# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T13:43:55Z", "synthesisSha256": "74ffd31b008d315cfaee9d703f31898f6226cfef1f03e4cc86b1056cd2ae3f92", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-015", "registryId": "vr.wm-xct-015", "name": "Event Register", "version": "1.0.0-reviewable", "previousVersions": [ { "version": "0.2.0-legacy", "url": "https://github.com/ver-cy/world-models/blob/feat/mega-model-registry/models/registries-ledgers/R3-event-register.md" } ], "entryKind": "pattern", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.EVREG" ], "tags": [ "event", "register", "xct.evreg" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-015-event-register/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-015", "model": { "registry_id": "vr.wm-xct-015", "model_id": "WM-XCT-015", "name": "Event Register", "entry_kind": "pattern", "purpose": "Describe governed domain event histories with explicit admission, order, time, integrity, replay and retention contracts.", "scope_statement": "A reusable pattern instantiated as a governed logical event register. It owns record admission and the declared history surface, including log-local positions, evidence, checkpoints and read boundaries. It does not own the truth or lifecycle of the domain objects described by events. Append-only means no silent rewrite of admitted history within the declared retention and integrity profile; lawful disposition is a separate governed operation with explicit loss of replay or verification capability.", "in_scope": [ "Register identity, domain coverage, producer contracts, event envelopes and admission receipts", "Scoped ordering, occurrence and recording times, corrections, provenance and continuity evidence", "Integrity profiles, checkpoint and proof evidence, authorized replay, consumer positions, preservation and retirement" ], "out_of_scope": [ "Domain object master state, the occurrence itself, accounting balances and business transaction execution", "Identity issuance, access-policy evaluation, access-audit semantics and federation conflict resolution", "Implementing consensus, cryptographic algorithms, broker operations, key custody, legal advice or universal exactly-once processing" ], "boundary_notes": [ { "neighbor": "WM-XCT-013", "distinction": "The frozen inbound COMPOSE candidate sends registry changes here. The producer owns registry state and change meaning; this pattern owns admission, scoped order, replay, integrity evidence and retention. The edge does not guarantee atomic registry-plus-log writes; the adopting producer must evidence its handoff.", "source_refs": [ "SRC-001", "SRC-007" ] }, { "neighbor": "WM-ACT-015 Occurrence / Event", "distinction": "An occurrence may have several reports and appear in several logs. The local record is an attributed account with admission identity, not the occurrence itself.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "neighbor": "WM-XCT-014 Ledger / Account", "distinction": "No balances, debit-credit constraints or financial finality are inferred from an admitted event or a sealed checkpoint.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "neighbor": "WM-XCT-016 Identity Register", "distinction": "Producer, registrar, consumer and verifier identities are references. Identity creation and trust resolution remain delegated through a pinned adoption binding.", "source_refs": [ "SRC-003", "SRC-004" ] }, { "neighbor": "WM-XCT-004 Access Audit", "distinction": "Record an external audit-evidence reference for register operations; do not duplicate audit policy, disclosure interpretation or investigation lifecycle.", "source_refs": [ "SRC-004" ] }, { "neighbor": "WM-XCT-018 Registry Federation", "distinction": "A replay export can support mirroring, but remote authority, topology, cross-register reconciliation and federation execution remain outside this pattern.", "source_refs": [ "SRC-003", "SRC-007" ] }, { "neighbor": "Transport, proof and event-envelope profiles", "distinction": "Envelope validity is not durable admission. A broker position is not portable event identity. A proof is relative to its tree, checkpoint, algorithm and trust assumptions, not proof of real-world truth.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ] } ] }, "sources": [ { "id": "SRC-001", "title": "CloudEvents Specification", "organization": "Cloud Native Computing Foundation", "url": "https://github.com/cloudevents/spec/blob/v1.0.2/cloudevents/spec.md", "version_or_date": "v1.0.2 tag; context specversion remains 1.0", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:42:12Z", "relevance": "Source plus event ID identifies a distinct event; context and data have different roles. Used as optional envelope alignment, not a log, authorization or delivery guarantee." }, { "id": "SRC-002", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002, sections 4 and 5", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:42:12Z", "relevance": "Timestamp lexical syntax and offsets; not a clock synchronization, causal ordering or precision guarantee." }, { "id": "SRC-003", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 2013-04-30", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:42:12Z", "relevance": "Entity, activity, agent, derivation and revision relations support attribution of recorded claims without establishing their truth." }, { "id": "SRC-004", "title": "Guide to Computer Security Log Management", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-92.pdf", "version_or_date": "SP 800-92, September 2006; sections 4, 5.1, 5.4 and 5.6", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:42:12Z", "relevance": "Log governance, preservation, access, storage and operational review as a security-log example. Historical algorithms and terminology are not admitted as current cryptographic guidance." }, { "id": "SRC-005", "title": "Certificate Transparency Version 2.0", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9162.html", "version_or_date": "RFC 9162, December 2021, Experimental; obsoletes RFC 6962", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:42:12Z", "relevance": "Selected Merkle inclusion, consistency, signed checkpoint and shutdown concepts. Certificate-specific protocol semantics are not generalized as Event Register conformance." }, { "id": "SRC-006", "title": "JSON Canonicalization Scheme", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc8785.html", "version_or_date": "RFC 8785, June 2020, Informational; section 3", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:42:12Z", "relevance": "Optional JSON byte-representation alignment with input restrictions. Signing a representation requires a declared encoding; this model remains format neutral." }, { "id": "SRC-007", "title": "Apache Kafka Design", "organization": "Apache Software Foundation", "url": "https://kafka.apache.org/41/design/design/", "version_or_date": "Versioned 4.1 documentation; selected design sections accessed 2026-10-06", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:42:12Z", "relevance": "Implementation example of partition positions, replay, delivery qualifications and compaction. It supplies counterexamples to global order and permanent complete-history assumptions, not a required storage product." }, { "id": "SRC-008", "title": "Time Ontology in OWL", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/owl-time/", "version_or_date": "Displayed Candidate Recommendation Draft 2022-11-15; sections 3 and 4", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:42:12Z", "relevance": "Instants, intervals, temporal reference systems and granularity. Draft status is preserved; uncertain-time handling below is a proposed local profile, not an ontology conformance claim." } ], "structure": { "bundles": [ { "id": "mandate", "name": "Mandate and representation", "description": "Identify the register and the event assertions it can represent.", "rationale": "Authored grouping of related decisions; cited sources motivate the questions, not this exact hierarchy.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007" ], "layers": [ { "id": "register-boundary", "name": "Register boundary", "description": "Declare identity and stewardship separately from event identity.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007" ], "findings": [ { "id": "register-mandate", "name": "Register mandate and boundary", "description": "Proposed adoption contract for one logical register, its domain, registrar role, profiles and lifecycle. One domain may use several logs and partitions; exclusivity must be evidenced rather than assumed.", "source_refs": [ "SRC-004", "SRC-007" ], "questions": [ { "id": "register-mandate-q-01", "text": "Which domain and event classes fall within this register mandate?", "kind": "definition", "answer_data": [ "domain reference", "included and excluded event classes" ] }, { "id": "register-mandate-q-02", "text": "Which registrar role has authority for the current register profile?", "kind": "ownership", "answer_data": [ "registrar reference", "authority evidence", "profile revision" ] }, { "id": "register-mandate-q-03", "text": "Which state permits admission, reading, freezing or retirement of this register?", "kind": "lifecycle", "answer_data": [ "register state", "permitted transitions", "transition authority" ] } ], "data_elements": [ { "id": "register-mandate-data-01", "name": "Register ID", "description": "Stable local master identifier of the logical register.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "register-mandate-data-02", "name": "Domain reference", "description": "Governed domain boundary with explicit exclusions.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "register-mandate-data-03", "name": "Registrar mandate", "description": "Role reference, authority basis and effective profile revision.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "register-mandate-data-04", "name": "Register state", "description": "Proposed states: draft, active, suspended, frozen, retired; preserve transition evidence.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-007" ] } ], "artifacts": [ { "id": "register-mandate-artifact", "name": "Register mandate", "description": "Versioned evidence for register mandate and boundary, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "record-identity", "name": "Event identity and admission identity", "description": "Separate producer event identity from each register admission and storage position. Copying an event to another register does not necessarily create a new occurrence; a payload digest does not safely substitute for identity.", "source_refs": [ "SRC-001", "SRC-003" ], "questions": [ { "id": "record-identity-q-01", "text": "What source-qualified event key identifies the producer assertion across retries?", "kind": "identity", "answer_data": [ "source reference", "producer event ID", "identity scheme" ] }, { "id": "record-identity-q-02", "text": "How is each local admission linked to its register, position and original event key?", "kind": "relationship", "answer_data": [ "admission ID", "register ID", "partition and epoch", "position", "event key" ] }, { "id": "record-identity-q-03", "text": "How are same-key events with different content handled without silent replacement?", "kind": "exception", "answer_data": [ "collision disposition", "compared representation", "quarantine reference" ] } ], "data_elements": [ { "id": "record-identity-data-01", "name": "Event key", "description": "Source namespace plus event ID; keep issuer scope.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "record-identity-data-02", "name": "Admission ID", "description": "Unique receipt identity independent of payload hash.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "record-identity-data-03", "name": "Position binding", "description": "Register, partition, epoch and native position after admission.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "record-identity-data-04", "name": "Collision evidence", "description": "Links to conflicting submissions and disposition.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "record-identity-artifact", "name": "Identity and collision record", "description": "Versioned evidence for event identity and admission identity, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "representation", "name": "Representation contract", "description": "Pin envelope, payload and reference semantics.", "source_refs": [ "SRC-001", "SRC-003" ], "findings": [ { "id": "envelope-contract", "name": "Typed envelope and schema evolution", "description": "Separate the envelope version from the event-type and payload-schema versions. Reference domain meaning and subject identities; unknown extensions and unresolved references require explicit handling.", "source_refs": [ "SRC-001", "SRC-003" ], "questions": [ { "id": "envelope-contract-q-01", "text": "Which envelope, event type and payload schema versions govern this submitted record?", "kind": "classification", "answer_data": [ "envelope version", "event type", "schema reference" ] }, { "id": "envelope-contract-q-02", "text": "Which subject and actor references are carried, with what roles and resolution state?", "kind": "composition", "answer_data": [ "typed references", "role codes", "resolution state" ] }, { "id": "envelope-contract-q-03", "text": "Which incompatible or unknown fields cause rejection, quarantine or a documented lossy mapping?", "kind": "interoperability", "answer_data": [ "compatibility policy", "unknown-field rule", "mapping loss report" ] } ], "data_elements": [ { "id": "envelope-contract-data-01", "name": "Envelope profile", "description": "Pinned representation and context contract.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "envelope-contract-data-02", "name": "Event type and schema", "description": "Type identifier, domain schema reference and version state.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "envelope-contract-data-03", "name": "Subject and actor references", "description": "May be absent when the event profile allows it; never fabricate subjects.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "envelope-contract-data-04", "name": "Payload binding", "description": "Content type, protected payload reference, schema and extension treatment.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "envelope-contract-artifact", "name": "Envelope validation record", "description": "Versioned evidence for typed envelope and schema evolution, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "capture", "name": "Admission and correction", "description": "Record admission decisions without turning receipts into truth or execution authority.", "rationale": "Authored grouping of related decisions; cited sources motivate the questions, not this exact hierarchy.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007" ], "layers": [ { "id": "admission", "name": "Admission discipline", "description": "Validate producer scope, retries and acknowledgement evidence.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007" ], "findings": [ { "id": "admission-authority", "name": "Producer authorization and validation", "description": "Proposed admission gate binds a producer grant to a register, event class and policy version. The register consumes an external authorization decision; schema acceptance does not certify the assertion.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "admission-authority-q-01", "text": "What authorization evidence permits this producer to submit this event class now?", "kind": "authority", "answer_data": [ "producer reference", "grant scope", "decision reference", "expiry" ] }, { "id": "admission-authority-q-02", "text": "Which validation checks and payload limits determine admission eligibility?", "kind": "validation", "answer_data": [ "schema checks", "reference checks", "size limits", "validation result" ] }, { "id": "admission-authority-q-03", "text": "Where does a refused or suspicious submission remain accessible under a bounded quarantine policy?", "kind": "security", "answer_data": [ "refusal reason", "quarantine reference", "access class", "expiry" ] } ], "data_elements": [ { "id": "admission-authority-data-01", "name": "Authorization evidence", "description": "Decision and policy version resolved externally.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "admission-authority-data-02", "name": "Admission check result", "description": "Checks performed and accepted, rejected or quarantined outcome.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "admission-authority-data-03", "name": "Resource limits", "description": "Profile-specific sizes, rates and attachment constraints.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "admission-authority-data-04", "name": "Refusal record", "description": "Minimal controlled diagnostic; no accidental sensitive payload logging.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "admission-authority-artifact", "name": "Admission assessment", "description": "Versioned evidence for producer authorization and validation, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "admission-receipt", "name": "Commit evidence and retry outcomes", "description": "A receipt distinguishes rejected, pending, committed, duplicate and unknown outcomes under an adopted runtime contract. Lost acknowledgements require reconciliation. Local deduplication never establishes exactly-once downstream effects.", "source_refs": [ "SRC-001", "SRC-007" ], "questions": [ { "id": "admission-receipt-q-01", "text": "Which durable acknowledgement condition was met before the register reported a committed admission?", "kind": "evidence", "answer_data": [ "commit condition", "receipt", "durability scope" ] }, { "id": "admission-receipt-q-02", "text": "What retry key and retention window allow a timed-out producer to reconcile an uncertain result?", "kind": "process", "answer_data": [ "retry key", "deduplication window", "reconciliation query" ] }, { "id": "admission-receipt-q-03", "text": "How are producer-state changes reconciled when their event handoff is missing or duplicated?", "kind": "exception", "answer_data": [ "producer handoff reference", "reconciliation state", "responsible role" ] } ], "data_elements": [ { "id": "admission-receipt-data-01", "name": "Receipt outcome", "description": "Pending, committed, duplicate, rejected or unknown; never coerce unknown to success.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "admission-receipt-data-02", "name": "Durability condition", "description": "Pinned runtime acknowledgement semantics and failure assumptions.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "admission-receipt-data-03", "name": "Retry contract", "description": "Identity key, collision rule and deduplication horizon.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "admission-receipt-data-04", "name": "Handoff evidence", "description": "Producer-side transaction or reconciliation evidence; producer retains ownership.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] } ], "artifacts": [ { "id": "admission-receipt-artifact", "name": "Admission receipt", "description": "Versioned evidence for commit evidence and retry outcomes, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-001", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "assertion-revision", "name": "Assertion revision", "description": "Keep attributed corrections separate from silent mutation.", "source_refs": [ "SRC-001", "SRC-003" ], "findings": [ { "id": "correction-provenance", "name": "Correction and attribution", "description": "A correction adds an attributed assertion referencing earlier records. It preserves original admission evidence subject to disposition policy and does not silently turn a disputed report into a fact.", "source_refs": [ "SRC-003", "SRC-001" ], "questions": [ { "id": "correction-provenance-q-01", "text": "Which earlier record is corrected, superseded or disputed and by whose authority?", "kind": "provenance", "answer_data": [ "prior admission reference", "relation type", "asserting role", "authority basis" ] }, { "id": "correction-provenance-q-02", "text": "How does the domain profile interpret the correction without rewriting original record bytes?", "kind": "state", "answer_data": [ "interpretation rule", "correction event key", "effective applicability" ] }, { "id": "correction-provenance-q-03", "text": "Which evidence distinguishes reported, observed, derived and contested event claims?", "kind": "quality", "answer_data": [ "claim status", "source evidence", "derivation activity", "dispute references" ] } ], "data_elements": [ { "id": "correction-provenance-data-01", "name": "Correction relation", "description": "Typed earlier-record reference and reason.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "correction-provenance-data-02", "name": "Attribution", "description": "Agent and activity references with evidence; no automatic truth inference.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "correction-provenance-data-03", "name": "Interpretation rule", "description": "Domain-owned effect of supersession or dispute.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "correction-provenance-data-04", "name": "Claim status", "description": "Explicit evidential status and unresolved alternatives.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-001" ] } ], "artifacts": [ { "id": "correction-provenance-artifact", "name": "Correction linkage record", "description": "Versioned evidence for correction and attribution, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-003", "SRC-001" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "timeline", "name": "Order and temporal evidence", "description": "State which history and temporal ordering claims are supported.", "rationale": "Authored grouping of related decisions; cited sources motivate the questions, not this exact hierarchy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-007", "SRC-008" ], "layers": [ { "id": "sequence", "name": "Sequence and coverage", "description": "Preserve scoped positions and explain absent records.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007" ], "findings": [ { "id": "order-domain", "name": "Ordering scope and positions", "description": "Declare whether order is per register, partition or stream and preserve epochs across replacement. Append order, temporal order and causal relationships are different assertions. Global order is an optional evidenced profile.", "source_refs": [ "SRC-007", "SRC-003" ], "questions": [ { "id": "order-domain-q-01", "text": "Within which register, partition and epoch is the position order defined?", "kind": "definition", "answer_data": [ "ordering scope", "partition scheme", "epoch", "position comparator" ] }, { "id": "order-domain-q-02", "text": "Which explicit event references support causal or correlation claims across streams?", "kind": "relationship", "answer_data": [ "causal references", "correlation identifier", "basis and uncertainty" ] }, { "id": "order-domain-q-03", "text": "What prevents a repartition or failover from making old positions ambiguous?", "kind": "constraint", "answer_data": [ "epoch transition", "position mapping", "migration evidence" ] } ], "data_elements": [ { "id": "order-domain-data-01", "name": "Ordering scope", "description": "Declared ordering relation and position comparator.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-003" ] }, { "id": "order-domain-data-02", "name": "Partition and epoch", "description": "Use explicit single-stream values when no partitioning exists.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-003" ] }, { "id": "order-domain-data-03", "name": "Causal references", "description": "Typed claims independent of numeric or clock order.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-003" ] }, { "id": "order-domain-data-04", "name": "Position migration", "description": "Mappings and unresolved gaps across topology changes.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-003" ] } ], "artifacts": [ { "id": "order-domain-artifact", "name": "Ordering profile", "description": "Versioned evidence for ordering scope and positions, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-007", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "history-coverage", "name": "Continuity and durable history coverage", "description": "Distinguish retained history from filtered, compacted, unavailable or lost ranges. A healthy local sequence does not establish that every real-world event was produced or captured.", "source_refs": [ "SRC-007", "SRC-004" ], "questions": [ { "id": "history-coverage-q-01", "text": "What retained range and committed high-water mark bound this history claim?", "kind": "measurement", "answer_data": [ "range bounds", "watermark", "measurement time", "ordering scope" ] }, { "id": "history-coverage-q-02", "text": "Which absent positions are explained by filtering, control records, compaction or suspected loss?", "kind": "quality", "answer_data": [ "gap classification", "supporting evidence", "unexplained ranges" ] }, { "id": "history-coverage-q-03", "text": "What recovery evidence supports the durability claim after an interrupted append or replica failure?", "kind": "evidence", "answer_data": [ "recovery report", "failure assumptions", "restored range", "unresolved uncertainty" ] } ], "data_elements": [ { "id": "history-coverage-data-01", "name": "Coverage range", "description": "Bounds, visibility filter and measurement scope.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "history-coverage-data-02", "name": "Committed watermark", "description": "Observed position and runtime isolation semantics.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "history-coverage-data-03", "name": "Gap evidence", "description": "Qualified gaps without fabricated replacement events.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "history-coverage-data-04", "name": "Recovery attestation", "description": "Dated tests and incident-specific evidence; no default guarantee.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] } ], "artifacts": [ { "id": "history-coverage-artifact", "name": "History coverage report", "description": "Versioned evidence for continuity and durable history coverage, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-007", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "time-semantics", "name": "Time semantics", "description": "Represent asserted and recorded times with uncertainty.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ], "findings": [ { "id": "time-assertions", "name": "Occurrence, observation and recording times", "description": "Keep source occurrence time, observation time and register recording time distinct. Preserve approximate intervals, unknowns and clock evidence; an ingestion timestamp must not masquerade as a measured occurrence.", "source_refs": [ "SRC-002", "SRC-008", "SRC-001" ], "questions": [ { "id": "time-assertions-q-01", "text": "What occurrence instant, interval or unknown value did the source assert?", "kind": "temporal", "answer_data": [ "asserted temporal value", "precision", "source time convention" ] }, { "id": "time-assertions-q-02", "text": "When was the event observed and durably recorded, with which clock and offset evidence?", "kind": "provenance", "answer_data": [ "observed time", "recorded time", "clock source", "offset status" ] }, { "id": "time-assertions-q-03", "text": "How are late arrivals, conflicting clocks or insufficient precision represented without resequencing history?", "kind": "exception", "answer_data": [ "lateness classification", "clock uncertainty", "interpretation rule" ] } ], "data_elements": [ { "id": "time-assertions-data-01", "name": "Occurrence time assertion", "description": "Known instant, interval, partial value or explicit unknown plus precision and basis.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-008", "SRC-001" ] }, { "id": "time-assertions-data-02", "name": "Observed time", "description": "Observation time where evidenced; no invented precision.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-008", "SRC-001" ] }, { "id": "time-assertions-data-03", "name": "Recorded time", "description": "Register recording time with seconds and explicit offset or Z.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-008", "SRC-001" ] }, { "id": "time-assertions-data-04", "name": "Clock and lateness evidence", "description": "Uncertainty, normalization provenance and source-clock caveats.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-008", "SRC-001" ] } ], "artifacts": [ { "id": "time-assertions-artifact", "name": "Temporal assertion record", "description": "Versioned evidence for occurrence, observation and recording times, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-002", "SRC-008", "SRC-001" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "integrity", "name": "Integrity evidence", "description": "Describe protected representations and bounded verification claims.", "rationale": "Authored grouping of related decisions; cited sources motivate the questions, not this exact hierarchy.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "commitment", "name": "Commitment representation", "description": "Select a reproducible protected representation.", "source_refs": [ "SRC-005", "SRC-006" ], "findings": [ { "id": "integrity-representation", "name": "Integrity profile and protected representation", "description": "Define exactly which bytes or canonical representation are committed and how envelope, payload and detached references bind together. A digest, a signature and a chain are distinct mechanisms; choose and test a profile before claiming tamper evidence.", "source_refs": [ "SRC-005", "SRC-006" ], "questions": [ { "id": "integrity-representation-q-01", "text": "Which representation, fields and detached content are covered by the integrity commitment?", "kind": "definition", "answer_data": [ "protected representation", "coverage exclusions", "content binding" ] }, { "id": "integrity-representation-q-02", "text": "Which encoding, algorithm identifiers and verification profile make the commitment reproducible?", "kind": "interoperability", "answer_data": [ "encoding profile", "algorithm identifiers", "profile version", "test evidence" ] }, { "id": "integrity-representation-q-03", "text": "How are re-encoding, redaction or algorithm changes prevented from silently preserving an obsolete assurance claim?", "kind": "constraint", "answer_data": [ "change classification", "new commitment reference", "assurance downgrade" ] } ], "data_elements": [ { "id": "integrity-representation-data-01", "name": "Integrity profile", "description": "Pinned byte, algorithm and trust contract; may explicitly declare no cryptographic proof.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "integrity-representation-data-02", "name": "Protected representation", "description": "Original bytes or specified canonicalization and exclusions.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "integrity-representation-data-03", "name": "Commitment binding", "description": "Digest value, algorithm, register/epoch and payload coverage.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "integrity-representation-data-04", "name": "Transformation evidence", "description": "Derived views retain separate provenance and assurance limits.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "integrity-representation-artifact", "name": "Integrity profile record", "description": "Versioned evidence for integrity profile and protected representation, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "proofs", "name": "Checkpoints and proofs", "description": "Keep issuance, release and verification evidence distinct.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "checkpoint-evidence", "name": "Checkpoint and publication evidence", "description": "Record the range or tree size covered by a checkpoint and any signature or witness evidence. Checkpoints may have zero or several proofs. Disclosure is policy-bound; public availability is not a default requirement.", "source_refs": [ "SRC-005", "SRC-004" ], "questions": [ { "id": "checkpoint-evidence-q-01", "text": "Which register epoch, size or range and root commitment define this checkpoint?", "kind": "identity", "answer_data": [ "checkpoint ID", "register epoch", "covered range or tree size", "root" ] }, { "id": "checkpoint-evidence-q-02", "text": "Which signing or witnessing evidence and trust reference support this checkpoint?", "kind": "authority", "answer_data": [ "signer reference", "key identifier", "signature evidence", "trust policy" ] }, { "id": "checkpoint-evidence-q-03", "text": "Where and to whom was checkpoint evidence released, and with what freshness limits?", "kind": "access", "answer_data": [ "release reference", "recipient scope", "release time", "freshness policy" ] } ], "data_elements": [ { "id": "checkpoint-evidence-data-01", "name": "Checkpoint descriptor", "description": "Stable checkpoint ID, root, size/range and epoch.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "checkpoint-evidence-data-02", "name": "Signature and witness references", "description": "Optional profile-specific evidence with no private keys.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "checkpoint-evidence-data-03", "name": "Release record", "description": "Recipients, access class, availability and publication observations.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "checkpoint-evidence-data-04", "name": "Checkpoint state", "description": "Proposed, sealed, released, suspect or retired under the adopted profile.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-004" ] } ], "artifacts": [ { "id": "checkpoint-evidence-artifact", "name": "Checkpoint evidence record", "description": "Versioned evidence for checkpoint and publication evidence, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-005", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "proof-assessment", "name": "Inclusion, consistency and verification limits", "description": "Inclusion is relative to one commitment; consistency compares compatible checkpoints. Neither proves event truth or independent absence of divergent histories. Missing evidence is indeterminate, not verified.", "source_refs": [ "SRC-005", "SRC-003" ], "questions": [ { "id": "proof-assessment-q-01", "text": "Which leaf and checkpoint does this inclusion assessment bind, using which verifier profile?", "kind": "validation", "answer_data": [ "leaf binding", "checkpoint reference", "verifier version", "result" ] }, { "id": "proof-assessment-q-02", "text": "Which earlier and later checkpoints are compared for consistency under the same log profile?", "kind": "relationship", "answer_data": [ "checkpoint pair", "profile compatibility", "consistency result" ] }, { "id": "proof-assessment-q-03", "text": "What suspected fork, stale evidence or missing proof prevents a positive verification conclusion?", "kind": "exception", "answer_data": [ "failure category", "evidence references", "assurance limitation", "escalation reference" ] } ], "data_elements": [ { "id": "proof-assessment-data-01", "name": "Verification input set", "description": "Exact record and checkpoint references plus profile and available proof.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-003" ] }, { "id": "proof-assessment-data-02", "name": "Verification result", "description": "Verified, failed, indeterminate or not-applicable with reason.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-003" ] }, { "id": "proof-assessment-data-03", "name": "Verification provenance", "description": "Verifier identity, version, time and trust dependencies.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-003" ] }, { "id": "proof-assessment-data-04", "name": "Exception evidence", "description": "Restricted references for investigation by the responsible function.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-003" ] } ], "artifacts": [ { "id": "proof-assessment-artifact", "name": "Proof assessment", "description": "Versioned evidence for inclusion, consistency and verification limits, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-005", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "consumption", "name": "Consumption and disclosure", "description": "Read and derive views within current grants and actual retained history.", "rationale": "Authored grouping of related decisions; cited sources motivate the questions, not this exact hierarchy.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-007" ], "layers": [ { "id": "replay", "name": "Replay and projection", "description": "Track requested, delivered and interpreted history separately.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007" ], "findings": [ { "id": "consumer-position", "name": "Replay selection and consumer checkpoints", "description": "A replay request declares its scope and position vector; the receipt declares what was actually delivered. Consumer acknowledgement and external processing success are separate. Expired or incompatible cursors require explicit recovery.", "source_refs": [ "SRC-007", "SRC-004" ], "questions": [ { "id": "consumer-position-q-01", "text": "Which authorized scope, position vector and isolation boundary define this replay request?", "kind": "process", "answer_data": [ "consumer reference", "scope predicate", "cursor vector", "isolation profile" ] }, { "id": "consumer-position-q-02", "text": "Which delivered and acknowledged positions are recorded without assuming downstream effects?", "kind": "state", "answer_data": [ "delivered positions", "acknowledged positions", "effect evidence reference" ] }, { "id": "consumer-position-q-03", "text": "What response is required for an expired cursor, unavailable history or revoked grant?", "kind": "exception", "answer_data": [ "failure reason", "available range", "recovery option", "grant state" ] } ], "data_elements": [ { "id": "consumer-position-data-01", "name": "Replay selection", "description": "Consumer, register, filter and requested position vector.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "consumer-position-data-02", "name": "Delivery receipt", "description": "Actual range, omissions and emitted cursor.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "consumer-position-data-03", "name": "Consumer checkpoint", "description": "Consumer-owned acknowledgement with epoch and profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "consumer-position-data-04", "name": "Replay exception", "description": "No silent reset to earliest or latest position.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-004" ] } ], "artifacts": [ { "id": "consumer-position-artifact", "name": "Replay receipt", "description": "Versioned evidence for replay selection and consumer checkpoints, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-007", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "derived-view", "name": "Projection, export and reconstruction limits", "description": "A subject timeline or snapshot is a derived view with source bounds, filters and transformation version. State rebuilding requires domain rules and adequate history; register replay alone does not authorize business actions.", "source_refs": [ "SRC-003", "SRC-007" ], "questions": [ { "id": "derived-view-q-01", "text": "Which source ranges, filters and transform version produced this timeline or export?", "kind": "provenance", "answer_data": [ "input coverage", "filter", "transform version", "view revision" ] }, { "id": "derived-view-q-02", "text": "What omissions or schema migrations limit reconstruction from the supplied history?", "kind": "quality", "answer_data": [ "missing ranges", "migration report", "reconstruction assumptions" ] }, { "id": "derived-view-q-03", "text": "Which external domain process owns interpretation and any side effects of replayed records?", "kind": "authority", "answer_data": [ "domain process reference", "side-effect policy", "execution authority" ] } ], "data_elements": [ { "id": "derived-view-data-01", "name": "Projection lineage", "description": "Input range vector, filter and transformation identity.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "derived-view-data-02", "name": "View reference", "description": "Separately identified output with version.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "derived-view-data-03", "name": "Reconstruction limits", "description": "Explicit full, partial or unknown coverage and migration caveats.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "derived-view-data-04", "name": "Consumer process reference", "description": "Domain interpretation remains external.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] } ], "artifacts": [ { "id": "derived-view-artifact", "name": "Projection manifest", "description": "Versioned evidence for projection, export and reconstruction limits, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "read-access", "name": "Read access", "description": "Control payload and metadata disclosure.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "findings": [ { "id": "disclosure-scope", "name": "Payload, metadata and proof disclosure", "description": "Read decisions cover payloads, indexes, cursor metadata and proofs separately. A permitted proof can still reveal association or activity. Views must recheck current grants and preserve the distinction between hidden and absent records.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "disclosure-scope-q-01", "text": "Which current authorization decision permits this recipient to see payloads and context metadata?", "kind": "access", "answer_data": [ "recipient reference", "policy decision", "field scope", "expiry" ] }, { "id": "disclosure-scope-q-02", "text": "What linkage or inference risk is introduced by indexes, digests, proof paths or counts?", "kind": "privacy", "answer_data": [ "exposure assessment", "minimization rule", "restricted fields" ] }, { "id": "disclosure-scope-q-03", "text": "How is a redacted or filtered response described without revealing protected existence details?", "kind": "security", "answer_data": [ "response policy", "redaction basis", "audit evidence reference" ] } ], "data_elements": [ { "id": "disclosure-scope-data-01", "name": "Disclosure decision", "description": "External policy decision with version and recipient scope.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "disclosure-scope-data-02", "name": "Field and artifact scope", "description": "Separate payload, metadata, proof and operational views.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "disclosure-scope-data-03", "name": "Exposure assessment", "description": "Profile-specific inference and minimization analysis.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "disclosure-scope-data-04", "name": "Response evidence", "description": "Minimal access-audit references governed externally.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "disclosure-scope-artifact", "name": "Disclosure assessment", "description": "Versioned evidence for payload, metadata and proof disclosure, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "continuity", "name": "Preservation and continuity", "description": "Govern the end of retention and the evolution of the register.", "rationale": "Authored grouping of related decisions; cited sources motivate the questions, not this exact hierarchy.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-007" ], "layers": [ { "id": "preservation", "name": "Preservation and disposition", "description": "Document component schedules, holds and loss of capability.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-007" ], "findings": [ { "id": "retention-coverage", "name": "Retention, preservation holds and replay horizon", "description": "Apply an adopted retention schedule separately to payloads, metadata, proofs and consumer checkpoints. Hold decisions are externally authorized. A compacted stream may support a latest-state view while losing event history.", "source_refs": [ "SRC-004", "SRC-007" ], "questions": [ { "id": "retention-coverage-q-01", "text": "Which retention class and clock start govern each record component?", "kind": "retention", "answer_data": [ "component class", "schedule reference", "start basis", "expiry rule" ] }, { "id": "retention-coverage-q-02", "text": "Which preservation hold covers the selected records and who can review or release it?", "kind": "authority", "answer_data": [ "hold reference", "scope", "review authority", "release evidence" ] }, { "id": "retention-coverage-q-03", "text": "What minimum replay and verification capabilities remain after the proposed compaction?", "kind": "requirement", "answer_data": [ "retained material", "lost capabilities", "consumer impact", "declared horizon" ] } ], "data_elements": [ { "id": "retention-coverage-data-01", "name": "Component schedule", "description": "Payload, metadata, proof and cursor rules with policy versions.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "retention-coverage-data-02", "name": "Hold references", "description": "External authorized preservation decisions and review dates.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "retention-coverage-data-03", "name": "Replay horizon", "description": "Available history, snapshot dependencies and uncertainty.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-007" ] }, { "id": "retention-coverage-data-04", "name": "Compaction impact", "description": "Capabilities lost or retained; no automatic proof-preservation assertion.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] } ], "artifacts": [ { "id": "retention-coverage-artifact", "name": "Preservation assessment", "description": "Versioned evidence for retention, preservation holds and replay horizon, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "disposition-evidence", "name": "Controlled disposition and residual evidence", "description": "Disposition changes availability under explicit authority rather than rewriting historical claims. Hashes, encrypted payloads and tombstones may retain sensitive associations; none automatically resolves erasure obligations.", "source_refs": [ "SRC-004", "SRC-001", "SRC-005" ], "questions": [ { "id": "disposition-evidence-q-01", "text": "What approved disposition action and hold check cover these payloads and replicas?", "kind": "decision", "answer_data": [ "approval reference", "hold check", "component and replica scope" ] }, { "id": "disposition-evidence-q-02", "text": "What residual identifiers, digests or proof material can lawfully remain under the adopting policy?", "kind": "privacy", "answer_data": [ "residual inventory", "basis", "retention limit", "linkability assessment" ] }, { "id": "disposition-evidence-q-03", "text": "What evidence records completed, partial or failed disposal and its effect on future verification?", "kind": "evidence", "answer_data": [ "disposal receipt", "unreached copies", "remaining capability", "failure reason" ] } ], "data_elements": [ { "id": "disposition-evidence-data-01", "name": "Disposition authority", "description": "External schedule and explicit scoped approval.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-001", "SRC-005" ] }, { "id": "disposition-evidence-data-02", "name": "Execution receipt", "description": "Executor, scope, time, outcome and remaining replicas.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-001", "SRC-005" ] }, { "id": "disposition-evidence-data-03", "name": "Residual record policy", "description": "Minimal lawful tombstone or removal without permanent-identity assumptions.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-001", "SRC-005" ] }, { "id": "disposition-evidence-data-04", "name": "Assurance change", "description": "Unavailable payload, lost proof ability and revised replay horizon.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "disposition-evidence-artifact", "name": "Disposition receipt", "description": "Versioned evidence for controlled disposition and residual evidence, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-004", "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "operations", "name": "Operational continuity", "description": "Keep health, recovery and closure evidence.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ], "findings": [ { "id": "operational-continuity", "name": "Health, recovery and register succession", "description": "Record lag, capacity, failed admissions and verification outcomes with observation scope. Freezing or migrating a register preserves resolvable lineage and explicit lost capabilities. Infrastructure recovery is delegated to the operator.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ], "questions": [ { "id": "operational-continuity-q-01", "text": "Which observed lag, failure and capacity measures trigger a review of the register service?", "kind": "measurement", "answer_data": [ "metric definitions", "units", "observation window", "threshold profile" ] }, { "id": "operational-continuity-q-02", "text": "Which restore or migration evidence proves the available range and identity mapping?", "kind": "validation", "answer_data": [ "restore test", "range coverage", "epoch mapping", "unresolved losses" ] }, { "id": "operational-continuity-q-03", "text": "What final checkpoint, successor reference and read policy govern a frozen or retired register?", "kind": "lifecycle", "answer_data": [ "closure authority", "final checkpoint", "successor reference", "read horizon" ] } ], "data_elements": [ { "id": "operational-continuity-data-01", "name": "Health observation", "description": "Measures with units, method, time, scope and confidence.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] }, { "id": "operational-continuity-data-02", "name": "Recovery evidence", "description": "Operational tests or incident reports; no fabricated success.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] }, { "id": "operational-continuity-data-03", "name": "Succession binding", "description": "Old and new identities, epochs, mapping and closure reasons.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] }, { "id": "operational-continuity-data-04", "name": "Closure profile", "description": "Admission cutoff, final evidence and access/retention obligations.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "operational-continuity-artifact", "name": "Continuity and closure report", "description": "Versioned evidence for health, recovery and register succession, with issuing role, scope, observation time and limitations.", "media_or_form": [ "Structured record", "Human-readable projection" ], "serial": true, "identity_strategy": "Authoritative master-system artifact ID first; otherwise governed IRI or locally assigned UUID. Include register reference, artifact kind and revision in the binding; time and digest alone are not identity.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "append-event", "name": "Admit event", "description": "Proposed, unimplemented operation contract. Assess and, only through an adopted runtime binding, append a domain event. This research run performs no append.", "inputs": [ "Register profile and expected epoch", "Producer assertion, event key and protected representation", "Current external authorization decision and retry key" ], "outputs": [ "Committed, duplicate, rejected, pending or unknown receipt", "Admission identity and position only when established" ], "preconditions": [ "Register active, grant current, schema accepted and resource limits met", "Atomic deduplication/admission and durability contract implemented and tested" ], "effects": [ "An authorized new record gains a local admission; prior record bytes are not overwritten", "Retry collision is quarantined or refused; uncertain commit is reconciled, never guessed", "No domain-state change or downstream effect is implied" ], "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "append-correction", "name": "Record correction link", "description": "Proposed, unimplemented operation contract. Admit a new correction assertion under the same admission contract.", "inputs": [ "Earlier admission references", "Correcting event, reason and authority", "Expected register epoch" ], "outputs": [ "New correction receipt or explicit refusal", "Typed revision or dispute links" ], "preconditions": [ "Target references resolvable or explicitly unresolved", "Correction authority and ordinary admission requirements satisfied" ], "effects": [ "Adds attributed evidence without rewriting earlier protected representation", "Domain consumers decide meaning under their pinned interpretation rules" ], "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "seal-checkpoint", "name": "Record sealed checkpoint", "description": "Proposed, unimplemented operation contract. Bind selected committed history to externally produced checkpoint evidence.", "inputs": [ "Register epoch and committed range", "Integrity profile and root evidence", "Signer or witness references when required" ], "outputs": [ "Checkpoint record or refused/indeterminate result" ], "preconditions": [ "Integrity implementation and algorithm profile tested", "Registrar authority and complete commitment inputs available" ], "effects": [ "Records exact protected range and optional signing evidence", "Does not make evidence public, certify truth or grant access", "Missing or conflicting inputs prevent a sealed-success claim" ], "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "assess-proof", "name": "Assess proof evidence", "description": "Proposed, unimplemented operation contract. Invoke an adopted verifier and record its bounded result.", "inputs": [ "Exact record/leaf and checkpoint pair as applicable", "Proof material and pinned verifier profile", "Trust references and authorized evidence access" ], "outputs": [ "Verified, failed, indeterminate or not-applicable assessment" ], "preconditions": [ "Profile declares inclusion or consistency semantics", "Verifier implementation and test evidence available; otherwise return indeterminate" ], "effects": [ "Creates an assessment with input references and limitations", "Flags suspicious divergence for separate investigation; does not repair history or certify event truth" ], "source_refs": [ "SRC-005", "SRC-003" ] }, { "id": "replay-slice", "name": "Read authorized history slice", "description": "Proposed, unimplemented operation contract. Read a bounded retained slice and issue a qualified receipt.", "inputs": [ "Consumer and current grant", "Filter, position vector and isolation boundary", "Limits and output profile" ], "outputs": [ "Visible history slice", "Delivery receipt, omissions and next cursor or explicit exception" ], "preconditions": [ "Grant evaluated externally for payload, metadata and proof access", "Requested positions resolve to retained history or explicit failure" ], "effects": [ "Records delivered positions without marking external business processing complete", "No silent cursor reset, hidden side-effect execution or canonical-state rebuild" ], "source_refs": [ "SRC-007", "SRC-004" ] }, { "id": "plan-disposition", "name": "Assess disposition proposal", "description": "Proposed, unimplemented operation contract. Prepare a reviewable component-level retention and disposal assessment.", "inputs": [ "Selected components and replica inventory", "Schedule, holds and authority references", "Expected register/profile revision" ], "outputs": [ "Eligible, blocked or indeterminate disposition plan", "Replay, privacy and proof-impact assessment" ], "preconditions": [ "Current policy and hold evidence accessible", "Authorized custodian role and complete scope identified" ], "effects": [ "Records a proposal and required approvals; executes no deletion", "Unresolved holds or replica scope block eligibility", "Separate authorized execution may later attach a receipt and revise availability claims" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-007" ] } ], "composition": [ { "target": "WM-XCT-013", "relation": "REFERENCE", "purpose": "Proposed backlink to the producer in the frozen inbound COMPOSE candidate. It does not reverse or replace that candidate edge or import producer-state lifecycle.", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "target": "WM-ACT-015", "relation": "REFERENCE", "purpose": "Optional domain occurrence reference; preserve reported-event identity independently. Pin the binding before adoption.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "WM-XCT-016", "relation": "REFERENCE", "purpose": "Candidate identity-master binding for registrar, producers, consumers and verifiers; identity issuance remains external.", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "target": "WM-XCT-004", "relation": "REFERENCE", "purpose": "Candidate external access-audit evidence binding; no local reimplementation of audit-trail semantics.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "WM-XCT-018", "relation": "REFERENCE", "purpose": "Optional federation consumer and provenance references; do not inherit legacy mandatory federation composition.", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] }, { "target": "CloudEvents v1.0.2", "relation": "ALIGN", "purpose": "Optional envelope mapping; preserve identity and explicit mapping losses without assuming durability or universal payload schema.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "PROV-O Recommendation 2013-04-30", "relation": "ALIGN", "purpose": "Optional attribution and derivation vocabulary, not a truth or legal-admissibility certificate.