# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T12:44:12Z", "synthesisSha256": "0b3981de0a0ecc6d782e2721f27bea3696a44327d16ce4a502d0ee2397d12407", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-035", "registryId": "vr.wm-xct-035", "name": "Retention / Disposition", "version": "0.1.0", "previousVersions": [], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.RET" ], "tags": [ "retention", "disposition", "xct.ret" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-035-retention-disposition/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-035", "model": { "registry_id": "vr.wm-xct-035", "model_id": "WM-XCT-035", "name": "Retention / Disposition", "entry_kind": "mixin", "purpose": "Attach accountable retention, hold, disposition and evidence context to an independently mastered subject.", "scope_statement": "A format-neutral host-attached mixin for records and information objects or explicitly bounded sets. It records applicable authority references, trigger observations, assessment results, scoped hold notices and disposition evidence. It is not a standalone record master, universal legal schedule, policy evaluator or destructive executor. All hierarchy and field choices are proposed local research design informed by the cited concepts.", "in_scope": [ "Host-specific scope, schedule binding, trigger evidence, cutoff and external eligibility assessments", "Scoped holds and releases, outcome authority and privacy reconciliation references", "Transfer acceptance, destruction reports, residual copies, evidence continuity and review obligations" ], "out_of_scope": [ "Mastering host payloads, schedules, legal cases, reusable rule expressions, generic lifecycle or access-control machinery", "Running policy or calendar engines, issuing legal decisions or holds, releasing holds, operating freezes, destroying data or media, transferring custody or executing backup remediation", "Archival arrangement and preservation operations, domain-specific mandatory durations, universal legal precedence and operational handling of controlled items" ], "boundary_notes": [ { "neighbor": "WM-REC-001", "distinction": "Host document or record master. Its content, identity and record lifecycle remain external; a non-document host must supply an equivalent pinned master binding.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "WM-KNW-013", "distinction": "Reusable constraint and requirement rule master owns expression, applicability and rule lifecycle. This mixin carries the selected revision and subject operands only.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "neighbor": "WM-XCT-038", "distinction": "External policy evaluator owns rule evaluation and explanation. Local functions record its input and output references without implementing its engine.", "source_refs": [ "SRC-002", "SRC-003" ] }, { "neighbor": "WM-XCT-021", "distinction": "Generic host lifecycle and transition semantics remain external. Eligibility, hold and execution observations are distinct subject-specific axes.", "source_refs": [ "SRC-001", "SRC-007" ] }, { "neighbor": "WM-REC-010", "distinction": "Approval and exception decision master owns authority, rationale and decision revision; attaching a decision does not issue or approve it.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] }, { "neighbor": "WM-REC-015", "distinction": "Optional archival fonds or collection owns accession, arrangement and preservation. This mixin references transfer scope and accepted custody.", "source_refs": [ "SRC-001", "SRC-008" ] }, { "neighbor": "WM-REC-011", "distinction": "Evidence record master owns original attestation and evidence validity; retain only retention-specific links and assessment context here.", "source_refs": [ "SRC-007", "SRC-008" ] }, { "neighbor": "WM-REC-013", "distinction": "Operational log master owns event persistence and audit-trail mechanisms. This mixin indexes relevant events without recreating logging infrastructure.", "source_refs": [ "SRC-007", "SRC-008" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Implementing Schedules", "organization": "National Archives and Records Administration", "url": "https://www.archives.gov/records-mgmt/scheduling/implementation", "version_or_date": "Undated living guidance; selected sections read 2026-10-06; current regulatory consolidation not verified", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:43:00Z", "relevance": "Applying Schedules: approved authority, supersession, temporary destruction, permanent transfer and custody acceptance. US federal example only." }, { "id": "SRC-002", "title": "Scheduling Records", "organization": "National Archives and Records Administration", "url": "https://www.archives.gov/records-mgmt/scheduling/sch-records", "version_or_date": "Undated living guidance; selected sections read 2026-10-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:43:00Z", "relevance": "Record Scheduling Basics, Cutoff Instructions and Options for Record Retention and Transfer Periods: scope, event or age based timing and unscheduled records. No universal retention period inferred." }, { "id": "SRC-003", "title": "Federal Records Centers Program Freeze Process Overview / FAQ", "organization": "National Archives and Records Administration", "url": "https://www.archives.gov/frc/arcis/freeze-faq", "version_or_date": "Living FAQ read 2026-10-06; older 36 CFR 1228 citations require current-law reconciliation", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:43:00Z", "relevance": "Sections 1-5 distinguish local holds from off-site freezes and describe authority, scoped suspension and full or partial lifting. Conceptual evidence only; obsolete citations and contact details are not operational instructions." }, { "id": "SRC-004", "title": "Principle (e): Storage limitation", "organization": "Information Commissioner's Office", "url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/", "version_or_date": "Living UK guidance read 2026-10-06; page explicitly under review following legislative change", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:43:00Z", "relevance": "Retention justification, periodic review, erasure or anonymisation, offline storage and purpose-qualified archival exceptions. UK guidance only; no fixed cross-sector period or current-law assurance." }, { "id": "SRC-005", "title": "Right to erasure", "organization": "Information Commissioner's Office", "url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-erasure/", "version_or_date": "Living UK guidance read 2026-10-06; page explicitly under review following legislative change", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:43:00Z", "relevance": "Sections on recipients, backup systems and exceptions support distinguishing requests, qualified decisions and incomplete erasure. No universal right, deadline or instant backup erasure is asserted." }, { "id": "SRC-006", "title": "SP 800-88 Rev. 2, Guidelines for Media Sanitization", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/88/r2/final", "version_or_date": "Revision 2, September 2025; landing-page planning note dated 2026-07-17", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:43:00Z", "relevance": "Official abstract and publication history only: sanitization addresses infeasible access at a stated effort and needs a sensitivity-appropriate program. Full technical procedures were not reviewed or imported." }, { "id": "SRC-007", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:43:00Z", "relevance": "Sections 2 and 3.1-3.2 supply conceptual entity, activity, agent, revision, attribution and invalidation links. Provenance assertions do not prove destruction or legal authority." }, { "id": "SRC-008", "title": "PREMIS Data Dictionary for Preservation Metadata, Version 3.0", "organization": "Library of Congress", "url": "https://www.loc.gov/standards/premis/v3/index.html", "version_or_date": "Version 3.0, full document listed as updated November 2015; overview footer 2023-01-18", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T12:43:00Z", "relevance": "Official overview identifies Objects, Events, Rights and Agents as preservation metadata entities. Overview-level alignment only; dictionary clauses, errata and schema conformance remain unreviewed." } ], "structure": { "bundles": [ { "id": "bundle-applicability", "name": "Subject and authority", "description": "Define the governed host scope and pin applicable authority.", "rationale": "Proposed grouping of source-grounded concerns for a host-attached mixin; the cited sources support concepts, not this hierarchy or its field names.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007" ], "layers": [ { "id": "layer-binding", "name": "Applicability", "description": "Bind one retention context to a host item, version, series or explicitly bounded set. Membership snapshots are local design proposals, not ownership of the host records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "findings": [ { "id": "finding-binding", "name": "Host binding", "description": "Bind one retention context to a host item, version, series or explicitly bounded set. Membership snapshots are local design proposals, not ownership of the host records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ], "questions": [ { "id": "q-binding-1", "text": "Which mastered subject and selection revision does this retention context govern?", "kind": "identity", "answer_data": [ "data-subject-binding" ] }, { "id": "q-binding-2", "text": "Which representations and copies are included in the governed scope?", "kind": "composition", "answer_data": [ "data-scope-members" ] }, { "id": "q-binding-3", "text": "Which accountable role maintains this binding when custody changes?", "kind": "ownership", "answer_data": [ "data-binding-steward" ] } ], "data_elements": [ { "id": "data-subject-binding", "name": "Subject binding", "description": "Host master identifier, version or set selector with its revision and membership evidence.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "data-scope-members", "name": "Scope members", "description": "Master references to included members, excluded copies, custodians and scope uncertainty; no copied record payload.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] }, { "id": "data-binding-steward", "name": "Binding steward", "description": "Role reference, delegation basis and custody-change review responsibility.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-binding", "name": "Scope binding record", "description": "Locally proposed evidence view for host binding. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-authority", "name": "Applicable rule", "description": "Pin the selected schedule item and its applicability decision. The rule master owns rule definitions and change approval; this mixin records the host-specific binding.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ], "findings": [ { "id": "finding-authority", "name": "Schedule authority", "description": "Pin the selected schedule item and its applicability decision. The rule master owns rule definitions and change approval; this mixin records the host-specific binding.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ], "questions": [ { "id": "q-authority-1", "text": "Which approved schedule item and revision apply to this subject?", "kind": "classification", "answer_data": [ "data-schedule-binding" ] }, { "id": "q-authority-2", "text": "Which jurisdiction and purpose establish the applicability of this schedule binding?", "kind": "authority", "answer_data": [ "data-applicability-basis" ] }, { "id": "q-authority-3", "text": "What unresolved or competing retention requirements prevent a disposition decision?", "kind": "exception", "answer_data": [ "data-requirement-conflicts" ] } ], "data_elements": [ { "id": "data-schedule-binding", "name": "Schedule binding", "description": "Schedule identifier, item code, revision, approval evidence, applicability dates and classification rationale.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "data-applicability-basis", "name": "Applicability basis", "description": "Jurisdiction and sector profile, stated purpose and references to authoritative decisions; business preference is not legal authority.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "id": "data-requirement-conflicts", "name": "Requirement conflicts", "description": "Missing or competing authorities, affected scope, reviewer and review date; unknown is not permission and longest duration is not automatic precedence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] } ], "artifacts": [ { "id": "artifact-authority", "name": "Schedule assignment assessment", "description": "Locally proposed evidence view for schedule authority. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-timing", "name": "Trigger and eligibility", "description": "Separate evidenced trigger, rule-based timing and assessed eligibility.", "rationale": "Proposed grouping of source-grounded concerns for a host-attached mixin; the cited sources support concepts, not this hierarchy or its field names.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ], "layers": [ { "id": "layer-trigger", "name": "Retention clock", "description": "Record the actual event or age basis selected by a pinned rule. A cutoff is not necessarily creation, ingestion or last modification.", "source_refs": [ "SRC-002", "SRC-007" ], "findings": [ { "id": "finding-trigger", "name": "Trigger evidence", "description": "Record the actual event or age basis selected by a pinned rule. A cutoff is not necessarily creation, ingestion or last modification.", "source_refs": [ "SRC-002", "SRC-007" ], "questions": [ { "id": "q-trigger-1", "text": "What observed event satisfies the selected retention trigger?", "kind": "event", "answer_data": [ "data-trigger-evidence" ] }, { "id": "q-trigger-2", "text": "What cutoff and calendar semantics govern the retention clock?", "kind": "temporal", "answer_data": [ "data-clock-semantics" ] }, { "id": "q-trigger-3", "text": "How is a corrected or reopened trigger reflected in the retention context?", "kind": "exception", "answer_data": [ "data-trigger-correction" ] } ], "data_elements": [ { "id": "data-trigger-evidence", "name": "Trigger evidence", "description": "Event reference, trigger type, source, event time, observation time and verified, disputed or absent status.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "data-clock-semantics", "name": "Clock semantics", "description": "Age or event basis, calendar or fiscal cutoff, duration unit, timezone, precision and inclusive or exclusive boundary from the profile.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "data-trigger-correction", "name": "Trigger correction", "description": "Superseding evidence, affected rule revision and required reassessment; a missing trigger yields an unknown date, never a fabricated one.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-trigger", "name": "Trigger assertion record", "description": "Locally proposed evidence view for trigger evidence. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-eligibility", "name": "Timing assessment", "description": "Reference a dated evaluation of the bound rules and holds. The evaluator owns computation; a due date is not authorization or evidence of execution.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "findings": [ { "id": "finding-eligibility", "name": "Eligibility assessment", "description": "Reference a dated evaluation of the bound rules and holds. The evaluator owns computation; a due date is not authorization or evidence of execution.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ], "questions": [ { "id": "q-eligibility-1", "text": "Which earliest action date and review deadline were assessed for this scope?", "kind": "retention", "answer_data": [ "data-timing-result" ] }, { "id": "q-eligibility-2", "text": "What evidence distinguishes pending, eligible, blocked and unknown eligibility?", "kind": "state", "answer_data": [ "data-eligibility-state" ] }, { "id": "q-eligibility-3", "text": "Which changes invalidate the recorded eligibility assessment?", "kind": "validation", "answer_data": [ "data-staleness-conditions" ] } ], "data_elements": [ { "id": "data-timing-result", "name": "Timing result", "description": "Evaluator reference, input revisions, earliest date or unknown, review date, duration basis and uncertainty; permanent retention has no destruction date.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "data-eligibility-state", "name": "Eligibility state", "description": "Proposed local assessment label with reason and evaluated-at time; distinct from the host lifecycle and execution status.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "data-staleness-conditions", "name": "Staleness conditions", "description": "Changes to membership, rule revision, trigger or hold snapshot that require a fresh external evaluation before action.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "artifacts": [ { "id": "artifact-eligibility", "name": "Eligibility assessment reference", "description": "Locally proposed evidence view for eligibility assessment. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-suspension", "name": "Holds and releases", "description": "Qualify suspension scope, custody coverage and release reassessment.", "rationale": "Proposed grouping of source-grounded concerns for a host-attached mixin; the cited sources support concepts, not this hierarchy or its field names.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "layers": [ { "id": "layer-hold", "name": "Suspension scope", "description": "Record how an externally authorized hold applies to this subject, including off-site copies. Hold matter management and legal determinations remain outside this mixin.", "source_refs": [ "SRC-003", "SRC-005" ], "findings": [ { "id": "finding-hold", "name": "Hold application", "description": "Record how an externally authorized hold applies to this subject, including off-site copies. Hold matter management and legal determinations remain outside this mixin.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "q-hold-1", "text": "Which authorized hold notice suspends which disposition actions?", "kind": "authority", "answer_data": [ "data-hold-binding" ] }, { "id": "q-hold-2", "text": "Which custodians and locations have acknowledged the applicable hold scope?", "kind": "spatial", "answer_data": [ "data-hold-coverage" ] }, { "id": "q-hold-3", "text": "What restrictions remain while hold applicability is unresolved?", "kind": "constraint", "answer_data": [ "data-hold-restrictions" ] } ], "data_elements": [ { "id": "data-hold-binding", "name": "Hold binding", "description": "Hold master ID, notice revision, issuing role, legal basis reference and covered action types.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "data-hold-coverage", "name": "Hold coverage", "description": "Affected member references, storage jurisdictions, custodian acknowledgments, unconfirmed copies and distribution evidence; no physical location inferred from a logical path.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "data-hold-restrictions", "name": "Hold restrictions", "description": "Pending review, preservation and access restrictions, responsible authority and next review; recording the notice does not implement a freeze.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-hold", "name": "Hold applicability record", "description": "Locally proposed evidence view for hold application. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-release", "name": "Release evidence", "description": "A release reference applies only to its authorized scope. Other holds and retention requirements must be reassessed; lifting a hold does not itself order destruction.", "source_refs": [ "SRC-003", "SRC-001" ], "findings": [ { "id": "finding-release", "name": "Hold release", "description": "A release reference applies only to its authorized scope. Other holds and retention requirements must be reassessed; lifting a hold does not itself order destruction.", "source_refs": [ "SRC-003", "SRC-001" ], "questions": [ { "id": "q-release-1", "text": "What authoritative evidence releases all or part of a hold binding?", "kind": "evidence", "answer_data": [ "data-release-evidence" ] }, { "id": "q-release-2", "text": "Which overlapping hold bindings remain after the release?", "kind": "relationship", "answer_data": [ "data-remaining-holds" ] }, { "id": "q-release-3", "text": "What reassessment and custodian acknowledgments are required after release?", "kind": "process", "answer_data": [ "data-release-followup" ] } ], "data_elements": [ { "id": "data-release-evidence", "name": "Release evidence", "description": "Release ID, signed decision reference, authority, effective time and scope revision.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "data-remaining-holds", "name": "Remaining holds", "description": "Active or unresolved hold references for each affected member, including partial-release exclusions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "data-release-followup", "name": "Release followup", "description": "Pending acknowledgments, refreshed eligibility reference and review responsibility; elapsed time treatment follows the pinned rule rather than an assumed clock restart.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] } ], "artifacts": [ { "id": "artifact-release", "name": "Hold release assessment", "description": "Locally proposed evidence view for hold release. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-003", "SRC-001" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-outcomes", "name": "Disposition and privacy decisions", "description": "Link reasoned outcome authority and purpose-limited retention decisions.", "rationale": "Proposed grouping of source-grounded concerns for a host-attached mixin; the cited sources support concepts, not this hierarchy or its field names.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-008" ], "layers": [ { "id": "layer-decision", "name": "Authorized outcome", "description": "Record a separately mastered decision for retention, review, transfer, destruction or another profile-supported outcome. Review is an intermediate outcome, not proof of disposal.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ], "findings": [ { "id": "finding-decision", "name": "Disposition decision", "description": "Record a separately mastered decision for retention, review, transfer, destruction or another profile-supported outcome. Review is an intermediate outcome, not proof of disposal.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ], "questions": [ { "id": "q-decision-1", "text": "Which outcome has the competent authority selected for the exact scope?", "kind": "decision", "answer_data": [ "data-disposition-decision" ] }, { "id": "q-decision-2", "text": "What approval and validity conditions must an external executor check?", "kind": "authority", "answer_data": [ "data-action-conditions" ] }, { "id": "q-decision-3", "text": "What remains pending when the decision requires continued retention or later review?", "kind": "lifecycle", "answer_data": [ "data-deferred-action" ] } ], "data_elements": [ { "id": "data-disposition-decision", "name": "Disposition decision", "description": "Decision ID and revision, outcome code, reason and frozen scope; anonymisation or donation require explicit applicable authority and are not universal defaults.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ] }, { "id": "data-action-conditions", "name": "Action conditions", "description": "Required roles, separation of duties, evidence freshness, validity window and final hold check specified by the adopting profile.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ] }, { "id": "data-deferred-action", "name": "Deferred action", "description": "Review date, justification, responsible role and outstanding conditions; do not label a deferred decision as completed disposition.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-decision", "name": "Disposition authorization binding", "description": "Locally proposed evidence view for disposition decision. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-privacy", "name": "Purpose and exceptions", "description": "Associate a privacy request or purpose review with its qualified decision. Request handling and legal exception determination remain owned by the privacy process.", "source_refs": [ "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-privacy", "name": "Erasure reconciliation", "description": "Associate a privacy request or purpose review with its qualified decision. Request handling and legal exception determination remain owned by the privacy process.", "source_refs": [ "SRC-004", "SRC-005" ], "questions": [ { "id": "q-privacy-1", "text": "Which purpose or erasure request requires reconsidering continued retention?", "kind": "privacy", "answer_data": [ "data-privacy-review" ] }, { "id": "q-privacy-2", "text": "Which reasoned decision resolves the tension between erasure and preservation?", "kind": "exception", "answer_data": [ "data-privacy-resolution" ] }, { "id": "q-privacy-3", "text": "What permitted uses and recipient notifications apply to the retained subset?", "kind": "access", "answer_data": [ "data-retained-use" ] } ], "data_elements": [ { "id": "data-privacy-review", "name": "Privacy review", "description": "Request or purpose-review reference, affected scope, restricted identity link and applicable response deadline from the external process.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "data-privacy-resolution", "name": "Privacy resolution", "description": "Decision reference, permitted retained subset, exception basis and review time; a hold label alone does not establish a lawful exception.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "data-retained-use", "name": "Retained use", "description": "Purpose limitation, access restrictions, recipient references and notification evidence; archival designation does not automatically permit unlimited reuse.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-privacy", "name": "Retention and privacy reconciliation", "description": "Locally proposed evidence view for erasure reconciliation. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-handoff", "name": "Execution and custody evidence", "description": "Distinguish transfer acceptance, external destruction reports and residual copies.", "rationale": "Proposed grouping of source-grounded concerns for a host-attached mixin; the cited sources support concepts, not this hierarchy or its field names.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-transfer", "name": "Custody handoff", "description": "Reference an archival handoff without owning accession, arrangement or preservation. Delivery and acceptance are separately evidenced events.", "source_refs": [ "SRC-001", "SRC-008", "SRC-007" ], "findings": [ { "id": "finding-transfer", "name": "Archival transfer", "description": "Reference an archival handoff without owning accession, arrangement or preservation. Delivery and acceptance are separately evidenced events.", "source_refs": [ "SRC-001", "SRC-008", "SRC-007" ], "questions": [ { "id": "q-transfer-1", "text": "Which repository and accession reference receive the retained material?", "kind": "relationship", "answer_data": [ "data-archive-target" ] }, { "id": "q-transfer-2", "text": "What proves the receiving custodian accepted the identified transfer?", "kind": "evidence", "answer_data": [ "data-custody-receipt" ] }, { "id": "q-transfer-3", "text": "Which rights and restrictions accompany the archival handoff?", "kind": "security", "answer_data": [ "data-transfer-restrictions" ] } ], "data_elements": [ { "id": "data-archive-target", "name": "Archive target", "description": "Target repository, proposed accession ID, selection revision and transfer agreement reference.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008", "SRC-007" ] }, { "id": "data-custody-receipt", "name": "Custody receipt", "description": "Acceptance record, manifest, event time and rejected or missing items; dispatch or successful upload alone does not establish accepted custody.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008", "SRC-007" ] }, { "id": "data-transfer-restrictions", "name": "Transfer restrictions", "description": "Access and purpose restrictions, rights references and agreed disposition of source copies; archival execution is delegated.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-transfer", "name": "Transfer evidence binding", "description": "Locally proposed evidence view for archival transfer. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-001", "SRC-008", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-erasure", "name": "Execution coverage", "description": "Record external execution outcomes per scoped representation. A deleted pointer, unavailable file or batch acknowledgment is not proof of complete sanitization.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ], "findings": [ { "id": "finding-erasure", "name": "Destruction and residual copies", "description": "Record external execution outcomes per scoped representation. A deleted pointer, unavailable file or batch acknowledgment is not proof of complete sanitization.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ], "questions": [ { "id": "q-erasure-1", "text": "Which executor and approved method profile produced the reported result?", "kind": "process", "answer_data": [ "data-execution-binding" ] }, { "id": "q-erasure-2", "text": "Which members succeeded, failed or remain unverified in a disposition batch?", "kind": "quality", "answer_data": [ "data-member-results" ] }, { "id": "q-erasure-3", "text": "Which residual copies or backups remain subject to an explicit expiry and restore restriction?", "kind": "retention", "answer_data": [ "data-residual-copies" ] } ], "data_elements": [ { "id": "data-execution-binding", "name": "Execution binding", "description": "Executor job ID, decision revision, method profile and evidence reference; this model carries no destruction instructions.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "data-member-results", "name": "Member results", "description": "Per-member outcome, event time, failure reason, evidence and retry reference; partial success cannot be promoted to total completion.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "data-residual-copies", "name": "Residual copies", "description": "Replica or backup references, lawful residual basis, beyond-use controls, expected expiry, notification and restore-time reapplication evidence; no claim of immediate universal erasure.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-erasure", "name": "Disposition execution coverage record", "description": "Locally proposed evidence view for destruction and residual copies. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance", "name": "Evidence and review", "description": "Keep accountable assertions, minimal continuity and reviewable projections.", "rationale": "Proposed grouping of source-grounded concerns for a host-attached mixin; the cited sources support concepts, not this hierarchy or its field names.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008" ], "layers": [ { "id": "layer-proof", "name": "Attestation and provenance", "description": "Maintain resolvable references to statements about disposition and their provenance. Evidence masters retain their own lifecycle; integrity checks do not prove truth.", "source_refs": [ "SRC-007", "SRC-008", "SRC-006" ], "findings": [ { "id": "finding-proof", "name": "Evidence continuity", "description": "Maintain resolvable references to statements about disposition and their provenance. Evidence masters retain their own lifecycle; integrity checks do not prove truth.", "source_refs": [ "SRC-007", "SRC-008", "SRC-006" ], "questions": [ { "id": "q-proof-1", "text": "Who attests to each disposition result and what evidence supports that assertion?", "kind": "provenance", "answer_data": [ "data-attestation" ] }, { "id": "q-proof-2", "text": "Which verification scope and integrity checks support accepting the evidence?", "kind": "validation", "answer_data": [ "data-verification" ] }, { "id": "q-proof-3", "text": "What minimal reference can remain after lawful removal of the evidence payload?", "kind": "identity", "answer_data": [ "data-evidence-continuity" ] } ], "data_elements": [ { "id": "data-attestation", "name": "Attestation", "description": "Attesting role, evidence master ID and revision, related activity and assessment status; operator report and independent verification remain distinct.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-006" ] }, { "id": "data-verification", "name": "Verification", "description": "Verifier reference, checked items, method, result, digest or signature metadata and remaining uncertainty; no automatic trust from a checksum.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-006" ] }, { "id": "data-evidence-continuity", "name": "Evidence continuity", "description": "Nonrevealing tombstone or successor reference, governing retention authority and authorized removal record; no indefinite preservation of personal payload.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-proof", "name": "Disposition evidence index", "description": "Locally proposed evidence view for evidence continuity. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-007", "SRC-008", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-review", "name": "Change and reassessment", "description": "Track local review obligations and proposed mapping changes without editing the rule master. Exports must preserve unknowns, scopes and evidence limits.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008" ], "findings": [ { "id": "finding-review", "name": "Retention governance review", "description": "Track local review obligations and proposed mapping changes without editing the rule master. Exports must preserve unknowns, scopes and evidence limits.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-review-1", "text": "When must this binding be reviewed because authority, custody or purpose changed?", "kind": "temporal", "answer_data": [ "data-review-obligation" ] }, { "id": "q-review-2", "text": "What information is lost when this retention context is projected to another system?", "kind": "interoperability", "answer_data": [ "data-mapping-assessment" ] }, { "id": "q-review-3", "text": "Which scoped measures reveal overdue retention or incomplete disposition?", "kind": "measurement", "answer_data": [ "data-assurance-measures" ] } ], "data_elements": [ { "id": "data-review-obligation", "name": "Review obligation", "description": "Review cause, due date, assigned role, outcome reference and unresolved overdue status.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008" ] }, { "id": "data-mapping-assessment", "name": "Mapping assessment", "description": "Source and target schema versions, code mappings, unsupported holds or timing precision and tested loss report; conceptual alignment is not conformance.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008" ] }, { "id": "data-assurance-measures", "name": "Assurance measures", "description": "Snapshot time, population denominator, overdue review or unresolved member counts, evidence coverage and known exclusions; no fabricated compliance score.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-review", "name": "Retention review record", "description": "Locally proposed evidence view for retention governance review. Reference authoritative external records and preserve scope, revision, author and uncertainty; do not duplicate their operational lifecycle.", "media_or_form": [ "Structured metadata with external evidence references", "Human-readable review projection" ], "serial": true, "identity_strategy": "Authoritative master-system identifier and revision first; otherwise a governed IRI or Dimension-assigned UUID. Use a separate revision and sequence; dates and digests are not primary identity.", "source_refs": [ "SRC-001", "SRC-004", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "function-bind-scope", "name": "Record scope and schedule binding", "description": "Proposed local operation, not implemented. Attach a reviewed scope and authority revision to the local context.", "inputs": [ "Host master reference and selection revision", "Applicable schedule decision and profile" ], "outputs": [ "Binding revision or explicit unresolved-binding result" ], "preconditions": [ "Records steward authority", "Resolvable master and supplied classification rationale" ], "effects": [ "Create only a local binding; do not modify records or approve rules" ], "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "function-record-trigger", "name": "Record trigger assertion", "description": "Proposed local operation, not implemented. Capture event evidence and distinguish absent or disputed trigger inputs.", "inputs": [ "Trigger evidence and selected rule", "Prior local revision" ], "outputs": [ "Trigger assertion and reassessment-needed marker" ], "preconditions": [ "Source attribution and event precision provided", "Authorized update and expected revision match" ], "effects": [ "Append a local assertion or correction; do not fabricate dates or calculate universal deadlines" ], "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "function-record-hold-change", "name": "Record hold applicability or release", "description": "Proposed local operation, not implemented. Associate an authorized external notice with its affected local scope.", "inputs": [ "Notice or release reference", "Affected member snapshot and remaining hold references" ], "outputs": [ "Scoped hold observation or unresolved-authority refusal" ], "preconditions": [ "Notice authority established by the external process", "Partial scope and custodian acknowledgment status supplied" ], "effects": [ "Update local context and flag stale assessments; do not create legal holds, release them or operate freezes" ], "source_refs": [ "SRC-003" ] }, { "id": "function-attach-assessment", "name": "Attach eligibility and disposition assessment", "description": "Proposed local operation, not implemented. Link a versioned external evaluation and decision for review.", "inputs": [ "Evaluator result and input digest", "Decision reference and scope revision" ], "outputs": [ "Assessment binding or stale/mismatched-input rejection" ], "preconditions": [ "Inputs match current scope, rule, trigger and hold revisions", "Decision authority and restrictions are evidenced" ], "effects": [ "Record assessment freshness and outcome; no approval, enforcement or destructive effect" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "id": "function-record-outcome", "name": "Reconcile external disposition evidence", "description": "Proposed local operation, not implemented. Index per-member transfer or destruction reports and unresolved copies.", "inputs": [ "External executor reports or custody receipts", "Member manifest and evidence verification references" ], "outputs": [ "Scoped outcome index with partial, failed or unverified results" ], "preconditions": [ "Authorized evidence ingestion", "Result scope matches the supplied decision and no unsupported completion claim" ], "effects": [ "Create local evidence links; do not erase data, sanitize media, transfer custody or retry jobs" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "function-prepare-review", "name": "Prepare retention review view", "description": "Proposed local operation, not implemented. Produce a purpose-limited view of pending reviews, residual copies and mapping losses.", "inputs": [ "Context revisions and authorized view scope", "External policy and evidence status" ], "outputs": [ "Review view with exclusions and unresolved items" ], "preconditions": [ "Read permission at all requested scopes", "Observation time and population denominator supplied for counts" ], "effects": [ "Read-only projection; no schedule mutation, retention extension or legal-compliance certification" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-008" ] } ], "composition": [ { "target": "WM-REC-001", "relation": "REFERENCE", "purpose": "Host document or record master. Its content, identity and record lifecycle remain external; a non-document host must supply an equivalent pinned master binding.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-KNW-013", "relation": "REFERENCE", "purpose": "Reusable constraint and requirement rule master owns expression, applicability and rule lifecycle. This mixin carries the selected revision and subject operands only.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "target": "WM-XCT-038", "relation": "REFERENCE", "purpose": "External policy evaluator owns rule evaluation and explanation. Local functions record its input and output references without implementing its engine.", "required": false, "source_refs": [ "SRC-002", "SRC-003" ] }, { "target": "WM-XCT-021", "relation": "REFERENCE", "purpose": "Generic host lifecycle and transition semantics remain external. Eligibility, hold and execution observations are distinct subject-specific axes.", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "target": "WM-REC-010", "relation": "REFERENCE", "purpose": "Approval and exception decision master owns authority, rationale and decision revision; attaching a decision does not issue or approve it.", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] }, { "target": "WM-REC-015", "relation": "REFERENCE", "purpose": "Optional archival fonds or collection owns accession, arrangement and preservation. This mixin references transfer scope and accepted custody.", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "target": "WM-REC-011", "relation": "REFERENCE", "purpose": "Evidence record master owns original attestation and evidence validity; retain only retention-specific links and assessment context here.", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "target": "WM-REC-013", "relation": "REFERENCE", "purpose": "Operational log master owns event persistence and audit-trail mechanisms. This mixin indexes relevant events without recreating logging infrastructure.", "required": false, "source_refs": [ "SRC-007", "SRC-008" ] }, { "target": "PROV-O", "relation": "ALIGN", "purpose": "Conceptual mapping of subject, activity, agent, revision and invalidation references; an invalidation assertion is not a destruction certificate.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "PREMIS 3.0", "relation": "ALIGN", "purpose": "Overview-level preservation object, event, rights and agent alignment. No schema or archival repository conformance is asserted.", "required": false, "source_refs": [ "SRC-008" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "An adopting Dimension designates an accountable records steward and competent approval roles without assigning ownership to any product or company.", "Supply pinned host, schedule, evaluator, decision, custodian and evidence bindings plus jurisdiction and sector applicability profiles.", "Publish separate storage, interface and process bindings with authorization, concurrency, retention and incident rules before operating instances." ], "namespace_guidance": "Use a governed Dimension namespace for host-attached retention-context identifiers. Preserve external master identifiers and revisions; labels, timestamps and file paths are not identity.", "registry_links": [ "vr.wm-xct-035", "Candidate composition links in this specification require profile-level version pins; they do not amend the registry." ] }, "canon_and_patch": { "canonicalization_rules": [ "Research remains a noncanonical reviewable draft under the provider waiver.", "Keep schedule text and decisions in their masters; local normalized values retain original reference, unit, precision and interpretation provenance.", "Unknown, inapplicable, not-yet-observed and false are distinct; separate eligibility, approval, execution and verification axes." ], "patch_rules": [ "Require expected revision, scoped update authority, reason and evidence; invalidate stale assessments when scope, trigger, authority or hold inputs change.", "Corrections supersede assertions with traceable references subject to lawful retention; do not silently rewrite completed outcomes or preserve personal payload indefinitely." ], "compatibility_rules": [ "A new period, trigger meaning, outcome code or scope interpretation requires a versioned profile and migration assessment.", "Exports must report omitted holds, lost precision and unsupported outcome semantics; a lossy projection cannot authorize action." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier with issuer and revision", "Governed global identifier or IRI", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and an explicit offset or Z. Separate event time from observation and ingestion time. Preserve date-only legal deadlines and unknown precision without inventing a midnight instant.", "serial_naming_rule": "Name serial artifacts with a stable context identifier, artifact type and revision or sequence. Dates are metadata, not primary identifiers.", "integrity_rule": "Record content digest algorithm and signature verification when supplied, alongside provenance and scope. Hash integrity does not prove lawful authority, truth, accepted custody or eradication of every copy." }, "policies": [ "This mixin owns retention context only. External records, rules, policy evaluation, legal matters, audit logs, archival operations and destructive execution retain separate masters.", "An unresolved authority, trigger, scope or hold blocks an actionable local recommendation and creates a time-bounded review obligation; this is not authority for indefinite retention.", "Refresh holds and authority at execution time in the separately governed executor. No local assessment or cached approval grants permission to destroy.", "Apply minimum lawful evidence retention, privacy minimisation and purpose-specific access to this mixin itself; deletion of host payload and deletion of disposition evidence are distinct decisions.", "Controlled or dangerous subject matter is limited to authorization, retention and evidence policy; no operational handling or destruction procedure is provided." ], "crud": { "read": [ "Resolve only authorized host and evidence references; restrict hold reasons, personal identifiers and sensitive locations." ], "create": [ "Create a local context only with accountable role, master reference, scope and provenance. Missing schedule or trigger facts are explicit gaps requiring review." ], "update": [ "Use optimistic concurrency, scoped authority and reasoned correction; separate notice receipt from implemented hold and partial outcome from completion." ], "delete": [ "Retire local bindings when superseded; the adopting Dimension retention policy and separately authorized storage executor own deletion of this model's payload.", "Before deletion check applicable holds and retention duties for the context and its evidence. Keep only a minimal lawful tombstone where justified, with its own review or expiry; neither evidence nor history is retained forever by default.", "Removing the mixin never deletes the host, releases a hold or removes a master evidence record." ] }, "roles": [ { "name": "Records steward", "responsibilities": [ "Maintain accurate scope and schedule references and route unknown applicability for review." ] }, { "name": "Competent disposition authority", "responsibilities": [ "Approve or refuse outcomes through the external decision process; assess unresolved legal conflicts." ] }, { "name": "Hold authority", "responsibilities": [ "Issue and release notices in the external matter process and define precise covered scope." ] }, { "name": "Custodian or executor", "responsibilities": [ "Acknowledge notices and supply scoped execution or transfer evidence under separate authorization." ] }, { "name": "Privacy reviewer", "responsibilities": [ "Assess purpose, minimisation and erasure exceptions through the applicable qualified process." ] }, { "name": "Evidence reviewer", "responsibilities": [ "Check attestation coverage, partial outcomes and residual copies independently of reported execution where the profile requires." ] } ], "access": { "default_rule": "Deny by default; permit role- and purpose-scoped access without disclosing restricted host content through metadata.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency or privileged access requires a recorded competent decision, narrow scope and expiry; it never bypasses a preservation duty or automatically authorizes destruction.", "Hold matters, subject identity and storage locations can require separate restricted views; absence in a view must not be read as absence of a hold." ], "audit_requirements": [ "Delegate tamper-evident access and change logging to the operational log master; reference actor, purpose, affected revision, time and outcome here.", "Review rejected updates, scope changes and access exceptions without indefinitely retaining sensitive payload in logs." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read AGENTS.md and research assurance holds.", "Read spec.yaml, adopting Dimension policies and pinned composition bindings before populating or changing an instance.", "Resolve only authorized evidence; report unknowns and defer externally effective actions to their approved processes." ] } }, "coverage": { "claim": "Source-grounded proposed host-attached retention and disposition mixin, with a separate frozen local no-tools Codex self-audit. Selected US federal records, UK privacy and preservation/provenance sources inform the design without establishing universal law or operational conformance. Reviewable draft only; independent review, source/version verification, legal profiles and executable bindings remain holds.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Host-attached context identity, scope revision and external master references are explicit." }, { "dimension": "lifecycle", "status": "covered", "notes": "Local observation axes distinguish eligibility, hold, decision, execution and verification; host lifecycle is referenced." }, { "dimension": "relationships", "status": "covered", "notes": "Candidate references preserve separate record, rule, evaluator, decision, archive and evidence ownership." }, { "dimension": "temporal", "status": "covered", "notes": "Event and observation times, cutoff, calendar, precision, missing triggers and reassessment are explicit." }, { "dimension": "provenance", "status": "covered", "notes": "Evidence source, role, activity and revision links; provenance is not proof of truth." }, { "dimension": "ownership", "status": "covered", "notes": "Accountable adopting-Dimension roles and external master boundaries; no brand or company is assigned ownership." }, { "dimension": "validation", "status": "gap", "notes": "Repository research checks do not validate operational instances; nested schemas, fixtures and evaluator/executor bindings remain pending." }, { "dimension": "access", "status": "covered", "notes": "Restricted hold metadata and recipient-specific views at all four hierarchy scopes." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Own context and evidence are subject to separate lawful retention, scoped holds and minimal expiring tombstones." }, { "dimension": "interoperability", "status": "gap", "notes": "PROV-O and PREMIS alignments are conceptual; mappings and loss tests are not implemented." }, { "dimension": "direct properties", "status": "covered", "notes": "Rule references, period units, scope, eligibility, hold and outcome are informational properties. Physical measurements of the mixin are not applicable." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Recognize retention context from host, rule, trigger and evidence links; do not infer disposition from an absent file." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Six proposed local functions have inputs, preconditions, outcomes and limited effects; no runtime executor is delivered." }, { "dimension": "spatial and custody", "status": "covered", "notes": "Custodians, storage jurisdiction and off-site coverage are references rather than geometry of the abstract mixin." }, { "dimension": "source assurance", "status": "gap", "notes": "Browser-selected primary evidence available for eight sources; no direct HTTP check attempted because the owner reports sandbox blocking. Current versions and legal applicability remain open." }, { "dimension": "independent review", "status": "gap", "notes": "Claude and Grok skipped under owner waiver; a separate local no-tools Codex audit is required and cannot count as external review." } ], "known_omissions": [ "Jurisdiction- and sector-specific schedules, qualified legal precedence and current consolidated law are not supplied.", "Full NIST sanitization procedures and PREMIS dictionary/schema conformance were not reviewed; no technical destruction recipe is supplied.", "Nested field schemas, date arithmetic engine, live integrations, pinned neighbor specifications and executable instance fixtures are absent.", "Actual backup inventories, cryptographic key dependencies, distributed propagation and restore-time remediation need system-specific operational evidence.", "No independently authored second-provider research exists for this run." ], "conflicts": [], "regional_assumptions": [ "US federal NARA examples and UK ICO guidance inform concepts separately; no US rule is applied to UK data or vice versa.", "ICO pages are marked under review following legislative change; the NARA freeze FAQ cites older regulation numbers. These sources do not establish current-law compliance.", "The registry has no legacy alias and no recorded relation edges for this model; all proposed composition links require review and version pins." ], "adversarial_checks": [ "A due date with an active or unknown hold cannot become a destruction instruction.", "Partial release leaves overlapping holds effective; release does not automatically restart the clock or authorize action.", "Unknown trigger and missing schedule stay unknown and require bounded review, not zero-duration deletion or indefinite default retention.", "Successful upload does not establish accepted archival custody; deletion of a pointer does not establish sanitization.", "A single successful batch item cannot establish complete disposition; residual copies and backups remain explicit.", "Provenance, a signature or a checksum does not independently prove that the reported action occurred.", "Disposition evidence and tombstones also need a lawful purpose, retention policy and possible erasure." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "mixin", "status": "accepted", "rationale": "The registry and result agree on mixin. A retention context depends on a separately mastered host item or bounded set; local context identity does not turn it into an independent record, schedule, case, evaluator or executor. A set binding references membership without owning its members. No legacy alias or recorded relation edge requires reconciliation." }, "decisions": [ { "concept": "Host scope and mixin identity", "disposition": "accepted", "rationale": "The binding finding records a stable host or selection revision, copies and accountable steward. Neither set membership nor local revision identity imports host content or aggregate lifecycle ownership." }, { "concept": "Schedule ownership and precedence", "disposition": "qualified", "rationale": "The authority finding binds an approved external item and applicability decision. Competing requirements remain reviewable gaps; the model does not apply a universal newest-rule or longest-duration rule across jurisdictions." }, { "concept": "Trigger and date arithmetic", "disposition": "accepted with delegation", "rationale": "Trigger and eligibility findings separate observed event, cutoff semantics and external evaluation. Missing or corrected events require reassessment; no invented date, generic clock restart or destruction date for permanent material is prescribed." }, { "concept": "Eligibility versus permission", "disposition": "separated", "rationale": "A due date, recorded eligible label or evaluator output cannot authorize disposition. Exact scope, authority, hold freshness and an external decision are separately represented, with execution-time checking delegated to the executor." }, { "concept": "Hold and release semantics", "disposition": "accepted with scope limits", "rationale": "Both hold findings distinguish received notices from implemented freezes, cover off-site acknowledgments and require remaining-hold review after partial release. Local recording neither creates legal effect nor releases a hold." }, { "concept": "Outcome and review states", "disposition": "accepted", "rationale": "Disposition decisions reference their own master and preserve review or continued-retention outcomes. An intermediate review is not completed disposal, and a profile must authorize any alternative outcome such as donation or anonymisation." }, { "concept": "Privacy and preservation tension", "disposition": "qualified", "rationale": "The privacy finding requires a reasoned external decision and allowed uses for retained subsets. It rejects a hold label as sufficient legal exception and does not infer unrestricted reuse from an archival label." }, { "concept": "Transfer and erasure evidence", "disposition": "separated", "rationale": "Transfer requires evidence of accepted custody, not dispatch alone. Destruction coverage preserves per-member failures, unknowns and residual copies, so a batch acknowledgment or missing pointer cannot establish complete erasure." }, { "concept": "Evidence and its own retention", "disposition": "accepted with minimisation", "rationale": "The evidence finding distinguishes attestation, verification and integrity. Its continuity fields and service delete rules allow lawful payload removal and minimal expiring references; the supplement's blanket ban on deleting evidence is rejected." }, { "concept": "Direct properties and recognition", "disposition": "qualified", "rationale": "Scope, authority, period units, state and outcome are informational properties. Physical measurements of the abstract mixin are inapplicable, but the supplement's broader no-properties claim is rejected. An unavailable file is not a reliable disposition observation." }, { "concept": "Proposed functions and composition", "disposition": "accepted as local design", "rationale": "All six functions have limited local or read-only effects and refuse or flag unsupported inputs. Candidate references leave rule expressions, evaluation, approval, legal matters, logging, archival operations and destructive execution with separate owners." }, { "concept": "Source scope and currency", "disposition": "limited", "rationale": "Eight primary sources support selected concepts, not the exact hierarchy. Older NARA regulatory citations, ICO review notices and overview-only NIST/PREMIS admission remain explicit. Direct HTTP checks were not attempted, so no measured current availability or current-law claim is possible." }, { "concept": "Executable schemas and operational assurance", "disposition": "deferred", "rationale": "Candidate answer fields and optional object groups do not enforce instance completeness. Required host bindings, nested schemas, pinned neighbor specifications, concurrency behavior, temporal fixtures and mapping tests must be supplied before operational use." }, { "concept": "Independent research and audit attribution", "disposition": "waived and held", "rationale": "Claude and Grok were skipped under explicit owner instruction. This separate frozen no-tools phase is a Codex self-audit, not independently authored research or a second-provider review; no waived-provider material can be merged." } ], "publicationHolds": [ "Independent external review is absent. Claude and Grok were skipped under the owner-authorized single-provider waiver; the separate local no-tools Codex self-audit is not an independent second-provider review.", "Live source and version verification remains incomplete. Direct HTTP requests were not attempted because the owner reports sandbox blocking; zero HTTP 200 responses were measured, not eight failed checks. Browser-selected evidence for eight sources is documented separately. Run check_sources.py outside the sandbox and review substantive versions and claims.", "Qualified jurisdiction and sector review is required before operational use. The NARA freeze FAQ cites older regulations and the ICO pages are under legislative review; current legal applicability, precedence, lawful periods, exceptions, archival rights and source reuse terms remain unverified.", "Executable instance schemas, pinned host and neighbor bindings, temporal and partial-outcome fixtures, policy evaluator and executor integrations, full standards review and tested PROV-O/PREMIS mappings are incomplete. No runtime, sanitization or legal-compliance certification is claimed.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Reconcile source versions and current consolidated legal rules with each adopting jurisdiction and sector profile, including multiple duties, scoped holds and privacy exceptions.", "Build nested instance schemas and adversarial fixtures for unknown triggers, calendar boundaries, concurrent holds, partial releases, stale approvals, partial batches, backup restoration and minimal evidence retention.", "Pin and test host, rule, evaluator, decision, archive and evidence interfaces with loss-aware mappings and authorized execution boundaries.", "Obtain independent external review before any canonical or publishable-draft promotion." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 12, "questions": 36, "artifacts": 12, "functions": 6 } }