Access Audit
Provide host-attached, integrity-aware evidence of observed access activity and grant changes, with explicit coverage and disclosure limits.
Bundle → Layer → Finding → Questions Filled
6 bundles · 12 layers · 12 findings · 48 questions
Attachment and capture governance Host identity and the bounded population of observable access activity.
Host and audit namespace
Attach a reusable audit capability to a host model instance and an accountable audit partition. The host, event occurrence, producer observation, stored entry and proof have distinct identities. A shared collector can serve several hosts without merging their authority boundaries.
Host and audit namespace
Attach a reusable audit capability to a host model instance and an accountable audit partition. The host, event occurrence, producer observation, stored entry and proof have distinct identities. A shared collector can serve several hosts without merging their authority boundaries.
- Which authoritative host and partition identify this audit attachment? identity
- Who is accountable for the audit purpose and who operates the collector? ownership
- How are source event IDs and locally allocated entry IDs kept distinct across tenants and collector restarts? constraint
- Which host revision and binding profile apply when the host is renamed, merged or retired? lifecycle
Capture scope and completeness limits
Declare required read, disclosure, grant-change, revocation and denial event classes, producers and observation points in a versioned capture profile. Coverage is a measured claim with exclusions; an empty log does not prove absence of access. Host decisions on behavior during logging failure stay external.
Capture scope and completeness limits
Declare required read, disclosure, grant-change, revocation and denial event classes, producers and observation points in a versioned capture profile. Coverage is a measured claim with exclusions; an empty log does not prove absence of access. Host decisions on behavior during logging failure stay external.
- Which event classes and observation points must each producer capture under the active policy? requirement
- Which cached, batch, indirect, offline or privileged paths can bypass the current observation points? exception
- What evidence reconciles expected producer observations with received entries for the stated window? measurement
- Which externally approved behavior applies if logging is unavailable, and how is that exception recorded? process
Access observations Action and attribution evidence without taking over authorization.
Access action and outcome observation
Represent what a producer says happened: attempted action, requested targets, observed outcome and stage. Authorization, data delivery and user consumption are separate propositions. An unknown or partial outcome must not be silently converted to success or denial.
Access action and outcome observation
Represent what a producer says happened: attempted action, requested targets, observed outcome and stage. Authorization, data delivery and user consumption are separate propositions. An unknown or partial outcome must not be silently converted to success or denial.
- Which action and target revisions does this observation describe? event
- Does the outcome describe a request, authorization decision, served response or confirmed receipt? classification
- How are partial batch success, timeout and cancellation distinguished from explicit refusal? state
- Which sanitized reason and evidence support a denial without exposing protected target existence? security
Actor attribution and authority evidence
Keep the reporting producer, authenticated principal, acting agent and represented party distinct. Preserve asserted identity, assurance and delegation references at event time. A grant reference is optional for denied or unauthenticated attempts and is evidence, not a new grant or a retrospective policy evaluation.
Actor attribution and authority evidence
Keep the reporting producer, authenticated principal, acting agent and represented party distinct. Preserve asserted identity, assurance and delegation references at event time. A grant reference is optional for denied or unauthenticated attempts and is evidence, not a new grant or a retrospective policy evaluation.
- Which principal, agent and represented party are asserted for the action, and by which producer? provenance
- What event-time authentication and delegation evidence supports attribution without storing credentials? evidence
- Which authority, contract and evaluated policy revisions were reported at the decision point? authority
- How is later identity resolution linked when an actor was anonymous or misattributed at capture time? lifecycle
Collection and time Receipt quality, scoped ordering and known coverage gaps.
Event time and scoped ordering
Separate occurrence time, producer recording time and collector ingestion time. Record uncertainty, clock source and sequence epoch; arrival order is not global causality. Missing time remains unknown, and ingest time is not substituted as a fabricated occurrence time.
Event time and scoped ordering
Separate occurrence time, producer recording time and collector ingestion time. Record uncertainty, clock source and sequence epoch; arrival order is not global causality. Missing time remains unknown, and ingest time is not substituted as a fabricated occurrence time.
- What occurrence interval, recording time and ingestion time are known for this observation? temporal
- Which clock basis, offset, precision and error bound qualify each reported time? quality
- Within which producer epoch or log partition is the sequence position meaningful? identity
- How are late arrivals and conflicting clocks displayed without rewriting original evidence? process
Receipt, replay and gap evidence
Track reception, validation, durable acceptance and rejection as separate states. Detect suspected duplicates using producer namespace and evidence, preserving independent observations of one event. Missing sequence positions, truncation and storage failures create coverage qualifications rather than invented replacement events.
Receipt, replay and gap evidence
Track reception, validation, durable acceptance and rejection as separate states. Detect suspected duplicates using producer namespace and evidence, preserving independent observations of one event. Missing sequence positions, truncation and storage failures create coverage qualifications rather than invented replacement events.
- What receipt, validation and durable-acceptance evidence exists for the submitted record? state
- Does a repeated identifier indicate transport replay, an independent observer or conflicting source content? validation
- Which intervals or partitions have gaps, truncation, backpressure or recovery uncertainty? measurement
- How are hostile or malformed submissions quarantined without executing embedded content or silently dropping evidence? security
Record continuity and integrity Accepted-entry lineage and qualified verification claims.
Sealed entries and correction lineage
Distinguish draft receipt from an accepted sealed entry. This proposed profile uses append-only logical correction: accepted content is not silently overwritten. Corrections, disputes and supersession link original evidence while retained; lawful disposal follows a separately authorized process and must expose loss of verification capability.
Sealed entries and correction lineage
Distinguish draft receipt from an accepted sealed entry. This proposed profile uses append-only logical correction: accepted content is not silently overwritten. Corrections, disputes and supersession link original evidence while retained; lawful disposal follows a separately authorized process and must expose loss of verification capability.
- Which observations and canonical byte representation were committed in this entry revision? composition
- Who accepted or sealed the entry and under which atomicity and concurrency conditions? authority
- Which later correction or dispute qualifies the original assertion without silently replacing it? provenance
- What remains resolvable after redaction, retention expiry or host retirement? retention
Integrity proof and trust limits
Select a protection profile appropriate to the threat model. Signed messages, protected storage and Merkle commitments are alternatives or complements, not universal mandatory machinery. A proof of membership is distinct from consistency and neither proves every real access was captured or that the recorded assertion is true.
Integrity proof and trust limits
Select a protection profile appropriate to the threat model. Signed messages, protected storage and Merkle commitments are alternatives or complements, not universal mandatory machinery. A proof of membership is distinct from consistency and neither proves every real access was captured or that the recorded assertion is true.
- Which integrity mechanism, canonicalization and trust anchors protect the specified entry range? security
- Does the evidence test membership, append-only consistency, signature origin or storage integrity? classification
- What verification result follows when keys, checkpoints or algorithm support are unavailable or compromised? validation
- Which privacy and comparison controls govern checkpoint distribution and detection of inconsistent log views? privacy
Disclosure and authorized review Served-output evidence and recipient-specific audit views.
Served projection evidence
Bind a reported disclosure to the external projection policy version, view or template version and a protected fingerprint of the actual served output when available. A template fingerprint alone cannot identify actual content. Auditing records the producer assertion and does not execute disclosure policy or infer receipt from authorization.
Served projection evidence
Bind a reported disclosure to the external projection policy version, view or template version and a protected fingerprint of the actual served output when available. A template fingerprint alone cannot identify actual content. Auditing records the producer assertion and does not execute disclosure policy or infer receipt from authorization.
- Which policy revision and view or template shaped the response reported by the producer? relationship
- What target revisions, field scope and output evidence identify what was actually served? evidence
- How are denied, partially redacted and abandoned responses represented without claiming a completed disclosure? state
- Which controls prevent stored output fingerprints or field names from revealing sensitive content? privacy
Authorized timelines and review extracts
Build authorized views over retained evidence, with restrictions protecting other parties and investigations. Subject or owner association does not automatically confer raw-log access. Extracts preserve query scope, omissions and evidence lineage; aggregation or removal of direct identifiers alone is not proof of anonymity.
Authorized timelines and review extracts
Build authorized views over retained evidence, with restrictions protecting other parties and investigations. Subject or owner association does not automatically confer raw-log access. Extracts preserve query scope, omissions and evidence lineage; aggregation or removal of direct identifiers alone is not proof of anonymity.
- What current authority and purpose allow this requester to inspect the selected audit scope? access
- Which third-party, security or investigation details require withholding, delay or an explanation? exception
- What query window, filters, truncation and known capture gaps qualify the resulting timeline? quality
- How are export recipients, derivation and reads of the audit view themselves recorded without an infinite logging loop? process
Retention and adoption assurance Disposition evidence, mappings and bounded investigation handoff.
Audit retention and disposition evidence
Bind audit entries, payloads, proofs, keys, exports and backups to applicable retention schedules and hold decisions. Append-only logical history is not indefinite retention. Disposition execution remains with the governed records process; this model records affected scope, authority, outcome and residual verification limits.
Audit retention and disposition evidence
Bind audit entries, payloads, proofs, keys, exports and backups to applicable retention schedules and hold decisions. Append-only logical history is not indefinite retention. Disposition execution remains with the governed records process; this model records affected scope, authority, outcome and residual verification limits.
- Which schedule, trigger and policy revision govern each class of audit material? retention
- What scoped hold or conflicting obligation prevents or limits a planned disposition? constraint
- Which payloads, indexes, replicas, proofs and keys remain after the external disposition process reports completion? evidence
- What lawful minimal tombstone and re-evaluation rule preserve continuity without retaining prohibited personal data? privacy
Profile validation and evidence handoff
A format-neutral model needs tested mappings and profile-specific acceptance rules before deployment. Preserve semantic losses in imports and exports; integrity alerts and suspicious activity are evidence for external investigation, not breach findings or automatic sanctions. Proposed functions below are unimplemented local record operations.
Profile validation and evidence handoff
A format-neutral model needs tested mappings and profile-specific acceptance rules before deployment. Preserve semantic losses in imports and exports; integrity alerts and suspicious activity are evidence for external investigation, not breach findings or automatic sanctions. Proposed functions below are unimplemented local record operations.
- Which schema, vocabulary and transport profile versions are bound to this deployment? interoperability
- Which tests demonstrate preservation of unknowns, independent observations, corrections and evidence lineage? validation
- How is an integrity or coverage concern handed to the responsible investigator without declaring a violation? decision
- What operational location and residency restrictions constrain collection and export without collecting unnecessary geolocation? spatial
Classifiers Filled
- Family
- World Models
- Category
- Cross-cutting context
- Entry kind
- mixin
- Navigation path
- NAV.XCT.AUD
- Domain
- XCT.AUD
- Industry
- Cross-industry
- Tags
- accessauditxct.aud
- Also called
- S4
What it is Filled
A reusable audit mixin for a governed host, defining observation, collection, entry, proof and review semantics. It is not a universal ledger service, an authorization engine or a formal audit engagement. An instance binds to a host and accountable audit namespace; individual audit entries are evidence entities within the capability.
In scope
- Audit attachment and event capture profile
- Observed reads, disclosures, grant changes, revocations and denied attempts
- Producer assertions, temporal ordering, ingestion quality and correction lineage
- Scoped integrity evidence, authorized review, retention evidence and mapping assurance
Out of scope
- Ownership and identity master registers
- Grant issuance, consent lifecycle, authorization or projection-policy execution
- Breach adjudication, investigation lifecycle or enforcement actions
- Runtime collectors, cryptographic implementations and deletion execution
- Universal legal rights to raw logs, unconditional public proofs or compliance certification
Why it exists Filled
Provide host-attached, integrity-aware evidence of observed access activity and grant changes, with explicit coverage and disclosure limits.
Distinguishing features Derived, awaiting review
- Unlike WM-XCT-001 Ownership / Stewardship: Resolve host and party relationships externally; stewardship association alone does not authorize a raw-log view.
- Unlike WM-XCT-002 Access Contract / Consent: Reference event-time authority and grant changes; do not create, revoke or re-evaluate grants.
- Unlike WM-XCT-003 Projection / Disclosure Policy: Incoming candidate REFERENCE requires policy version and output evidence on served projections. This model owns audit evidence; the neighbor owns projection policy and evaluation.
- Unlike WM-XCT-013 Registry Pattern: Incoming candidate MIX-IN attaches audit to registration acts and disclosures. Registry entry lifecycle remains external; the audit schema, ordering, integrity and own-record retention evidence stay here.
