# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T04:42:52Z", "synthesisSha256": "44b3813b8d883e23a9a891b267d2900a414e491b5ad290c10d4beec78bc6a725", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-017", "registryId": "vr.wm-xct-017", "name": "Attestation / Credential", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.CRED" ], "tags": [ "attestation", "credential", "xct.cred" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-017-attestation-credential/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-017", "model": { "registry_id": "vr.wm-xct-017", "model_id": "WM-XCT-017", "name": "Attestation / Credential", "entry_kind": "aggregate", "purpose": "Represent issuer-asserted claims with durable identity, evidence, validity, status, securing and purpose-bound presentation while remaining independent of storage and interface format.", "scope_statement": "Owns credential class and issued-instance identity, claim and schema references, issuer, subject and holder role bindings, issuance evidence, validity, status and lifecycle, secured representations, credential-specific verification evidence, presentations, disclosure manifests, interoperability mappings and governed retention. Party identity, issuer mandate, subject profile, source evidence, keys, permission-bearing grants, trust policy, authorization decisions and generic audit logs remain external.", "in_scope": [ "Credential and attestation definitions, instance and representation identity, typed claims, schema, vocabulary, issuer authority reference, subject binding and issuance evidence", "Validity and terms, status method and freshness, suspension, revocation, expiry, renewal, correction, supersession, secured representations and verification results", "Presentation requests, disclosures, holder binding, privacy and correlation, format mappings, role views, access, retention, provenance and safe agent operations" ], "out_of_scope": [ "Person, organization, issuer, subject, holder, verifier, mandate, source evidence, key, trust policy, permit grant, authorization decision or audit-log master lifecycle", "Implementing proof, signature, wallet, PKI path, status-list or presentation-protocol algorithms and storing private keys or undisclosed secrets", "Universal claim truth, issuer trust, identity proofing, authentication, authorization, eligibility, legal effect or certified cross-format equivalence" ], "boundary_notes": [ { "neighbor": "Claim / Evidence", "distinction": "The credential owns the issuer's claim expression and references evidence; source observations and evidence artifacts keep their own identity and provenance.", "source_refs": [ "SRC-001", "SRC-010" ] }, { "neighbor": "Identity / Key / Authentication", "distinction": "Issuer, subject, holder and verifier identities and public key references remain external; credential verification is not authentication by itself.", "source_refs": [ "SRC-002", "SRC-004", "SRC-009" ] }, { "neighbor": "Permit / Authorization / Decision", "distinction": "A licence or permit credential may evidence an external grant, but its authenticity and status do not themselves make an authorization decision.", "source_refs": [ "SRC-001", "SRC-009" ] }, { "neighbor": "Digital Signature / Proof", "distinction": "Generic proof artifacts and verification methods remain external or reusable mixins; this model binds them to credential claim, validity, status and presentation context.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ] }, { "neighbor": "Presentation / Wallet / Audit Log", "distinction": "This model records credential-specific presentations and verification evidence, while wallet inventory and generic append-only audit execution remain external.", "source_refs": [ "SRC-001", "SRC-008", "SRC-010" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines credentials, claims, issuer, holder, subject, verifier, validity, status, schemas, terms, evidence, extensibility, privacy and security considerations." }, { "id": "SRC-002", "title": "Verifiable Credential Data Integrity 1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-integrity/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines proof purpose, verification method, cryptosuite, proof value, challenge, domain, proof sets and chains, verification processing and privacy considerations." }, { "id": "SRC-003", "title": "Bitstring Status List v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-bitstring-status-list/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines privacy-aware revocation, suspension, status messages, refresh, status-list validity, retrieval and processing." }, { "id": "SRC-004", "title": "Controlled Identifiers v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/cid-1.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines controller documents, verification methods and relationships and associated privacy and correlation risks." }, { "id": "SRC-005", "title": "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List Profile", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc5280", "version_or_date": "RFC 5280, May 2008, with later updates", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines X.509 certificate identity, issuer, subject, validity, extensions, certification paths and CRL semantics." }, { "id": "SRC-006", "title": "X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc6960", "version_or_date": "RFC 6960, June 2013, updated by RFC 8954 and RFC 9654", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines signed status responses, responder authority, good, revoked and unknown status, response validity and freshness times." }, { "id": "SRC-007", "title": "Selective Disclosure for JSON Web Tokens", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9901", "version_or_date": "RFC 9901, November 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines selectively disclosable JSON claims, disclosures, digests, decoys, holder binding, issuance, presentation and verification." }, { "id": "SRC-008", "title": "OpenID for Verifiable Presentations 1.0", "organization": "OpenID Foundation", "url": "https://openid.net/specs/openid-4-verifiable-presentations-1_0-final.html", "version_or_date": "Final Specification, 9 July 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines requests for credentials and presentations, verifier and wallet interaction, nonce and client binding, formats and response validation." }, { "id": "SRC-009", "title": "Digital Identity Guidelines", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/800-63-4/sp800-63.html", "version_or_date": "NIST SP 800-63-4, July 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Separates proofing, enrollment, authenticators and federation assertions and defines assurance, risk, privacy, redress and wallet considerations." }, { "id": "SRC-010", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Provides entities, activities, agents, attribution, derivation and revision relations for issuance, status and presentation provenance." }, { "id": "SRC-011", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:36:00Z", "relevance": "Defines offset-bearing timestamps for issuance, validity, status observation, presentation, verification and knowledge events." } ], "structure": { "bundles": [ { "id": "attestation-definition-identity-and-schema", "name": "Attestation definition, identity and schema", "description": "Defines what the issued assertion is and how its class and instance are identified.", "rationale": "Claim, attestation, credential, manifestation, presentation and proof remain distinct.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-010" ], "layers": [ { "id": "concept-class-and-instance-identity", "name": "Concept, class and instance identity", "description": "Separates the asserted meaning from the credential container and each representation.", "source_refs": [ "SRC-001", "SRC-005", "SRC-010" ], "findings": [ { "id": "attestation-claim-credential-certificate-license-and-permit-distinction", "name": "Attestation, claim, credential, certificate, licence and permit distinction", "description": "Governed class, definition, legal or technical effect, inclusion and exclusion criteria and relation among assertion, evidence container and external grant.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ], "questions": [ { "id": "attestation-claim-credential-certificate-license-and-permit-distinction-q01", "text": "What identity, class, role, scope, version and values define attestation, claim, credential, certificate, licence and permit distinction?", "kind": "identity", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "attestation-claim-credential-certificate-license-and-permit-distinction-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support attestation, claim, credential, certificate, licence and permit distinction?", "kind": "evidence", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "attestation-claim-credential-certificate-license-and-permit-distinction-q03", "text": "How is attestation, claim, credential, certificate, licence and permit distinction validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "validation", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "attestation-claim-credential-certificate-license-and-permit-distinction-data", "name": "Attestation, claim, credential, certificate, licence and permit distinction data", "description": "Structured attestation and credential data for attestation, claim, credential, certificate, licence and permit distinction.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "attestation-claim-credential-certificate-license-and-permit-distinction-record", "name": "Attestation, claim, credential, certificate, licence and permit distinction record", "description": "Versioned evidence-bearing record for attestation, claim, credential, certificate, licence and permit distinction with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus attestation-claim-credential-certificate-license-and-permit-distinction assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "credential-identifier-type-version-lineage-and-representation-identity", "name": "Credential identifier, type, version, lineage and representation identity", "description": "Credential and attestation IDs, type hierarchy, profile version, predecessor or successor, representation ID, issuer serial and authoritative registry.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-010" ], "questions": [ { "id": "credential-identifier-type-version-lineage-and-representation-identity-q01", "text": "What identity, class, role, scope, version and values define credential identifier, type, version, lineage and representation identity?", "kind": "definition", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "credential-identifier-type-version-lineage-and-representation-identity-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support credential identifier, type, version, lineage and representation identity?", "kind": "authority", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "credential-identifier-type-version-lineage-and-representation-identity-q03", "text": "How is credential identifier, type, version, lineage and representation identity validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "interoperability", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "credential-identifier-type-version-lineage-and-representation-identity-data", "name": "Credential identifier, type, version, lineage and representation identity data", "description": "Structured attestation and credential data for credential identifier, type, version, lineage and representation identity.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "credential-identifier-type-version-lineage-and-representation-identity-record", "name": "Credential identifier, type, version, lineage and representation identity record", "description": "Versioned evidence-bearing record for credential identifier, type, version, lineage and representation identity with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus credential-identifier-type-version-lineage-and-representation-identity assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "claim-model-schema-and-subject-binding", "name": "Claim model, schema and subject binding", "description": "Defines what is asserted, about which subject, under which vocabulary and evidence.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ], "findings": [ { "id": "claim-set-predicate-value-language-unit-source-and-confidence", "name": "Claim set, predicate, value, language, unit, source and confidence", "description": "Typed claim paths, predicates, values or references, language, units, source assertion, confidence, uncertainty and explicit unknowns.", "source_refs": [ "SRC-001", "SRC-007", "SRC-010" ], "questions": [ { "id": "claim-set-predicate-value-language-unit-source-and-confidence-q01", "text": "What identity, class, role, scope, version and values define claim set, predicate, value, language, unit, source and confidence?", "kind": "relationship", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "claim-set-predicate-value-language-unit-source-and-confidence-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support claim set, predicate, value, language, unit, source and confidence?", "kind": "temporal", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "claim-set-predicate-value-language-unit-source-and-confidence-q03", "text": "How is claim set, predicate, value, language, unit, source and confidence validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "access", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "claim-set-predicate-value-language-unit-source-and-confidence-data", "name": "Claim set, predicate, value, language, unit, source and confidence data", "description": "Structured attestation and credential data for claim set, predicate, value, language, unit, source and confidence.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "claim-set-predicate-value-language-unit-source-and-confidence-record", "name": "Claim set, predicate, value, language, unit, source and confidence record", "description": "Versioned evidence-bearing record for claim set, predicate, value, language, unit, source and confidence with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus claim-set-predicate-value-language-unit-source-and-confidence assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "credential-schema-vocabulary-context-profile-and-subject-binding", "name": "Credential schema, vocabulary, context, profile and subject binding", "description": "Schema and vocabulary IDs and versions, semantic context, required claims, subject reference, subject role and binding method.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ], "questions": [ { "id": "credential-schema-vocabulary-context-profile-and-subject-binding-q01", "text": "What identity, class, role, scope, version and values define credential schema, vocabulary, context, profile and subject binding?", "kind": "requirement", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "credential-schema-vocabulary-context-profile-and-subject-binding-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support credential schema, vocabulary, context, profile and subject binding?", "kind": "decision", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "credential-schema-vocabulary-context-profile-and-subject-binding-q03", "text": "How is credential schema, vocabulary, context, profile and subject binding validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "exception", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "credential-schema-vocabulary-context-profile-and-subject-binding-data", "name": "Credential schema, vocabulary, context, profile and subject binding data", "description": "Structured attestation and credential data for credential schema, vocabulary, context, profile and subject binding.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "credential-schema-vocabulary-context-profile-and-subject-binding-record", "name": "Credential schema, vocabulary, context, profile and subject binding record", "description": "Versioned evidence-bearing record for credential schema, vocabulary, context, profile and subject binding with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus credential-schema-vocabulary-context-profile-and-subject-binding assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "parties-authority-issuance-and-custody", "name": "Parties, authority, issuance and custody", "description": "Makes issuer authority, issuance evidence and holder custody attributable.", "rationale": "Issuer identity is not issuer authority, and holder custody does not make the holder the subject or claim owner.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010" ], "layers": [ { "id": "issuer-subject-holder-verifier-and-authority", "name": "Issuer, subject, holder, verifier and authority", "description": "References external actors and the scoped authority for their roles.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009" ], "findings": [ { "id": "issuer-identity-role-mandate-scope-delegation-and-authority-validity", "name": "Issuer identity, role, mandate, scope, delegation and authority validity", "description": "External issuer, issuing role, mandate or accreditation, attestation classes, jurisdiction, delegation chain and effective interval.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-009" ], "questions": [ { "id": "issuer-identity-role-mandate-scope-delegation-and-authority-validity-q01", "text": "What identity, class, role, scope, version and values define issuer identity, role, mandate, scope, delegation and authority validity?", "kind": "ownership", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "issuer-identity-role-mandate-scope-delegation-and-authority-validity-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support issuer identity, role, mandate, scope, delegation and authority validity?", "kind": "provenance", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "issuer-identity-role-mandate-scope-delegation-and-authority-validity-q03", "text": "How is issuer identity, role, mandate, scope, delegation and authority validity validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "privacy", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "issuer-identity-role-mandate-scope-delegation-and-authority-validity-data", "name": "Issuer identity, role, mandate, scope, delegation and authority validity data", "description": "Structured attestation and credential data for issuer identity, role, mandate, scope, delegation and authority validity.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "issuer-identity-role-mandate-scope-delegation-and-authority-validity-record", "name": "Issuer identity, role, mandate, scope, delegation and authority validity record", "description": "Versioned evidence-bearing record for issuer identity, role, mandate, scope, delegation and authority validity with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus issuer-identity-role-mandate-scope-delegation-and-authority-validity assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "subject-holder-presenter-verifier-and-relying-party-reference", "name": "Subject, holder, presenter, verifier and relying-party reference", "description": "External actor IDs, protocol roles, subject-holder relation, representative authority, role validity and privacy marking.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ], "questions": [ { "id": "subject-holder-presenter-verifier-and-relying-party-reference-q01", "text": "What identity, class, role, scope, version and values define subject, holder, presenter, verifier and relying-party reference?", "kind": "classification", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "subject-holder-presenter-verifier-and-relying-party-reference-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support subject, holder, presenter, verifier and relying-party reference?", "kind": "quality", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "subject-holder-presenter-verifier-and-relying-party-reference-q03", "text": "How is subject, holder, presenter, verifier and relying-party reference validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "security", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "subject-holder-presenter-verifier-and-relying-party-reference-data", "name": "Subject, holder, presenter, verifier and relying-party reference data", "description": "Structured attestation and credential data for subject, holder, presenter, verifier and relying-party reference.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "subject-holder-presenter-verifier-and-relying-party-reference-record", "name": "Subject, holder, presenter, verifier and relying-party reference record", "description": "Versioned evidence-bearing record for subject, holder, presenter, verifier and relying-party reference with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus subject-holder-presenter-verifier-and-relying-party-reference assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "application-decision-issuance-delivery-and-custody", "name": "Application, decision, issuance, delivery and custody", "description": "Records credential-specific acts without importing generic workflow or wallet masters.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010" ], "findings": [ { "id": "issuance-request-eligibility-evidence-assessment-and-decision-reference", "name": "Issuance request, eligibility evidence, assessment and decision reference", "description": "External request, criteria and policy versions, evidence, assessor, outcome, reasons, appeals and decision provenance.", "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ], "questions": [ { "id": "issuance-request-eligibility-evidence-assessment-and-decision-reference-q01", "text": "What identity, class, role, scope, version and values define issuance request, eligibility evidence, assessment and decision reference?", "kind": "composition", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "issuance-request-eligibility-evidence-assessment-and-decision-reference-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support issuance request, eligibility evidence, assessment and decision reference?", "kind": "measurement", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "issuance-request-eligibility-evidence-assessment-and-decision-reference-q03", "text": "How is issuance request, eligibility evidence, assessment and decision reference validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "validation", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "issuance-request-eligibility-evidence-assessment-and-decision-reference-data", "name": "Issuance request, eligibility evidence, assessment and decision reference data", "description": "Structured attestation and credential data for issuance request, eligibility evidence, assessment and decision reference.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "issuance-request-eligibility-evidence-assessment-and-decision-reference-record", "name": "Issuance request, eligibility evidence, assessment and decision reference record", "description": "Versioned evidence-bearing record for issuance request, eligibility evidence, assessment and decision reference with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus issuance-request-eligibility-evidence-assessment-and-decision-reference assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "issuance-event-issuer-copy-holder-copy-delivery-acceptance-and-custody", "name": "Issuance event, issuer copy, holder copy, delivery, acceptance and custody", "description": "Issuance act, authoritative issuer record, holder representation, delivery channel, receipt, custody location, integrity and recovery rules.