# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "research-draft", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-28T20:31:33Z", "synthesisSha256": "96a40c5bc14bfef3d0e41c9e4de82e3fc57ecd38395fc784aa5752250c76ba5e", "providers": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-003", "registryId": "vr.wm-xct-003", "name": "Projection / Disclosure Policy", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.DSC" ], "tags": [ "projection", "disclosure", "policy", "xct.dsc" ], "status": "research draft" }, "canonicalUrl": "https://ver.cy/models/wm-xct-003-projection-disclosure-policy/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-003", "model": { "registry_id": "vr.wm-xct-003", "model_id": "WM-XCT-003", "name": "Projection / Disclosure Policy", "entry_kind": "mixin", "purpose": "Define, in a storage- and interface-neutral way, the shape data is permitted to leave in - which elements, after which transformations, over which records, at which grain - so one reusable shape specification can be bound to many contracts and audiences and can be reproduced and explained afterwards.", "scope_statement": "A mix-in that specializes a generic governed policy (WM-KNW-012) with output-shape semantics only. It owns the declarative output shape (element selection, per-element treatment, record scope, aggregation grain), the order relation and least-disclosure combination over shapes, the compiled output template and its fingerprint, the binding of a shape to a target and audience as references, the declared identifiability and assurance properties of the shape, shape-specific change classification, and alignment with external policy-expression standards. It does not own policy identity, authority, approval, versioning state or conflict resolution; nor ownership, authorization, consent, classification, source-schema semantics, threshold or budget computation, audit records, or any runtime evaluation, decision, enforcement or execution over instance data. It holds no instance data.", "in_scope": [ "Declarative output-shape definition: selection sets with a default treatment, per-element transformation technique and parameters, record-set scope, aggregation grain", "Shape algebra: the subsumption test deciding whether one shape is no wider than another, and the meet operation combining two applicable shapes into a least-disclosure shape", "Compiled output templates and their content fingerprints as reproducible derivations from a pinned policy version and pinned source schema version", "Binding of a shape to a target, audience and effective window, expressed purely as references", "Declared identifiability roles, assurance-method claims and cross-release linkability properties of a shape", "Shape-specific change classification (narrowing, widening, orthogonal) and invalidation signals", "Alignment of the shape vocabulary with external policy-expression and selective-disclosure standards", "The projection under which the policy record itself is published" ], "out_of_scope": [ "Generic policy identity, authority, approval, versioning state and conflict resolution (WM-KNW-012)", "Ownership, stewardship and delegation over the underlying data (WM-XCT-001)", "Authorization, purpose, parties and consent lifecycle (WM-XCT-002)", "Audit records, append-only access trails and their ordering, immutability and retention (WM-XCT-004)", "Cohort-floor and threshold computation, privacy budget accounting and aggregation assurance (WM-XCT-005)", "Sensitivity classification schemes, criteria and class assignment (WM-XCT-020)", "Source schema semantics, validation contracts and data quality (WM-DAT-004)", "Runtime evaluation, decision outcome, explanation, obligation discharge and enforcement for a concrete request (WM-XCT-038)", "Execution of transformations on instance data, key custody, and storage or transport of disclosed outputs", "Legal determination of lawfulness: regimes are cited as constraints, never interpreted here" ], "boundary_notes": [ { "neighbor": "WM-KNW-012 governed policy", "distinction": "The target owns policy identity, authoring authority, approval, version states, supersession and conflict resolution. This model adds only output-shape semantics and the shape-specific classification of a change; it never re-declares a policy lifecycle state machine.", "source_refs": [ "SRC-001", "SRC-011" ] }, { "neighbor": "WM-XCT-038 runtime enforcement", "distinction": "Using the XACML separation, this model is administration-side declarative content. Selecting applicable policies, evaluating conditions, producing a decision or explanation, discharging obligations and applying a shape to instance data all belong to the target.", "source_refs": [ "SRC-011", "SRC-001" ] }, { "neighbor": "WM-XCT-005 privacy aggregation", "distinction": "This model declares the grain, the measures and a reference to the applicable floor or budget instrument. Computing cohort floors, quantifying re-identification risk and accounting a differential-privacy budget belong to the target.", "source_refs": [ "SRC-004", "SRC-003" ] }, { "neighbor": "WM-XCT-020 sensitivity classification", "distinction": "The target owns the scheme, its criteria and the assignment of a class to an element. This model only keys a minimum-treatment constraint on an externally assigned class and reacts to reclassification as an input signal.", "source_refs": [ "SRC-008", "SRC-010" ] }, { "neighbor": "WM-DAT-004 source schema / data contract", "distinction": "The target owns source semantics, structure and validation. This model holds path expressions resolved against a pinned schema version, the resolution state of those paths, and the derived output template.", "source_refs": [ "SRC-006", "SRC-014" ] }, { "neighbor": "WM-XCT-004 access audit", "distinction": "This model defines only which shape-identifying values must be emitted with a served output. Writing, ordering, protecting and retaining the audit entry belong to the target; no audit-trail semantics are modelled here.", "source_refs": [ "SRC-003", "SRC-013" ] }, { "neighbor": "WM-XCT-002 access contract / consent", "distinction": "The target owns whether data may flow, for which purpose, to which party, under which consent. This model says only what the flow looks like and carries the binding reference.", "source_refs": [ "SRC-001", "SRC-005" ] }, { "neighbor": "WM-XCT-001 ownership and delegation", "distinction": "The target owns who holds an object and who may act for them. This model records only the reference to the authority required for a shape to be publishable and the party who accepted a residual-disclosure risk.", "source_refs": [ "SRC-012", "SRC-003" ] }, { "neighbor": "Serialization and interface layers (JSON, YAML, Markdown, Git, MCP, MongoDB)", "distinction": "Encodings are projections of one semantic shape. The model records which encodings are approved and whether semantics are preserved, and never treats a format as the definition of the shape.", "source_refs": [ "SRC-014", "SRC-007" ] } ] }, "sources": [ { "id": "SRC-001", "title": "ODRL Information Model 2.2", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/odrl-model/", "version_or_date": "W3C Recommendation, 15 February 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Normative model for Policy, Rule (Permission/Prohibition/Duty), Constraint, Asset, Party functions (assigner/assignee), conflict strategy and profiles. Grounds binding, applicability conditions and the boundary that generic conflict handling is not local." }, { "id": "SRC-002", "title": "ODRL Vocabulary & Expression 2.2", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/odrl-vocab/", "version_or_date": "W3C Recommendation, 15 February 2018; namespace http://www.w3.org/ns/odrl/2/", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Defines the actions anonymize, aggregate, derive, extract and index, and the constraint left operands (purpose, recipient, spatial, delivery channel). Verified against the published RDF that these actions carry no de-identification or field-selection parameters." }, { "id": "SRC-003", "title": "NIST SP 800-188, De-Identifying Government Datasets: Techniques and Governance", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/188/final", "version_or_date": "Final, September 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Release models (public dataset, synthetic data, query interface, protected enclave), Disclosure Review Board governance, removal of direct identifiers and transformation of quasi-identifiers, and the need for documented, measurable de-identification decisions." }, { "id": "SRC-004", "title": "NIST SP 800-226, Guidelines for Evaluating Differential Privacy Guarantees", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/226/final", "version_or_date": "Final, March 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Formal privacy guarantees, the differential privacy pyramid and privacy hazards. Grounds the aggregate-grain, perturbation and multi-release composition findings while leaving budget accounting to WM-XCT-005." }, { "id": "SRC-005", "title": "45 CFR 164.514 - Other requirements relating to uses and disclosures of protected health information", "organization": "U.S. Government Publishing Office / U.S. Department of Health and Human Services", "url": "https://www.govinfo.gov/content/pkg/CFR-2023-title45-vol2/pdf/CFR-2023-title45-vol2-sec164-514.pdf", "version_or_date": "Code of Federal Regulations, 2023 annual edition, title 45 volume 2", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Binding example of a regime-prescribed output shape: expert determination (b)(1), the Safe Harbor identifier list (b)(2), the re-identification code rule (c), minimum necessary (d) and the limited data set with a data use agreement (e)." }, { "id": "SRC-006", "title": "RFC 9535, JSONPath: Query Expressions for JSON", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9535.html", "version_or_date": "RFC 9535, February 2024, Standards Track", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Normative path grammar for addressing selected elements: segments, name/wildcard/index/slice/filter selectors, nodelists and Normalized Paths, plus its stated relationship to RFC 6901 JSON Pointer." }, { "id": "SRC-007", "title": "RFC 9901, Selective Disclosure for JSON Web Tokens (SD-JWT)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/info/rfc9901/", "version_or_date": "RFC 9901, November 2025, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Holder-selected disclosure: salted-hash digests, Disclosures, the _sd claim, decoy digests against structural leakage, and Issuer/Holder/Verifier roles. Grounds encoding profile, residual disclosure and accountability when the holder chooses the shape." }, { "id": "SRC-008", "title": "ISO/IEC 20889:2018 Privacy enhancing data de-identification terminology and classification of techniques", "organization": "International Organization for Standardization / International Electrotechnical Commission", "url": "https://www.iso.org/standard/69373.html", "version_or_date": "First edition, 2018-11", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Governed terminology for de-identification technique families and for identifier, quasi-identifier, sensitive attribute and re-identification risk. Catalogue record verified live; full normative text is paywalled, so the model cites terminology roles rather than clause numbers." }, { "id": "SRC-009", "title": "ISO/IEC 27559:2022 Privacy enhancing data de-identification framework", "organization": "International Organization for Standardization / International Electrotechnical Commission", "url": "https://www.iso.org/standard/71677.html", "version_or_date": "First edition, 2022-11", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Framework for assessing context, data environment, attacker capability and de-identification governance across the lifecycle of disclosed data. Grounds adversary assumptions, release-set effects and invalidation signals. Full text paywalled." }, { "id": "SRC-010", "title": "Data Privacy Vocabulary (DPV) version 2.1", "organization": "W3C Data Privacy Vocabularies and Controls Community Group", "url": "https://w3c-cg.github.io/dpv/2.1/dpv/", "version_or_date": "Version 2.1, 16 March 2025; namespace https://w3id.org/dpv#", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Machine-readable terms for Anonymisation, Pseudonymisation, De-Identification, Data Redaction, Generalisation, Aggregation, Differential Privacy, Synthetic Data and personal-data categories. Community Group output, not a W3C Recommendation." }, { "id": "SRC-011", "title": "eXtensible Access Control Markup Language (XACML) Version 3.0", "organization": "OASIS", "url": "https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html", "version_or_date": "OASIS Standard, 22 January 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "PolicySet/Policy/Rule structure, Target, combining algorithms, Obligations and Advice, and the PAP/PDP/PEP/PIP separation that grounds the boundary between this model (administration-side content) and WM-XCT-038 (evaluation and enforcement)." }, { "id": "SRC-012", "title": "Guidelines 4/2019 on Article 25 Data Protection by Design and by Default, Version 2.0", "organization": "European Data Protection Board", "url": "https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-42019-article-25-data-protection-design-and_en", "version_or_date": "Version 2.0, adopted 20 October 2020", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Supervisory-authority guidance that data minimisation and limited accessibility must be the default, achieved through measures such as limiting access, aggregation, pseudonymisation and anonymisation. Grounds default-deny selection and the class-to-treatment minimum." }, { "id": "SRC-013", "title": "RFC 3339, Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Normative timestamp profile: full-date, full-time with two-digit seconds, and a time-offset of Z or +/-hh:mm, with -00:00 reserved for an unknown local offset. Grounds the timestamp rule and the separation of event from observation time." }, { "id": "SRC-014", "title": "JSON Schema: A Media Type for Describing JSON Documents (2020-12 dialect)", "organization": "JSON Schema (IETF Internet-Draft draft-bhutton-json-schema-01)", "url": "https://json-schema.org/draft/2020-12/json-schema-core", "version_or_date": "2020-12 dialect, draft-bhutton-json-schema-01, 16 June 2022", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-28T09:00:00Z", "relevance": "Schema identification by $id and $schema, $ref, vocabularies and dialects, and the role of a schema as an assertion-plus-annotation contract. Grounds the compiled output template as a verifiable schema fragment. Expired Internet-Draft, not an RFC." }, { "id": "SRC-015", "title": "45 CFR 164.514 Other requirements relating to uses and disclosures of protected health information", "organization": "U.S. HHS (eCFR)", "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514", "version_or_date": "current as of 2026-08-26", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T00:00:00Z", "relevance": "Supplies the Safe Harbor identifier pack, expert determination, limited data set, re-identification code conditions, and minimum-necessary policy requirements used as treatment packs and binding constraints." }, { "id": "SRC-016", "title": "Regulation (EU) 2016/679 (GDPR) Article 5 — Principles relating to processing of personal data", "organization": "European Parliament and Council / EUR-Lex", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679", "version_or_date": "2016-04-27; OJ L 119, 4.5.2016", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T00:00:00Z", "relevance": "Article 5(1)(b)–(c) couple purpose limitation with data minimisation, grounding grain choice and binding purpose alignment." }, { "id": "SRC-017", "title": "eXtensible Access Control Markup Language (XACML) Version 3.0 Plus Errata 01", "organization": "OASIS", "url": "https://docs.oasis-open.org/xacml/3.0/errata01/os/xacml-3.0-core-spec-errata01-os-complete.html", "version_or_date": "2017-07-12", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T00:00:00Z", "relevance": "Targets, environment attributes and obligations cited for binding attachment and precedence parameters; combining algorithms and evaluation remain in sibling models." }, { "id": "SRC-018", "title": "XACML v3.0 Multiple Decision Profile Version 1.0", "organization": "OASIS", "url": "https://docs.oasis-open.org/xacml/3.0/xacml-3.0-multiple-v1-spec-cd-03-en.html", "version_or_date": "Committee Draft 03, 2010-03-11 (cited by XACML 3.0 core as [Multi])", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T00:00:00Z", "relevance": "Interprets a multiple:content-selector XPath as one decision per node, cited for hierarchical node selection in nested and graph extent." }, { "id": "SRC-019", "title": "OData Version 4.01. Part 1: Protocol — §11.2.5 Specifying Properties to Return; §8.2.8.6 omit-values; §10 Context URL", "organization": "OASIS", "url": "https://docs.oasis-open.org/odata/odata/v4.01/os/part1-protocol/odata-v4.01-os-part1-protocol.html", "version_or_date": "OASIS Standard, 2020-04-23", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T00:00:00Z", "relevance": "$select and $expand path selection, omit-values preference, and context URL fragments naming selected and expanded properties; source of the 'MAY return additional information' conflict." }, { "id": "SRC-020", "title": "GraphQL Specification — Selection Sets, Fields, Client-specified response", "organization": "GraphQL Foundation / Joint Development Foundation", "url": "https://spec.graphql.org/October2021/", "version_or_date": "October 2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T00:00:00Z", "relevance": "Hierarchical selection sets and client-specified exact response shape, with validation of a requested shape against the type system before execution." }, { "id": "SRC-021", "title": "HL7 FHIR R5 Search — _summary, _elements, SUBSETTED", "organization": "HL7 International", "url": "https://hl7.org/fhir/search.html", "version_or_date": "FHIR v5.0.0, current published version as retrieved 2026-08-28", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T00:00:00Z", "relevance": "Named summary modes (_summary true/text/data/count), _elements behaviour including mandatory elements, and SUBSETTED tagging of incomplete resources." }, { "id": "SRC-022", "title": "JSON:API 1.1 — Sparse Fieldsets", "organization": "jsonapi.org", "url": "https://jsonapi.org/format/#fetching-sparse-fieldsets", "version_or_date": "v1.1 (latest published as retrieved 2026-08-28)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T00:00:00Z", "relevance": "Sparse fieldsets: comma-separated field lists, empty value meaning no fields, and the requirement not to include additional fields when a restricted set is requested." } ], "structure": { "bundles": [ { "id": "shape-semantics", "name": "Shape Semantics", "description": "What an output shape actually is: which elements leave, how each is transformed, which records are in scope, at what grain, and how two shapes compare and combine.", "rationale": "This is the only concern the registry entry assigns exclusively to this model - the shape data leaves in. Every other bundle either derives from it or references a model that owns its subject.", "source_refs": [ "SRC-005", "SRC-008", "SRC-012", "SRC-003" ], "layers": [ { "id": "element-selection", "name": "Element Selection", "description": "Which elements of a source structure may leave, expressed as sets over a declared default, and how those elements are addressed.", "source_refs": [ "SRC-006", "SRC-012", "SRC-005" ], "findings": [ { "id": "selection-scope-and-defaults", "name": "Selection Sets and Default Treatment", "description": "Include and exclude sets over source elements, the default treatment applied to everything the sets do not name, and whether the shape is closed against elements it has never seen.", "source_refs": [ "SRC-012", "SRC-005", "SRC-001" ], "questions": [ { "id": "q-sel-default", "text": "What treatment applies to a source element that neither the include nor the exclude set names?", "kind": "constraint", "answer_data": [ "default treatment code (omit, deny, mask, pass-through)", "justification for a default other than omit" ] }, { "id": "q-sel-overlap", "text": "When an include path and an exclude path both match one element, which prevails and on what rule?", "kind": "decision", "answer_data": [ "resolution rule code (exclude-wins, most-specific-wins)", "worked example path pair" ] }, { "id": "q-sel-mandatory", "text": "Which elements must survive selection for the output to remain usable, and what happens when the policy would remove them?", "kind": "requirement", "answer_data": [ "mandatory element path list", "failure mode code (refuse, serve degraded, empty result)" ] }, { "id": "q-sel-unseen", "text": "How is an element treated that was added to the source after this shape was authored?", "kind": "exception", "answer_data": [ "closure mode code (closed, open)", "unmatched-element outcome code", "notification target reference" ] } ], "data_elements": [ { "id": "de-sel-include-set", "name": "Include path set", "description": "Ordered set of path expressions naming elements permitted to leave.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-sel-exclude-set", "name": "Exclude path set", "description": "Ordered set of path expressions naming elements that must not leave.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-005" ] }, { "id": "de-sel-default-treatment", "name": "Default treatment", "description": "Code applied to any element not matched by either set; default-deny is the expected value.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "de-sel-closure-mode", "name": "Closure mode", "description": "Whether the shape is closed (unknown elements never leave) or open (unknown elements follow the default).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Selection sets and their default are the policy record's own declarative content: structured values held with the policy, not a separate deliverable. Any file, table or document form is a projection of those values, so declaring an artifact here would confuse the shape with one of its encodings." }, { "id": "path-expression-and-addressing", "name": "Path Expression and Element Addressing", "description": "How a shape addresses source elements across media, which grammar it uses, and what keeps an address resolvable when the source moves or repeats elements.", "source_refs": [ "SRC-006", "SRC-014", "SRC-010" ], "questions": [ { "id": "q-path-grammar", "text": "Which path grammar and grammar version does this shape use to address source elements?", "kind": "definition", "answer_data": [ "grammar identifier (RFC 9535 JSONPath, RFC 6901 JSON Pointer, column name, property IRI)", "grammar version" ] }, { "id": "q-path-media", "text": "How is an element located when the source is not a JSON tree, such as a tabular column, an RDF triple, a binary region or a span of free text?", "kind": "interoperability", "answer_data": [ "media kind code", "media-specific locator expression", "locator normalisation rule" ] }, { "id": "q-path-stability", "text": "How does an address stay resolvable when the source element is renamed, moved or occurs many times?", "kind": "identity", "answer_data": [ "normalized path form", "prior-path alias list", "repetition semantics code (all matches, first match)" ] }, { "id": "q-path-forbidden", "text": "Which path constructs are forbidden because their result is non-deterministic or unbounded?", "kind": "constraint", "answer_data": [ "forbidden construct list", "rationale per construct" ] } ], "data_elements": [ { "id": "de-path-grammar-id", "name": "Path grammar identifier", "description": "The governed grammar in which every path expression of this shape is written.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-path-expression", "name": "Path expression", "description": "A single locator addressing one or more source elements.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-path-normalized-form", "name": "Normalized path", "description": "Canonical single-node form of a resolved path, used for ordering, digesting and diffing.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-path-media-kind", "name": "Source media kind", "description": "The medium the locator addresses, which determines the applicable locator syntax.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "Addressing is reference data that only has meaning when resolved against the source schema owned by WM-DAT-004. Materialising it as a local artifact would duplicate a structure this model does not own and would go stale independently of the schema." }, { "id": "graph-extent-and-nested-shape", "name": "Expansion, include, and hierarchical node selection", "description": "Output shape is a graph, not only a column list. OData $expand includes related resources inline and may nest $select; context URLs describe projected+expanded entities. GraphQL selection sets are hierarchical down to scalars. FHIR _include/_revinclude add referenced resources; they cannot mix with _summary=text. JSON:API compound documents require full linkage except where sparse fieldsets exclude relationship fields. XACML Multiple Decision Profile interprets a multiple:content-selector XPath as one decision per node. This model records maximum expand depth, allowed navigation paths, and whether related resources inherit the parent policy or a nested policy.", "source_refs": [ "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022" ], "questions": [ { "id": "graph-extent-and-nested-shape-q01", "text": "Which navigation/relationship paths may be expanded, and to what maximum depth?", "kind": "constraint", "answer_data": [ "expansion_extent — array<{path, max_depth}>, cardinality 0..n" ] }, { "id": "graph-extent-and-nested-shape-q02", "text": "Does each expanded type use this policy, a nested projection-policy reference, or inherit parent treatments?", "kind": "relationship", "answer_data": [ "nested_policy_binding — array<{type_or_path, policy_ref, inherit}>, cardinality 0..n" ] }, { "id": "graph-extent-and-nested-shape-q03", "text": "For hierarchical XML/JSON resources, is a content-selector (XPath/JSONPath) used to name the nodes whose shape is governed, analogous to XACML multiple:content-selector?", "kind": "identity", "answer_data": [ "hierarchical_selector — object{language, expression}, cardinality 0..1" ] } ], "data_elements": [ { "id": "graph-extent-and-nested-shape-data01", "name": "allowed_navigation_paths", "description": "Navigation or relationship paths that may be expanded inline.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-020" ] }, { "id": "graph-extent-and-nested-shape-data02", "name": "max_expand_depth", "description": "Maximum depth to which related resources may be expanded.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-020" ] }, { "id": "graph-extent-and-nested-shape-data03", "name": "nested_policy_ref", "description": "Projection policy reference governing an expanded type or path.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-021" ] }, { "id": "graph-extent-and-nested-shape-data04", "name": "related_inherits_parent", "description": "Whether expanded related resources inherit the parent policy's treatments.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-022" ] }, { "id": "graph-extent-and-nested-shape-data05", "name": "hierarchical_selector", "description": "Content-selector language and expression naming the nodes whose shape is governed, analogous to the XACML multiple:content-selector.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018" ] } ], "artifacts": [ { "id": "graph-extent-and-nested-shape-artifact01", "name": "Field scope document", "description": "Include/exclude path lists, default treatment, expansion extent, hierarchical selector, nested policy refs — compiled against one source schema version.", "media_or_form": [ "document" ], "serial": false, "identity_strategy": "Governed IRI when published, otherwise a Dimension-assigned UUID/ULID; scoped to one policy version and one source-schema version.", "source_refs": [ "SRC-019", "SRC-020", "SRC-022" ] } ], "inline_only_rationale": null } ] }, { "id": "element-treatment", "name": "Element Treatment", "description": "The transformation applied to a selected element before it leaves, its parameters, and whether it can be undone.", "source_refs": [ "SRC-008", "SRC-010", "SRC-005" ], "findings": [ { "id": "treatment-technique-and-parameters", "name": "Treatment Technique and Parameters", "description": "The de-identification or shaping technique applied to an element, named from a governed vocabulary and parameterised well enough that the transformed value is reproducible.", "source_refs": [ "SRC-008", "SRC-010", "SRC-003", "SRC-004" ], "questions": [ { "id": "q-treat-technique", "text": "Which technique is applied to this element and from which governed technique vocabulary is its name drawn?", "kind": "classification", "answer_data": [ "technique code", "vocabulary identifier and version", "technique family (suppression, generalisation, randomisation, pseudonymisation, cryptographic, aggregation, synthesis)" ] }, { "id": "q-treat-params", "text": "Which parameters fully determine the transformed value, and may those parameters themselves be disclosed?", "kind": "measurement", "answer_data": [ "parameter name and value map", "unit or precision", "parameter disclosability flag" ] }, { "id": "q-treat-determinism", "text": "Is the transformation deterministic across separate requests, and what does that imply for linkability?", "kind": "quality", "answer_data": [ "determinism flag", "salt or seed scope reference", "linkability consequence note" ] }, { "id": "q-treat-forbidden", "text": "Which technique-and-element combinations are refused outright regardless of who is asking?", "kind": "privacy", "answer_data": [ "forbidden technique and element pairs", "governing rule reference" ] } ], "data_elements": [ { "id": "de-treat-technique", "name": "Treatment technique", "description": "Governed code naming the transformation applied to the element.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-010" ] }, { "id": "de-treat-parameters", "name": "Technique parameters", "description": "Complete parameter set determining the transformed value, such as bucket width, rounding base, generalisation level or noise scale.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008" ] }, { "id": "de-treat-vocabulary-ref", "name": "Technique vocabulary reference", "description": "Identifier and version of the vocabulary from which the technique code is taken.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-010" ] }, { "id": "de-treat-determinism", "name": "Determinism flag", "description": "Whether repeated application to the same input yields the same output.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "A treatment declaration is structured content of the policy record and is meaningless apart from the element it qualifies. The transformation itself is executed by WM-XCT-038 over instance data this model never holds, so there is nothing local to materialise." }, { "id": "reversibility-and-recoding", "name": "Reversibility and Re-identification Coding", "description": "Whether a treatment can be undone, by whom under which separate authority, and how a pseudonym or re-identification code namespace is referenced without this model holding a key.", "source_refs": [ "SRC-005", "SRC-008", "SRC-010" ], "questions": [ { "id": "q-rev-class", "text": "Is this treatment reversible, and which party could reverse it under which separate instrument?", "kind": "authority", "answer_data": [ "reversibility class (irreversible, reversible-with-key, reversible-by-lookup)", "custodian reference", "authorising instrument reference" ] }, { "id": "q-rev-namespace", "text": "Where is the pseudonym or code namespace defined, and is it shared with any other shape?", "kind": "relationship", "answer_data": [ "pseudonym namespace identifier", "shapes sharing the namespace", "namespace rotation rule reference" ] }, { "id": "q-rev-derivation", "text": "What must never be embedded in or derivable from a disclosed code or token?", "kind": "security", "answer_data": [ "prohibited derivation list", "conformance statement reference" ] }, { "id": "q-rev-evidence", "text": "How is the irreversibility claim evidenced rather than merely asserted?", "kind": "evidence", "answer_data": [ "evidence reference", "assessor identity reference", "assessment validity window" ] } ], "data_elements": [ { "id": "de-rev-class", "name": "Reversibility class", "description": "Whether and how the treated value can be mapped back to its original.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-005" ] }, { "id": "de-rev-namespace-ref", "name": "Pseudonym namespace reference", "description": "Identifier of the code space in which pseudonyms for this element are minted.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-010" ] }, { "id": "de-rev-custodian-ref", "name": "Key or lookup custodian reference", "description": "Reference to the party holding the reversal key or crosswalk table, resolved in WM-XCT-001.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Only the classification and the pointers live here. Keys, crosswalk tables and the authority to re-identify are held under WM-XCT-001 and WM-XCT-002; creating a local artifact would risk drawing sensitive reversal material into a policy record that is itself widely read." } ] }, { "id": "record-scope-and-grain", "name": "Record Scope and Grain", "description": "Which records leave and at what level of summarisation, as distinct from which fields leave.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "population-and-record-scope", "name": "Population and Record Scope", "description": "The predicate deciding which records or instances appear in an output at all, and the disclosure created by membership in that set irrespective of field values.", "source_refs": [ "SRC-003", "SRC-009", "SRC-005" ], "questions": [ { "id": "q-rec-filter", "text": "Which predicate decides the set of records in an output, and over which attributes is it stated?", "kind": "composition", "answer_data": [ "record filter expression", "attributes referenced by the filter", "evaluation context reference" ] }, { "id": "q-rec-membership", "text": "Does membership in the released record set by itself reveal a sensitive fact about a subject?", "kind": "privacy", "answer_data": [ "membership sensitivity flag", "affected attribute list", "mitigation code" ] }, { "id": "q-rec-bounds", "text": "What minimum and maximum record counts apply to an output, and which model owns those floors?", "kind": "constraint", "answer_data": [ "floor instrument reference in WM-XCT-005", "declared ceiling value", "behaviour when the floor is unmet" ] }, { "id": "q-rec-stream", "text": "How is record scope stated when the source is a stream or an unbounded collection?", "kind": "temporal", "answer_data": [ "window definition as duration or count", "window anchor rule", "late-arrival handling code" ] } ], "data_elements": [ { "id": "de-rec-filter", "name": "Record filter expression", "description": "Declarative predicate restricting which records may appear in an output.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-rec-membership-sensitivity", "name": "Membership sensitivity flag", "description": "Whether inclusion in the released set is itself a disclosure about the subject.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-004" ] }, { "id": "de-rec-ceiling", "name": "Record ceiling", "description": "Maximum number of records a single served output may contain.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-rec-floor-ref", "name": "Cohort floor reference", "description": "Reference to the minimum-cohort instrument governing this shape, maintained in WM-XCT-005.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "The filter is a declarative clause of the policy record. Its evaluation happens in WM-XCT-038 and the floors it defers to are computed in WM-XCT-005, so a local artifact would either be empty or would restate values this model must not own." }, { "id": "aggregation-grain-declaration", "name": "Aggregation Grain Declaration", "description": "For summary-only shapes, the dimensions retained, the measures computed and the period, with cohort floors and privacy budgets referenced rather than defined.", "source_refs": [ "SRC-004", "SRC-003", "SRC-002" ], "questions": [ { "id": "q-agg-dimensions", "text": "Which dimensions are kept in the summary and at what level of each hierarchy?", "kind": "definition", "answer_data": [ "dimension list with retained level", "hierarchy reference", "suppressed dimension list" ] }, { "id": "q-agg-measures", "text": "Which measures are computed, and with what rounding or perturbation applied to each?", "kind": "measurement", "answer_data": [ "measure name and aggregate function", "rounding rule or base", "perturbation mechanism reference" ] }, { "id": "q-agg-period", "text": "Over which period is the summary computed, and may a recipient recombine periods?", "kind": "temporal", "answer_data": [ "period definition", "period alignment rule", "recombination prohibition flag" ] }, { "id": "q-agg-instrument", "text": "Which privacy floor or budget instrument governs this grain, and where is it maintained?", "kind": "relationship", "answer_data": [ "instrument reference in WM-XCT-005", "instrument version", "behaviour on exhaustion" ] } ], "data_elements": [ { "id": "de-agg-dimension", "name": "Kept dimension", "description": "A dimension retained in the summary output together with its retained hierarchy level.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-agg-measure", "name": "Measure definition", "description": "An aggregate function and the source element it summarises.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "de-agg-period", "name": "Aggregation period", "description": "The interval over which the summary is computed.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "de-agg-instrument-ref", "name": "Privacy instrument reference", "description": "Reference to the cohort floor or privacy budget instrument owned by WM-XCT-005.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "The grain is a declarative clause. Computing thresholds, testing cohort sufficiency and accounting a privacy budget are all owned by WM-XCT-005, so any artifact produced here would reproduce that model's assurance output." }, { "id": "leaving-shape-grain-class", "name": "Leaving-shape grain class", "description": "A projection policy names exactly one primary grain for what may leave: (a) record-level subset — selected paths of authorised instances; (b) named summary — a predefined reduced view such as FHIR _summary=true/text/data; (c) aggregate-only — statistical functions over a grouping, with no microdata. ISO/IEC 20889 classifies aggregation and sampling as statistical de-identification tools; NIST SP 800-188 distinguishes publishing de-identified microdata, synthetic data, query interfaces, and protected enclaves. FHIR defines discrete summary modes including count-only.", "source_refs": [ "SRC-008", "SRC-003", "SRC-021" ], "questions": [ { "id": "leaving-shape-grain-class-q01", "text": "What grain may leave under this policy: record-level subset, named summary, aggregate-only, or a documented hybrid?", "kind": "classification", "answer_data": [ "grain_class — enum(subset|summary|aggregate_only|hybrid), cardinality 1" ] }, { "id": "leaving-shape-grain-class-q02", "text": "If grain is summary, which named summary mode applies (for example FHIR true/text/data/count, or a locally named card)?", "kind": "classification", "answer_data": [ "summary_mode — string, cardinality 0..1" ] }, { "id": "leaving-shape-grain-class-q03", "text": "Are instance-level records permitted to leave at all, or only derived statistics?", "kind": "constraint", "answer_data": [ "microdata_permitted — boolean, cardinality 1" ] }, { "id": "leaving-shape-grain-class-q04", "text": "Which NIST SP 800-188 data-sharing model does this grain align to: publish de-identified data, synthetic data, query interface, or protected enclave — as alignment, not conformance?", "kind": "interoperability", "answer_data": [ "sharing_model_alignment — enum(publish_deidentified|synthetic|query_interface|enclave|unaligned), cardinality 0..1" ] } ], "data_elements": [ { "id": "leaving-shape-grain-class-data01", "name": "grain_class", "description": "The single primary grain a policy allows to leave: record-level subset, named summary, aggregate-only, or a documented hybrid.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-021" ] }, { "id": "leaving-shape-grain-class-data02", "name": "summary_mode", "description": "Named summary mode when the grain is summary, such as FHIR _summary true/text/data/count or a locally named card.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021" ] }, { "id": "leaving-shape-grain-class-data03", "name": "sharing_model_alignment", "description": "NIST SP 800-188 data-sharing model this grain aligns to: publish de-identified, synthetic, query interface, enclave, or unaligned.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "leaving-shape-grain-class-data04", "name": "microdata_permitted", "description": "Whether instance-level records may leave at all, or only derived statistics.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Grain class is a closed vocabulary plus references to sibling models (XCT-005 for floors, DAT-004 for source). It is classification metadata, not a stored document." } ] }, { "id": "shape-algebra", "name": "Shape Algebra", "description": "The order relation on shapes and the operation that merges two applicable shapes into one no wider than either.", "source_refs": [ "SRC-011", "SRC-001", "SRC-012" ], "findings": [ { "id": "shape-narrowing-and-combination", "name": "Narrowing Order and Least-Disclosure Combination", "description": "When one shape is no wider than another, how two applicable shapes combine into a single least-disclosure shape, and why this is distinct from deciding which policy takes precedence.", "source_refs": [ "SRC-011", "SRC-001", "SRC-012" ], "questions": [ { "id": "q-alg-subsume", "text": "Under what test is one shape judged to disclose no more than another?", "kind": "validation", "answer_data": [ "subsumption test definition per shape dimension", "witness paths returned on failure" ] }, { "id": "q-alg-meet", "text": "How are two applicable shapes merged, and is the result guaranteed no wider than either input?", "kind": "composition", "answer_data": [ "combination operator", "per-dimension merge rule for selection, treatment, record scope and grain", "monotonicity assertion" ] }, { "id": "q-alg-undefined", "text": "Which merges are undefined or unsafe and must be refused rather than approximated?", "kind": "exception", "answer_data": [ "undefined case list", "refusal outcome code", "escalation target reference" ] }, { "id": "q-alg-boundary", "text": "How does merging two shapes differ from deciding which of two policies prevails?", "kind": "relationship", "answer_data": [ "boundary statement", "precedence owner reference WM-KNW-012", "applicable-policy selection owner reference WM-XCT-038" ] } ], "data_elements": [ { "id": "de-alg-operator", "name": "Combination operator", "description": "The named meet operator producing the least-disclosure shape from two inputs.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "de-alg-verdict", "name": "Subsumption verdict", "description": "Result of comparing two shapes: narrower, equal, wider or incomparable.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-alg-witness", "name": "Comparison witness", "description": "Normalized paths that demonstrate why a subsumption test failed.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-alg-monotonicity", "name": "Monotonicity assertion", "description": "Whether the merge is asserted never to widen disclosure relative to either input.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "The algebra is a semantic rule set expressed once for the model, not per-instance content, and its execution belongs to callers. Recording it as an artifact would imply a deliverable that must be versioned separately from the model specification it defines." } ] } ] }, { "id": "output-template", "name": "Compiled Output Template", "description": "The concrete, verifiable shape a consumer actually receives, its derivation from pinned inputs, its encodings and the disclosure that survives beyond its stated values.", "rationale": "A shape only becomes checkable when compiled against a specific source schema and fingerprinted. This bundle exists so a served output can be verified and explained without re-reading the policy prose.", "source_refs": [ "SRC-014", "SRC-007", "SRC-006", "SRC-003" ], "layers": [ { "id": "template-derivation", "name": "Template Derivation", "description": "How a template is produced from pinned inputs, identified, and kept aligned with a moving source schema.", "source_refs": [ "SRC-014", "SRC-006", "SRC-003" ], "findings": [ { "id": "compiled-template-and-fingerprint", "name": "Compiled Template and Fingerprint", "description": "The derived output shape a consumer receives, produced from one policy version against one source schema version and digested so any party can verify what was served.", "source_refs": [ "SRC-014", "SRC-007", "SRC-006", "SRC-001" ], "questions": [ { "id": "q-tpl-inputs", "text": "Which inputs must be pinned for a template to be reproducible byte for byte?", "kind": "provenance", "answer_data": [ "policy version identifier", "source schema version identifier", "treatment matrix version identifier", "compiler identifier and version" ] }, { "id": "q-tpl-digest", "text": "Over which canonical form is the template fingerprint computed, and with which algorithm?", "kind": "identity", "answer_data": [ "digest algorithm", "canonicalisation rule reference", "digest value" ] }, { "id": "q-tpl-preview-access", "text": "Which part of a template may be shown to a prospective recipient before any authorization exists?", "kind": "access", "answer_data": [ "disclosable subset", "withheld part list with reason code" ] }, { "id": "q-tpl-recompile", "text": "When must a template be recompiled instead of reused?", "kind": "process", "answer_data": [ "recompilation trigger list", "staleness horizon", "behaviour when stale" ] } ], "data_elements": [ { "id": "de-tpl-fingerprint", "name": "Template fingerprint", "description": "Digest over the canonical template form and its pinned input identifiers.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-014" ] }, { "id": "de-tpl-policy-version-ref", "name": "Policy version reference", "description": "Identifier of the policy version compiled, resolved in WM-KNW-012.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-tpl-compiler-ref", "name": "Compiler identity", "description": "Identifier and version of the implementation that produced the template.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-tpl-compiled-at", "name": "Compilation timestamp", "description": "RFC 3339 instant at which the template was produced, distinct from any disclosure time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] } ], "artifacts": [ { "id": "compiled-output-template", "name": "Compiled Output Template", "description": "The concrete schema fragment, column manifest or claim set that a bound recipient receives, derived deterministically from a pinned policy version and source schema version and carrying a verifiable digest.", "media_or_form": [ "schema fragment in a declared dialect", "tabular column manifest", "selective-disclosure claim set", "graph shape or frame" ], "serial": false, "identity_strategy": "Composite key of the authoritative policy version identifier from the Dimension's policy register, the source schema version identifier and the treatment matrix version identifier; a governed IRI is used where the register issues one, and a Dimension-assigned UUID or ULID only where neither exists. The digest verifies integrity and is never the primary identifier; the compilation date is never part of the identity.", "source_refs": [ "SRC-014", "SRC-007", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "source-schema-binding-and-drift", "name": "Source Schema Binding and Drift", "description": "The dependency of a shape on a governed source schema version, how unresolved paths and newly appearing elements are detected, and who remediates.", "source_refs": [ "SRC-014", "SRC-006", "SRC-003" ], "questions": [ { "id": "q-drift-binding", "text": "To which source schema or data contract version is this shape bound, and how strictly?", "kind": "relationship", "answer_data": [ "schema reference in WM-DAT-004", "bound version", "binding strictness (pinned, range, floating)" ] }, { "id": "q-drift-unresolved", "text": "Which selection paths currently fail to resolve against the bound schema version?", "kind": "validation", "answer_data": [ "unresolved path list", "failure reason code", "remediation owner reference" ] }, { "id": "q-drift-newelement", "text": "What happens when the source adds an element this shape has never classified?", "kind": "exception", "answer_data": [ "new-element outcome code", "classification request target in WM-XCT-020", "notification target" ] }, { "id": "q-drift-cadence", "text": "How is drift detected, how often is the check run, and when was it last run?", "kind": "process", "answer_data": [ "drift check procedure reference", "check cadence", "last observation timestamp" ] } ], "data_elements": [ { "id": "de-drift-schema-ref", "name": "Bound source schema reference", "description": "Reference to the governed source schema or data contract in WM-DAT-004.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "de-drift-strictness", "name": "Binding strictness", "description": "Whether the shape is pinned to one schema version, accepts a range, or floats.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "de-drift-unresolved-path", "name": "Unresolved path", "description": "A declared path that no longer resolves against the bound schema version.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-drift-observed-at", "name": "Drift observation timestamp", "description": "RFC 3339 instant at which the drift check was performed, recorded separately from the schema change time.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Only the binding and its current resolution state are local; the schema itself and its validation contract are owned by WM-DAT-004. A local artifact would either copy that schema or become a second, competing source of truth about it." } ] }, { "id": "disclosure-surface", "name": "Disclosure Surface", "description": "How the shape is rendered into concrete encodings, and what a recipient can still infer beyond the stated values.", "source_refs": [ "SRC-007", "SRC-014", "SRC-004" ], "findings": [ { "id": "encoding-and-media-profile", "name": "Encoding and Media Profile", "description": "Which encodings a shape is approved to be served in, whether semantics are preserved in each, and which encoding choices are themselves disclosure decisions.", "source_refs": [ "SRC-007", "SRC-014", "SRC-006" ], "questions": [ { "id": "q-enc-approved", "text": "In which encodings is this shape approved to be served, and is the disclosed content identical in each?", "kind": "interoperability", "answer_data": [ "approved encoding list", "semantic equivalence assertion per encoding", "known divergence note" ] }, { "id": "q-enc-omission", "text": "Does the encoding let a recipient distinguish an omitted element from one present but masked or null?", "kind": "definition", "answer_data": [ "omission representation code", "null-versus-absent rule", "recipient-visible marker" ] }, { "id": "q-enc-metadata", "text": "Which encoding-level metadata such as field order, annotations, comments or provenance headers leaves with the output?", "kind": "privacy", "answer_data": [ "metadata element list with include or exclude decision", "rationale" ] }, { "id": "q-enc-holder", "text": "How is a holder-selected disclosure encoding constrained by an issuer-fixed shape?", "kind": "constraint", "answer_data": [ "holder-selectable element list", "issuer-mandatory element list", "protocol reference" ] } ], "data_elements": [ { "id": "de-enc-approved", "name": "Approved encoding", "description": "An encoding in which this shape may be served, with its semantic equivalence assertion.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-014", "SRC-007" ] }, { "id": "de-enc-omission-representation", "name": "Omission representation", "description": "How the absence of a withheld element is represented to the recipient.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "de-enc-metadata-decision", "name": "Metadata disclosure decision", "description": "Per encoding-level metadata item, whether it leaves with the output.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "Encodings are projections of one semantic shape, so the model stays format-neutral by recording approvals and equivalence assertions rather than the encodings themselves. Concrete encoded forms are instances of the compiled template artifact already declared." }, { "id": "residual-disclosure-and-side-channels", "name": "Residual Disclosure and Side Channels", "description": "What a recipient can still infer from a served output beyond its values: existence of a response, record counts, ordering, structural shape and the difference between error, refusal and empty result.", "source_refs": [ "SRC-004", "SRC-007", "SRC-009", "SRC-003" ], "questions": [ { "id": "q-res-existence", "text": "Which facts does a non-empty response reveal even when every value in it is masked?", "kind": "privacy", "answer_data": [ "revealed fact list", "affected subject class", "mitigation code" ] }, { "id": "q-res-cardinality", "text": "Does the count, ordering or structural padding of a response leak an attribute?", "kind": "quality", "answer_data": [ "cardinality leakage assessment", "ordering rule (stable, randomised)", "padding or decoy rule" ] }, { "id": "q-res-errors", "text": "Do error, refusal and empty-result responses differ in a way that discloses the withheld value?", "kind": "exception", "answer_data": [ "response uniformity rule", "indistinguishability requirement", "tested failure cases" ] }, { "id": "q-res-accepted", "text": "Which of these residual channels are accepted as tolerable, and on whose authority?", "kind": "decision", "answer_data": [ "accepted residual channel list", "acceptance rationale", "accepting authority reference in WM-XCT-001" ] } ], "data_elements": [ { "id": "de-res-channel", "name": "Residual disclosure channel", "description": "An inference path that survives the declared shape, such as existence, count, order or timing.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "de-res-uniformity-rule", "name": "Response uniformity rule", "description": "Rule making refusals, errors and empty results indistinguishable to a recipient.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-res-padding-rule", "name": "Padding or decoy rule", "description": "Rule obscuring the true number of withheld elements or records, such as decoy digests.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-res-accepted-risk", "name": "Accepted residual risk statement", "description": "Recorded acceptance of a named residual channel, with the reference to the accepting authority.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "This is analytical content attached to the policy record. The runtime behaviour that realises uniform responses and padding is executed by WM-XCT-038, so declaring an artifact here would imply this model produces or holds the responses themselves." } ] } ] }, { "id": "binding-and-applicability", "name": "Binding and Applicability", "description": "Where a shape applies: the targets and audiences it is attached to, the conditions under which it is the applicable shape, and the class and regime constraints that bound what is lawful.", "rationale": "A shape is reusable precisely because binding is separable from definition. This bundle keeps binding as pure reference so that authorization, party and classification semantics stay in their owning models.", "source_refs": [ "SRC-001", "SRC-011", "SRC-005", "SRC-012" ], "layers": [ { "id": "binding-attachment", "name": "Binding Attachment", "description": "The link record attaching a shape to a target and audience, and the declarative conditions for its applicability.", "source_refs": [ "SRC-001", "SRC-011" ], "findings": [ { "id": "binding-target-and-audience", "name": "Binding Target, Audience and Effective Window", "description": "The attachment of one shape to a contract or grant, object type or audience class, with the window in which it is effective and the authority the binding presupposes.", "source_refs": [ "SRC-001", "SRC-011", "SRC-013" ], "questions": [ { "id": "q-bind-target", "text": "What is the target of this binding, and which model owns that target?", "kind": "relationship", "answer_data": [ "target reference", "target kind code (contract, grant, object type, audience)", "owning model identifier" ] }, { "id": "q-bind-audience", "text": "Which recipient class does the binding serve, and how is that class defined without copying party records?", "kind": "classification", "answer_data": [ "audience class code", "class definition reference in WM-XCT-002", "party reference in WM-XCT-001" ] }, { "id": "q-bind-window", "text": "From when until when is the binding effective, and what governs an output already served under it?", "kind": "temporal", "answer_data": [ "effective-from timestamp", "effective-until timestamp", "already-served output rule" ] }, { "id": "q-bind-authority", "text": "Which authority must exist for this binding to be publishable at all, and what happens if it is absent?", "kind": "authority", "answer_data": [ "required authority reference", "evidence-of-authority reference", "refusal outcome when absent" ] } ], "data_elements": [ { "id": "de-bind-id", "name": "Binding identifier", "description": "Identifier of the attachment record linking one shape to one target.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-bind-target-ref", "name": "Binding target reference", "description": "Reference to the contract, grant, object type or audience the shape is attached to.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-011" ] }, { "id": "de-bind-effective-from", "name": "Effective from", "description": "RFC 3339 instant from which the binding applies.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "de-bind-effective-until", "name": "Effective until", "description": "RFC 3339 instant after which the binding no longer applies; absent means open-ended.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "A binding is a link record composed almost entirely of references. Materialising it would duplicate contract and party content owned by WM-XCT-002 and WM-XCT-001 and create a second place where an authorization appears to be recorded." }, { "id": "applicability-conditions", "name": "Applicability Conditions", "description": "The declarative conditions under which this shape is the applicable one, stated so an external evaluator can decide without this model performing or recording any decision.", "source_refs": [ "SRC-001", "SRC-002", "SRC-011" ], "questions": [ { "id": "q-cond-operands", "text": "Which condition operands does this shape use, and from which governed operand vocabulary are they drawn?", "kind": "definition", "answer_data": [ "operand name list", "operand vocabulary reference and version", "operator per condition" ] }, { "id": "q-cond-attributes", "text": "Which attribute values must an evaluator be able to obtain for a condition to be decidable?", "kind": "interoperability", "answer_data": [ "required attribute list", "attribute source reference", "behaviour when an attribute is unavailable" ] }, { "id": "q-cond-boundary", "text": "Where does declaring a condition end and deciding it begin?", "kind": "process", "answer_data": [ "boundary statement", "decision owner reference WM-XCT-038", "obligation hand-off list" ] }, { "id": "q-cond-criticality", "text": "Which conditions are mandatory for applicability and which are advisory?", "kind": "constraint", "answer_data": [ "criticality per condition", "effect when unmet", "default when unspecified" ] } ], "data_elements": [ { "id": "de-cond-operand", "name": "Condition operand", "description": "A named left operand such as purpose, recipient, delivery channel or spatial region.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-cond-operator", "name": "Condition operator", "description": "Comparison operator relating an operand to its expected value.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-cond-criticality", "name": "Condition criticality", "description": "Whether the condition is mandatory or advisory for the shape to apply.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-cond-required-attribute", "name": "Required evaluation attribute", "description": "Attribute an external evaluator must obtain to decide the condition.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Conditions are policy text carried with the shape. Attribute retrieval, evaluation, the resulting decision and its explanation all belong to WM-XCT-038, and producing an artifact here would look like a decision record this model must never own." } ] }, { "id": "class-and-regime-constraints", "name": "Class and Regime Constraints", "description": "Externally imposed lower bounds on treatment: governed sensitivity classes and legally prescribed shapes.", "source_refs": [ "SRC-005", "SRC-012", "SRC-008" ], "findings": [ { "id": "class-to-treatment-matrix", "name": "Class-to-Treatment Minimum Matrix", "description": "The governed table mapping an externally assigned sensitivity class to the weakest treatment a shape may apply, so that shapes can be checked mechanically rather than by reviewer opinion.", "source_refs": [ "SRC-005", "SRC-008", "SRC-012", "SRC-010" ], "questions": [ { "id": "q-mtx-minimum", "text": "For each referenced sensitivity class, what is the weakest treatment a shape may apply?", "kind": "requirement", "answer_data": [ "class identifier", "minimum treatment code", "pass-through permitted flag" ] }, { "id": "q-mtx-scheme", "text": "Which classification scheme and version does the matrix key on, and how are keys resolved?", "kind": "provenance", "answer_data": [ "scheme reference in WM-XCT-020", "scheme version", "key resolution rule" ] }, { "id": "q-mtx-check", "text": "How is a shape checked against the matrix, and what constitutes a violation?", "kind": "validation", "answer_data": [ "check procedure reference", "violation record structure", "violation severity code" ] }, { "id": "q-mtx-reclassify", "text": "What happens to existing shapes when an element is reclassified upward?", "kind": "event", "answer_data": [ "affected shape list", "required outcome code (recompile, withdraw, withhold element)", "execution owner reference" ] } ], "data_elements": [ { "id": "de-mtx-class-key", "name": "Sensitivity class key", "description": "Externally assigned class identifier that the matrix row is keyed on.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-mtx-minimum-treatment", "name": "Minimum treatment", "description": "Weakest treatment code permitted for elements carrying the class.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012", "SRC-005" ] }, { "id": "de-mtx-scheme-version", "name": "Classification scheme version", "description": "Version of the external scheme the matrix is valid against.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-010" ] } ], "artifacts": [ { "id": "sensitivity-class-treatment-matrix", "name": "Sensitivity Class Treatment Matrix", "description": "A reusable governed decision table binding each externally assigned sensitivity class to the minimum treatment any shape must apply, maintained independently of any single policy and cited by every shape it constrains.", "media_or_form": [ "governed decision table", "policy annex table", "machine-readable rule set" ], "serial": false, "identity_strategy": "Authoritative master-system identifier of the matrix in the adopting Dimension's policy register, qualified by the referenced classification scheme identifier and version; a governed IRI where the register issues one, otherwise a Dimension-assigned ULID. A content digest verifies integrity only; no date forms part of the identity.", "source_refs": [ "SRC-008", "SRC-012", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "regime-mandated-shapes", "name": "Regime-Mandated and Regime-Forbidden Shapes", "description": "Shapes that a legal or sectoral regime prescribes or forbids outright, recorded as named, cited constraints with their territorial and sectoral reach, never as restated law.", "source_refs": [ "SRC-005", "SRC-012", "SRC-003" ], "questions": [ { "id": "q-reg-prescribed", "text": "Which regime prescribes a fixed output shape for this data, and what exactly does it prescribe?", "kind": "requirement", "answer_data": [ "regime citation with version or date", "prescribed removals or generalisations", "named shape identifier" ] }, { "id": "q-reg-reach", "text": "In which territories and sectors does that prescription bind, and what shape applies elsewhere?", "kind": "spatial", "answer_data": [ "applicable jurisdiction list", "sector scope", "fallback shape reference" ] }, { "id": "q-reg-conflict", "text": "When two regimes prescribe incompatible shapes for one recipient, what is recorded and who resolves it?", "kind": "exception", "answer_data": [ "conflict description", "interim outcome code", "escalation owner reference" ] }, { "id": "q-reg-currency", "text": "How is a regime claim evidenced so it can be re-checked when the law changes?", "kind": "evidence", "answer_data": [ "citation with version or date", "last verification timestamp", "verifier identity reference" ] } ], "data_elements": [ { "id": "de-reg-citation", "name": "Regime citation", "description": "Reference to the instrument prescribing or forbidding a shape, with its version or date.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-012" ] }, { "id": "de-reg-named-shape", "name": "Named prescribed shape", "description": "Code for a shape the regime names, such as a rule-based identifier-removal shape or a limited data set.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-reg-jurisdiction", "name": "Applicable jurisdiction", "description": "Territory or sector in which the prescription binds.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-reg-verified-at", "name": "Regime verification timestamp", "description": "RFC 3339 instant at which the citation was last confirmed current, recorded separately from the instrument's own date.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Regimes are cited, never copied. The model records pointers and reach so that legal text stays with its publisher and no compliance determination is made or implied here; an artifact would invite a local restatement of law that would silently go stale." } ] } ] }, { "id": "assurance-and-evidence", "name": "Assurance and Evidence", "description": "Why a shape is defensible: the identifiability role of each element, the assurance method claimed, and the effect of serving several shapes over the same population.", "rationale": "A shape without a stated basis cannot be reviewed or falsified. This bundle records the claim and its evidence pointer while leaving all quantification to the models that own it.", "source_refs": [ "SRC-008", "SRC-009", "SRC-003", "SRC-004" ], "layers": [ { "id": "identifiability-declaration", "name": "Identifiability Declaration", "description": "The role each element plays in re-identification and the basis on which the resulting shape is claimed adequate.", "source_refs": [ "SRC-008", "SRC-009", "SRC-005" ], "findings": [ { "id": "element-identifiability-roles", "name": "Element Identifiability Roles", "description": "Whether each selected element is a direct identifier, a quasi-identifier, a sensitive attribute or non-identifying, and the context assumptions behind that assignment.", "source_refs": [ "SRC-008", "SRC-009", "SRC-003", "SRC-005" ], "questions": [ { "id": "q-idr-role", "text": "What identifiability role is assigned to each selected element, and from which terminology?", "kind": "classification", "answer_data": [ "element path with role code", "terminology source reference" ] }, { "id": "q-idr-assumptions", "text": "Which auxiliary datasets and adversary capabilities were assumed when assigning quasi-identifier status?", "kind": "provenance", "answer_data": [ "assumed auxiliary data list", "assumed adversary capability", "assumption review date" ] }, { "id": "q-idr-implication", "text": "How does an element's role raise the minimum treatment required for it?", "kind": "constraint", "answer_data": [ "role-to-treatment implication", "interaction with the class matrix", "override justification" ] }, { "id": "q-idr-unassigned", "text": "Which elements are deliberately left unassigned, and why is that defensible?", "kind": "quality", "answer_data": [ "unassigned element list", "reason code", "reviewer reference" ] } ], "data_elements": [ { "id": "de-idr-role", "name": "Element identifiability role", "description": "Per-element assignment of direct identifier, quasi-identifier, sensitive attribute or non-identifying.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-idr-adversary-assumption", "name": "Adversary capability assumption", "description": "The attacker model assumed when roles were assigned.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-idr-auxiliary-data", "name": "Assumed auxiliary data", "description": "External datasets assumed available to an adversary for linkage.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Role assignment is analytical annotation on the shape, not a governed register: it neither replaces the sensitivity classification owned by WM-XCT-020 nor quantifies risk. Keeping it inline prevents it being mistaken for an authoritative classification record." }, { "id": "assurance-method-and-evidence", "name": "Assurance Method and Evidence Pointer", "description": "The basis on which the shape is claimed adequate - a rule-based method, an expert determination, or a formal privacy guarantee - held as a claim plus a pointer to evidence maintained elsewhere.", "source_refs": [ "SRC-005", "SRC-003", "SRC-004", "SRC-009" ], "questions": [ { "id": "q-asr-method", "text": "Which assurance method is claimed for this shape, and against which standard?", "kind": "decision", "answer_data": [ "method code (rule-based, expert determination, formal guarantee, none)", "method standard reference", "claim statement" ] }, { "id": "q-asr-determiner", "text": "Who made the determination, when, and for how long does it remain valid?", "kind": "ownership", "answer_data": [ "determiner identity reference", "determination timestamp", "validity window or review date" ] }, { "id": "q-asr-evidence", "text": "Where is the supporting evidence held, and what does this model deliberately not hold?", "kind": "evidence", "answer_data": [ "evidence location reference", "held-elsewhere statement", "access constraint on the evidence" ] }, { "id": "q-asr-invalid", "text": "What invalidates the claim, and how must the shape behave while it is invalid?", "kind": "state", "answer_data": [ "invalidation condition list", "interim behaviour code", "notification target" ] } ], "data_elements": [ { "id": "de-asr-method", "name": "Assurance method", "description": "Code naming the basis on which the shape's adequacy is claimed.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de-asr-determination-ref", "name": "Determination reference", "description": "Pointer to the determination or assessment record held outside this model.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-003" ] }, { "id": "de-asr-determined-at", "name": "Determination timestamp", "description": "RFC 3339 instant at which the determination was made, distinct from when it was recorded here.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "de-asr-claim-status", "name": "Claim status", "description": "Whether the assurance claim is currently asserted, expired or withdrawn.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "This model holds the claim and a pointer only. Risk quantification, cohort sufficiency and privacy budget accounting are owned by WM-XCT-005 and the adopting Dimension's assessment process, so producing an assurance artifact here would assert ownership of evidence this model does not generate." } ] }, { "id": "cross-release-effects", "name": "Cross-Release Effects", "description": "Disclosure that arises from the set of shapes served rather than from any single shape.", "source_refs": [ "SRC-004", "SRC-009", "SRC-003" ], "findings": [ { "id": "release-set-linkability", "name": "Release-Set Linkability", "description": "The widening of disclosure when several shapes are served over the same population to the same or colluding recipients, through shared join keys, repeated queries or overlapping grains.", "source_refs": [ "SRC-004", "SRC-003", "SRC-009", "SRC-008" ], "questions": [ { "id": "q-lnk-companions", "text": "Which other shapes may be served over the same subjects to the same recipient class?", "kind": "relationship", "answer_data": [ "companion shape list", "recipient class reference", "overlap assessment" ] }, { "id": "q-lnk-joinkeys", "text": "Which elements act as join keys across shapes, and how is that overlap controlled?", "kind": "constraint", "answer_data": [ "join key element list", "namespace separation rule", "overlap acceptance decision" ] }, { "id": "q-lnk-budget", "text": "How many times may this shape be served over one population before the combined disclosure exceeds the claim?", "kind": "measurement", "answer_data": [ "release limit or budget reference", "accounting owner reference in WM-XCT-005", "behaviour at the limit" ] }, { "id": "q-lnk-detect", "text": "How is a change in the surrounding release set detected after this shape was approved?", "kind": "event", "answer_data": [ "detection signal list", "notification target", "re-review trigger" ] } ], "data_elements": [ { "id": "de-lnk-companion-ref", "name": "Companion shape reference", "description": "Another shape servable over the same population to the same recipient class.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-lnk-join-key", "name": "Join key element", "description": "Element whose values allow records from two shapes to be linked.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-003" ] }, { "id": "de-lnk-budget-ref", "name": "Release budget reference", "description": "Reference to the composition budget or release counter owned by WM-XCT-005.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-lnk-release-limit", "name": "Declared release limit", "description": "Maximum number of releases of this shape over one population before re-review.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "Linkability is a declared property of a set of shapes. Counting actual releases, maintaining a budget and enforcing a limit are runtime activities owned by WM-XCT-005 and WM-XCT-038, so no local artifact may hold a running total." } ] } ] }, { "id": "interoperability-and-publication", "name": "Interoperability and Publication", "description": "How the shape vocabulary maps onto external standards, how it behaves in holder-selected disclosure protocols, and the shape in which the policy record itself is published.", "rationale": "Shapes must travel between systems and must be browsable before any grant exists. This bundle records alignments and withheld conformance claims explicitly rather than assuming compatibility.", "source_refs": [ "SRC-001", "SRC-002", "SRC-011", "SRC-007", "SRC-010" ], "layers": [ { "id": "expression-alignment", "name": "Expression Alignment", "description": "Mapping between local shape vocabulary and external policy-expression and disclosure standards, including what does not map.", "source_refs": [ "SRC-001", "SRC-002", "SRC-011", "SRC-007" ], "findings": [ { "id": "policy-expression-crosswalk", "name": "Policy Expression Crosswalk", "description": "The mapping between this model's selection, treatment, scope and grain concepts and external policy-expression standards, recording mapping strength, unmapped concepts and conformance claims explicitly withheld.", "source_refs": [ "SRC-001", "SRC-002", "SRC-011", "SRC-010" ], "questions": [ { "id": "q-xwk-terms", "text": "Which external policy-language terms correspond to this model's selection, treatment and grain concepts?", "kind": "interoperability", "answer_data": [ "local term", "external term with namespace", "mapping strength code (exact, broader, narrower, none)" ] }, { "id": "q-xwk-unmapped", "text": "Which local concepts have no external equivalent and therefore require a profile?", "kind": "composition", "answer_data": [ "unmapped local term list", "required profile identifier", "profile status" ] }, { "id": "q-xwk-withheld", "text": "Which conformance claims are explicitly not made, and what evidence would be needed to make them?", "kind": "validation", "answer_data": [ "standard identifier", "withheld claim statement", "evidence that would be required" ] }, { "id": "q-xwk-currency", "text": "How is the crosswalk kept current when a mapped standard is revised?", "kind": "process", "answer_data": [ "watched standard list with version", "re-check cadence", "last verification timestamp" ] } ], "data_elements": [ { "id": "de-xwk-mapping", "name": "Term mapping", "description": "One local term related to one external term with a stated mapping strength.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "de-xwk-withheld-claim", "name": "Withheld conformance claim", "description": "A standard against which conformance is deliberately not asserted, with reason.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "de-xwk-verified-at", "name": "Crosswalk verification timestamp", "description": "RFC 3339 instant at which the mapping was last checked against the cited standard versions.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [ { "id": "expression-alignment-crosswalk", "name": "Expression Alignment Crosswalk", "description": "A maintained mapping table between this model's shape vocabulary and named external standards, carrying mapping strength per term, the list of unmapped concepts requiring a profile, and the conformance claims explicitly withheld.", "media_or_form": [ "term mapping table", "concept mapping set", "profile definition document" ], "serial": false, "identity_strategy": "Authoritative crosswalk identifier from the adopting Dimension's register, qualified by the external standard identifier and the exact standard version mapped; a governed IRI where available, otherwise a Dimension-assigned UUID. A digest verifies content and never identifies the crosswalk; the mapping date is not part of the identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "selective-disclosure-protocol-fit", "name": "Selective Disclosure Protocol Fit", "description": "How a governed shape behaves in protocols where the holder rather than the source chooses what is revealed, and where accountability for the final shape then sits.", "source_refs": [ "SRC-007", "SRC-014", "SRC-010" ], "questions": [ { "id": "q-sdp-elements", "text": "Which elements does the issuer make selectively disclosable, and which are always present?", "kind": "requirement", "answer_data": [ "selectively disclosable element list", "always-disclosed element list", "protocol reference" ] }, { "id": "q-sdp-accountable", "text": "Who is accountable for the final disclosed shape when the holder makes the selection?", "kind": "ownership", "answer_data": [ "accountable party reference", "issuer residual obligation list", "holder obligation list" ] }, { "id": "q-sdp-digest", "text": "How does a protocol's per-claim digest mechanism relate to this model's template fingerprint?", "kind": "identity", "answer_data": [ "digest scope statement", "relationship to template fingerprint", "verification procedure reference" ] }, { "id": "q-sdp-inexpressible", "text": "Which parts of a governed shape cannot be expressed in a holder-selected protocol at all?", "kind": "exception", "answer_data": [ "inexpressible construct list", "fallback approach", "recorded conflict" ] } ], "data_elements": [ { "id": "de-sdp-selectable-element", "name": "Selectively disclosable element", "description": "Element the issuer permits the holder to reveal or withhold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-sdp-always-element", "name": "Always-disclosed element", "description": "Element that is present in every presentation regardless of holder choice.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-sdp-protocol-ref", "name": "Disclosure protocol reference", "description": "Identifier and version of the selective-disclosure protocol in use.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "This is an alignment statement about protocol behaviour, not a deliverable. Credential issuance, wallet holding and verification are separate subjects with their own models, and an artifact here would imply this model produces presentations." } ] }, { "id": "publication-and-catalogue", "name": "Publication and Catalogue", "description": "The shape in which the policy record itself is disclosed to different readers.", "source_refs": [ "SRC-003", "SRC-012", "SRC-001" ], "findings": [ { "id": "self-applied-policy-projection", "name": "Self-Applied Policy Projection", "description": "The projection under which the policy record itself leaves, since a disclosure policy is itself sensitive: a browsable summary, a template-only view for a bound recipient, and a full view for a reviewer.", "source_refs": [ "SRC-003", "SRC-012", "SRC-001" ], "questions": [ { "id": "q-pub-card", "text": "Which projection of the policy record is published for unauthenticated browsing?", "kind": "access", "answer_data": [ "published field list", "omitted field list", "publication location reference" ] }, { "id": "q-pub-withheld", "text": "Which parts of a policy record are withheld because publishing them would assist an attacker?", "kind": "security", "answer_data": [ "withheld part list", "attack assisted", "withholding rationale" ] }, { "id": "q-pub-preview", "text": "How does a prospective recipient assess a shape without receiving any instance data?", "kind": "process", "answer_data": [ "preview procedure reference", "preview output description", "instance-data prohibition statement" ] }, { "id": "q-pub-reviewer", "text": "Which projection does a reviewer, auditor or supervisory authority receive, and on what basis?", "kind": "authority", "answer_data": [ "reviewer projection identifier", "authorising basis reference", "request handling route" ] } ], "data_elements": [ { "id": "de-pub-published-field", "name": "Published field", "description": "A policy attribute included in the publicly browsable projection.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-pub-withheld-part", "name": "Withheld part", "description": "A policy attribute deliberately excluded from publication, with its reason code.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-pub-projection-ref", "name": "Applied projection reference", "description": "Reference to the shape governing publication of this policy record, applied reflexively.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "disclosure-policy-catalogue-card", "name": "Disclosure Policy Catalogue Card", "description": "The published summary of a projection policy - name, grain, count of omitted elements, assurance method claimed and template fingerprint - shown to prospective recipients browsing what shapes an owner offers, without exposing per-element rules or adversary assumptions.", "media_or_form": [ "published catalogue entry", "summary record", "catalogue interface representation" ], "serial": false, "identity_strategy": "Derived identity: the authoritative policy master identifier from the Dimension's register, plus the identifier of the card shape and the policy version summarised; a Dimension-assigned ULID only where no register key exists. The card is never identified by its publication date.", "source_refs": [ "SRC-003", "SRC-001", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "change-and-fitness", "name": "Change and Fitness", "description": "Shape-specific consequences of change: whether a change widens or narrows disclosure, what must be emitted so a past disclosure stays explainable, and which signals mean a shape no longer protects adequately.", "rationale": "The generic policy lifecycle is owned elsewhere, but the question of whether a change lets more data out is purely a shape question and has no home in a generic policy model.", "source_refs": [ "SRC-001", "SRC-014", "SRC-009", "SRC-013" ], "layers": [ { "id": "shape-change-semantics", "name": "Shape Change Semantics", "description": "Classification of a change between two policy versions and the reproducibility obligations that follow.", "source_refs": [ "SRC-001", "SRC-014", "SRC-013" ], "findings": [ { "id": "disclosure-change-classification", "name": "Disclosure Change Classification", "description": "Whether a change between two policy versions narrows, widens or leaves disclosure unchanged, which dependents it affects, and what each class requires before taking effect.", "source_refs": [ "SRC-001", "SRC-011", "SRC-014", "SRC-012" ], "questions": [ { "id": "q-chg-class", "text": "Is this change narrowing, widening or orthogonal with respect to what leaves?", "kind": "classification", "answer_data": [ "change class code", "per-path change list", "subsumption test evidence" ] }, { "id": "q-chg-affected", "text": "Which compiled templates, bindings and recipients are affected by the change?", "kind": "relationship", "answer_data": [ "affected template list", "affected binding list", "notification target list" ] }, { "id": "q-chg-gate", "text": "What must be satisfied before a widening change may take effect, and who decides that?", "kind": "authority", "answer_data": [ "required approval reference in WM-KNW-012", "required re-validation list", "decision owner reference" ] }, { "id": "q-chg-indirect", "text": "How is a change treated when the policy text is unchanged but the treatment matrix or path grammar moved beneath it?", "kind": "provenance", "answer_data": [ "indirect change source", "recompilation requirement", "assigned change class" ] } ], "data_elements": [ { "id": "de-chg-class", "name": "Disclosure change class", "description": "Whether the compared versions narrow, widen or do not alter what leaves.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-chg-affected-template", "name": "Affected template reference", "description": "Compiled template that must be recompiled or withdrawn because of the change.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "de-chg-compared-versions", "name": "Compared version pair", "description": "The ordered from-version and to-version identifiers whose shapes were compared.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "shape-difference-report", "name": "Shape Difference Report", "description": "A structured comparison of two policy versions stating, per path, whether disclosure narrowed, widened or was unchanged, together with the overall change class and the dependent templates and bindings the change invalidates.", "media_or_form": [ "structured difference record", "review annex", "machine-readable diff" ], "serial": false, "identity_strategy": "Identified by the ordered pair of compared policy version identifiers from the authoritative policy register, plus the compiler identifier and version that produced the comparison; a Dimension-assigned UUID only where the register issues no version keys. A digest verifies the report content; the comparison date is never part of the identity.", "source_refs": [ "SRC-001", "SRC-014", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "served-output-reproducibility", "name": "Served Output Reproducibility", "description": "The minimum set of shape-identifying values that must accompany a served output so a past disclosure can be reconstructed and explained, and how long this model keeps them resolvable.", "source_refs": [ "SRC-013", "SRC-014", "SRC-003", "SRC-011" ], "questions": [ { "id": "q-rep-emit", "text": "Which values must be emitted alongside a served output so its shape can be reconstructed later?", "kind": "requirement", "answer_data": [ "policy version identifier", "template fingerprint", "binding identifier", "source schema version identifier" ] }, { "id": "q-rep-owner", "text": "Which model records those emitted values, and what is this model's obligation limited to?", "kind": "ownership", "answer_data": [ "recording owner reference WM-XCT-004", "emission obligation statement", "explicit non-ownership statement" ] }, { "id": "q-rep-resolvable", "text": "For how long must a superseded template stay resolvable, and what remains when it does not?", "kind": "retention", "answer_data": [ "minimum resolvable period", "tombstone content list", "disposition owner reference" ] }, { "id": "q-rep-times", "text": "How are compilation time, effective time and disclosure time kept distinct in the emitted values?", "kind": "temporal", "answer_data": [ "compiled-at timestamp", "effective-from timestamp", "statement that disclosure time is recorded by the audit model" ] } ], "data_elements": [ { "id": "de-rep-emitted-version", "name": "Emitted policy version identifier", "description": "The policy version identifier handed to the caller for recording elsewhere.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-rep-emitted-fingerprint", "name": "Emitted template fingerprint", "description": "The template digest handed to the caller so a served output can be tied to a shape.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "de-rep-tombstone", "name": "Template tombstone", "description": "Residual record retained for a withdrawn template, holding identifiers and a withdrawal reason and no source content.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "This finding defines an emission contract, not a record. The audit entry, its ordering, immutability, protection and retention are owned by WM-XCT-004, so declaring an artifact here would create a competing trail this model has no authority to hold." } ] }, { "id": "fitness-signals", "name": "Fitness Signals", "description": "Detectable conditions that mean a previously acceptable shape may now under-protect, with hand-off to the models that act.", "source_refs": [ "SRC-009", "SRC-003", "SRC-012" ], "findings": [ { "id": "shape-invalidation-signals", "name": "Shape Invalidation Signals", "description": "The observable conditions that make a shape unfit - upward reclassification, schema drift, changed adversary context, expired assurance, regime change - recorded as signals with safe interim behaviour and an explicit hand-off, not as a state machine.", "source_refs": [ "SRC-009", "SRC-003", "SRC-012", "SRC-014" ], "questions": [ { "id": "q-fit-signals", "text": "Which observable signals indicate that this shape may now under-protect?", "kind": "event", "answer_data": [ "signal list with originating model", "detection method", "observation timestamp" ] }, { "id": "q-fit-interim", "text": "What is the safe interim behaviour between detecting a signal and resolving it?", "kind": "state", "answer_data": [ "interim behaviour code (withhold element, serve narrower shape, refuse)", "authorising basis", "duration limit" ] }, { "id": "q-fit-handoff", "text": "Which model executes the resulting withdrawal or supersession, and what is handed to it?", "kind": "lifecycle", "answer_data": [ "execution owner reference WM-KNW-012", "hand-off payload", "confirmation expected" ] }, { "id": "q-fit-monitoring", "text": "How is a long absence of signals distinguished from a shape nobody is monitoring?", "kind": "quality", "answer_data": [ "last-checked timestamp", "monitoring coverage statement", "outcome when monitoring is stale" ] } ], "data_elements": [ { "id": "de-fit-signal", "name": "Invalidation signal", "description": "A detected condition suggesting the shape no longer protects adequately, with its originating model.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-fit-interim-behaviour", "name": "Interim behaviour", "description": "The conservative behaviour declared for the period between detection and resolution.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-fit-observed-at", "name": "Signal observation timestamp", "description": "RFC 3339 instant at which the signal was observed here, recorded separately from the instant the underlying change occurred.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "de-fit-monitoring-coverage", "name": "Monitoring coverage statement", "description": "Which signals are actively monitored for this shape and which are not.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Signals and interim behaviour are declarative annotations on the shape. State transitions, approval and supersession are executed by WM-KNW-012 and any runtime response by WM-XCT-038, so an artifact here would be mistaken for a lifecycle record this model does not own." } ] } ] } ] }, "functions": [ { "id": "compile-output-template", "name": "Compile Output Template", "description": "Derive the concrete output template from a pinned policy version, a pinned source schema version and a pinned treatment matrix version, and compute its fingerprint.", "inputs": [ "policy version reference", "source schema version reference", "treatment matrix version reference", "compiler identity and version" ], "outputs": [ "compiled output template", "template fingerprint", "unresolved path list" ], "preconditions": [ "The policy version is in a state that permits compilation according to WM-KNW-012; this function does not evaluate or grant that state", "The source schema version resolves in WM-DAT-004", "No instance data is supplied or accessible" ], "effects": [ "Creates or reproduces a compiled output template artifact identified by its pinned inputs", "Emits the fingerprint for callers to record; writes no audit entry" ], "source_refs": [ "SRC-014", "SRC-006", "SRC-007" ] }, { "id": "preview-shape-against-schema", "name": "Preview Shape Against Schema", "description": "Produce a template and an omitted-element report for a prospective recipient evaluating a shape before any grant exists, without touching instance data.", "inputs": [ "policy version reference", "source schema version reference", "requested audience class" ], "outputs": [ "preview template", "omitted element count and paths at the disclosable level", "unsupported construct list" ], "preconditions": [ "The requested policy is published in the catalogue projection", "The caller supplies no instance data and receives none" ], "effects": [ "Returns a design-time preview only", "Makes no authorization decision and creates no binding" ], "source_refs": [ "SRC-003", "SRC-001", "SRC-014" ] }, { "id": "test-shape-subsumption", "name": "Test Shape Subsumption", "description": "Decide whether one shape discloses no more than another across selection, treatment, record scope and grain, returning witnesses on failure.", "inputs": [ "candidate shape reference", "reference shape reference" ], "outputs": [ "subsumption verdict", "witness path list", "per-dimension comparison detail" ], "preconditions": [ "Both shapes use the same path grammar or a declared translation exists", "Both resolve against a common source schema version" ], "effects": [ "Produces a comparison result usable as evidence in review", "Changes no policy state and enforces nothing" ], "source_refs": [ "SRC-006", "SRC-011", "SRC-012" ] }, { "id": "derive-least-disclosure-shape", "name": "Derive Least-Disclosure Shape", "description": "Merge two applicable shapes into a single shape no wider than either, or refuse where the merge is undefined.", "inputs": [ "first shape reference", "second shape reference" ], "outputs": [ "derived shape", "monotonicity assertion", "refusal reason where undefined" ], "preconditions": [ "Both shapes are already determined to be applicable by the caller; this function performs no applicable-policy selection", "Both declare compatible grain and record-scope semantics" ], "effects": [ "Returns a derived shape for compilation", "Never resolves a precedence question between the source policies" ], "source_refs": [ "SRC-011", "SRC-001", "SRC-012" ] }, { "id": "check-shape-against-class-matrix", "name": "Check Shape Against Class Matrix", "description": "Verify that every selected element's declared treatment is at least the minimum required for its externally assigned sensitivity class.", "inputs": [ "shape reference", "treatment matrix version reference", "class assignment set from WM-XCT-020" ], "outputs": [ "violation list with severity", "unclassified element list", "pass or fail verdict" ], "preconditions": [ "Class assignments resolve for the elements in scope", "The matrix version is valid for the referenced classification scheme version" ], "effects": [ "Produces a design-time validation result", "Records no decision about a request and blocks nothing at runtime" ], "source_refs": [ "SRC-008", "SRC-012", "SRC-010" ] }, { "id": "detect-source-schema-drift", "name": "Detect Source Schema Drift", "description": "Compare a shape's declared paths against a newer source schema version and report unresolved paths, newly appearing elements and the outcome the shape's closure mode assigns them.", "inputs": [ "shape reference", "current source schema version reference", "previously bound schema version reference" ], "outputs": [ "unresolved path list", "new element list with assigned outcome", "drift observation timestamp" ], "preconditions": [ "Both schema versions resolve in WM-DAT-004", "The shape declares a closure mode" ], "effects": [ "Raises an invalidation signal for the affected shape", "Requests classification of new elements from WM-XCT-020 without assigning a class itself" ], "source_refs": [ "SRC-014", "SRC-006", "SRC-013" ] }, { "id": "classify-disclosure-change", "name": "Classify Disclosure Change", "description": "Compare two policy versions and assign a narrowing, widening or orthogonal change class, listing dependent templates and bindings.", "inputs": [ "from policy version reference", "to policy version reference", "dependent template index" ], "outputs": [ "change class", "shape difference report", "affected template and binding list" ], "preconditions": [ "Both versions resolve in the policy register maintained under WM-KNW-012", "Both compile against a common source schema version" ], "effects": [ "Produces the difference report artifact", "Signals a recompilation obligation; approval of the change remains with WM-KNW-012" ], "source_refs": [ "SRC-001", "SRC-014", "SRC-011" ] }, { "id": "assemble-disclosure-provenance-tuple", "name": "Assemble Disclosure Provenance Tuple", "description": "Return the shape-identifying values a caller must record with a served output: policy version identifier, template fingerprint, binding identifier, source schema version identifier and compilation timestamp.", "inputs": [ "binding identifier", "compiled template reference" ], "outputs": [ "provenance tuple", "resolvability guarantee statement" ], "preconditions": [ "The binding and template both resolve", "The caller is the party responsible for recording the disclosure" ], "effects": [ "Hands the tuple to the caller; WM-XCT-004 owns writing, ordering, protecting and retaining the resulting audit entry", "Writes nothing to any audit trail and asserts no audit-trail semantics" ], "source_refs": [ "SRC-013", "SRC-003", "SRC-014" ] }, { "id": "publish-policy-catalogue-projection", "name": "Publish Policy Catalogue Projection", "description": "Apply the model's own publication shape to a policy record and emit the browsable catalogue card, withholding parts whose publication would assist an attacker.", "inputs": [ "policy version reference", "publication shape reference" ], "outputs": [ "catalogue card artifact", "withheld part list with reason codes" ], "preconditions": [ "The policy version is marked publishable under WM-KNW-012", "A publication shape is bound to the policy record itself" ], "effects": [ "Publishes the card at the declared location", "Discloses no per-element rules, adversary assumptions or assurance evidence" ], "source_refs": [ "SRC-003", "SRC-012", "SRC-001" ] }, { "id": "require-cohort-floor-reference", "name": "Attach cohort floor reference", "description": "Require a WM-XCT-005 floor id on aggregate-only shapes; does not compute k or epsilon.", "inputs": [ "grain class", "cohort_floor_ref" ], "outputs": [ "validated cohort floor reference on the aggregate-only shape" ], "preconditions": [ "grain_class is aggregate_only" ], "effects": [ "Blocks an aggregate-only shape carrying no cohort floor reference", "Does not compute thresholds, k, or epsilon" ], "source_refs": [ "SRC-008", "SRC-003" ] } ], "composition": [ { "target": "WM-KNW-012 Governed Policy", "relation": "EXTEND", "purpose": "Specialize the generic governed policy with output-shape semantics only. Policy identity, authoring authority, approval, version states, supersession and conflict resolution remain in the target; this model adds selection, treatment, record scope, grain, shape algebra, templates and shape-specific change classification.", "required": true, "source_refs": [ "SRC-001", "SRC-011" ] }, { "target": "WM-XCT-001 Ownership and Delegation", "relation": "REFERENCE", "purpose": "Carry a reference to the owner or delegated steward whose authority a shape presupposes, and to the party who accepted a named residual-disclosure risk. Ownership records, delegation instruments and their lifecycle stay in the target.", "required": true, "source_refs": [ "SRC-012", "SRC-003" ] }, { "target": "WM-XCT-002 Access Contract and Consent", "relation": "REFERENCE", "purpose": "Bind a shape to an access contract or consent grant by reference and record the audience class the binding serves. Authorization, purpose, parties and consent lifecycle stay in the target.", "required": true, "source_refs": [ "SRC-001", "SRC-005" ] }, { "target": "WM-XCT-004 Access Audit", "relation": "REFERENCE", "purpose": "Supply the provenance tuple - policy version identifier, template fingerprint, binding identifier, source schema version - that the target records with each served disclosure. Audit events, append-only trail semantics, ordering, immutability and retention stay in the target.", "required": true, "source_refs": [ "SRC-013", "SRC-003" ] }, { "target": "WM-XCT-005 Privacy Aggregation and Cohort Floors", "relation": "REFERENCE", "purpose": "Reference the applicable cohort floor, perturbation mechanism or composition budget for an aggregate or repeated-release shape. Threshold calculation, risk quantification, budget accounting and aggregation assurance stay in the target.", "required": false, "source_refs": [ "SRC-004", "SRC-003" ] }, { "target": "WM-XCT-020 Sensitivity Classification", "relation": "REFERENCE", "purpose": "Key the minimum-treatment matrix on classes assigned in the target and consume reclassification as an input signal. Classification schemes, criteria, membership and assignment stay in the target.", "required": false, "source_refs": [ "SRC-008", "SRC-010" ] }, { "target": "WM-DAT-004 Source Schema and Data Contract", "relation": "REFERENCE", "purpose": "Resolve path expressions and compile output templates against a pinned governed schema version, and report drift. Source semantics, structure and validation contracts stay in the target.", "required": true, "source_refs": [ "SRC-014", "SRC-006" ] }, { "target": "WM-XCT-038 Runtime Policy Enforcement", "relation": "REFERENCE", "purpose": "Provide the declarative shape and its applicability conditions as evaluation input. Selecting applicable policies, evaluating conditions, producing decisions and explanations, discharging obligations and applying a shape to instance data stay in the target.", "required": true, "source_refs": [ "SRC-011", "SRC-001" ] }, { "target": "W3C ODRL 2.2 Information Model and Vocabulary (external standard)", "relation": "ALIGN", "purpose": "Map shape concepts onto Policy, Rule, Constraint, Party function and the anonymize, aggregate, derive and extract actions. Alignment only: ODRL actions carry no de-identification or field-selection parameters, so no conformance is claimed.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "ISO/IEC 20889:2018 de-identification terminology (external standard)", "relation": "ALIGN", "purpose": "Draw technique family names and the identifier, quasi-identifier and sensitive-attribute roles from a governed terminology instead of minting local terms. Conformance is not claimed because the normative text is paywalled and was not read clause by clause.", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] }, { "target": "IETF RFC 9901 SD-JWT selective disclosure (external standard)", "relation": "ALIGN", "purpose": "Align the encoding profile and residual-disclosure findings with a holder-selected disclosure protocol, including per-claim digests and decoy digests. Credential issuance, wallet holding and verification are separate subjects.", "required": false, "source_refs": [ "SRC-007" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name the policy register that issues authoritative master identifiers for projection policies, templates and matrices, and name the WM-KNW-012 authority under which shapes are approved; this model never mints a policy identity of its own.", "Declare, with versions, the three vocabularies a shape depends on: the path grammar, the treatment technique vocabulary and the classification scheme the treatment matrix is keyed on. A shape whose vocabularies are undeclared cannot be compiled or checked.", "Nominate the compiler implementation and version, because a template fingerprint is only reproducible against a named compiler; record it with every template.", "State where assurance evidence is held and which model owns risk quantification, since this model holds claims and pointers only.", "State the adopting Dimension's retention schedule for withdrawn policy records and tombstones, and which body executes disposition." ], "namespace_guidance": "Use one namespace per adopting Dimension for shape, binding and template identifiers, and a strictly separate namespace for pseudonym and re-identification code spaces so two shapes never silently share a join key. External standard terms keep their own namespaces - ODRL at http://www.w3.org/ns/odrl/2/, DPV at https://w3id.org/dpv# - and are referenced by IRI, never re-minted locally. Local kebab-case identifiers are model-internal and are not global identifiers.", "registry_links": [ "Registry entry vr.wm-xct-003 in the world-model record plane, navigation path NAV.XCT.DSC, domain tag XCT.DSC", "Registry entries for the eight related models: WM-KNW-012, WM-XCT-001, WM-XCT-002, WM-XCT-004, WM-XCT-005, WM-XCT-020, WM-DAT-004, WM-XCT-038", "External vocabulary registries cited as alignments: W3C ODRL vocabulary, W3C DPV, IETF RFC index for the path and timestamp grammars" ] }, "canon_and_patch": { "canonicalization_rules": [ "Express every path in the declared grammar's normalized single-node form and sort selection sets by that normalized form before digesting; declare the grammar identifier and version alongside.", "Sort treatment parameter maps by key, normalise numeric precision explicitly, and represent an absent optional value as absent rather than as null so omission and null never collide.", "Strip presentation-only annotations, comments and ordering hints before computing a template digest; a digest must depend only on what is disclosed and on the pinned input identifiers.", "Record every timestamp in the canonical RFC 3339 form with seconds and an explicit offset before digesting; never normalise an offset away." ], "patch_rules": [ "Address patch targets by stable local identifier and normalized path, never by array position, so reordering a selection set is not itself a change.", "Any patch touching a selection path, treatment technique or parameter, record filter, grain or closure mode obliges a change classification and recompilation of every dependent template.", "Never patch an already fingerprinted template in place: supersede it with a newly compiled template and retain the prior fingerprint as resolvable.", "A patch to a referenced vocabulary version is an indirect change to every shape bound to it and must be classified even when no policy text changed." ], "compatibility_rules": [ "Narrowing changes are safe for disclosure but breaking for consumers whose readers expect the wider shape; classify and announce them as consumer-breaking.", "Widening changes require fresh authority under WM-KNW-012 and a re-check against the treatment matrix before any template is recompiled; this model records the requirement and does not grant it.", "Adding an element under an open closure mode is a widening change; under a closed closure mode it is orthogonal until the element is explicitly selected.", "Compatibility is asserted per pinned source schema version: the same policy version may be narrowing against one schema version and widening against another, and both classifications must be retained." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier: the key issued by the adopting Dimension's policy register, which is the system of record for projection policies, bindings, templates and matrices under WM-KNW-012 governance. Use it verbatim and never re-mint it.", "Governed global identifier or IRI: a resolvable IRI in the Dimension's governed namespace, or an externally governed identifier such as an ODRL policy uid, where the register issues one.", "UUID or ULID assigned by the adopting Dimension, used only where neither a master-system key nor a governed IRI exists, and recorded as locally assigned.", "A content digest or fingerprint is an integrity value and never a primary identifier; a version label is not an identifier on its own; a date or timestamp is never an identifier under any circumstances." ], "timestamp_rule": "Every time value is an RFC 3339 date-time carrying explicit seconds and an explicit offset, either 'Z' or a numeric +/-hh:mm; offset-less or local-only values are rejected, and '-00:00' is used only to mean the local offset is unknown. Event time and observation or ingestion time are recorded as separate fields whenever they differ: the instant a schema changed, a class was reassigned or a determination was made is distinct from the instant this model observed it, and the compilation time of a template is distinct from the effective-from time of its binding and from the disclosure time recorded by WM-XCT-004. Never derive one from another and never overwrite an event time with an ingestion time.", "serial_naming_rule": "This model declares no inherently serial artifact: templates, matrices, crosswalks and difference reports are identified by their pinned inputs, not by position in a sequence. Where an adopting Dimension nonetheless serialises repeated compilations, the name takes the form @~# with a zero-padded monotonic counter appended, and carries no date component; ordering is read from the recorded RFC 3339 compilation timestamp, never from the name.", "integrity_rule": "Every compiled template, matrix and difference report carries a digest computed over its canonical form together with the identifiers of its pinned inputs, so any party can recompute the value and confirm it. A mismatch invalidates the artifact for serving and obliges recompilation; recording the mismatch, adjudicating it and taking any enforcement action belong to WM-XCT-004 and WM-XCT-038 respectively." }, "policies": [ "Default deny: an element that no selection rule names does not leave. A shape may only depart from this by stating a different default explicitly, with a recorded justification and the authority that accepted it.", "No instance data: this model stores, caches and transits no source records at any time. Every function operates on schemas, policies and identifiers only, and any implementation that reads instance data has stepped into WM-XCT-038's boundary.", "No local floors: cohort minimums, risk thresholds and privacy budgets are referenced by instrument identifier and never restated, defaulted or overridden locally, even when the reference is unresolvable - in that case the shape is unfit and must not be served.", "Every shape names its basis: a shape without a declared assurance method, or with an expired one, is recorded as unassured and must not be bound to any audience until the claim is restored.", "Alignment without conformance: external standard terms are referenced with a stated mapping strength, and no conformance claim is made without evidence recorded in the crosswalk.", "Need-to-shape: the published maximum leaving shape is the least revealing grain and strongest treatments still adequate for the referenced purpose (GDPR Art 5(1)(c) and 25(2); HIPAA 164.514(d)).", "Compile-before-serve: no instance payload is produced from an uncompiled or stale template; stale includes schema, classification-binding, or cohort-floor version drift.", "Reference-don't-copy: owner, grant, audit, classification, threshold, schema, and PDP semantics remain in sibling models; this model stores only refs and subject-specific parameters." ], "crud": { "read": [ "The default read of a policy record returns the catalogue card projection only; broader reads require an authorization decided under WM-XCT-002 and applied by WM-XCT-038.", "A bound recipient may read the compiled template and its fingerprint for the bindings that name them, and nothing beyond.", "Reviewers, auditors and supervisory authorities read the full record including adversary assumptions and evidence pointers, on a basis recorded outside this model.", "Every read of full policy content emits the provenance tuple for the caller to record; this model performs no logging itself." ], "create": [ "A shape may be created only with a resolvable source schema binding, a declared closure mode, a declared default treatment and a named path grammar and technique vocabulary with versions.", "Creation records a reference to the authority under which the shape is authored; it does not itself constitute approval, which is granted in WM-KNW-012.", "A binding may be created only when both its shape and its target reference resolve and an effective-from timestamp is supplied.", "Creating a template is a derivation, never a manual authoring act: a template that cannot be recompiled from its pinned inputs is invalid." ], "update": [ "Every update that touches shape content produces a change classification and a difference report before it may take effect.", "A widening update is blocked pending fresh authority recorded in WM-KNW-012 and a successful re-check against the treatment matrix; this model records the block and does not adjudicate it.", "Updating a referenced vocabulary version is an indirect update to every shape bound to it and triggers the same classification path.", "A fingerprinted template is never edited; it is superseded by a newly compiled one and the prior fingerprint remains resolvable." ], "delete": [ "Projection policies, bindings and compiled templates are not hard-deleted while any served output may still cite them: withdraw them by supersession in WM-KNW-012 and by marking the local binding inactive, leaving a tombstone in place.", "A tombstone retains only what is needed to explain a past disclosure - policy identifier and version, template fingerprint, binding identifier, source schema version, compilation timestamp and a withdrawal reason code - and never any source content, key material or pseudonym mapping.", "Because this model holds no instance data, a data-subject erasure request never acts on these records; erasure of source data is executed under WM-DAT-004 and the adopting Dimension's retention policy, and erasure of audit entries citing a fingerprint is executed under WM-XCT-004, which owns their retention, legal hold and disposition.", "Where an adopting Dimension's retention schedule requires destruction of a policy record itself, execution, approval and evidence of destruction are the Dimension's responsibility under WM-KNW-012 governance; this model contributes only the shape-specific reason code and the list of dependents that would become unresolvable.", "Deleting a tombstone is permitted only once every audit entry citing its fingerprint has itself been dispositioned under WM-XCT-004; this model may record the dependency but must not execute or approve the disposition." ] }, "roles": [ { "name": "Shape Author", "responsibilities": [ "Draft selection sets, treatments, record scope and grain with an explicit default and closure mode", "Declare the path grammar, technique vocabulary and classification scheme versions the shape depends on", "Record the identifiability role of every selected element and the assumptions behind it" ] }, { "name": "Disclosure Reviewer", "responsibilities": [ "Test a candidate shape against the treatment matrix and the declared assurance method", "Examine residual disclosure channels and record which are accepted and on whose authority", "Return a review result; approval authority itself is exercised in WM-KNW-012 and is not held by this role" ] }, { "name": "Template Compiler", "responsibilities": [ "Derive templates deterministically from pinned inputs and compute fingerprints", "Refuse compilation when any pinned input is unresolvable or any path fails to resolve", "Record its own implementation identity and version with every artifact produced" ] }, { "name": "Schema Liaison", "responsibilities": [ "Monitor bound source schema versions for drift and raise invalidation signals", "Request classification of newly appearing elements from WM-XCT-020 without assigning a class", "Maintain the alias list that keeps prior paths resolvable after a rename" ] }, { "name": "Catalogue Publisher", "responsibilities": [ "Apply the model's own publication shape to policy records and publish catalogue cards", "Withhold parts whose publication would assist an attacker and record the reason", "Keep published cards consistent with the current policy version or withdraw them" ] }, { "name": "Model Steward", "responsibilities": [ "Maintain the expression alignment crosswalk and re-verify it when a cited standard is revised", "Keep boundary notes current when a related model's scope moves, relocating any concept that drifts inward", "Record conflicts, gaps and regional assumptions rather than resolving them silently" ] } ], "access": { "default_rule": "Full policy content is need-to-know. The default read of any projection policy is the catalogue card projection - name, grain, assurance method claimed, count of omitted elements and template fingerprint. Anything beyond, including per-element treatments, adversary assumptions, join keys and evidence pointers, requires an authorization decided under WM-XCT-002 and applied by WM-XCT-038.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Reviewers, internal auditors and supervisory authorities receive the full record on a basis recorded outside this model, including parts withheld from every other reader.", "A bound recipient receives the compiled template and its fingerprint for their own bindings without further authorization, because that content is precisely what they are entitled to receive.", "Join keys, pseudonym namespace identifiers and adversary assumptions are withheld even from otherwise authorised readers, because disclosing them materially assists linkage attacks against outputs already served.", "In an incident, a shape may be narrowed or withdrawn immediately and the justification recorded afterwards; the shape may never be widened under an incident exception.", "Public catalogue cards (name, grain, omitted-path count) MAY be readable without a grant when the owner so binds.", "Emergency break-glass to read a full rule set is an access exception logged in WM-XCT-004, not modelled here.", "Preview endpoints MUST NOT accept or return instance data." ], "audit_requirements": [ "Every read of policy content beyond the catalogue card must be recorded together with the requesting party and the projection identifier served; this model supplies the provenance tuple and WM-XCT-004 writes and owns the entry.", "Every compilation, change classification and matrix violation must be attributable to a named actor and implementation version through the values this model emits.", "Acceptance of a residual disclosure channel and any departure from default-deny must be attributable to the accepting authority referenced in WM-XCT-001.", "This model holds no audit trail, performs no log writes and asserts no properties about ordering, immutability or retention of audit entries.", "Every compile, bind, and preview SHALL be eligible for an audit event in WM-XCT-004 carrying template_id, policy_version_id, and shape_fingerprint.", "This model SHALL NOT store append-only access trails." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Model ID", "Composition and boundary links", "Bootstrap validation steps" ], "read_order": [ "Read AGENTS.md first and resolve Name, Type and Model ID before touching any record, whatever the storage backend.", "Follow Specification URL to obtain scope, in-scope and out-of-scope lists and the boundary notes, and stop if a requested operation falls outside them.", "Follow Storage type URL to learn how records are physically held - document store, repository, collection or interface-backed - treating that form as a projection and never as the semantics.", "Follow Interface URL for the read, create, update and delete surface and the access default before attempting any operation.", "Follow Processes URL for compilation, validation, change classification and hand-off procedures, including which model executes each hand-off.", "Read Composition and boundary links last and re-check the intended operation against every outgoing relation; if the operation would evaluate, enforce, decide or audit, stop and call the owning model instead." ] } }, "coverage": { "claim": "The Claude base plus two Grok findings and one Grok function covers the declarative output-shape surface for WM-XCT-003: grain class, element selection with graph extent, per-element treatment and reversibility, record scope, shape algebra, compiled template and fingerprint, binding and applicability, class and regime constraints, identifiability and assurance declaration, cross-release linkability, expression alignment, self-applied publication, and shape change and fitness semantics. Coverage is evidenced only for US and EEA regimes and for JSON/tabular-style media; non-tree media, protocol profiles beyond the cited four, synthetic-data grain and risk quantification remain unmodelled or externally owned. No universal completeness and no conformance to any cited standard is claimed.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identity priority names the authoritative policy-register key first, then a governed IRI, then a Dimension-assigned UUID or ULID. Templates, matrices, crosswalks and difference reports are identified by pinned inputs; digests are integrity values only and dates are excluded from every identity strategy." }, { "dimension": "lifecycle", "status": "covered", "notes": "Only the shape-specific surface is local: change classification (narrowing, widening, orthogonal) and invalidation signals with declared interim behaviour. Policy states, approval, supersession and withdrawal execution are delegated to WM-KNW-012 by the EXTEND rationale and appear in out_of_scope and boundary notes, not as local machinery." }, { "dimension": "relationships", "status": "covered", "notes": "All eight ledger relations are carried as composition links with target-owned concepts named explicitly, plus three external ALIGN entries. Internally, shape-to-binding, shape-to-template, shape-to-companion-shape and shape-to-schema relations are modelled as references." }, { "dimension": "temporal", "status": "covered", "notes": "RFC 3339 with seconds and explicit offset throughout, with event time separated from observation time for schema drift, reclassification and determinations, and compilation time separated from binding effective-from and from the disclosure time owned by WM-XCT-004. Aggregation periods and stream windows are modelled separately from record timestamps." }, { "dimension": "provenance", "status": "covered", "notes": "Templates pin policy version, schema version, matrix version and compiler identity; the provenance tuple is defined as an emission contract; indirect change through a moved vocabulary is explicitly classified. Assurance evidence is pointed to, never copied." }, { "dimension": "ownership", "status": "covered", "notes": "Carried by reference only: the authority a shape presupposes, the party accepting a residual channel, and the accountable party when a holder selects the final shape. Ownership records and delegation instruments remain in WM-XCT-001." }, { "dimension": "validation", "status": "covered", "notes": "Three design-time checks are defined - subsumption testing, class-matrix conformance and schema-drift detection - each returning witnesses or violation lists and each explicitly blocking nothing at runtime." }, { "dimension": "access", "status": "covered", "notes": "Default read is the catalogue card; scopes span bundle, layer, finding and artifact; exceptions cover reviewers, bound recipients, withheld join keys and incident narrowing. The model applies its own projection semantics reflexively to the policy record." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Tombstone content is specified precisely, and execution ownership is assigned: source-data erasure to WM-DAT-004 and the Dimension, audit-entry disposition to WM-XCT-004, and destruction of the policy record itself to the Dimension under WM-KNW-012. Residual uncertainty over legal-hold interaction across those three owners is recorded as a conflict." }, { "dimension": "interoperability", "status": "covered", "notes": "A maintained crosswalk records mapping strength per term, unmapped concepts requiring a profile, and conformance claims explicitly withheld. Encoding profiles assert semantic equivalence per encoding, and holder-selected protocols are aligned with their inexpressible constructs named." }, { "dimension": "classification", "status": "covered", "notes": "Two distinct classification surfaces are kept apart: externally assigned sensitivity classes consumed from WM-XCT-020 as a minimum-treatment key, and locally declared identifiability roles used as review annotation that never substitutes for the governed class." }, { "dimension": "measurement and risk quantification", "status": "gap", "notes": "The model records assurance-method claims and parameter values but computes nothing. No cited source establishes an unambiguous owner for record-level expert-determination evidence: WM-XCT-005 is scoped to cohort floors and aggregation assurance, so evidence for a non-aggregate shape currently has no named home. Recorded as an unresolved boundary rather than claimed locally." }, { "dimension": "spatial and jurisdictional applicability", "status": "gap", "notes": "Territorial reach is modelled as a data element and one primary regime example is grounded, but only US and EEA sources were gathered. Applicability outside those regimes is asserted structurally, not evidenced, and cross-regime conflict resolution has no recorded owner." }, { "dimension": "security", "status": "covered", "notes": "Covers prohibited code derivations, withholding of join keys and pseudonym namespaces, response uniformity across error, refusal and empty result, and padding or decoy techniques against structural leakage. Key custody is referenced, never held." }, { "dimension": "privacy", "status": "covered", "notes": "Default-deny minimisation, class-driven minimum treatments, membership-in-set sensitivity, residual channels and cross-release linkability are all modelled, with quantification and budget accounting deferred to WM-XCT-005." }, { "dimension": "exception handling", "status": "covered", "notes": "Refusal of undefined shape merges, unresolved-path and new-element handling, incompatible regime prescriptions, inexpressible protocol constructs and stale monitoring each have a declared outcome and an escalation or hand-off target." } ], "known_omissions": [ "Non-tabular and non-tree media are addressed only through a generic locator hook: free-text redaction, image and audio masking, and geospatial generalisation have no modelled technique semantics.", "Aggregate function semantics beyond declaration are absent; sum, count and distinct-count are named but their disclosure properties are not differentiated.", "Synthetic data is named as a technique family but its fidelity and utility evidence, and the question of whether a synthetic output is a projection at all, are not modelled.", "Dynamic query interfaces are covered only through release-set linkability; adaptive query answering and query auditing are not modelled.", "A normative machine-readable encoding of the class-to-treatment matrix is left to the adopting Dimension, so mechanical checking is specified but not standardised.", "Watermarking, traitor tracing and post-disclosure attribution of a leaked output are not modelled anywhere in this structure.", "Utility loss caused by a shape is not measured, so no trade-off between protection and usefulness can be evaluated from this model alone.", "Binary/media-stream and large-object projection (OData stream properties, FHIR Binary) has no first-class treatment profile in the cited specs.", "Homomorphic or encrypted-field pass-through as a treatment class is mentioned in ISO 20889 cryptographic tools via secondary ITU-T X.1148 material; primary ISO text was not fully readable (paywalled). Marked gap.", "Synthetic microdata generation as a leaving grain vs a sibling generative-privacy model is unresolved.", "Differential-privacy query interfaces (NIST sharing model) as a grain class need epsilon/delta parameters that belong to XCT-005; the split may be too sharp for interactive query APIs.", "SCIM attribute returnability, GraphQL @skip/@include directive policies, and MongoDB/SQL view projections were not fetched as primary sources in this pass.", "National regimes beyond US HIPAA and EU GDPR (e.g. LGPD, PIPL, Australian Privacy Act APPs, UK DPA 2018 ICO anonymisation guidance) were not grounded in primary text.", "Re-identification attack libraries and Disclosure Review Board operating procedures (NIST SP 800-188) are process-governance of de-identification programmes, only partly overlapping this mixin.", "Format-preserving encryption and tokenisation vault semantics (PCI-adjacent) lack a primary