- Unlike WM-XCT-007 Access Breach / Enforcement: Provide qualified observations and integrity concerns; do not infer culpability, declare violations or execute sanctions.
- Unlike WM-XCT-035 Retention / Disposition: Reference schedules, holds and execution receipts for audit records; execution and authoritative disposition decisions stay with the adopting records process.
- Unlike Legacy S4 Access Audit: Reconcile as predecessor input only. Retain evidence separation and logical append-only corrections; reject unconditional raw owner feeds, universal hash chains, ownerless accountability and unsupported conformance labels.
Note: Derived from boundary notes against neighbouring models.
What robots and AI may and may not do Derived, awaiting review
Must not
- Minimize actor, query and payload data; never store credentials, secret tokens or unnecessary raw output in audit records.
- Deny raw-log access by default; authorize bounded purpose-specific views, including owner or subject routes where applicable.
- Deny by default.
May
- Register an access observation: Proposed local operation, not implemented. Record a sanitized producer assertion and receipt without granting access.
- Link a correction or dispute: Proposed local operation, not implemented. Preserve the original while adding a separately attributed qualification.
- Record integrity verification: Proposed local operation, not implemented. Store a verifier report with exact scope and trust context; no cryptographic verifier is supplied.
- Record capture reconciliation: Proposed local operation, not implemented. Compare declared expected observations with locally available evidence for a bounded window.
- Prepare an authorized local audit view: Proposed local operation, not implemented. Derive a recipient-specific extract using an externally authorized selection; no delivery is performed.
- Record external disposition evidence: Proposed local operation, not implemented. Link an authorized external retention or disposal outcome and its residual verification limits.
Note: Derived from functions, policies, CRUD and access rules; prohibitions were not authored for agents as such.
Moral aspects Derived, awaiting review
- Records and privacy steward
- Challenge retention expiry and hold conflicts without preserving personal data indefinitely.
- Grant issuance, consent lifecycle, authorization or projection-policy execution
- WM-XCT-002 Access Contract / Consent
Note: Sentences mentioning harm, privacy, consent or similar, collected from the specification.
Owners Filled
Steward
Identify an accountable audit policy steward, operator and independent reviewer roles, without company names as owners.
Roles
- Audit policy steward
- Define accountable purpose, capture scope, review authority and profile approvals.
- Audit producer
- Emit attributed, minimized observations and report capture failures.
- Audit operator
- Maintain receipt and entry evidence within scoped operating authority; no automatic entitlement to raw payloads.
- Audit reviewer
- Inspect authorized evidence, record contrary material and report uncertainty.
- Integrity verifier
- Record scoped proof results and trust limits without certifying event truth.
- Records and privacy steward
- Resolve applicable schedules, holds, view restrictions and lawful disposition evidence.
Links to other meta-models Filled
references
- WM-XCT-001 - Candidate reference to governed host and stewardship masters; access decisions remain explicit.
- WM-XCT-002 - Candidate reference to event-time authority and grant revisions; lifecycle stays external.
- WM-XCT-003 - Candidate reverse evidence reference complementing the incoming ledger edge; attach policy and actual-output evidence without owning evaluation.
- WM-XCT-013 - Candidate host binding consistent with its incoming MIX-IN edge; do not reverse that edge into containment of registry lifecycle.
- WM-XCT-007 - Candidate evidence handoff to an externally mastered investigation or enforcement case.
- WM-XCT-035 - Candidate schedule, hold and disposition-receipt references; no required runtime binding is yet pinned.
aligned
- RFC 5424 and RFC 5848 - Optional transport and signed-message alignment; mappings require testing.
- RFC 9162 - Optional experimental certificate-log proof pattern only; no certificate transparency conformance or public-log requirement.
- PROV-O - Optional evidence attribution and derivation vocabulary; not verification.
- FHIR R4 AuditEvent - Optional healthcare mapping example; no universal healthcare semantics.
neighbor
- WM-XCT-001 Ownership / Stewardship - Resolve host and party relationships externally; stewardship association alone does not authorize a raw-log view.
- WM-XCT-002 Access Contract / Consent - Reference event-time authority and grant changes; do not create, revoke or re-evaluate grants.