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010" ], "questions": [ { "id": "issuance-event-issuer-copy-holder-copy-delivery-acceptance-and-custody-q01", "text": "What identity, class, role, scope, version and values define issuance event, issuer copy, holder copy, delivery, acceptance and custody?", "kind": "state", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "issuance-event-issuer-copy-holder-copy-delivery-acceptance-and-custody-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support issuance event, issuer copy, holder copy, delivery, acceptance and custody?", "kind": "lifecycle", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "issuance-event-issuer-copy-holder-copy-delivery-acceptance-and-custody-q03", "text": "How is issuance event, issuer copy, holder copy, delivery, acceptance and custody validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "retention", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "issuance-event-issuer-copy-holder-copy-delivery-acceptance-and-custody-data", "name": "Issuance event, issuer copy, holder copy, delivery, acceptance and custody data", "description": "Structured attestation and credential data for issuance event, issuer copy, holder copy, delivery, acceptance and custody.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "issuance-event-issuer-copy-holder-copy-delivery-acceptance-and-custody-record", "name": "Issuance event, issuer copy, holder copy, delivery, acceptance and custody record", "description": "Versioned evidence-bearing record for issuance event, issuer copy, holder copy, delivery, acceptance and custody with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus issuance-event-issuer-copy-holder-copy-delivery-acceptance-and-custody assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "validity-status-and-lifecycle", "name": "Validity, status and lifecycle", "description": "Represents time-qualified standing and non-destructive change.", "rationale": "A credential can be authentic yet expired, suspended, revoked, superseded, untrusted or irrelevant to a decision.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011" ], "layers": [ { "id": "validity-terms-and-conditions", "name": "Validity terms and conditions", "description": "Separates issuance time, effective validity and usage conditions.", "source_refs": [ "SRC-001", "SRC-005", "SRC-011" ], "findings": [ { "id": "issued-valid-from-valid-until-effective-observed-and-knowledge-time", "name": "Issued, valid-from, valid-until, effective, observed and knowledge time", "description": "Distinct RFC 3339 event times, timezone, accuracy, source clock, uncertainty, interval boundaries and later correction knowledge.", "source_refs": [ "SRC-001", "SRC-005", "SRC-011" ], "questions": [ { "id": "issued-valid-from-valid-until-effective-observed-and-knowledge-time-q01", "text": "What identity, class, role, scope, version and values define issued, valid-from, valid-until, effective, observed and knowledge time?", "kind": "identity", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "issued-valid-from-valid-until-effective-observed-and-knowledge-time-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support issued, valid-from, valid-until, effective, observed and knowledge time?", "kind": "evidence", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "issued-valid-from-valid-until-effective-observed-and-knowledge-time-q03", "text": "How is issued, valid-from, valid-until, effective, observed and knowledge time validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "validation", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "issued-valid-from-valid-until-effective-observed-and-knowledge-time-data", "name": "Issued, valid-from, valid-until, effective, observed and knowledge time data", "description": "Structured attestation and credential data for issued, valid-from, valid-until, effective, observed and knowledge time.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-011" ] } ], "artifacts": [ { "id": "issued-valid-from-valid-until-effective-observed-and-knowledge-time-record", "name": "Issued, valid-from, valid-until, effective, observed and knowledge time record", "description": "Versioned evidence-bearing record for issued, valid-from, valid-until, effective, observed and knowledge time with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus issued-valid-from-valid-until-effective-observed-and-knowledge-time assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "terms-of-use-jurisdiction-purpose-condition-limitation-and-dependency", "name": "Terms of use, jurisdiction, purpose, condition, limitation and dependency", "description": "Credential-specific use terms, jurisdiction, audience, prerequisite or external grant, restrictions, dependency and interpretation warning.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ], "questions": [ { "id": "terms-of-use-jurisdiction-purpose-condition-limitation-and-dependency-q01", "text": "What identity, class, role, scope, version and values define terms of use, jurisdiction, purpose, condition, limitation and dependency?", "kind": "definition", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "terms-of-use-jurisdiction-purpose-condition-limitation-and-dependency-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support terms of use, jurisdiction, purpose, condition, limitation and dependency?", "kind": "authority", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "terms-of-use-jurisdiction-purpose-condition-limitation-and-dependency-q03", "text": "How is terms of use, jurisdiction, purpose, condition, limitation and dependency validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "interoperability", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "terms-of-use-jurisdiction-purpose-condition-limitation-and-dependency-data", "name": "Terms of use, jurisdiction, purpose, condition, limitation and dependency data", "description": "Structured attestation and credential data for terms of use, jurisdiction, purpose, condition, limitation and dependency.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "terms-of-use-jurisdiction-purpose-condition-limitation-and-dependency-record", "name": "Terms of use, jurisdiction, purpose, condition, limitation and dependency record", "description": "Versioned evidence-bearing record for terms of use, jurisdiction, purpose, condition, limitation and dependency with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus terms-of-use-jurisdiction-purpose-condition-limitation-and-dependency assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "status-method-events-and-lineage", "name": "Status method, events and lineage", "description": "Preserves status source, freshness, reason and successor chain.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-010", "SRC-011" ], "findings": [ { "id": "status-source-method-entry-purpose-value-freshness-and-error", "name": "Status source, method, entry, purpose, value, freshness and error", "description": "Status service and authority, method profile, entry or index, status purpose, value, retrieved and next-update time, cache age and processing errors.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-011" ], "questions": [ { "id": "status-source-method-entry-purpose-value-freshness-and-error-q01", "text": "What identity, class, role, scope, version and values define status source, method, entry, purpose, value, freshness and error?", "kind": "relationship", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "status-source-method-entry-purpose-value-freshness-and-error-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support status source, method, entry, purpose, value, freshness and error?", "kind": "temporal", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "status-source-method-entry-purpose-value-freshness-and-error-q03", "text": "How is status source, method, entry, purpose, value, freshness and error validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "access", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "status-source-method-entry-purpose-value-freshness-and-error-data", "name": "Status source, method, entry, purpose, value, freshness and error data", "description": "Structured attestation and credential data for status source, method, entry, purpose, value, freshness and error.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-011" ] } ], "artifacts": [ { "id": "status-source-method-entry-purpose-value-freshness-and-error-record", "name": "Status source, method, entry, purpose, value, freshness and error record", "description": "Versioned evidence-bearing record for status source, method, entry, purpose, value, freshness and error with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus status-source-method-entry-purpose-value-freshness-and-error assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "activate-suspend-reinstate-revoke-expire-renew-correct-and-supersede-event", "name": "Activate, suspend, reinstate, revoke, expire, renew, correct and supersede event", "description": "Typed lifecycle event, prior and next state, authority, reason, effective time, evidence, reversibility, successor and notification.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-010", "SRC-011" ], "questions": [ { "id": "activate-suspend-reinstate-revoke-expire-renew-correct-and-supersede-event-q01", "text": "What identity, class, role, scope, version and values define activate, suspend, reinstate, revoke, expire, renew, correct and supersede event?", "kind": "requirement", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "activate-suspend-reinstate-revoke-expire-renew-correct-and-supersede-event-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support activate, suspend, reinstate, revoke, expire, renew, correct and supersede event?", "kind": "decision", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "activate-suspend-reinstate-revoke-expire-renew-correct-and-supersede-event-q03", "text": "How is activate, suspend, reinstate, revoke, expire, renew, correct and supersede event validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "exception", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "activate-suspend-reinstate-revoke-expire-renew-correct-and-supersede-event-data", "name": "Activate, suspend, reinstate, revoke, expire, renew, correct and supersede event data", "description": "Structured attestation and credential data for activate, suspend, reinstate, revoke, expire, renew, correct and supersede event.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-010", "SRC-011" ] } ], "artifacts": [ { "id": "activate-suspend-reinstate-revoke-expire-renew-correct-and-supersede-event-record", "name": "Activate, suspend, reinstate, revoke, expire, renew, correct and supersede event record", "description": "Versioned evidence-bearing record for activate, suspend, reinstate, revoke, expire, renew, correct and supersede event with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus activate-suspend-reinstate-revoke-expire-renew-correct-and-supersede-event assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "securing-integrity-and-verification", "name": "Securing, integrity and verification", "description": "Binds a credential representation to named securing and validation methods.", "rationale": "Proof validation establishes only declared authenticity and integrity properties under pinned inputs and trust assumptions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-010" ], "layers": [ { "id": "proof-envelope-and-verification-material", "name": "Proof envelope and verification material", "description": "Identifies the exact representation, securing mechanism and public material.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-007" ], "findings": [ { "id": "secured-representation-canonical-form-digest-media-type-and-envelope", "name": "Secured representation, canonical form, digest, media type and envelope", "description": "Credential bytes or external artifact, semantic representation, canonicalization, digest, media type, encoding, envelope and detached-content binding.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007" ], "questions": [ { "id": "secured-representation-canonical-form-digest-media-type-and-envelope-q01", "text": "What identity, class, role, scope, version and values define secured representation, canonical form, digest, media type and envelope?", "kind": "ownership", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "secured-representation-canonical-form-digest-media-type-and-envelope-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support secured representation, canonical form, digest, media type and envelope?", "kind": "provenance", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "secured-representation-canonical-form-digest-media-type-and-envelope-q03", "text": "How is secured representation, canonical form, digest, media type and envelope validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "privacy", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "secured-representation-canonical-form-digest-media-type-and-envelope-data", "name": "Secured representation, canonical form, digest, media type and envelope data", "description": "Structured attestation and credential data for secured representation, canonical form, digest, media type and envelope.", "value_kind": "binary", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "secured-representation-canonical-form-digest-media-type-and-envelope-record", "name": "Secured representation, canonical form, digest, media type and envelope record", "description": "Versioned evidence-bearing record for secured representation, canonical form, digest, media type and envelope with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus secured-representation-canonical-form-digest-media-type-and-envelope assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "proof-signature-suite-purpose-method-controller-key-and-parameters", "name": "Proof or signature suite, purpose, method, controller, key and parameters", "description": "Proof type, cryptosuite or signature algorithm, proof purpose, verification method and controller, public key ref, parameters, created time and proof value.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-007" ], "questions": [ { "id": "proof-signature-suite-purpose-method-controller-key-and-parameters-q01", "text": "What identity, class, role, scope, version and values define proof or signature suite, purpose, method, controller, key and parameters?", "kind": "classification", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "proof-signature-suite-purpose-method-controller-key-and-parameters-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support proof or signature suite, purpose, method, controller, key and parameters?", "kind": "quality", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "proof-signature-suite-purpose-method-controller-key-and-parameters-q03", "text": "How is proof or signature suite, purpose, method, controller, key and parameters validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "security", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "proof-signature-suite-purpose-method-controller-key-and-parameters-data", "name": "Proof or signature suite, purpose, method, controller, key and parameters data", "description": "Structured attestation and credential data for proof or signature suite, purpose, method, controller, key and parameters.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "proof-signature-suite-purpose-method-controller-key-and-parameters-record", "name": "Proof or signature suite, purpose, method, controller, key and parameters record", "description": "Versioned evidence-bearing record for proof or signature suite, purpose, method, controller, key and parameters with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus proof-signature-suite-purpose-method-controller-key-and-parameters assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "validation-trust-and-result", "name": "Validation, trust and result", "description": "Records exact checks and keeps technical verification separate from external acceptance.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-009", "SRC-010" ], "findings": [ { "id": "schema-proof-path-key-status-time-and-policy-validation-checks", "name": "Schema, proof, path, key, status, time and policy validation checks", "description": "Validator and version, input digest, schema and semantic checks, signature or proof checks, path or key resolution, status, time and policy inputs.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007" ], "questions": [ { "id": "schema-proof-path-key-status-time-and-policy-validation-checks-q01", "text": "What identity, class, role, scope, version and values define schema, proof, path, key, status, time and policy validation checks?", "kind": "composition", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "schema-proof-path-key-status-time-and-policy-validation-checks-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support schema, proof, path, key, status, time and policy validation checks?", "kind": "measurement", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "schema-proof-path-key-status-time-and-policy-validation-checks-q03", "text": "How is schema, proof, path, key, status, time and policy validation checks validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "validation", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "schema-proof-path-key-status-time-and-policy-validation-checks-data", "name": "Schema, proof, path, key, status, time and policy validation checks data", "description": "Structured attestation and credential data for schema, proof, path, key, status, time and policy validation checks.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "schema-proof-path-key-status-time-and-policy-validation-checks-record", "name": "Schema, proof, path, key, status, time and policy validation checks record", "description": "Versioned evidence-bearing record for schema, proof, path, key, status, time and policy validation checks with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus schema-proof-path-key-status-time-and-policy-validation-checks assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "verification-outcome-errors-evidence-assurance-trust-and-decision-separation", "name": "Verification outcome, errors, evidence, assurance, trust and decision separation", "description": "Valid, invalid or indeterminate outcome, structured errors, evidence, assurance, issuer-trust result, observation time and explicit non-authorization marker.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "verification-outcome-errors-evidence-assurance-trust-and-decision-separation-q01", "text": "What identity, class, role, scope, version and values define verification outcome, errors, evidence, assurance, trust and decision separation?", "kind": "state", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "verification-outcome-errors-evidence-assurance-trust-and-decision-separation-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support verification outcome, errors, evidence, assurance, trust and decision separation?", "kind": "lifecycle", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "verification-outcome-errors-evidence-assurance-trust-and-decision-separation-q03", "text": "How is verification outcome, errors, evidence, assurance, trust and decision separation validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "retention", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "verification-outcome-errors-evidence-assurance-trust-and-decision-separation-data", "name": "Verification outcome, errors, evidence, assurance, trust and decision separation data", "description": "Structured attestation and credential data for verification outcome, errors, evidence, assurance, trust and decision separation.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "verification-outcome-errors-evidence-assurance-trust-and-decision-separation-record", "name": "Verification outcome, errors, evidence, assurance, trust and decision separation record", "description": "Versioned evidence-bearing record for verification outcome, errors, evidence, assurance, trust and decision separation with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus verification-outcome-errors-evidence-assurance-trust-and-decision-separation assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "presentation-disclosure-privacy-and-correlation", "name": "Presentation, disclosure, privacy and correlation", "description": "Governs use of credentials without assuming every verifier receives the full issuer record.", "rationale": "A presentation is a purpose-bound event and derivative artifact, not a mutation of the credential.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007", "SRC-008", "SRC-010", "SRC-011" ], "layers": [ { "id": "request-purpose-and-disclosure-policy", "name": "Request, purpose and disclosure policy", "description": "Captures what a verifier asks for and why before disclosure.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009" ], "findings": [ { "id": "presentation-request-verifier-purpose-audience-claims-format-nonce-and-expiry", "name": "Presentation request, verifier, purpose, audience, claims, format, nonce and expiry", "description": "Request ID, verifier and client, purpose, audience, requested claims and predicates, accepted formats, nonce, domain, issue and expiry time.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008" ], "questions": [ { "id": "presentation-request-verifier-purpose-audience-claims-format-nonce-and-expiry-q01", "text": "What identity, class, role, scope, version and values define presentation request, verifier, purpose, audience, claims, format, nonce and expiry?", "kind": "identity", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "presentation-request-verifier-purpose-audience-claims-format-nonce-and-expiry-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support presentation request, verifier, purpose, audience, claims, format, nonce and expiry?", "kind": "evidence", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "presentation-request-verifier-purpose-audience-claims-format-nonce-and-expiry-q03", "text": "How is presentation request, verifier, purpose, audience, claims, format, nonce and expiry validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "validation", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "presentation-request-verifier-purpose-audience-claims-format-nonce-and-expiry-data", "name": "Presentation request, verifier, purpose, audience, claims, format, nonce and expiry data", "description": "Structured attestation and credential data for presentation request, verifier, purpose, audience, claims, format, nonce and expiry.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "presentation-request-verifier-purpose-audience-claims-format-nonce-and-expiry-record", "name": "Presentation request, verifier, purpose, audience, claims, format, nonce and expiry record", "description": "Versioned evidence-bearing record for presentation request, verifier, purpose, audience, claims, format, nonce and expiry with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus presentation-request-verifier-purpose-audience-claims-format-nonce-and-expiry assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "disclosure-consent-authority-minimization-derived-claim-and-inference-risk", "name": "Disclosure authority, minimization, derived claim and inference risk", "description": "Consent or other authority, requested, disclosed, derived and withheld claims, necessity, policy, inference, linkability and residual privacy risk.