Notification / Subscription
Describe host-attached event interests, subscription control evidence and delivery preferences with explicit authority and channel limits.
Bundle → Layer → Finding → Questions Filled
3 bundles · 3 layers · 5 findings · 10 questions
Subscription Who wants to know what.
Interest and filter
The subscriber, the event class and filters.
Subscriber and topic
Who subscribed to which events.
- Who is the subscriber, and which topic or event class did they subscribe to?
- Which filter narrows the events, such as location, severity or subject?
Consent basis
The consent or entitlement behind the subscription.
- Did the subscriber opt in, and when and how was consent recorded?
- Is the subscriber entitled to see the events covered?
Delivery How notifications reach the subscriber.
Channel and preferences
Channels, frequency and quiet hours.
Channel
The endpoint used for delivery.
- Which channel and endpoint deliver the notifications?
- Is the endpoint verified and still reachable?
Preferences
Frequency, batching, language and quiet hours.
- Should notifications be immediate or batched into digests?
- Which quiet hours and language preferences apply?
Lifecycle How the subscription starts and ends.
Status and expiry
Active, paused, expired or cancelled.
Subscription status
The state of the subscription and how to end it.
- Is the subscription active, paused or expired?
- How can the subscriber unsubscribe, and is it honoured at once?
Classifiers Filled
- Family
- World Models
- Category
- Cross-cutting context
- Entry kind
- mixin
- Navigation path
- NAV.XCT.NTF
- Domain
- XCT.NTF
- Industry
- Cross-industry
- Tags
- notificationsubscriptionxct.ntf
What it is Filled
A notification subscription is a standing record that a party wants to be told about a class of events, with a filter, a delivery channel and preferences such as frequency and quiet hours. It governs which notifications are sent and how; the events themselves and the messages delivered are separate subjects, and so is a paid service subscription.
In scope
- Host attachment and local interest identity, subscriber and receiver references.
- Event selection parameters, channel preferences, timing, urgency and withdrawal intent.
- Evidence of confirmed subscription state, delivery limits, profile mappings and record governance.
Out of scope
- Paid service subscriptions, billing, entitlement products and contract lifecycle.
- Event truth, event registers, message payload lifecycle and recipient identity masters.
- Network dispatch, subscription protocol execution, matching engines, scheduling, deduplication, replay, retries and enforcement.
- Generic consent adjudication, legal service of notices, safety-critical alert certification and audit-trail implementation.
Why it exists Filled
Describe host-attached event interests, subscription control evidence and delivery preferences with explicit authority and channel limits.
Distinguishing features Filled
- It is a standing interest, separate from the events it matches and the messages it causes.
- Delivery preferences belong to the subscriber, not to the publisher of events.
- It depends on consent or entitlement and must be easy to end.
- Distinct from a commercial subscription, which is a paid service agreement.
What robots and AI may and may not do Filled
Must not
- Subscribe a person without their consent.
- Ignore or delay an unsubscribe request.
- Send notifications about events the subscriber is not entitled to see.
- Use a notification channel for unrelated marketing.
- Share subscriber endpoints with third parties.
Only with a human decision
- Subscribing on behalf of another person.
- Overriding quiet hours outside emergencies defined in policy.
- Changing the consent basis of existing subscriptions.
May
- Create subscriptions the user asks for and confirm them.
- Deliver notifications according to the subscriber's channel and preferences.
- Batch or suppress notifications in quiet hours as set.
- Remind users of active subscriptions and how to end them.
Moral aspects Filled
- Unwanted notifications are intrusive and can amount to spam or harassment.
- Alert fatigue causes important warnings to be missed.
- Subscription data reveals interests, locations and habits.
Who is affected
- Subscribers
- Publishers of events
- People named in notified events
Owners Filled
Steward
The subscriber controls the subscription; the operator of the notification service keeps the record and honours it.
Roles
- Dimension steward
- Own the profile, namespace and risk acceptance; approve schema and semantic migrations.
- Subscriber or authorized delegate
- Express scoped preferences and withdrawal intent within evidenced authority.
- Notification record custodian
- Maintain revisions, evidence references and restricted access; never infer remote state from intent.
- Channel operator
- Own endpoint verification, dispatch, retries and receipt semantics in the external delivery service.
- Privacy and access reviewer
- Review data minimization, permission scope, disclosure and retention exceptions.
- Conformance reviewer
- Assess binding loss, fixtures, failures and unsupported protocol features.
Master systems
- Notification service
- Consent and preference management system
Links to other meta-models Filled
references
- WM-REC-003 - Candidate optional Message binding: notification payloads, message identity and message lifecycle stay message-owned.
- WM-ACT-015 - Candidate optional Occurrence / Event binding: point to triggering facts without reproducing event identity or lifecycle.
- WM-XCT-002 - Candidate optional Access Contract / Consent binding: retain scoped authority references, never infer entitlement or legal consent from a subscription.
- WM-PER-014 - Candidate optional Preference / Personal Profile binding: use only selected notification preferences and preserve general profile ownership.
- WM-KNW-013 - Candidate optional rule binding: pin selector or precedence rule and operands; evaluator execution and generic rule lifecycle remain external.
- WM-XCT-004 - Candidate optional Access Audit binding: reference access evidence without implementing or redefining an audit trail.
- wm-rec-003-message - Notifications are delivered as messages.
aligned
- WebSub Recommendation 2026-06-02 - Conceptual topic, callback, confirmation and lease mapping; requires independently tested adapter.
- MQTT Version 5.0 - Conceptual topic-filter and subscription-option mapping; no end-to-end exactly-once guarantee.
- RFC 8639 - Optional configured or dynamic notification subscription profile; network-management rules are not universal.
- RFC 8030 and Push API Working Draft 2026-10-05 - Optional web push profile with protected endpoint and permission evidence; draft API support is not assumed.
- RFC 8058 - Optional one-click email withdrawal profile, distinct from arbitrary link retrieval and other channel methods.
- CloudEvents v1.0.2 - Event envelope references and correlation only; source plus event id is scoped identity, not a delivery contract.
neighbor
- WM-REC-003 - Candidate optional Message binding: notification payloads, message identity and message lifecycle stay message-owned.
- WM-ACT-015 - Candidate optional Occurrence / Event binding: point to triggering facts without reproducing event identity or lifecycle.
- WM-XCT-002 - Candidate optional Access Contract / Consent binding: retain scoped authority references, never infer entitlement or legal consent from a subscription.
- WM-PER-014 - Candidate optional Preference / Personal Profile binding: use only selected notification preferences and preserve general profile ownership.
- WM-KNW-013 - Candidate optional rule binding: pin selector or precedence rule and operands; evaluator execution and generic rule lifecycle remain external.
- WM-XCT-004 - Candidate optional Access Audit binding: reference access evidence without implementing or redefining an audit trail.
- Mixin versus standalone subscription entity - The registry mixin classification is retained. Local interest entries have keys only within a host attachment; independently managed transport subscriptions are referenced entities, not a new root owned by this mixin.
requires
- wm-xct-002-access-contract-consent - Subscriptions rest on consent or entitlement.
related
- wm-per-014-preference-personal-profile - Delivery preferences are part of a personal profile.
What else AI and robots need to interact with it Filled
Identity and identifiers required Filled
- A subscription is identified by an identifier issued by the notification service, linked to the subscriber and topic identifiers.
Direct properties not applicable Not applicable
Not applicable
A notification subscription is an information or software construct; its measurable attributes are configuration and operational data, not physical properties.
Recognition optional Filled
- A subscription names a subscriber, a topic or filter, a channel and a status.
- Often confused with a message, an event or a paid service subscription.
Capabilities and actions required Filled
- Subscriptions can be created, confirmed, paused, modified, expired and cancelled.
- Matching events trigger deliveries according to preferences.
Hazards and failure modes required Filled
- Missed critical alerts due to wrong preferences or dead endpoints.
- Notification floods and alert fatigue.
- Leakage of sensitive event content to lock screens or shared devices.
Standards and interfaces required Filled
- W3C WebSub for web publish and subscribe.
- IETF RFC 8030 Generic Event Delivery Using HTTP Push and the W3C Push API.
- CloudEvents for describing event data.
Context of use required Filled
- Used in apps, public alerting, monitoring and business systems.
- Consent for electronic notifications is regulated by privacy and electronic communications law.
Sources Filled
- WebSub - World Wide Web Consortium
- RFC 8030: Generic Event Delivery Using HTTP Push - Internet Engineering Task Force
- MQTT Version 5.0 - OASIS
- RFC 8639: Subscription to YANG Notifications - Internet Engineering Task Force
- RFC 8058: Signaling One-Click Functionality for List Email Headers - Internet Engineering Task Force
- Push API - World Wide Web Consortium
- Web Content Accessibility Guidelines (WCAG) 2.2 - World Wide Web Consortium
- RFC 5545: Internet Calendaring and Scheduling Core Object Specification (iCalendar) - Internet Engineering Task Force
- CloudEvents specification - Cloud Native Computing Foundation
- WebSub (W3C)
- CloudEvents specification (Cloud Native Computing Foundation)
Open questions
- Restore independent external review and resolve all source version, errata and applicability questions before canonical promotion.
- Build profile-specific schemas and fixtures for activation and withdrawal races, endpoint rotation, civil-time ambiguity, replay gaps, shared subscriptions and duplicate delivery.
- Obtain qualified adoption review for mandatory notices, privacy, communications law, emergency overrides, accessibility and retention without universalizing one protocol's rules.
- No independent second-provider review; local self-audit cannot replace it.
- No executable instance schemas, matching engine, scheduler, protocol adapter or tested conformance fixtures.
- Direct HTTP checks were not attempted because the owner reports sandbox blocking; no measured HTTP status or body digest is available. Browser retrieval is documented separately.
- No legal, jurisdictional, channel-specific marketing or safety-critical emergency compliance conclusion.
- Quiet-hour precedence, batching, multi-device behavior, shared subscriptions and mandatory notices need adoption-specific profiles.
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-xct-030-notification-subscription/spec.yaml, ver-cy/world-models/card-supplements/wm-xct-030-notification-subscription.json