# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T13:34:38Z", "synthesisSha256": "c4381b81297bb5831bc2350f180d78c6368ad66bf0340d4d53e353fda2711c38", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-004", "registryId": "vr.wm-xct-004", "name": "Access Audit", "version": "0.1.0", "previousVersions": [], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.AUD" ], "tags": [ "access", "audit", "xct.aud" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-004-access-audit/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-004", "model": { "registry_id": "vr.wm-xct-004", "model_id": "WM-XCT-004", "name": "Access Audit", "entry_kind": "mixin", "purpose": "Provide host-attached, integrity-aware evidence of observed access activity and grant changes, with explicit coverage and disclosure limits.", "scope_statement": "A reusable audit mixin for a governed host, defining observation, collection, entry, proof and review semantics. It is not a universal ledger service, an authorization engine or a formal audit engagement. An instance binds to a host and accountable audit namespace; individual audit entries are evidence entities within the capability.", "in_scope": [ "Audit attachment and event capture profile", "Observed reads, disclosures, grant changes, revocations and denied attempts", "Producer assertions, temporal ordering, ingestion quality and correction lineage", "Scoped integrity evidence, authorized review, retention evidence and mapping assurance" ], "out_of_scope": [ "Ownership and identity master registers", "Grant issuance, consent lifecycle, authorization or projection-policy execution", "Breach adjudication, investigation lifecycle or enforcement actions", "Runtime collectors, cryptographic implementations and deletion execution", "Universal legal rights to raw logs, unconditional public proofs or compliance certification" ], "boundary_notes": [ { "neighbor": "WM-XCT-001 Ownership / Stewardship", "distinction": "Resolve host and party relationships externally; stewardship association alone does not authorize a raw-log view.", "source_refs": [ "SRC-001", "SRC-007" ] }, { "neighbor": "WM-XCT-002 Access Contract / Consent", "distinction": "Reference event-time authority and grant changes; do not create, revoke or re-evaluate grants.", "source_refs": [ "SRC-001", "SRC-007" ] }, { "neighbor": "WM-XCT-003 Projection / Disclosure Policy", "distinction": "Incoming candidate REFERENCE requires policy version and output evidence on served projections. This model owns audit evidence; the neighbor owns projection policy and evaluation.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "neighbor": "WM-XCT-013 Registry Pattern", "distinction": "Incoming candidate MIX-IN attaches audit to registration acts and disclosures. Registry entry lifecycle remains external; the audit schema, ordering, integrity and own-record retention evidence stay here.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "neighbor": "WM-XCT-007 Access Breach / Enforcement", "distinction": "Provide qualified observations and integrity concerns; do not infer culpability, declare violations or execute sanctions.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "WM-XCT-035 Retention / Disposition", "distinction": "Reference schedules, holds and execution receipts for audit records; execution and authoritative disposition decisions stay with the adopting records process.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Legacy S4 Access Audit", "distinction": "Reconcile as predecessor input only. Retain evidence separation and logical append-only corrections; reject unconditional raw owner feeds, universal hash chains, ownerless accountability and unsupported conformance labels.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Security and Privacy Controls for Information Systems and Organizations", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf", "version_or_date": "SP 800-53 Revision 5, September 2020, updates December 10, 2020; later Release 5.2.0 noted but not audited", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:53Z", "relevance": "AU-2 through AU-12: selected event coverage, content, time, protection and retention. This pinned PDF is not a claim of the latest control release." }, { "id": "SRC-002", "title": "Guide to Computer Security Log Management", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-92.pdf", "version_or_date": "SP 800-92, September 2006", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:53Z", "relevance": "Sections 2-5 inform collection, operational gaps, preservation and disposal. Historical guidance, not a current technology or legal mandate." }, { "id": "SRC-003", "title": "RFC 5424: The Syslog Protocol", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc5424", "version_or_date": "March 2009", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:53Z", "relevance": "Sections 4, 6-8 support source envelopes, time quality, sequence scope and transport, truncation and hostile-input limits; no reliable-delivery guarantee." }, { "id": "SRC-004", "title": "RFC 5848: Signed Syslog Messages", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc5848", "version_or_date": "May 2010", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:53Z", "relevance": "Sections 1, 4, 7-8 support scoped signatures, sequence checks and missing-message detection; origin authentication does not certify event truth." }, { "id": "SRC-005", "title": "RFC 9162: Certificate Transparency Version 2.0", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9162", "version_or_date": "December 2021; Experimental", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:53Z", "relevance": "Section 2.1 supports an optional Merkle proof pattern, separating membership and append-only consistency. Certificate-specific protocol, not access-log conformance." }, { "id": "SRC-006", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, April 30, 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:53Z", "relevance": "Sections 3.1-3.3 provide entity, activity, agent, delegation and derivation vocabulary for evidence lineage; no authentication or truth guarantee." }, { "id": "SRC-007", "title": "AuditEvent - FHIR v4.0.1", "organization": "Health Level Seven International", "url": "https://hl7.org/fhir/R4/auditevent.html", "version_or_date": "FHIR R4 v4.0.1; AuditEvent Trial Use", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:53Z", "relevance": "Sections 6.4.1-6.4.3 distinguish actors, targets, outcomes and activity/recorded time; multiple observations and restricted raw access. Healthcare example only." }, { "id": "SRC-008", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:53Z", "relevance": "Sections 4-5 support explicit time offsets and timestamp syntax. Syntax does not establish clock accuracy or global causal order." } ], "structure": { "bundles": [ { "id": "attachment", "name": "Attachment and capture governance", "description": "Host identity and the bounded population of observable access activity.", "rationale": "Proposed grouping of related audit concerns; primary sources support the concerns, not a mandatory universal hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ], "layers": [ { "id": "host-binding-layer", "name": "Host and audit namespace", "description": "Attach a reusable audit capability to a host model instance and an accountable audit partition. The host, event occurrence, producer observation, stored entry and proof have distinct identities. A shared collector can serve several hosts without merging their authority boundaries.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "findings": [ { "id": "host-binding", "name": "Host and audit namespace", "description": "Attach a reusable audit capability to a host model instance and an accountable audit partition. The host, event occurrence, producer observation, stored entry and proof have distinct identities. A shared collector can serve several hosts without merging their authority boundaries.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "questions": [ { "id": "host-binding-q1", "text": "Which authoritative host and partition identify this audit attachment?", "kind": "identity", "answer_data": [ "hostRef", "partitionId", "attachmentId" ] }, { "id": "host-binding-q2", "text": "Who is accountable for the audit purpose and who operates the collector?", "kind": "ownership", "answer_data": [ "accountableRole", "operatorRole", "purpose", "separationOfDuties" ] }, { "id": "host-binding-q3", "text": "How are source event IDs and locally allocated entry IDs kept distinct across tenants and collector restarts?", "kind": "constraint", "answer_data": [ "producerNamespace", "sourceEventId", "entryId", "restartEpoch" ] }, { "id": "host-binding-q4", "text": "Which host revision and binding profile apply when the host is renamed, merged or retired?", "kind": "lifecycle", "answer_data": [ "hostRevision", "bindingVersion", "successorRef", "retirementState" ] } ], "data_elements": [ { "id": "host-binding-host-ref", "name": "host-ref", "description": "Reference to the governed host master, not a copy of its lifecycle.