# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T12:43:54Z", "synthesisSha256": "a3a885cd9cf0b6995eb49199034b7ff287bfc3401140954024f013e836367ea7", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-030", "registryId": "vr.wm-xct-030", "name": "Notification / Subscription", "version": "0.1.0", "previousVersions": [], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.NTF" ], "tags": [ "notification", "subscription", "xct.ntf" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-030-notification-subscription/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-030", "model": { "registry_id": "vr.wm-xct-030", "model_id": "WM-XCT-030", "name": "Notification / Subscription", "entry_kind": "mixin", "purpose": "Describe host-attached event interests, subscription control evidence and delivery preferences with explicit authority and channel limits.", "scope_statement": "A reusable information mixin attached to an identified host. Each interest entry carries scoped identity, selection and preference configuration, plus references to subscription and delivery evidence. It does not itself operate a notification service.", "in_scope": [ "Host attachment and local interest identity, subscriber and receiver references.", "Event selection parameters, channel preferences, timing, urgency and withdrawal intent.", "Evidence of confirmed subscription state, delivery limits, profile mappings and record governance." ], "out_of_scope": [ "Paid service subscriptions, billing, entitlement products and contract lifecycle.", "Event truth, event registers, message payload lifecycle and recipient identity masters.", "Network dispatch, subscription protocol execution, matching engines, scheduling, deduplication, replay, retries and enforcement.", "Generic consent adjudication, legal service of notices, safety-critical alert certification and audit-trail implementation." ], "boundary_notes": [ { "neighbor": "WM-REC-003", "distinction": "Candidate optional Message binding: notification payloads, message identity and message lifecycle stay message-owned.", "source_refs": [ "SRC-002", "SRC-009" ] }, { "neighbor": "WM-ACT-015", "distinction": "Candidate optional Occurrence / Event binding: point to triggering facts without reproducing event identity or lifecycle.", "source_refs": [ "SRC-004", "SRC-009" ] }, { "neighbor": "WM-XCT-002", "distinction": "Candidate optional Access Contract / Consent binding: retain scoped authority references, never infer entitlement or legal consent from a subscription.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "neighbor": "WM-PER-014", "distinction": "Candidate optional Preference / Personal Profile binding: use only selected notification preferences and preserve general profile ownership.", "source_refs": [ "SRC-006", "SRC-007" ] }, { "neighbor": "WM-KNW-013", "distinction": "Candidate optional rule binding: pin selector or precedence rule and operands; evaluator execution and generic rule lifecycle remain external.", "source_refs": [ "SRC-003", "SRC-004" ] }, { "neighbor": "WM-XCT-004", "distinction": "Candidate optional Access Audit binding: reference access evidence without implementing or redefining an audit trail.", "source_refs": [ "SRC-004", "SRC-006" ] }, { "neighbor": "Mixin versus standalone subscription entity", "distinction": "The registry mixin classification is retained. Local interest entries have keys only within a host attachment; independently managed transport subscriptions are referenced entities, not a new root owned by this mixin.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ] }, "sources": [ { "id": "SRC-001", "title": "WebSub", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/2026/REC-websub-20260602/", "version_or_date": "Recommendation 2026-06-02", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Sections 1, 5, 7 and 8: subscription identity, verified intent, leases and distribution security." }, { "id": "SRC-002", "title": "RFC 8030: Generic Event Delivery Using HTTP Push", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc8030", "version_or_date": "RFC 8030, December 2016", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Sections 4-8: transport resources, TTL, urgency, replacement, receipts and endpoint privacy." }, { "id": "SRC-003", "title": "MQTT Version 5.0", "organization": "OASIS", "url": "https://docs.oasis-open.org/mqtt/mqtt/v5.0/os/mqtt-v5.0-os.html", "version_or_date": "OASIS Standard, 7 March 2019", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Sections 3.8, 4.6 and 4.7: subscription options, ordering and topic filters; protocol-specific alignment only." }, { "id": "SRC-004", "title": "RFC 8639: Subscription to YANG Notifications", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc8639", "version_or_date": "RFC 8639, September 2019", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Sections 2-4 and 7: configured and dynamic subscriptions, filters, replay, state changes and authorization." }, { "id": "SRC-005", "title": "RFC 8058: Signaling One-Click Functionality for List Email Headers", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc8058", "version_or_date": "RFC 8058, January 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Sections 1, 3 and 6: authenticated one-click unsubscribe profile and distinction from link prefetch." }, { "id": "SRC-006", "title": "Push API", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/2026/WD-push-api-20261005/", "version_or_date": "Working Draft 2026-10-05; unstable, not a Recommendation", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Sections 3.4-4 and 7: push subscription, permission, endpoint refresh and deactivation. Draft evidence only." }, { "id": "SRC-007", "title": "Web Content Accessibility Guidelines (WCAG) 2.2", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/2024/REC-WCAG22-20241212/", "version_or_date": "Recommendation 2024-12-12", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Success criterion 2.2.4, level AAA: user control of interruptions with an emergency exception. Does not define a notification scheduler." }, { "id": "SRC-008", "title": "RFC 5545: Internet Calendaring and Scheduling Core Object Specification (iCalendar)", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc5545", "version_or_date": "RFC 5545, September 2009", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Sections 3.2.19 and 3.3.5: timezone references and local date-time semantics; alignment for proposed quiet-window profiles." }, { "id": "SRC-009", "title": "CloudEvents specification", "organization": "Cloud Native Computing Foundation", "url": "https://raw.githubusercontent.com/cloudevents/spec/v1.0.2/cloudevents/spec.md", "version_or_date": "Repository release v1.0.2; wire specversion 1.0", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:42:32Z", "relevance": "Context attributes id, source, type, subject, time and dataschema: event references and correlation, not delivery guarantees." } ], "structure": { "bundles": [ { "id": "bundle-interest", "name": "Interest attachment and authority", "description": "Identify the host-attached interest and the basis for managing it.", "rationale": "Proposed reusable context concern for host-attached notification interests, preserving subject and execution boundaries.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "layers": [ { "id": "layer-attachment", "name": "Host attachment and scoped identity", "description": "Context for host attachment and scoped identity. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "findings": [ { "id": "finding-attachment", "name": "Host attachment and scoped identity", "description": "Proposed mixin attachment to a host with zero or more interest entries. Keep host, local entry and transport subscription keys distinct; endpoint replacement need not replace the host preference.