← Back to catalogue
Published

Evidence / Rationale

vr.wm-xct-028 · wm-xct-028-evidence-rationale

Provide a format-neutral, attachable structure that records traceable support for a claim or decision: what supports it, by what reasoning, on whose authority, with what integrity, how strong the support is, and how it can be re-checked, contested, retained or withdrawn.

World Models Cross-cutting context XCT.EVD

Bundle → Layer → Finding → Questions Filled

6 bundles · 14 layers · 33 findings · 157 questions

Claim–Support Structure The argument skeleton: how a support record binds to exactly one supported claim or decision, what kind of support relation is asserted, what reasoning licenses the conclusion, and how contrary evidence is registered and resolved.

Support Binding and Relation Typing

How the mixin attaches to its host assertion and what typed relation each evidence item bears to it.

Host binding and scope of support

Identifies the single claim, decision or assertion the record supports, the part of it in scope, and the effect of host revision. Evidence attaches to a specific claim, not to a document.

  1. Which single claim, decision or assertion does this record support, and by which stable identifier in which master system? identity
  2. Does the support apply to the whole host assertion or only to a named component, qualifier or numeric bound within it? composition
  3. Can one evidence item support several claims by reference without being copied, and how is that many-to-many reuse represented? relationship
  4. When the host assertion is revised or superseded, does the support record carry over, lapse, or require re-affirmation? lifecycle

Typed support relation

The declared relation each evidence item bears to the supported subject — supports, corroborates, is authority for, qualifies, disputes, refutes — drawn from a named vocabulary rather than free text.

  1. Which governed vocabulary and version supplies the relation term, and what is its IRI? interoperability
  2. Is the relation supportive, neutral/informative or contrary, and is that polarity asserted or derived from the vocabulary? classification
  3. Who asserted that this item stands in this relation to the claim, as distinct from who created the item? provenance
  4. Does the relation carry a weight or contribution, and on what scale is that weight expressed? measurement

Relevance to a fact of consequence

Records the relevancy analysis without treating relevance as an inherent property of the item and without confusing it with sufficiency of the whole body of evidence.

  1. Does this item have any tendency to make the stated fact more or less probable than it would be without the item? evidence
  2. Is the fact to which the item is directed of consequence in determining the host action or decision? evidence
  3. Does probative value depend on a missing condition of fact, such as whether a statement was heard, that must be recorded as conditional relevance? constraint

Reasoning, Assumptions and Challenge

The inference that licenses moving from evidence to claim, the assumptions and context conditions it depends on, the alternatives rejected, and the counter-evidence and defeaters raised against it.

Inference, warrant and argumentation scheme

The reasoning step deriving the claim from its premises under a specified context, expressed as a justification, together with the scheme or rule applied and its defeasibility.

  1. What warrant licenses the step from these premises to this claim, stated so a reviewer can attack the step rather than the premises? definition
  2. Which argumentation scheme or inference rule is applied, and from which catalogue and version is it drawn? classification
  3. Is the inference deductive, inductive, abductive or statistical, and what conditions would defeat it without any premise being false? constraint
  4. Is the reasoning machine-checkable, reviewer-checkable, or asserted only, and what evidence supports that classification? validation
  5. If no evidence item is attached, on what basis other than evidence does the conclusion rest, and is that flagged to consumers? exception

Assumptions, context conditions and rejected alternatives

The explicit assumptions the argument depends on, the scope conditions bounding its validity, and the options considered and rejected with reasons — the part of rationale that explains why not something else.

  1. Which assumptions must hold for this support to stand, and is each validated, accepted-without-validation or known-unverifiable? constraint
  2. Under what context, population, environment or time window does the support hold, and where does it explicitly not apply? constraint
  3. Which alternative claims, options or interpretations were considered and rejected, and on what stated ground was each rejected? decision
  4. What observable change would invalidate an assumption, and who is accountable for monitoring it? process

Counter-evidence, defeaters and their resolution

Registration of evidence and arguments that rebut the claim, undercut the inference or undermine a premise, and the record of how each was adjudicated or left open.

  1. What contrary or non-confirming evidence is known to exist, including evidence sought but not found? evidence
  2. Does each challenge rebut the claim, undercut the inference, or undermine a premise? classification
  3. Who adjudicated the conflict, under what authority and by what stated rule of preference? authority
  4. What conflict remains unresolved, and is that residual disclosed to consumers of the claim? quality
  5. How is selective inclusion of only confirming evidence detected and prevented for this record? validation
Evidence Item, Anchoring and Custody The evidence item as an addressable thing: its identity and form, where in a source it is anchored and how faithfully it was excerpted, how it was acquired, and the custody record that makes it auditable.

Evidence Identity and Form

How an evidence item is identified and classified independently of where it is stored.

Evidence item identity

Assignment and precedence of identifiers for an evidence item, separation of the item from the record describing it, and content-digest identity for immutable items.

  1. Which identifier is authoritative for this item: a master-system identifier, a governed global identifier or IRI, or a Dimension-assigned UUID/ULID? identity
  2. Which identifier denotes the physical or digital item, and which denotes the record describing it? definition
  3. Is the item immutable and therefore identifiable by content digest, or mutable and identifiable only by reference plus captured state? identity
  4. When the item is revised, is a new identity minted or a version label appended, and how is the prior version reachable? lifecycle
  5. How are duplicate submissions of the same underlying item detected and merged without losing distinct custody histories? validation

Evidence form and modality

Classification of the item by evidentiary form (documentary, testimonial, observational, computational, attestation, physical) and by medium and encoding, and whether it is an original or a copy.