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "RFC 9162 selected proof concepts", "relation": "ALIGN", "purpose": "Conceptual alignment only; the experimental certificate protocol is not a general event-register standard.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "RFC 8785", "relation": "ALIGN", "purpose": "Optional JSON canonical representation where its input restrictions are satisfied; no required storage format.", "required": false, "source_refs": [ "SRC-006" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Identify the domain registrar by role and governed reference; never use a brand as owner.", "Pin the register namespace, domain boundary and authority source.", "Declare event, integrity, ordering, retention, privacy and consumer profiles with versions.", "Bind identity, authorization, audit, key custody and storage operators without copying their lifecycles.", "Provide Name, Type, Specification URL, Storage type URL, Interface URL and Processes URL even for non-file storage." ], "namespace_guidance": "Use the adopting Dimension namespace for register and artifact identities. Keep source event namespace, log admission ID, storage position and checkpoint identity separate.", "registry_links": [ "vr.wm-xct-015", "WM-XCT-013 inbound COMPOSE candidate", "Legacy R3 and world.eventRegister are migration references, not authorities." ] }, "canon_and_patch": { "canonicalization_rules": [ "Research assurance is reviewable-draft; local serialization does not establish canonical content.", "Preserve source bytes or an explicitly selected canonical representation, including algorithm and input restrictions. Human-facing formatting is not an integrity encoding." ], "patch_rules": [ "Correct domain assertions by new attributed records; never silently replace committed event content.", "Version mutable register configuration and consumer metadata with expected revision checks and effective scope.", "Disposition is a separately authorized, recorded availability change under the retention policy, not a covert history patch." ], "compatibility_rules": [ "Pin envelope, domain schema, identity, order and proof profiles separately; test changes and record losses.", "Changing an epoch, position scheme or proof profile requires explicit lineage; do not relabel historical receipts.", "Required/optional instance fields, nested schemas and transport adapters remain adoption work." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier", "Governed global identifier or IRI", "UUID or ULID assigned within the adopting Dimension" ], "timestamp_rule": "Represent known instants using RFC 3339 with seconds and an explicit offset or Z. Keep occurrence time, observation time and ingestion/recording time separate. Preserve source precision, unknown local offset and uncertain intervals without inventing an instant.", "serial_naming_rule": "Use register reference, artifact kind, stable artifact ID and revision. Dates, event positions and hashes alone must not become universal identifiers.", "integrity_rule": "Declare protected bytes, algorithms, commitment scope, key/trust references and verification evidence. A checksum is not a signature; inclusion is not truth or complete capture. No current algorithm suitability is certified here." }, "policies": [ "Collect only event content and context needed for the declared purpose; sensitive subjects remain protected and dangerous-domain records remain at policy level.", "Delegate authorization and legal applicability to adopted policies. Deny access when grant or scope is unknown.", "Keep failed proof, partial history and uncertain commit outcomes visible without exposing restricted details.", "Retention is component-specific. Preserve under valid holds; dispose only under scoped authority with availability and assurance changes recorded. Neither hash retention nor encryption establishes anonymization or completed erasure.", "No automated business action is authorized merely because an event was admitted or replayed." ], "crud": { "read": [ "Resolve current register profile and authorization before returning any payload, metadata, proof or cursor.", "Return declared visible coverage and explicit missing/expired history outcomes; use external access-audit references." ], "create": [ "Require producer grant, schema profile, deduplication key and tested commit binding. Allocate admission identity independently from event identity.", "Add checkpoint, receipt and assessment records with responsible role, evidence and profile version." ], "update": [ "Append corrections to event assertions; preserve historical bytes subject to separately governed disposition.", "Use revision checks for configuration, access bindings and consumer positions; record prior values under their own retention rules." ], "delete": [ "Retention and deletion follow the adopting Dimension schedule and valid preservation holds. The authorized storage custodian executes disposal across the declared replicas; this research model supplies plans and receipts, not deletion machinery.", "Keep only a lawful minimal tombstone or residual evidence where permitted; removal may end replay or verification capability and must be stated. Do not guarantee perpetual immutable personal data." ] }, "roles": [ { "name": "Domain registrar", "responsibilities": [ "Approve scope, profiles and register succession; resolve mandate references." ] }, { "name": "Producer", "responsibilities": [ "Supply attributed event keys and schema-qualified assertions; reconcile uncertain receipts." ] }, { "name": "Register operator", "responsibilities": [ "Operate the adopted admission and storage binding; report failure and recovery evidence." ] }, { "name": "Consumer", "responsibilities": [ "Use current grants and declared cursors; own downstream processing and effects." ] }, { "name": "Verifier", "responsibilities": [ "Assess exact proof inputs under a pinned profile and report limitations." ] }, { "name": "Records custodian", "responsibilities": [ "Review schedules and holds; coordinate authorized disposition and replica evidence." ] } ], "access": { "default_rule": "Deny by default; an external current policy decision must permit the recipient, purpose, field scope and operation.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Authorized emergency access requires a bounded external policy decision and audit evidence; no automatic privilege escalation.", "Proof-only access is a separate grant and still needs metadata-risk review." ], "audit_requirements": [ "Reference the separately mastered access-audit record for grants, reads, appends and disposition actions.", "Record policy version, subject scope and outcome without copying sensitive payloads into operational diagnostics." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read AGENTS.md and the adopting Dimension authority and access policy.", "Read spec.yaml, research holds and pinned storage, ordering and integrity profiles.", "Resolve referenced identities and master records before making assertions or operations.", "Inspect instance evidence and explicit unknowns; require current grants and operational implementation before invoking proposed functions." ] } }, "coverage": { "claim": "Source-grounded proposed Event Register pattern reconciled with legacy R3 and assessed in a separate frozen-evidence local no-tools audit. Admission, scoped history, integrity evidence, replay and controlled disposition are covered as research contracts. Independent review, source verification and operational adoption remain holds; this is a reviewable draft, not a deployed or certified log.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Source event, admission, register, position, checkpoint and artifact identities are distinct." }, { "dimension": "lifecycle", "status": "covered", "notes": "Admission outcomes, corrections, register freezing and succession are explicit." }, { "dimension": "relationships", "status": "covered", "notes": "Inbound producer contract preserved; subject, identity, audit and federation boundaries are references." }, { "dimension": "temporal", "status": "covered", "notes": "Occurrence, observation and recording times retain clock scope and uncertainty." }, { "dimension": "provenance", "status": "covered", "notes": "Attribution, revisions, view derivation and proof assessments retain evidence." }, { "dimension": "ownership", "status": "covered", "notes": "Domain registrar, producer, operator and records custodian are roles." }, { "dimension": "validation", "status": "gap", "notes": "Research structure validated separately; nested instance schemas and operational conformance tests are not supplied." }, { "dimension": "access", "status": "covered", "notes": "Payloads, metadata, proofs and cursors require current grants and controlled views." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Schedules, holds, residual data and loss of replay/verification are separate decisions." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual mappings only; pinned neighbor packages and executable adapters remain unverified." }, { "dimension": "direct properties", "status": "covered", "notes": "Logical properties include domain, profile, state, range and evidence; physical dimensions do not describe this abstract pattern." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Receipts, coverage reports, health observations and proof assessments distinguish claims from measurements." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Six proposed contracts declare inputs, refusal paths, preconditions and bounded effects." }, { "dimension": "regional applicability", "status": "gap", "notes": "No legal jurisdiction, retention period or privacy-compliance claim is universal." }, { "dimension": "source verification", "status": "gap", "notes": "Browser-mediated selected sections were read; direct HTTP checks were not attempted under the stated sandbox restriction. Current versions and claim-level independent review remain open." } ], "known_omissions": [ "Independent external review is absent; Claude and Grok were skipped by owner instruction.", "No executable instance schema, atomic admission implementation, broker configuration or proof verifier is delivered.", "No evidence of operational throughput, global order, complete capture, end-to-end exactly-once effects or recovery objectives.", "Cryptographic suite selection, key rotation, witness coordination and fork detection require a tested security profile.", "Jurisdiction-specific retention, privacy, licensing and lawful residual-data review remain unresolved.", "No live HTTP status or response hashes were measured; check_sources.py is prepared for coordinator execution." ], "conflicts": [], "regional_assumptions": [ "Format-neutral technical pattern; no particular jurisdiction is assumed.", "NIST guidance is a historical US security-log example, not a universal legal rule.", "Certificate Transparency and the implementation documentation are bounded examples, not mandatory register protocols." ], "adversarial_checks": [ "Same event key with altered content must not silently overwrite a committed record.", "A later recording time cannot prove a later occurrence or causal dependency.", "A valid inclusion proof cannot establish truth, full capture or the absence of another divergent view.", "An expired cursor and a compacted log must not silently produce a supposedly complete replay.", "A retained digest or tombstone cannot automatically satisfy a request for erasure.", "An inbound registry change can have an uncertain handoff; no atomic producer-plus-register transaction is presumed." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "pattern", "status": "accepted", "rationale": "The registry already classifies this subject as a pattern. The result describes a reusable governed history contract instantiated by logical registers, not one occurrence or a master register of domain objects. Admission, scoped order, replay, integrity evidence and retention fit the frozen inbound relationship responsibility." }, "decisions": [ { "concept": "Pattern and instantiated register", "disposition": "accepted", "rationale": "A reusable contract can describe register identities and lifecycle states without becoming an individual occurrence or claiming to own domain object truth." }, { "concept": "Inbound registry composition", "disposition": "preserved", "rationale": "The WM-XCT-013 inbound COMPOSE candidate remains visible. The optional backlink does not reverse ownership. Producer-state lifecycle and atomic handoff are explicitly external and conditional." }, { "concept": "Legacy universal log and proof cardinalities", "disposition": "rejected", "rationale": "One log per domain, exactly one proof per checkpoint, mandatory subjects and public proof access are not justified as universal constraints. The draft instead records partition, profile and disclosure scope." }, { "concept": "Portable event identity and local position", "disposition": "accepted", "rationale": "Source event keys, admission IDs, partition/epoch positions and artifacts remain distinct. Same-key altered-content submissions have collision treatment rather than overwrite semantics." }, { "concept": "Admission and delivery guarantees", "disposition": "qualified", "rationale": "Envelope acceptance does not imply durable admission. Receipts preserve unknown outcomes and deduplication horizons, and the proposed append operation requires a tested atomic admission binding without promising downstream exactly-once effects." }, { "concept": "Correction, provenance and truth", "disposition": "separated", "rationale": "Corrections are new attributed assertions with domain-owned interpretation. Provenance and unresolved references cannot promote contested reports to truth or modify original protected bytes silently." }, { "concept": "Order and completeness", "disposition": "limited", "rationale": "Positions have a declared ordering scope and epoch. Gaps are classified by evidence; sequence continuity does not prove all real-world events were produced, captured or causally ordered." }, { "concept": "Temporal precision", "disposition": "qualified", "rationale": "Occurrence, observation and recording time are separate. Source precision, intervals, unknown offset and clock uncertainty are retained instead of inventing exact occurrence instants or rewriting append order." }, { "concept": "Protected representation and cryptographic profile", "disposition": "held for adoption", "rationale": "The draft distinguishes digest, signature, encoding and proof mechanisms. No generic serializer is called a canonicalization implementation, and absent proof capability may be stated explicitly. Algorithm and runtime conformance need tests." }, { "concept": "Proof assurance", "disposition": "limited", "rationale": "Checkpoint issuance, release and verification are distinct. Inclusion and consistency conclusions are bounded by exact inputs and trust references; missing evidence is indeterminate and event truth or absence of divergent histories is not certified." }, { "concept": "Replay and projections", "disposition": "accepted with limits", "rationale": "Delivery and acknowledgement positions do not certify downstream processing. Expired cursors, missing history and lossy projections require explicit responses; register replay grants no business execution authority." }, { "concept": "Disclosure and delegated policy", "disposition": "accepted", "rationale": "Payloads, metadata, proofs and cursors are separately scoped, including inference risks. Authorization evaluation, identity issuance, access-audit semantics and federation operations remain delegated." }, { "concept": "Append-only history and disposition", "disposition": "reconciled", "rationale": "The scope forbids silent mutation of retained history while allowing separately authorized disposition with explicit loss of availability or assurance. Holds and residual-data review prevent blanket immutability or hash-retention claims." }, { "concept": "Source status and scope", "disposition": "limited", "rationale": "The evidence pack documents browser-mediated selected readings of eight documents, zero direct HTTP attempts, an experimental proof protocol, an informational encoding scheme, a draft temporal ontology and historical log guidance. These limits survive publication." }, { "concept": "Candidate fields and executable schemas", "disposition": "deferred", "rationale": "Candidate data fields and artifacts are substantive research shapes but do not provide conditional nested schemas. Required fields apply to their relevant record kind; profile applicability, non-applicable proof records, adapters and failure fixtures need adoption tests." }, { "concept": "Independent review and provider attribution", "disposition": "waived and held", "rationale": "Claude and Grok were explicitly skipped. This is a separate local Codex self-audit with no new facts or tools during assessment, not an independent provider pass. No waived-provider additions or agreement are admitted." } ], "publicationHolds": [ "Independent external review is absent under the owner-authorized single-provider waiver. Claude and Grok were skipped; the separate local Codex no-tools self-audit is not a second-provider review.", "Live source and version verification remains incomplete. Browser-mediated selected sections from eight primary documents were reviewed, but no direct HTTP checks were attempted under the stated sandbox restriction. HTTP status, response hashes, current versions, errata and independent claim support remain unverified. The coordinator can run check_sources.py outside the sandbox.", "Operational adoption requires conditional nested schemas, pinned neighbor bindings, tested atomic admission and replay behavior, protected-byte mappings, cryptographic profiles, key and trust management, and adversarial recovery/disposition fixtures. No runtime, performance, security or protocol conformance is certified.", "Jurisdiction-specific retention, privacy, preservation holds, licensing and lawful residual-data treatment require qualified profile review. Digests, encrypted payloads and tombstones are not automatically anonymous or sufficient evidence of erasure.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Complete direct HTTP retrieval, version and errata checks, licensing assessment and independent claim-level source review without treating retrieval success as substantive verification.", "Develop conditional instance schemas and operational fixtures for retry collisions, uncertain commits, producer handoff gaps, epoch changes, clock uncertainty, invalid proofs, expired cursors, revoked grants and partial disposal.", "Pin identity, authorization, audit, federation, storage and proof bindings; review cryptographic and legal profiles before any operational deployment.", "Restore independent external review before any canonical or publishable-draft promotion." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 18, "questions": 54, "artifacts": 18, "functions": 6 } }