World Models · Published

Attestation / Credential

Represent issuer-asserted claims with durable identity, evidence, validity, status, securing and purpose-bound presentation while remaining independent of storage and interface format.

AI YAMLAGENTS.mdResearch evidence
Published. Research assurance: reviewable-draft. The Codex-only synthesis is published under an explicit repository-owner provider waiver. It passed structural validation and a separate no-tools adversarial audit, but remains a reviewable draft until independent second-provider review and the holds below are closed.
Catalogue IDWM-XCT-017
Version0.3.0-research.1
Previous version-
Typeaggregate
ValidationPassed
Synthesis digestsha256:44b3813b8d883e23…
11Sources
6Bundles
12Layers
24Findings
72Questions
24Artifacts
Format-independent logical structure

Bundles → Layers → Findings → Questions + Artifacts

attestation-definition-identity-and-schemaAttestation definition, identity and schema2 layers

Defines what the issued assertion is and how its class and instance are identified.

concept-class-and-instance-identityConcept, class and instance identity2 findings

Separates the asserted meaning from the credential container and each representation.

attestation-claim-credential-certificate-license-and-permit-distinction

Attestation, claim, credential, certificate, licence and permit distinction

Governed class, definition, legal or technical effect, inclusion and exclusion criteria and relation among assertion, evidence container and external grant.

Questions
  1. What identity, class, role, scope, version and values define attestation, claim, credential, certificate, licence and permit distinction?identity
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support attestation, claim, credential, certificate, licence and permit distinction?evidence
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is attestation, claim, credential, certificate, licence and permit distinction validated, disclosed, contested, corrected, superseded and retained without changing issued history?validation
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Attestation, claim, credential, certificate, licence and permit distinction recordVersioned evidence-bearing record for attestation, claim, credential, certificate, licence and permit distinction with credential binding, authority, time, provenance and disclosure marking.
credential-identifier-type-version-lineage-and-representation-identity

Credential identifier, type, version, lineage and representation identity

Credential and attestation IDs, type hierarchy, profile version, predecessor or successor, representation ID, issuer serial and authoritative registry.

Questions
  1. What identity, class, role, scope, version and values define credential identifier, type, version, lineage and representation identity?definition
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support credential identifier, type, version, lineage and representation identity?authority
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is credential identifier, type, version, lineage and representation identity validated, disclosed, contested, corrected, superseded and retained without changing issued history?interoperability
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Credential identifier, type, version, lineage and representation identity recordVersioned evidence-bearing record for credential identifier, type, version, lineage and representation identity with credential binding, authority, time, provenance and disclosure marking.
claim-model-schema-and-subject-bindingClaim model, schema and subject binding2 findings

Defines what is asserted, about which subject, under which vocabulary and evidence.

claim-set-predicate-value-language-unit-source-and-confidence

Claim set, predicate, value, language, unit, source and confidence

Typed claim paths, predicates, values or references, language, units, source assertion, confidence, uncertainty and explicit unknowns.

Questions
  1. What identity, class, role, scope, version and values define claim set, predicate, value, language, unit, source and confidence?relationship
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support claim set, predicate, value, language, unit, source and confidence?temporal
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is claim set, predicate, value, language, unit, source and confidence validated, disclosed, contested, corrected, superseded and retained without changing issued history?access
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Claim set, predicate, value, language, unit, source and confidence recordVersioned evidence-bearing record for claim set, predicate, value, language, unit, source and confidence with credential binding, authority, time, provenance and disclosure marking.
credential-schema-vocabulary-context-profile-and-subject-binding

Credential schema, vocabulary, context, profile and subject binding

Schema and vocabulary IDs and versions, semantic context, required claims, subject reference, subject role and binding method.

Questions
  1. What identity, class, role, scope, version and values define credential schema, vocabulary, context, profile and subject binding?requirement
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support credential schema, vocabulary, context, profile and subject binding?decision
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is credential schema, vocabulary, context, profile and subject binding validated, disclosed, contested, corrected, superseded and retained without changing issued history?exception
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Credential schema, vocabulary, context, profile and subject binding recordVersioned evidence-bearing record for credential schema, vocabulary, context, profile and subject binding with credential binding, authority, time, provenance and disclosure marking.
parties-authority-issuance-and-custodyParties, authority, issuance and custody2 layers

Makes issuer authority, issuance evidence and holder custody attributable.

issuer-subject-holder-verifier-and-authorityIssuer, subject, holder, verifier and authority2 findings

References external actors and the scoped authority for their roles.

issuer-identity-role-mandate-scope-delegation-and-authority-validity

Issuer identity, role, mandate, scope, delegation and authority validity

External issuer, issuing role, mandate or accreditation, attestation classes, jurisdiction, delegation chain and effective interval.

Questions
  1. What identity, class, role, scope, version and values define issuer identity, role, mandate, scope, delegation and authority validity?ownership
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support issuer identity, role, mandate, scope, delegation and authority validity?provenance
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is issuer identity, role, mandate, scope, delegation and authority validity validated, disclosed, contested, corrected, superseded and retained without changing issued history?privacy
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Issuer identity, role, mandate, scope, delegation and authority validity recordVersioned evidence-bearing record for issuer identity, role, mandate, scope, delegation and authority validity with credential binding, authority, time, provenance and disclosure marking.
subject-holder-presenter-verifier-and-relying-party-reference

Subject, holder, presenter, verifier and relying-party reference

External actor IDs, protocol roles, subject-holder relation, representative authority, role validity and privacy marking.

Questions
  1. What identity, class, role, scope, version and values define subject, holder, presenter, verifier and relying-party reference?classification
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support subject, holder, presenter, verifier and relying-party reference?quality
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is subject, holder, presenter, verifier and relying-party reference validated, disclosed, contested, corrected, superseded and retained without changing issued history?security
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Subject, holder, presenter, verifier and relying-party reference recordVersioned evidence-bearing record for subject, holder, presenter, verifier and relying-party reference with credential binding, authority, time, provenance and disclosure marking.
application-decision-issuance-delivery-and-custodyApplication, decision, issuance, delivery and custody2 findings

Records credential-specific acts without importing generic workflow or wallet masters.

issuance-request-eligibility-evidence-assessment-and-decision-reference

Issuance request, eligibility evidence, assessment and decision reference

External request, criteria and policy versions, evidence, assessor, outcome, reasons, appeals and decision provenance.

Questions
  1. What identity, class, role, scope, version and values define issuance request, eligibility evidence, assessment and decision reference?composition
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support issuance request, eligibility evidence, assessment and decision reference?measurement
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is issuance request, eligibility evidence, assessment and decision reference validated, disclosed, contested, corrected, superseded and retained without changing issued history?validation
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Issuance request, eligibility evidence, assessment and decision reference recordVersioned evidence-bearing record for issuance request, eligibility evidence, assessment and decision reference with credential binding, authority, time, provenance and disclosure marking.
issuance-event-issuer-copy-holder-copy-delivery-acceptance-and-custody

Issuance event, issuer copy, holder copy, delivery, acceptance and custody

Issuance act, authoritative issuer record, holder representation, delivery channel, receipt, custody location, integrity and recovery rules.

Questions
  1. What identity, class, role, scope, version and values define issuance event, issuer copy, holder copy, delivery, acceptance and custody?state
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support issuance event, issuer copy, holder copy, delivery, acceptance and custody?lifecycle
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is issuance event, issuer copy, holder copy, delivery, acceptance and custody validated, disclosed, contested, corrected, superseded and retained without changing issued history?retention
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Issuance event, issuer copy, holder copy, delivery, acceptance and custody recordVersioned evidence-bearing record for issuance event, issuer copy, holder copy, delivery, acceptance and custody with credential binding, authority, time, provenance and disclosure marking.
validity-status-and-lifecycleValidity, status and lifecycle2 layers

Represents time-qualified standing and non-destructive change.

validity-terms-and-conditionsValidity terms and conditions2 findings

Separates issuance time, effective validity and usage conditions.

issued-valid-from-valid-until-effective-observed-and-knowledge-time

Issued, valid-from, valid-until, effective, observed and knowledge time

Distinct RFC 3339 event times, timezone, accuracy, source clock, uncertainty, interval boundaries and later correction knowledge.

Questions
  1. What identity, class, role, scope, version and values define issued, valid-from, valid-until, effective, observed and knowledge time?identity
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support issued, valid-from, valid-until, effective, observed and knowledge time?evidence
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is issued, valid-from, valid-until, effective, observed and knowledge time validated, disclosed, contested, corrected, superseded and retained without changing issued history?validation
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Issued, valid-from, valid-until, effective, observed and knowledge time recordVersioned evidence-bearing record for issued, valid-from, valid-until, effective, observed and knowledge time with credential binding, authority, time, provenance and disclosure marking.
terms-of-use-jurisdiction-purpose-condition-limitation-and-dependency

Terms of use, jurisdiction, purpose, condition, limitation and dependency

Credential-specific use terms, jurisdiction, audience, prerequisite or external grant, restrictions, dependency and interpretation warning.

Questions
  1. What identity, class, role, scope, version and values define terms of use, jurisdiction, purpose, condition, limitation and dependency?definition
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support terms of use, jurisdiction, purpose, condition, limitation and dependency?authority
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is terms of use, jurisdiction, purpose, condition, limitation and dependency validated, disclosed, contested, corrected, superseded and retained without changing issued history?interoperability
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Terms of use, jurisdiction, purpose, condition, limitation and dependency recordVersioned evidence-bearing record for terms of use, jurisdiction, purpose, condition, limitation and dependency with credential binding, authority, time, provenance and disclosure marking.
status-method-events-and-lineageStatus method, events and lineage2 findings

Preserves status source, freshness, reason and successor chain.

status-source-method-entry-purpose-value-freshness-and-error

Status source, method, entry, purpose, value, freshness and error

Status service and authority, method profile, entry or index, status purpose, value, retrieved and next-update time, cache age and processing errors.

Questions
  1. What identity, class, role, scope, version and values define status source, method, entry, purpose, value, freshness and error?relationship
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support status source, method, entry, purpose, value, freshness and error?temporal
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is status source, method, entry, purpose, value, freshness and error validated, disclosed, contested, corrected, superseded and retained without changing issued history?access
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Status source, method, entry, purpose, value, freshness and error recordVersioned evidence-bearing record for status source, method, entry, purpose, value, freshness and error with credential binding, authority, time, provenance and disclosure marking.
activate-suspend-reinstate-revoke-expire-renew-correct-and-supersede-event

Activate, suspend, reinstate, revoke, expire, renew, correct and supersede event

Typed lifecycle event, prior and next state, authority, reason, effective time, evidence, reversibility, successor and notification.

Questions
  1. What identity, class, role, scope, version and values define activate, suspend, reinstate, revoke, expire, renew, correct and supersede event?requirement
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support activate, suspend, reinstate, revoke, expire, renew, correct and supersede event?decision
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is activate, suspend, reinstate, revoke, expire, renew, correct and supersede event validated, disclosed, contested, corrected, superseded and retained without changing issued history?exception
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Activate, suspend, reinstate, revoke, expire, renew, correct and supersede event recordVersioned evidence-bearing record for activate, suspend, reinstate, revoke, expire, renew, correct and supersede event with credential binding, authority, time, provenance and disclosure marking.
securing-integrity-and-verificationSecuring, integrity and verification2 layers

Binds a credential representation to named securing and validation methods.

proof-envelope-and-verification-materialProof envelope and verification material2 findings

Identifies the exact representation, securing mechanism and public material.

secured-representation-canonical-form-digest-media-type-and-envelope

Secured representation, canonical form, digest, media type and envelope

Credential bytes or external artifact, semantic representation, canonicalization, digest, media type, encoding, envelope and detached-content binding.

Questions
  1. What identity, class, role, scope, version and values define secured representation, canonical form, digest, media type and envelope?ownership
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support secured representation, canonical form, digest, media type and envelope?provenance
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is secured representation, canonical form, digest, media type and envelope validated, disclosed, contested, corrected, superseded and retained without changing issued history?privacy
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Secured representation, canonical form, digest, media type and envelope recordVersioned evidence-bearing record for secured representation, canonical form, digest, media type and envelope with credential binding, authority, time, provenance and disclosure marking.
proof-signature-suite-purpose-method-controller-key-and-parameters

Proof or signature suite, purpose, method, controller, key and parameters

Proof type, cryptosuite or signature algorithm, proof purpose, verification method and controller, public key ref, parameters, created time and proof value.

Questions
  1. What identity, class, role, scope, version and values define proof or signature suite, purpose, method, controller, key and parameters?classification
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support proof or signature suite, purpose, method, controller, key and parameters?quality
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is proof or signature suite, purpose, method, controller, key and parameters validated, disclosed, contested, corrected, superseded and retained without changing issued history?security
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Proof or signature suite, purpose, method, controller, key and parameters recordVersioned evidence-bearing record for proof or signature suite, purpose, method, controller, key and parameters with credential binding, authority, time, provenance and disclosure marking.
validation-trust-and-resultValidation, trust and result2 findings

Records exact checks and keeps technical verification separate from external acceptance.

schema-proof-path-key-status-time-and-policy-validation-checks

Schema, proof, path, key, status, time and policy validation checks

Validator and version, input digest, schema and semantic checks, signature or proof checks, path or key resolution, status, time and policy inputs.

Questions
  1. What identity, class, role, scope, version and values define schema, proof, path, key, status, time and policy validation checks?composition
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support schema, proof, path, key, status, time and policy validation checks?measurement
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is schema, proof, path, key, status, time and policy validation checks validated, disclosed, contested, corrected, superseded and retained without changing issued history?validation
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Schema, proof, path, key, status, time and policy validation checks recordVersioned evidence-bearing record for schema, proof, path, key, status, time and policy validation checks with credential binding, authority, time, provenance and disclosure marking.
verification-outcome-errors-evidence-assurance-trust-and-decision-separation

Verification outcome, errors, evidence, assurance, trust and decision separation

Valid, invalid or indeterminate outcome, structured errors, evidence, assurance, issuer-trust result, observation time and explicit non-authorization marker.

Questions
  1. What identity, class, role, scope, version and values define verification outcome, errors, evidence, assurance, trust and decision separation?state
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support verification outcome, errors, evidence, assurance, trust and decision separation?lifecycle
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is verification outcome, errors, evidence, assurance, trust and decision separation validated, disclosed, contested, corrected, superseded and retained without changing issued history?retention
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Verification outcome, errors, evidence, assurance, trust and decision separation recordVersioned evidence-bearing record for verification outcome, errors, evidence, assurance, trust and decision separation with credential binding, authority, time, provenance and disclosure marking.
presentation-disclosure-privacy-and-correlationPresentation, disclosure, privacy and correlation2 layers

Governs use of credentials without assuming every verifier receives the full issuer record.

request-purpose-and-disclosure-policyRequest, purpose and disclosure policy2 findings

Captures what a verifier asks for and why before disclosure.

presentation-request-verifier-purpose-audience-claims-format-nonce-and-expiry

Presentation request, verifier, purpose, audience, claims, format, nonce and expiry

Request ID, verifier and client, purpose, audience, requested claims and predicates, accepted formats, nonce, domain, issue and expiry time.

Questions
  1. What identity, class, role, scope, version and values define presentation request, verifier, purpose, audience, claims, format, nonce and expiry?identity
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support presentation request, verifier, purpose, audience, claims, format, nonce and expiry?evidence
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is presentation request, verifier, purpose, audience, claims, format, nonce and expiry validated, disclosed, contested, corrected, superseded and retained without changing issued history?validation
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Presentation request, verifier, purpose, audience, claims, format, nonce and expiry recordVersioned evidence-bearing record for presentation request, verifier, purpose, audience, claims, format, nonce and expiry with credential binding, authority, time, provenance and disclosure marking.
presentation-holder-binding-and-receiptPresentation, holder binding and receipt2 findings

Binds disclosed material to request context and records its attributable verification.

presentation-identifier-holder-binding-credential-set-disclosures-and-integrity

Presentation identifier, holder binding, credential set, disclosures and integrity

Presentation ID, presenter or holder, holder-binding proof, included credentials, disclosure manifest, format, request binding, digest and created time.

Questions
  1. What identity, class, role, scope, version and values define presentation identifier, holder binding, credential set, disclosures and integrity?relationship
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support presentation identifier, holder binding, credential set, disclosures and integrity?temporal
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is presentation identifier, holder binding, credential set, disclosures and integrity validated, disclosed, contested, corrected, superseded and retained without changing issued history?access
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Presentation identifier, holder binding, credential set, disclosures and integrity recordVersioned evidence-bearing record for presentation identifier, holder binding, credential set, disclosures and integrity with credential binding, authority, time, provenance and disclosure marking.
presentation-receipt-verification-use-event-retention-and-correlation-control

Presentation receipt, verification, use event, retention and correlation control

Receiver, receipt and verification times, purpose, outcome, onward use, retention, replay control, pairwise handles and correlation assessment.

Questions
  1. What identity, class, role, scope, version and values define presentation receipt, verification, use event, retention and correlation control?requirement
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support presentation receipt, verification, use event, retention and correlation control?decision
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is presentation receipt, verification, use event, retention and correlation control validated, disclosed, contested, corrected, superseded and retained without changing issued history?exception
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Presentation receipt, verification, use event, retention and correlation control recordVersioned evidence-bearing record for presentation receipt, verification, use event, retention and correlation control with credential binding, authority, time, provenance and disclosure marking.
interoperability-access-provenance-and-agent-governanceInteroperability, access, provenance and agent governance2 layers

Provides loss-aware mappings and safe autonomous lifecycle operations.

format-profile-and-legal-effect-crosswalkFormat, profile and legal-effect crosswalk2 findings

Maps W3C, X.509, SD-JWT and presentation profiles with explicit loss.

vc-data-integrity-x509-sd-jwt-and-openid4vp-crosswalk

VC, Data Integrity, X.509, SD-JWT and OpenID4VP crosswalk

Source and target versions, identity, issuer, subject, claim, validity, proof, status and presentation mappings, omissions, conflicts and round-trip class.

Questions
  1. What identity, class, role, scope, version and values define vc, data integrity, x.509, sd-jwt and openid4vp crosswalk?ownership
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support vc, data integrity, x.509, sd-jwt and openid4vp crosswalk?provenance
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is vc, data integrity, x.509, sd-jwt and openid4vp crosswalk validated, disclosed, contested, corrected, superseded and retained without changing issued history?privacy
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • VC, Data Integrity, X.509, SD-JWT and OpenID4VP crosswalk recordVersioned evidence-bearing record for vc, data integrity, x.509, sd-jwt and openid4vp crosswalk with credential binding, authority, time, provenance and disclosure marking.
access-retention-provenance-and-safe-operationsAccess, retention, provenance and safe operations2 findings

Protects claims and usage history while preserving issuer accountability.

issuer-holder-subject-verifier-status-public-auditor-and-regulator-view

Issuer, holder, subject, verifier, status-public, auditor and regulator view

Audience, purpose, authority, included fields, redactions, pseudonymization, freshness, expiry, disclosure record and re-identification risk.

Questions
  1. What identity, class, role, scope, version and values define issuer, holder, subject, verifier, status-public, auditor and regulator view?composition
    Expected answer
    • identifiers
    • classes and roles
    • versions and scope
    • values and unknowns
  2. Which issuer authority, source, evidence, method and event or effective time support issuer, holder, subject, verifier, status-public, auditor and regulator view?measurement
    Expected answer
    • authority
    • source and evidence
    • method and profile
    • event and effective time
    • confidence
  3. How is issuer, holder, subject, verifier, status-public, auditor and regulator view validated, disclosed, contested, corrected, superseded and retained without changing issued history?validation
    Expected answer
    • validation
    • access and disclosure
    • contest and correction
    • lineage
    • retention
Artifacts
  • Issuer, holder, subject, verifier, status-public, auditor and regulator view recordVersioned evidence-bearing record for issuer, holder, subject, verifier, status-public, auditor and regulator view with credential binding, authority, time, provenance and disclosure marking.

Publication holds

  • Live source and version verification is outstanding for all eleven sources; RFC 9901 as Selective Disclosure for JSON Web Tokens dated November 2025, the four W3C Recommendations all dated 15 May 2025, the OpenID4VP final of 9 July 2025, NIST SP 800-63-4 of July 2025 and the RFC 6960 update chain must each be re-resolved before canonical promotion.
  • Independent second-provider review is absent by explicit repository-owner waiver of both Claude and Grok; this Codex result plus a local no-tools adversarial audit is not external review and must be shown as such in every publication artifact.
  • The record must publish as reviewable-draft with the corrected subject-model entry kind aggregate, and must state that the frozen registry classification is a record-plane value that was not re-readable here because frozen_context was empty.
  • No approved relation rows exist; all proposed links to identity, mandate, evidence, key, grant, policy, decision and audit models stay unpublished holds and no relationship edges may be emitted.
  • Question kind labels are template rotations and artifact media_or_form and identity strategies are boilerplate; both must be re-derived, and identity strategies reconciled with the {credential-id}--{artifact-kind}--{assertion-or-event-id} rule, before any freeze.
  • The jurisdiction, accreditation, legal effect and recognition finding is held from publication as a normative statement until a legal or conformity-assessment authority supports it.
  • Presentation, disclosure manifest and receipt ownership is held as an unresolved split candidate because presentation identity spans multiple credentials and cannot canonicalize under a single credential identifier.
  • The coverage checklist may not publish as sixteen-of-sixteen covered; spatial and interoperability must be downgraded to partial and the no-universal-completeness statement carried alongside the coverage claim.
  • Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft.

Deferred research

  • Resolve whether ISO/IEC 18013-5 mdoc and the eIDAS 2.0 / EUDI Wallet architecture belong in the crosswalk finding or in an explicit out-of-scope statement, given that OpenID4VP is widely deployed with mdoc and the model already claims loss-aware projections.
  • Add or explicitly exclude the W3C Securing Verifiable Credentials using JOSE and COSE specification; the secured-representation finding talks about envelopes and detached content while citing only the Data Integrity path.
  • Confirm the SD-JWT publication identity and number, and determine whether SD-JWT VC is a distinct source needed for credential-type binding beyond the base selective-disclosure mechanism.
  • Establish a legal and conformity-assessment source set for issuer accreditation, legal effect and mutual recognition so the recognition-profile finding is not carried on identity and PKI sources alone.
  • Settle the precedence rule between immutable issuer lineage and subject erasure or disposition rights, including a tombstone specification, before retention guidance is published as normative.
  • Design the subject-initiated contest and dispute intake path that the question set assumes but the ten functions do not expose, and decide whether it is an owned function or an external decision model reference.
  • Compare status-list herd privacy against OCSP request privacy and offline verification to produce a defensible freshness and correlation policy rather than the current statement of competing requirements.
  • Test the holder-copy custody boundary against the declared external wallet inventory, since the model owns delivery, custody, presentation history and disposition of holder representations while disclaiming wallet inventory.