  1. Which evidentiary form does the item take, and from which governed taxonomy is that class drawn? classification
  2. What media type, encoding and structural profile does the item use, and is it self-describing? interoperability
  3. Is this the original, a forensic image, a derived rendering or a summary, and where is the original if not held? provenance
  4. Does the form change the handling, integrity or admissibility obligations that apply to the item? requirement
  5. Is the item a composite of separately addressable parts, and is each part independently identified and hashed? composition

Source Anchoring and Excerpt Fidelity

Precise addressing of the part of a source relied on, capture of the source state, and the transformation chain from source to the excerpt actually used.

Source anchor and locator

Identification of the source resource, the selector addressing the relevant part, and the state of the source at the time of reliance so the anchor survives later change.

  1. Exactly which part of the source is relied on, expressed by which selector type and value? spatial
  2. What was the state of the source when it was relied on, and how is that state re-obtainable? temporal
  3. How is it detected that the source changed after anchoring, and what happens to the support when it has? validation
  4. What is recorded when the item has no source anchor at all, such as a direct sensor reading or live testimony? exception
  5. If the source becomes unavailable or paywalled, what preserved surrogate stands in and with what authority? access

Excerpt fidelity and transformation chain

Whether what is relied on is a verbatim quotation or a transformed derivative, which transformations were applied by which agent, and how the excerpt can be checked back against the source.

  1. Is the relied-on text or data a verbatim quotation from the source, a translation, an OCR output, a redaction or a paraphrase? provenance
  2. Which transformation steps were applied between the source and the excerpt, in what order, and by which agent or tool? process
  3. How can a third party verify the excerpt against the source, and what is the outcome of the last such check? validation
  4. In what language and script is the excerpt, and if translated, who translated it and is the original retained? quality
  5. Does the excerpt preserve the qualifications, negations and scope present in the source, and who confirmed that? quality

Acquisition and Chain of Custody

How the item was obtained and by what method and instrument, and the unbroken custody record from acquisition to present.

Acquisition method and instrument

The method, tool, settings and operator used to obtain the item, and whether the process is one shown to produce an accurate result.

  1. By which of identification, collection, acquisition or preservation was the item obtained, and what method was used? process
  2. Which instrument or tool, at which version and configuration, produced the item? provenance
  3. Who performed the acquisition, under what role and with what demonstrated competence? authority
  4. Is the process one shown to produce an accurate result, and where is that showing recorded? validation
  5. Where and under what conditions was the item acquired, to the precision the case requires? spatial

Chain of custody and handling

The custody record from the moment the item was acquired: who held it, when, what integrity check accompanied each transfer, and whether any gap exists. Custody is physical, logical and documentary.

  1. What sequence of custody events exists from acquisition to now, and is any interval unaccounted for? temporal
  2. Who held or controlled the item during each interval, and under what authority did control transfer? ownership
  3. What integrity value or seal was recorded at each transfer, and did it verify on receipt? validation
  4. Which custody modes apply — physical storage, logical seals and hashes, documentary access logs — and who maintains each? security
  5. For how long after the evidence ceases to be needed must the custody record itself be preserved? retention
Provenance, Attribution and Time Where the evidence came from, who is responsible for it and for the assertion of support, and the separated time points that let a reader judge currency and ordering.

Origin, Derivation and Attribution

The lineage of the evidence item and the responsibility relations attached to it and to the support assertion.

Derivation chain and primary source

The chain from the item back to its origin, distinguishing primary source produced by an agent with direct experience from quotation, revision and downstream derivation.

  1. Which preceding entity, produced by an agent with direct experience of the matter, is the primary source of this item? provenance
  2. What derivation, quotation and revision steps connect this item to that origin, and which activity generated each step? provenance
  3. Is the item primary, secondary or tertiary relative to the claim, and by whose classification? classification
  4. Does the lineage contain a cycle or converge on a single upstream origin shared with items counted as independent? validation
  5. When the item was composed from other assets, is each ingredient's own provenance retained rather than flattened? composition

Attribution, responsibility and independence

Which agents bear responsibility for the item and for the assertion that it supports the claim, on whose behalf they acted, and whether they are independent of the outcome.

  1. To which agent is the item attributed, and which agent asserted that it supports the claim? provenance
  2. Did the agent act on behalf of another agent who retains responsibility, and is that delegation recorded? authority
  3. Is the responsible agent a person, an organisation or a software agent, and does that change the weight given? classification
  4. Is the agent independent of the outcome the claim supports, and what interests are declared? quality
  5. Is the item self-reported by the party whose claim it supports, and is that flagged rather than silently equated with third-party evidence? quality

Temporal Frame and Currency

Separated time points, clock quality, and the window within which the support remains adequate.

Separated time points and clock quality

Distinct recording of when the fact occurred, when it was observed, when it was ingested and when support was asserted, each in RFC 3339 with explicit offset, plus the clock source that produced them.

  1. Which distinct time points are recorded — event, observation, ingestion, assertion, verification — and which are unknown? temporal
  2. Does every time value carry seconds and an explicit numeric offset or Z, and is -00:00 used only where the local offset is genuinely unknown? constraint
  3. What clock produced each timestamp, with what traceability and accuracy? measurement
  4. How is a partially known time expressed without inventing precision, for example a known date but unknown time? exception
  5. When two records disagree on ordering because their clocks differ, which ordering rule governs? validation

Validity window, staleness and supersession

The period over which the support is asserted to hold, the re-verification cadence, and how superseding evidence replaces it without erasing the prior state.