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "host-binding-partition-id", "name": "partition-id", "description": "Stable tenant and audit-stream partition identity.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "host-binding-attachment-id", "name": "attachment-id", "description": "Identity of this mixin attachment.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "host-binding-accountable-role", "name": "accountable-role", "description": "Role with policy accountability; no assumption of ownerless evidence.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "host-binding-binding-version", "name": "binding-version", "description": "Pinned mapping from host actions to audit evidence.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "host-binding-artifact", "name": "Audit attachment record", "description": "Versioned evidence for host and audit namespace; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "capture-contract-layer", "name": "Capture scope and completeness limits", "description": "Declare required read, disclosure, grant-change, revocation and denial event classes, producers and observation points in a versioned capture profile. Coverage is a measured claim with exclusions; an empty log does not prove absence of access. Host decisions on behavior during logging failure stay external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "findings": [ { "id": "capture-contract", "name": "Capture scope and completeness limits", "description": "Declare required read, disclosure, grant-change, revocation and denial event classes, producers and observation points in a versioned capture profile. Coverage is a measured claim with exclusions; an empty log does not prove absence of access. Host decisions on behavior during logging failure stay external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "questions": [ { "id": "capture-contract-q1", "text": "Which event classes and observation points must each producer capture under the active policy?", "kind": "requirement", "answer_data": [ "eventClasses", "producerRefs", "observationPoints", "policyVersion" ] }, { "id": "capture-contract-q2", "text": "Which cached, batch, indirect, offline or privileged paths can bypass the current observation points?", "kind": "exception", "answer_data": [ "excludedPaths", "rationale", "coverageGap", "reviewOwner" ] }, { "id": "capture-contract-q3", "text": "What evidence reconciles expected producer observations with received entries for the stated window?", "kind": "measurement", "answer_data": [ "expectedCount", "receivedCount", "window", "denominatorMethod", "unknownCount" ] }, { "id": "capture-contract-q4", "text": "Which externally approved behavior applies if logging is unavailable, and how is that exception recorded?", "kind": "process", "answer_data": [ "failurePolicyRef", "exceptionRecord", "notificationRef", "recoveryCriteria" ] } ], "data_elements": [ { "id": "capture-contract-capture-profile", "name": "capture-profile", "description": "Approved event selection and observation-point contract.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "capture-contract-producer-refs", "name": "producer-refs", "description": "Participating producer masters and their scoped commitments.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "capture-contract-coverage-window", "name": "coverage-window", "description": "Bounded interval and population used for completeness review.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "capture-contract-coverage-status", "name": "coverage-status", "description": "Proposed values: unknown, partial, reconciled-within-profile; never universal complete.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "capture-contract-exclusions", "name": "exclusions", "description": "Unobserved paths with reason and review responsibility.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "capture-contract-artifact", "name": "Capture coverage assessment", "description": "Versioned evidence for capture scope and completeness limits; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "observations", "name": "Access observations", "description": "Action and attribution evidence without taking over authorization.", "rationale": "Proposed grouping of related audit concerns; primary sources support the concerns, not a mandatory universal hierarchy.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ], "layers": [ { "id": "action-observation-layer", "name": "Access action and outcome observation", "description": "Represent what a producer says happened: attempted action, requested targets, observed outcome and stage. Authorization, data delivery and user consumption are separate propositions. An unknown or partial outcome must not be silently converted to success or denial.", "source_refs": [ "SRC-001", "SRC-007" ], "findings": [ { "id": "action-observation", "name": "Access action and outcome observation", "description": "Represent what a producer says happened: attempted action, requested targets, observed outcome and stage. Authorization, data delivery and user consumption are separate propositions. An unknown or partial outcome must not be silently converted to success or denial.", "source_refs": [ "SRC-001", "SRC-007" ], "questions": [ { "id": "action-observation-q1", "text": "Which action and target revisions does this observation describe?", "kind": "event", "answer_data": [ "actionType", "targetRefs", "targetRevisions", "eventCorrelation" ] }, { "id": "action-observation-q2", "text": "Does the outcome describe a request, authorization decision, served response or confirmed receipt?", "kind": "classification", "answer_data": [ "observationStage", "outcomeCode", "outcomeVocabulary", "evidenceRef" ] }, { "id": "action-observation-q3", "text": "How are partial batch success, timeout and cancellation distinguished from explicit refusal?", "kind": "state", "answer_data": [ "itemOutcomes", "failureClass", "unknownReason", "batchRef" ] }, { "id": "action-observation-q4", "text": "Which sanitized reason and evidence support a denial without exposing protected target existence?", "kind": "security", "answer_data": [ "reasonCode", "restrictedDetailRef", "disclosureClass", "decisionEvidence" ] } ], "data_elements": [ { "id": "action-observation-source-event-id", "name": "source-event-id", "description": "Producer event identity when available; absence is explicit.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "action-observation-action-type", "name": "action-type", "description": "Profile-pinned action vocabulary including reads and grant changes.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "action-observation-target-refs", "name": "target-refs", "description": "Scoped target identifiers and optional immutable revision references.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "action-observation-observation-stage", "name": "observation-stage", "description": "Request, decision, response or receipt stage, separately coded.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "action-observation-outcome", "name": "outcome", "description": "Success, refusal, partial, failure or unknown under the chosen vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] } ], "artifacts": [ { "id": "action-observation-artifact", "name": "Access observation", "description": "Versioned evidence for access action and outcome observation; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "actor-authority-layer", "name": "Actor attribution and authority evidence", "description": "Keep the reporting producer, authenticated principal, acting agent and represented party distinct. Preserve asserted identity, assurance and delegation references at event time. A grant reference is optional for denied or unauthenticated attempts and is evidence, not a new grant or a retrospective policy evaluation.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ], "findings": [ { "id": "actor-authority", "name": "Actor attribution and authority evidence", "description": "Keep the reporting producer, authenticated principal, acting agent and represented party distinct. Preserve asserted identity, assurance and delegation references at event time. A grant reference is optional for denied or unauthenticated attempts and is evidence, not a new grant or a retrospective policy evaluation.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ], "questions": [ { "id": "actor-authority-q1", "text": "Which principal, agent and represented party are asserted for the action, and by which producer?", "kind": "provenance", "answer_data": [ "producerRef", "principalRef", "agentRef", "representedPartyRef", "assertionStatus" ] }, { "id": "actor-authority-q2", "text": "What event-time authentication and delegation evidence supports attribution without storing credentials?", "kind": "evidence", "answer_data": [ "authenticationEvidenceRef", "delegationRef", "assurance", "unknownReason" ] }, { "id": "actor-authority-q3", "text": "Which authority, contract and evaluated policy revisions were reported at the decision point?", "kind": "authority", "answer_data": [ "authorityBasisRef", "contractRevision", "policyRevision", "decisionRef" ] }, { "id": "actor-authority-q4", "text": "How is later identity resolution linked when an actor was anonymous or misattributed at capture time?", "kind": "lifecycle", "answer_data": [ "originalAttribution", "correctionRef", "resolutionEvidence", "resolutionTime" ] } ], "data_elements": [ { "id": "actor-authority-producer-ref", "name": "producer-ref", "description": "Reporting source master identity.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "actor-authority-principal-ref", "name": "principal-ref", "description": "Asserted authenticated principal, if known.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "actor-authority-attribution-status", "name": "attribution-status", "description": "Asserted, corroborated, disputed or unknown under profile rules.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "actor-authority-delegation-ref", "name": "delegation-ref", "description": "External delegation evidence at the relevant time.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "actor-authority-decision-ref", "name": "decision-ref", "description": "External access decision and referenced policy or grant revision.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "actor-authority-artifact", "name": "Attribution evidence record", "description": "Versioned evidence for actor attribution and authority evidence; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "collection", "name": "Collection and time", "description": "Receipt quality, scoped ordering and known coverage gaps.", "rationale": "Proposed grouping of related audit concerns; primary sources support the concerns, not a mandatory universal hierarchy.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007", "SRC-008" ], "layers": [ { "id": "time-order-layer", "name": "Event time and scoped ordering", "description": "Separate occurrence time, producer recording time and collector ingestion time. Record uncertainty, clock source and sequence epoch; arrival order is not global causality. Missing time remains unknown, and ingest time is not substituted as a fabricated occurrence time.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008" ], "findings": [ { "id": "time-order", "name": "Event time and scoped ordering", "description": "Separate occurrence time, producer recording time and collector ingestion time. Record uncertainty, clock source and sequence epoch; arrival order is not global causality. Missing time remains unknown, and ingest time is not substituted as a fabricated occurrence time.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008" ], "questions": [ { "id": "time-order-q1", "text": "What occurrence interval, recording time and ingestion time are known for this observation?", "kind": "temporal", "answer_data": [ "eventInterval", "recordedAt", "ingestedAt", "unknownTimes" ] }, { "id": "time-order-q2", "text": "Which clock basis, offset, precision and error bound qualify each reported time?", "kind": "quality", "answer_data": [ "clockSource", "offset", "precision", "uncertainty", "synchronizationState" ] }, { "id": "time-order-q3", "text": "Within which producer epoch or log partition is the sequence position meaningful?", "kind": "identity", "answer_data": [ "producerEpoch", "partitionId", "sequence", "orderingRule" ] }, { "id": "time-order-q4", "text": "How are late arrivals and conflicting clocks displayed without rewriting original evidence?", "kind": "process", "answer_data": [ "lateArrivalFlag", "presentationOrder", "originalTimes", "correlationEvidence" ] } ], "data_elements": [ { "id": "time-order-event-time", "name": "event-time", "description": "Observed occurrence instant; an interval may be carried in a profile extension.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008" ] }, { "id": "time-order-recorded-at", "name": "recorded-at", "description": "Producer recording time, distinct from event time.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008" ] }, { "id": "time-order-ingested-at", "name": "ingested-at", "description": "Collector observation time using the local timestamp contract.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008" ] }, { "id": "time-order-clock-quality", "name": "clock-quality", "description": "Offset, uncertainty, granularity and source with explicit unknowns.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008" ] }, { "id": "time-order-sequence-context", "name": "sequence-context", "description": "Position, partition and epoch; no cross-partition total order implied.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "time-order-artifact", "name": "Temporal correlation record", "description": "Versioned evidence for event time and scoped ordering; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "ingestion-quality-layer", "name": "Receipt, replay and gap evidence", "description": "Track reception, validation, durable acceptance and rejection as separate states. Detect suspected duplicates using producer namespace and evidence, preserving independent observations of one event. Missing sequence positions, truncation and storage failures create coverage qualifications rather than invented replacement events.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007" ], "findings": [ { "id": "ingestion-quality", "name": "Receipt, replay and gap evidence", "description": "Track reception, validation, durable acceptance and rejection as separate states. Detect suspected duplicates using producer namespace and evidence, preserving independent observations of one event. Missing sequence positions, truncation and storage failures create coverage qualifications rather than invented replacement events.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007" ], "questions": [ { "id": "ingestion-quality-q1", "text": "What receipt, validation and durable-acceptance evidence exists for the submitted record?", "kind": "state", "answer_data": [ "receiptId", "validationState", "durabilityState", "acceptanceEvidence" ] }, { "id": "ingestion-quality-q2", "text": "Does a repeated identifier indicate transport replay, an independent observer or conflicting source content?", "kind": "validation", "answer_data": [ "deduplicationKey", "observerRef", "payloadComparison", "conflictRef" ] }, { "id": "ingestion-quality-q3", "text": "Which intervals or partitions have gaps, truncation, backpressure or recovery uncertainty?", "kind": "measurement", "answer_data": [ "gapRanges", "truncationFlag", "queueLoss", "recoveryWindow", "uncertainty" ] }, { "id": "ingestion-quality-q4", "text": "How are hostile or malformed submissions quarantined without executing embedded content or silently dropping evidence?", "kind": "security", "answer_data": [ "validationFailure", "quarantineRef", "sanitizedMetadata", "handlingPolicy" ] } ], "data_elements": [ { "id": "ingestion-quality-receipt-id", "name": "receipt-id", "description": "Local receipt identity separate from event and entry identity.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007" ] }, { "id": "ingestion-quality-durability-state", "name": "durability-state", "description": "Pending, accepted, rejected or unknown; transport receipt alone is insufficient.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007" ] }, { "id": "ingestion-quality-duplicate-relation", "name": "duplicate-relation", "description": "Candidate relationship, preserving observer and payload distinctions.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007" ] }, { "id": "ingestion-quality-gap-ranges", "name": "gap-ranges", "description": "Scoped known or suspected missing ranges and their evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007" ] }, { "id": "ingestion-quality-validation-report", "name": "validation-report", "description": "Schema, encoding, size and hostile-input assessment.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007" ] } ], "artifacts": [ { "id": "ingestion-quality-artifact", "name": "Ingestion assessment", "description": "Versioned evidence for receipt, replay and gap evidence; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "continuity", "name": "Record continuity and integrity", "description": "Accepted-entry lineage and qualified verification claims.", "rationale": "Proposed grouping of related audit concerns; primary sources support the concerns, not a mandatory universal hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "entry-continuity-layer", "name": "Sealed entries and correction lineage", "description": "Distinguish draft receipt from an accepted sealed entry. This proposed profile uses append-only logical correction: accepted content is not silently overwritten. Corrections, disputes and supersession link original evidence while retained; lawful disposal follows a separately authorized process and must expose loss of verification capability.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ], "findings": [ { "id": "entry-continuity", "name": "Sealed entries and correction lineage", "description": "Distinguish draft receipt from an accepted sealed entry. This proposed profile uses append-only logical correction: accepted content is not silently overwritten. Corrections, disputes and supersession link original evidence while retained; lawful disposal follows a separately authorized process and must expose loss of verification capability.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ], "questions": [ { "id": "entry-continuity-q1", "text": "Which observations and canonical byte representation were committed in this entry revision?", "kind": "composition", "answer_data": [ "entryId", "observationRefs", "representationVersion", "digestAlgorithm", "digest" ] }, { "id": "entry-continuity-q2", "text": "Who accepted or sealed the entry and under which atomicity and concurrency conditions?", "kind": "authority", "answer_data": [ "acceptorRole", "acceptanceTime", "expectedRevision", "storageReceipt" ] }, { "id": "entry-continuity-q3", "text": "Which later correction or dispute qualifies the original assertion without silently replacing it?", "kind": "provenance", "answer_data": [ "correctionRef", "originalEntryRef", "reason", "assertor", "evidence" ] }, { "id": "entry-continuity-q4", "text": "What remains resolvable after redaction, retention expiry or host retirement?", "kind": "retention", "answer_data": [ "retainedReferences", "disposalEvidence", "verificationLimit", "hostSuccessorRef" ] } ], "data_elements": [ { "id": "entry-continuity-entry-id", "name": "entry-id", "description": "Authoritative audit record identity, independent of content digest.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] }, { "id": "entry-continuity-entry-state", "name": "entry-state", "description": "Accepted, sealed, disputed, superseded or disposed under the profile.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] }, { "id": "entry-continuity-observation-refs", "name": "observation-refs", "description": "The evidence items wrapped by the entry.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] }, { "id": "entry-continuity-representation-version", "name": "representation-version", "description": "Canonical serialization profile for any digest or signature.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] }, { "id": "entry-continuity-correction-refs", "name": "correction-refs", "description": "Append-only links, not rewritten historical assertions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "entry-continuity-artifact", "name": "Sealed entry manifest", "description": "Versioned evidence for sealed entries and correction lineage; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "integrity-assessment-layer", "name": "Integrity proof and trust limits", "description": "Select a protection profile appropriate to the threat model. Signed messages, protected storage and Merkle commitments are alternatives or complements, not universal mandatory machinery. A proof of membership is distinct from consistency and neither proves every real access was captured or that the recorded assertion is true.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "findings": [ { "id": "integrity-assessment", "name": "Integrity proof and trust limits", "description": "Select a protection profile appropriate to the threat model. Signed messages, protected storage and Merkle commitments are alternatives or complements, not universal mandatory machinery. A proof of membership is distinct from consistency and neither proves every real access was captured or that the recorded assertion is true.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "integrity-assessment-q1", "text": "Which integrity mechanism, canonicalization and trust anchors protect the specified entry range?", "kind": "security", "answer_data": [ "mechanismProfile", "representationVersion", "range", "trustAnchorRef", "keyVersion" ] }, { "id": "integrity-assessment-q2", "text": "Does the evidence test membership, append-only consistency, signature origin or storage integrity?", "kind": "classification", "answer_data": [ "claimType", "proofRef", "checkpointRefs", "verifierVersion" ] }, { "id": "integrity-assessment-q3", "text": "What verification result follows when keys, checkpoints or algorithm support are unavailable or compromised?", "kind": "validation", "answer_data": [ "result", "failureReason", "trustStatus", "verificationTime", "algorithmStatus" ] }, { "id": "integrity-assessment-q4", "text": "Which privacy and comparison controls govern checkpoint distribution and detection of inconsistent log views?", "kind": "privacy", "answer_data": [ "distributionPolicy", "comparisonEvidence", "metadataExposure", "visibilityLimit" ] } ], "data_elements": [ { "id": "integrity-assessment-protection-profile", "name": "protection-profile", "description": "Selected integrity threat model and implementation profile.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "integrity-assessment-proof-claim", "name": "proof-claim", "description": "Specific claim tested; no generic proof-of-truth value.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "integrity-assessment-checkpoint-refs", "name": "checkpoint-refs", "description": "Bounded log identity, range, root and signature evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "integrity-assessment-verification-result", "name": "verification-result", "description": "Pass, fail, indeterminate or not-applicable, with scoped meaning.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "integrity-assessment-verification-context", "name": "verification-context", "description": "Tool version, trust and algorithm state, time and coverage.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "integrity-assessment-artifact", "name": "Integrity assessment report", "description": "Versioned evidence for integrity proof and trust limits; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "review", "name": "Disclosure and authorized review", "description": "Served-output evidence and recipient-specific audit views.", "rationale": "Proposed grouping of related audit concerns; primary sources support the concerns, not a mandatory universal hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ], "layers": [ { "id": "disclosure-lineage-layer", "name": "Served projection evidence", "description": "Bind a reported disclosure to the external projection policy version, view or template version and a protected fingerprint of the actual served output when available. A template fingerprint alone cannot identify actual content. Auditing records the producer assertion and does not execute disclosure policy or infer receipt from authorization.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ], "findings": [ { "id": "disclosure-lineage", "name": "Served projection evidence", "description": "Bind a reported disclosure to the external projection policy version, view or template version and a protected fingerprint of the actual served output when available. A template fingerprint alone cannot identify actual content. Auditing records the producer assertion and does not execute disclosure policy or infer receipt from authorization.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ], "questions": [ { "id": "disclosure-lineage-q1", "text": "Which policy revision and view or template shaped the response reported by the producer?", "kind": "relationship", "answer_data": [ "projectionPolicyRef", "policyRevision", "viewRef", "templateRevision" ] }, { "id": "disclosure-lineage-q2", "text": "What target revisions, field scope and output evidence identify what was actually served?", "kind": "evidence", "answer_data": [ "targetRevisions", "servedScope", "outputFingerprint", "representationVersion", "evidenceStatus" ] }, { "id": "disclosure-lineage-q3", "text": "How are denied, partially redacted and abandoned responses represented without claiming a completed disclosure?", "kind": "state", "answer_data": [ "responseStage", "withheldScope", "outcome", "unknownDelivery" ] }, { "id": "disclosure-lineage-q4", "text": "Which controls prevent stored output fingerprints or field names from revealing sensitive content?", "kind": "privacy", "answer_data": [ "fingerprintPolicy", "fieldNameProtection", "linkabilityReview", "restrictedEvidenceRef" ] } ], "data_elements": [ { "id": "disclosure-lineage-policy-revision-ref", "name": "policy-revision-ref", "description": "External projection policy version reported for this response.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "disclosure-lineage-view-revision-ref", "name": "view-revision-ref", "description": "Template or view identity; not a content fingerprint.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "disclosure-lineage-served-scope", "name": "served-scope", "description": "Minimized description of served and withheld field scopes.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "disclosure-lineage-output-fingerprint", "name": "output-fingerprint", "description": "Algorithm, representation and protected value for actual output, if available.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "disclosure-lineage-delivery-evidence", "name": "delivery-evidence", "description": "Separate receipt evidence; absence does not imply delivery failure or success.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "disclosure-lineage-artifact", "name": "Disclosure audit evidence", "description": "Versioned evidence for served projection evidence; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "authorized-review-layer", "name": "Authorized timelines and review extracts", "description": "Build authorized views over retained evidence, with restrictions protecting other parties and investigations. Subject or owner association does not automatically confer raw-log access. Extracts preserve query scope, omissions and evidence lineage; aggregation or removal of direct identifiers alone is not proof of anonymity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "findings": [ { "id": "authorized-review", "name": "Authorized timelines and review extracts", "description": "Build authorized views over retained evidence, with restrictions protecting other parties and investigations. Subject or owner association does not automatically confer raw-log access. Extracts preserve query scope, omissions and evidence lineage; aggregation or removal of direct identifiers alone is not proof of anonymity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "questions": [ { "id": "authorized-review-q1", "text": "What current authority and purpose allow this requester to inspect the selected audit scope?", "kind": "access", "answer_data": [ "requesterRef", "authorityDecisionRef", "purpose", "scope", "expiry" ] }, { "id": "authorized-review-q2", "text": "Which third-party, security or investigation details require withholding, delay or an explanation?", "kind": "exception", "answer_data": [ "restrictionBasis", "redactedFields", "withholdingReason", "reviewRoute" ] }, { "id": "authorized-review-q3", "text": "What query window, filters, truncation and known capture gaps qualify the resulting timeline?", "kind": "quality", "answer_data": [ "queryManifest", "window", "filters", "resultLimits", "coverageStatus" ] }, { "id": "authorized-review-q4", "text": "How are export recipients, derivation and reads of the audit view themselves recorded without an infinite logging loop?", "kind": "process", "answer_data": [ "recipientRefs", "extractId", "auditOfAuditRef", "recursionBoundary", "deliveryEvidence" ] } ], "data_elements": [ { "id": "authorized-review-review-request", "name": "review-request", "description": "Authorized request with purpose and bounded scope.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "authorized-review-authorization-ref", "name": "authorization-ref", "description": "Current external authorization, including subject access routes when applicable.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "authorized-review-query-manifest", "name": "query-manifest", "description": "Filters, window, versions, limits and capture qualifiers.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "authorized-review-restriction-records", "name": "restriction-records", "description": "Lawful or policy restrictions, with access-controlled reasons.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "authorized-review-extract-id", "name": "extract-id", "description": "Distinct derived artifact identity with recipient and provenance.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "authorized-review-artifact", "name": "Authorized audit extract", "description": "Versioned evidence for authorized timelines and review extracts; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "stewardship", "name": "Retention and adoption assurance", "description": "Disposition evidence, mappings and bounded investigation handoff.", "rationale": "Proposed grouping of related audit concerns; primary sources support the concerns, not a mandatory universal hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ], "layers": [ { "id": "retention-disposition-layer", "name": "Audit retention and disposition evidence", "description": "Bind audit entries, payloads, proofs, keys, exports and backups to applicable retention schedules and hold decisions. Append-only logical history is not indefinite retention. Disposition execution remains with the governed records process; this model records affected scope, authority, outcome and residual verification limits.", "source_refs": [ "SRC-001", "SRC-002" ], "findings": [ { "id": "retention-disposition", "name": "Audit retention and disposition evidence", "description": "Bind audit entries, payloads, proofs, keys, exports and backups to applicable retention schedules and hold decisions. Append-only logical history is not indefinite retention. Disposition execution remains with the governed records process; this model records affected scope, authority, outcome and residual verification limits.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "retention-disposition-q1", "text": "Which schedule, trigger and policy revision govern each class of audit material?", "kind": "retention", "answer_data": [ "recordClass", "scheduleRef", "trigger", "policyRevision", "dueEvaluationRef" ] }, { "id": "retention-disposition-q2", "text": "What scoped hold or conflicting obligation prevents or limits a planned disposition?", "kind": "constraint", "answer_data": [ "holdRef", "affectedScope", "conflictRef", "decisionAuthority", "reviewDate" ] }, { "id": "retention-disposition-q3", "text": "Which payloads, indexes, replicas, proofs and keys remain after the external disposition process reports completion?", "kind": "evidence", "answer_data": [ "dispositionReceipt", "affectedCopies", "residualCopies", "verificationImpact" ] }, { "id": "retention-disposition-q4", "text": "What lawful minimal tombstone and re-evaluation rule preserve continuity without retaining prohibited personal data?", "kind": "privacy", "answer_data": [ "tombstoneFields", "lawfulBasisRef", "tombstoneExpiry", "reviewRule" ] } ], "data_elements": [ { "id": "retention-disposition-schedule-ref", "name": "schedule-ref", "description": "External retention schedule and applicable revision.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "retention-disposition-hold-refs", "name": "hold-refs", "description": "External scoped holds with authority and duration evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "retention-disposition-disposition-ref", "name": "disposition-ref", "description": "External execution receipt; not an instruction to delete here.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "retention-disposition-residual-status", "name": "residual-status", "description": "Unresolved copies and limits on verification after disposal.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "retention-disposition-tombstone-policy", "name": "tombstone-policy", "description": "Policy authorizing minimized residual evidence and its expiry.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "retention-disposition-artifact", "name": "Audit disposition evidence", "description": "Versioned evidence for audit retention and disposition evidence; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "binding-assurance-layer", "name": "Profile validation and evidence handoff", "description": "A format-neutral model needs tested mappings and profile-specific acceptance rules before deployment. Preserve semantic losses in imports and exports; integrity alerts and suspicious activity are evidence for external investigation, not breach findings or automatic sanctions. Proposed functions below are unimplemented local record operations.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-007" ], "findings": [ { "id": "binding-assurance", "name": "Profile validation and evidence handoff", "description": "A format-neutral model needs tested mappings and profile-specific acceptance rules before deployment. Preserve semantic losses in imports and exports; integrity alerts and suspicious activity are evidence for external investigation, not breach findings or automatic sanctions. Proposed functions below are unimplemented local record operations.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-007" ], "questions": [ { "id": "binding-assurance-q1", "text": "Which schema, vocabulary and transport profile versions are bound to this deployment?", "kind": "interoperability", "answer_data": [ "schemaVersion", "vocabularyPins", "transportProfile", "mappingVersion" ] }, { "id": "binding-assurance-q2", "text": "Which tests demonstrate preservation of unknowns, independent observations, corrections and evidence lineage?", "kind": "validation", "answer_data": [ "testRefs", "inputCases", "expectedSemantics", "observedLosses" ] }, { "id": "binding-assurance-q3", "text": "How is an integrity or coverage concern handed to the responsible investigator without declaring a violation?", "kind": "decision", "answer_data": [ "concernRef", "evidenceScope", "recipientRole", "caseRef", "dispositionStatus" ] }, { "id": "binding-assurance-q4", "text": "What operational location and residency restrictions constrain collection and export without collecting unnecessary geolocation?", "kind": "spatial", "answer_data": [ "systemLocationRef", "residencyPolicy", "transferScope", "minimizationDecision" ] } ], "data_elements": [ { "id": "binding-assurance-profile-version", "name": "profile-version", "description": "Pinned executable binding version, when developed.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "binding-assurance-mapping-report", "name": "mapping-report", "description": "Declared losses and round-trip semantics.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "binding-assurance-conformance-evidence", "name": "conformance-evidence", "description": "Actual test reports, not asserted conformance labels.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "binding-assurance-handoff-ref", "name": "handoff-ref", "description": "External investigation or enforcement case reference.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "binding-assurance-residency-policy", "name": "residency-policy", "description": "Applicable collection and transfer constraints.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "binding-assurance-artifact", "name": "Binding assurance record", "description": "Versioned evidence for profile validation and evidence handoff; separate original observations, asserted values, corrections and unknowns. Access and retention follow the adopting profile.", "media_or_form": [ "Structured record", "Restricted human-readable view" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier, then governed IRI, then Dimension UUID or ULID. Bind the artifact revision to the host and audit partition. A date, sequence position or content hash alone is not global identity.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-observation", "name": "Register an access observation", "description": "Proposed local operation, not implemented. Record a sanitized producer assertion and receipt without granting access.", "inputs": [ "Producer envelope", "Source event identity and evidence", "Capture profile" ], "outputs": [ "Receipt and validation result", "Accepted entry reference or quarantined record", "Refusal or indeterminate result with reason when preconditions fail" ], "preconditions": [ "Authorized role, purpose and scoped host binding", "Expected current record or profile revision; reject stale concurrent mutation", "Producer binding, encoding and size validated", "No credentials or unapproved payload fields", "Duplicate and conflicting-content checks complete" ], "effects": [ "Append a local observation and receipt state", "Do not equate receipt with durable acceptance or authorization" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "link-correction", "name": "Link a correction or dispute", "description": "Proposed local operation, not implemented. Preserve the original while adding a separately attributed qualification.", "inputs": [ "Original entry reference", "Correction evidence", "Reason and assertor" ], "outputs": [ "Correction record and lineage link", "Refusal or indeterminate result with reason when preconditions fail" ], "preconditions": [ "Authorized role, purpose and scoped host binding", "Expected current record or profile revision; reject stale concurrent mutation", "Original identity resolves or unresolved state is explicit", "Correction authority and lawful retention scope established" ], "effects": [ "Append correction; do not silently rewrite the original", "Expose disputed and unknown values in derived views" ], "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "id": "record-verification", "name": "Record integrity verification", "description": "Proposed local operation, not implemented. Store a verifier report with exact scope and trust context; no cryptographic verifier is supplied.", "inputs": [ "Entry range", "Proof and checkpoint references", "External verifier report" ], "outputs": [ "Scoped integrity assessment", "Refusal or indeterminate result with reason when preconditions fail" ], "preconditions": [ "Authorized role, purpose and scoped host binding", "Expected current record or profile revision; reject stale concurrent mutation", "Claim type and verifier version known", "Trust and algorithm status recorded including unknowns" ], "effects": [ "Append pass, fail or indeterminate assessment", "Do not infer truth, full capture or legal admissibility from a pass" ], "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "reconcile-capture", "name": "Record capture reconciliation", "description": "Proposed local operation, not implemented. Compare declared expected observations with locally available evidence for a bounded window.", "inputs": [ "Capture profile", "Expected population evidence", "Received record index" ], "outputs": [ "Coverage assessment and unresolved gaps", "Refusal or indeterminate result with reason when preconditions fail" ], "preconditions": [ "Authorized role, purpose and scoped host binding", "Expected current record or profile revision; reject stale concurrent mutation", "Denominator and observation points declared", "Independent observations not collapsed as transport duplicates" ], "effects": [ "Record coverage limitations and conflict references", "Refer logging-failure behavior to external policy; do not block host actions here" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ] }, { "id": "prepare-audit-view", "name": "Prepare an authorized local audit view", "description": "Proposed local operation, not implemented. Derive a recipient-specific extract using an externally authorized selection; no delivery is performed.", "inputs": [ "Current authorization decision", "Query scope and restrictions", "Retained entry references" ], "outputs": [ "Restricted extract and query manifest", "Refusal or indeterminate result with reason when preconditions fail" ], "preconditions": [ "Authorized role, purpose and scoped host binding", "Expected current record or profile revision; reject stale concurrent mutation", "Recipient scope and restriction decisions validated", "Result limits, capture gaps and privacy risks declared" ], "effects": [ "Create a derived artifact with provenance", "Record audit-of-audit metadata with a bounded recursion policy", "Do not expand access or issue an external transmission" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "record-disposition", "name": "Record external disposition evidence", "description": "Proposed local operation, not implemented. Link an authorized external retention or disposal outcome and its residual verification limits.", "inputs": [ "Schedule and hold decisions", "External execution receipt", "Affected record and copy scope" ], "outputs": [ "Disposition evidence and permitted minimal tombstone", "Refusal or indeterminate result with reason when preconditions fail" ], "preconditions": [ "Authorized role, purpose and scoped host binding", "Expected current record or profile revision; reject stale concurrent mutation", "Disposition authority and scoped holds resolved externally", "Residual-copy and proof impacts stated, including unknowns" ], "effects": [ "Append disposition evidence or permitted minimal status", "Do not execute deletion or retain personal content merely to preserve the log" ], "source_refs": [ "SRC-001", "SRC-002" ] } ], "composition": [ { "target": "WM-XCT-001", "relation": "REFERENCE", "purpose": "Candidate reference to governed host and stewardship masters; access decisions remain explicit.", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "target": "WM-XCT-002", "relation": "REFERENCE", "purpose": "Candidate reference to event-time authority and grant revisions; lifecycle stays external.", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "target": "WM-XCT-003", "relation": "REFERENCE", "purpose": "Candidate reverse evidence reference complementing the incoming ledger edge; attach policy and actual-output evidence without owning evaluation.", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007" ] }, { "target": "WM-XCT-013", "relation": "REFERENCE", "purpose": "Candidate host binding consistent with its incoming MIX-IN edge; do not reverse that edge into containment of registry lifecycle.", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "target": "WM-XCT-007", "relation": "REFERENCE", "purpose": "Candidate evidence handoff to an externally mastered investigation or enforcement case.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-XCT-035", "relation": "REFERENCE", "purpose": "Candidate schedule, hold and disposition-receipt references; no required runtime binding is yet pinned.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "RFC 5424 and RFC 5848", "relation": "ALIGN", "purpose": "Optional transport and signed-message alignment; mappings require testing.", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "target": "RFC 9162", "relation": "ALIGN", "purpose": "Optional experimental certificate-log proof pattern only; no certificate transparency conformance or public-log requirement.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "PROV-O", "relation": "ALIGN", "purpose": "Optional evidence attribution and derivation vocabulary; not verification.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "FHIR R4 AuditEvent", "relation": "ALIGN", "purpose": "Optional healthcare mapping example; no universal healthcare semantics.", "required": false, "source_refs": [ "SRC-007" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Identify an accountable audit policy steward, operator and independent reviewer roles, without company names as owners.", "Declare host binding, tenant namespace, capture coverage, evidence sensitivity and regional applicability.", "Pin authorization, projection, retention, integrity and mapping profiles with their authoritative masters.", "Provide Name, Type, Specification URL, Storage type URL, Interface URL and Processes URL in the owner package." ], "namespace_guidance": "Use a governed namespace under the host Dimension for attachment, partition, observation, entry, correction, proof and extract identities. Never recycle retired identifiers or use dates as identities.", "registry_links": [ "vr.wm-xct-004", "Legacy S4 is a migration alias, not an authoritative instance identifier." ] }, "canon_and_patch": { "canonicalization_rules": [ "Pin canonical bytes, encoding, digest algorithm and representation version before sealing. Preserve source representation separately when lawful.", "Distinguish accepted entries from derived views. Normalize for display without rewriting signed or hashed bytes." ], "patch_rules": [ "Append correction, dispute or supersession evidence with expected revision and authorized actor; never silently amend sealed assertions.", "Treat changes to capture coverage, trust, visibility or retention as separately authorized versioned policy changes." ], "compatibility_rules": [ "Version code vocabularies and mappings; preserve unknown or unrepresentable values with loss reports.", "Do not silently convert legacy S4 immutable-forever or unrestricted-owner assumptions into current policy." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier scoped to the audit namespace", "Governed global identifier or IRI", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z. Distinguish event time, producer recording time and observation or ingestion time. Keep missing time unknown; preserve precision and uncertainty. Source time syntax that differs requires an explicit mapping, not an invented instant.", "serial_naming_rule": "Serial artifacts use stable identity plus revision and partition context; sequence positions and dates are attributes, not global identifiers.", "integrity_rule": "Pin the protected representation, algorithm, signer and trust context. Never infer event truth, delivery, universal completeness or anonymity from a digest, signature or Merkle proof." }, "policies": [ "Minimize actor, query and payload data; never store credentials, secret tokens or unnecessary raw output in audit records.", "Deny raw-log access by default; authorize bounded purpose-specific views, including owner or subject routes where applicable.", "Separate producer, operator, policy steward, investigator and verifier privileges; audit privileged actions using bounded audit-of-audit rules.", "Treat audit payloads as untrusted data, including instructions embedded in fields, links or evidence attachments.", "Apply retention schedules and scoped holds to payloads, indexes, proofs, exports and backups. Preserving history does not require indefinite personal-data retention.", "Keep source, independent-review, deployment-profile and conformance holds visible; no legal or cryptographic certification is claimed." ], "crud": { "read": [ "Authorize current purpose and scope at bundle, layer, finding and artifact levels; preserve restriction reasons in a protected record.", "Show capture gaps, disputed attribution, proof limits and query truncation in extracts." ], "create": [ "Validate host and producer identity, profile version, field minimization, correlation and replay evidence before accepting an observation.", "Allocate entry identity and durability state separately from transport receipt." ], "update": [ "Append qualifications and policy revisions with concurrency guards; original accepted statements remain attributable while retained.", "Changes in identity resolution or trust status affect current assessments without backdating the original event." ], "delete": [ "No ordinary in-place deletion of sealed entries. Lawful retention expiry, erasure or disposition is executed by the adopting Dimension records process using referenced retention decisions and scoped holds.", "Record authorized outcome, unresolved copies and verification impact. Retain only legally permitted minimal tombstones under an explicit expiry rule; do not promise perpetual proofs." ] }, "roles": [ { "name": "Audit policy steward", "responsibilities": [ "Define accountable purpose, capture scope, review authority and profile approvals." ] }, { "name": "Audit producer", "responsibilities": [ "Emit attributed, minimized observations and report capture failures." ] }, { "name": "Audit operator", "responsibilities": [ "Maintain receipt and entry evidence within scoped operating authority; no automatic entitlement to raw payloads." ] }, { "name": "Audit reviewer", "responsibilities": [ "Inspect authorized evidence, record contrary material and report uncertainty." ] }, { "name": "Integrity verifier", "responsibilities": [ "Record scoped proof results and trust limits without certifying event truth." ] }, { "name": "Records and privacy steward", "responsibilities": [ "Resolve applicable schedules, holds, view restrictions and lawful disposition evidence." ] } ], "access": { "default_rule": "Deny by default. A host owner, subject, producer or operator receives only the view authorized by applicable policy and purpose; association alone does not grant raw-log access.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency and investigation access require recorded authority, bounded scope, expiry and retrospective review; this model does not issue permission.", "Subject access and oversight extracts follow qualified legal and policy rules with third-party protections, not an unconditional public feed." ], "audit_requirements": [ "Record reads, exports, policy changes, correction links and integrity checks in a bounded audit-of-audit stream.", "Define recursion termination, failure reporting and reconciliation for the auditing subsystem itself." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Owner and Dimension AGENTS.md with authority and retention policies", "Model AGENTS.md and spec.yaml with all research holds", "Pinned capture, authorization, projection, integrity and storage profiles", "Bounded evidence and current revision before any proposed local operation" ] } }, "coverage": { "claim": "Source-grounded proposed host-attached Access Audit mixin covering bounded capture, attributed observations, collection quality, record continuity, scoped integrity claims, authorized review and disposition evidence. A separate frozen local no-tools self-audit found no critical contradiction. Independent review, source currency, qualified adoption and executable conformance remain holds; no universal completeness or runtime certification is claimed.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Host attachment, producer event, stored entry and proof identities are separate." }, { "dimension": "lifecycle", "status": "covered", "notes": "Receipt, acceptance, sealing, dispute, supersession and authorized disposition evidence." }, { "dimension": "relationships", "status": "covered", "notes": "Two incoming candidate edges reconciled; sibling masters stay external." }, { "dimension": "temporal", "status": "covered", "notes": "Occurrence, recording, ingestion, uncertainty and epoch-scoped order." }, { "dimension": "provenance", "status": "covered", "notes": "Assertions, attribution, delegation, correction and extract lineage." }, { "dimension": "ownership", "status": "covered", "notes": "Accountable role and tenant partition; no ownerless evidence premise." }, { "dimension": "validation", "status": "gap", "notes": "Research schema is testable; nested instance schemas and executable fixtures are not supplied." }, { "dimension": "access", "status": "covered", "notes": "Current authority and protected views at four service scopes." }, { "dimension": "retention and deletion", "status": "covered", "notes": "External schedules and execution with residual proof and copy limits." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual alignments only; bindings and round-trip tests remain." }, { "dimension": "direct properties", "status": "covered", "notes": "Event class, outcome, sensitivity, times and integrity state; physical mass and geometry are inapplicable to the mixin." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Producer and collector observation stages are distinguishable from real-world truth." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Six proposed local operations with authority, concurrency, refusal and effect rules." }, { "dimension": "spatial", "status": "covered", "notes": "Logical system location and residency-policy reference where relevant; unnecessary person geolocation excluded." }, { "dimension": "regional applicability", "status": "gap", "notes": "No jurisdiction-wide legal rights, retention durations or sector conformance established." }, { "dimension": "independent review", "status": "gap", "notes": "Codex only under owner waiver; local audit cannot replace independent review." } ], "known_omissions": [ "Independent external review is absent; Claude and Grok are skipped under the owner waiver.", "Direct HTTP, full version currency and all errata remain unverified. NIST Release 5.2.0 is noted; this research pins the older updated Revision 5 PDF.", "No executable nested instance schema, cryptographic profile, signed-log service, production mapping or performance validation.", "Legal rights to audit data, employee monitoring, cross-border transfers, retention periods and admissibility require qualified jurisdiction and sector review.", "No comprehensive physical-access, disconnected-device or classified-system audit profile.", "Neighbor references are unpinned candidates; no runtime composition certification." ], "conflicts": [], "regional_assumptions": [ "NIST material is US-origin guidance; adoption outside its original setting is a design choice requiring a local profile.", "FHIR R4 is a healthcare example, not a universal audit mandate.", "RFC 9162 is experimental and certificate-specific; only its proof distinctions inform an optional pattern." ], "adversarial_checks": [ "Challenge a forged actor identity behind a validly signed producer message.", "Challenge a complete Merkle proof over a log that omitted an uninstrumented access path.", "Challenge a cross-tenant query whose owner view leaks another person or protected target.", "Challenge late, duplicate and conflicting observations without collapsing independent witnesses.", "Challenge retention expiry and hold conflicts without preserving personal data indefinitely.", "Challenge recursive logging failure and a checkpoint comparison that leaks sensitive metadata." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "mixin", "status": "accepted", "rationale": "The root is a reusable audit capability bound to a governed host and accountable partition. Individual events, observations, entries and proofs have separate identities within it. This matches the registry mixin classification without treating the root as a global ledger service, a single event or an audit engagement." }, "decisions": [ { "concept": "Host-attached root and audit identity", "disposition": "accepted", "rationale": "Host, attachment, producer event, entry, correction, proof and extract identities are distinguished. Source sequence or hash alone is not promoted to global identity." }, { "concept": "Registry promise of every read and grant", "disposition": "qualified as capture target", "rationale": "The declared capture contract includes read, disclosure, grant-change, revocation and denial classes. Observation points, exclusions and reconciliation prevent an empty or apparently complete log from asserting universal capture." }, { "concept": "Incoming projection reference", "disposition": "accepted with completeness qualification", "rationale": "The model records external policy revision and actual served-output evidence without owning projection evaluation. Optional candidate fields allow non-disclosure or unknown cases; a served record missing the required evidence is incomplete and cannot satisfy the incoming relation merely by existing. Conditional instance validation remains a hold." }, { "concept": "Incoming registry mixin relationship", "disposition": "accepted", "rationale": "Registration acts and disclosures can emit evidence through the host binding. The reverse reference is not inverse containment; registry lifecycle stays external while audit ordering, integrity and own-record retention evidence stay here." }, { "concept": "Authorization, delivery and consumption", "disposition": "separated", "rationale": "Observation stage and outcome questions preserve request, decision, response and receipt distinctions, partial outcomes and unknowns. A grant reference or producer success code cannot alone prove delivery or reading by a person." }, { "concept": "Attribution and event-time authority", "disposition": "accepted as evidence", "rationale": "Producer, principal, acting agent and represented party are distinct assertions with authentication and delegation references. Unknown or corrected attribution is allowed without logging credentials or retroactively issuing authority." }, { "concept": "Temporal order and receipt quality", "disposition": "accepted", "rationale": "Occurrence, recording and ingestion time have separate meanings and uncertainty. Epoch-scoped sequence, replay assessment and gap evidence avoid inventing causal order or collapsing independent observations." }, { "concept": "Legacy permanent immutable log", "disposition": "rejected as universal retention rule", "rationale": "Accepted-entry correction is logically append-only while evidence is lawfully retained. Explicit disposition, scoped holds, residual copies and proof-loss accounting reconcile integrity with qualified records policy." }, { "concept": "Mandatory Merkle chains and public proofs", "disposition": "qualified as optional profile", "rationale": "Protection mechanisms are selected against a threat model. RFC 9162 is experimental and certificate-specific; its inclusion and consistency distinctions do not mandate public anchors or certify truth and capture completeness." }, { "concept": "Unrestricted owner access and ownerless accountability", "disposition": "rejected", "rationale": "The result requires accountable role separation and current purpose-specific access. Owner or subject association does not bypass third-party, investigation or security restrictions, and proof metadata can itself disclose sensitive information." }, { "concept": "Audit review and external enforcement", "disposition": "separated", "rationale": "An integrity concern or suspicious observation becomes qualified evidence for an external case. Neither the questions nor the proposed functions adjudicate breach, culpability or sanctions." }, { "concept": "Proposed local function effects", "disposition": "accepted as unimplemented operations", "rationale": "All six functions have scoped authority, revision guards and refusal or indeterminate results. Verification and disposition functions record external evidence; the review function prepares a local view without granting access or transmitting it." }, { "concept": "Candidate schemas and mapping assurance", "disposition": "deferred for implementation", "rationale": "Fields and object groups expose the design but do not supply conditional schemas, enumerated vocabularies, cryptographic bindings or operational fixtures. Those limits are explicit and prevent conformance or deployment claims." }, { "concept": "Source version and jurisdiction coverage", "disposition": "limited", "rationale": "Eight technical sources from four organizations support selected concerns. The later NIST release, current errata, sector mappings and legal applicability remain unverified. Direct HTTP was not attempted; browser access is not a measured HTTP status or legal review." }, { "concept": "Independent provider review", "disposition": "waived and held", "rationale": "Claude and Grok were skipped with zero attempts under the explicit owner instruction. This frozen Codex self-audit cannot be represented as independent external review or provider agreement." } ], "publicationHolds": [ "Independent external review is absent. Claude and Grok were skipped with zero attempts under the owner-authorized single-provider waiver; the separate frozen local Codex no-tools audit is not a second-provider review.", "Live source and version verification remains incomplete. Direct HTTP requests were not attempted under the owner-reported sandbox block, so no HTTP status was measured. Browser-selected evidence is documented in source-review.md. The NIST PDF is pinned to the 2020 update; newer Release 5.2.0, full errata and current applicability were not audited. The coordinator must run check_sources.py and complete substantive verification.", "Jurisdiction and sector profiles require qualified review of audit access rights, monitoring, lawful basis, third-party restrictions, cross-border handling, retention, erasure and admissibility. No universal legal right, retention duration or compliance certification is established.", "Executable nested schemas, conditional served-disclosure requirements, pinned neighbor bindings, cryptographic trust profiles, loss-aware mappings and adversarial fixtures remain incomplete. No production collector, verifier, authorization engine, deletion process or conformance certification is supplied.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore independent external review before canonical or publishable-draft promotion.", "Verify current source versions and errata, including NIST Release 5.2.0, and assess qualified legal and sector adoption profiles.", "Develop conditional instance schemas and fixtures for unknown targets and times, concurrent acceptance, replay, independent observers, hostile input, logging failure, cross-tenant views and missing served-output evidence.", "Test concrete integrity and retention profiles against inconsistent checkpoints, key compromise, sensitive fingerprints, scoped holds, erased payloads and residual copies without claiming complete event capture." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 12, "questions": 48, "artifacts": 12, "functions": 6 } }