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007", "SRC-008", "SRC-009" ], "questions": [ { "id": "disclosure-consent-authority-minimization-derived-claim-and-inference-risk-q01", "text": "What identity, class, role, scope, version and values define disclosure authority, minimization, derived claim and inference risk?", "kind": "definition", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "disclosure-consent-authority-minimization-derived-claim-and-inference-risk-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support disclosure authority, minimization, derived claim and inference risk?", "kind": "authority", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "disclosure-consent-authority-minimization-derived-claim-and-inference-risk-q03", "text": "How is disclosure authority, minimization, derived claim and inference risk validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "interoperability", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "disclosure-consent-authority-minimization-derived-claim-and-inference-risk-data", "name": "Disclosure authority, minimization, derived claim and inference risk data", "description": "Structured attestation and credential data for disclosure authority, minimization, derived claim and inference risk.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "disclosure-consent-authority-minimization-derived-claim-and-inference-risk-record", "name": "Disclosure authority, minimization, derived claim and inference risk record", "description": "Versioned evidence-bearing record for disclosure authority, minimization, derived claim and inference risk with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus disclosure-consent-authority-minimization-derived-claim-and-inference-risk assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "presentation-holder-binding-and-receipt", "name": "Presentation, holder binding and receipt", "description": "Binds disclosed material to request context and records its attributable verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-010", "SRC-011" ], "findings": [ { "id": "presentation-identifier-holder-binding-credential-set-disclosures-and-integrity", "name": "Presentation identifier, holder binding, credential set, disclosures and integrity", "description": "Presentation ID, presenter or holder, holder-binding proof, included credentials, disclosure manifest, format, request binding, digest and created time.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008" ], "questions": [ { "id": "presentation-identifier-holder-binding-credential-set-disclosures-and-integrity-q01", "text": "What identity, class, role, scope, version and values define presentation identifier, holder binding, credential set, disclosures and integrity?", "kind": "relationship", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "presentation-identifier-holder-binding-credential-set-disclosures-and-integrity-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support presentation identifier, holder binding, credential set, disclosures and integrity?", "kind": "temporal", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "presentation-identifier-holder-binding-credential-set-disclosures-and-integrity-q03", "text": "How is presentation identifier, holder binding, credential set, disclosures and integrity validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "access", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "presentation-identifier-holder-binding-credential-set-disclosures-and-integrity-data", "name": "Presentation identifier, holder binding, credential set, disclosures and integrity data", "description": "Structured attestation and credential data for presentation identifier, holder binding, credential set, disclosures and integrity.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "presentation-identifier-holder-binding-credential-set-disclosures-and-integrity-record", "name": "Presentation identifier, holder binding, credential set, disclosures and integrity record", "description": "Versioned evidence-bearing record for presentation identifier, holder binding, credential set, disclosures and integrity with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus presentation-identifier-holder-binding-credential-set-disclosures-and-integrity assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "presentation-receipt-verification-use-event-retention-and-correlation-control", "name": "Presentation receipt, verification, use event, retention and correlation control", "description": "Receiver, receipt and verification times, purpose, outcome, onward use, retention, replay control, pairwise handles and correlation assessment.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007", "SRC-008", "SRC-010", "SRC-011" ], "questions": [ { "id": "presentation-receipt-verification-use-event-retention-and-correlation-control-q01", "text": "What identity, class, role, scope, version and values define presentation receipt, verification, use event, retention and correlation control?", "kind": "requirement", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "presentation-receipt-verification-use-event-retention-and-correlation-control-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support presentation receipt, verification, use event, retention and correlation control?", "kind": "decision", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "presentation-receipt-verification-use-event-retention-and-correlation-control-q03", "text": "How is presentation receipt, verification, use event, retention and correlation control validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "exception", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "presentation-receipt-verification-use-event-retention-and-correlation-control-data", "name": "Presentation receipt, verification, use event, retention and correlation control data", "description": "Structured attestation and credential data for presentation receipt, verification, use event, retention and correlation control.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007", "SRC-008", "SRC-010", "SRC-011" ] } ], "artifacts": [ { "id": "presentation-receipt-verification-use-event-retention-and-correlation-control-record", "name": "Presentation receipt, verification, use event, retention and correlation control record", "description": "Versioned evidence-bearing record for presentation receipt, verification, use event, retention and correlation control with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus presentation-receipt-verification-use-event-retention-and-correlation-control assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007", "SRC-008", "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "interoperability-access-provenance-and-agent-governance", "name": "Interoperability, access, provenance and agent governance", "description": "Provides loss-aware mappings and safe autonomous lifecycle operations.", "rationale": "Credential families differ in semantics, trust and privacy and cannot be converted by field-name matching alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011" ], "layers": [ { "id": "format-profile-and-legal-effect-crosswalk", "name": "Format, profile and legal-effect crosswalk", "description": "Maps W3C, X.509, SD-JWT and presentation profiles with explicit loss.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ], "findings": [ { "id": "vc-data-integrity-x509-sd-jwt-and-openid4vp-crosswalk", "name": "VC, Data Integrity, X.509, SD-JWT and OpenID4VP crosswalk", "description": "Source and target versions, identity, issuer, subject, claim, validity, proof, status and presentation mappings, omissions, conflicts and round-trip class.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ], "questions": [ { "id": "vc-data-integrity-x509-sd-jwt-and-openid4vp-crosswalk-q01", "text": "What identity, class, role, scope, version and values define vc, data integrity, x.509, sd-jwt and openid4vp crosswalk?", "kind": "ownership", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "vc-data-integrity-x509-sd-jwt-and-openid4vp-crosswalk-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support vc, data integrity, x.509, sd-jwt and openid4vp crosswalk?", "kind": "provenance", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "vc-data-integrity-x509-sd-jwt-and-openid4vp-crosswalk-q03", "text": "How is vc, data integrity, x.509, sd-jwt and openid4vp crosswalk validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "privacy", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "vc-data-integrity-x509-sd-jwt-and-openid4vp-crosswalk-data", "name": "VC, Data Integrity, X.509, SD-JWT and OpenID4VP crosswalk data", "description": "Structured attestation and credential data for vc, data integrity, x.509, sd-jwt and openid4vp crosswalk.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "vc-data-integrity-x509-sd-jwt-and-openid4vp-crosswalk-record", "name": "VC, Data Integrity, X.509, SD-JWT and OpenID4VP crosswalk record", "description": "Versioned evidence-bearing record for vc, data integrity, x.509, sd-jwt and openid4vp crosswalk with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus vc-data-integrity-x509-sd-jwt-and-openid4vp-crosswalk assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "jurisdiction-sector-accreditation-legal-effect-and-recognition-profile", "name": "Jurisdiction, sector, accreditation, legal effect and recognition profile", "description": "Credential class, jurisdiction, sector, issuer qualification, legal or business effect, recognition authority, limitations and review date.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ], "questions": [ { "id": "jurisdiction-sector-accreditation-legal-effect-and-recognition-profile-q01", "text": "What identity, class, role, scope, version and values define jurisdiction, sector, accreditation, legal effect and recognition profile?", "kind": "classification", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "jurisdiction-sector-accreditation-legal-effect-and-recognition-profile-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support jurisdiction, sector, accreditation, legal effect and recognition profile?", "kind": "quality", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "jurisdiction-sector-accreditation-legal-effect-and-recognition-profile-q03", "text": "How is jurisdiction, sector, accreditation, legal effect and recognition profile validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "security", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "jurisdiction-sector-accreditation-legal-effect-and-recognition-profile-data", "name": "Jurisdiction, sector, accreditation, legal effect and recognition profile data", "description": "Structured attestation and credential data for jurisdiction, sector, accreditation, legal effect and recognition profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "jurisdiction-sector-accreditation-legal-effect-and-recognition-profile-record", "name": "Jurisdiction, sector, accreditation, legal effect and recognition profile record", "description": "Versioned evidence-bearing record for jurisdiction, sector, accreditation, legal effect and recognition profile with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus jurisdiction-sector-accreditation-legal-effect-and-recognition-profile assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "access-retention-provenance-and-safe-operations", "name": "Access, retention, provenance and safe operations", "description": "Protects claims and usage history while preserving issuer accountability.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009", "SRC-010", "SRC-011" ], "findings": [ { "id": "issuer-holder-subject-verifier-status-public-auditor-and-regulator-view", "name": "Issuer, holder, subject, verifier, status-public, auditor and regulator view", "description": "Audience, purpose, authority, included fields, redactions, pseudonymization, freshness, expiry, disclosure record and re-identification risk.