  1. From when until when is this support asserted to hold, and is the end open or fixed? temporal
  2. How often must the support be re-verified for its purpose, and when is the next re-verification due? process
  3. At what point does the support count as stale, and what does a consumer see when it is? state
  4. Which later support record supersedes this one, and is the superseded record retained and still resolvable? lifecycle
  5. What invalidates the evidence item itself, as distinct from the support lapsing, and how is that recorded? event
Integrity, Attestation and Verification Whether the evidence is what it purports to be and has not changed: content binding by digest, signatures and attestations, trusted timestamps, verification events, and reproducibility of derived evidence.

Cryptographic Binding and Attestation

Digests, signatures and timestamps that make an evidence record tamper-evident and its time of existence provable.

Content digest and hard binding

What is hashed, under which algorithm and canonical form, and how the binding survives storage-format change. Digest identity applies only to items treated as immutable.

  1. Which digest algorithms are recorded, and does the record permit more than one to support algorithm agility? security
  2. Exactly what bytes or structure does the digest cover, and under what canonicalisation? constraint
  3. Does a hard binding exist that ties the support record to this specific item rather than merely naming it? validation
  4. What happens to the binding when the item is transcoded, re-encoded or migrated between stores? exception
  5. For items that cannot be hashed, such as physical exhibits or live testimony, what stands in for content binding? exception

Signature and attestation

Who cryptographically asserted the record, under which securing mechanism, what the signature covers, and how signer trust and revocation are established.

  1. Which agent signed, with which key or certificate, and how is that signer identity resolved to a known party? identity
  2. Which securing mechanism is used, embedded or enveloping, and is more than one required? security
  3. What exactly does the signature cover — the claim, the assertion set, the payload — and what is deliberately outside it? constraint
  4. Against which trust list or policy is the signer accepted, and who curates that list? authority
  5. How is revocation or expiry of the signing credential detected, and does it retroactively invalidate the record? lifecycle

Trusted timestamp and temporal proof

Third-party attestation that the evidence existed before a stated time, with the accuracy and policy under which it was issued, and the long-term validity strategy.

  1. Is there a third-party timestamp proving the item existed before a stated time, and if not, why is a self-asserted time considered sufficient? evidence
  2. Which authority issued the token, under which policy identifier, and what serial number does it carry? authority
  3. What generation time and accuracy does the token assert, and is that precision adequate for the ordering the claim depends on? measurement
  4. How does the record stay verifiable after signing credentials expire or algorithms weaken? lifecycle
  5. What would distinguish a genuine token from a backdated one if the authority's key were compromised? security

Verification Events and Reproducibility

The record of checks actually performed on the evidence, and whether derived or computed evidence can be independently re-derived.

Verification events and current status

Each verification is an event with an actor, method, time and outcome; the current status is derived from events, not asserted independently, and integrity verification is kept separate from truth of the claim.

  1. When was the record last verified, by which agent, using which method and tool version? validation
  2. What was the outcome of each verification step, and which specific step failed when the outcome was negative? evidence
  3. Does the verification status assert only integrity and signer validity, and is it clearly not a statement that the claim is true? definition
  4. For how long is a verification result relied on before it must be repeated? temporal
  5. Can a party other than the issuer verify the record with only the exported package, and what does that require? interoperability

Reproducibility and method replay

For computed, analysed or derived evidence, whether the same result is obtainable by the same person with the same method (repeatability) and by a different person with a different setup (reproducibility).

  1. Can an independent party re-derive this evidence, and has anyone actually done so with what result? validation
  2. Which inputs, parameters, code versions and environment are recorded, and are they sufficient to re-run? process
  3. Is the derivation deterministic, and if not, what is the expected variation and its source? quality
  4. What prevents reproduction — licensed data, unavailable hardware, expired credentials, non-public source — and is that disclosed? exception
  5. Is the record claiming repeatability, reproducibility, or neither, and on what basis? definition

Authentication foundation

The proponent must produce support sufficient to find that the item is what it is claimed to be, using one or more recognized methods such as witness knowledge, distinctive characteristics, public-record custody, or process-or-system accuracy.

  1. What is the item claimed to be, and what would count as it being that thing? identity
  2. Which authentication method or methods are offered, and are they examples under a governing rule or another statute-provided method? validation
  3. Has authentication been distinguished from later bars such as hearsay, privilege or prejudice that can still exclude an authenticated item? constraint
Appraisal, Strength and Sufficiency How strong the support is against a declared scheme, what limits it, whether it meets the threshold the decision requires, and whether apparent corroboration is genuine.

Certainty and Limitations

Scheme-declared certainty grading and the explicit limitations that drive it.

Certainty grading against a declared scheme

The certainty or confidence level assigned, always paired with the identifier and version of the scheme that defines it, the domains that drove the rating and the grader.

  1. Which grading scheme and version defines the level assigned, and what are its permitted values? classification
  2. What certainty level is assigned, and which domains caused it to be rated down or up? measurement
  3. Who performed the grading, when, and were they independent of the claim's proponent? provenance
  4. Is certainty in the evidence kept distinct from the strength and direction of any recommendation or decision drawn from it? definition
  5. Can this level be compared with a level from a different scheme, and on what authority is any such mapping made? interoperability

Bias, limitations and measurement reliability

Known biases, coverage limits, indirectness and quantified uncertainty attaching to the evidence, recorded so consumers see them without re-deriving them.

  1. What biases are known or suspected in how this evidence was produced or selected? quality
  2. What measurement error, interval or confidence attaches to any quantitative evidence, and in what units? measurement
  3. What population, period, geography or system does the evidence actually cover, and where is it being applied beyond that? constraint
  4. How are these limitations surfaced to a downstream consumer who reads only the claim? access
  5. Which limitations are known to exist but are not quantified, and is that stated rather than omitted? exception

Quantitative statistic support

The numeric heart of scientific evidence: statistic type, quantity, unit, sample size, intervals, p values, model characteristics, and study or synthesis type.