- WM-XCT-003 Projection / Disclosure Policy - Incoming candidate REFERENCE requires policy version and output evidence on served projections. This model owns audit evidence; the neighbor owns projection policy and evaluation.
- WM-XCT-013 Registry Pattern - Incoming candidate MIX-IN attaches audit to registration acts and disclosures. Registry entry lifecycle remains external; the audit schema, ordering, integrity and own-record retention evidence stay here.
- WM-XCT-007 Access Breach / Enforcement - Provide qualified observations and integrity concerns; do not infer culpability, declare violations or execute sanctions.
- WM-XCT-035 Retention / Disposition - Reference schedules, holds and execution receipts for audit records; execution and authoritative disposition decisions stay with the adopting records process.
- Legacy S4 Access Audit - Reconcile as predecessor input only. Retain evidence separation and logical append-only corrections; reject unconditional raw owner feeds, universal hash chains, ownerless accountability and unsupported conformance labels.
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Filled
- Authoritative master-system identifier scoped to the audit namespace
- Governed global identifier or IRI
- UUID or ULID assigned by the adopting Dimension
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Filled
- Register an access observation: Proposed local operation, not implemented. Record a sanitized producer assertion and receipt without granting access.
- Link a correction or dispute: Proposed local operation, not implemented. Preserve the original while adding a separately attributed qualification.
- Record integrity verification: Proposed local operation, not implemented. Store a verifier report with exact scope and trust context; no cryptographic verifier is supplied.
- Record capture reconciliation: Proposed local operation, not implemented. Compare declared expected observations with locally available evidence for a bounded window.
- Prepare an authorized local audit view: Proposed local operation, not implemented. Derive a recipient-specific extract using an externally authorized selection; no delivery is performed.
- Record external disposition evidence: Proposed local operation, not implemented. Link an authorized external retention or disposal outcome and its residual verification limits.
Hazards and failure modes optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Derived, awaiting review
- RFC 5424: The Syslog Protocol
- RFC 5848: Signed Syslog Messages
- RFC 9162: Certificate Transparency Version 2.0
- PROV-O: The PROV Ontology
- AuditEvent - FHIR v4.0.1
- RFC 3339: Date and Time on the Internet: Timestamps
Context of use required Filled
- NIST material is US-origin guidance; adoption outside its original setting is a design choice requiring a local profile.
- FHIR R4 is a healthcare example, not a universal audit mandate.
- RFC 9162 is experimental and certificate-specific; only its proof distinctions inform an optional pattern.
Sources Filled
- Security and Privacy Controls for Information Systems and Organizations - National Institute of Standards and Technology
- Guide to Computer Security Log Management - National Institute of Standards and Technology
- RFC 5424: The Syslog Protocol - Internet Engineering Task Force
- RFC 5848: Signed Syslog Messages - Internet Engineering Task Force
- RFC 9162: Certificate Transparency Version 2.0 - Internet Engineering Task Force
- PROV-O: The PROV Ontology - World Wide Web Consortium
- AuditEvent - FHIR v4.0.1 - Health Level Seven International
- RFC 3339: Date and Time on the Internet: Timestamps - Internet Engineering Task Force
Open questions
- Restore independent external review before canonical or publishable-draft promotion.
- Verify current source versions and errata, including NIST Release 5.2.0, and assess qualified legal and sector adoption profiles.
- Develop conditional instance schemas and fixtures for unknown targets and times, concurrent acceptance, replay, independent observers, hostile input, logging failure, cross-tenant views and missing served-output evidence.
- Test concrete integrity and retention profiles against inconsistent checkpoints, key compromise, sensitive fingerprints, scoped holds, erased payloads and residual copies without claiming complete event capture.
- Independent external review is absent; Claude and Grok are skipped under the owner waiver.
- Direct HTTP, full version currency and all errata remain unverified. NIST Release 5.2.0 is noted; this research pins the older updated Revision 5 PDF.
- No executable nested instance schema, cryptographic profile, signed-log service, production mapping or performance validation.
- Legal rights to audit data, employee monitoring, cross-border transfers, retention periods and admissibility require qualified jurisdiction and sector review.
- No comprehensive physical-access, disconnected-device or classified-system audit profile.
- Neighbor references are unpinned candidates; no runtime composition certification.
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-xct-004-access-audit/spec.yaml