World Models · public research draft

Access Contract / Consent

Provide a format-neutral, machine-readable instrument of permission to read: which party permits which reader to read which slice of data, for which declared purpose, under which conditions and duties, until when, on what evidence of assent, and how that permission is verified, changed and ended.

AI YAMLAGENTS.mdResearch evidence
Research draft. The Claude + Grok synthesis is public for review and use with caution. It passed structural validation but is not yet a canonical Vercy release because the source and coverage holds below remain open.
Catalogue IDWM-XCT-002
Version0.3.0-research.1
Previous version-
Typemixin
ValidationPassed
Synthesis digestsha256:478f7f042a8e07f3…
19Sources
6Bundles
16Layers
29Findings
113Questions
24Artifacts
Format-independent logical structure

Bundles → Layers → Findings → Questions + Artifacts

grant-instrumentGrant Instrument4 layers

The permission itself as a durable object: who permits, who may read, over which slice, for which purpose, under which conditions, and with which duties attached to the reader.

parties-and-authorityParties and Authority3 findings

The grantor and the grantee, the capacity in which each acts, and the verification that the grantor was entitled to permit at all.

grantor-authority-basis

Grantor identity and authority basis

Who asserts the right to permit reading, in what capacity (self, personal representative, guardian, delegate, institutional custodian), what evidence supports that capacity, and the outcome and time of verification against the ownership or delegation record. A grant issued without a verified basis is void rather than merely disputed.

Questions
  1. Which authoritative identifier designates the grantor, and in which master system is it resolved?identity
    Expected answer
    • grantor identifier value
    • issuing master system identifier
    • identifier scheme or namespace
    • resolution timestamp
  2. In what capacity does the grantor act — data subject, owner, personal representative, guardian, or delegate?authority
    Expected answer
    • capacity code from governed vocabulary
    • reference to the delegation or guardianship record relied on
    • scope limits of that capacity
  3. What evidence documents the representative's authority, and when was it last verified?evidence
    Expected answer
    • evidence artefact reference
    • verifier identity
    • verification outcome
    • verification timestamp with offset
  4. What happens to an active grant if the authority basis lapses or is later found invalid?exception
    Expected answer
    • effect code (void ab initio, suspend, terminate forward)
    • effective instant of the effect
    • reason code
    • notification obligation
Artifacts
  • Authority verification recordThe captured evidence and outcome of confirming that the grantor could lawfully permit the read, including any representative documentation relied on.
grantee-designation

Grantee designation and onward recipients

Who may read under the grant — a named party, a defined class or collection, or the bearer of a ticket — and which onward recipients or sub-processors, if any, are inside the grant and under what flow-down duties.

Questions
  1. Is the grantee an individually named party, a party collection, or a bearer of a transferable ticket?classification
    Expected answer
    • grantee designation kind code
    • grantee identifier or collection selector
    • transferability flag
  2. Which onward recipients or sub-processors are within the grant, and under which flow-down duties?relationship
    Expected answer
    • recipient identifiers or recipient category codes
    • flow-down duty references
    • permitted onward jurisdictions
  3. How is the grantee authenticated at read time, and at what assurance level?security
    Expected answer
    • required authentication method
    • minimum assurance level
    • attribute source for the assurance claim
  4. May the grantee sub-delegate its read right, and what record must exist if it does?authority
    Expected answer
    • sub-delegation permitted flag
    • required sub-delegation record type
    • notification requirement to the grantor
party-functional-roles

Party functional roles

ODRL requires Agreement to name assigner and assignee; Offer requires assigner. FHIR names grantor (who grants rights), grantee (who must comply with the directive, including obligations), manager (lifecycle), controller (enforcer), and subject (who the consent is about). UMA distinguishes resource owner, requesting party, client, resource server and authorization server, and allows the requesting party to differ from the owner. Party collections may be refined (for example friends over age 18). FHIR comments that grantor/grantee are search conveniences and that fully computable consents list both as actors inside provisions. The Kantara Consent Receipt historically treats the PII principal as issuing a receipt to the controller, whereas ISO 27560 treats the organisation as issuing a receipt to the individual.

Questions
  1. Who is the grantor, and which ownership, parental-responsibility or delegation record authorises them to grant?authority
    Expected answer
    • grantor_party_id
    • capacity_code
    • ownership_authority_ref
  2. Which party or party collection is the grantee, and are members refined by attributes such as role or age?access
    Expected answer
    • grantee_party_id
    • party_collection_refinement
    • requesting_party_id
  3. Is the data subject a different person from the grantor, as with a parent granting over a child's record?relationship
    Expected answer
    • subject_party_id
    • grantor_party_id
    • capacity_code
  4. Which actor manages the instrument through its lifecycle and which actor evaluates reads against it?ownership
    Expected answer
    • manager_party_id
    • enforcer_party_id
Artifacts
  • Party rosterResolved party identifiers, roles, collection membership and authority references for one instrument.
scope-selectionScope Selection2 findings

Which objects and which of their attributes the grant covers, how the covered set is designated and resolved, and how sensitivity changes what is required.

scope-clause-selection

Scope clause and selection mechanism

How the covered slice is designated — enumerated identifiers, coded categories, or an evaluable selector expression — whether the covered set is frozen at activation or re-evaluated at every read, and the specificity floor below which a clause is rejected as not identifying the information in a specific and meaningful way.

Questions
  1. How is the covered set designated: enumerated identifiers, category codes, or an evaluable selector expression?composition
    Expected answer
    • selector kind code
    • selector value or expression
    • expression language identifier
  2. Is the covered set resolved as a snapshot at activation or re-evaluated live at each read?state
    Expected answer
    • resolution mode code
    • snapshot reference if frozen
    • re-evaluation trigger conditions
  3. Which creation or observation window of the covered objects falls inside the grant?temporal
    Expected answer
    • data period start
    • data period end
    • period semantics (creation, observation, or record time)
  4. What is the specificity floor below which a scope clause must be rejected as too broad to be meaningful?constraint
    Expected answer
    • minimum required selector precision
    • prohibited wildcard patterns
    • validation rule identifier
Artifacts
  • Scope clause setThe ordered set of clauses that partitions the grant into concrete, independently evaluable slices, each pointing at a projection policy.
data-category-sensitivity

Data category and sensitivity classification

Classification of the covered data by governed category and by sensitivity, because special or sensitive categories change the required form of the instrument, may demand explicit consent or a separate authorization, and may forbid combining the grant with others.

Questions
  1. Which data categories are covered, expressed in which governed vocabulary and version?classification
    Expected answer
    • category codes
    • vocabulary identifier
    • vocabulary version
  2. Does the scope include special-category or sensitive data that requires explicit consent or a separate instrument?requirement
    Expected answer
    • sensitivity flag per category
    • required instrument form code
    • separate-instrument requirement flag
  3. Which categories are explicitly excluded by carve-out, and how is the exclusion enforced at read time?constraint
    Expected answer
    • excluded category codes
    • enforcement point reference
    • behaviour when exclusion cannot be applied
  4. Which security labels or handling caveats travel with the covered data once disclosed?security
    Expected answer
    • security label codes
    • label propagation rule
    • handling caveat text
purpose-and-actionPurpose and Permitted Action2 findings

The declared use the grant is limited to and the operations it permits, which together bound what a lawful read may become.

purpose-specification

Purpose specification and limitation

The declared purpose in human-readable form and in a governed purpose taxonomy, the granularity required when several purposes are bundled, and the factors by which a proposed further use is judged compatible or is refused and sent back for a new grant.

Questions
  1. What is the declared purpose, and which coded purpose terms express it?definition
    Expected answer
    • purpose text
    • coded purpose terms
    • taxonomy identifier and version
  2. Is a proposed use inside the declared purpose, or does it require a new grant?decision
    Expected answer
    • compatibility assessment factors applied
    • assessment outcome
    • assessor identity and time
  3. How granular must purposes be when several are offered in one instrument?requirement
    Expected answer
    • separability rule
    • per-purpose acceptance record
    • bundling prohibition flag
  4. How is a later narrowing or widening of the declared purpose detected and handled?lifecycle
    Expected answer
    • purpose change event
    • required re-consent flag
    • effective instant of the change
Artifacts
  • Purpose statementThe bounded declaration of use, pairing the wording shown to the grantor with the coded terms that machines evaluate, plus any compatibility notes.
permitted-action-read-semantics

Permitted action and read semantics

Which operations the grant permits and which it prohibits, and what a permitted read actually includes — retrieval only, or also caching, indexing, derivation, aggregation and re-disclosure. Ambiguity here is the most common cause of a grant being exceeded without anyone noticing.

Questions
  1. Which action terms are permitted and which are explicitly prohibited under this instrument?classification
    Expected answer
    • permitted action codes
    • prohibited action codes
    • action vocabulary identifier
  2. Does a permitted read include caching, indexing, derivation or aggregation of the disclosed data?definition
    Expected answer
    • derived-use permission flags per operation
    • retention limit for cached copies
    • attribution or provenance requirement on derivatives
  3. Is one decision valid for a single read, a session, or a standing entitlement?state
    Expected answer
    • exercise unit code
    • maximum reliance duration
    • re-evaluation trigger
  4. Which actions beyond read fall outside this mixin and must be modelled elsewhere?interoperability
    Expected answer
    • excluded action codes
    • target model reference for each excluded action
conditions-and-obligationsConditions and Obligations2 findings

The machine-evaluable limits on the permission and the duties the reader accepts in exchange for it.

constraints-validity-window

Constraints and validity window

Every bound that a decision engine must evaluate: entry into force, expiry by date or by event, frequency and volume caps, spatial and jurisdictional limits, and environment conditions — together with the behaviour when a constraint attribute is simply unavailable.

Questions
  1. When does the grant enter into force and when does it end — a fixed instant, a defined event, or never?temporal
    Expected answer
    • valid-from timestamp with offset
    • valid-until timestamp with offset
    • expiry event definition
    • no-expiry flag with justification
  2. Which quantitative limits apply, such as reads per period, total count or data volume?measurement
    Expected answer
    • limit operand
    • limit operator
    • limit value and unit
    • counter reset period
  3. Which spatial or jurisdictional constraints restrict where the read may occur or where disclosed data may land?spatial
    Expected answer
    • permitted territory codes
    • prohibited territory codes
    • transfer safeguard reference
  4. What outcome applies when a constraint cannot be evaluated because an attribute is missing?exception
    Expected answer
    • default outcome code
    • attribute source fallback
    • alerting requirement
Artifacts
  • Constraint expression setThe machine-evaluable expressions attached to a rule or clause, in a declared expression language, that a decision point must satisfy before permitting a read.
obligations-and-duties

Obligations and duties on the grantee

Duties the reader accepts as the price of the grant — no onward sharing, deletion or return at the end, ethics approval, publication, attribution, collaboration — classified by whether they are pre-conditions, continuing duties or post-termination survivals, with the evidence needed to consider each discharged.

Questions
  1. Which duties attach to the grantee, and is each a pre-condition, a continuing duty, or a post-termination survival?requirement
    Expected answer
    • duty codes
    • duty timing class
    • duty deadline or duration
  2. What consequence applies if a duty is not discharged by its deadline?exception
    Expected answer
    • consequence code
    • automatic suspension flag
    • escalation target in the enforcement model
  3. What evidence is required before a duty is treated as discharged?evidence
    Expected answer
    • required evidence type
    • acceptable evidence issuer
    • evidence retention period
  4. Which duties survive revocation or expiry of the grant, and for how long?lifecycle
    Expected answer
    • surviving duty codes
    • survival duration
    • termination condition for the survival
Artifacts
  • Obligation discharge evidenceThe attestation, receipt or log excerpt submitted to show that a specific duty, such as end-of-grant erasure or return of results, was fulfilled.
consent-actConsent Act and Evidence2 layers

Where the grant rests on consent, the human act behind the instrument: how it was expressed, in what context, whether it meets the validity test, and what durable, portable evidence exists.

consent-expressionConsent Expression and Validity2 findings

The act itself, its capture context, and whether it satisfies the normative test for valid consent in the governing regime.

consent-evidenceConsent Evidence and Receipt2 findings

The durable record that supports demonstrability and the portable copy given back to the grantor.

receipt-and-portability

Receipt issuance and portability

The grantor-facing copy of what was agreed: what it must contain to be actionable, how it is delivered and re-obtained, whether a third party can verify it and check its current status, and whether it is machine-readable enough to drive withdrawal in another system.

Questions
  1. What must the receipt contain for the grantor to understand and act on what they agreed?definition
    Expected answer
    • required receipt field set
    • controller and contact details
    • withdrawal method description
  2. Through which channel is the receipt delivered, and how is it re-obtained later?process
    Expected answer
    • delivery channel
    • re-issue endpoint or procedure
    • delivery confirmation record
  3. Can a third party verify the receipt without contacting the issuer, and how is its current status checked?validation
    Expected answer
    • verification method
    • status check mechanism
    • status values and their meaning
  4. Is the receipt machine-readable enough to drive withdrawal in a system other than the issuer's?interoperability
    Expected answer
    • machine-readable format identifier
    • withdrawal endpoint carried in the receipt
    • cross-system identifier binding
Artifacts
  • Consent receiptThe durable, portable copy of what the grantor agreed to, issued back to them and independently presentable to third parties.
lifecycleLifecycle and Change3 layers

How a grant is born, changes, is suspended, ends, and how its ending reaches everyone who relied on it.

states-and-transitionsStates and Transitions2 findings

The enumerated states of an instrument, the legal transitions between them, and the clocks that govern them.

contract-state-model

Instrument state model

The state set and the legal transitions, so that any reader can determine deterministically whether the grant is live, including the treatment of proposed-but-unaccepted instruments, suspension short of termination, and disagreement between the record store and an already-issued token.

Questions
  1. What is the enumerated state set, and which transitions between states are legal?state
    Expected answer
    • state codes
    • permitted transition pairs
    • transition trigger per pair
  2. Which state is authoritative when the record store and a previously issued token disagree?decision
    Expected answer
    • precedence rule
    • maximum token reliance window
    • reconciliation procedure
  3. Can an instrument be suspended without being terminated, and what does suspension permit?lifecycle
    Expected answer
    • suspension supported flag
    • permitted operations while suspended
    • resumption conditions
  4. How is a proposed or requested instrument distinguished from an accepted and active one?classification
    Expected answer
    • instrument kind code (request, offer, agreement)
    • acceptance event reference
    • activation precondition list
Artifacts
  • State transition tableThe governed matrix of states, legal transitions, triggers and required preconditions that implementations must enforce.
temporal-semantics

Temporal semantics of the instrument

The several distinct times a grant carries and which one governs which question: the act time, the record time, entry into force, lapse, the decision time, and the correction time. Getting the wrong clock produces a decision that is defensible in code and indefensible in fact.

Questions
  1. Which timestamps are mandatory on every instrument and every consent event?temporal
    Expected answer
    • mandatory timestamp field list
    • format rule
    • offset requirement
  2. Is a time without an explicit offset ever acceptable, and what is the fallback if one is received?constraint
    Expected answer
    • acceptance rule
    • fallback offset assumption
    • quality flag raised
  3. How is a correction to a recorded time captured without rewriting history?provenance
    Expected answer
    • correction event record
    • superseded value
    • corrector identity and time
  4. Which time governs a read that begins before expiry and completes after it?exception
    Expected answer
    • governing instant rule
    • in-flight read handling
    • maximum completion grace
amendment-and-supersessionAmendment and Supersession1 findings

How a live instrument is narrowed, widened or renewed, and which changes require a fresh act of consent.

amendment-versioning-reconsent

Amendment, versioning and re-consent triggers

Which changes may be applied to a live instrument in place, which force a new consent act, how versions are identified and linked to their predecessors, from which instant a superseding version governs, and whether the regime imposes a refresh interval after which consent must be renewed.

Questions
  1. Which changes may be applied in place and which require a new consent act?decision
    Expected answer
    • change class codes
    • re-consent trigger rule per class
    • approver of the classification
  2. How are versions identified, ordered, and linked to the version they supersede?identity
    Expected answer
    • version identifier scheme
    • predecessor reference
    • ordering rule
  3. From which instant does a superseding version govern, and what governs reads already in flight?temporal
    Expected answer
    • supersession effective instant
    • in-flight read rule
    • overlap handling
  4. Is there an interval after which the instrument must be refreshed or re-confirmed?lifecycle
    Expected answer
    • refresh interval
    • basis for the interval
    • behaviour on lapse of the interval
Artifacts
  • Amendment recordThe structured record of one change to a live instrument: what changed, on whose authority, with which effect on scope, and whether a fresh consent act was required and obtained.
termination-and-propagationTermination and Propagation3 findings

Ending a grant early and making that ending real for everyone downstream.

revocation-and-withdrawal

Revocation, withdrawal and their effect

Who may end the grant early, through which channels it must be at least as easy as granting, from which instant termination bites, what it does not undo — prior lawful reads remain lawful and a reliance exception may apply — and what confirmation the grantor receives.

Questions
  1. Who may issue a withdrawal or revocation, and through which channels must it be possible?authority
    Expected answer
    • authorised issuer roles
    • required channels
    • effort-parity evidence against the granting channel
  2. From which instant does termination take effect, and are prior reads thereby invalidated?temporal
    Expected answer
    • effective instant
    • retroactivity rule
    • status of reads already performed
  3. Which processing may lawfully continue after withdrawal, and on what stated basis?exception
    Expected answer
    • continuing activity list
    • legal or reliance basis per activity
    • duration of continuation
  4. What confirmation is returned to the grantor that the withdrawal took effect?evidence
    Expected answer
    • confirmation artefact reference
    • confirmation delivery time
    • downstream propagation status at time of confirmation
Artifacts
  • Revocation or withdrawal noticeThe signed act that ends the grant, naming its issuer, reason, effective instant and the contract version terminated.
propagation-and-erasure

Downstream propagation and erasure confirmation

Making termination effective beyond the first holder: identifying every recipient that received data under the grant, notifying them within a deadline, collecting cutoff and deletion evidence, handling the case where notification is impossible or disproportionate, and deciding what happens to irreversible derivatives.

Questions
  1. Which recipients must be notified of termination, and within what deadline?process
    Expected answer
    • recipient list or category list
    • notification deadline
    • channel per recipient
  2. What counts as acceptable proof that a recipient stopped reading and deleted its copies?evidence
    Expected answer
    • acceptable proof types
    • proof issuer requirements
    • verification step
  3. What is done when notification is impossible or would involve disproportionate effort?exception
    Expected answer
    • impossibility justification record
    • alternative measure taken
    • grantor-facing disclosure of the gap
  4. How are irreversible derivatives such as trained models, aggregates and publications handled?constraint
    Expected answer
    • derivative class
    • permitted continuation basis
    • mitigation or attribution requirement
Artifacts
  • Propagation ledgerThe record of every recipient notified of a termination, the notification time, the acknowledgement received and any unresolved gap.
entitlement-cutoff

Entitlement tokens and cutoff

UMA issues an RPT unique to requesting party, client, authorization server, resource server and resource owner; permissions on the token are opaque to the client. Refresh MUST NOT re-run authorization assessment. RFC 7009 revocation, with UMA token type hint pct, cuts tokens. FHIR expects signatures and ceremony stages in Provenance, DocumentReference or Contract attachments rather than in Consent itself. After withdrawal or expiry, every holder of data under the grant must be notified and must confirm cutoff; ISO 27560 does not define that protocol, so this mixin records propagation status as an operating concern and leaves transport to implementations. Partial propagation is a first-class state, not a success. Cached validity tokens MUST expire no later than the grant window and SHOULD be revoked when the instrument is withdrawn.

Questions
  1. Is there a current entitlement token, of which kind, expiring when, and is it unique to this requesting party and client?security
    Expected answer
    • entitlement_token_id
    • token_kind
    • token_expires_at
  2. Which parties currently hold copies or caches under this grant, and which have confirmed cutoff?process
    Expected answer
    • holder_party_ids
    • propagation_status
    • cutoff_confirmed_time
  3. Were RPTs, refresh tokens and persisted-claims tokens revoked, at what time, and did refresh continue to mint access without re-assessment?security
    Expected answer
    • token_revoked_time
    • token_kind
Artifacts
  • Revocation propagation ledgerPer-holder cutoff acknowledgements and token revocation times for one termination event.
decision-surfaceDecision and Verification Surface2 layers

The minimal, privacy-preserving interface by which a data holder asks whether a specific read is covered, and how competing instruments are combined into one answer.

coverage-decisionCoverage Decision2 findings

The request, the outcome vocabulary, the returned obligations and the handling of unevaluable cases.

coverage-decision-exchange

Coverage decision request and response

What a holder must supply for a decision to be evaluable, what may be returned beyond the bare outcome, and how long a decision may be relied on — deliberately structured so the asking party learns nothing about parties, purpose or terms it does not need.

Questions
  1. Which attributes must the requester supply before a decision can be evaluated at all?process
    Expected answer
    • required attribute list
    • attribute source or issuer
    • behaviour on missing attribute
  2. Which decision values may be returned, and what must the enforcing party do for each?decision
    Expected answer
    • outcome vocabulary
    • required enforcement behaviour per outcome
    • logging obligation per outcome
  3. What may be returned alongside the outcome — obligations, scope fingerprint, expiry — without disclosing contract content?privacy
    Expected answer
    • permitted response field set
    • scope fingerprint construction rule
    • fields explicitly withheld
  4. How long may a decision be cached and relied upon before re-evaluation?temporal
    Expected answer
    • maximum reliance duration
    • invalidation triggers
    • cache key composition
Artifacts
  • Decision responseThe structured answer returned to an enforcing party: outcome, obligations, validity horizon and correlation identifier, and nothing else.
fail-closed-handling

Unevaluable outcomes and fail-closed behaviour

What happens when the instrument cannot be evaluated — missing attributes, unreachable authority record, unverifiable proof, contradictory state — including the distinction between a constraint that is unsatisfied and one that could not be evaluated, and which unevaluable outcomes must raise an operational alert rather than a silent denial.

Questions
  1. Is the default outcome denial, and under which narrow, declared conditions may any fallback permit apply?constraint
    Expected answer
    • default outcome
    • fallback conditions if any
    • approver of each fallback
  2. How is an unevaluable constraint distinguished from one that was evaluated and not satisfied?validation
    Expected answer
    • outcome discriminator code
    • diagnostic reason code
    • attribute that could not be resolved
  3. What diagnostic detail may be returned to the requester without leaking contract content?privacy
    Expected answer
    • permitted reason code set
    • prohibited detail list
    • internal-only diagnostic channel
  4. Which unevaluable outcomes must raise an operational alert rather than resolve to a silent denial?exception
    Expected answer
    • alertable reason codes
    • alert target
    • suppression rules and their review interval
conflict-precedenceConflict and Precedence1 findings

How several applicable instruments, prohibitions and overriding duties are combined into one defensible outcome.

multi-grant-conflict

Multi-instrument conflict resolution

The declared strategy for combining a permission with a prohibition, whether a later or narrower instrument supersedes an earlier or broader one, how a conflict between a grant and an overriding legal duty is recorded rather than silently resolved, and whether the strategy is declared on the instrument or fixed by the adopting Dimension.

Questions
  1. Which combining strategy applies when one instrument permits and another prohibits the same read?decision
    Expected answer
    • strategy identifier
    • outcome under the strategy
    • precedence order applied
  2. Does a narrower or later instrument automatically supersede a broader or earlier one?constraint
    Expected answer
    • supersession rule
    • tie-break rule
    • explicit non-supersession cases
  3. How is a conflict between the instrument and an overriding legal duty recorded and surfaced?exception
    Expected answer
    • override basis reference
    • recorded conflict entry
    • notification obligation to the grantor
  4. Is the combining strategy declared on the instrument or fixed by the adopting Dimension?authority
    Expected answer
    • declaration site
    • default strategy when undeclared
    • who may change it and under what review
Artifacts
  • Conflict resolution declarationThe published statement of combining strategy and precedence order that every decision point in the Dimension must apply identically.
assurance-and-stewardshipAssurance and Stewardship3 layers

Trustworthiness of the instrument and its evidence over time: provenance, integrity, retention, and who may read the contract record itself.

provenance-integrityProvenance and Integrity2 findings

Where each record came from, who is accountable for it, and how it is made tamper-evident and comparable.

record-provenance-integrity

Record provenance and integrity

The authoritative system of record for each instrument, who created and last changed it, how imported or migrated records are distinguished from natively captured ones, and how the record is canonicalised before hashing or signing so that integrity checks remain stable across storage formats.

Questions
  1. Which system of record is authoritative for this instrument, and what is its identifier there?provenance
    Expected answer
    • system of record identifier
    • native record identifier
    • synchronisation state and time
  2. How is the record canonicalised before it is hashed or signed?quality
    Expected answer
    • canonicalisation algorithm identifier
    • field ordering and normalisation rules
    • fields excluded from the digest
  3. Who is accountable for the correctness of each recorded assertion?ownership
    Expected answer
    • accountable role
    • named steward reference
    • escalation path for disputed assertions
  4. How are imported or migrated records distinguished from natively captured ones?classification
    Expected answer
    • capture origin code
    • migration batch reference
    • confidence or completeness flag
Artifacts
  • Integrity manifestThe digest and signature manifest covering a specific record version, naming the canonicalisation rule applied and the fields it covers.
instrument-identity

Instrument identity

An access contract MUST have a unique identifier. ODRL requires Policy.uid as an IRI. ISO/IEC TS 27560 requires a record identifier and a schema_version, and a distinct receipt identifier when a receipt is issued. FHIR Consent.identifier is a business identifier for a copy of the statement and is not the FHIR resource id. A calendar date is not an identifier. When the adopting Dimension masters the record, it assigns a UUID or ULID only after master-system and IRI identifiers are absent.

Questions
  1. What is the canonical identifier of this access contract, in which scheme, and which mastering system assigned it?identity
    Expected answer
    • access_contract_id
    • id_scheme
    • mastering_system
  2. Which information-model profile and schema version interpret the terms of this instrument?interoperability
    Expected answer
    • schema_profile_uri
    • schema_version
  3. Is this instance the master record, a FHIR copy identifier, or a receipt that only references the record?provenance
    Expected answer
    • instance_role
    • source_record_id
    • receipt_id
Artifacts
  • Instrument header recordStable identity envelope: identifiers, schema/profile, version, language, jurisdiction, created and updated observation times.
retention-erasureRetention and Erasure1 findings

How long the instrument and its evidence are kept once the grant has ended, and the tension between demonstrability and minimisation.

retention-of-records

Retention and erasure of instrument and evidence

How long each record class survives termination and on what basis, which fields must be minimised while keeping the record demonstrable, whether an erasure request extinguishes the consent evidence itself, and what remains as a tombstone once the substantive record is gone.

Questions
  1. How long must the instrument and its consent evidence be retained after termination, and on what stated basis?retention
    Expected answer
    • retention period per record class
    • legal or contractual basis
    • review trigger at end of period
  2. Which fields must be minimised or redacted while keeping the record capable of demonstrating the act?privacy
    Expected answer
    • minimisable field list
    • redaction method
    • effect on the integrity digest
  3. Does an erasure request from the grantor extinguish the consent evidence itself?exception
    Expected answer
    • erasure scope decision
    • competing obligation cited
    • documented outcome and its approver
  4. What is deleted, what is anonymised, and what remains as a tombstone after the retention period?decision
    Expected answer
    • deleted field set
    • anonymised field set
    • tombstone field set and its retention
Artifacts
  • Retention scheduleThe governed table mapping each record class to its retention period, basis, minimisation rule and disposal outcome.
contract-record-accessAccess to the Contract Record1 findings

Governing reads of the instrument itself, which contains personal data about the grantor and commercially sensitive terms.

access-to-contract-record

Access to the instrument and its evidence

The recursive problem: who may read the instrument as opposed to merely relying on a validity token, which projection each role receives, whether a grantee may learn about other grantees or other grants, and how supervisory or regulator access is authorised and logged.

Questions
  1. Who may read the full instrument, and who may receive only a validity token?access
    Expected answer
    • role to projection mapping
    • default projection for unlisted roles
    • approval required for full access
  2. Which named projection does each role receive, and what does each omit?access
    Expected answer
    • projection name
    • included field set
    • explicitly omitted field set
  3. May a grantee learn the identity of other grantees or the existence of other grants over the same objects?privacy
    Expected answer
    • visibility rule
    • aggregation and inference safeguards
    • exception conditions
  4. How is supervisory or regulator access authorised, bounded and logged?authority
    Expected answer
    • authorising instrument reference
    • permitted scope and duration
    • logging and grantor notification rules
Artifacts
  • Contract projection profileThe declared set of named projections over the instrument — validity token, grantor ledger, grantee entitlement list — each with its included and omitted fields.
interoperabilityInteroperability and Jurisdiction2 layers

Declared, evidence-backed mappings to external standards, and the parameters that change with the governing legal regime.

standards-alignmentStandards Alignment1 findings

Crosswalks to external vocabularies with explicit statements of fidelity and loss.

standards-alignment-map

Standards alignment and conformance claims

Which external concept each core element maps to and at what fidelity, which mappings lose information and in which direction, whether any conformance claim is asserted and on what evidence, and the fallback when a target standard has no equivalent concept.

Questions
  1. To which external standard concept does each core element map, and at what fidelity?interoperability
    Expected answer
    • source element
    • target standard and version
    • target concept identifier
    • fidelity rating
  2. Which mappings are lossy, and precisely what is lost in each direction?quality
    Expected answer
    • lossy mapping identifier
    • lost element per direction
    • mitigating carrier field
  3. Is a conformance claim asserted against any target standard, and what evidence supports it?evidence
    Expected answer
    • claim statement or explicit absence
    • test or audit evidence reference
    • claim scope and expiry
  4. What is the fallback when a target standard has no equivalent concept for a required element?exception
    Expected answer
    • extension mechanism used
    • profile or namespace identifier
    • interoperability warning raised to consumers
Artifacts
  • Alignment crosswalkThe versioned mapping table from this model's elements to external standard concepts, with fidelity, direction and loss recorded per row.
jurisdictional-varianceJurisdictional Variance2 findings

The parameters that must be supplied per legal regime before the instrument can be validated at all.

jurisdictional-parameters

Jurisdictional parameters and instrument form

Which law governs the instrument, which authority is competent, whether consent or a differently-shaped authorization is the correct instrument, the age threshold at which a person may consent for themselves, whether conditioning a service on the grant is permitted, and which cross-border transfer conditions attach to the covered read.

Questions
  1. Which law governs this instrument, and which supervisory authority is competent over it?authority
    Expected answer
    • governing law identifier
    • competent authority reference
    • choice-of-law basis
  2. In this jurisdiction, is the correct instrument a consent, an authorization, or another form with different mandatory elements?classification
    Expected answer
    • instrument form code
    • mandatory element set for that form
    • validity defect list for that form
  3. What is the age at which a person may grant for themselves in this jurisdiction, and how is a lower age handled?constraint
    Expected answer
    • age threshold
    • verification method for parental responsibility
    • behaviour when age is unknown
  4. Which cross-border transfer conditions attach to a read performed outside the originating jurisdiction?spatial
    Expected answer
    • permitted destinations
    • required safeguard instrument
    • record of the safeguard relied on
Artifacts
  • Jurisdiction profileThe per-regime parameter set — instrument form, mandatory elements, age threshold, conditioning rules, transfer conditions, retention floor — that a validator loads before assessing an instrument.
instrument-flavour-classification

Instrument classification

The same mixin covers several disjoint subtypes that MUST be classified rather than conflated: ODRL Set (generic rules), Offer (assigner offers, does not grant), Agreement (assigner has granted to assignee); FHIR privacy consent directive versus treatment or research-participation consent; ISO 27560 consent record (privacy processing) versus a non-personal usage licence. FHIR decision is permit or deny as the default, with nested provisions as exceptions. ODRL Policy may declare a conflict strategy (perm, prohibit, invalid). Regulatory basis and category support indexing but do not themselves grant access.

Questions
  1. Is this instrument an Offer, an Agreement already granted, a FHIR draft, or a mere Set of rules?classification
    Expected answer
    • policy_subclass
    • status
  2. Does this grant authorise processing of personal data on a consent legal basis, or only usage of a non-personal asset?classification
    Expected answer
    • grant_flavour
    • regulatory_basis_codes
  3. If a requested read matches no provision, is the default permit, deny, or invalid-by-conflict?decision
    Expected answer
    • default_decision
    • conflict_strategy
Artifacts
  • Classification blockTyped flags that tell evaluators which rule family and default decision to apply.

Publication holds

  • Source liveness and version pinning is unverified for all nineteen accepted sources. Two specific reconciliations are mandatory before publication: pin FHIR Consent to the version-qualified R5 URL rather than the unversioned current URL that will drift, and reconcile the two DPVCG 27560-guide citations that disagree on both host and date (w3c-cg.github.io retrieved 2026-08-23 versus w3id.org Final Community Group Report 15 February 2026).
  • Domain-profile validation is incomplete. The model has been exercised only against EU/GDPR, the US health sector under 45 CFR 164.508, and a healthcare FHIR profile. At least one non-health, non-EU jurisdiction profile must be run end to end before publication to test whether the instrument-form and flavour parameters actually generalise.
  • Normative text for ISO/IEC TS 27560:2023 and ISO/IEC 29184:2020 is paywalled; field inventories rest on catalogue pages plus the DPVCG mapping rather than annex text. TS 27560 is a Technical Specification, not an International Standard, and a revision (CD 27560.2) may change mandatory fields. Any field-level claim must be labelled as mapping-derived.
  • The security dimension is self-declared a gap by the base (key management, token binding, replay resistance, cryptographic proof suites). Now that entitlement cutoff is imported, publication must name the sibling security model that owns these and state plainly that this model does not close them.
  • Collective, community and Indigenous group permission is unsupported by any source in either pack and must be published as an explicitly unmodelled gap, never approximated through the delegate capacity.

Deferred research

  • Grantor succession: death, loss of capacity, corporate merger, joint-controller arrangements and restoration after accidental withdrawal. GDPR Recital 27 leaves deceased persons to Member State law and no consulted source supplies a primary encoding; needs jurisdiction-profile research before any structure is minted.
  • Preference signals under ISO/IEC TS 27560 Annex F, including Global Privacy Control and CPRA-style opt-out signals. The base lists these as unexamined omissions and Grok flags promoting them to consent as an unproven alignment; research must settle whether they are ever a valid control input.
  • ODRL action inheritance via includedIn and implies, and the inherited permission/prohibition conflicts it produces within a single instrument. Needs grounding in the ODRL Vocabulary before folding into the conflict-precedence layer and the newly added conflict-evaluation function.
  • Informedness testing sources are split across providers: only the base fetched EDPB Guidelines 05/2020 and only Grok cited ISO/IEC 29184:2020. Reconcile both against the transparency sibling boundary so notice-content controls are tested without duplicating the notice model.
  • Regimes not examined by either provider: ePrivacy and cookie consent, LGPD, PIPL, APPI, and the consent-manager architecture of India's DPDP Act, each of which may change the instrument form rather than merely its parameters.
  • Machine and AI agents as grantees, and multi-hop delegation chains of arbitrary depth. Sub-delegation is asked about in the base but the transitive closure of delegated grants has no primary encoding in either pack.