  1. What statistic type, quantity, unit of measure and sample size are reported for this evidence bit? measurement
  2. What confidence intervals, p values, heterogeneity estimates and statistic-model characteristics qualify the quantity? measurement
  3. From what study type, and if synthesized from what synthesis type, was the statistic obtained? classification

Sufficiency, Burden and Corroboration

Whether the assembled support clears the threshold the decision requires, and whether multiple items are genuinely independent.

Sufficiency threshold and burden

The standard the support must meet for this decision, who set it, whether it is met, and what would be needed if not. Sufficiency is a property of the assembled support, not of any single item.

  1. What standard must the support meet for this decision, and who set that standard? requirement
  2. Is the standard met on the evidence currently assembled, and who determined that? decision
  3. If it is not met, precisely what additional evidence or reasoning would close the gap? requirement
  4. Which party bears the burden of producing support, and does that burden shift on any condition? authority
  5. What happens operationally when a decision proceeds despite insufficient support, and how is that override recorded? exception

Corroboration and genuine independence

Whether multiple supporting items are independent or trace to one origin, and detection of double counting and circular citation that inflate apparent support.

  1. How many distinct items support the claim, and how many remain after collapsing items that share an origin? measurement
  2. Are the supporting items independent in origin, method and agent, and on what basis is independence asserted? validation
  3. Does any supporting item ultimately cite the claim it is offered to support, or cite a sibling item as its own source? relationship
  4. If support rests on a single item or agent, is that single-source dependency flagged to consumers? quality
  5. Does convergence of independent items change the certainty level, and under which rule of the declared scheme? decision
Governance, Access, Retention and Interoperability Who owns and approves the support record, what rights govern its reuse, who may see it and in what form, how long it is kept and how it is disposed of, how it moves through lifecycle states, and how it maps to and exchanges with external models.

Ownership, Authority and Rights

Accountable parties for the record and the rights that constrain reuse of what it contains.

Ownership, stewardship and approving authority

The accountable owner, the day-to-day steward, and the authority that approved the support as adequate, together with the mandate under which that approval was given.

  1. Which party is accountable for this support record and able to demonstrate its compliance on demand? ownership
  2. Who maintains the record day to day, and how does stewardship differ from ownership here? ownership
  3. Which authority approved the support as adequate, under what mandate, and when? authority
  4. May approval authority be delegated, to whom, and does the delegating party retain responsibility? authority
  5. What happens to ownership when the owning party is dissolved, reorganised or leaves, and who is the fallback? lifecycle

Rights, licence and permitted use

The rights attaching to source material quoted or held as evidence, what reuse and redistribution are permitted, and the attribution obligations that travel with the excerpt.

  1. Under what licence or legal basis is the source material held, quoted and stored? authority
  2. May the evidence item or excerpt be redistributed outside the holding organisation, and to whom? access
  3. What attribution must accompany the excerpt wherever it is displayed or exported? requirement
  4. Does the material contain third-party rights or personal data that constrain use beyond the licence? privacy
  5. Do any territorial, export-control or contractual restrictions limit where the evidence may be transferred? constraint

Access, Confidentiality, Retention and Disposition

Who may see the evidence and in what form, and how long it is kept before disposal.

Access classification and redaction

Classification of the support record and its items, the distinction between disclosing existence and disclosing content, and the relationship between a redacted disclosure copy and the unredacted original.

  1. What classification applies to the support record, and does it differ from that of individual evidence items? security
  2. May the existence of the evidence be disclosed to a party who may not see its content, and to whom? access
  3. Is legal privilege, commercial confidence or a statutory restriction claimed, by whom and on what basis? exception
  4. How does a redacted disclosure copy relate to the original, and is the redaction itself recorded and reversible by authorised parties? privacy
  5. Is personal data in the evidence limited to what is necessary for the evidential purpose, and who reviews that? privacy

Retention, legal hold and disposition

How long the support record and its items are kept, the floors and caps that apply, the effect of a legal hold, how erasure requests interact with evidential need, and what remains after disposal.

  1. How long must this record be kept, and what is the legal or policy basis for that period? retention
  2. Does a sectoral floor apply, such as a minimum log-retention period for high-risk systems, and does it exceed the general policy? requirement
  3. Does storage limitation cap how long the material may be kept in identifiable form, and how is the conflict with the floor resolved? constraint
  4. Is a legal hold in force, who placed it, and what does it suspend? exception
  5. How is an erasure request handled when the material is needed for the establishment, exercise or defence of legal claims? privacy
  6. After disposal, what remains — a tombstone, a hash, nothing — and how is disposal itself evidenced? provenance

Record Lifecycle and Interoperability

States the support record moves through, the difference between correcting and retracting it, and how it maps to and exchanges with external evidence and provenance models.

Lifecycle states, correction and retraction

The permitted states of a support record and the transitions between them, with correction distinguished from retraction and history preserved rather than overwritten.

  1. Which states may a support record occupy, and which transitions between them are permitted? state
  2. Who may move the record to disputed, withdrawn or retracted, and does that differ from who may create it? authority
  3. What distinguishes correcting a support record from retracting it, and which is recorded when the underlying evidence proves false? lifecycle
  4. How are downstream consumers of the claim notified that its support was retracted or superseded? process
  5. Is the change history append-only, and how is that immutability enforced and checked? security

Standards alignment and exchange packaging

Declared mappings from this model to external provenance, assurance-case, credential, attestation, citation and annotation models, and the self-contained package by which a support record moves between systems. Alignments are not conformance claims.

  1. To which external models does this model declare a mapping, at which versions, and for which elements? interoperability
  2. Is each mapping lossless in both directions, and what is lost in the direction that is not? interoperability
  3. Is any conformance to an external standard claimed, and what evidence supports that claim as opposed to mere alignment? evidence
  4. What does a self-contained export contain so that a receiving system can verify the record without access to the originating store? composition
  5. On import, how are referential integrity, identifier collisions and unresolvable references handled? validation

Classifiers Filled

Family
World Models
Category
Cross-cutting context
Entry kind
mixin
Navigation path
NAV.XCT.EVD
Domain
XCT.EVD
Industry
Cross-industry
Tags
evidencerationalexct.evd

What it is Filled

This mixin is attached to a host record that already asserts something (a claim, decision, classification, requirement or measurement held in a sibling model). It supplies the support apparatus around that assertion: typed support relations to evidence items, the inference/warrant and assumptions that license the conclusion, counter-evidence and its resolution, evidence identity, anchoring into sources, acquisition and custody, provenance and time, cryptographic integrity and verification, quality appraisal and sufficiency, and the governance surface (authority, rights, access, retention, lifecycle, interoperability). It never carries the propositional content of the claim itself and never duplicates the bibliographic record of a source, the agent registry or the audit-log infrastructure.

In scope

  • Typed support and counter-support relations between evidence items and a supported claim or decision
  • Reasoning apparatus: warrant/inference, argumentation scheme, assumptions, scope conditions, alternatives considered and rejected
  • Evidence item identity, form/modality, anchoring into a source location and state, and excerpt fidelity
  • Acquisition method, instrument, and chain of custody including auditability, repeatability and reproducibility
  • Provenance, attribution, independence/conflict of interest, and separated event/observation/record/assertion times
  • Cryptographic content binding, signatures/attestations, trusted timestamps and verification events
  • Certainty grading against a declared scheme, bias and limitations, sufficiency thresholds and corroboration
  • Governance of the support record: ownership, approving authority, rights, access classification, redaction, retention, legal hold, lifecycle states and retraction
  • Declared alignments and exchange packaging to external provenance, assurance-case, credential and attestation models

Out of scope

  • The propositional content, truth value or semantics of the supported claim itself (belongs to the parent knowledge/claim model)
  • The full bibliographic or catalogue record of a source document, dataset or publication (sibling source/citation model)
  • The agent, organisation and role registry that identifiers here resolve into (sibling agent/party model)
  • General-purpose provenance/lineage of arbitrary artefacts not offered in support of a claim (sibling provenance model)
  • Audit-log and telemetry infrastructure design, log shipping and SIEM operation
  • Legal case management, court procedure, disclosure workflow and forensic investigation case files
  • Evidence synthesis statistics: meta-analysis, pooling, effect-size estimation and study design
  • Dialogue and argumentation protocols (turn taking, burden shifting in dialogue games)
  • Trust or reputation scoring of agents and sources as a standalone scored model
  • Cryptographic key management, PKI operation and trust-list curation

Why it exists Filled

Provide a format-neutral, attachable structure that records traceable support for a claim or decision: what supports it, by what reasoning, on whose authority, with what integrity, how strong the support is, and how it can be re-checked, contested, retained or withdrawn.

Distinguishing features Filled

  • A mixin that adds support for an existing assertion: evidence items, warrant, assumptions and counter-evidence.
  • Differs from provenance, which tracks origin; this model argues why a conclusion is justified.
  • Differs from a citation record, which identifies sources but not how they support a claim.
  • Records custody, sealing and certainty appraisal of the evidence body.

What robots and AI may and may not do Filled

Must not

  • Fabricate or paraphrase evidence and present it as a quotation.
  • Omit known counter-evidence.
  • Claim sufficiency without assessing against the decision threshold.
  • Break chain of custody by altering sealed items.
  • Disclose evidence containing personal data beyond the declared audience.

Only with a human decision

  • Judging sufficiency for a legal, clinical or safety decision.
  • Adjudicating counter-evidence.
  • Releasing evidence to external parties.

May

  • Attach evidence to a claim or decision with a typed support relation.
  • Anchor an excerpt to the exact location in its source.
  • Register counter-evidence and record how it was resolved.
  • Produce a redacted disclosure copy for an authorized requester.

Moral aspects Filled

  • People can be harmed by decisions based on weak or selectively presented evidence.
  • Evidence often contains personal data about third parties.
  • Agents must not make generated text look like source evidence.

Who is affected

  • People affected by the supported decision
  • Authors and subjects of evidence items
  • Reviewers and courts

Owners Filled

Steward

The adopting Dimension MUST designate a single accountable owner for each support record and be able to demonstrate compliance for it on request, plus a named steward for day-to-day maintenance.

Roles

Evidence steward
Registers evidence items, applies identifier precedence and maintains digests; Maintains the chain-of-custody log and investigates any custody gap; Maintains source anchors and re-captures source state when drift is detected
Rationale author
States the warrant, inference mode, assumptions and context conditions; Records alternatives considered and the reasons each was rejected; Flags assumption-only support and unquantified limitations
Appraiser
Applies a declared grading scheme and records per-domain judgements; Assesses bias, indirectness, coverage limits and independence of sources; Declares interests and abstains where independence is compromised
Verifier
Runs integrity, signature, timestamp and binding checks and records the outcome per step; Confirms independent verifiability of exported packages; Reports failures without altering the record under verification
Adjudicating authority
Decides challenges to the claim or its inference under a stated rule of preference; Records residual unresolved conflict rather than closing it artificially; Approves or refuses sufficiency overrides and records the rationale
Records and privacy officer
Resolves retention floors against storage-limitation caps and records the governing rule; Places and lifts legal holds and authorises disposition; Authorises redaction and handles erasure requests including exemption determinations

Links to other meta-models Filled

child

  • WM-KNW-008 (parent knowledge/claim model) - This mixin is a child of the knowledge model and attaches to the assertion it holds; the claim remains addressable and meaningful without support, and the support is meaningless without the claim.

composes

  • Decision record model (decision, options, outcome) - Supplies rationale, alternatives-rejected reasons, assumptions and supporting evidence to a recorded decision, in the same way rationale is recorded as description content separate from the thing described.
  • Provenance / lineage model - Composes entity, activity and agent lineage with derivation, generation and attribution relations for evidence items, and treats the provenance bundle as itself an attributable entity.

references

  • Source / citation / bibliographic model - Resolves source-ref to a described source; this model contributes only the locator, selector, captured state and citation intent, never the bibliographic description.
  • Agent / party / organisation registry - Resolves every agent reference — asserter, custodian, signer, grader, approver, adjudicator — to a governed party record with roles and delegation.
  • Access classification and authorisation model - Resolves classification codes and access conditions; this model contributes only evidence-specific exceptions such as privilege claims and redaction maps.
  • Records retention and disposition model - Resolves retention-rule-ref to a schedule with legal bases, floors and caps; disposition execution and certification are performed here against that schedule.
  • Measurement / observation model - Resolves observational evidence items to their measurement semantics, units and uncertainty rather than restating instrument and method semantics in this model.

aligned

  • W3C PROV-O / PROV-DM - Alignment target for derivation, primary source, quotation, revision, attribution, delegation, invalidation and bundle-level provenance-of-provenance. Alignment only; no conformance is claimed.
  • OMG SACM 2.3 and ISO/IEC/IEEE 15026-2:2022 - Alignment target for the claim/argumentation/evidence separation, inference as a reasoning step under a specified context, explicit assumptions and justification, and auditability of the case.
  • W3C Verifiable Credentials Data Model 2.0 - Alignment target for issuer, evidence, proof, validFrom/validUntil and credentialStatus, and for the separation of credential verification from evaluation of claim truth.
  • C2PA Technical Specification 2.2 and in-toto Attestation Framework - Alignment targets for digest-based subject identity, hard bindings, hashed URIs, created versus gathered assertions, ingredient provenance and signed statement envelopes.
  • W3C Web Annotation Data Model and CiTO - Alignment targets for selector-based anchoring with source state, and for the governed vocabulary of support, authority, agreement and refutation relations with factual/rhetorical polarity.
  • ISO/IEC 27037:2012 digital evidence handling - Alignment target for the identification/collection/acquisition/preservation processes, the auditability, repeatability and reproducibility principles, and unbroken chain of custody across physical, logical and documentary modes.
  • GRADE certainty-of-evidence approach - Alignment target for scheme-declared certainty levels, rating-down and rating-up domains, and separation of evidence certainty from recommendation strength and direction.

extends

  • Regulatory logging and technical documentation obligations (EU AI Act, NIST SP 800-53 AU family) - Extends the model with mandated machine-generated evidence, minimum log content for defined system classes, and audit-record governance including retention floors, without absorbing the logging subsystem itself.

neighbor

  • WM-KNW-008 (parent knowledge/claim model) - The parent holds the assertion; this mixin holds why the assertion is held. An assurance case separates the top-level claim from the structured argumentation and the evidence and assumptions underlying it, so the claim must remain addressable independently of its support.
  • Source / citation / bibliographic model - This model references a source by identifier and adds a locator, selector and captured state; it does not carry title, authorship, edition or catalogue metadata. Web Annotation separates the Target resource from the Specific Resource plus Selector used to address part of it.
  • Provenance / lineage model - PROV describes generation, derivation and attribution for any entity. This mixin uses that vocabulary only for entities offered in support of a claim, and additionally records the assertion of support itself, which PROV does not model.
  • Attestation / verifiable credential model - A verifiable credential is itself a signed claim container whose optional evidence property describes how the issuer verified claims before issuance. A credential may be an evidence item here, but credential issuance, holding and presentation are governed elsewhere.
  • Audit trail / event log model - Automatically generated logs are a source of evidence items and are separately mandated with their own retention floors; the logging subsystem, its content requirements and its retention schedule belong to the log model, not to this mixin.
  • Digital forensic case model - ISO/IEC 27037 governs identification, collection, acquisition and preservation of potential digital evidence by designated roles. This mixin records the custody and integrity facts needed to reason about admissibility, not the forensic process, tooling competence regime or investigation case file.
  • Decision record model - The decision, its options and its outcome live in the decision model. This mixin supplies the rationale, alternatives-rejected reasons and supporting evidence attached to that decision, in the same way an architecture description carries rationale separately from the architecture it describes.
  • Measurement / observation model - An observation's method, unit, uncertainty and sensor semantics belong to the measurement model. Here an observation is treated as an evidence item with an acquisition record and an appraisal, not re-specified.

parent

  • WM-KNW-008

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative master-system identifier issued by the system of record that owns the artefact (for example an instrument run identifier, a case number, an issuer-assigned credential identifier).
  • Governed global identifier or IRI from a recognised registry or vocabulary where no master system exists.
  • UUID or ULID minted by the adopting Dimension, recorded together with the scheme that minted it.
  • For immutable digital artefacts, a content digest under a declared algorithm and canonicalisation accompanies the chosen identifier and is used for equality and subject matching; it does not replace the identifier.
  • A date, a filename, a URL alone or a human label is never an identifier and MUST NOT be used as one.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • A support record links an assertion to evidence items with relation types, warrant and certainty.
  • Often confused with a bibliography, an audit log and an attachment folder.

Capabilities and actions required Filled

  • Attach support to a claim or decision: Bind a new evidence/rationale record to exactly one host assertion, declaring the supported aspect and the initial reasoning.
  • Register an evidence item: Create an evidence item record with identifier precedence applied, form classification, and content digests where the item is immutable.
  • Anchor an excerpt into a source: Record the selector addressing the relied-on part of a source, capture the source state, and store the excerpt with its fidelity mode and transformation chain.
  • Record a custody event: Append an acquisition, transfer, access, storage or disposal event to the custody chain for an evidence item, with an integrity value at transfer.
  • Seal and timestamp a support record: Compute the integrity manifest, sign the record and obtain a third-party timestamp token proving it existed before a stated time.
  • Verify integrity, signature and bindings: Run the verification sequence over a support record: locate the manifest, check the signature, check the timestamp, validate referenced items, compare hard bindings, and recurse into ingredient provenance.
  • Appraise certainty of the evidence body: Apply a declared grading scheme to the assembled evidence, recording per-domain judgements and the resulting level, separately from any recommendation strength.
  • Assess sufficiency against the decision threshold: Determine whether the assembled support meets the standard required for the host decision, and describe the gap when it does not.
  • Register and adjudicate counter-evidence: Record an item or argument that rebuts the claim, undercuts the inference or undermines a premise, and capture the adjudication outcome.
  • Revalidate or supersede a support record: Re-run verification and appraisal at the declared cadence, and where evidence has moved on, issue a successor record linked to the prior one.
  • Redact and release a disclosure copy: Produce a derived copy with restricted content removed or masked for a named recipient, linked to the original by a recorded derivation.
  • Export a self-contained evidence package: Assemble the support record, its items or digests, provenance, signatures and timestamps into a package a receiving party can verify independently.
  • Apply retention, hold or disposition: Evaluate retention floors, identifiability caps and any legal hold, and where retention has expired without a hold, execute the declared disposition and issue a certificate.
  • Authenticate an evidence item: Record the foundation that the item is what it is claimed to be, using one or more recognized methods.
  • Challenge or invalidate support: Mark support as challenged, withdrawn, superseded or invalidated and point to successor or grounds.

Hazards and failure modes required Filled

  • Cherry-picked evidence leads to unjust decisions.
  • Broken custody makes evidence inadmissible.
  • Hallucinated citations mislead reviewers.

Standards and interfaces required Filled

  • W3C PROV-O and PROV-DM.
  • ISO/IEC/IEEE 15026-2 assurance cases.
  • OMG Structured Assurance Case Metamodel (SACM).
  • W3C Web Annotation Data Model for anchoring excerpts.
  • GRADE approach for certainty of evidence.

Context of use required Filled

  • The six-month retention floor for automatically generated logs derives from EU law applying to high-risk AI systems and was read from a secondary rendering of Article 19; it does not apply outside that scope and must be re-verified against the Official Journal text.
  • Erasure, storage-limitation, accuracy and accountability constraints assume EU/EEA personal-data scope; other regimes impose different and sometimes stricter or looser obligations.
  • Authentication examples and the sufficiency framing drawn from Rule 901 are United States federal practice. Civil-law jurisdictions generally apply free evaluation of evidence without an equivalent authentication threshold, so sufficiency-standard codes must be jurisdiction-qualified.
  • The legal effect of a trusted timestamp is assumed to require a jurisdiction-specific framework (for example a qualified trust service regime); RFC 3161 alone establishes a technical, not a legal, proof of time.
  • Certainty grading practice drawn from GRADE originates in health-care guideline development; its transfer to engineering, legal or operational evidence is by analogy and is not endorsed by the cited source.
  • Language and script handling assumes excerpts carry a language tag; no standard for tagging was verified in this research, and multilingual evidence with mixed scripts may need Dimension-specific rules.
  • Legal relevance and authentication examples use United States Federal Rules of Evidence as published via LII; other jurisdictions need local mapping.
  • GRADE is globally used in health guidelines but remains health-originated; non-health decisions must not assume GRADE categories without a documented profile.
  • ISO/IEC 27037:2012 remains current after 2018 confirmation but is under review; device examples include obsolete media classes that adopting Dimensions should extend.
  • Privacy minimization follows W3C VC privacy considerations and C2PA creator-control guidance, not a specific GDPR or sectoral statute.

Sources Filled

  1. PROV-O: The PROV Ontology - World Wide Web Consortium (W3C)
  2. PROV-DM: The PROV Data Model - World Wide Web Consortium (W3C)
  3. Verifiable Credentials Data Model v2.0 - World Wide Web Consortium (W3C)
  4. Web Annotation Data Model - World Wide Web Consortium (W3C)
  5. Structured Assurance Case Metamodel (SACM), Version 2.3 - Object Management Group (OMG)
  6. ISO/IEC/IEEE 15026-2:2022 Systems and software engineering — Systems and software assurance — Part 2: Assurance case - ISO/IEC/IEEE
  7. ISO/IEC/IEEE 42010:2022 Software, systems and enterprise — Architecture description - ISO/IEC/IEEE
  8. ISO/IEC 27037:2012 Information technology — Security techniques — Guidelines for identification, collection, acquisition and preservation of digital evidence - ISO/IEC
  9. RFC 3339: Date and Time on the Internet: Timestamps - Internet Engineering Task Force (IETF)
  10. RFC 3161: Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) - Internet Engineering Task Force (IETF)
  11. Content Credentials: C2PA Technical Specification, Version 2.2 - Coalition for Content Provenance and Authenticity (C2PA)
  12. in-toto Attestation Framework — Statement layer, v1 - in-toto project (Cloud Native Computing Foundation)
  13. CiTO, the Citation Typing Ontology - SPAR Ontologies (Semantic Publishing and Referencing)
  14. GRADE (Grading of Recommendations Assessment, Development and Evaluation) Working Group - GRADE Working Group
  15. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) - European Parliament and Council of the European Union
  16. Regulation (EU) 2016/679 (General Data Protection Regulation) - European Parliament and Council of the European Union
  17. Federal Rules of Evidence, Rule 901 — Authenticating or Identifying Evidence - Legal Information Institute, Cornell Law School (publishing the U.S. Federal Rules of Evidence)
  18. NIST Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations - National Institute of Standards and Technology (NIST), U.S. Department of Commerce
  19. EU Artificial Intelligence Act — Article 19: Automatically generated logs - Future of Life Institute (AI Act Explorer)
  20. FHIR Resource Evidence - HL7 International
  21. Federal Rules of Evidence Rule 401. Test for Relevant Evidence - Supreme Court of the United States
  22. Content Credentials: C2PA Technical Specification - Coalition for Content Provenance and Authenticity
  23. NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response - National Institute of Standards and Technology

Open questions

  • Metrological representation of uncertainty: no GUM/VIM-class primary was consulted by either provider, so the internal representation of measurement error, intervals and coverage factors remains unsupported and must be settled against the measurement sibling model.
  • Cross-scheme certainty comparability: no cited source licenses mapping a GRADE level onto assurance-case confidence or onto a legal standard of proof. Levels stay scheme-local until a mapping authority with primary backing is identified.
  • Argument interchange formats (Toulmin, IBIS, QOC, AIF): neither provider fetched a primary, so the warrant layer is expressed generically and any canonical argument-graph serialisation is unresearched.
  • Wider legal-evidence surface: FRE 403, 702, 801-807 and 902, plus at least one civil-law evidence code, to qualify authentication, sufficiency and expert-evidence framing outside US federal practice.
  • Forensic-handling interoperability: ISO/IEC 27042, ISO/IEC 27043, ISO/IEC 17025, NIST SP 800-86, and the CASE/UCO and EDRM vocabularies, to test whether the custody and handling findings exchange cleanly with investigation tooling.
  • OMG SACM 2.3 normative element names and ISO/IEC/IEEE 15026-2 clause structure, needed before any structural claim is attributed to those specifications by name.
  • Consent and testimonial-capture chains for human-subject and oral evidence, currently reachable only through personal-data flags rather than a consent model.
  • Clause-level requirements of ISO/IEC/IEEE 15026-2:2022, ISO/IEC/IEEE 42010:2022 and ISO/IEC 27037:2012 were taken from official catalogue abstracts and standards-body summaries, not from the paywalled normative texts; specific clause numbers and mandatory wording must be confirmed before any conformance claim.
  • The OMG SACM 2.3 metamodel element names (Claim, ArgumentReasoning, ArtifactReference, AssertedInference, AssertedEvidence, AssertedContext and the Artifact metamodel classes) were not verified against the normative PDF; only the specification landing page and its definition of an assurance case were retrieved. Structure derived from SACM is expressed generically rather than by SACM class name.
  • Dialogue and argumentation protocols — burden shifting within a dialogue, commitment stores, turn taking — are not modelled; only the resulting argument structure is.
  • Evidence synthesis statistics (meta-analysis, pooling, effect-size estimation, heterogeneity measures) are excluded; the model records a certainty judgement, not the computation behind it.
  • Trust and reputation scoring of sources and agents is excluded; independence and interest declarations are recorded, but no score is computed.
  • Machine-learning explanation artefacts (feature attributions, counterfactuals, saliency) are not modelled as a distinct evidence form, although they would be registered as computational evidence.
  • Consent chains for testimonial and human-subject evidence are covered only through the personal-data flags and GDPR-derived constraints, not through a consent model.
  • Cost, effort and timeliness of obtaining further evidence — inputs to a real sufficiency decision — are not modelled.
  • Cryptographic key management, certificate issuance and trust-list curation are referenced but deliberately not specified.
  • No primary Toulmin, IBIS, QOC or Argument Interchange Format schema was fetched; argument-graph interchange is therefore a gap rather than a canonical layer.
  • ISO/IEC 27042 analysis, ISO/IEC 27043 process architecture and ISO/IEC 17025 laboratory competence were not incorporated as fetched primaries.
  • Federal Rules 403, 702, 801-807 and 902, and non-US evidence codes, are not modelled; prejudice, expert qualification, hearsay and self-authentication remain legal-sibling concerns.
  • EDRM e-discovery, CASE/UCO cyber-investigation ontology, STIX opinion/sighting and OMG DMN knowledge sources were not fetched as primaries.
  • Bayesian likelihood ratios, evidence of absence, and statistical sampling designs as first-class objects are omitted.
  • Oral testimony capture, real-time live-video evidence beyond C2PA live-video clauses, and AI-generated-content admissibility tests are emerging and under-specified here.
  • Privilege, work-product and classified-information doctrines lack a single global primary and are represented only as access exceptions.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-xct-028-evidence-rationale/spec.yaml, ver-cy/world-models/card-supplements/wm-xct-028-evidence-rationale.json