# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-23T12:53:00Z", "synthesisSha256": "0ebeb503af7d3f82fb200df593a274a5f3e4d3cc4454945b4a78be805dab4dd3", "providerMode": "dual-provider", "providers": [ "Claude", "Grok" ], "waivedProviders": [] }, "metaModel": { "id": "WM-XCT-028", "registryId": "vr.wm-xct-028", "name": "Evidence / Rationale", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.EVD" ], "tags": [ "evidence", "rationale", "xct.evd" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-028-evidence-rationale/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-028", "model": { "registry_id": "vr.wm-xct-028", "model_id": "WM-XCT-028", "name": "Evidence / Rationale", "entry_kind": "mixin", "purpose": "Provide a format-neutral, attachable structure that records traceable support for a claim or decision: what supports it, by what reasoning, on whose authority, with what integrity, how strong the support is, and how it can be re-checked, contested, retained or withdrawn.", "scope_statement": "This mixin is attached to a host record that already asserts something (a claim, decision, classification, requirement or measurement held in a sibling model). It supplies the support apparatus around that assertion: typed support relations to evidence items, the inference/warrant and assumptions that license the conclusion, counter-evidence and its resolution, evidence identity, anchoring into sources, acquisition and custody, provenance and time, cryptographic integrity and verification, quality appraisal and sufficiency, and the governance surface (authority, rights, access, retention, lifecycle, interoperability). It never carries the propositional content of the claim itself and never duplicates the bibliographic record of a source, the agent registry or the audit-log infrastructure.", "in_scope": [ "Typed support and counter-support relations between evidence items and a supported claim or decision", "Reasoning apparatus: warrant/inference, argumentation scheme, assumptions, scope conditions, alternatives considered and rejected", "Evidence item identity, form/modality, anchoring into a source location and state, and excerpt fidelity", "Acquisition method, instrument, and chain of custody including auditability, repeatability and reproducibility", "Provenance, attribution, independence/conflict of interest, and separated event/observation/record/assertion times", "Cryptographic content binding, signatures/attestations, trusted timestamps and verification events", "Certainty grading against a declared scheme, bias and limitations, sufficiency thresholds and corroboration", "Governance of the support record: ownership, approving authority, rights, access classification, redaction, retention, legal hold, lifecycle states and retraction", "Declared alignments and exchange packaging to external provenance, assurance-case, credential and attestation models" ], "out_of_scope": [ "The propositional content, truth value or semantics of the supported claim itself (belongs to the parent knowledge/claim model)", "The full bibliographic or catalogue record of a source document, dataset or publication (sibling source/citation model)", "The agent, organisation and role registry that identifiers here resolve into (sibling agent/party model)", "General-purpose provenance/lineage of arbitrary artefacts not offered in support of a claim (sibling provenance model)", "Audit-log and telemetry infrastructure design, log shipping and SIEM operation", "Legal case management, court procedure, disclosure workflow and forensic investigation case files", "Evidence synthesis statistics: meta-analysis, pooling, effect-size estimation and study design", "Dialogue and argumentation protocols (turn taking, burden shifting in dialogue games)", "Trust or reputation scoring of agents and sources as a standalone scored model", "Cryptographic key management, PKI operation and trust-list curation" ], "boundary_notes": [ { "neighbor": "WM-KNW-008 (parent knowledge/claim model)", "distinction": "The parent holds the assertion; this mixin holds why the assertion is held. An assurance case separates the top-level claim from the structured argumentation and the evidence and assumptions underlying it, so the claim must remain addressable independently of its support.", "source_refs": [ "SRC-006", "SRC-005" ] }, { "neighbor": "Source / citation / bibliographic model", "distinction": "This model references a source by identifier and adds a locator, selector and captured state; it does not carry title, authorship, edition or catalogue metadata. Web Annotation separates the Target resource from the Specific Resource plus Selector used to address part of it.", "source_refs": [ "SRC-004", "SRC-013" ] }, { "neighbor": "Provenance / lineage model", "distinction": "PROV describes generation, derivation and attribution for any entity. This mixin uses that vocabulary only for entities offered in support of a claim, and additionally records the assertion of support itself, which PROV does not model.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Attestation / verifiable credential model", "distinction": "A verifiable credential is itself a signed claim container whose optional evidence property describes how the issuer verified claims before issuance. A credential may be an evidence item here, but credential issuance, holding and presentation are governed elsewhere.", "source_refs": [ "SRC-003" ] }, { "neighbor": "Audit trail / event log model", "distinction": "Automatically generated logs are a source of evidence items and are separately mandated with their own retention floors; the logging subsystem, its content requirements and its retention schedule belong to the log model, not to this mixin.", "source_refs": [ "SRC-015", "SRC-018" ] }, { "neighbor": "Digital forensic case model", "distinction": "ISO/IEC 27037 governs identification, collection, acquisition and preservation of potential digital evidence by designated roles. This mixin records the custody and integrity facts needed to reason about admissibility, not the forensic process, tooling competence regime or investigation case file.", "source_refs": [ "SRC-008" ] }, { "neighbor": "Decision record model", "distinction": "The decision, its options and its outcome live in the decision model. This mixin supplies the rationale, alternatives-rejected reasons and supporting evidence attached to that decision, in the same way an architecture description carries rationale separately from the architecture it describes.", "source_refs": [ "SRC-007" ] }, { "neighbor": "Measurement / observation model", "distinction": "An observation's method, unit, uncertainty and sensor semantics belong to the measurement model. Here an observation is treated as an evidence item with an acquisition record and an appraisal, not re-specified.", "source_refs": [ "SRC-014", "SRC-008" ] } ] }, "sources": [ { "id": "SRC-001", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:05:00Z", "relevance": "Normative OWL2 vocabulary for Entity, Activity, Agent and the properties wasDerivedFrom, wasGeneratedBy, wasAttributedTo, used, hadPrimarySource, wasQuotedFrom, wasRevisionOf and prov:Bundle; grounds derivation, primary-source and quotation semantics for evidence items." }, { "id": "SRC-002", "title": "PROV-DM: The PROV Data Model", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-dm/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:06:00Z", "relevance": "Defines attribution, association, delegation, invalidation, specialization/alternate, generation/usage/start/end times, and Bundle as an entity enabling provenance-of-provenance so that the support record itself can be attributed and dated." }, { "id": "SRC-003", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:07:00Z", "relevance": "Defines the optional evidence property (how an issuer verified claims before issuance), proof/securing mechanisms, issuer, validFrom/validUntil and credentialStatus, and states that verification of a credential does not imply evaluation of the truth of its claims — a key separation between integrity and validity." }, { "id": "SRC-004", "title": "Web Annotation Data Model", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/annotation-model/", "version_or_date": "W3C Recommendation, 23 February 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:08:00Z", "relevance": "Body/Target model, motivation vocabulary, Specific Resource with FragmentSelector, TextQuoteSelector, TextPositionSelector, RangeSelector, CssSelector, XPathSelector, plus TimeState and creator/created/generator; grounds precise anchoring of an excerpt into a source and pinning of the source state." }, { "id": "SRC-005", "title": "Structured Assurance Case Metamodel (SACM), Version 2.3", "organization": "Object Management Group (OMG)", "url": "https://www.omg.org/spec/SACM/", "version_or_date": "Version 2.3, formal specification, October 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:09:00Z", "relevance": "Defines an assurance case as a set of auditable claims, arguments and evidence created to support a claim that a system or service satisfies particular requirements; grounds the separation of claim, argumentation and evidence artefacts and the auditability requirement." }, { "id": "SRC-006", "title": "ISO/IEC/IEEE 15026-2:2022 Systems and software engineering — Systems and software assurance — Part 2: Assurance case", "organization": "ISO/IEC/IEEE", "url": "https://www.iso.org/standard/80625.html", "version_or_date": "Second edition, 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:10:00Z", "relevance": "Specifies minimum structure and content of an assurance case: a top-level claim, systematic argumentation, and the evidence and explicit assumptions underlying it; defines inference as a reasoning step deriving a claim from subclaims under a specified context, with confidence depending on the validity of the inference expressed as a justification and on confidence in the premises. Explicitly does not mandate a concrete or graphical representation." }, { "id": "SRC-007", "title": "ISO/IEC/IEEE 42010:2022 Software, systems and enterprise — Architecture description", "organization": "ISO/IEC/IEEE", "url": "https://www.iso.org/standard/74393.html", "version_or_date": "Second edition, 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:11:00Z", "relevance": "Specifies required content for architecture descriptions and distinguishes the entity of interest from the description expressing it; supplies the precedent that rationale, concerns and correspondences are recorded as first-class description content separate from the thing described." }, { "id": "SRC-008", "title": "ISO/IEC 27037:2012 Information technology — Security techniques — Guidelines for identification, collection, acquisition and preservation of digital evidence", "organization": "ISO/IEC", "url": "https://www.iso.org/standard/44381.html", "version_or_date": "First edition, 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:12:00Z", "relevance": "Defines the four handling processes (identification, collection, acquisition, preservation) and the principles of auditability, repeatability and reproducibility, and requires an unbroken chain of custody maintained across the lifetime of the evidence and beyond, covering physical, logical (hashes, seals, qualified timestamps) and documentary custody." }, { "id": "SRC-009", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://datatracker.ietf.org/doc/html/rfc3339", "version_or_date": "Proposed Standard, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:13:00Z", "relevance": "Mandatory timestamp profile: four-digit year, seconds, and a mandatory numeric offset or Z; distinguishes -00:00 (UTC known, local offset unknown) from Z/+00:00. Governs every time value in this model." }, { "id": "SRC-010", "title": "RFC 3161: Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://datatracker.ietf.org/doc/html/rfc3161", "version_or_date": "Proposed Standard, August 2001", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:14:00Z", "relevance": "A TSA acting as trusted third party establishes evidence that a datum existed before a particular time; defines messageImprint, genTime, accuracy, nonce and serialNumber and requires a trustworthy time source and audit trails allowing genuine tokens to be distinguished from backdated ones." }, { "id": "SRC-011", "title": "Content Credentials: C2PA Technical Specification, Version 2.2", "organization": "Coalition for Content Provenance and Authenticity (C2PA)", "url": "https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html", "version_or_date": "Version 2.2, May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-23T09:15:00Z", "relevance": "Manifest = assertions + a signed claim + claim signature; requires at least one hard binding so a validator can confirm the manifest belongs with the asset and the asset is unmodified; defines hashed URIs (location plus hash), created vs gathered assertions, ingredient manifests for derived works, and trusted time-stamps enabling indefinite validation after credential expiry." }, { "id": "SRC-012", "title": "in-toto Attestation Framework — Statement layer, v1", "organization": "in-toto project (Cloud Native Computing Foundation)", "url": "https://github.com/in-toto/attestation/blob/main/spec/v1/statement.md", "version_or_date": "Statement layer specification v1 (https://in-toto.io/Statement/v1)", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-23T09:16:00Z", "relevance": "Layered Envelope/Statement/Predicate model; subject is a set of ResourceDescriptors matched purely by digest regardless of content type and assumed immutable, with predicateType as a TypeURI. Grounds digest-based evidence identity, typed predicates and separation of the signed envelope from the asserted content." }, { "id": "SRC-013", "title": "CiTO, the Citation Typing Ontology", "organization": "SPAR Ontologies (Semantic Publishing and Referencing)", "url": "https://sparontologies.github.io/cito/current/cito.html", "version_or_date": "Version 2.8.2, released 2017-10-30 (document last modified 2026-06-22)", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-23T09:17:00Z", "relevance": "Roughly 41 sub-properties of cito:cites providing a governed vocabulary of support relations — citesAsEvidence, citesAsAuthority, citesAsDataSource, supports, confirms, agreesWith, disputes, disagreesWith, refutes, corrects, extends, qualifies, usesMethodIn — and the factual vs rhetorical (positive/neutral/negative) classification." }, { "id": "SRC-014", "title": "GRADE (Grading of Recommendations Assessment, Development and Evaluation) Working Group", "organization": "GRADE Working Group", "url": "https://www.gradeworkinggroup.org/", "version_or_date": "Working group established 2000; methodology series in J Clin Epidemiol from 2011, criteria update 2023", "source_type": "scientific", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-23T09:18:00Z", "relevance": "Four-level certainty of evidence (high/moderate/low/very low) with explicit rating-down domains (risk of bias, imprecision, inconsistency, indirectness, publication bias) and rating-up factors (large effect, dose-response, plausible opposing bias), and separation of certainty from strength and direction of recommendation." }, { "id": "SRC-015", "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689", "version_or_date": "Regulation (EU) 2024/1689 of 13 June 2024; OJ publication 12 July 2024", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:19:00Z", "relevance": "Article 11 requires technical documentation; Article 12(1) requires high-risk AI systems to technically allow automatic recording of events (logs) over the system lifetime, with Article 12(3) prescribing minimum log content for biometric identification (use periods with timestamps, reference database, matching input data, identity of verifying persons). Grounds mandated machine-generated evidence and its documentation." }, { "id": "SRC-016", "title": "Regulation (EU) 2016/679 (General Data Protection Regulation)", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng", "version_or_date": "Regulation (EU) 2016/679 of 27 April 2016", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:20:00Z", "relevance": "Article 5(1)(d) accuracy, 5(1)(e) storage limitation (identifiable form no longer than necessary), 5(2) accountability (controller must be able to demonstrate compliance), Article 30 records of processing, and Article 17 erasure with the 17(3)(e) exemption for establishment, exercise or defence of legal claims — the governing tension between immutable evidence and deletion rights." }, { "id": "SRC-017", "title": "Federal Rules of Evidence, Rule 901 — Authenticating or Identifying Evidence", "organization": "Legal Information Institute, Cornell Law School (publishing the U.S. Federal Rules of Evidence)", "url": "https://www.law.cornell.edu/rules/fre/rule_901", "version_or_date": "Restyled rules effective 1 December 2011, as amended", "source_type": "legislation", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-23T09:21:00Z", "relevance": "Requires the proponent to produce evidence sufficient to support a finding that the item is what the proponent claims it is, and enumerates authentication methods including distinctive characteristics, public records, ancient documents/data, and evidence describing a process or system and showing it produces an accurate result. Grounds authentication, originality and sufficiency-of-foundation questions." }, { "id": "SRC-018", "title": "NIST Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST), U.S. Department of Commerce", "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final", "version_or_date": "Revision 5, September 2020, with updates (release 5.2.0, 27 August 2025)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T09:22:00Z", "relevance": "Control catalogue including the Audit and Accountability (AU) family, which establishes organisational requirements for event logging, audit record content, protection of audit information, non-repudiation, time stamps and audit record retention; grounds the governance controls around evidence records treated as accountability artefacts." }, { "id": "SRC-019", "title": "EU Artificial Intelligence Act — Article 19: Automatically generated logs", "organization": "Future of Life Institute (AI Act Explorer)", "url": "https://artificialintelligenceact.eu/article/19/", "version_or_date": "Article text of Regulation (EU) 2024/1689 as published; accessed 2026", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-08-23T09:23:00Z", "relevance": "Used only to obtain the Article 19 retention floor: providers must keep automatically generated logs under their control for a period appropriate to the intended purpose, of at least six months, unless otherwise provided by Union or national law, in particular data-protection law. Retention floor must be re-verified against the OJ text before operational use." }, { "id": "SRC-020", "title": "FHIR Resource Evidence", "organization": "HL7 International", "url": "https://www.hl7.org/fhir/evidence.html", "version_or_date": "FHIR v5.0.0 Release 5", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T16:45:00Z", "relevance": "Machine-interpretable evidence record with identifiers, status lifecycle, authors, reviewers, endorsers, description, assertion, notes, related artifacts, statistics, study and synthesis types, and a certainty element for overall and subcomponent quality." }, { "id": "SRC-021", "title": "Federal Rules of Evidence Rule 401. Test for Relevant Evidence", "organization": "Supreme Court of the United States", "url": "https://www.law.cornell.edu/rules/fre/rule_401", "version_or_date": "as restyled effective 1 December 2011", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T16:45:00Z", "relevance": "Defines relevance as a relation: evidence is relevant only if it tends to make a fact of consequence more or less probable. Relevancy is not an inherent property of an item." }, { "id": "SRC-022", "title": "Content Credentials: C2PA Technical Specification", "organization": "Coalition for Content Provenance and Authenticity", "url": "https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html", "version_or_date": "2.4", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T16:45:00Z", "relevance": "Tamper-evident manifests binding hashed assertions, claims, signatures and timestamps to assets, with validation states, redaction, unique identifiers and an explicit refusal to judge provenance as good or bad." }, { "id": "SRC-023", "title": "NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/86/final", "version_or_date": "August 2006 (Final)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-23T16:45:00Z", "relevance": "Forensic process guidance for collecting, examining and analyzing digital sources while preserving integrity for later reliance, from an IT and incident-response view rather than a law-enforcement view." } ], "structure": { "bundles": [ { "id": "claim-support-structure", "name": "Claim–Support Structure", "description": "The argument skeleton: how a support record binds to exactly one supported claim or decision, what kind of support relation is asserted, what reasoning licenses the conclusion, and how contrary evidence is registered and resolved.", "rationale": "An assurance case is a top-level claim plus systematic argumentation plus the evidence and explicit assumptions underlying it, so support cannot be modelled as a bare list of attachments; the inference step and its justification are separately addressable and separately confidence-bearing.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007", "SRC-013" ], "layers": [ { "id": "support-binding", "name": "Support Binding and Relation Typing", "description": "How the mixin attaches to its host assertion and what typed relation each evidence item bears to it.", "source_refs": [ "SRC-005", "SRC-006", "SRC-003", "SRC-013" ], "findings": [ { "id": "host-binding-and-support-scope", "name": "Host binding and scope of support", "description": "Identifies the single claim, decision or assertion the record supports, the part of it in scope, and the effect of host revision. Evidence attaches to a specific claim, not to a document.", "source_refs": [ "SRC-005", "SRC-006", "SRC-003" ], "questions": [ { "id": "q-host-id", "text": "Which single claim, decision or assertion does this record support, and by which stable identifier in which master system?", "kind": "identity", "answer_data": [ "supported-subject-ref", "supported-subject-system", "support-record-id" ] }, { "id": "q-host-partial", "text": "Does the support apply to the whole host assertion or only to a named component, qualifier or numeric bound within it?", "kind": "composition", "answer_data": [ "supported-aspect-path", "scope-note" ] }, { "id": "q-host-reuse", "text": "Can one evidence item support several claims by reference without being copied, and how is that many-to-many reuse represented?", "kind": "relationship", "answer_data": [ "reuse-mode", "support-record-id", "supported-subject-ref" ] }, { "id": "q-host-revision", "text": "When the host assertion is revised or superseded, does the support record carry over, lapse, or require re-affirmation?", "kind": "lifecycle", "answer_data": [ "carryover-policy-code", "reaffirmed-at", "supported-subject-version" ] } ], "data_elements": [ { "id": "support-record-id", "name": "Support record identifier", "description": "Stable identifier of this evidence/rationale record, distinct from the identifier of the host assertion and from any evidence item.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-012" ] }, { "id": "supported-subject-ref", "name": "Supported subject reference", "description": "Reference to the host claim, decision, classification or measurement whose support is being recorded.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-005" ] }, { "id": "supported-aspect-path", "name": "Supported aspect path", "description": "Pointer to the part of the host assertion actually supported when support is partial.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "reuse-mode", "name": "Reuse mode", "description": "Whether the evidence item is referenced in place or embedded as a copy in this support record.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "carryover-policy-code", "name": "Host-revision carryover policy", "description": "Declared behaviour of the support record when the host assertion changes version.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Binding is pure referential structure held on the host record; it produces no separable document, and materialising it as a file would create a second identity for a relationship that must remain single-valued." }, { "id": "support-relation-typing", "name": "Typed support relation", "description": "The declared relation each evidence item bears to the supported subject — supports, corroborates, is authority for, qualifies, disputes, refutes — drawn from a named vocabulary rather than free text.", "source_refs": [ "SRC-013", "SRC-005", "SRC-001" ], "questions": [ { "id": "q-rel-vocab", "text": "Which governed vocabulary and version supplies the relation term, and what is its IRI?", "kind": "interoperability", "answer_data": [ "relation-vocabulary-iri", "relation-type-code" ] }, { "id": "q-rel-polarity", "text": "Is the relation supportive, neutral/informative or contrary, and is that polarity asserted or derived from the vocabulary?", "kind": "classification", "answer_data": [ "polarity-code", "polarity-source" ] }, { "id": "q-rel-asserter", "text": "Who asserted that this item stands in this relation to the claim, as distinct from who created the item?", "kind": "provenance", "answer_data": [ "relation-asserted-by-ref", "relation-asserted-at" ] }, { "id": "q-rel-weight", "text": "Does the relation carry a weight or contribution, and on what scale is that weight expressed?", "kind": "measurement", "answer_data": [ "relation-weight", "relation-weight-scale" ] } ], "data_elements": [ { "id": "relation-type-code", "name": "Relation type code", "description": "Term identifying the support relation, e.g. an equivalent of citesAsEvidence, citesAsAuthority, supports, qualifies, disputes or refutes.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "relation-vocabulary-iri", "name": "Relation vocabulary IRI", "description": "IRI and version of the vocabulary from which the relation term is drawn.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "polarity-code", "name": "Relation polarity", "description": "Supportive, informative/neutral or contrary classification of the relation.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "relation-asserted-by-ref", "name": "Relation asserter", "description": "Agent responsible for asserting the support relation itself.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-001" ] }, { "id": "relation-weight", "name": "Relation weight", "description": "Optional contribution weight of this item to the overall support, meaningless without its declared scale.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "The typed relation is an edge attribute in a graph; it has no independent media form. Its vocabulary is an external artefact owned by the vocabulary publisher, referenced by IRI rather than reproduced." }, { "id": "relevance-to-consequential-fact", "name": "Relevance to a fact of consequence", "description": "Records the relevancy analysis without treating relevance as an inherent property of the item and without confusing it with sufficiency of the whole body of evidence.", "source_refs": [ "SRC-021" ], "questions": [ { "id": "relevance-to-consequential-fact-q01", "text": "Does this item have any tendency to make the stated fact more or less probable than it would be without the item?", "kind": "evidence", "answer_data": [ "has_probative_tendency", "probability_direction", "basis_of_tendency" ] }, { "id": "relevance-to-consequential-fact-q02", "text": "Is the fact to which the item is directed of consequence in determining the host action or decision?", "kind": "evidence", "answer_data": [ "is_of_consequence", "host_action", "consequence_rationale" ] }, { "id": "relevance-to-consequential-fact-q03", "text": "Does probative value depend on a missing condition of fact, such as whether a statement was heard, that must be recorded as conditional relevance?", "kind": "constraint", "answer_data": [ "is_conditional", "condition_of_fact", "condition_status" ] } ], "data_elements": [ { "id": "relevance-to-consequential-fact-data01", "name": "Has probative tendency", "description": "Whether the item tends to change the probability of the fact.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-021" ] }, { "id": "relevance-to-consequential-fact-data02", "name": "Probability direction", "description": "More probable or less probable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-021" ] }, { "id": "relevance-to-consequential-fact-data03", "name": "Is of consequence", "description": "Whether the fact is of consequence in determining the action.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-021" ] }, { "id": "relevance-to-consequential-fact-data04", "name": "Conditional relevance", "description": "Optional condition of fact on which relevancy depends.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021" ] } ], "artifacts": [], "inline_only_rationale": "Relevance is a recorded relation and legal-reasoning analysis, not an exhibit." } ] }, { "id": "reasoning-warrant-and-challenge", "name": "Reasoning, Assumptions and Challenge", "description": "The inference that licenses moving from evidence to claim, the assumptions and context conditions it depends on, the alternatives rejected, and the counter-evidence and defeaters raised against it.", "source_refs": [ "SRC-006", "SRC-005", "SRC-007", "SRC-014" ], "findings": [ { "id": "inference-warrant-and-scheme", "name": "Inference, warrant and argumentation scheme", "description": "The reasoning step deriving the claim from its premises under a specified context, expressed as a justification, together with the scheme or rule applied and its defeasibility.", "source_refs": [ "SRC-006", "SRC-005" ], "questions": [ { "id": "q-warrant-text", "text": "What warrant licenses the step from these premises to this claim, stated so a reviewer can attack the step rather than the premises?", "kind": "definition", "answer_data": [ "rationale-text", "justification-ref" ] }, { "id": "q-warrant-scheme", "text": "Which argumentation scheme or inference rule is applied, and from which catalogue and version is it drawn?", "kind": "classification", "answer_data": [ "scheme-ref", "scheme-catalogue-id", "inference-mode-code" ] }, { "id": "q-warrant-defeasible", "text": "Is the inference deductive, inductive, abductive or statistical, and what conditions would defeat it without any premise being false?", "kind": "constraint", "answer_data": [ "inference-mode-code", "defeat-condition" ] }, { "id": "q-warrant-checkable", "text": "Is the reasoning machine-checkable, reviewer-checkable, or asserted only, and what evidence supports that classification?", "kind": "validation", "answer_data": [ "checkability-code", "check-method-ref" ] }, { "id": "q-warrant-noevidence", "text": "If no evidence item is attached, on what basis other than evidence does the conclusion rest, and is that flagged to consumers?", "kind": "exception", "answer_data": [ "assumption-only-flag", "assumption-list" ] } ], "data_elements": [ { "id": "rationale-text", "name": "Rationale statement", "description": "Human-readable justification of the inference step in the declared context.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-007" ] }, { "id": "inference-mode-code", "name": "Inference mode", "description": "Deductive, inductive, abductive, statistical, analogical or authority-based character of the step.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "scheme-ref", "name": "Argumentation scheme reference", "description": "Reference to the scheme or inference rule instantiated, with catalogue and version.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "defeat-condition", "name": "Defeat condition", "description": "Stated condition under which the inference would no longer license the claim.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "assumption-only-flag", "name": "Assumption-only support flag", "description": "True when the claim rests on assumptions and reasoning with no attached evidence item.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "argument-structure-record", "name": "Argument structure record", "description": "Serialised graph of claims, inference steps, justifications and evidence references expressing the structured argumentation for one supported claim, independent of any particular graphical notation.", "media_or_form": [ "structured graph document", "tabular argument table", "narrative rationale document", "graphical assurance-case diagram export" ], "serial": false, "identity_strategy": "Identified by the support-record identifier plus an argument-version label; where an external assurance-case tool is the master system, its identifier takes precedence, otherwise a Dimension-assigned ULID.", "source_refs": [ "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "assumptions-alternatives-and-context", "name": "Assumptions, context conditions and rejected alternatives", "description": "The explicit assumptions the argument depends on, the scope conditions bounding its validity, and the options considered and rejected with reasons — the part of rationale that explains why not something else.", "source_refs": [ "SRC-006", "SRC-007", "SRC-005" ], "questions": [ { "id": "q-assume-list", "text": "Which assumptions must hold for this support to stand, and is each validated, accepted-without-validation or known-unverifiable?", "kind": "constraint", "answer_data": [ "assumption-list", "assumption-status" ] }, { "id": "q-assume-context", "text": "Under what context, population, environment or time window does the support hold, and where does it explicitly not apply?", "kind": "constraint", "answer_data": [ "context-condition", "exclusion-condition" ] }, { "id": "q-alt-options", "text": "Which alternative claims, options or interpretations were considered and rejected, and on what stated ground was each rejected?", "kind": "decision", "answer_data": [ "alternative-option", "rejection-reason" ] }, { "id": "q-assume-invalidate", "text": "What observable change would invalidate an assumption, and who is accountable for monitoring it?", "kind": "process", "answer_data": [ "assumption-monitor-ref", "assumption-review-due" ] } ], "data_elements": [ { "id": "assumption-list", "name": "Explicit assumption", "description": "A stated assumption underlying the argumentation, recorded explicitly rather than left implicit.", "value_kind": "text", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "assumption-status", "name": "Assumption status", "description": "Validated, accepted, contested or unverifiable status of an assumption.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "context-condition", "name": "Context condition", "description": "Specified context within which the inference is claimed to hold.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "alternative-option", "name": "Alternative considered", "description": "An option or interpretation that was evaluated and not adopted.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "rejection-reason", "name": "Rejection reason", "description": "Stated reason an alternative was not adopted, paired with the alternative.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "assumption-review-due", "name": "Assumption review due", "description": "Date by which an assumption must be re-examined.", "value_kind": "date", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015" ] } ], "artifacts": [ { "id": "decision-rationale-record", "name": "Decision rationale record", "description": "Durable record attached to a decision capturing context, options considered, the option chosen, rejection reasons and the assumptions the decision depends on.", "media_or_form": [ "structured record", "narrative document", "register entry" ], "serial": true, "identity_strategy": "Sequential rationale record number within the owning decision register, qualified by the register identifier; the decision model's identifier is authoritative where one exists.", "source_refs": [ "SRC-007", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "counter-evidence-defeaters-and-resolution", "name": "Counter-evidence, defeaters and their resolution", "description": "Registration of evidence and arguments that rebut the claim, undercut the inference or undermine a premise, and the record of how each was adjudicated or left open.", "source_refs": [ "SRC-006", "SRC-005", "SRC-014" ], "questions": [ { "id": "q-counter-known", "text": "What contrary or non-confirming evidence is known to exist, including evidence sought but not found?", "kind": "evidence", "answer_data": [ "counter-evidence-ref", "absent-evidence-note" ] }, { "id": "q-counter-type", "text": "Does each challenge rebut the claim, undercut the inference, or undermine a premise?", "kind": "classification", "answer_data": [ "defeater-type", "challenged-element-ref" ] }, { "id": "q-counter-adjudicate", "text": "Who adjudicated the conflict, under what authority and by what stated rule of preference?", "kind": "authority", "answer_data": [ "resolution-authority-ref", "resolution-rule", "resolution-decision" ] }, { "id": "q-counter-residual", "text": "What conflict remains unresolved, and is that residual disclosed to consumers of the claim?", "kind": "quality", "answer_data": [ "residual-conflict-flag", "residual-conflict-note" ] }, { "id": "q-counter-selection", "text": "How is selective inclusion of only confirming evidence detected and prevented for this record?", "kind": "validation", "answer_data": [ "selection-control-method", "publication-bias-judgement" ] } ], "data_elements": [ { "id": "counter-evidence-ref", "name": "Counter-evidence reference", "description": "Reference to an evidence item bearing a contrary relation to the supported subject.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-006" ] }, { "id": "defeater-type", "name": "Defeater type", "description": "Rebutting, undercutting or undermining character of the challenge.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "resolution-decision", "name": "Resolution decision", "description": "Outcome of adjudicating the conflict, including 'unresolved'.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "resolution-authority-ref", "name": "Resolving authority", "description": "Agent or body that adjudicated the conflict.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "residual-conflict-flag", "name": "Residual conflict flag", "description": "True when a material conflict remains open after adjudication.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "publication-bias-judgement", "name": "Selective-reporting judgement", "description": "Assessment of whether contrary evidence is likely to be missing from the record.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [ { "id": "conflict-adjudication-record", "name": "Conflict adjudication record", "description": "Record of a challenge to the claim or its inference, the arguments on each side, the deciding authority and the outcome, retained whether or not the challenge succeeded.", "media_or_form": [ "structured record", "minuted decision", "review report" ], "serial": true, "identity_strategy": "Sequential challenge number within the support record, prefixed by the support-record identifier; adjudicating-body case number takes precedence when one exists.", "source_refs": [ "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "evidence-item-and-anchoring", "name": "Evidence Item, Anchoring and Custody", "description": "The evidence item as an addressable thing: its identity and form, where in a source it is anchored and how faithfully it was excerpted, how it was acquired, and the custody record that makes it auditable.", "rationale": "Digest-based subject matching treats artefacts as immutable and identifies them by content, while annotation selectors address parts of mutable resources; evidence handling separately requires an unbroken chain of custody with auditability, repeatability and reproducibility. All three are needed and none subsumes the others.", "source_refs": [ "SRC-012", "SRC-004", "SRC-008", "SRC-011", "SRC-001" ], "layers": [ { "id": "evidence-identity-and-typing", "name": "Evidence Identity and Form", "description": "How an evidence item is identified and classified independently of where it is stored.", "source_refs": [ "SRC-012", "SRC-011", "SRC-001", "SRC-017" ], "findings": [ { "id": "evidence-item-identity", "name": "Evidence item identity", "description": "Assignment and precedence of identifiers for an evidence item, separation of the item from the record describing it, and content-digest identity for immutable items.", "source_refs": [ "SRC-012", "SRC-011", "SRC-001" ], "questions": [ { "id": "q-evid-idsource", "text": "Which identifier is authoritative for this item: a master-system identifier, a governed global identifier or IRI, or a Dimension-assigned UUID/ULID?", "kind": "identity", "answer_data": [ "evidence-id", "id-scheme", "master-system-id" ] }, { "id": "q-evid-record-vs-thing", "text": "Which identifier denotes the physical or digital item, and which denotes the record describing it?", "kind": "definition", "answer_data": [ "evidence-id", "evidence-record-id" ] }, { "id": "q-evid-digest-identity", "text": "Is the item immutable and therefore identifiable by content digest, or mutable and identifiable only by reference plus captured state?", "kind": "identity", "answer_data": [ "immutability-flag", "content-digest", "captured-state-ref" ] }, { "id": "q-evid-version", "text": "When the item is revised, is a new identity minted or a version label appended, and how is the prior version reachable?", "kind": "lifecycle", "answer_data": [ "version-label", "prior-version-ref" ] }, { "id": "q-evid-dupe", "text": "How are duplicate submissions of the same underlying item detected and merged without losing distinct custody histories?", "kind": "validation", "answer_data": [ "content-digest", "duplicate-of-ref", "merge-decision" ] } ], "data_elements": [ { "id": "evidence-id", "name": "Evidence item identifier", "description": "Authoritative identifier of the item, assigned by precedence: master-system identifier, then governed global identifier/IRI, then Dimension-assigned UUID or ULID.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-001" ] }, { "id": "id-scheme", "name": "Identifier scheme", "description": "Scheme and issuing authority of the identifier, required to interpret it.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "evidence-record-id", "name": "Evidence record identifier", "description": "Identifier of the descriptive record, always distinct from the item identifier.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "immutability-flag", "name": "Immutability flag", "description": "Whether the item is treated as immutable, licensing digest-based identity.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "version-label", "name": "Version label", "description": "Version designation where the item is versioned rather than re-identified.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "duplicate-of-ref", "name": "Duplicate-of reference", "description": "Link to a previously registered item found to be the same underlying thing.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "evidence-item", "name": "Evidence item", "description": "The addressable thing offered in support: a file, message, image, dataset extract, signed attestation, physical exhibit or recorded testimony, held or referenced under a stable identifier.", "media_or_form": [ "digital file", "dataset extract", "message or communication record", "still image, audio or video", "signed attestation or credential", "physical exhibit", "transcribed testimony" ], "serial": false, "identity_strategy": "Master-system identifier where the item originates in a system of record; otherwise governed IRI; otherwise Dimension-assigned ULID, always paired with a content digest for immutable digital items.", "source_refs": [ "SRC-012", "SRC-011", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "evidence-form-and-modality", "name": "Evidence form and modality", "description": "Classification of the item by evidentiary form (documentary, testimonial, observational, computational, attestation, physical) and by medium and encoding, and whether it is an original or a copy.", "source_refs": [ "SRC-011", "SRC-017", "SRC-008" ], "questions": [ { "id": "q-form-class", "text": "Which evidentiary form does the item take, and from which governed taxonomy is that class drawn?", "kind": "classification", "answer_data": [ "evidence-class-code", "class-taxonomy-id" ] }, { "id": "q-form-media", "text": "What media type, encoding and structural profile does the item use, and is it self-describing?", "kind": "interoperability", "answer_data": [ "media-type", "encoding", "format-profile" ] }, { "id": "q-form-original", "text": "Is this the original, a forensic image, a derived rendering or a summary, and where is the original if not held?", "kind": "provenance", "answer_data": [ "original-or-copy", "original-location-ref" ] }, { "id": "q-form-handling", "text": "Does the form change the handling, integrity or admissibility obligations that apply to the item?", "kind": "requirement", "answer_data": [ "handling-regime-code", "admissibility-note" ] }, { "id": "q-form-composite", "text": "Is the item a composite of separately addressable parts, and is each part independently identified and hashed?", "kind": "composition", "answer_data": [ "part-count", "part-ref", "part-digest" ] } ], "data_elements": [ { "id": "evidence-class-code", "name": "Evidence class", "description": "Documentary, testimonial, observational/measured, computational/derived, attestation or physical classification.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-017", "SRC-008" ] }, { "id": "media-type", "name": "Media type", "description": "Registered media type and, where relevant, format profile of a digital item.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "original-or-copy", "name": "Original or copy", "description": "Whether the held artefact is the original, an acquired image, a derived rendering or a summary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-017" ] }, { "id": "part-ref", "name": "Component part reference", "description": "Reference to an independently addressable part of a composite item.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "handling-regime-code", "name": "Handling regime", "description": "Handling and preservation regime triggered by the item's form.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "Form and modality are classifying attributes of the evidence item artefact already declared in this bundle; minting a second artefact for the classification would duplicate identity for the same physical or digital thing." } ] }, { "id": "anchoring-and-excerpting", "name": "Source Anchoring and Excerpt Fidelity", "description": "Precise addressing of the part of a source relied on, capture of the source state, and the transformation chain from source to the excerpt actually used.", "source_refs": [ "SRC-004", "SRC-001", "SRC-011" ], "findings": [ { "id": "source-anchor-and-locator", "name": "Source anchor and locator", "description": "Identification of the source resource, the selector addressing the relevant part, and the state of the source at the time of reliance so the anchor survives later change.", "source_refs": [ "SRC-004", "SRC-011", "SRC-001" ], "questions": [ { "id": "q-anchor-where", "text": "Exactly which part of the source is relied on, expressed by which selector type and value?", "kind": "spatial", "answer_data": [ "selector-type-code", "selector-object", "source-ref" ] }, { "id": "q-anchor-state", "text": "What was the state of the source when it was relied on, and how is that state re-obtainable?", "kind": "temporal", "answer_data": [ "source-state-timestamp", "captured-state-ref", "retrieval-uri" ] }, { "id": "q-anchor-drift", "text": "How is it detected that the source changed after anchoring, and what happens to the support when it has?", "kind": "validation", "answer_data": [ "anchor-check-result", "anchor-drift-status" ] }, { "id": "q-anchor-absent", "text": "What is recorded when the item has no source anchor at all, such as a direct sensor reading or live testimony?", "kind": "exception", "answer_data": [ "anchor-absent-reason", "acquisition-method-code" ] }, { "id": "q-anchor-unavailable", "text": "If the source becomes unavailable or paywalled, what preserved surrogate stands in and with what authority?", "kind": "access", "answer_data": [ "captured-state-ref", "surrogate-authority-note" ] } ], "data_elements": [ { "id": "source-ref", "name": "Source reference", "description": "Identifier of the source resource, resolved in a sibling source model rather than described here.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "selector-type-code", "name": "Selector type", "description": "Kind of selector used, such as fragment, text-quote, text-position, range, CSS, XPath or data-position.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "selector-object", "name": "Selector value", "description": "Structured selector payload, including prefix and suffix context for quote selectors.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "source-state-timestamp", "name": "Source state timestamp", "description": "RFC 3339 time of the source representation relied on, with explicit offset or Z.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-009" ] }, { "id": "anchor-drift-status", "name": "Anchor drift status", "description": "Whether the anchor still resolves to the content originally selected.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "anchor-absent-reason", "name": "Anchor-absent reason", "description": "Stated reason the item carries no source anchor.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [ { "id": "source-snapshot", "name": "Source snapshot", "description": "Captured representation of the source as it stood at the time of reliance, retained so the anchor remains resolvable after the live source changes or disappears.", "media_or_form": [ "web archive capture", "rendered document copy", "database extract", "screen capture with hash" ], "serial": false, "identity_strategy": "Content digest of the capture plus the capture timestamp; where a memento or archive service is the master system, its archived-resource identifier takes precedence.", "source_refs": [ "SRC-004", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "excerpt-fidelity-and-transformation", "name": "Excerpt fidelity and transformation chain", "description": "Whether what is relied on is a verbatim quotation or a transformed derivative, which transformations were applied by which agent, and how the excerpt can be checked back against the source.", "source_refs": [ "SRC-001", "SRC-004", "SRC-011" ], "questions": [ { "id": "q-exc-verbatim", "text": "Is the relied-on text or data a verbatim quotation from the source, a translation, an OCR output, a redaction or a paraphrase?", "kind": "provenance", "answer_data": [ "fidelity-mode", "excerpt-text" ] }, { "id": "q-exc-chain", "text": "Which transformation steps were applied between the source and the excerpt, in what order, and by which agent or tool?", "kind": "process", "answer_data": [ "transformation-step", "transformation-agent-ref", "transformation-order" ] }, { "id": "q-exc-verify", "text": "How can a third party verify the excerpt against the source, and what is the outcome of the last such check?", "kind": "validation", "answer_data": [ "fidelity-check-method", "fidelity-check-result", "fidelity-checked-at" ] }, { "id": "q-exc-language", "text": "In what language and script is the excerpt, and if translated, who translated it and is the original retained?", "kind": "quality", "answer_data": [ "language-code", "translation-agent-ref", "original-excerpt-ref" ] }, { "id": "q-exc-meaning", "text": "Does the excerpt preserve the qualifications, negations and scope present in the source, and who confirmed that?", "kind": "quality", "answer_data": [ "context-preservation-check", "reviewer-ref" ] } ], "data_elements": [ { "id": "excerpt-text", "name": "Excerpt", "description": "The quoted or extracted content actually relied on.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-001" ] }, { "id": "fidelity-mode", "name": "Fidelity mode", "description": "Verbatim, translated, machine-transcribed, redacted or paraphrased character of the excerpt.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "transformation-step", "name": "Transformation step", "description": "An ordered transformation applied between source and excerpt, modelled as a derivation.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "transformation-agent-ref", "name": "Transformation agent", "description": "Person, organisation or software agent that performed a transformation step.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "language-code", "name": "Language tag", "description": "Language and script tag of the excerpt.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "fidelity-check-result", "name": "Fidelity check result", "description": "Outcome of comparing the excerpt against the anchored source.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "excerpt-record", "name": "Excerpt record", "description": "Retained excerpt together with its anchor, fidelity mode and transformation chain, so the quotation can be audited without re-fetching the source.", "media_or_form": [ "structured record", "annotated text fragment", "tabular data extract" ], "serial": false, "identity_strategy": "Digest of the excerpt content combined with the anchor identifier; no independent external identifier is assumed.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "acquisition-and-custody", "name": "Acquisition and Chain of Custody", "description": "How the item was obtained and by what method and instrument, and the unbroken custody record from acquisition to present.", "source_refs": [ "SRC-008", "SRC-017", "SRC-018" ], "findings": [ { "id": "acquisition-method-and-instrument", "name": "Acquisition method and instrument", "description": "The method, tool, settings and operator used to obtain the item, and whether the process is one shown to produce an accurate result.", "source_refs": [ "SRC-008", "SRC-017" ], "questions": [ { "id": "q-acq-how", "text": "By which of identification, collection, acquisition or preservation was the item obtained, and what method was used?", "kind": "process", "answer_data": [ "acquisition-method-code", "acquisition-process-note" ] }, { "id": "q-acq-tool", "text": "Which instrument or tool, at which version and configuration, produced the item?", "kind": "provenance", "answer_data": [ "tool-name-version", "acquisition-parameters" ] }, { "id": "q-acq-who", "text": "Who performed the acquisition, under what role and with what demonstrated competence?", "kind": "authority", "answer_data": [ "acquisition-agent-ref", "agent-role-code", "competence-evidence-ref" ] }, { "id": "q-acq-validated", "text": "Is the process one shown to produce an accurate result, and where is that showing recorded?", "kind": "validation", "answer_data": [ "method-validation-ref", "accuracy-showing-note" ] }, { "id": "q-acq-where", "text": "Where and under what conditions was the item acquired, to the precision the case requires?", "kind": "spatial", "answer_data": [ "collection-location", "collection-conditions", "acquired-at" ] } ], "data_elements": [ { "id": "acquisition-method-code", "name": "Acquisition method", "description": "Coded method by which the item was obtained.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "tool-name-version", "name": "Tool and version", "description": "Instrument, software or device with version used in acquisition.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "acquisition-agent-ref", "name": "Acquiring agent", "description": "Agent that performed the acquisition, in a declared role.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-002" ] }, { "id": "acquired-at", "name": "Acquisition time", "description": "RFC 3339 time of acquisition with explicit offset or Z.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-008" ] }, { "id": "collection-location", "name": "Collection location", "description": "Place, system or endpoint from which the item was collected.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "method-validation-ref", "name": "Method validation reference", "description": "Reference to the record showing the process produces an accurate result.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017" ] } ], "artifacts": [ { "id": "acquisition-log", "name": "Acquisition log", "description": "Contemporaneous record of the acquisition event: method, tool and version, parameters, operator, time and location, sufficient for an independent party to repeat the acquisition.", "media_or_form": [ "structured log record", "forensic acquisition report", "instrument output log" ], "serial": true, "identity_strategy": "Sequential acquisition number within the acquiring organisation's case or batch, qualified by that organisation's identifier; instrument-assigned run identifier takes precedence where the instrument is the master system.", "source_refs": [ "SRC-008", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "chain-of-custody-and-handling", "name": "Chain of custody and handling", "description": "The custody record from the moment the item was acquired: who held it, when, what integrity check accompanied each transfer, and whether any gap exists. Custody is physical, logical and documentary.", "source_refs": [ "SRC-008", "SRC-018", "SRC-017" ], "questions": [ { "id": "q-coc-events", "text": "What sequence of custody events exists from acquisition to now, and is any interval unaccounted for?", "kind": "temporal", "answer_data": [ "custody-event", "custody-timestamp", "custody-gap-flag" ] }, { "id": "q-coc-holder", "text": "Who held or controlled the item during each interval, and under what authority did control transfer?", "kind": "ownership", "answer_data": [ "custody-holder-ref", "transfer-authority-ref" ] }, { "id": "q-coc-integrity", "text": "What integrity value or seal was recorded at each transfer, and did it verify on receipt?", "kind": "validation", "answer_data": [ "seal-or-hash-at-transfer", "transfer-verify-result" ] }, { "id": "q-coc-modes", "text": "Which custody modes apply — physical storage, logical seals and hashes, documentary access logs — and who maintains each?", "kind": "security", "answer_data": [ "custody-mode-code", "custody-maintainer-ref" ] }, { "id": "q-coc-duration", "text": "For how long after the evidence ceases to be needed must the custody record itself be preserved?", "kind": "retention", "answer_data": [ "custody-retention-until", "custody-retention-basis" ] } ], "data_elements": [ { "id": "custody-event", "name": "Custody event", "description": "A single acquisition, transfer, access, storage or disposal event in the custody chain.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "custody-holder-ref", "name": "Custodian", "description": "Agent holding or controlling the item during an interval.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "custody-timestamp", "name": "Custody event time", "description": "RFC 3339 time of a custody event with explicit offset or Z.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009", "SRC-008" ] }, { "id": "seal-or-hash-at-transfer", "name": "Transfer seal or hash", "description": "Integrity value, seal or qualified timestamp recorded at a custody transfer.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-010" ] }, { "id": "custody-gap-flag", "name": "Custody gap flag", "description": "True when an interval in the chain is unaccounted for.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "custody-retention-until", "name": "Custody record retention", "description": "Time until which the custody record itself must be preserved, typically outlasting the evidence.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-018" ] } ], "artifacts": [ { "id": "chain-of-custody-log", "name": "Chain of custody log", "description": "Append-only sequence of custody events maintained from acquisition and preserved beyond the evidence lifetime, covering physical, logical and documentary custody.", "media_or_form": [ "append-only log", "signed transfer form", "access log extract" ], "serial": true, "identity_strategy": "Monotonically increasing event sequence number within the evidence item identifier; each entry additionally carries the custodian identifier and an RFC 3339 timestamp.", "source_refs": [ "SRC-008", "SRC-018" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "provenance-attribution-and-time", "name": "Provenance, Attribution and Time", "description": "Where the evidence came from, who is responsible for it and for the assertion of support, and the separated time points that let a reader judge currency and ordering.", "rationale": "Provenance records generation, derivation and attribution, and treats a provenance bundle as itself an entity so that provenance can be attributed and its trustworthiness assessed; primary-source, quotation and revision relations are distinguished, and generation, usage, start and end times are separately expressible.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-003" ], "layers": [ { "id": "origin-and-attribution", "name": "Origin, Derivation and Attribution", "description": "The lineage of the evidence item and the responsibility relations attached to it and to the support assertion.", "source_refs": [ "SRC-001", "SRC-002", "SRC-014" ], "findings": [ { "id": "derivation-and-primary-source", "name": "Derivation chain and primary source", "description": "The chain from the item back to its origin, distinguishing primary source produced by an agent with direct experience from quotation, revision and downstream derivation.", "source_refs": [ "SRC-001", "SRC-002", "SRC-011" ], "questions": [ { "id": "q-der-primary", "text": "Which preceding entity, produced by an agent with direct experience of the matter, is the primary source of this item?", "kind": "provenance", "answer_data": [ "primary-source-ref", "primary-source-basis" ] }, { "id": "q-der-chain", "text": "What derivation, quotation and revision steps connect this item to that origin, and which activity generated each step?", "kind": "provenance", "answer_data": [ "derived-from-ref", "derivation-kind", "generating-activity-ref" ] }, { "id": "q-der-tier", "text": "Is the item primary, secondary or tertiary relative to the claim, and by whose classification?", "kind": "classification", "answer_data": [ "source-tier-code", "tier-assessor-ref" ] }, { "id": "q-der-circular", "text": "Does the lineage contain a cycle or converge on a single upstream origin shared with items counted as independent?", "kind": "validation", "answer_data": [ "shared-origin-flag", "circularity-check-result", "lineage-depth" ] }, { "id": "q-der-ingredient", "text": "When the item was composed from other assets, is each ingredient's own provenance retained rather than flattened?", "kind": "composition", "answer_data": [ "ingredient-ref", "ingredient-provenance-retained" ] } ], "data_elements": [ { "id": "primary-source-ref", "name": "Primary source reference", "description": "Reference to the preceding entity produced by an agent with direct experience of the subject matter.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "derived-from-ref", "name": "Derived-from reference", "description": "Reference to an entity from which this item was derived, quoted or revised.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "derivation-kind", "name": "Derivation kind", "description": "Whether the step is a general derivation, a quotation or a revision.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "generating-activity-ref", "name": "Generating activity", "description": "Activity whose completion produced the item.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "source-tier-code", "name": "Source tier", "description": "Primary, secondary or tertiary standing of the item relative to the claim.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-014" ] }, { "id": "ingredient-ref", "name": "Ingredient reference", "description": "Reference to a constituent asset incorporated into a composed item, whose own provenance is retained.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "provenance-graph", "name": "Provenance graph", "description": "Serialised graph of entities, activities and agents with derivation, generation and attribution relations for the evidence items in this support record; itself an entity that can be attributed and dated.", "media_or_form": [ "RDF or graph serialisation", "structured lineage document", "tabular lineage extract" ], "serial": false, "identity_strategy": "Named bundle identifier assigned by the Dimension, distinct from the identifiers of the entities it describes, enabling provenance-of-provenance.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "attribution-responsibility-and-independence", "name": "Attribution, responsibility and independence", "description": "Which agents bear responsibility for the item and for the assertion that it supports the claim, on whose behalf they acted, and whether they are independent of the outcome.", "source_refs": [ "SRC-002", "SRC-001", "SRC-014" ], "questions": [ { "id": "q-attr-who", "text": "To which agent is the item attributed, and which agent asserted that it supports the claim?", "kind": "provenance", "answer_data": [ "attributed-to-ref", "relation-asserted-by-ref" ] }, { "id": "q-attr-behalf", "text": "Did the agent act on behalf of another agent who retains responsibility, and is that delegation recorded?", "kind": "authority", "answer_data": [ "acted-on-behalf-of-ref", "delegation-note" ] }, { "id": "q-attr-kind", "text": "Is the responsible agent a person, an organisation or a software agent, and does that change the weight given?", "kind": "classification", "answer_data": [ "agent-kind-code", "weight-adjustment-note" ] }, { "id": "q-attr-independence", "text": "Is the agent independent of the outcome the claim supports, and what interests are declared?", "kind": "quality", "answer_data": [ "independence-assessment", "coi-declaration" ] }, { "id": "q-attr-self", "text": "Is the item self-reported by the party whose claim it supports, and is that flagged rather than silently equated with third-party evidence?", "kind": "quality", "answer_data": [ "self-reported-flag", "corroborating-item-ref" ] } ], "data_elements": [ { "id": "attributed-to-ref", "name": "Attributed-to agent", "description": "Agent to whom responsibility for the item's existence is ascribed.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "acted-on-behalf-of-ref", "name": "Acted on behalf of", "description": "Agent on whose behalf the responsible agent acted, retaining some responsibility.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "agent-kind-code", "name": "Agent kind", "description": "Person, organisation or software agent classification.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "coi-declaration", "name": "Interest declaration", "description": "Declared interests of the responsible or asserting agent relevant to the claim.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "self-reported-flag", "name": "Self-reported flag", "description": "True when the item originates from the party benefiting from the claim.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "competence-evidence-ref", "name": "Competence evidence", "description": "Reference to qualification, accreditation or training evidence for the responsible agent.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-017" ] } ], "artifacts": [ { "id": "interest-declaration-record", "name": "Interest and independence declaration", "description": "Signed declaration by an asserting or appraising agent of interests, affiliations and relationships bearing on independence, retained alongside the appraisal it qualifies.", "media_or_form": [ "signed declaration form", "structured record" ], "serial": false, "identity_strategy": "Declaring agent identifier plus the identifier of the support record or appraisal it qualifies, plus an RFC 3339 declaration timestamp.", "source_refs": [ "SRC-014" ] } ], "inline_only_rationale": null } ] }, { "id": "temporal-frame", "name": "Temporal Frame and Currency", "description": "Separated time points, clock quality, and the window within which the support remains adequate.", "source_refs": [ "SRC-009", "SRC-002", "SRC-015", "SRC-003" ], "findings": [ { "id": "time-points-and-clock-quality", "name": "Separated time points and clock quality", "description": "Distinct recording of when the fact occurred, when it was observed, when it was ingested and when support was asserted, each in RFC 3339 with explicit offset, plus the clock source that produced them.", "source_refs": [ "SRC-009", "SRC-002", "SRC-018" ], "questions": [ { "id": "q-time-which", "text": "Which distinct time points are recorded — event, observation, ingestion, assertion, verification — and which are unknown?", "kind": "temporal", "answer_data": [ "event-time", "observed-at", "recorded-at", "asserted-at" ] }, { "id": "q-time-format", "text": "Does every time value carry seconds and an explicit numeric offset or Z, and is -00:00 used only where the local offset is genuinely unknown?", "kind": "constraint", "answer_data": [ "time-format-conformance", "offset-semantics-note" ] }, { "id": "q-time-clock", "text": "What clock produced each timestamp, with what traceability and accuracy?", "kind": "measurement", "answer_data": [ "clock-source", "time-accuracy", "time-precision" ] }, { "id": "q-time-partial", "text": "How is a partially known time expressed without inventing precision, for example a known date but unknown time?", "kind": "exception", "answer_data": [ "time-precision", "time-known-flag" ] }, { "id": "q-time-conflict", "text": "When two records disagree on ordering because their clocks differ, which ordering rule governs?", "kind": "validation", "answer_data": [ "ordering-rule", "clock-skew-note" ] } ], "data_elements": [ { "id": "event-time", "name": "Event time", "description": "RFC 3339 time at which the fact evidenced actually occurred.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-002" ] }, { "id": "observed-at", "name": "Observation time", "description": "RFC 3339 time at which the fact was observed or measured.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-002" ] }, { "id": "recorded-at", "name": "Record/ingestion time", "description": "RFC 3339 time at which the item entered the holding system.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-018" ] }, { "id": "asserted-at", "name": "Assertion time", "description": "RFC 3339 time at which the support relation was asserted.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-002" ] }, { "id": "clock-source", "name": "Clock source", "description": "Identification of the clock or time service that produced a timestamp.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-018" ] }, { "id": "time-precision", "name": "Time precision", "description": "Declared precision of a time value so that unknown components are not read as zero.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Time points are scalar attributes of other artefacts (evidence item, custody event, verification event) and are meaningless when detached from them; a separate time artefact would introduce a spurious identity and invite divergence from the record it stamps." }, { "id": "validity-window-and-supersession", "name": "Validity window, staleness and supersession", "description": "The period over which the support is asserted to hold, the re-verification cadence, and how superseding evidence replaces it without erasing the prior state.", "source_refs": [ "SRC-003", "SRC-002", "SRC-014" ], "questions": [ { "id": "q-val-window", "text": "From when until when is this support asserted to hold, and is the end open or fixed?", "kind": "temporal", "answer_data": [ "valid-from", "valid-until" ] }, { "id": "q-val-refresh", "text": "How often must the support be re-verified for its purpose, and when is the next re-verification due?", "kind": "process", "answer_data": [ "revalidation-interval", "revalidation-due" ] }, { "id": "q-val-stale", "text": "At what point does the support count as stale, and what does a consumer see when it is?", "kind": "state", "answer_data": [ "staleness-status", "staleness-rule" ] }, { "id": "q-val-supersede", "text": "Which later support record supersedes this one, and is the superseded record retained and still resolvable?", "kind": "lifecycle", "answer_data": [ "superseded-by-ref", "supersedes-ref", "superseded-at" ] }, { "id": "q-val-invalidate", "text": "What invalidates the evidence item itself, as distinct from the support lapsing, and how is that recorded?", "kind": "event", "answer_data": [ "invalidated-at", "invalidation-reason" ] } ], "data_elements": [ { "id": "valid-from", "name": "Valid from", "description": "RFC 3339 start of the period over which the support is asserted to hold.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-009" ] }, { "id": "valid-until", "name": "Valid until", "description": "RFC 3339 end of the asserted validity period, absent when open-ended.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-009" ] }, { "id": "revalidation-due", "name": "Revalidation due", "description": "Date by which re-verification must occur for the support to remain current.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015" ] }, { "id": "staleness-status", "name": "Staleness status", "description": "Current, due-for-review or stale standing of the support record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "superseded-by-ref", "name": "Superseded by", "description": "Reference to the support record that replaces this one.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "invalidated-at", "name": "Invalidation time", "description": "RFC 3339 time marking the start of destruction, cessation or expiry of the evidence entity.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Validity and supersession are state attributes carried on the support record and expressed through references to successor records; materialising a separate 'validity artefact' would split a single record's state across two identities." } ] } ] }, { "id": "integrity-and-verification", "name": "Integrity, Attestation and Verification", "description": "Whether the evidence is what it purports to be and has not changed: content binding by digest, signatures and attestations, trusted timestamps, verification events, and reproducibility of derived evidence.", "rationale": "A hard binding lets a validator confirm both that the manifest belongs with the asset and that the asset has not been modified; attestation subjects are matched purely by digest; a time-stamp authority establishes that a datum existed before a particular time. Verification of integrity is explicitly not evaluation of the truth of the claims carried.", "source_refs": [ "SRC-011", "SRC-012", "SRC-010", "SRC-003", "SRC-008" ], "layers": [ { "id": "cryptographic-binding", "name": "Cryptographic Binding and Attestation", "description": "Digests, signatures and timestamps that make an evidence record tamper-evident and its time of existence provable.", "source_refs": [ "SRC-011", "SRC-012", "SRC-003", "SRC-010" ], "findings": [ { "id": "content-digest-and-binding", "name": "Content digest and hard binding", "description": "What is hashed, under which algorithm and canonical form, and how the binding survives storage-format change. Digest identity applies only to items treated as immutable.", "source_refs": [ "SRC-011", "SRC-012" ], "questions": [ { "id": "q-dig-alg", "text": "Which digest algorithms are recorded, and does the record permit more than one to support algorithm agility?", "kind": "security", "answer_data": [ "digest-algorithm", "digest-set" ] }, { "id": "q-dig-scope", "text": "Exactly what bytes or structure does the digest cover, and under what canonicalisation?", "kind": "constraint", "answer_data": [ "covered-range", "canonicalization-method" ] }, { "id": "q-dig-binding", "text": "Does a hard binding exist that ties the support record to this specific item rather than merely naming it?", "kind": "validation", "answer_data": [ "hard-binding-present", "binding-kind" ] }, { "id": "q-dig-transcode", "text": "What happens to the binding when the item is transcoded, re-encoded or migrated between stores?", "kind": "exception", "answer_data": [ "rebinding-policy", "rebinding-event-ref" ] }, { "id": "q-dig-unhashable", "text": "For items that cannot be hashed, such as physical exhibits or live testimony, what stands in for content binding?", "kind": "exception", "answer_data": [ "binding-substitute-code", "seal-or-hash-at-transfer" ] } ], "data_elements": [ { "id": "digest-algorithm", "name": "Digest algorithm", "description": "Named hash algorithm used, recorded alongside each digest value.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012", "SRC-011" ] }, { "id": "digest-value", "name": "Digest value", "description": "Computed hash of the covered content.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "canonicalization-method", "name": "Canonicalisation method", "description": "Method fixing the byte form hashed, without which digests are not comparable.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "covered-range", "name": "Covered range", "description": "Byte ranges, boxes or structural extent covered by the digest.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "hard-binding-present", "name": "Hard binding present", "description": "True when at least one binding lets a validator confirm the record belongs with this item and the item is unmodified.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "binding-substitute-code", "name": "Binding substitute", "description": "Non-cryptographic substitute used where hashing is impossible, such as a tamper-evident seal and custody record.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [ { "id": "integrity-manifest", "name": "Integrity manifest", "description": "Set of digests and covered ranges for the evidence items and excerpts in a support record, referenced by hashed URIs so that a reference cannot silently point at changed content.", "media_or_form": [ "structured manifest", "detached checksum file", "embedded manifest store" ], "serial": false, "identity_strategy": "Digest of the manifest itself, referenced by a hashed URI combining location and hash; no external identifier assumed.", "source_refs": [ "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "signature-and-attestation", "name": "Signature and attestation", "description": "Who cryptographically asserted the record, under which securing mechanism, what the signature covers, and how signer trust and revocation are established.", "source_refs": [ "SRC-003", "SRC-011", "SRC-012" ], "questions": [ { "id": "q-sig-who", "text": "Which agent signed, with which key or certificate, and how is that signer identity resolved to a known party?", "kind": "identity", "answer_data": [ "signing-agent-ref", "key-identifier", "certificate-ref" ] }, { "id": "q-sig-mech", "text": "Which securing mechanism is used, embedded or enveloping, and is more than one required?", "kind": "security", "answer_data": [ "securing-mechanism-code", "signature-value" ] }, { "id": "q-sig-scope", "text": "What exactly does the signature cover — the claim, the assertion set, the payload — and what is deliberately outside it?", "kind": "constraint", "answer_data": [ "signature-coverage", "excluded-from-signature" ] }, { "id": "q-sig-trust", "text": "Against which trust list or policy is the signer accepted, and who curates that list?", "kind": "authority", "answer_data": [ "trust-list-ref", "trust-policy-id" ] }, { "id": "q-sig-revoke", "text": "How is revocation or expiry of the signing credential detected, and does it retroactively invalidate the record?", "kind": "lifecycle", "answer_data": [ "revocation-status", "revocation-checked-at", "post-revocation-rule" ] } ], "data_elements": [ { "id": "signature-value", "name": "Signature value", "description": "Cryptographic signature securing the record or attestation envelope.", "value_kind": "binary", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-011" ] }, { "id": "signing-agent-ref", "name": "Signing agent", "description": "Agent whose key produced the signature, distinct from the agent asserting support.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "securing-mechanism-code", "name": "Securing mechanism", "description": "Embedded or enveloping securing mechanism identifier.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "signature-coverage", "name": "Signature coverage", "description": "Statement of what content the signature covers.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "id": "revocation-status", "name": "Revocation status", "description": "Current status of the signing credential at last check.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-011" ] }, { "id": "trust-list-ref", "name": "Trust list reference", "description": "Trust list or policy against which the signer is evaluated.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "signed-attestation-envelope", "name": "Signed attestation envelope", "description": "Envelope carrying a typed statement about identified subjects together with its signature, keeping the signed payload separable from the signature and from the predicate content.", "media_or_form": [ "signed envelope document", "embedded manifest with claim signature", "verifiable credential" ], "serial": false, "identity_strategy": "Subject digests plus predicate type URI identify what is attested; the envelope itself is addressed by its own digest, with issuer-assigned credential identifier taking precedence where present.", "source_refs": [ "SRC-012", "SRC-003", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "trusted-timestamp", "name": "Trusted timestamp and temporal proof", "description": "Third-party attestation that the evidence existed before a stated time, with the accuracy and policy under which it was issued, and the long-term validity strategy.", "source_refs": [ "SRC-010", "SRC-011" ], "questions": [ { "id": "q-ts-present", "text": "Is there a third-party timestamp proving the item existed before a stated time, and if not, why is a self-asserted time considered sufficient?", "kind": "evidence", "answer_data": [ "timestamp-token", "self-asserted-time-rationale" ] }, { "id": "q-ts-tsa", "text": "Which authority issued the token, under which policy identifier, and what serial number does it carry?", "kind": "authority", "answer_data": [ "tsa-ref", "timestamp-policy-id", "token-serial" ] }, { "id": "q-ts-accuracy", "text": "What generation time and accuracy does the token assert, and is that precision adequate for the ordering the claim depends on?", "kind": "measurement", "answer_data": [ "gen-time", "accuracy-value" ] }, { "id": "q-ts-longterm", "text": "How does the record stay verifiable after signing credentials expire or algorithms weaken?", "kind": "lifecycle", "answer_data": [ "long-term-validation-strategy", "re-timestamped-at" ] }, { "id": "q-ts-backdate", "text": "What would distinguish a genuine token from a backdated one if the authority's key were compromised?", "kind": "security", "answer_data": [ "tsa-audit-trail-ref", "token-serial" ] } ], "data_elements": [ { "id": "timestamp-token", "name": "Timestamp token", "description": "Signed token binding a hash of the record to a generation time.", "value_kind": "binary", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "tsa-ref", "name": "Timestamp authority", "description": "Identity of the trusted third party that issued the token.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "gen-time", "name": "Token generation time", "description": "Time asserted by the authority at which the token was created.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-009" ] }, { "id": "accuracy-value", "name": "Timestamp accuracy", "description": "Declared deviation around the generation time.", "value_kind": "duration", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "timestamp-policy-id", "name": "Timestamp policy identifier", "description": "Policy under which the authority issued the token.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "long-term-validation-strategy", "name": "Long-term validation strategy", "description": "Declared approach to preserving verifiability past credential expiry or algorithm weakening.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-010" ] } ], "artifacts": [ { "id": "timestamp-token-artifact", "name": "Timestamp token artefact", "description": "Retained time-stamp token proving the bound record existed before the asserted time, stored so it remains verifiable independently of the issuing service.", "media_or_form": [ "binary token", "embedded time-stamp assertion" ], "serial": true, "identity_strategy": "Authority identifier plus the token serial number assigned by that authority; the message imprint links the token to the record it stamps.", "source_refs": [ "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "verification-and-reproducibility", "name": "Verification Events and Reproducibility", "description": "The record of checks actually performed on the evidence, and whether derived or computed evidence can be independently re-derived.", "source_refs": [ "SRC-011", "SRC-008", "SRC-012", "SRC-003" ], "findings": [ { "id": "verification-events-and-status", "name": "Verification events and current status", "description": "Each verification is an event with an actor, method, time and outcome; the current status is derived from events, not asserted independently, and integrity verification is kept separate from truth of the claim.", "source_refs": [ "SRC-011", "SRC-003", "SRC-018" ], "questions": [ { "id": "q-ver-last", "text": "When was the record last verified, by which agent, using which method and tool version?", "kind": "validation", "answer_data": [ "verified-at", "verifier-ref", "verification-method" ] }, { "id": "q-ver-outcome", "text": "What was the outcome of each verification step, and which specific step failed when the outcome was negative?", "kind": "evidence", "answer_data": [ "verification-outcome", "failed-step-ref", "failure-detail" ] }, { "id": "q-ver-separation", "text": "Does the verification status assert only integrity and signer validity, and is it clearly not a statement that the claim is true?", "kind": "definition", "answer_data": [ "verification-scope-note", "truth-evaluation-disclaimer" ] }, { "id": "q-ver-expiry", "text": "For how long is a verification result relied on before it must be repeated?", "kind": "temporal", "answer_data": [ "verification-validity-period", "revalidation-due" ] }, { "id": "q-ver-independence", "text": "Can a party other than the issuer verify the record with only the exported package, and what does that require?", "kind": "interoperability", "answer_data": [ "independent-verifiability-flag", "verification-prerequisites" ] } ], "data_elements": [ { "id": "verification-event", "name": "Verification event", "description": "A single verification attempt with actor, method, time and result.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-018" ] }, { "id": "verified-at", "name": "Verification time", "description": "RFC 3339 time of a verification event.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "verifier-ref", "name": "Verifier", "description": "Agent that performed the verification.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "verification-method", "name": "Verification method", "description": "Named method and tool version used to verify.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "verification-outcome", "name": "Verification outcome", "description": "Result of the verification, including partial success with named failed steps.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "independent-verifiability-flag", "name": "Independent verifiability", "description": "True when a third party can verify using only the exported package.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-012" ] } ], "artifacts": [ { "id": "verification-report", "name": "Verification report", "description": "Report of a verification run over a support record: manifest located, signature checked, timestamp checked, assertions validated, bindings compared, with per-step outcomes.", "media_or_form": [ "structured report", "signed report document", "machine-readable result set" ], "serial": true, "identity_strategy": "Sequential run number within the verifying system, qualified by that system's identifier and the digest of the record verified.", "source_refs": [ "SRC-011", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "reproducibility-and-method-replay", "name": "Reproducibility and method replay", "description": "For computed, analysed or derived evidence, whether the same result is obtainable by the same person with the same method (repeatability) and by a different person with a different setup (reproducibility).", "source_refs": [ "SRC-008", "SRC-012", "SRC-014" ], "questions": [ { "id": "q-rep-third", "text": "Can an independent party re-derive this evidence, and has anyone actually done so with what result?", "kind": "validation", "answer_data": [ "replication-result", "replicator-ref", "replicated-at" ] }, { "id": "q-rep-inputs", "text": "Which inputs, parameters, code versions and environment are recorded, and are they sufficient to re-run?", "kind": "process", "answer_data": [ "input-manifest", "method-description", "environment-descriptor" ] }, { "id": "q-rep-determinism", "text": "Is the derivation deterministic, and if not, what is the expected variation and its source?", "kind": "quality", "answer_data": [ "determinism-flag", "expected-variation" ] }, { "id": "q-rep-blockers", "text": "What prevents reproduction — licensed data, unavailable hardware, expired credentials, non-public source — and is that disclosed?", "kind": "exception", "answer_data": [ "reproduction-blocker", "blocker-disclosure-flag" ] }, { "id": "q-rep-distinction", "text": "Is the record claiming repeatability, reproducibility, or neither, and on what basis?", "kind": "definition", "answer_data": [ "repeatability-claim", "reproducibility-claim" ] } ], "data_elements": [ { "id": "method-description", "name": "Method description", "description": "Description of the derivation method at a level allowing re-execution.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "input-manifest", "name": "Input manifest", "description": "Identified and digested inputs consumed by the derivation.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "environment-descriptor", "name": "Environment descriptor", "description": "Execution environment, code versions and configuration used.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "determinism-flag", "name": "Determinism flag", "description": "Whether re-running the method on the same inputs yields identical output.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "replication-result", "name": "Replication result", "description": "Outcome of an attempted independent reproduction.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-014" ] }, { "id": "reproduction-blocker", "name": "Reproduction blocker", "description": "Stated obstacle preventing independent reproduction.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [ { "id": "reproduction-package", "name": "Reproduction package", "description": "Self-contained bundle of inputs, method, parameters and environment description enabling an independent party to attempt re-derivation of computed evidence.", "media_or_form": [ "archive bundle", "container or environment definition", "notebook or script set with input manifest" ], "serial": false, "identity_strategy": "Digest of the package plus the identifier of the evidence item it reproduces; a build or pipeline run identifier from the master system takes precedence where one exists.", "source_refs": [ "SRC-012", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "authentication-foundation", "name": "Authentication foundation", "description": "The proponent must produce support sufficient to find that the item is what it is claimed to be, using one or more recognized methods such as witness knowledge, distinctive characteristics, public-record custody, or process-or-system accuracy.", "source_refs": [ "SRC-017" ], "questions": [ { "id": "authentication-foundation-q01", "text": "What is the item claimed to be, and what would count as it being that thing?", "kind": "identity", "answer_data": [ "claimed_identity", "claimed_source", "claimant" ] }, { "id": "authentication-foundation-q02", "text": "Which authentication method or methods are offered, and are they examples under a governing rule or another statute-provided method?", "kind": "validation", "answer_data": [ "authentication_methods", "method_authority", "foundation_summary" ] }, { "id": "authentication-foundation-q03", "text": "Has authentication been distinguished from later bars such as hearsay, privilege or prejudice that can still exclude an authenticated item?", "kind": "constraint", "answer_data": [ "authentication_status", "remaining_bars", "admissibility_not_implied" ] } ], "data_elements": [ { "id": "authentication-foundation-data01", "name": "Claimed identity of item", "description": "What the proponent claims the item is.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-017" ] }, { "id": "authentication-foundation-data02", "name": "Authentication methods", "description": "Non-exclusive methods used to authenticate or identify the item.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-017" ] }, { "id": "authentication-foundation-data03", "name": "Authentication status", "description": "Whether a sufficient foundation has been recorded.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-017" ] }, { "id": "authentication-foundation-data04", "name": "Remaining bars", "description": "Noted bars that authentication does not remove.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017" ] } ], "artifacts": [ { "id": "authentication-foundation-artifact01", "name": "Authentication foundation record", "description": "Record of the method and supporting testimony or system description used to authenticate the item.", "media_or_form": [ "application/json", "application/pdf", "text/plain" ], "serial": true, "identity_strategy": "Item master identifier plus authentication-event serial.", "source_refs": [ "SRC-017" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "appraisal-strength-and-sufficiency", "name": "Appraisal, Strength and Sufficiency", "description": "How strong the support is against a declared scheme, what limits it, whether it meets the threshold the decision requires, and whether apparent corroboration is genuine.", "rationale": "Certainty of evidence is rated against explicit domains and is separate from the strength of any recommendation drawn from it; legal sufficiency requires evidence sufficient to support a finding that an item is what it is claimed to be. Strength is therefore scheme-relative and threshold-relative, never a bare number.", "source_refs": [ "SRC-014", "SRC-006", "SRC-017" ], "layers": [ { "id": "quality-appraisal", "name": "Certainty and Limitations", "description": "Scheme-declared certainty grading and the explicit limitations that drive it.", "source_refs": [ "SRC-014", "SRC-006", "SRC-008" ], "findings": [ { "id": "certainty-grading", "name": "Certainty grading against a declared scheme", "description": "The certainty or confidence level assigned, always paired with the identifier and version of the scheme that defines it, the domains that drove the rating and the grader.", "source_refs": [ "SRC-014", "SRC-006" ], "questions": [ { "id": "q-cert-scheme", "text": "Which grading scheme and version defines the level assigned, and what are its permitted values?", "kind": "classification", "answer_data": [ "grading-scheme-id", "scheme-version", "permitted-levels" ] }, { "id": "q-cert-level", "text": "What certainty level is assigned, and which domains caused it to be rated down or up?", "kind": "measurement", "answer_data": [ "certainty-level-code", "rating-domain-judgement", "rating-direction" ] }, { "id": "q-cert-who", "text": "Who performed the grading, when, and were they independent of the claim's proponent?", "kind": "provenance", "answer_data": [ "grader-ref", "graded-at", "independence-assessment" ] }, { "id": "q-cert-separate", "text": "Is certainty in the evidence kept distinct from the strength and direction of any recommendation or decision drawn from it?", "kind": "definition", "answer_data": [ "certainty-level-code", "recommendation-strength", "recommendation-direction" ] }, { "id": "q-cert-compare", "text": "Can this level be compared with a level from a different scheme, and on what authority is any such mapping made?", "kind": "interoperability", "answer_data": [ "cross-scheme-mapping-ref", "mapping-authority" ] } ], "data_elements": [ { "id": "grading-scheme-id", "name": "Grading scheme identifier", "description": "Identifier and version of the scheme defining the certainty vocabulary; a level without this is uninterpretable.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "certainty-level-code", "name": "Certainty level", "description": "Assigned level within the declared scheme, such as high, moderate, low or very low.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "rating-domain-judgement", "name": "Rating domain judgement", "description": "Per-domain judgement driving the rating, for example risk of bias, inconsistency, indirectness, imprecision or selective reporting.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "grader-ref", "name": "Grader", "description": "Agent that assigned the certainty level.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "graded-at", "name": "Grading time", "description": "RFC 3339 time at which the grading was performed.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "recommendation-strength", "name": "Recommendation strength", "description": "Strength of any recommendation drawn, recorded separately from evidence certainty.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [ { "id": "appraisal-record", "name": "Evidence appraisal record", "description": "Structured summary of the body of evidence for one claim: per-domain judgements, the resulting certainty level, the scheme applied and the reasons for each downgrade or upgrade.", "media_or_form": [ "summary-of-findings table", "structured appraisal record", "review report" ], "serial": false, "identity_strategy": "Support-record identifier plus scheme identifier plus grading timestamp; where a guideline or review body is the master system, its appraisal identifier takes precedence.", "source_refs": [ "SRC-014", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "bias-limitations-and-reliability", "name": "Bias, limitations and measurement reliability", "description": "Known biases, coverage limits, indirectness and quantified uncertainty attaching to the evidence, recorded so consumers see them without re-deriving them.", "source_refs": [ "SRC-014", "SRC-008" ], "questions": [ { "id": "q-bias-known", "text": "What biases are known or suspected in how this evidence was produced or selected?", "kind": "quality", "answer_data": [ "bias-domain", "bias-judgement", "bias-note" ] }, { "id": "q-bias-uncertainty", "text": "What measurement error, interval or confidence attaches to any quantitative evidence, and in what units?", "kind": "measurement", "answer_data": [ "uncertainty-quantity", "uncertainty-basis", "measurement-unit" ] }, { "id": "q-bias-coverage", "text": "What population, period, geography or system does the evidence actually cover, and where is it being applied beyond that?", "kind": "constraint", "answer_data": [ "coverage-limitation", "indirectness-note" ] }, { "id": "q-bias-surface", "text": "How are these limitations surfaced to a downstream consumer who reads only the claim?", "kind": "access", "answer_data": [ "limitation-disclosure-mode", "limitation-summary" ] }, { "id": "q-bias-unmeasured", "text": "Which limitations are known to exist but are not quantified, and is that stated rather than omitted?", "kind": "exception", "answer_data": [ "unquantified-limitation", "limitation-summary" ] } ], "data_elements": [ { "id": "bias-domain", "name": "Bias domain", "description": "Named domain in which bias is assessed.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "bias-judgement", "name": "Bias judgement", "description": "Assessment outcome for a bias domain, such as low, some concerns or high.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "uncertainty-quantity", "name": "Uncertainty", "description": "Quantified uncertainty attaching to a measured value, with its unit and basis.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "coverage-limitation", "name": "Coverage limitation", "description": "Stated boundary of what the evidence actually covers.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "indirectness-note", "name": "Indirectness note", "description": "Statement of the gap between the evidence obtained and the question asked.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "unquantified-limitation", "name": "Unquantified limitation", "description": "Known limitation for which no quantification is available.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "Limitations are qualifying attributes of the appraisal record already declared in this layer. Separating them into their own artefact would allow a certainty level to circulate without its caveats, which is the specific failure this finding exists to prevent." }, { "id": "quantitative-statistic", "name": "Quantitative statistic support", "description": "The numeric heart of scientific evidence: statistic type, quantity, unit, sample size, intervals, p values, model characteristics, and study or synthesis type.", "source_refs": [ "SRC-020" ], "questions": [ { "id": "quantitative-statistic-q01", "text": "What statistic type, quantity, unit of measure and sample size are reported for this evidence bit?", "kind": "measurement", "answer_data": [ "statistic_type", "quantity", "unit", "sample_size" ] }, { "id": "quantitative-statistic-q02", "text": "What confidence intervals, p values, heterogeneity estimates and statistic-model characteristics qualify the quantity?", "kind": "measurement", "answer_data": [ "confidence_interval", "p_value", "heterogeneity", "model_characteristics" ] }, { "id": "quantitative-statistic-q03", "text": "From what study type, and if synthesized from what synthesis type, was the statistic obtained?", "kind": "classification", "answer_data": [ "study_type", "synthesis_type", "variable_definitions" ] } ], "data_elements": [ { "id": "quantitative-statistic-data01", "name": "Statistic", "description": "Machine-interpretable statistic backbone including quantity and type.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "quantitative-statistic-data02", "name": "Quantity", "description": "Numeric result of the statistic.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "quantitative-statistic-data03", "name": "Sample size", "description": "Sample size associated with the statistic.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "quantitative-statistic-data04", "name": "Study type", "description": "Type of study from which the evidence was obtained.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "quantitative-statistic-data05", "name": "Synthesis type", "description": "Type of synthesis if the evidence is derived from synthesis.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "quantitative-statistic-data06", "name": "Variable definitions", "description": "Population, exposure, outcome and other variable roles the statistic is about.", "value_kind": "collection", "cardinality": "1..n", "required": false, "source_refs": [ "SRC-020" ] } ], "artifacts": [ { "id": "quantitative-statistic-artifact01", "name": "Statistic payload", "description": "Computable statistic object matching a single combination of variable definitions.", "media_or_form": [ "application/fhir+json", "application/json" ], "serial": false, "identity_strategy": "Evidence resource identifier plus statistic index.", "source_refs": [ "SRC-020" ] } ], "inline_only_rationale": null } ] }, { "id": "sufficiency-and-corroboration", "name": "Sufficiency, Burden and Corroboration", "description": "Whether the assembled support clears the threshold the decision requires, and whether multiple items are genuinely independent.", "source_refs": [ "SRC-017", "SRC-006", "SRC-014" ], "findings": [ { "id": "sufficiency-threshold-and-burden", "name": "Sufficiency threshold and burden", "description": "The standard the support must meet for this decision, who set it, whether it is met, and what would be needed if not. Sufficiency is a property of the assembled support, not of any single item.", "source_refs": [ "SRC-017", "SRC-006" ], "questions": [ { "id": "q-suf-standard", "text": "What standard must the support meet for this decision, and who set that standard?", "kind": "requirement", "answer_data": [ "sufficiency-standard-code", "threshold-definition", "standard-setter-ref" ] }, { "id": "q-suf-met", "text": "Is the standard met on the evidence currently assembled, and who determined that?", "kind": "decision", "answer_data": [ "sufficiency-met-flag", "decider-ref", "determined-at" ] }, { "id": "q-suf-gap", "text": "If it is not met, precisely what additional evidence or reasoning would close the gap?", "kind": "requirement", "answer_data": [ "gap-description", "required-additional-evidence" ] }, { "id": "q-suf-burden", "text": "Which party bears the burden of producing support, and does that burden shift on any condition?", "kind": "authority", "answer_data": [ "burden-bearer-ref", "burden-shift-condition" ] }, { "id": "q-suf-proceed", "text": "What happens operationally when a decision proceeds despite insufficient support, and how is that override recorded?", "kind": "exception", "answer_data": [ "override-flag", "override-authority-ref", "override-rationale" ] } ], "data_elements": [ { "id": "sufficiency-standard-code", "name": "Sufficiency standard", "description": "Named standard or threshold the support must satisfy for this decision class.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-017", "SRC-006" ] }, { "id": "threshold-definition", "name": "Threshold definition", "description": "Operational statement of what satisfying the standard requires.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "sufficiency-met-flag", "name": "Sufficiency met", "description": "Whether the assembled support meets the declared standard.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-017" ] }, { "id": "gap-description", "name": "Sufficiency gap", "description": "Description of what is missing when the standard is not met.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "override-flag", "name": "Override flag", "description": "True when a decision proceeded despite declared insufficiency.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "override-authority-ref", "name": "Override authority", "description": "Agent who authorised proceeding despite insufficient support.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Sufficiency is a determination about a support record as a whole and is recorded as state on that record; the deliberation behind it, where written down, is captured by the decision-rationale-record and conflict-adjudication-record artefacts already declared, so a third artefact would fragment one determination." }, { "id": "corroboration-and-independence", "name": "Corroboration and genuine independence", "description": "Whether multiple supporting items are independent or trace to one origin, and detection of double counting and circular citation that inflate apparent support.", "source_refs": [ "SRC-014", "SRC-017", "SRC-002" ], "questions": [ { "id": "q-cor-count", "text": "How many distinct items support the claim, and how many remain after collapsing items that share an origin?", "kind": "measurement", "answer_data": [ "corroboration-count", "effective-independent-count" ] }, { "id": "q-cor-indep", "text": "Are the supporting items independent in origin, method and agent, and on what basis is independence asserted?", "kind": "validation", "answer_data": [ "independence-assessment", "independence-basis" ] }, { "id": "q-cor-circular", "text": "Does any supporting item ultimately cite the claim it is offered to support, or cite a sibling item as its own source?", "kind": "relationship", "answer_data": [ "circularity-check-result", "shared-origin-flag" ] }, { "id": "q-cor-single", "text": "If support rests on a single item or agent, is that single-source dependency flagged to consumers?", "kind": "quality", "answer_data": [ "single-source-flag", "single-source-note" ] }, { "id": "q-cor-conv", "text": "Does convergence of independent items change the certainty level, and under which rule of the declared scheme?", "kind": "decision", "answer_data": [ "certainty-level-code", "convergence-rule-ref" ] } ], "data_elements": [ { "id": "corroboration-count", "name": "Corroborating item count", "description": "Number of items asserted to support the claim.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "effective-independent-count", "name": "Effective independent count", "description": "Count remaining after collapsing items sharing an upstream origin.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-014" ] }, { "id": "independence-assessment", "name": "Independence assessment", "description": "Judgement of whether supporting items or agents are genuinely independent.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "shared-origin-flag", "name": "Shared origin flag", "description": "True when two or more nominally independent items trace to one origin.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "circularity-check-result", "name": "Circularity check result", "description": "Outcome of testing the citation and derivation graph for cycles.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "single-source-flag", "name": "Single-source flag", "description": "True when all support traces to one item or one agent.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-017" ] } ], "artifacts": [], "inline_only_rationale": "Independence is computed over the provenance graph artefact already declared in the provenance bundle; the analysis result is state on the support record, and duplicating it as a standalone artefact would let a stale independence count outlive the graph it was derived from." } ] } ] }, { "id": "governance-access-and-lifecycle", "name": "Governance, Access, Retention and Interoperability", "description": "Who owns and approves the support record, what rights govern its reuse, who may see it and in what form, how long it is kept and how it is disposed of, how it moves through lifecycle states, and how it maps to and exchanges with external models.", "rationale": "Accountability requires a controller able to demonstrate compliance, storage limitation caps identifiable retention, erasure rights are qualified by a legal-claims exemption, and sectoral rules impose explicit retention floors on machine-generated logs. Evidence records therefore need an explicit governance surface rather than inheriting one.", "source_refs": [ "SRC-016", "SRC-015", "SRC-018", "SRC-005", "SRC-001" ], "layers": [ { "id": "authority-rights-and-ownership", "name": "Ownership, Authority and Rights", "description": "Accountable parties for the record and the rights that constrain reuse of what it contains.", "source_refs": [ "SRC-015", "SRC-016", "SRC-005", "SRC-002" ], "findings": [ { "id": "ownership-stewardship-and-approving-authority", "name": "Ownership, stewardship and approving authority", "description": "The accountable owner, the day-to-day steward, and the authority that approved the support as adequate, together with the mandate under which that approval was given.", "source_refs": [ "SRC-015", "SRC-005", "SRC-002" ], "questions": [ { "id": "q-own-who", "text": "Which party is accountable for this support record and able to demonstrate its compliance on demand?", "kind": "ownership", "answer_data": [ "owner-ref", "accountability-basis" ] }, { "id": "q-own-steward", "text": "Who maintains the record day to day, and how does stewardship differ from ownership here?", "kind": "ownership", "answer_data": [ "steward-ref", "steward-duties" ] }, { "id": "q-own-approve", "text": "Which authority approved the support as adequate, under what mandate, and when?", "kind": "authority", "answer_data": [ "approving-authority-ref", "mandate-ref", "approval-timestamp" ] }, { "id": "q-own-delegate", "text": "May approval authority be delegated, to whom, and does the delegating party retain responsibility?", "kind": "authority", "answer_data": [ "delegation-note", "acted-on-behalf-of-ref" ] }, { "id": "q-own-succession", "text": "What happens to ownership when the owning party is dissolved, reorganised or leaves, and who is the fallback?", "kind": "lifecycle", "answer_data": [ "succession-rule", "fallback-owner-ref" ] } ], "data_elements": [ { "id": "owner-ref", "name": "Accountable owner", "description": "Party accountable for the support record and able to demonstrate its compliance.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-015" ] }, { "id": "steward-ref", "name": "Steward", "description": "Party responsible for day-to-day maintenance of the record.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018" ] }, { "id": "approving-authority-ref", "name": "Approving authority", "description": "Agent or body that approved the support as adequate for its purpose.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "mandate-ref", "name": "Mandate reference", "description": "Policy, delegation or terms of reference under which approval was given.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015" ] }, { "id": "approval-timestamp", "name": "Approval time", "description": "RFC 3339 time of approval with explicit offset or Z.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "succession-rule", "name": "Succession rule", "description": "Declared rule for reassigning ownership when the owner ceases to exist.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018" ] } ], "artifacts": [ { "id": "approval-record", "name": "Approval record", "description": "Record of the authority's sign-off that the assembled support is adequate for the stated purpose, including mandate, scope of approval and any conditions attached.", "media_or_form": [ "signed approval record", "minuted decision", "workflow approval entry" ], "serial": true, "identity_strategy": "Sequential approval number within the approving body's register plus the support-record identifier; the approving body's own case reference takes precedence where it exists.", "source_refs": [ "SRC-005", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "rights-licence-and-permitted-use", "name": "Rights, licence and permitted use", "description": "The rights attaching to source material quoted or held as evidence, what reuse and redistribution are permitted, and the attribution obligations that travel with the excerpt.", "source_refs": [ "SRC-004", "SRC-011", "SRC-016" ], "questions": [ { "id": "q-rights-licence", "text": "Under what licence or legal basis is the source material held, quoted and stored?", "kind": "authority", "answer_data": [ "licence-id", "legal-basis-code", "rights-holder-ref" ] }, { "id": "q-rights-redistribute", "text": "May the evidence item or excerpt be redistributed outside the holding organisation, and to whom?", "kind": "access", "answer_data": [ "permitted-use-code", "redistribution-constraint" ] }, { "id": "q-rights-attribution", "text": "What attribution must accompany the excerpt wherever it is displayed or exported?", "kind": "requirement", "answer_data": [ "attribution-statement", "attribution-required-flag" ] }, { "id": "q-rights-third", "text": "Does the material contain third-party rights or personal data that constrain use beyond the licence?", "kind": "privacy", "answer_data": [ "third-party-rights-note", "contains-personal-data-flag" ] }, { "id": "q-rights-export", "text": "Do any territorial, export-control or contractual restrictions limit where the evidence may be transferred?", "kind": "constraint", "answer_data": [ "territorial-restriction", "transfer-condition" ] } ], "data_elements": [ { "id": "licence-id", "name": "Licence identifier", "description": "Identifier of the licence governing the source material.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "rights-holder-ref", "name": "Rights holder", "description": "Party holding rights in the source material.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "permitted-use-code", "name": "Permitted use", "description": "Coded scope of permitted use, quotation and redistribution.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "attribution-statement", "name": "Attribution statement", "description": "Attribution text that must accompany the excerpt on display or export.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "contains-personal-data-flag", "name": "Contains personal data", "description": "True when the evidence contains data relating to identifiable persons, triggering additional obligations.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-016" ] }, { "id": "territorial-restriction", "name": "Territorial restriction", "description": "Restriction on where the evidence may be stored or transferred.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] } ], "artifacts": [], "inline_only_rationale": "Licence terms are published artefacts owned by the rights holder and are referenced by identifier rather than reproduced; copying them into this model would create an unmaintained fork of a text the Dimension has no authority to amend." } ] }, { "id": "access-confidentiality-and-retention", "name": "Access, Confidentiality, Retention and Disposition", "description": "Who may see the evidence and in what form, and how long it is kept before disposal.", "source_refs": [ "SRC-016", "SRC-015", "SRC-018", "SRC-017", "SRC-019" ], "findings": [ { "id": "access-classification-and-redaction", "name": "Access classification and redaction", "description": "Classification of the support record and its items, the distinction between disclosing existence and disclosing content, and the relationship between a redacted disclosure copy and the unredacted original.", "source_refs": [ "SRC-016", "SRC-018", "SRC-017" ], "questions": [ { "id": "q-acc-class", "text": "What classification applies to the support record, and does it differ from that of individual evidence items?", "kind": "security", "answer_data": [ "classification-code", "item-classification-code" ] }, { "id": "q-acc-existence", "text": "May the existence of the evidence be disclosed to a party who may not see its content, and to whom?", "kind": "access", "answer_data": [ "existence-disclosure-rule", "access-condition" ] }, { "id": "q-acc-privilege", "text": "Is legal privilege, commercial confidence or a statutory restriction claimed, by whom and on what basis?", "kind": "exception", "answer_data": [ "privilege-claim", "privilege-basis", "claimant-ref" ] }, { "id": "q-acc-redact", "text": "How does a redacted disclosure copy relate to the original, and is the redaction itself recorded and reversible by authorised parties?", "kind": "privacy", "answer_data": [ "redaction-map", "disclosure-copy-ref", "redaction-authority-ref" ] }, { "id": "q-acc-minimise", "text": "Is personal data in the evidence limited to what is necessary for the evidential purpose, and who reviews that?", "kind": "privacy", "answer_data": [ "minimisation-review-ref", "contains-personal-data-flag" ] } ], "data_elements": [ { "id": "classification-code", "name": "Classification", "description": "Access classification applied to the support record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018" ] }, { "id": "access-condition", "name": "Access condition", "description": "Condition under which a party may read the record or an item.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-016" ] }, { "id": "privilege-claim", "name": "Privilege or confidentiality claim", "description": "Claimed privilege, confidentiality or statutory restriction over the material.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017" ] }, { "id": "redaction-map", "name": "Redaction map", "description": "Record of what was removed or masked in a disclosure copy and under what authority.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "disclosure-copy-ref", "name": "Disclosure copy reference", "description": "Reference from the original to a derived redacted copy released to a specific audience.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "redaction-authority-ref", "name": "Redaction authority", "description": "Agent who authorised the redaction.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] } ], "artifacts": [ { "id": "redacted-disclosure-copy", "name": "Redacted disclosure copy", "description": "Derived copy of an evidence item or support record with restricted content removed or masked, linked to the unredacted original by a recorded derivation so the two are never confused.", "media_or_form": [ "redacted document", "masked data extract", "disclosure bundle" ], "serial": true, "identity_strategy": "Own identifier distinct from the original, carrying an explicit derivation link to the original identifier plus its own digest and a sequential disclosure number per recipient.", "source_refs": [ "SRC-016", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "retention-legal-hold-and-disposition", "name": "Retention, legal hold and disposition", "description": "How long the support record and its items are kept, the floors and caps that apply, the effect of a legal hold, how erasure requests interact with evidential need, and what remains after disposal.", "source_refs": [ "SRC-016", "SRC-015", "SRC-019", "SRC-018" ], "questions": [ { "id": "q-ret-period", "text": "How long must this record be kept, and what is the legal or policy basis for that period?", "kind": "retention", "answer_data": [ "retention-rule-ref", "retention-until", "retention-basis" ] }, { "id": "q-ret-floor", "text": "Does a sectoral floor apply, such as a minimum log-retention period for high-risk systems, and does it exceed the general policy?", "kind": "requirement", "answer_data": [ "retention-floor", "retention-floor-basis" ] }, { "id": "q-ret-cap", "text": "Does storage limitation cap how long the material may be kept in identifiable form, and how is the conflict with the floor resolved?", "kind": "constraint", "answer_data": [ "identifiability-cap", "conflict-resolution-rule" ] }, { "id": "q-ret-hold", "text": "Is a legal hold in force, who placed it, and what does it suspend?", "kind": "exception", "answer_data": [ "legal-hold-flag", "hold-authority-ref", "hold-scope" ] }, { "id": "q-ret-erasure", "text": "How is an erasure request handled when the material is needed for the establishment, exercise or defence of legal claims?", "kind": "privacy", "answer_data": [ "erasure-request-ref", "erasure-exemption-basis", "erasure-outcome" ] }, { "id": "q-ret-tomb", "text": "After disposal, what remains — a tombstone, a hash, nothing — and how is disposal itself evidenced?", "kind": "provenance", "answer_data": [ "tombstone-record", "disposition-action", "disposition-timestamp" ] } ], "data_elements": [ { "id": "retention-rule-ref", "name": "Retention rule reference", "description": "Reference to the retention schedule or legal provision governing this record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-015" ] }, { "id": "retention-until", "name": "Retention until", "description": "Date until which the record must be retained.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-018" ] }, { "id": "retention-floor", "name": "Retention floor", "description": "Minimum retention period imposed by sectoral law, for example at least six months for automatically generated logs of high-risk AI systems.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-015" ] }, { "id": "legal-hold-flag", "name": "Legal hold", "description": "True when disposal is suspended by a hold.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-016" ] }, { "id": "disposition-action", "name": "Disposition action", "description": "Action taken at end of retention: destroy, anonymise, transfer to archive or extend.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016", "SRC-018" ] }, { "id": "tombstone-record", "name": "Tombstone record", "description": "Minimal residue retained after disposal recording that the item existed, its identifier and its disposal, without its content.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-018" ] } ], "artifacts": [ { "id": "disposition-certificate", "name": "Disposition certificate", "description": "Signed record evidencing that a retention period expired or a hold was lifted and that the declared disposition action was carried out, retained after the material itself is gone.", "media_or_form": [ "signed certificate", "structured disposition log entry" ], "serial": true, "identity_strategy": "Sequential disposition number within the retention register plus the identifier of the disposed record; the certificate outlives the record and retains that identifier as a tombstone key.", "source_refs": [ "SRC-018", "SRC-016" ] } ], "inline_only_rationale": null } ] }, { "id": "lifecycle-and-interoperability", "name": "Record Lifecycle and Interoperability", "description": "States the support record moves through, the difference between correcting and retracting it, and how it maps to and exchanges with external evidence and provenance models.", "source_refs": [ "SRC-003", "SRC-002", "SRC-011", "SRC-001", "SRC-005", "SRC-012" ], "findings": [ { "id": "record-lifecycle-and-retraction", "name": "Lifecycle states, correction and retraction", "description": "The permitted states of a support record and the transitions between them, with correction distinguished from retraction and history preserved rather than overwritten.", "source_refs": [ "SRC-003", "SRC-002", "SRC-011" ], "questions": [ { "id": "q-life-states", "text": "Which states may a support record occupy, and which transitions between them are permitted?", "kind": "state", "answer_data": [ "lifecycle-state", "permitted-transitions" ] }, { "id": "q-life-who", "text": "Who may move the record to disputed, withdrawn or retracted, and does that differ from who may create it?", "kind": "authority", "answer_data": [ "state-change-agent-ref", "transition-authority-rule" ] }, { "id": "q-life-correct", "text": "What distinguishes correcting a support record from retracting it, and which is recorded when the underlying evidence proves false?", "kind": "lifecycle", "answer_data": [ "correction-vs-retraction", "retraction-reason" ] }, { "id": "q-life-notify", "text": "How are downstream consumers of the claim notified that its support was retracted or superseded?", "kind": "process", "answer_data": [ "notification-mechanism", "notified-at", "downstream-consumer-ref" ] }, { "id": "q-life-immutable", "text": "Is the change history append-only, and how is that immutability enforced and checked?", "kind": "security", "answer_data": [ "history-immutability-mode", "history-integrity-check" ] } ], "data_elements": [ { "id": "lifecycle-state", "name": "Lifecycle state", "description": "Current state such as draft, asserted, verified, disputed, superseded, withdrawn or retracted.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-002" ] }, { "id": "state-changed-at", "name": "State change time", "description": "RFC 3339 time of the most recent state transition.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "state-change-agent-ref", "name": "State change agent", "description": "Agent that performed the state transition.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "retraction-reason", "name": "Retraction reason", "description": "Stated reason for withdrawal or retraction, retained permanently.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "prior-version-ref", "name": "Prior version reference", "description": "Reference to the immediately preceding version of the support record.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "history-immutability-mode", "name": "History immutability mode", "description": "Mechanism enforcing append-only history, such as hash chaining or a write-once store.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-018" ] } ], "artifacts": [], "inline_only_rationale": "Lifecycle state is a single-valued attribute of the support record whose history is already carried by the append-only chain-of-custody log and the change history required by the service layer; a separate lifecycle artefact would create a second, divergent statement of current state." }, { "id": "standards-alignment-and-exchange", "name": "Standards alignment and exchange packaging", "description": "Declared mappings from this model to external provenance, assurance-case, credential, attestation, citation and annotation models, and the self-contained package by which a support record moves between systems. Alignments are not conformance claims.", "source_refs": [ "SRC-001", "SRC-005", "SRC-012", "SRC-011", "SRC-003", "SRC-013", "SRC-004" ], "questions": [ { "id": "q-int-targets", "text": "To which external models does this model declare a mapping, at which versions, and for which elements?", "kind": "interoperability", "answer_data": [ "alignment-target-id", "alignment-version", "mapped-element-pair" ] }, { "id": "q-int-lossy", "text": "Is each mapping lossless in both directions, and what is lost in the direction that is not?", "kind": "interoperability", "answer_data": [ "mapping-direction", "lossy-flag", "loss-description" ] }, { "id": "q-int-conformance", "text": "Is any conformance to an external standard claimed, and what evidence supports that claim as opposed to mere alignment?", "kind": "evidence", "answer_data": [ "conformance-claim", "conformance-evidence-ref" ] }, { "id": "q-int-package", "text": "What does a self-contained export contain so that a receiving system can verify the record without access to the originating store?", "kind": "composition", "answer_data": [ "package-manifest", "package-contents", "independent-verifiability-flag" ] }, { "id": "q-int-import", "text": "On import, how are referential integrity, identifier collisions and unresolvable references handled?", "kind": "validation", "answer_data": [ "import-integrity-rule", "collision-policy", "unresolved-reference-action" ] } ], "data_elements": [ { "id": "alignment-target-id", "name": "Alignment target", "description": "Identifier and version of an external model this model is mapped to.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "mapped-element-pair", "name": "Mapped element pair", "description": "A local element paired with its external counterpart under a stated relation.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-013" ] }, { "id": "lossy-flag", "name": "Lossy mapping flag", "description": "True when the mapping loses information in at least one direction.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "conformance-claim", "name": "Conformance claim", "description": "Any asserted conformance to an external standard, which must be evidenced or left absent.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-011" ] }, { "id": "package-manifest", "name": "Package manifest", "description": "Manifest of everything included in an export, with digests for each part.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "id": "import-integrity-rule", "name": "Import integrity rule", "description": "Rule governing referential integrity and identifier collisions on import.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] } ], "artifacts": [ { "id": "crosswalk-mapping-document", "name": "Crosswalk mapping document", "description": "Element-by-element mapping between this model and an external provenance, assurance-case, credential, attestation, citation or annotation model, recording relation type, direction and information loss.", "media_or_form": [ "mapping table", "structured crosswalk record", "machine-readable alignment file" ], "serial": false, "identity_strategy": "Local model identifier plus external target identifier and version; each crosswalk is uniquely keyed by that pair and its own revision label.", "source_refs": [ "SRC-001", "SRC-005", "SRC-013" ] }, { "id": "evidence-exchange-package", "name": "Evidence exchange package", "description": "Self-contained package carrying the support record, its evidence items or their digests, provenance, signatures and timestamps, so a receiving party can verify without reaching back to the originating store.", "media_or_form": [ "archive bundle", "manifest store embedded in an asset", "signed export document set" ], "serial": false, "identity_strategy": "Digest of the package manifest, with each contained part addressed by a hashed reference combining location and hash; the originating support-record identifier is preserved inside the package.", "source_refs": [ "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "attach-support", "name": "Attach support to a claim or decision", "description": "Bind a new evidence/rationale record to exactly one host assertion, declaring the supported aspect and the initial reasoning.", "inputs": [ "supported-subject-ref", "supported-aspect-path", "rationale-text", "inference-mode-code", "asserting agent identity" ], "outputs": [ "support-record-id", "lifecycle-state set to draft or asserted", "asserted-at" ], "preconditions": [ "Host assertion exists and is resolvable by identifier", "Asserting agent is authenticated and authorised for the host's Dimension" ], "effects": [ "Creates a support record referencing the host", "Records assertion time and asserting agent", "Sets assumption-only-flag when no evidence item is attached" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-003" ] }, { "id": "register-evidence-item", "name": "Register an evidence item", "description": "Create an evidence item record with identifier precedence applied, form classification, and content digests where the item is immutable.", "inputs": [ "item content or reference", "master-system-id if any", "evidence-class-code", "digest-algorithm set" ], "outputs": [ "evidence-id", "digest-value set", "immutability-flag", "evidence-record-id" ], "preconditions": [ "Identifier precedence resolved: master-system identifier, else governed IRI, else Dimension ULID", "Acquisition record exists or is created in the same transaction" ], "effects": [ "Registers the item and its digests", "Opens a chain-of-custody log for the item", "Flags a duplicate-of reference when an identical digest is already registered" ], "source_refs": [ "SRC-012", "SRC-011", "SRC-008" ] }, { "id": "anchor-and-excerpt", "name": "Anchor an excerpt into a source", "description": "Record the selector addressing the relied-on part of a source, capture the source state, and store the excerpt with its fidelity mode and transformation chain.", "inputs": [ "source-ref", "selector-type-code", "selector-object", "excerpt-text", "fidelity-mode" ], "outputs": [ "anchor record", "source-state-timestamp", "captured-state-ref", "fidelity-check-result" ], "preconditions": [ "Source is resolvable at the time of anchoring, or an anchor-absent reason is supplied", "Excerpt is compared against the source before storage" ], "effects": [ "Stores the anchor and a source snapshot", "Records the transformation chain from source to excerpt", "Enables later drift detection against the captured state" ], "source_refs": [ "SRC-004", "SRC-001", "SRC-011" ] }, { "id": "record-custody-event", "name": "Record a custody event", "description": "Append an acquisition, transfer, access, storage or disposal event to the custody chain for an evidence item, with an integrity value at transfer.", "inputs": [ "evidence-id", "custody-event type", "custody-holder-ref", "custody-timestamp", "seal-or-hash-at-transfer" ], "outputs": [ "appended custody log entry", "transfer-verify-result", "updated custody-gap-flag" ], "preconditions": [ "Evidence item is registered", "Event time is RFC 3339 with explicit offset or Z", "Prior entry exists or this is the acquisition entry" ], "effects": [ "Appends to an append-only log", "Recomputes the custody gap flag over the full chain", "Blocks silent overwrite of prior entries" ], "source_refs": [ "SRC-008", "SRC-018" ] }, { "id": "seal-and-timestamp", "name": "Seal and timestamp a support record", "description": "Compute the integrity manifest, sign the record and obtain a third-party timestamp token proving it existed before a stated time.", "inputs": [ "support-record-id", "canonicalization-method", "signing key or credential", "timestamp authority endpoint" ], "outputs": [ "integrity-manifest", "signature-value", "timestamp-token", "gen-time" ], "preconditions": [ "Record content is canonicalised before hashing", "Signing credential is valid and not revoked at signing time", "Timestamp authority is trusted under the declared policy" ], "effects": [ "Makes the record tamper-evident", "Establishes that the record existed before the token generation time", "Records the securing mechanism and trust list used" ], "source_refs": [ "SRC-010", "SRC-011", "SRC-003" ] }, { "id": "verify-record", "name": "Verify integrity, signature and bindings", "description": "Run the verification sequence over a support record: locate the manifest, check the signature, check the timestamp, validate referenced items, compare hard bindings, and recurse into ingredient provenance.", "inputs": [ "support-record-id or exchange package", "trust-list-ref", "verification-method" ], "outputs": [ "verification-report", "verification-outcome", "failed-step-ref", "verified-at" ], "preconditions": [ "Integrity manifest and signature are present or their absence is recorded as a finding", "Verifier identity is recorded" ], "effects": [ "Appends a verification event", "Updates derived verification status without asserting the truth of the claim", "Marks anchor-drift status when bindings no longer match" ], "source_refs": [ "SRC-011", "SRC-012", "SRC-003" ] }, { "id": "appraise-certainty", "name": "Appraise certainty of the evidence body", "description": "Apply a declared grading scheme to the assembled evidence, recording per-domain judgements and the resulting level, separately from any recommendation strength.", "inputs": [ "support-record-id", "grading-scheme-id", "rating-domain-judgement set", "grader identity" ], "outputs": [ "certainty-level-code", "appraisal-record", "graded-at" ], "preconditions": [ "Grading scheme and version are declared and their permitted values known", "Grader independence is assessed and recorded" ], "effects": [ "Attaches a scheme-qualified certainty level", "Records reasons for each downgrade or upgrade", "Leaves recommendation strength and direction as separate values" ], "source_refs": [ "SRC-014", "SRC-006" ] }, { "id": "assess-sufficiency", "name": "Assess sufficiency against the decision threshold", "description": "Determine whether the assembled support meets the standard required for the host decision, and describe the gap when it does not.", "inputs": [ "support-record-id", "sufficiency-standard-code", "threshold-definition", "decider identity" ], "outputs": [ "sufficiency-met-flag", "gap-description", "required-additional-evidence" ], "preconditions": [ "A sufficiency standard is declared for the decision class", "Counter-evidence has been registered and adjudicated or explicitly left open" ], "effects": [ "Records the sufficiency determination and its decider", "Sets override-flag and override authority when a decision proceeds despite insufficiency" ], "source_refs": [ "SRC-017", "SRC-006" ] }, { "id": "register-counter-evidence", "name": "Register and adjudicate counter-evidence", "description": "Record an item or argument that rebuts the claim, undercuts the inference or undermines a premise, and capture the adjudication outcome.", "inputs": [ "support-record-id", "counter-evidence-ref", "defeater-type", "challenged-element-ref" ], "outputs": [ "conflict-adjudication-record", "resolution-decision", "residual-conflict-flag" ], "preconditions": [ "Adjudicating authority is identified and mandated", "Challenge is linked to the specific element it attacks" ], "effects": [ "Moves the support record to disputed while unresolved", "Retains the challenge permanently whether or not it succeeded", "Triggers re-appraisal of certainty when resolution changes the evidence body" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-014" ] }, { "id": "revalidate-or-supersede", "name": "Revalidate or supersede a support record", "description": "Re-run verification and appraisal at the declared cadence, and where evidence has moved on, issue a successor record linked to the prior one.", "inputs": [ "support-record-id", "revalidation-due", "new evidence items if any" ], "outputs": [ "updated staleness-status", "successor support-record-id", "superseded-by-ref", "supersedes-ref" ], "preconditions": [ "Revalidation interval is declared", "Prior record is retained and remains resolvable" ], "effects": [ "Refreshes verification and certainty or marks the record stale", "Creates a successor without deleting the predecessor", "Notifies downstream consumers of supersession" ], "source_refs": [ "SRC-003", "SRC-002", "SRC-014" ] }, { "id": "redact-and-release", "name": "Redact and release a disclosure copy", "description": "Produce a derived copy with restricted content removed or masked for a named recipient, linked to the original by a recorded derivation.", "inputs": [ "support-record-id or evidence-id", "redaction-map", "recipient identity", "redaction-authority-ref" ], "outputs": [ "redacted-disclosure-copy", "disclosure-copy-ref", "disclosure log entry" ], "preconditions": [ "Classification, privilege claims and personal-data flags are evaluated", "Redaction is authorised by a mandated agent" ], "effects": [ "Creates a separately identified derivative, never overwriting the original", "Records what was removed, by whom and for whom", "Appends an access event to the custody chain" ], "source_refs": [ "SRC-016", "SRC-017", "SRC-018" ] }, { "id": "export-evidence-package", "name": "Export a self-contained evidence package", "description": "Assemble the support record, its items or digests, provenance, signatures and timestamps into a package a receiving party can verify independently.", "inputs": [ "support-record-id", "export scope", "recipient trust requirements" ], "outputs": [ "evidence-exchange-package", "package-manifest", "independent-verifiability-flag" ], "preconditions": [ "All included parts have digests and resolvable references", "Rights, licence and territorial restrictions permit transfer to the recipient" ], "effects": [ "Produces a portable package addressed by manifest digest", "Preserves originating identifiers inside the package", "Records the export as an access event" ], "source_refs": [ "SRC-011", "SRC-012", "SRC-001" ] }, { "id": "apply-retention-or-disposition", "name": "Apply retention, hold or disposition", "description": "Evaluate retention floors, identifiability caps and any legal hold, and where retention has expired without a hold, execute the declared disposition and issue a certificate.", "inputs": [ "support-record-id", "retention-rule-ref", "legal-hold-flag", "disposition-action" ], "outputs": [ "disposition-certificate", "tombstone-record", "disposition-timestamp" ], "preconditions": [ "Retention floor and identifiability cap are both evaluated and any conflict resolved by declared rule", "No legal hold is in force, or the action is limited to hold-compatible steps" ], "effects": [ "Destroys, anonymises, archives or extends per the declared action", "Retains a tombstone and certificate after content removal", "Records the erasure exemption basis when an erasure request is refused" ], "source_refs": [ "SRC-016", "SRC-015", "SRC-019", "SRC-018" ] }, { "id": "authenticate-item", "name": "Authenticate an evidence item", "description": "Record the foundation that the item is what it is claimed to be, using one or more recognized methods.", "inputs": [ "item claimed identity", "authentication method", "supporting testimony or system description" ], "outputs": [ "authentication status", "foundation record" ], "preconditions": [ "An item has been identified and offered as support." ], "effects": [ "Records authentication without implying legal admissibility or absence of other bars." ], "source_refs": [ "SRC-017" ] }, { "id": "challenge-or-invalidate", "name": "Challenge or invalidate support", "description": "Mark support as challenged, withdrawn, superseded or invalidated and point to successor or grounds.", "inputs": [ "support identifier", "grounds", "actor", "event time" ], "outputs": [ "updated challenge or invalidation status", "successor reference if any" ], "preconditions": [ "Support record exists and is not already disposed." ], "effects": [ "Prevents silent continued reliance on invalidated support.", "Preserves prior versions for audit." ], "source_refs": [ "SRC-002", "SRC-020" ] } ], "composition": [ { "target": "WM-KNW-008 (parent knowledge/claim model)", "relation": "CHILD", "purpose": "This mixin is a child of the knowledge model and attaches to the assertion it holds; the claim remains addressable and meaningful without support, and the support is meaningless without the claim.", "required": true, "source_refs": [ "SRC-006", "SRC-005" ] }, { "target": "Decision record model (decision, options, outcome)", "relation": "MIX-IN", "purpose": "Supplies rationale, alternatives-rejected reasons, assumptions and supporting evidence to a recorded decision, in the same way rationale is recorded as description content separate from the thing described.", "required": false, "source_refs": [ "SRC-007", "SRC-006" ] }, { "target": "Source / citation / bibliographic model", "relation": "REFERENCE", "purpose": "Resolves source-ref to a described source; this model contributes only the locator, selector, captured state and citation intent, never the bibliographic description.", "required": true, "source_refs": [ "SRC-004", "SRC-013" ] }, { "target": "Agent / party / organisation registry", "relation": "REFERENCE", "purpose": "Resolves every agent reference — asserter, custodian, signer, grader, approver, adjudicator — to a governed party record with roles and delegation.", "required": true, "source_refs": [ "SRC-002", "SRC-001" ] }, { "target": "Provenance / lineage model", "relation": "COMPOSE", "purpose": "Composes entity, activity and agent lineage with derivation, generation and attribution relations for evidence items, and treats the provenance bundle as itself an attributable entity.", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Access classification and authorisation model", "relation": "REFERENCE", "purpose": "Resolves classification codes and access conditions; this model contributes only evidence-specific exceptions such as privilege claims and redaction maps.", "required": true, "source_refs": [ "SRC-018", "SRC-016" ] }, { "target": "Records retention and disposition model", "relation": "REFERENCE", "purpose": "Resolves retention-rule-ref to a schedule with legal bases, floors and caps; disposition execution and certification are performed here against that schedule.", "required": true, "source_refs": [ "SRC-016", "SRC-015" ] }, { "target": "Measurement / observation model", "relation": "REFERENCE", "purpose": "Resolves observational evidence items to their measurement semantics, units and uncertainty rather than restating instrument and method semantics in this model.", "required": false, "source_refs": [ "SRC-014", "SRC-008" ] }, { "target": "W3C PROV-O / PROV-DM", "relation": "ALIGN", "purpose": "Alignment target for derivation, primary source, quotation, revision, attribution, delegation, invalidation and bundle-level provenance-of-provenance. Alignment only; no conformance is claimed.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "OMG SACM 2.3 and ISO/IEC/IEEE 15026-2:2022", "relation": "ALIGN", "purpose": "Alignment target for the claim/argumentation/evidence separation, inference as a reasoning step under a specified context, explicit assumptions and justification, and auditability of the case.", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "target": "W3C Verifiable Credentials Data Model 2.0", "relation": "ALIGN", "purpose": "Alignment target for issuer, evidence, proof, validFrom/validUntil and credentialStatus, and for the separation of credential verification from evaluation of claim truth.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "C2PA Technical Specification 2.2 and in-toto Attestation Framework", "relation": "ALIGN", "purpose": "Alignment targets for digest-based subject identity, hard bindings, hashed URIs, created versus gathered assertions, ingredient provenance and signed statement envelopes.", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "target": "W3C Web Annotation Data Model and CiTO", "relation": "ALIGN", "purpose": "Alignment targets for selector-based anchoring with source state, and for the governed vocabulary of support, authority, agreement and refutation relations with factual/rhetorical polarity.", "required": false, "source_refs": [ "SRC-004", "SRC-013" ] }, { "target": "ISO/IEC 27037:2012 digital evidence handling", "relation": "ALIGN", "purpose": "Alignment target for the identification/collection/acquisition/preservation processes, the auditability, repeatability and reproducibility principles, and unbroken chain of custody across physical, logical and documentary modes.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "GRADE certainty-of-evidence approach", "relation": "ALIGN", "purpose": "Alignment target for scheme-declared certainty levels, rating-down and rating-up domains, and separation of evidence certainty from recommendation strength and direction.", "required": false, "source_refs": [ "SRC-014" ] }, { "target": "Regulatory logging and technical documentation obligations (EU AI Act, NIST SP 800-53 AU family)", "relation": "EXTEND", "purpose": "Extends the model with mandated machine-generated evidence, minimum log content for defined system classes, and audit-record governance including retention floors, without absorbing the logging subsystem itself.", "required": false, "source_refs": [ "SRC-015", "SRC-018", "SRC-019" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension MUST designate a single accountable owner for each support record and be able to demonstrate compliance for it on request, plus a named steward for day-to-day maintenance.", "The Dimension MUST declare, before first use, its identifier precedence policy (master-system identifier, then governed IRI, then Dimension-assigned UUID/ULID), its canonicalisation method for digests, and its default digest algorithm set with an agility path.", "The Dimension MUST declare the grading scheme(s) and sufficiency standards it recognises, with versions, and MUST NOT permit a certainty level to be stored without its scheme identifier.", "The Dimension MUST publish a retention schedule resolving sectoral retention floors against storage-limitation caps, and MUST define the tombstone residue kept after disposal.", "The Dimension MUST maintain a trust list or policy identifying signers and timestamp authorities it accepts, and record which was applied at each verification." ], "namespace_guidance": "Model-local identifiers are lower-kebab-case and unique within WM-XCT-028. The Dimension SHOULD mint a stable namespace IRI for its instance data, distinct from the model namespace, and MUST NOT reuse an external standard's namespace (prov:, cito:, oa:, in-toto, C2PA) for locally defined terms. Terms borrowed from an external vocabulary MUST be referenced by that vocabulary's IRI and version, never copied into the local namespace. Evidence item identifiers, support record identifiers and artefact identifiers occupy separate namespaces so that a thing, the record about it and any derivative copy can never collide.", "registry_links": [ "vr.wm-xct-028 is the registry entry for this model; nav path NAV.XCT.EVD, domain tag XCT.EVD.", "Parent registry entry WM-KNW-008 must resolve before this mixin can be attached to any host assertion.", "External alignment targets are registered by their published specification IRI and version, not by local alias: PROV-O, SACM 2.3, ISO/IEC/IEEE 15026-2:2022, VC-DM 2.0, Web Annotation Data Model, CiTO 2.8.2, C2PA 2.2, in-toto Statement v1, ISO/IEC 27037:2012." ] }, "canon_and_patch": { "canonicalization_rules": [ "All time values are RFC 3339 with seconds and an explicit numeric offset or Z; -00:00 is used only where UTC is known but the local offset is genuinely unknown, and MUST NOT be normalised to Z.", "A declared canonicalisation method MUST be recorded alongside every digest; digests computed under different canonicalisations are not comparable and MUST NOT be equated.", "Identifiers are compared as opaque strings after scheme-qualified normalisation; case folding is applied only where the identifier scheme defines it.", "Free text is stored with a language tag; excerpts are stored verbatim in the source's original script with any translation held as a separate derived value linked to the original.", "Ordering of custody, verification and lifecycle events is by recorded event time; where clocks disagree, the declared ordering rule and any trusted timestamp take precedence over local clocks." ], "patch_rules": [ "Support records are append-only in respect of history: a change produces a new version linked by prior-version-ref, and prior versions remain resolvable.", "Correction and retraction are distinct operations. Correction supersedes content while retaining the prior version; retraction withdraws the support and permanently retains the retraction reason.", "A patch MUST NOT alter a signed or timestamped record in place; it produces a new record that must be re-sealed and re-timestamped, and the predecessor's seal remains verifiable.", "Deletion of content permitted or required by law leaves a tombstone carrying the identifier, digests and disposition certificate reference, so that references from other records do not silently dangle.", "Any patch that changes evidence content, anchors, digests or counter-evidence invalidates the current verification status and certainty level, which MUST be re-derived rather than carried forward." ], "compatibility_rules": [ "Adding an optional element, a new lifecycle state that is not reachable by default, or a new alignment target is a compatible change.", "Removing an element, tightening cardinality, changing an identifier scheme, changing the canonicalisation method or narrowing a permitted state transition is a breaking change requiring a new model version and a migration note.", "External alignments are versioned independently; an upstream standard revision does not silently change this model's semantics, and crosswalks record the exact upstream version they map to.", "No conformance to an external standard is asserted anywhere in an instance unless a conformance-evidence-ref resolves to a test result or certification; alignment alone is recorded as alignment." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record that owns the artefact (for example an instrument run identifier, a case number, an issuer-assigned credential identifier).", "Governed global identifier or IRI from a recognised registry or vocabulary where no master system exists.", "UUID or ULID minted by the adopting Dimension, recorded together with the scheme that minted it.", "For immutable digital artefacts, a content digest under a declared algorithm and canonicalisation accompanies the chosen identifier and is used for equality and subject matching; it does not replace the identifier.", "A date, a filename, a URL alone or a human label is never an identifier and MUST NOT be used as one." ], "timestamp_rule": "Every recorded time value uses RFC 3339 with seconds and an explicit numeric offset or Z. Event time, observation time, record/ingestion time, assertion time, verification time and timestamp-token generation time are stored in separate fields and never conflated; declared precision accompanies any partially known value so unknown components are not read as zero.", "serial_naming_rule": "Artefacts marked serial are numbered by a monotonically increasing sequence scoped to a declared parent key — custody events by evidence item, verification runs by verifying system, adjudications and approvals by their register, disclosure copies by recipient, disposition certificates by retention register. The full name is parent-key plus zero-padded sequence; sequence numbers are never reused, and a gap in the sequence is itself a finding to be investigated.", "integrity_rule": "Every stored artefact carries at least one digest under a declared algorithm and canonicalisation. References between artefacts use a hashed reference combining location and digest, so a reference that resolves to changed content fails rather than silently succeeding. Signed and timestamped artefacts are write-once; long-term verifiability is preserved by re-timestamping before algorithm or credential expiry, and the original seal is retained alongside." }, "policies": [ "Integrity verification asserts only that an artefact is unaltered and validly signed; it never asserts that the supported claim is true. Systems MUST NOT present a passing verification as validation of the claim.", "A certainty level, confidence value or sufficiency determination MUST NOT be stored, displayed or exported without the identifier and version of the scheme or standard that defines it.", "Counter-evidence and failed verifications are retained permanently and are disclosed alongside supporting evidence; selective retention of only confirming material is prohibited.", "Evidence containing personal data is limited to what is necessary for the evidential purpose; where a retention floor and a storage-limitation cap conflict, the conflict is resolved by a declared, recorded rule rather than by default to the longer period.", "Self-reported evidence, single-source support and unresolved conflicts are flagged on the record and surfaced to any consumer that reads the claim, not only to those who open the support record.", "Assumption-only support — a rationale with no attached evidence item — is permitted but MUST be explicitly flagged and MUST NOT be graded as if it were evidence-backed.", "Do not treat cryptographic proofs, C2PA validation success or GRADE high certainty as substitutes for relevance, authentication or legal admissibility.", "Preserve chain-of-custody and rating history even when the host claim is retired, redacted or superseded.", "Apply data minimization and privilege review before disclosing evidence bodies that may contain personal or restricted content.", "Mark every external-standard mapping as alignment unless a Dimension-level conformance assessment is on file." ], "crud": { "read": [ "Reading a support record returns its lifecycle state, staleness status, certainty level with scheme, residual-conflict flag, self-reported flag and single-source flag together; these MUST NOT be separable in a summary view.", "Reading an evidence item's existence is separately authorisable from reading its content, so a party may be told that support exists without seeing restricted material.", "Every read of restricted evidence is recorded as an access event on the custody chain with reader identity and RFC 3339 time.", "Exported reads produce a package manifest with digests so the receiver can detect truncation or substitution." ], "create": [ "Creating a support record requires a resolvable host assertion, an asserting agent, an assertion time and either at least one evidence item or an explicit assumption-only flag.", "Creating an evidence item requires identifier precedence to be applied and, for immutable digital items, at least one digest with its canonicalisation method.", "Creation opens an append-only custody chain whose first entry is the acquisition event.", "Creation of a redacted disclosure copy mints a new identifier and records a derivation link to the original; it never reuses the original's identifier." ], "update": [ "Content updates produce a new version linked to its predecessor; in-place mutation of signed, timestamped or custody-logged material is prohibited.", "Any update touching evidence, anchors, digests or counter-evidence clears derived verification status and certainty, which must be re-derived by the appropriate function.", "Lifecycle transitions are restricted by role: moving a record to verified requires a verification event; moving it to retracted requires a mandated authority and a permanently retained reason.", "Updates while a legal hold is in force are limited to hold-compatible operations and are themselves logged." ], "delete": [ "Hard deletion is prohibited while a legal hold is in force or while a sectoral retention floor is unexpired.", "Where deletion is required by law, content is removed but a tombstone carrying the identifier, digests, retention basis and disposition certificate reference is retained so references do not dangle.", "Deletion of an evidence item does not delete the support record that cited it; the record retains the citation, the tombstone reference and the fact of deletion.", "Every deletion produces a disposition certificate naming the authorising rule, the action taken and the executing agent, retained beyond the deleted material." ] }, "roles": [ { "name": "Evidence steward", "responsibilities": [ "Registers evidence items, applies identifier precedence and maintains digests", "Maintains the chain-of-custody log and investigates any custody gap", "Maintains source anchors and re-captures source state when drift is detected" ] }, { "name": "Rationale author", "responsibilities": [ "States the warrant, inference mode, assumptions and context conditions", "Records alternatives considered and the reasons each was rejected", "Flags assumption-only support and unquantified limitations" ] }, { "name": "Appraiser", "responsibilities": [ "Applies a declared grading scheme and records per-domain judgements", "Assesses bias, indirectness, coverage limits and independence of sources", "Declares interests and abstains where independence is compromised" ] }, { "name": "Verifier", "responsibilities": [ "Runs integrity, signature, timestamp and binding checks and records the outcome per step", "Confirms independent verifiability of exported packages", "Reports failures without altering the record under verification" ] }, { "name": "Adjudicating authority", "responsibilities": [ "Decides challenges to the claim or its inference under a stated rule of preference", "Records residual unresolved conflict rather than closing it artificially", "Approves or refuses sufficiency overrides and records the rationale" ] }, { "name": "Records and privacy officer", "responsibilities": [ "Resolves retention floors against storage-limitation caps and records the governing rule", "Places and lifts legal holds and authorises disposition", "Authorises redaction and handles erasure requests including exemption determinations" ] } ], "access": { "default_rule": "Deny by default. A principal may read a scope only if an explicit grant names that principal or a role it holds, and access to the existence of a record is granted separately from access to its content. Write access is further restricted by the role definitions above; verification and appraisal roles hold no write access to the material they assess.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Legal privilege, commercial confidence or statutory restriction may withhold artefact content while the existence of the support record and its lifecycle state remain visible to the host claim's audience.", "Regulators, auditors and adjudicating bodies acting under a stated mandate may be granted read access across all four scopes, including artefacts otherwise restricted, with the mandate recorded on the access event.", "A redacted disclosure copy may be released to a principal who has no access to the original; the copy carries its own identifier and access rules and never inherits the original's grants.", "Emergency or break-glass access may be granted where withholding evidence would cause harm; it requires a named authorising agent, is time-boxed, and is reviewed after the fact.", "A data subject exercising access rights may be shown personal data held as evidence, subject to restrictions protecting third-party rights and the establishment, exercise or defence of legal claims.", "Compulsory legal process or documented safety disclosure may override default deny, and must itself be recorded as an access event with authority and time.", "The original author or issuer may read their own unredacted submissions unless a higher privilege or safety hold applies.", "Redacted views may be served to a wider audience when a manifested redaction exists." ], "audit_requirements": [ "Every read, export, redaction, state transition and disposition is recorded with principal identity, scope, RFC 3339 time and the grant or exception relied on.", "Audit records are protected against modification and deletion independently of the evidence they describe, and are retained at least as long as the evidence plus any custody-record extension.", "Failed access attempts are recorded with the same fidelity as successful ones.", "Break-glass and mandate-based accesses are flagged for mandatory post-hoc review, with the review outcome recorded.", "The audit trail must permit reconstruction of who could see what at any past point in time, not only who did see it.", "Record who read, exported, validated, rated, transferred, redacted or disposed of support, with event time and ingestion time.", "Retain audit events at least as long as the support record and its legal holds.", "Validation and rating events must capture the policy or rating-system version used." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Model ID and registry ID (WM-XCT-028 / vr.wm-xct-028)", "Identifier precedence and canonicalisation policy in force", "Declared grading schemes and sufficiency standards with versions", "Retention schedule reference, retention floors and tombstone policy", "Trust list or policy for accepted signers and timestamp authorities", "Accountable owner and steward contacts" ], "read_order": [ "AGENTS.md — establishes Name, Type and the four URLs, and states the Dimension-level policies (identifier precedence, canonicalisation, grading schemes, retention, trust list) that every later step depends on.", "Specification URL — the format-neutral model definition: bundles, layers, findings, data elements and artefacts, read before any instance data is interpreted.", "Storage type URL — how the model is projected onto the store in use (document, relational, graph, object store, Git or MCP-served), including where digests, signatures and append-only logs physically live.", "Interface URL — the access surface, its scopes, the deny-by-default rule and the exception grants, read before any read or write is attempted.", "Processes URL — the operational functions (attach, register, anchor, custody, seal, verify, appraise, adjudicate, revalidate, redact, export, dispose) with their preconditions, read before any state-changing call.", "Registry entry vr.wm-xct-028 and parent WM-KNW-008 — confirms the mixin may be attached to the intended host and that the parent model resolves.", "Declared alignment crosswalks — consulted only when importing from or exporting to an external model; alignments are never treated as conformance." ] } }, "coverage": { "claim": "Merged model covers claim/decision binding and typed support relations, warrant and assumptions with counter-evidence adjudication, evidence identity, source anchoring and excerpt fidelity, acquisition and chain of custody, provenance/attribution and separated time points, cryptographic binding, attestation, trusted timestamping and verification/reproducibility, appraisal of certainty with relevance and reported statistics, sufficiency and corroboration, and governance (ownership, rights, access, retention, lifecycle, exchange). Coverage is defensible for these named surfaces only; quantitative-uncertainty metrology, cross-scheme certainty comparability and argument-interchange formats remain declared gaps, and no universal completeness is claimed.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identifier precedence (master-system, governed IRI, Dimension UUID/ULID) is stated in artifact_rules and enforced in register-evidence-item; digest-based subject matching is used only for items flagged immutable, following in-toto's treatment of subjects as immutable and matched purely by digest. Item identity, record identity and disclosure-copy identity are held in separate namespaces." }, { "dimension": "lifecycle", "status": "covered", "notes": "States, transitions, correction versus retraction, supersession, invalidation of the evidence entity and post-disposal tombstones are covered across validity-window-and-supersession, record-lifecycle-and-retraction and retention-legal-hold-and-disposition. PROV invalidation supplies the entity-cessation semantics." }, { "dimension": "relationships", "status": "covered", "notes": "Typed support relations use a governed vocabulary with polarity (CiTO); challenge relations distinguish rebutting, undercutting and undermining; derivation, ingredient and corroboration relations are separately modelled, and circularity and shared-origin detection guard against inflated support." }, { "dimension": "temporal", "status": "covered", "notes": "Event, observation, ingestion, assertion, verification and token-generation times are separate fields in RFC 3339 with mandatory offset or Z; -00:00 is preserved as distinct from Z; precision is declared for partially known values; RFC 3161 supplies third-party proof of existence before a stated time." }, { "dimension": "provenance", "status": "covered", "notes": "PROV derivation, primary source, quotation, revision, attribution, association and delegation are used, and the provenance bundle is itself treated as an attributable entity so provenance-of-provenance is expressible. Transformation chains from source to excerpt are recorded step by step." }, { "dimension": "ownership", "status": "covered", "notes": "Accountable owner, steward, approving authority, mandate and succession are modelled; rights holders and licence terms are separately referenced. GDPR accountability supplies the requirement that the owner be able to demonstrate compliance." }, { "dimension": "validation", "status": "covered", "notes": "Verification is modelled as events with actor, method, per-step outcome and time, kept explicitly distinct from truth of the claim per VC-DM 2.0; fidelity checks, anchor-drift detection, custody-gap detection, reproducibility and independence checks are all separately represented." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default with grants at bundle, layer, finding and artifact scope; existence disclosure separated from content disclosure; privilege, mandate-based regulator access, break-glass and data-subject access handled as named exceptions with audit requirements." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Sectoral floors (at least six months for automatically generated logs of high-risk AI systems), storage-limitation caps, legal hold, erasure with the legal-claims exemption, disposition certificates and tombstones are all modelled, with an explicit requirement to record how a floor/cap conflict was resolved." }, { "dimension": "interoperability", "status": "covered", "notes": "Crosswalks to PROV, SACM/15026-2, VC-DM, C2PA, in-toto, CiTO, Web Annotation and ISO/IEC 27037 are declared as alignments with direction and loss recorded; conformance requires resolvable evidence and is otherwise absent. Self-contained exchange packages support independent verification." }, { "dimension": "authority", "status": "covered", "notes": "Approving authority, mandate, delegation with retained responsibility, adjudicating authority, redaction authority and sufficiency-override authority are distinct and separately referenced; citesAsAuthority-style relations let an item be offered as authority rather than as evidence." }, { "dimension": "integrity and non-repudiation", "status": "covered", "notes": "Digests with declared canonicalisation, hard bindings, hashed references, signatures with coverage statements and trust lists, revocation checking, trusted timestamps and long-term validation strategy are modelled. Non-hashable evidence uses declared substitutes (seals plus custody)." }, { "dimension": "strength and sufficiency", "status": "covered", "notes": "Scheme-qualified certainty grading with rating domains, separation of certainty from recommendation strength, sufficiency standards with thresholds and burdens, and recorded overrides where a decision proceeds on insufficient support." }, { "dimension": "defeasibility and counter-evidence", "status": "covered", "notes": "Defeaters are typed and linked to the specific element attacked; adjudication, residual conflict and selective-reporting controls are modelled, and counter-evidence retention is a stated policy rather than an option." }, { "dimension": "spatial", "status": "covered", "notes": "Covered narrowly and deliberately: collection location and conditions are recorded on acquisition, and selectors provide location within a source. No geospatial geometry is modelled; where the location of an event is itself the fact in issue, that belongs to the host claim or a geospatial sibling model." }, { "dimension": "quantitative uncertainty", "status": "gap", "notes": "Uncertainty is carried as a quantity with a declared basis, but no metrological standard (for example a guide to expression of uncertainty in measurement, or a vocabulary of metrology) was consulted in this research. The representation of uncertainty is therefore unsupported by primary source here and must be settled against the measurement sibling model before operational use." }, { "dimension": "cross-scheme comparability", "status": "gap", "notes": "No cited source supports mapping a certainty level from one grading scheme onto another, or onto a legal standard of proof. The model requires a mapping authority to be named for any such mapping, and otherwise treats levels as scheme-local and incomparable." } ], "known_omissions": [ "Clause-level requirements of ISO/IEC/IEEE 15026-2:2022, ISO/IEC/IEEE 42010:2022 and ISO/IEC 27037:2012 were taken from official catalogue abstracts and standards-body summaries, not from the paywalled normative texts; specific clause numbers and mandatory wording must be confirmed before any conformance claim.", "The OMG SACM 2.3 metamodel element names (Claim, ArgumentReasoning, ArtifactReference, AssertedInference, AssertedEvidence, AssertedContext and the Artifact metamodel classes) were not verified against the normative PDF; only the specification landing page and its definition of an assurance case were retrieved. Structure derived from SACM is expressed generically rather than by SACM class name.", "Dialogue and argumentation protocols — burden shifting within a dialogue, commitment stores, turn taking — are not modelled; only the resulting argument structure is.", "Evidence synthesis statistics (meta-analysis, pooling, effect-size estimation, heterogeneity measures) are excluded; the model records a certainty judgement, not the computation behind it.", "Trust and reputation scoring of sources and agents is excluded; independence and interest declarations are recorded, but no score is computed.", "Machine-learning explanation artefacts (feature attributions, counterfactuals, saliency) are not modelled as a distinct evidence form, although they would be registered as computational evidence.", "Consent chains for testimonial and human-subject evidence are covered only through the personal-data flags and GDPR-derived constraints, not through a consent model.", "Cost, effort and timeliness of obtaining further evidence — inputs to a real sufficiency decision — are not modelled.", "Cryptographic key management, certificate issuance and trust-list curation are referenced but deliberately not specified.", "No primary Toulmin, IBIS, QOC or Argument Interchange Format schema was fetched; argument-graph interchange is therefore a gap rather than a canonical layer.", "ISO/IEC 27042 analysis, ISO/IEC 27043 process architecture and ISO/IEC 17025 laboratory competence were not incorporated as fetched primaries.", "Federal Rules 403, 702, 801-807 and 902, and non-US evidence codes, are not modelled; prejudice, expert qualification, hearsay and self-authentication remain legal-sibling concerns.", "EDRM e-discovery, CASE/UCO cyber-investigation ontology, STIX opinion/sighting and OMG DMN knowledge sources were not fetched as primaries.", "Bayesian likelihood ratios, evidence of absence, and statistical sampling designs as first-class objects are omitted.", "Oral testimony capture, real-time live-video evidence beyond C2PA live-video clauses, and AI-generated-content admissibility tests are emerging and under-specified here.", "Privilege, work-product and classified-information doctrines lack a single global primary and are represented only as access exceptions." ], "conflicts": [ "The word 'evidence' is overloaded across the cited sources: in VC-DM 2.0 it is information about how an issuer verified claims before issuance; in SACM and 15026-2 it is the artefact base supporting a structured argument; in ISO/IEC 27037 it is data with potential probative value in legal proceedings. The model keeps these as distinct roles and does not assume a single semantics.", "'Primary source' is used in three incompatible ways: PROV's hadPrimarySource means an entity produced by an agent with direct experience; bibliographic practice means an original rather than derivative publication; GRADE's 'primary study' means an original study rather than a synthesis. The model records source-tier separately from the PROV relation and requires the assessor to be named.", "Certainty scales are not commensurable. GRADE's four-level certainty, assurance-case confidence, and legal standards of proof rest on different foundations, and no cited source licenses a mapping between them. The model refuses to store a scheme-free level.", "Append-only, tamper-evident evidence conflicts with the GDPR right to erasure. Article 17(3)(e) exempts retention necessary for the establishment, exercise or defence of legal claims, but that exemption is purpose-bound and does not license indefinite retention of all evidence; the conflict is real and is handled per-record by a recorded rule rather than by a blanket policy.", "Digest-based binding assumes immutable artefacts, while selector-based anchoring addresses mutable web resources. A single 'anchor' abstraction cannot satisfy both, so the model requires the binding mode to be declared and records anchor drift explicitly.", "RFC 3339's -00:00 (UTC known, local offset unknown) is semantically distinct from Z and +00:00, yet widespread tooling normalises them together. The model forbids that normalisation, which will conflict with some storage layers.", "A retention floor (at least six months for certain automatically generated logs) and a storage-limitation cap can point in opposite directions for the same record; neither instrument resolves the other, so the model requires the resolution rule to be recorded per record.", "FRE relevance is a low relational bar and is not the same as GRADE certainty of a body of evidence or FHIR statistical quality.", "W3C Verifiable Credentials treat evidence as supporting information and treat proofs as a different mechanism; collapsing them would contradict SRC-003.", "C2PA forbids value judgments about whether provenance is good or bad, while GRADE and legal triers must make graded or admissibility judgments.", "NIST SP 800-86 is explicitly an IT and incident-response view, not a law-enforcement forensic standard, and must not be cited as courtroom procedure.", "ISO/IEC 27037 addresses potential digital evidence handling, not scientific evidence synthesis or credential issuance.", "US FRE alignments do not travel as global law; treating them as universal would be a false conformance claim." ], "regional_assumptions": [ "The six-month retention floor for automatically generated logs derives from EU law applying to high-risk AI systems and was read from a secondary rendering of Article 19; it does not apply outside that scope and must be re-verified against the Official Journal text.", "Erasure, storage-limitation, accuracy and accountability constraints assume EU/EEA personal-data scope; other regimes impose different and sometimes stricter or looser obligations.", "Authentication examples and the sufficiency framing drawn from Rule 901 are United States federal practice. Civil-law jurisdictions generally apply free evaluation of evidence without an equivalent authentication threshold, so sufficiency-standard codes must be jurisdiction-qualified.", "The legal effect of a trusted timestamp is assumed to require a jurisdiction-specific framework (for example a qualified trust service regime); RFC 3161 alone establishes a technical, not a legal, proof of time.", "Certainty grading practice drawn from GRADE originates in health-care guideline development; its transfer to engineering, legal or operational evidence is by analogy and is not endorsed by the cited source.", "Language and script handling assumes excerpts carry a language tag; no standard for tagging was verified in this research, and multilingual evidence with mixed scripts may need Dimension-specific rules.", "Legal relevance and authentication examples use United States Federal Rules of Evidence as published via LII; other jurisdictions need local mapping.", "GRADE is globally used in health guidelines but remains health-originated; non-health decisions must not assume GRADE categories without a documented profile.", "ISO/IEC 27037:2012 remains current after 2018 confirmation but is under review; device examples include obsolete media classes that adopting Dimensions should extend.", "Privacy minimization follows W3C VC privacy considerations and C2PA creator-control guidance, not a specific GDPR or sectoral statute." ], "adversarial_checks": [ "Attempted to absorb the source/bibliographic record into this mixin so that citations would be self-contained. Rejected: Web Annotation separates Target from the Specific Resource plus Selector, and duplicating catalogue metadata here would create a second, drifting description of a source the Dimension does not own. The model keeps only locator, selector, captured state and citation intent.", "Attempted to expose a single scheme-free confidence number for ease of ranking. Rejected: GRADE levels are defined only relative to explicit rating domains, and no cited source supports a scheme-independent scalar or a cross-scheme mapping. The model makes the scheme identifier mandatory alongside the level and marks comparability as a gap.", "Attempted to use the acquisition timestamp as the evidence identifier for append-only logs. Rejected under the identity rule that a date is not an identifier, and because in-toto matches subjects purely by digest; timestamps are retained as attributes, never as keys.", "Searched for counterexamples where evidence has no source anchor — direct sensor readings, live testimony, physical exhibits. Found several, so anchoring is optional and an anchor-absent reason plus acquisition metadata is required instead. A model that mandated selectors would have been unusable for observational and physical evidence.", "Tested whether rationale collapses into evidence, which would have removed a whole layer. Rejected: 15026-2 treats inference as a reasoning step whose validity is expressed as a justification, with confidence depending on both the inference and the premises, so a support record can legitimately exist with zero evidence items. The model therefore keeps warrant separate and requires assumption-only support to be flagged.", "Tested whether cryptographic integrity could be made mandatory across all evidence. Rejected: testimonial and physical evidence cannot be hash-bound, so integrity is per-item and mode-dependent, with declared non-cryptographic substitutes (tamper-evident seals plus custody records) drawn from digital-evidence handling practice.", "Considered claiming conformance to PROV-O and SACM to strengthen the model's standing. Rejected: no conformance testing was performed and the SACM normative text was not retrievable, so all external relationships are recorded as alignments with version and loss noted, and conformance claims require a resolvable evidence reference.", "Checked whether a passing verification could be presented as validating the claim, which is the most likely misuse of this model in production. VC-DM 2.0 states explicitly that verification does not imply evaluation of the truth of claims, so a policy forbidding that presentation was added rather than left implicit.", "Would a cryptographic proof or C2PA valid state be stored as the evidence itself? If yes, the model is being misused against SRC-003 and SRC-008.", "Would a GRADE high rating be treated as legal admissibility or as authentication under Rule 901? If yes, domain conflict is being ignored.", "Would a date, hash or exhibit nickname be used as the record identifier? If yes, identity priority is violated.", "Would this mixin replace WM-KNW-008 Knowledge or a general provenance graph? If yes, the mixin boundary has been breached.", "Would silent overwrite of a certainty rating or custody event be allowed? If yes, patch and integrity rules have failed.", "Would depicted-event truth be inferred from content credentials? If yes, C2PA scope is being exceeded.", "Would Toulmin or AIF structures be required as canonical without a fetched primary? If yes, a gap is being presented as standard." ] }, "researchAdjudication": { "providerMode": "dual-provider", "activeProviders": [ "claude", "grok" ], "waivedProviders": [], "providerPolicy": {}, "boundaryDecision": { "entry_kind": "mixin", "status": "accepted", "rationale": "Both providers independently converge on mixin, and both keep the host proposition, the source/bibliographic record, the agent registry and general provenance outside the model. Claude's boundary is the operative one: eight neighbour distinctions each carry a source-backed criterion (host claim vs support apparatus, locator+selector vs catalogue metadata, PROV entities vs asserted support, VC issuance vs evidence item, log subsystem vs custody facts, forensic case vs custody/integrity facts, decision act vs rationale, measurement semantics vs appraised observation). One narrowing is recorded with the accepted statistic finding: reported statistics and their precision qualifiers may be carried as support attributes, while synthesis computation (meta-analysis, pooling, effect-size estimation, study design) remains out of scope." }, "decisions": [ { "concept": "Base provider selection", "disposition": "Accept Claude as base", "rationale": "Claude's boundaries are the more completely closed set: explicit in-scope and out-of-scope lists, eight source-backed neighbour distinctions, and layer-level inline_only_rationale for every non-materialising finding. Grok's larger size advantage does not exist here, and its bundle seams (relevance/certainty split from rationale/inference) leave custody, anchoring and verification less separable." }, { "concept": "Entry kind", "disposition": "Confirm mixin", "rationale": "Both providers independently declare mixin and both exclude the host proposition, so the attachable-support framing is settled without adjudication." }, { "concept": "Relevance as a relational test (FRE 401)", "disposition": "Accept into support-binding", "rationale": "Materially missing from the base, which conflates the relation type with the probative question. Tier-1 primary backing, and it repairs a real failure mode where an item is graded certain yet directed at no fact of consequence." }, { "concept": "Reported statistic and precision qualifiers (FHIR Evidence)", "disposition": "Accept into quality-appraisal, scope-narrowed", "rationale": "Fills a gap the base itself declares as unsupported by primary source, with tier-1 backing. Narrowed to recording statistics carried as support so the base exclusion of meta-analysis, pooling and effect-size estimation survives intact." }, { "concept": "Authentication foundation (FRE 901 methods)", "disposition": "Accept into verification-and-reproducibility", "rationale": "Base treats authentication only through cryptographic binding and an acquisition-validity question, leaving non-hashable evidence without a first-class foundation. Grok's finding is tier-1 backed and preserves the authentication-versus-admissibility separation." }, { "concept": "Evidence-to-Decision criterion judgments (GRADE EtD)", "disposition": "Defer", "rationale": "Overlaps the base separation of certainty from recommendation strength and the base rejected-alternatives finding, and the criterion catalogue is health-originated. The decision act and its criteria belong to the sibling decision model; revisit only with a documented non-health profile." }, { "concept": "Evidence record identity and business version (grok evidence-record-identity)", "disposition": "Reject as duplicative", "rationale": "Base already separates the identifier of the item from the identifier of the record describing it, states identifier precedence in artifact rules, and forbids dates as identifiers. Adding a second identity finding would create two competing identity statements for one record." }, { "concept": "Custody chronology (grok chain-of-custody)", "disposition": "Reject as duplicative", "rationale": "Base chain-of-custody-and-handling is strictly broader: it adds gap detection over intervals, custody modes, transfer-time integrity verification and the retention period of the custody record itself." }, { "concept": "Access, privilege and data minimisation (grok access-privilege-disclosure)", "disposition": "Reject as duplicative", "rationale": "Base access-classification-and-redaction covers classification, existence-versus-content disclosure, privilege claims, reversible redaction and personal-data minimisation, with GDPR and NIST backing rather than annotation-rights backing." }, { "concept": "Related artifacts, citations and selectors (grok related-artifacts-and-selectors)", "disposition": "Reject as duplicative", "rationale": "Split across two stronger base findings: source-anchor-and-locator carries selector type, captured state and drift detection, and standards-alignment-and-exchange carries alignment-not-conformance and packaging." }, { "concept": "Handling stages and alteration minimisation (grok handling-process layer)", "disposition": "Reject as covered", "rationale": "Base acquisition-method-and-instrument already asks which of identification, collection, acquisition or preservation applied, with tool version, operator competence and process validity; the residual alteration-minimisation wording is a question-level nuance, not a missing finding." }, { "concept": "Rationale narrative and motivation (grok rationale-narrative-and-motivation)", "disposition": "Reject as covered", "rationale": "Base inference-warrant-and-scheme plus the decision-rationale-record artifact carry the reasoning, its scheme, defeasibility and the no-evidence case; motivation alone does not justify a parallel finding in the same layer." }, { "concept": "C2PA specification version divergence (2.2 versus 2.4)", "disposition": "Hold, not a conflict", "rationale": "Both providers cite C2PA as a primary and neither derives a contradictory requirement from it; this is a version-pin question for the synthesiser to resolve against the live specification before publication." }, { "concept": "NIST SP 800-86 (grok-only source)", "disposition": "Do not add", "rationale": "No accepted finding depends on it, and grok itself warns it is an incident-response view that must not be cited as courtroom procedure. Recorded as deferred research for the forensic-handling profile instead." }, { "concept": "Service layers", "disposition": "Merge", "rationale": "Both providers place governance, access, retention, lifecycle and interoperability in a single service surface; merging avoids two divergent statements of record state and access policy." } ], "publicationHolds": [ "Source verification incomplete: re-resolve every accepted source URL and pin its live version before publication, including the C2PA divergence (base cites 2.2, the accepted grok findings sit alongside a 2.4 citation), the CiTO version-versus-modified date, and the two newly relied-on grok sources (FHIR R5 Evidence, FRE 401).", "Paywalled and unretrieved normative texts: ISO/IEC/IEEE 15026-2:2022, ISO/IEC/IEEE 42010:2022 and ISO/IEC 27037:2012 were read from catalogue abstracts, and the OMG SACM 2.3 normative PDF was never retrieved. Publish alignment language only; no clause numbers, no metamodel class names and no conformance claims until the normative texts are confirmed.", "EU AI Act Article 19 six-month log-retention floor was read from a secondary rendering (Future of Life Institute AI Act Explorer). Re-verify against the Official Journal text of Regulation (EU) 2024/1689 before the floor is stated as a requirement.", "Multi-profile validation not complete: the model must be exercised against at least the legal-evidence profile (US FRE 401/901, jurisdiction-qualified), the health/guideline profile (GRADE plus FHIR Evidence statistics), the engineering-assurance profile (SACM, 15026-2) and the content-provenance profile (C2PA, in-toto). GRADE categories and FRE tests must not travel as global defaults.", "The accepted quantitative-statistic finding must be reconciled with the sibling Quantity/Unit and Measurement models before operational use, so that unit, interval and uncertainty semantics are stated once and referenced, not duplicated inside the support record.", "Confirm that the accepted authentication-foundation finding does not silently import US admissibility doctrine: authentication must remain a recorded foundation, never a ruling, and the exclusionary bars (hearsay, privilege, prejudice) stay with the legal sibling model." ], "deferredResearch": [ "Metrological representation of uncertainty: no GUM/VIM-class primary was consulted by either provider, so the internal representation of measurement error, intervals and coverage factors remains unsupported and must be settled against the measurement sibling model.", "Cross-scheme certainty comparability: no cited source licenses mapping a GRADE level onto assurance-case confidence or onto a legal standard of proof. Levels stay scheme-local until a mapping authority with primary backing is identified.", "Argument interchange formats (Toulmin, IBIS, QOC, AIF): neither provider fetched a primary, so the warrant layer is expressed generically and any canonical argument-graph serialisation is unresearched.", "Wider legal-evidence surface: FRE 403, 702, 801-807 and 902, plus at least one civil-law evidence code, to qualify authentication, sufficiency and expert-evidence framing outside US federal practice.", "Forensic-handling interoperability: ISO/IEC 27042, ISO/IEC 27043, ISO/IEC 17025, NIST SP 800-86, and the CASE/UCO and EDRM vocabularies, to test whether the custody and handling findings exchange cleanly with investigation tooling.", "OMG SACM 2.3 normative element names and ISO/IEC/IEEE 15026-2 clause structure, needed before any structural claim is attributed to those specifications by name.", "Consent and testimonial-capture chains for human-subject and oral evidence, currently reachable only through personal-data flags rather than a consent model." ] }, "statistics": { "sources": 23, "bundles": 6, "layers": 14, "findings": 33, "questions": 157, "artifacts": 23, "functions": 15 } }