# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "research-draft", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-29T09:28:01Z", "synthesisSha256": "251f77bc8b044797ff027753e4c1f8cb7c99ecfd01567e40d31525df61a9cb85", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-XCT-013", "registryId": "vr.wm-xct-013", "name": "Registry Pattern", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "pattern", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.REG" ], "tags": [ "registry", "pattern", "xct.reg" ], "status": "research draft" }, "canonicalUrl": "https://ver.cy/models/wm-xct-013-registry-pattern/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-013", "model": { "registry_id": "vr.wm-xct-013", "model_id": "WM-XCT-013", "name": "Registry Pattern", "entry_kind": "pattern", "purpose": "Give an agent the format-neutral context needed to understand, constitute, inspect and operate an authoritative register: what subject matter a register admits, how entries are composed and identified, what status and ordering they carry, what effect registration produces in the world, and what may be inspected, searched or certified — while delegating identifier, provenance, ownership, access, audit, evidence, status, version, application, decision, event, federation, projection, mandate and dispute semantics to sibling models.", "scope_statement": "The pattern covers the register as an authoritative book and the registry that operates it. It owns register constitution (field of application, item classes, entry model, registration policy), the entry record and its supersession and priority ordering, the registration act that changes the book, the effect and reliance regime attached to registration, the publicity/search/extract surface, and register-level assurance and currency measures. It does not own any machinery that a linked model already governs; where a concern is target-owned this model carries only the binding, the subject-specific parameters and the reference.", "in_scope": [ "Constitution of a register: field of application, item classes, entry content model and registration policy strictness", "Register entries as authoritative records: composition, subject binding, status binding and temporal validity", "Registration acts (addition, clarification, amendment, supersession, retirement, invalidation, correction, cancellation, lapse) and their authority basis", "Registration ordering and priority stamp, including the rule that order of registration can determine rank", "Effect of registration: constitutive, declaratory, evidentiary-presumption, priority-conferring or opposability effect and its commencement instant", "Publicity regime classification per register and per attribute, index and search surface, certified extract attestation, and fee/cost-recovery basis", "Register-level assurance: rectification regime, liability and indemnity posture, contested marking, coverage and currency measures", "Registry instance hosting one or more registers, registrar continuity and succession, and alignment bindings to external registry vocabularies" ], "out_of_scope": [ "Identifier scheme syntax, allocation, lifecycle and resolution (WM-XCT-011)", "Provenance agents, derivations and source lineage semantics (WM-XCT-012)", "Ownership transfer, delegation and stewardship lifecycle (WM-XCT-001)", "Authorization, purpose, consent, party and grant lifecycle, and runtime access decisions (WM-XCT-002)", "Audit event schema, ordering, integrity and audit retention (WM-XCT-004)", "Evidence custody, verification workflow, support, challenge and rationale semantics (WM-XCT-028)", "Generic status vocabulary, transition rules and lifecycle history (WM-XCT-021)", "Version identity, diffs and change-history semantics (WM-XCT-022)", "Application intake, applicant payload and request lifecycle (WM-REC-009)", "Decision outcome, reasons, approval evidence and signoff (WM-REC-010)", "Event ordering, replay, integrity proof and event retention (WM-XCT-015)", "Federation authority topology, routing, mirroring, freshness and drift (WM-XCT-018)", "Projection selection, transformation, grain, compilation and runtime disclosure enforcement (WM-XCT-003)", "Registry mandate issuance, jurisdiction and mandate lifecycle (WM-POL-013)", "Dispute forum procedure, hearings and adjudication (WM-POL-010)", "Domain-specific register content such as parcel geometry, civil-status facts or licence conditions" ], "boundary_notes": [ { "neighbor": "WM-XCT-011 Identifier scheme", "distinction": "This model states which governed scheme an entry identifier is drawn from, whether values may be reused after retirement, and how the identifier is bound to an entry; syntax, allocation procedure and resolution stay in WM-XCT-011. RFC 8126 treats reclamation of assigned values as a change-control question, which reinforces that the reuse rule is register policy while the value space is scheme-owned.", "source_refs": [ "SRC-003", "SRC-002" ] }, { "neighbor": "WM-XCT-028 Evidence", "distinction": "This model owns only the evidentiary requirement specification — which evidence classes an item class demands before an act may be applied — and the reference from entry to evidence. Custody, verification workflow, sufficiency challenge and rationale remain WM-XCT-028. The previous R1 'evidence' bundle with a verification layer is therefore deliberately removed.", "source_refs": [ "SRC-005", "SRC-009" ] }, { "neighbor": "WM-REC-009 Application record and WM-REC-010 Decision record", "distinction": "Lodgement payload, applicant identity and request lifecycle belong to WM-REC-009; outcome, reasons and signoff belong to WM-REC-010. What remains here is the registration act itself — the mutation of the book — plus the ordering stamp attached at lodgement, because that stamp is what confers rank inside the register.", "source_refs": [ "SRC-005", "SRC-012" ] }, { "neighbor": "WM-XCT-003 Projection and disclosure shape", "distinction": "The shape, field selection and grain of a public view, extract or bulk view, and its runtime enforcement, are WM-XCT-003 and its evaluator. This model carries only the publicity classification of register content and the registrar's attestation that an extract corresponds to the register at a stated instant.", "source_refs": [ "SRC-004", "SRC-009" ] }, { "neighbor": "WM-XCT-021 Status and lifecycle", "distinction": "Status vocabulary, transition legality and lifecycle history are WM-XCT-021. This model binds register-specific meanings to those states — notably which states remain publicly exposed and which cease to support new use while being retained for interpreting older data, as ISO 19135 requires for superseded, retired and invalid items.", "source_refs": [ "SRC-001", "SRC-008" ] }, { "neighbor": "WM-XCT-004 Audit and WM-XCT-015 Event register", "distinction": "Registration acts and disclosures generate audit and domain events, but this model neither defines their schema nor guarantees their ordering, integrity proof or retention; it only hands off the change notification and the disclosure signal.", "source_refs": [ "SRC-004", "SRC-011" ] }, { "neighbor": "WM-POL-013 Registry mandate and WM-POL-010 Dispute forum", "distinction": "Registrar powers, jurisdiction and mandate lifecycle sit in WM-POL-013; objection and appeal procedure sits in WM-POL-010. Here the register records only that its field of application is derived from a referenced mandate, and that an entry carries a contested marking pointing to a case.", "source_refs": [ "SRC-002", "SRC-009" ] }, { "neighbor": "Domain registers that specialize this pattern", "distinction": "Cadastres, civil registers, identity registers, licence books, security-rights registries and protocol-parameter registries inherit this skeleton inbound. Domain payload — parcel geometry, civil-status facts, collateral descriptions, protocol semantics — stays in the domain model; only the register skeleton is factored here.", "source_refs": [ "SRC-003", "SRC-005", "SRC-009" ] }, { "neighbor": "ISO 15489 records management", "distinction": "Authenticity, reliability, integrity and usability are general record properties applying to any records system. This model uses them as assurance criteria for register content but does not restate general records-management process or disposition-authority machinery.", "source_refs": [ "SRC-011" ] } ] }, "sources": [ { "id": "SRC-001", "title": "ISO 19135-1:2015 Geographic information — Procedures for item registration — Part 1: Fundamentals", "organization": "International Organization for Standardization (ISO/TC 211)", "url": "https://www.iso.org/standard/54721.html", "version_or_date": "First edition, 2015 (replaces ISO 19135:2005)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:05:00Z", "relevance": "Normative reference model for registers: register, register item, item class, register manager, register owner, control body, submitting organization, item identifier, and item status values (notValid, valid, superseded, retired, invalid) with retention of superseded and retired items for interpreting earlier data." }, { "id": "SRC-002", "title": "ISO/TC 211 good practice: How to set up an ISO register based on ISO 19135", "organization": "ISO/TC 211 Geographic information/Geomatics", "url": "https://committee.iso.org/sites/tc211/home/resolutions/isotc-211-good-practices/--how-to-set-up-an-iso-register.html", "version_or_date": "ISO/TC 211 good practices page, accessed 2026-08-28", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:06:00Z", "relevance": "Operational governance of a register: register owner versus register manager/registration authority versus control body versus submitting organization, qualification and continuity requirements for the manager, proposal actions (add, clarify, supersede, retire), identifier assignment as the minimum delegated registration service, and bounded response deadlines." }, { "id": "SRC-003", "title": "RFC 8126 / BCP 26 — Guidelines for Writing an IANA Considerations Section in RFCs", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc8126.html", "version_or_date": "June 2017, Best Current Practice 26 (obsoletes RFC 5226)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:07:00Z", "relevance": "Registration policy ladder (Private Use, Experimental, Hierarchical Allocation, First Come First Served, Expert Review, Specification Required, RFC Required, IETF Review, Standards Action, IESG Approval), required registry definition fields, designated-expert review criteria, change-controller fields, provisional registration, deprecation/obsoletion, and the risks of reclaiming assigned values." }, { "id": "SRC-004", "title": "Directive (EU) 2017/1132 relating to certain aspects of company law (codification)", "organization": "European Parliament and Council of the European Union (EUR-Lex)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32017L1132", "version_or_date": "14 June 2017, OJ L 169, 30.6.2017, p. 46", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:08:00Z", "relevance": "Statutory register obligations: a file per company in a central/commercial/companies register, a unique identifier for cross-border identification, mandatory electronic filing, certified and uncertified copies, opposability of disclosed documents to third parties, fees limited to administrative cost with core particulars free, and the system of interconnection of registers with a standard message format." }, { "id": "SRC-005", "title": "UNCITRAL Model Law on Secured Transactions with Guide to Enactment (including the Model Registry Provisions)", "organization": "United Nations Commission on International Trade Law (UNCITRAL)", "url": "https://uncitral.un.org/sites/uncitral.un.org/files/media-documents/uncitral/en/19-08779_e_ebook.pdf", "version_or_date": "Model Law adopted 2016; Guide to Enactment 2017; UN publication issued 2019", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:10:00Z", "relevance": "Notice-based registration in a public searchable registry: registration without lodging the underlying agreement, registrant identity and authorization, minimum notice content, time of effectiveness, limited periods of effectiveness with extension, amendment and cancellation notices, indexing by grantor identifier, narrow rejection grounds, registry-error correction, removal of expired information from the public record with archival, and registrar liability and fee limits." }, { "id": "SRC-006", "title": "Judgment of the Court (Grand Chamber), Joined Cases C-37/20 and C-601/20, WM and Sovim SA v Luxembourg Business Registers", "organization": "Court of Justice of the European Union (via EUR-Lex)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A62020CJ0037", "version_or_date": "22 November 2022", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:12:00Z", "relevance": "Authoritative limit on register publicity: general public access to beneficial-ownership information was declared invalid as a serious interference with Charter Articles 7 and 8 that went beyond what is strictly necessary; legitimate-interest gating, defined data categories, case-by-case exemptions and accountability for accessors are treated as the safeguards that publicity design must supply." }, { "id": "SRC-007", "title": "IANA — Protocol Registration and Requests", "organization": "Internet Assigned Numbers Authority / Public Technical Identifiers", "url": "https://www.iana.org/help/protocol-registration", "version_or_date": "IANA operational guidance page, accessed 2026-08-28", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-28T09:13:00Z", "relevance": "First-party account of an operating registry: how registration requests are submitted and expert-reviewed, early allocation, what a registry definition contains (name, group, registration procedure, per-entry fields, initial assignments), publication at stable URLs, change controller assignment, and re-review when a request materially changes." }, { "id": "SRC-008", "title": "INSPIRE Registry (EU Vocabularies)", "organization": "Publications Office of the European Union / European Commission", "url": "https://op.europa.eu/en/web/eu-vocabularies/inspire-registry", "version_or_date": "Operational management transferred to the Publications Office as of 1 July 2026; legal basis Directive 2007/2/EC and Commission Regulation (EU) No 1089/2010", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:14:00Z", "relevance": "A registry instance hosting many registers (themes, code lists, CRS, layers, media types, status, reference documents), with persistent resolvable item URIs surviving operator change, multilingual labels and definitions, a dedicated status register, deprecated items retained for backward compatibility, API and dataset access, and a published feedback channel for change proposals." }, { "id": "SRC-009", "title": "Land Registration Act 2002 (c. 9)", "organization": "United Kingdom Parliament (legislation.gov.uk)", "url": "https://www.legislation.gov.uk/ukpga/2002/9/contents", "version_or_date": "2002 c. 9, as revised on legislation.gov.uk", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:16:00Z", "relevance": "A title-registration regime: register of title (s.1), conclusiveness of registration as proprietor (s.58), inspection and official copies (s.66), evidential value of official copies (s.67), the index (s.68), historical information (s.69), priority protection by official search (s.72), alteration and rectification of the register (Schedule 4) and indemnity for loss (Schedule 8)." }, { "id": "SRC-010", "title": "ISO/IEC 11179-6:2023 Information technology — Metadata registries (MDR) — Part 6: Registration", "organization": "ISO/IEC JTC 1/SC 32", "url": "https://www.iso.org/standard/78916.html", "version_or_date": "2023 edition (supersedes ISO/IEC 11179-6:2015)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:18:00Z", "relevance": "Independent registry-governance model: administered items, registration authority, submitting organization and stewardship, internationally unique item identification, and the distinction between registration status (lifecycle and documentation categories signalling metadata quality and usage preference) and administrative status (position in the registration authority's handling of a request)." }, { "id": "SRC-011", "title": "ISO 15489-1:2016 Information and documentation — Records management — Part 1: Concepts and principles", "organization": "ISO/TC 46/SC 11", "url": "https://www.iso.org/standard/62542.html", "version_or_date": "Second edition, 2016", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:19:00Z", "relevance": "Characteristics of an authoritative record — authenticity, reliability, integrity and usability — plus records controls including access and permission rules and disposition authorities, used here as assurance criteria for register content and as the boundary for retention execution." }, { "id": "SRC-012", "title": "Convention on International Interests in Mobile Equipment (Cape Town Convention) and the International Registry", "organization": "International Institute for the Unification of Private Law (UNIDROIT)", "url": "https://www.unidroit.org/instruments/security-interests/cape-town-convention/", "version_or_date": "Adopted 16 November 2001, Cape Town", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-28T09:21:00Z", "relevance": "A transnational notice-based electronic registry with a separated Supervisory Authority and Registrar, registrations searchable in chronological order of receipt, priority determined by order of registration irrespective of knowledge, electronic search certificates on demand, and defined registrar liability for loss caused by registry error, omission or malfunction." } ], "structure": { "bundles": [ { "id": "register-constitution", "name": "Register constitution", "description": "What brings a register into existence and fixes what it may contain: its identity as a book, the subject matter it admits, who may submit, and the item classes and entry model it publishes.", "rationale": "Every authoritative register cited — ISO 19135 registers, IANA protocol registries, INSPIRE registers, company registers, security-rights registries and title registers — is constituted before any entry exists, by a definition that fixes field of application, item classes, entry content and who may propose. Without this bundle an agent cannot tell whether a given fact is registrable at all.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-007", "SRC-008" ], "layers": [ { "id": "register-definition", "name": "Register definition", "description": "The register as a governed object: its identity and constitution, the boundary of what it covers, and the policy controlling who may cause entries to exist.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-008" ], "findings": [ { "id": "register-identity-and-constitution", "name": "Register identity and constituting act", "description": "A register is a named, individually identified book of entries constituted by an instrument that names an accountable keeper and, where public, derives its powers from a referenced mandate. ISO/TC 211 separates the register owner from the register manager and the control body; UNIDROIT separates the Supervisory Authority from the Registrar; INSPIRE shows the operator can change while item URIs persist. The constitution is therefore distinct from both the operator and the storage.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012" ], "questions": [ { "id": "q-register-constituting-instrument", "text": "Which instrument constitutes this register and what does it authorise the register to contain?", "kind": "authority", "answer_data": [ "Reference to the constituting instrument or mandate record (WM-POL-013)", "Instrument type: statute, regulation, standard, charter, contract or internal policy", "Date of entry into force of the constitution" ] }, { "id": "q-register-distinct-identity", "text": "What identifier distinguishes this register from every other register, including from the registry that operates it?", "kind": "identity", "answer_data": [ "Register identifier drawn from a governed scheme (binding to WM-XCT-011)", "Register short name and official title", "Operating registry identifier hosting the register" ] }, { "id": "q-register-role-separation", "text": "Which distinct parties hold register ownership, register management and control-body review for this register?", "kind": "ownership", "answer_data": [ "Owner party reference (resolved via WM-XCT-001)", "Register manager / registrar party reference", "Control body or designated expert reference where review is delegated" ] }, { "id": "q-register-operator-succession", "text": "What happens to register identity and item references if the operating organisation changes?", "kind": "lifecycle", "answer_data": [ "Persistence commitment for register and item references", "Successor-operator designation rule", "Continuity conditions required of a manager (legal entity, funding, minimum commitment period)" ] } ], "data_elements": [ { "id": "de-register-identifier", "name": "Register identifier", "description": "Stable identifier of the register itself, drawn from a governed scheme owned by WM-XCT-011.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "de-constituting-instrument-ref", "name": "Constituting instrument reference", "description": "Reference to the statute, regulation, standard or charter that establishes the register and its powers.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-012" ] }, { "id": "de-register-role-binding", "name": "Register role binding", "description": "Binding of owner, manager/registrar and control body roles to accountable parties resolved outside this model.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-012" ] } ], "artifacts": [ { "id": "register-constitution-record", "name": "Register constitution record", "description": "The durable statement of what this register is: identity, constituting instrument reference, role bindings, operating language and persistence commitment.", "media_or_form": [ "structured record", "normative text", "registry metadata entry" ], "serial": false, "identity_strategy": "Register identifier from the governed scheme; where no master-system identifier exists, a Dimension-assigned UUID bound to the constituting instrument reference.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "register-field-of-application", "name": "Field of application and completeness claim", "description": "The register's declared subject-matter boundary, its territorial or jurisdictional reach, and how strong a completeness claim it makes. A register that claims to hold every instance of its subject supports negative inference ('not registered means not existing'); one that does not must say so, because search results are otherwise misread.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-009" ], "questions": [ { "id": "q-register-subject-boundary", "text": "What classes of item does this register admit, and what closely similar items does it explicitly exclude?", "kind": "classification", "answer_data": [ "Admitted subject-matter description", "Explicit exclusion list with the register that holds each excluded class", "Derivation of the boundary from the constituting mandate" ] }, { "id": "q-register-territorial-reach", "text": "Over which jurisdiction, territory or namespace does this register claim authority?", "kind": "spatial", "answer_data": [ "Jurisdiction or territory code", "Namespace or value-space covered where the register is non-geographic", "Overlap statement with neighbouring registers of the same kind" ] }, { "id": "q-register-completeness-claim", "text": "Does absence of an entry permit a negative inference, and under what conditions?", "kind": "constraint", "answer_data": [ "Completeness claim level: exhaustive, compulsory-with-exceptions, voluntary or partial", "Known coverage gaps and legacy backlog statement", "Wording that must accompany a nil search result" ] }, { "id": "q-register-mandatory-trigger", "text": "What events compel registration, and what remains voluntary?", "kind": "requirement", "answer_data": [ "Compulsory registration triggers", "Voluntary registration eligibility", "Consequence of non-registration (unenforceability, non-opposability, penalty or none)" ] } ], "data_elements": [ { "id": "de-field-of-application", "name": "Field of application", "description": "Declared subject-matter scope of the register expressed as admitted item classes plus explicit exclusions.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "de-completeness-claim", "name": "Completeness claim", "description": "Coded strength of the register's coverage claim, controlling whether absence of an entry is meaningful.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-009" ] }, { "id": "de-jurisdictional-reach", "name": "Jurisdictional reach", "description": "Territory, jurisdiction or value-space over which the register asserts authority.", "value_kind": "code", "cardinality": "1..n", "required": false, "source_refs": [ "SRC-004", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Field of application, completeness claim and jurisdictional reach are declarative properties of the constitution record rather than separately issued objects; minting a second artifact for them would split one authoritative statement across two documents and invite divergence." }, { "id": "registration-policy-and-submission-rights", "name": "Registration policy and submission rights", "description": "The rule fixing who may cause an entry to exist and how much review precedes it. RFC 8126 sets out an explicit strictness ladder from Private Use through First Come First Served and Expert Review to Standards Action, advises choosing the least strict policy that suits the register, and requires a named change controller; UNCITRAL by contrast permits registration by any authorised registrant without document lodgement.", "source_refs": [ "SRC-003", "SRC-005", "SRC-007", "SRC-002" ], "questions": [ { "id": "q-registration-policy-strictness", "text": "Which registration policy governs each range or class of this register, and why is that strictness chosen?", "kind": "decision", "answer_data": [ "Policy code per item class or value range", "Justification for any policy stricter than the minimum needed", "Reviewer designation where expert review applies" ] }, { "id": "q-who-may-submit", "text": "Who is entitled to submit a registration request, and must the submitter be the affected subject?", "kind": "authority", "answer_data": [ "Eligible submitter classes", "Whether third-party submission on behalf of a subject is permitted", "Authorization requirement linking submitter to subject" ] }, { "id": "q-change-controller-per-entry", "text": "Who controls later changes to an individual registered value once it exists?", "kind": "ownership", "answer_data": [ "Change controller value per entry", "Escalation path when the change controller is unreachable or defunct", "Whether change control differs from original submitter" ] }, { "id": "q-provisional-registration", "text": "May an entry be registered provisionally and later converted to permanent status?", "kind": "state", "answer_data": [ "Provisional registration permitted flag", "Conversion criteria to permanent status", "Maximum provisional duration" ] } ], "data_elements": [ { "id": "de-registration-policy", "name": "Registration policy", "description": "Coded policy controlling how a registration request is reviewed before it may change the register.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "de-submitter-eligibility-rule", "name": "Submitter eligibility rule", "description": "Rule stating which classes of party may submit a registration request for a given item class.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "de-change-controller", "name": "Change controller", "description": "Party entitled to authorise later modification of a specific registered value.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Registration policy is a normative parameter of the register definition and of each item class, consumed by the admission function; it produces no separately issued object, and modelling it as an artifact would duplicate the constitution record it belongs to." } ] }, { "id": "item-class-and-entry-model", "name": "Item class and entry model", "description": "The typed shape of what may be registered: item classes with their required attributes, and the identifier binding that gives each entry its place in the book.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008" ], "findings": [ { "id": "item-class-definition", "name": "Item class and required attribute set", "description": "ISO 19135 organises a register into item classes, each fixing the attributes a conforming item must carry; RFC 8126 likewise requires a registry definition to state the required information, size, format and syntax of entries plus initial assignments and reservations. Item classes are the register's contract with submitters and consumers alike.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-item-class-attributes", "text": "For each item class, which attributes are mandatory, which are optional, and what syntax constrains them?", "kind": "composition", "answer_data": [ "Attribute list per item class with cardinality", "Value syntax, size or format constraint per attribute", "Controlled vocabulary reference where an attribute is coded" ] }, { "id": "q-item-class-reserved-values", "text": "Which values in this register are reserved, pre-assigned or set aside for private use?", "kind": "constraint", "answer_data": [ "Reserved and pre-assigned value ranges", "Private or experimental use range with its non-registration rule", "Initial assignment table at register creation" ] }, { "id": "q-item-class-extension", "text": "May an item class be extended by adopters, and what stays fixed under extension?", "kind": "interoperability", "answer_data": [ "Extensibility flag per item class", "Attributes that may not be overridden by an extending domain register", "Extension namespace rule" ] }, { "id": "q-item-class-language", "text": "In which languages must item names and definitions be supplied, and which language is authoritative?", "kind": "quality", "answer_data": [ "Operating language of the register", "Languages in which labels and definitions are published", "Rule identifying the authoritative language on divergence" ] } ], "data_elements": [ { "id": "de-item-class", "name": "Item class", "description": "Named class of registrable item within a register, carrying its own required attribute set and admission rules.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "de-required-attribute-spec", "name": "Required attribute specification", "description": "Per-attribute statement of cardinality, value kind and syntax constraint for a given item class.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "de-reserved-value-range", "name": "Reserved value range", "description": "Range of values withheld from ordinary assignment, including private-use and experimental ranges.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "item-class-specification", "name": "Item class specification", "description": "Published definition of one item class: required and optional attributes, syntax constraints, reserved ranges, extensibility and language rules.", "media_or_form": [ "structured schema", "normative text", "registry metadata entry" ], "serial": false, "identity_strategy": "Item class identifier scoped to the register identifier; governed IRI where the register publishes resolvable class URIs.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "entry-identifier-binding", "name": "Entry identifier binding and reuse rule", "description": "Every entry carries an identifier that locates it in the book. ISO/TC 211 treats identifier assignment as the minimum service delegated to the register manager; ISO/IEC 11179-6 requires internationally unique item identification. What is register-owned here is the binding, the uniqueness scope and the reuse-after-retirement rule — RFC 8126 warns that reclaiming assigned values breaks deployed consumers.", "source_refs": [ "SRC-002", "SRC-003", "SRC-010", "SRC-008" ], "questions": [ { "id": "q-entry-identifier-scheme-binding", "text": "From which governed identifier scheme is an entry identifier drawn, and who assigns the value?", "kind": "identity", "answer_data": [ "Scheme reference resolved through WM-XCT-011", "Assigning role (register manager, submitter, or external authority)", "Point in the act at which the identifier is assigned" ] }, { "id": "q-entry-identifier-uniqueness-scope", "text": "Within what scope must an entry identifier be unique — the register, the registry, or globally?", "kind": "constraint", "answer_data": [ "Uniqueness scope code", "Composite key structure where uniqueness is scoped", "Collision handling rule" ] }, { "id": "q-entry-identifier-reuse", "text": "May an identifier be reassigned after its entry is retired or cancelled?", "kind": "exception", "answer_data": [ "Reuse permitted flag", "Quarantine period before any reuse", "Consultation requirement with prior assignee before reclamation" ] }, { "id": "q-entry-identifier-resolvability", "text": "Is an entry identifier resolvable to a published representation, and does resolution survive operator change?", "kind": "interoperability", "answer_data": [ "Resolution commitment statement", "Persistent URI pattern where published", "Behaviour of resolution for retired and superseded entries" ] } ], "data_elements": [ { "id": "de-entry-identifier", "name": "Entry identifier", "description": "Identifier locating a single entry within the register, bound from a scheme governed by WM-XCT-011.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-010" ] }, { "id": "de-identifier-reuse-rule", "name": "Identifier reuse rule", "description": "Register policy on whether and when a retired identifier value may be reassigned.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "This finding carries only a binding and two policy parameters onto entries whose record artifact is declared elsewhere; the identifier value space, its allocation and its resolution are owned by WM-XCT-011, so declaring a local identifier artifact would claim custody of a target model's asset." } ] } ] }, { "id": "entry-record", "name": "Entry record", "description": "The entry as the atomic authoritative record: what it contains, what it is about, what state and validity period it holds, and how entries relate to and rank against one another.", "rationale": "Across all sampled regimes the entry — not the file, the application or the decision — is the unit that carries authority, and the sampled sources converge on the same four questions about it: composition, subject binding, status and time, and ordering. ISO 19135 requires superseded and retired items to remain in the register to interpret older data; Cape Town makes order of registration decisive for priority.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-009", "SRC-012" ], "layers": [ { "id": "entry-content-and-subject", "name": "Entry content and subject binding", "description": "What an entry says and what it is about, including which of its fields are authoritative and which are merely carried.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-009" ], "findings": [ { "id": "entry-composition-and-subject", "name": "Entry composition and subject binding", "description": "An entry binds a content payload to a subject. UNCITRAL notices carry grantor and secured-creditor identifiers plus a collateral description sufficient for identification, without the underlying agreement; company registers hold a file of prescribed particulars per company. Not every field is equally authoritative: some are the registered fact, others are contact or administrative carriage.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-009" ], "questions": [ { "id": "q-entry-subject-identification", "text": "What real-world subject is this entry about, and how is that subject identified?", "kind": "identity", "answer_data": [ "Subject reference with the identifier scheme used", "Subject description sufficient for identification where no identifier exists", "Cardinality: one entry per subject, or many entries per subject" ] }, { "id": "q-entry-authoritative-fields", "text": "Which fields of the entry are the registered fact and which are administrative carriage?", "kind": "classification", "answer_data": [ "Per-field authority classification", "Fields excluded from any reliance claim", "Fields sourced from another register by reference rather than restated" ] }, { "id": "q-entry-subject-multiplicity", "text": "May one entry cover an aggregate of subjects, and how is the aggregate delimited?", "kind": "composition", "answer_data": [ "Aggregate entry permitted flag", "Delimitation rule for the aggregate", "Effect of a change to one member of the aggregate" ] }, { "id": "q-entry-payload-restatement", "text": "Does the entry restate content from a lodged instrument or only reference it?", "kind": "provenance", "answer_data": [ "Restatement versus reference policy per item class", "Reference to the source instrument held under WM-XCT-028", "Divergence rule when restated content conflicts with the source instrument" ] } ], "data_elements": [ { "id": "de-entry-subject-ref", "name": "Entry subject reference", "description": "Reference identifying the real-world subject the entry is about.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-entry-content-field", "name": "Entry content field", "description": "One field of the entry payload, classified as authoritative registered fact or administrative carriage.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "de-supporting-evidence-ref", "name": "Supporting evidence reference", "description": "Pointer to the evidence item grounding the entry; custody and challenge semantics remain in WM-XCT-028.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "register-entry-record", "name": "Register entry record", "description": "The authoritative record of one registered item: identifier, item class, subject binding, content fields, status binding, validity period and references to the acts that created and changed it.", "media_or_form": [ "structured record", "register page or file", "registry API resource" ], "serial": true, "identity_strategy": "Entry identifier assigned by the register manager from the bound governed scheme; serial position recorded separately from the identifier so that ordering does not depend on identifier arithmetic.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "entry-state-and-time", "name": "Entry state and time", "description": "The status an entry holds, what that status means for use and publication, and the several distinct times an entry carries.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-012" ], "findings": [ { "id": "entry-status-publication-effect", "name": "Entry status binding and publication consequence", "description": "ISO 19135 distinguishes notValid, valid, superseded, retired and invalid, exposes valid, superseded and retired publicly, keeps proposed and unaccepted items for management only, and retains no-longer-valid items so that data produced earlier can still be interpreted. INSPIRE similarly retains deprecated items for backward compatibility. The status vocabulary and its transitions are governed by WM-XCT-021; what is register-owned is the mapping from state to publication and to permitted use.", "source_refs": [ "SRC-001", "SRC-008", "SRC-003" ], "questions": [ { "id": "q-entry-status-vocabulary-binding", "text": "Which governed status vocabulary does this register bind to, and which of its values does it actually use?", "kind": "state", "answer_data": [ "Vocabulary reference resolved through WM-XCT-021", "Subset of values used by this register", "Local meaning statement for each used value" ] }, { "id": "q-status-publication-mapping", "text": "For each status value, is the entry exposed in the public face of the register?", "kind": "access", "answer_data": [ "Exposure flag per status value", "Statuses confined to management views", "Rule for exposing invalid or rejected items" ] }, { "id": "q-status-permitted-use", "text": "For each status value, may the entry still be used to produce new data or new reliance?", "kind": "constraint", "answer_data": [ "Permitted-use classification per status", "Retention justification for no-longer-valid entries", "Warning text that must accompany a non-current entry" ] }, { "id": "q-status-change-authority", "text": "Who may cause an entry's status to change, and does that differ by status value?", "kind": "authority", "answer_data": [ "Authorised role per status change", "Whether a control body or expert review is required", "Reference to the decision record authorising the change" ] } ], "data_elements": [ { "id": "de-entry-status-binding", "name": "Entry status binding", "description": "Binding of an entry to a value in the governed status vocabulary owned by WM-XCT-021.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "de-status-publication-rule", "name": "Status publication rule", "description": "Register-level mapping from a status value to whether entries in that status appear in public views and whether they support new use.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "The status vocabulary, its transition legality and its history are owned by WM-XCT-021; this finding contributes only a binding and a publication/use mapping, so it must not mint a status artifact of its own." }, { "id": "entry-temporal-model", "name": "Entry temporal model", "description": "An entry carries several times that must not be collapsed: when the act was received and stamped, when the entry became effective in the register, the period for which registration remains effective, and when the fact it records took place. UNCITRAL limits effectiveness to a stated period extendable by amendment; Cape Town makes registrations searchable in chronological order of receipt.", "source_refs": [ "SRC-005", "SRC-012", "SRC-004", "SRC-009" ], "questions": [ { "id": "q-entry-time-kinds", "text": "Which distinct time values does an entry carry, and which of them is decisive for effect?", "kind": "temporal", "answer_data": [ "Receipt or lodgement instant", "Registration/effectiveness instant", "Real-world event instant where different from registration", "Statement of which instant governs effect" ] }, { "id": "q-entry-effectiveness-period", "text": "Does registration lapse after a fixed period, and how is it extended?", "kind": "lifecycle", "answer_data": [ "Effectiveness period length or perpetual flag", "Extension mechanism and its deadline", "Consequence of lapse on effect and on publication" ] }, { "id": "q-entry-retroactivity", "text": "Can an entry take effect from a time earlier than its registration, and on what basis?", "kind": "exception", "answer_data": [ "Retroactive effect permitted flag", "Basis for backdating (priority protection window, court order, correction)", "Treatment of third parties who relied in the interval" ] }, { "id": "q-entry-as-at-reconstruction", "text": "Can the register state as at a past instant be reconstructed, and to what granularity?", "kind": "evidence", "answer_data": [ "As-at reconstruction supported flag", "Time granularity of reconstruction", "Reference to the version or event record supplying the history" ] } ], "data_elements": [ { "id": "de-receipt-instant", "name": "Receipt instant", "description": "RFC 3339 timestamp with seconds and explicit offset recording when the registration request was received by the registry.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-005" ] }, { "id": "de-registration-instant", "name": "Registration instant", "description": "RFC 3339 timestamp with seconds and explicit offset at which the entry became effective in the register.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-009" ] }, { "id": "de-effectiveness-period", "name": "Effectiveness period", "description": "Period for which the registration remains effective, where the regime imposes lapse rather than perpetual validity.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-effect-commencement-instant", "name": "Effect commencement instant", "description": "Instant from which the registered effect runs, which may precede the registration instant where backdating is permitted.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "These are timestamp and interval fields carried on the entry record artifact already declared; the reconstructed history itself is supplied by WM-XCT-022 and WM-XCT-015, so no separate temporal artifact may be claimed here." } ] }, { "id": "entry-relations-and-ordering", "name": "Entry relations and ordering", "description": "How entries succeed one another over time and how they rank against one another at a moment.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-012" ], "findings": [ { "id": "supersession-and-continuity", "name": "Supersession, retirement and continuity chains", "description": "ISO 19135 distinguishes replacement by an alternative (supersession) from simple withdrawal (retirement), and keeps both in the register. Continuity must be traceable in both directions, and registers of composite subjects additionally need split and merge relations so that a successor entry can be reached from any predecessor.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ], "questions": [ { "id": "q-supersession-linkage", "text": "When an entry is superseded, how is the successor entry linked and is the link bidirectional?", "kind": "relationship", "answer_data": [ "Superseded-by and supersedes reference pairs", "Whether both directions are stored or one is derived", "Behaviour when a successor is itself later superseded" ] }, { "id": "q-retirement-versus-supersession", "text": "What distinguishes retirement from supersession and from invalidation in this register?", "kind": "classification", "answer_data": [ "Definition of each outcome in register terms", "Which outcomes require a named successor", "Which outcomes assert that the entry was never validly made" ] }, { "id": "q-split-merge-continuity", "text": "How are split and merge of a registered subject represented across entries?", "kind": "composition", "answer_data": [ "Split and merge relation types supported", "Identifier policy for successor entries", "Rule for carrying effects and priority across a split or merge" ] }, { "id": "q-historical-entry-retrieval", "text": "Are closed entries still retrievable, and by which access route?", "kind": "retention", "answer_data": [ "Retrieval route for closed and historical entries", "Whether closed entries appear in ordinary search results", "Reference to the historical-information provision authorising retention" ] } ], "data_elements": [ { "id": "de-supersession-link", "name": "Supersession link", "description": "Directed reference from a superseded entry to the entry that replaces it, with the inverse relation where stored.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "de-continuity-relation-type", "name": "Continuity relation type", "description": "Coded relation expressing supersession, retirement, split, merge or cancellation between entries.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Continuity links are reference fields on entry records rather than independently issued objects, and the change history that reconstructs a chain over time is owned by WM-XCT-022, so no local artifact may be declared." }, { "id": "priority-rank-and-ordering", "name": "Registration ordering and priority rank", "description": "Where a register allocates rank, the order of registration is decisive: a registered interest takes priority over later registrations and over unregistered interests regardless of knowledge, and registrations are searchable in chronological order of receipt. Priority protection windows let a search freeze rank for a short period before the act is lodged. This ordering is register-owned and must not be confused with event-log ordering.", "source_refs": [ "SRC-012", "SRC-009", "SRC-005" ], "questions": [ { "id": "q-priority-basis", "text": "Does this register allocate rank, and is rank derived from time of registration or from another criterion?", "kind": "constraint", "answer_data": [ "Rank-allocating flag", "Basis of rank: receipt order, registration order, statutory class or none", "Whether knowledge of a competing interest affects rank" ] }, { "id": "q-priority-stamp-granularity", "text": "At what granularity is the ordering stamp recorded, and how are simultaneous receipts broken?", "kind": "measurement", "answer_data": [ "Timestamp granularity used for ordering", "Monotonic sequence number where timestamps can tie", "Tie-breaking rule and its authority" ] }, { "id": "q-priority-protection-window", "text": "Can a search or notice reserve rank before the substantive act is lodged?", "kind": "process", "answer_data": [ "Priority protection mechanism supported flag", "Protection period length", "Conditions under which protection is lost" ] }, { "id": "q-rank-carryover", "text": "What happens to rank when an entry is amended, corrected or superseded?", "kind": "exception", "answer_data": [ "Rank preservation rule per act type", "Cases in which amendment creates a new rank position", "Effect of rectification on the rank of intervening entries" ] } ], "data_elements": [ { "id": "de-ordering-stamp", "name": "Ordering stamp", "description": "Register-assigned position value combining an RFC 3339 receipt timestamp with a monotonic sequence number for tie-breaking.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-009" ] }, { "id": "de-priority-rank", "name": "Priority rank", "description": "Resolved rank of an entry relative to competing entries over the same subject, where the register allocates rank.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-priority-protection-ref", "name": "Priority protection reference", "description": "Reference to a search or notice that reserved rank ahead of a lodged act.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Rank and ordering stamps are computed properties recorded on the entry and act records already declared; the append-only sequencing infrastructure that can corroborate them belongs to WM-XCT-015, so this finding carries parameters only." } ] } ] }, { "id": "registration-act", "name": "Registration act", "description": "The act that changes the book: its typology, who may perform it, and the admission criteria and evidentiary requirements it must satisfy.", "rationale": "ISO/TC 211 enumerates proposal actions (add, clarify, supersede, retire); UNCITRAL adds amendment and cancellation notices with narrow rejection grounds; RFC 8126 adds deprecation and reclamation. The act is separable from the application that requested it and the decision that approved it, both of which are owned by sibling models, so it needs its own bounded treatment here.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ], "layers": [ { "id": "act-typology-and-authority", "name": "Act typology and authority", "description": "What kinds of change to the register exist, and who is competent to make each.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-012" ], "findings": [ { "id": "registration-act-typology", "name": "Registration act typology", "description": "The closed set of operations that can change a register: addition, clarification (a change that does not alter meaning), amendment, supersession, retirement, invalidation, cancellation, correction of registry error and lapse on expiry. Distinguishing clarification from amendment matters because only one of them disturbs reliance.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-009" ], "questions": [ { "id": "q-act-types-supported", "text": "Which act types can change this register, and which are unavailable by design?", "kind": "classification", "answer_data": [ "Supported act type codes", "Act types explicitly excluded and why", "Whether lapse occurs automatically or requires an act" ] }, { "id": "q-clarification-vs-amendment", "text": "How does this register distinguish a clarification that preserves meaning from an amendment that changes it?", "kind": "definition", "answer_data": [ "Criterion separating clarification from amendment", "Consequence of each for prior reliance and for rank", "Approval path required for each" ] }, { "id": "q-act-idempotence", "text": "What makes a submitted act a duplicate of one already applied?", "kind": "validation", "answer_data": [ "Duplicate detection key", "Behaviour on resubmission of an already applied act", "Whether duplicates are rejected or recorded as no-ops" ] }, { "id": "q-act-linkage-to-request", "text": "How does an applied act reference the request and the decision that authorised it?", "kind": "provenance", "answer_data": [ "Application record reference (WM-REC-009)", "Decision record reference (WM-REC-010)", "Handling of acts performed on the registrar's own initiative with no external request" ] } ], "data_elements": [ { "id": "de-act-type", "name": "Registration act type", "description": "Coded operation applied to the register, drawn from the register's closed act typology.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "de-act-decision-ref", "name": "Authorising decision reference", "description": "Reference to the decision record that authorised the act; outcome and reasons remain in WM-REC-010.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-009" ] }, { "id": "de-act-target-entry-ref", "name": "Target entry reference", "description": "Reference to the entry created or affected by the act.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "registration-act-record", "name": "Registration act record", "description": "Durable record of one applied change to the register: act type, target entry, ordering stamp, authorising decision reference and the acting role.", "media_or_form": [ "structured record", "register day-book entry", "registry API resource" ], "serial": true, "identity_strategy": "Act identifier assigned by the register manager from the bound governed scheme, paired with the monotonic ordering stamp; never derived from a date alone.", "source_refs": [ "SRC-002", "SRC-005", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "act-authority-and-role-binding", "name": "Act authority and role binding", "description": "Competence to apply an act is distributed across roles. ISO/TC 211 separates the register manager from the control body that reviews proposals and constrains the manager's delegated authority; UNIDROIT separates the Supervisory Authority that appoints the Registrar and approves regulations from the Registrar that operates the registry. This model records the binding, not the mandate lifecycle.", "source_refs": [ "SRC-002", "SRC-012", "SRC-007" ], "questions": [ { "id": "q-act-competence-matrix", "text": "Which role is competent to apply each act type in this register?", "kind": "authority", "answer_data": [ "Role-to-act-type competence matrix", "Acts reserved to a supervisory or control body", "Acts a registrar may perform without external request" ] }, { "id": "q-registrar-delegation-binding", "text": "Which registrar functions are delegated, and which are reserved to the constituting authority?", "kind": "ownership", "answer_data": [ "Delegated function list", "Reserved function list", "Reference to the mandate record defining the delegation (WM-POL-013)" ] }, { "id": "q-review-turnaround", "text": "What bounded time is allowed for review before an act must be applied or refused?", "kind": "process", "answer_data": [ "Review response deadline", "Total processing deadline", "Consequence of exceeding a deadline" ] }, { "id": "q-reviewer-conflict", "text": "How is a reviewer's conflict of interest handled for a specific proposal?", "kind": "exception", "answer_data": [ "Recusal rule", "Substitute reviewer designation", "Record of the recusal on the act" ] } ], "data_elements": [ { "id": "de-acting-role-binding", "name": "Acting role binding", "description": "Role under which an act was applied, bound to an accountable party resolved through WM-XCT-001.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-012" ] }, { "id": "de-competence-matrix-entry", "name": "Competence matrix entry", "description": "Statement that a named role may apply a named act type, optionally conditioned on prior review.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "de-review-deadline", "name": "Review deadline", "description": "Bounded period within which a control body or designated expert must respond to a proposal.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "The competence matrix is a parameter set on the register constitution and on act records; issuance, jurisdiction and lifecycle of the underlying mandate are owned by WM-POL-013 and party stewardship by WM-XCT-001, so no local authority artifact may be minted." } ] }, { "id": "admission-and-evidentiary-requirements", "name": "Admission and evidentiary requirements", "description": "How deeply a register examines what is submitted before it becomes authoritative, and what evidence classes it demands.", "source_refs": [ "SRC-005", "SRC-009", "SRC-003", "SRC-012" ], "findings": [ { "id": "admission-and-examination-depth", "name": "Examination depth and rejection grounds", "description": "Registers differ sharply in how much they check. A notice-filing registry accepts a notice without the underlying agreement and rejects only on narrow formal grounds; a title register examines substance before conferring a conclusive effect; a protocol registry may accept on first-come-first-served or require a permanent public specification. Examination depth is the single strongest predictor of how far an entry may be relied on.", "source_refs": [ "SRC-005", "SRC-009", "SRC-003", "SRC-007" ], "questions": [ { "id": "q-examination-depth", "text": "How far does this register examine a submission before the entry becomes authoritative?", "kind": "process", "answer_data": [ "Examination depth code: none, formal completeness, expert review, substantive verification", "Checks actually performed at each depth", "Statement of what the register does not check" ] }, { "id": "q-rejection-grounds", "text": "On what grounds may a submission be refused, and is that list exhaustive?", "kind": "constraint", "answer_data": [ "Enumerated rejection grounds", "Whether the list is exhaustive or indicative", "Whether refusal must be reasoned and communicated" ] }, { "id": "q-examination-effect-link", "text": "How does examination depth constrain the effect the register may claim for an entry?", "kind": "decision", "answer_data": [ "Mapping from examination depth to claimable effect", "Effects unavailable at low examination depth", "Disclaimer text required where depth is shallow" ] }, { "id": "q-post-admission-recheck", "text": "Are admitted entries ever re-examined after registration, and on what trigger?", "kind": "quality", "answer_data": [ "Re-examination trigger list", "Periodic revalidation interval where used", "Outcome routes for a failed re-examination" ] } ], "data_elements": [ { "id": "de-examination-depth", "name": "Examination depth", "description": "Coded level of scrutiny applied before a submission becomes an authoritative entry.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-009" ] }, { "id": "de-rejection-ground", "name": "Rejection ground", "description": "Enumerated ground on which the register may refuse to apply a submitted act.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Examination depth and rejection grounds are register-definition parameters consumed by the admission function; the record of a particular refusal, with its outcome and reasons, is a decision record owned by WM-REC-010." }, { "id": "evidentiary-requirement-specification", "name": "Evidentiary requirement specification", "description": "What a register demands as grounds for an entry, expressed per item class: which evidence classes are required, whether originals or references suffice, and whether the register restates or merely points at them. Custody, verification workflow, sufficiency challenge and rationale are owned by WM-XCT-028; only the requirement and the binding sit here.", "source_refs": [ "SRC-005", "SRC-009", "SRC-001" ], "questions": [ { "id": "q-required-evidence-classes", "text": "Which evidence classes must accompany an act for each item class in this register?", "kind": "requirement", "answer_data": [ "Required evidence class list per item class and act type", "Whether references suffice or artefacts must be lodged", "Minimum count or combination rules" ] }, { "id": "q-evidence-retention-in-register", "text": "Is lodged evidence retained inside the register, held elsewhere, or returned?", "kind": "retention", "answer_data": [ "Retention location for lodged evidence", "Reference form used when evidence is held externally", "Register policy on retaining a content hash rather than the artefact" ] }, { "id": "q-evidence-publicity", "text": "Is supporting evidence inspectable to the same extent as the entry it grounds?", "kind": "access", "answer_data": [ "Publicity classification for evidence separate from entry content", "Redaction requirement before any evidence disclosure", "Route for a party with legitimate interest to obtain evidence" ] }, { "id": "q-evidence-absence-handling", "text": "What may be registered when the required evidence cannot be produced?", "kind": "exception", "answer_data": [ "Qualified or provisional entry mechanism", "Marking applied to an entry with deficient grounds", "Time limit for perfecting the grounds" ] } ], "data_elements": [ { "id": "de-evidence-requirement", "name": "Evidence requirement", "description": "Statement that a named evidence class is required for a given item class and act type.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-009" ] }, { "id": "de-evidence-sufficiency-marking", "name": "Evidence sufficiency marking", "description": "Register-side marking that an entry's grounds are complete, qualified or deficient, without restating verification semantics.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Evidence items themselves are artifacts of WM-XCT-028, which owns custody, verification, support and challenge; declaring an evidence artifact here would take ownership of a target model's asset, so this finding carries only requirement parameters and a marking." } ] } ] }, { "id": "effect-and-assurance", "name": "Effect and assurance", "description": "What registration changes in the world, how far third parties may rely on it, and what happens when the register is wrong.", "rationale": "A book of records without a declared effect is a database, not a register. The sampled regimes attach sharply different effects — conclusiveness of registered proprietorship, opposability of disclosed particulars to third parties, priority irrespective of knowledge — and each pairs its effect with a correction and compensation regime. Effect and assurance therefore have to be modelled together.", "source_refs": [ "SRC-004", "SRC-009", "SRC-012", "SRC-005", "SRC-011" ], "layers": [ { "id": "legal-effect-and-opposability", "name": "Effect and opposability", "description": "The kind of effect registration produces, when it commences, and how far a third party may rely on the register against the registered subject.", "source_refs": [ "SRC-004", "SRC-009", "SRC-012" ], "findings": [ { "id": "effect-kind-and-commencement", "name": "Effect kind and commencement", "description": "Registration may be constitutive (the right exists only once registered), declaratory (registration records a right that already exists), evidentiary (registration raises a presumption), priority-conferring (registration fixes rank), or a notice function (registration makes an interest effective against third parties). These are not mutually exclusive and each has its own commencement instant.", "source_refs": [ "SRC-004", "SRC-009", "SRC-012", "SRC-005" ], "questions": [ { "id": "q-effect-kinds-produced", "text": "Which effects does registration in this register produce, and are they cumulative?", "kind": "definition", "answer_data": [ "Effect kind codes produced", "Whether effects are cumulative or alternative per item class", "Statutory or contractual basis for each effect" ] }, { "id": "q-effect-commencement", "text": "From which instant does each effect run, and can it differ from the registration instant?", "kind": "temporal", "answer_data": [ "Commencement instant per effect kind", "Divergence rule where commencement predates registration", "Effect duration or expiry where limited" ] }, { "id": "q-effect-on-cancellation", "text": "What becomes of an effect when the entry is cancelled, retired or lapses?", "kind": "lifecycle", "answer_data": [ "Termination rule per effect kind", "Whether termination is prospective or retroactive", "Residual effects surviving cancellation" ] }, { "id": "q-effect-jurisdictional-limit", "text": "In which jurisdictions or contexts is the registered effect recognised?", "kind": "interoperability", "answer_data": [ "Recognition scope statement", "Known non-recognising jurisdictions", "Basis for cross-border recognition where it exists" ] } ], "data_elements": [ { "id": "de-effect-kind", "name": "Effect kind", "description": "Coded consequence registration produces: constitutive, declaratory, evidentiary presumption, priority-conferring or third-party notice.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-009", "SRC-012" ] }, { "id": "de-effect-basis-ref", "name": "Effect basis reference", "description": "Reference to the provision or instrument from which the effect derives.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Effect kind and commencement are declarative attributes of the register definition and of individual entries; they are asserted by the constituting instrument rather than issued as an object, and creating an artifact would imply the register can mint effects independently of its mandate." }, { "id": "third-party-reliance-and-limits", "name": "Third-party reliance and its limits", "description": "Company-law disclosure makes documents opposable to third parties only once properly disclosed, and permits reliance on voluntarily published translations unless the company proves knowledge of the original; title registration makes registered proprietorship conclusive; Cape Town gives a registered interest priority irrespective of knowledge. Every regime nevertheless carries carve-outs — overriding interests, undisclosed particulars, and content the register expressly does not warrant.", "source_refs": [ "SRC-004", "SRC-009", "SRC-012" ], "questions": [ { "id": "q-reliance-scope", "text": "Which register content may a third party rely on, and which content is expressly unwarranted?", "kind": "constraint", "answer_data": [ "Warranted content list", "Expressly unwarranted or informational-only content", "Notice text accompanying unwarranted content" ] }, { "id": "q-overriding-interests", "text": "What binds a subject despite not appearing in the register?", "kind": "exception", "answer_data": [ "Categories of interest effective without registration", "Duty on a searcher to enquire beyond the register", "Reference to the provision creating each carve-out" ] }, { "id": "q-reliance-good-faith-condition", "text": "Must a relying party act in good faith or without notice for reliance to hold?", "kind": "requirement", "answer_data": [ "Good-faith or absence-of-notice condition", "Whether actual knowledge defeats reliance", "Evidence a relying party should preserve" ] }, { "id": "q-multilingual-reliance", "text": "Where content is published in several languages, which version governs a reliance claim?", "kind": "quality", "answer_data": [ "Authoritative language designation", "Reliance status of published translations", "Rule where a translation diverges from the authoritative version" ] } ], "data_elements": [ { "id": "de-reliance-scope-statement", "name": "Reliance scope statement", "description": "Statement of which register content supports third-party reliance and under what conditions.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-009" ] }, { "id": "de-overriding-interest-class", "name": "Overriding interest class", "description": "Category of interest that binds despite non-appearance in the register.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Reliance scope and carve-outs are normative statements attached to the register constitution and surfaced on published views; the published view itself is a projection owned by WM-XCT-003, so no separate artifact is claimed here." } ] }, { "id": "rectification-and-liability", "name": "Rectification and liability", "description": "How a wrong register is put right, what compensation follows, and how a contested entry is marked while a challenge is pending.", "source_refs": [ "SRC-005", "SRC-009", "SRC-012", "SRC-011" ], "findings": [ { "id": "error-and-rectification-regime", "name": "Error classification and rectification regime", "description": "Registers separate registry error (introduced by the registry itself) from submitted error (introduced by the requester), because only the first typically triggers the register's own liability. Title regimes provide for alteration and rectification with defined protection for the proprietor in possession; notice-filing regimes provide registrar correction of registry errors and amendment notices for the rest.", "source_refs": [ "SRC-009", "SRC-005", "SRC-012" ], "questions": [ { "id": "q-error-classification", "text": "How does the register classify an inaccuracy as registry error, submitted error or a change of underlying facts?", "kind": "validation", "answer_data": [ "Error class codes and their tests", "Evidence needed to establish each class", "Consequence of each class for liability and for who bears cost" ] }, { "id": "q-rectification-initiation", "text": "Who may initiate rectification, and can the registrar act without a request?", "kind": "process", "answer_data": [ "Eligible initiators", "Registrar own-initiative correction powers and limits", "Notification duties to affected parties before correction" ] }, { "id": "q-rectification-retroactivity", "text": "Does a rectification take effect retroactively, and what protects a party who relied in the interim?", "kind": "exception", "answer_data": [ "Retroactivity classification per error class", "Protection for a good-faith relying party", "Interaction with rank of intervening entries" ] }, { "id": "q-superseded-content-visibility", "text": "Is the erroneous content preserved and visible after rectification?", "kind": "retention", "answer_data": [ "Preservation rule for corrected-away content", "Visibility of the pre-correction state and to whom", "Reference to the version record supplying the prior state" ] } ], "data_elements": [ { "id": "de-error-class", "name": "Error class", "description": "Coded classification of an inaccuracy as registry error, submitted error or a change in underlying facts.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-005" ] }, { "id": "de-rectification-retroactivity", "name": "Rectification retroactivity", "description": "Whether a correction operates from the original registration instant or only prospectively.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "A rectification is applied through the registration act record already declared and is authorised by a decision record owned by WM-REC-010, while the prior state is preserved by WM-XCT-022; declaring a further artifact would duplicate all three." }, { "id": "liability-indemnity-and-contested-marking", "name": "Liability posture, indemnity and contested marking", "description": "A register that invites reliance must state what it answers for. Cape Town makes the Registrar liable in compensatory damages for loss directly resulting from registry error, omission or malfunction, while excluding liability for inaccurate information received; title regimes provide a statutory indemnity for loss from rectification or from an uncorrected mistake. Separately, an entry under challenge carries a contested marking that points at a case handled elsewhere.", "source_refs": [ "SRC-012", "SRC-009", "SRC-005" ], "questions": [ { "id": "q-liability-scope", "text": "For what failures does the register accept liability, and what is expressly excluded?", "kind": "authority", "answer_data": [ "Liability grounds accepted (error, omission, malfunction, unavailability)", "Exclusions such as inaccurate information supplied by others or force majeure", "Monetary or temporal cap on liability" ] }, { "id": "q-indemnity-entitlement", "text": "Who may claim indemnity for loss caused by the register, and how is entitlement reduced?", "kind": "requirement", "answer_data": [ "Eligible claimant classes", "Reduction for claimant fault or lack of care", "Time limit for bringing a claim" ] }, { "id": "q-contested-marking", "text": "How is an entry marked while it is under challenge, and what does the marking change?", "kind": "state", "answer_data": [ "Contested marking value and its visibility", "Reference to the dispute case (WM-POL-010)", "Whether the marking suspends effect, blocks further acts, or is informational only" ] }, { "id": "q-marking-removal", "text": "On what basis is a contested marking removed?", "kind": "event", "answer_data": [ "Removal trigger (case closure, withdrawal, lapse of time)", "Role competent to remove the marking", "Record left behind after removal" ] } ], "data_elements": [ { "id": "de-liability-statement", "name": "Liability statement", "description": "Statement of the failures for which the register answers, the exclusions and any cap.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-009" ] }, { "id": "de-contested-marking", "name": "Contested marking", "description": "Marking on an entry indicating a pending challenge, with a reference to the case handled by WM-POL-010.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-dispute-case-ref", "name": "Dispute case reference", "description": "Reference to the forum case contesting the entry; procedure and adjudication remain outside this model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Liability posture is a constitutional statement and the contested marking is a flag plus a reference on the entry record; the case itself, its procedure and its outcome are owned by WM-POL-010, so no local artifact is defensible." } ] } ] }, { "id": "publicity-and-disclosure", "name": "Publicity and disclosure", "description": "What the register shows to whom, on what terms, how it can be searched, and how an authenticated extract is issued.", "rationale": "Publicity is what distinguishes a register from an internal database, and it is also where the strongest legal constraints bite. Company-law rules require copies and cost-based fees with core particulars free, while the Court of Justice has struck down unrestricted public access to beneficial-ownership data; the search index and the certified extract are the two operative surfaces through which publicity is actually exercised.", "source_refs": [ "SRC-004", "SRC-006", "SRC-009", "SRC-005", "SRC-012" ], "layers": [ { "id": "publicity-regime", "name": "Publicity regime", "description": "The classification of register content by who may see it, and the terms on which access is priced.", "source_refs": [ "SRC-004", "SRC-006", "SRC-009" ], "findings": [ { "id": "publicity-classification-and-restriction", "name": "Publicity classification and restriction", "description": "Publicity is graded, not binary, and is set per attribute rather than per register. The Court of Justice held that opening beneficial-ownership data to any member of the public was a serious interference with Charter rights that went beyond what was strictly necessary, and pointed to legitimate-interest gating, defined data categories, case-by-case exemptions and accountability for accessors as the safeguards that were missing. Access decisions themselves are evaluated by WM-XCT-002 and shaped by WM-XCT-003.", "source_refs": [ "SRC-006", "SRC-004", "SRC-009", "SRC-005" ], "questions": [ { "id": "q-publicity-tier-per-attribute", "text": "Which publicity tier applies to each attribute of an entry?", "kind": "access", "answer_data": [ "Tier per attribute: open, legitimate-interest, party-only, authority-only or closed", "Attribute groups sharing a tier", "Basis in law or policy for each restriction" ] }, { "id": "q-legitimate-interest-gate", "text": "Where access is gated on legitimate interest, how is that interest defined for this register?", "kind": "privacy", "answer_data": [ "Definition of legitimate interest used", "Categories presumed to qualify", "Reference to the access contract that evaluates and grants (WM-XCT-002)" ] }, { "id": "q-subject-exemption", "text": "Can a registered subject obtain suppression of otherwise public content, and on what showing?", "kind": "exception", "answer_data": [ "Exemption grounds such as disproportionate risk of harm", "Decision route and evidentiary threshold", "Scope and duration of a granted suppression" ] }, { "id": "q-bulk-versus-individual-access", "text": "Does bulk or machine access carry different publicity limits from individual inspection?", "kind": "security", "answer_data": [ "Bulk access permitted flag and its tier", "Rate, purpose or refresh conditions attached", "Re-identification and aggregation safeguards required" ] } ], "data_elements": [ { "id": "de-publicity-tier", "name": "Publicity tier", "description": "Coded disclosure tier applying to a register attribute or attribute group.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004", "SRC-006" ] }, { "id": "de-restriction-basis-ref", "name": "Restriction basis reference", "description": "Reference to the legal or policy provision grounding a restriction on publicity.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-009" ] }, { "id": "de-suppression-marking", "name": "Suppression marking", "description": "Marking that specified content is withheld from a tier that would otherwise show it.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "publicity-regime-schedule", "name": "Publicity regime schedule", "description": "Register-level schedule mapping each attribute or attribute group to a publicity tier, with the legal basis for each restriction and the suppression grounds available to subjects.", "media_or_form": [ "structured table", "normative text", "registry metadata entry" ], "serial": false, "identity_strategy": "Composite of register identifier and schedule name; the governing version identity is supplied by WM-XCT-022 rather than embedded in the artifact name.", "source_refs": [ "SRC-004", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "fee-and-cost-recovery-basis", "name": "Fee and cost-recovery basis", "description": "Access to a public register is typically priced at cost rather than at value: company-law rules cap fees for copies at administrative cost and require core particulars to be free of charge, while registry regimes elsewhere set fees to sustain operation without unduly burdening users. Fee design is part of publicity because a prohibitive fee is a restriction by other means.", "source_refs": [ "SRC-004", "SRC-005", "SRC-012" ], "questions": [ { "id": "q-fee-basis", "text": "On what basis is a fee for register access or registration set?", "kind": "constraint", "answer_data": [ "Fee basis: free, administrative cost, cost recovery, or other", "Cap or ceiling rule", "Authority competent to set or change the fee" ] }, { "id": "q-free-at-point-of-use-content", "text": "Which register content must be obtainable without charge?", "kind": "requirement", "answer_data": [ "Free-of-charge content list", "Channels through which free access is provided", "Whether free access differs between individual and bulk consumers" ] }, { "id": "q-fee-differentiation", "text": "Do fees differ by requester class, channel or product type?", "kind": "classification", "answer_data": [ "Fee schedule dimensions", "Concessions or waivers and their grounds", "Whether certification attracts a separate fee" ] } ], "data_elements": [ { "id": "de-fee-basis", "name": "Fee basis", "description": "Coded basis on which fees for registration or access are set.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-free-content-list", "name": "Free content list", "description": "Enumeration of register content obtainable without charge.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "Fee parameters attach to the register constitution and to product definitions; the priced transaction itself is an access grant governed by WM-XCT-002, so no local fee artifact is warranted." } ] }, { "id": "search-and-extracts", "name": "Search surface and extracts", "description": "The index through which the register is interrogated and the authenticated products issued from it.", "source_refs": [ "SRC-005", "SRC-009", "SRC-012", "SRC-004" ], "findings": [ { "id": "index-and-search-criteria", "name": "Index, search criteria and result completeness", "description": "A register is only as usable as its index. UNCITRAL requires the registry record to be indexed and searchable by the criteria that make notices findable — chiefly the grantor identifier — and Cape Town requires registrations to be searchable in chronological order of receipt. Where matching is exact, a small error in the indexed key can hide an entry entirely, so the register must state its matching rule and what a nil result means.", "source_refs": [ "SRC-005", "SRC-012", "SRC-009" ], "questions": [ { "id": "q-search-keys", "text": "By which keys can the register be searched, and which key is authoritative for a definitive search?", "kind": "identity", "answer_data": [ "Supported search key list", "Authoritative key for a definitive or priority search", "Keys deliberately not offered and why" ] }, { "id": "q-matching-rule", "text": "Is matching exact, normalised or fuzzy, and who bears the risk of a near-miss?", "kind": "validation", "answer_data": [ "Matching rule per key", "Normalisation applied before matching", "Allocation of risk for an entry missed through a defective key" ] }, { "id": "q-nil-result-meaning", "text": "What does an empty search result assert, and what does it not assert?", "kind": "evidence", "answer_data": [ "Wording accompanying a nil result", "Interaction with the register's completeness claim", "Excluded categories such as pending acts or overriding interests" ] }, { "id": "q-search-result-currency", "text": "To which instant is a search result current, and is there a gap for pending acts?", "kind": "temporal", "answer_data": [ "As-at instant of the result", "Existence and length of any pending-act window", "Disclosure of the pending window to the searcher" ] } ], "data_elements": [ { "id": "de-search-key", "name": "Search key", "description": "Indexed key by which entries may be retrieved, with its matching rule.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-012" ] }, { "id": "de-result-completeness-statement", "name": "Result completeness statement", "description": "Statement bounding what a search result covers, including pending acts and excluded categories.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "registry-search-certificate", "name": "Registry search certificate", "description": "Issued record of a search: the criteria used, the as-at instant, the entries returned or an express statement that none exist, and the completeness bounds of the result.", "media_or_form": [ "structured record", "authenticated document", "registry API response" ], "serial": true, "identity_strategy": "Search certificate identifier assigned by the registry at issue, carrying its own as-at instant; never identified by the search date alone.", "source_refs": [ "SRC-012", "SRC-009", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "extract-attestation-and-as-at", "name": "Certified extract attestation and as-at instant", "description": "A certified extract is the registrar's attestation that stated content corresponded to the register at a stated instant. Company-law rules entitle a requester to certified or uncertified copies obtainable electronically; title regimes make official copies admissible in evidence to the same extent as the original. The shape and field selection of the extract are owned by WM-XCT-003; what is register-owned is the attestation, the as-at instant and the evidential claim.", "source_refs": [ "SRC-004", "SRC-009", "SRC-012" ], "questions": [ { "id": "q-extract-attestation-content", "text": "What exactly does the registrar attest when certifying an extract?", "kind": "evidence", "answer_data": [ "Attestation wording and its scope", "Whether the attestation covers correctness or only correspondence to the register", "Signature, seal or equivalent authenticity mark applied" ] }, { "id": "q-extract-as-at-instant", "text": "To which instant does a certified extract speak, and how long does it remain usable?", "kind": "temporal", "answer_data": [ "As-at instant recorded on the extract", "Validity or currency period for reliance purposes", "Whether pending acts are disclosed on the extract" ] }, { "id": "q-extract-evidential-status", "text": "What evidential status does the extract carry before a court or counterparty?", "kind": "authority", "answer_data": [ "Admissibility statement", "Equivalence to the original register record", "Jurisdictions in which the status is recognised" ] }, { "id": "q-extract-verification-route", "text": "How can a recipient verify that an extract is genuine and unmodified?", "kind": "security", "answer_data": [ "Verification route offered by the registry", "Integrity value published with the extract", "Behaviour when verification fails or the extract is superseded" ] } ], "data_elements": [ { "id": "de-extract-as-at-instant", "name": "Extract as-at instant", "description": "RFC 3339 timestamp with seconds and explicit offset identifying the register state the extract reproduces.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-009" ] }, { "id": "de-attestation-mark", "name": "Attestation mark", "description": "Signature, seal or equivalent mark by which the registrar authenticates the extract.", "value_kind": "binary", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-012" ] }, { "id": "de-extract-evidential-status", "name": "Extract evidential status", "description": "Declared evidential weight of the extract and the jurisdictions recognising it.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [ { "id": "certified-register-extract", "name": "Certified register extract", "description": "Authenticated reproduction of specified register content as at a stated instant, bearing the registrar's attestation and an integrity value for verification.", "media_or_form": [ "authenticated document", "structured record", "registry API response" ], "serial": true, "identity_strategy": "Extract identifier assigned by the issuing registry at issue, bound to the subject entry identifier and the as-at instant, which is a field rather than part of the identifier.", "source_refs": [ "SRC-004", "SRC-009", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "registry-operation-and-interoperability", "name": "Registry operation and interoperability", "description": "The registry that holds and serves registers, the measures by which its quality is judged, and the bindings that let it work with other registers.", "rationale": "A register is a governed object; a registry is the operating instance that holds it. INSPIRE shows one registry hosting fourteen registers with item URIs that persist across an operator change, and the EU interconnection of company registers shows independent registers exchanging in a standard message format. Separating the two, and stating quality and alignment explicitly, is what keeps domain registers comparable.", "source_refs": [ "SRC-008", "SRC-004", "SRC-007", "SRC-001", "SRC-011" ], "layers": [ { "id": "registry-instance-and-continuity", "name": "Registry instance, continuity and quality", "description": "The operating instance, its continuity commitments, and the measures by which the register's fitness is assessed.", "source_refs": [ "SRC-008", "SRC-002", "SRC-011", "SRC-004" ], "findings": [ { "id": "registry-instance-and-hosting", "name": "Registry instance and register hosting", "description": "A registry is the operating environment that holds one or more registers and offers registration and search services. Its properties — availability, service hours, operating language, publication endpoints and the commitment that references keep resolving after an operator change — are separable from the constitution of any register it hosts.", "source_refs": [ "SRC-008", "SRC-002", "SRC-007", "SRC-004" ], "questions": [ { "id": "q-registry-hosted-registers", "text": "Which registers does this registry hold, and can a register move between registries?", "kind": "composition", "answer_data": [ "Hosted register list", "Portability rule for a register", "Effect of a move on item references" ] }, { "id": "q-registry-service-availability", "text": "What availability and service-hour commitments does the registry make?", "kind": "quality", "answer_data": [ "Availability target and measurement window", "Service hours where registration is time-critical", "Treatment of acts received during an outage for ordering purposes" ] }, { "id": "q-registry-continuity-commitment", "text": "What continuity commitments protect published references if the operator changes?", "kind": "lifecycle", "answer_data": [ "Persistence commitment for item references", "Successor arrangements and escrow of register content", "Minimum operator qualification and commitment period" ] }, { "id": "q-registry-publication-endpoints", "text": "Through which stable endpoints is register content published, and in what representations?", "kind": "interoperability", "answer_data": [ "Publication endpoint list", "Representations offered per endpoint", "Deprecation policy for an endpoint" ] } ], "data_elements": [ { "id": "de-registry-identifier", "name": "Registry identifier", "description": "Identifier of the operating registry instance, distinct from the identifiers of the registers it holds.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-002" ] }, { "id": "de-availability-commitment", "name": "Availability commitment", "description": "Stated availability target and service-hour window for registration and search services.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-004" ] }, { "id": "de-persistence-commitment", "name": "Persistence commitment", "description": "Commitment that published register and item references continue to resolve across operator or platform change.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "The registry instance is described by properties recorded in the register constitution record and the AGENTS.md bootstrap contract; treating the running service as an artifact of this model would confuse a deployment with the governed record it serves." }, { "id": "register-quality-and-currency", "name": "Register quality and currency measures", "description": "An authoritative record is expected to be authentic, reliable, complete and unaltered, and usable — locatable and interpretable for as long as needed. For a register these general properties become measurable: coverage against the declared field of application, lag between a real-world change and its registration, backlog of unapplied acts, and rate of established registry error.", "source_refs": [ "SRC-011", "SRC-004", "SRC-008", "SRC-009" ], "questions": [ { "id": "q-currency-lag-measure", "text": "How is the lag between a real-world change and its appearance in the register measured and reported?", "kind": "measurement", "answer_data": [ "Lag metric definition and unit", "Measurement window and sampling method", "Published target and current value" ] }, { "id": "q-coverage-measure", "text": "How is coverage against the declared field of application quantified?", "kind": "quality", "answer_data": [ "Coverage metric definition", "Reference population used as denominator", "Known systematic gaps" ] }, { "id": "q-error-rate-reporting", "text": "Is the rate of established registry error tracked and published?", "kind": "validation", "answer_data": [ "Error rate definition and error classes counted", "Reporting frequency and audience", "Remediation threshold triggering review" ] }, { "id": "q-usability-over-time", "text": "What ensures register content remains interpretable after schema or vocabulary change?", "kind": "retention", "answer_data": [ "Retention of superseded item classes and vocabularies", "Migration or conversion policy for stored content", "Documentation kept alongside historical entries" ] } ], "data_elements": [ { "id": "de-currency-lag", "name": "Currency lag", "description": "Measured interval between a real-world change and its registration, reported over a stated window.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-004" ] }, { "id": "de-coverage-ratio", "name": "Coverage ratio", "description": "Proportion of the declared field of application actually represented by entries.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-009" ] }, { "id": "de-registry-error-rate", "name": "Registry error rate", "description": "Rate of established registry errors over a stated window and denominator.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "register-quality-statement", "name": "Register quality statement", "description": "Periodic statement of coverage, currency lag, backlog and established error rate for a register, with metric definitions and known systematic gaps.", "media_or_form": [ "structured record", "published report" ], "serial": true, "identity_strategy": "Composite of register identifier and a monotonic statement sequence number, with the reporting period carried as explicit start and end timestamps rather than encoded in the identifier.", "source_refs": [ "SRC-011", "SRC-008", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "interoperability-alignment", "name": "Interoperability and alignment", "description": "How this register refers to and is referred to by others, and how it aligns with external registry vocabularies without claiming conformance.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-008", "SRC-010" ], "findings": [ { "id": "cross-register-reference-binding", "name": "Cross-register reference and federation binding", "description": "Registers reference one another: an entry in one register may cite an identifier maintained in another, and independent registers may participate in an interconnection that distributes information in a standard message format. This model records which external register a reference resolves against and what freshness is expected; topology, routing, mirroring and drift are owned by WM-XCT-018.", "source_refs": [ "SRC-004", "SRC-008", "SRC-007" ], "questions": [ { "id": "q-external-reference-targets", "text": "Which external registers does this register cite, and for which fields?", "kind": "relationship", "answer_data": [ "External register reference list with the fields resolved against each", "Whether values are restated locally or resolved on demand", "Behaviour when the external register is unavailable" ] }, { "id": "q-authoritative-source-precedence", "text": "When a locally held value conflicts with the external register that owns it, which prevails?", "kind": "decision", "answer_data": [ "Precedence rule per referenced field", "Detection route for divergence", "Correction path once divergence is detected" ] }, { "id": "q-federation-participation", "text": "Does this register participate in an interconnection or mirroring arrangement, and in what role?", "kind": "interoperability", "answer_data": [ "Participation role: authoritative node, mirror or consumer", "Reference to the federation arrangement (WM-XCT-018)", "Expected freshness of any mirrored copy" ] }, { "id": "q-cross-border-identifier-use", "text": "Which identifier allows this register's entries to be matched unambiguously across borders or systems?", "kind": "identity", "answer_data": [ "Cross-system identifier used and its governing scheme", "Scope in which the identifier is unequivocal", "Fallback matching attributes where the identifier is absent" ] } ], "data_elements": [ { "id": "de-external-register-ref", "name": "External register reference", "description": "Reference to another register against which specified fields resolve.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-008" ] }, { "id": "de-precedence-rule", "name": "Precedence rule", "description": "Rule stating which register's value prevails when a locally held value diverges from its authoritative source.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "These are reference and policy fields on the register constitution; the federation arrangement itself, including routing, mirroring and drift handling, is an asset of WM-XCT-018 and must not be reproduced as a local artifact." }, { "id": "registry-vocabulary-alignment", "name": "External registry vocabulary alignment", "description": "Several standards describe registers in overlapping but non-identical terms: ISO 19135 uses register manager, control body and item status; ISO/IEC 11179-6 separates registration status from administrative status and adds submitting organization and stewardship; RFC 8126 uses registration policy and change controller. These are alignments, not conformance claims, and their disagreements must be recorded rather than smoothed over.", "source_refs": [ "SRC-001", "SRC-010", "SRC-003", "SRC-008", "SRC-004" ], "questions": [ { "id": "q-alignment-targets", "text": "Which external registry vocabularies does this register align to, and at which version?", "kind": "interoperability", "answer_data": [ "Aligned standard or vocabulary list with version", "Scope of each alignment (roles, statuses, policies, message formats)", "Statement that alignment is not a conformance claim" ] }, { "id": "q-term-crosswalk", "text": "How do local role and status terms map onto each aligned vocabulary?", "kind": "definition", "answer_data": [ "Term-by-term crosswalk with mapping strength", "Terms with no counterpart in an aligned vocabulary", "Directionality of each mapping" ] }, { "id": "q-alignment-conflict-record", "text": "Where aligned vocabularies disagree, which disagreement is recorded and how is it resolved locally?", "kind": "exception", "answer_data": [ "Recorded conflict list", "Local resolution chosen and its justification", "Impact of the conflict on exchanged data" ] }, { "id": "q-conformance-evidence", "text": "What evidence would be needed before a conformance claim to an aligned standard could be made?", "kind": "evidence", "answer_data": [ "Conformance test or assessment referenced by the standard", "Artefacts that would have to be produced", "Party competent to assert or certify conformance" ] } ], "data_elements": [ { "id": "de-alignment-target", "name": "Alignment target", "description": "External registry standard or vocabulary to which this register is aligned, with its version.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-010", "SRC-003" ] }, { "id": "de-term-mapping", "name": "Term mapping", "description": "Mapping of a local role, status or policy term to a term in an aligned vocabulary, with mapping strength.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "de-alignment-conflict", "name": "Alignment conflict", "description": "Recorded disagreement between aligned vocabularies and the local resolution adopted.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-010" ] } ], "artifacts": [ { "id": "registry-alignment-profile", "name": "Registry alignment profile", "description": "Declared alignments to external registry vocabularies with a term crosswalk, recorded conflicts, local resolutions and an explicit statement that no conformance is claimed without assessment evidence.", "media_or_form": [ "structured record", "crosswalk table", "normative text" ], "serial": false, "identity_strategy": "Composite of register identifier and alignment profile name; version identity is supplied by WM-XCT-022 and never encoded as a date in the identifier.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-constitute-register", "name": "Constitute register", "description": "Bring a register into existence by fixing its identity, field of application, role bindings, registration policy and publicity schedule under a referenced constituting instrument.", "inputs": [ "Constituting instrument or mandate reference", "Proposed field of application and exclusions", "Role bindings for owner, manager and control body", "Registration policy per intended item class" ], "outputs": [ "Register constitution record", "Register identifier binding", "Initial publicity regime schedule" ], "preconditions": [ "A constituting instrument exists and is referenced; its issuance and lifecycle are governed by WM-POL-013", "An identifier for the register is obtainable from a scheme governed by WM-XCT-011", "Accountable parties for each role resolve through WM-XCT-001" ], "effects": [ "A register exists as a governed object distinct from the registry that operates it", "Later acts can be tested against a declared field of application", "Publicity classification becomes available to the access and projection models as input" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012" ] }, { "id": "fn-define-item-class", "name": "Define item class", "description": "Add or revise an item class in a register, fixing its required attributes, syntax constraints, reserved ranges, extensibility and language rules.", "inputs": [ "Register identifier", "Proposed attribute specification with cardinality and syntax", "Reserved and private-use ranges", "Extensibility and language rules" ], "outputs": [ "Item class specification", "Updated register constitution record" ], "preconditions": [ "The register is constituted and its field of application admits the class", "The registration policy for the class is stated", "Review by the competent control body or designated expert has been obtained where the policy requires it" ], "effects": [ "Submissions can be validated against a published attribute contract", "Reserved ranges are withheld from ordinary assignment", "Extending domain registers gain a stable contract to specialize" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008" ] }, { "id": "fn-apply-registration-act", "name": "Apply registration act", "description": "Apply an authorised change to the register — addition, clarification, amendment, supersession, retirement, invalidation or cancellation — creating or altering an entry and binding its identifier.", "inputs": [ "Act type", "Target register and item class", "Entry content payload", "Application record reference", "Authorising decision record reference", "Evidence references where the item class requires them" ], "outputs": [ "Registration act record", "Created or updated register entry record", "Bound entry identifier" ], "preconditions": [ "An authorising decision exists in WM-REC-010; this function does not decide the outcome", "Submitted content satisfies the item class specification and the register's admission criteria", "An entry identifier is obtainable from the scheme governed by WM-XCT-011", "The acting role is competent for the act type under the register's competence matrix" ], "effects": [ "The register content changes and becomes the authoritative statement for the subject", "A change notification becomes available for hand-off to the event register", "Audit and provenance mix-ins receive the references they need, without this model defining their records" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-009" ] }, { "id": "fn-stamp-registration-order", "name": "Stamp registration order", "description": "Assign the receipt instant and monotonic sequence position that fix an act's place in the register's ordering, and derive priority rank where the register allocates rank.", "inputs": [ "Received act reference", "Registry receipt clock reading", "Existing ordering state for the affected subject" ], "outputs": [ "Ordering stamp", "Derived priority rank where applicable", "Tie-break resolution record" ], "preconditions": [ "The register declares whether and how it allocates rank", "A monotonic sequence source is available so that equal timestamps can still be ordered", "Any applicable priority protection window has been checked" ], "effects": [ "Competing acts over the same subject acquire a deterministic order", "Rank becomes computable independently of storage or event-log ordering", "Priority protection reservations are consumed or released" ], "source_refs": [ "SRC-012", "SRC-009", "SRC-005" ] }, { "id": "fn-apply-supersession-or-retirement", "name": "Apply supersession or retirement", "description": "Close an entry by replacing it with a named successor or withdrawing it without replacement, preserving both directions of the continuity chain and the register's retention obligation.", "inputs": [ "Target entry reference", "Outcome kind: supersession, retirement or invalidation", "Successor entry reference where a successor exists", "Authorising decision reference" ], "outputs": [ "Updated continuity links on predecessor and successor", "Registration act record for the closure", "Updated status binding on the affected entries" ], "preconditions": [ "The target status transition is legal under the governed vocabulary owned by WM-XCT-021", "A successor is supplied for supersession and withheld for retirement", "The register's retention rule permits closure rather than deletion" ], "effects": [ "Closed entries remain available for interpreting data produced before closure", "Publication of the entry follows the status-to-exposure mapping rather than disappearing", "Consumers can traverse from any predecessor to the current successor" ], "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] }, { "id": "fn-record-rectification", "name": "Record rectification", "description": "Correct an inaccuracy in the register, classifying it as registry error, submitted error or a change of underlying facts, and record whether the correction operates retroactively.", "inputs": [ "Target entry reference", "Error classification and its supporting material references", "Corrected content", "Authorising decision reference", "Retroactivity determination" ], "outputs": [ "Registration act record of type correction", "Updated entry record", "Error classification and retroactivity markers" ], "preconditions": [ "The inaccuracy is established and classified against the register's error classes", "Affected parties have been notified where the register requires notification before correction", "Any protection for a party who relied in the interim has been evaluated by the competent decision maker" ], "effects": [ "The register content ceases to be inaccurate from the determined commencement instant", "Liability and indemnity consequences become assessable from the error classification", "The pre-correction state remains reconstructable through the version mix-in" ], "source_refs": [ "SRC-009", "SRC-005", "SRC-012" ] }, { "id": "fn-issue-certified-extract", "name": "Issue certified extract", "description": "Produce an authenticated reproduction of specified register content as at a stated instant, bearing the registrar's attestation and an integrity value.", "inputs": [ "Entry or content selection", "Requested as-at instant", "Requester and access grant reference", "Extract shape reference" ], "outputs": [ "Certified register extract", "Attestation mark and integrity value", "Recorded as-at instant" ], "preconditions": [ "An access grant covering the requested content has been resolved by WM-XCT-002", "The extract shape is supplied by WM-XCT-003; this function does not select or transform fields", "The register state as at the requested instant is reconstructable" ], "effects": [ "A third party holds a verifiable statement of register content at a known instant", "A disclosure signal is handed to the audit mix-in without this model defining the audit record", "Pending acts outside the extract are disclosed as bounds on reliance" ], "source_refs": [ "SRC-004", "SRC-009", "SRC-012" ] }, { "id": "fn-execute-register-search", "name": "Execute register search", "description": "Interrogate the register index by declared search keys and return a result set with an explicit as-at instant and completeness bounds, or an express nil statement.", "inputs": [ "Search keys and values", "Requested as-at instant", "Access grant reference", "Product type: informational search or definitive search certificate" ], "outputs": [ "Result set or express nil statement", "Registry search certificate where a definitive product is requested", "Result completeness statement" ], "preconditions": [ "The supplied keys are among the register's declared search keys", "An access grant covering the requested publicity tier has been resolved by WM-XCT-002", "The matching rule and any normalisation for each key are published" ], "effects": [ "The requester learns what the register does and does not show for the given keys", "Risk allocation for a near-miss becomes explicit through the published matching rule", "A definitive search may reserve rank where the register offers priority protection" ], "source_refs": [ "SRC-005", "SRC-012", "SRC-009" ] }, { "id": "fn-publish-register-change", "name": "Publish register change", "description": "Hand a completed registration act to the register's change-notification channel so that downstream consumers and the append-only event register can take it up.", "inputs": [ "Applied registration act record", "Affected entry references", "Publicity tier applying to the changed content" ], "outputs": [ "Change notification payload", "Hand-off acknowledgement reference" ], "preconditions": [ "The act has been applied and its ordering stamp assigned", "The publicity tier permits the level of detail included in the notification", "A destination event register is configured" ], "effects": [ "Downstream consumers can detect that the register changed", "Ordering guarantees, replay and integrity proof for the published stream are supplied by WM-XCT-015, not by this model", "Restricted content is excluded from notifications by tier rather than by ad hoc filtering" ], "source_refs": [ "SRC-008", "SRC-004", "SRC-007" ] }, { "id": "fn-assess-register-currency", "name": "Assess register currency", "description": "Compute and publish coverage, currency lag, backlog and established error rate for a register against its declared field of application.", "inputs": [ "Register identifier", "Reporting window start and end instants", "Reference population for coverage", "Established error records for the window" ], "outputs": [ "Register quality statement", "Metric values with definitions", "Known systematic gap list" ], "preconditions": [ "The field of application and completeness claim are declared", "A reference population exists or its absence is stated", "Error classification is available for the window" ], "effects": [ "Consumers can calibrate how far a nil result or a stale entry may be relied on", "Remediation thresholds become testable", "The completeness claim is either corroborated or falsified by published measurement" ], "source_refs": [ "SRC-011", "SRC-004", "SRC-008", "SRC-009" ] } ], "composition": [ { "target": "WM-XCT-011", "relation": "REFERENCE", "purpose": "Bind register and entry identifiers to governed identifier schemes and record the reuse-after-retirement rule. Scheme syntax, allocation procedure, lifecycle and resolution stay in the target; this model carries only the scheme reference, the uniqueness scope and the subject-specific reuse parameter.", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-010" ] }, { "target": "WM-XCT-012", "relation": "MIX-IN", "purpose": "Attach provenance references to entries and registration acts so their source lineage can be traced. Provenance agents, derivations and lineage semantics remain in the target; this model neither defines provenance records nor asserts derivation.", "required": true, "source_refs": [ "SRC-001", "SRC-011" ] }, { "target": "WM-XCT-001", "relation": "MIX-IN", "purpose": "Resolve register owner, register manager, control body and change controller to accountable parties. Ownership transfer, delegation and stewardship lifecycle remain in the target; this model records only the role-to-party binding and the competence matrix that uses it.", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-012" ] }, { "target": "WM-XCT-002", "relation": "REFERENCE", "purpose": "Route inspection, extract issuance and bulk access through access contracts. Authorization, purpose, consent, parties and grant lifecycle remain in the target; this model supplies only the publicity tier of each attribute and the legitimate-interest definition as input to the grant decision.", "required": true, "source_refs": [ "SRC-004", "SRC-006", "SRC-009" ] }, { "target": "WM-XCT-004", "relation": "MIX-IN", "purpose": "Let registration acts and disclosures contribute audit events. Audit event schema, ordering, integrity and audit retention remain in the target; referencing audit here confers no ownership of audit-trail semantics and this model defines no audit record.", "required": true, "source_refs": [ "SRC-011", "SRC-004" ] }, { "target": "WM-XCT-028", "relation": "REFERENCE", "purpose": "Point entries and registration acts at the evidence grounding them. Evidence custody, verification workflow, support, challenge and rationale remain in the target; this model owns only the per-item-class evidentiary requirement and a sufficiency marking.", "required": true, "source_refs": [ "SRC-005", "SRC-009" ] }, { "target": "WM-XCT-021", "relation": "MIX-IN", "purpose": "Bind registers, entries and registry cases to governed lifecycle states. Status vocabulary, transition legality and lifecycle history remain in the target; this model adds only the mapping from a bound state to publication exposure and permitted use.", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] }, { "target": "WM-XCT-022", "relation": "MIX-IN", "purpose": "Expose governed versions and change history for register definitions and entries. Version identity, diffs and change-history semantics remain in the target; this model relies on it for as-at reconstruction and pre-correction states rather than storing history locally.", "required": true, "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] }, { "target": "WM-REC-009", "relation": "REFERENCE", "purpose": "Reference the generic application record behind a filing, amendment or cancellation request. Intake, applicant payload and request lifecycle remain in the target; this model retains only the receipt instant and ordering stamp, because those determine rank inside the register.", "required": true, "source_refs": [ "SRC-005", "SRC-012" ] }, { "target": "WM-REC-010", "relation": "REFERENCE", "purpose": "Reference the decision record authorising acceptance, refusal, correction or cancellation. Outcome, reasons, approval evidence and signoff remain in the target; this model owns only the resulting mutation of the book.", "required": true, "source_refs": [ "SRC-005", "SRC-009" ] }, { "target": "WM-XCT-015", "relation": "COMPOSE", "purpose": "Publish register changes to an append-only event register. Event ordering, replay, integrity proof and event retention remain in the target; this model produces a change notification and a hand-off, and derives its own priority ordering independently rather than from the event log.", "required": false, "source_refs": [ "SRC-008", "SRC-012" ] }, { "target": "WM-XCT-018", "relation": "REFERENCE", "purpose": "Record participation in interconnection or controlled mirroring and the expected freshness of a mirrored copy. Authority topology, routing, mirroring mechanics and drift handling remain in the target.", "required": false, "source_refs": [ "SRC-004", "SRC-008" ] }, { "target": "WM-XCT-003", "relation": "REFERENCE", "purpose": "Bind public views, certified extracts and bulk views to governed disclosure shapes. Projection selection, transformation, grain, compilation and runtime enforcement remain in the target and its evaluator; this model contributes the publicity classification and the registrar's attestation and as-at instant.", "required": true, "source_refs": [ "SRC-004", "SRC-009" ] }, { "target": "WM-POL-013", "relation": "REFERENCE", "purpose": "Reference the mandate defining registrar powers and the subject scope a public register may cover. Mandate issuance, authority, jurisdiction and mandate lifecycle remain in the target; this model records the derivation of its field of application from that mandate.", "required": false, "source_refs": [ "SRC-002", "SRC-009", "SRC-012" ] }, { "target": "WM-POL-010", "relation": "REFERENCE", "purpose": "Reference the competent forum for objections, appeals and contested entries. Case procedure, jurisdiction, hearings and adjudication remain in the target; this model owns only the contested marking on an entry and its removal trigger.", "required": false, "source_refs": [ "SRC-009", "SRC-006" ] }, { "target": "ISO 19135-1:2015 Procedures for item registration", "relation": "ALIGN", "purpose": "Align register, register item, item class, register manager, control body, submitting organization and item status vocabulary. Alignment only: no conformance is claimed without assessment evidence, and the standard's newer edition is tracked as a conflict.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "ISO/IEC 11179-6:2023 Metadata registries — Registration", "relation": "ALIGN", "purpose": "Align registration authority, submitting organization, stewardship and the separation of registration status from administrative status. Alignment only; the two ISO vocabularies disagree on status naming and that disagreement is recorded rather than reconciled silently.", "required": false, "source_refs": [ "SRC-010", "SRC-001" ] }, { "target": "RFC 8126 / BCP 26 registration policy framework", "relation": "ALIGN", "purpose": "Align the registration policy ladder, required registry definition fields, change controller, provisional registration and deprecation practice. Alignment only; IETF change-control semantics apply to IETF-stream registries and are not asserted for legal registers.", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "An adopting Dimension must name a single accountable owner package for each register it constitutes, and that package must reference the constituting instrument or mandate rather than asserting registrar powers on its own authority.", "The owner package must declare which sibling models supply identifier, provenance, ownership, access, audit, evidence, status, version, application, decision, event, federation, projection, mandate and dispute semantics, and must not implement local substitutes for them.", "The owner package must publish the register's field of application, completeness claim, examination depth, effect kinds and publicity schedule before any entry is admitted, because every downstream reliance depends on those four declarations.", "The owner package must separate the register (governed object) from the registry (operating instance) in its own structure, so that a change of operator does not invalidate published references." ], "namespace_guidance": "Use a stable namespace of the form .registry. for register-level definitions and .registry.. for item classes. Namespaces must not encode operator names, hosting platforms, storage formats or dates, since all four change while register identity must persist; entry identifiers live in the scheme governed by WM-XCT-011 and are never minted from the namespace path.", "registry_links": [ "Vercy world-model registry entry vr.wm-xct-013 is the canonical record for this pattern; domain registers that specialize it must link back to it rather than restating the skeleton.", "Each adopted register must be listed in the adopting Dimension's own register-of-registers with its identifier, operating registry, field of application and publicity schedule.", "External alignment targets must be recorded in the registry alignment profile with version, mapping strength and any recorded conflict." ] }, "canon_and_patch": { "canonicalization_rules": [ "The canonical form of a register entry is the ordered set of its authoritative content fields plus its identifier, item class, status binding and validity instants; administrative carriage fields are excluded from the canonical form so that transport metadata cannot alter an integrity value.", "Timestamps are canonicalized to RFC 3339 with seconds and an explicit offset or Z; a value expressed without an offset is invalid rather than assumed to be local time.", "Text fields are canonicalized in the register's declared authoritative language; published translations are carried alongside and never replace the authoritative value.", "Ordering stamps canonicalize as the pair (receipt timestamp, monotonic sequence number) so that rank is reproducible even where two receipts share a timestamp." ], "patch_rules": [ "A patch to a register entry is expressed as a registration act of a declared type; direct field mutation without an act record is prohibited, because the act is what carries authority and ordering.", "A patch that changes meaning is an amendment and disturbs reliance; a patch that does not change meaning is a clarification. The distinguishing test must be stated per register and applied consistently, since only amendments require the fuller approval path.", "A patch correcting a registry error must carry its error classification and retroactivity determination, because liability and the position of intervening parties both follow from them.", "Patches to a register definition or item class must state whether existing entries remain conforming; where they do not, a migration statement is required before the patch is applied." ], "compatibility_rules": [ "Removing an item class attribute, narrowing a value range, changing a matching rule or tightening a publicity tier are breaking changes for consumers and require notice plus a stated transition period.", "Retired, superseded and invalid entries must remain retrievable so that data produced before their closure can still be interpreted; deleting them to simplify a schema is a breaking change even when no current entry is affected.", "Identifier reuse after retirement is breaking unless the register published a reuse rule and quarantine period in advance.", "Adding an item class, adding an optional attribute or adding a search key is non-breaking, provided the result completeness statement is updated to reflect the new surface." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier: the entry, act or extract identifier assigned by the register manager of record in the register that is the master system for the subject.", "Governed global identifier or IRI: a persistent resolvable identifier published by the register under a scheme governed by WM-XCT-011, used when the master-system identifier is not exposed to consumers.", "UUID or ULID assigned by the adopting Dimension: used only where neither of the above exists, and recorded as locally assigned so that it is never mistaken for an authoritative reference.", "A date, a filing period, a version label or a file name is never an identifier; where an identifier appears to embed a date it must be treated as opaque and never parsed for temporal meaning." ], "timestamp_rule": "All time values use RFC 3339 with explicit seconds and either an explicit UTC offset or Z; values lacking an offset are rejected rather than defaulted. Event time and observation or ingestion time are recorded separately whenever they can differ: the receipt instant (when the registry received the act), the registration instant (when the entry became effective in the register), the effect commencement instant (when the registered effect began, which may precede registration where backdating is permitted) and the real-world event instant (when the recorded fact occurred) are four distinct fields and must never be collapsed into one. Extract and search products additionally carry their own as-at instant, which is an observation time over the register and not an event time.", "serial_naming_rule": "Serial artifacts — entry records, registration act records, certified extracts, search certificates and quality statements — are named by the register or registry identifier plus a monotonic sequence assigned at issue. The sequence is opaque and gap-tolerant; consumers must not infer volume, ordering across registers, or dates from it. Where rank matters, the ordering stamp is the authoritative ordering field, not the serial. Reporting periods and as-at instants are carried as explicit timestamp fields and never encoded into the serial.", "integrity_rule": "Every issued artifact carries a content integrity value computed over its canonical form, and certified extracts and search certificates additionally carry the registrar's attestation mark. A recipient must be able to verify both the integrity value and the attestation through a route the registry publishes. Integrity values bind an artifact to a stated as-at instant; they do not assert that the artifact is still current, and a verification route must be able to report that a verified extract has since been superseded." }, "policies": [ "Publicity is graded per attribute, not per register, and any tier that exposes personal data to an undefined audience requires a recorded basis, defined data categories, a legitimate-interest definition and an available subject exemption; unrestricted public access adopted by default is treated as a defect.", "No entry may be created, altered or closed except through a recorded registration act that names its act type, its acting role and its authorising decision reference; direct mutation of register content is prohibited regardless of storage technology.", "A register must publish its examination depth alongside every effect it claims, and may not claim an effect stronger than its examination depth supports.", "Closed entries are retained and remain retrievable for as long as data produced under them may need interpretation; simplification of storage is never a sufficient ground for removal.", "External standards are recorded as alignments with version and mapping strength; a conformance claim requires assessment evidence identified in the alignment profile." ], "crud": { "read": [ "Reads are resolved against the publicity schedule: an attribute is readable only at or above the tier the schedule assigns it, and the access grant itself is decided by WM-XCT-002, not here.", "Every read product states its as-at instant and its completeness bounds, including whether pending acts are disclosed; a nil result must be returned as an express statement rather than as an empty payload.", "Reads of closed, superseded, retired or invalid entries follow the status-to-exposure mapping and carry the warning text the register prescribes for non-current content.", "Bulk and machine reads are distinguishable from individual inspection in the request record so that different tiers, rate conditions and safeguards can apply." ], "create": [ "Creation occurs only through an addition act that satisfies the item class specification, the register's admission criteria and its evidentiary requirements, and that references an authorising decision.", "An ordering stamp is assigned at receipt, before examination, so that examination duration cannot alter rank.", "An entry identifier is bound from the governed scheme at the point the act is applied; identifiers are not pre-minted by submitters unless the registration policy expressly delegates assignment.", "Duplicate detection runs against the declared duplicate key before an act is applied, and a resubmission of an already applied act is recorded as a no-op rather than silently creating a second entry." ], "update": [ "Updates are amendments, clarifications or corrections, each recorded as its own act type with its own approval path; the register must state which of the three a given change is before it is applied.", "An amendment must state whether rank is preserved or a new rank position is created, since the answer changes third-party positions.", "A correction must carry its error classification and retroactivity determination, and must record whether any protection applied to a party who relied in the interim.", "Prior states are preserved through WM-XCT-022; an update that would make the pre-update state unreconstructable is rejected." ], "delete": [ "This model does not delete register entries. Closure is achieved by supersession, retirement, invalidation, cancellation or lapse, and the closed entry is retained so that data produced before closure remains interpretable; a tombstone consisting of the identifier, item class, closure act reference, closure instant and status binding is retained even where content is withdrawn from public view.", "Withdrawal from the public record is distinct from destruction: expired or closed information may be removed from the searchable public record while being archived and remaining retrievable by the registrar and by parties with a recorded basis, and the register must state which of the two it is performing.", "Content may be redacted or suppressed where a subject exemption or a restriction basis applies; the redaction is recorded on the entry and the suppressed content remains accessible to roles at the tier that governs it.", "Actual destruction of records, and the retention schedule or disposition authority that permits it, is outside this model's boundary: execution is owned by the adopting Dimension's records-management and retention policy together with WM-XCT-004 for audit retention and WM-XCT-015 for event retention. This model contributes only the minimum-retention constraint that flows from its completeness, interpretability and reliance obligations, and a destruction request that would breach that constraint must be refused by the owning policy rather than silently honoured here." ] }, "roles": [ { "name": "Register owner", "responsibilities": [ "Hold accountability for the register's existence and its field of application under the constituting instrument", "Appoint and, where necessary, replace the register manager", "Approve changes to the register definition, publicity schedule and fee basis" ] }, { "name": "Register manager / registrar", "responsibilities": [ "Operate the register: receive acts, stamp ordering, apply authorised acts and bind entry identifiers", "Issue certified extracts and search certificates and answer for registry error within the declared liability posture", "Maintain continuity of published references and hand over completely on succession" ] }, { "name": "Control body or designated expert", "responsibilities": [ "Review proposals against the item class specification and registration policy within the register's published deadlines", "Recuse where conflicted and record the recusal against the affected act", "Advise on whether a change is a clarification or an amendment when the distinction is contested" ] }, { "name": "Submitting organization or registrant", "responsibilities": [ "Lodge acts that conform to the item class specification and supply the required evidence references", "Maintain accurate change-controller contact details for entries they control", "Bear responsibility for submitted error as distinct from registry error" ] }, { "name": "Inspection consumer", "responsibilities": [ "Request access at the tier appropriate to the content and the stated purpose", "Read result completeness statements and as-at instants before relying on a result", "Report suspected inaccuracies through the register's rectification route" ] } ], "access": { "default_rule": "Deny by default at every scope. A request is served only where the publicity schedule assigns the requested attribute a tier that the requester's resolved grant reaches; the grant itself is evaluated and issued by WM-XCT-002, and this model supplies only the tier, the legitimate-interest definition and any suppression marking as inputs to that evaluation.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Core identifying particulars that the constituting instrument requires to be free and open are served without a grant, but the request is still recorded so that bulk harvesting through open endpoints remains detectable.", "A registered subject may access their own entry and its restricted attributes, including content suppressed from public tiers, without demonstrating legitimate interest.", "A subject exemption granted on evidence of disproportionate risk suppresses otherwise public content for the granted scope and duration, overriding the default tier.", "Competent authorities exercising a statutory function may reach tiers closed to the public where the constituting instrument provides for it; the provision must be named on the grant.", "Emergency read access to a register in an incident may be granted at a broader tier only with a named approver and an expiry no longer than the incident, after which the grant lapses automatically." ], "audit_requirements": [ "Every applied registration act and every disclosure event must produce the references an audit record needs — actor, role, act or product identifier, tier served and instants — and hand them to WM-XCT-004, which owns the audit record schema, its ordering, its integrity and its retention.", "Grants relied on for restricted-tier access must be referenceable from the disclosure hand-off so that a later review can reconstruct on what basis content was served.", "Suppression and exemption decisions must be traceable to a named approver and a stated basis without exposing the suppressed content in the trace itself.", "This model asserts no audit-trail semantics of its own and must not be treated as the system of record for audit completeness or tamper evidence." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Register identifier and operating registry identifier", "Field of application, completeness claim and examination depth", "Publicity schedule URL and legitimate-interest definition", "Composition links to sibling models with the concerns each one owns" ], "read_order": [ "AGENTS.md — establishes name, type and the four URLs before anything else is fetched", "Specification URL — the register constitution record: identity, field of application, role bindings, effect kinds and completeness claim", "Storage type URL — how records are persisted and canonicalized, understood as a projection and never as semantics", "Interface URL — registration, search and extract operations with their preconditions and access requirements", "Processes URL — act typology, admission criteria, ordering and rectification procedures", "Publicity schedule and registry alignment profile — what may be disclosed to whom, and which external vocabularies are aligned rather than conformed to", "Composition links — resolve each sibling model before assuming any behaviour this model explicitly does not own" ] } }, "coverage": { "claim": "Single-provider coverage only, not universal. The audited result covers the register-pattern surface reachable from twelve cited sources (EU company-law and CJEU instruments, one UK statute, UN/UNIDROIT model instruments, IETF/IANA registry guidance, INSPIRE, and three ISO standards not read in the original): register constitution, item classes, entry composition and subject binding, status and time, ordering and priority, registration acts, admission depth, effect and reliance, rectification and liability, publicity, search and extracts, registry operation, quality and alignment. It is not a complete theory of registers: privacy/personal-data and register-level security are declared gaps; retention non-destruction, admission and register termination have structural holes recorded in the decisions; no Asian, African or Latin American legal family and no deeds-registration or registry-registrar-registrant topology was sampled; and no independent second-provider review was performed.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Register identity, entry identifier binding, uniqueness scope, reuse-after-retirement and cross-system matching are modelled; the identifier value space, allocation and resolution are referenced to WM-XCT-011 rather than restated. Identity priority names the authoritative master-system identifier first and excludes dates." }, { "dimension": "lifecycle", "status": "covered", "notes": "Entry status binding, supersession versus retirement versus invalidation, effectiveness periods with lapse and extension, provisional registration and operator succession are covered. The status vocabulary and transition legality themselves belong to WM-XCT-021 and are only bound here." }, { "dimension": "relationships", "status": "covered", "notes": "Entry-to-subject, entry-to-evidence, supersession and split/merge continuity, priority rank between competing entries, and cross-register references with precedence rules are modelled. Federation topology is referenced to WM-XCT-018." }, { "dimension": "temporal", "status": "covered", "notes": "Four distinct instants are separated (receipt, registration, effect commencement, real-world event) plus product as-at instants; RFC 3339 with seconds and explicit offset is mandated and offset-less values are rejected. Retroactivity and as-at reconstruction are explicit." }, { "dimension": "provenance", "status": "covered", "notes": "Entries carry provenance and evidence references and every change is traceable to an act, a decision reference and an acting role. Provenance agents, derivations and lineage semantics remain in WM-XCT-012 and are not reproduced." }, { "dimension": "ownership", "status": "covered", "notes": "Register owner, manager, control body, submitting organization and per-entry change controller are distinguished and bound to parties resolved through WM-XCT-001. Transfer, delegation and stewardship lifecycle are out of scope." }, { "dimension": "validation", "status": "covered", "notes": "Examination depth, rejection grounds, duplicate detection, matching rules, evidentiary requirements and error classification are modelled, and examination depth is explicitly tied to the strength of effect a register may claim." }, { "dimension": "access", "status": "covered", "notes": "Per-attribute publicity tiers, legitimate-interest gating, subject exemptions, bulk versus individual access and a deny-by-default rule across all four scopes are modelled, grounded in the Court of Justice ruling and company-law disclosure rules. Grant evaluation and enforcement stay with WM-XCT-002 and WM-XCT-003." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Closure never deletes: tombstones are retained, withdrawal from the searchable public record is distinguished from destruction and archival, and execution of destruction is explicitly assigned to the adopting Dimension's retention policy with WM-XCT-004 and WM-XCT-015 owning audit and event retention. This model contributes only a minimum-retention constraint." }, { "dimension": "interoperability", "status": "covered", "notes": "Cross-register references, interconnection participation, standard message exchange, persistent resolvable identifiers, multilingual authoritative-language rules and an explicit alignment profile with recorded conflicts are modelled; no conformance is claimed." }, { "dimension": "authority and mandate", "status": "covered", "notes": "Competence matrix, delegated versus reserved registrar functions, review deadlines and recusal are modelled as bindings. Mandate issuance, jurisdiction and lifecycle remain in WM-POL-013." }, { "dimension": "legal and operational effect", "status": "covered", "notes": "Effect kinds (constitutive, declaratory, evidentiary, priority-conferring, notice), commencement, termination and jurisdictional recognition are modelled, with reliance scope and overriding-interest carve-outs stated explicitly." }, { "dimension": "measurement and quality", "status": "covered", "notes": "Coverage ratio, currency lag, backlog and registry error rate are defined as published measures against the declared completeness claim, so that the claim is falsifiable rather than assumed." }, { "dimension": "exceptions and contestation", "status": "covered", "notes": "Rejection, subject exemption, retroactivity carve-outs, contested marking and rank carryover on amendment are modelled. Case procedure and adjudication remain in WM-POL-010; only the marking and its removal trigger are local." }, { "dimension": "privacy and personal data", "status": "gap", "notes": "Publicity limits are grounded in one authoritative EU ruling and company-law texts. Data-minimisation, lawful-basis analysis and erasure rights for personal data in registers are only partially reachable from the cited sources and are not modelled as a first-class surface; an adopting Dimension in a personal-data-bearing domain must supply this from its own data-protection model." }, { "dimension": "security of the register itself", "status": "gap", "notes": "Integrity values, attestation and verification routes are specified for issued artifacts, but tamper-evidence for the register as a whole, key management for attestation marks and incident handling are not modelled here and are only partly delegable to WM-XCT-015; treated as an evidence gap rather than presented as canonical." } ], "known_omissions": [ "Full normative text of ISO 19135-1:2015, ISO/IEC 11179-6:2023 and ISO 15489-1:2016 is paywalled; the model relies on the ISO/TC 211 good-practice page, published abstracts and secondary summaries for their content, so clause-level citation is not available and specific clause numbers are deliberately not asserted.", "Article numbers within the UNCITRAL Model Registry Provisions were not verified individually against the source text; the model cites the Provisions at the level of their mechanisms (notice-based registration, indexing, effectiveness periods, removal and archival, registrar liability) rather than by article.", "UNECE land administration guidelines and the FAO Voluntary Guidelines on tenure were sought but their PDFs were not text-extractable during research; land-registration content therefore rests on the UK Land Registration Act 2002 alone, which narrows the legal-family base.", "Blockchain and distributed-ledger registries, and the question of whether an immutable ledger can satisfy a rectification and indemnity regime, are not modelled.", "Domain-name and IP-address registries with registry-registrar-registrant separation and escrow obligations were not sampled; that three-party commercial topology may reveal roles this model collapses into registrar plus submitter.", "Registers whose entries are machine-generated at high volume (telemetry, observation registers) are not represented; the sampled sources are all human- or application-mediated and the ordering and examination model may not transfer.", "Cost, staffing and organisational-capacity aspects of running a register are excluded as operational rather than semantic.", "Insolvency, beneficial-ownership and land-register interconnection regimes beyond the company-law instance were not examined in detail." ], "conflicts": [ "ISO 19135 and ISO/IEC 11179-6 name register statuses differently: the former uses notValid, valid, superseded, retired and invalid, while the latter separates registration status (lifecycle and documentation categories) from administrative status. This model binds to whatever vocabulary WM-XCT-021 governs and records the divergence rather than picking a winner.", "A newer edition of the geographic-information registration standard (EN ISO 19135:2026) has appeared alongside ISO 19135-1:2015. Its content could not be retrieved during research, so this model cites the 2015 edition and flags the newer edition as an unresolved alignment risk.", "Publicity conflicts directly with data protection: company-law disclosure pushes toward open access and cost-based fees, while the Court of Justice held general public access to beneficial-ownership data invalid. The model resolves this by making publicity per-attribute and gated, but the tension is jurisdictional and cannot be settled at pattern level.", "Notice-filing registries deliberately register without examining the underlying agreement, whereas title registries examine before conferring conclusiveness. Both are authoritative registers, so examination depth cannot be normatively fixed and is instead modelled as a declared parameter constraining claimable effect.", "Registrar liability differs sharply: the Cape Town regime imposes compensatory liability for registry error while excluding liability for inaccurate information received, and some public registries limit liability heavily. Liability posture is therefore a declared property, not a pattern invariant.", "RFC 8126 change-control semantics assume a standards-development community and do not map cleanly onto registers whose change control derives from statute; the alignment is recorded as partial." ], "regional_assumptions": [ "Legal grounding is drawn predominantly from EU instruments, one UK statute and UN/UNIDROIT model instruments; no source from Asia, Africa or Latin America was read in the original during this research.", "Title registration with statutory indemnity is a common-law-influenced pattern; deeds-registration systems, which record instruments rather than guarantee title, are represented only by inference from the examination-depth parameter and were not separately sourced.", "Cost-based fee ceilings and free core particulars reflect an EU statutory choice, not a universal rule; jurisdictions that fund registries from user fees at market rates are not represented.", "Legitimate-interest gating as a safeguard reflects the EU Charter analysis; jurisdictions applying freedom-of-information presumptions may reach the opposite default for the same content.", "The assumption that registration ordering can be made monotonic presumes a single logical registry clock; genuinely distributed registers with no such clock are not addressed and are deferred to WM-XCT-018." ], "adversarial_checks": [ "Boundary sweep against every known relation: the previous R1 evidence bundle (source documents plus verification) was removed because verification belongs to WM-XCT-028; the registrar-mandate layer was reduced to a binding because WM-POL-013 owns mandate lifecycle; the decision-and-recourse layer was split so that decisions go to WM-REC-010 and recourse to WM-POL-010, leaving only the contested marking here; and application intake was surrendered to WM-REC-009 while the receipt ordering stamp was retained because rank is register-owned.", "Audit and event ownership test: no bundle, layer, finding or function defines an audit record, its ordering, its integrity proof or its retention. The audit mix-in and the composed event register receive hand-offs only, and both the access audit requirements and the publish function state explicitly that this model asserts no audit-trail or event-ordering semantics.", "Projection ownership test: certified extracts and public views are declared to take their shape, field selection and runtime enforcement from WM-XCT-003. What was kept locally is only the registrar's attestation and as-at instant, which are legal acts of the register rather than transformation logic — a distinction recorded in boundary_notes so a reviewer can reject it if unpersuaded.", "Counterexample search for structure: the assumption that every register examines before registering fails against notice-filing registries, so examination depth became a parameter rather than a stage; the assumption that every register allocates rank fails against protocol-parameter registries, so priority is conditional; the assumption that publicity is binary fails against gated beneficial-ownership registers, so publicity became per-attribute and tiered.", "Attractive-but-unsupported structure rejected: a generic objection or appeal lifecycle, a certification-authority or key-management model, a fee-transaction ledger, a workflow engine for examination, and a register-of-registers governance layer were all considered and excluded because they are either target-owned or unsupported by the cited sources.", "Falsifiability check on the completeness claim: rather than asserting that registers are authoritative, the model requires a declared completeness claim and pairs it with published coverage and currency measures, so that a nil search result can be checked against measured coverage instead of trusted.", "Identifier discipline check: every local ID was reviewed for date-like components and none encode dates; the artifact rules require reporting periods and as-at instants to be explicit fields, and identifiers that appear to embed a date must be treated as opaque." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "pattern", "status": "accepted", "rationale": "Entry kind 'pattern' is confirmed against the frozen registry record (entry_kind pattern, legacy_alias R1, empty parent_ids/contains_ids) and against what the model actually does: it factors a reusable skeleton that domain registers specialise inbound and declares no domain payload (parcel geometry, civil-status facts, collateral descriptions are all excluded). The aggregate root is the register as an authoritative book, with the registry instance retained as its operating context rather than split into a separate model, because every cited authority pairs the book with a keeper — ISO/TC 211 register owner, manager and control body; UNIDROIT Supervisory Authority and Registrar; IANA operator guidance — and the legacy R1 held the same combined scope. Splitting on a single-provider run at medium confidence would be premature and is deferred instead. Acceptance is conditional on the corrections recorded in decisions, chiefly the inverted containment in the registry-instance rationale, the missing admission function, and the coverage-checklist reconciliation." }, "decisions": [ { "concept": "Aggregate root: the register as book versus the registry as operator", "disposition": "Accepted — register is the aggregate root, registry retained as hosting context in the same model", "rationale": "Every cited authority binds the book to a keeper (ISO/TC 211 owner/manager/control body, UNIDROIT Supervisory Authority/Registrar, IANA operational guidance), and legacy R1 held the same combined scope, so a split is unwarranted on a single-provider run at medium confidence." }, { "concept": "Inverted containment in the registry-instance-and-hosting inline rationale", "disposition": "Accepted with mandatory correction before publication", "rationale": "The rationale places registry-wide availability, endpoints and continuity properties inside 'the register constitution record', but a registry hosts one or more registers, so one register's constitution cannot own registry-level properties; either declare a registry-instance record or state the properties are asserted per hosted register." }, { "concept": "Admission function referenced by two inline rationales but absent from the function set", "disposition": "Rejected as internally consistent — correction required", "rationale": "Both registration-policy-and-submission-rights and admission-and-examination-depth defer parameters to 'the admission function', yet none of the ten declared functions is an admission function; either bind the parameters to fn-apply-registration-act or declare an examination/admission function that refuses without minting a WM-REC-010 decision record." }, { "concept": "Lapse on expiry has no operating function and is dropped from the act enumeration", "disposition": "Deferred to a required pre-publication edit", "rationale": "The act typology finding lists correction and lapse on expiry, and q-entry-effectiveness-period presumes lapse, but fn-apply-registration-act enumerates only seven act types and omits both; correction is carried by fn-record-rectification while time-triggered closure has no owner at all." }, { "concept": "Certified extract and search certificate artifacts against WM-XCT-003 projection ownership", "disposition": "Accepted, narrowed to the attestation wrapper only", "rationale": "Register-owned content is the registrar's attestation, the as-at instant, the integrity value and the evidential claim; the payload shape, field selection and grain must be declared as compiled by WM-XCT-003 so these artifacts do not re-import projection logic the contract surrendered." }, { "concept": "Publicity regime schedule as register-owned policy versus projection or access input", "disposition": "Accepted as an input-policy artifact with an explicit non-enforcement statement", "rationale": "Per-attribute tiering is a constitutional classification grounded in the disclosure and proportionality sources, but the schedule must be declared an input to WM-XCT-003 compilation and WM-XCT-002 grant evaluation and must never be described as a runtime evaluator." }, { "concept": "Removal of the legacy R1 evidence bundle (source documents plus verification)", "disposition": "Accepted", "rationale": "Legacy evidence.sourceDocuments and evidence.verification map cleanly onto WM-XCT-028 custody and verification workflow; retaining only the per-item-class evidentiary requirement and the entry-to-evidence reference is the narrower reading and matches the frozen REFERENCE relation." }, { "concept": "Retention non-destruction invariant has no structural home", "disposition": "Deferred as a required edit", "rationale": "The checklist and fn-apply-supersession-or-retirement assert tombstone preservation and a retention obligation, but no finding, question or declared parameter states a minimum-retention constraint; retention of the book itself is register-owned and cannot rest on WM-XCT-004 audit retention or WM-XCT-015 event retention." }, { "concept": "Coverage checklist asserts mechanisms absent from the emitted structure", "disposition": "Rejected as published — reconcile before draft release", "rationale": "Checklist notes claim RFC 3339 offset enforcement with rejection of offset-less values, a deny-by-default rule across four scopes, tombstone retention and identity-priority ordering that excludes dates, none of which appear in any finding, question, artifact or function; the notes must be reduced to what the structure carries." }, { "concept": "COMPOSE relation to WM-XCT-015 versus the model's hand-off-only narrative", "disposition": "Deferred to relationship-contract review", "rationale": "The frozen contract states COMPOSE while the model and fn-publish-register-change describe only a change-notification hand-off asserting no ordering or integrity semantics; a composed event register is normally constitutive of change history, so either the relation type or the narrative must move." }, { "concept": "As-at reconstruction warranty delegated to WM-XCT-022 while the register warrants extracts", "disposition": "Accepted with a register-side requirement statement", "rationale": "The registrar attests an extract's as-at instant and a search result's currency, so the register must state the reconstruction granularity and warranty it relies on even though the change-history substrate is owned by the target model." }, { "concept": "Load-bearing paywalled standards carried as primary_source true at authority tier 1", "disposition": "Accepted as cited, with evidentiary weight downgraded in the draft", "rationale": "Status vocabulary, item classes and record-quality properties rest on ISO 19135-1, ISO/IEC 11179-6 and ISO 15489-1, which the known omissions say were reached only through abstracts, the ISO/TC 211 good-practice page and secondary summaries; the draft must mark them as unverified in the original." }, { "concept": "Characterisation of the Court of Justice beneficial-ownership judgment", "disposition": "Accepted as the model's interpretation, not as the holding", "rationale": "The publicity finding attributes a specific list of missing safeguards — legitimate-interest gating, defined data categories, case-by-case exemptions, accessor accountability — to the Court; that reads as a derived design consequence of the proportionality reasoning and must be labelled as inference rather than quoted disposition." }, { "concept": "Inbound EXTEND family asserted in boundary notes but absent from the frozen contract", "disposition": "Accepted as narrative only", "rationale": "The frozen contract carries fifteen outbound relations and no inbound EXTEND, and the registry record has empty parent_ids and contains_ids; the boundary note may describe the specialisation family, but the draft must not assert inbound relations that the child domain registers have not declared." }, { "concept": "Legacy mu-registry-doctrine ALIGN import has no successor relation", "disposition": "Deferred", "rationale": "R1 aligned to an internal catalogue doctrine fixing the shared meaning of entry, evidence and effect across the catalogue, but the new alignment profile covers only external vocabularies (ISO 19135, ISO/IEC 11179-6, RFC 8126), so the internal doctrine alignment is dropped without a recorded decision." }, { "concept": "Delegation list in purpose and out_of_scope against the frozen relationship contract", "disposition": "Accepted — exact one-to-one match verified by inspection", "rationale": "The fifteen delegated concerns named in the purpose sentence and mirrored in out_of_scope correspond one-to-one to the fifteen frozen contract relations, with no orphan delegation and no undeclared target, which is the strongest structural evidence that the ownership boundary is coherent." }, { "concept": "Boundary-note parity across contract relations", "disposition": "Accepted as sufficient for a reviewable draft, parity required before final publication", "rationale": "Nine boundary notes cover eleven relations; WM-XCT-012 provenance, WM-XCT-001 ownership, WM-XCT-002 access, WM-XCT-022 version and WM-XCT-018 federation carry their distinctions only inside inline_only_rationale text, which is adequate for review but not for a published contract surface." }, { "concept": "Artifact serial flag on item-class-specification", "disposition": "Reclassify to serial true or restate as a single consolidated schedule", "rationale": "A register carries several item classes and fn-define-item-class adds or revises them one at a time, so the specification is issued repeatedly; serial false holds only if the artifact is one consolidated schedule covering every class of a single register." }, { "concept": "Register-level termination and succession of the book itself", "disposition": "Deferred as an acknowledged structural gap", "rationale": "fn-constitute-register has no counterpart for winding up a register, transferring its entries or archiving the book; only operator succession and inter-registry movement are asked, so the end of a register's life is unmodelled while its beginning is fully specified." }, { "concept": "Model name against the model's own ISO 19135 vocabulary", "disposition": "Rejected rename — keep the frozen registry-record name", "rationale": "The model makes the register the aggregate root while reserving 'registry' for the operating environment, so 'Registry Pattern' names the secondary concept; the frozen record fixes the name and legacy alias R1, and the purpose already leads with the register, so continuity outweighs the vocabulary mismatch." } ], "publicationHolds": [ "Live source and version verification hold: before release, confirm that all twelve source URLs resolve and that each version pin still holds — in particular ISO 19135-1:2015 against the reported EN ISO 19135:2026 edition flagged as an unresolved alignment risk, ISO/IEC 11179-6:2023, ISO 15489-1:2016, and the INSPIRE Registry entry asserting transfer of operational management to the Publications Office as of 1 July 2026.", "Unverified-in-original hold: mark ISO 19135-1, ISO/IEC 11179-6 and ISO 15489-1 as paywalled and not read in the original wherever they carry load-bearing structure — the item status vocabulary and publication mapping, the item class attribute contract, and the authenticity/reliability/integrity/usability quality properties — so that no clause-level authority is implied and the disclosed omission travels with the claim.", "Single-provider hold: publish with a visible banner recording that independent second-provider review by Grok is absent under an explicit repository-owner waiver dated 2026-08-29T09:06:27Z, that the only adversarial check is this no-tools same-provider-family audit, and that the artifact remains a reviewable draft rather than a validated cross-provider consensus.", "Provenance-string hygiene hold: the frozen registry record's provenance field reads 'current-112 + Grok review + Claude adversarial audit' and its origin reads 'grok-union-current', both describing the prior described-previous-version record; the published draft must state explicitly that no Grok result exists for this research run so that legacy provenance is not read as second-provider review of this result.", "Coverage-checklist hold: reconcile the checklist notes with the emitted structure before release, because the claims of RFC 3339 offset enforcement, a deny-by-default rule across four scopes, tombstone retention and date-excluding identity priority have no referent in any finding, question, artifact or function of the audited result.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Retrieve EN ISO 19135:2026 and determine whether it supersedes or merely parallels ISO 19135-1:2015 for register roles, item classes and item status, then re-pin SRC-001 and re-check every finding that binds to the 2015 status vocabulary.", "Verify whether EU instruments adopted after the 22 November 2022 judgment in Joined Cases C-37/20 and C-601/20 changed the beneficial-ownership access position, before the draft treats legitimate-interest gating as the current EU default rather than as one jurisdiction's proportionality outcome.", "Sample a domain-name or IP-address registry with registry-registrar-registrant separation and escrow obligations to test whether the model's collapse of roles into registrar plus submitter hides a third commercial party and an escrow continuity duty.", "Source at least one non-EU/UK legal family (Asia, Africa or Latin America) and one deeds-registration system that records instruments without guaranteeing title, to test whether examination depth as a declared parameter really absorbs the difference or whether a distinct register family is missing.", "Settle whether registry-operation-and-interoperability should become a separate registry-instance model: this audit accepted the combined boundary for continuity with legacy R1 and the frozen record, but did not resolve it, and the inverted containment defect is the symptom that would justify revisiting it.", "Test the registration-ordering model against a genuinely distributed register with no single logical clock, and record whether monotonic ordering and priority stamping must move to WM-XCT-018 or survive as a declared register parameter with a stated clock assumption.", "Decide whether the dropped mu-registry-doctrine internal alignment needs a successor relation or catalogue-level doctrine model, since the shared meaning of entry, evidence and effect across sibling registers is currently unanchored." ] }, "statistics": { "sources": 12, "bundles": 6, "layers": 13, "findings": 26, "questions": 103, "artifacts": 9, "functions": 10 } }