# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T13:32:55Z", "synthesisSha256": "be731523f14dc54233e8923549a8940718f77d8b81d307778a804b37f2e985d0", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-005", "registryId": "vr.wm-xct-005", "name": "Privacy Aggregation Floor", "version": "0.1.0", "previousVersions": [], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.PRV" ], "tags": [ "privacy", "aggregation", "floor", "xct.prv" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-005-privacy-aggregation-floor/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-005", "model": { "registry_id": "vr.wm-xct-005", "model_id": "WM-XCT-005", "name": "Privacy Aggregation Floor", "entry_kind": "mixin", "purpose": "Attach qualified cohort-floor and statistical disclosure assurance to a host aggregate or release candidate.", "scope_statement": "A reusable host-attached capability for defining the protected population unit, applicable aggregation floor, protection evidence and release-assurance result. It owns subject-specific floor evaluation and privacy aggregation assurance. Host dataset, series, access policy, enforcement and audit systems retain their own identities and operations. All local functions below are proposed contracts, not implemented software.", "in_scope": [ "Host and cohort bindings, protected counting units, versioned floor profiles and aggregate lineage", "Suppression and perturbation evidence, optional differential privacy claims and cumulative accounting references", "Joint release review, purpose-specific utility, assurance expiration, revision and restricted evidence projections" ], "out_of_scope": [ "Person registers, source microdata custody, general statistical product or series lifecycle", "General ownership, legal basis, consent, access grants, projection enforcement and audit-log execution", "A universal safe k value, legal anonymity certification, production DP implementation or proof of standards conformance", "Publishing or transmitting source data or aggregates; actual release and disposition execution belong to authorized host systems" ], "boundary_notes": [ { "neighbor": "WM-XCT-003 Projection / Disclosure Policy", "distinction": "The incoming registry REFERENCE leaves threshold calculation and privacy aggregation assurance here. Projection policy selects the audience and representation; this mixin supplies qualified assurance evidence and cannot grant access or execute that policy.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "neighbor": "WM-XCT-001 Ownership / Stewardship and WM-XCT-002 Access Contract / Consent", "distinction": "Reference effective-dated authority and permitted purpose. Neither attaching a floor nor passing it creates ownership, consent or a lawful processing basis.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "neighbor": "WM-XCT-004 Access Audit", "distinction": "Local assurance records link audit receipts. Audit-trail storage, tamper controls and general access-event semantics stay with the audit system.", "source_refs": [ "SRC-001", "SRC-006" ] }, { "neighbor": "Host dataset, aggregate and statistical series", "distinction": "The mixin has an attachment identifier and revisions but no independent population or series master. Authorized internal computation can examine small counts; the outward observable result must follow the selected profile and assurance gate.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "neighbor": "Legacy S5 specification and unreviewed supplement", "distinction": "Retain cohort, floor, computation and review leads. Reject claims that a count floor proves k-anonymity, every noise addition has a DP budget, budgets reset each period, or no internal measure may exist below a floor. No source data ownership transfer or agent publication authority follows from this model.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "De-Identifying Government Datasets: Techniques and Governance", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-188.pdf", "version_or_date": "NIST SP 800-188, September 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:26Z", "relevance": "Selected sections on governance, k-anonymity, tabular disclosure controls and validation; PDF pages 30, 66 and 121. Supports risk review and the distinction between equivalence classes and cohort counts. The hierarchy and local operations are authored proposals, not a NIST schema." }, { "id": "SRC-002", "title": "Guidelines for Evaluating Differential Privacy Guarantees", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-226.pdf", "version_or_date": "NIST SP 800-226, March 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:26Z", "relevance": "Sections 2, 3.4 and 4: privacy unit, parameters, composition, bounds, query models and deployment hazards. Used to constrain optional DP evidence, not to certify any implementation or universal parameter value." }, { "id": "SRC-003", "title": "How do we ensure anonymisation is effective?", "organization": "Information Commissioner's Office", "url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/anonymisation/how-do-we-ensure-anonymisation-is-effective/", "version_or_date": "Official guidance accessed 2026-10-06; page states guidance is under review after the Data (Use and Access) Act", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:26Z", "relevance": "Selected identifiability, singling-out, linkability, inference, audience and reassessment guidance. UK-specific context; no universal legal anonymity determination is imported." }, { "id": "SRC-004", "title": "Protecting personal data in Census 2021 results", "organization": "Office for National Statistics", "url": "https://www.ons.gov.uk/peoplepopulationandcommunity/populationandmigration/populationestimates/methodologies/protectingpersonaldataincensus2021results", "version_or_date": "Last revised 2023-03-09", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:26Z", "relevance": "Sections 1-6 describe Census 2021 disclosure control, perturbation, differencing and sparse tables. This is an application example, not a mandatory international threshold or a DP guarantee." }, { "id": "SRC-005", "title": "Comparison of post-tabular statistical disclosure control methods", "organization": "Office for National Statistics", "url": "https://www.ons.gov.uk/peoplepopulationandcommunity/populationandmigration/populationestimates/methodologies/comparisonofposttabularstatisticaldisclosurecontrolmethods", "version_or_date": "Released 2024-05-03", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:26Z", "relevance": "Sections 5-7 compare thresholds, perturbation and utility. Supports a context-dependent choice; does not justify transplanting the illustrated 10-5 rule to all datasets." }, { "id": "SRC-006", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:26Z", "relevance": "Entity, activity, agent, derivation and revision vocabulary for conceptual provenance alignment. Does not prove authorization, truth or privacy." }, { "id": "SRC-007", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "RFC 3339, July 2002, section 5.6", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:31:26Z", "relevance": "Timestamp syntax for local evidence events. Time format does not define release windows, privacy accounting scope or retention periods." } ], "structure": { "bundles": [ { "id": "b-binding", "name": "Binding and authority", "description": "Which host, purpose and audience the assurance concerns.", "rationale": "Authored grouping of related assurance questions, grounded in the cited concepts; not an external normative schema.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "layers": [ { "id": "l-attachment", "name": "Attachment identity", "description": "Context for attachment identity within the host attachment.", "source_refs": [ "SRC-001", "SRC-006" ], "findings": [ { "id": "f-attachment", "name": "Attachment identity", "description": "Design rule: pin the host revision and attachment separately from cohort, source and release identifiers. An assertion about one release is not transferable to another.", "source_refs": [ "SRC-001", "SRC-006" ], "questions": [ { "id": "f-attachment-q01", "text": "Which host revision and attachment identifier does this assurance describe?", "kind": "identity", "answer_data": [ "host_binding" ] }, { "id": "f-attachment-q02", "text": "Which candidate release, cohort definition and source revisions are linked?", "kind": "relationship", "answer_data": [ "linked_revisions" ] }, { "id": "f-attachment-q03", "text": "When was this attachment effective and when was its evidence observed?", "kind": "temporal", "answer_data": [ "binding_times" ] }, { "id": "f-attachment-q04", "text": "What changed when the host or cohort definition was superseded?", "kind": "lifecycle", "answer_data": [ "supersession" ] } ], "data_elements": [ { "id": "f-attachment-d01", "name": "host_binding", "description": "Host master identifier, attachment master identifier, host revision and namespace. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "f-attachment-d02", "name": "linked_revisions", "description": "Qualified external references with resolution status; unresolved is not equivalent to absent. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "f-attachment-d03", "name": "binding_times", "description": "Effective interval, event time, observation time and source clock uncertainty; date-only periods remain periods. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006" ] }, { "id": "f-attachment-d04", "name": "supersession", "description": "Prior revision, change reason, invalidated assurance references and reassessment state. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006" ] } ], "artifacts": [ { "id": "f-attachment-artifact", "name": "Attachment binding record", "description": "Versioned assurance evidence for attachment identity. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "l-authority", "name": "Purpose and audience", "description": "Context for purpose and audience within the host attachment.", "source_refs": [ "SRC-001", "SRC-003" ], "findings": [ { "id": "f-authority", "name": "Purpose and audience", "description": "Design rule: evaluate only within the host-authorized processing context. Assurance is evidence for the release authority and never an access grant.", "source_refs": [ "SRC-001", "SRC-003" ], "questions": [ { "id": "f-authority-q01", "text": "Which authority permits computation for the stated purpose and audience?", "kind": "authority", "answer_data": [ "authority_binding" ] }, { "id": "f-authority-q02", "text": "Which role maintains the floor profile and which role approves release assurance?", "kind": "ownership", "answer_data": [ "role_assignments" ] }, { "id": "f-authority-q03", "text": "What protected details may each reviewer or recipient inspect?", "kind": "access", "answer_data": [ "evidence_views" ] }, { "id": "f-authority-q04", "text": "How is an unsupported purpose or exception request handled?", "kind": "exception", "answer_data": [ "exception_request" ] } ], "data_elements": [ { "id": "f-authority-d01", "name": "authority_binding", "description": "External authority and access-contract references, permitted operations, purpose, validity and unknown status. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "f-authority-d02", "name": "role_assignments", "description": "Role identifiers, accountable steward and distinct reviewer assignments; role labels alone are not permission. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "f-authority-d03", "name": "evidence_views", "description": "Recipient scope for counts, predicates, risk reports and accounting; public method summaries require review. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "f-authority-d04", "name": "exception_request", "description": "Documented basis, authority, expiry and refusal or pending outcome; an exception cannot silently waive a privacy guarantee. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "f-authority-artifact", "name": "Authority and audience binding", "description": "Versioned assurance evidence for purpose and audience. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-cohort", "name": "Cohort and floor", "description": "Define what is counted and why a particular floor applies.", "rationale": "Authored grouping of related assurance questions, grounded in the cited concepts; not an external normative schema.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005" ], "layers": [ { "id": "l-population", "name": "Population and counting unit", "description": "Context for population and counting unit within the host attachment.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ], "findings": [ { "id": "f-population", "name": "Population and counting unit", "description": "Design rule: distinguish records from protected contributors and bind the selection semantics before evaluating any floor. Do not persist membership lists in this mixin.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ], "questions": [ { "id": "f-population-q01", "text": "What population unit and membership predicate define this cohort?", "kind": "definition", "answer_data": [ "cohort_definition" ] }, { "id": "f-population-q02", "text": "How are repeated records, weights and multiple contributions treated in the support count?", "kind": "measurement", "answer_data": [ "support_measure" ] }, { "id": "f-population-q03", "text": "Which geographic, temporal and categorical intersections define the evaluated cells?", "kind": "spatial", "answer_data": [ "cell_domain" ] }, { "id": "f-population-q04", "text": "Which related cohorts or external information can narrow the protected group?", "kind": "privacy", "answer_data": [ "overlap_context" ] } ], "data_elements": [ { "id": "f-population-d01", "name": "cohort_definition", "description": "Person, household, establishment or other unit; host reference, predicate revision, exclusions and missing-data handling. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "f-population-d02", "name": "support_measure", "description": "Unit deduplication method and trusted evidence for unweighted distinct support; weighted estimates and noisy counts are labelled separately. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "f-population-d03", "name": "cell_domain", "description": "Dimension vocabularies, geographic resolution, period boundaries and cross-classification rules. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "f-population-d04", "name": "overlap_context", "description": "Overlap and linkage evidence references, untested intersections and context-specific attacker knowledge; no identity list in a public view. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "f-population-artifact", "name": "Cohort definition and count evidence", "description": "Versioned assurance evidence for population and counting unit. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "l-floor", "name": "Applicable floor profile", "description": "Context for applicable floor profile within the host attachment.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "findings": [ { "id": "f-floor", "name": "Applicable floor profile", "description": "A count floor is a selected release constraint, not proof of k-anonymity or legal anonymity. Design rule: no default numeric floor; unknown profile or untrusted support yields unresolved assurance.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "f-floor-q01", "text": "Which floor rule and comparison apply to this cell and release context?", "kind": "constraint", "answer_data": [ "floor_rule" ] }, { "id": "f-floor-q02", "text": "What evidence and approval justify this floor and its next review?", "kind": "authority", "answer_data": [ "floor_basis" ] }, { "id": "f-floor-q03", "text": "Does trustworthy support satisfy the bound under the pinned rule?", "kind": "validation", "answer_data": [ "floor_result" ] }, { "id": "f-floor-q04", "text": "Is a k-anonymity claim being made beyond the cohort count constraint?", "kind": "classification", "answer_data": [ "claim_classification" ] } ], "data_elements": [ { "id": "f-floor-d01", "name": "floor_rule", "description": "Profile identifier and revision, counting unit, integer threshold, inclusive or exclusive comparison, method, scope and applicability evidence. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "f-floor-d02", "name": "floor_basis", "description": "Risk and utility rationale, sensitivity context, approving role, effective interval and reassessment trigger. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "f-floor-d03", "name": "floor_result", "description": "Measured support reference and pass, fail, not-applicable or unresolved result; equality and missing-count cases must be explicit. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "f-floor-d04", "name": "claim_classification", "description": "Separate threshold-only, k-anonymity or DP claim; a k claim requires quasi-identifier equivalence-class evidence and its stated limits. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "f-floor-artifact", "name": "Versioned floor evaluation", "description": "Versioned assurance evidence for applicable floor profile. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-transformation", "name": "Computation and disclosure control", "description": "Bind aggregate lineage and controls to the candidate output.", "rationale": "Authored grouping of related assurance questions, grounded in the cited concepts; not an external normative schema.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "l-measure", "name": "Aggregate lineage", "description": "Context for aggregate lineage within the host attachment.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "findings": [ { "id": "f-measure", "name": "Aggregate lineage", "description": "Design rule: keep source, method, internal exact result and proposed outward value distinct. Computation evidence does not itself authorize disclosure.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "questions": [ { "id": "f-measure-q01", "text": "Which statistic, denominator and unit does this output represent?", "kind": "measurement", "answer_data": [ "measure_definition" ] }, { "id": "f-measure-q02", "text": "Which source revision, approved method and execution produced the aggregate?", "kind": "provenance", "answer_data": [ "computation_lineage" ] }, { "id": "f-measure-q03", "text": "Is the candidate value exact, suppressed, rounded, perturbed or otherwise unavailable?", "kind": "state", "answer_data": [ "value_state" ] }, { "id": "f-measure-q04", "text": "Which raw counts, parameters or intermediate results require restricted storage?", "kind": "security", "answer_data": [ "internal_material" ] } ], "data_elements": [ { "id": "f-measure-d01", "name": "measure_definition", "description": "Measure kind, numerator and denominator definitions, units, null and zero semantics, sampling and weight method references. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "f-measure-d02", "name": "computation_lineage", "description": "Source and method digests, protected execution receipt, observation time and external actor references; no raw rows. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "f-measure-d03", "name": "value_state", "description": "Unambiguous status with transformed value reference; suppression and missingness must not be serialized as numeric zero. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "f-measure-d04", "name": "internal_material", "description": "Access and retention classifications for exact counts, predicates and randomness; public evidence excludes reconstructive secrets. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "f-measure-artifact", "name": "Aggregate lineage record", "description": "Versioned assurance evidence for aggregate lineage. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "l-suppression", "name": "Suppression and perturbation", "description": "Context for suppression and perturbation within the host attachment.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "findings": [ { "id": "f-suppression", "name": "Suppression and perturbation", "description": "Disclosure controls must be assessed over connected outputs. Design rule: review totals, denominators and secondary suppression; generic perturbation is not labelled DP.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "f-suppression-q01", "text": "Which suppression, coarsening, rounding or perturbation transformations were applied?", "kind": "process", "answer_data": [ "control_sequence" ] }, { "id": "f-suppression-q02", "text": "Can totals, margins, percentages or companion tables reconstruct a suppressed value?", "kind": "validation", "answer_data": [ "reconstruction_review" ] }, { "id": "f-suppression-q03", "text": "Can the presence or absence of a cell disclose a private threshold decision?", "kind": "privacy", "answer_data": [ "selection_review" ] }, { "id": "f-suppression-q04", "text": "What consistency and utility limitations do the transformed results carry?", "kind": "quality", "answer_data": [ "control_limitations" ] } ], "data_elements": [ { "id": "f-suppression-d01", "name": "control_sequence", "description": "Ordered method revisions, affected output references, rationale and transformation evidence. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "f-suppression-d02", "name": "reconstruction_review", "description": "Joint output-set identifier, primary and secondary suppression evidence, tested constraints and unresolved paths. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "f-suppression-d03", "name": "selection_review", "description": "Observable cells, flags, errors, timing and selection mechanism assessment; private data-dependent selection cannot bypass a claimed guarantee. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "f-suppression-d04", "name": "control_limitations", "description": "Non-additivity, distortion and withheld categories, reviewer-qualified accuracy summary and recipient-facing status legend. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "f-suppression-artifact", "name": "Disclosure control assessment", "description": "Versioned assurance evidence for suppression and perturbation. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-formal", "name": "Optional formal privacy assurance", "description": "Record a qualified DP claim and the accounting evidence on which it depends.", "rationale": "Authored grouping of related assurance questions, grounded in the cited concepts; not an external normative schema.", "source_refs": [ "SRC-001", "SRC-002" ], "layers": [ { "id": "l-guarantee", "name": "Differential privacy claim", "description": "Context for differential privacy claim within the host attachment.", "source_refs": [ "SRC-002" ], "findings": [ { "id": "f-guarantee", "name": "Differential privacy claim", "description": "Noise is insufficient evidence of DP. Design rule: mark this section not-applicable with rationale when no DP claim exists; otherwise require a reviewed guarantee covering the whole observable mechanism.", "source_refs": [ "SRC-002" ], "questions": [ { "id": "f-guarantee-q01", "text": "Which privacy definition, adjacency and protected unit does the DP claim use?", "kind": "definition", "answer_data": [ "dp_definition" ] }, { "id": "f-guarantee-q02", "text": "Which parameters, contribution bounds and sensitivity support the mechanism?", "kind": "constraint", "answer_data": [ "dp_parameters" ] }, { "id": "f-guarantee-q03", "text": "What review establishes the implemented mechanism matches the stated guarantee?", "kind": "evidence", "answer_data": [ "dp_assurance" ] }, { "id": "f-guarantee-q04", "text": "Does the guarantee cover selection, tuning, diagnostics and all outward observations?", "kind": "security", "answer_data": [ "observable_boundary" ] } ], "data_elements": [ { "id": "f-guarantee-d01", "name": "dp_definition", "description": "Claim state, pure or approximate or other named definition, privacy unit, adjacency relation, trust model and proof reference; explicit not-applicable rationale allowed. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "f-guarantee-d02", "name": "dp_parameters", "description": "Epsilon, delta where applicable, units, clipping and contribution limits, sensitivity derivation and mechanism revision; none inferred from a generic noise label. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "f-guarantee-d03", "name": "dp_assurance", "description": "Proof and implementation review references, tested numerical behavior, secure randomness controls, limitations and unresolved status. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "f-guarantee-d04", "name": "observable_boundary", "description": "Private preprocessing, choice of partitions, threshold refusals, errors, timing, metadata and diagnostics; exclude raw-data-dependent side channels or leave assurance unresolved. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "f-guarantee-artifact", "name": "Formal privacy claim record", "description": "Versioned assurance evidence for differential privacy claim. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "l-accounting", "name": "Cumulative privacy accounting", "description": "Context for cumulative privacy accounting within the host attachment.", "source_refs": [ "SRC-002" ], "findings": [ { "id": "f-accounting", "name": "Cumulative privacy accounting", "description": "Design rule: composition follows the protected unit and declared mechanism across overlapping releases. A date change, retraction or new dataset label does not restore spent privacy loss.", "source_refs": [ "SRC-002" ], "questions": [ { "id": "f-accounting-q01", "text": "Which previous and planned releases share the protected units or source lineage?", "kind": "composition", "answer_data": [ "accounting_scope" ] }, { "id": "f-accounting-q02", "text": "What cumulative bound and authorized limit does the accountant report?", "kind": "measurement", "answer_data": [ "accountant_result" ] }, { "id": "f-accounting-q03", "text": "How are concurrent evaluations, retries and uncertain disclosures reconciled?", "kind": "event", "answer_data": [ "reservation_evidence" ] }, { "id": "f-accounting-q04", "text": "What evidence prevents withdrawal or a new reporting period from resetting privacy accounting?", "kind": "retention", "answer_data": [ "continuity_evidence" ] } ], "data_elements": [ { "id": "f-accounting-d01", "name": "accounting_scope", "description": "Accountant scope identifier, unit overlap, release history, pending reservations and justified disjointness assumptions; explicit not-applicable state when no DP claim. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "f-accounting-d02", "name": "accountant_result", "description": "Accountant algorithm and revision, parameter representation, composed bound, limit, evidence and ledger revision; incompatible variants cannot be added without a justified conversion. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "f-accounting-d03", "name": "reservation_evidence", "description": "Idempotency key, expected ledger revision, reservation and commit receipts; unknown external exposure retains a conservative reservation pending review. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "f-accounting-d04", "name": "continuity_evidence", "description": "Prior-release receipts and minimal lawful continuity records; distinguish cached post-processing from a fresh computation over private data. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "f-accounting-artifact", "name": "Accounting and reservation evidence", "description": "Versioned assurance evidence for cumulative privacy accounting. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-review", "name": "Release-set review", "description": "Combine risk, utility and evidence before returning a qualified assurance result.", "rationale": "Authored grouping of related assurance questions, grounded in the cited concepts; not an external normative schema.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005" ], "layers": [ { "id": "l-joint-risk", "name": "Joint disclosure risk", "description": "Context for joint disclosure risk within the host attachment.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "findings": [ { "id": "f-joint-risk", "name": "Joint disclosure risk", "description": "Design rule: evaluate the whole requested release set against known previous outputs and plausible auxiliary information. Individually passing cells do not imply a safe combination.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "questions": [ { "id": "f-joint-risk-q01", "text": "Which singling-out, linkage and inference scenarios are relevant to the intended audience?", "kind": "privacy", "answer_data": [ "threat_assessment" ] }, { "id": "f-joint-risk-q02", "text": "Which earlier tables, revised periods and alternate projections were considered together?", "kind": "relationship", "answer_data": [ "release_inventory" ] }, { "id": "f-joint-risk-q03", "text": "What evidence addresses differencing, dominance and homogeneous sensitive attributes?", "kind": "validation", "answer_data": [ "attack_review" ] }, { "id": "f-joint-risk-q04", "text": "What new information or change makes the disclosure assessment stale?", "kind": "temporal", "answer_data": [ "risk_expiry" ] } ], "data_elements": [ { "id": "f-joint-risk-d01", "name": "threat_assessment", "description": "Audience context, plausible auxiliary information, protected attributes, risk rationale and assessment limits. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] }, { "id": "f-joint-risk-d02", "name": "release_inventory", "description": "Candidate digest, previous release references, overlap map, unknown external outputs and joint-review boundary. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] }, { "id": "f-joint-risk-d03", "name": "attack_review", "description": "Authorized assessment references for complementary cohorts, contributor concentration, attribute disclosure and remaining uncertainty; no universal safe count assumption. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] }, { "id": "f-joint-risk-d04", "name": "risk_expiry", "description": "Evidence age, review deadline and triggers including new releases, source revisions, audience changes and credible new linkage evidence. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "f-joint-risk-artifact", "name": "Joint disclosure assessment", "description": "Versioned assurance evidence for joint disclosure risk. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "l-utility", "name": "Utility and population impact", "description": "Context for utility and population impact within the host attachment.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ], "findings": [ { "id": "f-utility", "name": "Utility and population impact", "description": "Privacy controls alter the usefulness of statistics. Design rule: review fitness for the stated task and harm to poorly represented groups without treating utility as authority to waive protection.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ], "questions": [ { "id": "f-utility-q01", "text": "What error, bias and missing-cell effects matter for this intended analysis?", "kind": "quality", "answer_data": [ "utility_assessment" ] }, { "id": "f-utility-q02", "text": "How does protection affect small or rarely represented groups?", "kind": "measurement", "answer_data": [ "group_impact" ] }, { "id": "f-utility-q03", "text": "Which utility criteria were accepted and which uses remain unsupported?", "kind": "decision", "answer_data": [ "utility_decision" ] }, { "id": "f-utility-q04", "text": "How are suppression, uncertainty and method revisions conveyed without exposing protected data?", "kind": "interoperability", "answer_data": [ "consumer_metadata" ] } ], "data_elements": [ { "id": "f-utility-d01", "name": "utility_assessment", "description": "Task-specific metrics, uncertainty, suppression coverage and limitations; no imported universal accuracy target. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] }, { "id": "f-utility-d02", "name": "group_impact", "description": "Qualified subgroup utility evidence, limits of comparison and known gaps; protected group comparisons remain access-controlled. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] }, { "id": "f-utility-d03", "name": "utility_decision", "description": "Reviewed criteria, decision rationale, responsible role and restricted uses; utility failure may block or narrow the candidate. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] }, { "id": "f-utility-d04", "name": "consumer_metadata", "description": "Status-code mapping, units, period and method references, disclosure-reviewed summaries and loss warnings for target formats. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] } ], "artifacts": [ { "id": "f-utility-artifact", "name": "Utility and impact review", "description": "Versioned assurance evidence for utility and population impact. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-assurance", "name": "Assurance outcome and continuity", "description": "Record an evidence-bound outcome and maintain it across host release changes.", "rationale": "Authored grouping of related assurance questions, grounded in the cited concepts; not an external normative schema.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006", "SRC-007" ], "layers": [ { "id": "l-decision", "name": "Assurance decision", "description": "Context for assurance decision within the host attachment.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "f-decision", "name": "Assurance decision", "description": "Design rule: bind a decision to the exact candidate digest, profile, audience and ledger revision. Passing assurance is necessary only within the adopting profile and never a publication command.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ], "questions": [ { "id": "f-decision-q01", "text": "What assurance outcome follows from all applicable floor, control, risk and utility checks?", "kind": "decision", "answer_data": [ "assurance_outcome" ] }, { "id": "f-decision-q02", "text": "Who approved the evidence-bound outcome and under which delegated authority?", "kind": "authority", "answer_data": [ "review_receipt" ] }, { "id": "f-decision-q03", "text": "Which candidate, audience and accounting revision must still match at the release handoff?", "kind": "constraint", "answer_data": [ "handoff_conditions" ] }, { "id": "f-decision-q04", "text": "What does the host receive when a required check fails or remains unresolved?", "kind": "exception", "answer_data": [ "refusal_view" ] } ], "data_elements": [ { "id": "f-decision-d01", "name": "assurance_outcome", "description": "Pass, fail, unresolved or not-applicable with required evidence references; missing mandatory evidence cannot produce pass. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "f-decision-d02", "name": "review_receipt", "description": "Reviewer identity reference, separation-of-duties evidence, authority revision, decision event time and rationale. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "f-decision-d03", "name": "handoff_conditions", "description": "Candidate and method digests, audience scope, validity interval, ledger compare-and-swap token and external access decision; stale evidence requires reevaluation. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] }, { "id": "f-decision-d04", "name": "refusal_view", "description": "Restricted reason and externally safe status; no raw count, sensitive predicate or guarantee-breaking refusal detail in public responses. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "f-decision-artifact", "name": "Bound release assurance receipt", "description": "Versioned assurance evidence for assurance decision. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "l-continuity", "name": "Revision and retirement", "description": "Context for revision and retirement within the host attachment.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-007" ], "findings": [ { "id": "f-continuity", "name": "Revision and retirement", "description": "Design rule: keep the mixin assurance lifecycle separate from host publication. Retraction cannot undo a disclosure and evidence retention is scoped by lawful policy, not unlimited history.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-007" ], "questions": [ { "id": "f-continuity-q01", "text": "What authorized host receipt confirms what was actually disclosed and when?", "kind": "event", "answer_data": [ "release_receipt" ] }, { "id": "f-continuity-q02", "text": "Which change invalidates or supersedes this assurance revision?", "kind": "lifecycle", "answer_data": [ "assurance_transition" ] }, { "id": "f-continuity-q03", "text": "Which evidence and sensitive intermediates must be retained, restricted or disposed of?", "kind": "retention", "answer_data": [ "disposition_binding" ] }, { "id": "f-continuity-q04", "text": "How can another system resolve revisions and interpret a withdrawn or corrected release?", "kind": "interoperability", "answer_data": [ "revision_projection" ] } ], "data_elements": [ { "id": "f-continuity-d01", "name": "release_receipt", "description": "External release identifier, actual payload digest, recipient class, event and observation timestamps, partial or unknown disclosure state. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "f-continuity-d02", "name": "assurance_transition", "description": "Proposed, assessed, approved, expired, superseded or withdrawn assurance state; new payload, audience or profile triggers review before reuse. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "f-continuity-d03", "name": "disposition_binding", "description": "Applicable retention schedule and hold references, minimum continuity evidence, payload disposal request and receipt from the authorized custodian. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "f-continuity-d04", "name": "revision_projection", "description": "Stable identifiers, supersedes and derivation links, withdrawal reason classification and safe machine-readable status; conceptual mappings require binding validation. Candidate structured answer group; nested instance schema remains an adoption hold.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "f-continuity-artifact", "name": "Assurance continuity record", "description": "Versioned assurance evidence for revision and retirement. Restricted by default; no microdata or secret randomness belongs in the public projection.", "media_or_form": [ "Structured record", "Human-readable controlled report" ], "serial": true, "identity_strategy": "Use the authoritative master-system identifier and immutable revision; otherwise a governed IRI, then a Dimension-assigned UUID or ULID. Bind to the attachment and host revision. A digest checks integrity and a timestamp orders evidence; neither replaces identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-bind", "name": "Bind an assurance attachment", "description": "Proposed local operation, not implemented: Bind host, cohort, purpose and evidence revisions without altering the host.", "inputs": [ "Host and candidate references", "Authority and floor profile revisions" ], "outputs": [ "Bound attachment or unresolved-reference report" ], "preconditions": [ "Authorized local editor", "Identifiers resolve or are explicitly unresolved" ], "effects": [ "Create a versioned attachment; grant no source access and perform no computation" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] }, { "id": "fn-floor", "name": "Evaluate the applicable floor", "description": "Proposed local operation, not implemented: Calculate threshold satisfaction from trusted count evidence and the selected rule.", "inputs": [ "Pinned floor profile", "Distinct support evidence", "Host and cohort revisions" ], "outputs": [ "Pass, fail, not-applicable or unresolved floor result" ], "preconditions": [ "Count unit matches profile", "Known comparison semantics and authenticated evidence" ], "effects": [ "Record local evaluation; a floor pass cannot become release assurance by itself", "Do not expose private counts or data-dependent refusal details" ], "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "fn-controls", "name": "Assess disclosure control evidence", "description": "Proposed local operation, not implemented: Check completeness and consistency of transformation and joint-output evidence.", "inputs": [ "Candidate digest and value states", "Transformation sequence", "Joint release inventory and assessment" ], "outputs": [ "Control assessment with gaps and qualified result" ], "preconditions": [ "Authorized reviewer", "Known observable output boundary" ], "effects": [ "Record assurance findings; perform no general projection enforcement or source transformation" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005" ] }, { "id": "fn-accounting", "name": "Assess formal privacy accounting", "description": "Proposed local operation, not implemented: Compare an authenticated accountant receipt to the declared DP claim and release set.", "inputs": [ "DP claim and implementation evidence", "Accountant bound and limit", "Reservation and ledger revision receipts" ], "outputs": [ "Qualified accounting assessment or unresolved result" ], "preconditions": [ "DP claim or explicit not-applicable rationale", "Receipt scope and units match; proposed runtime adapter must validate concurrency" ], "effects": [ "Reference external accounting state without spending or refunding budget", "Mark changed or missing ledger evidence unresolved; never reset loss locally" ], "source_refs": [ "SRC-002" ] }, { "id": "fn-decide", "name": "Record release assurance", "description": "Proposed local operation, not implemented: Combine the required checks under the pinned profile and reviewer authority.", "inputs": [ "Floor, control, DP where applicable, risk and utility results", "Exact candidate digest and audience", "Authority and accounting receipts" ], "outputs": [ "Bound assurance decision or refusal" ], "preconditions": [ "All applicable mandatory checks resolved", "Authorized reviewer distinct from requester where policy requires", "Evidence revisions still match" ], "effects": [ "Create a local assurance receipt with expiry and handoff preconditions", "Do not publish, send data, grant access or execute audit logging" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "fn-supersede", "name": "Supersede assurance evidence", "description": "Proposed local operation, not implemented: Invalidate stale assurance and link host release or disposition receipts.", "inputs": [ "Changed host, audience, rule or source reference", "Prior assurance and host receipts", "Applicable retention and hold references" ], "outputs": [ "Superseding assurance revision and outstanding reassessment or disposal needs" ], "preconditions": [ "Authorized steward", "Preserve references and known disclosure history subject to lawful retention" ], "effects": [ "Mark stale results unusable for new release handoffs", "Request rather than execute custody-side disposal; preserve cumulative privacy accounting evidence" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] } ], "composition": [ { "target": "WM-XCT-001", "relation": "REFERENCE", "purpose": "Proposed binding: Reference the source steward and authority context; this mixin neither transfers ownership nor operates a stewardship registry.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "WM-XCT-002", "relation": "REFERENCE", "purpose": "Proposed binding: Reference permitted processing and recipient access; a floor check cannot create consent or execute access contracts.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "WM-XCT-003", "relation": "REFERENCE", "purpose": "Proposed binding: Reference the selected audience and outward projection. The incoming ledger edge is preserved: threshold calculation and privacy aggregation assurance stay here, while projection policy and enforcement remain external.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "WM-XCT-004", "relation": "REFERENCE", "purpose": "Proposed binding: Reference audit receipts for assurance operations; do not duplicate audit-trail execution or storage semantics.", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "target": "Host dataset and statistical series", "relation": "REFERENCE", "purpose": "Proposed binding: Resolve source, measure, release and correction identities in host masters. Attachment lifecycle concerns only privacy assurance.", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "target": "PROV-O", "relation": "ALIGN", "purpose": "Conceptual derivation, attribution and revision links only; executable RDF mapping and conformance are deferred.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "RFC 3339", "relation": "ALIGN", "purpose": "Evidence timestamps use section 5.6 syntax; reporting periods and accounting scope are separately modelled.", "required": false, "source_refs": [ "SRC-007" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name the adopting Dimension, accountable statistics steward and authoritative host namespace.", "Pin the floor and assurance profile, jurisdictional review, permitted audience and delegated roles.", "Declare source, accountant, release, audit and retention bindings with authority and unresolved-reference behavior.", "Supply instance schemas, validation fixtures and controlled storage before operational adoption." ], "namespace_guidance": "Use a governed attachment namespace scoped to the host; stable local IDs contain no dates. Keep identity separate from definition revision and observation interval.", "registry_links": [ "vr.wm-xct-005", "WM-XCT-001", "WM-XCT-002", "WM-XCT-003", "WM-XCT-004" ] }, "canon_and_patch": { "canonicalization_rules": [ "This package remains a noncanonical reviewable draft under a single-provider waiver.", "Canonicalize controlled identifiers and parameter encodings only within a pinned adoption profile; never equate exact, noisy, weighted or suppressed values." ], "patch_rules": [ "Apply authorized optimistic-concurrency patches to evidence revisions; record rationale, actor and source links.", "A change to floor, population unit, audience, mechanism or candidate invalidates affected assurance; no silent relaxation or budget reset." ], "compatibility_rules": [ "Version semantic changes to counting units, profile comparisons and DP definitions; migrations require explicit loss reports.", "Unknown status values, unresolved references or incompatible accountants yield unresolved assurance, never a default pass." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with a separate immutable revision", "Governed global identifier or IRI", "Dimension-assigned UUID or ULID" ], "timestamp_rule": "Use RFC 3339 with seconds and an explicit offset or Z. Record event time and observation or ingestion time separately. Keep date-only reporting periods and uncertain intervals distinct from instants.", "serial_naming_rule": "Name serial evidence by stable attachment and artifact identifiers plus revision; dates are metadata, never the primary identity.", "integrity_rule": "Bind review to candidate, method and evidence digests and external receipts; a digest establishes byte integrity, not privacy, authority or truth. Do not export membership hashes or secret random seeds as proof." }, "policies": [ "No fixed threshold, epsilon or delta is supplied by this model. Qualified adoption chooses and documents rules.", "Passing a floor cannot establish k-anonymity, DP, legal anonymity or release authority.", "Optional DP claims require evidence covering the full observable mechanism, and compatible cumulative accounting; no automatic period reset.", "No microdata, raw suppressed counts or reconstructive secrets in public methodology or logs.", "Local self-audit is not independent external review; source verification and executable conformance remain holds." ], "crud": { "read": [ "Read only the authorized evidence view for a declared purpose; protect counts, predicates and accountant details." ], "create": [ "Create an attachment with resolved host identity, profile revision, provenance and authority binding; mark missing facts unresolved." ], "update": [ "Append an authorized revision with expected prior version; invalidate stale approvals and preserve protected disclosure continuity." ], "delete": [ "Retire local assurance through the adopting retention schedule and active holds. The host custodian executes payload deletion and provides a receipt. Retain only lawful minimal tombstones and accounting continuity; deletion or withdrawal never refunds disclosed privacy loss." ] }, "roles": [ { "name": "Statistics steward", "responsibilities": [ "Maintain floor profile and approved purpose within delegated authority." ] }, { "name": "Protected computation custodian", "responsibilities": [ "Supply controlled count, method and source-revision evidence through approved interfaces." ] }, { "name": "Privacy method reviewer", "responsibilities": [ "Review suppression, joint disclosure risks and any formal privacy guarantee." ] }, { "name": "Release assurance reviewer", "responsibilities": [ "Bind the assurance outcome to the exact candidate and audience; refer actual release to the authorized host." ] }, { "name": "Evidence custodian", "responsibilities": [ "Maintain restricted revisions, audit links and lawful disposal receipts." ] }, { "name": "Statistical consumer", "responsibilities": [ "Use only released projections with their limitations; do not interpret suppression as zero." ] } ], "access": { "default_rule": "Deny access to unpublished assurance evidence unless a current purpose and role binding permits it. Public access is limited to separately reviewed released summaries.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Exceptions require an external authority reference, explicit scope, reason and expiry; they cannot silently weaken a claimed mathematical guarantee or create publication permission." ], "audit_requirements": [ "Link local changes and review decisions to protected external audit receipts; logging execution remains external.", "Record who accessed sensitive evidence without leaking suppressed values, predicates or random seeds into public audit projections." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Provider waiver and research holds", "Authority and profile references" ], "read_order": [ "Read AGENTS.md and the review state and holds.", "Resolve host identity, authority and profile references before reading controlled evidence.", "Inspect specification, evidence and validation status before proposing local changes." ] } }, "coverage": { "claim": "Source-grounded proposed host-attached mixin for aggregation-floor evaluation and privacy assurance. A separate local no-tools self-audit found no critical semantic conflict. The draft distinguishes cohort counts, k-anonymity, optional DP evidence and release authority; independent review, source/version verification, qualified adoption and executable conformance remain holds.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Attachment, host, cohort and artifact identities have separate revisions." }, { "dimension": "lifecycle", "status": "covered", "notes": "Assurance expiration and supersession do not replace host series lifecycle." }, { "dimension": "relationships", "status": "covered", "notes": "Candidate registry edge and legacy references are reconciled without copying neighbor operations." }, { "dimension": "temporal", "status": "covered", "notes": "Reporting periods, effective intervals, event time and observation time are distinct." }, { "dimension": "provenance", "status": "covered", "notes": "Source and method revision references bind each evaluated output." }, { "dimension": "ownership", "status": "covered", "notes": "Role-based stewardship is external authority, never ownership inferred from aggregation." }, { "dimension": "validation", "status": "covered", "notes": "Evidence-qualified floor and joint review outcomes include unresolved state." }, { "dimension": "access", "status": "covered", "notes": "Restricted counts and metadata; only approved outward views may leave." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Lawful minimization, host disposal receipts and cumulative-accounting continuity are explicit." }, { "dimension": "interoperability", "status": "gap", "notes": "Format-neutral answer groups and provenance alignment exist; nested schemas and SDMX binding remain incomplete." }, { "dimension": "formal privacy", "status": "gap", "notes": "Claim and accounting contracts are present; no runtime proof or accountant implementation is certified." }, { "dimension": "utility and group impact", "status": "covered", "notes": "Review questions address distortion, small groups and permitted uses." }, { "dimension": "source verification", "status": "gap", "notes": "Seven selected sources read through browser tools; direct HTTP and full current-version verification remain pending." }, { "dimension": "independent review", "status": "gap", "notes": "Claude and Grok skipped; separate local no-tools self-audit does not replace external review." } ], "known_omissions": [ "No executable instance schemas, floor engine, DP accountant, mechanism proof, concurrency adapter or conformance fixtures are supplied.", "No universal legal anonymity decision, jurisdictional authorization, threshold or privacy parameter is supplied.", "SDMX exchange binding from the legacy lead is deferred; no version or conformance claim is admitted.", "Adversarial scenarios are design checks, not executed privacy attacks or measured leakage results." ], "conflicts": [ "Resolved legacy overclaim: cohort floor is not k-anonymity proof and protected internal counts may exist below a release floor.", "Resolved legacy overclaim: only qualified DP mechanisms support DP accounting; reporting periods do not erase cumulative loss." ], "regional_assumptions": [ "NIST guidance and UK regulator/statistical examples ground concepts without imposing one jurisdiction on every adopter.", "The ICO source says it is under review; qualified current-law and sector review remains required." ], "adversarial_checks": [ "One individual contributes many rows: record count must not masquerade as distinct-person support.", "All cells pass a floor but a marginal total reveals a suppressed value: whole-output review remains required.", "A raw-count threshold changes a public suppression flag: assess that observable branch within any claimed DP mechanism.", "Two concurrent candidates reuse one accountant revision: handoff must reject stale evidence rather than overspend.", "A calendar rollover, withdrawal or renamed dataset must not reset prior loss for overlapping protected units.", "A changed recipient or candidate digest invalidates a prior assurance decision.", "Suppression is not zero; a large cohort with homogeneous sensitive attributes may still disclose information." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "mixin", "status": "accepted", "rationale": "The root attaches subject-specific privacy aggregation assurance to a host and retains no independent population or statistical-series master. Attachment identity and revision are compatible with mixin status. The incoming WM-XCT-003 reference explicitly leaves threshold calculation and privacy aggregation assurance here while generic projection policy and enforcement remain external." }, "decisions": [ { "concept": "Host-attached boundary", "disposition": "accepted", "rationale": "All twelve findings concern evidence for a host-bound privacy assurance attachment. The six proposed functions neither publish nor take over host series, general access or audit operations." }, { "concept": "Registry and legacy composition", "disposition": "qualified", "rationale": "The incoming projection-policy edge is respected. Legacy S1-S4 links become proposed external bindings; optional registry targets do not remove the textual requirement for valid host and authority evidence." }, { "concept": "Cohort counts and k-anonymity", "disposition": "separated", "rationale": "Distinct contributors, duplicate rows and weighted or noisy counts are separated. A count-floor result is not admitted as equivalence-class evidence or a legal anonymity conclusion." }, { "concept": "Below-floor internal computation", "disposition": "legacy restriction rejected", "rationale": "The draft allows protected internal evidence needed to evaluate a rule. The release observable must satisfy the selected profile; no universal claim forbids every small noisy value." }, { "concept": "Threshold authority", "disposition": "accepted with profile hold", "rationale": "No arbitrary numeric floor is supplied. Applicability, counting unit, comparison semantics and evidence must be pinned; unknown facts yield unresolved assurance rather than a default pass." }, { "concept": "Joint reconstruction risk", "disposition": "accepted", "rationale": "Suppression, totals, percentages, overlapping releases, dominance and homogeneous sensitive attributes are reviewed beyond individual cell counts. The checks are design requirements, not claimed executed privacy attacks." }, { "concept": "Observable threshold decisions", "disposition": "qualified", "rationale": "A private threshold-dependent refusal, status or cell-selection branch can undermine the claimed observable mechanism. The draft requires that boundary to be reviewed; the phrase safe status is an intended design property, not a proven privacy guarantee." }, { "concept": "Perturbation and differential privacy", "disposition": "separated", "rationale": "Generic noise cannot imply DP. The optional formal claim needs a definition, adjacency, unit, parameters, bounds, reviewed implementation and complete observable scope. Not-applicable requires rationale." }, { "concept": "Cumulative accounting and retries", "disposition": "accepted with runtime hold", "rationale": "The record tracks overlapping units, compatible accountant evidence and reservation revisions. Calendar changes, withdrawal and relabeling do not refund loss. Atomic handoff and uncertain exposure reconciliation require an external implementation and tests." }, { "concept": "Release assurance versus publication", "disposition": "separated", "rationale": "The decision binds exact payload, audience, profile and ledger revision. It is evidence for the host release authority and never a command to publish, a consent grant or an access decision." }, { "concept": "Utility and affected groups", "disposition": "accepted", "rationale": "Task-specific distortion and small-group effects are explicit, but utility cannot silently waive the privacy profile. Suppressed, missing, exact and transformed values remain distinct." }, { "concept": "Evidence retention and identity", "disposition": "accepted with adoption dependency", "rationale": "Stable master identifiers and revisions precede digests or dates. Restricted evidence, host disposal receipts and minimal lawful accounting continuity avoid both public leakage and an unlimited-retention mandate." }, { "concept": "Source and provider assurance", "disposition": "limited", "rationale": "Selected browser readings support concepts only. Direct HTTP has zero attempts and no measured statuses; guidance currency and applicability remain open. The local self-audit cannot stand in for waived independent external review." }, { "concept": "Instance schemas and exchange mappings", "disposition": "deferred", "rationale": "All answer groups are candidate objects rather than executable schemas. SDMX, RDF bindings, mechanism validation, nested constraints and adversarial acceptance fixtures remain explicitly incomplete." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped with zero attempts; the separate local Codex no-tools self-audit is not a second-provider review.", "Source and version verification remains incomplete. Seven selected sources were read through browser tools; direct HTTP checks were not attempted under the owner-reported sandbox restriction and all seven statuses remain unmeasured. The coordinator must run check_sources.py and review current versions and claim support; HTTP success alone is insufficient.", "Qualified adoption review must establish the protected unit, floor and mechanism parameters, audience, jurisdiction, legal authority, lawful retention and acceptable utility. The ICO guidance is under review. No universal anonymity, k-anonymity, DP or legal-compliance certification is supplied.", "Executable conformance remains incomplete: nested instance schemas, version-pinned neighbor and exchange bindings, mechanism proof and implementation review, accountant compatibility, atomic release handoff, privacy-safe observable behavior and adversarial fixtures must be implemented and tested before operational use.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore independent external review before any canonical or publishable-draft promotion.", "Verify direct source access, current versions, selected claim support, licensing and jurisdictional applicability outside the sandbox.", "Develop profile schemas and fixtures for repeated records, equality at the floor, suppressed margins, homogeneous groups, threshold side channels, overlapping periods, concurrent reservations, unknown disclosures and stale approvals.", "Pin and test external accountant, access, release, audit and retention interfaces; assess SDMX and PROV-O exchange mappings without implying conformance from conceptual alignment." ] }, "statistics": { "sources": 7, "bundles": 6, "layers": 12, "findings": 12, "questions": 48, "artifacts": 12, "functions": 6 } }