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "questions": [ { "id": "question-attachment-1", "text": "Which host and authoritative namespace identify this notification-interest entry?", "kind": "identity", "answer_data": [ "host_ref", "entry_id", "master_namespace" ] }, { "id": "question-attachment-2", "text": "Is the entry a human preference, a program subscription or a configured organizational interest?", "kind": "classification", "answer_data": [ "subscriber_kind", "profile_ref" ] }, { "id": "question-attachment-3", "text": "Which subscriber and receiver identities are bound here, and can they differ?", "kind": "relationship", "answer_data": [ "subscriber_ref", "receiver_refs", "delegation_ref" ] }, { "id": "question-attachment-4", "text": "What evidence distinguishes a continuing local interest from a new transport subscription?", "kind": "validation", "answer_data": [ "binding_history", "continuity_decision", "transport_ids" ] } ], "data_elements": [ { "id": "data-attachment-entry-id", "name": "entry-id", "description": "Host-scoped stable key, resolved with the master namespace.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "data-attachment-binding-history", "name": "binding-history", "description": "Versioned local-to-transport mappings; endpoint URLs are sensitive references, not universal identity.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-attachment", "name": "Attachment and binding record", "description": "Proposed governed evidence projection for host attachment and scoped identity. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-authority", "name": "Intent, permission and content entitlement", "description": "Context for intent, permission and content entitlement. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "findings": [ { "id": "finding-authority", "name": "Intent, permission and content entitlement", "description": "Record separate evidence for requesting notifications, controlling a receiver and accessing event content. An opt-in or browser permission cannot by itself establish every authorization or legal basis.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "questions": [ { "id": "question-authority-1", "text": "Who may create or change this interest on behalf of the subscriber?", "kind": "authority", "answer_data": [ "actor_ref", "delegation_ref", "authority_evidence" ] }, { "id": "question-authority-2", "text": "Which intent confirmation applies to this exact receiver and requested scope?", "kind": "evidence", "answer_data": [ "confirmation_ref", "confirmed_scope", "confirmed_at" ] }, { "id": "question-authority-3", "text": "Which external authorization decision permits the receiver to see the selected event content?", "kind": "access", "answer_data": [ "access_decision_ref", "policy_revision", "decision_expiry" ] }, { "id": "question-authority-4", "text": "How is an administratively configured interest distinguished from a voluntary user preference?", "kind": "exception", "answer_data": [ "creation_basis", "profile_authority", "user_control_limits" ] } ], "data_elements": [ { "id": "data-authority-authority-links", "name": "authority-links", "description": "References to scoped intent, delegation and access evidence; legal interpretation remains external.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "data-authority-permission-state", "name": "permission-state", "description": "Observed channel permission with observation time and origin scope.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-authority", "name": "Authority binding assessment", "description": "Proposed governed evidence projection for intent, permission and content entitlement. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-selection", "name": "Event selection contract", "description": "Express what is selected without owning event facts or the matching engine.", "rationale": "Proposed reusable context concern for host-attached notification interests, preserving subject and execution boundaries.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "layers": [ { "id": "layer-event-scope", "name": "Event vocabulary and subject scope", "description": "Context for event vocabulary and subject scope. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "findings": [ { "id": "finding-event-scope", "name": "Event vocabulary and subject scope", "description": "Bind the interest to a publisher namespace, event class or stream and a pinned schema. Event facts remain in their master; a notification can summarize or reference them without becoming the occurrence.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "questions": [ { "id": "question-event-scope-1", "text": "Which event vocabulary defines what this interest can select?", "kind": "definition", "answer_data": [ "vocabulary_ref", "vocabulary_revision", "event_types" ] }, { "id": "question-event-scope-2", "text": "Which source, stream and subject references delimit the selection scope?", "kind": "composition", "answer_data": [ "source_ref", "stream_ref", "subject_refs" ] }, { "id": "question-event-scope-3", "text": "If location is a filter operand, which spatial reference and disclosure policy govern it?", "kind": "spatial", "answer_data": [ "spatial_operand_ref", "spatial_system_ref", "location_access_ref" ] }, { "id": "question-event-scope-4", "text": "How are unknown event types or incompatible schema revisions handled?", "kind": "interoperability", "answer_data": [ "schema_ref", "unsupported_type_policy", "migration_ref" ] } ], "data_elements": [ { "id": "data-event-scope-scope-binding", "name": "scope-binding", "description": "Source namespace, vocabulary revision and optional subject constraints; not a copy of event payloads.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] }, { "id": "data-event-scope-schema-ref", "name": "schema-ref", "description": "Pinned event schema or declared unknown value.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-event-scope", "name": "Event scope mapping", "description": "Proposed governed evidence projection for event vocabulary and subject scope. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-filter", "name": "Filter expression and matching contract", "description": "Context for filter expression and matching contract. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "findings": [ { "id": "finding-filter", "name": "Filter expression and matching contract", "description": "Store a versioned selector with its language and evaluator reference. Matching and authorization are distinct. Wildcards, absent attributes and shared-group fan-out cannot be silently translated across protocols.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "questions": [ { "id": "question-filter-1", "text": "Which filter language and version interpret the stored selector?", "kind": "requirement", "answer_data": [ "language_ref", "language_version", "expression", "evaluator_ref" ] }, { "id": "question-filter-2", "text": "What is the declared result when a required attribute is absent, malformed or unknown?", "kind": "constraint", "answer_data": [ "missing_value_policy", "invalid_value_policy", "unknown_result_policy" ] }, { "id": "question-filter-3", "text": "Does the binding request per-receiver fan-out, shared-group delivery or suppression of self-originated events?", "kind": "process", "answer_data": [ "fanout_mode", "group_ref", "self_event_policy" ] }, { "id": "question-filter-4", "text": "Which positive and negative examples demonstrate the intended match boundary?", "kind": "quality", "answer_data": [ "fixture_refs", "expected_match_results", "reviewer_ref" ] } ], "data_elements": [ { "id": "data-filter-selector", "name": "selector", "description": "Expression, dialect, revision and evaluator binding; never execute untrusted expressions during inspection.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] }, { "id": "data-filter-filter-fixtures", "name": "filter-fixtures", "description": "References to examples with match, no-match or unknown expectations.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-filter", "name": "Selector review record", "description": "Proposed governed evidence projection for filter expression and matching contract. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-receiver", "name": "Receiver and presentation preferences", "description": "Bind a protected channel and describe supported recipient preferences.", "rationale": "Proposed reusable context concern for host-attached notification interests, preserving subject and execution boundaries.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-channel", "name": "Receiver channel and endpoint binding", "description": "Context for receiver channel and endpoint binding. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "findings": [ { "id": "finding-channel", "name": "Receiver channel and endpoint binding", "description": "Bind delivery preferences to channel capabilities and protected endpoint references. Identity verification and a past successful contact are evidence with a time limit, not proof of permanent reachability.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "questions": [ { "id": "question-channel-1", "text": "Which channel binding maps this interest to a receiver endpoint?", "kind": "relationship", "answer_data": [ "channel_profile", "endpoint_ref", "receiver_ref", "origin_scope" ] }, { "id": "question-channel-2", "text": "Which proof and policy authorize the endpoint without exposing capability URLs or secret material?", "kind": "security", "answer_data": [ "verification_ref", "secret_handle", "endpoint_policy_ref" ] }, { "id": "question-channel-3", "text": "When was reachability last observed and when must that evidence be refreshed?", "kind": "temporal", "answer_data": [ "observed_at", "valid_until", "health_evidence_ref" ] }, { "id": "question-channel-4", "text": "Which authorized fallback applies when the endpoint is unavailable or rotated?", "kind": "exception", "answer_data": [ "fallback_binding_ref", "fallback_authority_ref", "rotation_ref" ] } ], "data_elements": [ { "id": "data-channel-channel-binding", "name": "channel-binding", "description": "Channel profile, private endpoint handle, receiver and origin scope.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] }, { "id": "data-channel-endpoint-observation", "name": "endpoint-observation", "description": "References to dated channel observations; no network probing is a model operation.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-channel", "name": "Protected channel binding record", "description": "Proposed governed evidence projection for receiver channel and endpoint binding. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-presentation", "name": "Presentation and interruption controls", "description": "Context for presentation and interruption controls. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-006", "SRC-007" ], "findings": [ { "id": "finding-presentation", "name": "Presentation and interruption controls", "description": "Proposed human-facing preferences include language, modality and content previews. The channel renderer owns display; the mixin records requested settings and evidence of support. Machine-only profiles may mark these fields inapplicable.", "source_refs": [ "SRC-006", "SRC-007" ], "questions": [ { "id": "question-presentation-1", "text": "Which human-facing or machine-only presentation profile applies?", "kind": "classification", "answer_data": [ "presentation_profile", "applicability_reason" ] }, { "id": "question-presentation-2", "text": "Which language, modality and assistive presentation preferences are requested?", "kind": "requirement", "answer_data": [ "language_preferences", "modality_preferences", "accessibility_profile_ref" ] }, { "id": "question-presentation-3", "text": "Which event details may appear in shared-device or lock-screen previews?", "kind": "privacy", "answer_data": [ "preview_policy_ref", "redaction_profile_ref", "device_context_ref" ] }, { "id": "question-presentation-4", "text": "Which requested interruption controls are actually supported by the selected channel?", "kind": "validation", "answer_data": [ "requested_controls", "supported_controls", "unsupported_control_disposition" ] } ], "data_elements": [ { "id": "data-presentation-presentation-preferences", "name": "presentation-preferences", "description": "Requested language, modality and preview policy with explicit applicability.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] }, { "id": "data-presentation-support-evidence", "name": "support-evidence", "description": "Channel capability or accessibility review references; not an accessibility certification.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-presentation", "name": "Presentation preference assessment", "description": "Proposed governed evidence projection for presentation and interruption controls. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-timing", "name": "Timing and interruption preferences", "description": "Separate optional scheduling and urgency from execution and safety authority.", "rationale": "Proposed reusable context concern for host-attached notification interests, preserving subject and execution boundaries.", "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-schedule", "name": "Cadence, quiet windows and bounded batching", "description": "Context for cadence, quiet windows and bounded batching. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-007", "SRC-008" ], "findings": [ { "id": "finding-schedule", "name": "Cadence, quiet windows and bounded batching", "description": "Proposed optional scheduling parameters express immediate, digest or quiet-window preferences. A pinned scheduling service resolves recurrence and civil-time ambiguity; these sources do not prescribe a universal batching policy.", "source_refs": [ "SRC-007", "SRC-008" ], "questions": [ { "id": "question-schedule-1", "text": "Which timezone definition and recurrence policy give the quiet window its meaning?", "kind": "temporal", "answer_data": [ "timezone_ref", "timezone_version", "window_definition", "ambiguity_policy" ] }, { "id": "question-schedule-2", "text": "When should selected events be immediate, delayed or summarized into a digest?", "kind": "process", "answer_data": [ "cadence_mode", "digest_interval", "max_delay", "scheduler_ref" ] }, { "id": "question-schedule-3", "text": "What happens when a digest exceeds its size or age limit?", "kind": "constraint", "answer_data": [ "item_limit", "age_limit", "overflow_disposition" ] }, { "id": "question-schedule-4", "text": "Which policy resolves a conflict between a recipient preference and an organizational schedule?", "kind": "decision", "answer_data": [ "precedence_policy_ref", "resolution_ref", "effective_schedule_revision" ] } ], "data_elements": [ { "id": "data-schedule-schedule-preference", "name": "schedule-preference", "description": "Civil-time window or cadence, units, timezone and ambiguity policy.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "data-schedule-batch-limits", "name": "batch-limits", "description": "Proposed item and duration limits with overflow behavior; execution stays in the scheduler.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-schedule", "name": "Schedule preference revision", "description": "Proposed governed evidence projection for cadence, quiet windows and bounded batching. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-urgency", "name": "Urgency, expiry and override limits", "description": "Context for urgency, expiry and override limits. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-002", "SRC-007" ], "findings": [ { "id": "finding-urgency", "name": "Urgency, expiry and override limits", "description": "Keep requested urgency, message freshness and subscription lease separate. A proposed emergency override requires a scoped policy and authority reference; high priority alone cannot establish authority to interrupt.", "source_refs": [ "SRC-002", "SRC-007" ], "questions": [ { "id": "question-urgency-1", "text": "Which urgency vocabulary and channel mapping apply to this interest?", "kind": "classification", "answer_data": [ "urgency_vocabulary_ref", "requested_urgency", "channel_mapping_ref" ] }, { "id": "question-urgency-2", "text": "What maximum useful age limits a notification after its triggering event?", "kind": "temporal", "answer_data": [ "freshness_duration", "age_anchor", "expiry_policy_ref" ] }, { "id": "question-urgency-3", "text": "Who may authorize an interruption override for a defined emergency class?", "kind": "authority", "answer_data": [ "override_policy_ref", "authorized_role", "emergency_class_ref" ] }, { "id": "question-urgency-4", "text": "What disposition applies when quiet hours would delay a notification beyond its useful lifetime?", "kind": "exception", "answer_data": [ "delay_expiry_disposition", "escalation_ref", "decision_evidence" ] } ], "data_elements": [ { "id": "data-urgency-urgency-preference", "name": "urgency-preference", "description": "Urgency and freshness parameters, including duration units and time anchor.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "data-urgency-override-ref", "name": "override-ref", "description": "External authorized policy, not an executable emergency response or safety guarantee.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-urgency", "name": "Urgency and freshness contract", "description": "Proposed governed evidence projection for urgency, expiry and override limits. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-lifecycle", "name": "Subscription control evidence", "description": "Track desired and confirmed state through activation and withdrawal.", "rationale": "Proposed reusable context concern for host-attached notification interests, preserving subject and execution boundaries.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "layer-activation", "name": "Requested and confirmed lifecycle state", "description": "Context for requested and confirmed lifecycle state. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "findings": [ { "id": "finding-activation", "name": "Requested and confirmed lifecycle state", "description": "Track desired changes separately from externally confirmed activation, suspension or expiry. Lifecycle labels are profile-defined; a request acknowledgment does not necessarily mean the subscription is active.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ], "questions": [ { "id": "question-activation-1", "text": "What are the desired and observed subscription states under the selected profile?", "kind": "state", "answer_data": [ "desired_state", "observed_state", "state_profile", "observed_at" ] }, { "id": "question-activation-2", "text": "Which confirmation or rejection establishes the outcome of an activation request?", "kind": "lifecycle", "answer_data": [ "request_ref", "outcome_ref", "confirmation_method", "rejection_reason" ] }, { "id": "question-activation-3", "text": "Which accepted lease or validity interval governs renewal and expiry?", "kind": "temporal", "answer_data": [ "requested_lease", "accepted_lease", "lease_anchor", "expires_at" ] }, { "id": "question-activation-4", "text": "Which actor and evidence justify the latest state assertion?", "kind": "provenance", "answer_data": [ "actor_ref", "evidence_ref", "event_time", "recorded_at" ] } ], "data_elements": [ { "id": "data-activation-state-assertion", "name": "state-assertion", "description": "Separate desired and observed states with profile, evidence and timestamp.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "data-activation-lease", "name": "lease", "description": "Requested and accepted validity; never infer a perpetual lease from missing evidence.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-activation", "name": "Subscription state assertion", "description": "Proposed governed evidence projection for requested and confirmed lifecycle state. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-withdrawal", "name": "Withdrawal, suspension and endpoint replacement", "description": "Context for withdrawal, suspension and endpoint replacement. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ], "findings": [ { "id": "finding-withdrawal", "name": "Withdrawal, suspension and endpoint replacement", "description": "Record unsubscribe or pause intent, local suppression preference and remote acknowledgment separately. A local stop request cannot retract already delivered content or guarantee that all in-flight messages have stopped.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ], "questions": [ { "id": "question-withdrawal-1", "text": "Which entry, receiver, topic or list is the withdrawal intended to affect?", "kind": "lifecycle", "answer_data": [ "withdrawal_scope", "request_ref", "requested_at" ] }, { "id": "question-withdrawal-2", "text": "Which evidence separates an authorized unsubscribe action from a prefetched link or forged request?", "kind": "security", "answer_data": [ "intent_evidence_ref", "channel_method", "validation_result_ref" ] }, { "id": "question-withdrawal-3", "text": "Which acknowledgment establishes remote withdrawal and what remains in flight?", "kind": "event", "answer_data": [ "remote_outcome_ref", "effective_at", "in_flight_disposition", "uncertainty" ] }, { "id": "question-withdrawal-4", "text": "Which renewal, resume or replacement request may proceed after a stop request without reviving it silently?", "kind": "constraint", "answer_data": [ "revision_precondition", "new_authority_ref", "replacement_binding", "resume_policy_ref" ] } ], "data_elements": [ { "id": "data-withdrawal-stop-intent", "name": "stop-intent", "description": "Scoped stop request and local desired suppression, separate from observed remote state.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] }, { "id": "data-withdrawal-replacement-links", "name": "replacement-links", "description": "Supersession links for transport bindings; no unauthorized endpoint reuse or automatic reactivation.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-withdrawal", "name": "Withdrawal and replacement record", "description": "Proposed governed evidence projection for withdrawal, suspension and endpoint replacement. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance", "name": "History and delivery assurance", "description": "Record replay limits, duplicate preferences and correctly scoped delivery evidence.", "rationale": "Proposed reusable context concern for host-attached notification interests, preserving subject and execution boundaries.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-009" ], "layers": [ { "id": "layer-replay", "name": "Replay, duplicates and overlap preferences", "description": "Context for replay, duplicates and overlap preferences. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "findings": [ { "id": "finding-replay", "name": "Replay, duplicates and overlap preferences", "description": "Declare retained-history and overlap preferences while keeping broker logs and deduplication execution external. A replay may be incomplete, and multiple subscriptions can select the same event.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ], "questions": [ { "id": "question-replay-1", "text": "What requested replay interval and available-history boundary apply?", "kind": "temporal", "answer_data": [ "requested_start", "requested_stop", "available_start", "replay_capability_ref" ] }, { "id": "question-replay-2", "text": "Which event identity and scope are used to recognize duplicate selections?", "kind": "identity", "answer_data": [ "event_identity_profile", "source_namespace", "event_id", "deduplication_scope" ] }, { "id": "question-replay-3", "text": "Should overlapping interests generate separate notifications, collapse them or defer the decision?", "kind": "constraint", "answer_data": [ "overlap_policy_ref", "collapse_scope", "unknown_overlap_disposition" ] }, { "id": "question-replay-4", "text": "Which evidence reports replay completion, a gap or an unavailable retained history?", "kind": "evidence", "answer_data": [ "completion_ref", "gap_ref", "history_limit_ref", "observed_at" ] } ], "data_elements": [ { "id": "data-replay-history-preference", "name": "history-preference", "description": "Requested replay range, retained-content option and observed support.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] }, { "id": "data-replay-overlap-policy", "name": "overlap-policy", "description": "Pinned correlation or deduplication policy; no universal exactly-once claim.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-replay", "name": "History and overlap assessment", "description": "Proposed governed evidence projection for replay, duplicates and overlap preferences. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-003", "SRC-004", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-outcomes", "name": "Delivery evidence and bounded failure policy", "description": "Context for delivery evidence and bounded failure policy. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ], "findings": [ { "id": "finding-outcomes", "name": "Delivery evidence and bounded failure policy", "description": "Reference delivery attempts, failures and channel receipts without owning their execution. Acceptance, transport receipt, rendering and human acknowledgment are different assertions; some may remain unknown.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ], "questions": [ { "id": "question-outcomes-1", "text": "What delivery evidence is available and which stage does each assertion actually prove?", "kind": "evidence", "answer_data": [ "attempt_refs", "receipt_refs", "evidence_stage", "observed_at" ] }, { "id": "question-outcomes-2", "text": "Which latency or failure measure is meaningful with its clock anchors, denominator and sample window?", "kind": "measurement", "answer_data": [ "metric_name", "unit", "time_anchors", "sample_window", "denominator" ] }, { "id": "question-outcomes-3", "text": "Which external retry or escalation policy handles failures within expiry and rate limits?", "kind": "exception", "answer_data": [ "retry_policy_ref", "retry_budget", "expiry_limit", "escalation_authority_ref" ] }, { "id": "question-outcomes-4", "text": "Which gaps prevent a claim that the subscriber received or acted on the information?", "kind": "quality", "answer_data": [ "missing_evidence", "clock_uncertainty", "human_ack_ref", "assurance_limit" ] } ], "data_elements": [ { "id": "data-outcomes-outcome-refs", "name": "outcome-refs", "description": "References to attempts and receipts with their assertion scope; no embedded transport state machine.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "data-outcomes-failure-policy-ref", "name": "failure-policy-ref", "description": "Approved delivery-service policy; no execution authority follows from the link.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-outcomes", "name": "Delivery evidence index", "description": "Proposed governed evidence projection for delivery evidence and bounded failure policy. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-governance", "name": "Continuity and interoperability", "description": "Govern sensitive records and qualify profile mappings before operational use.", "rationale": "Proposed reusable context concern for host-attached notification interests, preserving subject and execution boundaries.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009" ], "layers": [ { "id": "layer-continuity", "name": "Revision provenance and data minimization", "description": "Context for revision provenance and data minimization. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "findings": [ { "id": "finding-continuity", "name": "Revision provenance and data minimization", "description": "Proposed governance preserves preference provenance while limiting sensitive endpoint and interest data. Retirement, withdrawal and erasure have different effects; repository history is not a mandate for indefinite retention.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "questions": [ { "id": "question-continuity-1", "text": "Which role owns the local preference record and which master owns its referenced endpoints?", "kind": "ownership", "answer_data": [ "local_steward_role", "master_refs", "responsibility_boundary" ] }, { "id": "question-continuity-2", "text": "What evidence and prior revision explain a changed topic, endpoint or preference?", "kind": "provenance", "answer_data": [ "prior_revision", "change_reason", "authority_ref", "evidence_refs" ] }, { "id": "question-continuity-3", "text": "Which retention schedule and lawful hold determine disposal of interest and endpoint data?", "kind": "retention", "answer_data": [ "retention_policy_ref", "hold_ref", "disposal_due", "disposal_owner" ] }, { "id": "question-continuity-4", "text": "What minimal suppression or tombstone evidence may remain without retaining unnecessary personal data?", "kind": "privacy", "answer_data": [ "minimal_record_profile", "purpose_ref", "expiry_rule", "erasure_evidence_ref" ] } ], "data_elements": [ { "id": "data-continuity-revision-provenance", "name": "revision-provenance", "description": "Revision, actor role, authority reference and change reason; history access is restricted.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] }, { "id": "data-continuity-retention-binding", "name": "retention-binding", "description": "Adopting-Dimension policy governs preservation, lawful disposal and external execution.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-continuity", "name": "Preference revision and disposition assessment", "description": "Proposed governed evidence projection for revision provenance and data minimization. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-mapping", "name": "Profile interoperability and conformance limits", "description": "Context for profile interoperability and conformance limits. Candidate fields require a binding-specific nested schema.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009" ], "findings": [ { "id": "finding-mapping", "name": "Profile interoperability and conformance limits", "description": "A format-neutral profile maps local meanings to a chosen protocol without declaring protocols interchangeable. Unsupported fields and semantic loss require an explicit disposition before operational use.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009" ], "questions": [ { "id": "question-mapping-1", "text": "Which exact protocol, version and optional capabilities implement the selected profile?", "kind": "interoperability", "answer_data": [ "protocol_ref", "version", "capability_set", "binding_revision" ] }, { "id": "question-mapping-2", "text": "Which conformance fixtures cover pending activation, withdrawal races, expiry and duplicate delivery?", "kind": "validation", "answer_data": [ "fixture_refs", "expected_results", "test_run_ref", "unverified_cases" ] }, { "id": "question-mapping-3", "text": "Which local preferences cannot be represented by the target binding?", "kind": "exception", "answer_data": [ "unsupported_fields", "loss_report", "rejection_or_degradation_decision" ] }, { "id": "question-mapping-4", "text": "Which dependencies must be resolved before the proposed model operations are enabled?", "kind": "requirement", "answer_data": [ "required_bindings", "authority_checks", "review_holds", "activation_gate" ] } ], "data_elements": [ { "id": "data-mapping-binding-profile", "name": "binding-profile", "description": "Protocol revision, option set, field mapping and loss report.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009" ] }, { "id": "data-mapping-conformance-evidence", "name": "conformance-evidence", "description": "Executable evidence references; absent evidence remains an explicit operational hold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009" ] } ], "artifacts": [ { "id": "artifact-mapping", "name": "Binding conformance assessment", "description": "Proposed governed evidence projection for profile interoperability and conformance limits. Store references instead of duplicating target-owned records; restrict sensitive fields.", "media_or_form": [ "Structured record", "Human review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first; governed IRI second; Dimension-issued UUID or ULID third. Stable identity plus separate revision and time metadata.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "function-draft-interest", "name": "Draft an interest attachment", "description": "Create a reviewable local proposal for a scoped host attachment. Proposed and unimplemented.", "inputs": [ "host_ref", "subscriber_ref", "scope_binding", "authority_refs" ], "outputs": [ "draft_entry", "validation_issues", "Refusal or unresolved-evidence result" ], "preconditions": [ "Authorized local role and declared purpose.", "Resolvable scoped references and current revision; otherwise refuse or report unknown." ], "effects": [ "A local draft is stored; no network subscription or delivery occurs." ], "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "function-revise-preferences", "name": "Revise local delivery preferences", "description": "Prepare a versioned local change with explicit schedule, channel and presentation support gaps. Proposed and unimplemented.", "inputs": [ "entry_id", "expected_revision", "preference_patch", "authority_ref" ], "outputs": [ "new_revision_or_conflict", "unsupported_preferences", "Refusal or unresolved-evidence result" ], "preconditions": [ "Authorized local role and declared purpose.", "Resolvable scoped references and current revision; otherwise refuse or report unknown." ], "effects": [ "Only the governed local preference record changes; channel and schedule execution remain external." ], "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "function-record-state", "name": "Record a subscription state observation", "description": "Attach externally supplied activation, lease, rejection or suspension evidence to its exact binding. Proposed and unimplemented.", "inputs": [ "entry_id", "transport_binding", "evidence_ref", "observed_at", "expected_revision" ], "outputs": [ "state_assertion_or_rejection", "unresolved_state_conflicts", "Refusal or unresolved-evidence result" ], "preconditions": [ "Authorized local role and declared purpose.", "Resolvable scoped references and current revision; otherwise refuse or report unknown." ], "effects": [ "Add a scoped observation; do not turn a request acknowledgment into confirmed activation." ], "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "id": "function-record-withdrawal", "name": "Record withdrawal intent", "description": "Record the requested stop scope and identify the required external acknowledgment. Proposed and unimplemented.", "inputs": [ "entry_id", "stop_scope", "authority_evidence", "expected_revision" ], "outputs": [ "withdrawal_record", "external_handoff_requirements", "Refusal or unresolved-evidence result" ], "preconditions": [ "Authorized local role and declared purpose.", "Resolvable scoped references and current revision; otherwise refuse or report unknown." ], "effects": [ "Set local desired stop state with evidence; no remote unsubscribe, deletion or recall is executed." ], "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] }, { "id": "function-link-outcome", "name": "Link delivery evidence", "description": "Index supplied channel evidence under a stated assertion stage without claiming human receipt. Proposed and unimplemented.", "inputs": [ "entry_id", "event_ref", "attempt_or_receipt_ref", "evidence_stage" ], "outputs": [ "evidence_link_or_rejection", "assurance_gaps", "Refusal or unresolved-evidence result" ], "preconditions": [ "Authorized local role and declared purpose.", "Resolvable scoped references and current revision; otherwise refuse or report unknown." ], "effects": [ "Store references and limits; do not deliver, retry, replay or run a matching engine." ], "source_refs": [ "SRC-002", "SRC-004", "SRC-009" ] }, { "id": "function-assess-binding", "name": "Assess a proposed profile mapping", "description": "Compare required preference meanings with documented binding capabilities and supplied fixtures. Proposed and unimplemented.", "inputs": [ "profile_revision", "mapping_ref", "capability_evidence", "fixture_results" ], "outputs": [ "loss_report", "unverified_cases", "operational_hold_recommendation", "Refusal or unresolved-evidence result" ], "preconditions": [ "Authorized local role and declared purpose.", "Resolvable scoped references and current revision; otherwise refuse or report unknown." ], "effects": [ "Produce a local review record; no conformance certificate or runtime activation is issued." ], "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-009" ] } ], "composition": [ { "target": "WM-REC-003", "relation": "REFERENCE", "purpose": "Candidate optional Message binding: notification payloads, message identity and message lifecycle stay message-owned.", "required": false, "source_refs": [ "SRC-002", "SRC-009" ] }, { "target": "WM-ACT-015", "relation": "REFERENCE", "purpose": "Candidate optional Occurrence / Event binding: point to triggering facts without reproducing event identity or lifecycle.", "required": false, "source_refs": [ "SRC-004", "SRC-009" ] }, { "target": "WM-XCT-002", "relation": "REFERENCE", "purpose": "Candidate optional Access Contract / Consent binding: retain scoped authority references, never infer entitlement or legal consent from a subscription.", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006" ] }, { "target": "WM-PER-014", "relation": "REFERENCE", "purpose": "Candidate optional Preference / Personal Profile binding: use only selected notification preferences and preserve general profile ownership.", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] }, { "target": "WM-KNW-013", "relation": "REFERENCE", "purpose": "Candidate optional rule binding: pin selector or precedence rule and operands; evaluator execution and generic rule lifecycle remain external.", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "target": "WM-XCT-004", "relation": "REFERENCE", "purpose": "Candidate optional Access Audit binding: reference access evidence without implementing or redefining an audit trail.", "required": false, "source_refs": [ "SRC-004", "SRC-006" ] }, { "target": "WebSub Recommendation 2026-06-02", "relation": "ALIGN", "purpose": "Conceptual topic, callback, confirmation and lease mapping; requires independently tested adapter.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "MQTT Version 5.0", "relation": "ALIGN", "purpose": "Conceptual topic-filter and subscription-option mapping; no end-to-end exactly-once guarantee.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "RFC 8639", "relation": "ALIGN", "purpose": "Optional configured or dynamic notification subscription profile; network-management rules are not universal.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "RFC 8030 and Push API Working Draft 2026-10-05", "relation": "ALIGN", "purpose": "Optional web push profile with protected endpoint and permission evidence; draft API support is not assumed.", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] }, { "target": "RFC 8058", "relation": "ALIGN", "purpose": "Optional one-click email withdrawal profile, distinct from arbitrary link retrieval and other channel methods.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "CloudEvents v1.0.2", "relation": "ALIGN", "purpose": "Event envelope references and correlation only; source plus event id is scoped identity, not a delivery contract.", "required": false, "source_refs": [ "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Owner designated by the adopting Dimension as a role, never a brand or company name.", "Declare host namespace, local interest master, transport bindings and their responsible roles.", "Pin privacy, retention, access, scheduling and channel profiles before enabling operations.", "Declare whether a profile is human-facing, machine-only or configured by organizational authority." ], "namespace_guidance": "Use an owner-controlled namespace for host, local entry and artifact identities. Keep transport keys and sensitive endpoint handles in separately scoped bindings.", "registry_links": [ "vr.wm-xct-030", "Candidate references require version-pinned bindings; no global relation update is implied." ] }, "canon_and_patch": { "canonicalization_rules": [ "Preserve protocol case sensitivity, unknown values and distinctions between absent, false, denied and unobserved.", "Keep local entry identity stable through revisions; transport replacement has its own identity and continuity evidence." ], "patch_rules": [ "Require current revision and role-scoped authority for each change; reject stale writes and record the reason.", "Record stop intent before considering resume or renewal; never overwrite a stop with a delayed activation observation." ], "compatibility_rules": [ "Changing topic scope, receiver, precedence or authority requires an explicit migration review.", "Lossy protocol projections cannot silently discard quiet windows, expiry, privacy controls or withdrawal state." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier in its namespace", "Governed global identifier or IRI", "UUID or ULID issued by the adopting Dimension" ], "timestamp_rule": "Time values use RFC 3339 with seconds and an explicit offset or Z. Record event time, effective time and observation or ingestion time separately. Recurring civil-time preferences also require a timezone definition and ambiguity policy.", "serial_naming_rule": "Stable artifact key plus separate revision. Dates, addresses, endpoint URLs and filenames are not the sole identity.", "integrity_rule": "Record digest, media type, issuer, retrieval context and revision where available. A digest proves byte continuity only, not delivery, authority or truth. Do not hash exposed capability tokens into public identifiers." }, "policies": [ "These are proposed local information operations, not implemented delivery functions. A binding may act only under separately established authority.", "Treat interests, recipient endpoints, selectors and preview content as potentially sensitive. Publish no credentials or capability URLs.", "Recheck external access and permission evidence under the applicable profile before dispatch; a stored match cannot authorize disclosure.", "Emergency overrides require a defined class, authorized role and reviewable rationale; keep hazardous-subject handling at policy level.", "Apply minimization to copies and history; preserve only justified evidence under a scoped retention policy." ], "crud": { "read": [ "Resolve host and record authority before reading; redact endpoint handles, event payloads and sensitive interest expressions according to scope." ], "create": [ "Create a host-attached draft with stable identity, subscriber reference, proposed scope and authority evidence; draft creation does not subscribe a remote endpoint." ], "update": [ "Use optimistic concurrency and attributable patches; separate requested state from observed remote facts and preserve supersession links." ], "delete": [ "Retire local interests separately from remote unsubscribe and personal-data erasure. A Dimension-designated retention and disposal service executes deletion, checks holds and records minimal lawful tombstones; do not retain private endpoints indefinitely." ] }, "roles": [ { "name": "Dimension steward", "responsibilities": [ "Own the profile, namespace and risk acceptance; approve schema and semantic migrations." ] }, { "name": "Subscriber or authorized delegate", "responsibilities": [ "Express scoped preferences and withdrawal intent within evidenced authority." ] }, { "name": "Notification record custodian", "responsibilities": [ "Maintain revisions, evidence references and restricted access; never infer remote state from intent." ] }, { "name": "Channel operator", "responsibilities": [ "Own endpoint verification, dispatch, retries and receipt semantics in the external delivery service." ] }, { "name": "Privacy and access reviewer", "responsibilities": [ "Review data minimization, permission scope, disclosure and retention exceptions." ] }, { "name": "Conformance reviewer", "responsibilities": [ "Assess binding loss, fixtures, failures and unsupported protocol features." ] } ], "access": { "default_rule": "Deny by default; permit only purpose-bound access to the subscriber or authorized role. Endpoint capabilities, secrets and event payloads remain protected references.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Break-glass access or emergency override requires explicit scoped authority, expiry and recorded review; urgency alone is insufficient.", "Recipient self-service access is limited to owned or delegated interests and cannot expose other receivers." ], "audit_requirements": [ "Reference attributable access and mutation evidence with actor, purpose, object revision and time; external audit storage owns trail semantics.", "Report missing evidence, stale permissions and unresolved recipients; redact tokens from logs and exports." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read AGENTS.md and this specification, including publication holds.", "Resolve the host, Dimension policy and pinned composition bindings before using candidate fields.", "Inspect authority, evidence, current revision and unsupported features before proposing a change." ] } }, "coverage": { "claim": "Source-grounded proposed host-attached notification-interest mixin with a separate local no-tools self-audit. Selected technical standards inform the structure; direct source checks, independent review, legal applicability and executable profile conformance remain open. This is a reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Host attachment, local key and external transport identity are distinct." }, { "dimension": "lifecycle", "status": "covered", "notes": "Desired and observed activation, withdrawal, expiry and replacement are separated." }, { "dimension": "relationships", "status": "covered", "notes": "Event, message, permission, rule and personal profile masters remain external; bindings are candidates." }, { "dimension": "temporal", "status": "covered", "notes": "Lease, event freshness, quiet windows, replay and observation time have separate anchors." }, { "dimension": "provenance", "status": "covered", "notes": "State observations and preference changes carry attributable evidence and revisions." }, { "dimension": "ownership", "status": "covered", "notes": "Role-based Dimension stewardship and channel custody are explicit." }, { "dimension": "validation", "status": "gap", "notes": "Research schema can be validated; nested instance schemas and executable profile fixtures remain to be built." }, { "dimension": "access", "status": "covered", "notes": "Intent, channel permission and event entitlement are distinct; endpoint capabilities are restricted." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Disposal policy and minimal lawful suppression evidence are profile-dependent, not perpetual history." }, { "dimension": "interoperability", "status": "gap", "notes": "Standards alignments are conceptual; protocol translation and optional feature support need tests." }, { "dimension": "direct properties", "status": "covered", "notes": "Filter scope, channel, urgency, state and timing are nonphysical properties." }, { "dimension": "physical measurement", "status": "not-applicable", "notes": "The mixin is informational; physical properties belong to referenced subjects." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Evidence stages and distinguishing identifiers prevent conflation with messages or commercial subscriptions." }, { "dimension": "capabilities and behavior", "status": "covered", "notes": "Local proposal and evidence operations have preconditions, refusal outputs and limited effects." }, { "dimension": "regional applicability", "status": "gap", "notes": "Privacy, communications law, mandatory notices and sector-specific emergency rules require qualified adoption review." } ], "known_omissions": [ "No independent second-provider review; local self-audit cannot replace it.", "No executable instance schemas, matching engine, scheduler, protocol adapter or tested conformance fixtures.", "Direct HTTP checks were not attempted because the owner reports sandbox blocking; no measured HTTP status or body digest is available. Browser retrieval is documented separately.", "No legal, jurisdictional, channel-specific marketing or safety-critical emergency compliance conclusion.", "Quiet-hour precedence, batching, multi-device behavior, shared subscriptions and mandatory notices need adoption-specific profiles." ], "conflicts": [], "regional_assumptions": [ "Technical standards provide protocol examples, not a universal legal regime.", "Permission, intent verification and a lawful processing basis are distinct concepts; local qualified review supplies legal applicability." ], "adversarial_checks": [ "A pending activation response must not defeat a newer stop intent.", "Endpoint ownership or control must not be treated as event-content authorization.", "Transport receipt and protocol QoS must not become proof of human reading or global exactly-once effects.", "Unknown selector semantics, clock ambiguity or unsupported preferences must produce a visible gap rather than silent delivery.", "Endpoint rotation and replay must not revive cancelled interests or leak one subscriber data to another." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "mixin", "status": "accepted", "rationale": "The frozen registry purpose is event-interest and delivery preference. The result consistently attaches local interest entries to a host while referencing separately managed transport subscriptions, events and messages. Scoped entry identity does not turn the mixin into a standalone delivery-service entity." }, "decisions": [ { "concept": "Mixin boundary and local keys", "disposition": "accepted", "rationale": "Host, local entry and transport subscription identities are explicitly separated. The chosen boundary supports reusable preferences without owning remote subscription allocation or a new universal entity root." }, { "concept": "Relation ledger and candidate links", "disposition": "qualified", "rationale": "The frozen ledger has no rows for this model. Six neighbor references and protocol alignments are explicitly candidates; no mandatory dependency or shared registry change is inferred from them." }, { "concept": "Intent, permission and entitlement", "disposition": "separated", "rationale": "The questions distinguish requested scope, receiver control, delegation and content authorization. Browser permission and callback verification do not silently become legal consent or authority to disclose all events." }, { "concept": "Configured subscriptions and subscriber control", "disposition": "accepted with profile qualification", "rationale": "The model allows human, program and organizational profiles. This avoids the supplement's overbroad assumption that every subscription rests on a voluntary personal opt-in, while requiring an explicit creation basis." }, { "concept": "Selector and event ownership", "disposition": "accepted", "rationale": "Event vocabulary, schema, filter language, missing values and fan-out are parameters or references. Event truth, generic rule lifecycle, matching execution and content authorization remain separately owned." }, { "concept": "Channel identity and endpoint continuity", "disposition": "qualified", "rationale": "Protected handles and dated observations avoid treating endpoint addresses as universal identity or permanent reachability. Transport replacement can preserve local preference continuity only with binding evidence." }, { "concept": "Quiet windows and presentation", "disposition": "proposed profile choices", "rationale": "Accessibility and time standards motivate the questions but do not prescribe the proposed batching, precedence or preview policies. The result labels these choices as proposed and leaves execution in the channel or scheduler." }, { "concept": "Urgency and emergency authority", "disposition": "separated", "rationale": "Urgency, useful message age and lease duration have distinct meanings. The override question requires scoped policy and role evidence, and neither implements an emergency response nor certifies a safety-critical channel." }, { "concept": "Desired and observed lifecycle", "disposition": "accepted", "rationale": "Activation requests, confirmation, rejection, lease evidence and stop intent remain distinct. Patch rules protect a newer withdrawal from being overwritten by a delayed activation observation." }, { "concept": "Withdrawal and recall", "disposition": "qualified", "rationale": "The withdrawal finding records scope, authorized intent, acknowledgment and in-flight uncertainty. It does not claim that a local record performs remote unsubscribe, retracts delivered content or establishes a universal legal deadline." }, { "concept": "Replay, overlap and delivery evidence", "disposition": "accepted with assurance limits", "rationale": "Replay availability, correlation identity, overlap policy and receipt stages are explicit. Protocol QoS and transport evidence are not promoted into a global exactly-once claim or proof that a person read the message." }, { "concept": "Local operation effects", "disposition": "accepted as proposed only", "rationale": "All six functions produce local proposals, observations or review records and include refusal or unresolved-evidence outcomes. Dispatch, matching, scheduling, replay, retries and remote control are excluded from their effects." }, { "concept": "Retention and record history", "disposition": "accepted with external policy dependency", "rationale": "The governance finding and delete rule distinguish retirement, withdrawal and erasure. Preservation is constrained by minimization and a scoped retention policy; external disposal and audit execution are not absorbed by this mixin." }, { "concept": "Instance schemas and source assurance", "disposition": "deferred for operational adoption", "rationale": "Candidate object groups, conceptual mappings and planned fixtures do not establish executable validation. Browser access supports selected claims only; no direct HTTP request was attempted and no measured status or body digest is available." }, { "concept": "Provider attribution and completeness", "disposition": "waived and held", "rationale": "Claude and Grok were skipped under the owner override. This separate semantic phase is a local Codex self-audit of frozen evidence, not independent provider agreement or canonical completion. No source or node is added by the audit." } ], "publicationHolds": [ "Independent external review is absent. Claude and Grok were skipped under the owner-authorized single-provider waiver; the separate local Codex no-tools self-audit is not a second-provider review.", "Direct source and version verification remains incomplete. No direct HTTP requests were attempted because the owner reports sandbox blocking; zero HTTP 200 responses were measured. Browser retrieval supports only the selected sections documented in source-review.md. The coordinator must run check_sources.py outside the sandbox and review versions, errata and claim support; Push API is an unstable Working Draft.", "Jurisdictional privacy and communications rules, legal basis, mandatory notices, emergency authority, accessibility requirements, licensing and retention need qualified adoption-profile review. No legal or safety-critical compliance is claimed.", "Nested instance schemas, pinned neighbor bindings, protocol adapters, timezone behavior, race handling and executable conformance fixtures remain incomplete. All functions are proposed local operations; no runtime implementation or delivery guarantee is supplied.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore independent external review and resolve all source version, errata and applicability questions before canonical promotion.", "Build profile-specific schemas and fixtures for activation and withdrawal races, endpoint rotation, civil-time ambiguity, replay gaps, shared subscriptions and duplicate delivery.", "Obtain qualified adoption review for mandatory notices, privacy, communications law, emergency overrides, accessibility and retention without universalizing one protocol's rules." ] }, "statistics": { "sources": 9, "bundles": 7, "layers": 14, "findings": 14, "questions": 56, "artifacts": 14, "functions": 6 } }