source in this research set." ], "conflicts": [ "ODRL 2.2 defines anonymize, aggregate, derive and extract as actions without parameters for technique or field selection, verified against the published vocabulary RDF. Local treatment declarations are therefore strictly finer-grained than ODRL and no round-trip is lossless; no ODRL conformance is claimed.", "XACML 3.0 expresses obligations but has no native output-shape or field-projection type, so any mapping requires a profile. Its combining algorithms also resolve competing policies, which is precisely the concern the EXTEND rationale leaves in WM-KNW-012 - the local shape-merge operation must not be read as a combining algorithm.", "45 CFR 164.514 Safe Harbor is a fixed removal list; EDPB Guidelines 4/2019 expects risk-based minimisation assessed in context. A shape lawful under one is not automatically lawful under the other, and this model records both as constraints without reconciling them.", "De-identified under 45 CFR 164.514 is not equivalent to anonymous under EU law; equating them would misstate the residual obligations attached to an output.", "RFC 9535 JSONPath and RFC 6901 JSON Pointer differ in expressiveness: a shape written with filter selectors may have no JSON Pointer equivalent, so path grammar is not freely substitutable across encodings.", "DPV 2.1 is Community Group output rather than a W3C Recommendation, and the JSON Schema 2020-12 core document is an expired Internet-Draft; both are treated as lower-tier alignments than ISO/IEC, OASIS or IETF Standards Track material.", "Legal-hold interaction is unresolved across three owners: WM-XCT-004 controls audit-entry disposition, WM-DAT-004 and the Dimension control source-data erasure, and WM-KNW-012 controls destruction of the policy record. A hold in one may strand a tombstone in another with no recorded precedence.", "OData 4.01 §11.2.5: service MAY return additional information beyond $select. JSON:API 1.1 Sparse Fieldsets: endpoint MUST NOT include additional fields when fields[TYPE] is restricted. Local additional_fields_permitted records the chosen alignment.", "GraphQL client-specified exact shape vs GDPR Article 25(2) controller-default minimisation vs FHIR servers SHOULD return mandatory elements even if unrequested. Intersection_rule and mandatory_path_override make the conflict explicit.", "HIPAA Safe Harbor is a US-health implementation specification; it is not GDPR anonymisation (Recital 26 / WP29 remaining-risk test). Treatment packs are jurisdictional alignments.", "NIST SP 800-188: encryption or hashing of direct identifiers is not de-identification if keys remain. ISO/IEC 20889 still lists cryptographic tools as de-identification techniques. reversibility + crypto_key_retained capture the tension.", "FHIR servers are not obliged to return only requested _elements; JSON:API is. Compile-time templates cannot assume wire-level identical behaviour across protocols." ], "regional_assumptions": [ "Safe Harbor, the limited data set and the re-identification code rule are drawn from US federal health regulation and must not be applied as global defaults for any other sector or territory.", "Minimisation-by-default framing follows EDPB guidance and applies in the EEA; other regimes may accept different defaults or different definitions of adequate de-identification.", "NIST SP 800-188 and SP 800-226 are US federal guidance and are non-binding elsewhere, including their release models and Disclosure Review Board governance pattern.", "No sources were gathered for APPI, LGPD, DPDP, PIPL or comparable regimes, so a shape defensible under the evidenced regimes may be unlawful under them.", "Sector-specific disclosure rules in finance, telecommunications and statistics were not examined and may impose prescribed shapes this structure names only generically.", "HIPAA 45 CFR 164.514 applies to US covered entities and business associates for PHI; it is an optional treatment-pack alignment, not a global default.", "GDPR Articles 5 and 25 apply to personal data of natural persons in the Union's material/territorial scope; legal-person data are outside GDPR (Recital 14).", "ISO/IEC 20889:2018 remains current after 2024 confirmation; ISO/IEC 27559:2022 is the companion framework. Full normative text is paywalled; technique lists also rely on publicly visible abstracts, ITU-T X.1148 citations, and ISO OBP fragments.", "OData 4.01 (2020-04-23) is cited rather than the in-progress 4.02 CSD, which is not yet an OASIS Standard.", "FHIR R5 Search is normative; earlier R4 _elements/_summary behaviour is substantially similar but not byte-identical." ], "adversarial_checks": [ "Every bundle, layer, finding and function was re-read against all eight relation rationales. The previous version's entire lifecycle bundle - authoring, approval and versioning - was rejected as owned by WM-KNW-012 under the EXTEND rationale and relocated to out_of_scope, a composition link and a boundary note.", "Precedence between competing bindings, present in the previous version, was rejected as generic conflict handling. Only the shape-merge operation was retained, and a dedicated question forces the distinction between merging two shapes and deciding which policy prevails to be stated explicitly.", "Every function was tested for whether it touches instance data or produces a decision. Compilation, preview, subsumption, matrix checking, drift detection and change classification are all design-time with no request context; the provenance function was renamed and rewritten so it hands values to a caller and writes nothing.", "Tested whether the model was quietly owning audit semantics: the served-output finding was rewritten as an emission contract, and the audit-requirements block now states plainly that this model holds no trail and asserts nothing about ordering, immutability or retention.", "Tested whether the model was quietly owning privacy thresholds: no floor, k value, epsilon or budget is defined locally, and the no-local-floors policy makes an unresolvable floor reference render the shape unfit rather than triggering a local default.", "Searched for counterexamples to the premise that a shape is a field subset. Three were found and modelled as distinct findings: record-set scope (which rows leave, not which columns), residual side channels (existence, cardinality, ordering, error behaviour), and cross-release linkability (disclosure arising from the set of shapes rather than any one shape).", "Checked whether ODRL alone could carry this model, which would make it redundant. The published vocabulary RDF confirms its actions carry no technique or selection parameters, so the model is justified - but this is recorded as an alignment conflict rather than a claim of superiority.", "Checked the identifiability-role finding against WM-XCT-020's scope and constrained it to review annotation, with an explicit question about deliberately unassigned elements so the local roles can never be mistaken for a governed classification.", "Did any finding reproduce WM-KNW-012 identity/authority/lifecycle/conflict, WM-XCT-001 ownership, WM-XCT-002 consent, WM-XCT-004 audit trail, WM-XCT-005 threshold math, WM-XCT-020 label assignment, WM-DAT-004 source semantics, or WM-XCT-038 evaluation/enforcement? Reviewed: those appear only as refs or out_of_scope.", "Would a public-release statistical table, a GraphQL allowlist, and a HIPAA limited data set all instantiate this mixin without stretching grain_class? Yes: aggregate_only, subset, and subset+treatment_pack respectively.", "Can a malicious client over-fetch by omitting fields[TYPE] (JSON:API MAY then send all, some, or none) or by relying on OData additional properties? Intersection_rule and default_treatment exist to close that; implementations that set default_treatment=pass_through fail the integrity_rule.", "If a field is reclassified more sensitive (XCT-020) after compile, does the model notice? Yes via invalidation_refs on the compiled template; the classification change itself is not local.", "Does fingerprinting the template without instance data still allow a recipient to infer omitted sensitive path names from omitted_path_count or catalogue cards? Residual metadata leakage is an acknowledged gap, not claimed solved." ] }, "researchAdjudication": { "boundaryDecision": { "entry_kind": "mixin", "status": "accepted", "rationale": "Both providers independently reached entry_kind=mixin over the same registry id, specialising the governed policy WM-KNW-012 with output-shape semantics only. The Claude scope statement is the cleaner boundary: it is storage- and interface-neutral, enumerates nine neighbour distinctions with source refs, and explicitly disclaims policy lifecycle, ownership, consent, audit trail, threshold/budget computation, classification scheme, source-schema semantics and all runtime evaluation, decision and enforcement. It also holds no instance data, which keeps the mixin usable across grain classes. The boundary is therefore accepted unchanged, and the one substantive scope divergence (Grok excludes record/row filtering predicates, Claude owns record-set scope declaratively) is resolved in favour of the base because a shape that never says which records leave cannot express aggregate-only or membership-disclosure cases." }, "decisions": [ { "concept": "Base provider selection", "disposition": "base = claude", "rationale": "Claude carries the more complete boundary apparatus: nine sourced neighbour distinctions, an out_of_scope list that names the owning model for every excluded concern, explicit format-neutrality, and adversarial checks that record what was removed from the previous version and why. Grok leaves two boundary notes marked unresolved and anchors much of its structure in four wire protocols. Size was not decisive; boundary clarity was." }, { "concept": "Entry kind and aggregate root", "disposition": "accepted as mixin over WM-KNW-012", "rationale": "Both providers converge on mixin with identical registry id and both delegate policy identity, authority, approval and supersession to WM-KNW-012. No reclassification or split is warranted, and fixing this before node acceptance is what allows lifecycle-flavoured Grok nodes to be judged consistently." }, { "concept": "Record-set scope ownership", "disposition": "retained in base; Grok exclusion overruled", "rationale": "Grok places row/record filtering predicates out of scope while the base owns the declarative record predicate and membership-disclosure question. A shape that cannot say which records leave cannot express aggregate-only grain or set-membership sensitivity, so the base position is kept and this divergence is resolved by base choice rather than recorded as a conflict." }, { "concept": "Leaving-shape grain class vocabulary", "disposition": "accepted into record-scope-and-grain", "rationale": "Materially missing discriminator between subset, named summary and aggregate-only grain; evidence-backed in ISO/IEC 20889, NIST SP 800-188 and FHIR summary modes, framed as alignment not conformance, and non-duplicative of the base's aggregation and record-scope findings." }, { "concept": "Graph extent and nested-shape policy", "disposition": "accepted into element-selection", "rationale": "The base has no expansion depth, navigation-path allowance or nested-policy inheritance rule, so shapes over graph-shaped sources are unexpressible. The added questions are semantic; the protocol citations are addressing analogues and do not make a format the definition of the shape." }, { "concept": "Client-requested fieldset intersection rule", "disposition": "deferred", "rationale": "Framed around what is served when a concrete client asks for less or more than the maximum, which sits on the WM-XCT-038 side of the base's administration-versus-runtime boundary, and its narrowing semantics partly restate the base's subsumption and meet operations. Accepting it verbatim would import a serving decision into a model that owns no decisions." }, { "concept": "HIPAA Safe Harbor and limited-data-set treatment packs", "disposition": "rejected; pack concept deferred for re-authoring", "rationale": "The description restates regulatory content (18 identifier classes, 164.514(e)(2) residual retention) which the base's regime-mandated-shapes finding forbids by design, and its expert-determination and attestation questions duplicate assurance-method-and-evidence. The underlying idea of a reusable named pack of per-path rules is worth re-authoring later as a pack reference without restated law." }, { "concept": "Shape fingerprint and SUBSETTED marking", "disposition": "rejected as duplicative; completeness-token concept deferred", "rationale": "Two of its three questions restate the base's template digest question and the served-output emission contract, so copying it verbatim would create a second fingerprint node and a competing audit-field contract. The genuinely novel part, marking a served payload incomplete so it cannot overwrite a complete record, is recorded as deferred research instead." }, { "concept": "Dry-run compile and invalidation triggers", "disposition": "rejected as duplicative", "rationale": "Covered by the base's preview-shape-against-schema function, source-schema-binding-and-drift finding and shape-invalidation-signals finding, each of which already names the invalidating references and the safe interim behaviour." }, { "concept": "Binding precedence and specificity hint", "disposition": "rejected", "rationale": "The base explicitly removed precedence between competing bindings as generic conflict handling owned by WM-KNW-012, keeping only the shape-merge operation with a question that forces merging and prevailing to be distinguished. Re-admitting a precedence integer would reopen exactly that boundary; the effective-window content is already carried by binding-target-and-audience." }, { "concept": "Attachment target and aggregate rollup dimensions", "disposition": "rejected as duplicative", "rationale": "Grok's binding-target-attach maps onto the base's binding-target-and-audience, and its rollup dimensions, measures, period and floor reference map onto aggregation-grain-declaration question for question; adding either would produce two homes for the same declarative content." }, { "concept": "Enumerate omitted paths function", "disposition": "rejected as duplicative", "rationale": "The base's preview-shape-against-schema already returns a template plus an omitted-element report for a prospective recipient, and publish-policy-catalogue-projection covers the catalogue-card use, so a separate diff function adds no capability." }, { "concept": "Cohort floor reference check", "disposition": "accepted as function require-cohort-floor-reference", "rationale": "Design-time validation that an aggregate-only shape carries a resolvable WM-XCT-005 floor reference, explicitly computing no k and no epsilon, which operationalises the base's no-local-floors policy and pairs with the accepted grain-class finding." }, { "concept": "Protocol-specific vocabulary from OData, GraphQL, FHIR and JSON:API", "disposition": "admitted only as alignment evidence inside the two accepted findings", "rationale": "The base treats encodings as projections of one semantic shape and keeps external mappings in the policy-expression crosswalk with mapping strength and withheld conformance claims. Further protocol detail belongs in that crosswalk, not as new structure, so the base stays interface-neutral while the accepted findings retain their citations." } ], "publicationHolds": [ "Source verification hold: re-check live URLs, version pins and current status for all 14 base sources and the Grok sources backing the accepted additions before publication. ISO/IEC 20889 and 27559 are paywalled and were not read in full, the JSON Schema 2020-12 core document is an expired Internet-Draft, DPV 2.1 is Community Group output, and the XACML Multiple Decision Profile is a committee draft; each must be re-tiered or replaced if it has moved.", "Multi-profile validation hold: the merged structure has not been exercised against one instance per accepted grain class (record-level subset, named summary, aggregate-only) nor against a non-JSON medium such as a tabular extract, an RDF graph or free text. Until that is done, the selection and graph-extent findings are asserted to generalise, not shown to.", "Jurisdictional profile hold: only US federal and EEA sources were gathered. Regime-mandated-shapes, the identifiability roles and the assurance-method claims must be published as US/EEA-evidenced only, with no implied applicability to APPI, LGPD, DPDP, PIPL or UK DPA regimes.", "Ownership gap hold: record-level expert-determination evidence has no named owning model. WM-XCT-005 is scoped to cohort floors and aggregation assurance, so a non-aggregate shape's assurance evidence currently has no home; publish only with this stated as unresolved or after an owner is assigned.", "Cross-model retention hold: legal-hold precedence across WM-XCT-004 audit-entry disposition, WM-DAT-004 and Dimension source-data erasure, and WM-KNW-012 destruction of the policy record is unrecorded, so a hold in one owner may strand a tombstone in another. Publish only with the missing precedence explicit." ], "deferredResearch": [ "Decide whether the client-requested fieldset intersection rule (clip, reject, never expand) is a declarative parameter of this mixin or belongs entirely to WM-XCT-038 runtime evaluation, and only then author a node for it.", "Re-author reusable named identifier treatment packs (Safe Harbor 18, limited data set 16, local packs) as pack references with jurisdiction and expansion semantics, without restating regulatory text inside the model.", "Model completeness marking of a served payload (SUBSETTED-style token) so an incomplete projection cannot be used to overwrite a complete record, and determine whether that marking is a treatment, an encoding property or a downstream integrity contract.", "Model a self-describing context handle that lets a recipient interpret a projected payload without out-of-band rules, and relate it to the existing compiled template fingerprint.", "Resolve whether synthetic microdata generation is a treatment on this model or a sibling generative-privacy model, and whether a differential-privacy query interface is a grain class here with parameters owned by WM-XCT-005.", "Gather primary evidence for non-tree media technique semantics: free-text redaction, image and audio masking, geospatial generalisation, and binary or large-object projection, none of which currently have modelled treatment semantics." ] }, "statistics": { "sources": 22, "bundles": 6, "layers": 14, "findings": 26, "questions": 103, "artifacts": 6, "functions": 10 } }