revision. Never use a service name, time or trace ID alone as a universal record key.", "registry_links": [ "vr.wm-sft-017", "WM-MAT-008 candidate alignment", "WM-SFT-010 and WM-SFT-009 optional master bindings", "WM-SFT-018 inbound reference ledger" ] }, "canon_and_patch": { "canonicalization_rules": [ "This proposed local profile is not a canonical release. Preserve source values and unknowns; normalization produces a derived revision with a loss report.", "Do not merge records on timestamp or name alone. Pin discriminator, unit, profile and source namespace before deduplication." ], "patch_rules": [ "Use expected revision, actor role and reason. Correct interpretations by supersession; never silently rewrite an observed payload.", "Sampling, routing, production retention and alert changes are outside these local functions and require their own owner authority." ], "compatibility_rules": [ "Class-specific profiles must define required nested fields; a storage projection must preserve identifiers, precise time, units, unknowns and access controls.", "Breaking type, unit, temporality, identity or privacy changes require a versioned migration and comparison fixtures." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier and revision", "Governed global identifier or IRI", "Dimension-assigned UUID or ULID" ], "timestamp_rule": "Use RFC 3339 with seconds and explicit offset or Z for known normalized time values. Keep event time, observation time and ingestion time distinct. Preserve original epoch precision separately; unknown source time or offset stays unknown and is never invented.", "serial_naming_rule": "Use stable artifact ID plus revision and record reference; descriptive time may be a label but never sole identity.", "integrity_rule": "Record digest algorithm and representation with verified/unverified state. A checksum is not provenance authentication or truth; protect source locators and do not hash secrets into public indexes." }, "policies": [ "Proposed local governance rules derived from the stated boundary; external sources do not mandate these exact fields or workflows.", "Collect and retain only purpose-justified content; scope redaction, exports and correlations by recipient and tenant.", "Missing, dropped, stale or sampled-out telemetry never proves normal operation.", "No local function acknowledges an alert, changes production configuration, evaluates a service commitment or executes incident response." ], "crud": { "read": [ "Check tenant, purpose, field and artifact access, then show source revision, selection limits and unresolved bindings." ], "create": [ "Admit supplied records only under a pinned class profile; preserve raw representation by protected reference and quarantine malformed or unknown classes." ], "update": [ "Apply concurrency checks and versioned interpretation patches; keep original evidence within retention limits and record losses." ], "delete": [ "The authorized custodian workflow enforces retention, hold resolution and payload deletion across controlled copies; this model records the decision and disposition evidence. Retire IDs without reuse and retain only lawful minimal tombstones.", "External incident or evidential records retain their own master identity and disposition authority; a local deletion does not prove external deletion." ] }, "roles": [ { "name": "Service steward", "responsibilities": [ "Approve meaning, purpose and runtime bindings." ] }, { "name": "Telemetry custodian", "responsibilities": [ "Maintain local records and execute separately authorized retention workflows." ] }, { "name": "Evidence analyst", "responsibilities": [ "Interpret qualified views without treating missing signals as normal operation." ] }, { "name": "Privacy and access reviewer", "responsibilities": [ "Review sensitivity, recipient scopes and exceptional disclosure." ] }, { "name": "Profile maintainer", "responsibilities": [ "Version schemas and test conversions; no automatic production change authority." ] } ], "access": { "default_rule": "Deny unless explicitly authorized for tenant, purpose, field and artifact. Correlation and derived views inherit applicable restrictions.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Time-limited approved emergency access requires a named accountable role, purpose, scope and minimal audit reference; it does not bypass confidentiality by default." ], "audit_requirements": [ "Record actor role, decision, scope, time, revision and outcome without echoing restricted payloads.", "Audit storage and retention are owned by the adopting Dimension; link the external audit record rather than claiming an immutable audit service here." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Nearest owner and Dimension policies", "AGENTS.md", "spec.yaml including holds", "Pinned class profile and external master bindings", "Authorized evidence and current revision" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one typed operational signal record, with metric, log and span profiles. Separate frozen local no-tools self-audit completed; external review, source verification, nested schemas and operational conformance remain holds. This is a reviewable draft, not a complete telemetry platform or canonical specification.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Separate record, stream, trace and revision keys." }, { "dimension": "lifecycle", "status": "covered", "notes": "Correction and retirement states preserve limited continuity." }, { "dimension": "relationships", "status": "covered", "notes": "External runtime and consumers remain independently mastered." }, { "dimension": "temporal", "status": "covered", "notes": "Clock source, event/observation/ingestion distinction and precision." }, { "dimension": "provenance", "status": "covered", "notes": "Emitter and derived-view lineage with uncertainty." }, { "dimension": "ownership", "status": "covered", "notes": "Role-based stewardship and namespace authority." }, { "dimension": "validation", "status": "gap", "notes": "Research schema validatable; nested class schemas and executable conformance fixtures deferred." }, { "dimension": "access", "status": "covered", "notes": "Tenant, field, recipient and artifact scopes." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Policy-driven disposition, holds and external copy limitations." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual alignments only; immutable version pins and adapters pending." }, { "dimension": "direct properties", "status": "covered", "notes": "Type, unit, severity, duration and quality are meaningful; signal records have no intrinsic physical mass or dimensions." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Typed supplied payload, attribution and clock evidence; not automatic truth recognition." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Proposed local operations separate permission, precondition, effect and failure." }, { "dimension": "spatial context", "status": "covered", "notes": "Region or host location is an optional time-qualified resource attribute, not a required geometry." }, { "dimension": "source verification", "status": "gap", "notes": "Selected browser text reviewed; direct HTTP and immutable revision checks pending outside sandbox." }, { "dimension": "independent review", "status": "gap", "notes": "Claude and Grok skipped under owner waiver; local self-audit is not independent review." } ], "known_omissions": [ "Executable nested metric/log/span schemas, profile fixtures and tested adapters are not supplied.", "Immutable source snapshots, errata and revision pins need coordinator verification.", "Continuous profiling, complete trace graphs, workload-specific selection bias and statistical error estimators remain deferred.", "Storage residency, lawful bases, retention periods and security controls require adopting-profile review.", "No production runtime, collector or remote publication was tested." ], "conflicts": [], "regional_assumptions": [ "Technical concepts are cross-region proposals. No universal privacy, evidence, residency or retention compliance is asserted." ], "adversarial_checks": [ "Reject treating a metric name or trace ID as universal occurrence identity.", "Reject assuming a missing record proves system health or a complete workload.", "Reject collapsing batch partial acceptance into per-signal persistence.", "Reject treating trace correlation as authentication or a verified causal graph.", "Reject rewriting observed payloads through enrichment or correction.", "Reject adopting the unreviewed supplement as provider evidence." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The root is an information record for one typed observation, not the observed event, whole trace, metric stream or collector. Stable local identity and versioned evidence views support entity. The registry standalone-mm value classifies the catalogue record plane, not the subject-kind enum." }, "decisions": [ { "concept": "Typed record root", "disposition": "accepted", "rationale": "Metric point, log occurrence and span observation are conditional record profiles. Stream and trace-group identities remain references rather than interchangeable root keys." }, { "concept": "Endpoint relationship direction", "disposition": "accepted with qualification", "rationale": "The frozen ledger has WM-SFT-018 referencing telemetry. The optional backlink is explicitly a consumer binding and transfers no endpoint exposure, identity or lifecycle authority." }, { "concept": "Runtime and other neighbor bindings", "disposition": "proposed only", "rationale": "The result preserves external master ownership and unknown bindings. Optional runtime, deployment, reliability and incident references need adopter version pins, not mandatory containment." }, { "concept": "Metric and log properties", "disposition": "accepted", "rationale": "Units, value types, temporality and severity are meaningful record properties. The supplement's blanket not-applicable properties claim is rejected; intrinsic physical properties remain inapplicable." }, { "concept": "Trace identity and trust", "disposition": "qualified", "rationale": "Trace context is signal-specific correlation evidence. Neither parent/link assertions nor identifiers prove causal truth, caller identity or permission to access a record." }, { "concept": "Time and unknowns", "disposition": "accepted", "rationale": "Source, observation and ingestion times remain distinct. Original precision and clock evidence survive projection; the rules permit unknown source time without fabricating a timestamp." }, { "concept": "Sampling and delivery completeness", "disposition": "qualified", "rationale": "Selection bias, pipeline loss and partial acceptance are separate qualifications. Batch receipts cannot prove per-record persistence, and the local functions perform no export or retry." }, { "concept": "Lineage and integrity", "disposition": "accepted", "rationale": "Derived outputs keep references and loss reports; a content digest is not treated as authentication or truth. The proposed view artifacts do not create new authoritative masters." }, { "concept": "Access and disposition", "disposition": "accepted with policy dependency", "rationale": "Tenant and recipient scope applies to correlations and derived views. Retention controls original payload history, minimal tombstones and copy verification; retirement is not a claim of external deletion." }, { "concept": "Operational completeness", "disposition": "held", "rationale": "Candidate objects and conceptual alignments lack executable nested schemas, fixtures and tested adapters. This limits operational use but does not invalidate the stated research-draft boundary." }, { "concept": "Sources and supplement", "disposition": "limited", "rationale": "Selected browser text was reviewed, while direct HTTP checks were not attempted and immutable revision verification is incomplete. The unreviewed supplement supplies leads only, not independent provider evidence." }, { "concept": "Independent review", "disposition": "waived and held", "rationale": "Claude and Grok were explicitly skipped with zero attempts. This separate local Codex no-tools assessment cannot count as a second provider or justify canonical promotion." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; this local Codex self-audit is not an independent second-provider review.", "Direct HTTP and immutable source-version verification remain pending. No direct requests were attempted because the owner reports sandbox blocking; zero HTTP 200 responses were measured. Selected browser text and retrieval limits are documented in source-review.md. The coordinator must run check_sources.py outside the sandbox and review versions, errata and applicability.", "Executable metric/log/span profile schemas, unknown-state vocabularies, protocol adapters, versioned neighbor bindings and adversarial instance fixtures remain incomplete. Structural research validation is not runtime or protocol conformance.", "Adopting-profile review must establish content classification, authorized purposes, lawful retention, residency, external disclosure controls and custodian authority before operational use; no universal legal or security compliance is claimed.", "Continuous profiling, whole-trace/stream aggregates, workload-specific sampling bias and quantitative error estimation remain deferred; coverage is limited to the registry's metrics, logs and traces purpose.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Pin immutable technical source revisions and current errata, complete external HTTP checks and restore independent provider review before any canonical promotion.", "Define conditional nested schemas and test fixtures for missing source time, reset counters, incompatible distributions, untrusted trace context, partial export, duplicate receipts, redaction and expiry.", "Resolve adopter-specific master bindings, retention and privacy policies and test adapters against the chosen protocol versions.", "Evaluate whether profiling or whole-stream/trace models need separately bounded extensions rather than expanding this record root." ] }, "statistics": { "sources": 10, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }