Access Breach / Enforcement
Attach evidence-qualified access violation, enforcement and redress records to a host without taking over its identity or authority.
Bundle → Layer → Finding → Questions Filled
6 bundles · 12 layers · 12 findings · 36 questions
Attachment and applicable authority Keep host identity, rules and competence explicit.
Attachment identity
Require one explicit host reference per attachment and separate affected resource and party references. Link related attachments without merging identities.
Host and subject binding
Require one explicit host reference per attachment and separate affected resource and party references. Link related attachments without merging identities.
- Which authoritative host, attachment identifier and local revision identify this enforcement context? identity
- Which resources, parties and external cases are affected, and which links remain uncertain? relationship
- Which custodian maintains the attachment and which external masters retain grants, rights and evidence? ownership
Policy and authority
Pin the relevant rule and effective interval. A role assignment, a policy expression and legal competence are separate assertions.
Applicable rules and delegated competence
Pin the relevant rule and effective interval. A role assignment, a policy expression and legal competence are separate assertions.
- Which policy, contract or legal profile revision allegedly governs the action and at what time? requirement
- Who may investigate, determine a breach, authorize a measure and review it under this profile? authority
- Which exceptions, overriding duties or unresolved rule conflicts affect the alleged violation? exception
Recognition and evidence Separate observations from evaluated assertions.
Signals and triage
Keep a report or anomaly distinct from a finding. Failed attempts, permitted exceptions, accidental events and incomplete evidence remain representable.
Observation without presumption
Keep a report or anomaly distinct from a finding. Failed attempts, permitted exceptions, accidental events and incomplete evidence remain representable.
- What report or observation raised the concern and what action, target and actor attribution does it actually support? event
- Is the concern a suspected access violation, a personal-data breach candidate, another incident or an unresolved category? classification
- What triage disposition, priority and next review were recorded, including dismissal or linkage to an existing case? decision
Evidence and chronology
Preserve supporting and contrary material, source access restrictions and clock uncertainty. A digest checks byte integrity, not factual truth.
Traceable and contestable support
Preserve supporting and contrary material, source access restrictions and clock uncertainty. A digest checks byte integrity, not factual truth.
- Which evidence supports or challenges each assertion and where is its authoritative retained copy? evidence
- Who collected, transformed or transferred the evidence and what integrity or custody gaps remain? provenance
- How do occurrence, detection, awareness and recording times differ and what uncertainty affects their order? temporal
Determinations and measures Separate responsibility, authorization and actual effects.
Assessment and outcomes
Represent each allegation separately with pending, substantiated, unsubstantiated, dismissed or overturned assertions under a versioned local vocabulary. Mixed case outcomes and reopening remain possible.
Per-allegation determinations
Represent each allegation separately with pending, substantiated, unsubstantiated, dismissed or overturned assertions under a versioned local vocabulary. Mixed case outcomes and reopening remain possible.
- Which action and rule operands were assessed and what evidence standard or method was applied? validation
- What outcome is recorded for each allegation and which reasons, reviewer and unresolved objections qualify it? state
- How are impact and severity assessed separately from responsibility and what limits qualify any counts? measurement
Measures and execution evidence
Separate precautionary containment from formal sanctions and distinguish proposed, authorized, attempted and observed effects. No source grants this mixin enforcement authority.
Precautionary and punitive effects
Separate precautionary containment from formal sanctions and distinguish proposed, authorized, attempted and observed effects. No source grants this mixin enforcement authority.
- Is the measure precautionary, remedial or punitive and what authority, purpose and review limit support it? authority
- Which external executor and decision record govern the measure and what refusal, partial completion or failure was observed? process
- What approved safeguards govern uncertain access decisions, emergency exceptions and revocation propagation? security
Notification and redress Track communication and remedy obligations separately.
Notice and reporting
Assess notification requirements promptly under the applicable profile without waiting for final attribution or sanction. Do not impose a universal deadline or infer receipt from dispatch.
Recipient-specific notification assessment
Assess notification requirements promptly under the applicable profile without waiting for final attribution or sanction. Do not impose a universal deadline or infer receipt from dispatch.
- Which recipients, thresholds, awareness triggers and timing rules apply to each notification assessment? requirement
- Why was notification required, withheld, phased or delayed and who reviewed that reasoning? exception
- What approved content version was dispatched and what delivery, receipt or correction evidence exists? event
Remedies and verification
Track redress obligations and evidence of fulfillment independently of sanctions. An ODRL remedy state is not legal exoneration or erasure of historical evidence.
Obligations and redress progress
Track redress obligations and evidence of fulfillment independently of sanctions. An ODRL remedy state is not legal exoneration or erasure of historical evidence.
- Which remedies address which allegations, affected interests and beneficiaries? composition
- What completion criteria, responsible roles and deadlines govern each remedy and what partial or disputed performance exists? lifecycle
- Who verified remedy completion and what residual harm, limitations or follow-up remain? validation
Review and scoped standing Support corrections and qualified status projections.
Challenge and review
Keep review routes and procedural rights profile-specific. Record challenge, stay, correction and outcome references without assuming every appeal suspends every measure.
Corrections and external proceedings
Keep review routes and procedural rights profile-specific. Record challenge, stay, correction and outcome references without assuming every appeal suspends every measure.
- What authorized view, reasons and opportunity to challenge are available to each affected participant? access
- Which external case and forum handle a referral or challenge and what transmission authority applies? relationship
- What review outcome changes the determination or measure and how are prior assertions superseded? lifecycle
Standing and reinstatement
Standing is a limited projection with source cases, policy version and as-of time, never a universal reputation badge. Reinstatement evidence does not create a new access grant.
Scoped derived status
Standing is a limited projection with source cases, policy version and as-of time, never a universal reputation badge. Reinstatement evidence does not create a new access grant.
- What standing can be derived for this subject, scope and policy version from active decision records? state
- Which stale, missing, stayed or overturned inputs prevent a reliable standing projection? quality
- Which conditions and authorized verification support reinstatement and which separate grant decision remains necessary? authority
Stewardship and exchange Protect evidence and preserve adoption limits.
Record stewardship
Balance protected evidence with lawful storage limits. Keep minimal authorized continuity metadata while applying disposition rules to payloads, copies and projections.
Retention holds and restricted views
Balance protected evidence with lawful storage limits. Keep minimal authorized continuity metadata while applying disposition rules to payloads, copies and projections.
- Which retention schedule, trigger, scoped hold and disposition authority apply to each evidence or case record? retention
- What personal or sensitive information is necessary in each permitted view and how are redactions and onward disclosure controlled? privacy
- How are corrections and authorized erasure propagated to copies and derived standing while lawful continuity evidence remains? lifecycle
Interoperability and assurance
Map concepts explicitly and report losses. This research structure neither implements an access engine nor certifies source, legal or runtime conformance.
Mappings and adoption gates
Map concepts explicitly and report losses. This research structure neither implements an access engine nor certifies source, legal or runtime conformance.
- Which pinned mappings preserve policy decisions, obligations, evidence lineage and timestamp semantics in export? interoperability
- Which profile and runtime restrictions prevent a local record operation from triggering an external enforcement action? constraint
- Which adversarial fixtures and independent reviews are still required before this profile is operationally accepted? validation
Classifiers Filled
- Family
- World Models
- Category
- Cross-cutting context
- Entry kind
- mixin
- Navigation path
- NAV.XCT.ENF
- Domain
- XCT.ENF
- Industry
- Cross-industry
- Tags
- accessbreachenforcementxct.enf
- Also called
- S7
What it is Filled
A host-attached mixin for resources, agreements or cases that need access-breach accountability. The attachment identifies its host, authority profile and local assertions. It references separately mastered signals, cases, decisions, evidence and grants. It records allegations, assessments and effects without operating access controls, imposing sanctions or deciding legal rights. All structure and local functions are proposed research design.
In scope
- Host and policy revision binding; signals, disputed assertions and investigation references
- Authority-qualified findings, precautionary measures, sanctions, notification assessment and remedies
- Scoped standing, reinstatement evidence, review, retention and permitted projections
Out of scope
- Access policy authoring, identity and consent masters, raw audit log ownership, incident command and court or arbitration case management
- Executing revocation, surveillance, penalties, payments, notices or erasure; tactical physical enforcement, detention or controlled-item procedures
- Universal legal breach definitions, automatic guilt, cross-context reputation scores or executable compliance certification
Why it exists Filled
Attach evidence-qualified access violation, enforcement and redress records to a host without taking over its identity or authority.
Distinguishing features Derived, awaiting review
- Unlike WM-XCT-002 Access Contract / Consent: Reference the effective policy or grant revision. A breach attachment neither creates consent nor changes a grant.
- Unlike WM-XCT-004 Access Audit: Logs and proofs remain audit-owned. The attachment records evidence references and assessment status; a log entry is not a proven violation.
- Unlike WM-ACT-019 Incident / Emergency: Response coordination is external. Precautionary containment can precede a responsibility determination and must not be recorded as a punitive sanction by inference.
- Unlike WM-POL-009 Court / Arbitration Case and WM-POL-010 Dispute Forum: Legacy A19 is ambiguous across case and forum successors. Reference a case for a proceeding and a forum for authority; do not merge either master into this mixin.
- Unlike WM-XCT-001 Ownership / Stewardship and WM-POL-014 Rights / Entitlements: Legacy S1 is split across stewardship and rights. Custody of the attachment does not prove substantive ownership or entitlement.
- Unlike WM-XCT-035 Retention / Disposition and WM-XCT-005 Privacy Aggregation Floor: Use external retention rules and separately approved disclosure profiles. Case closure does not erase evidence automatically and an aggregate view is not automatically anonymous.
Note: Derived from boundary notes against neighbouring models.
What robots and AI may and may not do Derived, awaiting review
Must not
- No automated attribution of guilt, public accusation, universal standing score or implicit grant modification
- Deny by default for attachment reads and writes unless the host policy explicitly authorizes purpose, role, scope and record view.
- This is the proposed local storage rule, not a claim that every XACML enforcement profile is deny-biased.
May
- Record a qualified signal: Proposed and unimplemented. Append a local observation without establishing a breach.
- Link evidence and contrary material: Proposed and unimplemented. Record evidence lineage and evaluation links while leaving the source master unchanged.
- Record a determination reference: Proposed and unimplemented. Append an authorized external determination for one allegation; do not adjudicate guilt.
- Record a measure result: Proposed and unimplemented. Record the evidence of an external measure, notice or remedy operation; do not execute it.
- Project scoped standing: Proposed and unimplemented. Compute a proposed local view from eligible evidence-qualified records, with no grant changes.
- Validate a restricted export: Proposed and unimplemented. Check a proposed evidence view and mapping for completeness and access before local serialization.
Note: Derived from functions, policies, CRUD and access rules; prohibitions were not authored for agents as such.
Moral aspects Derived, awaiting review
- Privacy and records custodian
- This is the proposed local storage rule, not a claim that every XACML enforcement profile is deny-biased.
- Access policy authoring, identity and consent masters, raw audit log ownership, incident command and court or arbitration case management
- Executing revocation, surveillance, penalties, payments, notices or erasure; tactical physical enforcement, detention or controlled-item procedures
- WM-XCT-002 Access Contract / Consent
- A breach attachment neither creates consent nor changes a grant.
- WM-XCT-035 Retention / Disposition and WM-XCT-005 Privacy Aggregation Floor
Note: Sentences mentioning harm, privacy, consent or similar, collected from the specification.
Owners Filled
Steward
Identify the responsible enforcement registrar role and host custodian without using company names as owners
Roles
- Enforcement registrar
- Maintain host bindings, case references and qualified record revisions
- Investigator
- Collect permitted evidence and record uncertainty and contrary material
- Authorized decision reviewer
- Verify competence, reasons, measure scope and challenge handling
- Remedy verifier
- Evaluate completion evidence without granting access or absolving responsibility
- Privacy and records custodian
- Approve restricted views, retention schedules and disposition holds
- Independent assessor
- Evaluate mappings, adversarial fixtures and remaining assurance gaps
Links to other meta-models Filled
references
- WM-XCT-002 - Candidate binding to the effective access instrument; resolve its identity and revision before use.
- WM-XCT-004 - Candidate binding to audit evidence masters; do not copy their lifecycle.
- WM-XCT-001 - Candidate custodian and stewardship binding; substantive rights remain separately evidenced.
- WM-POL-014 - Candidate rights and entitlement reference when relevant; legacy S1 does not select a unique successor.
- WM-ACT-019 - Candidate incident response context; operational command remains external.
- WM-POL-009 - Optional external adjudication case; legacy A19 also refers to a forum, so resolve explicitly.
- WM-POL-010 - Optional forum authority reference distinct from a proceeding.
- WM-XCT-035 - Candidate retention and disposition profile with scoped legal holds.
- WM-XCT-005 - Candidate aggregate disclosure policy; no automatic anonymity guarantee.
aligned
- ODRL 2.2 - Conceptual policy, duty and remedy alignment; not a mapping implementation or legal judgment.
- XACML 3.0 - Conceptual decision and enforcement-point distinction; selected bias and obligations need a runtime profile.
- PROV-O - Conceptual evidence derivation and attribution; not a truth or authority certificate.
neighbor
- WM-XCT-002 Access Contract / Consent - Reference the effective policy or grant revision. A breach attachment neither creates consent nor changes a grant.
- WM-XCT-004 Access Audit - Logs and proofs remain audit-owned. The attachment records evidence references and assessment status; a log entry is not a proven violation.
- WM-ACT-019 Incident / Emergency - Response coordination is external. Precautionary containment can precede a responsibility determination and must not be recorded as a punitive sanction by inference.
- WM-POL-009 Court / Arbitration Case and WM-POL-010 Dispute Forum - Legacy A19 is ambiguous across case and forum successors. Reference a case for a proceeding and a forum for authority; do not merge either master into this mixin.
- WM-XCT-001 Ownership / Stewardship and WM-POL-014 Rights / Entitlements - Legacy S1 is split across stewardship and rights. Custody of the attachment does not prove substantive ownership or entitlement.
- WM-XCT-035 Retention / Disposition and WM-XCT-005 Privacy Aggregation Floor - Use external retention rules and separately approved disclosure profiles. Case closure does not erase evidence automatically and an aggregate view is not automatically anonymous.
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Filled
- Authoritative master-system identifier and namespace
- Owner-issued stable record identifier scoped to host and attachment
- Content digest as integrity aid only, never sufficient subject identity
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Filled
- Record a qualified signal: Proposed and unimplemented. Append a local observation without establishing a breach.
- Link evidence and contrary material: Proposed and unimplemented. Record evidence lineage and evaluation links while leaving the source master unchanged.
- Record a determination reference: Proposed and unimplemented. Append an authorized external determination for one allegation; do not adjudicate guilt.
- Record a measure result: Proposed and unimplemented. Record the evidence of an external measure, notice or remedy operation; do not execute it.
- Project scoped standing: Proposed and unimplemented. Compute a proposed local view from eligible evidence-qualified records, with no grant changes.
- Validate a restricted export: Proposed and unimplemented. Check a proposed evidence view and mapping for completeness and access before local serialization.
Hazards and failure modes optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Derived, awaiting review
- PROV-O: The PROV Ontology
Context of use required Filled
- NIST publications are control and incident-response guidance, not a universal legal mandate
- EDPB guidance and Charter Article 47 are bounded EU examples; applicability and jurisdiction must be supplied by the adopting profile
Sources Filled
- ODRL Information Model 2.2 - World Wide Web Consortium
- eXtensible Access Control Markup Language Version 3.0 - OASIS Open
- Incident Response Recommendations and Considerations for Cybersecurity Risk Management - National Institute of Standards and Technology
- Security and Privacy Controls for Information Systems and Organizations - National Institute of Standards and Technology
- Guidelines 9/2022 on personal data breach notification under GDPR - European Data Protection Board
- PROV-O: The PROV Ontology - World Wide Web Consortium
- Date and Time on the Internet: Timestamps - Internet Engineering Task Force
- EU Charter Article 47 - Right to an effective remedy and to a fair trial - European Union Agency for Fundamental Rights
Open questions
- Complete direct source checks, version reconciliation and qualified current-law applicability review without treating HTTP success as claim verification.
- Implement and test profiles for mixed outcomes, uncertain authority, early notification, partial effects, stayed sanctions, stale standing, overturned allegations and lawful scoped disposal.
- Restore independent external review before canonical or publishable-draft promotion.
- Independent second-provider review is absent under the owner waiver
- Direct HTTP checks were not attempted under the owner-reported sandbox block; no HTTP status measured
- SP 800-53 release 5.2.0 is announced but changes are not reconciled with the selected 2020 PDF
- Current consolidated law, sector-specific sanctions, employment rules and physical access profiles require qualified review
- Candidate object fields lack nested schemas, executable calendars, pinned neighbor interfaces and acceptance fixtures
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-xct-007-access-breach-enforcement/spec.yaml