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ], "questions": [ { "id": "issuer-holder-subject-verifier-status-public-auditor-and-regulator-view-q01", "text": "What identity, class, role, scope, version and values define issuer, holder, subject, verifier, status-public, auditor and regulator view?", "kind": "composition", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "issuer-holder-subject-verifier-status-public-auditor-and-regulator-view-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support issuer, holder, subject, verifier, status-public, auditor and regulator view?", "kind": "measurement", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "issuer-holder-subject-verifier-status-public-auditor-and-regulator-view-q03", "text": "How is issuer, holder, subject, verifier, status-public, auditor and regulator view validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "validation", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "issuer-holder-subject-verifier-status-public-auditor-and-regulator-view-data", "name": "Issuer, holder, subject, verifier, status-public, auditor and regulator view data", "description": "Structured attestation and credential data for issuer, holder, subject, verifier, status-public, auditor and regulator view.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "issuer-holder-subject-verifier-status-public-auditor-and-regulator-view-record", "name": "Issuer, holder, subject, verifier, status-public, auditor and regulator view record", "description": "Versioned evidence-bearing record for issuer, holder, subject, verifier, status-public, auditor and regulator view with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus issuer-holder-subject-verifier-status-public-auditor-and-regulator-view assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "provenance-retention-legal-hold-disposition-agent-authority-and-audit", "name": "Provenance, retention, legal hold, disposition, agent authority and audit", "description": "Generation and revision provenance, retention trigger, hold, disposition authority, expected head, idempotency, pre-write and post-write checks, rollback and audit evidence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-010", "SRC-011" ], "questions": [ { "id": "provenance-retention-legal-hold-disposition-agent-authority-and-audit-q01", "text": "What identity, class, role, scope, version and values define provenance, retention, legal hold, disposition, agent authority and audit?", "kind": "state", "answer_data": [ "identifiers", "classes and roles", "versions and scope", "values and unknowns" ] }, { "id": "provenance-retention-legal-hold-disposition-agent-authority-and-audit-q02", "text": "Which issuer authority, source, evidence, method and event or effective time support provenance, retention, legal hold, disposition, agent authority and audit?", "kind": "lifecycle", "answer_data": [ "authority", "source and evidence", "method and profile", "event and effective time", "confidence" ] }, { "id": "provenance-retention-legal-hold-disposition-agent-authority-and-audit-q03", "text": "How is provenance, retention, legal hold, disposition, agent authority and audit validated, disclosed, contested, corrected, superseded and retained without changing issued history?", "kind": "retention", "answer_data": [ "validation", "access and disclosure", "contest and correction", "lineage", "retention" ] } ], "data_elements": [ { "id": "provenance-retention-legal-hold-disposition-agent-authority-and-audit-data", "name": "Provenance, retention, legal hold, disposition, agent authority and audit data", "description": "Structured attestation and credential data for provenance, retention, legal hold, disposition, agent authority and audit.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-010", "SRC-011" ] } ], "artifacts": [ { "id": "provenance-retention-legal-hold-disposition-agent-authority-and-audit-record", "name": "Provenance, retention, legal hold, disposition, agent authority and audit record", "description": "Versioned evidence-bearing record for provenance, retention, legal hold, disposition, agent authority and audit with credential binding, authority, time, provenance and disclosure marking.", "media_or_form": [ "logical attestation assertion", "credential, evidence, event or validation reference" ], "serial": true, "identity_strategy": "Credential or attestation identifier plus provenance-retention-legal-hold-disposition-agent-authority-and-audit assertion, artifact or event identifier; subject name, serial, timestamp and digest never identify the credential alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "define-credential-class-and-profile", "name": "Define credential class and profile", "description": "Establish claim vocabulary, schema, required evidence, issuer authority, validity, status and representation rules.", "inputs": [ "class purpose", "authority", "claim schema", "profile inputs" ], "outputs": [ "credential-class profile" ], "preconditions": [ "namespace, semantic definitions, issuer mandate, privacy and interoperability validate" ], "effects": [ "a versioned class is available without issuing an instance" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-009" ] }, { "id": "issue-attestation-or-credential", "name": "Issue attestation or credential", "description": "Create an immutable issued assertion and representations after an authorized evidence-backed decision.", "inputs": [ "credential class", "issuer", "subject", "claims", "decision and evidence" ], "outputs": [ "issued credential revision and issuance event" ], "preconditions": [ "issuer authority, subject binding, schema, evidence, validity, status method and expected serial validate" ], "effects": [ "issuer record and permitted holder copy are created with provenance" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-009", "SRC-010" ] }, { "id": "deliver-accept-and-custody-holder-copy", "name": "Deliver, accept and custody holder copy", "description": "Transfer a representation to a holder or wallet and record receipt without transferring issuer authority.", "inputs": [ "issued credential", "holder", "delivery policy" ], "outputs": [ "holder-copy and custody event" ], "preconditions": [ "holder authority, channel, integrity, privacy and recovery policy validate" ], "effects": [ "a controlled copy becomes available to the holder" ], "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] }, { "id": "publish-or-refresh-status", "name": "Publish or refresh status", "description": "Issue a privacy-aware, time-qualified credential status assertion or list update.", "inputs": [ "credential", "status transition or observation", "status authority" ], "outputs": [ "status entry or response" ], "preconditions": [ "authority, method, purpose, index, freshness, signing and privacy validate" ], "effects": [ "relying parties can obtain current source-qualified standing" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ] }, { "id": "suspend-reinstate-revoke-expire-renew-or-supersede", "name": "Suspend, reinstate, revoke, expire, renew or supersede", "description": "Append a credential lifecycle event and derived state while preserving earlier claims and representations.", "inputs": [ "credential", "transition", "authority", "reason and evidence" ], "outputs": [ "lifecycle event and successor revision" ], "preconditions": [ "transition guard, authority, effective time, status publication, notification and lineage validate" ], "effects": [ "current standing changes without rewriting issued history" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-010", "SRC-011" ] }, { "id": "create-presentation-request", "name": "Create presentation request", "description": "Record verifier, purpose, audience, requested claims or predicates, formats, nonce and expiry.", "inputs": [ "verifier", "purpose", "requirements", "accepted formats" ], "outputs": [ "presentation request" ], "preconditions": [ "verifier identity, authority, minimization, client binding, nonce and expiry validate" ], "effects": [ "a bounded disclosure request becomes attributable" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-008" ] }, { "id": "derive-and-present-credential", "name": "Derive and present credential", "description": "Create a request-bound presentation with permitted disclosure and optional holder binding.", "inputs": [ "holder credentials", "request", "disclosure authority" ], "outputs": [ "presentation and disclosure manifest" ], "preconditions": [ "credential status, request, nonce, audience, holder binding, minimization and format validate" ], "effects": [ "the verifier receives purpose-bound evidence without mutating the credentials" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007", "SRC-008" ] }, { "id": "verify-credential-or-presentation", "name": "Verify credential or presentation", "description": "Record schema, proof, key, path, status, time and request-binding checks and structured outcome.", "inputs": [ "credential or presentation", "verification material", "status sources", "trust policy" ], "outputs": [ "verification result" ], "preconditions": [ "algorithms, canonicalization, keys, status freshness, time, trust input and policy version validate" ], "effects": [ "technical outcome becomes attributable without making an authorization decision" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "project-or-transform-loss-aware", "name": "Project or transform loss-aware", "description": "Map a credential to another representation or sector profile with explicit omissions and semantic conflicts.", "inputs": [ "credential revision", "target profile", "purpose" ], "outputs": [ "mapped projection and loss report" ], "preconditions": [ "source and target versions, issuer, subject, claims, validity, proof, status and round-trip class validate" ], "effects": [ "consumer receives a traceable representation with visible limitations" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007", "SRC-008" ] }, { "id": "correct-retain-dispose-and-audit", "name": "Correct, retain, dispose and audit", "description": "Create a successor correction or execute authorized retention and disposition while preserving required lineage.", "inputs": [ "credential lineage", "change or retention authority", "reason", "policy" ], "outputs": [ "successor, disposition or audit event" ], "preconditions": [ "expected head, issuer authority, legal hold, subject rights, minimum tombstone and post-write checks validate" ], "effects": [ "current data changes without erasing accountable issuance and status history" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-010", "SRC-011" ] } ], "composition": [ { "target": "Identity Register, Person, Organization and Agent models", "relation": "REFERENCE", "purpose": "Resolve issuer, subject, holder, presenter and verifier without copying identity profiles.", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-009" ] }, { "target": "Mandate, Evidence, Key, Grant, Policy, Decision and Audit models", "relation": "REFERENCE", "purpose": "Resolve authority, source support, verification material and external legal or business effects.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010" ] }, { "target": "W3C Verifiable Credentials, Data Integrity, Status List and Controlled Identifiers", "relation": "ALIGN", "purpose": "Project claims, roles, validity, status, proof and identifier-control semantics.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] }, { "target": "IETF X.509, OCSP and SD-JWT", "relation": "ALIGN", "purpose": "Project certificate, status-response and selective-disclosure representations with declared loss.", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] }, { "target": "OpenID4VP, PROV-O and RFC 3339", "relation": "ALIGN", "purpose": "Represent request-bound presentations, accountable activities and explicit event times.", "required": false, "source_refs": [ "SRC-008", "SRC-010", "SRC-011" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension identity, owner, credential governance authority, issuer registry and privacy and records stewards", "Credential-class, claim-schema, issuer-authority, status-method, trust, presentation-profile and retention registries", "Master mappings for issuers, subjects, holders, verifiers, mandates, evidence, keys, grants, policies, decisions and audit logs", "Issuance, validity, status, proof, disclosure, verification, correction, access, retention and agent-operation policies" ], "namespace_guidance": "Mint stable IDs for credential classes and issued attestation instances. Preserve authoritative issuer serials and external subject, issuer, key, mandate and evidence identities; never use subject name, date or digest alone.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local credential-class, issuer, schema, status, trust and profile registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize an issued instance by authoritative issuer plus credential identifier under a versioned profile, not by subject name, serial alone, claim values, timestamp or proof digest.", "Secure representation canonicalization, schema, vocabulary, proof, status and presentation versions are explicit and never inferred solely from file format." ], "patch_rules": [ "Extensions declare credential family, target finding, claim semantics, issuer authority, validity, status, proof, privacy and interoperability impact.", "Issued claims are immutable. Corrections, renewals, schema changes and representation upgrades create successor revisions or credentials with migration mappings and preserved provenance." ], "compatibility_rules": [ "Unknown additive fields may be ignored only when identity, issuer, subject, claims, validity, proof, status, access and provenance remain intact.", "Every VC, Data Integrity, X.509, SD-JWT or OpenID4VP mapping pins versions and states omissions, semantic conflicts, privacy changes and round-trip limits." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system credential or attestation identifier qualified by issuer and class.", "Governed globally resolvable credential IRI or certificate issuer and serial tuple.", "Dimension UUID when no authoritative or governed global identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; separate issuance, delivery, valid-from, valid-until, status, presentation, receipt, verification, decision and knowledge times.", "serial_naming_rule": "Use {credential-id}--{artifact-kind}--{assertion-or-event-id}; never use subject name, issuer serial alone, date or digest alone.", "integrity_rule": "Store digest, media type, credential and representation binding, schema and proof versions, issuer and subject references, event and knowledge times, status freshness, access marking and provenance." }, "policies": [ "Credential authenticity, integrity, current status, issuer authority, claim truth, subject control, authorization, eligibility and business acceptance are separate attributable judgments.", "Holder custody does not make the holder the subject or issuer, and a licence or permit credential may evidence but does not replace the external permission-bearing grant.", "Issued claims are immutable; correction, renewal, suspension, revocation and supersession append events and lineage and never silently rewrite issuer history.", "Agents may perform allowlisted reversible validation and projection, but issuance, revocation, broader disclosure, trust-policy change and destructive disposition require delegated authority and policy-defined confirmation." ], "crud": { "read": [ "Resolve Dimension policy, credential profile, issuer authority, subject binding, current lineage head, proof and status methods, status freshness, trust inputs and access purpose." ], "create": [ "Define class and schema before issuing; record issuer mandate, subject binding, claims, evidence, validity, status method, representation and provenance atomically." ], "update": [ "Append delivery, status, presentation, verification, correction, renewal or supersession events with actor, authority, reason, event and knowledge time and provenance; never overwrite issued claims." ], "delete": [ "Apply subject-rights, retention, legal-hold and audit policy; remove eligible holder copies, presentation data or expired proof material only through authorized disposition while preserving required issuer lineage and tombstone evidence." ] }, "roles": [ { "name": "Credential class and schema steward", "responsibilities": [ "Own definitions, claim vocabulary, profiles and migration rules." ] }, { "name": "Issuer and issuing authority", "responsibilities": [ "Own issued assertions, evidence-based decisions, status and correction history." ] }, { "name": "Subject", "responsibilities": [ "Is the referent of claims and exercises applicable rights without automatically controlling the credential." ] }, { "name": "Holder or presenter", "responsibilities": [ "Custody representations and authorize purpose-bound presentations under policy." ] }, { "name": "Verifier and relying party", "responsibilities": [ "Request minimum evidence, verify pinned profiles and own external acceptance decisions." ] }, { "name": "Status and trust steward", "responsibilities": [ "Maintain status methods, issuer qualification, trust inputs and freshness requirements." ] }, { "name": "Privacy and records steward", "responsibilities": [ "Control disclosure, correlation, retention, legal hold, disposition and auditability." ] } ], "access": { "default_rule": "Deny claim values, issuance evidence, private subject identifiers, holder inventory, presentation history and correlation handles; publish only minimum status or credential data authorized for a purpose.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Issuer, holder, subject-self, auditor, regulator, incident-response or court access cites authority and remains minimum-necessary, attributable, time-limited and separately logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, credential, operation, policy, RFC 3339 time, affected claims or status, source revision and outcome without copying protected claim content unnecessarily." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension credential, issuer, schema, trust, status, disclosure, access, retention and agent-operation policies.", "Read this model and linked identity, mandate, evidence, key, grant, policy, decision and audit models before mutation." ] } }, "coverage": { "claim": "Covers the issued attestation/credential aggregate from class and claim semantics through issuance, validity, status, securing, presentation, verification, loss-aware projection and governed disposition, grounded in eleven tier-1 W3C, IETF, OpenID Foundation and NIST sources whose citations are topically consistent with the findings that invoke them. This is explicitly not universal coverage: ISO/IEC 18013-5 mdoc, eIDAS/EUDI, sectoral credential families, legal-effect and accreditation regimes, and the VC JOSE/COSE securing path are absent or source-thin; question kinds and artifact identity are template-generated rather than analytically derived; no relation rows are approved; and no independent second-provider review exists under the owner waiver.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Credential class, issued instance, claim, representation, proof, status, presentation and event identities are distinct." }, { "dimension": "classification and definition", "status": "covered", "notes": "Credential, attestation, certificate, licence, permit and profile definitions are versioned." }, { "dimension": "direct properties", "status": "covered", "notes": "Issuer, subject, claims, schema, validity, proof, status, evidence, terms and lineage are first-class." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Schema, proof, path, key, status, time, trust, evidence and verification outcomes are explicit." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Define, issue, deliver, status, transition, request, present, verify, transform and dispose are governed." }, { "dimension": "composition", "status": "covered", "notes": "Issuer, subject, holder, verifier, mandate, evidence, key, grant, policy, decision and audit masters remain external." }, { "dimension": "lifecycle", "status": "covered", "notes": "Issuance, delivery, activation, suspension, reinstatement, revocation, expiry, renewal, correction and supersession preserve history." }, { "dimension": "relationships", "status": "covered", "notes": "Issuer, subject, holder, schema, evidence, proof, status, presentation and successor links are typed." }, { "dimension": "temporal", "status": "covered", "notes": "Issuance, delivery, validity, status, presentation, receipt, verification and knowledge times remain distinct." }, { "dimension": "spatial", "status": "covered", "notes": "Jurisdiction and processing location are referenced when material and source-qualified." }, { "dimension": "provenance", "status": "covered", "notes": "Issuance, proof, status, presentation, verification, transformation and disposition preserve responsible-agent provenance." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Schema, issuer, holder, subject, verifier, trust, privacy and records responsibilities are separated." }, { "dimension": "validation and quality", "status": "covered", "notes": "Schema, semantics, authority, proof, status, status, time, trust, stale-head and privacy checks are explicit." }, { "dimension": "access and privacy", "status": "covered", "notes": "Purpose-bound disclosure, selective disclosure, correlation controls and deny-by-default histories are explicit." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Issuer lineage, holder copies, presentations, proof material, legal hold, disposition and tombstones are distinguished." }, { "dimension": "interoperability", "status": "covered", "notes": "VC, Data Integrity, X.509, OCSP, SD-JWT and OpenID4VP projections are versioned and loss-aware." } ], "known_omissions": [ "No independent Claude or Grok result was available; later credential, PKI, privacy and legal review is required before canonical promotion.", "No approved relation rows were supplied; proposed links to identity, mandate, evidence, key, grant, policy, decision and audit models remain holds.", "National identity documents, mobile driving licences, professional licences, academic credentials, health certificates and regulated trust services require separate profiles.", "X.509 and OCSP have later updates and deployment profiles; certified processing and algorithm suites require profile-specific review." ], "conflicts": [ "An authentic credential may contain a disputed or stale claim, come from an untrusted issuer or be irrelevant to a relying-party decision.", "Holder, subject and presenter can be different parties and holder binding can increase privacy risk or correlation.", "Revocation freshness, offline verification, availability, privacy and status-list correlation impose competing requirements." ], "regional_assumptions": [ "Legal effect, issuer qualification, subject rights, retention, revocation reasons and recognition depend on jurisdiction and sector.", "W3C and OpenID specifications define technical data and protocol models but do not establish universal issuer trust or authorization.", "NIST guidance focuses on digital identity services and does not define every civil, professional, product or organizational credential." ], "adversarial_checks": [ "Reject an issued credential whose class, issuer authority, subject binding, claims, validity, schema or current lineage cannot be resolved.", "Reject technical proof success represented as claim truth, issuer trust, authorization, eligibility or legal effect.", "Reject silent claim mutation, status removal, identifier reuse, renewal without lineage or correction without issuer authority.", "Reject a presentation that is unbound to request, audience, nonce or purpose where the profile requires them, or that discloses more than authorized.", "Reject an agent operation that issues, revokes, broadens disclosure, changes trust or destroys held evidence without delegated authority." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "reclassified", "rationale": "Two axes must be separated. On the record plane, a frozen registry value such as standalone-mm classifies how the entry is stored and governed in the registry, not what the subject is; it is never a subject-model entry kind. The pack ships frozen_context as an empty object, so the registry value could not be re-read here and its cross-check is held. On the subject-model plane, the declared 'mixin' is not defensible against the provider's own evidence: the model mints and canonicalizes issued-instance identity (authoritative issuer plus credential identifier), owns an append-only lifecycle with activate/suspend/revoke/renew/correct/supersede events, defines disposition authority, legal hold, tombstones, an artifact identity priority ladder and seven steward roles. A mixin is a reusable trait attached to a host entity and owns no independent identity, retention authority or delete policy. 'aggregate' is preferred over 'entity' because credential class, typed claims, secured representations, proofs, status entries, presentations, disclosure manifests and receipts are non-independent parts governed under a single root, and the provider's own coverage claim already calls the subject 'an issued attestation and credential aggregate'. Status is reclassified rather than split, but presentation and disclosure ownership is recorded as the leading split candidate because a presentation binds a set of credentials from possibly several issuers and cannot canonicalize under one credential identifier." }, "decisions": [ { "concept": "Declared entry kind 'mixin'", "disposition": "rejected - reclassified to aggregate", "rationale": "The scope statement, canonicalization rules, artifact identity ladder, CRUD delete policy and steward roles all describe a root that owns instance identity and retention authority; a mixin owns none of these, and the provider's own coverage claim already names the subject an aggregate." }, { "concept": "Aggregate root = issued credential instance qualified by issuing authority", "disposition": "accepted", "rationale": "Canonicalization by authoritative issuer plus credential identifier, with explicit refusal of subject name, issuer serial alone, timestamp, claim values or proof digest as identity, is internally consistent across canon_and_patch, artifact_rules and every artifact identity_strategy, and matches SRC-001 and SRC-005 identity practice." }, { "concept": "Presentation, disclosure manifest and receipt ownership inside the credential aggregate", "disposition": "deferred - split candidate under hold", "rationale": "A presentation carries its own identifier, holder binding, proof and a credential set that may span issuers, so it cannot canonicalize under the mandated {credential-id} serial rule; the boundary is retained for the draft but flagged for a split decision once relation rows exist." }, { "concept": "Verifier-authored presentation request as an owned function", "disposition": "deferred", "rationale": "create-presentation-request records verifier, purpose, audience, nonce and expiry, which are authored outside the credential aggregate; retaining it risks duplicating a Verifier or Request model, so it is kept as a reference-only record pending cross-model adjudication." }, { "concept": "Externalization of issuer, subject, holder, key, mandate, grant, decision and audit masters", "disposition": "accepted", "rationale": "out_of_scope, the five boundary_notes, the composition checklist row and the stated policies agree without contradiction, and this externalization is what keeps credential authenticity from collapsing into authorization, which is the central risk for this subject." }, { "concept": "Separation of technical verification from claim truth, issuer trust and authorization", "disposition": "accepted", "rationale": "This distinction is carried consistently by a dedicated finding with an explicit non-authorization marker, a service-layer policy, an adversarial check and a declared conflict, and is directly supported by SRC-001 and SRC-009; it is the strongest and most defensible part of the result." }, { "concept": "Three-question template with rotated kind labels", "disposition": "rejected - requires re-labelling before publication", "rationale": "All 24 findings carry the same three question stems and the kind values rotate mechanically, so an identity-shaped stem is labelled 'ownership' and the histogram is a flat 3 per kind with validation at 6; the labels are generation artifacts and must not be published as evidence of analytic coverage." }, { "concept": "Uniform artifact media_or_form and slug-derived identity_strategy", "disposition": "accepted with correction", "rationale": "All 24 artifacts share identical media_or_form and a strategy templated from the finding slug, which omits the artifact-kind token that serial_naming_rule mandates and couples durable artifact identity to editorial slugs; the naming rule and the strategies must be reconciled before freeze." }, { "concept": "Identifier and name drift across findings", "disposition": "accepted with correction", "rationale": "disclosure-consent-authority-... is named 'Disclosure authority, ...' with consent dropped, and the licence/license spelling differs between id and name; because ids are load-bearing for artifact identity, drift must be reconciled rather than silently tolerated." }, { "concept": "Coverage checklist marking all sixteen dimensions covered", "disposition": "rejected - downgrade spatial and interoperability to partial", "rationale": "The spatial note concedes jurisdiction is referenced only when material, and interoperability claims loss-aware projections while omitting ISO/IEC 18013-5 mdoc and the VC JOSE/COSE securing path; a fully covered checklist also contradicts the declared medium confidence and the known omissions list." }, { "concept": "Legal effect, accreditation and recognition finding source support", "disposition": "deferred - source-thin, held from publication", "rationale": "The finding cites only SRC-001, SRC-005 and SRC-009, none of which establish legal effect, issuer accreditation or mutual recognition, so no legal-effect assertion may be published until a legal or conformity-assessment authority is added." }, { "concept": "Source version pins including RFC 9901 and four co-dated W3C Recommendations", "disposition": "deferred to live verification", "rationale": "A no-tools audit cannot confirm that SD-JWT is RFC 9901 dated November 2025, that SRC-001 to SRC-004 all carry the 15 May 2025 Recommendation date, or that RFC 6960 is updated by RFC 8954 and RFC 9654; each pin must be re-resolved against the live source before promotion." }, { "concept": "Audit logging of affected claims", "disposition": "accepted with hardening", "rationale": "audit_requirements permits logging affected claims qualified only by 'unnecessarily', which is too weak beside a deny-by-default rule on claim values; the log must be constrained to claim paths, status references and outcomes rather than claim content." }, { "concept": "Immutable issued claims versus subject erasure and disposition rights", "disposition": "deferred", "rationale": "The delete rules assert both issuer-lineage immutability and subject-rights disposition without a precedence test or a tombstone specification, so retention guidance cannot be published as normative until the jurisdictional precedence rule is settled." }, { "concept": "Absence of a subject-initiated contest or dispute intake function", "disposition": "deferred", "rationale": "Every third question asks how the item is contested, yet the ten functions expose only issuer-side correction; the missing intake path is recorded for a later provider pass rather than added here, because add_functions must remain empty under the single-provider waiver." }, { "concept": "Proposed cross-model relation rows", "disposition": "accepted as hold", "rationale": "All links to identity, mandate, evidence, key, grant, policy, decision and audit models remain unapproved proposals in known_omissions, so the deterministic synthesizer must emit no relationship edges for this record." } ], "publicationHolds": [ "Live source and version verification is outstanding for all eleven sources; RFC 9901 as Selective Disclosure for JSON Web Tokens dated November 2025, the four W3C Recommendations all dated 15 May 2025, the OpenID4VP final of 9 July 2025, NIST SP 800-63-4 of July 2025 and the RFC 6960 update chain must each be re-resolved before canonical promotion.", "Independent second-provider review is absent by explicit repository-owner waiver of both Claude and Grok; this Codex result plus a local no-tools adversarial audit is not external review and must be shown as such in every publication artifact.", "The record must publish as reviewable-draft with the corrected subject-model entry kind aggregate, and must state that the frozen registry classification is a record-plane value that was not re-readable here because frozen_context was empty.", "No approved relation rows exist; all proposed links to identity, mandate, evidence, key, grant, policy, decision and audit models stay unpublished holds and no relationship edges may be emitted.", "Question kind labels are template rotations and artifact media_or_form and identity strategies are boilerplate; both must be re-derived, and identity strategies reconciled with the {credential-id}--{artifact-kind}--{assertion-or-event-id} rule, before any freeze.", "The jurisdiction, accreditation, legal effect and recognition finding is held from publication as a normative statement until a legal or conformity-assessment authority supports it.", "Presentation, disclosure manifest and receipt ownership is held as an unresolved split candidate because presentation identity spans multiple credentials and cannot canonicalize under a single credential identifier.", "The coverage checklist may not publish as sixteen-of-sixteen covered; spatial and interoperability must be downgraded to partial and the no-universal-completeness statement carried alongside the coverage claim.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Resolve whether ISO/IEC 18013-5 mdoc and the eIDAS 2.0 / EUDI Wallet architecture belong in the crosswalk finding or in an explicit out-of-scope statement, given that OpenID4VP is widely deployed with mdoc and the model already claims loss-aware projections.", "Add or explicitly exclude the W3C Securing Verifiable Credentials using JOSE and COSE specification; the secured-representation finding talks about envelopes and detached content while citing only the Data Integrity path.", "Confirm the SD-JWT publication identity and number, and determine whether SD-JWT VC is a distinct source needed for credential-type binding beyond the base selective-disclosure mechanism.", "Establish a legal and conformity-assessment source set for issuer accreditation, legal effect and mutual recognition so the recognition-profile finding is not carried on identity and PKI sources alone.", "Settle the precedence rule between immutable issuer lineage and subject erasure or disposition rights, including a tombstone specification, before retention guidance is published as normative.", "Design the subject-initiated contest and dispute intake path that the question set assumes but the ten functions do not expose, and decide whether it is an owned function or an external decision model reference.", "Compare status-list herd privacy against OCSP request privacy and offline verification to produce a defensible freshness and correlation policy rather than the current statement of competing requirements.", "Test the holder-copy custody boundary against the declared external wallet inventory, since the model owns delivery, custody, presentation history and disposition of holder representations while disclaiming wallet inventory." ] }, "statistics": { "sources": 11, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }