# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T12:41:13Z", "synthesisSha256": "b7238bf4634e2a83fb94906635b40ffe7edc9df21fafb94bf4269a40ec8d8dc8", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-SFT-018", "registryId": "vr.wm-sft-018", "name": "Network / Endpoint", "version": "0.1.0-reviewable-draft", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.SFT.NET" ], "tags": [ "network", "endpoint", "inf.sft.net" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-sft-018-network-endpoint/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-018", "model": { "registry_id": "vr.wm-sft-018", "model_id": "WM-SFT-018", "name": "Network / Endpoint", "entry_kind": "entity", "purpose": "Describe one stable logical network endpoint with effective-dated address bindings, contextual connectivity and bounded exposure assertions.", "scope_statement": "One governed logical endpoint instance. Network denotes its connectivity context, not ownership of a whole topology. Proposed local records preserve declarations, evidence references and assessments separately. This research is a reviewable draft under a single-provider waiver, with no operational conformance claim.", "in_scope": [ "Endpoint identity, accountable roles, classification and contextual service, runtime and interface bindings", "Effective-dated locator sets, protocol properties, discovery evidence and expected versus presented service identity", "Topology references, bounded exposure declarations, reachability evidence links, local assessments and record continuity" ], "out_of_scope": [ "Whole network inventory or routing engine; device, software, runtime and interface contract masters", "Traffic collection, telemetry lifecycle, credentials, certificate issuance, access-policy enforcement and operational security decisions", "Active scans, network writes, production changes, deployment, universal availability guarantees and compliance certification" ], "boundary_notes": [ { "neighbor": "WM-SFT-002", "distinction": "Candidate ledger edge: software identity and lifecycle stay software-owned; retain service reference and effective binding only.", "source_refs": [ "SRC-003", "SRC-009" ] }, { "neighbor": "WM-SFT-010", "distinction": "Candidate ledger edge: runtime identity and capacity stay runtime-owned; retain hosting and network-context references only.", "source_refs": [ "SRC-002" ] }, { "neighbor": "WM-SFT-003", "distinction": "Candidate ledger edge, including reciprocal incoming reference: bind interface contract revisions without owning their semantics, operations or compatibility.", "source_refs": [ "SRC-009" ] }, { "neighbor": "WM-SFT-017", "distinction": "Candidate ledger edge: reference traffic and reachability evidence; telemetry occurrence, collection lifecycle and signal identity stay telemetry-owned.", "source_refs": [ "SRC-010" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Uniform Resource Identifier (URI): Generic Syntax", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3986", "version_or_date": "RFC 3986, January 2005", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Sections 1.1, 3 and 6: identifiers, locator components and scheme-sensitive comparison. Stable endpoint identity is a local modeling choice, not guaranteed by URI syntax." }, { "id": "SRC-002", "title": "A YANG Data Model for Network Topologies", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc8345", "version_or_date": "RFC 8345, March 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Sections 3 and 6.2: topology, nodes, links and termination-point references. Supports scoped connectivity alignment, not equivalence of every application endpoint to a topology termination point." }, { "id": "SRC-003", "title": "Data Catalog Vocabulary (DCAT) - Version 3", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-dcat-3/", "version_or_date": "Recommendation, 22 August 2024; selected edition, not a latest-version claim", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Sections 6.9.1 and 6.9.2 distinguish a service endpoint location from its description. Optional data-service projection only." }, { "id": "SRC-004", "title": "Zero Trust Architecture", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/207/final", "version_or_date": "SP 800-207, August 2020", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Official abstract reviewed: network location or asset ownership alone does not confer trust; authentication and authorization are distinct. Full publication was not read." }, { "id": "SRC-005", "title": "Domain names - concepts and facilities", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc1034", "version_or_date": "RFC 1034, November 1987; later updates not exhaustively reviewed", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Sections 2.2 and 3.6: names, typed records and cache TTL. DNS observation is separate from a locally approved binding interval." }, { "id": "SRC-006", "title": "IPv6 Scoped Address Architecture", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc4007", "version_or_date": "RFC 4007, March 2005; later updates not exhaustively reviewed", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Sections 6, 11 and 12: limited-scope addresses require zone context. Does not supply a complete modern URI encoding profile." }, { "id": "SRC-007", "title": "Service Identity in TLS", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9525", "version_or_date": "RFC 9525, November 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Sections 4, 5 and 6 distinguish reference and presented identifiers with application-specific matching. Certificate presentation alone is not an authenticated service claim." }, { "id": "SRC-008", "title": "Service Name and Transport Protocol Port Number Registry", "organization": "Internet Assigned Numbers Authority", "url": "https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml", "version_or_date": "Browser page displayed Last Updated 2026-09-30; registry remains mutable", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Registry introduction and caution: port assignment is qualified by transport and does not prove observed application identity or safe traffic. Full registry not downloaded." }, { "id": "SRC-009", "title": "OpenAPI Specification v3.1.1", "organization": "OpenAPI Initiative", "url": "https://spec.openapis.org/oas/v3.1.1.html", "version_or_date": "3.1.1, 24 October 2024; selected edition", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Sections 4.8.5, 4.8.6 and 4.8.8: server URL, variables and path binding. Interface operations and compatibility remain owned by the contract model." }, { "id": "SRC-010", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:39:59Z", "relevance": "Starting-point entities, activities and attribution; derivation and revision relations. Conceptual provenance alignment does not certify claim truth." } ], "structure": { "bundles": [ { "id": "b-identity", "name": "Identity and stewardship", "description": "Identify one logical endpoint and its accountable record authority.", "rationale": "Proposed grouping keeps identity and stewardship answerable within one endpoint boundary.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-010" ], "layers": [ { "id": "l-identity", "name": "Persistent endpoint identity", "description": "Endpoint-local context for persistent endpoint identity.", "source_refs": [ "SRC-001", "SRC-010" ], "findings": [ { "id": "f-identity", "name": "Persistent endpoint identity", "description": "One endpoint retains its governed identifier across locator changes. Neither a shared IP address nor a reused hostname alone establishes continuity.", "source_refs": [ "SRC-001", "SRC-010" ], "questions": [ { "id": "q-identity-1", "text": "Which master-system identifier and namespace distinguish this endpoint from other endpoints sharing its addresses?", "kind": "identity", "answer_data": [ "Master system, namespace and immutable endpoint identifier" ] }, { "id": "q-identity-2", "text": "What endpoint class and identity-continuity rule apply when its address, tenant or service role changes?", "kind": "classification", "answer_data": [ "Class code, profile revision, continuity criteria and split or merge decision reference" ] }, { "id": "q-identity-3", "text": "Which accountable role can establish this endpoint identity and resolve disputed aliases?", "kind": "ownership", "answer_data": [ "Owner role reference, assignment interval, authority reference and disputed aliases" ] } ], "data_elements": [ { "id": "d-endpoint-key", "name": "Endpoint key", "description": "Master system, namespace and immutable endpoint identifier. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "d-identity-profile", "name": "Identity profile", "description": "Class code, profile revision, continuity criteria and split or merge decision reference. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "d-stewardship", "name": "Stewardship", "description": "Owner role reference, assignment interval, authority reference and disputed aliases. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] } ], "artifacts": [ { "id": "a-identity", "name": "Persistent endpoint identity record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-001", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "l-context", "name": "Service and environment bindings", "description": "Endpoint-local context for service and environment bindings.", "source_refs": [ "SRC-002", "SRC-003", "SRC-009" ], "findings": [ { "id": "f-context", "name": "Service and environment bindings", "description": "Record optional software, runtime and interface references. A service may use multiple endpoints and a runtime may host several independently governed endpoints.", "source_refs": [ "SRC-002", "SRC-003", "SRC-009" ], "questions": [ { "id": "q-context-1", "text": "Which software service references explain the purpose of this endpoint without making the endpoint the service master?", "kind": "relationship", "answer_data": [ "Software master references, relationship roles and effective intervals" ] }, { "id": "q-context-2", "text": "Which environment, tenant and network-context references bound the meaning of this endpoint?", "kind": "spatial", "answer_data": [ "Runtime references, environment codes, tenant scopes and network-context identifiers" ] }, { "id": "q-context-3", "text": "Which interface contract revisions are bound here and which interface details remain externally mastered?", "kind": "composition", "answer_data": [ "Contract master references, revision pins, binding selectors and unresolved-reference states" ] } ], "data_elements": [ { "id": "d-service-links", "name": "Service links", "description": "Software master references, relationship roles and effective intervals. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-009" ] }, { "id": "d-environment-links", "name": "Environment links", "description": "Runtime references, environment codes, tenant scopes and network-context identifiers. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-009" ] }, { "id": "d-contract-links", "name": "Contract links", "description": "Contract master references, revision pins, binding selectors and unresolved-reference states. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-009" ] } ], "artifacts": [ { "id": "a-context", "name": "Service and environment bindings record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-002", "SRC-003", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-addressing", "name": "Address bindings and discovery", "description": "Separate approved locator history from time-limited discovery observations.", "rationale": "Proposed grouping keeps address bindings and discovery answerable within one endpoint boundary.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-010" ], "layers": [ { "id": "l-bindings", "name": "Effective-dated locator sets", "description": "Endpoint-local context for effective-dated locator sets.", "source_refs": [ "SRC-001", "SRC-006", "SRC-010" ], "findings": [ { "id": "f-bindings", "name": "Effective-dated locator sets", "description": "A proposed binding record carries its own identity, endpoint reference and validity interval. Concurrent locators are permitted with explicit roles; they are not forced into a single current address.", "source_refs": [ "SRC-001", "SRC-006", "SRC-010" ], "questions": [ { "id": "q-bindings-1", "text": "Which locator bindings apply at the requested effective time and which overlaps are intentional?", "kind": "temporal", "answer_data": [ "Binding identifiers, endpoint key, locator kind and value, role, valid-from, valid-to and overlap rationale" ] }, { "id": "q-bindings-2", "text": "What address family and network or zone context make each locator unambiguous?", "kind": "constraint", "answer_data": [ "Address family, literal or name, network-context reference, IPv6 zone context and applicability state" ] }, { "id": "q-bindings-3", "text": "Which profile rules validate the locator while preserving its original spelling and meaning?", "kind": "validation", "answer_data": [ "Raw value, parsed components, normalization profile revision, validation outcome and unresolved ambiguity" ] } ], "data_elements": [ { "id": "d-binding-history", "name": "Binding history", "description": "Binding identifiers, endpoint key, locator kind and value, role, valid-from, valid-to and overlap rationale. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-010" ] }, { "id": "d-locator-scope", "name": "Locator scope", "description": "Address family, literal or name, network-context reference, IPv6 zone context and applicability state. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-010" ] }, { "id": "d-locator-validation", "name": "Locator validation", "description": "Raw value, parsed components, normalization profile revision, validation outcome and unresolved ambiguity. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-010" ] } ], "artifacts": [ { "id": "a-bindings", "name": "Effective-dated locator sets record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-001", "SRC-006", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "l-discovery", "name": "Name resolution observations", "description": "Endpoint-local context for name resolution observations.", "source_refs": [ "SRC-005", "SRC-010" ], "findings": [ { "id": "f-discovery", "name": "Name resolution observations", "description": "Discovery evidence is a contextual observation, not an identity assignment or deployment approval. Cached records and approved binding intervals have different meanings.", "source_refs": [ "SRC-005", "SRC-010" ], "questions": [ { "id": "q-discovery-1", "text": "Which name-resolution response supports this candidate locator and from which resolver view was it obtained?", "kind": "evidence", "answer_data": [ "Evidence master reference, query name, record type, returned set, resolver identity and network view" ] }, { "id": "q-discovery-2", "text": "What TTL, observation time and freshness rule qualify reuse of the recorded resolution evidence?", "kind": "measurement", "answer_data": [ "TTL in seconds, observed-at, ingested-at, cache context, freshness policy and unknown state" ] }, { "id": "q-discovery-3", "text": "How are an empty answer, lookup failure, conflicting views or an alias chain represented without silently replacing the approved binding?", "kind": "exception", "answer_data": [ "Outcome class, alias path, error evidence, conflicting candidate references and steward disposition" ] } ], "data_elements": [ { "id": "d-resolution-evidence", "name": "Resolution evidence", "description": "Evidence master reference, query name, record type, returned set, resolver identity and network view. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-010" ] }, { "id": "d-resolution-freshness", "name": "Resolution freshness", "description": "TTL in seconds, observed-at, ingested-at, cache context, freshness policy and unknown state. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-010" ] }, { "id": "d-resolution-exceptions", "name": "Resolution exceptions", "description": "Outcome class, alias path, error evidence, conflicting candidate references and steward disposition. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-010" ] } ], "artifacts": [ { "id": "a-discovery", "name": "Name resolution observations record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-005", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-interfaces", "name": "Protocol and service identity", "description": "Describe protocol-facing endpoint properties while preserving external contract and credential authority.", "rationale": "Proposed grouping keeps protocol and service identity answerable within one endpoint boundary.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008", "SRC-009" ], "layers": [ { "id": "l-protocol", "name": "Transport and interface selection", "description": "Endpoint-local context for transport and interface selection.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ], "findings": [ { "id": "f-protocol", "name": "Transport and interface selection", "description": "Transport, port and application selector are separate properties. A registered port is a vocabulary hint, never proof of an actual application or a safe connection.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ], "questions": [ { "id": "q-protocol-1", "text": "Which transport, port and application protocol are declared, observed or explicitly inapplicable for each binding?", "kind": "classification", "answer_data": [ "Transport code, port number, protocol identifier, version, assertion basis and applicability" ] }, { "id": "q-protocol-2", "text": "Which server variables, base location and path selectors connect this endpoint to a pinned interface description?", "kind": "interoperability", "answer_data": [ "Contract revision reference, base URL, variable assignments, selector and mapping profile" ] }, { "id": "q-protocol-3", "text": "Where do observed protocol properties disagree with declared properties or registry labels?", "kind": "quality", "answer_data": [ "Declared tuple, observed evidence references, mismatched fields, confidence and disposition" ] } ], "data_elements": [ { "id": "d-protocol-tuple", "name": "Protocol tuple", "description": "Transport code, port number, protocol identifier, version, assertion basis and applicability. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] }, { "id": "d-interface-selection", "name": "Interface selection", "description": "Contract revision reference, base URL, variable assignments, selector and mapping profile. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] }, { "id": "d-protocol-discrepancy", "name": "Protocol discrepancy", "description": "Declared tuple, observed evidence references, mismatched fields, confidence and disposition. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "a-protocol", "name": "Transport and interface selection record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "l-authentication", "name": "Presented and expected service identity", "description": "Endpoint-local context for presented and expected service identity.", "source_refs": [ "SRC-007", "SRC-004" ], "findings": [ { "id": "f-authentication", "name": "Presented and expected service identity", "description": "For a TLS profile, retain expected identifiers separately from certificate or handshake evidence. The external verifier owns authentication decisions and trust configuration.", "source_refs": [ "SRC-007", "SRC-004" ], "questions": [ { "id": "q-authentication-1", "text": "Which expected service identifiers and application verification profile apply to this endpoint binding?", "kind": "security", "answer_data": [ "Reference identifier types and values, application profile revision and derivation authority" ] }, { "id": "q-authentication-2", "text": "Which certificate reference and presented identifiers were observed at which termination point and time?", "kind": "evidence", "answer_data": [ "Certificate master reference or fingerprint, presented identifiers, termination-point reference and observed-at" ] }, { "id": "q-authentication-3", "text": "What external verification result and validity limits support or contradict the authenticated-identity claim?", "kind": "validation", "answer_data": [ "Verifier reference, policy revision, match and trust outcomes, evaluation time, expiry evidence and unknown or failed state" ] } ], "data_elements": [ { "id": "d-expected-identity", "name": "Expected identity", "description": "Reference identifier types and values, application profile revision and derivation authority. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "d-presented-identity", "name": "Presented identity", "description": "Certificate master reference or fingerprint, presented identifiers, termination-point reference and observed-at. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "d-identity-verification", "name": "Identity verification", "description": "Verifier reference, policy revision, match and trust outcomes, evaluation time, expiry evidence and unknown or failed state. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] } ], "artifacts": [ { "id": "a-authentication", "name": "Presented and expected service identity record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-007", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-connectivity", "name": "Connectivity and exposure", "description": "Bound connectivity claims by topology, direction, audience and time.", "rationale": "Proposed grouping keeps connectivity and exposure answerable within one endpoint boundary.", "source_refs": [ "SRC-002", "SRC-004", "SRC-006" ], "layers": [ { "id": "l-topology", "name": "Topology attachment and mediation", "description": "Endpoint-local context for topology attachment and mediation.", "source_refs": [ "SRC-002", "SRC-006" ], "findings": [ { "id": "f-topology", "name": "Topology attachment and mediation", "description": "Carry contextual topology and intermediary references. Application endpoints and topology termination points have a qualified mapping, not universal one-to-one identity.", "source_refs": [ "SRC-002", "SRC-006" ], "questions": [ { "id": "q-topology-1", "text": "Which network, node and termination-point references support the declared connectivity?", "kind": "relationship", "answer_data": [ "Topology master, network identifier, node reference, termination-point reference and revision" ] }, { "id": "q-topology-2", "text": "Which proxy, gateway or translation references distinguish the client-facing binding from downstream bindings?", "kind": "composition", "answer_data": [ "Intermediary references, upstream and downstream binding identifiers, direction and mapping interval" ] }, { "id": "q-topology-3", "text": "What scope or topology uncertainty prevents interpreting the recorded connectivity as an end-to-end route guarantee?", "kind": "constraint", "answer_data": [ "Layer, network scope, missing dependencies, unresolved mappings and evidence limits" ] } ], "data_elements": [ { "id": "d-topology-links", "name": "Topology links", "description": "Topology master, network identifier, node reference, termination-point reference and revision. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] }, { "id": "d-mediation-links", "name": "Mediation links", "description": "Intermediary references, upstream and downstream binding identifiers, direction and mapping interval. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] }, { "id": "d-topology-limits", "name": "Topology limits", "description": "Layer, network scope, missing dependencies, unresolved mappings and evidence limits. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] } ], "artifacts": [ { "id": "a-topology", "name": "Topology attachment and mediation record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-002", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "l-exposure", "name": "Bounded exposure assertions", "description": "Endpoint-local context for bounded exposure assertions.", "source_refs": [ "SRC-004", "SRC-002" ], "findings": [ { "id": "f-exposure", "name": "Bounded exposure assertions", "description": "Exposure is an assertion about a binding and an audience in context. It does not establish authorization, continuous availability or universal internet reachability.", "source_refs": [ "SRC-004", "SRC-002" ], "questions": [ { "id": "q-exposure-1", "text": "For which origin scope, destination binding, direction and protocol is exposure declared?", "kind": "access", "answer_data": [ "Assertion identifier, origin scope, destination binding, direction, protocol and effective interval" ] }, { "id": "q-exposure-2", "text": "Which approving role and external control-policy references justify that exposure assertion?", "kind": "authority", "answer_data": [ "Approver role, authority reference, control-policy revision, enforcement-point references and approval interval" ] }, { "id": "q-exposure-3", "text": "Which exceptions, expiry conditions and unknowns limit the exposure assertion?", "kind": "exception", "answer_data": [ "Exception scope, expiry, approving authority, unresolved conditions and next review criterion" ] } ], "data_elements": [ { "id": "d-exposure-scope", "name": "Exposure scope", "description": "Assertion identifier, origin scope, destination binding, direction, protocol and effective interval. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-002" ] }, { "id": "d-exposure-authority", "name": "Exposure authority", "description": "Approver role, authority reference, control-policy revision, enforcement-point references and approval interval. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-002" ] }, { "id": "d-exposure-exceptions", "name": "Exposure exceptions", "description": "Exception scope, expiry, approving authority, unresolved conditions and next review criterion. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-002" ] } ], "artifacts": [ { "id": "a-exposure", "name": "Bounded exposure assertions record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-004", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-evidence", "name": "Observation and assessment", "description": "Reference externally mastered observations and record only endpoint-specific interpretations.", "rationale": "Proposed grouping keeps observation and assessment answerable within one endpoint boundary.", "source_refs": [ "SRC-004", "SRC-008", "SRC-010" ], "layers": [ { "id": "l-reachability", "name": "Contextual reachability evidence", "description": "Endpoint-local context for contextual reachability evidence.", "source_refs": [ "SRC-004", "SRC-008", "SRC-010" ], "findings": [ { "id": "f-reachability", "name": "Contextual reachability evidence", "description": "A reachability observation has a vantage point, test layer and time. An unsuccessful observation leaves cause uncertain; a transport success does not prove application success.", "source_refs": [ "SRC-004", "SRC-008", "SRC-010" ], "questions": [ { "id": "q-reachability-1", "text": "Which telemetry or test master record supports the reachability statement and who collected it under what authorization?", "kind": "provenance", "answer_data": [ "Telemetry reference, collector role, method reference, authorization scope and collection time" ] }, { "id": "q-reachability-2", "text": "From which vantage, binding and protocol stage was reachability assessed and what result was observed?", "kind": "measurement", "answer_data": [ "Origin network, resolver view, target binding, protocol stage, outcome, units where measured and uncertainty" ] }, { "id": "q-reachability-3", "text": "How long may the observation support the statement and what untested paths or populations remain?", "kind": "quality", "answer_data": [ "Freshness threshold, sample window, coverage exclusions, ingestion lag and stale or unknown state" ] } ], "data_elements": [ { "id": "d-observation-reference", "name": "Observation reference", "description": "Telemetry reference, collector role, method reference, authorization scope and collection time. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-010" ] }, { "id": "d-observation-context", "name": "Observation context", "description": "Origin network, resolver view, target binding, protocol stage, outcome, units where measured and uncertainty. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-010" ] }, { "id": "d-observation-limits", "name": "Observation limits", "description": "Freshness threshold, sample window, coverage exclusions, ingestion lag and stale or unknown state. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "a-reachability", "name": "Contextual reachability evidence record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-004", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "l-assessment", "name": "Declaration and evidence reconciliation", "description": "Endpoint-local context for declaration and evidence reconciliation.", "source_refs": [ "SRC-010", "SRC-004" ], "findings": [ { "id": "f-assessment", "name": "Declaration and evidence reconciliation", "description": "An endpoint-local assessment links compatible claims and contrary evidence without rewriting telemetry. Matching scope and time are prerequisites to comparison.", "source_refs": [ "SRC-010", "SRC-004" ], "questions": [ { "id": "q-assessment-1", "text": "Which declared exposure and observation references are comparable under the same scope and time window?", "kind": "decision", "answer_data": [ "Claim reference, evidence references, binding version, comparison window and scope compatibility" ] }, { "id": "q-assessment-2", "text": "What supported, contradicted, stale or unknown status is assigned with what rationale?", "kind": "state", "answer_data": [ "Assessment identifier, status, rationale, evaluator role, evaluated-at and contrary evidence" ] }, { "id": "q-assessment-3", "text": "Which review referral or local correction follows the discrepancy without automatically changing network controls?", "kind": "process", "answer_data": [ "Review reference, responsible role, proposed correction, due criterion and completion evidence" ] } ], "data_elements": [ { "id": "d-comparison-inputs", "name": "Comparison inputs", "description": "Claim reference, evidence references, binding version, comparison window and scope compatibility. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-004" ] }, { "id": "d-assessment-result", "name": "Assessment result", "description": "Assessment identifier, status, rationale, evaluator role, evaluated-at and contrary evidence. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-004" ] }, { "id": "d-assessment-disposition", "name": "Assessment disposition", "description": "Review reference, responsible role, proposed correction, due criterion and completion evidence. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-004" ] } ], "artifacts": [ { "id": "a-assessment", "name": "Declaration and evidence reconciliation record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-010", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-continuity", "name": "Change, retirement and exchange", "description": "Govern the endpoint record lifecycle and loss-aware projections.", "rationale": "Proposed grouping keeps change, retirement and exchange answerable within one endpoint boundary.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-010" ], "layers": [ { "id": "l-lifecycle", "name": "Binding transition and endpoint retirement", "description": "Endpoint-local context for binding transition and endpoint retirement.", "source_refs": [ "SRC-010", "SRC-001" ], "findings": [ { "id": "f-lifecycle", "name": "Binding transition and endpoint retirement", "description": "Proposed record states are planned, active, suspended and retired; operational observations remain separate. Retirement closes local claims and does not decommission external infrastructure.", "source_refs": [ "SRC-010", "SRC-001" ], "questions": [ { "id": "q-lifecycle-1", "text": "Which endpoint record state and approved transition distinguish suspension, retirement and a temporary outage?", "kind": "lifecycle", "answer_data": [ "Record state, transition reason, authority reference, effective time and separate observation state" ] }, { "id": "q-lifecycle-2", "text": "How are replacement bindings, overlap windows and supersession recorded without reusing endpoint identity for an unrelated subject?", "kind": "temporal", "answer_data": [ "Predecessor and successor references, binding intervals, overlap rationale, identity decision and record revision" ] }, { "id": "q-lifecycle-3", "text": "Which retention and disposal rules govern endpoint history, sensitive locators and minimal tombstones?", "kind": "retention", "answer_data": [ "Policy reference, retention trigger, legal hold reference if any, payload disposition and tombstone scope" ] } ], "data_elements": [ { "id": "d-lifecycle-state", "name": "Lifecycle state", "description": "Record state, transition reason, authority reference, effective time and separate observation state. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] }, { "id": "d-transition-history", "name": "Transition history", "description": "Predecessor and successor references, binding intervals, overlap rationale, identity decision and record revision. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] }, { "id": "d-retention-policy", "name": "Retention policy", "description": "Policy reference, retention trigger, legal hold reference if any, payload disposition and tombstone scope. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] } ], "artifacts": [ { "id": "a-lifecycle", "name": "Binding transition and endpoint retirement record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-010", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "l-exchange", "name": "Evidence lineage and external projections", "description": "Endpoint-local context for evidence lineage and external projections.", "source_refs": [ "SRC-003", "SRC-009", "SRC-010" ], "findings": [ { "id": "f-exchange", "name": "Evidence lineage and external projections", "description": "Exports preserve local identity and evidence lineage. Endpoint URL, topology and interface mappings are selective projections with explicit losses, not conformance certificates.", "source_refs": [ "SRC-003", "SRC-009", "SRC-010" ], "questions": [ { "id": "q-exchange-1", "text": "Which versioned mapping exposes the endpoint through a catalogue, topology or interface binding and which semantics are lost?", "kind": "interoperability", "answer_data": [ "Target schema revision, mapping identifier, field correspondences, omitted semantics and round-trip limits" ] }, { "id": "q-exchange-2", "text": "Which source revision, contributor and derivation record explain each exported assertion?", "kind": "provenance", "answer_data": [ "Assertion reference, source master revision, contributor role, derivation reference and generated-at" ] }, { "id": "q-exchange-3", "text": "Which recipient-specific projection removes sensitive inventory details while preserving authorized evidence references?", "kind": "privacy", "answer_data": [ "Recipient scope, purpose, redaction policy, withheld fields, expiry and export audit reference" ] } ], "data_elements": [ { "id": "d-projection-profile", "name": "Projection profile", "description": "Target schema revision, mapping identifier, field correspondences, omitted semantics and round-trip limits. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-009", "SRC-010" ] }, { "id": "d-export-lineage", "name": "Export lineage", "description": "Assertion reference, source master revision, contributor role, derivation reference and generated-at. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-009", "SRC-010" ] }, { "id": "d-export-access", "name": "Export access", "description": "Recipient scope, purpose, redaction policy, withheld fields, expiry and export audit reference. Candidate group; nested schema and profile constraints remain to be implemented.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "a-exchange", "name": "Evidence lineage and external projections record", "description": "Versioned local record of this finding, linking external masters and contrary evidence. It is not a network configuration or executable action.", "media_or_form": [ "Structured record", "Restricted evidence reference index" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed global IRI second; Dimension-assigned UUID or ULID third. Use a separate revision identifier, no dates as identity. Preserve digest and source reference.", "source_refs": [ "SRC-003", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-register", "name": "Register an endpoint record", "description": "Proposed and unimplemented local operation. Create a local identity record after duplicate and authority review.", "inputs": [ "Endpoint identity, class, namespace and steward references" ], "outputs": [ "New endpoint key and revision or duplicate or authority refusal" ], "preconditions": [ "Authorized role and purpose; resolvable endpoint or new-identity authority; current policy and expected revision match.", "Required evidence and profile fields are complete or an explicit refusal is returned. Untrusted URLs are not fetched automatically." ], "effects": [ "Record only the stated local result with contributor, timestamp and prior revision. Preserve conflicts and audit attribution.", "No probing, credential use, external writes, network control changes or mutation of referenced master records." ], "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "fn-bind", "name": "Record an approved binding revision", "description": "Proposed and unimplemented local operation. Append an approved effective-dated locator binding without changing DNS, routing or deployed services.", "inputs": [ "Endpoint key, expected revision, approval reference and candidate locator intervals" ], "outputs": [ "Binding revision and overlap report or validation refusal" ], "preconditions": [ "Authorized role and purpose; resolvable endpoint or new-identity authority; current policy and expected revision match.", "Required evidence and profile fields are complete or an explicit refusal is returned. Untrusted URLs are not fetched automatically." ], "effects": [ "Record only the stated local result with contributor, timestamp and prior revision. Preserve conflicts and audit attribution.", "No probing, credential use, external writes, network control changes or mutation of referenced master records." ], "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] }, { "id": "fn-link-evidence", "name": "Link an observation reference", "description": "Proposed and unimplemented local operation. Attach authorized existing evidence with scope and freshness metadata without collecting traffic or running probes.", "inputs": [ "Evidence master reference, endpoint binding, vantage and observation window" ], "outputs": [ "Evidence link and unresolved-reference report or access refusal" ], "preconditions": [ "Authorized role and purpose; resolvable endpoint or new-identity authority; current policy and expected revision match.", "Required evidence and profile fields are complete or an explicit refusal is returned. Untrusted URLs are not fetched automatically." ], "effects": [ "Record only the stated local result with contributor, timestamp and prior revision. Preserve conflicts and audit attribution.", "No probing, credential use, external writes, network control changes or mutation of referenced master records." ], "source_refs": [ "SRC-010", "SRC-008" ] }, { "id": "fn-assess", "name": "Record an exposure assessment", "description": "Proposed and unimplemented local operation. Compare already admitted claims and evidence of compatible scope; preserve unknowns and contrary material.", "inputs": [ "Declared exposure, comparable evidence references and assessment profile" ], "outputs": [ "Endpoint-local assessment revision or incomparable-scope result" ], "preconditions": [ "Authorized role and purpose; resolvable endpoint or new-identity authority; current policy and expected revision match.", "Required evidence and profile fields are complete or an explicit refusal is returned. Untrusted URLs are not fetched automatically." ], "effects": [ "Record only the stated local result with contributor, timestamp and prior revision. Preserve conflicts and audit attribution.", "No probing, credential use, external writes, network control changes or mutation of referenced master records." ], "source_refs": [ "SRC-004", "SRC-010" ] }, { "id": "fn-retire", "name": "Retire the endpoint record", "description": "Proposed and unimplemented local operation. Close local lifecycle and binding intervals under approved policy without removing external resources.", "inputs": [ "Endpoint key, expected revision, retirement authority and retention policy" ], "outputs": [ "Retirement revision, successor references and tombstone plan or policy refusal" ], "preconditions": [ "Authorized role and purpose; resolvable endpoint or new-identity authority; current policy and expected revision match.", "Required evidence and profile fields are complete or an explicit refusal is returned. Untrusted URLs are not fetched automatically." ], "effects": [ "Record only the stated local result with contributor, timestamp and prior revision. Preserve conflicts and audit attribution.", "No probing, credential use, external writes, network control changes or mutation of referenced master records." ], "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "fn-project", "name": "Build an authorized projection", "description": "Proposed and unimplemented local operation. Prepare a recipient-scoped export using a pinned mapping and report any lost semantics.", "inputs": [ "Endpoint revision, recipient authority, mapping profile and redaction policy" ], "outputs": [ "Local export artifact and loss report or access refusal" ], "preconditions": [ "Authorized role and purpose; resolvable endpoint or new-identity authority; current policy and expected revision match.", "Required evidence and profile fields are complete or an explicit refusal is returned. Untrusted URLs are not fetched automatically." ], "effects": [ "Record only the stated local result with contributor, timestamp and prior revision. Preserve conflicts and audit attribution.", "No probing, credential use, external writes, network control changes or mutation of referenced master records." ], "source_refs": [ "SRC-003", "SRC-009", "SRC-010" ] } ], "composition": [ { "target": "WM-SFT-002", "relation": "REFERENCE", "purpose": "Candidate ledger edge: software identity and lifecycle stay software-owned; retain service reference and effective binding only.", "required": false, "source_refs": [ "SRC-003", "SRC-009" ] }, { "target": "WM-SFT-010", "relation": "REFERENCE", "purpose": "Candidate ledger edge: runtime identity and capacity stay runtime-owned; retain hosting and network-context references only.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "WM-SFT-003", "relation": "REFERENCE", "purpose": "Candidate ledger edge, including reciprocal incoming reference: bind interface contract revisions without owning their semantics, operations or compatibility.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "WM-SFT-017", "relation": "REFERENCE", "purpose": "Candidate ledger edge: reference traffic and reachability evidence; telemetry occurrence, collection lifecycle and signal identity stay telemetry-owned.", "required": false, "source_refs": [ "SRC-010" ] }, { "target": "RFC 8345 network topology", "relation": "ALIGN", "purpose": "Optional versioned mapping from an endpoint binding to topology references; no universal equivalence to a termination point.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "DCAT 3 endpointURL and endpointDescription", "relation": "ALIGN", "purpose": "Optional data-service projection; the endpoint root is not a dataset or the full service description.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "OpenAPI 3.1.1 Server Object", "relation": "ALIGN", "purpose": "Optional HTTP interface binding projection with pinned variables and selector semantics; no executable conformance claim.", "required": false, "source_refs": [ "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Assign a neutral accountable endpoint steward role, authority scope and master-system namespace.", "Pin endpoint identity, binding, exposure and evidence profiles; declare required and inapplicable fields before operational use.", "Provide purpose-specific access, retention, export and local change-review policies with responsible roles." ], "namespace_guidance": "Qualify endpoint keys by master and namespace; qualify locators by address family and network context. Aliases and addresses are not master keys. Separate tenants and environments.", "registry_links": [ "vr.wm-sft-018", "WM-SFT-002", "WM-SFT-010", "WM-SFT-003", "WM-SFT-017" ] }, "canon_and_patch": { "canonicalization_rules": [ "Keep raw locators with any normalized representation and name the normalization profile. Do not lowercase entire URLs or erase scoped-address context.", "Maintain stable local identity separately from binding, observation and revision identifiers. Proposed canonicalization rules do not make this research canonical." ], "patch_rules": [ "Require expected revision, authorized role, rationale and evidence; append a superseding record rather than silently overwriting contradictory assertions.", "Distinguish effective time, observed-at, evaluated-at and ingested-at; preserve concurrent binding sets and explicit end intervals." ], "compatibility_rules": [ "Pin mapping and neighboring specification revisions before runtime use. Unresolved references remain explicit.", "Reject lossy imports that merge endpoints solely by address, port, certificate or hostname; issue a steward review item." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier", "Governed global identifier or IRI", "Dimension-assigned UUID or ULID" ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z. Separate effective, event, observation and ingestion times; record unknown precision honestly.", "serial_naming_rule": "Use endpoint key, artifact role and independent revision or sequence; timestamps may label display names but never define identity.", "integrity_rule": "Retain source master revision and content digest where permitted; a hash detects changed bytes, not truth or authorization. Keep secrets outside artifacts." }, "policies": [ "Local governance proposal: classify inventories as restricted by default; redact internal addresses, topology and sensitive query material for recipient-specific exports.", "A locator or reference is data, not permission to connect. Active tests, production binding changes and exposure expansion require separate scoped authorization and external execution procedures.", "Never infer permission or safe traffic from network location, a familiar port or a valid-looking certificate.", "Keep private keys, tokens and credentials in their authorized external secret store; endpoint records carry only non-secret references.", "Retain minimal evidence and attribution according to the adopted policy; privacy and licensing applicability need profile review." ], "crud": { "read": [ "Enforce purpose and recipient scope for each bundle, layer, finding and artifact; show unknown and stale states." ], "create": [ "Require a namespace, accountable role, identity rule and creation authority; distinguish an imported candidate from a confirmed endpoint." ], "update": [ "Use revision preconditions and approved evidence; changing a local declaration never changes a network control or external master." ], "delete": [ "Retire local records with minimal resolvable tombstones when policy permits; check retention and holds before payload deletion. The adopting Dimension executes lawful disposal; referenced software, runtime, contracts and telemetry follow their own masters.", "Do not preserve sensitive inventory indefinitely merely to keep history; retain only authorized attribution and necessary reference continuity." ] }, "roles": [ { "name": "Endpoint steward", "responsibilities": [ "Resolve identity, namespace and binding disputes within delegated authority." ] }, { "name": "Network policy approver", "responsibilities": [ "Approve bounded exposure declarations; external enforcement remains separately controlled." ] }, { "name": "Evidence curator", "responsibilities": [ "Link permitted observations with scope, provenance and freshness; do not rewrite telemetry masters." ] }, { "name": "Profile reviewer", "responsibilities": [ "Review schema constraints, neighbor pins and projection losses before operational adoption." ] }, { "name": "Authorized consumer", "responsibilities": [ "Read or export only purpose-approved views and report ambiguity." ] } ], "access": { "default_rule": "Deny access to sensitive endpoint inventories unless the adopted purpose and role authorize it. Public model publication does not publish private instances.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Time-limited access exceptions need scope, purpose, approver, expiry and audit reference. Emergency authority must be established externally." ], "audit_requirements": [ "Record local reads where policy requires, writes, redactions and exports with actor role, purpose, target revision, time and outcome. Do not copy telemetry payloads or secrets into access logs." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md and adopted owner/Dimension policy", "spec.yaml and visible research holds", "Pinned neighbor specifications and authorized evidence references" ] } }, "coverage": { "claim": "Source-grounded proposed structure for one stable logical endpoint with effective-dated locators and bounded exposure assertions. A separate frozen-evidence local Codex no-tools self-audit found no critical conflicts. Independent review, live source/version verification, specialist profiles and executable conformance remain holds. This is a reviewable draft, not a complete network model or operational certification.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Stable endpoint master key, scoped aliases and continuity decisions." }, { "dimension": "lifecycle", "status": "covered", "notes": "Local planned, active, suspended and retired states; external resources unaffected." }, { "dimension": "relationships", "status": "covered", "notes": "Four candidate registry references retain external master ownership." }, { "dimension": "temporal", "status": "covered", "notes": "Binding validity, observation freshness and record revision are distinct." }, { "dimension": "provenance", "status": "covered", "notes": "External source references and local assessment attribution." }, { "dimension": "ownership", "status": "covered", "notes": "Neutral roles and authority references; no inferred ownership from an address." }, { "dimension": "validation", "status": "gap", "notes": "Research schema validation is available; nested instance and profile conformance are incomplete." }, { "dimension": "access", "status": "covered", "notes": "Restricted inventories and recipient-specific projections." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Policy-driven retirement, payload disposal and minimal tombstones." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual topology, DCAT and OpenAPI mappings; executable round trips unproven." }, { "dimension": "direct properties", "status": "covered", "notes": "Locator, protocol, network context and record state are direct nonphysical properties." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Contextual evidence and discrepancies, without identifying endpoints solely by locators." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Declared protocol capability and six proposed local operations; external actions require separate authority." }, { "dimension": "physical properties", "status": "not-applicable", "notes": "Logical root has no mass or dimensions; hosting device properties remain externally mastered." } ], "known_omissions": [ "Independent external provider review is absent; this Codex result can only be a reviewable draft.", "Direct HTTP checks were not run because the owner reports sandbox blocking; response status, final URLs and body digests remain unmeasured. Browser readings cover selected sections only; latest versions and all errata are not certified.", "Nested instance schemas, mandatory profile fields, loss-aware executable mappings and adverse-instance fixtures remain unimplemented.", "Protocol-specific discovery beyond the selected DNS concepts, non-IP transports, multicast or anycast behavior, complex mediation and full certificate lifecycle need specialist profiles.", "Legal authority for testing, privacy, retention, export, licensing and sector requirements need adopting-context review." ], "conflicts": [], "regional_assumptions": [ "Technical examples center on IP, DNS, TLS and HTTP; these are not mandatory for every endpoint.", "No jurisdiction-specific testing permission, retention duration or compliance requirement is inferred." ], "adversarial_checks": [ "Shared addresses, reused hostnames and certificates must not collapse unrelated endpoint identities.", "A stale or failed observation cannot establish a permanent outage or the cause of a failure.", "Private network placement, registered ports and certificate presentation cannot establish authorization.", "A declaration update or record retirement cannot claim an external network change occurred.", "Conflicting resolution views and concurrent locators remain representable without inventing a single true address." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "The frozen registry purpose defines stable logical endpoint identity. Network describes connectivity context, not a whole topology aggregate. The root persists across binding and observation revisions. The registry standalone-mm value classifies the record plane and is not a subject-kind enum." }, "decisions": [ { "concept": "Root and title scope", "disposition": "accepted", "rationale": "The result consistently models one endpoint entity and excludes a complete network inventory or routing engine, resolving the broader title against the registry purpose." }, { "concept": "Endpoint identity continuity", "disposition": "accepted", "rationale": "Master namespace and continuity decisions prevent shared or reused locators, certificate references and tenant changes from silently merging unrelated subjects." }, { "concept": "Binding validity and discovery", "disposition": "separated", "rationale": "Approved binding intervals, resolver evidence and cache TTL remain distinct. Concurrent locators, aliases and conflicting views are explicitly representable." }, { "concept": "Scoped address and normalization", "disposition": "qualified", "rationale": "Network and IPv6 zone context are preserved with raw locator values. Detailed normalization and modern discovery profiles are explicitly incomplete, not claimed as implemented." }, { "concept": "Protocol and certificate evidence", "disposition": "accepted with limits", "rationale": "Transport, port and application selector remain separate; expected and presented identities link external verification. No familiar port or certificate presentation confers trust or authorization." }, { "concept": "Topology mapping and exposure", "disposition": "qualified", "rationale": "A topology termination point is an optional mapping. Exposure has audience, direction, protocol, binding and time qualifiers, and cannot imply a universal route or continuous availability." }, { "concept": "Reachability and assessment ownership", "disposition": "accepted", "rationale": "The endpoint references scoped observations and creates only local interpretations. Telemetry collection, occurrence and signal masters remain external; inconclusive failure causes remain unknown." }, { "concept": "Registry relation ownership", "disposition": "accepted as candidate references", "rationale": "The software, runtime, interface and telemetry references preserve their master boundaries. The reciprocal interface edge is consistent; the registry parent does not establish software inheritance." }, { "concept": "Supplement and legacy evidence", "disposition": "reconciled", "rationale": "No legacy alias or previous spec is registered. The supplement is an untrusted lead, not source or provider evidence; its blanket no-properties and universal response-capability claims are rejected." }, { "concept": "Local functions and authority", "disposition": "accepted as proposed only", "rationale": "All six operations have local effects, authorization and revision preconditions, and refusal outcomes. They do not scan, deploy, change network controls or mutate referenced masters." }, { "concept": "Retirement, integrity and disposal", "disposition": "accepted with policy dependency", "rationale": "Retirement closes local records rather than decommissioning infrastructure. Evidence history is bounded by retention, disposal and minimal tombstones, avoiding indefinite inventory retention." }, { "concept": "Five facets and instance conformance", "disposition": "partly deferred", "rationale": "Logical properties, recognition, context and capabilities are represented; physical properties are inapplicable to this root. Candidate object groups and conceptual mappings still need nested schemas, profile requirements and fixtures." }, { "concept": "Source verification", "disposition": "limited", "rationale": "Selected browser readings support the admitted concepts. Direct HTTP checks were not attempted under the sandbox instruction; status, response digests, complete update chains and applicability remain unverified." }, { "concept": "Provider independence", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the owner instruction. This separate local Codex self-audit adds no external evidence and cannot count as independent provider review." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not a second-provider review.", "Live source and version verification is incomplete. Direct HTTP requests were not attempted because the owner reports sandbox blocking; HTTP status and response digests are unmeasured. Selected browser readings do not certify current versions, complete RFC update chains or errata, a complete mutable registry snapshot, licensing or operational applicability. The coordinator must run check_sources.py and review claims separately.", "Adopting profiles must resolve non-IP and advanced discovery cases, scope and mediation semantics, identity continuity, certificate verification, testing authority, privacy, retention, licensing and sector requirements before operational use.", "Nested instance schemas, required profile fields, pinned neighbor specifications, executable topology/DCAT/OpenAPI/PROV mappings and adversarial conformance fixtures remain incomplete. No runtime, security or compliance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Complete independent source verification with response metadata, version and errata review, claim support and applicability checks; restore external provider review before canonical promotion.", "Develop nested instance schemas and pinned mappings with fixtures for shared addresses, concurrent bindings, conflicting resolver views, scoped IPv6, stale evidence, identity mismatch, retirement and redacted export.", "Review specialist protocol, mediation, authorization, privacy and retention profiles with accountable operators before any operational adoption." ] }, "statistics": { "sources": 10, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }