# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-21T17:23:35.362988+00:00", "synthesisSha256": "f080bb8789bfc85f47ef143ad0846a544a7cdfe3909efd51eb396ee4b445cd38", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-XCT-036", "registryId": "vr.wm-xct-036", "name": "Alias / Same-as Mapping", "version": "0.3.2-enterprise.1", "previousVersions": [ { "version": "0.3.1-enterprise.1", "url": "https://ver.cy/models/wm-xct-036-alias-same-as-mapping/versions/0.3.1-enterprise.1/" }, { "version": "0.3.0-research.1", "url": "/models/wm-xct-036-alias-same-as-mapping/versions/0.3.0-research.1/" } ], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.ALS" ], "tags": [ "alias", "same", "as", "mapping", "xct.als" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-036-alias-same-as-mapping/", "sourceUrl": "https://ver.cy/enterprise/research/em-xct-01/", "model": { "registry_id": "vr.wm-xct-036", "model_id": "WM-XCT-036", "name": "Alias / Same-as Mapping", "entry_kind": "mixin", "purpose": "Provide a format-neutral mixin for federated identity equivalence: identified, versioned assertions that two externally owned references denote the same subject, carrying issuing authority, applicability, evidence and confidence, without merging, renaming or taking ownership of either endpoint.", "scope_statement": "WM-XCT-036 models the alias / same-as assertion as a first-class but weakly identified mixin attached to a host record. It covers the assertion envelope (its own identifier and version, issuer and authorship, assertion and effective times, tenant or adopting Dimension, jurisdiction, purpose and applicable entity/type scope); the endpoint-reference boundary (source and target roles, locator form and namespace or scheme binding, version pins, composite keys, immutable snapshots versus live references, explicit provenance locators and recorded resolution status); the shape of the claim (one-to-one, one-to-many, many-to-one, many-to-many and conditional mappings with explicit membership, ordering and condition guards); the relation-classification slot bound to external predicate vocabularies; the evidence, justification and confidence attached to the claim; the assertion's own lifecycle from proposal through assertion, dispute, supersession, retraction and tombstoning; and the governance that names issuing authority and records conflicts without resolving them. It deliberately holds no power over the things it links: it never allocates or renames an identifier, never edits an endpoint record, and never executes matching, merge, redirect, reasoning closure, authorization or audit.", "in_scope": [ "Identity and versioning of the assertion itself, distinct from every identifier cited at its endpoints", "Issuer, authorship, review attribution, assertion time, effective window and separately recorded observation or ingestion time", "Purpose, tenant or adopting Dimension, jurisdiction, licence and applicable entity/type scope that bound the claim", "Source and target role assignment, directionality and the explicit statement of endpoint non-ownership", "Endpoint locator form, namespace or scheme binding, compact-form expansion and recorded comparison or normalization level", "Endpoint version pins, composite keys, immutable snapshot versus live reference mode and last recorded resolution status", "Explicit provenance locators: originating set or linkset, primary source, derivation lineage and issue references", "Cardinality of the claim (one-to-one, one-to-many, many-to-one, many-to-many) with explicit membership, combination rule and ordering", "Conditional and qualified mappings expressed as attribute-value guards rather than hidden in repeated fields", "The relation-classification slot that binds the claim to an external predicate vocabulary, and the evidence, justification and confidence carried with it", "The assertion's own lifecycle states and supersession, retraction and tombstone semantics", "Degenerate and error states: absence versus explicit unknown versus explicit not-same, dangling and unresolved endpoints, malformed or relative references, self links, duplicate envelopes and conflicting endpoint version pins" ], "out_of_scope": [ "Allocation, minting, naming, formatting, deprecation or non-reuse enforcement of either endpoint identifier", "The endpoint records themselves: their attributes, descriptions, labels, classifications and lifecycles", "Definition of the predicate vocabularies (owl:sameAs, owl:differentFrom, skos:*Match, ConceptMap relationship codes) and their formal semantics", "Entailment, transitive closure, equivalence-class computation and any reasoner behaviour over asserted pairs", "Record-linkage and matching engine execution: candidate generation, blocking, similarity functions and scoring algorithms", "Data merge, survivorship, golden-record construction and master-data consolidation", "Dereference, redirect execution, HTTP status handling and resolution-service operation", "Authorization decisions, policy evaluation and enforcement", "Audit-trail record structure, storage, retention and tamper evidence", "Human identity verification, proofing or credential issuance for the subjects at either endpoint" ], "boundary_notes": [ { "neighbor": "WM-XCT-011 Identifier / Reference (registered parent)", "distinction": "The parent owns identifier syntax, scheme and namespace registration, allocation, non-reuse guarantees and reference resolution semantics generally. WM-XCT-036 specializes only the case where two such references are asserted to denote the same subject, and reuses the parent's identifier and resolution machinery by reference rather than restating it.", "source_refs": [ "SRC-004", "SRC-005", "SRC-002" ] }, { "neighbor": "Endpoint entity and record models at each side of the assertion", "distinction": "Those models own the described subjects, their attributes and their lifecycles. This model carries only role-bearing locators, version pins, snapshot digests and recorded resolution observations; it never imports endpoint content and never mutates an endpoint record.", "source_refs": [ "SRC-007", "SRC-006", "SRC-010" ] }, { "neighbor": "Identifier issuing and registration authority model", "distinction": "The issuing authority allocates identifiers, guarantees uniqueness, and decides deprecation and tombstoning of its own identifiers. This model cites that authority and its version tokens; it never allocates, reassigns or retires an endpoint identifier.", "source_refs": [ "SRC-017", "SRC-014" ] }, { "neighbor": "Relation classification and semantic predicate vocabularies", "distinction": "Vocabulary owners define what owl:sameAs, owl:differentFrom, skos:exactMatch, skos:closeMatch and ConceptMap relationship codes mean and entail. This model holds a typed predicate slot that names one such term plus an optional negation modifier; it does not define, extend or reinterpret those terms.", "source_refs": [ "SRC-001", "SRC-003", "SRC-013" ] }, { "neighbor": "Formal equivalence closure and reasoning model", "distinction": "Entailment, transitive closure and equivalence-class materialisation belong to a reasoning model. This model supplies asserted pairs as input and explicitly forbids chaining assertions locally, because skos:closeMatch is deliberately non-transitive while skos:exactMatch is transitive and owl:sameAs propagates to all properties.", "source_refs": [ "SRC-003", "SRC-001", "SRC-012" ] }, { "neighbor": "Record-linkage and matching engine model", "distinction": "The matching engine generates candidates and computes similarity. This model records the resulting justification locator, tool reference and creator-supplied confidence as evidence about a claim; it does not execute, tune or reproduce the scoring.", "source_refs": [ "SRC-011", "SRC-012" ] }, { "neighbor": "Authorization and access decision model", "distinction": "That model evaluates and enforces access. WM-XCT-036 supplies tenant, jurisdiction, purpose and licence attributes as decision inputs, and separates the DID-style distinction between a subject, a controller and an assertion about a subject; it makes no access decision and stores no decision record.", "source_refs": [ "SRC-014", "SRC-013" ] }, { "neighbor": "Audit and event-log model", "distinction": "Assertion creation, supersession, retraction and tombstoning emit events for external capture. Audit-record structure, retention, integrity and query are owned entirely by the audit model; this model stores no audit trail and offers no tamper-evidence guarantee.", "source_refs": [ "SRC-009", "SRC-008" ] } ] }, "sources": [ { "id": "SRC-001", "title": "OWL 2 Web Ontology Language Structural Specification and Functional-Style Syntax (Second Edition)", "organization": "W3C", "url": "https://www.w3.org/TR/owl2-syntax/", "version_or_date": "W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:10:00Z", "relevance": "Section 9.6 defines individual equality (owl:sameAs) and individual inequality (owl:differentFrom) as assertion axioms, giving the normative distinction between asserting sameness and asserting explicit not-sameness." }, { "id": "SRC-002", "title": "RDF 1.2 Concepts and Abstract Syntax", "organization": "W3C", "url": "https://www.w3.org/TR/rdf12-concepts/", "version_or_date": "W3C Candidate Recommendation Snapshot, 07 April 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:12:00Z", "relevance": "Requires IRIs to be absolute and resolved per RFC 3986, mandates exact code-point comparison with no normalization before comparison, and defines triple terms and rdf:reifies, which give a statement its own referable identity." }, { "id": "SRC-003", "title": "SKOS Simple Knowledge Organization System Reference", "organization": "W3C", "url": "https://www.w3.org/TR/skos-reference/", "version_or_date": "W3C Recommendation, 18 August 2009", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:14:00Z", "relevance": "Defines skos:mappingRelation, exactMatch, closeMatch, broadMatch, narrowMatch and relatedMatch, with exactMatch symmetric and transitive and closeMatch deliberately non-transitive to avoid compound error across chained mappings." }, { "id": "SRC-004", "title": "RFC 3986: Uniform Resource Identifier (URI): Generic Syntax", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc3986.html", "version_or_date": "STD 66, January 2005", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:16:00Z", "relevance": "Section 6 gives the comparison and normalization ladder and the rule that comparison minimises false negatives while strictly avoiding false positives; states that a URI provides identification only and access is neither guaranteed nor implied." }, { "id": "SRC-005", "title": "RFC 3987: Internationalized Resource Identifiers (IRIs)", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc3987.html", "version_or_date": "Proposed Standard, January 2005", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:17:00Z", "relevance": "Defines IRI-to-URI mapping, requires reliance on pre-character-normalized (NFC) IRIs rather than normalizing at comparison time, and repeats the graduated comparison ladder for internationalized locators." }, { "id": "SRC-006", "title": "RFC 8288: Web Linking", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc8288.html", "version_or_date": "Internet Standard, October 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:19:00Z", "relevance": "Defines the four-part link model (context, relation type, target, target attributes) and the anchor parameter that moves a link's context to a third resource, which is the structural precedent for an assertion about two externally owned endpoints." }, { "id": "SRC-007", "title": "RFC 9264: Linkset: Media Types and a Link Relation Type for Link Sets", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc9264.html", "version_or_date": "Proposed Standard, July 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:21:00Z", "relevance": "Standardises third-party links, where a party publishes links about resources it does not host, and requires absolute anchors and hrefs for portability; the direct precedent for an assertion envelope whose endpoints are owned elsewhere." }, { "id": "SRC-008", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "Proposed Standard, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:22:00Z", "relevance": "Defines the date-time production with a mandatory seconds field and a mandatory time-offset of Z or a numeric offset, and the distinct semantics of -00:00 where UTC is known but the local offset is not." }, { "id": "SRC-009", "title": "PROV-O: The PROV Ontology", "organization": "W3C", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:24:00Z", "relevance": "Supplies attribution, derivation, generation-time and primary-source terms, prov:Bundle for naming a set of provenance descriptions, and prov:alternateOf / prov:specializationOf as weaker-than-identity alternatives to sameAs." }, { "id": "SRC-010", "title": "Describing Linked Datasets with the VoID Vocabulary", "organization": "W3C", "url": "https://www.w3.org/TR/void/", "version_or_date": "W3C Interest Group Note, 03 March 2011", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:26:00Z", "relevance": "Defines void:Linkset with void:linkPredicate, void:subjectsTarget and void:objectsTarget, establishing that a set of equivalence links declares which dataset supplies subjects and which supplies objects, i.e. explicit endpoint directionality at set level." }, { "id": "SRC-011", "title": "Simple Standard for Sharing Ontological Mappings (SSSOM) specification", "organization": "Mapping Commons", "url": "https://mapping-commons.github.io/sssom/dev/", "version_or_date": "Development specification snapshot, accessed 2026-09-04", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:28:00Z", "relevance": "Defines the mapping slots used here as alignment targets: subject_id, predicate_id, object_id, mapping_justification, predicate_modifier, mapping_cardinality, subject_source and object_source with version slots, curie_map, mapping_date, author_id, licence and confidence; only predicate_id and mapping_justification are required." }, { "id": "SRC-012", "title": "A Simple Standard for Sharing Ontological Mappings (SSSOM)", "organization": "Database (Oxford Academic)", "url": "https://academic.oup.com/database/article/doi/10.1093/database/baac035/6591806", "version_or_date": "Database, volume 2022, doi:10.1093/database/baac035, 25 May 2022", "source_type": "scientific", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:30:00Z", "relevance": "First-party description of SSSOM by its authors: argues that bare equivalence predicates obscure scope differences, that mappings need explicit justification and provenance, and acknowledges that mappings as standardised carry no context, which is the counterexample motivating explicit purpose scope here." }, { "id": "SRC-013", "title": "HL7 FHIR R5 ConceptMap Resource", "organization": "HL7 International", "url": "https://hl7.org/fhir/R5/conceptmap.html", "version_or_date": "FHIR Release 5 (5.0.0)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:33:00Z", "relevance": "Provides normative structures for canonical url plus business version and versionAlgorithm, jurisdiction and purpose, group.source/sourceVersion and group.target/targetVersion pinning, element.noMap, group.unmapped modes, target.relationship codes, and dependsOn/product attribute-value guards for conditional mappings." }, { "id": "SRC-014", "title": "Decentralized Identifiers (DIDs) v1.0", "organization": "W3C", "url": "https://www.w3.org/TR/did-core/", "version_or_date": "W3C Recommendation, 19 July 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:35:00Z", "relevance": "Defines alsoKnownAs as a set of RFC 3986 URIs asserting other identifiers for the same subject, warns that its presence does not prove the assertion true, advises independent verification, and recommends not treating the pair as equivalent without a reciprocated inverse relationship; also separates subject, controller and document." }, { "id": "SRC-015", "title": "Decentralized Identifier Resolution (DID Resolution) v1.0", "organization": "W3C", "url": "https://www.w3.org/TR/did-resolution/", "version_or_date": "W3C Candidate Recommendation Draft, 28 August 2026", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:37:00Z", "relevance": "Defines equivalentId (a set, guaranteed logically equivalent to id, retained by requesting parties so later interactions are handled as equivalent) and canonicalId (single value, used as the primary identifier with all others treated as secondary aliases) as authority-backed contrasts to unverified alsoKnownAs claims." }, { "id": "SRC-016", "title": "Link Relation Types registry", "organization": "IANA", "url": "https://www.iana.org/assignments/link-relations/link-relations.xhtml", "version_or_date": "Registry, last updated 2026-06-12", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:39:00Z", "relevance": "Authoritative evidence that no 'same-as' relation type is registered, and that canonical, alternate, duplicate, describedby, via, memento and original carry narrower representation-level or provenance meanings; constrains link-shaped projections of this model." }, { "id": "SRC-017", "title": "Identifiers for the 21st century: How to design, provision, and reuse persistent identifiers to maximize utility and impact of life science data", "organization": "PLOS Biology", "url": "https://journals.plos.org/plosbiology/article?id=10.1371/journal.pbio.2001414", "version_or_date": "PLOS Biology 15(6):e2001414, doi:10.1371/journal.pbio.2001414, 29 June 2017", "source_type": "scientific", "primary_source": false, "authority_tier": 2, "accessed_at": "2026-09-04T09:41:00Z", "relevance": "Identifier-authority guidance: local identifiers require a prefix binding to be resolvable, prefixes should be registered against a URI pattern, published identifiers may be deprecated but must never be deleted or reassigned, and retired identifiers should continue to resolve to a tombstone." }, { "id": "SRC-018", "title": "OWL 2 Web Ontology Language Structural Specification and Functional-Style Syntax (Second Edition)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/2012/REC-owl2-syntax-20121211/", "version_or_date": "W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Defines the SameIndividual and DifferentIndividuals axioms and their RDF mapping to owl:sameAs and owl:differentFrom, grounding the strict-identity and explicit not-same relation kinds." }, { "id": "SRC-019", "title": "OWL 2 Web Ontology Language Direct Semantics (Second Edition)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/owl2-direct-semantics/", "version_or_date": "W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Gives the satisfaction conditions for SameIndividual, where all named individuals map to the identical domain element, and for DifferentIndividuals, establishing that strict identity is an equality relation and therefore reflexive, symmetric and transitive." }, { "id": "SRC-020", "title": "SKOS Simple Knowledge Organization System Reference", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/2009/REC-skos-reference-20090818/", "version_or_date": "W3C Recommendation, 18 August 2009", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Normative source for skos:exactMatch, skos:closeMatch, skos:mappingRelation and the label properties. S44 makes closeMatch, exactMatch and relatedMatch symmetric; S45 makes only exactMatch transitive; S42 makes exactMatch a sub-property of closeMatch; S46 makes exactMatch disjoint with broadMatch and relatedMatch." }, { "id": "SRC-021", "title": "RDF 1.1 Concepts and Abstract Syntax", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/rdf11-concepts/", "version_or_date": "W3C Recommendation, 25 February 2014", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "States that IRIs have global scope so two appearances of an IRI denote the same resource, that the IRI owner determines the intended referent, and separates the IRI, the resource denoted and any retrieved representation." }, { "id": "SRC-022", "title": "Architecture of the World Wide Web, Volume One", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/webarch/", "version_or_date": "W3C Recommendation, 15 December 2004", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Defines URI collision, where the same URI directly identifies different resources, and URI aliases, and gives the good-practice constraint that a URI owner should not associate arbitrarily different URIs with the same resource. Grounds the identifier-alias plane and the resource versus representation distinction." }, { "id": "SRC-023", "title": "RFC 9110: HTTP Semantics", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9110.html", "version_or_date": "STD 97, RFC 9110, June 2022, Internet Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Section 15.4 distinguishes permanent redirection (301, 308) from temporary redirection (302, 303, 307) and frames redirection as guidance on which URI to target for future requests, not as an assertion that two resources denote the same entity." }, { "id": "SRC-024", "title": "RFC 6596: The Canonical Link Relation", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc6596.html", "version_or_date": "RFC 6596, April 2012, Informational", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Defines rel=canonical as specifying the preferred IRI from a set of resources whose content is duplicative or a superset, an explicitly representation-level preference and not a referent-identity claim; it is also informational rather than standards-track." }, { "id": "SRC-025", "title": "schema.org property: sameAs", "organization": "Schema.org", "url": "https://schema.org/sameAs", "version_or_date": "Schema.org release v30.0, 2026-03-19", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Defines sameAs as the URL of a reference web page that unambiguously indicates the item's identity, with expected type URL on domain Thing. Confirms that schema.org sameAs is a reference-page pointer, not an OWL identity axiom." }, { "id": "SRC-026", "title": "DCMI Metadata Terms", "organization": "Dublin Core Metadata Initiative (DCMI)", "url": "https://www.dublincore.org/specifications/dublin-core/dcmi-terms/", "version_or_date": "2020-01-20", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Defines dcterms:replaces and dcterms:isReplacedBy as a related resource supplanted, displaced or superseded by the described resource and the inverse, plus dcterms:identifier, grounding the referent-replacement plane and the distinction between replacement and equivalence." }, { "id": "SRC-027", "title": "HL7 FHIR Release 5: Patient resource, including Patient.link", "organization": "Health Level Seven International (HL7)", "url": "https://hl7.org/fhir/R5/patient.html", "version_or_date": "FHIR R5, version 5.0.0", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Provides a production example of a record-equivalence taxonomy with four disjoint link types (replaced-by, replaces, refer, seealso) plus an active flag, demonstrating that record supersession and record cross-reference are distinct kinds and that neither equals real-world entity identity." }, { "id": "SRC-028", "title": "A Simple Standard for Sharing Ontological Mappings (SSSOM)", "organization": "Matentzoglu, Balhoff, Bello and colleagues, in Database (Oxford)", "url": "https://pmc.ncbi.nlm.nih.gov/articles/PMC9216545/", "version_or_date": "Database (Oxford), 2022:baac035, 2022, doi 10.1093/database/baac035", "source_type": "scientific", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Defines a mapping as subject_id, predicate_id and object_id with justification, confidence, subject and object type, cardinality and a predicate modifier that negates the predicate; argues that mappings lacking semantics and provenance metadata are unsafe to reuse." }, { "id": "SRC-029", "title": "Wikidata Property P460: said to be the same as", "organization": "Wikimedia and the Wikidata community", "url": "https://www.wikidata.org/wiki/Property:P460", "version_or_date": "Live property page, state as accessed 2026-09-04", "source_type": "registry", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "A deployed, symmetric, deliberately hedged sameness property described as this item is said to be the same as that item though this may be uncertain or disputed, with sourcing-circumstance and determination-method qualifiers; the contrasting P1889 different from and P2888 exact match show a live three-way split between probable, negative and exact claims." }, { "id": "SRC-030", "title": "When owl:sameAs Isn't the Same: An Analysis of Identity in Linked Data", "organization": "Halpin, Hayes, McCusker, McGuinness and Thompson, ISWC 2010, Springer LNCS 6496", "url": "https://link.springer.com/chapter/10.1007/978-3-642-17746-0_20", "version_or_date": "International Semantic Web Conference 2010, LNCS volume 6496", "source_type": "scientific", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Secondary evidence of systematic owl:sameAs misuse in deployed Linked Data, of identity behaving as a scale rather than a binary, and of referentially opaque contexts where identity substitution is invalid. Used to discover omissions and competing interpretations, not to establish normative structure." }, { "id": "SRC-031", "title": "OWL 2 Web Ontology Language Primer (Second Edition)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/owl2-primer/", "version_or_date": "W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "States that OWL does not assume that different names denote different individuals, so difference must be asserted explicitly. Grounds the rule that absence of an alias assertion is not a not-same claim." }, { "id": "SRC-032", "title": "PROV-DM: The PROV Data Model", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-dm/", "version_or_date": "W3C Recommendation 30 April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:06:00Z", "relevance": "Defines alternateOf and specializationOf for entities that present aspects of the same thing, plus hadPrimarySource, wasRevisionOf, wasInvalidatedBy and Bundle for provenance-of-provenance: directly supports lineage, supersession and non-destructive revision of alias assertions." }, { "id": "SRC-033", "title": "Data on the Web Best Practices: Data Quality Vocabulary", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vocab-dqv/", "version_or_date": "W3C Working Group Note 15 December 2016", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:09:00Z", "relevance": "QualityMeasurement, Metric, value, isMeasurementOf, computedOn, QualityAnnotation and QualityCertificate, with PROV reused for the provenance of quality assessments: the pattern for attaching calibration and evaluation results without inventing a local metric model." }, { "id": "SRC-034", "title": "SSSOM specification: Mapping and MappingSet data model", "organization": "Mapping Commons / SSSOM community", "url": "https://mapping-commons.github.io/sssom/dev/spec-model/", "version_or_date": "SSSOM specification version 1.1 (sssom_version slot introduced), accessed 2026-09-04", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:10:00Z", "relevance": "First-party technical definition of the mapping metadata surface: mapping_justification, confidence, similarity_score and measure, mapping_tool and mapping_tool_version, author_id, creator_id, reviewer_id, mapping_date, subject_source_version, predicate_modifier, curation_rule and mapping_cardinality." }, { "id": "SRC-035", "title": "A Simple Standard for Sharing Ontological Mappings (SSSOM)", "organization": "Matentzoglu et al., Database (Oxford University Press)", "url": "https://arxiv.org/abs/2112.07051", "version_or_date": "Submitted 13 December 2021; published in Database, doi:10.1093/database/baac035", "source_type": "scientific", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:11:00Z", "relevance": "Peer-reviewed argument that mappings circulated without justification, confidence and review provenance cause incorrect assumptions and are unsafe for precision-critical use, and that curated and automated mappings cannot be reconciled without recorded method metadata." }, { "id": "SRC-036", "title": "A Theory for Record Linkage", "organization": "Fellegi and Sunter, Journal of the American Statistical Association", "url": "https://www.tandfonline.com/doi/abs/10.1080/01621459.1969.10501049", "version_or_date": "1969, volume 64, number 328, pages 1183-1210", "source_type": "scientific", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:12:00Z", "relevance": "Foundational decision theory for probabilistic linkage: likelihood-ratio weights from m- and u-probabilities, two thresholds, and the three-way decision link, possible link and non-link at stipulated error bounds. Normative basis for an explicit undetermined state rather than a forced binary outcome." }, { "id": "SRC-037", "title": "Record Linkage Project Process Model", "organization": "Statistics Canada", "url": "https://www150.statcan.gc.ca/n1/pub/12-605-x/12-605-x2017001-eng.htm", "version_or_date": "Catalogue 12-605-X, released 5 June 2017", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:13:00Z", "relevance": "Public-authority process model covering data preparation and standardization, blocking and indexing, deterministic versus probabilistic method selection, comparison functions and decision rules, threshold setting, clerical review, internal and external validation of false-positive and false-negative rates, documentation duties, and secure storage with data destruction timelines." }, { "id": "SRC-038", "title": "NIST Special Publication 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/63/a/4/final", "version_or_date": "Revision 4, final, published 31 July 2025, doi:10.6028/NIST.SP.800-63a-4", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:14:00Z", "relevance": "Establishes that identity claims rest on graded evidence at defined identity assurance levels, and that resolution to a unique identity plus the evidence relied upon must be recorded. Anchors the separation of authority-derived assurance from statistical match confidence." }, { "id": "SRC-039", "title": "HL7 FHIR Release 5: Person resource and IdentityAssuranceLevel value set", "organization": "HL7 International", "url": "https://hl7.org/fhir/R5/person.html", "version_or_date": "FHIR R5, v5.0.0, published 26 March 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:15:00Z", "relevance": "Person.link.target with Person.link.assurance bound to IdentityAssuranceLevel (level1 little or no confidence, level2 some confidence, level3 high confidence, level4 very high confidence): a deployed normative example of an equivalence link carrying an ordinal assurance qualifier distinct from the link itself." }, { "id": "SRC-040", "title": "A guide to evaluating linkage quality for the analysis of linked data", "organization": "Harron et al., International Journal of Epidemiology (Oxford University Press)", "url": "https://academic.oup.com/ije/article/46/5/1699/4107250", "version_or_date": "2017, volume 46, issue 5, pages 1699-1710, doi:10.1093/ije/dyx177", "source_type": "scientific", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:17:00Z", "relevance": "Peer-reviewed methodology for evaluating linkage quality: gold-standard validation yielding sensitivity and positive predictive value, comparison of linked against unlinked records using standardized differences to expose subgroup bias, and sensitivity analyses across thresholds and algorithms." }, { "id": "SRC-041", "title": "OWL 2 Web Ontology Language Quick Reference Guide (Second Edition)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/owl2-quick-reference/", "version_or_date": "W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:07:00Z", "relevance": "Compact normative listing of axiom names used to name declared property values in the relation-kind catalogue, including owl:deprecated and disjoint property axioms." }, { "id": "SRC-042", "title": "OWL 2 Web Ontology Language New Features and Rationale (Second Edition)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/owl2-new-features/", "version_or_date": "W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:08:00Z", "relevance": "Explains that HasKey applies only to explicitly named individuals and differs in force from InverseFunctionalProperty, and describes property chains, self restrictions and qualified cardinality." }, { "id": "SRC-043", "title": "SKOS Simple Knowledge Organization System Primer", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/skos-primer/", "version_or_date": "W3C Working Group Note, 18 August 2009", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:10:00Z", "relevance": "Explains why closeMatch is deliberately not transitive so similarity does not propagate across schemes, and why SKOS avoids owl:sameAs between concepts." }, { "id": "SRC-044", "title": "RDF 1.1 Semantics", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/rdf11-mt/", "version_or_date": "W3C Recommendation, 25 February 2014", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:11:00Z", "relevance": "Establishes that distinct IRIs may denote the same thing (no unique name assumption) and that entailment regimes are monotonic under an open-world assumption, which is why alias edges must be asserted rather than inferred from difference of identifier." }, { "id": "SRC-045", "title": "Shapes Constraint Language (SHACL)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/shacl/", "version_or_date": "W3C Recommendation, 20 July 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:14:00Z", "relevance": "Separates validation from inference, and defines the validation report structure (conforms, focus node, source constraint component, severity) referenced for declared-semantics reporting." }, { "id": "SRC-046", "title": "schema.org Releases", "organization": "Schema.org Community Group", "url": "https://schema.org/docs/releases.html", "version_or_date": "Release v30.0, 2026-03-19", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:16:00Z", "relevance": "Fixes the vocabulary version against which the schema.org alignment is recorded, so alignment tables can be versioned rather than assumed stable." }, { "id": "SRC-047", "title": "Revisiting the probabilistic method of record linkage", "organization": "arXiv (stat.ME), Dasylva, Goussanou, Ajavon and Abousaleh", "url": "https://arxiv.org/abs/1911.01874", "version_or_date": "arXiv:1911.01874v1, submitted 5 November 2019", "source_type": "scientific", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-04T09:23:00Z", "relevance": "Shows that probabilistic linkage produces error-bounded statistical links dependent on model assumptions and clerical review, not logical identity — grounding the rule that a linkage score never licenses an identity axiom." }, { "id": "SRC-048", "title": "SPARQL 1.1 Query Language", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/sparql11-query/", "version_or_date": "W3C Recommendation 21 March 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:08:00Z", "relevance": "Property paths define arbitrary-length connectivity matching: it does not introduce duplicates and does not count the number of ways a connection can be made, and 'the graph matched may include cycles. Connectivity matching is defined so that matching cycles does not lead to undefined or infinite results.' Grounds repeated-node handling, duplicate-path suppression and the fact that a standard traversal operator returns solutions, not new assertions." }, { "id": "SRC-049", "title": "ISO 25964 — the international standard for thesauri and interoperability with other vocabularies (data model and XML schema)", "organization": "National Information Standards Organization (NISO), host of the freely published ISO 25964 data model and schema", "url": "https://www.niso.org/schemas/iso25964", "version_or_date": "ISO 25964-1:2011 and ISO 25964-2:2013; schema version 1.4", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:13:00Z", "relevance": "ISO 25964-2 covers interoperability with other vocabularies and distinguishes equivalence, hierarchical and associative mappings and exact, inexact and partial equivalence. Grounds the graded strength classification of alias edges. The normative text is paywalled; only the freely published data model and schema material was consulted, so the alignment is recorded as partial." }, { "id": "SRC-050", "title": "The sameAs Problem: A Survey on Identity Management in the Web of Data", "organization": "arXiv (Raad, Pernelle, Saïs, Beek, van Harmelen)", "url": "https://arxiv.org/abs/1907.10528", "version_or_date": "arXiv:1907.10528, submitted 24 July 2019", "source_type": "scientific", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-04T09:15:00Z", "relevance": "Survey establishing that incorrect identity links have wide-ranging effects in a global knowledge space and that identity-link quality is an unresolved problem. Used only to justify contamination, cluster-reliability and integrity-safeguard findings as real risks, not to derive normative structure." }, { "id": "SRC-051", "title": "OxO2 — A SSSOM mapping browser for logically sound crosswalks", "organization": "arXiv (Harmse, Iqbal, Parkinson, McLaughlin, EMBL-EBI)", "url": "https://arxiv.org/abs/2506.04286", "version_or_date": "arXiv:2506.04286, 4 June 2025", "source_type": "scientific", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-04T09:16:00Z", "relevance": "Documents that a prior mapping browser produced crosswalks that were not necessarily logically sound and lacked provenance, and that restricting derivation to conditions the mapping standard defines is what makes chained mappings usable. Supports the traversal-policy and predicate-composition findings as practice evidence; the specific hop limits are implementation choices, not standards." }, { "id": "SRC-052", "title": "RFC 8126 / BCP 26: Guidelines for Writing an IANA Considerations Section in RFCs", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc8126.html", "version_or_date": "Best Current Practice, June 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:08:00Z", "relevance": "Registry governance precedent: entries are marked deprecated or obsolete rather than removed, change control is named per entry, designated experts review requests against documented criteria, and reclamation or reuse of registered values is discouraged because deployed consumers depend on them." }, { "id": "SRC-053", "title": "ISO/IEC 11179-6:2023 Information technology - Metadata registries (MDR) - Part 6: Registration", "organization": "ISO/IEC (published via IEC Webstore)", "url": "https://webstore.iec.ch/en/publication/81978", "version_or_date": "Edition 4.0, published 2023-01-16", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:10:00Z", "relevance": "Registration status is the state of an administered item in the view of the registration authority, split into lifecycle statuses (progression, e.g. Candidate, Recorded) and documentation statuses (no further progression, e.g. Retired, Superseded); establishes registration authority responsibility and mandatory-attribute entry conditions." }, { "id": "SRC-054", "title": "CCSDS 650.0-M-2, Reference Model for an Open Archival Information System (OAIS), Magenta Book", "organization": "Consultative Committee for Space Data Systems (CCSDS); technically identical to ISO 14721", "url": "https://ccsds.org/Pubs/650x0m2.pdf", "version_or_date": "Issue 2, June 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:13:00Z", "relevance": "Preservation Description Information (Reference, Provenance, Context, Fixity, Access Rights) grounds the requirement that history, integrity evidence and access conditions travel with the record and that provenance documents custody and change over time." }, { "id": "SRC-055", "title": "Universal Electronic Records Management (ERM) Requirements", "organization": "U.S. National Archives and Records Administration (NARA)", "url": "https://www.archives.gov/records-mgmt/policy/universalermrequirements", "version_or_date": "Version 3, June 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:14:00Z", "relevance": "Lifecycle-structured records requirements (capture, maintenance and use, metadata, disposal, transfer) establishing that metadata must be captured and maintained across the lifecycle and that disposal follows an approved schedule rather than ad hoc deletion." }, { "id": "SRC-056", "title": "Tombstone Pages (DataCite Support documentation)", "organization": "DataCite", "url": "https://support.datacite.org/docs/tombstone-pages", "version_or_date": "Last updated 7 August 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:16:00Z", "relevance": "Normative practice that a registered persistent identifier cannot be deleted; after withdrawal the identifier must still resolve to a tombstone carrying the citation, the identifier in human- and machine-readable form and a stated reason for unavailability." }, { "id": "SRC-057", "title": "Semantic Sensor Network Ontology (SOSA/SSN)", "organization": "W3C and Open Geospatial Consortium (OGC)", "url": "https://www.w3.org/TR/vocab-ssn/", "version_or_date": "W3C Recommendation, 19 October 2017", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:17:00Z", "relevance": "sosa:phenomenonTime (when the result applies to the feature) versus sosa:resultTime (when the activity completed and the result became available) is the standards anchor for separating event/effective time from observation and ingestion time." }, { "id": "SRC-058", "title": "DOI States (DataCite Support documentation)", "organization": "DataCite", "url": "https://support.datacite.org/docs/doi-states", "version_or_date": "Accessed 4 September 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:18:00Z", "relevance": "A worked identifier state machine (draft, registered, findable) in which only the pre-registration draft state is deletable and later states differ in resolvability and index visibility - precedent for pre-publication candidate discard versus post-publication irreversibility." }, { "id": "SRC-059", "title": "RFC 7089: HTTP Framework for Time-Based Access to Resource States -- Memento", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc7089.html", "version_or_date": "December 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:12:00Z", "relevance": "Primary model for as-of access: Accept-Datetime, Memento-Datetime, TimeGate, TimeMap, Original Resource versus Memento, and the statement that best-match selection is server-discretionary and must be consistent." }, { "id": "SRC-060", "title": "Decentralized Identifiers (DIDs) v1.0", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/did-1.0/", "version_or_date": "W3C Recommendation, 19 July 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:19:00Z", "relevance": "States that an alsoKnownAs assertion does not prove itself, advises independent verification, and treats equivalence as best assumed only when the relation is reciprocated." }, { "id": "SRC-061", "title": "ResourceSync Framework Specification (ANSI/NISO Z39.99-2017)", "organization": "National Information Standards Organization (NISO) / Open Archives Initiative", "url": "https://www.openarchives.org/rs/1.1/resourcesync", "version_or_date": "Version 1.1, ANSI/NISO Z39.99-2017, approved 2 February 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:21:00Z", "relevance": "Change List / Change Dump model with created, updated and deleted change types and the from/until/at/completed datetime attributes; basis for impact enumeration and change notification content." }, { "id": "SRC-062", "title": "The Idempotency-Key HTTP Header Field (draft-ietf-httpapi-idempotency-key-header-07)", "organization": "IETF HTTP APIs Working Group", "url": "https://datatracker.ietf.org/doc/html/draft-ietf-httpapi-idempotency-key-header", "version_or_date": "Internet-Draft 07, 15 October 2025 (expired 18 April 2026)", "source_type": "standard", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-09-04T09:22:00Z", "relevance": "Idempotency key plus request fingerprint, replay of the previously computed result, conflict when a key is in flight, rejection when a key is reused with a different payload, and key expiry." }, { "id": "SRC-063", "title": "Handling Organization Status Changes in ROR", "organization": "Research Organization Registry (ROR)", "url": "https://ror.org/blog/2022-12-07-handling-org-status/", "version_or_date": "7 December 2022", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:26:00Z", "relevance": "Active/inactive/withdrawn record statuses, the rule that identifiers are never deleted or reused and must keep resolving, and predecessor/successor relationships representing mergers and splits without requiring bidirectionality." }, { "id": "SRC-064", "title": "Person — FHIR Release 5", "organization": "HL7 International", "url": "https://www.hl7.org/fhir/person.html", "version_or_date": "FHIR R5 (v5.0.0), published 26 March 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:16:00Z", "relevance": "Person.link with an assurance element qualifies confidence in an asserted cross-organisation link, explicitly tying a probabilistic match to the weakest level and a government-issued photo ID to a stronger level; also states that such records must be protected as identifying information and that inspecting a linked reference can itself reveal sensitive facts." }, { "id": "SRC-065", "title": "Linkage — FHIR Release 5", "organization": "HL7 International", "url": "https://www.hl7.org/fhir/linkage.html", "version_or_date": "FHIR R5 (v5.0.0), published 26 March 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:16:30Z", "relevance": "Defines an equivalence assertion held separately from the linked records, with an author that establishes the context for evaluating the linkage, an active flag for withdrawal, and item types source, alternate and historical that designate which endpoint is authoritative." }, { "id": "SRC-066", "title": "Security Labels — FHIR Release 5", "organization": "HL7 International", "url": "https://www.hl7.org/fhir/security-labels.html", "version_or_date": "FHIR R5 (v5.0.0), published 26 March 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:18:00Z", "relevance": "Confidentiality, sensitivity and compartment codes, purpose-of-use values, obligation and refrain policies such as mask, redact and no-disclosure-without-consent, and the break-the-glass pattern with its audit requirement; grounds sensitivity labelling, tenant compartments and emergency release." }, { "id": "SRC-067", "title": "eXtensible Access Control Markup Language (XACML) Version 3.0", "organization": "OASIS", "url": "https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html", "version_or_date": "OASIS Standard, 22 January 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "Normative separation of policy administration point, policy decision point, policy information point and policy enforcement point, plus obligations that a PEP must perform and advice it may ignore; establishes that this model may supply attributes and obligation references but must not evaluate or enforce." }, { "id": "SRC-068", "title": "NIST Special Publication 800-162, Guide to Attribute Based Access Control (ABAC) Definition and Considerations", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/162/upd2/final", "version_or_date": "January 2014, updated 2 August 2019", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:22:00Z", "relevance": "Defines access control by evaluating subject, object, operation and environment attributes and the trust required in attribute sources; supports treating this model's privacy, purpose and tenant values as governed attributes consumed by an external decision engine." }, { "id": "SRC-069", "title": "NIST Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final", "version_or_date": "Revision 5, September 2020, updated 10 December 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:24:00Z", "relevance": "Control catalogue for access enforcement (AC-3), separation of duties (AC-5), least privilege (AC-6), event logging and audit protection (AU-2, AU-9), information management and retention (SI-12) and the privacy family covering authority to process and processing purposes (PT-2, PT-3); grounds least privilege, duty separation, retention binding and the externality of audit." }, { "id": "SRC-070", "title": "Regulation (EU) 2016/679 (United Kingdom General Data Protection Regulation), Article 5 — Principles relating to processing of personal data", "organization": "The National Archives (legislation.gov.uk)", "url": "https://www.legislation.gov.uk/eur/2016/679/article/5", "version_or_date": "Regulation of 27 April 2016, article text as published on legislation.gov.uk, accessed 4 September 2026", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:26:00Z", "relevance": "Purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and the controller's accountability to demonstrate compliance; the legal basis for declared purposes, retention justification and correction of inaccurate assertions about people." }, { "id": "SRC-071", "title": "Regulation (EU) 2016/679 (United Kingdom General Data Protection Regulation), Article 9 — Processing of special categories of personal data", "organization": "The National Archives (legislation.gov.uk)", "url": "https://www.legislation.gov.uk/eur/2016/679/article/9", "version_or_date": "Regulation of 27 April 2016, article text as published on legislation.gov.uk, accessed 4 September 2026", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:27:00Z", "relevance": "Enumerates the special categories — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health, sex life and sexual orientation — that an equivalence assertion may reveal, and the narrow conditions under which such processing is permitted." }, { "id": "SRC-072", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:31:00Z", "relevance": "Defines selective disclosure as fine-grained holder control over what is shared, unlinkable disclosure, validity periods and credential status, and privacy guidance on data minimisation and identifier correlatability; grounds disclosure classes and the correlation risk of publishing a mapping." }, { "id": "SRC-073", "title": "ODRL Information Model 2.2", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/odrl-model/", "version_or_date": "W3C Recommendation, 15 February 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:33:00Z", "relevance": "Permission, prohibition, duty, constraint, assigner and assignee parties, and the conflict property with perm, prohibit and invalid strategies; a precedent for declaring rules and conflict handling declaratively while leaving enforcement and evaluation outside the information model." }, { "id": "SRC-074", "title": "Data Privacy Vocabulary (DPV) version 2.2", "organization": "W3C Data Privacy Vocabularies and Controls Community Group (DPVCG)", "url": "https://w3c-cg.github.io/dpv/2.2/dpv/", "version_or_date": "Version 2.2, Final Community Group Report, 31 October 2025", "source_type": "ontology", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-09-04T09:37:00Z", "relevance": "Machine-readable taxonomies for purpose, personal data and special-category personal data, legal basis and consent states, controller and processor roles, technical and organisational measures including access control and pseudonymisation, and storage condition and processing duration for retention expression. Not a W3C Standard, so used as an alignment vocabulary only." }, { "id": "SRC-075", "title": "ValueSet: IdentityAssuranceLevel — FHIR Release 5", "organization": "HL7 International", "url": "https://www.hl7.org/fhir/valueset-identity-assuranceLevel.html", "version_or_date": "FHIR R5 (v5.0.0), generated 26 March 2023", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:41:00Z", "relevance": "Four graduated codes describing confidence in an asserted identity, from little or no confidence through some, high and very high confidence; a published, citable tier scale that approval thresholds can align to instead of inventing one." }, { "id": "SRC-076", "title": "OWL 2 Web Ontology Language Mapping to RDF Graphs (Second Edition)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/owl2-mapping-to-rdf/", "version_or_date": "Second Edition, W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Defines the bidirectional mapping between the SameIndividual axiom and owl:sameAs triples, grounding the strict-identity export binding and its entailment consequences." }, { "id": "SRC-077", "title": "RDF Dataset Canonicalization (RDFC-1.0)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/rdf-canon/", "version_or_date": "RDFC-1.0, W3C Recommendation, 21 May 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Canonical N-Quads form with deterministic blank-node labels; two datasets share a canonical form iff isomorphic. Grounds canonicalization and digest rules for RDF projections." }, { "id": "SRC-078", "title": "RFC 9562: Universally Unique IDentifiers (UUIDs)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9562.html", "version_or_date": "RFC 9562, May 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Obsoletes RFC 4122; specifies UUIDv4 for unpredictability and UUIDv7 for time-ordered keys, and the canonical hex-and-dash form. Grounds the third identity tier." }, { "id": "SRC-079", "title": "RFC 6902: JavaScript Object Notation (JSON) Patch", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc6902.html", "version_or_date": "RFC 6902, April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Ordered, atomic operation sequence with a test operation; a failed operation means no operation is applied. Grounds the patch rules and the base-edition digest guard." }, { "id": "SRC-080", "title": "JSON-LD 1.1: A JSON-based Serialization for Linked Data", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/json-ld11/", "version_or_date": "W3C Recommendation, 16 July 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Context-driven term-to-IRI expansion and compaction, and blank-node identifier handling. Grounds deterministic prefix expansion in JSON projections and known round-trip caveats." }, { "id": "SRC-081", "title": "Controlled Identifiers v1.0", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/cid-1.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Defines alsoKnownAs for asserting that identifiers refer to the same subject, and states it is best practice not to treat them as equivalent without a reciprocating assertion, and that the assertion itself is not proof. Grounds reciprocity controls." }, { "id": "SRC-082", "title": "Data Catalog Vocabulary (DCAT) - Version 3", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vocab-dcat-3/", "version_or_date": "W3C Recommendation, 22 August 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Separates a dataset from its distributions in multiple serializations and formats, and defines version, previousVersion and hasCurrentVersion. Grounds treating storage/interface bindings as distributions of one format-neutral alias set." }, { "id": "SRC-083", "title": "Generating RDF from Tabular Data on the Web", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/csv2rdf/", "version_or_date": "W3C Recommendation, 17 December 2015", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Minimal mode retains only cell information and strips row/table framing; a separate metadata document is needed to preserve subject URIs, datatypes and relations. Grounds documented loss in tabular projections." }, { "id": "SRC-084", "title": "Best Practice Recipes for Publishing RDF Vocabularies", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/swbp-vocab-pub/", "version_or_date": "W3C Working Group Note, 28 August 2008", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "States the namespace chosen must be a Web address to which the publisher has write access, and specifies hash vs slash namespaces, 303 See Other for slash namespaces and content negotiation. Grounds namespace ownership and resolution layout." }, { "id": "SRC-085", "title": "Semantic Versioning 2.0.0", "organization": "Semantic Versioning (semver.org)", "url": "https://semver.org/", "version_or_date": "Semantic Versioning 2.0.0", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "MAJOR for incompatible changes, MINOR for backward-compatible additions, PATCH for fixes, and the rule that a released version's contents MUST NOT be modified. Grounds compatibility and edition-immutability rules." }, { "id": "SRC-086", "title": "AGENTS.md - an open format for guiding coding agents", "organization": "agents.md (open format community)", "url": "https://agents.md/", "version_or_date": "Open format, no versioned specification, accessed 4 September 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Establishes AGENTS.md as a vendor-neutral Markdown orientation file placed at the root, with nested files where the nearest file wins and no required fields of its own. Grounds the bootstrap contract's placement and read-order rules; the six required fields are a Vercy contract layered on top." }, { "id": "SRC-087", "title": "SSSOM/TSV Serialisation", "organization": "SSSOM / Mapping Commons", "url": "https://mapping-commons.github.io/sssom/dev/spec-formats-tsv/", "version_or_date": "SSSOM 1.1 development specification, accessed 4 September 2026", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Embedded YAML metadata block prefixed with '#' versus an external .sssom.yml file, fixed column order, pipe-separated multi-valued slots with escaping, mandatory slot condensation, and the rule that implementations not supporting non-standard slots MUST discard unknown keys and columns on read." }, { "id": "SRC-088", "title": "SSSOM Support Functions: Hashing Mapping Records", "organization": "SSSOM / Mapping Commons", "url": "https://mapping-commons.github.io/sssom/dev/spec-support-hashing/", "version_or_date": "SSSOM 1.1 development specification, accessed 4 September 2026", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:00:00Z", "relevance": "Defines a canonical S-expression over all Mapping slots except record_id and mapping_cardinality, with float truncation to three fractional digits and FNV-1a 64-bit hashing, and states equal hashes make records only 'highly likely' identical. Grounds the digest-is-not-identity rule." }, { "id": "SRC-089", "title": "RFC 9457: Problem Details for HTTP APIs", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9457.html", "version_or_date": "July 2023 (obsoletes RFC 7807)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T00:00:00Z", "relevance": "Defines the machine-readable failure document: type, title, status, detail, instance (Sec. 3.1), extension members that consumers must ignore when unrecognised (Sec. 3.2), the guidance to represent the most relevant problem rather than a generic batch type, and the validation-error pattern using an errors extension array with pointers to the offending element." }, { "id": "SRC-090", "title": "ISO/IEC 11179-6:2023 Information technology — Metadata registries (MDR) — Part 6: Registration", "organization": "ISO/IEC JTC 1/SC 32", "url": "https://committee.iso.org/es/sites/isoorg/contents/data/standard/07/89/78916.html", "version_or_date": "Edition 4, published 2023-01-16, stage 60.60", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T00:00:00Z", "relevance": "Establishes that registration of an administered item specifies the information to be supplied, the conditions to be met and the procedures to be followed, under a registration authority. Consulted through the ISO catalogue record only; the normative status enumeration was not accessible, so it is used as an alignment for the existence of a governed registration procedure, not as a source of specific status values." }, { "id": "SRC-091", "title": "SPARQL 1.1 Entailment Regimes", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/sparql11-entailment/", "version_or_date": "W3C Recommendation 21 March 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:12:00Z", "relevance": "Defines conditions a regime must satisfy, finiteness of answers, and the divergent inconsistency handling (MUST raise an error under OWL 2 Direct Semantics, MAY warn under RDF-Based Semantics); grounds the entailment-stance declaration." }, { "id": "SRC-092", "title": "SPARQL 1.1 Federated Query", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/sparql11-federated-query/", "version_or_date": "W3C Recommendation 21 March 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:14:00Z", "relevance": "Normative SERVICE/SILENT semantics: a silenced failure yields a single solution with no bindings, indistinguishable from an empty answer; grounds the mandatory completeness and source-failure disclosure." }, { "id": "SRC-093", "title": "SPARQL 1.1 Service Description", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/sparql11-service-description/", "version_or_date": "W3C Recommendation 21 March 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:16:00Z", "relevance": "Vocabulary for declaring endpoint capability, default dataset, available graphs and default entailment regime; grounds the capability-profile artifact and pre-request discovery." }, { "id": "SRC-094", "title": "SPARQL 1.1 Protocol", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/sparql11-protocol/", "version_or_date": "W3C Recommendation 21 March 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:18:00Z", "relevance": "Defines the read-only query operation, MalformedQuery and QueryRequestRefused faults, and the rule that a protocol-level dataset overrides a request-embedded dataset; grounds request validation and scope precedence." }, { "id": "SRC-095", "title": "Time Ontology in OWL", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/owl-time/", "version_or_date": "W3C Candidate Recommendation Draft 15 November 2022", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:44:00Z", "relevance": "Instant and Interval entities, interval relations and the requirement to state a temporal reference system; grounds served-state intervals. Not a Recommendation, so used as alignment only." }, { "id": "SRC-096", "title": "LEI Mapping", "organization": "Global Legal Entity Identifier Foundation (GLEIF)", "url": "https://www.gleif.org/en/lei-data/lei-mapping", "version_or_date": "Accessed 4 September 2026; mapping services dated February 2018 to June 2026", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:50:00Z", "relevance": "Real-world authority-published, certified identifier-to-identifier mapping files with declared owners and update cadence (daily to monthly); grounds authority-scoped assertion sources, staleness and cadence metadata." }, { "id": "SRC-097", "title": "HL7 FHIR Release 5 - OperationOutcome Resource", "organization": "HL7 International", "url": "https://hl7.org/fhir/R5/operationoutcome.html", "version_or_date": "FHIR v5.0.0 (R5), published 26 March 2023", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:11:00Z", "relevance": "A collection of error, warning or information messages resulting from a system action, with issue.severity (fatal, error, warning, information, success), issue.code, issue.details, issue.diagnostics and issue.expression. It is explicitly not a clinical decision or adjudication, which is the second independent precedent for a report that carries graded findings without deciding them." }, { "id": "SRC-098", "title": "Federal Records Centers Program - Freeze Process Overview (FAQ)", "organization": "National Archives and Records Administration (NARA), United States", "url": "https://www.archives.gov/frc/arcis/freeze-faq", "version_or_date": "Page last reviewed 29 January 2024; cites 36 CFR 1228.54 and 44 U.S.C. 2909", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:13:00Z", "relevance": "Distinguishes a freeze (requested of NARA for records in Federal Records Center custody) from a litigation hold or moratorium issued by an agency Counsel's Office, states that a hold suspends the normal disposition cycle to prevent premature disposal, and that normal disposition resumes only on formal notification. Primary evidence that hold placement and release are owned by an external authority, not by the reporting system." }, { "id": "SRC-099", "title": "Linked Data Notifications", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/ldn/", "version_or_date": "W3C Recommendation 2 May 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:14:00Z", "relevance": "Separates sender, receiver and consumer roles from the notification payload and states that 'the actual vocabulary of the payload is deliberately not specified here'. Inbox discovery uses an HTTP Link header with rel http://www.w3.org/ns/ldp#inbox. Normative basis for producing notification content while leaving subscription, delivery and receipt to an external service." }, { "id": "SRC-100", "title": "Activity Vocabulary", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/activitystreams-vocabulary/", "version_or_date": "W3C Recommendation 23 May 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:15:00Z", "relevance": "Defines Update, Delete and Undo activity content and the Tombstone object with formerType (the type of the object that was deleted) and deleted (a timestamp for when the object was deleted). Supplies a standards-based shape for change-notice content and for the tombstone residue that survives an authorised disposition." }, { "id": "SRC-101", "title": "Regulation (EU) 2016/679 (General Data Protection Regulation), Article 19 - Notification obligation regarding rectification or erasure of personal data or restriction of processing", "organization": "The National Archives (United Kingdom), legislation.gov.uk rendering of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016", "url": "https://www.legislation.gov.uk/eur/2016/679/article/19", "version_or_date": "Regulation of 27 April 2016; legislation.gov.uk assimilated-law rendering", "source_type": "legislation", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:16:00Z", "relevance": "The controller must communicate any rectification, erasure or restriction of processing to each recipient to whom the personal data have been disclosed, 'unless this proves impossible or involves disproportionate effort', and must inform the data subject about those recipients on request. Directly grounds downstream-reference impact reporting, the reach-completeness qualifier and the notification-content obligation." }, { "id": "SRC-102", "title": "RFC 8785: JSON Canonicalization Scheme (JCS)", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc8785.html", "version_or_date": "RFC 8785, June 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:00:00Z", "relevance": "Deterministic JSON serialization for hashing: I-JSON subset, lexicographic member ordering by UTF-16 code units, ECMAScript number serialization, and the IEEE 754 precision limitation." }, { "id": "SRC-103", "title": "Model for Tabular Data and Metadata on the Web", "organization": "W3C", "url": "https://www.w3.org/TR/tabular-data-model/", "version_or_date": "W3C Recommendation, 17 December 2015", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:00:00Z", "relevance": "Annotated tabular data model, cell/column annotations, metadata discovery precedence, and the explicit statement that the model cannot distinguish an empty unquoted from an empty quoted field." }, { "id": "SRC-104", "title": "Model Context Protocol Specification: Resources", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2025-06-18/server/resources", "version_or_date": "Protocol revision 2025-06-18", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:00:00Z", "relevance": "Resource URI, name, title, mimeType, size, text vs blob contents, URI templates, annotations and subscription/list-changed capabilities; defines the MCP-backed projection surface and what the server, not this model, owns." }, { "id": "SRC-105", "title": "MongoDB Extended JSON (v2)", "organization": "MongoDB, Inc.", "url": "https://www.mongodb.com/docs/manual/reference/mongodb-extended-json/", "version_or_date": "MongoDB Manual 8.3", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:00:00Z", "relevance": "Canonical vs relaxed modes and the specific BSON types (Int32, Int64, Double, Date) that lose type fidelity in relaxed mode; grounds declared type-fidelity loss for database projections." }, { "id": "SRC-106", "title": "RFC 9530: Digest Fields", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc9530.html", "version_or_date": "RFC 9530, February 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T10:00:00Z", "relevance": "Content-Digest vs Repr-Digest scope, the registered hash algorithm registry, and the explicit statement that digests detect corruption but do not provide authenticity." }, { "id": "SRC-107", "title": "YAML Ain't Markup Language (YAML) version 1.2, Revision 1.2.2", "organization": "YAML Language Development Team", "url": "https://yaml.org/spec/1.2.2/", "version_or_date": "Revision 1.2.2, 1 October 2021", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:00:00Z", "relevance": "Representation graph, anchors and aliases as serialization-level node identity, tag resolution, and the explicit discarding of key order, anchor names and presentation detail on composition." }, { "id": "SRC-108", "title": "JSON Schema: A Media Type for Describing JSON Documents (draft-bhutton-json-schema-01)", "organization": "JSON Schema", "url": "https://json-schema.org/draft/2020-12/json-schema-core", "version_or_date": "Draft 2020-12, 16 June 2022", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T10:00:00Z", "relevance": "$schema as dialect declaration, $id as canonical base URI, $ref resolution and vocabularies; grounds the self-description requirement on JSON-family projections." } ], "structure": { "bundles": [ { "id": "als-asrt-envelope-bundle", "name": "Assertion Envelope", "description": "The alias assertion treated as an identified, versioned, weakly identified resource in its own right: what denotes it, who issued it, when it holds, for what purpose and tenant, under which jurisdiction, over which entity types, and from which citable origin it derives.", "rationale": "Web Linking and Linkset standardise third-party links, where a party publishes typed connections about resources it does not host; RDF 1.2 triple terms and rdf:reifies give a statement referable identity; FHIR ConceptMap and SSSOM both carry the mapping's own url, version, date, publisher, jurisdiction and purpose separately from the codes being mapped. Together these establish that the envelope is a distinct governed object, not a property of either endpoint.", "source_refs": [ "SRC-006", "SRC-007", "SRC-002", "SRC-013", "SRC-011", "SRC-009" ], "layers": [ { "id": "als-asrt-identity-layer", "name": "Assertion Identity and Issuance", "description": "What identifies the assertion itself, how it depends on a host record, how it is versioned and superseded, who issued and reviewed it, and how its several distinct times are recorded.", "source_refs": [ "SRC-002", "SRC-013", "SRC-009", "SRC-008", "SRC-011" ], "findings": [ { "id": "als-asrt-identity-finding", "name": "Assertion identifier, version and weak host-dependent identity", "description": "The assertion is denoted by an identifier minted in a namespace disjoint from both endpoint namespaces, so it can never be mistaken for, nor substituted by, either endpoint identifier. Because this is a mixin, identity is weak and host-dependent: the addressable key is the host reference plus an assertion-local identifier, and the envelope has its own version series independent of any endpoint version. A change to any claim-bearing field is made by issuing a successor envelope that links to the one it supersedes, never by editing in place, so that consumers holding a cached copy can detect divergence.", "source_refs": [ "SRC-002", "SRC-013", "SRC-009", "SRC-017", "SRC-011" ], "questions": [ { "id": "als-asrt-q-id-own", "text": "Which identifier denotes this alias assertion itself, and which authority assigned it?", "kind": "identity", "answer_data": [ "Assertion identifier value and its identifier scheme", "Assigning registry or system of record reference", "Statement of whether the identifier is opaque" ] }, { "id": "als-asrt-q-id-distinct", "text": "How is the assertion identifier kept structurally distinguishable from the identifiers cited at its endpoints?", "kind": "constraint", "answer_data": [ "Namespace or prefix reserved for assertion identifiers", "Rule forbidding derivation of the assertion identifier from an endpoint locator", "Collision test result against endpoint namespaces" ] }, { "id": "als-asrt-q-id-host", "text": "On which host record does this mixin instance depend, and what becomes of the assertion when the host is withdrawn?", "kind": "composition", "answer_data": [ "Host record reference", "Dependency strength (host-scoped versus independently addressable)", "Declared disposition when the host is withdrawn" ] }, { "id": "als-asrt-q-id-version", "text": "How is a new version of the assertion issued, and how does it cite the version it supersedes?", "kind": "lifecycle", "answer_data": [ "Envelope version token", "Supersedes reference to the prior envelope identifier and version", "List of fields classified as claim-bearing and therefore immutable" ] }, { "id": "als-asrt-q-id-key", "text": "Which combination of recorded fields forms the structural key by which two envelopes would count as the same claim?", "kind": "validation", "answer_data": [ "Structural key field list (normalized source locator, predicate slot, normalized target locator, purpose scope, tenant)", "Normalization level applied before key comparison" ] } ], "data_elements": [ { "id": "als-asrt-de-assertion-id", "name": "assertion_id", "description": "Identifier denoting this assertion, minted in a namespace disjoint from every endpoint namespace.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-013", "SRC-017" ] }, { "id": "als-asrt-de-envelope-version", "name": "envelope_version", "description": "Opaque business version token for this envelope, ordered by an explicitly declared version algorithm and carrying no date-like component.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-011" ] }, { "id": "als-asrt-de-host-ref", "name": "host_record_ref", "description": "Reference to the record that hosts this mixin instance and supplies its weak identity context and retention scope.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-006" ] }, { "id": "als-asrt-de-supersedes-ref", "name": "supersedes_ref", "description": "Reference to the envelope identifier and version that this envelope replaces.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-013" ] }, { "id": "als-asrt-de-structural-key", "name": "structural_key", "description": "Derived comparison key over normalized source locator, predicate slot, normalized target locator, purpose scope and tenant, used only to detect structurally identical envelopes.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-002" ] } ], "artifacts": [ { "id": "als-asrt-art-envelope-record", "name": "Alias assertion envelope record", "description": "The addressable record carrying one assertion: its own identifier and version, issuer and times, purpose and tenant scope, the two role-bearing endpoint references with their pins and resolution observations, the predicate slot, the declared shape and any anomaly flags. It contains no copy of either endpoint record.", "media_or_form": [ "structured record in any serialization", "reifying triple with a triple term", "row in a tabular mapping set", "entry within a link set document" ], "serial": false, "identity_strategy": "Authoritative master-system assertion identifier held by the adopting Dimension's assertion registry; otherwise a governed IRI minted in a Dimension-controlled namespace disjoint from both endpoint namespaces; otherwise a UUID or ULID assigned by the adopting Dimension. The envelope identifier is never derived from, and never substitutes for, either endpoint identifier, and no date is used as an identifier.", "source_refs": [ "SRC-002", "SRC-007", "SRC-013", "SRC-011", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "als-asrt-issuance-finding", "name": "Issuer, authorship and the separated times of an assertion", "description": "An alias assertion is a speech act by a named agent, and issuing one confers no authority over either endpoint. The envelope records who asserted it, who authored and who reviewed or endorsed it as distinct roles, and keeps at least three time axes apart: when the issuer asserted it, the window over which it is declared effective, and when this Dimension observed or ingested it. Conflating these makes a stale ingest indistinguishable from a fresh claim and makes retraction unverifiable.", "source_refs": [ "SRC-008", "SRC-009", "SRC-011", "SRC-013", "SRC-014" ], "questions": [ { "id": "als-asrt-q-issue-agent", "text": "Who issued this assertion, and under what authority do they speak about both endpoints at once?", "kind": "authority", "answer_data": [ "Issuer agent reference", "Basis of authority over each side (owner, third party, aggregator)", "Explicit statement that issuance grants no control over either endpoint" ] }, { "id": "als-asrt-q-issue-time", "text": "When was the assertion made, and over which window is it declared effective?", "kind": "temporal", "answer_data": [ "Assertion timestamp", "Effective-from and effective-until values or an open-ended declaration", "Version algorithm used to order successive envelopes" ] }, { "id": "als-asrt-q-issue-observed", "text": "How is the time this Dimension observed or ingested the assertion recorded separately from the time it was asserted?", "kind": "provenance", "answer_data": [ "Observation or ingestion timestamp", "Ingesting agent or channel reference", "Rule forbidding substitution of ingestion time for assertion time" ] }, { "id": "als-asrt-q-issue-review", "text": "Which agents reviewed or endorsed the assertion, and is endorsement distinguished from authorship?", "kind": "ownership", "answer_data": [ "Author agent references", "Reviewer or endorser agent references", "Role vocabulary distinguishing creator, author, reviewer and publisher" ] } ], "data_elements": [ { "id": "als-asrt-de-issuer-ref", "name": "issuer_ref", "description": "Reference to the agent accountable for the claim; the agent record itself is owned by an external party model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-011", "SRC-013" ] }, { "id": "als-asrt-de-author-ref", "name": "author_ref", "description": "References to agents who authored the assertion, distinct from the issuing organisation.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-009" ] }, { "id": "als-asrt-de-reviewer-ref", "name": "reviewer_ref", "description": "References to agents who reviewed or endorsed the assertion without authoring it.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "als-asrt-de-asserted-at", "name": "asserted_at", "description": "Event time at which the issuer made the claim, as an RFC 3339 date-time with seconds and an explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-011" ] }, { "id": "als-asrt-de-effective-window", "name": "effective_window", "description": "Declared validity window of the claim, with effective-from and optional effective-until bounds.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-008" ] }, { "id": "als-asrt-de-observed-at", "name": "observed_at", "description": "Observation or ingestion time at which this Dimension recorded the assertion, never substituted for the assertion time.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Issuer, role and time values are atomic attributes of the envelope record already declared as an artifact in this layer, and produce no separately addressable document. Agent records themselves are owned by an external party model, so only references are carried here; materialising an agent artifact locally would duplicate that model." } ] }, { "id": "als-asrt-applicability-layer", "name": "Applicability, Governing Context and Provenance Locators", "description": "The conditions under which the claim is offered and may legitimately be reused: declared purpose, tenant, jurisdiction, licence and the entity types bounding each side; plus the citable origin and derivation lineage of the assertion recorded strictly as locators.", "source_refs": [ "SRC-013", "SRC-011", "SRC-012", "SRC-009", "SRC-010" ], "findings": [ { "id": "als-asrt-scope-finding", "name": "Purpose, tenant, jurisdiction and applicable entity/type scope", "description": "An equivalence asserted for one purpose is not automatically valid for another. The envelope carries an explicit purpose statement, the owning tenant or adopting Dimension, the jurisdictions whose rules govern its use, the licence under which it may be redistributed, and value-set or type bounds on each side that say which classes of things the claim ranges over. This is a direct response to the standardised mapping formats that carry no context, and it means a consumer can reject an assertion as out of scope without disputing its truth.", "source_refs": [ "SRC-013", "SRC-012", "SRC-011", "SRC-014" ], "questions": [ { "id": "als-asrt-q-scope-purpose", "text": "For which declared purpose is this equivalence asserted, and which purposes are excluded from it?", "kind": "requirement", "answer_data": [ "Purpose statement text", "Enumerated permitted use contexts", "Explicitly excluded use contexts" ] }, { "id": "als-asrt-q-scope-tenant", "text": "Which tenant or adopting Dimension owns this assertion instance, and may it be shared beyond that tenant?", "kind": "ownership", "answer_data": [ "Tenant or Dimension reference", "Shareability declaration and any onward-transfer restriction" ] }, { "id": "als-asrt-q-scope-jurisdiction", "text": "Which jurisdictions or regulatory contexts govern the use of this assertion?", "kind": "spatial", "answer_data": [ "Jurisdiction code list", "Statement of whether jurisdiction constrains use, publication or both" ] }, { "id": "als-asrt-q-scope-types", "text": "Which entity types or value sets bound the source side and the target side of the assertion?", "kind": "classification", "answer_data": [ "Source scope reference (type, value set or register)", "Target scope reference", "Subject and object type codes" ] }, { "id": "als-asrt-q-scope-licence", "text": "Under which licence or usage terms may this assertion and its set be redistributed?", "kind": "access", "answer_data": [ "Licence reference", "Attribution requirement", "Any inherited restriction from an endpoint publisher" ] } ], "data_elements": [ { "id": "als-asrt-de-purpose-statement", "name": "purpose_statement", "description": "Free-text statement of why the equivalence is asserted and what it is meant to support.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-012" ] }, { "id": "als-asrt-de-tenant-ref", "name": "tenant_ref", "description": "Reference to the tenant or adopting Dimension that owns this assertion instance.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-014" ] }, { "id": "als-asrt-de-jurisdiction-code", "name": "jurisdiction_code", "description": "Codes for the legal or regulatory regions in which the assertion is intended to be used.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "als-asrt-de-source-scope-ref", "name": "source_scope_ref", "description": "Reference to the type, register or value set that bounds admissible source-side subjects.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-011" ] }, { "id": "als-asrt-de-target-scope-ref", "name": "target_scope_ref", "description": "Reference to the type, register or value set that bounds admissible target-side subjects.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-011" ] }, { "id": "als-asrt-de-licence-ref", "name": "licence_ref", "description": "Reference to the licence governing redistribution of the assertion and any inherited endpoint-publisher terms.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Purpose, tenant, jurisdiction, scope bounds and licence are qualifying attributes of the envelope artifact rather than separable documents. The value sets, registers, tenant records, jurisdiction code lists and licence texts they point to are all owned by external models and registries, so this finding carries resolvable references only and deliberately materialises nothing locally." }, { "id": "als-asrt-provenance-finding", "name": "Provenance locators and derivation lineage of the assertion", "description": "Provenance is recorded as locators, never as imported content. The envelope cites the set or link set it belongs to, the primary source document or dataset it came from, the prior assertion or upstream mapping set it was derived from, the activity or tool that produced it, and any issue reference where it is discussed. Set-level metadata is held once on the set descriptor and inherited by members rather than copied onto each envelope, and none of these locators is dereferenced by this model.", "source_refs": [ "SRC-009", "SRC-010", "SRC-007", "SRC-011", "SRC-006" ], "questions": [ { "id": "als-asrt-q-prov-origin", "text": "Which document, dataset or link set is the citable origin of this assertion?", "kind": "provenance", "answer_data": [ "Primary source locator", "Originating set or link set reference", "Retrieval or publication reference where the origin was obtained" ] }, { "id": "als-asrt-q-prov-derivation", "text": "From which prior assertion or upstream mapping set was this one derived, and by which activity?", "kind": "process", "answer_data": [ "Derived-from references", "Producing activity or tool reference with its version", "Statement of whether derivation was manual, tool-assisted or bulk import" ] }, { "id": "als-asrt-q-prov-locator-discipline", "text": "How are provenance targets recorded as resolvable locators without copying the referenced records into this model?", "kind": "interoperability", "answer_data": [ "Locator form rule (absolute IRI or expandable compact form)", "Prohibition on embedding target record content", "Fields permitted to carry only references" ] }, { "id": "als-asrt-q-prov-set", "text": "Which set does this assertion belong to, and which set-level metadata does it inherit rather than restate?", "kind": "composition", "answer_data": [ "Assertion set reference and set version token", "List of inherited set-level fields (licence, issuer, curie map, default scope)", "Rule for member-level override of an inherited value" ] } ], "data_elements": [ { "id": "als-asrt-de-set-ref", "name": "assertion_set_ref", "description": "Reference to the assertion set or link set this envelope belongs to, together with the set version token.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-011", "SRC-007" ] }, { "id": "als-asrt-de-primary-source-locator", "name": "primary_source_locator", "description": "Locator of the document or dataset that is the citable origin of the claim.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-016" ] }, { "id": "als-asrt-de-derived-from-ref", "name": "derived_from_ref", "description": "References to prior assertions or upstream mapping sets from which this envelope was derived.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-011" ] }, { "id": "als-asrt-de-producing-activity-ref", "name": "producing_activity_ref", "description": "Reference to the activity, tool or pipeline that produced the assertion, with its version; the tool itself is external.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-011" ] }, { "id": "als-asrt-de-issue-locator", "name": "issue_locator", "description": "Locators of issue-tracker items or review threads where the assertion is discussed.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "als-asrt-art-set-descriptor", "name": "Alias assertion set descriptor", "description": "A published descriptor for a coherent set of assertions: set identity and edition, issuer and licence, the namespace binding map in force, the datasets or registers supplying source-side and target-side references and their directionality, declared default scope, and counts. Member envelopes inherit set-level metadata by reference rather than by copy.", "media_or_form": [ "link set document", "mapping set manifest with a metadata header", "dataset or link set description record" ], "serial": true, "identity_strategy": "Authoritative master-system set identifier from the publishing registry; otherwise a governed set IRI in a Dimension-controlled namespace paired with an opaque edition token; otherwise a UUID or ULID. The edition token orders successive publications and carries no date-like component; the series identifier is never reused for a different endpoint pairing.", "source_refs": [ "SRC-010", "SRC-007", "SRC-011", "SRC-013" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-asrt-endpoint-bundle", "name": "Endpoint Reference Boundary", "description": "The disciplined edge between the assertion and the two externally owned things it links: role assignment and directionality, locator form and namespace binding, version pinning and snapshot capture, the declared shape of the claim across cardinalities and conditions, and the degenerate states that must be representable rather than silently absent.", "rationale": "RFC 3986 and RFC 3987 fix the comparison ladder and the rule that a locator identifies without implying access; RDF 1.2 requires absolute IRIs and exact code-point comparison; VoID and Linkset establish explicit subject-side and object-side targets and third-party anchors; FHIR ConceptMap supplies source and target version pinning, noMap, unmapped modes and dependsOn guards; SSSOM supplies explicit mapping cardinality and a negation modifier. These give primary support for treating the endpoint boundary as governed structure rather than as two opaque string fields.", "source_refs": [ "SRC-004", "SRC-005", "SRC-002", "SRC-010", "SRC-007", "SRC-013", "SRC-011" ], "layers": [ { "id": "als-asrt-locator-layer", "name": "Endpoint Roles and Locators", "description": "How each side is named, which role it occupies, how its locator is written and bound to a namespace, how it is pinned to a version or snapshot, and what resolution state has been observed about it.", "source_refs": [ "SRC-004", "SRC-005", "SRC-002", "SRC-010", "SRC-013", "SRC-017" ], "findings": [ { "id": "als-asrt-role-finding", "name": "Source and target roles, directionality and endpoint non-ownership", "description": "One reference occupies the source role and the other the target, in a canonical written order that survives serialization even when the recorded predicate is symmetric, because directionality is what makes one-to-many distinguishable from many-to-one and what lets a set declare which register supplies subjects and which supplies objects. The assertion cites the authority for each endpoint rather than assuming it, and states explicitly what it does not claim: no precedence, no preferred name, no ownership, no merge. Following the strongest available guidance, a pair is not treated as equivalent on the strength of a single unreciprocated claim.", "source_refs": [ "SRC-010", "SRC-014", "SRC-015", "SRC-006", "SRC-007" ], "questions": [ { "id": "als-asrt-q-role-order", "text": "Which reference occupies the source role and which the target, and does the recorded predicate make that order significant?", "kind": "relationship", "answer_data": [ "Source-role reference and target-role reference", "Canonical role order rule", "Whether the predicate slot names a symmetric or directional term" ] }, { "id": "als-asrt-q-role-nonownership", "text": "What does this assertion explicitly not claim about ownership, naming or precedence of either endpoint?", "kind": "ownership", "answer_data": [ "Non-ownership declaration text", "Statement that no preferred or canonical endpoint is selected here", "Pointer to the endpoint authority that may select a canonical form" ] }, { "id": "als-asrt-q-role-reciprocity", "text": "Is a reciprocal assertion from the target side required before the pair may be acted on as equivalent?", "kind": "validation", "answer_data": [ "Reciprocity requirement flag", "Reciprocal assertion reference where one exists", "Assurance level recorded (unverified claim versus authority-guaranteed equivalence)" ] }, { "id": "als-asrt-q-role-authority", "text": "Which system is authoritative for each endpoint, and how is that authority cited rather than assumed?", "kind": "authority", "answer_data": [ "Source-side authority reference", "Target-side authority reference", "Evidence that the cited authority actually governs that namespace" ] } ], "data_elements": [ { "id": "als-asrt-de-source-ref", "name": "source_ref", "description": "The reference occupying the source role, carried as a locator with no imported endpoint content.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-011", "SRC-007" ] }, { "id": "als-asrt-de-target-ref", "name": "target_ref", "description": "The reference occupying the target role, carried as a locator with no imported endpoint content.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-011", "SRC-007" ] }, { "id": "als-asrt-de-role-order", "name": "role_directionality", "description": "Code stating whether the recorded predicate is directional or symmetric, and whether role order is semantically significant.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001", "SRC-010" ] }, { "id": "als-asrt-de-source-authority-ref", "name": "source_authority_ref", "description": "Reference to the system or registration authority authoritative for the source endpoint.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017", "SRC-015" ] }, { "id": "als-asrt-de-target-authority-ref", "name": "target_authority_ref", "description": "Reference to the system or registration authority authoritative for the target endpoint.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017", "SRC-015" ] }, { "id": "als-asrt-de-reciprocal-ref", "name": "reciprocal_assertion_ref", "description": "Reference to a converse assertion issued from the target side, recorded because unreciprocated claims are not to be treated as equivalence.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "Roles, directionality and authority citations are attributes of the envelope artifact and produce no separate document. The endpoint records and the authority registers they point at are owned by external models; materialising either here would import records this model is explicitly forbidden to own, so only role-bearing references are held inline." }, { "id": "als-asrt-locator-finding", "name": "Locator form, namespace binding and comparison discipline", "description": "Each endpoint locator is recorded in a declared form: an absolute IRI, a compact prefixed form expandable through a published binding map, or a local code paired with an explicit scheme. Comparison is not a free choice: RDF-facing use requires exact code-point comparison of absolute IRIs with no normalization beforehand, while URI and IRI guidance defines a graduated ladder whose whole design principle is to minimise false negatives while strictly avoiding false positives. The envelope therefore records which normalization level was applied, keeps character data in Normalization Form C, states how percent-encoding and fragment components were handled, and flags locators declared opaque so that no meaning is parsed out of their internal structure.", "source_refs": [ "SRC-004", "SRC-005", "SRC-002", "SRC-011", "SRC-017" ], "questions": [ { "id": "als-asrt-q-loc-form", "text": "In what form is each endpoint locator recorded: absolute IRI, compact prefixed form, or local code plus scheme?", "kind": "definition", "answer_data": [ "Locator form code per side", "The recorded locator string", "Base reference declared where a relative form was supplied" ] }, { "id": "als-asrt-q-loc-binding", "text": "Which prefix or namespace binding expands a compact endpoint locator, and where is that binding published?", "kind": "interoperability", "answer_data": [ "Prefix token and its bound IRI pattern", "Reference to the published binding map and its edition", "Resolution provider or registry through which the prefix is registered" ] }, { "id": "als-asrt-q-loc-normalization", "text": "Which normalization level was applied before two locators were treated as the same string?", "kind": "validation", "answer_data": [ "Normalization level code (simple string, syntax-based, scheme-based, protocol-based)", "Whether exact code-point comparison was required by the consuming context", "Record of any locator pair rejected as a possible false positive" ] }, { "id": "als-asrt-q-loc-encoding", "text": "How are percent-encoding, Unicode normalization and fragment components handled when locators are compared?", "kind": "constraint", "answer_data": [ "Declaration that stored locators are pre-normalized to Normalization Form C", "Percent-encoding policy for non-ASCII characters", "Rule for whether a fragment component participates in identity" ] }, { "id": "als-asrt-q-loc-opacity", "text": "Which locators are declared opaque, so that no meaning may be parsed from their internal structure?", "kind": "quality", "answer_data": [ "Opacity flag per side", "Any structure that consumers are explicitly forbidden to infer", "Authority statement supporting the opacity declaration" ] } ], "data_elements": [ { "id": "als-asrt-de-source-locator", "name": "source_locator", "description": "Recorded locator for the source endpoint, absolute after expansion and never a relative reference without a declared base.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-002", "SRC-005" ] }, { "id": "als-asrt-de-target-locator", "name": "target_locator", "description": "Recorded locator for the target endpoint, absolute after expansion and never a relative reference without a declared base.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-002", "SRC-005" ] }, { "id": "als-asrt-de-locator-form", "name": "locator_form", "description": "Code stating whether a side is recorded as an absolute IRI, a compact prefixed form or a local code plus scheme.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-017", "SRC-011" ] }, { "id": "als-asrt-de-namespace-binding-ref", "name": "namespace_binding_ref", "description": "Reference to the published prefix-to-IRI binding used to expand a compact locator, with its edition.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-017" ] }, { "id": "als-asrt-de-normalization-level", "name": "normalization_level", "description": "Code recording the comparison level applied to locators, so that comparison behaviour is reproducible.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-002" ] }, { "id": "als-asrt-de-opacity-flag", "name": "locator_opacity_flag", "description": "Flag declaring that a locator is opaque and that no semantics may be inferred from its internal structure.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017", "SRC-004" ] } ], "artifacts": [ { "id": "als-asrt-art-prefix-map", "name": "Endpoint namespace and prefix binding map", "description": "The published map from prefix tokens to IRI patterns used to expand compact endpoint locators, together with its edition and the authority that publishes each binding. It is the only sanctioned way a compact locator becomes comparable, and a change to a binding changes the meaning of every stored assertion that cites it.", "media_or_form": [ "prefix-to-IRI binding table", "context or namespace declaration document", "curie map header within a mapping set" ], "serial": false, "identity_strategy": "Master-system identifier for the binding map issued by its publishing registry; otherwise a governed IRI in the adopting Dimension namespace; otherwise a UUID or ULID. Individual prefix tokens are keys within the map and are never identifiers of the map itself, and the map identifier is never an endpoint identifier.", "source_refs": [ "SRC-011", "SRC-017", "SRC-005", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "als-asrt-pin-finding", "name": "Version pins, composite keys, snapshots and endpoint resolution status", "description": "An endpoint reference is either pinned to a stated version of its source register or left to float to whatever is current, and the difference must be explicit because a floating reference can silently change the claim. Where an endpoint is identified by more than one field, the composite key is recorded as structured parts, not concatenated into an unparseable string. The envelope distinguishes an immutable snapshot capture, which fixes what was seen, from a live reference, which does not, and it records the last observed resolution status with the time of that observation, treating resolution as an observation made elsewhere rather than an act performed here.", "source_refs": [ "SRC-013", "SRC-011", "SRC-004", "SRC-016", "SRC-017", "SRC-008" ], "questions": [ { "id": "als-asrt-q-pin-version", "text": "Is each endpoint pinned to a stated version of its source register, or left to float to the current version?", "kind": "temporal", "answer_data": [ "Source-side version pin token", "Target-side version pin token", "Explicit floating declaration where no pin is set" ] }, { "id": "als-asrt-q-pin-composite", "text": "When an endpoint is identified by more than one field, how is the composite key recorded so it remains comparable?", "kind": "composition", "answer_data": [ "Named key parts with their individual values", "Ordering and equality rule across the parts", "Prohibition on lossy concatenation into a single string" ] }, { "id": "als-asrt-q-pin-mode", "text": "Does the assertion cite an immutable snapshot of the endpoint or a live reference that may change beneath it?", "kind": "state", "answer_data": [ "Reference mode code (snapshot or live)", "Snapshot reference and content digest where captured", "Consequence declared for the claim when a live reference changes" ] }, { "id": "als-asrt-q-pin-resolution", "text": "What was the last recorded resolution status of each endpoint, and when was that status observed?", "kind": "evidence", "answer_data": [ "Resolution status code per side", "Observation timestamp with explicit offset", "Reference to the resolution service that produced the observation" ] }, { "id": "als-asrt-q-pin-tombstone", "text": "How is a retired or tombstoned endpoint distinguished from one that never existed?", "kind": "exception", "answer_data": [ "Endpoint status code (active, deprecated, tombstoned, never-existed)", "Tombstone locator where the retired identifier still resolves", "Deprecation notice reference from the endpoint authority" ] } ], "data_elements": [ { "id": "als-asrt-de-source-version-pin", "name": "source_version_pin", "description": "Version token of the source register or vocabulary against which the source endpoint is pinned.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-011" ] }, { "id": "als-asrt-de-target-version-pin", "name": "target_version_pin", "description": "Version token of the target register or vocabulary against which the target endpoint is pinned.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-011" ] }, { "id": "als-asrt-de-endpoint-composite-key", "name": "endpoint_composite_key", "description": "Structured multi-part key for an endpoint whose identity requires more than one field, with named parts and an equality rule.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-017" ] }, { "id": "als-asrt-de-reference-mode", "name": "reference_mode", "description": "Code declaring whether each endpoint reference is an immutable snapshot or a live reference.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-013" ] }, { "id": "als-asrt-de-snapshot-ref", "name": "endpoint_snapshot_ref", "description": "Reference to an immutable capture of the endpoint as seen at pin time, with its content digest.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016", "SRC-009" ] }, { "id": "als-asrt-de-resolution-status", "name": "resolution_status", "description": "Last recorded resolution outcome for an endpoint locator, supplied by an external resolution service.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-017" ] }, { "id": "als-asrt-de-resolution-observed-at", "name": "resolution_observed_at", "description": "Observation time of the recorded resolution outcome, as an RFC 3339 date-time with seconds and an explicit offset.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "als-asrt-art-endpoint-snapshot", "name": "Endpoint reference snapshot", "description": "An immutable capture of what an endpoint reference presented at pin time: the locator, the version token in force, the composite key parts and a content digest of the captured representation. It exists so that a claim remains interpretable after the live endpoint changes, and it is a capture of a reference, not a copy of the endpoint's record content beyond what is needed to fix identity.", "media_or_form": [ "content-addressed reference capture", "fixed memento-style reference", "immutable pin record with digest" ], "serial": true, "identity_strategy": "Content digest of the captured reference bound to the endpoint's authoritative master-system identifier and the capture sequence; otherwise a governed snapshot IRI in the Dimension namespace; otherwise a UUID or ULID. The snapshot identifier never replaces the endpoint's own identifier and is never used as the assertion identifier.", "source_refs": [ "SRC-016", "SRC-009", "SRC-013", "SRC-017" ] } ], "inline_only_rationale": null } ] }, { "id": "als-asrt-shape-layer", "name": "Assertion Shape: Cardinality, Membership and Conditions", "description": "How the claim's arity, membership semantics, ordering and applicability guards are made explicit on the envelope instead of being inferred from repeated entries.", "source_refs": [ "SRC-011", "SRC-013", "SRC-010", "SRC-012" ], "findings": [ { "id": "als-asrt-cardinality-finding", "name": "Cardinality, ordered membership and conditional applicability", "description": "Cardinality is declared, not inferred. A bare two-column mapping cannot distinguish a genuine one-to-many claim from several independent one-to-one claims, so the envelope carries an explicit cardinality declaration covering one-to-one, one-to-many, many-to-one and many-to-many, together with a combination rule stating whether a multi-member side is a union, a set of alternatives or a ranked preference order, and an explicit rank where order matters. Conditional mappings are expressed as attribute-value guards naming externally defined attributes, with any attributes produced by applying the mapping recorded separately. This model declares the guards; evaluating them at runtime is done elsewhere.", "source_refs": [ "SRC-011", "SRC-013", "SRC-012", "SRC-010" ], "questions": [ { "id": "als-asrt-q-shape-cardinality", "text": "What cardinality does this assertion declare, and is that declaration explicit or merely implied by repeated entries?", "kind": "classification", "answer_data": [ "Cardinality code (one-to-one, one-to-many, many-to-one, many-to-many)", "Whether the declaration is asserted or derived", "Count of members on each side" ] }, { "id": "als-asrt-q-shape-membership", "text": "When several targets are asserted for one source, is the member set a union, a list of alternatives or a ranked preference?", "kind": "composition", "answer_data": [ "Combination rule code", "Member list per side", "Tie-breaking rule where ranks collide" ] }, { "id": "als-asrt-q-shape-condition", "text": "Which conditions must hold for the assertion to apply, and how are they expressed as attribute-value guards?", "kind": "constraint", "answer_data": [ "Condition attribute references", "Required values or bounding value sets per condition", "Statement that guard evaluation is performed by an external evaluator" ] }, { "id": "als-asrt-q-shape-order", "text": "How is a member's rank within a multi-member side recorded so that it survives serialization?", "kind": "interoperability", "answer_data": [ "Explicit rank value per member", "Rule forbidding reliance on serialization order", "Declared behaviour when ranks are absent" ] }, { "id": "als-asrt-q-shape-unit", "text": "Which combination of source and target members forms the smallest independently assertable unit?", "kind": "decision", "answer_data": [ "Definition of the atomic assertable unit", "Rule for splitting a multi-member claim into units", "Effect of splitting on the declared cardinality" ] } ], "data_elements": [ { "id": "als-asrt-de-cardinality-declaration", "name": "cardinality_declaration", "description": "Explicit code declaring the arity of the claim across both sides.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "id": "als-asrt-de-member-combination-rule", "name": "member_combination_rule", "description": "Code stating whether a multi-member side is a union, a set of alternatives or a ranked preference order.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-010" ] }, { "id": "als-asrt-de-member-rank", "name": "member_rank", "description": "Explicit rank of a member within its side, recorded so ordering does not depend on serialization order.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "als-asrt-de-applicability-condition", "name": "applicability_condition", "description": "Attribute-value guard that must hold for the assertion to apply, expressed against externally defined attributes.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "als-asrt-de-condition-attribute-ref", "name": "condition_attribute_ref", "description": "Reference to the external definition of an attribute named in a guard; the definition is not copied here.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-011" ] }, { "id": "als-asrt-de-produced-attribute", "name": "produced_attribute", "description": "Attribute-value pair recorded as a stated consequence of applying the mapping, distinct from a guard.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Cardinality, membership, ordering and guards are structural fields of the envelope record already declared as an artifact, and they gain nothing from a separate document. The attribute definitions named in guards are owned by external terminology and schema models, and guard evaluation belongs to a runtime evaluator outside this boundary, so this finding declares shape as inline data and references those definitions only." } ] }, { "id": "als-asrt-anomaly-layer", "name": "Degenerate, Conflicting and Malformed References", "description": "The states that a two-column mapping cannot represent: absence versus explicit unknown versus explicit denial, dangling and unresolved endpoints, malformed references, self links, duplicate envelopes and conflicting pins.", "source_refs": [ "SRC-001", "SRC-011", "SRC-013", "SRC-004", "SRC-017" ], "findings": [ { "id": "als-asrt-anomaly-finding", "name": "Absence, explicit unknown, explicit not-same, dangling endpoints, self links, duplicates and conflicts", "description": "Three states must be kept apart and none may be inferred from silence: no assertion exists, an endpoint is explicitly recorded as unknown, and equivalence is explicitly denied. Explicit denial is a positive claim with its own justification and issuer, expressible either through an inequality predicate or a negation modifier on the predicate slot, and it must never degrade into an absent or weak claim. Alongside these, the envelope represents dangling and unresolved endpoints, malformed or unresolvable relative references, self links where both sides normalize to the same locator, structurally identical duplicate envelopes, and conflicts where two assertions about the same pair pin different endpoint versions or make opposing claims. Conflicts are recorded and linked here; adjudicating, remediating, retracting or enforcing them is done elsewhere.", "source_refs": [ "SRC-001", "SRC-011", "SRC-013", "SRC-004", "SRC-002", "SRC-014", "SRC-017" ], "questions": [ { "id": "als-asrt-q-anom-absent", "text": "How does the record distinguish a missing endpoint from an endpoint explicitly recorded as unknown?", "kind": "validation", "answer_data": [ "Presence state code (present, absent, explicitly unknown)", "Rule that absence is never read as a claim", "Reason code for a declared unknown" ] }, { "id": "als-asrt-q-anom-negation", "text": "How is an explicit denial of equivalence recorded so that it cannot be read as a weak or absent claim?", "kind": "definition", "answer_data": [ "Negation modifier or inequality predicate reference", "Justification and issuer for the denial", "Statement that a denial carries the same standing as a positive claim" ] }, { "id": "als-asrt-q-anom-malformed", "text": "What is recorded when an endpoint locator is malformed or is a relative reference that cannot be resolved to an absolute form?", "kind": "exception", "answer_data": [ "Malformed-reference note with the offending value preserved verbatim", "Missing base reference indication", "Quarantine state preventing the envelope from being treated as a live claim" ] }, { "id": "als-asrt-q-anom-selflink", "text": "How is a self link, where both sides normalize to the same locator, detected and flagged?", "kind": "quality", "answer_data": [ "Self-link flag", "Normalization level at which the collision was found", "Declared handling (retain as flagged, or reject at creation)" ] }, { "id": "als-asrt-q-anom-conflict", "text": "When two assertions about the same pair pin different endpoint versions or make opposing claims, how is the conflict recorded without being resolved here?", "kind": "relationship", "answer_data": [ "Conflicts-with references between envelope identifiers", "Conflict type code (version divergence, opposing claim, duplicate)", "Reference to the external model that adjudicates and enforces resolution" ] } ], "data_elements": [ { "id": "als-asrt-de-endpoint-presence-state", "name": "endpoint_presence_state", "description": "Code per side distinguishing a present endpoint, an absent one and one explicitly recorded as unknown.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-011" ] }, { "id": "als-asrt-de-negation-modifier", "name": "negation_modifier", "description": "Modifier or inequality predicate reference recording that equivalence is explicitly denied rather than merely unasserted.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-011", "SRC-013" ] }, { "id": "als-asrt-de-malformed-note", "name": "malformed_reference_note", "description": "Record of a syntactically invalid or unresolvable relative locator, preserving the offending value verbatim.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-002" ] }, { "id": "als-asrt-de-self-link-flag", "name": "self_link_flag", "description": "Flag set when both sides normalize to the same locator at the declared normalization level.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-002" ] }, { "id": "als-asrt-de-duplicate-of-ref", "name": "duplicate_of_ref", "description": "Reference to a structurally identical envelope within the same declared scope, linked rather than silently merged.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-017" ] }, { "id": "als-asrt-de-conflicts-with-ref", "name": "conflicts_with_ref", "description": "References to envelopes that make opposing claims or pin divergent endpoint versions for the same pair.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "Every item here is a state code, flag or link recorded on the envelope record itself, so no separate document is warranted. Materialising an exception or conflict register as an artifact would drift into the audit-record and enforcement semantics that belong to the audit and authorization models, so these anomalies are held strictly as inline attributes and cross-references between envelope identifiers." } ] } ] }, { "id": "als-tax-relation-semantics", "name": "Relation Kind Taxonomy and Semantic Strength", "description": "The governed catalogue of mutually exclusive relation kinds, their formal logical properties, their ordinal semantic strength and inference permission, the subject plane each assertion operates on, and the versioned bindings that project each kind onto external vocabularies.", "rationale": "Deployed practice collapses many materially different claims into a single sameAs link, and primary sources disagree on what that link means: OWL 2 interprets sameAs as domain-element equality, SKOS deliberately separates exactMatch from owl:sameAs and withholds transitivity from closeMatch, schema.org sameAs is a reference-page URL, and HTTP redirection is a request-targeting instruction. A discriminating taxonomy with declared formal properties is the only way an agent can tell which claim is actually being made.", "source_refs": [ "SRC-018", "SRC-019", "SRC-020", "SRC-022", "SRC-023", "SRC-025", "SRC-030" ], "layers": [ { "id": "als-tax-kind-catalogue", "name": "Relation Kind Catalogue and External Bindings", "description": "Defines the closed, governed set of relation kinds with non-overlapping normative definitions and discriminating tests, and the versioned crosswalk that binds each kind to external vocabulary terms as an alignment rather than a conformance claim.", "source_refs": [ "SRC-018", "SRC-020", "SRC-025", "SRC-026", "SRC-027", "SRC-029" ], "findings": [ { "id": "als-tax-kind-register", "name": "Governed register of mutually exclusive relation kinds", "description": "WM-XCT-036 recognises nine relation kinds, each with a normative definition and a discriminating test that separates it from its nearest neighbour: identifier-alias, where two identifiers designate the same subject within a declared identifier system; historical-identifier, a former identifier superseded by a current one for the same subject; referent-replacement, where the source resource or record is supplanted by a replacement that may be a different subject after a merge; exact-semantic-match, where terms are interchangeable across a wide range of retrieval applications; close-match, where terms are interchangeable in some applications only; equivalent-in-context, where equivalence is asserted only inside a declared context and is void outside it; probable-entity-match, an evidence-weighted, non-asserted hypothesis that two records denote one entity; not-same-assertion, an explicit negative claim; and strict-identity, a formal claim that both endpoints denote one and the same individual. Exactly one kind is assigned per assertion. Register status, effective interval and successor are held per kind so that retirement of a kind is itself governed.", "source_refs": [ "SRC-018", "SRC-020", "SRC-022", "SRC-026", "SRC-027", "SRC-029" ], "questions": [ { "id": "als-tax-q-kind-definition", "text": "Which relation kind in the register exactly matches the claim being made, and what is that kind's normative definition?", "kind": "definition", "answer_data": [ "relation_kind_code", "normative definition text", "register release in force" ] }, { "id": "als-tax-q-kind-discriminator", "text": "What discriminating test separates the selected relation kind from the adjacent kind that would otherwise be chosen?", "kind": "classification", "answer_data": [ "adjacent kind code", "discriminating test statement", "outcome of the test for this assertion" ] }, { "id": "als-tax-q-kind-authority", "text": "Which role is authorised to add, amend or retire a relation kind in the register, and under which decision record?", "kind": "authority", "answer_data": [ "authorising role identifier", "decision record reference", "effective register release" ] }, { "id": "als-tax-q-kind-exclusivity", "text": "Is exactly one relation kind carried on this assertion, and how is a multi-kind or blended claim rejected?", "kind": "constraint", "answer_data": [ "assigned kind count", "exclusivity rule reference", "rejection outcome code" ] }, { "id": "als-tax-q-kind-status", "text": "What is the register status of the relation kind, and if it is deprecated which successor kind replaces it?", "kind": "lifecycle", "answer_data": [ "register status value", "deprecation effective timestamp", "successor kind code" ] } ], "data_elements": [ { "id": "als-tax-de-relation-kind-code", "name": "relation_kind_code", "description": "Controlled code identifying exactly one relation kind from the governed register.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-028" ] }, { "id": "als-tax-de-kind-definition", "name": "kind_normative_definition", "description": "The normative definition text of the relation kind as published in the register release in force.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-020" ] }, { "id": "als-tax-de-kind-discriminator", "name": "kind_discriminating_test", "description": "Stated test that distinguishes this kind from its nearest neighbouring kinds, expressed so that a wrong assignment is detectable.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-020", "SRC-022" ] }, { "id": "als-tax-de-kind-status", "name": "kind_register_status", "description": "Governed status of the relation kind: proposed, active, deprecated or withdrawn.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-026", "SRC-016" ] }, { "id": "als-tax-de-kind-successor", "name": "kind_successor_code", "description": "Relation kind that replaces a deprecated kind; absent while the kind is active.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-026" ] } ], "artifacts": [ { "id": "als-tax-kind-register-doc", "name": "Relation Kind Register", "description": "The published, versioned register of relation kinds carrying for each kind its code, normative definition, discriminating tests, register status, effective interval and successor. It is a declarative catalogue; nothing in it evaluates or enforces an assertion.", "media_or_form": [ "controlled register", "versioned tabular release", "structured record set" ], "serial": true, "identity_strategy": "Register entries are keyed by the authoritative master-system relation-kind code issued by the register owner; a governed IRI is minted per kind within the adopting Dimension namespace; a ULID is assigned to a register release only where the master system issues no release identifier.", "source_refs": [ "SRC-020", "SRC-016", "SRC-026" ] } ], "inline_only_rationale": null }, { "id": "als-tax-projection-crosswalk", "name": "Versioned alignment bindings to external vocabularies", "description": "Each relation kind carries zero or more bindings to external terms, declared as alignments with an explicit comparability verdict (narrower, broader, equivalent-as-used or incomparable) and the dated edition the binding was read from. Representative bindings: strict-identity to owl:sameAs and SameIndividual; not-same-assertion to owl:differentFrom, DifferentIndividuals and the SSSOM predicate modifier that negates a predicate; exact-semantic-match to skos:exactMatch; close-match to skos:closeMatch; referent-replacement to dcterms:isReplacedBy, to HTTP 301 and 308 responses and to FHIR Patient.link replaced-by; identifier-alias to database secondary keys and to the registered alternate relation; representation preference to rel=canonical and the registered duplicate relation; probable-entity-match to Wikidata P460 with SSSOM confidence and justification. Bindings never assert conformance and never import the target's operational behaviour.", "source_refs": [ "SRC-018", "SRC-020", "SRC-023", "SRC-024", "SRC-016", "SRC-025", "SRC-026", "SRC-027", "SRC-028", "SRC-029" ], "questions": [ { "id": "als-tax-q-binding-target", "text": "Which external vocabulary term is this relation kind bound to, and is the binding recorded as an alignment rather than a conformance claim?", "kind": "interoperability", "answer_data": [ "external term IRI or registered token", "binding declaration type", "alignment statement text" ] }, { "id": "als-tax-q-binding-comparability", "text": "Is the external term narrower than, broader than, equivalent-as-used to, or incomparable with the local relation kind?", "kind": "relationship", "answer_data": [ "comparability verdict code", "justification note", "known divergence list" ] }, { "id": "als-tax-q-binding-edition", "text": "Which dated edition or release of the external vocabulary was the binding taken from, and when was it last reconfirmed?", "kind": "provenance", "answer_data": [ "external specification version or date", "binding author reference", "reconfirmation timestamp" ] }, { "id": "als-tax-q-binding-evidence", "text": "What documented statement in the external specification supports the asserted binding strength?", "kind": "evidence", "answer_data": [ "cited clause or axiom reference", "specification section identifier", "evidence sufficiency verdict" ] } ], "data_elements": [ { "id": "als-tax-de-binding-term", "name": "external_term_reference", "description": "IRI or registered token of the external vocabulary term bound to the local relation kind.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-020", "SRC-016" ] }, { "id": "als-tax-de-binding-comparability", "name": "binding_comparability", "description": "Verdict on how the external term compares with the local kind: narrower, broader, equivalent-as-used or incomparable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-025" ] }, { "id": "als-tax-de-binding-edition", "name": "external_specification_edition", "description": "Dated edition, version or registry snapshot of the external vocabulary from which the binding was read.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-028" ] }, { "id": "als-tax-de-binding-clause", "name": "binding_evidence_clause", "description": "Reference to the specific clause, axiom or registry row in the external specification that supports the binding.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-019", "SRC-020", "SRC-024" ] } ], "artifacts": [ { "id": "als-tax-crosswalk-table", "name": "Relation Kind Projection Crosswalk", "description": "Published crosswalk from each local relation kind to external vocabulary terms, carrying the comparability verdict, the dated external edition, the supporting clause reference and recorded divergences. It documents alignment only and confers no conformance.", "media_or_form": [ "crosswalk table", "versioned mapping release", "structured record set" ], "serial": true, "identity_strategy": "Each crosswalk row is keyed by the authoritative master-system pair of relation-kind code and external term identifier; a governed IRI is minted per crosswalk release; a ULID is used only when no master-system release identifier is available.", "source_refs": [ "SRC-020", "SRC-016", "SRC-028" ] } ], "inline_only_rationale": null } ] }, { "id": "als-tax-formal-properties", "name": "Formal Relation Properties and Strength Control", "description": "Declares, per relation kind, the logical properties that govern how the relation may be read, and the ordinal strength rank with an explicit inference-permission flag. All declarations are stated, never computed.", "source_refs": [ "SRC-019", "SRC-020", "SRC-023", "SRC-006", "SRC-030" ], "findings": [ { "id": "als-tax-property-profile", "name": "Per-kind directionality, symmetry, reflexivity, transitivity and invertibility", "description": "Every relation kind carries a property profile with four-valued property states (asserted, denied, not-asserted-by-source, not-applicable) so that silence in a source vocabulary is never recorded as a negative. Grounded profile examples: strict-identity is non-directional, symmetric, reflexive and transitive because the axiom is satisfied only when the named individuals map to the identical domain element; exact-semantic-match is symmetric and transitive under SKOS S44 and S45, with reflexivity not asserted by the source; close-match is symmetric under S44 but transitivity is deliberately withheld to prevent compound error, so it is recorded as denied rather than unstated; not-same-assertion is symmetric and irreflexive and is not transitive; referent-replacement and historical-identifier are directional and invertible through a declared inverse and are asserted as single hops, never as a chain closure; probable-entity-match is symmetric, consistent with the deployed symmetric said-to-be-the-same-as property, and its transitivity is denied.", "source_refs": [ "SRC-019", "SRC-020", "SRC-023", "SRC-006", "SRC-026", "SRC-029" ], "questions": [ { "id": "als-tax-q-prop-symmetry", "text": "Is symmetry or reflexivity asserted for this relation kind by its source vocabulary, denied, or simply left unstated?", "kind": "constraint", "answer_data": [ "symmetry state four-valued code", "reflexivity state four-valued code", "source clause reference" ] }, { "id": "als-tax-q-prop-transitivity", "text": "Is transitivity asserted, explicitly withheld, or unstated, and does the kind have a named inverse relation?", "kind": "relationship", "answer_data": [ "transitivity state four-valued code", "inverse relation kind code", "withholding rationale text" ] }, { "id": "als-tax-q-prop-direction", "text": "For a directional kind, which endpoint is the subject and which is the object, and what does reversing them change?", "kind": "identity", "answer_data": [ "directionality code", "subject endpoint role", "object endpoint role", "reversal semantics note" ] }, { "id": "als-tax-q-prop-inference", "text": "Is inference permitted from this relation kind, and which externally owned entailment regime would perform it?", "kind": "decision", "answer_data": [ "inference permitted flag", "named entailment regime reference", "owning system reference" ] } ], "data_elements": [ { "id": "als-tax-de-directionality", "name": "directionality", "description": "Whether the relation kind is directional with distinct subject and object roles, or non-directional.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-026" ] }, { "id": "als-tax-de-symmetry-state", "name": "symmetry_state", "description": "Four-valued symmetry declaration: asserted, denied, not-asserted-by-source or not-applicable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-029" ] }, { "id": "als-tax-de-reflexivity-state", "name": "reflexivity_state", "description": "Four-valued reflexivity declaration; strict-identity is asserted reflexive, not-same-assertion is irreflexive, SKOS matches are not asserted by source.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-020" ] }, { "id": "als-tax-de-transitivity-state", "name": "transitivity_state", "description": "Four-valued transitivity declaration; close-match is denied, exact-semantic-match and strict-identity are asserted.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-020" ] }, { "id": "als-tax-de-inverse-kind", "name": "inverse_relation_kind", "description": "Relation kind that expresses the inverse reading of a directional kind, where one exists.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020", "SRC-026" ] } ], "artifacts": [ { "id": "als-tax-property-matrix", "name": "Relation Property Matrix", "description": "Matrix of relation kinds against directionality, symmetry, reflexivity, transitivity, invertibility, inference permission and the supporting source clause. It is a declaration surface only; it does not compute or materialise any closure.", "media_or_form": [ "matrix table", "structured record set" ], "serial": false, "identity_strategy": "Keyed by the authoritative master-system relation-kind code plus the identifier of the register release it was generated against; no separate serial number is issued, and a UUID is assigned only if that register release lacks a master-system identifier.", "source_refs": [ "SRC-019", "SRC-020", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "als-tax-strength-inference", "name": "Ordinal semantic strength and inference permission", "description": "Each relation kind carries an ordinal strength rank on a single declared scale, from a non-asserted hypothesis (probable-entity-match), through scoped or retrieval-level interchangeability (close-match, equivalent-in-context, exact-semantic-match), through system-scoped designation (identifier-alias, historical-identifier, referent-replacement), to a maximal formal identity claim (strict-identity), with explicit negation (not-same-assertion) held on its own high-strength negative rank. Strength is a declared attribute of the kind, not a computed similarity score; a confidence value in the interval 0 to 1 may accompany an assertion but never upgrades its rank. The inference-permission flag states whether substitution or entailment is allowed at all, and any permitted inference is executed by an externally owned regime. Published analysis that identity behaves as a scale rather than a binary supports the ordinal treatment, while OWL semantics fix the maximal rank.", "source_refs": [ "SRC-019", "SRC-020", "SRC-028", "SRC-029", "SRC-030" ], "questions": [ { "id": "als-tax-q-strength-rank", "text": "What ordinal semantic-strength rank does this relation kind carry on the declared scale, and what is the scale's top rank?", "kind": "measurement", "answer_data": [ "strength rank ordinal value", "scale definition reference", "top rank kind code" ] }, { "id": "als-tax-q-strength-prohibited", "text": "Which downstream operations are prohibited at this strength rank without a higher-ranked assertion?", "kind": "constraint", "answer_data": [ "prohibited operation list", "minimum rank required per operation", "rule reference" ] }, { "id": "als-tax-q-strength-exception", "text": "Under what recorded exception may a lower-strength assertion be consumed as if it were stronger, and who authorises that exception?", "kind": "exception", "answer_data": [ "exception record identifier", "authorising role", "exception validity interval", "scope limitation" ] }, { "id": "als-tax-q-strength-confidence", "text": "Does a confidence value accompany this assertion, and is it prevented from altering the declared strength rank?", "kind": "decision", "answer_data": [ "confidence value between 0 and 1", "confidence method reference", "rank immutability rule reference" ] } ], "data_elements": [ { "id": "als-tax-de-strength-rank", "name": "strength_rank", "description": "Ordinal rank of the relation kind on the declared semantic-strength scale.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-030" ] }, { "id": "als-tax-de-inference-permitted", "name": "inference_permitted", "description": "Declared flag stating whether any inference or substitution may be drawn from the relation kind; execution belongs to an external regime.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-030" ] }, { "id": "als-tax-de-confidence", "name": "confidence_value", "description": "Optional confidence in the interval 0 to 1 supplied by the asserting party, where 1 indicates full confidence.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-028", "SRC-029" ] }, { "id": "als-tax-de-justification-category", "name": "justification_category", "description": "Controlled category describing how the assertion was justified, for example lexical, logical, human-curated or similarity-based.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-028", "SRC-029" ] } ], "artifacts": [], "inline_only_rationale": "Strength rank, inference permission, confidence and justification category are scalar attributes carried on the relation-kind register entry and on the individual assertion record. Publishing them as a separate artifact would duplicate the register and create a second place where the ordinal scale could drift. The scale definition itself is a short inline declaration held with the register release, and the reasoning regime that would act on the inference flag is owned outside this model, so there is nothing further to materialise here." } ] }, { "id": "als-tax-subject-planes", "name": "Equivalence Planes and Endpoint Scope", "description": "Separates the six planes on which an equivalence or replacement claim can be made and constrains which endpoint types and contextual scopes each relation kind admits.", "source_refs": [ "SRC-021", "SRC-022", "SRC-024", "SRC-016", "SRC-027" ], "findings": [ { "id": "als-tax-plane-discrimination", "name": "Six discriminated equivalence planes", "description": "Every assertion declares exactly one plane. Identifier equivalence: two identifier tokens designate the same subject within a declared identifier system, which web architecture treats as a URI alias with acknowledged costs. Record equivalence: two records or descriptions concern the same subject, as with a record-level link between patient resources that concern the same actual individual. Real-world entity identity: the endpoints denote one and the same individual in a domain of discourse. Name or label alias: a lexical variant of a label, which is a property of one subject and never an equivalence between two subjects. Representation equivalence: two representations or serialisations of one resource, covered by registered relations such as alternate, duplicate and canonical, which RDF and web architecture keep separate from the resource denoted. Referent replacement: the referent, record or resource is supplanted or superseded rather than equated. Cross-plane assertions are rejected by default; a plane change requires a new assertion.", "source_refs": [ "SRC-021", "SRC-022", "SRC-024", "SRC-016", "SRC-026", "SRC-027" ], "questions": [ { "id": "als-tax-q-plane-selection", "text": "On which of the six equivalence planes does this assertion operate?", "kind": "classification", "answer_data": [ "equivalence plane code", "plane definition reference", "selection justification" ] }, { "id": "als-tax-q-plane-endpoint-denotation", "text": "What does each side of the assertion actually denote: an identifier token, a record, a resource, a label literal or a real-world entity?", "kind": "identity", "answer_data": [ "subject denotation type", "object denotation type", "endpoint identifier values" ] }, { "id": "als-tax-q-plane-crossing", "text": "Are the two endpoints on the same plane, and what is the rejection rule when they are not?", "kind": "constraint", "answer_data": [ "plane congruence verdict", "cross-plane rejection rule reference", "remediation instruction" ] }, { "id": "als-tax-q-plane-label-vs-subject", "text": "How is a name or label alias kept distinct from an equivalence between two distinct subjects?", "kind": "definition", "answer_data": [ "label alias definition", "subject count for the assertion", "counterexample reference" ] } ], "data_elements": [ { "id": "als-tax-de-equivalence-plane", "name": "equivalence_plane", "description": "Controlled code naming the plane on which the assertion operates: identifier, record, entity, label, representation or replacement.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-021", "SRC-022", "SRC-027" ] }, { "id": "als-tax-de-subject-endpoint", "name": "subject_endpoint_reference", "description": "Reference to the subject endpoint, resolved through the owning identifier or record system and never minted by this model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-021", "SRC-028" ] }, { "id": "als-tax-de-object-endpoint", "name": "object_endpoint_reference", "description": "Reference to the object endpoint, resolved through the owning identifier or record system.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-021", "SRC-028" ] }, { "id": "als-tax-de-endpoint-denotation", "name": "endpoint_denotation_type", "description": "Declared type of what each endpoint denotes, distinguishing identifier token, record, resource, label literal and real-world entity.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-021", "SRC-022", "SRC-028" ] } ], "artifacts": [], "inline_only_rationale": "The plane declaration is a single coded attribute on each assertion plus a short definitional enumeration held with the relation-kind register release; it produces no separate deliverable. The endpoints it points at are records owned by other models, so materialising a plane artifact would either duplicate the register or begin to shadow endpoint records that this model must not own." }, { "id": "als-tax-endpoint-scope", "name": "Admissible endpoint types and contextual scope of an assertion", "description": "Each relation kind declares which endpoint types it admits and the scope inside which the assertion holds. SKOS mapping properties are conventionally used between concepts in different concept schemes, so a semantic match asserted inside a single scheme is flagged. Identifier alias holds only within its declared identifier system or systems. Equivalent-in-context requires a named context such as jurisdiction, purpose, dataset or time window and is void outside it. Representation-level relations hold between a context IRI and a target IRI in the sense of the web-linking model. Strict identity admits only endpoints that denote individuals in a shared domain of discourse. Each assertion also declares a validity interval and what is recorded when an endpoint cannot be resolved, without this model attempting resolution.", "source_refs": [ "SRC-020", "SRC-021", "SRC-022", "SRC-006", "SRC-028" ], "questions": [ { "id": "als-tax-q-endpoint-types", "text": "Which endpoint entity types are admissible for the selected relation kind, and does each endpoint satisfy them?", "kind": "constraint", "answer_data": [ "admissible endpoint type list", "subject type code", "object type code", "admissibility verdict" ] }, { "id": "als-tax-q-scope-interval", "text": "Over which validity interval and named context does this equivalence hold, and when does it lapse?", "kind": "temporal", "answer_data": [ "context identifier", "valid from timestamp", "valid to timestamp", "lapse condition" ] }, { "id": "als-tax-q-endpoint-authority", "text": "Which authority owns each endpoint, and is a cross-authority assertion permitted for this relation kind?", "kind": "ownership", "answer_data": [ "subject owning authority", "object owning authority", "cross-authority permission verdict" ] }, { "id": "als-tax-q-endpoint-unresolvable", "text": "What is recorded when an endpoint reference cannot be resolved at the time the assertion is made?", "kind": "state", "answer_data": [ "endpoint resolution state code", "observation timestamp", "referral target for resolution" ] } ], "data_elements": [ { "id": "als-tax-de-subject-type", "name": "subject_type", "description": "Declared type of the subject endpoint, for example ontology class, SKOS concept, named individual, record or identifier token.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-028", "SRC-020" ] }, { "id": "als-tax-de-object-type", "name": "object_type", "description": "Declared type of the object endpoint, drawn from the same controlled list as subject_type.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-028", "SRC-020" ] }, { "id": "als-tax-de-context-scope", "name": "context_scope_reference", "description": "Named context, such as a jurisdiction, purpose, dataset or scheme pair, inside which an equivalent-in-context or otherwise scoped assertion holds.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020", "SRC-030" ] }, { "id": "als-tax-de-validity-interval", "name": "assertion_validity_interval", "description": "Interval during which the assertion is claimed to hold, expressed as RFC 3339 start and end instants with seconds and explicit offset.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-029" ] }, { "id": "als-tax-de-endpoint-resolution-state", "name": "endpoint_resolution_state", "description": "Recorded state of each endpoint reference at assertion time: resolved, unresolvable or not-checked; this model records the state and does not perform resolution.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-021", "SRC-023" ] } ], "artifacts": [], "inline_only_rationale": "Endpoint typing and contextual scope are inline attributes of an individual assertion, and the admissible-type lists live as columns on the relation-kind register rather than as a separate deliverable. Producing an artifact here would require holding endpoint inventories or resolution results, which belong to the endpoint-owning and resolution models and are explicitly outside this model's boundary." } ] } ] }, { "id": "als-tax-assertion-integrity", "name": "Applicability, Negation and Classification Integrity", "description": "The rules that make misuse of the taxonomy detectable: applicability tests with documented counterexamples, the separation of explicit not-same from unknown, unassessed and absent, and the declarative treatment of invalid combinations, cycles, contradictions and strength changes.", "rationale": "A taxonomy that cannot be shown to be misused is not falsifiable. Primary sources supply concrete counterexamples: OWL makes no unique-name assumption so absence proves nothing, SKOS withholds transitivity from closeMatch and declares exactMatch disjoint with broadMatch and relatedMatch, web architecture forbids one URI directly identifying different resources, HTTP redirection targets future requests rather than asserting identity, and canonical designates a preferred IRI for duplicated content. Deployed practice and published analysis show these are routinely overclaimed, so downgrade, negation and contradiction handling must be first-class.", "source_refs": [ "SRC-020", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-028", "SRC-030", "SRC-031" ], "layers": [ { "id": "als-tax-applicability-layer", "name": "Applicability Rules and Counterexamples", "description": "Defines when each relation kind may legitimately be used, the documented counterexamples that mark misuse, and the evidence threshold required before a high-strength kind may be asserted.", "source_refs": [ "SRC-020", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-028", "SRC-030" ], "findings": [ { "id": "als-tax-applicability-tests", "name": "Applicability tests, counterexamples and overclaiming detection", "description": "Applicability is expressed as pass or fail tests bound to documented counterexamples so that misuse is detectable rather than merely discouraged. Standing counterexamples: asserting strict identity between a real-world entity and a web page describing it, which is a URI collision under web architecture and is exactly what schema.org sameAs points at when it names a reference page; asserting strict identity between two thesaurus concepts that are only interchangeable for retrieval, which SKOS separates from OWL identity; reading a permanent redirect as identity of the denoted things when the specification frames it as which URI to use for future requests; reading rel=canonical as sameness when it designates a preferred IRI for duplicative or superset content and is informational; chaining close-match transitively when SKOS withholds transitivity from it precisely to avoid compound error; attaching a probabilistic score to a strict-identity assertion. Each detected pattern names the lower-strength kind the assertion must be downgraded to. This model publishes the tests; running them and enforcing outcomes belongs to the adopting Dimension's validation and enforcement services.", "source_refs": [ "SRC-020", "SRC-022", "SRC-023", "SRC-024", "SRC-025", "SRC-028", "SRC-030" ], "questions": [ { "id": "als-tax-q-applicability-failure", "text": "Which applicability test does this assertion fail, and which documented counterexample does it match?", "kind": "validation", "answer_data": [ "failed test identifier", "counterexample identifier", "failure explanation text" ] }, { "id": "als-tax-q-applicability-evidence", "text": "What evidence must exist before a kind at this strength rank may be asserted at all?", "kind": "evidence", "answer_data": [ "required evidence class", "evidence reference", "sufficiency verdict" ] }, { "id": "als-tax-q-applicability-overclaim", "text": "Which overclaiming pattern is suspected, and which lower-strength relation kind is the correct replacement?", "kind": "quality", "answer_data": [ "overclaim pattern code", "recommended downgrade target kind", "supporting source clause" ] }, { "id": "als-tax-q-applicability-review", "text": "Which review step must complete before an assertion may be published at the top strength rank?", "kind": "process", "answer_data": [ "review step identifier", "reviewing role", "review completion timestamp" ] } ], "data_elements": [ { "id": "als-tax-de-applicability-test", "name": "applicability_test_reference", "description": "Identifier of the published applicability test that governs use of a relation kind in a given plane and context.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-020", "SRC-022" ] }, { "id": "als-tax-de-counterexample", "name": "counterexample_reference", "description": "Identifier of a documented counterexample demonstrating a misuse of a relation kind, together with its supporting source clause.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-022", "SRC-024", "SRC-025", "SRC-030" ] }, { "id": "als-tax-de-evidence-reference", "name": "evidence_reference", "description": "Pointer to the evidence relied on for the assertion; the evidence itself and its adjudication are owned elsewhere.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-028", "SRC-029" ] }, { "id": "als-tax-de-overclaim-flag", "name": "overclaim_pattern_code", "description": "Code naming a recognised overclaiming pattern matched by an assertion, together with the recommended downgrade target.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-030", "SRC-020" ] } ], "artifacts": [ { "id": "als-tax-applicability-test-set", "name": "Applicability and Counterexample Test Set", "description": "Published, versioned set of applicability tests, each paired with a documented counterexample, the source clause that grounds it and the recommended downgrade target. It is a declarative test catalogue: execution, verdict recording and any enforcement are performed by services outside this model.", "media_or_form": [ "test catalogue", "versioned structured record set", "annotated example collection" ], "serial": true, "identity_strategy": "Each test is keyed by the authoritative master-system test identifier issued by the register owner, expressed as a governed IRI within the adopting Dimension namespace; a ULID is assigned to a test-set release only where the master system issues no release identifier.", "source_refs": [ "SRC-020", "SRC-022", "SRC-024", "SRC-030" ] } ], "inline_only_rationale": null } ] }, { "id": "als-tax-consistency-layer", "name": "Negation, Contradiction and Classification Change", "description": "Holds explicit not-same assertions apart from unknown, unassessed and absent, and declares the invalid combinations, cycles, contradictory pairings and change-control obligations that apply when a classification is downgraded, upgraded or superseded.", "source_refs": [ "SRC-018", "SRC-020", "SRC-026", "SRC-028", "SRC-029", "SRC-031" ], "findings": [ { "id": "als-tax-negative-unknown", "name": "Explicit not-same held apart from unknown, unassessed and absent", "description": "Four distinct states are recorded and never conflated. Explicit not-same is a positive assertion that the endpoints do not denote the same thing, projecting to owl:differentFrom and DifferentIndividuals, to the deployed different-from property, and to a negated mapping predicate in SSSOM. Unknown means the question was asked and no determination could be reached. Unassessed means the pair has never been examined. Absent means no record exists at all. Because OWL does not assume that different names denote different individuals, the absence of an alias assertion carries no negative content, and no consumer may read absence as a not-same claim. A not-same assertion carries its own justification category, evidence reference and validity interval, and is symmetric and irreflexive.", "source_refs": [ "SRC-018", "SRC-028", "SRC-029", "SRC-031" ], "questions": [ { "id": "als-tax-q-negation-state", "text": "Is this pair explicitly not-same, unknown, unassessed, or simply absent from the record set?", "kind": "state", "answer_data": [ "assertion state code", "state observation timestamp", "asserting party reference" ] }, { "id": "als-tax-q-negation-openworld", "text": "May the absence of an alias assertion be read as a not-same claim, and which open-world rule forbids it?", "kind": "constraint", "answer_data": [ "absence interpretation verdict", "open-world rule reference", "consumer instruction text" ] }, { "id": "als-tax-q-negation-evidence", "text": "What evidence supports an explicit not-same assertion, as distinct from a failure to find a match?", "kind": "evidence", "answer_data": [ "negative evidence class", "evidence reference", "distinguishing note versus non-match" ] }, { "id": "als-tax-q-negation-retention", "text": "How long is a not-same assertion retained after its endpoints are retired, and which policy owns that disposition?", "kind": "retention", "answer_data": [ "retention period declaration", "owning policy reference", "tombstone requirement flag" ] } ], "data_elements": [ { "id": "als-tax-de-assertion-state", "name": "assertion_state", "description": "Four-valued state distinguishing explicit not-same, unknown, unassessed and absent for a given endpoint pair and plane.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-031" ] }, { "id": "als-tax-de-predicate-negation", "name": "predicate_negation_flag", "description": "Flag negating the relation kind so that an assertion reads as not a match of this kind, mirroring the SSSOM predicate modifier.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-028", "SRC-018" ] }, { "id": "als-tax-de-negative-evidence", "name": "negative_evidence_class", "description": "Class of evidence supporting an explicit negative claim, distinguished from mere absence of a positive match.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-028", "SRC-029" ] } ], "artifacts": [], "inline_only_rationale": "The negation and unknown-state distinction is a single coded attribute plus a negation flag on the assertion record, with supporting references pointing at evidence held by other models. There is no separately publishable deliverable, and creating one would either duplicate the assertion set or imply that this model stores the underlying evidence, which it does not." }, { "id": "als-tax-conflict-change", "name": "Invalid combinations, cycles, contradictions and strength change control", "description": "Declarative integrity rules over sets of assertions. Contradiction: the same endpoint pair on the same plane and context may not carry both strict-identity and explicit not-same. Disjointness carried from SKOS: an exact match is disjoint with broad match and related match, so those combinations are invalid. Plane contradiction: strict identity on the entity plane conflicts with a referent-replacement assertion that treats the endpoints as distinct successive referents. Cycles: replacement and historical-identifier chains must be acyclic and must terminate in a current endpoint; a closed cycle is recorded as a defect for referral, not silently broken. Cardinality: strict identity on the entity plane implies a one-to-one pairing, while probable-entity-match may stand at many-to-many pending adjudication elsewhere. Change control: any change of relation kind is a new classification carrying the prior kind, the reason, the authorising role and effective and observation timestamps; upgrade to the top strength rank additionally requires an authority declaration and an evidence reference, and downgrade must preserve the superseded classification rather than overwrite it. Detection, adjudication and enforcement of these rules are performed by services outside this model.", "source_refs": [ "SRC-018", "SRC-020", "SRC-026", "SRC-027", "SRC-028", "SRC-029" ], "questions": [ { "id": "als-tax-q-conflict-pairs", "text": "Which relation-kind combinations are declared mutually invalid for the same endpoint pair, plane and context?", "kind": "validation", "answer_data": [ "invalid combination rule identifier", "conflicting kind codes", "source clause reference" ] }, { "id": "als-tax-q-change-record", "text": "What must be recorded when an assertion's relation kind is downgraded or upgraded?", "kind": "lifecycle", "answer_data": [ "prior kind code", "new kind code", "change reason code", "authorising role", "superseded classification reference" ] }, { "id": "als-tax-q-change-timing", "text": "Which effective interval and observation timestamp distinguish a superseded classification from the current one?", "kind": "temporal", "answer_data": [ "effective from timestamp", "effective to timestamp", "observation timestamp" ] }, { "id": "als-tax-q-cycle-handling", "text": "How is a replacement or historical-identifier chain handled when it closes on itself?", "kind": "exception", "answer_data": [ "cycle defect record identifier", "chain member list", "referral target for adjudication" ] }, { "id": "als-tax-q-change-trigger", "text": "What event obliges a mandatory re-classification review of an existing assertion?", "kind": "event", "answer_data": [ "trigger event code", "event timestamp", "review obligation deadline" ] } ], "data_elements": [ { "id": "als-tax-de-invalid-combination", "name": "invalid_combination_rule", "description": "Declarative rule naming a pair or set of relation kinds that may not co-occur for the same endpoint pair, plane and context.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-020", "SRC-018" ] }, { "id": "als-tax-de-prior-kind", "name": "prior_relation_kind", "description": "Relation kind carried before a downgrade or upgrade, retained so that the classification history is reconstructible.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-026", "SRC-027" ] }, { "id": "als-tax-de-change-reason", "name": "classification_change_reason", "description": "Controlled reason for a change of relation kind, such as new evidence, overclaim correction, external vocabulary revision or authority decision.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-028", "SRC-029" ] }, { "id": "als-tax-de-mapping-cardinality", "name": "mapping_cardinality", "description": "Declared cardinality of the pairing, such as one-to-one, one-to-many, many-to-one or many-to-many.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-028" ] }, { "id": "als-tax-de-observation-time", "name": "observation_timestamp", "description": "RFC 3339 instant with seconds and explicit offset at which the classification was observed or ingested, recorded separately from the effective interval.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-028" ] } ], "artifacts": [ { "id": "als-tax-conflict-rule-catalogue", "name": "Invalid Combination and Cycle Rule Catalogue", "description": "Declarative catalogue of contradiction rules, disjointness rules carried from aligned vocabularies, cycle constraints on directed chains, cardinality expectations per relation kind and the mandatory content of a classification-change record. It states the rules; evaluating assertions against them, raising defects and enforcing outcomes are functions of services outside this model.", "media_or_form": [ "rule catalogue", "structured record set" ], "serial": false, "identity_strategy": "Each rule is keyed by the authoritative master-system rule identifier issued by the register owner and expressed as a governed IRI in the adopting Dimension namespace; a UUID is used only where the master system issues no identifier.", "source_refs": [ "SRC-018", "SRC-020", "SRC-028" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-evid-b-provenance", "name": "Assertion provenance, responsibility and time", "description": "Everything needed to say who stands behind an alias assertion, on what authority, out of which source systems, derived from what earlier assertion, and at which distinct points in time.", "rationale": "PROV establishes that responsibility for an entity is expressed through attribution to typed agents with qualified roles, and that derivation and primary source are first-class. SSSOM shows that mapping consumers cannot calibrate trust without author, creator, reviewer, source version and date. A same-as claim without an attributable asserter and a resolvable source binding cannot be audited, disputed or reproduced.", "source_refs": [ "SRC-009", "SRC-032", "SRC-034", "SRC-035", "SRC-008" ], "layers": [ { "id": "als-evid-l-actor-authority", "name": "Responsible actors and authority basis", "description": "The distinct agent roles attached to one equivalence assertion and the mandate under which an authoritative assertion is made.", "source_refs": [ "SRC-009", "SRC-034", "SRC-038" ], "findings": [ { "id": "als-evid-f-actor-roles", "name": "Distinct actor roles and authority mandate on one assertion", "description": "An alias assertion carries several separable responsibilities that are routinely collapsed in practice: the claimant or asserter that states the equivalence, the responsible authority accountable for it, the publisher that releases it, the reviewer of record who inspected it and the approving actor who authorised it. Each is a reference to an agent in an external registry, typed as person, organization or software agent, and each may be absent. The finding also carries the mandate or instrument giving an authority the standing to assert equivalence and the scope of that mandate, which is what makes an assertion authoritative rather than merely confident.", "source_refs": [ "SRC-009", "SRC-034", "SRC-035", "SRC-038" ], "questions": [ { "id": "als-evid-q-asserter-who", "text": "Which agent asserted this equivalence, and is that agent a person, an organization or a software agent?", "kind": "identity", "answer_data": [ "Resolvable agent reference in an external party registry", "Agent type code aligned to PROV Person, Organization or SoftwareAgent", "Origin marker distinguishing automated, manual and mixed assertion" ] }, { "id": "als-evid-q-authority-mandate", "text": "Under what mandate or instrument does the responsible authority have standing to declare these identifiers equivalent, and over what scope?", "kind": "authority", "answer_data": [ "Reference to the authority agent", "Citation of the mandating instrument, register designation or delegation", "Scope expression covering subject population, identifier namespaces and jurisdiction" ] }, { "id": "als-evid-q-publisher-accountable", "text": "Who published this assertion and who remains accountable for it after publication?", "kind": "ownership", "answer_data": [ "Publisher agent reference", "Accountable authority reference", "Publication channel or mapping-set reference" ] }, { "id": "als-evid-q-approval-act", "text": "Was the assertion approved by an actor distinct from the asserter, and what act recorded that approval?", "kind": "decision", "answer_data": [ "Approver agent reference", "Reference to the approval activity or decision record", "Boolean indicating separation of asserter and approver" ] }, { "id": "als-evid-q-role-attribution", "text": "How is each role attributed so that a consumer can resolve the agent without ambiguity?", "kind": "provenance", "answer_data": [ "Qualified attribution structure naming agent and role", "Persistent agent identifier such as an organisational register key or researcher identifier", "Statement of which roles were left unrecorded and why" ] } ], "data_elements": [ { "id": "als-evid-d-asserter-ref", "name": "Asserter reference", "description": "Reference to the agent that states the equivalence assertion.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-034" ] }, { "id": "als-evid-d-asserter-kind", "name": "Asserter agent kind", "description": "Code distinguishing a person, an organization and a software agent, aligned to PROV agent subtypes.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-evid-d-origin-mode", "name": "Origin mode", "description": "Whether the assertion originated from automated processing, manual curation, or a mixed workflow.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-034", "SRC-035" ] }, { "id": "als-evid-d-authority-ref", "name": "Responsible authority reference", "description": "Reference to the agent accountable for the assertion once published.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-038" ] }, { "id": "als-evid-d-authority-basis", "name": "Authority basis", "description": "The mandate, instrument or delegation that gives the authority standing to declare equivalence.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-038" ] }, { "id": "als-evid-d-authority-scope", "name": "Authority scope", "description": "Subject population, identifier namespaces and jurisdiction over which the mandate applies.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037", "SRC-038" ] }, { "id": "als-evid-d-publisher-ref", "name": "Publisher reference", "description": "Agent that released the assertion or the mapping set containing it.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034" ] }, { "id": "als-evid-d-approver-ref", "name": "Approving actor reference", "description": "Agent that authorised publication or operational use of the assertion.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-reviewer-ref", "name": "Reviewer of record reference", "description": "Agent or agents who inspected the assertion and signed off, distinct from the asserter.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-034", "SRC-035" ] } ], "artifacts": [], "inline_only_rationale": "Actor roles are pure reference data: each role resolves to an agent held in an external party or authority registry, and the mandate is a citation rather than a document this model holds. Materialising an actor file here would duplicate the referenced registry and create a second, divergent record of agent identity." } ] }, { "id": "als-evid-l-lineage-time", "name": "Source lineage and assertion time points", "description": "The systems and prior assertions an equivalence claim came from, and the separately recorded moments at which it was observed, decided, ingested and made valid.", "source_refs": [ "SRC-032", "SRC-034", "SRC-037", "SRC-008" ], "findings": [ { "id": "als-evid-f-source-lineage", "name": "Source-system binding and derivation lineage", "description": "Each side of an equivalence assertion is bound to the source system that supplied the identifier and, where one exists, to the authoritative master-system record that governs the subject. The source version or edition matters because a mapping valid against one release of a source may be invalid against the next. The finding also records derivation from prior assertions, the primary source of a re-published claim, and the provenance container that lets provenance itself be described and attributed.", "source_refs": [ "SRC-032", "SRC-034", "SRC-037" ], "questions": [ { "id": "als-evid-q-source-binding", "text": "Which source system supplied each identifier in this assertion, and which version or edition of that source was in effect?", "kind": "identity", "answer_data": [ "Source-system reference per side", "Source version or edition label per side", "Namespace or prefix declaration used to expand each identifier" ] }, { "id": "als-evid-q-master-record", "text": "Does an authoritative master-system record govern either side, and how is it referenced rather than copied?", "kind": "provenance", "answer_data": [ "Master-record reference with issuing-system identification", "Statement that the local record dereferences rather than mirrors the master attributes", "Flag where no master system exists for that side" ] }, { "id": "als-evid-q-derivation-chain", "text": "Was this assertion derived from an earlier assertion or re-published from another mapping set, and what is its primary source?", "kind": "relationship", "answer_data": [ "References to predecessor assertions", "Primary-source reference for republished claims", "Revision relationship where the assertion supersedes an earlier version" ] }, { "id": "als-evid-q-lineage-portability", "text": "What must travel with the assertion so that lineage survives export to a different serialisation or repository?", "kind": "interoperability", "answer_data": [ "Provenance container or bundle reference grouping the assertion's provenance statements", "Minimum portable lineage element set", "Identifier expansion map required for round-tripping" ] } ], "data_elements": [ { "id": "als-evid-d-subject-source-ref", "name": "Subject-side source reference", "description": "Source system that supplied the subject identifier of the assertion.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "als-evid-d-object-source-ref", "name": "Object-side source reference", "description": "Source system that supplied the object identifier of the assertion.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "als-evid-d-source-version", "name": "Source version", "description": "Version or edition label of each bound source, recorded per side.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-034" ] }, { "id": "als-evid-d-master-record-ref", "name": "Authoritative master-record reference", "description": "Reference to the governing record in the master system for a side, where such a system exists.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037", "SRC-038" ] }, { "id": "als-evid-d-derived-from-ref", "name": "Derived-from reference", "description": "Prior assertion or mapping set from which this assertion was derived or revised.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "als-evid-d-provenance-bundle-ref", "name": "Provenance container reference", "description": "Named container grouping the provenance statements about this assertion, itself attributable.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-032" ] } ], "artifacts": [], "inline_only_rationale": "Lineage is a set of references and version labels pointing at systems and records owned elsewhere. Producing a lineage document here would copy master-system content into this model and create a stale second copy that competes with the authoritative record it points at." }, { "id": "als-evid-f-time-points", "name": "Separately recorded assertion time points", "description": "Alias assertions have several genuinely different times that are routinely conflated: the moment the compared source states were observed, the moment the equivalence decision was reached, the moment the assertion entered this store, the moment the record was created, and the interval over which the equivalence is asserted to hold. Conflating them makes it impossible to tell a stale decision from a stale ingest, or to reason about an assertion that was correct when made and wrong now. All values follow RFC 3339 with seconds and an explicit offset or Z.", "source_refs": [ "SRC-032", "SRC-034", "SRC-008" ], "questions": [ { "id": "als-evid-q-decision-observation", "text": "When was the equivalence decision reached, and when were the source states it compared actually observed?", "kind": "temporal", "answer_data": [ "Decision timestamp in RFC 3339 with seconds and explicit offset or Z", "Observation timestamp per side where source states were read at different moments", "Statement of the clock or time authority relied on" ] }, { "id": "als-evid-q-ingestion-separate", "text": "When did this assertion enter the current store, and how is that kept distinct from when it was decided?", "kind": "provenance", "answer_data": [ "Ingestion timestamp", "Record creation timestamp", "Rule that ingestion time is never substituted for decision time when the two differ" ] }, { "id": "als-evid-q-validity-window", "text": "Over what interval is the equivalence asserted to hold, and what happens outside that interval?", "kind": "lifecycle", "answer_data": [ "Validity interval start and end", "Open-ended marker where no end is asserted", "Behaviour for queries outside the interval, expressed as a declared assumption" ] }, { "id": "als-evid-q-time-conformance", "text": "How is a timestamp with an unknown local offset represented without silently claiming UTC preference?", "kind": "validation", "answer_data": [ "Use of the -00:00 offset form for a known UTC instant with unknown local offset", "Rejection rule for timestamps lacking seconds or an offset", "Conformance check applied at ingestion" ] } ], "data_elements": [ { "id": "als-evid-d-decision-time", "name": "Decision time", "description": "Instant at which the equivalence decision was reached by the asserting agent or method.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-034", "SRC-008" ] }, { "id": "als-evid-d-observation-time", "name": "Observation time", "description": "Instant at which the compared source record states were read, recorded per side when they differ.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-032", "SRC-008" ] }, { "id": "als-evid-d-ingestion-time", "name": "Ingestion time", "description": "Instant at which the assertion entered the current store.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "als-evid-d-record-created-time", "name": "Record creation time", "description": "Instant at which this alias-assertion record was created.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-008" ] }, { "id": "als-evid-d-validity-interval", "name": "Asserted validity interval", "description": "Interval over which the equivalence is asserted to hold, with an open-ended end permitted.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "als-evid-d-time-authority", "name": "Time authority", "description": "Clock, service or agent relied on for the recorded instants.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "Time points are scalar values attached directly to the assertion record. There is no document, media object or serialised deliverable to identify separately, and creating one would fragment values that must be read atomically with the assertion." } ] } ] }, { "id": "als-evid-b-method", "name": "Match method, score and calibrated confidence", "description": "The recorded specification of how an equivalence was reached and how much weight its confidence deserves, sufficient for an independent party to reproduce the decision without this model containing the matching engine.", "rationale": "Fellegi and Sunter define linkage as a decision rule over likelihood ratios with two thresholds and an explicit possible-link region at stipulated error bounds; Statistics Canada operationalises that into standardization, blocking, comparison rules, thresholds and quality assessment; SSSOM shows the metadata that must accompany a mapping for the decision to be interpretable. Reproduction requires the method identity, configuration, features and thresholds to be recorded as data, not inferred from a running system.", "source_refs": [ "SRC-034", "SRC-036", "SRC-037", "SRC-040" ], "layers": [ { "id": "als-evid-l-method-reproducibility", "name": "Reproducible method specification", "description": "Identity and version of the method that produced the assertion, and the feature, normalization and candidate-generation configuration it ran with.", "source_refs": [ "SRC-034", "SRC-036", "SRC-037" ], "findings": [ { "id": "als-evid-f-method-identity", "name": "Method identity, justification category, tool version and configuration digest", "description": "Every assertion names the method that produced it, classified by justification category such as manual curation, lexical matching, logical inference or composite matching, and identified by tool name and exact version. Where the method is a deterministic rule set, the exact rule expression or a resolvable reference to it is carried, and rules that are local heuristics rather than governed standard methods are labelled as such. A configuration digest binds the assertion to the precise parameter set used, which is what makes the decision reproducible rather than merely describable.", "source_refs": [ "SRC-034", "SRC-035", "SRC-037" ], "questions": [ { "id": "als-evid-q-method-which", "text": "Which method produced this assertion, and what tool and exact version executed it?", "kind": "identity", "answer_data": [ "Method reference resolvable to a specification", "Tool name and immutable version string", "Configuration digest binding the assertion to a parameter set" ] }, { "id": "als-evid-q-justification-class", "text": "What category of justification underlies the assertion: manual curation, lexical or structural matching, logical inference, or composite?", "kind": "classification", "answer_data": [ "Justification category code drawn from a governed mapping-justification vocabulary", "Statement of unspecified justification where the category is genuinely unknown", "Composite decomposition where several justifications combine" ] }, { "id": "als-evid-q-rule-exactness", "text": "For a deterministic method, what is the exact rule expression applied, and is it a governed standard method or a local heuristic?", "kind": "requirement", "answer_data": [ "Rule expression text or resolvable curation-rule reference", "Flag distinguishing governed method from local heuristic", "Order of rule passes where a hierarchical deterministic strategy is used" ] }, { "id": "als-evid-q-reproduce-without-engine", "text": "What must be recorded so an independent party can reproduce the decision without access to the original matching engine?", "kind": "validation", "answer_data": [ "Method specification artifact and its version tag", "Configuration snapshot and its content digest", "Explicit list of runtime dependencies referenced but not held by this model" ] } ], "data_elements": [ { "id": "als-evid-d-method-ref", "name": "Method reference", "description": "Resolvable reference to the match, curation or inference method that produced the assertion.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "als-evid-d-justification-code", "name": "Mapping justification code", "description": "Governed category describing the kind of justification, such as manual curation, lexical matching or logical inference.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-034", "SRC-035" ] }, { "id": "als-evid-d-tool-name", "name": "Matching tool name", "description": "Name of the tool or pipeline that executed the method.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034" ] }, { "id": "als-evid-d-tool-version", "name": "Matching tool version", "description": "Immutable version string of the executing tool.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034" ] }, { "id": "als-evid-d-config-digest", "name": "Configuration digest", "description": "Content digest of the serialized parameter set in effect for the decision.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-rule-expression-ref", "name": "Rule expression reference", "description": "Exact deterministic rule text or a resolvable curation-rule reference.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-037" ] }, { "id": "als-evid-d-local-heuristic-flag", "name": "Local heuristic flag", "description": "Marks a rule that is a locally invented heuristic rather than a governed standard method.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-035" ] } ], "artifacts": [ { "id": "als-evid-a-method-spec", "name": "Match method specification", "description": "The versioned human- and machine-readable description of the method: its decision logic, parameter meanings, assumptions and known limitations, referenced by every assertion the method produced.", "media_or_form": [ "versioned specification document in PDF, HTML or Markdown", "machine-readable rule or pipeline definition" ], "serial": false, "identity_strategy": "Method identifier issued by the owning method registry or repository, combined with an immutable version tag; where no registry exists, a ULID assigned by the adopting Dimension and permanently bound to the specification content digest.", "source_refs": [ "SRC-034", "SRC-037" ] }, { "id": "als-evid-a-config-snapshot", "name": "Method configuration snapshot", "description": "The exact serialized parameter set, feature weights, threshold values and environment manifest used for one execution of the method, retained so a decision can be re-derived.", "media_or_form": [ "serialized parameter set", "environment or container manifest" ], "serial": true, "identity_strategy": "Content digest of the serialized configuration as the primary key, accompanied by a monotonically increasing run sequence number scoped to the method identifier; no date component is used in the identifier.", "source_refs": [ "SRC-037" ] } ], "inline_only_rationale": null }, { "id": "als-evid-f-feature-normalization", "name": "Feature inventory, normalization, comparison functions and candidate generation", "description": "What the method actually compared, how each field was standardised before comparison, which comparison function and parameters were applied per field, and which blocking or indexing keys generated the candidate set. Blocking is decisive because a pair never generated as a candidate can never be linked, so a missing blocking record makes false negatives uninterpretable. This finding also records whether features were held in cleartext, hashed or privacy-preserving encoded form, and which attributes were deliberately excluded and why.", "source_refs": [ "SRC-036", "SRC-037", "SRC-040" ], "questions": [ { "id": "als-evid-q-feature-inventory", "text": "Which fields were used as comparison features, and which available fields were deliberately excluded?", "kind": "composition", "answer_data": [ "Ordered inventory of comparison fields with source path per side", "Excluded-field list with a recorded reason for each exclusion", "Discriminating power or agreement weight recorded per field where estimated" ] }, { "id": "als-evid-q-normalization-steps", "text": "What normalization or standardization was applied to each field before comparison, and in what order?", "kind": "process", "answer_data": [ "Ordered preprocessing step list per field", "Comparison function and parameters per field", "Handling rule for missing and partially populated values" ] }, { "id": "als-evid-q-blocking-strategy", "text": "How was the candidate pair set generated, and what pairs could the blocking strategy never produce?", "kind": "constraint", "answer_data": [ "Blocking or indexing keys and pass order", "Declared coverage limitation of the blocking strategy", "Estimated recall loss attributable to blocking where measured" ] }, { "id": "als-evid-q-privacy-features", "text": "Were features compared in cleartext, hashed or privacy-preserving encoded form, and what does that choice cost in interpretability?", "kind": "privacy", "answer_data": [ "Feature representation code covering cleartext, hashed and encoded forms", "Encoding parameter reference where a privacy-preserving representation is used", "Statement of reduced explainability under encoded comparison" ] }, { "id": "als-evid-q-feature-quality", "text": "What was the assessed quality of each linkage variable in the sources, and how did that constrain the method?", "kind": "quality", "answer_data": [ "Per-field completeness and discordance assessment", "Note on fields whose recording quality varies across subgroups", "Method adjustments made in response to poor field quality" ] } ], "data_elements": [ { "id": "als-evid-d-feature-inventory", "name": "Comparison feature inventory", "description": "Ordered list of fields compared, with the source path for each side.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-036", "SRC-037" ] }, { "id": "als-evid-d-normalization-step", "name": "Normalization step", "description": "Ordered preprocessing operation applied to a field before comparison.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-comparison-function", "name": "Comparison function", "description": "Comparator and its parameters applied to a field pair, including agreement and disagreement handling.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-036", "SRC-037" ] }, { "id": "als-evid-d-blocking-key", "name": "Blocking key", "description": "Key or index used to generate candidate pairs, with its pass order.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-feature-representation", "name": "Feature representation", "description": "Whether features were compared in cleartext, hashed or privacy-preserving encoded form.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-excluded-feature", "name": "Excluded feature", "description": "Attribute deliberately withheld from comparison, with the recorded reason.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037", "SRC-040" ] } ], "artifacts": [], "inline_only_rationale": "The feature and normalization configuration is structured data that must be queryable per field and per assertion; it is bound by digest to the method configuration snapshot already declared under method identity. Emitting a second document here would duplicate that snapshot and risk the two diverging." } ] }, { "id": "als-evid-l-confidence-calibration", "name": "Score, calibration and the meaning of strength", "description": "The numeric or ordinal strength attached to an assertion, the evidence that the number means what it claims, and the rules that stop a score from being read as semantics or as authority.", "source_refs": [ "SRC-003", "SRC-001", "SRC-033", "SRC-036", "SRC-039", "SRC-040" ], "findings": [ { "id": "als-evid-f-score-threshold", "name": "Score, scale, thresholds and decision region", "description": "A confidence value is uninterpretable without its scale and the thresholds it was compared against. Fellegi-Sunter weights are unbounded log-likelihood ratios, SSSOM confidence is a bounded zero-to-one value and FHIR assurance is a four-point ordinal scale; these are not interchangeable. The decision region records whether the pair fell in the link, possible-link or non-link band, which preserves the possible-link outcome instead of forcing a binary answer. An explanation, such as per-field weight contributions or a rule trace, makes the outcome inspectable.", "source_refs": [ "SRC-034", "SRC-036", "SRC-039" ], "questions": [ { "id": "als-evid-q-score-scale", "text": "What is the score value and on which scale is it expressed, so it is not compared against an incompatible scale?", "kind": "measurement", "answer_data": [ "Score value", "Scale code covering bounded probability, unbounded likelihood weight and ordinal assurance level", "Scale bounds and direction where applicable" ] }, { "id": "als-evid-q-threshold-region", "text": "Which upper and lower thresholds were in force, and in which decision region did the pair fall?", "kind": "decision", "answer_data": [ "Upper and lower threshold values with their scale", "Decision region code covering link, possible link and non-link", "Reference to the threshold-setting decision and who set it" ] }, { "id": "als-evid-q-score-explanation", "text": "What per-feature contributions or rule trace explain how this score arose?", "kind": "evidence", "answer_data": [ "Per-field weight or agreement contribution list", "Rule trace for deterministic methods", "Statement where the method is not decomposable into per-feature contributions" ] }, { "id": "als-evid-q-possible-link-handling", "text": "What state does a pair in the possible-link band hold before any clerical review resolves it?", "kind": "state", "answer_data": [ "Undetermined state marker distinct from rejected", "Queue or escalation reference for pending resolution", "Rule prohibiting silent promotion of a possible link to a link" ] } ], "data_elements": [ { "id": "als-evid-d-score-value", "name": "Score value", "description": "Numeric strength reported by the referenced method for this pair.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-036" ] }, { "id": "als-evid-d-score-scale", "name": "Score scale", "description": "Scale on which the score is expressed, including its bounds and direction.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-036", "SRC-039" ] }, { "id": "als-evid-d-threshold-upper", "name": "Upper threshold", "description": "Threshold at or above which the method declares a link.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-036" ] }, { "id": "als-evid-d-threshold-lower", "name": "Lower threshold", "description": "Threshold at or below which the method declares a non-link.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-036" ] }, { "id": "als-evid-d-decision-region", "name": "Decision region", "description": "Band the pair fell into: link, possible link or non-link.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-036", "SRC-037" ] }, { "id": "als-evid-d-score-explanation", "name": "Score explanation", "description": "Per-feature contributions or rule trace supporting the reported score.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-035", "SRC-036" ] } ], "artifacts": [], "inline_only_rationale": "Score, scale, thresholds and region are scalar values that must be read atomically with the assertion and compared across assertions in queries. They carry no media form of their own, and the reproducible configuration behind them is already held as the method configuration snapshot artifact." }, { "id": "als-evid-f-calibration-evaluation", "name": "Calibration, evaluation results, subgroup performance and cost asymmetry", "description": "A score deserves weight only insofar as it has been evaluated. This finding attaches evaluation evidence to the method or mapping set rather than inventing it per pair: the gold-standard or training reference used, estimated false-positive and false-negative rates with precision and recall, whether scores are calibrated probabilities or merely monotone rankings, performance disaggregated by subgroup to expose differential linkage error, and the declared relative cost of a false positive against a false negative that justifies where thresholds sit.", "source_refs": [ "SRC-033", "SRC-037", "SRC-040" ], "questions": [ { "id": "als-evid-q-calibration-claim", "text": "Are the reported scores calibrated probabilities, or only a monotone ranking that must not be read as a probability?", "kind": "quality", "answer_data": [ "Calibration statement with the calibration method used", "Reference to the calibration measurement", "Explicit non-calibration declaration where none was performed" ] }, { "id": "als-evid-q-error-rates", "text": "What false-positive and false-negative rates were estimated for this method, and against what reference?", "kind": "measurement", "answer_data": [ "False-positive and false-negative rate estimates with uncertainty intervals", "Precision, recall or sensitivity and positive predictive value", "Gold-standard or training-data reference and its representativeness caveat" ] }, { "id": "als-evid-q-evaluation-method", "text": "How was linkage quality evaluated where no representative gold standard was available?", "kind": "validation", "answer_data": [ "Comparison of linked against unlinked records using standardized differences", "Sensitivity analysis across thresholds or alternative algorithms", "External validation by confrontation with an independent source" ] }, { "id": "als-evid-q-subgroup-performance", "text": "Does linkage error differ across identifiable subgroups, and how is that disparity reported?", "kind": "evidence", "answer_data": [ "Performance metrics disaggregated by subgroup", "Statement of which subgroup attributes were available for disaggregation and which were not", "Declared limitation where subgroup evaluation was not possible" ] }, { "id": "als-evid-q-cost-asymmetry", "text": "What relative cost of a false positive against a false negative was assumed when the thresholds were placed?", "kind": "exception", "answer_data": [ "Declared cost asymmetry statement", "Consequence description for each error type in the adopting use case", "Reference to the actor who accepted the residual error rates" ] } ], "data_elements": [ { "id": "als-evid-d-evaluation-ref", "name": "Evaluation reference", "description": "Reference to an evaluation run whose results qualify this method or mapping set.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-033", "SRC-040" ] }, { "id": "als-evid-d-gold-standard-ref", "name": "Gold-standard reference", "description": "Reference to the dataset of known true match status used for validation, with its representativeness caveat.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-040" ] }, { "id": "als-evid-d-error-rate", "name": "Error-rate measurement", "description": "Estimated false-positive and false-negative rates, precision and recall, with uncertainty intervals.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037", "SRC-040" ] }, { "id": "als-evid-d-subgroup-result", "name": "Subgroup performance result", "description": "Linkage-quality metrics disaggregated by subgroup to expose differential error.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-040" ] }, { "id": "als-evid-d-calibration-statement", "name": "Calibration statement", "description": "Whether scores are calibrated probabilities, and by what method, or explicitly uncalibrated.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-033", "SRC-040" ] }, { "id": "als-evid-d-cost-asymmetry", "name": "Declared cost asymmetry", "description": "Stated relative cost of a false positive against a false negative for the adopting use case.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037", "SRC-040" ] } ], "artifacts": [ { "id": "als-evid-a-evaluation-report", "name": "Linkage quality evaluation report", "description": "The report of one evaluation of a method or mapping set: reference data used, metrics obtained, disaggregated subgroup results, sensitivity analyses, limitations and the residual error accepted.", "media_or_form": [ "report document", "tabular metric set", "structured quality-measurement record" ], "serial": true, "identity_strategy": "Evaluation-run identifier issued by the evaluating organisation's system of record where one exists; otherwise a ULID assigned by the adopting Dimension, scoped to the method identifier and the evaluation reference dataset, with no date component in the identifier.", "source_refs": [ "SRC-033", "SRC-037", "SRC-040" ] } ], "inline_only_rationale": null }, { "id": "als-evid-f-strength-separation", "name": "Separation of statistical confidence, relation semantics and authority", "description": "Three independent axes are habitually collapsed and must be kept apart. The relation predicate carries formal semantics: an exact-match predicate is transitive and a same-individual axiom licenses full substitution, while a close-match predicate is deliberately non-transitive precisely to stop compound errors accumulating across schemes. Statistical confidence is a property of a method's output. Authority-derived assurance is a property of who asserted it. A score of 0.99 does not license substitution; an authoritative registry assertion carries no statistical error estimate; and a negative assertion of non-identity is a first-class claim rather than the absence of a positive one.", "source_refs": [ "SRC-003", "SRC-001", "SRC-034", "SRC-038", "SRC-039" ], "questions": [ { "id": "als-evid-q-predicate-semantics", "text": "Which formal predicate is asserted, and does that predicate license transitive closure or full substitution?", "kind": "definition", "answer_data": [ "Relation predicate identifier from a governed vocabulary", "Transitivity and symmetry properties of the chosen predicate", "Substitution licence flag indicating whether downstream inference may replace one identifier with the other" ] }, { "id": "als-evid-q-strength-axes", "text": "How are statistical confidence, semantic strength and authority-derived assurance recorded so that none can be derived from another?", "kind": "classification", "answer_data": [ "Semantic strength code separate from the score field", "Authority-derived assurance level separate from both", "Rule prohibiting derivation of one axis from another" ] }, { "id": "als-evid-q-authority-not-certainty", "text": "When an authority asserts equivalence without a method, what does that imply and not imply about error probability?", "kind": "authority", "answer_data": [ "Assurance level recorded with no implied score", "Explicit statement that no error estimate exists for authority-only assertions", "Reference to the mandate under which the assertion was made" ] }, { "id": "als-evid-q-negative-assertion", "text": "How is an explicit assertion that two identifiers are not the same represented, distinctly from an unproven or absent link?", "kind": "relationship", "answer_data": [ "Negation modifier applied to the predicate", "Distinct different-individuals style assertion", "Separation of asserted non-identity from undetermined and from unassessed" ] } ], "data_elements": [ { "id": "als-evid-d-relation-predicate", "name": "Relation predicate", "description": "The formal predicate asserted between the two identifiers, drawn from a governed relation vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-001", "SRC-034" ] }, { "id": "als-evid-d-semantic-strength", "name": "Semantic strength", "description": "Declared strength of the relation: substitutable equivalence, scheme-local close match, related, or asserted non-identity.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "als-evid-d-assurance-level", "name": "Authority-derived assurance level", "description": "Ordinal assurance in the asserted identity's accuracy derived from evidence and authority, recorded independently of any score.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-038", "SRC-039" ] }, { "id": "als-evid-d-substitution-permitted", "name": "Substitution licence", "description": "Whether downstream systems may substitute one identifier for the other in inference or query.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "als-evid-d-projection-constraint", "name": "Projection constraint", "description": "Constraint on projecting this assertion onto a transitive or substitution-licensing predicate during export.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-001", "SRC-035" ] } ], "artifacts": [], "inline_only_rationale": "These are typed classification values and constraint statements evaluated at query and export time. They exist only as attributes of the assertion, have no independent media form, and any document restating them would duplicate the governed relation vocabularies this model aligns to rather than owns." } ] } ] }, { "id": "als-evid-b-evidence-adjudication", "name": "Evidence, contradiction and adjudication", "description": "The cited evidence for and against an equivalence, its integrity and freshness, the human review that resolved it, and the handling of competing authorities and genuinely undetermined cases.", "rationale": "Identity proofing rests on graded evidence that must be recorded together with the resolution decision. Statistics Canada builds clerical review into the linkage process, and Fellegi-Sunter reserves an explicit possible-link outcome rather than forcing a choice. SSSOM records reviewer sign-off precisely because a tool-proposed mapping and a human-confirmed mapping warrant different trust. None of this is available if evidence is unattributed, undated or silently overwritten.", "source_refs": [ "SRC-032", "SRC-034", "SRC-036", "SRC-037", "SRC-038" ], "layers": [ { "id": "als-evid-l-evidence-corpus", "name": "Evidence items and their integrity over time", "description": "What was cited for or against the equivalence, how it is identified and verified, and how its currency, retraction and absence are handled.", "source_refs": [ "SRC-032", "SRC-037", "SRC-038" ], "findings": [ { "id": "als-evid-f-evidence-items", "name": "Positive, negative and contradictory evidence items with citation and integrity", "description": "Evidence is registered as discrete items rather than folded into a narrative, each with polarity (supporting, refuting or ambiguous), a resolvable citation or locator, a content digest so tampering or substitution is detectable, a graded strength, a sensitivity classification identifying special-category or restricted identifiers, and the jurisdiction the evidence originated in. Contradictory items are retained side by side; the model does not resolve them by discarding one.", "source_refs": [ "SRC-032", "SRC-037", "SRC-038" ], "questions": [ { "id": "als-evid-q-evidence-polarity", "text": "Which items support the equivalence, which refute it, and which are ambiguous?", "kind": "evidence", "answer_data": [ "Evidence item references with polarity code", "Retention rule keeping refuting items alongside supporting ones", "Note where the same item supports one interpretation and refutes another" ] }, { "id": "als-evid-q-evidence-strength", "text": "How strong is each evidence item, and on what graded scale is that strength expressed?", "kind": "classification", "answer_data": [ "Graded evidence strength code with its scale definition", "Basis for the grade, such as issuing authority and verification performed", "Distinction between validating the evidence and verifying it belongs to the subject" ] }, { "id": "als-evid-q-evidence-integrity", "text": "How is each cited item identified and verified so that substitution or alteration is detectable?", "kind": "security", "answer_data": [ "Resolvable citation or locator", "Content digest with the algorithm named", "Digest stub retained where the item itself may not be stored" ] }, { "id": "als-evid-q-evidence-sensitivity", "text": "Which cited items contain sensitive or special-category identifiers, and from which jurisdiction did they originate?", "kind": "privacy", "answer_data": [ "Sensitivity classification per item", "Jurisdiction of origin code", "Reference to the policy model that decides permitted reuse, which this model does not evaluate" ] }, { "id": "als-evid-q-evidence-access", "text": "Who may read a given evidence item, and how is the assertion still usable when an item is not readable to a consumer?", "kind": "access", "answer_data": [ "Access classification per item referencing an external policy", "Redacted projection exposing polarity and strength without content", "Statement that access enforcement is performed by the referenced policy model" ] } ], "data_elements": [ { "id": "als-evid-d-evidence-item-ref", "name": "Evidence item reference", "description": "Reference to a discrete item cited in relation to the equivalence.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-032", "SRC-038" ] }, { "id": "als-evid-d-evidence-polarity", "name": "Evidence polarity", "description": "Whether an item supports, refutes or is ambiguous with respect to the equivalence.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-evidence-citation", "name": "Evidence citation", "description": "Resolvable citation or locator for the item as held by its owning system.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "als-evid-d-evidence-digest", "name": "Evidence digest", "description": "Content digest of the item, with the algorithm named, enabling integrity verification.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-038" ] }, { "id": "als-evid-d-evidence-strength", "name": "Evidence strength", "description": "Graded strength of the item on a declared scale, with the basis for the grade.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-038", "SRC-039" ] }, { "id": "als-evid-d-evidence-sensitivity", "name": "Evidence sensitivity classification", "description": "Classification identifying special-category or otherwise restricted content in the item.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-evidence-jurisdiction", "name": "Evidence jurisdiction of origin", "description": "Jurisdiction under which the item was created or released, recorded for the policy model to evaluate.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] } ], "artifacts": [ { "id": "als-evid-a-evidence-exhibit", "name": "Retained evidence exhibit", "description": "The retained copy, extract or verifiable digest stub of one cited evidence item, held so that a later reviewer can inspect what the original asserter actually saw.", "media_or_form": [ "document copy or extract", "image or scan", "structured record excerpt", "digest stub where the item itself must not be retained" ], "serial": true, "identity_strategy": "Authoritative source-system identifier of the evidence document where the issuing system provides one; otherwise the content digest of the retained exhibit; a ULID assigned by the adopting Dimension is used only when neither is available.", "source_refs": [ "SRC-037", "SRC-038" ] } ], "inline_only_rationale": null }, { "id": "als-evid-f-evidence-freshness", "name": "Evidence currency, retraction and declared absence", "description": "Evidence decays. An item that justified an equivalence three source-releases ago may since have been superseded, corrected or withdrawn by its issuer, and an equivalence may have rested on evidence that was never available at all. This finding records the instant each item speaks to, the freshness window beyond which it should not be relied on unreviewed, retraction and supersession pointers, an explicit declaration of evidence that is missing or was sought and not found, and the point at which the assertion is due for revalidation.", "source_refs": [ "SRC-032", "SRC-037", "SRC-008" ], "questions": [ { "id": "als-evid-q-evidence-asof", "text": "What instant does each evidence item speak to, as distinct from when it was cited?", "kind": "temporal", "answer_data": [ "As-of instant per item in RFC 3339 with seconds and explicit offset or Z", "Citation instant recorded separately", "Note where the as-of instant is unknown rather than assumed" ] }, { "id": "als-evid-q-freshness-window", "text": "Beyond what age should an evidence item no longer be relied on without re-checking?", "kind": "quality", "answer_data": [ "Freshness window expressed as a duration per evidence class", "Revalidation due point for the assertion", "Consequence of an expired window, expressed as a state change rather than an enforcement action" ] }, { "id": "als-evid-q-retraction", "text": "How is an item recorded once its issuer has corrected, superseded or withdrawn it?", "kind": "state", "answer_data": [ "Retraction reference with the retracting agent", "Supersession pointer to the replacement item", "Rule that the retracted item is marked and retained, never deleted in place" ] }, { "id": "als-evid-q-absent-evidence", "text": "What evidence was expected but missing, and how is a deliberate absence distinguished from a silent gap?", "kind": "retention", "answer_data": [ "Declared absent-evidence note with the reason", "Distinction between not sought, sought and unavailable, and withheld under policy", "Effect of the declared absence on the recorded confidence" ] } ], "data_elements": [ { "id": "als-evid-d-evidence-asof-time", "name": "Evidence as-of instant", "description": "Instant the evidence item speaks to, distinct from when it was cited.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "als-evid-d-freshness-window", "name": "Freshness window", "description": "Duration beyond which the item should not be relied on without re-checking.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-retraction-ref", "name": "Retraction reference", "description": "Reference to a correction, supersession or withdrawal issued by the evidence owner.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "als-evid-d-absent-evidence-note", "name": "Absent-evidence note", "description": "Declaration of evidence that was expected but not obtained, with the reason and its effect on confidence.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037", "SRC-040" ] }, { "id": "als-evid-d-revalidation-due", "name": "Revalidation due point", "description": "Point at which the assertion is scheduled for evidence revalidation.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] } ], "artifacts": [], "inline_only_rationale": "Freshness, retraction and absence are temporal and status attributes of evidence items whose content already lives in the retained exhibit artifact. Holding a separate document would split one item's status from its content and invite the two to disagree." } ] }, { "id": "als-evid-l-review-disagreement", "name": "Review, disagreement and undetermined state", "description": "How human judgement is recorded, how competing assertions from different authorities coexist, and how the model refuses to invent a winner.", "source_refs": [ "SRC-001", "SRC-034", "SRC-036", "SRC-037" ], "findings": [ { "id": "als-evid-f-review-adjudication", "name": "Human review, adjudication outcome and reason", "description": "Clerical review is a defined part of linkage, not an afterthought, and reviewer sign-off is what separates a tool proposal from a curated assertion. This finding records why a pair reached review at all (a possible-link band, a random quality sample, an external challenge), who reviewed it and whether they were independent of the asserter, what outcome they reached (confirmed, rejected, amended or deferred) and the reason given. A deferred outcome is preserved rather than converted into a rejection.", "source_refs": [ "SRC-034", "SRC-035", "SRC-036", "SRC-037" ], "questions": [ { "id": "als-evid-q-review-trigger", "text": "Why did this pair enter human review rather than being accepted or rejected automatically?", "kind": "process", "answer_data": [ "Review trigger code covering possible-link band, quality sample, escalation and external challenge", "Reference to the sampling or escalation rule applied", "Volume context showing what proportion of comparable pairs were reviewed" ] }, { "id": "als-evid-q-review-outcome", "text": "What outcome did the reviewer reach, and what reason was recorded for it?", "kind": "decision", "answer_data": [ "Outcome code covering confirmed, rejected, amended and deferred", "Free-text or coded reason", "Amended predicate or amended confidence where the outcome changed the assertion" ] }, { "id": "als-evid-q-review-event", "text": "When did the review occur and what activity record ties the outcome to the reviewer?", "kind": "event", "answer_data": [ "Review instant in RFC 3339 with seconds and explicit offset or Z", "Reference to the review activity and its qualified association with the reviewer", "Adjudication record reference" ] }, { "id": "als-evid-q-review-independence", "text": "Was the reviewer independent of the asserter, and who owns the adjudication outcome once recorded?", "kind": "ownership", "answer_data": [ "Independence flag comparing reviewer against asserter and approver", "Owning authority for the adjudication outcome", "Statement that the outcome is content of this model while any proof-of-access log belongs to the referenced audit model" ] } ], "data_elements": [ { "id": "als-evid-d-review-ref", "name": "Review activity reference", "description": "Reference to the review activity and its association with the reviewing agent.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-034" ] }, { "id": "als-evid-d-adjudication-outcome", "name": "Adjudication outcome", "description": "Outcome reached by the reviewer: confirmed, rejected, amended or deferred.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-036", "SRC-037" ] }, { "id": "als-evid-d-adjudication-reason", "name": "Adjudication reason", "description": "Recorded reason supporting the adjudication outcome.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "als-evid-d-review-trigger", "name": "Review trigger", "description": "Basis on which the pair was routed to human review.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-036", "SRC-037" ] }, { "id": "als-evid-d-reviewer-independence", "name": "Reviewer independence flag", "description": "Whether the reviewer is distinct from the asserter and the approving actor.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] } ], "artifacts": [ { "id": "als-evid-a-adjudication-record", "name": "Adjudication record", "description": "The durable record of one review decision on one assertion: reviewer, trigger, evidence consulted, outcome, reason and any amendment made, retained so the decision can be re-examined by a later reviewer or an external challenger.", "media_or_form": [ "structured decision record", "signed or countersigned reviewer note" ], "serial": true, "identity_strategy": "Case identifier issued by the adjudicating authority's review system where one exists; otherwise a ULID assigned by the adopting Dimension, scoped to the assertion identifier with a monotonically increasing review sequence number and no date component.", "source_refs": [ "SRC-034", "SRC-037" ] } ], "inline_only_rationale": null }, { "id": "als-evid-f-disagreement-state", "name": "Competing assertions, confidence revision and the undetermined state", "description": "Two authorities can assert incompatible things about the same pair, and a probabilistic method can land in a band where no decision is warranted. The model represents disagreement as a state over a set of coexisting assertions rather than as a single mutated record: each competing assertion keeps its own asserter, authority, method and evidence; a confidence revision adds a new statement and marks the prior one superseded rather than overwriting it; and undetermined is a first-class terminal-for-now state distinct from rejected and from unassessed. Selection of an operative assertion, where a consumer needs one, is a downstream decision recorded with its own attribution, not an inference this model performs.", "source_refs": [ "SRC-032", "SRC-003", "SRC-001", "SRC-036" ], "questions": [ { "id": "als-evid-q-competing-assertions", "text": "How are two incompatible assertions about the same pair held together without either being discarded?", "kind": "state", "answer_data": [ "References to each competing assertion with its own attribution and method", "Disagreement state code covering agreed, disputed and undetermined", "Rule prohibiting deletion or in-place edit of a competing assertion" ] }, { "id": "als-evid-q-confidence-revision", "text": "When confidence changes, how is the prior confidence statement preserved rather than overwritten?", "kind": "lifecycle", "answer_data": [ "New confidence statement with its own decision instant and method reference", "Supersession pointer from the new statement to the prior one", "Immutability rule for superseded statements" ] }, { "id": "als-evid-q-undetermined-meaning", "text": "What does an undetermined state assert, and how does it differ from rejected and from never assessed?", "kind": "exception", "answer_data": [ "Undetermined state definition with the recorded reason for no decision", "Distinction from asserted non-identity and from an unassessed pair", "Conditions under which the state may be revisited" ] }, { "id": "als-evid-q-no-silent-winner", "text": "Who selects an operative assertion for downstream use, and how is that selection kept out of the evidence record?", "kind": "ownership", "answer_data": [ "Reference to the consuming system or policy model that performs selection", "Attribution of the selection decision to its own actor and instant", "Statement that this model records but never performs the selection" ] }, { "id": "als-evid-q-disagreement-export", "text": "How is a disputed or undetermined pair exported to a vocabulary that has no way to express disagreement?", "kind": "interoperability", "answer_data": [ "Export rule suppressing disputed pairs from transitive or substitution-licensing predicates", "Downgrade rule to a non-transitive close-match style predicate where suppression is not acceptable", "Warning annotation carried alongside the exported statement" ] } ], "data_elements": [ { "id": "als-evid-d-competing-assertion-ref", "name": "Competing assertion reference", "description": "Reference to another assertion about the same pair that conflicts with this one.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-032", "SRC-001" ] }, { "id": "als-evid-d-disagreement-state", "name": "Disagreement state", "description": "State over the set of assertions about a pair: agreed, disputed or undetermined.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-036" ] }, { "id": "als-evid-d-confidence-revision-ref", "name": "Confidence revision reference", "description": "Pointer from a new confidence statement to the prior statement it supersedes, which remains immutable.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "als-evid-d-supersession-ref", "name": "Supersession reference", "description": "Pointer recording that this assertion has been superseded by a later one, without removal.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "als-evid-d-nondecision-reason", "name": "No-decision reason", "description": "Recorded reason why no equivalence decision was reached for this pair.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-036", "SRC-037" ] } ], "artifacts": [], "inline_only_rationale": "Disagreement is a computed relationship over assertion records that already exist, expressed as state codes and cross-references. Materialising a dispute document would create a fourth account of the pair competing with the assertions it summarises, and would need its own reconciliation the moment any member assertion changed." } ] } ] }, { "id": "als-prop-formal-semantics", "name": "Declared formal relation semantics", "description": "What each alias relation kind actually asserts: its owning specification, its semantic class, its declared algebraic properties, its applicability and its cardinality force. Covers the catalogue of kinds, the strength ordering between them, symmetry and inversion, composition and transitivity, and domain/range and cardinality declarations.", "rationale": "Alias edges are routinely treated as one uniform symmetric-transitive relation. The cited specifications contradict that: owl:sameAs licenses substitution of identicals, skos:exactMatch is transitive while skos:closeMatch is deliberately not, broadMatch and narrowMatch form an inverse pair, dcterms:isReplacedBy is directional succession, HTTP permanent redirect is relocation of a resource, and schema.org sameAs declares no algebra at all. A defensible model must declare properties per kind rather than assume them.", "source_refs": [ "SRC-001", "SRC-019", "SRC-003", "SRC-043", "SRC-025", "SRC-026", "SRC-023" ], "layers": [ { "id": "als-prop-layer-kind-catalogue", "name": "Relation-kind catalogue and semantic strength", "description": "Governed catalogue of the relation predicates an alias edge may name, each with the semantics its owning specification actually licenses, and the partial order of strength that governs how an incoming assertion may be re-expressed locally.", "source_refs": [ "SRC-001", "SRC-003", "SRC-025", "SRC-026", "SRC-023", "SRC-034" ], "findings": [ { "id": "als-prop-find-kind-profile", "name": "Relation-kind semantic profile", "description": "Every alias edge names exactly one governed predicate, and each predicate carries a normative profile taken from its owning specification. The profile records the semantic class actually asserted: referential identity of individuals (owl:sameAs, licensing substitution), class co-extension (owl:equivalentClass, not individual identity), graded cross-scheme equivalence (skos:exactMatch, skos:closeMatch), cross-scheme hierarchy (skos:broadMatch, skos:narrowMatch), cross-scheme association (skos:relatedMatch), documentary succession (dcterms:replaces, dcterms:isReplacedBy), resolution-level relocation (HTTP 301/308), reference-page identity indication with no declared entailment (schema.org sameAs), and statistical linkage results carrying a score rather than an axiom. The profile also records which entailments are licensed and which are commonly assumed but not licensed.", "source_refs": [ "SRC-001", "SRC-019", "SRC-003", "SRC-025", "SRC-026", "SRC-023", "SRC-047" ], "questions": [ { "id": "als-prop-q-kind-predicate", "text": "Which single governed relation predicate does this alias edge assert, and which specification and version owns its meaning?", "kind": "definition", "answer_data": [ "Predicate IRI", "Owning specification reference", "Specification version or publication date" ] }, { "id": "als-prop-q-kind-semantic-class", "text": "Does the asserted predicate claim referential identity, class co-extension, graded equivalence, cross-scheme hierarchy, documentary succession, resolution-level relocation, or a statistical link?", "kind": "classification", "answer_data": [ "Semantic class code", "Citation of the clause that fixes the class", "Whether substitution of identicals is licensed" ] }, { "id": "als-prop-q-kind-authority", "text": "Which body governs this predicate's normative semantics and may change them without the adopting Dimension's consent?", "kind": "authority", "answer_data": [ "Governing organisation identifier", "Change-notification channel reference", "Local review obligation on external version change" ] }, { "id": "als-prop-q-kind-entailments", "text": "Which entailments does the owning specification actually license for this predicate, and which are widely assumed but unlicensed?", "kind": "interoperability", "answer_data": [ "Licensed entailment list", "Explicitly unlicensed or disclaimed entailment list", "Known misuse notes with source citation" ] } ], "data_elements": [ { "id": "als-prop-de-predicate-iri", "name": "Predicate IRI", "description": "Resolvable IRI of the relation predicate as minted by its owning specification, or by the adopting Dimension for a local kind.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-025" ] }, { "id": "als-prop-de-semantic-class", "name": "Semantic class code", "description": "Coded semantic class of the predicate: identity, co-extension, graded-equivalence, hierarchical, associative, succession, relocation, reference-indication or statistical-link.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-026", "SRC-023" ] }, { "id": "als-prop-de-owning-spec-ref", "name": "Owning specification reference", "description": "Reference to the specification document and clause that fixes the predicate's semantics, with the version or publication date in force.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-041", "SRC-003", "SRC-046" ] }, { "id": "als-prop-de-licensed-entailments", "name": "Licensed entailment set", "description": "Enumerated entailments the owning specification licenses for the predicate, each with its clause citation.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-003" ] }, { "id": "als-prop-de-disclaimed-entailments", "name": "Disclaimed entailment note", "description": "Entailments commonly assumed for this predicate that the owning specification does not license, recorded to prevent silent over-reading.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-043", "SRC-025", "SRC-030" ] } ], "artifacts": [ { "id": "als-prop-art-kind-profile", "name": "Relation-kind semantic profile record", "description": "A durable record of one relation kind: its predicate IRI, semantic class, owning specification and version, declared algebraic properties, applicability, cardinality force, licensed and disclaimed entailments, and deprecation state. It is descriptive of an external specification and confers no conformance claim.", "media_or_form": [ "structured record", "catalogue table row", "vocabulary annotation projection" ], "serial": false, "identity_strategy": "Identified by the predicate IRI minted by the owning standards body where one exists; for a Dimension-local kind, by a resolvable IRI in a Dimension-controlled namespace; failing both, by a ULID marked as locally minted. Version or publication date of the owning specification is a qualifier, never the identifier.", "source_refs": [ "SRC-001", "SRC-003", "SRC-025", "SRC-026" ] } ], "inline_only_rationale": null }, { "id": "als-prop-find-strength-preservation", "name": "Strength ordering and preservation on carriage", "description": "The catalogue is partially ordered by asserted strength, and carriage of an external assertion must preserve the strongest semantics actually asserted and no stronger. Concretely: a schema.org sameAs value or a probabilistic linkage result must not be re-encoded as owl:sameAs; skos:closeMatch must not be promoted to skos:exactMatch; an HTTP 308 relocation or a dcterms:isReplacedBy succession must not be read as identity of the described thing; and a high confidence value never licenses promotion. Some pairs are incomparable rather than ordered (for example associative relatedness versus documentary succession), and unrepresentable incoming kinds are recorded as lossy with a justification instead of being approximated upward.", "source_refs": [ "SRC-003", "SRC-043", "SRC-025", "SRC-023", "SRC-012", "SRC-030", "SRC-047" ], "questions": [ { "id": "als-prop-q-strength-source", "text": "What is the strongest relation kind the originating authority actually asserted for this edge, as opposed to what a consumer inferred?", "kind": "evidence", "answer_data": [ "Source-asserted predicate IRI", "Source record or payload reference", "Extraction method note" ] }, { "id": "als-prop-q-strength-reencoding", "text": "Is re-encoding the incoming kind into a different local kind permitted here, and what justification must be recorded?", "kind": "decision", "answer_data": [ "Re-encoding permitted flag", "Target local kind", "Recorded justification text", "Deciding role" ] }, { "id": "als-prop-q-strength-prohibited", "text": "Which promotions between kinds are prohibited outright regardless of any confidence value?", "kind": "constraint", "answer_data": [ "Prohibited ordered kind pairs", "Prohibition rationale with source citation" ] }, { "id": "als-prop-q-strength-lossy", "text": "What must be recorded when an incoming assertion cannot be expressed in the local catalogue without loss of meaning?", "kind": "requirement", "answer_data": [ "Lossy-encoding flag", "Retained original predicate IRI verbatim", "Description of what was lost", "Escalation target" ] } ], "data_elements": [ { "id": "als-prop-de-source-kind", "name": "Source-asserted kind", "description": "The predicate IRI exactly as asserted by the originating system, retained verbatim even when a different local kind is used.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-034", "SRC-012" ] }, { "id": "als-prop-de-strength-relation", "name": "Strength relation code", "description": "Relation of the local kind to the source kind in the declared partial order: equal, weaker, stronger or incomparable. A value of stronger is invalid for carriage.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-025", "SRC-030" ] }, { "id": "als-prop-de-lossy-flag", "name": "Lossy encoding flag", "description": "Indicates that the local catalogue cannot express the incoming semantics exactly, requiring a recorded description of the loss.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "als-prop-de-reencoding-justification", "name": "Re-encoding justification", "description": "Free-text justification and deciding role for any change of predicate between the source assertion and the stored assertion.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "The strength ordering is declared reference data over kinds that are already carried by the relation-kind semantic profile record, and the per-edge preservation outcome is a small set of typed fields on the alias assertion itself. Minting a separate ordering document would duplicate the profile records, create a second place where an external specification version change must be reflected, and invite drift between the ordering and the profiles it orders. Recording the ordering inline on the profiles and the outcome inline on the assertion keeps a single authoritative statement per kind." } ] }, { "id": "als-prop-layer-algebraic-properties", "name": "Declared algebraic and structural properties", "description": "Per-kind declarations of symmetry and inversion, composition and transitivity, reflexivity, and applicability and cardinality force — each stated only where the owning specification actually asserts it, with the axiomatic force of the assertion recorded.", "source_refs": [ "SRC-001", "SRC-019", "SRC-042", "SRC-003", "SRC-043", "SRC-026", "SRC-034" ], "findings": [ { "id": "als-prop-find-symmetry-inversion", "name": "Symmetry, inversion and reflexivity declarations", "description": "Each kind declares, separately and with axiomatic force noted, whether it is symmetric, asymmetric or neither; whether it has a declared inverse predicate and whether the inverse edge may be materialised; and whether a self-edge is permitted, required or prohibited. SKOS declares relatedMatch, closeMatch and exactMatch symmetric and narrowMatch the inverse of broadMatch; owl:sameAs is symmetric and reflexive as equality; dcterms:replaces and isReplacedBy are a documentary inverse pair without an OWL axiom; HTTP relocation is directional; schema.org sameAs declares no inverse. Where the source records only one direction, the reverse must not be reported as asserted unless symmetry is declared for that kind.", "source_refs": [ "SRC-001", "SRC-019", "SRC-041", "SRC-003", "SRC-025", "SRC-026", "SRC-023" ], "questions": [ { "id": "als-prop-q-symmetry-declared", "text": "Is this kind declared symmetric, asymmetric, or neither by its owning specification, and with what axiomatic force?", "kind": "relationship", "answer_data": [ "Symmetry declaration code", "Axiomatic force code covering formal axiom, documentary statement or undeclared", "Clause citation" ] }, { "id": "als-prop-q-inverse-pairing", "text": "Does this kind have a declared inverse predicate, and must the inverse edge be materialised or left implicit?", "kind": "relationship", "answer_data": [ "Inverse predicate IRI", "Inverse materialisation policy code", "Whether the inverse pairing is an OWL axiom or a documentary convention" ] }, { "id": "als-prop-q-reflexivity", "text": "Is a self-edge, where subject and object identifiers are the same, permitted, required or prohibited for this kind?", "kind": "constraint", "answer_data": [ "Reflexivity declaration code", "Handling rule for a submitted self-edge", "Clause citation" ] }, { "id": "als-prop-q-direction-asserted", "text": "When the originating record captures only one direction, may the reverse direction be reported as asserted rather than derived?", "kind": "validation", "answer_data": [ "Direction asserted code", "Derivation permitted flag", "Required annotation when a direction is derived rather than asserted" ] } ], "data_elements": [ { "id": "als-prop-de-symmetry-declaration", "name": "Symmetry declaration", "description": "Coded declaration of symmetric, asymmetric or undeclared for the kind, with the axiomatic force of the declaration.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "als-prop-de-inverse-predicate", "name": "Inverse predicate reference", "description": "IRI of the declared inverse predicate where one exists, together with whether the pairing is an OWL inverse axiom or a documentary convention.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-026" ] }, { "id": "als-prop-de-reflexivity-declaration", "name": "Reflexivity declaration", "description": "Coded declaration of reflexive, irreflexive or undeclared for the kind, governing whether self-edges are accepted.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-041" ] }, { "id": "als-prop-de-direction-asserted", "name": "Direction asserted", "description": "Records whether the stored direction is the one the originating authority asserted, or a direction obtained under a declared symmetry or inverse rule.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-034" ] } ], "artifacts": [], "inline_only_rationale": "Symmetry, inverse pairing and reflexivity are three enumerated declarations attached to the relation-kind semantic profile plus one direction field on each assertion. They have no independent existence, no separate lifecycle and no separate authority from the kind whose semantics they describe. Splitting them into their own artifact would fragment a single normative profile across records that must always be read together, and would create the possibility of a profile whose declared algebra disagrees with itself." }, { "id": "als-prop-find-composition-rules", "name": "Composition, transitivity and path admissibility", "description": "Whether an edge A to B of kind K1 and an edge B to C of kind K2 yield anything about A to C is decided by a declared composition rule for the ordered kind pair, not assumed. owl:sameAs and skos:exactMatch are declared transitive; skos:closeMatch is deliberately not, so similarity does not propagate across schemes; mixed pairs yield at most the weaker kind, and many yield nothing. OWL property chain axioms are the formal device for stating such compositions. A result may never exceed the weakest link in the supplied sequence, and a formally composable chain is still inadmissible when adjacent edges are context-incompatible. Closure computation and path discovery are performed elsewhere; this model states the rule and evaluates it over a caller-supplied sequence.", "source_refs": [ "SRC-001", "SRC-019", "SRC-042", "SRC-003", "SRC-043", "SRC-012", "SRC-030" ], "questions": [ { "id": "als-prop-q-composition-result", "text": "For this ordered pair of declared kinds, what result kind, if any, does the declared composition rule yield?", "kind": "composition", "answer_data": [ "Left kind IRI", "Right kind IRI", "Result kind IRI or explicit none", "Rule citation" ] }, { "id": "als-prop-q-composition-noncomposable", "text": "Which ordered kind pairs are declared non-composable, so that no result may be reported at all?", "kind": "constraint", "answer_data": [ "Non-composable ordered pairs", "Reason code", "Source clause establishing the absence of transitivity" ] }, { "id": "als-prop-q-composition-weakest-link", "text": "How does the weakest link in a supplied edge sequence bound the strength of any reported result?", "kind": "validation", "answer_data": [ "Weakest-link kind in the sequence", "Bounded result kind", "Bound violation code when a caller requests a stronger result" ] }, { "id": "als-prop-q-composition-inadmissible", "text": "Under what conditions is a formally composable chain still inadmissible because of context, conditionality or a negated edge?", "kind": "exception", "answer_data": [ "Inadmissibility reason code", "Identifier of the offending edge in the sequence", "Context incompatibility reference" ] }, { "id": "als-prop-q-composition-owner", "text": "Which component discovers paths and computes closure, and what does this model provide in its place?", "kind": "process", "answer_data": [ "External closure or reasoner reference", "Entailment regime or profile parameter carried locally", "Statement of the locally provided rule-evaluation output" ] } ], "data_elements": [ { "id": "als-prop-de-left-kind", "name": "Left kind of the ordered pair", "description": "Predicate IRI of the first edge in the ordered pair the composition rule governs.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "als-prop-de-right-kind", "name": "Right kind of the ordered pair", "description": "Predicate IRI of the second edge in the ordered pair the composition rule governs.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "als-prop-de-result-kind", "name": "Composed result kind", "description": "Predicate IRI of the strongest kind the rule licenses for the composed pair, absent when the pair is non-composable.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-003" ] }, { "id": "als-prop-de-composable-flag", "name": "Composable flag", "description": "Boolean stating whether the ordered pair composes at all under the declared rule set.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-043" ] }, { "id": "als-prop-de-closure-owner-ref", "name": "External closure owner reference", "description": "Reference to the external reasoner, entailment regime or closure service responsible for materialising inferences, with the profile or regime parameter carried locally.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-045" ] } ], "artifacts": [ { "id": "als-prop-art-composition-rule", "name": "Declared relation composition rule record", "description": "A durable record stating, for one ordered pair of relation kinds, whether composition is licensed, what the strongest licensed result kind is, the bounding weakest-link rule, and the source clause supporting or denying transitivity. It is a declaration consumed by external evaluators; it does not itself compute or store closure.", "media_or_form": [ "structured record", "rule table row", "OWL property-chain axiom projection" ], "serial": false, "identity_strategy": "Identified by the authoritative rule identifier assigned by the owning rule set where one exists; otherwise by a governed IRI formed in a Dimension-controlled namespace from the ordered pair of predicate IRIs; failing both, by a ULID marked as locally minted.", "source_refs": [ "SRC-001", "SRC-042", "SRC-003", "SRC-043" ] } ], "inline_only_rationale": null }, { "id": "als-prop-find-applicability-cardinality", "name": "Applicability, functionality and cardinality force", "description": "Each kind declares which node kinds may occupy subject and object position, and what force any cardinality statement carries. OWL 2 DL restricts SameIndividual to individuals and equivalentClass to classes, so asserting identity between classes changes the reasoning regime; SKOS mapping properties relate concepts, which is why merging concepts with owl:sameAs conflicts with SKOS label constraints; schema.org sameAs takes a URL value on a Thing; relocation relations hold between resolvable locators, not between the things they describe. Separately, a mapping cardinality value such as one-to-one is descriptive metadata about an observed mapping set, whereas FunctionalProperty, InverseFunctionalProperty and HasKey are axioms — and HasKey applies only to explicitly named individuals. Declaring a mapping one-to-one therefore entails nothing.", "source_refs": [ "SRC-001", "SRC-019", "SRC-042", "SRC-003", "SRC-043", "SRC-025", "SRC-023", "SRC-034" ], "questions": [ { "id": "als-prop-q-applicability-nodes", "text": "Which node kinds may occupy the subject and object positions for this relation kind?", "kind": "constraint", "answer_data": [ "Permitted subject node kind codes", "Permitted object node kind codes", "Clause citation for the restriction" ] }, { "id": "als-prop-q-cardinality-force", "text": "Is the recorded cardinality descriptive metadata about an observed mapping set or an enforced axiom, and which specification gives it that force?", "kind": "requirement", "answer_data": [ "Cardinality force code", "Axiom reference where the force is axiomatic", "Statement of what the value does and does not entail" ] }, { "id": "als-prop-q-cardinality-observed", "text": "What cardinality is actually observed for this mapping set, and over which subject and object sources and versions was it measured?", "kind": "measurement", "answer_data": [ "Observed cardinality code", "Subject source and version", "Object source and version", "Measurement scope note" ] }, { "id": "als-prop-q-applicability-referent", "text": "Is each endpoint a real-world entity, a concept in a scheme, a document, or a resolvable locator, and does the kind respect that distinction?", "kind": "identity", "answer_data": [ "Subject referent type code", "Object referent type code", "Referent mismatch violation code where the kind is inapplicable" ] } ], "data_elements": [ { "id": "als-prop-de-subject-node-kind", "name": "Permitted subject node kind", "description": "Coded node kind allowed in subject position for the relation kind, such as individual, class, concept, document or locator.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-025" ] }, { "id": "als-prop-de-object-node-kind", "name": "Permitted object node kind", "description": "Coded node kind allowed in object position for the relation kind, including the case where only a resolvable URL is permitted.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-025" ] }, { "id": "als-prop-de-declared-cardinality", "name": "Declared mapping cardinality", "description": "Coded cardinality of the mapping such as one-to-one, one-to-many, many-to-one, many-to-many or a zero-sided value, recorded as descriptive metadata.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-012" ] }, { "id": "als-prop-de-cardinality-force", "name": "Cardinality force", "description": "Whether the cardinality statement is descriptive, or is backed by a functional, inverse-functional or key axiom, with the axiom reference.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-042", "SRC-034" ] }, { "id": "als-prop-de-referent-type", "name": "Endpoint referent type", "description": "Coded referent type for each endpoint distinguishing entity, concept, document and resolvable locator, used to detect inapplicable kinds.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-023", "SRC-030" ] } ], "artifacts": [], "inline_only_rationale": "Applicability and cardinality force are typed fields that belong to the relation-kind semantic profile, and observed cardinality is a measured attribute of an assertion set that changes whenever a source version changes. None of them has an independent owner, retention class or audience. Holding them inline keeps the declaration in one place with the specification version it was derived from, and avoids a second record that could contradict the owning specification after an external version change." } ] } ] }, { "id": "als-prop-contextual-validity", "name": "Contextual validity, warrant and conflict reporting", "description": "The conditions under which a declared equivalence actually holds, the warrant that supports it, and the reporting of contradictions and exposure. Covers context and temporal scoping, context incompatibility and controlled strength change, justification and confidence, and explicit non-equivalence constraints with contagion-exposure indicators.", "rationale": "Identity assertions in federated settings are rarely unconditional. The cited literature shows that owl:sameAs is one point on a similarity scale and that referentially opaque contexts exist where substitution must not be applied; mapping standards require justification, confidence and source versions to be explicit precisely because imprecision is the normal case. Because equality licenses substitution, one false strong assertion propagates, so declared non-equivalence and exposure reporting are structural requirements rather than optional metadata.", "source_refs": [ "SRC-019", "SRC-003", "SRC-002", "SRC-009", "SRC-045", "SRC-034", "SRC-012", "SRC-030", "SRC-047" ], "layers": [ { "id": "als-prop-layer-context-scope", "name": "Context, time and controlled strength change", "description": "How an assertion is bound to a Dimension, jurisdiction, purpose, source versions and effective interval; when two contexts are incompatible; and how strength or scope may be changed only by an authorised, evidenced superseding assertion.", "source_refs": [ "SRC-002", "SRC-026", "SRC-008", "SRC-034", "SRC-030" ], "findings": [ { "id": "als-prop-find-context-binding", "name": "Context and temporal binding of an assertion", "description": "An alias assertion is bound to the context in which it is claimed to hold: the adopting Dimension, an optional jurisdiction or territorial scope, one or more purposes of use, the subject-source and object-source versions in force, and an effective interval expressed with explicit offsets. Assertion time, the interval over which the equivalence is claimed to hold, and the time this model observed or ingested the assertion are recorded separately. An assertion submitted without a declared context is stored as scope-unknown and must never be read as globally valid, which follows from the absence of a unique name assumption and the open-world reading of the underlying data: silence is not a claim of universality.", "source_refs": [ "SRC-044", "SRC-002", "SRC-026", "SRC-008", "SRC-034", "SRC-030" ], "questions": [ { "id": "als-prop-q-context-interval", "text": "Over which effective interval is this equivalence asserted to hold, expressed with seconds and an explicit offset?", "kind": "temporal", "answer_data": [ "Effective from instant", "Effective to instant or open-ended marker", "Assertion instant", "Observation or ingestion instant" ] }, { "id": "als-prop-q-context-jurisdiction", "text": "Which jurisdiction or territorial scope conditions this assertion, and is that scope exclusive?", "kind": "spatial", "answer_data": [ "Jurisdiction code", "Scope exclusivity flag", "Authority that fixed the jurisdictional scope" ] }, { "id": "als-prop-q-context-ownership", "text": "Which Dimension and which purposes does the assertion serve, and who owns the binding?", "kind": "ownership", "answer_data": [ "Dimension reference", "Purpose codes", "Binding owner role and contact reference" ] }, { "id": "als-prop-q-context-source-version", "text": "Which subject-source and object-source versions were in force when the assertion was made?", "kind": "provenance", "answer_data": [ "Subject source identifier and version", "Object source identifier and version", "Version-in-force determination method" ] }, { "id": "als-prop-q-context-default", "text": "How is an assertion interpreted when no context at all is declared?", "kind": "definition", "answer_data": [ "Scope-unknown marker", "Default interpretation statement", "Consumer obligation on encountering scope-unknown" ] } ], "data_elements": [ { "id": "als-prop-de-dimension-ref", "name": "Adopting Dimension reference", "description": "Reference to the Dimension within which the assertion is claimed to hold and which owns the context binding.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "als-prop-de-jurisdiction-code", "name": "Jurisdiction or territorial scope code", "description": "Coded jurisdiction conditioning the assertion, supplied by the adopting Dimension; absent where the assertion is not jurisdictionally conditioned.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-026", "SRC-030" ] }, { "id": "als-prop-de-purpose-code", "name": "Purpose of use code", "description": "Coded purpose or application context for which the equivalence is asserted to be adequate.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-043", "SRC-012" ] }, { "id": "als-prop-de-effective-interval", "name": "Effective interval", "description": "Start and optional end instants over which the equivalence is asserted to hold, each an RFC 3339 date-time with seconds and an explicit offset.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-026", "SRC-008" ] }, { "id": "als-prop-de-asserted-at", "name": "Assertion instant", "description": "Event time at which the asserting agent made the claim, distinct from the interval over which the claim holds.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-008" ] }, { "id": "als-prop-de-observed-at", "name": "Observation or ingestion instant", "description": "Time at which this model observed or ingested the assertion, recorded separately from the assertion instant and always retained when the two differ.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-008" ] }, { "id": "als-prop-de-scope-declared", "name": "Scope declared flag", "description": "Boolean indicating whether any context attribute was declared; false marks the assertion scope-unknown rather than global.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-044", "SRC-030" ] } ], "artifacts": [ { "id": "als-prop-art-context-binding", "name": "Alias assertion context binding record", "description": "A durable record binding one alias assertion to its Dimension, jurisdiction, purposes, subject and object source versions and effective interval, with assertion time and observation time held separately. It states the conditions of the claim; it does not evaluate whether the conditions currently obtain.", "media_or_form": [ "structured record", "named-graph annotation projection", "statement-reifier annotation projection" ], "serial": false, "identity_strategy": "Identified by the authoritative assertion identifier assigned by the originating mapping system of record; where none exists, by a governed IRI or reifier IRI minted in a Dimension-controlled namespace; failing both, by a ULID assigned by the adopting Dimension. The effective interval and source versions are qualifiers and are never used as the identifier.", "source_refs": [ "SRC-002", "SRC-026", "SRC-008", "SRC-034" ] } ], "inline_only_rationale": null }, { "id": "als-prop-find-context-incompatibility", "name": "Context incompatibility and controlled strength change", "description": "Two assertions are context-incompatible when their declared scopes cannot both apply: disjoint jurisdictions, mutually exclusive purposes, non-overlapping effective intervals, or subject and object source versions that are not co-valid. Incompatible edges must not be composed and must not be treated as corroborating one another; a declared scope compared against a scope-unknown assertion is reported as undetermined, never as compatible. Strength or scope may change only through a superseding assertion carrying an authority reference, a reason and a new effective interval — never by silent mutation. Weakening and strengthening carry different evidence bars, since strengthening enlarges what may be substituted while weakening only reduces it.", "source_refs": [ "SRC-003", "SRC-043", "SRC-026", "SRC-034", "SRC-012", "SRC-030" ], "questions": [ { "id": "als-prop-q-incompat-attributes", "text": "Which declared scope attributes make two assertions incompatible rather than merely different?", "kind": "constraint", "answer_data": [ "Incompatibility code set", "Comparison rule per scope attribute", "Undetermined outcome rule for scope-unknown comparisons" ] }, { "id": "als-prop-q-incompat-state", "text": "What state does an assertion enter when its effective interval has ended or its source version has been superseded?", "kind": "state", "answer_data": [ "Assertion state code", "Trigger that caused the state change", "Whether the assertion remains readable and to whom" ] }, { "id": "als-prop-q-incompat-authority", "text": "Who is authorised to weaken or strengthen a declared edge, and what evidence bar applies to strengthening?", "kind": "authority", "answer_data": [ "Authorised role reference", "Evidence bar description per change direction", "Authority reference recorded on the change" ] }, { "id": "als-prop-q-incompat-supersession", "text": "How is a superseding assertion linked to the assertion it replaces without deleting the original?", "kind": "lifecycle", "answer_data": [ "Superseded assertion reference", "Superseding assertion reference", "Retention treatment of the superseded record" ] }, { "id": "als-prop-q-incompat-chain", "text": "Which chains become inadmissible once one link is context-incompatible with the next?", "kind": "exception", "answer_data": [ "Offending adjacent edge pair", "Incompatibility code", "Reported chain outcome of inadmissible" ] } ], "data_elements": [ { "id": "als-prop-de-incompatibility-code", "name": "Context incompatibility code", "description": "Coded reason two context bindings cannot both apply, such as disjoint jurisdiction, exclusive purpose, non-overlapping interval or non-co-valid source versions.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-034", "SRC-030" ] }, { "id": "als-prop-de-change-direction", "name": "Strength change direction", "description": "Coded direction of a superseding change: weakened, strengthened, scope narrowed, scope widened or retracted.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-026" ] }, { "id": "als-prop-de-change-authority-ref", "name": "Change authority reference", "description": "Reference to the role or body that authorised the strength or scope change, together with the evidence bar applied.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-034" ] }, { "id": "als-prop-de-superseded-ref", "name": "Superseded assertion reference", "description": "Reference from the superseding assertion to the assertion it replaces, mirroring documentary replaces and isReplacedBy semantics.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-026" ] }, { "id": "als-prop-de-assertion-state", "name": "Assertion state code", "description": "Coded state of the assertion: active, expired, superseded, retracted or deprecated, with the trigger recorded.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-041", "SRC-026" ] } ], "artifacts": [ { "id": "als-prop-art-strength-change", "name": "Strength and scope supersession record", "description": "An append-only record of one authorised change to an existing alias edge: the superseded and superseding assertion references, the change direction, the authority and reason, and the new effective interval. It records that a change was made and on whose authority; it does not enforce the change downstream and is not the audit trail of the change.", "media_or_form": [ "structured record", "append-only ledger entry", "supersession annotation projection" ], "serial": true, "identity_strategy": "Identified by the authoritative supersession identifier from the mapping system of record where one exists; otherwise by a governed IRI in a Dimension-controlled namespace combined with a monotonic sequence number for the parent assertion; failing both, by a ULID assigned by the adopting Dimension.", "source_refs": [ "SRC-009", "SRC-026", "SRC-034" ] } ], "inline_only_rationale": null } ] }, { "id": "als-prop-layer-warrant-conflict", "name": "Warrant, non-equivalence and declared-semantics reporting", "description": "The evidential basis reported for each assertion, and the declared negative constraints, invalid combinations and exposure indicators that make a false strong identity assertion detectable before it propagates.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-045", "SRC-034", "SRC-012", "SRC-030", "SRC-047" ], "findings": [ { "id": "als-prop-find-warrant-confidence", "name": "Justification, confidence and asserting authority", "description": "Every edge carries a justification type stating how the mapping was arrived at — human curation, lexical or string similarity, logical derivation, or unspecified — plus the asserting agent and the activity or tool that generated it, with a generation time. Confidence, where present, is a value on a declared scale whose meaning and estimation method must be stated: a probabilistic linkage posterior derived from a statistical model with its own error rates and assumptions is not the same quantity as a curator's subjective degree of belief. Absence of confidence is recorded as unknown and never defaulted to certainty, and no confidence value ever changes the relation kind.", "source_refs": [ "SRC-009", "SRC-034", "SRC-012", "SRC-030", "SRC-047" ], "questions": [ { "id": "als-prop-q-warrant-agent", "text": "Which agent asserted this edge, under what activity or tool, and at what generation time?", "kind": "provenance", "answer_data": [ "Asserting agent reference", "Activity or tool reference with version", "Generation instant" ] }, { "id": "als-prop-q-warrant-justification", "text": "What justification type supports this assertion, and was it human-curated, lexical, logically derived or unspecified?", "kind": "evidence", "answer_data": [ "Justification type code", "Supporting evidence reference", "Review state and reviewer reference" ] }, { "id": "als-prop-q-warrant-confidence-meaning", "text": "What does the recorded confidence value mean, on what scale, and by which estimation method was it produced?", "kind": "measurement", "answer_data": [ "Confidence value", "Scale and range declaration", "Estimation method identifier", "Known error-rate or assumption caveats" ] }, { "id": "als-prop-q-warrant-unknown", "text": "How is the absence of any confidence estimate represented so that it cannot be read as certainty?", "kind": "quality", "answer_data": [ "Unknown-confidence marker", "Prohibition on defaulting to a numeric value", "Consumer handling rule for unknown confidence" ] }, { "id": "als-prop-q-warrant-access", "text": "Who may read warrant fields when the underlying matching evidence is sensitive or re-identifying?", "kind": "access", "answer_data": [ "Restricted field list", "Permitted role list", "Purpose grant reference required for restricted access" ] } ], "data_elements": [ { "id": "als-prop-de-justification-code", "name": "Mapping justification code", "description": "Coded justification for the assertion, such as manual curation, lexical match, logical derivation or unspecified.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-034", "SRC-012" ] }, { "id": "als-prop-de-confidence-value", "name": "Confidence value", "description": "Numeric confidence on a declared scale; absent rather than zero or one when no estimate exists.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-047" ] }, { "id": "als-prop-de-confidence-semantics", "name": "Confidence semantics declaration", "description": "Declaration of what the confidence quantity means, its range, and the estimation method that produced it, including model assumptions where statistical.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-047" ] }, { "id": "als-prop-de-asserting-agent-ref", "name": "Asserting agent reference", "description": "Reference to the agent, and optionally the activity or tool with version, credited with the assertion under the referenced provenance model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-034" ] }, { "id": "als-prop-de-review-state", "name": "Review state", "description": "Coded review state of the assertion, such as unreviewed, reviewed, disputed or withdrawn, with the reviewer reference where applicable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-034", "SRC-012" ] } ], "artifacts": [ { "id": "als-prop-art-warrant", "name": "Assertion warrant record", "description": "A durable record of the evidential basis for one alias assertion: justification type, confidence with its declared semantics and estimation method, asserting agent and activity references, generation time and review state. It references the provenance model rather than restating its lifecycle.", "media_or_form": [ "structured record", "qualified-attribution projection", "mapping-set table row" ], "serial": false, "identity_strategy": "Identified by the authoritative warrant or curation-record identifier from the originating mapping system where one exists; otherwise by a governed IRI in a Dimension-controlled namespace; failing both, by a ULID assigned by the adopting Dimension.", "source_refs": [ "SRC-009", "SRC-034", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "als-prop-find-negative-constraints", "name": "Non-equivalence constraints, contradiction and contagion exposure", "description": "Explicit not-same declarations are first-class: difference axioms between individuals, a negated-predicate modifier stating that a mapping does not hold, and standard disjointness such as exact match being disjoint with broad match and with related match. Against these the model reports, without enforcing: direct contradiction where identity is asserted and denied over the same pair in compatible contexts; invalid combinations such as exact match together with related match, or identity together with difference; breaches of declared applicability or cardinality; and contagion exposure — indicators of how many distinct authoritative identifiers, sources or classes a strength-of-identity edge would draw together, because equality licenses substitution and one false strong assertion propagates to everything reachable from it. Reports are derived and non-authoritative; disposition, repair and retention belong elsewhere.", "source_refs": [ "SRC-001", "SRC-019", "SRC-041", "SRC-003", "SRC-045", "SRC-034", "SRC-012", "SRC-030" ], "questions": [ { "id": "als-prop-q-negative-declared", "text": "Which not-same or disjointness constraints are declared over this pair of identifiers or over this predicate set?", "kind": "constraint", "answer_data": [ "Difference or negated-predicate declaration reference", "Disjoint predicate pairs", "Declaring authority and context binding" ] }, { "id": "als-prop-q-negative-invalid-combos", "text": "Which declared combinations are reported as invalid, and at what severity?", "kind": "validation", "answer_data": [ "Violation code", "Severity code", "Focus pair identifiers", "Source constraint reference" ] }, { "id": "als-prop-q-negative-exposure", "text": "What exposure indicators are reported for a strength-of-identity assertion before a consumer accepts it?", "kind": "measurement", "answer_data": [ "Count of distinct authoritative sources drawn together", "Count of distinct declared classes or types drawn together", "Presence of any conflicting not-same declaration", "Indicator computation scope note" ] }, { "id": "als-prop-q-negative-disposition", "text": "When a contradiction is reported, who decides the disposition and who carries it out?", "kind": "decision", "answer_data": [ "Deciding role reference", "Disposition outcome code", "Executing component reference outside this model" ] }, { "id": "als-prop-q-negative-retention", "text": "How long is a declared-semantics report kept, and which policy owns its retention and audit trail?", "kind": "retention", "answer_data": [ "Retention class reference", "Owning retention policy reference", "Audit model reference that holds the trail" ] } ], "data_elements": [ { "id": "als-prop-de-negative-declaration-ref", "name": "Non-equivalence declaration reference", "description": "Reference to an explicit not-same declaration over a pair of identifiers, or to a negated-predicate modifier stating that a mapping does not hold.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-034" ] }, { "id": "als-prop-de-violation-code", "name": "Violation code", "description": "Coded outcome of a declared-semantics check, such as identity contradicted by difference, disjoint predicates co-asserted, applicability breach or cardinality breach.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-045" ] }, { "id": "als-prop-de-severity-code", "name": "Result severity", "description": "Coded severity of a reported result, aligned to violation, warning and informational levels of the referenced validation model.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-045" ] }, { "id": "als-prop-de-exposure-indicator", "name": "Contagion exposure indicator", "description": "Quantified indicator of how many distinct authoritative sources, identifier schemes or declared classes a strength-of-identity assertion would draw together, with the scope over which it was computed.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-012", "SRC-030" ] }, { "id": "als-prop-de-evaluated-set-hash", "name": "Evaluated assertion-set digest", "description": "Digest of the exact assertion set and constraint version a report evaluated, so a report can be shown stale without re-running validation.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-prop-de-disposition-owner-ref", "name": "Disposition owner reference", "description": "Reference to the role that decides and the component that executes the disposition of a reported conflict, both outside this model's boundary.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-045", "SRC-012" ] } ], "artifacts": [ { "id": "als-prop-art-conformance-report", "name": "Declared-semantics conformance report", "description": "A derived, non-authoritative report over a named assertion set: overall conformance, individual results with focus pair, violation code, severity and source constraint reference, plus contagion exposure indicators and the digest of the evaluated set. It reports only; it applies no remediation, blocks no operation, and its persistence, retention and audit trail are owned by the referenced validation and audit models.", "media_or_form": [ "report record", "validation-report graph projection", "tabular result set" ], "serial": true, "identity_strategy": "Identified by the report identifier assigned by the executing validation service where one exists; otherwise by a governed IRI in a Dimension-controlled namespace combined with a monotonic sequence number per evaluated assertion set; failing both, by a ULID assigned by the adopting Dimension. The evaluated-set digest is a qualifier, not the identifier.", "source_refs": [ "SRC-045", "SRC-034", "SRC-030" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-graph-traversal-bundle", "name": "Alias graph structure and governed traversal", "description": "The alias graph as a first-class object — its nodes, edges, per-predicate strength profile — together with the declared policy under which the graph may be walked and the evidence record a walk produces. Covers bounds, cycles, repeated nodes, path provenance, weakest-edge reporting, contradiction markers and the boundary between reporting a path and asserting an identity.", "rationale": "Alias assertions are only useful when chained, but chaining is exactly where the semantics break: SKOS makes exactMatch transitive while deliberately refusing transitivity to closeMatch to avoid compound errors, and OWL 2 makes SameIndividual a full interchangeability claim. A governed traversal surface is therefore required, and it must be separable from the reasoning engine that would otherwise materialise conclusions. SPARQL 1.1 supplies the only widely normative statement about how arbitrary-length connectivity is to behave with respect to duplicates and cycles.", "source_refs": [ "SRC-018", "SRC-003", "SRC-048", "SRC-002" ], "layers": [ { "id": "als-graph-structure-layer", "name": "Graph structure and edge qualification", "description": "What a node and an edge are in the alias graph, how each is identified and annotated, and what each mapping predicate licenses in terms of symmetry, transitivity, strength and substitution.", "source_refs": [ "SRC-018", "SRC-003", "SRC-002", "SRC-034" ], "findings": [ { "id": "als-graph-node-edge-structure", "name": "Alias graph node and edge structure", "description": "The alias graph is a directed multigraph whose nodes are endpoint identifiers held by external systems and whose edges are the alias assertions themselves. An edge carries its own identity so that it can be annotated, cited in a path, contradicted or retracted independently of its endpoints; endpoint identity remains owned by the endpoint's system of record. Nodes are not created by this model — a node exists in the graph only because at least one edge references it.", "source_refs": [ "SRC-002", "SRC-034", "SRC-009" ], "questions": [ { "id": "als-graph-q-node-def", "text": "What constitutes a node in the alias graph, and does referencing an identifier in an edge create any claim about that identifier beyond the edge itself?", "kind": "definition", "answer_data": [ "Node definition rule: a node is an endpoint identifier appearing as subject or object of at least one recorded edge", "Statement that node presence carries no existence, validity or ownership claim about the referenced subject", "Reference to the endpoint's system of record or governing namespace" ] }, { "id": "als-graph-q-edge-identity", "text": "How is an individual alias edge identified so that it can be cited in a path, annotated or retracted without ambiguity?", "kind": "identity", "answer_data": [ "Edge identifier value and the authority that issued it", "Canonical edge tuple used for digest computation (subject IRI, predicate IRI, object IRI, predicate modifier)", "Digest algorithm identifier and the digest value", "Rule that two edges with identical tuples but different asserting authorities are distinct edges" ] }, { "id": "als-graph-q-edge-direction", "text": "Is the recorded direction of an edge semantically meaningful, or is it a storage artefact of a symmetric assertion?", "kind": "relationship", "answer_data": [ "Asserted direction flag (subject-to-object as asserted)", "Symmetry profile of the predicate, indicating whether the reverse direction is licensed without a second assertion", "Canonical ordering rule used so that a symmetric pair yields one digest" ] }, { "id": "als-graph-q-edge-annotation", "text": "What annotations may be attached to an edge, and how are they kept distinct from the edge assertion itself?", "kind": "composition", "answer_data": [ "Annotation type list (justification reference, confidence, contradiction marker, integrity result, retraction)", "Reification or edge-annotation binding used by the projection, recording that annotating a statement does not assert it", "Annotating agent reference and annotation instant" ] } ], "data_elements": [ { "id": "als-graph-de-edge-id", "name": "Alias edge identifier", "description": "Identifier of a single alias assertion, stable across annotation, contradiction and retraction.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "als-graph-de-subject-endpoint", "name": "Subject endpoint reference", "description": "Reference to the identifier appearing in the subject position of the assertion, resolved to an absolute IRI or governed identifier.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-034" ] }, { "id": "als-graph-de-object-endpoint", "name": "Object endpoint reference", "description": "Reference to the identifier appearing in the object position of the assertion.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-034" ] }, { "id": "als-graph-de-edge-direction", "name": "Asserted edge direction", "description": "Whether the stored orientation is the orientation as asserted, or a canonicalised orientation of a symmetric assertion.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "als-graph-de-edge-annotation-ref", "name": "Edge annotation reference", "description": "Reference to an annotation about the edge that does not itself assert the edge, such as a contradiction marker or integrity result.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-045" ] }, { "id": "als-graph-de-edge-digest", "name": "Canonical edge digest", "description": "Digest over the canonical edge tuple, used to detect duplicates and to bind path reports to exact edge states.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Node and edge structure is the model's own reference semantics rather than a produced deliverable. Nodes are pointers into external systems of record and edges are records already governed by the alias assertion surface of this mixin; introducing a separate 'graph document' artefact here would create a second, competing statement of edge existence and invite drift between the artefact and the asserted edges. Any concrete serialisation of the graph is a projection into a storage format, which this model is explicitly independent of." }, { "id": "als-graph-edge-strength-profile", "name": "Edge predicate strength and composition profile", "description": "Each alias edge binds a mapping predicate whose formal profile determines whether the edge is symmetric, whether it may be chained, and whether it licenses substitution of one endpoint for the other. OWL 2 SameIndividual is a full interchangeability claim; SKOS exactMatch is transitive while closeMatch is explicitly not, precisely to prevent compound error across schemes; ISO 25964-2 distinguishes exact from inexact and partial equivalence. Not-same edges are recorded in the same structure with a modifier, so that a contradiction is visible as data rather than inferred at read time.", "source_refs": [ "SRC-018", "SRC-003", "SRC-034", "SRC-049", "SRC-030" ], "questions": [ { "id": "als-graph-q-predicate-class", "text": "Which mapping predicate does this edge bind, and from which governed vocabulary is that predicate drawn?", "kind": "classification", "answer_data": [ "Predicate IRI and source vocabulary reference (OWL 2, SKOS, or a registered local vocabulary)", "Strength class assigned to the predicate (full interchangeability, exact equivalence, close or inexact equivalence, partial equivalence, related, not-same)", "Predicate modifier where the edge negates the predicate" ] }, { "id": "als-graph-q-transitivity-profile", "text": "Does this predicate permit chaining with another edge, and under what composition rule?", "kind": "constraint", "answer_data": [ "Transitivity flag and symmetry flag for the predicate", "Composition table stating which predicate pairs may be chained and what predicate the resulting path is reported under", "Explicit prohibition on chaining non-transitive predicates such as closeMatch", "Reference to the vocabulary statement that establishes the profile" ] }, { "id": "als-graph-q-notsame-edge", "text": "How is an explicit not-same assertion recorded so that it constrains rather than merely comments on the graph?", "kind": "evidence", "answer_data": [ "Not-same edge with its own identifier, authority and justification reference", "Predicate modifier or difference predicate IRI used", "Scope statement declaring which contexts the difference claim applies to", "Statement that the absence of an alias edge is not a difference claim, because no unique name assumption applies" ] }, { "id": "als-graph-q-strength-order", "text": "How are strength classes ordered, and is that order defined for predicates drawn from different vocabularies?", "kind": "interoperability", "answer_data": [ "Ordered strength lattice with each class mapped to its source vocabulary term", "Cross-vocabulary comparability statement, including any pairs declared incomparable", "Fallback rule when a predicate has no registered strength class" ] } ], "data_elements": [ { "id": "als-graph-de-predicate-ref", "name": "Mapping predicate reference", "description": "IRI of the predicate that the edge binds, drawn from a governed vocabulary.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-003", "SRC-034" ] }, { "id": "als-graph-de-predicate-strength-class", "name": "Predicate strength class", "description": "Position of the predicate on the registered strength lattice, from full interchangeability down to related or not-same.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-049", "SRC-030" ] }, { "id": "als-graph-de-transitivity-flag", "name": "Transitivity flag", "description": "Whether the predicate is declared transitive by its defining vocabulary and may therefore be chained with itself.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "als-graph-de-symmetry-flag", "name": "Symmetry flag", "description": "Whether the predicate is declared symmetric, determining whether reverse traversal is licensed without a separate assertion.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "als-graph-de-predicate-modifier", "name": "Predicate modifier", "description": "Modifier that negates or qualifies the predicate, used to record not-same edges in the same structure as same-as edges.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034" ] }, { "id": "als-graph-de-substitution-license", "name": "Substitution license", "description": "Whether and in which contexts the edge licenses substituting one endpoint for the other, recognising that some contexts are referentially opaque.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-030" ] } ], "artifacts": [], "inline_only_rationale": "The strength and composition profile is reference lookup data derived from external vocabularies that this model aligns to rather than owns. Publishing it as an artefact would present a local copy of OWL 2 and SKOS profile facts as though this model were their source; instead the profile is carried inline on each edge and on a registered predicate table whose authoritative statements resolve back to the defining vocabulary." } ] }, { "id": "als-graph-traversal-control-layer", "name": "Traversal policy and termination control", "description": "The named, versioned policy that bounds any walk of the alias graph: which predicates may be followed, in which direction, how deep, how many paths, how cycles and repeated nodes are treated, and how a run reports why it stopped.", "source_refs": [ "SRC-048", "SRC-003", "SRC-051" ], "findings": [ { "id": "als-graph-traversal-policy", "name": "Declared traversal policy, bounds and repeated-node handling", "description": "Traversal is never ad hoc: every walk executes under a named policy version that fixes the allowed predicate set, direction, maximum hop depth, maximum returned path count and result cap, and the treatment of cycles and repeated nodes. SPARQL 1.1 establishes the baseline that arbitrary-length connectivity matching does not introduce duplicates and does not count the number of ways a connection can be made, and that cycles must not lead to undefined or infinite results; this model makes those guarantees explicit and adds finite bounds so that runs are reproducible and citable. Every run reports a termination reason, distinguishing exhaustion from bound-limited truncation.", "source_refs": [ "SRC-048", "SRC-003", "SRC-051", "SRC-034" ], "questions": [ { "id": "als-graph-q-policy-authority", "text": "Who owns this traversal policy version, and what approval was required before results under it could be published?", "kind": "authority", "answer_data": [ "Policy owner reference and approving role", "Approval instant and approval record reference", "Statement of which decisions the policy is fit to support and which it is not" ] }, { "id": "als-graph-q-depth-bound", "text": "What maximum hop depth and maximum path count apply, and what happens when a walk reaches either bound?", "kind": "requirement", "answer_data": [ "Maximum depth value in hops and maximum returned path count", "Truncation behaviour and whether truncated results may be cited", "Rule that a truncated result is never reported as an exhaustive answer" ] }, { "id": "als-graph-q-cycle-rule", "text": "How are cycles and repeated nodes handled so that a walk terminates and does not report the same connection more than once?", "kind": "constraint", "answer_data": [ "Repeated-node rule (simple path only, node-visit-once, or bounded revisit)", "Duplicate-path suppression rule aligned with connectivity matching that does not count the number of ways a connection can be made", "Cycle detection outcome recorded as a diagnostic rather than an error where the cycle is legitimate under a symmetric predicate" ] }, { "id": "als-graph-q-termination-state", "text": "In what state did the traversal terminate, and can a consumer tell truncation from exhaustion?", "kind": "state", "answer_data": [ "Termination reason code (exhausted, depth bound reached, path cap reached, time budget reached, integrity stop)", "Counts of nodes visited, edges examined and paths returned", "Flag indicating whether further paths may exist beyond the bound" ] }, { "id": "als-graph-q-policy-reproducibility", "text": "What must be recorded for a traversal result to be reproducible by a different agent at a later time?", "kind": "quality", "answer_data": [ "Policy identifier and immutable version tag", "Input graph digest or snapshot reference pinning the edge set walked", "Ordering rule applied to returned paths", "Statement of any non-deterministic element and how it is bounded" ] } ], "data_elements": [ { "id": "als-graph-de-policy-id", "name": "Traversal policy identifier", "description": "Identifier of the named traversal policy under which a run executes.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-048" ] }, { "id": "als-graph-de-policy-version", "name": "Traversal policy version", "description": "Immutable version tag of the policy; any change to bounds, predicate set or repeated-node rule produces a new version.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "als-graph-de-allowed-predicate-set", "name": "Allowed predicate set", "description": "The set of predicate IRIs the walk may follow, together with the permitted direction for each.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-048" ] }, { "id": "als-graph-de-max-depth", "name": "Maximum hop depth", "description": "Upper bound on the number of edges in any returned path.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-048", "SRC-051" ] }, { "id": "als-graph-de-max-paths", "name": "Maximum returned path count", "description": "Upper bound on the number of distinct paths returned by a single run.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-048" ] }, { "id": "als-graph-de-repeated-node-rule", "name": "Repeated-node rule", "description": "Declared treatment of nodes already visited on the current path and across the run.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-048" ] }, { "id": "als-graph-de-termination-reason", "name": "Termination reason", "description": "Why the run stopped, distinguishing exhaustion from any bound-limited truncation.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-048" ] } ], "artifacts": [ { "id": "als-graph-art-traversal-policy-profile", "name": "Alias traversal policy profile", "description": "The versioned, approved declaration of allowed predicates and directions, hop and path bounds, repeated-node and cycle rules, ordering, time budget and termination semantics, against which every traversal run is executed and every path report is bound.", "media_or_form": [ "declarative policy record", "versioned configuration profile", "human-readable policy statement" ], "serial": false, "identity_strategy": "Policy identifier issued by the adopting Dimension's policy register (authoritative master system for policies), combined with an immutable version tag; a digest over the canonical policy form binds published reports to the exact bounds in force. The version tag and approval instant are qualifiers, never the identifier.", "source_refs": [ "SRC-048", "SRC-051" ] } ], "inline_only_rationale": null } ] }, { "id": "als-graph-path-evidence-layer", "name": "Path evidence and the inference boundary", "description": "What a traversal produces: an ordered, provenance-bearing path record whose reported strength is that of its weakest edge, carrying contradiction markers, and explicitly typed as candidate evidence rather than an identity assertion.", "source_refs": [ "SRC-009", "SRC-048", "SRC-018", "SRC-045" ], "findings": [ { "id": "als-graph-path-provenance-record", "name": "Path provenance and weakest-edge reporting", "description": "A returned path is a derived entity: it records the ordered list of edge identifiers traversed, the hop count, the policy version and input digest under which it was produced, the agent and activity that produced it, and its production instant. Its reported strength is the strength of its weakest edge and never higher, because a chain is only as good as its least certain link; where per-edge confidence values exist they are reported alongside, not multiplied into a single reassuring number. PROV-O supplies the derivation, attribution and generation vocabulary.", "source_refs": [ "SRC-009", "SRC-048", "SRC-034", "SRC-003" ], "questions": [ { "id": "als-graph-q-path-record", "text": "What exactly is recorded for a returned path so that a reader can re-inspect every link in it?", "kind": "provenance", "answer_data": [ "Ordered list of edge identifiers with their canonical digests", "Hop count and the endpoint pair", "Policy identifier and version, input graph digest", "References to the per-edge justifications supplied by the asserting authorities" ] }, { "id": "als-graph-q-weakest-edge", "text": "Which edge on this path is the weakest, and how is the path-level strength derived from it?", "kind": "measurement", "answer_data": [ "Reference to the weakest edge and its strength class", "Path strength class equal to the minimum edge strength on the path", "Per-edge confidence values reported individually with their source", "Explicit prohibition on any aggregation that reports a path stronger than its weakest edge" ] }, { "id": "als-graph-q-path-time", "text": "At what instant was the path produced, and over which state of the graph?", "kind": "temporal", "answer_data": [ "Traversal run instant in RFC 3339 with seconds and explicit offset", "Input graph snapshot reference or digest identifying the edge state walked", "Validity interval of each edge on the path at the run instant, where edges carry validity" ] }, { "id": "als-graph-q-path-attribution", "text": "Which agent ran this traversal and on whose behalf, and who is accountable for citing the result?", "kind": "ownership", "answer_data": [ "Traversing agent reference and, where distinct, the requesting principal reference", "Audit record reference issued by the referenced audit model", "Named accountable role for downstream citation of the report" ] } ], "data_elements": [ { "id": "als-graph-de-path-id", "name": "Path record identifier", "description": "Identifier of a single returned path within a traversal run.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-graph-de-ordered-edge-list", "name": "Ordered edge list", "description": "The sequence of edge identifiers traversed from subject endpoint to object endpoint, in order.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-048" ] }, { "id": "als-graph-de-hop-count", "name": "Hop count", "description": "Number of edges on the path, checked against the policy maximum depth.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-048" ] }, { "id": "als-graph-de-weakest-edge-ref", "name": "Weakest edge reference", "description": "Reference to the edge on the path with the lowest strength class, which sets the path strength.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-030" ] }, { "id": "als-graph-de-path-strength", "name": "Reported path strength", "description": "Strength class of the path, equal to the minimum strength class present on it.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-049" ] }, { "id": "als-graph-de-traversal-run-instant", "name": "Traversal run instant", "description": "Observation time at which the traversal executed, distinct from the event times at which the traversed edges were asserted.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-graph-de-traversal-agent", "name": "Traversing agent reference", "description": "Reference to the agent that ran the traversal, for attribution of the derived path record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] } ], "artifacts": [ { "id": "als-graph-art-path-evidence-report", "name": "Alias path evidence report", "description": "The output record of one traversal run: the returned path set with ordered edge lists, per-path hop count and weakest-edge strength, contradiction markers, termination reason, policy binding, input digest and run provenance. Framed throughout as candidate evidence for a human or an external decision process.", "media_or_form": [ "structured evidence record", "tabular path listing", "human-readable traversal report" ], "serial": false, "identity_strategy": "Where the executing query or workflow system is the authoritative master system for run records, its run identifier is the report identifier; otherwise a governed IRI in the adopting Dimension's report namespace; otherwise a ULID minted here and recorded with the minting agent. The report also carries a digest over the ordered edge lists plus policy version; the run instant is a qualifier and is never the identifier.", "source_refs": [ "SRC-009", "SRC-048" ] } ], "inline_only_rationale": null }, { "id": "als-graph-inference-boundary", "name": "Non-materialisation rule and contradiction markers", "description": "The controlling constraint of the whole traversal surface: a path is evidence of connectivity, not an assertion of identity, and running a traversal must never write a new alias edge back into the graph. OWL 2 SameIndividual is a strong interchangeability claim and DifferentIndividuals its explicit negation, with no unique name assumption making silence informative; SHACL processing likewise does not modify the graph it reads. Where a path or a cluster spans an explicit not-same edge, or joins a pair whose predicates are disjoint under SKOS S46, the result is marked with a contradiction marker that travels with it and blocks summarisation as a confirmed equivalence.", "source_refs": [ "SRC-018", "SRC-003", "SRC-045", "SRC-030", "SRC-002" ], "questions": [ { "id": "als-graph-q-no-materialization", "text": "What prevents a traversal result from being written back as a new alias edge, and how is that state visible on the record?", "kind": "decision", "answer_data": [ "Assertion status code distinguishing asserted edges from derived candidate paths", "Explicit prohibition statement carried on every derived record", "Name of the external process authorised to convert a candidate into an assertion, and the separate justification it must supply" ] }, { "id": "als-graph-q-contradiction-marker", "text": "Which contradiction conditions raise a marker on a path or cluster, and what does a marker forbid downstream?", "kind": "exception", "answer_data": [ "Marker condition list (path spans an explicit not-same edge; disjoint predicates asserted between the same pair; equivalence asserted where a difference claim holds in the same scope)", "References to the conflicting edges that raised the marker", "Downstream prohibition: a marked result may not be reported as a confirmed equivalence and may not be used as membership evidence until resolved", "Resolution state and the authority responsible for resolving it" ] }, { "id": "als-graph-q-entailment-owner", "text": "If entailment closure over these edges is wanted, which component owns it and what does this model hand over?", "kind": "ownership", "answer_data": [ "Reference to the external reasoning or entailment service and its owning authority", "Statement that computing, storing and refreshing entailments lies outside this model", "The edge set, predicate profiles and policy bindings handed over as input", "Statement that holding this reference confers no evaluation or execution semantics here" ] }, { "id": "als-graph-q-consumer-warning", "text": "What must a consuming system be told so that it does not mistake a candidate path for an established equivalence?", "kind": "interoperability", "answer_data": [ "Mandatory fields on every exported path record: assertion status, path strength, weakest edge, termination reason, contradiction markers", "Rule that unknown or unparsed contradiction markers are treated as blocking rather than ignorable", "Statement that substitution licensing is context-dependent and not implied by connectivity" ] } ], "data_elements": [ { "id": "als-graph-de-assertion-status", "name": "Assertion status", "description": "Whether a record is an asserted edge from a named authority or a derived candidate produced by traversal.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-002" ] }, { "id": "als-graph-de-contradiction-marker", "name": "Contradiction marker", "description": "Coded marker raised where a path or cluster conflicts with an explicit difference claim or with a disjointness condition on the bound predicates.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-003" ] }, { "id": "als-graph-de-contradiction-evidence-ref", "name": "Contradiction evidence reference", "description": "References to the specific conflicting edges or assertions that caused a marker to be raised.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-045" ] }, { "id": "als-graph-de-entailment-owner-ref", "name": "Entailment owner reference", "description": "Reference to the external reasoning or entailment service that owns closure computation, carried without transferring evaluation semantics into this model.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-045", "SRC-018" ] } ], "artifacts": [], "inline_only_rationale": "This finding is a constraint and a set of flags, not a deliverable. The non-materialisation rule has to be enforced as a field on every derived record and every export, and contradiction markers must travel inline with the path or cluster they qualify; packaging them into a separate artefact would let a consumer receive a path record without its blocking marker attached, which is the exact failure the finding exists to prevent. Where a marker needs adjudication, that adjudication record belongs to the authority that resolves it, not here." } ] } ] }, { "id": "als-graph-cluster-bundle", "name": "Equivalence cluster boundary, representatives and lineage", "description": "Equivalence clusters and canonical representatives treated strictly as derived views and external decisions: how a cluster snapshot is registered with its calculation rule, version, inputs and validity; how a representative reference is carried without rewriting endpoints; how split and merge lineage preserves prior membership and prior representative decisions; and how graph pathologies are reported.", "rationale": "Transitive closure over identity links produces very large classes whose quality depends entirely on the weakest links inside them, and incorrect identity links have wide-ranging effects across a federated knowledge space. The cluster is therefore not a fact but a calculation output that must be pinned to a rule version and an input state to be citable at all, and the choice of a representative within a cluster is a preference decision no standard supplies — OWL 2 and RDF 1.2 both leave co-denoting IRIs equal in standing. PROV-O provides the derivation and revision vocabulary needed to keep the resulting lineage inspectable.", "source_refs": [ "SRC-009", "SRC-018", "SRC-002", "SRC-050", "SRC-045" ], "layers": [ { "id": "als-graph-cluster-view-layer", "name": "Derived cluster views and external representative references", "description": "Registration of externally calculated equivalence clusters as immutable, reproducible snapshots, and the carrying of canonical-representative decisions as references to an external authority's rule rather than as local identity changes.", "source_refs": [ "SRC-009", "SRC-034", "SRC-018", "SRC-008" ], "findings": [ { "id": "als-graph-cluster-derived-view", "name": "Equivalence cluster as a registered derived view", "description": "An equivalence cluster is a view computed by an external reasoning or master-data process, not a fact this model holds. It enters the model only by registration, and only with the calculation rule identifier, the rule version, a digest of the input edge state, the snapshot instant and the membership evidence for each member. Snapshots are immutable: a corrected calculation yields a new snapshot linked as a revision of the prior one. Reproducibility is a property of the record — a snapshot that cannot be regenerated from its recorded inputs and rule version is marked unreproducible and may not be cited as membership evidence.", "source_refs": [ "SRC-009", "SRC-034", "SRC-008", "SRC-050", "SRC-048" ], "questions": [ { "id": "als-graph-q-cluster-rule", "text": "Which calculation rule and rule version produced this cluster, and which authority owns that rule?", "kind": "process", "answer_data": [ "Calculation rule reference and immutable rule version", "Owning authority reference for the rule and for its change control", "Parameters supplied to the rule, including the predicate set and any strength threshold applied", "Statement that this model registers the output and does not execute the rule" ] }, { "id": "als-graph-q-cluster-snapshot-time", "text": "As of what instant does this cluster membership hold, and over what interval may it be cited?", "kind": "temporal", "answer_data": [ "Snapshot instant in RFC 3339 with seconds and explicit offset", "Registration instant recorded separately from the snapshot instant", "Validity interval or expiry after which the snapshot must be recalculated before citation", "Reference to the superseding snapshot once one exists" ] }, { "id": "als-graph-q-membership-evidence", "text": "For each member of this cluster, what evidence places it in the cluster?", "kind": "evidence", "answer_data": [ "Per-member reference to the edge set or path that connects it to the cluster", "Weakest edge strength on that connecting evidence", "Justification references carried from the underlying assertions", "Any member admitted by rule-specific criteria rather than by a recorded path, flagged as such" ] }, { "id": "als-graph-q-cluster-reproducibility", "text": "What is stored so that an independent party can regenerate this exact cluster?", "kind": "validation", "answer_data": [ "Input graph digest pinning the edge state used", "Rule identifier, rule version and full parameter set", "Snapshot digest over the sorted member list", "Reproducibility status flag and the instant of the last successful regeneration check" ] }, { "id": "als-graph-q-cluster-stability", "text": "How stable is this cluster across successive calculations, and what does instability indicate?", "kind": "quality", "answer_data": [ "Membership churn measure between consecutive snapshots", "Count of members whose inclusion depends on a single weak or unconfirmed edge", "Size of the cluster and a flag where size exceeds a declared review threshold", "Statement that low stability is reported, not corrected, here" ] } ], "data_elements": [ { "id": "als-graph-de-cluster-id", "name": "Cluster snapshot identifier", "description": "Identifier of a registered equivalence-cluster snapshot.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-034" ] }, { "id": "als-graph-de-cluster-rule-ref", "name": "Calculation rule reference", "description": "Reference to the external rule that computed the cluster and to the authority that owns it.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-050" ] }, { "id": "als-graph-de-cluster-rule-version", "name": "Calculation rule version", "description": "Immutable version tag of the calculation rule, required for citation and regeneration.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "als-graph-de-snapshot-instant", "name": "Snapshot instant", "description": "Instant as of which membership is asserted to hold, recorded separately from the registration instant.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-graph-de-input-graph-digest", "name": "Input graph digest", "description": "Digest pinning the exact edge state over which the calculation ran.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-graph-de-member-evidence-ref", "name": "Member evidence reference", "description": "Per-member reference to the connecting edges or path that justify membership.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-034", "SRC-048" ] }, { "id": "als-graph-de-cluster-stability-score", "name": "Cluster stability measure", "description": "Reported measure of membership churn between consecutive snapshots of the same cluster line.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-050" ] } ], "artifacts": [ { "id": "als-graph-art-cluster-snapshot", "name": "Equivalence cluster snapshot record", "description": "The immutable registered record of one externally calculated cluster: sorted member list, per-member evidence references, calculation rule identifier and version, parameters, input digest, snapshot instant, reproducibility status and any revision link to a superseded snapshot.", "media_or_form": [ "immutable derived-view record", "member listing with evidence references", "provenance-bearing dataset release" ], "serial": false, "identity_strategy": "The snapshot identifier issued by the external calculation system, which is the authoritative master system for cluster outputs, takes priority; failing that a governed IRI in the adopting Dimension's snapshot namespace; failing that a ULID minted here with the minting agent recorded. Rule version, snapshot instant and member-list digest are qualifiers used for reproducibility checks and never serve as the identifier.", "source_refs": [ "SRC-009", "SRC-034", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "als-graph-representative-reference", "name": "Canonical representative as a referenced external decision", "description": "Naming one member of a cluster as the canonical representative is a preference decision taken by a master-data, curation or publication authority; no equivalence semantics support it, since OWL 2 makes co-denoting individuals interchangeable without privileging any name and RDF 1.2 gives every IRI equal standing as a denotation. This model therefore records only the reference: which authority decided, under which rule and version, for which scope, over which effective interval. Endpoint identities are never rewritten, non-representative members are never demoted to aliases of the representative, and preference is never upgraded into an equivalence assertion.", "source_refs": [ "SRC-018", "SRC-002", "SRC-009", "SRC-008" ], "questions": [ { "id": "als-graph-q-representative-authority", "text": "Which authority selected this representative, and under what named rule and version?", "kind": "authority", "answer_data": [ "Selecting authority reference and the accountable role within it", "Selection rule reference and immutable rule version", "Decision record reference held by that authority", "Statement that this model neither evaluates nor re-derives the selection" ] }, { "id": "als-graph-q-representative-scope", "text": "For which scope does this representative hold, and can different scopes name different representatives for the same cluster?", "kind": "ownership", "answer_data": [ "Scope descriptor (publication channel, consuming system, jurisdiction, product line, or other declared context)", "Statement permitting concurrent scope-specific representatives for one cluster without conflict", "Conflict rule where two decisions claim the same scope and interval, and the authority that resolves it" ] }, { "id": "als-graph-q-representative-interval", "text": "Over what interval is this representative decision effective, and what is retained when it changes?", "kind": "temporal", "answer_data": [ "Effective interval start and end as RFC 3339 instants with seconds and explicit offsets", "Decision instant recorded separately from the effective start", "Rule that a superseded decision is closed and retained, never overwritten", "Reference to the succeeding decision" ] }, { "id": "als-graph-q-preference-not-equivalence", "text": "What guarantees that naming a representative changes nothing about the identity or standing of the other members?", "kind": "decision", "answer_data": [ "Explicit non-rewrite statement covering endpoint identifiers and endpoint records", "Statement that representative status confers no additional equivalence and creates no new alias edge", "Statement that resolution or redirection behaviour for non-representative identifiers is owned elsewhere", "Handling rule for a representative that is later found not to be a cluster member" ] } ], "data_elements": [ { "id": "als-graph-de-representative-ref", "name": "Representative member reference", "description": "Reference to the cluster member designated as canonical for a given scope and interval.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "als-graph-de-representative-authority-ref", "name": "Selecting authority reference", "description": "Reference to the external authority that took the representative decision and owns its rule.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-graph-de-representative-rule-version", "name": "Selection rule version", "description": "Immutable version tag of the rule the authority applied, recorded so that the decision remains interpretable after the rule changes.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "als-graph-de-representative-scope", "name": "Representative scope", "description": "The declared context within which the representative holds, permitting different representatives per scope for the same cluster.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-030" ] }, { "id": "als-graph-de-representative-effective-interval", "name": "Representative effective interval", "description": "Start and end instants over which the decision applies, each in RFC 3339 form with seconds and an explicit offset; an open end marks a decision still in force.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "The representative decision is made and documented by an external authority, which holds the decision record. What belongs here is a binding — authority, rule version, scope, interval and the member reference — carried alongside the cluster snapshot it qualifies. Issuing a local artefact would duplicate the authority's decision document, create a second place where a representative appears to be established, and risk that document drifting from or being mistaken for the authoritative decision. Keeping it as an inline reference also makes the non-rewrite rule structurally obvious: there is nothing here to publish that could displace an endpoint identity." } ] }, { "id": "als-graph-lineage-integrity-layer", "name": "Cluster lineage, impact and graph integrity", "description": "How clusters change over time without losing history, what a change means for anything that cited the old cluster, and how the recurring pathologies of identity graphs are detected and reported.", "source_refs": [ "SRC-009", "SRC-045", "SRC-050", "SRC-003" ], "findings": [ { "id": "als-graph-cluster-lineage-impact", "name": "Split and merge lineage, retained aliases and downstream impact", "description": "Clusters split when a contaminating edge is retracted and merge when a new edge connects previously separate components. Each such change is recorded as a lineage event linking predecessor and successor snapshots, with the event time distinguished from the time the change was recorded here. Prior membership and prior representative decisions are preserved and remain queryable, aliases that stay valid across the change are marked retained, and the assertions and downstream references that cited the affected snapshot are enumerated in an impact report. This model reports impact; it does not update, notify or reconcile the downstream systems.", "source_refs": [ "SRC-009", "SRC-008", "SRC-034", "SRC-050" ], "questions": [ { "id": "als-graph-q-lineage-event", "text": "What kind of lineage event occurred, and which predecessor and successor snapshots does it connect?", "kind": "lifecycle", "answer_data": [ "Event kind code (split, merge, member added, member removed, representative changed, snapshot superseded)", "Predecessor snapshot references and successor snapshot references", "Triggering cause reference, such as a retracted edge or a newly asserted edge", "Rule version in force at the time of the event" ] }, { "id": "als-graph-q-retained-alias", "text": "Which alias edges remain valid across this change, and which are now confined to a different successor cluster?", "kind": "relationship", "answer_data": [ "Retained alias edge references and their new cluster assignment", "Edges whose endpoints now fall in different successor clusters", "Edges whose status is unchanged but whose citation context has changed", "Statement that a lineage event does not by itself retract any edge" ] }, { "id": "als-graph-q-historical-member", "text": "How can a caller find out which cluster an identifier belonged to at a past instant, and which representative applied then?", "kind": "identity", "answer_data": [ "Historical membership lookup keyed by member identifier and instant", "Snapshot chain from which the answer was reconstructed", "Representative reference in force at that instant, with its authority and rule version", "Statement that historical answers are served from retained snapshots, never recomputed from current data" ] }, { "id": "als-graph-q-impact-report", "text": "Which downstream assertions and references cited the affected cluster, and what are they told?", "kind": "event", "answer_data": [ "List of impacted assertion and reference identifiers with the snapshot version each cited", "Impact classification per item (still valid, now spanning two clusters, representative changed, membership withdrawn)", "Recipient owner references for each impacted item", "Explicit statement that remediation is executed by the owning systems, not here" ] }, { "id": "als-graph-q-lineage-retention", "text": "How long are superseded snapshots and closed representative decisions kept, and who sets that period?", "kind": "retention", "answer_data": [ "Retention class reference for superseded snapshots, lineage events and closed decisions", "Reference to the retention policy model that owns the schedule and its execution", "Minimum preservation requirement needed to answer historical membership queries", "Tombstone content retained where the underlying record has been disposed of" ] } ], "data_elements": [ { "id": "als-graph-de-lineage-event-kind", "name": "Lineage event kind", "description": "Coded kind of cluster change, distinguishing splits, merges, membership changes and representative changes.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-graph-de-predecessor-cluster-ref", "name": "Predecessor snapshot reference", "description": "Reference to the snapshot or snapshots superseded by this event.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-graph-de-successor-cluster-ref", "name": "Successor snapshot reference", "description": "Reference to the snapshot or snapshots produced by this event.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-graph-de-retained-alias-ref", "name": "Retained alias reference", "description": "Reference to an alias edge that remains valid across the lineage event, with its new cluster assignment.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-034" ] }, { "id": "als-graph-de-impacted-assertion-ref", "name": "Impacted assertion reference", "description": "Reference to a downstream assertion or reference that cited an affected snapshot, with its impact classification.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-050", "SRC-009" ] }, { "id": "als-graph-de-lineage-event-instant", "name": "Lineage event instant", "description": "Event time at which the cluster change took effect, in RFC 3339 form with seconds and an explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "als-graph-de-lineage-record-instant", "name": "Lineage record instant", "description": "Observation or ingestion time at which the change was recorded here, stored separately from the event instant.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "als-graph-art-lineage-impact-report", "name": "Cluster lineage and downstream impact report", "description": "The issued report for one lineage event: predecessor and successor snapshots, retained aliases, members moved or withdrawn, representative decisions closed or opened, and the enumerated downstream assertions and references affected with their owners and impact classification.", "media_or_form": [ "issued impact report", "notification payload for owning systems", "human-readable change summary" ], "serial": true, "identity_strategy": "Where the owning calculation or change-management system is the authoritative master system for change records, its report identifier is used; otherwise the report takes a governed identifier composed of the cluster-line series key plus a monotonically increasing sequence number held in a separate field, with a ULID as last resort. The event instant is a qualifier and never part of the identifier or the sequence.", "source_refs": [ "SRC-009", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "als-graph-integrity-safeguards", "name": "Graph pathologies, contamination and safeguards", "description": "The recurring failure modes of identity graphs, detected and reported as results with severities rather than repaired. Covers false strong edges that collapse distinct subjects into one cluster; contradictory not-same edges found inside a cluster; disconnected subgraphs that a bounded policy cannot join; stale members whose endpoint has been withdrawn upstream; orphaned representatives no longer in their cluster; and breaches of the declared hop and path safeguards. Results follow the validation-report shape of focus node, source shape or condition, and severity, and no result triggers automatic correction.", "source_refs": [ "SRC-045", "SRC-018", "SRC-003", "SRC-050", "SRC-030" ], "questions": [ { "id": "als-graph-q-false-strong-edge", "text": "How is a suspected false strong edge identified, and what happens to the clusters that depend on it?", "kind": "quality", "answer_data": [ "Detection signals recorded (single edge whose removal splits the cluster, edge strength inconsistent with its justification class, cluster size beyond a declared review threshold)", "Reference to the dependent snapshots and members whose membership rests solely on that edge", "Severity assigned and the authority notified", "Statement that the edge is not retracted or downgraded by this model" ] }, { "id": "als-graph-q-disconnected-subgraph", "text": "How are disconnected subgraphs distinguished from an artefact of the traversal bounds in force?", "kind": "validation", "answer_data": [ "Termination reason of the run that produced the finding", "Whether a connection exists beyond the declared maximum depth or outside the allowed predicate set", "Re-check result under a broader policy version, where one is authorised", "Rule that absence of a path is never reported as a difference claim" ] }, { "id": "als-graph-q-stale-member", "text": "What marks a cluster member or representative as stale or orphaned, and how is that surfaced without changing the snapshot?", "kind": "exception", "answer_data": [ "Staleness signals (endpoint withdrawn or tombstoned upstream, member absent from the latest snapshot, representative no longer a member)", "Reference to the upstream withdrawal record and the system that issued it", "Annotation attached to the immutable snapshot rather than an edit to it", "Owner notified and the expected remediation path outside this model" ] }, { "id": "als-graph-q-orphan-representative", "text": "Which access controls apply to integrity findings, given that they can expose links a reader is not entitled to see?", "kind": "access", "answer_data": [ "Default deny rule and the scopes at which read entitlement is evaluated", "Exception permitting severity and condition code to be visible where the underlying evidence is restricted", "Masking rule for endpoint identifiers that themselves carry sensitive data", "Audit record reference for each disclosure of a restricted finding" ] }, { "id": "als-graph-q-safeguard-breach", "text": "What counts as a breach of the declared hop and path safeguards, and what must a run do when one occurs?", "kind": "constraint", "answer_data": [ "Safeguard set in force (maximum depth, maximum paths, time budget, maximum cluster size for automatic registration)", "Breach flag and the value that exceeded the bound", "Required run behaviour: stop, report the termination reason, and mark results as non-exhaustive", "Escalation route and the role authorised to approve a broader policy version" ] } ], "data_elements": [ { "id": "als-graph-de-integrity-check-id", "name": "Integrity check run identifier", "description": "Identifier of a single integrity evaluation over a defined subgraph or snapshot.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-graph-de-integrity-condition-code", "name": "Integrity condition code", "description": "Coded condition that produced the result, such as contradictory not-same edge inside a cluster, single-edge dependency, stale member or orphaned representative.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-045", "SRC-003", "SRC-018" ] }, { "id": "als-graph-de-result-severity", "name": "Result severity", "description": "Severity of the result, aligned to a violation, warning and informational scale.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-graph-de-focus-node-ref", "name": "Focus reference", "description": "Reference to the edge, node, path or snapshot the result concerns.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-graph-de-safeguard-breach-flag", "name": "Safeguard breach flag", "description": "Whether a declared hop, path, time or size safeguard was exceeded during the run that produced the result.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-048", "SRC-051" ] } ], "artifacts": [ { "id": "als-graph-art-integrity-check-report", "name": "Alias graph integrity check report", "description": "The result set of one integrity evaluation: per-result focus reference, condition code, severity, supporting evidence references, safeguard breach flags, the subgraph or snapshot evaluated and the check-run provenance. Reporting only; it carries no remediation instruction and triggers no automatic change.", "media_or_form": [ "structured validation result set", "severity-ranked finding list", "human-readable integrity summary" ], "serial": false, "identity_strategy": "Where an external validation service is the authoritative master system for check runs, its run identifier is used; otherwise a governed IRI in the adopting Dimension's check-run namespace; otherwise a ULID minted here with the minting agent recorded. A digest over the result set plus the evaluated snapshot digest binds the report to the exact state checked; the check instant is a qualifier only.", "source_refs": [ "SRC-045", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-state-b-status-control", "name": "Assertion status and controlled transitions", "description": "The status vocabulary that qualifies an alias/same-as assertion, the taxonomy of change kinds that move it, the matrix of allowed and forbidden transitions with entry and exit conditions, and the attribution of the authority recorded as responsible for each decision.", "rationale": "A registration authority's view of an administered item is expressed as a registration status split into progression and terminal categories, and registry practice marks entries deprecated or obsolete rather than removing them. An alias assertion is exactly such an administered item: consumers act on it, so its status and the conditions for changing it must be governed and explicit before any history can be meaningful.", "source_refs": [ "SRC-053", "SRC-052", "SRC-058" ], "layers": [ { "id": "als-state-l-status-semantics", "name": "Status vocabulary and change-kind semantics", "description": "Normative meaning of each status value, its consumption rule, and the disjoint kinds of change that can alter an assertion without deleting endpoints, rewriting history or erasing negative evidence.", "source_refs": [ "SRC-053", "SRC-052", "SRC-056", "SRC-003" ], "findings": [ { "id": "als-state-f-status-vocabulary", "name": "Canonical assertion status vocabulary", "description": "Defines the governed status values for an alias/same-as assertion - candidate/proposed, under-review, active, disputed, superseded, retracted, rejected, expired, tombstoned - each with a normative definition, a category (progression versus terminal documentation status), and an explicit rule stating what a consuming agent may do with the equivalence while that status holds. Status qualifies the assertion record, never the identifiers it references.", "source_refs": [ "SRC-053", "SRC-052", "SRC-058", "SRC-003" ], "questions": [ { "id": "als-state-q-status-meaning", "text": "What is the normative meaning of each status value, and what may a consuming agent do with the asserted equivalence while that status holds?", "kind": "definition", "answer_data": [ "Status code from the governed code list", "Normative definition text", "Consumption rule (may act, may act with caution, must not act, read-only historical)", "Whether the status permits transitive chaining of the equivalence" ] }, { "id": "als-state-q-status-category", "text": "Is a given status a progression status that can still improve, or a terminal documentation status with no further progression?", "kind": "classification", "answer_data": [ "Status category (progression or terminal documentation)", "Terminality flag", "Permitted re-entry conditions if not strictly terminal" ] }, { "id": "als-state-q-status-scope", "text": "Does the status apply to the whole assertion or only within a named scope, dataset or endpoint pair?", "kind": "state", "answer_data": [ "Scope expression or scope identifier", "Endpoint-pair reference when scoped narrowly", "Statement of whether an out-of-scope consumer may rely on the status" ] }, { "id": "als-state-q-status-mapping", "text": "Which external status or predicate vocabulary term does each local status map to, and where is that mapping only partial?", "kind": "interoperability", "answer_data": [ "External vocabulary IRI", "Mapping relation (exact, close, broader, narrower, none)", "Recorded divergence note where no faithful counterpart exists" ] } ], "data_elements": [ { "id": "als-state-de-status-code", "name": "Assertion status code", "description": "Governed code denoting the current lifecycle status of the assertion record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-053" ] }, { "id": "als-state-de-status-category", "name": "Status category", "description": "Whether the status is a progression status or a terminal documentation status in the registration-authority sense.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-053" ] }, { "id": "als-state-de-consumption-rule", "name": "Consumption rule", "description": "Normative instruction to consuming agents for this status, including whether the equivalence may be relied upon or chained.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-058" ] }, { "id": "als-state-de-status-scope", "name": "Status scope expression", "description": "Named context, dataset or endpoint pair within which the status applies; absent means assertion-wide.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "als-state-de-status-term-iri", "name": "Status term identifier", "description": "Governed IRI of the status term in the owning registration authority's namespace; never reused or reassigned.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-052", "SRC-053" ] } ], "artifacts": [ { "id": "als-state-af-status-code-list", "name": "Assertion status code list", "description": "The published, versioned register of status terms with definitions, category, consumption rule and declared external mappings; the normative reference for producers and consumers of assertions.", "media_or_form": [ "Controlled vocabulary / code list", "Machine-readable term register", "Human-readable status reference page" ], "serial": false, "identity_strategy": "Each term carries a governed IRI in the registration authority's namespace; terms are never reused or reassigned after first publication, and superseded terms remain published with a deprecation marker. The register itself carries the authority's specification identifier plus a semantic version tag.", "source_refs": [ "SRC-052", "SRC-053" ] } ], "inline_only_rationale": null }, { "id": "als-state-f-change-kind-taxonomy", "name": "Change-kind taxonomy and non-destruction rule", "description": "Distinguishes the disjoint kinds of change that act on an assertion: correction (the record misstated the decision or facts), supersession (a newer assertion replaces this one), retraction (the assertion is withdrawn as wrong or unsupportable), endpoint-deprecation notice (a referenced endpoint was deprecated upstream), replacement/redirect notice (an endpoint was replaced upstream), authority withdrawal (the asserting party revokes its mandate or backing) and evidence expiry (the evidence validity horizon passed). No change kind may delete an endpoint reference, rewrite an earlier record or erase refuting evidence.", "source_refs": [ "SRC-052", "SRC-056", "SRC-032", "SRC-055" ], "questions": [ { "id": "als-state-q-change-kind-distinction", "text": "How does this change differ from a correction, a supersession, a retraction, an endpoint-deprecation notice, a replacement/redirect notice, an authority withdrawal and an evidence expiry?", "kind": "classification", "answer_data": [ "Change-kind code", "Discriminating criterion applied", "Whether the earlier assertion is still considered to have been correct when made" ] }, { "id": "als-state-q-change-kind-facets", "text": "Which facets of the assertion does this change alter, and which facets must remain unchanged afterwards?", "kind": "constraint", "answer_data": [ "Altered facet list", "Frozen facet list (identifier, endpoint references, prior decisions, prior reasons)", "Post-change status code" ] }, { "id": "als-state-q-change-kind-prohibitions", "text": "What must never occur as a side effect of this change kind?", "kind": "exception", "answer_data": [ "Prohibited side effects (endpoint deletion, silent history rewrite, removal of refuting evidence, identifier reassignment)", "Detection signal if a prohibited effect is attempted", "Escalation target for the violation" ] }, { "id": "als-state-q-change-kind-trigger", "text": "Which upstream model reported the event that triggered this change, and what reference points to that upstream record?", "kind": "provenance", "answer_data": [ "Triggering model or authority reference", "Upstream record identifier", "Upstream event time as reported" ] } ], "data_elements": [ { "id": "als-state-de-change-kind", "name": "Change kind code", "description": "Governed code naming the kind of change applied to the assertion.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-052", "SRC-056" ] }, { "id": "als-state-de-prior-validity-claim", "name": "Prior-validity claim", "description": "Whether the change asserts the earlier state was wrong when made (correction, retraction) or correct when made but no longer current (supersession, expiry, deprecation).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-053" ] }, { "id": "als-state-de-upstream-event-ref", "name": "Upstream trigger reference", "description": "Reference to the endpoint-registry, authority or evidence record whose event triggered the change; carried as a reference, never as a copy of that model's lifecycle.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-052", "SRC-056" ] }, { "id": "als-state-de-frozen-facets", "name": "Frozen facet list", "description": "Facets that the change kind must leave byte-identical, used as the validation contract for the change.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055", "SRC-054" ] } ], "artifacts": [ { "id": "als-state-af-change-kind-code-list", "name": "Assertion change-kind code list", "description": "Published register of change kinds with discriminating criteria, permitted target statuses, prior-validity semantics and the prohibited side effects for each kind.", "media_or_form": [ "Controlled vocabulary / code list", "Machine-readable change-kind register" ], "serial": false, "identity_strategy": "Governed IRI per change-kind term in the registration authority's namespace; deprecated kinds remain published and are never reassigned to a different meaning.", "source_refs": [ "SRC-052", "SRC-053" ] } ], "inline_only_rationale": null } ] }, { "id": "als-state-l-transition-control", "name": "Transition rules and decision-authority attribution", "description": "The governed transition matrix with entry and exit conditions, the handling of forbidden transition attempts, and the recorded attribution of the authority responsible for each status decision.", "source_refs": [ "SRC-053", "SRC-058", "SRC-052", "SRC-009" ], "findings": [ { "id": "als-state-f-transition-matrix", "name": "Allowed and forbidden transitions with entry and exit conditions", "description": "The normative from-status/to-status matrix for the assertion lifecycle, with per-transition entry conditions (mandatory attributes, required evidence, required reviewer role), exit conditions (open obligations that block departure), terminality, and the rule that a forbidden attempt is recorded as a rejected transition rather than silently discarded. Post-publication statuses are not deletable; only a never-published candidate may be discarded, and then only if it was never externally referenced.", "source_refs": [ "SRC-053", "SRC-058", "SRC-052" ], "questions": [ { "id": "als-state-q-transition-reachable", "text": "Which target statuses are reachable from the current status, and which are explicitly forbidden?", "kind": "lifecycle", "answer_data": [ "From-status code", "Permitted to-status list", "Forbidden to-status list with the reason each is forbidden" ] }, { "id": "als-state-q-transition-entry", "text": "What entry conditions must hold before a transition into this status can be recorded?", "kind": "requirement", "answer_data": [ "Mandatory attribute completeness check", "Required evidence references", "Required reviewer role or mandate", "Required predicate-strength declaration" ] }, { "id": "als-state-q-transition-exit", "text": "What open obligations block leaving this status?", "kind": "constraint", "answer_data": [ "Open obligation list (unresolved dispute, missing successor link, pending evidence refresh)", "Obligation owner reference", "Obligation due time" ] }, { "id": "als-state-q-transition-reopen", "text": "Is this status terminal, or may the assertion be re-opened, and on what recorded justification?", "kind": "state", "answer_data": [ "Terminality flag", "Re-open precondition", "Required justification text and authority level" ] }, { "id": "als-state-q-transition-rejected", "text": "How is an attempted transition that the matrix forbids recorded and reported back to the requester?", "kind": "validation", "answer_data": [ "Rejected-transition record identifier", "Violated rule reference", "Requester reference and rejection reason", "Whether the assertion status changed (it must not)" ] } ], "data_elements": [ { "id": "als-state-de-from-status", "name": "From-status", "description": "Status the assertion held immediately before the transition.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-053" ] }, { "id": "als-state-de-to-status", "name": "To-status", "description": "Status the assertion holds immediately after the transition.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-053" ] }, { "id": "als-state-de-transition-allowed", "name": "Transition permitted flag", "description": "Whether the from/to pair is permitted by the governed matrix.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-053", "SRC-058" ] }, { "id": "als-state-de-entry-condition", "name": "Entry condition expression", "description": "Machine-checkable condition that must hold before the transition is recordable.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-053" ] }, { "id": "als-state-de-exit-obligation", "name": "Exit obligation", "description": "Outstanding obligation that must be discharged before the assertion may leave the status.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-055" ] } ], "artifacts": [ { "id": "als-state-af-transition-matrix", "name": "Assertion state-transition matrix", "description": "The versioned normative specification of permitted and forbidden transitions, entry and exit conditions, terminality and the rejected-transition recording rule.", "media_or_form": [ "Normative transition table", "Machine-readable state-transition specification" ], "serial": false, "identity_strategy": "Identified by the registration authority's specification identifier plus a semantic version tag; a revised matrix is a new version linked by supersedes/superseded-by and never an in-place edit, so historical records remain interpretable against the matrix version in force at decision time.", "source_refs": [ "SRC-052", "SRC-053" ] } ], "inline_only_rationale": null }, { "id": "als-state-f-decision-authority", "name": "Responsible authority attribution for a status decision", "description": "Records which agent is held responsible for each status decision, in which role, under which mandate or delegation, and against which governing decision policy. Attribution is a provenance record: it names the responsible party and cites the policy, and it neither evaluates nor enforces whether that party was permitted to act, which the referenced access-policy model owns. Change control over the assertion record and over the status vocabulary is named separately per registry practice.", "source_refs": [ "SRC-009", "SRC-053", "SRC-052", "SRC-054" ], "questions": [ { "id": "als-state-q-authority-agent", "text": "Which agent is recorded as responsible for this status decision, and in what role?", "kind": "authority", "answer_data": [ "Agent reference into the agent registry", "Role code held at decision time", "Organisational affiliation as recorded" ] }, { "id": "als-state-q-authority-change-control", "text": "Which body holds change control over this assertion record and over the status vocabulary itself?", "kind": "ownership", "answer_data": [ "Change controller reference for the assertion", "Change controller reference for the vocabulary", "Escalation path when the two differ" ] }, { "id": "als-state-q-authority-mandate", "text": "Under which mandate, delegation or review policy was the deciding agent acting, and where is that policy referenced?", "kind": "decision", "answer_data": [ "Mandate or delegation reference", "Governing decision-policy reference", "Mandate validity interval" ] }, { "id": "als-state-q-authority-quorum", "text": "How is a multi-party or quorum review recorded when several reviewers contribute to one decision?", "kind": "relationship", "answer_data": [ "Reviewer references with individual roles", "Quorum rule reference", "Dissenting opinion text where recorded" ] } ], "data_elements": [ { "id": "als-state-de-deciding-agent", "name": "Deciding agent reference", "description": "Reference to the agent recorded as responsible for the transition; resolved in the external agent registry.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-state-de-agent-role", "name": "Decision role code", "description": "Role the agent held with respect to the decision, such as registrar, designated expert reviewer or records custodian.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-052" ] }, { "id": "als-state-de-mandate-ref", "name": "Mandate or delegation reference", "description": "Reference to the mandate, delegation instrument or review policy under which the agent acted.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-053", "SRC-054" ] }, { "id": "als-state-de-change-controller", "name": "Change controller reference", "description": "Party holding change control over the assertion record, named per registry practice.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-052" ] } ], "artifacts": [], "inline_only_rationale": "Authority attribution is a set of reference-valued fields carried inside the transition record; it produces no separate document. The agents, roles, mandates and decision policies it points to are maintained by the agent registry and the access-policy model, and reproducing them here would duplicate models that own their own lifecycle and evaluation semantics." } ] } ] }, { "id": "als-state-b-history-time", "name": "Immutable transition history and temporal reconstruction", "description": "The append-only history of status decisions, the evidence and link structures that must survive every change, the bitemporal frame separating effective validity from record time, and the handling of conflicts, late arrivals, rollback requests, authority loss and post-retraction readability.", "rationale": "Records requirements demand that lifecycle metadata be captured and maintained rather than overwritten, preservation description information requires provenance and fixity to travel with the record, and registered-identifier practice requires that a withdrawn item remain resolvable to a tombstone stating why. Together these make the transition history, not the current status field, the authoritative artefact of this model.", "source_refs": [ "SRC-055", "SRC-054", "SRC-056", "SRC-057" ], "layers": [ { "id": "als-state-l-transition-record", "name": "Transition records, evidence and links", "description": "Content, ordering and integrity of the append-only transition record, and the supersession, dispute and evidence references - including refuting evidence - that it must preserve.", "source_refs": [ "SRC-054", "SRC-055", "SRC-009", "SRC-050" ], "findings": [ { "id": "als-state-f-transition-record", "name": "Immutable transition record content and integrity", "description": "Each status decision produces exactly one append-only record carrying the assertion reference, monotonic ordinal, from-status, to-status, change kind, reason in the decider's own words, deciding agent and role, decision time, matrix version in force, and an integrity digest chained to its predecessor. Decided fields are never edited in place; a mistake is corrected by appending a correction record that references the target.", "source_refs": [ "SRC-054", "SRC-055", "SRC-009", "SRC-053" ], "questions": [ { "id": "als-state-q-record-identity", "text": "What identifier and ordinal uniquely denote this transition record within the assertion's history?", "kind": "identity", "answer_data": [ "Transition record identifier", "Monotonic ordinal within the assertion scope", "Assertion record reference" ] }, { "id": "als-state-q-record-event", "text": "Which decision does the record describe, expressed as prior status, new status, change kind and outcome?", "kind": "event", "answer_data": [ "From-status and to-status", "Change-kind code", "Decision outcome code (accepted, rejected, deferred)" ] }, { "id": "als-state-q-record-reason", "text": "What reason and rationale were given at decision time, in the decider's own words?", "kind": "provenance", "answer_data": [ "Reason text as recorded", "Rationale or deliberation reference", "Language tag of the reason text" ] }, { "id": "als-state-q-record-procedure", "text": "By which recording procedure was the entry appended, checked and sealed?", "kind": "process", "answer_data": [ "Recording procedure reference", "Matrix version in force at decision time", "Validation outcome before append" ] }, { "id": "als-state-q-record-integrity", "text": "How would tampering with an already-appended record be detected?", "kind": "validation", "answer_data": [ "Canonical-form digest of the record", "Predecessor digest", "Digest algorithm identifier", "Verification outcome and integrity-suspect flag" ] } ], "data_elements": [ { "id": "als-state-de-transition-id", "name": "Transition record identifier", "description": "Stable identifier of one appended transition record.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-054", "SRC-053" ] }, { "id": "als-state-de-ordinal", "name": "Transition ordinal", "description": "Monotonically increasing sequence number of the record within the assertion's history; a sequence token, never a date.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-052", "SRC-008" ] }, { "id": "als-state-de-reason-text", "name": "Decision reason", "description": "Free-text reason recorded by the deciding agent at decision time and never rewritten afterwards.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-055", "SRC-056" ] }, { "id": "als-state-de-record-digest", "name": "Record integrity digest", "description": "Digest over the canonical serialisation of the record, chained to the predecessor digest to make silent alteration detectable.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-054" ] }, { "id": "als-state-de-matrix-version", "name": "Matrix version in force", "description": "Version tag of the transition matrix against which the decision was validated, so historical records stay interpretable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-052", "SRC-053" ] } ], "artifacts": [ { "id": "als-state-af-transition-record", "name": "Assertion transition record entry", "description": "One sealed, append-only entry in the assertion's history, carrying the decision, its attribution, its time coordinates and its integrity digest.", "media_or_form": [ "Append-only history entry", "Serialised record in the adopting Dimension's store", "Exportable history line for transfer" ], "serial": true, "identity_strategy": "Priority: the authoritative record identifier issued by the master system that owns the assertion register; otherwise a governed IRI in the owner namespace; otherwise a ULID minted by the adopting Dimension. Entries are ordered within an assertion by a zero-padded monotonic ordinal that carries no date component and is never reused, even after a rejected or rolled-back attempt.", "source_refs": [ "SRC-053", "SRC-052", "SRC-054" ] } ], "inline_only_rationale": null }, { "id": "als-state-f-evidence-and-links", "name": "Evidence polarity and assertion-to-assertion links", "description": "Every decision cites the evidence considered, separating supporting from refuting items with the strength assessed at decision time, and records the links between assertions: supersedes / superseded-by, disputes / disputed-by, corrects / corrected-by and replaced-by. Refuting evidence references are retained through retraction and tombstoning; a later positive decision never removes earlier negative evidence. Evidence content and its own lifecycle stay with the evidence and match models.", "source_refs": [ "SRC-050", "SRC-055", "SRC-009", "SRC-054" ], "questions": [ { "id": "als-state-q-evidence-polarity", "text": "Which evidence items were considered supporting and which refuting at the time of the decision?", "kind": "evidence", "answer_data": [ "Evidence reference", "Polarity (supporting or refuting)", "Evidence type reference", "Whether the item was decisive" ] }, { "id": "als-state-q-evidence-strength", "text": "What strength or confidence was assessed for each evidence item, and by which stated method?", "kind": "quality", "answer_data": [ "Assessed strength value or band", "Assessment method reference", "Assessor agent reference" ] }, { "id": "als-state-q-links-supersession", "text": "Which assertion does this one supersede, and which assertion supersedes it?", "kind": "relationship", "answer_data": [ "Supersedes reference", "Superseded-by reference", "Link establishment time", "Whether the successor narrows, widens or reverses the equivalence" ] }, { "id": "als-state-q-evidence-retention", "text": "For how long must refuting evidence references be preserved after the assertion is retracted or tombstoned?", "kind": "retention", "answer_data": [ "Retention class reference", "Minimum preservation period", "Policy owner reference for disposition execution" ] } ], "data_elements": [ { "id": "als-state-de-evidence-ref", "name": "Evidence reference", "description": "Reference to an evidence item considered in the decision, held externally.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-050", "SRC-054" ] }, { "id": "als-state-de-evidence-polarity", "name": "Evidence polarity", "description": "Whether the cited item supported or refuted the asserted equivalence.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-050" ] }, { "id": "als-state-de-supersedes-ref", "name": "Supersedes / superseded-by reference", "description": "Directed link between the assertion and the assertion that replaces or is replaced by it.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-053" ] }, { "id": "als-state-de-dispute-ref", "name": "Dispute reference", "description": "Reference to the raised dispute, including the disputing party and the contested facet.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-050", "SRC-055" ] } ], "artifacts": [], "inline_only_rationale": "These are reference-valued and link-valued fields inside transition records rather than a separate deliverable. The evidence documents, match scores and dispute cases they point to are produced and governed by the evidence, entity-resolution and case models; materialising local copies would duplicate content whose lifecycle and quality semantics belong to those models." } ] }, { "id": "als-state-l-temporal-frame", "name": "Effective intervals and bitemporal record time", "description": "Separation of the interval over which the equivalence is claimed to hold from the times at which decisions were made, observed and ingested, together with the reconstruction rules for late arrivals and retroactive corrections.", "source_refs": [ "SRC-008", "SRC-057", "SRC-032", "SRC-055" ], "findings": [ { "id": "als-state-f-temporal-frame", "name": "Effective interval and bitemporal timestamps", "description": "Each assertion carries an effective interval over which the equivalence is claimed to hold, and each transition record carries a decision/event time, an observation time and an ingestion time. All are RFC 3339 date-time values with seconds and an explicit numeric offset or Z; the originating offset is preserved alongside any normalised UTC value. Open-ended intervals are represented explicitly as unbounded-at-this-time rather than as an unqualified null, and evidence-validity horizons drive expiry.", "source_refs": [ "SRC-008", "SRC-057", "SRC-032" ], "questions": [ { "id": "als-state-q-time-effective", "text": "Over which effective interval is the asserted equivalence claimed to hold?", "kind": "temporal", "answer_data": [ "Effective-from timestamp", "Effective-to timestamp or unbounded marker", "Interval boundary inclusivity", "Basis for the interval (source validity, decision, evidence horizon)" ] }, { "id": "als-state-q-time-axes", "text": "What are the decision time, the observation time and the ingestion time of this record, and where do they differ?", "kind": "event", "answer_data": [ "Decision/event timestamp", "Observation timestamp", "Ingestion timestamp", "Explanation of any material gap between them" ] }, { "id": "als-state-q-time-format", "text": "How must each time value be expressed, and what precision and offset must be present?", "kind": "requirement", "answer_data": [ "RFC 3339 date-time with seconds", "Explicit numeric offset or Z", "Originating offset retained", "Clock source or authority reference" ] }, { "id": "als-state-q-time-openness", "text": "How is an unknown or open-ended interval endpoint represented without implying an unlimited claim?", "kind": "constraint", "answer_data": [ "Open-endpoint marker distinct from null", "Reason for openness (not yet ended, unknown, pending review)", "Review-due timestamp" ] }, { "id": "als-state-q-time-expiry", "text": "When does the assertion expire automatically because its evidence-validity horizon has passed?", "kind": "lifecycle", "answer_data": [ "Evidence-validity horizon timestamp", "Expiry-due timestamp", "Whether expiry is automatic or requires a recorded decision", "Post-expiry consumption rule" ] } ], "data_elements": [ { "id": "als-state-de-effective-from", "name": "Effective-from", "description": "Instant from which the asserted equivalence is claimed to hold, as an RFC 3339 date-time with seconds and explicit offset or Z.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-057" ] }, { "id": "als-state-de-effective-to", "name": "Effective-to", "description": "Instant at which the claim ceases to hold, or an explicit unbounded marker with a stated reason.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-032" ] }, { "id": "als-state-de-decision-time", "name": "Decision (event) time", "description": "Instant at which the status decision was taken by the responsible authority.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-state-de-observation-time", "name": "Observation time", "description": "Instant at which the decision or upstream event became known to the recording system.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-057" ] }, { "id": "als-state-de-ingestion-time", "name": "Ingestion time", "description": "Instant at which the record was committed to the store, establishing the as-known-at axis for reconstruction.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-057", "SRC-055" ] } ], "artifacts": [], "inline_only_rationale": "Temporal framing is expressed entirely as typed fields on assertions and transition records; it yields no separate document or media object. The clock authority, calendar services and any timestamping trust service are external and retain their own governance." }, { "id": "als-state-f-retroactive-correction", "name": "Late arrivals, retroactive corrections and as-of reconstruction", "description": "Handles events recorded after later events already exist and corrections that change what is believed to have been true in the past. Records are never reordered or overwritten: a late arrival is appended with its own decision time and a later ingestion time, and a retroactive correction appends a record that restates the effective interval or the corrected facts while pointing at the record it corrects. Two reconstructions are supported and must be distinguishable: the status as it was known at a past instant, and the status now believed to have applied at that instant.", "source_refs": [ "SRC-057", "SRC-055", "SRC-008", "SRC-054" ], "questions": [ { "id": "als-state-q-late-arrival", "text": "How is an event recorded after a later event already exists reconciled without reordering the history?", "kind": "temporal", "answer_data": [ "Late-arrival flag", "Decision time versus ingestion time gap", "Records whose interpretation changes as a result", "Recomputed current status after insertion" ] }, { "id": "als-state-q-correction-procedure", "text": "What procedure records a retroactive correction to a past effective interval or a past decision?", "kind": "process", "answer_data": [ "Corrected record reference", "Corrected field path and restated value", "Correction reason and deciding agent", "Statement that the original record remains readable" ] }, { "id": "als-state-q-asof-reconstruction", "text": "How is the status as it was known at a past instant distinguished from the status now believed to have applied then?", "kind": "validation", "answer_data": [ "As-of event-time parameter", "As-known-at ingestion-time parameter", "Resulting status for each axis", "Set of records included in each reconstruction" ] }, { "id": "als-state-q-late-notification", "text": "What signals a late arrival or correction to downstream consumers that already acted on the earlier state?", "kind": "interoperability", "answer_data": [ "Change-notification payload reference", "Affected effective interval", "Advisory action for consumers", "Consumer acknowledgement reference where captured" ] } ], "data_elements": [ { "id": "als-state-de-corrects-ref", "name": "Corrects reference", "description": "Reference from a correction record to the earlier record whose content it restates; the earlier record remains readable.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055", "SRC-054" ] }, { "id": "als-state-de-late-arrival-flag", "name": "Late-arrival flag", "description": "Marks a record whose decision time precedes the decision time of an already-committed later record.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-057" ] }, { "id": "als-state-de-asof-event", "name": "As-of event-time parameter", "description": "Query coordinate selecting the effective state that applied at a given instant according to current belief.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-057" ] }, { "id": "als-state-de-asof-known", "name": "As-known-at parameter", "description": "Query coordinate selecting the state as it was recorded and knowable at a given instant, excluding later arrivals.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-057" ] } ], "artifacts": [], "inline_only_rationale": "Late arrival and retroactive correction are expressed through fields already present on appended records plus query coordinates over the two time axes; they create no additional artefact. Materialising a separate correction document would risk becoming a second, divergent source of truth alongside the append-only history." } ] }, { "id": "als-state-l-exception-handling", "name": "Conflicts, rollback, authority loss and tombstones", "description": "Detection and representation of mutually inconsistent statuses, handling of rollback requests and authority loss, and the guaranteed readable remainder after retraction or tombstoning.", "source_refs": [ "SRC-056", "SRC-050", "SRC-052", "SRC-055" ], "findings": [ { "id": "als-state-f-conflict-rollback-tombstone", "name": "Conflicting states, rollback requests, authority loss and post-retraction readability", "description": "Covers two or more simultaneously recorded, mutually inconsistent statuses for the same assertion (typically from different authorities or a partitioned write path), which are represented as an explicit disputed state naming the conflicting records rather than being silently reconciled; rollback requests, which are satisfied by appending a forward transition that restores an earlier status with its own justification, never by removing records; authority loss or withdrawal, which freezes further transitions by that authority and marks affected assertions for review while leaving their history intact; and the tombstone, which keeps the assertion identifier resolvable and carries the identifier, terminal status, reason, effective interval, links and history pointer after retraction.", "source_refs": [ "SRC-056", "SRC-052", "SRC-050", "SRC-055" ], "questions": [ { "id": "als-state-q-conflict-detection", "text": "How are two simultaneously recorded, mutually inconsistent statuses for one assertion detected and represented?", "kind": "exception", "answer_data": [ "Conflict identifier", "Conflicting record references and their authorities", "Representation rule (explicit disputed state, no silent reconciliation)", "Consumption rule while unresolved" ] }, { "id": "als-state-q-authority-loss", "text": "What happens to an assertion when the authority that made it loses or withdraws its mandate?", "kind": "state", "answer_data": [ "Authority-withdrawal record reference", "Freeze scope for further transitions by that authority", "Review-required marker on affected assertions", "Statement that prior history remains unchanged and readable" ] }, { "id": "als-state-q-rollback-handling", "text": "How is a rollback request satisfied when the append-only rule forbids removing records?", "kind": "decision", "answer_data": [ "Rollback request reference and requester", "Forward transition that restores the earlier status", "Justification text", "List of records that remain in place" ] }, { "id": "als-state-q-post-retraction-access", "text": "Which fields remain readable, and to which audiences, after retraction or tombstoning?", "kind": "access", "answer_data": [ "Always-readable field set (identifier, terminal status, reason, effective interval, links)", "Restricted or redacted field set", "Audience classes and the policy reference governing them" ] }, { "id": "als-state-q-tombstone-retention", "text": "What minimum content must a tombstone retain, and under which retention class?", "kind": "retention", "answer_data": [ "Mandatory tombstone content list", "Retention class reference", "Disposition authority reference", "Statement that the identifier is never reassigned" ] } ], "data_elements": [ { "id": "als-state-de-conflict-id", "name": "Conflict identifier", "description": "Identifier of a detected inconsistency between simultaneously recorded statuses for one assertion.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-050" ] }, { "id": "als-state-de-rollback-ref", "name": "Rollback request reference", "description": "Reference to the request that prompted a restoring forward transition, retained with its outcome.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-055" ] }, { "id": "als-state-de-authority-withdrawal-ref", "name": "Authority-withdrawal reference", "description": "Reference to the record of an authority losing or withdrawing its mandate, with the affected scope.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-052", "SRC-054" ] }, { "id": "als-state-de-tombstone-reason", "name": "Tombstone reason", "description": "Stated reason for unavailability shown on the tombstone, required so that a resolver confirms the identifier was found and explains its withdrawal.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056" ] }, { "id": "als-state-de-readable-after-tombstone", "name": "Post-tombstone readable field set", "description": "Enumerated fields guaranteed to remain readable after retraction or tombstoning, subject to redaction of personal data.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056", "SRC-055" ] } ], "artifacts": [ { "id": "als-state-af-tombstone-record", "name": "Assertion tombstone record", "description": "The persistent notice that replaces an operational assertion after retraction: it keeps the identifier resolvable and presents the terminal status, the stated reason, the effective interval that once applied, supersession or replacement links and a pointer to the full history.", "media_or_form": [ "Tombstone entry", "Publicly readable withdrawal notice", "Machine-readable terminal-status response" ], "serial": false, "identity_strategy": "The tombstone carries the retracted assertion's own identifier unchanged so existing references keep resolving; the identifier is never deleted or reassigned. A distinct tombstone record identifier is minted for the notice itself, following the same identifier priority as other records of this model.", "source_refs": [ "SRC-056", "SRC-052" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-res-bundle-historical-answering", "name": "Historical and As-Of Resolution", "description": "Everything needed to answer an alias question deterministically at a stated instant: the two time axes the question is asked on, the endpoint versions the answer was evaluated against, the closed outcome vocabulary, and the observed condition of each endpoint.", "rationale": "Memento shows that time-based access requires an explicit requested datetime, an explicit response datetime and a consistent selection rule; DID Resolution shows that a resolution interface needs a closed status vocabulary plus versionTime/versionId options and deactivation metadata; RFC 3339 fixes the timestamp form. Together these force a distinct top-level concern for answering as of a point in time rather than only now.", "source_refs": [ "SRC-059", "SRC-008", "SRC-015" ], "layers": [ { "id": "als-res-layer-asof-frame", "name": "As-Of Frame and Version Binding", "description": "The temporal frame of a resolution request and the version state of the endpoints it is evaluated against.", "source_refs": [ "SRC-059", "SRC-008", "SRC-015" ], "findings": [ { "id": "als-res-finding-time-basis", "name": "As-Of Time Basis and Dual Timeline", "description": "Every resolution request selects on two independent axes: the real-world validity or event time of the assertions being considered, and the observation or ingestion time at which this model came to hold the evidence. A current answer is the degenerate case where both axes are set to 'now'. Recording only one axis makes a historical answer irreproducible, because evidence that arrived late would silently change a past answer.", "source_refs": [ "SRC-059", "SRC-008", "SRC-009" ], "questions": [ { "id": "als-res-q-time-axes", "text": "Which event or validity instant and which observation or ingestion instant does this as-of resolution request select on?", "kind": "temporal", "answer_data": [ "as-of event instant as an RFC 3339 timestamp with seconds and explicit offset", "as-of observation/ingestion instant as an RFC 3339 timestamp with seconds and explicit offset", "flag indicating whether either axis defaulted to request time" ] }, { "id": "als-res-q-answer-mode", "text": "Is the answer a current answer or a reconstructed historical answer, and how is that difference marked on the answer itself?", "kind": "state", "answer_data": [ "answer mode code: current or historical-reconstruction", "reference to the assertion population snapshot used", "statement of whether late-arriving evidence was excluded" ] }, { "id": "als-res-q-late-evidence", "text": "How is a later answer for the same as-of instant distinguished from an earlier one after new evidence arrives?", "kind": "provenance", "answer_data": [ "answer identifier and generation activity per PROV-O wasGeneratedBy and generatedAtTime", "prior answer identifier that this answer revises (wasRevisionOf)", "enumerated evidence items added or invalidated since the prior answer" ] }, { "id": "als-res-q-open-interval", "text": "What rule applies when an assertion's validity interval is open-ended or the asserting authority supplied no time-zone offset?", "kind": "constraint", "answer_data": [ "open-interval handling rule (treated as valid until superseded or withdrawn)", "rule that a missing offset is recorded as -00:00 meaning unknown local offset, never silently as Z", "rejection condition for timestamps lacking seconds or an offset" ] }, { "id": "als-res-q-clock-skew", "text": "How is clock skew between the asserting authority and this model bounded and disclosed on the answer?", "kind": "quality", "answer_data": [ "declared maximum tolerated skew as a duration", "skew note or measured offset per source authority", "behaviour when an assertion's event time is later than its ingestion time" ] } ], "data_elements": [ { "id": "als-res-de-asof-event-instant", "name": "As-of event instant", "description": "The validity/event instant the resolution question is asked about.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-059", "SRC-008" ] }, { "id": "als-res-de-asof-record-instant", "name": "As-of observation instant", "description": "The ingestion/observation cut-off; evidence recorded after it is excluded from the answer.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-res-de-answer-mode", "name": "Answer mode", "description": "Closed code distinguishing a current answer from a reconstructed historical answer.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-059", "SRC-015" ] }, { "id": "als-res-de-validity-interval", "name": "Assertion validity interval", "description": "Start and optional end of the interval in which an assertion is claimed to hold.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-res-de-skew-note", "name": "Clock skew disclosure", "description": "Declared or measured skew between the asserting authority's clock and this model's clock.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "The time basis is not a document but a pair of scalar fields plus a mode code carried on every request, assertion and answer of this model. Materialising it as a separate artifact would create a second place where the authoritative instants live and would invite drift between the artifact and the records it describes; the reproducibility guarantee depends on these values being inline on the very record whose meaning they fix." }, { "id": "als-res-finding-version-pinning", "name": "Source and Target Version Pins", "description": "An assertion is evaluated against particular states of its two endpoints. Recording which state was seen turns an unfalsifiable claim into a checkable one and lets a historical answer be re-derived. Where the endpoint authority publishes a version identifier or a time-based access mechanism, the pin binds to it; where it does not, the pin degrades explicitly to an observation timestamp plus a payload digest rather than being omitted.", "source_refs": [ "SRC-059", "SRC-015", "SRC-056" ], "questions": [ { "id": "als-res-q-pin-values", "text": "Which version identifier of the source endpoint and which of the target endpoint was this assertion evaluated against?", "kind": "provenance", "answer_data": [ "source endpoint version identifier or memento reference", "target endpoint version identifier or memento reference", "observation timestamp for each endpoint state" ] }, { "id": "als-res-q-pin-fallback", "text": "How is a pin expressed when the endpoint authority publishes no version identifier or time-based access mechanism?", "kind": "identity", "answer_data": [ "fallback pin mechanism code (observation-timestamp-and-digest)", "digest of the observed endpoint representation", "explicit degradation flag so consumers do not treat the pin as authority-issued" ] }, { "id": "als-res-q-pin-mechanism", "text": "Which external version or as-of mechanism is bound for each endpoint namespace, and who declares that binding?", "kind": "interoperability", "answer_data": [ "per-namespace pin mechanism registry entry", "mechanism kind (memento datetime negotiation, resolver versionTime, resolver versionId, authority-native revision id)", "owning authority of the mechanism declaration" ] }, { "id": "als-res-q-pin-verification", "text": "How is a pin checked as still dereferenceable before an answer cites it, and what happens if it is not?", "kind": "validation", "answer_data": [ "last successful pin verification timestamp", "verification outcome code", "answer degradation rule when a pin can no longer be verified" ] } ], "data_elements": [ { "id": "als-res-de-source-version-pin", "name": "Source endpoint version pin", "description": "Version identifier, memento reference or degraded digest pin for the source endpoint state.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-059", "SRC-015" ] }, { "id": "als-res-de-target-version-pin", "name": "Target endpoint version pin", "description": "Version identifier, memento reference or degraded digest pin for the target endpoint state.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-059", "SRC-015" ] }, { "id": "als-res-de-pin-mechanism", "name": "Pin mechanism", "description": "Closed code naming how the pin was obtained.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-059", "SRC-015" ] }, { "id": "als-res-de-pin-verified-at", "name": "Pin verification instant", "description": "Observation instant of the most recent successful verification that the pinned state is still retrievable.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-056" ] }, { "id": "als-res-de-pin-digest", "name": "Pinned representation digest", "description": "Cryptographic digest of the observed endpoint representation, used when no authority version identifier exists.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-059" ] } ], "artifacts": [ { "id": "als-res-artifact-pin-manifest", "name": "Version pin manifest", "description": "Immutable manifest listing, for one assertion or one answer, every endpoint state pin with its mechanism, digest and verification history.", "media_or_form": [ "structured record set", "tabular listing", "human-readable manifest rendering" ], "serial": false, "identity_strategy": "Identified by the authoritative master-system identifier of the assertion or answer it pins, extended by a manifest discriminator; where the adopting Dimension holds no master-system identifier, a governed IRI is used, and only failing that a UUID or ULID assigned by the Dimension.", "source_refs": [ "SRC-059", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "als-res-layer-outcome-determinacy", "name": "Resolution Outcome Determinacy", "description": "The closed vocabulary of answers this model may emit, including ambiguity and no-answer outcomes, and the observed condition of each endpoint that shaped the outcome.", "source_refs": [ "SRC-023", "SRC-015", "SRC-056", "SRC-063" ], "findings": [ { "id": "als-res-finding-outcome-status", "name": "Deterministic Resolution Status and No-Answer Outcomes", "description": "A resolution answer carries a status drawn from a closed vocabulary. Where more than one endpoint remains admissible the answer returns the candidate set with an ambiguity status; it never silently elects a canonical endpoint. Where nothing is admissible at the requested instant it returns an explicit no-answer status with a reason, never an empty success. The inputs that determined the status are enumerated so the answer can be recomputed.", "source_refs": [ "SRC-023", "SRC-059", "SRC-015" ], "questions": [ { "id": "als-res-q-status-vocabulary", "text": "Which closed status vocabulary may an alias resolution answer carry, and who may extend it?", "kind": "classification", "answer_data": [ "enumerated status codes (resolved-single, ambiguous-multiple, no-admissible-assertion, endpoint-unresolved, endpoint-tombstoned, chain-budget-exhausted, chain-loop-detected, quarantined-suppressed, invalid-request)", "extension authority and registration rule for Dimension-local codes", "mapping notes to external resolver status vocabularies" ] }, { "id": "als-res-q-ambiguity", "text": "When several candidate endpoints remain admissible, is one selected as canonical or is the ambiguity returned to the caller?", "kind": "decision", "answer_data": [ "rule that the full candidate set is returned with an ambiguity status", "per-candidate authority and confidence carried through unaltered", "statement that no tie-break or ranking decision is made by this model" ] }, { "id": "als-res-q-no-answer", "text": "What is emitted when no assertion is admissible at the requested as-of instant?", "kind": "exception", "answer_data": [ "no-answer status code and machine-readable reason", "distinction between never-asserted, not-yet-valid, expired and suppressed", "guidance on what the caller must not infer from a no-answer outcome" ] }, { "id": "als-res-q-determinism-inputs", "text": "Which inputs must be enumerated on the answer so the same answer can be recomputed later?", "kind": "evidence", "answer_data": [ "ordered list of assertion identifiers considered and their disposition", "as-of instants on both axes and the pin manifest reference", "digest over the ordered determinant input set" ] }, { "id": "als-res-q-nondeterminism", "text": "Which conditions make an answer non-deterministic and therefore invalid to emit?", "kind": "constraint", "answer_data": [ "unpinned endpoint state combined with a historical request", "unordered candidate set or unstable tie ordering", "incomplete evidence ingestion at the stated observation cut-off" ] } ], "data_elements": [ { "id": "als-res-de-resolution-status", "name": "Resolution status", "description": "Closed status code of the answer.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] }, { "id": "als-res-de-candidate-set", "name": "Candidate endpoint set", "description": "Ordered set of admissible endpoints with the assertion, authority and confidence that admitted each.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-015" ] }, { "id": "als-res-de-no-answer-reason", "name": "No-answer reason", "description": "Machine-readable reason accompanying a no-answer or suppressed status.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015", "SRC-056" ] }, { "id": "als-res-de-determinant-digest", "name": "Determinant input digest", "description": "Digest over the ordered set of inputs that determined the status, enabling replay verification.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] } ], "artifacts": [ { "id": "als-res-artifact-answer-record", "name": "Alias resolution answer record", "description": "Immutable record of one issued answer: request frame, status, candidate set or no-answer reason, pin manifest reference and determinant digest.", "media_or_form": [ "structured record", "human-readable answer rendering", "append-only record series entry" ], "serial": true, "identity_strategy": "Identified by the authoritative master-system identifier assigned by the resolution service of record; where none exists, a governed IRI under the adopting Dimension's namespace; only failing both, a Dimension-assigned UUID or ULID. Series position is a separate ordinal attribute and never the identifier.", "source_refs": [ "SRC-009", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "als-res-finding-endpoint-condition", "name": "Endpoint Condition: Stale, Missing, Unresolved and Tombstoned", "description": "An assertion names two endpoints whose condition may have changed since the assertion was made. Registries such as ROR and DataCite keep identifiers resolvable while marking them inactive, withdrawn or tombstoned rather than deleting them, and HTTP distinguishes an absent resource from one deliberately gone. This model records the observed condition of each endpoint with its observation instant and evidence, and uses it to qualify rather than to erase assertions.", "source_refs": [ "SRC-023", "SRC-056", "SRC-063" ], "questions": [ { "id": "als-res-q-endpoint-condition", "text": "What condition did each endpoint present at the observation instant, and on what evidence?", "kind": "state", "answer_data": [ "condition code (reachable, stale, missing, unresolved, deprecated, tombstoned, withdrawn)", "observation instant with seconds and offset", "reference to the captured observation evidence item" ] }, { "id": "als-res-q-tombstone-effect", "text": "How does a deprecated, withdrawn or tombstoned endpoint change the admissibility of assertions naming it?", "kind": "lifecycle", "answer_data": [ "admissibility rule per condition code (admissible, admissible-with-warning, inadmissible)", "requirement that the assertion is retained and marked, never deleted", "successor or replacement hint carried through without being treated as an equivalence assertion" ] }, { "id": "als-res-q-unreachable-vs-absent", "text": "What distinguishes an endpoint that was unreachable from one that is genuinely absent, in the recorded evidence?", "kind": "evidence", "answer_data": [ "transport-level outcome captured by the observing component", "distinction between a not-found response, a deliberately-gone response and a failure to obtain any response", "number of independent observations and their observers" ] }, { "id": "als-res-q-staleness-budget", "text": "For how long may a prior endpoint condition observation be reused before re-observation is required?", "kind": "retention", "answer_data": [ "staleness budget as a duration, per namespace or condition", "behaviour when the budget is exceeded during a current-mode answer", "exemption rule for historical-mode answers, which must use the contemporaneous observation" ] } ], "data_elements": [ { "id": "als-res-de-endpoint-condition", "name": "Endpoint condition", "description": "Closed code for the observed condition of one endpoint.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-063" ] }, { "id": "als-res-de-condition-observed-at", "name": "Condition observation instant", "description": "Instant at which the condition was observed by the reporting component.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "als-res-de-condition-evidence-ref", "name": "Condition evidence reference", "description": "Reference to the captured evidence supporting the recorded condition.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-res-de-staleness-budget", "name": "Staleness budget", "description": "Maximum age of a condition observation that a current-mode answer may rely on.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056" ] }, { "id": "als-res-de-successor-hint", "name": "Successor hint", "description": "Replacement or successor endpoint published by the endpoint's own authority, carried as a hint only.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-056", "SRC-063" ] } ], "artifacts": [], "inline_only_rationale": "Endpoint condition is a derived qualification held as fields on the assertion and on the answer, pointing outward to evidence that other components captured and to registries that other authorities own. Declaring a local artifact for endpoint state would create a shadow availability register, which is explicitly outside this model's boundary; the authoritative statement of an endpoint's condition always remains with the endpoint's own authority." } ] } ] }, { "id": "als-res-bundle-operational-edge-cases", "name": "Chain Evidence, Change Impact and Contention Control", "description": "The operational failure surface of alias mapping: externally observed relocation and canonical-hint chains, the fallout of endpoint merges and splits, and contention between competing or conflicting assertions about the same endpoint pair.", "rationale": "RFC 9110 and RFC 6596 supply the relocation and canonical-hint semantics together with the warning that these are transport preferences rather than identity proofs; DID Core states plainly that an alsoKnownAs assertion does not prove itself; ROR and DataCite supply merge, split and tombstone practice; RFC 9110 conditional requests and the IETF idempotency-key work supply the contention controls. These are operating rather than answering concerns and belong in a separate top-level bundle.", "source_refs": [ "SRC-023", "SRC-024", "SRC-060", "SRC-062", "SRC-056", "SRC-063" ], "layers": [ { "id": "als-res-layer-chain-evidence", "name": "Relocation and Hint Chain Evidence", "description": "How externally observed hop sequences and canonical hints are admitted, bounded, classified and weighted as evidence about identifier equivalence.", "source_refs": [ "SRC-023", "SRC-024", "SRC-006", "SRC-060" ], "findings": [ { "id": "als-res-finding-chain-traversal", "name": "Chain Traversal Budget, Loop Detection and Relocation Class", "description": "A hop sequence reported to this model is admitted as an ordered, terminating trace under an explicit hop budget. RFC 9110 only advises clients to detect cyclical redirections and notes a historical five-redirect recommendation, so the budget and the loop rule must be declared locally rather than assumed. Each hop is classified as permanent relocation, temporary relocation or non-relocating hint, because only the permanent class is even a candidate for promotion into an equivalence proposal.", "source_refs": [ "SRC-023", "SRC-024", "SRC-006" ], "questions": [ { "id": "als-res-q-chain-admission", "text": "How is an externally observed hop sequence admitted, ordered and declared terminated?", "kind": "process", "answer_data": [ "ordered hop list with per-hop observer and observation instant", "termination condition code (terminal endpoint reached, budget exhausted, loop detected, observation failed)", "identity of the observing component and its capture method" ] }, { "id": "als-res-q-hop-budget", "text": "What is the maximum hop budget for a chain and what outcome is emitted when it is exhausted?", "kind": "constraint", "answer_data": [ "declared maximum hop count and where it is configured", "chain-budget-exhausted status on the answer with the partial trace retained", "rule that an unbounded chain is never followed and never silently truncated to a success" ] }, { "id": "als-res-q-loop-detection", "text": "How is a cyclical chain detected, and what is recorded when a loop is found?", "kind": "exception", "answer_data": [ "cycle detection rule over the ordered set of visited endpoints", "loop-detected status plus the repeating endpoint and the hop index of repetition", "retention of the loop trace as evidence for later diagnosis" ] }, { "id": "als-res-q-relocation-class", "text": "How is each hop classified as permanent relocation, temporary relocation or a non-relocating hint?", "kind": "classification", "answer_data": [ "per-hop relocation class code", "source signal used for the classification (permanent relocation response, temporary relocation response, canonical link relation, other registered link relation)", "rule that a temporary relocation never contributes to a permanent equivalence proposal" ] }, { "id": "als-res-q-chain-time-binding", "text": "How is a hop observation bound to the as-of frame of an answer that relies on it?", "kind": "temporal", "answer_data": [ "per-hop observation instant with seconds and explicit offset", "rule that a historical answer may only use hops observed at or before its observation cut-off", "re-observation requirement when the chain is older than the staleness budget" ] } ], "data_elements": [ { "id": "als-res-de-hop-sequence", "name": "Hop sequence", "description": "Ordered list of observed hops, each with source endpoint, target endpoint, signal type and observation instant.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-023", "SRC-006" ] }, { "id": "als-res-de-hop-budget", "name": "Hop budget", "description": "Declared maximum number of hops that may be admitted into one trace.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-023" ] }, { "id": "als-res-de-loop-detected", "name": "Loop detected flag", "description": "Whether a repeated endpoint was found in the ordered trace.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-023" ] }, { "id": "als-res-de-relocation-class", "name": "Relocation class", "description": "Per-hop classification as permanent, temporary or non-relocating hint.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-023", "SRC-024" ] }, { "id": "als-res-de-termination-reason", "name": "Chain termination reason", "description": "Closed code stating why traversal of the trace stopped.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023" ] } ], "artifacts": [ { "id": "als-res-artifact-chain-trace", "name": "Chain observation trace", "description": "Append-only trace of one observed relocation or hint chain: ordered hops, per-hop class and observation instant, budget, termination reason and observing component.", "media_or_form": [ "append-only trace record", "structured hop list", "human-readable trace rendering" ], "serial": true, "identity_strategy": "Identified by the authoritative master-system identifier of the observation run that produced it where the observing system of record assigns one; otherwise a governed IRI, and only failing that a Dimension-assigned UUID or ULID. The hop index is an ordinal within the trace, never an identifier.", "source_refs": [ "SRC-023", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "als-res-finding-hint-evidence", "name": "Transport Hints Are Evidence, Not Identity Proof", "description": "A permanent relocation response, a canonical link relation or a published alsoKnownAs statement is a preference or a claim about where content is served, not a demonstration that two identifiers denote the same real-world subject. RFC 6596 defines canonical as a preferred IRI over duplicative or superset content; RFC 8288 warns against inferring extra semantics from relation types; DID Core states that an alsoKnownAs assertion does not prove itself and advises independent verification and reciprocity. This model therefore captures hints as attributable evidence and requires a separate, authority-backed promotion step before any equivalence assertion exists.", "source_refs": [ "SRC-023", "SRC-024", "SRC-006", "SRC-060" ], "questions": [ { "id": "als-res-q-hint-weight", "text": "What evidential weight may a permanent relocation or canonical link carry towards identifier equivalence?", "kind": "evidence", "answer_data": [ "evidence class and declared weight or confidence contribution", "explicit statement that transport relocation alone does not establish subject identity", "record of which stronger evidence classes are required alongside it" ] }, { "id": "als-res-q-hint-promotion", "text": "What additional confirmation is required before a captured hint becomes a proposed equivalence assertion?", "kind": "validation", "answer_data": [ "reciprocity check outcome where the target publishes a return hint", "named asserting authority willing to stand behind the proposal", "promotion-eligibility flag and the rule that failed checks leave the hint as evidence only" ] }, { "id": "als-res-q-hint-provenance", "text": "Who observed the hint, from which endpoint and in which representation?", "kind": "provenance", "answer_data": [ "observing agent and activity per PROV-O attribution and generation time", "context endpoint the hint was published from", "digest of the captured hint payload and its media form" ] }, { "id": "als-res-q-hint-vocabulary", "text": "Which hint relation vocabularies are recognised, and how are unregistered relation types handled?", "kind": "interoperability", "answer_data": [ "recognised relation types drawn from the IANA Link Relation Types registry", "handling rule for unregistered or extension relation types (captured, never auto-promoted)", "mapping notes for non-HTTP hint mechanisms such as resolver equivalence metadata" ] } ], "data_elements": [ { "id": "als-res-de-hint-relation-type", "name": "Hint relation type", "description": "Registered or extension relation type under which the hint was published.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-024", "SRC-006" ] }, { "id": "als-res-de-hint-observer", "name": "Hint observer", "description": "Agent that captured the hint, attributable per PROV-O.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-res-de-hint-captured-at", "name": "Hint capture instant", "description": "Observation instant at which the hint was captured.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "als-res-de-hint-payload-digest", "name": "Hint payload digest", "description": "Digest over the captured hint payload for integrity and duplicate detection.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-res-de-hint-promotion-eligible", "name": "Promotion eligibility", "description": "Whether the hint has passed the checks required to become a proposed assertion.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-060" ] } ], "artifacts": [ { "id": "als-res-artifact-hint-evidence-item", "name": "Captured hint evidence item", "description": "Attributable capture of one published hint: context endpoint, relation type, target, representation digest, observer and capture instant.", "media_or_form": [ "evidence record", "captured response snapshot", "structured link description" ], "serial": false, "identity_strategy": "Identified by the authoritative master-system identifier of the capture in the observing system of record; otherwise a governed IRI naming context endpoint, relation type and capture instant; only failing that a Dimension-assigned UUID or ULID.", "source_refs": [ "SRC-006", "SRC-009", "SRC-060" ] } ], "inline_only_rationale": null } ] }, { "id": "als-res-layer-change-impact", "name": "Endpoint Change Impact and Readiness Reporting", "description": "How externally decided merges, splits, withdrawals and reinstatements of endpoints propagate into re-evaluation of this model's own assertion population, and how impact and readiness are reported outward.", "source_refs": [ "SRC-061", "SRC-056", "SRC-063" ], "findings": [ { "id": "als-res-finding-merge-split-impact", "name": "Merge, Split and Withdrawal Consequences with Readiness Reporting", "description": "When an endpoint authority merges two identifiers, splits one into several, or withdraws one, the decision is theirs; the consequence for every assertion naming that endpoint is this model's. ROR keeps every identifier resolvable and expresses these events as predecessor and successor relationships that need not be bidirectional, which means a merge or split gives a hint about continuity but not an equivalence. This model records the change event, marks the affected assertions for re-evaluation, enumerates impacted downstream references and emits an impact and readiness report plus notification content.", "source_refs": [ "SRC-061", "SRC-056", "SRC-063" ], "questions": [ { "id": "als-res-q-change-triggers", "text": "Which externally decided endpoint change events are in-scope triggers for cluster re-evaluation?", "kind": "event", "answer_data": [ "change class vocabulary (merge, split, withdrawal, deactivation, reinstatement, namespace relocation)", "reference to the deciding authority's own change record and its effective instant", "ingestion instant at which this model learned of the change" ] }, { "id": "als-res-q-predecessor-successor", "text": "How are predecessor and successor endpoints recorded without themselves being treated as equivalence assertions?", "kind": "relationship", "answer_data": [ "continuity hint fields separate from the assertion store", "explicit non-equivalence note where a split produced several successors", "requirement for a named asserting authority before any successor becomes an assertion" ] }, { "id": "als-res-q-reevaluation-flow", "text": "How is a cluster re-evaluation request raised, tracked and closed?", "kind": "process", "answer_data": [ "re-evaluation request state (raised, in-review, resolved, abandoned) with instants", "set of assertions placed under review and their interim admissibility", "closure decision reference and the resulting assertion state changes" ] }, { "id": "als-res-q-change-ownership", "text": "Who decides the endpoint change, who owns the re-evaluation and who consumes the readiness report?", "kind": "ownership", "answer_data": [ "deciding authority identifier for the endpoint change", "accountable steward for the re-evaluation within the adopting Dimension", "named consumer set for the impact and readiness report" ] }, { "id": "als-res-q-impact-enumeration", "text": "How are impacted downstream references enumerated and how is the change made discoverable to them?", "kind": "interoperability", "answer_data": [ "impacted assertion and answer sets with change type per entry (created, updated, deleted)", "change list interval boundaries expressed as from and until instants", "readiness signal stating whether consumers may migrate yet" ] } ], "data_elements": [ { "id": "als-res-de-change-event-ref", "name": "Endpoint change event reference", "description": "Reference to the externally decided change record at the endpoint's own authority.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-063" ] }, { "id": "als-res-de-change-class", "name": "Change class", "description": "Closed code for the kind of endpoint change.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-056", "SRC-063" ] }, { "id": "als-res-de-impacted-set", "name": "Impacted assertion set", "description": "Enumerated assertions and answers affected by the change, each with a change type.", "value_kind": "collection", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-061" ] }, { "id": "als-res-de-reevaluation-state", "name": "Re-evaluation request state", "description": "Lifecycle state of a cluster re-evaluation request raised by this model.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-063" ] }, { "id": "als-res-de-readiness-signal", "name": "Migration readiness signal", "description": "Whether downstream consumers may act on the change yet, and under which conditions.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-061" ] } ], "artifacts": [ { "id": "als-res-artifact-impact-report", "name": "Change impact and migration readiness report", "description": "Report for one endpoint change event listing impacted assertions and answers, interim admissibility, re-evaluation state and the readiness signal for downstream migration.", "media_or_form": [ "structured report", "human-readable report rendering", "tabular impact listing" ], "serial": true, "identity_strategy": "Identified by the authoritative master-system identifier of the change event in the deciding authority's register combined with this model's report discriminator; otherwise a governed IRI; only failing that a Dimension-assigned UUID or ULID. Edition ordinals are attributes, not identifiers.", "source_refs": [ "SRC-061", "SRC-063" ] }, { "id": "als-res-artifact-change-notice", "name": "Alias change notice", "description": "Notification content describing created, updated and deleted alias entries within a stated time interval, prepared for downstream consumers; delivery is performed elsewhere.", "media_or_form": [ "change list document", "structured notification payload", "human-readable notice" ], "serial": true, "identity_strategy": "Identified by the authoritative master-system identifier of the publishing service's notice register; otherwise a governed IRI incorporating the interval start instant; only failing that a Dimension-assigned UUID or ULID.", "source_refs": [ "SRC-061" ] } ], "inline_only_rationale": null } ] }, { "id": "als-res-layer-contention-control", "name": "Contention, Duplication and Containment", "description": "Controls that keep a federated assertion store consistent when several parties propose, retry or contradict assertions about the same endpoint pair at the same time.", "source_refs": [ "SRC-023", "SRC-009", "SRC-062", "SRC-056" ], "findings": [ { "id": "als-res-finding-concurrency-control", "name": "Concurrent Proposals, Idempotency and Duplicate Detection", "description": "Two proposals about the same endpoint pair may arrive simultaneously, and any one proposal may be retried after an ambiguous failure. Optimistic concurrency with an expected-version precondition rejects a blind overwrite; an idempotency key combined with a request fingerprint distinguishes a retry from a genuinely new proposal and lets the original outcome be replayed. Semantic duplicate detection is separate again, because two textually different payloads can assert the same equivalence.", "source_refs": [ "SRC-023", "SRC-009", "SRC-062" ], "questions": [ { "id": "als-res-q-precondition-token", "text": "Which precondition token must a proposal carry so that a lost update is rejected rather than applied?", "kind": "constraint", "answer_data": [ "expected-version or entity-tag style validator for the targeted assertion", "rejection outcome when the validator does not match current state", "policy on whether an unconditional proposal is refused outright" ] }, { "id": "als-res-q-retry-recognition", "text": "How is a retried proposal recognised as the same operation rather than accepted as a new one?", "kind": "process", "answer_data": [ "idempotency key supplied by the proposing client", "request fingerprint or digest over the proposal payload", "replay behaviour returning the originally computed outcome, success or failure" ] }, { "id": "als-res-q-duplicate-detection", "text": "How is a semantically duplicate assertion detected when its payload differs textually from an existing one?", "kind": "validation", "answer_data": [ "normalised endpoint pair key including direction and authority", "comparison rule over validity interval and asserting authority", "duplicate-of reference recorded on the later proposal instead of a second active assertion" ] }, { "id": "als-res-q-inflight-collision", "text": "What happens when two proposals for the same endpoint pair are in flight at the same moment?", "kind": "exception", "answer_data": [ "conflict outcome for a key already being processed", "serialisation or rejection rule for competing endpoint-pair proposals", "guidance to the loser on safe retry after re-reading current state" ] }, { "id": "als-res-q-key-lifetime", "text": "How long is an idempotency key honoured, and what prevents its reuse with a different payload?", "kind": "security", "answer_data": [ "declared key retention window and expiry behaviour", "rejection outcome when a stored key is presented with a different fingerprint", "scope of key uniqueness (per proposing client, per operation)" ] } ], "data_elements": [ { "id": "als-res-de-expected-version-token", "name": "Expected version token", "description": "Validator naming the assertion state the proposer believed current.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] }, { "id": "als-res-de-idempotency-key", "name": "Idempotency key", "description": "Client-generated key allowing a retry to be recognised as the same operation.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-062" ] }, { "id": "als-res-de-request-fingerprint", "name": "Request fingerprint", "description": "Digest over the proposal payload, paired with the idempotency key to detect key reuse with different content.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-062" ] }, { "id": "als-res-de-duplicate-of", "name": "Duplicate-of reference", "description": "Reference from a rejected duplicate proposal to the surviving assertion.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-res-de-concurrency-outcome", "name": "Concurrency outcome", "description": "Closed code recording how a contended proposal was disposed of.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-062" ] } ], "artifacts": [], "inline_only_rationale": "Concurrency and idempotency data are control fields carried on the proposal and on the resulting assertion state, not documents in their own right. Their whole value lies in being evaluated atomically with the state transition they guard, so materialising them as a separate artifact would introduce a second write that could itself be lost or reordered. The durable output of a contended proposal is the assertion record and the answer record already declared elsewhere in this model." }, { "id": "als-res-finding-conflict-containment", "name": "Conflicting Active Assertions, Compensation and Emergency Quarantine", "description": "Two authorities may hold contradictory active assertions about the same endpoint pair, and a harmful assertion may need to stop influencing answers before its dispute is settled. Following registry practice that identifiers are never deleted and withdrawn items keep resolving to a tombstone that states the reason, containment here suppresses visibility and issues compensating actions while retaining every prior decision and evidence item unchanged.", "source_refs": [ "SRC-009", "SRC-056", "SRC-063" ], "questions": [ { "id": "als-res-q-conflict-states", "text": "What states may a contradictory pair of active assertions be placed in without deleting either?", "kind": "state", "answer_data": [ "conflict set identifier and member assertion references", "per-member containment state (active, contested, suppressed, superseded)", "effect of each state on answer inclusion and on the ambiguity status" ] }, { "id": "als-res-q-quarantine-authority", "text": "Who may raise an emergency quarantine, and on what evidence threshold?", "kind": "authority", "answer_data": [ "named roles entitled to raise quarantine and their delegation basis", "minimum evidence or trigger condition required", "record of the raising agent, activity and instant per PROV-O attribution" ] }, { "id": "als-res-q-quarantine-lifecycle", "text": "How is a quarantine lifted, allowed to expire, or escalated to permanent withdrawal?", "kind": "lifecycle", "answer_data": [ "quarantine expiry instant and default behaviour on expiry", "review outcome codes and the decision reference for each", "transition rule from quarantine to withdrawal with a stated reason" ] }, { "id": "als-res-q-compensation-retention", "text": "What must be retained when an assertion is withdrawn or a prior action is compensated?", "kind": "retention", "answer_data": [ "immutable retention of the superseded assertion, its evidence and the answers that cited it", "compensating action record linking to the action it reverses", "tombstone content stating the identifier, the prior claim and the reason it no longer applies" ] }, { "id": "als-res-q-quarantine-visibility", "text": "Which consumers may still see a quarantined assertion, and in which part of the answer does it appear?", "kind": "access", "answer_data": [ "visibility tier per consumer class (suppressed from candidate set, visible in diagnostics, visible to stewards)", "field placement rule so a suppressed assertion is never silently absent", "statement that enforcement of these tiers is performed by the adopting Dimension's access-control model" ] } ], "data_elements": [ { "id": "als-res-de-conflict-set", "name": "Conflict set", "description": "Group of mutually contradictory assertions about the same endpoint pair, with per-member containment state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-res-de-containment-action", "name": "Containment action", "description": "Closed code for the action taken (contest, suppress, quarantine, withdraw, reinstate).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-056", "SRC-063" ] }, { "id": "als-res-de-compensating-action-ref", "name": "Compensating action reference", "description": "Reference from a compensating action to the earlier action it reverses.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-res-de-quarantine-expiry", "name": "Quarantine expiry instant", "description": "Instant at which a quarantine lapses unless reviewed or escalated.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "als-res-de-retained-decision-ref", "name": "Retained decision reference", "description": "References to every prior decision and evidence item retained through the containment action.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009", "SRC-056" ] } ], "artifacts": [ { "id": "als-res-artifact-containment-record", "name": "Containment and compensation record", "description": "Record of one containment action: conflict set, action taken, raising agent and instant, evidence threshold met, expiry, compensating linkage and the tombstone statement shown in place of the suppressed assertion.", "media_or_form": [ "structured record", "tombstone statement rendering", "append-only decision series entry" ], "serial": true, "identity_strategy": "Identified by the authoritative master-system identifier of the governing case or decision in the steward's system of record; otherwise a governed IRI under the adopting Dimension's namespace; only failing that a Dimension-assigned UUID or ULID.", "source_refs": [ "SRC-009", "SRC-056" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-grole-authority-bundle", "name": "Authority, Delegation and Approval Control", "description": "Who may assert, review and approve an equivalence between identifiers governed by different parties; how their authority is scoped, delegated and time-bounded; how competing authorities are ordered; and what approval an assertion needs before it may be published at a given relation strength.", "rationale": "An equivalence assertion is an act by an agent about identifiers that the agent may not govern. Provenance standards require attribution and delegation to be recorded explicitly, mapping standards separate author, creator, curator and reviewer, and healthcare linkage standards make the asserting author the context for evaluating the link. Without an explicit authority and approval layer, a probabilistic guess and an evidence-backed identity claim are indistinguishable once published.", "source_refs": [ "SRC-009", "SRC-034", "SRC-064", "SRC-065", "SRC-069" ], "layers": [ { "id": "als-grole-authority-layer", "name": "Authority Roles, Delegation and Precedence", "description": "The separated control roles that may act on an assertion, the instruments and time windows that grant their authority, and the rules that order competing or contested authority claims.", "source_refs": [ "SRC-009", "SRC-034", "SRC-065", "SRC-073" ], "findings": [ { "id": "als-grole-role-separation-finding", "name": "Separated control roles, delegation instruments and authority windows", "description": "Distinguishes the control roles that may act on an alias assertion — owner/steward, source authority, target authority, assertion publisher, matching operator, reviewer/adjudicator, policy authority, privacy officer and records authority — and for each records the holding agent, the party on whose behalf it acts, the instrument delegating the authority, the scope of that authority and the instant at which it lapses or requires re-attestation. It also records which role pairs may not be held by the same agent for the same assertion.", "source_refs": [ "SRC-009", "SRC-034", "SRC-065", "SRC-069", "SRC-055" ], "questions": [ { "id": "als-grole-q-role-holder", "text": "Which agent holds each control role for this assertion, and are those roles held by distinct agents?", "kind": "authority", "answer_data": [ "Role code drawn from the model's control-role code list", "Identifier of the holding agent (person, organisation or software agent)", "Flag recording whether the required distinctness between roles is satisfied" ] }, { "id": "als-grole-q-delegation-basis", "text": "On whose behalf does each role holder act, and which instrument delegates that authority?", "kind": "provenance", "answer_data": [ "Identifier of the delegating agent", "Reference to the delegation instrument or mandate record", "Qualified delegation entry naming delegate, delegator and role" ] }, { "id": "als-grole-q-authority-window", "text": "When does each role assignment take effect, and when does it expire or require re-attestation?", "kind": "temporal", "answer_data": [ "Effective time of the role assignment", "Expiry time or re-attestation due time", "Observation time at which this model captured the assignment" ] }, { "id": "als-grole-q-role-scope", "text": "Which namespace, tenant or identifier range does each authority cover, and what lies explicitly outside it?", "kind": "ownership", "answer_data": [ "Authority scope expression (namespace, prefix, tenant or identifier range)", "Explicit exclusions from that scope", "Reference to the register that publishes the scope" ] }, { "id": "als-grole-q-role-independence", "text": "Which role combinations are prohibited for the same agent acting on the same assertion?", "kind": "security", "answer_data": [ "Incompatible role pairs, for example matching operator and reviewer", "Reference to the separation-of-duties rule that forbids the pair", "Recorded outcome when an incompatible combination is detected" ] } ], "data_elements": [ { "id": "als-grole-authority-role-code", "name": "Control role code", "description": "Coded control role held in relation to an assertion, from the model's role list (owner/steward, source authority, target authority, assertion publisher, matching operator, reviewer, policy authority, privacy officer, records authority).", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-034", "SRC-065" ] }, { "id": "als-grole-role-holder-ref", "name": "Role holder reference", "description": "Reference to the agent holding the role, resolvable in the adopting Dimension's agent register.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009", "SRC-065" ] }, { "id": "als-grole-delegation-instrument-ref", "name": "Delegation instrument reference", "description": "Reference to the mandate, contract or attestation under which the holder acts on behalf of another agent.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-grole-authority-effective-time", "name": "Authority effective time", "description": "Instant from which the role assignment is valid, recorded as an event time distinct from the ingestion time of the record.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-069" ] }, { "id": "als-grole-authority-expiry-time", "name": "Authority expiry or re-attestation time", "description": "Instant at which the role assignment lapses or must be re-attested; absence means the assignment is open-ended and subject to periodic review.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-069", "SRC-072" ] }, { "id": "als-grole-authority-scope-expression", "name": "Authority scope expression", "description": "Declared namespace, identifier range, tenant or subject class over which the role holder's authority applies, with explicit exclusions.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-068" ] }, { "id": "als-grole-incompatible-role-pair", "name": "Incompatible role pair", "description": "Pair of control roles that must not be held by the same agent for the same assertion, expressing separation of duties.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-069" ] } ], "artifacts": [ { "id": "als-grole-delegation-instrument-artifact", "name": "Authority delegation instrument", "description": "Attested record that names the delegating authority, the delegate, the role, the scope of authority and its expiry, and that is cited by every assertion the delegate publishes under it.", "media_or_form": [ "Signed or sealed mandate document", "Structured attestation record in an authority register", "Registry entry with delegator, delegate, role, scope and expiry" ], "serial": false, "identity_strategy": "Use the authoritative identifier issued by the mandate or authority register that governs the instrument; if none exists, use a governed IRI in the delegating authority's namespace; only if neither exists, mint a UUID or ULID in the adopting Dimension. A signing date is never used as the identifier.", "source_refs": [ "SRC-009", "SRC-069" ] } ], "inline_only_rationale": null }, { "id": "als-grole-authority-precedence-finding", "name": "Endpoint authority designation, precedence and contest", "description": "How competing authority claims over the same equivalence are ordered: which linked endpoint is designated authoritative source, which is alternate and which is historical; whether a publisher may assert equivalence over identifiers it does not govern and what acknowledgement each endpoint authority gives; which precedence rule resolves conflicting assertions; and how a contested or refuted assertion is represented without silently changing its declared relation strength.", "source_refs": [ "SRC-065", "SRC-073", "SRC-003", "SRC-050", "SRC-034" ], "questions": [ { "id": "als-grole-q-endpoint-designation", "text": "Which linked endpoint is designated authoritative source, which is alternate and which is historical?", "kind": "classification", "answer_data": [ "Endpoint role code (source, alternate, historical)", "Identifier of the authority governing each endpoint", "Reference to the register in which the designation is published" ] }, { "id": "als-grole-q-third-party-assertion", "text": "May a publisher assert equivalence over identifiers it does not govern, and what acknowledgement is required from each endpoint authority?", "kind": "requirement", "answer_data": [ "Identifier of the asserting party", "Acknowledgement state per endpoint authority (unsolicited, notified, acknowledged, disputed)", "Condition under which an unacknowledged assertion may still be published" ] }, { "id": "als-grole-q-precedence-rule", "text": "Which precedence rule resolves conflicting assertions from different authorities, and what is recorded when no rule applies?", "kind": "decision", "answer_data": [ "Reference to the applicable precedence rule", "Selected outcome (source authority prevails, later assertion prevails, both retained as unresolved)", "Recorded reason when no rule applies" ] }, { "id": "als-grole-q-contest-state", "text": "What states may a contested assertion occupy, and does an open contest suspend downstream use?", "kind": "state", "answer_data": [ "Contest state value (uncontested, contested, refuted, resolved)", "Reference to the contest record and the contesting authority", "Suspension flag and the disclosure consequence of suspension" ] }, { "id": "als-grole-q-chain-propagation", "text": "Does an assertion inherit authority when it is chained through another party's equivalence, and how is that inheritance limited?", "kind": "interoperability", "answer_data": [ "Chain propagation flag and the maximum chain depth permitted", "Identifier of each intermediate assertion relied upon", "Declared relation strength ceiling applied to a chained assertion" ] } ], "data_elements": [ { "id": "als-grole-endpoint-role-code", "name": "Endpoint authority role code", "description": "Designation of a linked endpoint as authoritative source, alternate representation or historical representation of the same real-world subject.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-065" ] }, { "id": "als-grole-asserting-party-ref", "name": "Asserting party reference", "description": "Reference to the agent that published the assertion and therefore supplies the context in which the link is to be evaluated.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-065", "SRC-034" ] }, { "id": "als-grole-endpoint-acknowledgement-state", "name": "Endpoint acknowledgement state", "description": "State of each endpoint authority's response to the assertion: unsolicited, notified, acknowledged or disputed.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-065", "SRC-073" ] }, { "id": "als-grole-precedence-rule-ref", "name": "Precedence rule reference", "description": "Reference to the declared rule that orders competing assertions, analogous to a declared conflict strategy in a rights policy.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-073" ] }, { "id": "als-grole-contest-record-ref", "name": "Contest record reference", "description": "Reference to a contest or refutation raised by an endpoint authority or third party, with the contest state it produced.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-050", "SRC-065" ] }, { "id": "als-grole-chain-depth-limit", "name": "Chain propagation limit", "description": "Maximum number of intermediate assertions through which authority may be inherited, and the relation strength ceiling applied to chained results.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-050" ] } ], "artifacts": [], "inline_only_rationale": "Endpoint designation, acknowledgement state, precedence rule reference and contest state are inline reference values carried on the assertion record itself; they are read as attributes by consumers and by an external decision point rather than published as a standalone document. The documents that do result from a contest — the reviewer's adjudication and any retraction — are produced under the approval and records findings, so declaring a separate artifact here would duplicate them and create two competing sources of truth for one decision." } ] }, { "id": "als-grole-approval-layer", "name": "Approval Thresholds and Scoped Exceptions", "description": "The graduated evidence and review required before an assertion may be published at a given relation strength, and the narrow, time-boxed exceptions to that requirement.", "source_refs": [ "SRC-064", "SRC-075", "SRC-003", "SRC-034", "SRC-069" ], "findings": [ { "id": "als-grole-approval-threshold-finding", "name": "Approval tiers keyed to relation strength and evidence class", "description": "Binds each declared relation strength — strict identity, curated exact match, curated close or related match, local alias, unreviewed candidate hint — to a minimum evidence class, a minimum reviewer independence and an approval tier. Strict identity claims require documentary or authority-issued evidence and a reviewer independent of the matching operator and the publisher; weaker relations may be self-approved by the publisher and must then carry the weaker relation strength. It also records what is captured when an approval is refused or an assertion is downgraded, and which changes force re-review.", "source_refs": [ "SRC-064", "SRC-075", "SRC-034", "SRC-012", "SRC-003", "SRC-069" ], "questions": [ { "id": "als-grole-q-evidence-sufficiency", "text": "What evidence class is minimally sufficient to approve each declared relation strength?", "kind": "evidence", "answer_data": [ "Declared relation strength tier", "Minimum evidence class (authority-issued document, deterministic key match, curated lexical match, probabilistic score only)", "Coded justification recorded with the assertion" ] }, { "id": "als-grole-q-reviewer-independence", "text": "Which approvals require a reviewer independent of the matching operator and the publisher, and how is that independence demonstrated?", "kind": "validation", "answer_data": [ "Reviewer independence requirement per approval tier", "Identifier of the reviewing agent and of the matching operator", "Result of the separation-of-duties check performed before approval is recorded" ] }, { "id": "als-grole-q-threshold-calibration", "text": "How is a numeric confidence value interpreted for approval, and who sets and periodically reviews that threshold?", "kind": "measurement", "answer_data": [ "Confidence value and the scale on which it was produced", "Threshold value per approval tier and the authority that set it", "Date of last threshold review and the review cadence" ] }, { "id": "als-grole-q-approval-outcome", "text": "What is recorded when an approval is granted, refused or downgraded to a weaker relation?", "kind": "decision", "answer_data": [ "Approval decision code (approved, refused, downgraded, deferred)", "Resulting relation strength and assurance level after the decision", "Reason text and reference to the evidence considered" ] }, { "id": "als-grole-q-reapproval-trigger", "text": "Which changes to the endpoints, the evidence or the matching method invalidate an existing approval?", "kind": "lifecycle", "answer_data": [ "Trigger list (endpoint deprecation, evidence withdrawal, tool or version change, threshold change)", "State to which the assertion returns when a trigger fires", "Deadline by which re-review must complete" ] } ], "data_elements": [ { "id": "als-grole-relation-strength-tier", "name": "Declared relation strength tier", "description": "The strength of the asserted relation as declared by the publisher, used as the governing input to approval requirements; graduated in the manner of exact, close and related mapping properties.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-034" ] }, { "id": "als-grole-required-evidence-class", "name": "Required evidence class", "description": "Minimum class of evidence that must be present for the declared relation strength to be approved, from authority-issued documentary evidence down to probabilistic score only.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-064", "SRC-034" ] }, { "id": "als-grole-assurance-level-code", "name": "Assurance level code", "description": "Graduated confidence in the asserted identity, aligned to a published four-level assurance scale ranging from little or no confidence to very high confidence.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-075", "SRC-064" ] }, { "id": "als-grole-confidence-threshold-value", "name": "Approval confidence threshold", "description": "Numeric threshold on the reported confidence value below which the corresponding approval tier may not be granted, together with the scale it applies to.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-012" ] }, { "id": "als-grole-approval-tier-code", "name": "Approval tier code", "description": "Required approval route: publisher self-approval, steward approval, or independent review with adjudication.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-069", "SRC-034" ] }, { "id": "als-grole-approval-decision-code", "name": "Approval decision code", "description": "Outcome recorded by the reviewer or adjudicator: approved, refused, downgraded to a weaker relation, or deferred pending evidence.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-012" ] }, { "id": "als-grole-reapproval-trigger", "name": "Re-approval trigger", "description": "Condition whose occurrence invalidates an existing approval and returns the assertion to a pending state.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-069" ] } ], "artifacts": [ { "id": "als-grole-approval-threshold-schedule-artifact", "name": "Approval threshold schedule", "description": "Versioned schedule binding each relation strength tier to its required evidence class, confidence threshold, reviewer independence requirement and approval tier; published by the policy authority and cited by every approval decision.", "media_or_form": [ "Versioned tabular schedule", "Machine-readable rule table", "Published policy statement" ], "serial": false, "identity_strategy": "Use the authoritative identifier issued by the policy authority's document register; if absent, use a governed IRI in the publishing authority's policy namespace with an explicit version segment; only if neither exists, mint a ULID in the adopting Dimension. Version labels are separate from the identifier and an effective date is never the identifier.", "source_refs": [ "SRC-003", "SRC-075", "SRC-069" ] }, { "id": "als-grole-review-decision-record-artifact", "name": "Review decision record", "description": "One record per review event, naming the reviewing agent, the independence check performed, the evidence considered, the decision and the resulting relation strength and assurance level.", "media_or_form": [ "Structured decision record", "Signed adjudication note", "Entry in a review register" ], "serial": true, "identity_strategy": "Use the authoritative identifier issued by the review register that owns the decision; if absent, use a governed IRI in the reviewing organisation's namespace; only if neither exists, mint a ULID. Sequence position within a register is a label, not the identifier.", "source_refs": [ "SRC-034", "SRC-012", "SRC-069" ] } ], "inline_only_rationale": null }, { "id": "als-grole-exception-waiver-finding", "name": "Scoped, time-boxed and reviewable approval exceptions", "description": "An exception permits an assertion to be created or kept in use without the evidence or review its declared relation strength normally requires. Each exception names the requester, the granting policy authority, the exact scope, the mandatory expiry instant, any compensating condition and the post-hoc review due date. An exception may relax an approval requirement; it may never raise the declared relation strength, the recorded assurance level or the evidence class of the assertion it covers, and its presence remains visible on the assertion.", "source_refs": [ "SRC-069", "SRC-073", "SRC-066", "SRC-034" ], "questions": [ { "id": "als-grole-q-exception-trigger", "text": "Which conditions justify granting an exception, and which authority alone may grant it?", "kind": "exception", "answer_data": [ "Coded exception reason (operational continuity, evidence unavailable, regulatory instruction, pilot)", "Identifier of the granting policy authority and the mandate relied upon", "Identifier of the requesting agent" ] }, { "id": "als-grole-q-exception-expiry", "text": "What is the maximum duration of an exception, and what happens automatically when it expires?", "kind": "temporal", "answer_data": [ "Mandatory expiry instant of the exception", "Maximum permitted duration for that exception class", "Default state the assertion returns to at expiry, such as pending re-review or suspended" ] }, { "id": "als-grole-q-exception-invariant", "text": "What must remain unchanged in the assertion while an exception is in force?", "kind": "constraint", "answer_data": [ "Invariant attributes (relation strength, assurance level, evidence class, justification)", "Visibility rule requiring the exception to be disclosed with the assertion", "Rejection outcome recorded if a strengthening change is attempted" ] }, { "id": "als-grole-q-exception-review", "text": "Who reviews granted exceptions after the fact, on what cadence, and what must that review reference?", "kind": "process", "answer_data": [ "Reviewing role and review due date", "Review cadence for the exception class", "References the review must cite: the exception record, the covered assertions and any audit event references" ] } ], "data_elements": [ { "id": "als-grole-exception-reason-code", "name": "Exception reason code", "description": "Coded justification for granting the exception, drawn from a closed list maintained by the policy authority.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-069", "SRC-066" ] }, { "id": "als-grole-exception-granting-authority-ref", "name": "Granting authority reference", "description": "Reference to the policy authority that granted the exception and to the mandate under which it acted.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-073" ] }, { "id": "als-grole-exception-scope-expression", "name": "Exception scope expression", "description": "Precise scope of the exception: the assertions, namespaces, tenants or relation strengths it covers, and everything it does not.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-073", "SRC-068" ] }, { "id": "als-grole-exception-expiry-time", "name": "Exception expiry time", "description": "Mandatory instant at which the exception ceases to have effect; an exception without an expiry is invalid.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-072", "SRC-069" ] }, { "id": "als-grole-compensating-condition", "name": "Compensating condition", "description": "Duty attached to the exception that must be discharged while it is in force, such as restricted disclosure, additional monitoring or mandatory notification.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-073", "SRC-066" ] }, { "id": "als-grole-exception-review-due-date", "name": "Exception review due date", "description": "Date by which the post-hoc review of the granted exception must be completed.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-069", "SRC-055" ] } ], "artifacts": [ { "id": "als-grole-exception-record-artifact", "name": "Exception and waiver record", "description": "One record per granted exception, carrying requester, granting authority, reason, scope, expiry, compensating conditions and review due date, and cited by every assertion that relies on it.", "media_or_form": [ "Structured exception record", "Signed waiver document", "Entry in an exception register" ], "serial": true, "identity_strategy": "Use the authoritative identifier issued by the exception register of the granting authority; if absent, use a governed IRI in that authority's namespace; only if neither exists, mint a ULID in the adopting Dimension. The grant date is metadata, never the identifier.", "source_refs": [ "SRC-069", "SRC-073" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-grole-privacy-records-bundle", "name": "Privacy, Disclosure and Records Control", "description": "How an equivalence assertion is classified for privacy, bounded by purpose and tenant, split into public and restricted disclosure classes, and bound to retention, hold, retraction and provenance-preservation rules — while leaving decision, enforcement, deletion and audit storage to external components.", "rationale": "Linking two identifiers can reveal more than either identifier alone: it can defeat a pseudonym, expose a special category of personal data or reveal a protected location, and standards for cross-organisation person linking already warn that inspecting a linked reference can disclose sensitive facts. Data protection law requires purpose limitation, minimisation, accuracy and storage limitation with demonstrable accountability, and records programmes require a disposition authority and hold discipline. This bundle supplies the classifications, scopes and bindings needed to satisfy those obligations without absorbing the systems that execute them.", "source_refs": [ "SRC-064", "SRC-066", "SRC-070", "SRC-071", "SRC-055", "SRC-072" ], "layers": [ { "id": "als-grole-privacy-classification-layer", "name": "Privacy Classification, Purpose and Tenant Scope", "description": "Classification of the identifiers, labels and matching features as personal, special-category, protected-identity or protected-location data, and the declared purposes, lawful-basis references and tenant boundaries within which the assertion may be used.", "source_refs": [ "SRC-070", "SRC-071", "SRC-074", "SRC-066", "SRC-064" ], "findings": [ { "id": "als-grole-sensitive-identifier-finding", "name": "Personal, special-category, protected-identity and protected-location content", "description": "Classifies each endpoint identifier, label, matching feature and reviewer note as personal data or not, flags any special category revealed by the link, records pseudonymisation state, and marks protected identity or protected location exposure. The controlling concern is emergent: an equivalence can defeat a pseudonym or reveal a sensitive affiliation even when neither endpoint does so alone, so the classification of the assertion is not simply the union of the endpoint classifications.", "source_refs": [ "SRC-070", "SRC-071", "SRC-064", "SRC-066", "SRC-074" ], "questions": [ { "id": "als-grole-q-personal-data-scope", "text": "Which elements of this assertion are personal data, and which of them reveal a special category?", "kind": "privacy", "answer_data": [ "Per-element personal data flag covering identifiers, labels, features and notes", "Special category codes revealed, such as health, biometric, genetic, religious or trade union affiliation", "Reference to the lawful basis or special-category condition relied upon" ] }, { "id": "als-grole-q-reidentification-effect", "text": "Does linking these endpoints defeat a pseudonym or reveal a protected identity that neither endpoint reveals alone?", "kind": "security", "answer_data": [ "Pseudonymisation state of each endpoint", "Re-identification effect assessment for the link itself", "Mitigation applied, such as withholding the link, masking an endpoint or restricting the audience" ] }, { "id": "als-grole-q-protected-location", "text": "Does the assertion expose a protected or restricted location, and at what granularity may that location be disclosed?", "kind": "spatial", "answer_data": [ "Protected location flag and the protection scheme relied upon", "Maximum disclosable granularity, such as region rather than address", "Compartment or audience permitted to receive the finer granularity" ] }, { "id": "als-grole-q-accuracy-correction", "text": "How is an inaccurate or objected-to assertion about a person corrected or suppressed, and within what period?", "kind": "quality", "answer_data": [ "Correction or suppression route and the role that initiates it", "Target period for completing the correction", "Reference to the privacy model record that owns the underlying subject request" ] }, { "id": "als-grole-q-label-combination", "text": "How do the sensitivity labels of the two endpoints combine into the label carried by the assertion?", "kind": "classification", "answer_data": [ "Combination rule, such as taking the most restrictive endpoint label", "Resulting confidentiality and sensitivity labels on the assertion", "Additional label added because of the emergent effect of linking" ] } ], "data_elements": [ { "id": "als-grole-personal-data-flag", "name": "Personal data flag", "description": "Whether the assertion or an identified part of it constitutes personal data relating to an identified or identifiable natural person.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-070", "SRC-074" ] }, { "id": "als-grole-special-category-code", "name": "Special category code", "description": "Coded special category of personal data that the assertion reveals, drawn from the categories enumerated in data protection law.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-071", "SRC-074" ] }, { "id": "als-grole-confidentiality-label", "name": "Confidentiality label", "description": "Graduated confidentiality classification carried by the assertion, aligned to a published confidentiality code system.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-066" ] }, { "id": "als-grole-sensitivity-label", "name": "Sensitivity label", "description": "Non-hierarchical sensitivity marking supporting finer-grained handling than confidentiality alone.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-066" ] }, { "id": "als-grole-pseudonymisation-state", "name": "Pseudonymisation state", "description": "Whether an endpoint identifier is a direct identifier, a pseudonym, or a pseudonym whose linkage key is held separately, and whether the assertion reverses that pseudonymisation.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-070", "SRC-074" ] }, { "id": "als-grole-protected-location-flag", "name": "Protected location exposure flag", "description": "Whether the assertion exposes a location under a protection scheme, together with the maximum granularity that may be disclosed.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-064", "SRC-066" ] } ], "artifacts": [], "inline_only_rationale": "Privacy classification here is a set of labels and flags carried on the assertion and on each evidence element so that an external decision point can act on them as attributes; they are inline values, not a document. The documents that would otherwise be tempting to place here — the impact assessment, the lawful-basis record and the data subject request file — are owned by the referenced privacy model, and reproducing them would give this mixin ownership of privacy programme records it does not administer." }, { "id": "als-grole-purpose-tenant-finding", "name": "Declared purpose, lawful basis reference and tenant isolation", "description": "Records the purposes for which the equivalence may be used, the purposes explicitly excluded, the reference to the authority or lawful basis permitting the processing, and the tenant or compartment inside which the assertion is valid. Cross-tenant reuse is never inherited: it requires an explicit binding naming the receiving tenant, the purpose it may serve and the authority that permitted it.", "source_refs": [ "SRC-070", "SRC-074", "SRC-066", "SRC-069", "SRC-068" ], "questions": [ { "id": "als-grole-q-declared-purpose", "text": "For which declared purposes may this equivalence be used, and which uses are explicitly excluded?", "kind": "privacy", "answer_data": [ "Declared purpose codes", "Explicitly excluded purpose codes", "Reference to the notice or agreement in which the purposes were specified" ] }, { "id": "als-grole-q-lawful-basis-reference", "text": "Which authority or lawful basis permits processing these identifiers for the declared purpose, and where is that record held?", "kind": "authority", "answer_data": [ "Lawful basis or authority-to-process reference", "Identifier of the controller accountable for demonstrating compliance", "Location of the record of processing in the referenced privacy model" ] }, { "id": "als-grole-q-tenant-boundary", "text": "Within which tenant, compartment or community is this assertion valid, and what is required to use it outside that boundary?", "kind": "access", "answer_data": [ "Tenant scope reference and any compartment codes", "Cross-tenant binding requirement and the authority that must grant it", "Behaviour when an assertion is encountered outside its tenant scope" ] }, { "id": "als-grole-q-secondary-use", "text": "How is a request to use the equivalence for a purpose that was not originally declared assessed and recorded?", "kind": "decision", "answer_data": [ "Compatibility assessment outcome for the new purpose", "Deciding authority and the date of the decision", "Resulting change to the declared or excluded purpose list" ] } ], "data_elements": [ { "id": "als-grole-declared-purpose-code", "name": "Declared purpose code", "description": "Coded purpose for which the equivalence assertion may be processed, drawn from a governed purpose taxonomy.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-070", "SRC-074" ] }, { "id": "als-grole-excluded-purpose-code", "name": "Excluded purpose code", "description": "Purpose for which use of the assertion is explicitly forbidden, expressed so that a decision point can act on it.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-074", "SRC-073" ] }, { "id": "als-grole-lawful-basis-ref", "name": "Lawful basis or authority-to-process reference", "description": "Reference to the externally held record establishing the authority or legal basis for processing the identifiers involved.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-069", "SRC-070" ] }, { "id": "als-grole-tenant-scope-ref", "name": "Tenant scope reference", "description": "Reference to the tenant, organisation or data space within which the assertion is valid and beyond which it must not be resolved by default.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-066", "SRC-068" ] }, { "id": "als-grole-compartment-code", "name": "Compartment code", "description": "Marking that restricts the assertion to a defined community, project or care setting inside the tenant.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-066" ] }, { "id": "als-grole-cross-tenant-binding-ref", "name": "Cross-tenant binding reference", "description": "Explicit binding permitting a named other tenant to use the assertion for a named purpose, with the granting authority and validity window.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-073", "SRC-068" ] } ], "artifacts": [], "inline_only_rationale": "Purpose codes, exclusions, tenant scope and compartment markings are scoping parameters attached to the assertion and consumed as attributes by an external decision point; they generate no document of their own. The instruments they point at — the privacy notice, the lawful-basis record, the records of processing and any data sharing agreement — are held and versioned by the referenced privacy and agreement models, so this finding carries references and subject-specific parameters only." } ] }, { "id": "als-grole-disclosure-access-layer", "name": "Disclosure Separation and Access Scoping", "description": "Separation of the publishable equivalence statement from restricted matching evidence, features and reviewer material, the scope levels at which each may be released, and the declarations an external decision point consumes.", "source_refs": [ "SRC-072", "SRC-066", "SRC-067", "SRC-069", "SRC-073" ], "findings": [ { "id": "als-grole-disclosure-scope-finding", "name": "Public mapping, restricted evidence and access scoping declarations", "description": "Splits an assertion into disclosure classes — the public equivalence statement, the private matching evidence and features, the reviewer notes, and reviewer identity — and declares for each which audience may receive it, at which scope level (bundle, layer, finding or artifact), with which handling obligation such as masking or redaction, and under which emergency release condition. Every declaration is an attribute or obligation statement consumed by an external decision and enforcement point; this model publishes no permit or deny result and executes no enforcement.", "source_refs": [ "SRC-072", "SRC-066", "SRC-064", "SRC-067", "SRC-069", "SRC-073" ], "questions": [ { "id": "als-grole-q-disclosure-class", "text": "Which parts of the assertion are publishable, and which remain restricted evidence or reviewer material?", "kind": "access", "answer_data": [ "Disclosure class per part (public statement, restricted evidence, restricted features, reviewer notes)", "Default class applied when none is declared", "Audience codes permitted for each class" ] }, { "id": "als-grole-q-scope-granularity", "text": "At which scope — bundle, layer, finding or artifact — is each restricted part released, and what is the smallest grant that meets a legitimate need?", "kind": "requirement", "answer_data": [ "Scope level at which the grant is expressed", "Minimum grant satisfying the stated need, expressing least privilege", "Operations permitted at that scope, such as read of metadata only" ] }, { "id": "als-grole-q-reviewer-visibility", "text": "Is the reviewer's identity published with the decision, pseudonymised or withheld, and what condition reveals it?", "kind": "privacy", "answer_data": [ "Reviewer visibility mode (published, pseudonymised, withheld)", "Condition and authority under which the identity may be revealed", "Audience entitled to the revealed identity" ] }, { "id": "als-grole-q-emergency-release", "text": "Who may invoke emergency release of restricted evidence, which purpose of use must be declared, and when does that grant lapse?", "kind": "exception", "answer_data": [ "Roles entitled to invoke emergency release", "Purpose-of-use value that must accompany the invocation", "Lapse instant of the grant and the mandatory post-hoc review reference" ] }, { "id": "als-grole-q-decision-boundary", "text": "What does this model publish in place of an allow or deny result, and which component consumes it?", "kind": "decision", "answer_data": [ "Attribute set published for the decision point (classification, purpose, tenant, disclosure class)", "Obligation references that an enforcement point must discharge, such as mask or redact", "Identifier of the external decision point relied upon" ] } ], "data_elements": [ { "id": "als-grole-disclosure-class-code", "name": "Disclosure class code", "description": "Class assigned to each part of the assertion determining whether it is publishable or restricted: public statement, restricted evidence, restricted feature, reviewer note or reviewer identity.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-072", "SRC-066" ] }, { "id": "als-grole-audience-scope-code", "name": "Audience code", "description": "Audience permitted to receive a given disclosure class, such as public, tenant member, endpoint authority, reviewer, regulator or data subject.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-066", "SRC-068" ] }, { "id": "als-grole-scope-level-code", "name": "Grant scope level", "description": "Level at which a disclosure grant is expressed: bundle, layer, finding or artifact.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-069", "SRC-067" ] }, { "id": "als-grole-handling-obligation-code", "name": "Handling obligation code", "description": "Obligation that travels with a disclosure, such as mask, redact, encrypt, no onward disclosure without consent or no reuse.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-066", "SRC-067", "SRC-073" ] }, { "id": "als-grole-reviewer-visibility-mode", "name": "Reviewer visibility mode", "description": "Whether the reviewing agent's identity is published with the decision, pseudonymised, or withheld pending a named condition.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-072", "SRC-034" ] }, { "id": "als-grole-emergency-release-descriptor", "name": "Emergency release descriptor", "description": "Declaration of who may invoke emergency release, what it unlocks, the purpose of use it must declare, its lapse instant and the review it triggers.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-066", "SRC-069" ] }, { "id": "als-grole-external-decision-point-ref", "name": "External decision point reference", "description": "Reference to the authorization decision point that consumes these declarations; recorded so that the boundary of responsibility is explicit and resolvable.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-067", "SRC-068" ] } ], "artifacts": [ { "id": "als-grole-disclosure-profile-artifact", "name": "Disclosure profile", "description": "Versioned declarative profile mapping disclosure class by audience and scope level to the permitted projection and the handling obligations that accompany it; published by the owner package and read by the external decision and enforcement points. It is a declaration of what may be released, never a record of a decision taken.", "media_or_form": [ "Versioned profile document", "Machine-readable rule table", "Published disclosure notice" ], "serial": false, "identity_strategy": "Use the authoritative identifier issued by the owner package's document register; if absent, use a governed IRI in the publishing Dimension's policy namespace including an explicit version segment; only if neither exists, mint a ULID. Effective dates and version labels are attributes, not identifiers.", "source_refs": [ "SRC-072", "SRC-066", "SRC-073" ] } ], "inline_only_rationale": null } ] }, { "id": "als-grole-records-layer", "name": "Retention, Hold, Retraction and Provenance Preservation", "description": "Binding of this model's own records to a retention class and disposition authority, the hold discipline that suspends disposition, and the retraction and tombstone rules that keep withdrawal detectable while preserving provenance.", "source_refs": [ "SRC-055", "SRC-069", "SRC-070", "SRC-009", "SRC-065" ], "findings": [ { "id": "als-grole-retention-hold-finding", "name": "Retention class, disposition authority citation and hold state", "description": "Binds each record this model owns — the assertion, its evidence, the review decision and the exception record — to a retention class and a citation of the disposition authority that governs it, and records the current hold state with the agent that applied it and the instant it took effect. The binding and the hold reference live here; approving the schedule, executing destruction or transfer, and lifting a hold are performed by the records authority.", "source_refs": [ "SRC-055", "SRC-069", "SRC-070", "SRC-074" ], "questions": [ { "id": "als-grole-q-retention-class", "text": "Which retention class and disposition authority govern the assertion, its evidence and its review record?", "kind": "retention", "answer_data": [ "Retention class code per record kind", "Citation of the approved disposition authority", "Retention period start event, such as approval or last use" ] }, { "id": "als-grole-q-hold-state", "text": "What is the current hold state, who applied it, and what evidence is required to lift it?", "kind": "state", "answer_data": [ "Hold state value (none, applied, lifted)", "Identifier of the applying authority and the event time of application", "Reference to the hold notice and the condition for lifting it" ] }, { "id": "als-grole-q-differential-retention", "text": "May private evidence be disposed of earlier than the published mapping, and what must survive that disposal?", "kind": "constraint", "answer_data": [ "Separate retention classes for evidence and for the published statement", "Minimum surviving record after evidence disposal, such as justification code and approval reference", "Effect on the assertion's assurance level once supporting evidence is gone" ] }, { "id": "als-grole-q-disposition-execution", "text": "Which system executes destruction or transfer, and what remains in this model afterwards?", "kind": "process", "answer_data": [ "Identifier of the executing records system or programme", "Confirmation reference returned after disposition", "Residual record retained locally, such as a tombstone and disposition citation" ] } ], "data_elements": [ { "id": "als-grole-retention-class-code", "name": "Retention class code", "description": "Coded retention class assigned to a record kind owned by this model, referencing the schedule that defines its period and disposition action.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-055", "SRC-069" ] }, { "id": "als-grole-disposition-authority-citation", "name": "Disposition authority citation", "description": "Citation of the approved authority that permits eventual disposal or transfer of the record, held as a resolvable identifier rather than reproduced text.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055" ] }, { "id": "als-grole-hold-state-code", "name": "Hold state code", "description": "Whether a legal hold or freeze currently suspends disposition of the record.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055" ] }, { "id": "als-grole-hold-applied-by-ref", "name": "Hold applying authority reference", "description": "Reference to the authority that applied or lifted the hold, together with the notice it relied upon.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055", "SRC-009" ] }, { "id": "als-grole-hold-effective-time", "name": "Hold effective time", "description": "Event time at which the hold took effect, recorded separately from the time this model ingested the hold notice.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055", "SRC-009" ] }, { "id": "als-grole-evidence-retention-class-code", "name": "Evidence retention class code", "description": "Retention class applied specifically to private matching evidence, features and reviewer notes, which may be shorter than that of the published statement.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-070", "SRC-055" ] } ], "artifacts": [], "inline_only_rationale": "Retention class, disposition authority citation and hold state are reference values bound to records this model owns; the governing documents — the approved retention schedule, the disposition authority instrument and the hold or freeze notice — are created, versioned and executed by the records authority. Reproducing them locally would create a second, unauthoritative copy of a records-programme artifact and would imply that this model can approve or lift a hold, which it cannot." }, { "id": "als-grole-retraction-tombstone-finding", "name": "Retraction, tombstone content and preserved provenance", "description": "Withdrawal of an assertion is an event, not an erasure: it produces a retraction record naming the retracting authority, the reason and the event time, and leaves a tombstone that lets downstream consumers detect that a previously published equivalence no longer holds. The tombstone carries the assertion identifier, the retraction reason, any superseding assertion and the audit event reference, while the substantive evidence may already have been disposed of under its own retention class.", "source_refs": [ "SRC-009", "SRC-065", "SRC-055", "SRC-072", "SRC-070" ], "questions": [ { "id": "als-grole-q-retraction-trigger", "text": "What causes an assertion to be withdrawn, and which authority may withdraw it?", "kind": "event", "answer_data": [ "Retraction reason code (error, refutation, endpoint retirement, legal instruction, expiry of exception)", "Identifier of the retracting authority and its mandate", "Event time of the retraction and its ingestion time" ] }, { "id": "als-grole-q-tombstone-content", "text": "What minimum record survives withdrawal so that downstream consumers can detect it?", "kind": "identity", "answer_data": [ "Retained assertion identifier and its version", "Retraction status value and effective instant", "Fields deliberately omitted from the tombstone for privacy reasons" ] }, { "id": "als-grole-q-provenance-preservation", "text": "Which provenance of the withdrawn assertion must be preserved, and under whose retention rule?", "kind": "provenance", "answer_data": [ "Preserved attribution: publisher, matching operator, reviewer and approval reference", "Invalidating activity and the agent responsible for it", "Retention class that governs the preserved provenance and any audit event reference" ] }, { "id": "als-grole-q-supersession-path", "text": "Is the withdrawn assertion replaced by a corrected one, and how is that replacement expressed?", "kind": "lifecycle", "answer_data": [ "Identifier of the superseding assertion, if any", "Revision or derivation relation between the two records", "Guidance to consumers on which record is now current" ] } ], "data_elements": [ { "id": "als-grole-retraction-reason-code", "name": "Retraction reason code", "description": "Coded reason for withdrawing the assertion, drawn from a closed list maintained by the owner package.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-065", "SRC-009" ] }, { "id": "als-grole-retraction-event-time", "name": "Retraction event time", "description": "Instant at which the assertion ceased to be valid, recorded separately from the instant this model ingested the retraction.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-072" ] }, { "id": "als-grole-tombstone-status", "name": "Tombstone status value", "description": "Status carried by the surviving record indicating that the assertion was withdrawn rather than never published.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-065", "SRC-072" ] }, { "id": "als-grole-superseding-assertion-ref", "name": "Superseding assertion reference", "description": "Reference to a corrected assertion that replaces the withdrawn one, expressed as a revision relation.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-grole-preserved-provenance-ref", "name": "Preserved provenance reference", "description": "References to the attribution, approval and invalidation records preserved after withdrawal, including the responsible agents.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-055" ] }, { "id": "als-grole-audit-event-ref", "name": "Audit event reference", "description": "Reference to the audit event recorded in the external audit store for the retraction; the reference only, never the audit record itself.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-069", "SRC-066" ] } ], "artifacts": [ { "id": "als-grole-retraction-notice-artifact", "name": "Retraction notice and tombstone", "description": "One record per withdrawal, carrying the withdrawn assertion identifier and version, the retraction reason, the retracting authority, the event time, any superseding assertion and the preserved provenance references; published so that consumers who previously received the assertion can detect the withdrawal.", "media_or_form": [ "Structured retraction record", "Published notice to prior recipients", "Tombstone entry in the assertion register" ], "serial": true, "identity_strategy": "Use the authoritative identifier issued by the assertion register that owns the withdrawn record; if absent, use a governed IRI derived from the withdrawn assertion's IRI plus a retraction segment; only if neither exists, mint a ULID. The retraction date is recorded as an event time, never used as the identifier.", "source_refs": [ "SRC-009", "SRC-065", "SRC-072" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-gplat-representation-interoperability", "name": "Representation, Projection and Interoperability", "description": "How one format-neutral alias set is expressed across storage bindings, interfaces and external equivalence vocabularies, and how every loss, weakening and unsupported relation kind incurred by each expression is declared before publication.", "rationale": "DCAT separates a dataset from its distributions, and SSSOM mandates only one serialization while permitting implementations to discard unknown slots on read; CSVW minimal mode strips structural framing. Every published form is therefore a lossy or lossless distribution whose fidelity must be measured, not assumed, and external vocabularies (SKOS, OWL 2, alsoKnownAs) carry different and partly incompatible strengths.", "source_refs": [ "SRC-082", "SRC-034", "SRC-087", "SRC-083", "SRC-003", "SRC-076", "SRC-081" ], "layers": [ { "id": "als-gplat-projection-neutrality-layer", "name": "Storage and Interface Projection Neutrality", "description": "Declares each supported storage and interface binding as a distribution of the same format-neutral alias set, states what each can carry, and maintains an evidence-backed register of what each loses on a write-then-read cycle.", "source_refs": [ "SRC-082", "SRC-034", "SRC-087", "SRC-083", "SRC-080" ], "findings": [ { "id": "als-gplat-projection-capability-matrix", "name": "Storage and Interface Projection Capability Matrix", "description": "A per-projection capability declaration covering Git-tracked file trees, MCP server resources, document-store collections, RDF graphs, tabular exports and HTTP APIs. For each projection it states which alias features are carried natively, which require an accompanying metadata document, which are unsupported, and which single projection is normative when two disagree. The matrix exists because a projection is a distribution of the alias set, never a variant of its meaning.", "source_refs": [ "SRC-082", "SRC-034", "SRC-087", "SRC-083", "SRC-080" ], "questions": [ { "id": "als-gplat-q-projection-inventory", "text": "Which storage and interface projections are declared conformant for this alias set, and which alias features can each carry natively?", "kind": "interoperability", "answer_data": [ "Projection identifier and binding kind (file tree, MCP resource, document collection, RDF graph, tabular export, HTTP API)", "Per-feature capability flag: native, requires-companion-metadata, or unsupported", "Declared conformance level and the schema version the projection is pinned to" ] }, { "id": "als-gplat-q-companion-metadata", "text": "Which accompanying metadata document must travel with a projection that cannot embed alias-set metadata inline?", "kind": "composition", "answer_data": [ "Metadata embedding mode: embedded block or external document", "Reference to the external metadata document and its edition", "Binding rule stating that the projection is invalid when read without its companion metadata" ] }, { "id": "als-gplat-q-normative-projection", "text": "Which projection is normative when two projections of the same alias set disagree?", "kind": "constraint", "answer_data": [ "Designated normative projection identifier", "Ordered precedence list for the remaining projections", "Divergence handling rule and the defect class raised on disagreement" ] }, { "id": "als-gplat-q-projection-evidence", "text": "What conformance evidence shows that a projection preserves the alias features it claims to carry?", "kind": "validation", "answer_data": [ "Reference to the conformance test suite and the corpus edition used", "Test run outcome per declared feature, with pass, fail or waived status", "RFC 3339 timestamp of the run and the tool plus version that produced it" ] } ], "data_elements": [ { "id": "als-gplat-de-projection-descriptor", "name": "Projection descriptor", "description": "Identifies one declared storage or interface binding of the alias set, including its binding kind and the schema version it is pinned to.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-082", "SRC-034" ] }, { "id": "als-gplat-de-capability-flag", "name": "Feature capability flag", "description": "Per alias feature and per projection, whether the feature is carried natively, requires a companion metadata document, or is unsupported.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-083", "SRC-087" ] }, { "id": "als-gplat-de-normative-projection", "name": "Normative projection designation", "description": "The single projection that resolves disagreement between distributions of the same alias set, plus the precedence order for the rest.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-082" ] } ], "artifacts": [ { "id": "als-gplat-art-capability-matrix", "name": "Projection capability matrix", "description": "Machine-readable matrix of alias features against declared projections, with capability flags, companion-metadata requirements, precedence order and the pinned schema version.", "media_or_form": [ "Structured table serialized in any supported projection", "Distribution description attached to the alias-set catalogue record" ], "serial": false, "identity_strategy": "Governed IRI in a namespace the owner package controls; no master-system identifier exists for this artifact, so tier two of the identity priority applies. The matrix filename and schema version are never its identity.", "source_refs": [ "SRC-082", "SRC-084", "SRC-034" ] } ], "inline_only_rationale": null }, { "id": "als-gplat-roundtrip-loss-register", "name": "Round-Trip and Information-Loss Register", "description": "An evidence-backed inventory of every information loss, semantic weakening, unsupported relation kind and round-trip limitation observed when an alias set is written to and re-read from each declared projection. Each entry names the affected feature, the projection, whether the loss is detectable by the reader, and the compensating carrier if one exists. Publication of a projection is blocked until its losses are declared here.", "source_refs": [ "SRC-087", "SRC-083", "SRC-080", "SRC-077", "SRC-034" ], "questions": [ { "id": "als-gplat-q-loss-inventory", "text": "Which alias features are lost or silently weakened on each declared write-then-read cycle?", "kind": "quality", "answer_data": [ "Lost or weakened feature name and the projection that causes it", "Loss class: dropped, coerced, flattened, reordered, or semantically weakened", "Detectability flag stating whether a reader can notice the loss without the source", "Compensating carrier reference, or an explicit statement that none exists" ] }, { "id": "als-gplat-q-loss-evidence", "text": "What round-trip test corpus and result set demonstrate that the loss inventory is current?", "kind": "evidence", "answer_data": [ "Test corpus reference and edition serial", "Result set with per-case source and re-read canonical digests", "RFC 3339 run timestamp and the implementation plus version under test" ] }, { "id": "als-gplat-q-unknown-slot-handling", "text": "What must an implementation do when it encounters a non-standard slot or an unsupported relation kind it cannot represent?", "kind": "exception", "answer_data": [ "Required behaviour: discard-and-report, refuse, or route to an extension carrier", "The loss-register entry the discard must be recorded against", "Notice returned to the caller naming the discarded keys or columns" ] }, { "id": "als-gplat-q-lossy-publication-decision", "text": "On what basis may a lossy projection still be accepted for publication rather than rejected?", "kind": "decision", "answer_data": [ "Acceptance criteria and the severity threshold applied", "Approving role and the reference to the approval record", "Mitigation or companion-metadata requirement attached to the acceptance" ] } ], "data_elements": [ { "id": "als-gplat-de-loss-entry", "name": "Loss register entry", "description": "One declared information loss or semantic weakening, bound to a feature, a projection, a loss class and a detectability flag.", "value_kind": "object", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-087", "SRC-083" ] }, { "id": "als-gplat-de-roundtrip-verdict", "name": "Round-trip fidelity verdict", "description": "Result of comparing the canonical form of a source alias set with the canonical form of the same set after a write-then-read cycle through a projection.", "value_kind": "code", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-077", "SRC-088" ] }, { "id": "als-gplat-de-compensating-carrier", "name": "Compensating carrier reference", "description": "The companion metadata document, extension slot or annotation that preserves a feature the projection cannot carry natively.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-083", "SRC-087" ] } ], "artifacts": [ { "id": "als-gplat-art-loss-register", "name": "Round-trip loss register", "description": "Published register of declared losses, weakenings and unsupported relation kinds per projection, with detectability and compensating carriers.", "media_or_form": [ "Structured register serialized in any supported projection", "Human-readable release note derived from the same register" ], "serial": true, "identity_strategy": "Governed IRI for the register plus an opaque monotonic edition sequence assigned by the owner package; the sequence is not a date and the register digest is not its identity.", "source_refs": [ "SRC-087", "SRC-084", "SRC-088" ] }, { "id": "als-gplat-art-roundtrip-corpus", "name": "Round-trip conformance corpus", "description": "Fixture alias sets exercising every declared feature, including graded matches, negated assertions, multi-valued slots, non-ASCII labels, extension slots and blank-node-bearing RDF fragments, with expected canonical forms.", "media_or_form": [ "Fixture collection with expected canonical forms and digests", "Test manifest binding each fixture to the features it exercises" ], "serial": true, "identity_strategy": "Governed IRI plus an opaque monotonic edition sequence; individual fixtures carry Dimension-assigned UUIDs only where no governed IRI is warranted.", "source_refs": [ "SRC-077", "SRC-088", "SRC-078" ] } ], "inline_only_rationale": null } ] }, { "id": "als-gplat-semantic-binding-layer", "name": "External Predicate Binding and Semantic Fidelity", "description": "Binds internal alias strength to predicates in external equivalence vocabularies, records the downgrade or refusal applied when the target cannot carry a feature, and controls the entailment and reciprocity risks that binding creates.", "source_refs": [ "SRC-003", "SRC-076", "SRC-081", "SRC-034", "SRC-030" ], "findings": [ { "id": "als-gplat-predicate-binding-profile", "name": "External Equivalence Predicate Binding Profile", "description": "The declared mapping from each internal alias strength and kind to a predicate in a target vocabulary — owl:sameAs for strict individual identity, skos:exactMatch or skos:closeMatch for graded concept-level matches, alsoKnownAs for unverified subject-level claims, and an SSSOM predicate_id with an optional predicate_modifier for interchange — together with the exact downgrade recorded whenever the target predicate is weaker or the alias feature is inexpressible. Bindings are alignments, not conformance claims.", "source_refs": [ "SRC-003", "SRC-076", "SRC-081", "SRC-034" ], "questions": [ { "id": "als-gplat-q-predicate-selection", "text": "Which target-vocabulary predicate is bound to each internal alias strength, and how is negation expressed?", "kind": "classification", "answer_data": [ "Internal alias strength or kind", "Bound target predicate IRI and target vocabulary version", "Negation or modifier term used to express an explicit non-equivalence" ] }, { "id": "als-gplat-q-disjointness-constraints", "text": "Which predicate combinations are prohibited because the target vocabulary declares them disjoint?", "kind": "constraint", "answer_data": [ "Prohibited predicate pair and the integrity condition that forbids it", "Detection rule applied before export", "Required resolution: withhold, re-classify, or split the assertion" ] }, { "id": "als-gplat-q-inexpressible-feature-carriage", "text": "How is an alias feature the target vocabulary cannot express carried alongside the exported statement?", "kind": "interoperability", "answer_data": [ "Inexpressible feature name, for example confidence, validity interval or asserting authority", "Carriage mechanism: reified annotation, companion mapping-set metadata, or omission", "Loss-register entry the omission is recorded against" ] }, { "id": "als-gplat-q-binding-approval-authority", "text": "Who may approve a binding that would export an assertion under a stronger predicate than the internal strength?", "kind": "authority", "answer_data": [ "Approving role and the scope of the delegation", "Reference to the approval record and its RFC 3339 decision time", "Default outcome when no approval exists, namely refusal to export" ] } ], "data_elements": [ { "id": "als-gplat-de-binding-entry", "name": "Predicate binding entry", "description": "One declared correspondence between an internal alias strength and a target-vocabulary predicate, with the target vocabulary version.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-076", "SRC-034" ] }, { "id": "als-gplat-de-downgrade-note", "name": "Semantic downgrade note", "description": "Records that an exported statement is weaker than the internal assertion, or that a feature was dropped, with the reason and the affected feature.", "value_kind": "text", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-003", "SRC-081" ] }, { "id": "als-gplat-de-predicate-modifier", "name": "Predicate modifier", "description": "Qualifier that negates or otherwise conditions the bound predicate, so that an explicit non-equivalence is not exported as an equivalence.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-076" ] } ], "artifacts": [ { "id": "als-gplat-art-binding-profile", "name": "Predicate binding profile", "description": "Declarative profile binding internal alias strengths to target-vocabulary predicates, with disjointness prohibitions, downgrade table and inexpressible-feature carriage rules.", "media_or_form": [ "Declarative mapping profile in any supported projection", "Context or vocabulary-alignment document consumable by an export tool" ], "serial": true, "identity_strategy": "Governed IRI in the owner package's namespace plus an opaque monotonic edition sequence; target vocabulary versions are referenced, never re-minted.", "source_refs": [ "SRC-084", "SRC-003", "SRC-034" ] } ], "inline_only_rationale": null }, { "id": "als-gplat-entailment-reciprocity-controls", "name": "Entailment and Reciprocity Risk Controls", "description": "The guard settings that prevent an export from creating inference the alias record does not support. owl:sameAs licenses full substitution and unlimited closure; skos:exactMatch is symmetric and transitive within the mapping vocabulary but entails no individual identity; alsoKnownAs asserts nothing verified in the absence of a reciprocating assertion in the other subject's document. These controls set the thresholds and refusal conditions applied at export time and the invalidation signal sent when a previously exported equivalence is retracted.", "source_refs": [ "SRC-003", "SRC-076", "SRC-081", "SRC-030" ], "questions": [ { "id": "als-gplat-q-closure-licensed", "text": "Which entailment closure does each bound predicate license in the consuming system?", "kind": "constraint", "answer_data": [ "Bound predicate and the closure properties it carries: symmetry, transitivity, substitution", "Maximum cluster size or closure depth accepted before human review", "Statement of what the internal assertion does and does not warrant" ] }, { "id": "als-gplat-q-reciprocity-requirement", "text": "What reciprocity evidence is required before an incoming third-party equivalence claim may be treated as equivalence?", "kind": "requirement", "answer_data": [ "Reciprocity status: reciprocated, unreciprocated, or unverifiable", "Reference to the reciprocating document and its retrieval time", "Downgraded internal strength applied while reciprocity is pending" ] }, { "id": "als-gplat-q-strengthening-guard", "text": "What guard prevents a graded or low-confidence alias from being emitted under a strict identity predicate?", "kind": "security", "answer_data": [ "Minimum confidence and justification class required for a strict-identity export", "Guard outcome: emit, downgrade, or withhold", "Record of every withheld alias with the reason code" ] }, { "id": "als-gplat-q-retraction-invalidation", "text": "How is a consumer of a previously exported equivalence notified when that equivalence is retracted or contested?", "kind": "event", "answer_data": [ "Invalidation signal kind and the projections it must be issued to", "Reference to the superseding or retracting record and its event time", "Cache and redirect regeneration obligation triggered by the signal" ] } ], "data_elements": [ { "id": "als-gplat-de-closure-license", "name": "Closure licence declaration", "description": "Per bound predicate, the entailment closure the consuming system is expected to perform and the limit beyond which review is required.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-076", "SRC-003" ] }, { "id": "als-gplat-de-reciprocity-status", "name": "Reciprocity status", "description": "Whether an equivalence claim made about a subject is reciprocated in the counterpart's own controlling document, and when that was checked.", "value_kind": "code", "cardinality": "0..1", "required": true, "source_refs": [ "SRC-081" ] }, { "id": "als-gplat-de-export-guard-outcome", "name": "Export guard outcome", "description": "The emit, downgrade or withhold decision applied to a single alias at export time, with its reason code.", "value_kind": "code", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-030", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "These are inline threshold and guard parameters evaluated per export request against the predicate binding profile; they are decision inputs, not a separately published document. Emitting them as their own artifact would create a second copy that drifts from the binding profile it must be read with, and would misrepresent ownership: the guard is applied by the referenced export and validation runtime, which owns execution, while this model owns only the parameter values and the recorded outcome." } ] }, { "id": "als-gplat-resolution-projection-layer", "name": "Resolution and Redirect Projection", "description": "How an alias set is expressed as resolvable web behaviour — status-code binding, Location targets, namespace layout and cache validity — while the service that executes the behaviour remains outside this model.", "source_refs": [ "SRC-023", "SRC-084", "SRC-082" ], "findings": [ { "id": "als-gplat-redirect-projection-binding", "name": "Redirect and Resolution Projection Binding", "description": "Binds alias status to HTTP behaviour: a superseded identifier whose canonical replacement is settled maps to a permanent redirect (301 or 308), a provisional or under-review equivalence maps to a temporary redirect (302 or 307), and a slash-namespace term that denotes a non-information resource is served with 303 See Other. Graded matches are never projected as permanent redirects. This model emits a server-agnostic redirect rule set and cache directives; the HTTP service that executes them is a referenced neighbour.", "source_refs": [ "SRC-023", "SRC-084", "SRC-003", "SRC-082" ], "questions": [ { "id": "als-gplat-q-status-binding", "text": "Which HTTP status class is bound to each alias status, and what is the Location target?", "kind": "interoperability", "answer_data": [ "Alias status and the bound status code with its permanence semantics", "Location target IRI, drawn from the canonical-identifier selection", "Explicit exclusion list of alias strengths that must not be redirected at all" ] }, { "id": "als-gplat-q-namespace-write-authority", "text": "Who holds write authority over the namespace whose URIs a redirect projection claims to govern?", "kind": "ownership", "answer_data": [ "Namespace stem and the authority holding write access to it", "Evidence of delegation where the authority is not the owner package", "Refusal rule for emitting redirects into a namespace the owner package does not control" ] }, { "id": "als-gplat-q-redirect-execution-split", "text": "What does this model emit for redirect behaviour, and which system actually performs the redirect?", "kind": "process", "answer_data": [ "Emitted rule-set form and its projection binding", "Named executing system or service class, held as a reference", "Statement that request handling, content negotiation execution and logging are outside this model" ] }, { "id": "als-gplat-q-redirect-cache-validity", "text": "How long may a redirect projection be cached, and when must it be regenerated after an alias change?", "kind": "temporal", "answer_data": [ "Cache directive and maximum validity period per status class", "Regeneration trigger events, including retraction and canonical-identifier change", "RFC 3339 generation time of the rule set and the alias-set edition it was derived from" ] } ], "data_elements": [ { "id": "als-gplat-de-redirect-rule", "name": "Redirect rule", "description": "One server-agnostic rule binding a source identifier to a target IRI and an HTTP status class, with its permanence semantics.", "value_kind": "object", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-023", "SRC-084" ] }, { "id": "als-gplat-de-namespace-authority", "name": "Namespace write authority", "description": "The party holding write access to the namespace stem for which redirect or canonical-identifier claims are published.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-084" ] }, { "id": "als-gplat-de-cache-directive", "name": "Cache validity directive", "description": "Maximum caching period for a redirect rule and the events that force regeneration.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] } ], "artifacts": [ { "id": "als-gplat-art-redirect-ruleset", "name": "Redirect projection rule set", "description": "Server-agnostic set of source-to-target redirect rules with bound status classes, cache directives and content-negotiation preferences, derived from a named alias-set edition and intended for execution by an external HTTP service.", "media_or_form": [ "Declarative rule set in any supported projection, translatable to a specific server configuration", "Accompanying derivation record naming the source alias-set edition and its digest" ], "serial": true, "identity_strategy": "Governed IRI plus an opaque monotonic edition sequence; the rule set is never identified by the digest of its generated server configuration or by the generation timestamp.", "source_refs": [ "SRC-023", "SRC-084", "SRC-077" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-gplat-canonical-governance", "name": "Canonical Identity, Namespace and Change Control", "description": "The governance controls that keep an alias set stable and comparable over time: who owns the namespaces and prefixes, what the canonical schema and version promise, how records are identified and timed, and how canonical form and digests are computed and verified.", "rationale": "SSSOM requires every compact identifier to expand without external lookup; the W3C vocabulary-publishing recipes require write authority over the namespace published; Semantic Versioning forbids mutating a released version; RFC 3339, RFC 9562 and the SSSOM hashing rules together fix how time, identity and integrity are recorded. Without these, two readers of the same alias set can legitimately disagree about what it says.", "source_refs": [ "SRC-034", "SRC-084", "SRC-085", "SRC-008", "SRC-078", "SRC-077", "SRC-088", "SRC-079" ], "layers": [ { "id": "als-gplat-namespace-schema-layer", "name": "Namespace Ownership and Canonical Schema Versioning", "description": "Declares which namespaces the owner package controls, how compact identifiers expand deterministically, what canonical schema and version an alias set claims, and what compatibility a consumer may rely on.", "source_refs": [ "SRC-034", "SRC-084", "SRC-080", "SRC-085", "SRC-082" ], "findings": [ { "id": "als-gplat-namespace-prefix-governance", "name": "Namespace Ownership and Prefix Expansion Governance", "description": "Declares the namespaces the owner package owns outright versus those it merely references under another authority's control, and publishes the prefix-to-IRI map that lets every compact identifier in an alias set expand to a full IRI without consulting any external resource. Covers collision handling when two declarations bind one prefix to different stems, and pins which prefix-map edition was in force when a record was written.", "source_refs": [ "SRC-034", "SRC-084", "SRC-080", "SRC-081" ], "questions": [ { "id": "als-gplat-q-namespace-ownership-split", "text": "Which namespaces does the adopting Dimension own outright, and which are referenced under another authority?", "kind": "ownership", "answer_data": [ "Namespace stem and ownership class: owned, delegated, or referenced", "Controlling authority reference for each referenced stem", "Permitted operations per class, in particular the prohibition on redefining referenced stems" ] }, { "id": "als-gplat-q-curie-expansion", "text": "How is every compact identifier in an alias set expanded to a full IRI without consulting an external registry?", "kind": "identity", "answer_data": [ "Prefix-to-IRI stem declarations bundled with or referenced by the alias set", "Expansion algorithm and the rule that unresolvable prefixes reject the record", "Round-trip requirement that compaction of an expanded IRI returns the original compact form" ] }, { "id": "als-gplat-q-prefix-collision", "text": "What happens when two prefix declarations bind the same prefix to different IRI stems?", "kind": "exception", "answer_data": [ "Collision detection point: authoring, ingest, or export", "Resolution rule and precedence between set-level and external declarations", "Rejection or quarantine outcome and the defect record raised" ] }, { "id": "als-gplat-q-prefix-edition-provenance", "text": "Which prefix-map edition was in force when a given alias record was written?", "kind": "provenance", "answer_data": [ "Prefix-map edition serial pinned by the record or its set", "Digest of the pinned prefix-map edition", "Re-expansion obligation when a later edition changes a stem" ] } ], "data_elements": [ { "id": "als-gplat-de-namespace-declaration", "name": "Namespace ownership declaration", "description": "One namespace stem with its ownership class and, where not owned, the controlling authority reference.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-084", "SRC-034" ] }, { "id": "als-gplat-de-prefix-binding", "name": "Prefix binding", "description": "A compact-identifier prefix bound to a full IRI stem, sufficient for unambiguous expansion without external lookup.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-034", "SRC-080" ] }, { "id": "als-gplat-de-prefix-edition-pin", "name": "Prefix map edition pin", "description": "The prefix-map edition serial and digest that an alias record or set was authored against.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-034", "SRC-088" ] } ], "artifacts": [ { "id": "als-gplat-art-prefix-map", "name": "Prefix and namespace map", "description": "Published prefix-to-IRI stem map with ownership classes, collision precedence and deprecation markers, sufficient on its own to expand every compact identifier in the alias sets that pin it.", "media_or_form": [ "Prefix map serialized in any supported projection", "Context document consumable by a linked-data processor", "Namespace document served from the owned stem" ], "serial": true, "identity_strategy": "Governed IRI in an owned namespace plus an opaque monotonic edition sequence; the map is never identified by its publication date or by the digest of its serialized form.", "source_refs": [ "SRC-084", "SRC-034", "SRC-080" ] } ], "inline_only_rationale": null }, { "id": "als-gplat-schema-version-compatibility", "name": "Canonical Schema, Versioning and Compatibility Promise", "description": "The canonical schema an alias record and alias set are validated against, the version identifier they declare, which changes count as breaking for a consumer, how a released edition is superseded without being mutated, and what a consumer must do when it meets a version it does not fully recognise. This is the promise that makes safe evolution possible without renegotiating every consumer.", "source_refs": [ "SRC-085", "SRC-034", "SRC-079", "SRC-082", "SRC-087" ], "questions": [ { "id": "als-gplat-q-schema-declaration", "text": "Which canonical schema and version does an alias set declare, and where is that schema dereferenced?", "kind": "requirement", "answer_data": [ "Canonical schema reference and its dereferenceable location", "Declared version identifier in MAJOR.MINOR.PATCH form", "Validation profile applied, and whether it is strict or lenient about unknown slots" ] }, { "id": "als-gplat-q-breaking-change-class", "text": "Which schema changes are breaking for a consumer of an exported alias set?", "kind": "classification", "answer_data": [ "Change class: additive, restrictive, renaming, semantic re-binding, or removal", "Breaking or non-breaking verdict with the version increment it forces", "Consumer impact statement and any migration path offered" ] }, { "id": "als-gplat-q-edition-supersession", "text": "How is a released schema or alias-set edition superseded without mutating what was already published?", "kind": "lifecycle", "answer_data": [ "New edition serial and its supersession pointer to the prior edition", "Immutability assertion for the prior edition and its digest", "Support window during which the superseded edition remains dereferenceable" ] }, { "id": "als-gplat-q-unrecognised-version-behaviour", "text": "What must a consumer do when it reads a minor version whose additions it does not recognise?", "kind": "validation", "answer_data": [ "Required behaviour within a major line: ignore unknown slots rather than fail", "Obligation to report discarded slots so the loss register stays accurate", "Failure condition that does justify rejection, namely an unrecognised major version" ] } ], "data_elements": [ { "id": "als-gplat-de-schema-reference", "name": "Canonical schema reference", "description": "Dereferenceable pointer to the schema an alias record or set is validated against, with its declared version.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-085", "SRC-034" ] }, { "id": "als-gplat-de-compatibility-verdict", "name": "Compatibility verdict", "description": "Whether a proposed change is breaking for consumers, and the version increment it therefore requires.", "value_kind": "code", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-085" ] }, { "id": "als-gplat-de-supersession-pointer", "name": "Edition supersession pointer", "description": "Reference from a new edition to the edition it supersedes, preserving the prior edition unmodified.", "value_kind": "reference", "cardinality": "0..1", "required": true, "source_refs": [ "SRC-085", "SRC-082" ] } ], "artifacts": [ { "id": "als-gplat-art-canonical-schema", "name": "Canonical alias-set schema", "description": "The authoritative, dereferenceable schema defining alias record and alias-set slots, cardinalities, value kinds and validation constraints, independent of any serialization.", "media_or_form": [ "Schema document dereferenceable from an owned namespace", "Projection-specific schema bindings generated from it and marked as derived" ], "serial": true, "identity_strategy": "Governed IRI for the schema plus a declared semantic version; version strings and file names locate an edition but never constitute the schema's identity.", "source_refs": [ "SRC-084", "SRC-085", "SRC-034" ] }, { "id": "als-gplat-art-change-log", "name": "Schema and edition change log", "description": "Ordered record of every edition, the patch document that produced it, its compatibility verdict, its base and resulting digests, and its supersession pointer.", "media_or_form": [ "Ordered change record in any supported projection", "Patch series with base-digest test operations" ], "serial": true, "identity_strategy": "Governed IRI plus an opaque monotonic edition sequence; the sequence carries order only and never encodes the change date.", "source_refs": [ "SRC-079", "SRC-085", "SRC-077" ] } ], "inline_only_rationale": null } ] }, { "id": "als-gplat-record-identity-integrity-layer", "name": "Record Identity, Time Discipline and Integrity", "description": "Fixes how alias records are identified, how their times are recorded and distinguished, how their canonical form is computed and how integrity is verified without confusing a digest with an identifier.", "source_refs": [ "SRC-008", "SRC-078", "SRC-077", "SRC-088", "SRC-009", "SRC-034" ], "findings": [ { "id": "als-gplat-record-identity-time-discipline", "name": "Alias Record Identity and Time Discipline", "description": "Applies the identity priority to alias records and sets — an authoritative master-system identifier where one exists, otherwise a governed IRI in a controlled namespace, otherwise a Dimension-assigned UUID or ULID — and forbids dates, version strings, digests, file names and projection-local surrogate keys from acting as identity. Separately fixes the time discipline: the time the equivalence was asserted by its authority, the time this model first observed it, and the time it was written into a projection are three distinct values recorded whenever they differ.", "source_refs": [ "SRC-008", "SRC-078", "SRC-034", "SRC-088", "SRC-009" ], "questions": [ { "id": "als-gplat-q-authoritative-identifier", "text": "Which identifier is authoritative for an alias record when a master system already assigns one?", "kind": "identity", "answer_data": [ "Master-system identifier value and the system of record that assigns it", "Identity tier actually applied, with the reason a lower tier was needed if so", "Immutability assertion binding that identifier to the record for its lifetime" ] }, { "id": "als-gplat-q-three-clocks", "text": "How are the time an equivalence was asserted, first observed and written recorded distinctly?", "kind": "temporal", "answer_data": [ "Assertion event time as an RFC 3339 date-time with seconds and an explicit offset", "Observation time recorded when this model first saw the assertion", "Ingestion time recorded when the record was written into a projection" ] }, { "id": "als-gplat-q-digest-not-identity", "text": "Why may a content digest, file name or version string never be promoted to a record identifier?", "kind": "constraint", "answer_data": [ "Statement that equal digests establish only high likelihood of identical content, not identity of records", "Statement that identity fields are excluded from the canonical form, so a digest cannot be self-referential", "Rejection rule applied when a projection proposes a digest or path as a key" ] }, { "id": "als-gplat-q-offset-provenance", "text": "Which clock and offset applied when a timestamp was recorded, and was the local offset known?", "kind": "provenance", "answer_data": [ "Recorded numeric offset or Z, and the source of the clock", "Use of the minus-zero-zero offset convention where the instant is known in UTC but the local offset is not", "Agent or tool reference that generated the timestamp" ] } ], "data_elements": [ { "id": "als-gplat-de-record-identifier", "name": "Alias record identifier", "description": "The single identifier of an alias record or set, assigned by the identity priority and immutable thereafter.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-078", "SRC-034", "SRC-084" ] }, { "id": "als-gplat-de-assertion-event-time", "name": "Assertion event time", "description": "RFC 3339 date-time, with seconds and an explicit offset, at which the asserting authority made or retracted the equivalence claim.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-034" ] }, { "id": "als-gplat-de-observation-ingestion-time", "name": "Observation and ingestion times", "description": "RFC 3339 date-times at which this model first observed the assertion and at which the record was written into a projection, recorded separately from event time.", "value_kind": "timestamp", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Identity and time are field-level constraints that must hold inside every alias record in every projection; they are enforced by the canonical schema and the validation profile that already exist as artifacts. Publishing them separately would duplicate the schema and create a second source of truth for constraints that must be checked in-band at create and patch time, and it would invite drift between the published document and the rules actually applied." }, { "id": "als-gplat-canonical-form-integrity", "name": "Canonical Form, Digest and Integrity Verification", "description": "Defines the deterministic canonical form used for comparison, diffing, digesting and signing. Two regimes apply and are declared explicitly rather than merged: RDF projections are canonicalized to canonical N-Quads with deterministic blank-node labels, where two datasets share a canonical form if and only if they are isomorphic; slot-record projections are canonicalized by propagating set-level slots, ordering slots by the schema's slot order, sorting multi-valued slots, truncating floating-point confidence, and excluding identity and computed-cardinality fields. Digests verify integrity and detect drift only.", "source_refs": [ "SRC-077", "SRC-088", "SRC-034", "SRC-087", "SRC-079" ], "questions": [ { "id": "als-gplat-q-canonical-form-definition", "text": "What is the canonical form of an alias record, and which fields are excluded from it?", "kind": "definition", "answer_data": [ "Ordered normalization steps: slot propagation, slot ordering, multi-value sorting, numeric truncation, encoding", "Excluded fields, specifically the record identity field and any computed cardinality field", "Statement of the canonicalization regime that applies to the projection at hand" ] }, { "id": "als-gplat-q-digest-algorithm", "text": "Which digest algorithm and encoding are used, and what collision assumption is stated alongside them?", "kind": "measurement", "answer_data": [ "Algorithm identifier and output encoding", "Stated collision assumption and the permitted uses of the digest", "Prohibited uses, in particular use as an identifier or as proof of record identity" ] }, { "id": "als-gplat-q-integrity-verification", "text": "How does a consumer verify that a received alias set matches the published edition byte for byte?", "kind": "evidence", "answer_data": [ "Published integrity manifest entry for the edition, with its digest and algorithm", "Verification procedure the consumer runs after canonicalization", "Mismatch handling: reject, quarantine, and the defect record raised" ] }, { "id": "als-gplat-q-blank-node-canonicalization", "text": "How is canonical form computed for a graph projection that contains unlabelled nodes?", "kind": "interoperability", "answer_data": [ "Canonicalization algorithm applied and the deterministic labels it assigns", "Isomorphism guarantee and its limits", "Statement that digests from the graph regime and the slot-record regime are not comparable" ] } ], "data_elements": [ { "id": "als-gplat-de-canonical-form-profile", "name": "Canonicalization profile", "description": "The named regime and ordered normalization steps applied before any digest, diff or signature is computed for a given projection.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-077", "SRC-088" ] }, { "id": "als-gplat-de-edition-digest", "name": "Edition digest", "description": "Digest of the canonical form of one published edition, with its algorithm and encoding, used solely for integrity and drift detection.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-088", "SRC-077" ] }, { "id": "als-gplat-de-integrity-verdict", "name": "Integrity verification verdict", "description": "Outcome of comparing a received edition's recomputed digest with the published manifest entry.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-077", "SRC-079" ] } ], "artifacts": [ { "id": "als-gplat-art-canonicalization-profile", "name": "Canonicalization profile specification", "description": "Declares each canonicalization regime, its ordered normalization steps, excluded fields, numeric truncation rule and encoding, and states which regime applies to which projection.", "media_or_form": [ "Specification document dereferenceable from an owned namespace", "Machine-readable profile consumable by a canonicalization implementation" ], "serial": true, "identity_strategy": "Governed IRI plus a declared semantic version; the profile is never identified by the digest it produces.", "source_refs": [ "SRC-077", "SRC-088", "SRC-084" ] }, { "id": "als-gplat-art-integrity-manifest", "name": "Integrity manifest", "description": "Per-edition list of canonical-form digests with algorithm and encoding identifiers, published alongside each alias-set edition for verification.", "media_or_form": [ "Manifest in any supported projection, paired with the edition it covers", "Detached verification record referenced by the edition's catalogue entry" ], "serial": true, "identity_strategy": "Governed IRI plus an opaque monotonic edition sequence matching the edition it covers; the manifest's own digest is not its identity.", "source_refs": [ "SRC-088", "SRC-077", "SRC-082" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-cmd-bundle-envelope-and-validation", "name": "Command Envelope, Concurrency Control and Pre-commit Validation", "description": "Everything a mutation command must carry before the alias register will consider it, and everything the register checks before any record is appended: command identity and idempotency, the optimistic-concurrency precondition, the declarative validation check set and the machine-readable outcome or failure report.", "rationale": "Alias assertions are federated statements about identity that other systems act on; an unsafe retry, a lost update or an unvalidated contradiction propagates a false equivalence. HTTP semantics supply the normative precondition and conflict vocabulary, the idempotency-key work supplies duplicate-command handling, SHACL supplies the report structure and Problem Details supplies the failure projection. Grouping them as one concern keeps the accept/reject gate in a single auditable place.", "source_refs": [ "SRC-023", "SRC-062", "SRC-089", "SRC-045" ], "layers": [ { "id": "als-cmd-layer-envelope-control", "name": "Command Envelope and Concurrency Control", "description": "The identity, idempotency and version-precondition contract that every mutation command must satisfy, and how duplicate, in-flight and stale commands are distinguished from one another.", "source_refs": [ "SRC-023", "SRC-062" ], "findings": [ { "id": "als-cmd-find-idempotency-envelope", "name": "Idempotency key, request fingerprint and duplicate-command resolution", "description": "Every mutation command carries a client-generated idempotency key and is reduced to a canonical fingerprint. The register keeps a receipt series keyed by (submitting client, idempotency key) and uses it to classify an arriving command as a first occurrence, an in-flight duplicate, a completed replay whose recorded outcome is returned unchanged, or a key reuse with a differing payload. This makes retry safe for commands that are not naturally idempotent, without ever applying an effect twice.", "source_refs": [ "SRC-062", "SRC-023", "SRC-089" ], "questions": [ { "id": "als-cmd-q-envelope-required-identity", "text": "What command identifier, idempotency key and command-type code must a mutation command carry before the alias register will accept it for processing?", "kind": "identity", "answer_data": [ "Command identifier minted by the submitting agent", "Idempotency key value and its generation method (for example a random UUID)", "Command-type code drawn from the governed command vocabulary", "Submitting client or agent reference forming the composite lookup key" ] }, { "id": "als-cmd-q-envelope-fingerprint-scope", "text": "Which parts of a command are included in the canonical fingerprint compared against a replayed idempotency key, and which are deliberately excluded?", "kind": "constraint", "answer_data": [ "Included: command type, target assertion reference, endpoint references, relation property, effective interval, declared access scope, evidence references", "Excluded: transport headers, trace identifiers, observation timestamp, retry counter", "Canonicalisation profile identifier and digest algorithm identifier", "Fingerprint digest value" ] }, { "id": "als-cmd-q-envelope-replay-classification", "text": "How is an incoming command classified as a first occurrence, an in-flight duplicate, a completed replay or a key reuse with a different payload?", "kind": "process", "answer_data": [ "Receipt lookup result for the composite key", "Receipt state value (accepted, in-progress, completed, failed)", "Fingerprint comparison result (match or mismatch)", "Resulting outcome code and, for a completed replay, the reference to the previously recorded outcome" ] }, { "id": "als-cmd-q-envelope-key-retention", "text": "How long is a command receipt retained for replay resolution, and how is a retry that arrives after the key has expired treated?", "kind": "retention", "answer_data": [ "Published key retention window and its start reference (observation time of first acceptance)", "Receipt expiry instant", "Post-expiry treatment rule (treated as a new first occurrence, with the concurrency precondition as the remaining safeguard)", "Reference to the retention model that executes receipt disposal" ] }, { "id": "als-cmd-q-envelope-missing-key", "text": "Which outcome is recorded when the required idempotency key is absent, malformed or exceeds the declared length or entropy constraints?", "kind": "exception", "answer_data": [ "Outcome code for a missing or malformed key", "Problem type identifier for the failure document", "Whether any record other than a rejection receipt is appended (none)", "Whether the failure is retryable after correction" ] } ], "data_elements": [ { "id": "als-cmd-de-command-identifier", "name": "Command identifier", "description": "Identifier of the individual mutation command instance as submitted.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-062" ] }, { "id": "als-cmd-de-idempotency-key", "name": "Idempotency key", "description": "Client-generated value, unique per distinct payload and never reused across differing payloads, used to recognise retries of the same command.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-062" ] }, { "id": "als-cmd-de-command-type", "name": "Command type code", "description": "Governed code naming the mutation command: propose, validate, submit-evidence, approve, reject, activate, supersede, retract or quarantine.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-052" ] }, { "id": "als-cmd-de-request-fingerprint", "name": "Canonical request fingerprint", "description": "Digest over the canonical serialisation of the semantically significant command content, used only for comparison; it is never an identifier.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-062" ] }, { "id": "als-cmd-de-receipt-state", "name": "Command receipt state", "description": "State of the receipt for a composite (client, idempotency key) pair: in-progress, completed, failed or expired.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-062", "SRC-023" ] }, { "id": "als-cmd-de-receipt-expiry", "name": "Receipt expiry instant", "description": "Instant after which the receipt no longer resolves replays, expressed with seconds and an explicit offset.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-062", "SRC-008" ] } ], "artifacts": [ { "id": "als-cmd-art-command-receipt", "name": "Alias Command Receipt", "description": "Append-only record of one accepted or rejected mutation command: command identifier, composite idempotency lookup key, fingerprint digest, submitting agent reference, command event time, register observation time, outcome code and reference to the records the command produced. Replays return the recorded outcome rather than reprocessing.", "media_or_form": [ "structured record in the alias register", "interface projection carrying the idempotency key and recorded response" ], "serial": true, "identity_strategy": "Identified by the register's own receipt identifier; the composite (submitting client reference, idempotency key) is a unique lookup constraint within the retention window, not the identifier. Sequenced per submitting client.", "source_refs": [ "SRC-062", "SRC-023" ] } ], "inline_only_rationale": null }, { "id": "als-cmd-find-concurrency-precondition", "name": "Optimistic-concurrency precondition and stale-version detection", "description": "Every command that targets an existing assertion must supply a validator proving which version the submitter observed. The register compares that validator against the current version token of the target and refuses the command if they differ, so concurrent proposals cannot silently overwrite one another. Precondition failure is semantically distinct from idempotent replay: a replay returns the earlier outcome, a stale validator is a rejection that requires the submitter to re-read and re-derive.", "source_refs": [ "SRC-023", "SRC-062" ], "questions": [ { "id": "als-cmd-q-concurrency-validator-source", "text": "Which validator does a mutation command supply to prove it observed the current assertion version, and how is that validator derived?", "kind": "state", "answer_data": [ "Observed version token of the target assertion", "Validator strength (strong validator over the canonical assertion state, or weak validator)", "Derivation rule linking the token to the appended record series", "Interface projection of the validator, such as an entity-tag carried in a conditional request" ] }, { "id": "als-cmd-q-concurrency-vs-replay", "text": "What distinguishes a stale-version rejection from a duplicate-command replay when both arrive from the same submitting agent?", "kind": "exception", "answer_data": [ "Fingerprint comparison result against the receipt series", "Validator comparison result against the current version token", "Distinct outcome codes for precondition failure and for replay", "Rule that replay resolution is evaluated before precondition evaluation" ] }, { "id": "als-cmd-q-concurrency-race-order", "text": "How are two concurrent proposals against the same endpoint pair ordered, and which one is recorded as losing the race?", "kind": "constraint", "answer_data": [ "Register-assigned sequence position at durable acceptance", "Version token held by each command at submission", "Loser outcome code and the recorded reason", "Whether the losing submitter must re-propose or may re-target the winning version" ] }, { "id": "als-cmd-q-concurrency-scope-granularity", "text": "At what granularity is the concurrency token scoped: the individual assertion, the endpoint pair or the whole alias register?", "kind": "composition", "answer_data": [ "Declared concurrency scope code", "Identifier of the scoped unit", "Rule for commands that span more than one assertion", "Behaviour when a scoped unit has no prior version (creation case)" ] }, { "id": "als-cmd-q-concurrency-validator-strength", "text": "When is a weak validator acceptable for an alias command and when must the validator be strong?", "kind": "validation", "answer_data": [ "Command types requiring a strong validator (activate, supersede, retract, quarantine)", "Command types permitted a weak validator (evidence submission that cannot change decided state)", "Definition of equivalence used by the weak validator", "Outcome code when validator strength is insufficient" ] } ], "data_elements": [ { "id": "als-cmd-de-observed-version-token", "name": "Observed version token", "description": "Validator supplied by the command asserting which version of the target assertion the submitter observed.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] }, { "id": "als-cmd-de-current-version-token", "name": "Current version token", "description": "Register-maintained validator for the current version of an assertion, derived from its appended record series.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-023" ] }, { "id": "als-cmd-de-precondition-mode", "name": "Precondition mode", "description": "Whether the command requires the target to match the observed version, to be absent, or to be unmodified since a stated instant.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023" ] }, { "id": "als-cmd-de-concurrency-scope", "name": "Concurrency scope", "description": "The unit over which the version token is defined: assertion, endpoint pair or register partition.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023" ] }, { "id": "als-cmd-de-conflict-outcome-code", "name": "Conflict outcome code", "description": "Governed code distinguishing precondition failure, in-flight duplicate, key reuse with differing payload and state conflict.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-062" ] } ], "artifacts": [], "inline_only_rationale": "The concurrency precondition is a declared parameter of the command envelope evaluated against the register's current version pointer; it produces no durable object of its own. Its successful outcome is already recorded on the command receipt series and its failure is already recorded in the validation and failure report series. Declaring a third artifact here would create two competing records of the same event and would make the version chain ambiguous, so the precondition is modelled purely as inline envelope data plus a comparison result." } ] }, { "id": "als-cmd-layer-precommit-validation", "name": "Pre-commit Validation Contract", "description": "The declarative catalogue of checks a command must pass before any assertion record is appended, and the machine-readable outcome record that reports which checks passed, which failed and on which element.", "source_refs": [ "SRC-045", "SRC-089", "SRC-003", "SRC-031" ], "findings": [ { "id": "als-cmd-find-validation-check-set", "name": "Declared validation check set for alias commands", "description": "A versioned catalogue of named checks with declared severity and applicability per command type. It covers endpoint reference and version presence, the relation-property contract and its vocabulary binding, type/scheme/context compatibility of the two endpoints, required evidence and review sufficiency, contradiction with existing active assertions, violation of declared not-same constraints, effective-interval well-formedness and overlap, and the declared access scope. The catalogue states what must be checked; it does not resolve endpoints, does not infer entailments and does not decide access.", "source_refs": [ "SRC-045", "SRC-003", "SRC-031", "SRC-060", "SRC-072" ], "questions": [ { "id": "als-cmd-q-checkset-blocking-vs-advisory", "text": "Which checks must pass before a proposed alias assertion may be activated, and which are advisory only?", "kind": "requirement", "answer_data": [ "Check identifier and its governed name", "Severity assigned per command type (blocking or advisory)", "Applicability expression naming the command types the check applies to", "Catalogue version in force at evaluation time" ] }, { "id": "als-cmd-q-checkset-endpoint-reference", "text": "How is the endpoint reference and its version verified without resolving or dereferencing the endpoint itself?", "kind": "validation", "answer_data": [ "Endpoint reference syntax and namespace conformance result", "Presence and format of the endpoint version or validator token supplied with the reference", "Comparison of the supplied endpoint version against the version last recorded on this assertion", "Explicit statement that dereferencing and resolution are delegated to the resolver model" ] }, { "id": "als-cmd-q-checkset-property-compatibility", "text": "Which relation-property, type, scheme and context compatibility rules make a proposed endpoint pairing admissible?", "kind": "interoperability", "answer_data": [ "Declared relation property and its governed vocabulary term (for example an exact-match or close-match mapping property)", "Subject type compatibility rule between the two endpoints", "Concept scheme or namespace pairing rule", "Context or profile identifier under which the pairing is asserted" ] }, { "id": "als-cmd-q-checkset-contradiction", "text": "How are contradictions with existing active assertions and with declared not-same constraints detected and reported?", "kind": "relationship", "answer_data": [ "Set of existing active assertions over the same endpoint pair and their relation properties", "Disjointness rule violated (for example an exact-match asserted where a broader-match already holds)", "Existing distinctness or not-same constraint that the proposal would violate", "Contradiction result records with the offending element path, without any attempt to resolve which side is correct" ] }, { "id": "als-cmd-q-checkset-interval-and-scope", "text": "How are the effective interval and the declared access scope of a proposal checked against the target assertion?", "kind": "temporal", "answer_data": [ "Effective interval start and end with seconds and explicit offset, and the ordering check between them", "Overlap result against existing active intervals for the same pair", "Declared access scope value and whether it is registered", "Result of comparing the declared scope against the scope recorded on the target assertion" ] } ], "data_elements": [ { "id": "als-cmd-de-check-identifier", "name": "Check identifier", "description": "Governed identifier of a single named check in the catalogue.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-cmd-de-check-severity", "name": "Check severity", "description": "Declared severity of a failed check: blocking violation, warning or informational.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-cmd-de-check-applicability", "name": "Check applicability", "description": "The command types and assertion classes to which a check applies.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-cmd-de-relation-property-binding", "name": "Relation-property binding", "description": "Reference to the governed vocabulary term that the assertion's relation property is bound to.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-031" ] }, { "id": "als-cmd-de-not-same-constraint-ref", "name": "Not-same constraint reference", "description": "Reference to a recorded distinctness constraint that forbids equating the named endpoints.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-031" ] }, { "id": "als-cmd-de-check-catalogue-version", "name": "Check catalogue version", "description": "Version of the check catalogue applied to a given command evaluation.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-045", "SRC-052" ] } ], "artifacts": [ { "id": "als-cmd-art-check-catalogue", "name": "Alias Command Check Catalogue", "description": "Versioned, non-serial declaration of every named check, its severity, its applicability per command type and the governed vocabulary bindings it enforces. It is the shapes-side counterpart to the per-command validation report and changes only through the register's own registration procedure.", "media_or_form": [ "check catalogue record", "constraint-shapes graph projection", "tabular catalogue projection" ], "serial": false, "identity_strategy": "Identified by a governed catalogue IRI in the adopting Dimension's namespace plus an explicit version identifier; individual checks are identified by governed check IRIs that are never reused after retirement.", "source_refs": [ "SRC-045", "SRC-052" ] } ], "inline_only_rationale": null }, { "id": "als-cmd-find-validation-outcome-report", "name": "Validation outcome record and machine-readable failure report", "description": "Each validation run produces one outcome record stating whether the command conforms and, if not, one result per failed check naming the focus element, the path within it, the offending value, the check that produced the result and its severity. The same outcome projects into a machine-readable failure document for the calling interface. The report binds the digest of the exact command payload and catalogue version it judged, so a later edit of either is detectable.", "source_refs": [ "SRC-045", "SRC-089", "SRC-023" ], "questions": [ { "id": "als-cmd-q-outcome-result-content", "text": "What must a validation outcome record contain so a caller can tell exactly which check failed on which element?", "kind": "quality", "answer_data": [ "Overall conformance boolean", "Per-result focus element reference and path within it", "Offending value and the check identifier that produced the result", "Human-readable result message and its language" ] }, { "id": "als-cmd-q-outcome-severity-mapping", "text": "How are check severities mapped to a machine-readable failure response and to an accept, hold or reject outcome?", "kind": "classification", "answer_data": [ "Severity to outcome-code mapping table", "Rule that any blocking violation prevents any assertion record being appended", "Treatment of warnings (recorded, does not block)", "Interface status projection for each outcome code" ] }, { "id": "als-cmd-q-outcome-input-binding", "text": "Which evidence of the validated input is bound into the outcome so a later change to the proposal is detectable?", "kind": "evidence", "answer_data": [ "Digest of the canonical command payload evaluated", "Identifier and version of the proposal version evaluated", "Check catalogue version identifier", "Register observation time of the evaluation with seconds and explicit offset" ] }, { "id": "als-cmd-q-outcome-multiple-failures", "text": "How are multiple simultaneous check failures reported without collapsing them into a single opaque error?", "kind": "interoperability", "answer_data": [ "Single problem type identifier for validation failure", "Extension array carrying one entry per failed check with its element pointer", "Ordering or ranking rule for the primary reported problem", "Rule that unrecognised extension members are ignored by consumers" ] }, { "id": "als-cmd-q-outcome-retryable", "text": "Which validation and processing failures are retryable, and how is that signalled to the submitting agent?", "kind": "exception", "answer_data": [ "Retryable classification per outcome code", "Whether the same idempotency key may be reused for the retry", "Advisory retry delay where the failure is transient", "Failures that are permanently non-retryable without a corrected payload" ] } ], "data_elements": [ { "id": "als-cmd-de-conforms-flag", "name": "Conformance flag", "description": "True when the validation run produced no blocking results, false otherwise.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-cmd-de-validation-result", "name": "Validation result entry", "description": "One failed or advisory check with focus element, path, value, source check and severity.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-045" ] }, { "id": "als-cmd-de-problem-type", "name": "Problem type identifier", "description": "Stable URI identifying the class of failure reported to the caller.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-089" ] }, { "id": "als-cmd-de-evaluated-payload-digest", "name": "Evaluated payload digest", "description": "Digest of the canonical command payload the outcome was computed over.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-045", "SRC-062" ] }, { "id": "als-cmd-de-retryability", "name": "Retryability classification", "description": "Whether the outcome is transient and retryable, retryable only after payload correction, or permanent.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023" ] } ], "artifacts": [ { "id": "als-cmd-art-validation-report", "name": "Alias Command Validation Report", "description": "Append-only report for one validation run over one command: conformance flag, ordered result entries with element pointers and severities, the digests of the evaluated payload and catalogue version, and the evaluation observation time. It is the record a decision assertion later cites as the basis it relied on.", "media_or_form": [ "validation report record", "problem-details projection for the calling interface", "shapes validation report graph projection" ], "serial": true, "identity_strategy": "Identified by a register-assigned report identifier; sequenced per target assertion and per validation attempt so that repeated attempts against the same proposal remain individually citable. Sequence gaps are permitted and never renumbered.", "source_refs": [ "SRC-045", "SRC-089" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-cmd-bundle-lifecycle-commands", "name": "Alias Assertion Lifecycle Commands and Immutable Decision Record", "description": "The append-only command sequence that moves an alias assertion through its life: proposal, evidence submission, approval or rejection, activation, supersession, retraction and emergency quarantine, together with the compensating records used when a command applies only partially.", "rationale": "Registry practice requires that changes to registered items follow a declared procedure under a named change controller and that entries be marked rather than removed, and provenance practice requires that revision and invalidation be recorded as first-class events attributed to agents. Modelling the commands as an append-only series of immutable records gives a defensible history without duplicating any downstream decision, resolution or enforcement behaviour.", "source_refs": [ "SRC-052", "SRC-009", "SRC-090", "SRC-072" ], "layers": [ { "id": "als-cmd-layer-proposal-intake", "name": "Proposal Intake and Evidence Submission", "description": "How an alias assertion is first proposed, how repeated proposals over the same endpoint pair are versioned, and how supporting evidence is attached to a specific proposal version.", "source_refs": [ "SRC-052", "SRC-009", "SRC-072", "SRC-090" ], "findings": [ { "id": "als-cmd-find-propose-command", "name": "Propose command and proposal versioning", "description": "The propose command records a candidate equivalence: the endpoint references and their versions, the declared relation property and its vocabulary binding, direction and canonical designation, proposed effective interval, declared confidence, asserting authority reference and declared access scope. It creates a new immutable proposal version; it never edits an earlier one. A re-proposal over the same endpoint pair appends a new version linked as a revision of its predecessor.", "source_refs": [ "SRC-052", "SRC-009", "SRC-003", "SRC-060", "SRC-090" ], "questions": [ { "id": "als-cmd-q-propose-minimum-content", "text": "What minimum content must a propose command carry to create the first version of an alias assertion?", "kind": "requirement", "answer_data": [ "Two or more endpoint references with their version or validator tokens", "Declared relation property and its governed vocabulary binding", "Direction and canonical designation, or an explicit statement that the assertion is symmetric", "Proposed effective interval, declared confidence and asserting authority reference" ] }, { "id": "als-cmd-q-propose-version-identity", "text": "How is a proposal identified and versioned when the same endpoint pair is proposed repeatedly by different agents?", "kind": "identity", "answer_data": [ "Assertion identifier that is stable across versions", "Proposal version identifier and its sequence position", "Revision link to the predecessor version", "Rule that the endpoint pair is a lookup constraint, not the identifier" ] }, { "id": "als-cmd-q-propose-initial-state", "text": "Which state does a newly recorded proposal enter, and which commands are legal from that state?", "kind": "lifecycle", "answer_data": [ "Initial state code for a recorded proposal", "Legal successor commands from that state (validate, submit evidence, approve, reject, retract)", "Commands that are illegal from that state (activate before approval, supersede a never-active assertion)", "Outcome code for an illegal transition attempt" ] }, { "id": "als-cmd-q-propose-agent-vs-authority", "text": "How are the proposing agent and the asserting authority recorded, and how do they differ?", "kind": "provenance", "answer_data": [ "Proposing agent reference and its role in the proposal activity", "Asserting authority reference on whose behalf the equivalence is claimed", "Command event time asserted by the agent and register observation time, recorded separately", "Attribution link from the proposal version to the responsible agent" ] }, { "id": "als-cmd-q-propose-superseding-proposal", "text": "What happens to a pending proposal when a competing proposal over the same endpoint pair is recorded before any decision is taken?", "kind": "state", "answer_data": [ "Whether both proposals remain pending or the earlier is marked overtaken", "Version tokens held by each pending proposal", "Rule requiring a decision to name the exact proposal version it judges", "Outcome code recorded on the proposal that is not carried forward" ] } ], "data_elements": [ { "id": "als-cmd-de-assertion-identifier", "name": "Assertion identifier", "description": "Stable identifier of the alias assertion, constant across all its versions.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-052", "SRC-090" ] }, { "id": "als-cmd-de-proposal-version-id", "name": "Proposal version identifier", "description": "Identifier of one immutable proposal version within an assertion's version chain.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-cmd-de-endpoint-reference", "name": "Endpoint reference", "description": "Reference to one identifier endpoint participating in the equivalence, together with its version or validator token.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-060", "SRC-003" ] }, { "id": "als-cmd-de-declared-confidence", "name": "Declared confidence", "description": "Confidence declared by the asserting authority, expressed on a scale named by the adopting Dimension.", "value_kind": "other", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-072" ] }, { "id": "als-cmd-de-asserting-authority-ref", "name": "Asserting authority reference", "description": "Reference to the party on whose authority the equivalence is claimed; this model records the reference and does not evaluate competence.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-072", "SRC-052" ] }, { "id": "als-cmd-de-command-event-time", "name": "Command event time", "description": "Instant at which the submitting agent asserts the command was issued, with seconds and explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "als-cmd-art-proposal-version", "name": "Alias Assertion Proposal Version", "description": "Immutable record of one proposed state of an alias assertion, carrying the endpoint references and versions, relation property binding, direction and canonical designation, proposed effective interval, declared confidence, asserting authority reference, declared access scope, proposing agent and both event and observation times, plus a revision link to its predecessor.", "media_or_form": [ "structured assertion record", "serialised graph projection using mapping and provenance vocabularies" ], "serial": true, "identity_strategy": "Identified by the assertion identifier plus a monotonic version sequence assigned by the register; the version sequence is never reused or renumbered and gaps are permitted.", "source_refs": [ "SRC-009", "SRC-052" ] } ], "inline_only_rationale": null }, { "id": "als-cmd-find-evidence-submission", "name": "Evidence submission bound to a proposal version", "description": "The submit-evidence command appends an evidence item to a named proposal version rather than to the assertion as a whole, so a decision can be traced to exactly the material available when it was taken. Evidence items are immutable: a mistaken attachment is corrected by appending a withdrawal record, never by editing or removing the original entry.", "source_refs": [ "SRC-072", "SRC-009", "SRC-052" ], "questions": [ { "id": "als-cmd-q-evidence-binding", "text": "How is a submitted evidence item bound to a specific proposal version rather than to the assertion as a whole?", "kind": "evidence", "answer_data": [ "Target proposal version identifier", "Evidence item identifier and its sequence position within the version", "Digest of the evidence payload or of its external reference", "Evidence role code stating which check it is offered to satisfy" ] }, { "id": "als-cmd-q-evidence-provenance", "text": "Which provenance attributes must accompany an evidence item for it to count toward the required-evidence check?", "kind": "provenance", "answer_data": [ "Submitting agent reference and the party responsible for the evidence content", "Source system or document reference from which the evidence was obtained", "Evidence generation time and register observation time, recorded separately", "Method or verification procedure by which the evidence was produced" ] }, { "id": "als-cmd-q-evidence-withdrawal", "text": "Can an evidence item be withdrawn, and what record remains if the underlying material must be removed?", "kind": "retention", "answer_data": [ "Withdrawal record referencing the withdrawn evidence item and its reason code", "Rule that the original entry and its digest are retained as a tombstone", "Reference to the retention or privacy model that executes any removal of the payload itself", "Effect of withdrawal on any decision that already cited the item (none retroactively; a new decision is required)" ] }, { "id": "als-cmd-q-evidence-restricted", "text": "How is restricted or confidential evidence declared so the decision record stays readable when the evidence itself is not?", "kind": "access", "answer_data": [ "Declared access scope or classification code on the evidence item", "Which fields remain visible when the payload is withheld (identifier, digest, role, provenance summary)", "Reference to the authorization model that decides who may read the payload", "Outcome code when a reader requests a withheld payload" ] }, { "id": "als-cmd-q-evidence-correction", "text": "Which command corrects an evidence item that was attached to the wrong proposal version?", "kind": "constraint", "answer_data": [ "Withdrawal record on the incorrect binding", "New evidence submission against the correct proposal version", "Idempotency key and concurrency validator required for both commands", "Link recording that the second submission compensates the first" ] } ], "data_elements": [ { "id": "als-cmd-de-evidence-item-id", "name": "Evidence item identifier", "description": "Identifier of one immutable evidence attachment.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-072" ] }, { "id": "als-cmd-de-evidence-role", "name": "Evidence role code", "description": "Which validation check or review requirement the evidence item is offered to satisfy.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-045", "SRC-072" ] }, { "id": "als-cmd-de-evidence-digest", "name": "Evidence payload digest", "description": "Digest over the evidence payload or over the canonical form of its external reference.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-072", "SRC-009" ] }, { "id": "als-cmd-de-evidence-classification", "name": "Evidence access classification", "description": "Declared classification or access scope governing visibility of the evidence payload.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-072" ] }, { "id": "als-cmd-de-evidence-observation-time", "name": "Evidence observation time", "description": "Instant at which the register durably recorded the evidence item, with seconds and explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "als-cmd-art-evidence-attachment", "name": "Evidence Attachment Record", "description": "Immutable record binding one evidence item to one proposal version, carrying the evidence role, payload digest or external reference, provenance attributes, declared classification, submitting agent and both generation and observation times. Withdrawals are appended as separate records in the same series.", "media_or_form": [ "structured evidence record", "external document or dataset reference with digest" ], "serial": true, "identity_strategy": "Identified by a register-assigned evidence identifier; sequenced per proposal version. Where the evidence originates in a master system, that system's identifier is recorded as the authoritative source reference alongside the register identifier.", "source_refs": [ "SRC-072", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "als-cmd-layer-decision-record", "name": "Immutable Decision Record", "description": "How approval and rejection are recorded as immutable decision assertions bound to the exact proposal version and validation report they relied on, referencing but never evaluating the deciding authority.", "source_refs": [ "SRC-009", "SRC-052", "SRC-072" ], "findings": [ { "id": "als-cmd-find-decision-assertion", "name": "Approve and reject decision assertions", "description": "An approve or reject command appends a decision assertion naming the decided proposal version, the validation report relied on, the deciding authority reference, the decision outcome and reason code, and both decision event time and register observation time. Decision assertions are immutable; a reversal is expressed by appending a later decision or a retraction, never by editing the earlier record. The register records that a decision was made by a named authority; it does not determine whether that authority was competent to make it.", "source_refs": [ "SRC-009", "SRC-072", "SRC-052", "SRC-090" ], "questions": [ { "id": "als-cmd-q-decision-content", "text": "What does an approve or reject decision assertion record, and what does it deliberately not record?", "kind": "decision", "answer_data": [ "Decision outcome code and governed reason code", "Decided proposal version identifier and validation report identifier", "Deciding authority reference and decision event time", "Explicit exclusion: no authorization evaluation result and no enforcement instruction" ] }, { "id": "als-cmd-q-decision-authority-reference", "text": "How is the deciding authority referenced without this model determining whether that authority was competent to decide?", "kind": "authority", "answer_data": [ "Authority reference resolvable in the referenced authority or role model", "Delegation or mandate reference presented with the decision", "Rule that presence of a reference is validated but competence is not evaluated here", "Outcome code when the authority reference is absent or unresolvable in form" ] }, { "id": "als-cmd-q-decision-immutability", "text": "Why can a recorded decision never be edited, and how is a reversal expressed instead?", "kind": "constraint", "answer_data": [ "Append-only rule and the digest chain that makes edits detectable", "Reversal expressed as a later decision assertion or a retraction record", "Link type relating the reversing record to the reversed one", "Effect on the assertion's current state pointer" ] }, { "id": "als-cmd-q-decision-input-binding", "text": "How is a decision bound to the exact proposal version and validation report it relied on?", "kind": "provenance", "answer_data": [ "Proposal version identifier and its payload digest", "Validation report identifier, its conformance flag and its digest", "Check catalogue version in force at the time of validation", "Rule that a decision citing a superseded validation report is rejected" ] }, { "id": "als-cmd-q-decision-emergency-basis", "text": "How is a decision taken under delegated or emergency authority distinguished from an ordinary decision?", "kind": "classification", "answer_data": [ "Decision basis code (ordinary, delegated, emergency)", "Mandate or break-glass reference supporting the basis", "Required post-hoc review marker and its due condition", "Whether advisory check warnings were overridden and on what recorded ground" ] } ], "data_elements": [ { "id": "als-cmd-de-decision-outcome", "name": "Decision outcome code", "description": "Approved, rejected or returned for revision.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-052", "SRC-090" ] }, { "id": "als-cmd-de-decision-reason", "name": "Decision reason code", "description": "Governed reason accompanying the decision outcome.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-052" ] }, { "id": "als-cmd-de-deciding-authority-ref", "name": "Deciding authority reference", "description": "Reference to the authority recorded as having taken the decision.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-072", "SRC-052" ] }, { "id": "als-cmd-de-relied-report-ref", "name": "Relied-upon validation report reference", "description": "Reference to the validation report the decision cites as its basis, with its digest.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-045", "SRC-009" ] }, { "id": "als-cmd-de-decision-basis", "name": "Decision basis code", "description": "Whether the decision was ordinary, delegated or taken under emergency mandate.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-052" ] }, { "id": "als-cmd-de-decision-event-time", "name": "Decision event time", "description": "Instant at which the authority states the decision was taken, recorded separately from the register observation time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "als-cmd-art-decision-assertion", "name": "Alias Decision Assertion Record", "description": "Immutable record of one approve or reject decision, binding decision outcome and reason to the decided proposal version, the relied-upon validation report and their digests, the deciding authority reference and decision basis, and both decision event time and register observation time.", "media_or_form": [ "structured decision record", "provenance graph projection with qualified attribution", "optionally secured record carrying a cryptographic proof" ], "serial": true, "identity_strategy": "Identified by a register-assigned decision identifier; sequenced per assertion. Where the deciding authority's own case-management system is the master, its case or decision identifier is recorded as the authoritative source identifier alongside the register identifier.", "source_refs": [ "SRC-009", "SRC-072" ] } ], "inline_only_rationale": null } ] }, { "id": "als-cmd-layer-state-transition", "name": "Activation, Supersession, Retraction and Quarantine", "description": "The commands that change which assertion is in force: activation with an effective interval, supersession of a conflicting or outdated assertion, retraction of one previously in force, emergency quarantine marking, and the compensating records used after a partial failure.", "source_refs": [ "SRC-052", "SRC-009", "SRC-072", "SRC-023" ], "findings": [ { "id": "als-cmd-find-activate-supersede", "name": "Activation and supersession with effective intervals", "description": "Activation makes an approved assertion version the one in force from a stated effective start, optionally until a stated end. Supersession appends a record relating a new version to the one it replaces and closes the predecessor's effective interval; the predecessor is retained and remains readable. Where two active assertions over the same endpoint pair would conflict, the register records the conflict and the supersession that resolves it, and does not attempt to decide the truth of either.", "source_refs": [ "SRC-072", "SRC-009", "SRC-052", "SRC-003" ], "questions": [ { "id": "als-cmd-q-activate-event-record", "text": "Which event marks an assertion as active, and what is recorded at that moment?", "kind": "event", "answer_data": [ "Activation transition record identifier and its sequence position", "Approved proposal version being activated and the decision assertion authorising it", "Effective start instant and optional effective end, each with seconds and explicit offset", "Register observation time of the activation, recorded separately from the effective start" ] }, { "id": "als-cmd-q-activate-interval-overlap", "text": "How is the effective interval of an activation set, and what happens when it overlaps an existing active interval for the same endpoint pair?", "kind": "temporal", "answer_data": [ "Effective start and end values and their ordering constraint", "Overlap detection result against existing active intervals", "Whether overlap is permitted for compatible relation properties and forbidden for conflicting ones", "Outcome code and required supersession when overlap is not permitted" ] }, { "id": "als-cmd-q-supersede-conflict-rule", "text": "When two active assertions conflict, which one is superseded and by what recorded rule?", "kind": "relationship", "answer_data": [ "Conflict type (incompatible relation properties, violated distinctness constraint, contradictory canonical designation)", "Recorded precedence rule applied, including authority precedence where declared", "Superseding and superseded version identifiers", "Reference to the decision assertion authorising the supersession" ] }, { "id": "als-cmd-q-supersede-linkage", "text": "How does supersession relate a new assertion version to the one it replaces without removing the replaced record?", "kind": "lifecycle", "answer_data": [ "Revision or derivation link from the new version to its predecessor", "Terminal state code applied to the superseded version", "Closed effective interval on the superseded version", "Rule that the superseded record remains readable and citable" ] }, { "id": "als-cmd-q-activate-downstream-ownership", "text": "Which downstream systems learn of an activation, and who owns delivering that signal?", "kind": "ownership", "answer_data": [ "Correlation identifier emitted with the transition record", "Reference to the notification or eventing model that owns delivery", "Explicit statement that this model performs no delivery, retry or acknowledgement tracking", "Reference to the resolver model that owns any redirect or merge behaviour" ] } ], "data_elements": [ { "id": "als-cmd-de-lifecycle-state", "name": "Assertion lifecycle state", "description": "Current state of an assertion version: proposed, under review, approved, rejected, active, superseded, retracted or quarantined.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-052", "SRC-090" ] }, { "id": "als-cmd-de-effective-start", "name": "Effective start", "description": "Instant from which the assertion is in force, with seconds and explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-072", "SRC-008" ] }, { "id": "als-cmd-de-effective-end", "name": "Effective end", "description": "Instant after which the assertion is no longer in force, with seconds and explicit offset; absent while open-ended.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-072", "SRC-008" ] }, { "id": "als-cmd-de-supersedes-ref", "name": "Supersedes reference", "description": "Reference from a superseding assertion version to the version it replaces.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-cmd-de-conflict-type", "name": "Conflict type code", "description": "Governed code naming the kind of conflict between two active assertions.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-031" ] }, { "id": "als-cmd-de-correlation-id", "name": "Transition correlation identifier", "description": "Identifier emitted with a transition record for downstream correlation by other models.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-089", "SRC-009" ] } ], "artifacts": [ { "id": "als-cmd-art-transition-record", "name": "Alias Assertion State Transition Record", "description": "Immutable record of one lifecycle transition (activation or supersession), naming the prior and resulting states, the authorising decision assertion, the effective interval applied, any superseded version and conflict type, the acting agent, and both transition event time and register observation time.", "media_or_form": [ "structured transition record", "provenance graph projection using generation and revision relations", "state-history table projection" ], "serial": true, "identity_strategy": "Identified by a register-assigned transition identifier; sequenced per assertion so the state history is a gap-tolerant monotonic series. Sequence positions are never reused.", "source_refs": [ "SRC-009", "SRC-052" ] } ], "inline_only_rationale": null }, { "id": "als-cmd-find-retract-quarantine", "name": "Retraction, emergency quarantine and compensating records", "description": "Retraction records that an assertion previously in force is withdrawn by its asserting or deciding authority, closing its effective interval and marking it invalidated without removing it. Emergency quarantine marks an assertion as not to be relied upon pending review, and may be applied before or after a decision. When a command applies only partially, the register derives a compensating record set that restores a consistent state by appending counter-records; it never rewrites or deletes what was already appended.", "source_refs": [ "SRC-009", "SRC-052", "SRC-023", "SRC-072" ], "questions": [ { "id": "als-cmd-q-retract-meaning", "text": "What exactly does a retract command assert about an assertion that was previously in force?", "kind": "definition", "answer_data": [ "Retraction reason code (erroneous, no longer asserted, evidence withdrawn, authority withdrawn)", "Whether the assertion is withdrawn from a stated instant or treated as never valid", "Invalidating agent and invalidation time", "Rule that the retracted record and its history remain readable" ] }, { "id": "als-cmd-q-quarantine-conditions", "text": "Under what emergency conditions may an assertion be quarantined before a decision, and who may lift the hold?", "kind": "exception", "answer_data": [ "Quarantine trigger code and the recorded justification", "Requesting party reference and quarantine basis (ordinary or break-glass)", "Required review deadline or expiry of the hold", "Reference to the party permitted to append a lift record and the required decision basis" ] }, { "id": "als-cmd-q-partial-failure-compensation", "text": "When a command applies only partially, which compensating records are appended to restore a consistent state?", "kind": "process", "answer_data": [ "Set of records already durably appended by the failed command", "Derived counter-record set with a link to the records each compensates", "Idempotency key and concurrency validator required for the compensating command", "Outcome code recorded when compensation itself cannot complete and manual custodial action is required" ] }, { "id": "als-cmd-q-retract-retention", "text": "What is retained after retraction or quarantine, and which model executes any physical erasure?", "kind": "retention", "answer_data": [ "Tombstone content retained: assertion identifier, version chain, terminal state, reason code and digests", "Retention class and any legal-hold reference", "Reference to the retention model that owns schedule and erasure execution", "Reference to the privacy model where personal-data erasure duties apply" ] }, { "id": "als-cmd-q-retract-visibility", "text": "How is a retracted or quarantined assertion represented to readers so it is not silently missing from results?", "kind": "access", "answer_data": [ "Terminal state code exposed on read", "Default read filter behaviour and the parameter that includes terminal states", "Declared access scope governing who may read the reason code", "Reference to the authorization model that decides read access" ] } ], "data_elements": [ { "id": "als-cmd-de-retraction-reason", "name": "Retraction reason code", "description": "Governed reason for withdrawing an assertion previously in force.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-052", "SRC-009" ] }, { "id": "als-cmd-de-invalidation-time", "name": "Invalidation time", "description": "Instant at which the assertion ceased to be asserted, with seconds and explicit offset.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-008" ] }, { "id": "als-cmd-de-quarantine-basis", "name": "Quarantine basis code", "description": "Whether the hold was applied under ordinary review or under an emergency break-glass mandate.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-052", "SRC-072" ] }, { "id": "als-cmd-de-compensates-ref", "name": "Compensates reference", "description": "Reference from a compensating record to the record whose effect it neutralises.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-023" ] }, { "id": "als-cmd-de-tombstone-marker", "name": "Tombstone marker", "description": "Marker preserving the identifier, version chain and terminal state of a record whose payload may later be removed by the retention model.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-052", "SRC-009" ] }, { "id": "als-cmd-de-retention-class", "name": "Retention class reference", "description": "Reference to the retention class assigned to the record series by the adopting Dimension.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-052" ] } ], "artifacts": [ { "id": "als-cmd-art-retraction-record", "name": "Alias Retraction and Quarantine Record", "description": "Immutable record of a retraction or quarantine marking: terminal state applied, reason and basis codes, requesting and invalidating agent references, invalidation time and register observation time, any review deadline, and the tombstone marker preserving identifier and version chain.", "media_or_form": [ "structured terminal-state record", "provenance graph projection using invalidation relations" ], "serial": true, "identity_strategy": "Identified by a register-assigned record identifier; sequenced per assertion within the same terminal-state series so retraction, quarantine and lift records are ordered without renumbering.", "source_refs": [ "SRC-009", "SRC-052" ] }, { "id": "als-cmd-art-compensation-plan", "name": "Compensating Record Plan", "description": "Derived, recorded plan listing each record already appended by a partially applied command and the counter-record proposed to neutralise it, with the originating command identifier, the failure outcome code and the concurrency validators required to apply each counter-record. It is a calculation and a record, not an execution.", "media_or_form": [ "structured plan record", "problem-details projection describing the partial failure" ], "serial": true, "identity_strategy": "Identified by a register-assigned plan identifier; sequenced per originating command identifier so repeated compensation attempts remain distinguishable.", "source_refs": [ "SRC-023", "SRC-089", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-query-read-and-resolution", "name": "Alias Read and Resolution Semantics", "description": "The request contract, resolution semantics and temporal read semantics that let an agent ask what an identifier is asserted to be equivalent to, under fully explicit parameters, without any canonical choice being made on its behalf.", "rationale": "SPARQL 1.1 makes dataset scope, entailment regime and solution sequences explicit constituents of a query's meaning, and its protocol makes scope precedence and refusal explicit; HTTP 300 shows an authority can enumerate alternatives and leave selection to the agent; Memento makes as-of retrieval a negotiated parameter with a disclosed best-match rule. Equivalence answers need at least this level of explicitness because identity links are empirically over-asserted.", "source_refs": [ "SRC-048", "SRC-094", "SRC-059", "SRC-023", "SRC-030" ], "layers": [ { "id": "als-query-request-contract", "name": "Query Request Contract and Capability Declaration", "description": "What a caller must supply, and what the answering service must publish in advance, before an alias read, resolution or traversal has a defined meaning and a replayable result.", "source_refs": [ "SRC-048", "SRC-093", "SRC-094", "SRC-067" ], "findings": [ { "id": "als-query-parameter-set", "name": "Explicit Query Parameter Set and Declared Capability", "description": "An alias read, resolution or traversal is meaningful only when relation kinds, direction, hop limit, maximum allowed strength loss, declared context, as-of instants, access scope and dataset or authority scope are explicit, and only when the answering service has published which of these it supports and with what hard limits. Every applied parameter, including service defaults, is echoed in the result.", "source_refs": [ "SRC-048", "SRC-093", "SRC-094", "SRC-008", "SRC-067" ], "questions": [ { "id": "als-query-q-param-required", "text": "Which request parameters must be supplied explicitly, and which have service defaults that must be echoed back in the result?", "kind": "requirement", "answer_data": [ "Parameter list with required or optional flag", "Service default value per optional parameter", "Echo obligation and the location of the echo in the result" ] }, { "id": "als-query-q-param-capability", "text": "How does the answering service publish its supported relation kinds, entailment stance, temporal coverage and hard hop and result limits before a request is built?", "kind": "interoperability", "answer_data": [ "Capability profile reference and version identifier", "Supported relation-kind codes with external alignment IRIs", "Maximum hop count, maximum result count and temporal coverage window" ] }, { "id": "als-query-q-param-scope", "text": "Which dataset, graph or authority scope was actually used to answer, and does a protocol-level scope override a scope embedded in the request?", "kind": "constraint", "answer_data": [ "Effective scope identifier list", "Precedence rule between protocol-level and request-level scope", "Record of the override when precedence was applied" ] }, { "id": "als-query-q-param-validation", "text": "What makes a request malformed or refused, and how is that outcome distinguished from a well-formed request that returns no candidates?", "kind": "validation", "answer_data": [ "Malformed-request condition list", "Refusal condition list with reason codes", "Distinct answer-state code for an empty but valid answer" ] }, { "id": "als-query-q-param-identity", "text": "How is a request record identified so that its result can be replayed later and compared with an earlier answer?", "kind": "identity", "answer_data": [ "Request record identifier assigned by the adopting Dimension", "Bound capability profile and relation-property profile versions", "Request receipt instant recorded as an attribute, not as the identifier" ] } ], "data_elements": [ { "id": "als-query-de-relation-kind-filter", "name": "Relation Kind Filter", "description": "The set of relation-kind codes admitted into the answer; an empty filter is invalid because it would leave the composed semantics of the answer undefined.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-093" ] }, { "id": "als-query-de-direction", "name": "Traversal Direction", "description": "Whether asymmetric relation kinds are followed outbound, inbound or in both directions from the supplied identifier.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-048", "SRC-003" ] }, { "id": "als-query-de-hop-limit", "name": "Hop Limit", "description": "Maximum number of alias edges the answer may cross, bounded by the service maximum published in the capability profile.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-048", "SRC-093" ] }, { "id": "als-query-de-max-strength-loss", "name": "Maximum Allowed Strength Loss", "description": "The caller's budget for cumulative confidence or semantic strength lost along a path; paths exceeding it are excluded with a stated reason rather than dropped silently.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-033" ] }, { "id": "als-query-de-context-ref", "name": "Declared Context Reference", "description": "The context in which equivalence is claimed to hold and in which the caller intends to use the answer; referentially opaque contexts make an assertion valid for one purpose and not another.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-030", "SRC-003" ] } ], "artifacts": [ { "id": "als-query-art-capability-profile", "name": "Alias Query Capability Profile", "description": "The versioned, publishable declaration of what the alias query surface supports: relation kinds and their alignments, entailment stance, temporal coverage and timelines, hard hop and result limits, supported scopes and default parameter values.", "media_or_form": [ "machine-readable service capability description", "human-readable capability page" ], "serial": false, "identity_strategy": "Authoritative master-system identifier of the answering service endpoint where one exists, otherwise a governed IRI published by the service, otherwise a Dimension-assigned UUID; each release carries a version identifier that is not a date.", "source_refs": [ "SRC-093", "SRC-094" ] }, { "id": "als-query-art-request-record", "name": "Alias Query Request Record", "description": "The immutable record of one submitted request: every supplied parameter, every applied default, the effective scope, the access scope reference and the profile versions in force at receipt.", "media_or_form": [ "structured request record", "request log entry" ], "serial": true, "identity_strategy": "Dimension-assigned ULID per request, ordered by receipt; the receipt instant is an attribute and never the identifier.", "source_refs": [ "SRC-094", "SRC-048" ] } ], "inline_only_rationale": null }, { "id": "als-query-access-scope-binding", "name": "Access Scope Carried Into a Query", "description": "Every alias query carries an access scope reference and, where one exists, a reference to an externally produced access decision. The model binds those references to the request and to the disclosure statement and signals that content was withheld, but the decision itself and its enforcement are produced elsewhere. An Indeterminate or unavailable decision is treated as deny and reported as not answerable in scope, never as an absence of equivalence.", "source_refs": [ "SRC-067", "SRC-023", "SRC-094" ], "questions": [ { "id": "als-query-q-access-scope-ref", "text": "Which access scope, subject attributes and external decision reference were bound to this particular request?", "kind": "access", "answer_data": [ "Access scope identifier", "Reference to the decision record produced by the external decision point", "Attribute set names supplied, without their values" ] }, { "id": "als-query-q-access-suppression", "text": "How does a result signal that candidates or evidence exist but were withheld, without revealing what was withheld?", "kind": "privacy", "answer_data": [ "Suppression flag on the result", "Coarse suppression band instead of an exact withheld count", "Channel in which the suppression signal itself is authorised to appear" ] }, { "id": "als-query-q-access-indeterminate", "text": "What does the query surface return when the external access decision is Indeterminate, NotApplicable or unavailable?", "kind": "exception", "answer_data": [ "Mapping from each decision value to an answer state", "Deny-by-default rule for Indeterminate and unavailable outcomes", "Reason code distinguishing this outcome from an empty answer" ] }, { "id": "als-query-q-access-policy-owner", "text": "Who owns the policy that produced the decision, and where is that policy resolvable for review?", "kind": "ownership", "answer_data": [ "Policy administration owner reference", "Resolvable policy identifier or location", "Statement that evaluation and enforcement are performed outside this model" ] } ], "data_elements": [ { "id": "als-query-de-access-scope-ref", "name": "Access Scope Reference", "description": "Identifier of the access scope under which the request was submitted; an input to the query, never a decision made by it.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-067" ] }, { "id": "als-query-de-decision-ref", "name": "External Access Decision Reference", "description": "Reference to the decision record produced by the external decision point, retained so the answer can be reviewed without reproducing the decision.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-067" ] }, { "id": "als-query-de-suppression-flag", "name": "Suppression Flag", "description": "Indicates that at least one candidate, edge or evidence reference was withheld from this result by the access scope.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-067" ] }, { "id": "als-query-de-suppression-band", "name": "Suppression Magnitude Band", "description": "Coarse band describing how much was withheld, used instead of an exact count so that the existence of specific withheld items is not disclosed.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] } ], "artifacts": [], "inline_only_rationale": "The access scope is purely reference data pointing at an externally owned decision and its governing policy: this model stores a scope identifier, an optional decision reference and a coarse suppression signal. Producing an access artifact here would duplicate the decision point's own record and would imply that this model owns policy evaluation, enforcement or the audit trail of access, none of which are within its boundary." } ] }, { "id": "als-query-resolution-semantics", "name": "Resolution Semantics and Candidate Sets", "description": "How a supplied identifier maps to a set of candidate equivalents, how relation-kind semantics and the declared entailment stance constrain that set, and how ambiguity, no-answer and authority-published canonical claims are expressed.", "source_refs": [ "SRC-048", "SRC-091", "SRC-001", "SRC-003", "SRC-023" ], "findings": [ { "id": "als-query-candidate-set-result", "name": "Candidate Set Result Without Canonical Selection", "description": "Resolution returns the complete admitted candidate set with the supporting path and per-edge provenance for each candidate, plus an explicit answer state. The service never collapses the set to one preferred identifier. Where an authority publishes its own canonical or preferred identifier, that is carried as an attributed claim of that authority, not as a selection made by the query surface.", "source_refs": [ "SRC-023", "SRC-014", "SRC-006", "SRC-030", "SRC-048" ], "questions": [ { "id": "als-query-q-candidate-ambiguity", "text": "What is returned when several mutually inconsistent candidates satisfy the request, and how is that ambiguity state distinguished from a single-candidate answer?", "kind": "decision", "answer_data": [ "Answer-state code for ambiguous resolution", "Full candidate list with per-candidate supporting paths", "Statement that no automatic tie-break or collapse was applied" ] }, { "id": "als-query-q-candidate-no-answer", "text": "How is no equivalent asserted distinguished from not answerable within the requested scope?", "kind": "exception", "answer_data": [ "Distinct answer-state codes for each outcome", "Scope and limit values that produced the not-answerable outcome", "Explicit statement that neither outcome is evidence of non-equivalence" ] }, { "id": "als-query-q-candidate-canonical-claim", "text": "When an authority publishes its own canonical identifier for a subject, how is that recorded without the query surface adopting it?", "kind": "authority", "answer_data": [ "Canonical claim value with the asserting authority reference", "Guarantee level declared by that authority for the claim", "Flag marking the claim as attributed and not applied" ] }, { "id": "als-query-q-candidate-ordering", "text": "Is the ordering of candidates meaningful, and which ordering key and tie-breaking rule were disclosed?", "kind": "quality", "answer_data": [ "Ordering key reference or an explicit unordered marker", "Tie-breaking rule", "Warning that ordering must not be read as preference unless declared meaningful" ] } ], "data_elements": [ { "id": "als-query-de-candidate-identifier", "name": "Candidate Identifier", "description": "An identifier returned as a candidate equivalent of the supplied identifier, carried in the canonical form of its issuing authority and never rewritten.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-096" ] }, { "id": "als-query-de-candidate-relation-kind", "name": "Candidate Relation Kind", "description": "The relation kind or kinds by which the candidate is connected to the supplied identifier, retained per candidate because strength differs by kind.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-014" ] }, { "id": "als-query-de-answer-state", "name": "Answer State", "description": "Single code covering resolved-single, resolved-multiple-ambiguous, no-asserted-equivalent, not-answerable-in-scope and truncated outcomes.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-092" ] }, { "id": "als-query-de-authority-canonical-claim", "name": "Authority Canonical Claim", "description": "A canonical or preferred identifier published by an authority about its own subject, carried with its attribution and guarantee level and explicitly not applied by this model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-006" ] }, { "id": "als-query-de-ordering-key", "name": "Ordering Key Declaration", "description": "The declared basis of candidate ordering, or an explicit statement that the sequence carries no meaning.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-048" ] } ], "artifacts": [ { "id": "als-query-art-candidate-result-set", "name": "Alias Candidate Resolution Result Set", "description": "The complete admitted candidate set for one resolution request, with per-candidate relation kinds, supporting paths, edge provenance references, answer state, parameter echo and attributed canonical claims.", "media_or_form": [ "structured result set", "tabular candidate listing", "narrative resolution summary" ], "serial": true, "identity_strategy": "Dimension-assigned ULID bound one-to-one to the request record identifier; each endpoint inside retains the authoritative master-system identifier issued by its own authority.", "source_refs": [ "SRC-048", "SRC-023" ] } ], "inline_only_rationale": null }, { "id": "als-query-entailment-stance", "name": "Relation Semantics and Entailment Stance of an Answer", "description": "Each answer declares the relation-kind semantics applied, including symmetry, transitivity and disjointness per kind, and the entailment stance under which it was computed. Every returned edge is labelled asserted or derived, derived edges exist only for the duration of the answer, and inconsistency detected under the requested stance is reported rather than resolved.", "source_refs": [ "SRC-091", "SRC-001", "SRC-019", "SRC-003", "SRC-030" ], "questions": [ { "id": "als-query-q-entail-regime", "text": "Under which entailment regime or closure rules was this answer computed, and was that regime requested by the caller or applied as a service default?", "kind": "classification", "answer_data": [ "Entailment regime identifier", "Requested or default indicator", "Capability profile version that declared the available regimes" ] }, { "id": "als-query-q-entail-asserted-derived", "text": "How is an asserted edge distinguished from an edge derived by symmetry or transitivity within a returned path?", "kind": "provenance", "answer_data": [ "Per-edge derivation label", "Reference to the asserted edges a derived edge was computed from", "Statement that derived edges are not written back to any store" ] }, { "id": "als-query-q-entail-relation-properties", "text": "Which relation kinds in this answer are transitive, symmetric or mutually disjoint, and from which declaration is that sourced?", "kind": "definition", "answer_data": [ "Relation-property profile reference and version", "Per-kind transitivity, symmetry and disjointness flags", "External alignment IRI per relation kind where one exists" ] }, { "id": "als-query-q-entail-inconsistency", "text": "What is returned when the requested stance finds the underlying assertions inconsistent, for example an exact match that is also asserted as a not-same pair?", "kind": "exception", "answer_data": [ "Inconsistency signal code", "Whether the regime treats inconsistency as an error or a warning", "The specific assertion references implicated, without adjudication" ] } ], "data_elements": [ { "id": "als-query-de-entailment-regime-ref", "name": "Entailment Regime Reference", "description": "Identifier of the regime or closure rule set under which the answer was computed, echoed on every result because the same data yields different outcomes under different regimes.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-091", "SRC-093" ] }, { "id": "als-query-de-edge-derivation-label", "name": "Edge Derivation Label", "description": "Per-edge label recording whether the edge was asserted by an authority or derived for this answer by symmetry or transitivity.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-003" ] }, { "id": "als-query-de-relation-property-profile", "name": "Relation Property Profile Reference", "description": "Versioned declaration of symmetry, transitivity and disjointness per supported relation kind, with external alignment references.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "als-query-de-inconsistency-signal", "name": "Inconsistency Signal", "description": "Code reporting that the requested stance detected an inconsistency among the assertions used, together with the regime's prescribed handling.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-091" ] } ], "artifacts": [], "inline_only_rationale": "The entailment stance is a declared parameter plus per-edge labels attached to results that the capability profile and the candidate result set already carry. Issuing a separate artifact would create a standing derived-edge record, which is indistinguishable in practice from materialising a closure, and would imply that this model owns a reasoner's output rather than reporting the stance an external reasoning service applied." } ] }, { "id": "als-query-temporal-read", "name": "Temporal and As-Of Read Semantics", "description": "Bitemporal read semantics for alias assertions: assertion validity time against record or observation time, as-of instants, exact against nearest-preceding match disclosure, admitted lifecycle states and stale endpoint detection.", "source_refs": [ "SRC-008", "SRC-059", "SRC-009", "SRC-095", "SRC-096" ], "findings": [ { "id": "als-query-as-of-read", "name": "As-Of Read With Separate Assertion and Record Time", "description": "A read may be requested at an as-of instant on the assertion validity timeline, on the record or observation timeline, or on both. The answer reports which instants were used and on which timeline, whether the served state is an exact or nearest-preceding match, the interval that state covers, which lifecycle states were admitted, and whether any endpoint or evidence reference is stale or invalidated as at those instants.", "source_refs": [ "SRC-008", "SRC-059", "SRC-009", "SRC-095", "SRC-072", "SRC-096" ], "questions": [ { "id": "als-query-q-asof-instants", "text": "Which as-of instants were supplied, on which timeline does each apply, and in which offset were they interpreted?", "kind": "temporal", "answer_data": [ "As-of validity instant with explicit offset or Z", "As-of record or observation instant with explicit offset or Z", "Timeline label per instant and the handling of an unknown offset" ] }, { "id": "als-query-q-asof-match", "text": "Was the served assertion state an exact match for the requested instant or the nearest preceding state, and which interval does that state cover?", "kind": "measurement", "answer_data": [ "Match mode code", "Start and end of the covered interval", "Rule used to select the served state when no exact match exists" ] }, { "id": "als-query-q-asof-stale", "text": "How is an endpoint or evidence reference flagged as stale, unresolvable or invalidated as at the as-of instant?", "kind": "state", "answer_data": [ "Staleness flag per endpoint or evidence reference", "Last successful observation instant", "Source refresh cadence declared by the asserting authority" ] }, { "id": "als-query-q-asof-lifecycle", "text": "Which assertion lifecycle states are admitted by default at an as-of instant, and how is a retraction distinguished from a deletion?", "kind": "lifecycle", "answer_data": [ "Admitted lifecycle state list and the default set", "Retraction record with its own record-time instant", "Distinction between a retracted assertion that remains readable and a disposed record" ] }, { "id": "als-query-q-asof-replay", "text": "What must be recorded so that the same as-of query returns the same answer when it is run again later?", "kind": "evidence", "answer_data": [ "Parameter echo including both instants and admitted states", "Capability and relation-property profile versions in force", "Content digest of the served state set" ] } ], "data_elements": [ { "id": "als-query-de-as-of-valid-instant", "name": "As-Of Validity Instant", "description": "Instant on the timeline over which the assertion is claimed to hold, expressed with seconds and an explicit offset or Z.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-095" ] }, { "id": "als-query-de-as-of-record-instant", "name": "As-Of Record Instant", "description": "Instant on the timeline of when this service observed, ingested or recorded the assertion, kept separately from validity time.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-query-de-served-state-interval", "name": "Served State Interval", "description": "The interval that the served assertion state covers, with a stated temporal reference system, so that a nearest-preceding answer can be evaluated by the caller.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-059", "SRC-095" ] }, { "id": "als-query-de-match-mode", "name": "Temporal Match Mode", "description": "Whether the served state is an exact match for the requested instant, the nearest preceding state, or whether no state exists before the instant.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-059" ] }, { "id": "als-query-de-staleness-flag", "name": "Staleness Flag", "description": "Per endpoint or evidence reference, an indicator that it was unresolvable, invalidated or older than the authority's declared refresh cadence as at the as-of instant.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-096" ] } ], "artifacts": [ { "id": "als-query-art-assertion-time-map", "name": "Alias Assertion Time Map", "description": "An index of the retrievable prior states of the alias assertions held for a subject, each entry giving the interval it covers on the validity and record timelines and a reference to that state, so that an as-of read is auditable and replayable.", "media_or_form": [ "structured time index", "list of state references with covered intervals" ], "serial": true, "identity_strategy": "Composite of the authoritative master-system identifier of the subject endpoint and a Dimension-assigned ULID for the index build; the build instant is an attribute and never the identifier.", "source_refs": [ "SRC-059", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-query-traversal-and-comparison", "name": "Alias Traversal, Comparison and Result Integrity", "description": "Multi-hop path enumeration across mixed relation kinds, non-adjudicating comparison of competing assertions, and the disclosure contract covering ambiguity, truncation, cycles, contradictions, stale endpoints, withheld evidence and unreachable sources.", "rationale": "SKOS makes transitivity a per-relation property and refuses it for closeMatch precisely to prevent compound errors when mappings are chained; SPARQL property paths define cycle-safe connectivity; SPARQL Federated Query shows that a silenced source failure is indistinguishable from an empty answer at the solution level; SHACL and the Verifiable Credentials model establish report-only, non-adjudicating output where verification is separated from deciding whether to rely on a claim.", "source_refs": [ "SRC-048", "SRC-092", "SRC-003", "SRC-045", "SRC-072" ], "layers": [ { "id": "als-query-traversal-paths", "name": "Path Traversal and Path Reporting", "description": "Directed and undirected multi-hop enumeration with hop limits, cycle handling, strength-loss budgets, contradictory not-same edges and explicit truncation reporting.", "source_refs": [ "SRC-048", "SRC-003", "SRC-019", "SRC-006" ], "findings": [ { "id": "als-query-path-enumeration", "name": "Path Enumeration, Cycles and Truncation", "description": "Traversal returns every candidate path satisfying the request within the hop and result limits, in a cycle-safe way that neither loops nor drops genuine paths, and states explicitly whether the enumeration is complete, truncated by a limit, or truncated because a source was unreachable. Asymmetric relation kinds keep their direction on every returned path.", "source_refs": [ "SRC-048", "SRC-092", "SRC-006", "SRC-093", "SRC-003" ], "questions": [ { "id": "als-query-q-path-completeness", "text": "Is the returned path list complete for the requested parameters, and if not, which limit or failure truncated it?", "kind": "constraint", "answer_data": [ "Completeness state code", "Limit or failure that caused truncation", "Count of paths returned against the applicable limit" ] }, { "id": "als-query-q-path-cycles", "text": "How are cycles detected and reported so that traversal terminates without duplicating or discarding a genuine path?", "kind": "process", "answer_data": [ "Cycle notice per affected path", "Termination rule applied at the cycle", "Statement that connectivity matching does not produce duplicate results" ] }, { "id": "als-query-q-path-continuation", "text": "How can a caller continue a truncated traversal deterministically without re-running the entire request?", "kind": "interoperability", "answer_data": [ "Continuation token", "Continuation link relation and its target", "Validity window of the token against the profile versions in force" ] }, { "id": "als-query-q-path-edge-provenance", "text": "What provenance must accompany each individual edge on each returned path?", "kind": "provenance", "answer_data": [ "Asserting authority reference per edge", "Attribution and generation record references per edge", "Assertion identifier and its record-time instant" ] }, { "id": "als-query-q-path-direction", "text": "How is direction handled for asymmetric relation kinds such as broader or narrower match when traversal is requested in both directions?", "kind": "relationship", "answer_data": [ "Per-edge direction marker", "Inverse relation pairing used", "Statement of whether a mixed-direction path is admitted by the profile" ] } ], "data_elements": [ { "id": "als-query-de-path-edge-sequence", "name": "Path Edge Sequence", "description": "Ordered sequence of edges forming one candidate path, each carrying its relation kind, direction, derivation label and provenance references.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-048", "SRC-009" ] }, { "id": "als-query-de-path-hop-count", "name": "Path Hop Count", "description": "Number of edges crossed on the path, compared against the requested and service hop limits.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-048" ] }, { "id": "als-query-de-cycle-notice", "name": "Cycle Notice", "description": "Notice that a cycle was encountered on or adjacent to a path, with the termination rule applied.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-048" ] }, { "id": "als-query-de-truncation-reason", "name": "Truncation Reason", "description": "Reason the enumeration stopped short of completeness: hop limit, result limit, timeout, refused source or unreachable source.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-092", "SRC-094" ] }, { "id": "als-query-de-continuation-token", "name": "Continuation Token", "description": "Opaque token allowing deterministic continuation of a truncated traversal under the same profile versions and parameters.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "als-query-art-traversal-path-report", "name": "Alias Traversal Path Report", "description": "The report of one traversal request: every candidate path with per-edge provenance and derivation labels, composed strength and exclusion reasons, cycle and contradiction notices, truncation reason, continuation token and the full parameter echo.", "media_or_form": [ "structured path report", "graph path rendering", "narrative traversal explanation" ], "serial": true, "identity_strategy": "Dimension-assigned ULID bound to the request record identifier and to the capability and relation-property profile versions; continuation segments reuse the report identifier with an incrementing segment number.", "source_refs": [ "SRC-048", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "als-query-strength-and-contradiction", "name": "Strength Loss Budget and Contradictory Edges", "description": "A path carries a composed strength derived from per-edge confidence and relation-kind semantics under a declared, versioned composition method. Paths exceeding the requested maximum strength loss are excluded with a stated reason rather than dropped. A path crossing an asserted not-same pair, or combining relation kinds declared disjoint, is reported as contradicted and is never silently removed from the answer.", "source_refs": [ "SRC-003", "SRC-001", "SRC-019", "SRC-033", "SRC-030" ], "questions": [ { "id": "als-query-q-strength-method", "text": "Which composition method converted per-edge confidence into a path strength, and is it presented as a declared measurement rather than a truth claim?", "kind": "measurement", "answer_data": [ "Composition method reference and version", "Per-edge confidence inputs and any defaults applied", "Statement that the value is an annotation, not an assertion of fact" ] }, { "id": "als-query-q-strength-budget", "text": "How was the maximum allowed strength loss applied, and are excluded paths reported together with the reason for exclusion?", "kind": "constraint", "answer_data": [ "Budget value applied", "Excluded path references with computed loss", "Exclusion reason code per excluded path" ] }, { "id": "als-query-q-strength-contradiction", "text": "How is a path that crosses an asserted not-same pair or a disjoint relation-kind combination reported to the caller?", "kind": "exception", "answer_data": [ "Contradiction notice with the implicated assertion references", "Both conflicting assertions with their authorities and instants", "Explicit statement that the contradiction is reported and not resolved" ] }, { "id": "als-query-q-strength-heterogeneous", "text": "How is strength composed across a path that mixes relation kinds with different transitivity guarantees?", "kind": "quality", "answer_data": [ "Per-kind transitivity flags encountered on the path", "Rule applied where a non-transitive kind is chained", "Warning marker where the composed value is not defensible" ] } ], "data_elements": [ { "id": "als-query-de-edge-confidence", "name": "Edge Confidence Value", "description": "Confidence or strength value asserted for an individual edge by its asserting authority, or the declared default for its relation kind where none was asserted.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-033", "SRC-003" ] }, { "id": "als-query-de-path-strength", "name": "Composed Path Strength", "description": "Value computed for a whole path under the declared composition method, together with the loss relative to a fully asserted exact-equivalence path.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-033", "SRC-003" ] }, { "id": "als-query-de-strength-method-ref", "name": "Strength Composition Method Reference", "description": "Versioned reference to the arithmetic and per-kind weighting used, without which a composed value is not interpretable across authorities.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-033" ] }, { "id": "als-query-de-contradiction-notice", "name": "Contradiction Notice", "description": "Notice that a path crosses an asserted not-same pair or combines relation kinds declared disjoint, listing the implicated assertions.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "als-query-de-exclusion-reason", "name": "Path Exclusion Reason", "description": "Reason a path satisfying the structural filter was nevertheless excluded from the admitted answer, such as exceeding the strength-loss budget.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-033" ] } ], "artifacts": [], "inline_only_rationale": "Strength values, exclusion reasons and contradiction notices are computed annotations attached to paths that the traversal path report already carries. Emitting them as a separate artifact would create a standing conflict record with its own lifecycle, which would imply that this model resolves contradictions between authorities; resolution belongs to the asserting authorities and to the adopting Dimension's stewardship process." } ] }, { "id": "als-query-comparison-integrity", "name": "Assertion Comparison and Result Integrity", "description": "Non-adjudicating comparison of competing assertions, and the completeness and disclosure statement that must accompany every answer, including access-suppressed content, unreachable sources and request-validation outcomes.", "source_refs": [ "SRC-092", "SRC-045", "SRC-067", "SRC-072", "SRC-033" ], "findings": [ { "id": "als-query-assertion-comparison", "name": "Non-Adjudicating Comparison of Competing Assertions", "description": "Given two or more assertions about the same endpoint pair or the same candidate, the comparison reports how they differ across asserting authority, relation semantics, confidence, declared context, temporal validity, evidence and lifecycle state, and identifies which dimensions were unavailable. It does not rank authorities, does not declare a winner, and separates verification of an assertion's integrity from any decision to rely on it.", "source_refs": [ "SRC-072", "SRC-045", "SRC-009", "SRC-033", "SRC-030", "SRC-014" ], "questions": [ { "id": "als-query-q-compare-dimensions", "text": "Along which dimensions were the assertions compared, and which of those dimensions were unavailable for at least one of them?", "kind": "composition", "answer_data": [ "Comparison dimension set applied", "Per-dimension difference summary", "List of dimensions marked unavailable and why" ] }, { "id": "als-query-q-compare-authority", "text": "How is a difference in asserting authority represented without implying a precedence order between those authorities?", "kind": "authority", "answer_data": [ "Authority reference and declared remit per assertion", "Guarantee level each authority states for its own claims", "Explicit marker that no precedence was applied" ] }, { "id": "als-query-q-compare-context", "text": "How are two assertions that hold in different declared contexts reported, given that neither refutes the other?", "kind": "classification", "answer_data": [ "Declared context per assertion", "Context overlap or disjointness assessment", "Outcome code recording context divergence rather than conflict" ] }, { "id": "als-query-q-compare-evidence", "text": "What evidence reference and verification state are shown for each assertion, and is verification kept separate from acceptance of the claim?", "kind": "evidence", "answer_data": [ "Evidence reference per assertion", "Verification state and the mechanism that produced it", "Statement that verification does not establish the truth of the claim" ] }, { "id": "als-query-q-compare-outcome", "text": "Which outcome vocabulary is used when the comparison cannot be settled from the recorded facts alone?", "kind": "state", "answer_data": [ "Outcome code set covering context, time, authority, contradiction and non-comparability", "Referral target for unresolved outcomes", "Statement that the query surface does not adjudicate" ] } ], "data_elements": [ { "id": "als-query-de-compared-assertion-ref", "name": "Compared Assertion Reference", "description": "Reference to each assertion entering the comparison, using the authoritative master-system identifier issued by its asserting authority.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009", "SRC-096" ] }, { "id": "als-query-de-difference-dimension", "name": "Difference Dimension", "description": "The dimension along which a difference was found: authority, relation semantics, confidence, context, time, evidence or lifecycle state.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-072", "SRC-003" ] }, { "id": "als-query-de-difference-summary", "name": "Difference Summary", "description": "Factual statement of how the assertions differ on one dimension, phrased without preference between them.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-045", "SRC-072" ] }, { "id": "als-query-de-evidence-verification-state", "name": "Evidence Verification State", "description": "Whether the evidence supporting an assertion was verified, unverifiable within scope, or not verified, kept distinct from any judgement of the claim.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-072", "SRC-014" ] }, { "id": "als-query-de-comparison-outcome", "name": "Comparison Outcome Code", "description": "Single code recording the nature of the divergence, such as differ-in-context, differ-in-time, differ-in-authority, mutually-contradictory or not-comparable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-072", "SRC-045" ] } ], "artifacts": [ { "id": "als-query-art-assertion-comparison-report", "name": "Alias Assertion Comparison Report", "description": "The report of one comparison request: the assertions compared, the dimensions applied, per-dimension differences, evidence and verification states, unavailable dimensions and a single outcome code, with no ranking or selection.", "media_or_form": [ "structured comparison record", "side-by-side comparison table", "narrative difference explanation" ], "serial": true, "identity_strategy": "Dimension-assigned ULID bound to the request record identifier; each compared assertion is referenced by the authoritative master-system identifier issued by its asserting authority.", "source_refs": [ "SRC-072", "SRC-045" ] } ], "inline_only_rationale": null }, { "id": "als-query-result-integrity-disclosure", "name": "Result Integrity and Disclosure Statement", "description": "Every answer is accompanied by a statement of what was and was not reachable: sources consulted, skipped, refused or failed, and whether a failure was silenced or hard; limits reached; access-suppressed candidates or evidence; unresolvable endpoints; and the request-validation outcome with severities. Absence of an answer is never presented as evidence of non-equivalence.", "source_refs": [ "SRC-092", "SRC-094", "SRC-045", "SRC-023", "SRC-067" ], "questions": [ { "id": "als-query-q-integrity-sources", "text": "Which sources were consulted, which failed or were skipped, and was a failure treated as silent or as a hard error?", "kind": "process", "answer_data": [ "Source list with per-source outcome", "Failure mode per failed source", "Effect of each failure on the completeness state" ] }, { "id": "als-query-q-integrity-hidden", "text": "How does the statement separate nothing asserted, withheld by access scope, and source unavailable?", "kind": "security", "answer_data": [ "Distinct completeness codes for each condition", "Suppression signal that does not reveal withheld content", "Note that transport-level concealment may collapse these at the projection layer" ] }, { "id": "als-query-q-integrity-validation", "text": "Which request-validation results, severities and focus parameters are returned to the caller?", "kind": "validation", "answer_data": [ "Conformance flag for the request", "Per-result severity and focus parameter", "Constraint or capability limit that produced each result" ] }, { "id": "als-query-q-integrity-retention", "text": "For how long are a result and its disclosure statement retained for replay and dispute handling, and who owns the disposition decision?", "kind": "retention", "answer_data": [ "Retention period and its governing policy reference", "Tombstone content retained after disposition", "Owner accountable for executing disposition" ] } ], "data_elements": [ { "id": "als-query-de-sources-consulted", "name": "Sources Consulted", "description": "The authority scopes, datasets or endpoints actually consulted for this answer, including those consulted and returning nothing.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-092", "SRC-093" ] }, { "id": "als-query-de-source-failure-mode", "name": "Source Failure Mode", "description": "Per source, whether a failure was silenced into an empty result, raised as a hard error, refused by the service, or skipped as out of scope.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-092", "SRC-094" ] }, { "id": "als-query-de-completeness-state", "name": "Completeness State", "description": "Overall statement of whether the answer is complete for the requested parameters, partial with disclosed causes, or not answerable in scope.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-092", "SRC-023" ] }, { "id": "als-query-de-validation-severity", "name": "Validation Result Severity", "description": "Severity attached to each request-validation result, with the focus parameter it concerns.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-045" ] }, { "id": "als-query-de-retention-policy-ref", "name": "Retention Policy Reference", "description": "Reference to the adopting Dimension's retention and disposition policy governing this result record; the policy is referenced, not implemented here.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-067", "SRC-009" ] } ], "artifacts": [ { "id": "als-query-art-disclosure-statement", "name": "Alias Query Completeness and Disclosure Statement", "description": "The mandatory companion record to any result set or path report, stating sources consulted and their outcomes, limits reached, suppression signal, unresolvable endpoints and the resulting completeness state.", "media_or_form": [ "structured disclosure record", "human-readable caveat note" ], "serial": true, "identity_strategy": "Dimension-assigned ULID bound one-to-one to the identifier of the result set or path report it qualifies, and through it to the request record identifier.", "source_refs": [ "SRC-092", "SRC-023", "SRC-067" ] }, { "id": "als-query-art-request-validation-report", "name": "Alias Query Request Validation Report", "description": "Report of validating a request against the capability profile: a conformance flag plus, for each result, a severity, the focus parameter and the constraint or limit that produced it, leaving the request and the assertions unchanged.", "media_or_form": [ "structured validation report", "validation summary listing" ], "serial": true, "identity_strategy": "Dimension-assigned ULID bound to the request record identifier and to the capability profile version validated against.", "source_refs": [ "SRC-045", "SRC-094", "SRC-093" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-report-conflict-and-impact", "name": "Conflict and Change-Impact Reporting", "description": "Everything needed to state, without deciding, what is incompatible within a federated alias assertion set, and what a change to that set does to assertions, derived cluster views and downstream references.", "rationale": "Two independent normative precedents establish the shape of a report that grades findings but does not resolve them: the SHACL validation report (results with focus item, source constraint and severity) and the FHIR OperationOutcome (severity-graded issues that are explicitly not an adjudication). The substance of what can conflict is fixed by OWL 2 (SameIndividual versus DifferentIndividuals is an inconsistency; no unique name assumption), SKOS (exactMatch is transitive, closeMatch deliberately is not, to avoid compound errors), FHIR link types and assurance levels (directed supersession, ordinal confidence), and PROV-O (derivation, revision and invalidation lineage). Grouping conflict and impact together is justified because both are read-only projections over the same assertion set at a declared observation time, and both must publish their own coverage limits rather than imply completeness.", "source_refs": [ "SRC-045", "SRC-009", "SRC-003", "SRC-001", "SRC-027", "SRC-039", "SRC-097" ], "layers": [ { "id": "als-report-conflict-surface", "name": "Conflict Surface and Report Request Contract", "description": "What can be in conflict within an alias assertion set, and the bounded, reproducible request contract under which a conflict report is produced.", "source_refs": [ "SRC-045", "SRC-003", "SRC-001", "SRC-039", "SRC-008" ], "findings": [ { "id": "als-report-conflict-taxonomy", "name": "Conflict class taxonomy over alias assertions", "description": "The governed set of conflict classes a report may state over an alias assertion set: incompatible asserting authorities over the same endpoint pair; incompatible equivalence strength or semantics; divergent confidence or assurance; mismatched context of assertion; temporal incompatibility between validity intervals; conflicting or absent evidence; violation of an explicit not-same constraint; and incompatible lifecycle states. Each class is defined by what makes two claims incompatible rather than merely different, and by the comparison that detects it. The taxonomy is extensible by an adopting Dimension through namespaced codes but the base classes are fixed so that consumers can rely on them.", "source_refs": [ "SRC-045", "SRC-003", "SRC-001", "SRC-039" ], "questions": [ { "id": "als-report-conflict-class-set", "text": "Which conflict classes may a conflict report state over an alias assertion set, and how is each class defined?", "kind": "classification", "answer_data": [ "Conflict class code from the governed base vocabulary", "Normative definition of incompatibility for that class", "Comparison operation that detects the class", "Minimum number and role of participating assertions" ] }, { "id": "als-report-not-same-versus-strength", "text": "How does a report distinguish a formal not-same violation from a mere disagreement about equivalence strength?", "kind": "constraint", "answer_data": [ "Flag indicating whether the incompatibility is logically entailed (SameIndividual plus DifferentIndividuals) or semantic (exactMatch versus closeMatch versus alternateOf)", "Reference to the asserted difference constraint", "Reference to the strength vocabulary and version each participant used" ] }, { "id": "als-report-conflict-versus-scope-difference", "text": "What makes two competing assertions genuinely conflicting rather than merely scoped to different contexts?", "kind": "definition", "answer_data": [ "Context qualifier of each participating assertion", "Result of context-overlap test", "Reason code for classifying as conflict, as scoped-difference, or as undecidable" ] }, { "id": "als-report-time-dependent-classes", "text": "Which conflict classes become detectable only when validity intervals or observation times are compared?", "kind": "temporal", "answer_data": [ "Validity interval start and end of each participant", "Observation time of each participant", "Interval relation code (overlap, meets, disjoint, unbounded)", "Flag for conflicts that vanish when intervals are respected" ] }, { "id": "als-report-taxonomy-extension", "text": "How may an adopting Dimension extend the conflict class vocabulary without breaking existing report consumers?", "kind": "interoperability", "answer_data": [ "Extension namespace identifier", "Vocabulary version bound to the report", "Consumer rule for unknown codes", "Deprecation state of any base code" ] } ], "data_elements": [ { "id": "als-report-conflict-class-code", "name": "Conflict class code", "description": "Governed code identifying the class of incompatibility being stated, drawn from the base vocabulary or a declared extension namespace.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-045", "SRC-097" ] }, { "id": "als-report-conflict-class-definition", "name": "Conflict class definition", "description": "Normative text stating what makes participating claims incompatible for this class, so that a consumer can falsify the classification.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "als-report-conflict-detection-basis", "name": "Detection basis", "description": "The comparison that produced the classification, for example logical entailment over difference axioms, strength-vocabulary comparison, interval relation, or assurance-level divergence.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-039" ] }, { "id": "als-report-strength-vocabulary-binding", "name": "Equivalence strength vocabulary binding", "description": "Identifier and version of the vocabulary each participating assertion used to express equivalence strength, required because transitive and deliberately non-transitive relations must not be silently merged.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-009" ] }, { "id": "als-report-conflict-extension-namespace", "name": "Conflict class extension namespace", "description": "Namespace under which an adopting Dimension registers additional conflict classes.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-045" ] } ], "artifacts": [], "inline_only_rationale": "The taxonomy is governed controlled-vocabulary content, not a produced document. It is consumed by reference from every conflict report instance through a vocabulary identifier and version, and materialising it as a separate artifact per report would create drifting copies of a definition that must stay single-sourced. The classes themselves are inline reference data owned by the vocabulary steward role." }, { "id": "als-report-conflict-request-contract", "name": "Conflict report request scope, preconditions and failure modes", "description": "The bounded request contract that makes a conflict report reproducible and honest about its own limits: which assertion population is in scope, which preconditions must hold before a report can be produced, which failure mode applies when each precondition is unmet, how partial coverage is declared when a participating authority is unreachable, and which observation cut-off time governs the whole report.", "source_refs": [ "SRC-045", "SRC-097", "SRC-008", "SRC-033" ], "questions": [ { "id": "als-report-scope-definition", "text": "What scope selector defines the assertion population that a conflict report covers?", "kind": "composition", "answer_data": [ "Selector expression over endpoints, authorities, subject types or clusters", "Included and explicitly excluded authority references", "Resolved count of assertions in scope", "Immutable scope binding reference" ] }, { "id": "als-report-preconditions", "text": "Which preconditions must hold before a conflict report can be produced, and which failure mode applies when each is unmet?", "kind": "requirement", "answer_data": [ "Precondition identifier and outcome", "Failure mode code (unresolvable scope, snapshot unavailable, vocabulary version mismatch, authority unreachable)", "Whether the failure aborts the report or degrades it", "Failure outcome record reference" ] }, { "id": "als-report-partial-coverage", "text": "How does a report record partial coverage when a participating authority is unreachable at production time?", "kind": "exception", "answer_data": [ "Unreachable authority reference and reason", "Coverage completeness qualifier for the affected scope", "Statement that absence of a conflict for that authority is not a negative finding", "Retry or re-request guidance reference" ] }, { "id": "als-report-cutoff-versus-event-time", "text": "Which observation cut-off time governs the report, and how is it kept distinct from the event times of the assertions it covers?", "kind": "temporal", "answer_data": [ "Observation cut-off timestamp with explicit offset", "Covered event-time range of the assertion population", "Input snapshot ingestion timestamp", "Statement that assertions with a later event time are outside the report" ] } ], "data_elements": [ { "id": "als-report-scope-selector", "name": "Scope selector", "description": "Declarative expression resolving the assertion population in scope for a report, retained so a later run over the same snapshot yields the same population.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-report-precondition-outcome", "name": "Precondition outcome", "description": "Per-precondition record of whether the condition held, was waived, or triggered a failure mode.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-097" ] }, { "id": "als-report-failure-mode-code", "name": "Failure mode code", "description": "Code identifying why report production aborted or degraded, aligned to a severity-graded issue vocabulary.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-097", "SRC-045" ] }, { "id": "als-report-coverage-completeness", "name": "Coverage completeness qualifier", "description": "Explicit statement of how completely the declared scope was actually examined, cited as a referenced quality measurement where one exists.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-033", "SRC-101" ] }, { "id": "als-report-observation-cutoff-time", "name": "Observation cut-off time", "description": "RFC 3339 timestamp with explicit seconds and offset defining the instant beyond which no input was considered.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "A report request is an input binding and a set of gate outcomes, not a retained document. Its durable value is carried forward into the released report instance as the frozen scope binding, snapshot reference and cut-off time, so persisting it as a second artifact would duplicate the reproducibility basis and create two things that can disagree about the same run." } ] }, { "id": "als-report-conflict-statement", "name": "Conflict Statement Composition and Neutrality", "description": "How an individual conflict is stated so that it is traceable, gradeable and independently checkable, and the rules that stop a report from quietly resolving what it is only supposed to expose.", "source_refs": [ "SRC-045", "SRC-001", "SRC-039", "SRC-097", "SRC-009" ], "findings": [ { "id": "als-report-conflict-result-record", "name": "Individual conflict result record", "description": "The atomic unit of a conflict report: a single stated incompatibility naming its participating assertions, the identifier endpoints and asserting authorities involved, the conflict class, an optional severity or significance grade, a human-readable message and the evidence and comparison basis that lets a consumer re-derive the finding. The record grades significance but decides nothing: it never marks a participant as correct, never removes a participant and never changes any assertion's lifecycle state.", "source_refs": [ "SRC-045", "SRC-097", "SRC-001", "SRC-039" ], "questions": [ { "id": "als-report-result-identity", "text": "What identifies a single conflict result within a report, and is that identity stable when the report is reissued?", "kind": "identity", "answer_data": [ "Conflict result identifier", "Derivation rule for the identifier (participants plus class plus context)", "Stability guarantee across reissues of the same series", "Link to the corresponding result in a prior instance" ] }, { "id": "als-report-result-participants", "text": "Which participating assertions, asserting authorities and identifier endpoints must every conflict result cite?", "kind": "relationship", "answer_data": [ "Participating assertion references", "Asserting authority reference per participant", "Identifier endpoint references", "Role of each participant in the conflict (both required, or focus plus counterpart)" ] }, { "id": "als-report-result-severity-limit", "text": "What severity or significance grade may a conflict result carry, and what does that grade explicitly not decide?", "kind": "decision", "answer_data": [ "Severity code and the vocabulary it comes from", "Explicit non-adjudication statement bound to the result", "Named party or model responsible for any resolution decision", "Statement that severity is not a truth ranking of participants" ] }, { "id": "als-report-result-evidence", "text": "What evidence and comparison basis must be cited so a consumer can independently re-derive the stated conflict?", "kind": "evidence", "answer_data": [ "Evidence references per participant", "Source constraint or rule reference that produced the result", "Values or interval relations compared", "Snapshot reference the comparison ran against" ] } ], "data_elements": [ { "id": "als-report-conflict-result-id", "name": "Conflict result identifier", "description": "Stable identifier for one stated conflict, derived deterministically from participants, class and context so that the same conflict keeps the same identity across reissues.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-report-conflict-participant", "name": "Conflict participant", "description": "Reference to one participating alias assertion together with its asserting authority and identifier endpoint, and its role in the conflict.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-027", "SRC-001" ] }, { "id": "als-report-conflict-severity", "name": "Conflict severity grade", "description": "Graded significance of the stated conflict drawn from a declared severity vocabulary; informational only, never a ruling on which participant is correct.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-045", "SRC-097" ] }, { "id": "als-report-conflict-source-constraint", "name": "Source constraint reference", "description": "Reference to the rule, shape or definition whose comparison produced this result, so the finding is attributable rather than opaque.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-report-conflict-evidence-ref", "name": "Conflict evidence reference", "description": "References to the evidence each participant relies on, including any externally computed assurance level or quality measurement.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-039", "SRC-033" ] }, { "id": "als-report-conflict-message", "name": "Conflict result message", "description": "Human-readable statement of the incompatibility, phrased descriptively and without recommending a winner.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-045", "SRC-097" ] } ], "artifacts": [ { "id": "als-report-conflict-report", "name": "Alias conflict report instance", "description": "A released, immutable report over a frozen assertion scope, containing a conformance-style summary, the ordered set of conflict result records, the declared coverage and completeness statement, the vocabulary version bindings and the report provenance. It states incompatibilities and adjudicates none.", "media_or_form": [ "Structured record set with a conformance summary and an ordered result collection", "Graph serialisation aligned to a validation-report shape", "Tabular or document rendering derived from the same canonical record set" ], "serial": true, "identity_strategy": "Identified by the report series identifier plus the instance identifier minted per artifact_rules.identity_priority; a conflict result inside the instance is identified by als-report-conflict-result-id, which is deterministic over participants, class and context so results can be diffed across instances.", "source_refs": [ "SRC-045", "SRC-097", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "als-report-minority-claim-preservation", "name": "Non-adjudication and minority-claim preservation", "description": "The rules that keep a conflict report honest: every participating claim that falls inside the declared scope appears in the report regardless of its authority weight or confidence, any ordering presented is labelled with its basis and marked as presentational rather than resolutive, exclusion by scope is disclosed and distinguished from exclusion by judgement, and the party or model accountable for any downstream adjudication is named by reference rather than acted for.", "source_refs": [ "SRC-045", "SRC-097", "SRC-001", "SRC-033" ], "questions": [ { "id": "als-report-no-suppression", "text": "Which rules prevent a conflict report from dropping, collapsing or down-weighting a minority or low-confidence claim out of view?", "kind": "constraint", "answer_data": [ "Inclusion status per in-scope claim", "Prohibition rule identifier that forbids silent omission", "Count of in-scope claims versus count of reported claims", "Reconciliation statement when the two counts differ" ] }, { "id": "als-report-ordering-basis-question", "text": "How is an authority-weighted or confidence-weighted ordering presented so that it cannot be read as a resolution?", "kind": "quality", "answer_data": [ "Ordering basis descriptor and the property it sorts on", "Presentational-only marker", "Referenced measurement or assurance level used for ordering", "Statement that ordering does not alter any assertion state" ] }, { "id": "als-report-exclusion-transparency", "text": "How does a report disclose that a claim was excluded by scope rather than by judgement about its merit?", "kind": "provenance", "answer_data": [ "Exclusion reason code (out of scope, unreachable authority, later than cut-off)", "Selector clause that caused the exclusion", "Excluded claim reference where the reference itself is in scope to disclose" ] }, { "id": "als-report-adjudication-accountability", "text": "Who is recorded as accountable for the adjudication that the report deliberately leaves open?", "kind": "ownership", "answer_data": [ "Referral target reference (role, model or adopting-Dimension body)", "Statement that this model performs no resolution", "Open-conflict handoff payload reference" ] } ], "data_elements": [ { "id": "als-report-claim-inclusion-status", "name": "Claim inclusion status", "description": "Per in-scope claim, whether it was included in the report, and if not, the disclosed reason.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-report-exclusion-reason", "name": "Exclusion reason", "description": "Reason code and selector clause explaining a scope-based exclusion, so that omission is never mistaken for a merit judgement.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-097", "SRC-101" ] }, { "id": "als-report-ordering-basis", "name": "Ordering basis descriptor", "description": "Declared property and direction used to order results or participants, with an explicit presentational-only marker.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-033", "SRC-039" ] }, { "id": "als-report-adjudication-referral-ref", "name": "Adjudication referral reference", "description": "Reference to the role, model or body accountable for resolving an open conflict, recorded so the report can hand off without acting.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-098", "SRC-055" ] } ], "artifacts": [], "inline_only_rationale": "These are invariants that constrain how the conflict report artifact is composed, plus per-claim inclusion metadata that lives inside that artifact. Emitting a separate neutrality document would produce a policy statement this model does not own and would let the rules drift from the reports they govern; the rules belong in the model's policy layer and their per-run evidence belongs inline in the report." } ] }, { "id": "als-report-impact-projection", "name": "Change Impact Projection", "description": "Which changes to an alias assertion set trigger an impact report, and how impact is projected across assertions, derived cluster views and downstream references with full lineage and declared uncertainty.", "source_refs": [ "SRC-009", "SRC-027", "SRC-100", "SRC-101", "SRC-033" ], "findings": [ { "id": "als-report-impact-trigger-classification", "name": "Impact trigger event classification", "description": "The classified change events that warrant an impact report: supersession of an assertion by a later one; retraction or withdrawal of an assertion by its authority; merge of two endpoint clusters into one; split of a cluster into two or more; a policy change that alters which equivalence strengths or confidence levels are admissible; and discovery that a previously accepted strong-identity assertion was false. Retraction and supersession are kept apart because their retrospective reach differs: supersession leaves the prior claim historically true within its interval, retraction asserts it was never sound.", "source_refs": [ "SRC-009", "SRC-027", "SRC-100", "SRC-001" ], "questions": [ { "id": "als-report-trigger-classes", "text": "Which change events trigger an impact report, and how is each event class defined?", "kind": "event", "answer_data": [ "Trigger class code (supersession, retraction, merge, split, policy change, false strong identity)", "Definition and minimum evidence for each class", "Reference to the triggering change record", "Event time of the trigger with explicit offset" ] }, { "id": "als-report-retraction-versus-supersession", "text": "How is a retraction distinguished from a supersession in impact terms?", "kind": "lifecycle", "answer_data": [ "Prior lifecycle state and posterior lifecycle state", "Whether the prior claim remains historically valid within its interval", "Invalidation time where the claim was invalidated rather than revised", "Revision link where a successor assertion exists" ] }, { "id": "als-report-false-identity-reach", "text": "When a strong-identity assertion is later found false, what retrospective scope must the impact report cover?", "kind": "exception", "answer_data": [ "Retrospective window start (earliest event time at which the false claim could have propagated)", "Set of derived views computed while the false claim held", "Downstream references issued during the window", "Statement of what could not be enumerated" ] }, { "id": "als-report-policy-change-trigger", "text": "How is a policy change that alters admissible equivalence strength or confidence represented as an impact trigger?", "kind": "authority", "answer_data": [ "Policy reference and version before and after", "Issuing authority reference", "Effective time of the policy change", "Set of assertions whose admissibility status changes, without any state change being applied" ] } ], "data_elements": [ { "id": "als-report-impact-trigger-code", "name": "Impact trigger class code", "description": "Governed code for the class of change that occasioned the impact report.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-100", "SRC-027" ] }, { "id": "als-report-trigger-event-time", "name": "Trigger event time", "description": "RFC 3339 timestamp with explicit seconds and offset for when the triggering change occurred, distinct from when this model observed it.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-report-trigger-source-ref", "name": "Trigger source reference", "description": "Reference to the change record, authority decision or policy version that constitutes the trigger, held by whichever model owns it.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-098" ] }, { "id": "als-report-retrospective-window", "name": "Retrospective window", "description": "Bounded event-time interval during which a now-falsified or superseded claim could have propagated, defining the report's backward reach.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-101" ] } ], "artifacts": [], "inline_only_rationale": "Trigger classification is governed vocabulary plus per-run parameters that are carried inside the impact report artifact. The triggering change records themselves are owned by the assertion lifecycle surface and by the policy or authority models that issued them, so materialising a separate trigger artifact here would duplicate records this model does not own." }, { "id": "als-report-impact-surface-and-lineage", "name": "Impact surfaces, lineage and residual uncertainty", "description": "Impact is projected across three surfaces with distinct units. At assertion level the unit is a single alias assertion whose admissibility, strength or lifecycle relevance changes. At cluster-view level the unit is a derived endpoint cluster that gains, loses, merges or splits members, and the fate of each member must be stated. At downstream-reference level the unit is a consuming reference that resolved through the changed alias. Every impacted item carries lineage back to the triggering change and to its prior state, and the report states the residual uncertainty where downstream reach cannot be fully enumerated rather than implying complete coverage.", "source_refs": [ "SRC-009", "SRC-101", "SRC-033", "SRC-027", "SRC-100" ], "questions": [ { "id": "als-report-impact-surfaces", "text": "Which impact surfaces must an impact report cover, and what is the unit of impact on each?", "kind": "composition", "answer_data": [ "Surface code (assertion, cluster view, downstream reference)", "Unit of impact and its identifier type per surface", "Impacted item count per surface", "Surfaces explicitly not assessed and why" ] }, { "id": "als-report-impact-lineage", "text": "What lineage must be attached so a consumer can trace an impacted item back to the triggering change and to its prior state?", "kind": "provenance", "answer_data": [ "Derivation chain from impacted item to trigger", "Prior state reference or snapshot for the impacted item", "Revision or invalidation link where applicable", "Agent attributed with the triggering change" ] }, { "id": "als-report-cluster-split-fate", "text": "How does the report represent a cluster that splits into two or more clusters, including the fate of every member?", "kind": "state", "answer_data": [ "Predecessor cluster reference", "Successor cluster references", "Per-member assignment with the assertion that justifies it", "Members whose assignment is undetermined and the reason" ] }, { "id": "als-report-reach-uncertainty", "text": "How is residual uncertainty expressed when downstream reference reach cannot be fully enumerated?", "kind": "measurement", "answer_data": [ "Reach completeness qualifier and the measurement it cites", "Known-unknown categories (unindexed consumers, cached copies, offline replicas)", "Effort basis for stopping enumeration", "Explicit statement that unenumerated does not mean unaffected" ] }, { "id": "als-report-reference-knowability", "text": "Which downstream references are knowable to this model, and which are knowable only to the consuming system?", "kind": "interoperability", "answer_data": [ "Downstream reference index reference and its owner", "Index completeness declaration supplied by that owner", "Consumer-side reconciliation guidance", "Boundary statement that consumer-side propagation is not performed here" ] } ], "data_elements": [ { "id": "als-report-impact-surface-code", "name": "Impact surface code", "description": "Code identifying which of the assertion, cluster-view or downstream-reference surfaces an impacted item belongs to.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-027" ] }, { "id": "als-report-impacted-item-ref", "name": "Impacted item reference", "description": "Reference to the assertion, derived cluster or downstream reference that the triggering change affects.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009", "SRC-101" ] }, { "id": "als-report-prior-state-ref", "name": "Prior state reference", "description": "Reference or snapshot capturing the impacted item as it stood immediately before the trigger, without which impact cannot be verified.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-report-lineage-chain", "name": "Lineage chain", "description": "Ordered derivation, revision and invalidation links connecting the impacted item to the triggering change and to the responsible agent.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-report-cluster-member-fate", "name": "Cluster member fate", "description": "Per-member outcome of a merge or split, naming the successor cluster and the assertion that justifies the assignment, or recording that the assignment is undetermined.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-027", "SRC-009" ] }, { "id": "als-report-reach-completeness", "name": "Downstream reach completeness", "description": "Declared completeness of downstream-reference enumeration, citing the index that supplied it and the effort basis for stopping.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-101", "SRC-033" ] }, { "id": "als-report-uncertainty-qualifier", "name": "Residual uncertainty qualifier", "description": "Structured statement of what remains unknown about impact, including known-unknown categories, so a consumer never reads silence as absence of effect.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-033", "SRC-101" ] } ], "artifacts": [ { "id": "als-report-impact-report", "name": "Alias change-impact report instance", "description": "A released, immutable report describing a single classified triggering change and its projected effects across the assertion, cluster-view and downstream-reference surfaces, with per-item lineage back to the trigger and prior state, per-member fate for merges and splits, and an explicit reach-completeness and residual-uncertainty statement. It projects effects and performs none of them.", "media_or_form": [ "Structured record set partitioned by impact surface with an embedded lineage graph", "Graph serialisation using derivation, revision and invalidation relations", "Rendered summary derived from the same canonical record set" ], "serial": true, "identity_strategy": "Identified by the report series identifier plus the instance identifier minted per artifact_rules.identity_priority, and bound to exactly one trigger source reference and trigger event time; an impacted item entry is keyed by impact surface code plus impacted item reference.", "source_refs": [ "SRC-009", "SRC-101", "SRC-100" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-report-disposition-and-release", "name": "Disposition Readiness and Report Release Governance", "description": "Reporting on whether alias mapping records are ready for disposition without performing it, and governing the report instances themselves as identified, provenance-bearing, access-scoped objects whose delivery is somebody else's job.", "rationale": "NARA's Universal ERM Requirements treat Disposal, Transfer, Metadata and Reporting as distinct requirement areas, which supports reporting readiness as a capability separate from executing disposal. NARA's freeze process documentation shows that holds and freezes are placed by an agency Counsel's Office or by NARA, suspend the normal disposition cycle, and are released only on formal notification from that authority - so a readiness report can cite a block but can neither create nor lift it. GDPR Article 19 obliges a controller to communicate rectification, erasure or restriction to each recipient unless that proves impossible or involves disproportionate effort, which is exactly a downstream notification-content obligation with an explicit effort limit. Linked Data Notifications separates payload from sender, receiver and consumer roles and leaves the payload vocabulary open, and the Activity Vocabulary supplies Update, Delete, Undo and the Tombstone object with formerType and deleted. PROV-O and RFC 3339 govern report-instance lineage and time.", "source_refs": [ "SRC-055", "SRC-098", "SRC-099", "SRC-100", "SRC-101", "SRC-009", "SRC-008" ], "layers": [ { "id": "als-report-disposition-readiness", "name": "Disposition Readiness Assessment", "description": "Classifying each alias mapping record's readiness for disposition, citing the governing rule and any blocking hold, declaring what must survive as residue, and handing execution to the authority that owns it.", "source_refs": [ "SRC-055", "SRC-098", "SRC-100", "SRC-101" ], "findings": [ { "id": "als-report-disposition-status-classification", "name": "Disposition readiness status classification", "description": "Every alias mapping record in scope receives exactly one readiness status: eligible (a cited retention rule has run and no block applies); blocked (a cited legal hold, litigation hold or records freeze suspends disposition until the issuing authority formally releases it); retained (the record must persist as a tombstone or provenance residue even after content disposal); externally governed (disposition authority sits with a source authority or jurisdiction outside the adopting Dimension); or not assessed (readiness could not be determined within the report's observation window). Each status must cite its basis; a status is a finding about the record, never an instruction that disposal may proceed.", "source_refs": [ "SRC-055", "SRC-098", "SRC-100", "SRC-101" ], "questions": [ { "id": "als-report-status-set", "text": "Which disposition-readiness statuses can be reported for an alias mapping record, and how is each defined?", "kind": "classification", "answer_data": [ "Status code from the governed status set", "Definition and required citation for each status", "Rule that exactly one status applies per record per report", "Record reference the status is asserted about" ] }, { "id": "als-report-block-evidence", "text": "What must be cited for a blocked status, and which external authority issued the block?", "kind": "authority", "answer_data": [ "Hold or freeze reference and its type (litigation hold, agency freeze, other)", "Issuing authority reference", "Scope of the hold as issued", "Condition under which the issuing authority would release it" ] }, { "id": "als-report-eligibility-rule", "text": "Which retention rule or schedule reference makes a record eligible, and where is that rule owned?", "kind": "retention", "answer_data": [ "Retention rule or schedule reference and version", "Owning model or adopting-Dimension policy for that rule", "Earliest eligibility time computed under the rule", "Trigger event the rule keys on where the rule is event-based" ] }, { "id": "als-report-jurisdictional-governance", "text": "How is a record whose disposition authority sits in another jurisdiction or with a source authority reported?", "kind": "spatial", "answer_data": [ "Governing jurisdiction or authority reference", "Applicable instrument reference where known", "Statement that this report makes no determination under that regime", "Contact or handoff reference for the governing authority" ] }, { "id": "als-report-undetermined-readiness", "text": "What is reported when readiness cannot be determined within the report's observation window?", "kind": "state", "answer_data": [ "Not-assessed status with reason code", "Missing input references (unreachable hold register, unresolved retention rule)", "Statement that not assessed must never be treated as eligible", "Re-assessment condition" ] } ], "data_elements": [ { "id": "als-report-disposition-status-code", "name": "Disposition readiness status code", "description": "Exactly one governed status per record per report: eligible, blocked, retained, externally governed or not assessed.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-055", "SRC-098" ] }, { "id": "als-report-hold-reference", "name": "Hold or freeze reference", "description": "Reference to the litigation hold, legal hold or records freeze that blocks disposition, together with its issuing authority and scope as issued.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-098" ] }, { "id": "als-report-retention-rule-ref", "name": "Retention rule reference", "description": "Reference and version of the retention schedule or rule relied on for an eligible status, owned by the records retention model.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055", "SRC-098" ] }, { "id": "als-report-eligibility-earliest-time", "name": "Earliest eligibility time", "description": "RFC 3339 timestamp with explicit seconds and offset for the earliest instant the cited rule makes the record eligible; a reported readiness date is never used as the record's identifier.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-055" ] }, { "id": "als-report-governing-jurisdiction", "name": "Governing jurisdiction or authority", "description": "The jurisdiction or source authority holding disposition authority where it lies outside the adopting Dimension.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-101", "SRC-098" ] }, { "id": "als-report-status-basis-note", "name": "Status basis note", "description": "Short statement of why the status was assigned, so the classification is falsifiable by the receiving authority.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-055" ] } ], "artifacts": [ { "id": "als-report-disposition-readiness-report", "name": "Alias disposition-readiness report instance", "description": "A released, immutable report classifying each in-scope alias mapping record as eligible, blocked, retained, externally governed or not assessed, with the cited retention rule, hold and jurisdiction for each, the required residue for each, and a handoff payload addressed to the executing authority. It reports readiness and executes nothing.", "media_or_form": [ "Structured per-record status register with citations", "Handoff payload addressed to the executing records authority", "Rendered summary derived from the same canonical record set" ], "serial": true, "identity_strategy": "Identified by the report series identifier plus the instance identifier minted per artifact_rules.identity_priority; each per-record entry is keyed by the aliased mapping record's authoritative identifier plus the report instance identifier, never by an eligibility date.", "source_refs": [ "SRC-055", "SRC-098", "SRC-100" ] } ], "inline_only_rationale": null }, { "id": "als-report-disposition-residue-and-external-ownership", "name": "Required residue and execution handoff", "description": "What must survive an authorised disposition of an alias mapping record, why, and who acts. A tombstone retains only control metadata - the record identifier, its former type, the deletion time, the superseded-by or successor link and the disposition reference - so that dangling downstream references resolve to an explanatory marker rather than to nothing, while all alias content and any personal data are removed. The finding also fixes the handoff: which external model or adopting-Dimension policy executes disposition, and what the readiness report must contain so that executor need not re-derive scope.", "source_refs": [ "SRC-100", "SRC-055", "SRC-098", "SRC-101", "SRC-009" ], "questions": [ { "id": "als-report-residue-content", "text": "Which fragments of a disposed alias mapping record must survive as tombstone or provenance residue, and on what basis?", "kind": "retention", "answer_data": [ "Residue element list with a justification per element", "Former type of the disposed record", "Deletion timestamp with explicit offset", "Successor or superseded-by link where one exists" ] }, { "id": "als-report-execution-ownership", "text": "Which external model or adopting-Dimension policy executes the disposition that this report only declares readiness for?", "kind": "ownership", "answer_data": [ "Executing authority or model reference", "Instrument granting that authority", "Explicit statement that this model performs no deletion, destruction or transfer", "Confirmation channel by which execution is reported back" ] }, { "id": "als-report-handoff-sufficiency", "text": "What must a readiness report contain so the executing authority can act without re-deriving scope?", "kind": "process", "answer_data": [ "Frozen scope binding reference", "Per-record identifier list with statuses", "Cited rules and holds per record", "Report observation cut-off and validity limit of the assessment" ] }, { "id": "als-report-residue-reidentification", "text": "How is a residue record prevented from re-identifying a subject after erasure of personal data?", "kind": "privacy", "answer_data": [ "Residue field allow-list restricted to non-identifying control metadata", "Prohibited field list", "Linkability assessment reference", "Controller obligation reference for communicating erasure to recipients" ] } ], "data_elements": [ { "id": "als-report-residue-element", "name": "Required residue element", "description": "One field that must persist after disposition, with the justification that requires it; restricted to non-identifying control metadata where personal data is involved.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-100", "SRC-101" ] }, { "id": "als-report-residue-former-type", "name": "Former type of disposed record", "description": "The type the disposed alias mapping record formerly had, retained so a dangling reference resolves to an explanatory marker.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-100" ] }, { "id": "als-report-residue-deleted-time", "name": "Residue deletion time", "description": "RFC 3339 timestamp with explicit seconds and offset recording when the executing authority reported the record disposed; distinct from when this model observed that report.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-100", "SRC-008" ] }, { "id": "als-report-executing-authority-ref", "name": "Executing authority reference", "description": "Reference to the model, role or adopting-Dimension policy that performs the disposition and confirms it back.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-055", "SRC-098" ] }, { "id": "als-report-handoff-payload-ref", "name": "Handoff payload reference", "description": "Reference to the self-contained payload the executing authority receives: frozen scope, per-record statuses, cited rules and holds, and the assessment's validity limit.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-055", "SRC-009" ] }, { "id": "als-report-reidentification-risk-note", "name": "Re-identification risk note", "description": "Assessment of whether the retained residue could, alone or combined, re-identify a subject, with the mitigation applied.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-101" ] } ], "artifacts": [], "inline_only_rationale": "The residue specification is a declarative rule set, and the tombstone record it describes is created by the executing records authority at the moment of disposition, not by this model. Declaring an artifact here would imply that this model produces tombstones and therefore performs deletion, which the disposition boundary forbids; the handoff payload is a section of the readiness report artifact rather than an independent document." } ] }, { "id": "als-report-instance-governance", "name": "Report Instance Identity, Provenance and Release Boundary", "description": "Treating a released report as a governed object in its own right: how it is identified and versioned, which times it must carry, what provenance makes it reproducible, how it is access-scoped and redacted before release, and where this model's responsibility for change notification stops.", "source_refs": [ "SRC-009", "SRC-099", "SRC-100", "SRC-101", "SRC-008", "SRC-055" ], "findings": [ { "id": "als-report-instance-identity-and-release", "name": "Report instance identity, provenance, access scope and notification content", "description": "A report instance is an immutable, identified, provenance-bearing object belonging to a named series. It carries its generation time, the observation cut-off, the covered event-time range and the input snapshot ingestion time as separate values; corrections are issued as new instances linked to their predecessor by a revision relation, never by editing a released instance. Provenance records the generating agent, the frozen scope binding and the input snapshot so the instance is reproducible. Each section carries an access scope and any redaction applied before release. Where a change must be communicated, this model composes notification content describing the change and pointing at the released instance; discovery of an inbox, delivery, storage, receipt acknowledgement, retry and escalation belong entirely to the notification service.", "source_refs": [ "SRC-009", "SRC-099", "SRC-100", "SRC-101", "SRC-008" ], "questions": [ { "id": "als-report-instance-identity", "text": "What identifies a report instance, how does it relate to its series, and how is a corrected instance linked to the one it replaces?", "kind": "identity", "answer_data": [ "Report instance identifier minted under the identity priority", "Report series identifier", "Revision link to the predecessor instance", "Superseded marker on the predecessor and the reason for reissue" ] }, { "id": "als-report-instance-times", "text": "Which distinct times must a report instance carry, and how are event, observation and ingestion times kept separate?", "kind": "temporal", "answer_data": [ "Generation time with explicit seconds and offset", "Observation cut-off time", "Covered event-time range of the reported subject matter", "Input snapshot ingestion time" ] }, { "id": "als-report-instance-reproducibility", "text": "What provenance must be recorded so that a report instance can be reproduced from the same inputs?", "kind": "provenance", "answer_data": [ "Generating agent reference", "Frozen scope binding reference", "Input snapshot reference and its content digest", "Vocabulary and rule versions in force at generation" ] }, { "id": "als-report-instance-access-scope", "text": "Which access scope applies to each report section, and what redaction must be applied before release to a given audience?", "kind": "access", "answer_data": [ "Per-section access scope classification", "Redaction rule applied and the audience it was applied for", "Reference to the external authorization decision that permitted release", "Record of which sections were withheld" ] }, { "id": "als-report-notice-boundary", "text": "What notification content may this model produce for a reported change, and where does responsibility for delivery begin?", "kind": "interoperability", "answer_data": [ "Notice content payload describing the change type and affected items", "Dereferenceable reference to the released report instance", "Audience scope the content was redacted for", "Explicit statement that subscription, delivery, receipt and escalation are performed by the external notification service" ] } ], "data_elements": [ { "id": "als-report-instance-id", "name": "Report instance identifier", "description": "Identifier of one released report instance, minted under the model's identity priority and never derived from a date.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-008" ] }, { "id": "als-report-series-id", "name": "Report series identifier", "description": "Identifier of the ongoing series to which the instance belongs, giving the stable address consumers subscribe against.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-099" ] }, { "id": "als-report-generated-at-time", "name": "Report generation time", "description": "RFC 3339 timestamp with explicit seconds and offset for when the instance was generated, distinct from the observation cut-off and from the event times it covers.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-report-covered-event-time-range", "name": "Covered event-time range", "description": "Interval of subject-matter event time the instance reports on, so a consumer can tell what the report could and could not have seen.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "als-report-generating-agent-ref", "name": "Generating agent reference", "description": "The agent to which the report instance is attributed, whether a service or an accountable role.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-report-input-snapshot-ref", "name": "Input snapshot reference", "description": "Reference plus content digest for the frozen inputs the instance was produced from, the basis of every reproducibility claim.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-report-revision-of-ref", "name": "Revision-of reference", "description": "Link from a corrected or reissued instance to the instance it revises, so no released instance is ever silently rewritten.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-report-section-access-scope", "name": "Section access scope", "description": "Access classification for each report section, evaluated and enforced by an external authorization service.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-101", "SRC-055" ] }, { "id": "als-report-redaction-applied", "name": "Redaction applied", "description": "Record of which redaction rule was applied for which audience and which sections were withheld from that audience.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-101" ] }, { "id": "als-report-notice-payload", "name": "Change notice payload", "description": "Delivery-neutral content describing a reported change and pointing at the released report instance, produced without any assumption about transport.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-099", "SRC-100", "SRC-101" ] } ], "artifacts": [ { "id": "als-report-instance-provenance-record", "name": "Report instance provenance record", "description": "The provenance attached to a released report instance: attribution to the generating agent, generation time, the frozen scope binding and input snapshot with digest, the vocabulary and rule versions in force, and revision or invalidation links to predecessor instances. It is evidence for reproducibility, not an audit trail.", "media_or_form": [ "Provenance record aligned to derivation, revision, attribution and invalidation relations", "Structured header embedded in the report instance", "Standalone graph serialisation referencing the instance" ], "serial": true, "identity_strategy": "Keyed one-to-one by the report instance identifier it describes; the record is created with the instance and is never re-keyed, and predecessor linkage uses the revision-of reference rather than any ordering by generation time.", "source_refs": [ "SRC-009", "SRC-008" ] }, { "id": "als-report-change-notice-content", "name": "Alias change notice content", "description": "Delivery-neutral notification content describing a reported alias change - its change type, affected items, effective time and a dereferenceable reference to the released report instance - redacted for a stated audience scope. It is a payload only: it carries no inbox, endpoint, subscription, receipt or escalation semantics.", "media_or_form": [ "Structured notification payload with change type, affected items and a report reference", "Graph serialisation using update, delete and undo activity content and tombstone markers", "Plain-language summary rendered from the same payload" ], "serial": true, "identity_strategy": "Identified by the report instance identifier it describes plus the audience scope it was redacted for; the notification service assigns its own delivery identifiers, which this model neither mints nor stores.", "source_refs": [ "SRC-099", "SRC-100", "SRC-101" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "als-proj-bundle-surface", "name": "Projection surfaces and deterministic form", "description": "What alias assertions may be rendered into, how each target is described as a versioned capability profile, and how output is made byte-stable, self-describing and digestible.", "rationale": "Export semantics cannot be stated without a per-target capability declaration: constructs, qualifier slots, identifier forms, cardinality and metadata mechanisms differ sharply between RDF, tabular, document, MCP, database and HTTP surfaces. Only canonicalized, self-describing output can be compared, digested or re-imported, so determinism belongs with the surface definitions rather than with fidelity reporting.", "source_refs": [ "SRC-023", "SRC-024", "SRC-102", "SRC-077", "SRC-080", "SRC-103", "SRC-104", "SRC-105" ], "layers": [ { "id": "als-proj-layer-targets", "name": "Projection targets and binding", "description": "Capability profiles for each supported target, the distinct semantics of web-preference surfaces, and the binding parameters for record, document, interface and database projections.", "source_refs": [ "SRC-023", "SRC-024", "SRC-080", "SRC-103", "SRC-104", "SRC-105" ], "findings": [ { "id": "als-proj-target-profile", "name": "Projection target capability profile", "description": "A named, versioned declaration of what a projection target (Git/file template, Markdown, HTML, JSON, YAML, CSV, an RDF serialization, an HTTP API, an MCP resource, a MongoDB collection, or an HTTP redirect/canonical surface) can express: which relation strengths it can carry, which qualifiers have native slots, which identifier form it requires, what cardinality and ordering it guarantees, and which specification defines its metadata and typing mechanism. Nothing may be projected into a target that has no resolvable profile.", "source_refs": [ "SRC-080", "SRC-103", "SRC-104", "SRC-105", "SRC-108" ], "questions": [ { "id": "als-proj-q-tp-scope", "text": "What does a projection target profile declare, and what is the smallest set of capabilities a target must expose before an alias assertion may be projected into it?", "kind": "definition", "answer_data": [ "Target profile name and target family", "Declared capability list (constructs, qualifier slots, identifier forms, cardinality, ordering)", "Minimum-capability threshold and the consequence of falling below it" ] }, { "id": "als-proj-q-tp-identity", "text": "How is a target profile identified and versioned so that a released projection can be traced to the exact profile that governed it?", "kind": "identity", "answer_data": [ "Profile identifier under the Dimension namespace", "Monotonic profile version label", "Profile content digest recorded on the projection" ] }, { "id": "als-proj-q-tp-class", "text": "Which capability class does the target fall into: full-fidelity, lossy-but-qualified, or preference-only?", "kind": "classification", "answer_data": [ "Capability class code", "Set of relation strengths the target can carry", "Set of qualifiers with native slots and those without" ] }, { "id": "als-proj-q-tp-interop", "text": "Which external specification defines the target's metadata and typing mechanism, and which version of it does the profile bind to?", "kind": "interoperability", "answer_data": [ "Specification reference IRI", "Specification version or date", "Binding notes and known divergences from the specification" ] } ], "data_elements": [ { "id": "als-proj-de-tp-id", "name": "Profile identifier", "description": "Stable identifier of the target capability profile.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-108" ] }, { "id": "als-proj-de-tp-version", "name": "Profile version", "description": "Monotonic version label of the profile; never a date.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-108" ] }, { "id": "als-proj-de-tp-strengths", "name": "Supported relation strengths", "description": "Recorded strengths the target can express, each bound to its strongest permissible construct.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-041", "SRC-003" ] }, { "id": "als-proj-de-tp-qualifiers", "name": "Qualifier support map", "description": "Per-qualifier statement of whether the target has a native slot, an annotation workaround, or no representation.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-103" ] }, { "id": "als-proj-de-tp-idform", "name": "Required identifier form", "description": "Identifier form the target requires, such as absolute IRI, compact term, column value, or document key.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-105" ] }, { "id": "als-proj-de-tp-metaref", "name": "Metadata mechanism reference", "description": "Specification and version defining the target's metadata, typing or dialect declaration mechanism.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-103", "SRC-104", "SRC-108" ] } ], "artifacts": [ { "id": "als-proj-art-target-profile", "name": "Projection target capability profile", "description": "Versioned declaration of a single target's expressive capabilities, qualifier support, identifier form, cardinality and ordering guarantees, with citations to the specification that defines its constructs.", "media_or_form": [ "structured capability declaration in whatever form the adopting store uses", "human-readable profile page for reviewers" ], "serial": true, "identity_strategy": "Authoritative master-system profile identifier where the adopting Dimension registers profiles; otherwise the governed profile IRI under the Dimension namespace; otherwise a Dimension-minted UUID or ULID. The version is a monotonic sequence label and never encodes a date or digest.", "source_refs": [ "SRC-103", "SRC-104", "SRC-108" ] } ], "inline_only_rationale": null }, { "id": "als-proj-web-surface-binding", "name": "Web-preference projections: redirect, canonical link, HTML and RDF links", "description": "Binding rules for rendering alias assertions onto HTTP 3xx redirection, the canonical link relation, HTML link markup and RDF link predicates. These surfaces express routing or editorial preference, not identity: 301 and 308 assign a new permanent URI, 303 explicitly points at a different resource, and rel=canonical designates a preferred IRI whose content is duplicative of or a superset of the context IRI. RFC 8288 additionally forbids inferring further semantics from a relation type's presence, absence or cardinality. Output is an advisory map handed to the serving infrastructure.", "source_refs": [ "SRC-023", "SRC-024", "SRC-006", "SRC-041", "SRC-025" ], "questions": [ { "id": "als-proj-q-web-permitted", "text": "Which HTTP status code or link relation may a given recorded strength be projected onto, and which projections are forbidden for that strength?", "kind": "relationship", "answer_data": [ "Recorded strength code", "Permitted status code and relation-type set", "Forbidden set with the specification citation that forbids each" ] }, { "id": "als-proj-q-web-noidentity", "text": "What travels with a projected 301, 308 or canonical link to stop a consumer reading it as strict identity?", "kind": "constraint", "answer_data": [ "Emitted non-identity qualifier or note", "Specification citation carried alongside the projection", "Corresponding loss-report entry identifier" ] }, { "id": "als-proj-q-web-direction", "text": "How is the direction of a web projection determined when the underlying assertion is recorded as symmetric?", "kind": "classification", "answer_data": [ "Recorded canonical-preference value", "Direction rule identifier", "Flag stating whether both directions were emitted and why not" ] }, { "id": "als-proj-q-web-withhold", "text": "Under what conditions must a web projection be withheld even though the underlying assertion is publishable?", "kind": "exception", "answer_data": [ "Withholding condition code", "Affected identifiers or IRIs", "Reference to the refusal or partial-projection decision" ] }, { "id": "als-proj-q-web-owner", "text": "Who owns the infrastructure that would actually emit the redirect or canonical link, and what exactly is handed to them?", "kind": "authority", "answer_data": [ "Serving-infrastructure owner reference", "Handover artifact reference and format", "Advisory-only flag confirming this model does not deploy the change" ] } ], "data_elements": [ { "id": "als-proj-de-web-kind", "name": "Web surface kind", "description": "Which web surface the entry targets: status-code redirect, link-relation header, HTML markup, or RDF link predicate.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-006" ] }, { "id": "als-proj-de-web-status", "name": "Projected status code", "description": "HTTP status code proposed for the redirect projection, with its permanence semantics.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] }, { "id": "als-proj-de-web-rel", "name": "Link relation type", "description": "IANA-registered relation type proposed for the projection.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-024", "SRC-006" ] }, { "id": "als-proj-de-web-target", "name": "Preferred target IRI", "description": "IRI designated as the preferred or replacement target of the projection.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-024" ] }, { "id": "als-proj-de-web-advisory", "name": "Advisory-only flag", "description": "Assertion that the entry is a recommendation to the serving infrastructure and has not been deployed.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-006" ] }, { "id": "als-proj-de-web-note", "name": "Non-identity note", "description": "Text carried with the projection stating that the web surface expresses preference or routing, not equivalence.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-024", "SRC-025" ] } ], "artifacts": [ { "id": "als-proj-art-redirect-map", "name": "Advisory redirect and canonical projection map", "description": "Calculated, non-executing map of proposed redirect targets, canonical link entries and HTML or RDF link fragments, each carrying its permitted status code, direction rule and non-identity note.", "media_or_form": [ "tabular map of context IRI to preferred target", "non-executing server-configuration template", "link-header and HTML fragment listing" ], "serial": true, "identity_strategy": "Authoritative master-system map identifier where the serving platform issues one; otherwise a governed map IRI under the Dimension namespace; otherwise a Dimension-minted UUID or ULID, with a monotonic serial label that is never a date.", "source_refs": [ "SRC-023", "SRC-024", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "als-proj-record-store-binding", "name": "Record, document, interface and database bindings", "description": "Binding parameters for projecting assertions into structured records: JSON and YAML documents, CSV rows under a CSVW metadata description, HTTP API payloads, MCP resources with uri, name, mimeType and text or blob contents, and MongoDB documents in canonical or relaxed Extended JSON. Covers identifier conversion, cardinality flattening of multi-valued qualifiers, and type fidelity, including the Int32/Int64/Double collapse in relaxed Extended JSON and YAML implicit tag resolution. A database view, secondary key or YAML anchor is a storage or serialization convenience with no assertional force.", "source_refs": [ "SRC-080", "SRC-103", "SRC-104", "SRC-105", "SRC-107" ], "questions": [ { "id": "als-proj-q-rec-decompose", "text": "How is a multi-qualifier assertion decomposed into the target's record structure, and which container carries qualifiers that have no native slot?", "kind": "composition", "answer_data": [ "Field binding map from assertion element to target field", "Overflow container name or sidecar record reference", "List of qualifiers dropped rather than carried" ] }, { "id": "als-proj-q-rec-idconv", "text": "Which identifier form does the target require, and what is the reversible conversion rule from the assertion's identifier to that form?", "kind": "interoperability", "answer_data": [ "Source identifier form", "Target identifier form", "Conversion rule identifier and its reversibility flag" ] }, { "id": "als-proj-q-rec-fidelity", "text": "Which numeric, temporal or typed values lose fidelity in the chosen serialization mode, and what tolerance is declared?", "kind": "quality", "answer_data": [ "Affected field list", "Selected serialization mode, such as canonical or relaxed Extended JSON", "Type-fidelity class and declared tolerance note" ] }, { "id": "als-proj-q-rec-notalias", "text": "Why must a YAML anchor, a database view or a secondary key never be exported or read back as an alias assertion?", "kind": "constraint", "answer_data": [ "Mechanism name and the specification that defines its scope", "Scope statement, such as node identity within one serialization", "Marker asserting the mechanism carries no authority, strength or confidence" ] } ], "data_elements": [ { "id": "als-proj-de-rec-shape", "name": "Target record shape", "description": "Structural form the assertion takes in the target: flat row, nested document, resource contents, or payload member.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-103", "SRC-104" ] }, { "id": "als-proj-de-rec-fieldmap", "name": "Field binding map", "description": "Mapping from assertion elements and qualifiers to concrete target fields, columns or members.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-103" ] }, { "id": "als-proj-de-rec-idrule", "name": "Identifier conversion rule", "description": "Named, versioned rule converting the assertion's identifier into the target's required form, with reversibility stated.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-105" ] }, { "id": "als-proj-de-rec-ejson", "name": "Extended JSON mode", "description": "Canonical or relaxed mode selected for MongoDB projections, determining preserved BSON type information.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-105" ] }, { "id": "als-proj-de-rec-mcpuri", "name": "MCP resource URI or template", "description": "Resource URI or RFC 6570 template under which the projection is exposed by an MCP server, with declared mimeType.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-104" ] }, { "id": "als-proj-de-rec-typeclass", "name": "Type-fidelity class", "description": "Declared class of type preservation for the binding, from full preservation to declared collapse.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-105", "SRC-107" ] } ], "artifacts": [], "inline_only_rationale": "The binding is a compact set of reference parameters carried on the projection request and echoed in the loss report: target record shape, field map, identifier conversion rule, Extended JSON mode and MCP resource template. The emitted documents, collections and resources are named, stored and served by the host platform, so this model holds only the parameters and the declared type-fidelity expectation. Materialising a separate binding artifact would duplicate the versioned capability profile already governed under als-proj-target-profile and would create two places where the same target could drift." } ] }, { "id": "als-proj-layer-determinism", "name": "Deterministic form, self-description and integrity", "description": "Byte-stable serialization, content digests as integrity qualifiers, and the schema, version and provenance declaration every projection must carry to be interpretable without out-of-band knowledge.", "source_refs": [ "SRC-102", "SRC-077", "SRC-106", "SRC-009", "SRC-008", "SRC-108" ], "findings": [ { "id": "als-proj-deterministic-form", "name": "Deterministic serialization and content digest", "description": "Rules producing byte-stable output so that two exports of the same assertion set are comparable and digestible: JCS for JSON-family output, RDFC-1.0 canonical N-Quads for RDF datasets, explicit row and column ordering with normalized quoting for tabular output, and fixed UTF-8 encoding with fixed line endings for Git, Markdown and HTML templates. YAML anchors, aliases and implicit tag resolution are suppressed because they are discarded on composition. The resulting digest is recorded as an integrity qualifier using a registered algorithm; it detects corruption, is not proof of authenticity or truth, and is never the artifact's identifier.", "source_refs": [ "SRC-102", "SRC-077", "SRC-103", "SRC-106", "SRC-107" ], "questions": [ { "id": "als-proj-q-det-order", "text": "Which canonicalization algorithm applies to each target format, and in what order are canonicalization, digesting and any signature applied?", "kind": "process", "answer_data": [ "Target format", "Canonicalization algorithm identifier and version", "Ordered processing steps from source records to digest" ] }, { "id": "als-proj-q-det-digest", "text": "What digest algorithm and value are recorded for the produced projection, and over which byte range?", "kind": "measurement", "answer_data": [ "Hash algorithm name with Active status in the registered set", "Digest value", "Covered scope, distinguishing representation data from transferred content" ] }, { "id": "als-proj-q-det-suppress", "text": "Which format features must be suppressed to keep output byte-stable, and what is emitted in their place?", "kind": "constraint", "answer_data": [ "Suppressed feature list per format", "Substitute construct used instead", "Residual instability that cannot be removed, with its cause" ] }, { "id": "als-proj-q-det-proof", "text": "How can a reviewer establish that a stored projection corresponds to the assertion set it claims to represent?", "kind": "evidence", "answer_data": [ "Canonical form reference and algorithm", "Digest comparison result", "Source assertion set identifier and version" ] } ], "data_elements": [ { "id": "als-proj-de-det-algo", "name": "Canonicalization algorithm", "description": "Named algorithm and version applied before digesting, such as JCS or RDFC-1.0.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-102", "SRC-077" ] }, { "id": "als-proj-de-det-digalgo", "name": "Digest algorithm", "description": "Hash algorithm name drawn from the registered set of Active algorithms.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-106" ] }, { "id": "als-proj-de-det-digvalue", "name": "Digest value", "description": "Digest computed over the canonical byte sequence.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-106" ] }, { "id": "als-proj-de-det-scope", "name": "Digest scope", "description": "Whether the digest covers representation data or transferred content.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-106" ] }, { "id": "als-proj-de-det-encoding", "name": "Encoding and newline profile", "description": "Character encoding, line ending and whitespace normalization applied to text-template output.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-103", "SRC-107" ] }, { "id": "als-proj-de-det-suppressed", "name": "Suppressed features", "description": "Format features disabled to achieve byte stability, such as YAML anchors or unordered members.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-102", "SRC-107" ] } ], "artifacts": [ { "id": "als-proj-art-canonical-package", "name": "Canonical projection package", "description": "The canonicalized byte sequence of a projection in its target format together with its digest manifest, encoding profile and the identifier and version of the assertion set it was produced from.", "media_or_form": [ "canonicalized byte stream in the target format", "digest manifest naming algorithm and covered scope", "Git-tracked file set for template projections" ], "serial": true, "identity_strategy": "Authoritative master-system export identifier from the system of record where one exists; otherwise a governed export IRI under the Dimension namespace; otherwise a Dimension-minted UUID or ULID. The content digest is an integrity qualifier and must never serve as the identifier, and the serial label is a monotonic sequence independent of any date.", "source_refs": [ "SRC-102", "SRC-077", "SRC-106" ] } ], "inline_only_rationale": null }, { "id": "als-proj-version-declaration", "name": "Schema, version and provenance self-description", "description": "Every projection carries a self-description block: the dialect or context identifier appropriate to the target ($schema for JSON-family output, @context for JSON-LD, a CSVW metadata descriptor for tabular data, mimeType and annotations for MCP resources, front matter for Git templates), the model version, the target-profile version, the strength-mapping-table version, and provenance stamps naming the producing agent and the derivation from the source assertion set. All times are RFC 3339 values with seconds and an explicit offset, and the assertion's event time is kept distinct from the export generation time and any later observation time.", "source_refs": [ "SRC-080", "SRC-103", "SRC-104", "SRC-009", "SRC-008", "SRC-108" ], "questions": [ { "id": "als-proj-q-ver-prov", "text": "Which agent, activity and source assertion set produced this projection, and how is that derivation expressed inside the target?", "kind": "provenance", "answer_data": [ "Producing agent reference", "Export activity reference", "Source assertion set identifier and version, with the derivation predicate or field used" ] }, { "id": "als-proj-q-ver-time", "text": "Which distinct time points are recorded on a projection, and how are they kept apart from the assertion's own event time?", "kind": "temporal", "answer_data": [ "Assertion event time per assertion", "Export generation time", "Re-import or observation time, plus any declared validity window" ] }, { "id": "als-proj-q-ver-minimum", "text": "What is the minimum self-description a projection must carry to be interpretable without out-of-band knowledge?", "kind": "requirement", "answer_data": [ "Dialect or context identifier", "Model version and target-profile version", "Strength-mapping-table version and canonicalization algorithm identifier" ] }, { "id": "als-proj-q-ver-supersede", "text": "How is a superseded projection marked so that consumers stop treating it as current?", "kind": "lifecycle", "answer_data": [ "Supersession pointer to the replacing projection", "Withdrawal flag and withdrawal time", "Statement that withdrawal does not invalidate the underlying assertion" ] } ], "data_elements": [ { "id": "als-proj-de-ver-dialect", "name": "Dialect or context identifier", "description": "Identifier of the schema dialect, context or metadata descriptor governing the projection's structure.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-108" ] }, { "id": "als-proj-de-ver-model", "name": "Model version", "description": "Version of WM-XCT-036 under which the projection was produced.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-108" ] }, { "id": "als-proj-de-ver-profile", "name": "Target profile version", "description": "Version of the capability profile that governed the projection.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-103" ] }, { "id": "als-proj-de-ver-maptable", "name": "Strength-mapping table version", "description": "Version of the relation-strength mapping table applied.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-041", "SRC-003" ] }, { "id": "als-proj-de-ver-generated", "name": "Export generation time", "description": "RFC 3339 timestamp with seconds and explicit offset recording when the projection was produced.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "als-proj-de-ver-eventtime", "name": "Assertion event time", "description": "RFC 3339 timestamp of when each projected equivalence was asserted, distinct from export time.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "als-proj-de-ver-agent", "name": "Producing agent", "description": "Reference to the agent responsible for the export activity.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "als-proj-de-ver-supersedes", "name": "Supersession pointer", "description": "Reference to the projection version this one replaces, if any.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "The declaration is a header block that must live inside whichever artifact the target format already defines: a $schema or @context member, a CSVW metadata descriptor, an MCP resource mimeType with annotations, or Git file front matter. Extracting it into a separate artifact would destroy the self-description property it exists to provide and would let the header drift from the bytes it describes. It is therefore modelled as inline reference data present on every projection rather than as an artifact of its own." } ] } ] }, { "id": "als-proj-bundle-fidelity", "name": "Semantic preservation, loss disclosure and round-trip", "description": "Rules that keep a projection from asserting more than its source, the machine-readable disclosure of everything the target could not carry, and the verification and refusal behaviour that follows.", "rationale": "Targets differ in expressive power, so every export is a weakening or an annotation. The contract is trustworthy only if strengthening is structurally impossible, every omission is declared in a typed report, re-import is verified against canonical forms, and the failure mode when no safe weakening exists is refusal rather than silent misstatement.", "source_refs": [ "SRC-041", "SRC-003", "SRC-023", "SRC-024", "SRC-045", "SRC-106", "SRC-025" ], "layers": [ { "id": "als-proj-layer-strength", "name": "Relation-strength preservation", "description": "The governed mapping from recorded strength to permissible target construct, and the invariant that projection may weaken or annotate but never strengthen.", "source_refs": [ "SRC-041", "SRC-003", "SRC-024", "SRC-025" ], "findings": [ { "id": "als-proj-strength-mapping", "name": "Relation-strength mapping and the non-upgrade invariant", "description": "A governed table binding each recorded strength to the strongest construct each target may use, under a hard invariant: a projection may weaken, annotate or omit, never strengthen. SameIndividual and owl:sameAs assert individual equality and are permitted only where a competent authority recorded strict identity. skos:exactMatch is transitive and a sub-property of skos:closeMatch, while skos:closeMatch is symmetric and deliberately non-transitive, so a chain of close matches must never be projected as exact matches. schema.org sameAs is defined as the URL of a reference page indicating identity, not as an identity axiom. Confidence values, evidence records, cluster membership, canonical preference and redirect targets remain qualifiers; crossing a confidence threshold is not an upgrade.", "source_refs": [ "SRC-041", "SRC-003", "SRC-023", "SRC-024", "SRC-006", "SRC-025" ], "questions": [ { "id": "als-proj-q-str-ceiling", "text": "Which target construct is the strongest permissible expression of each recorded strength, per target profile?", "kind": "classification", "answer_data": [ "Recorded strength code", "Strongest permissible target construct token or IRI", "Permitted or forbidden verdict with citation" ] }, { "id": "als-proj-q-str-block", "text": "Which candidate projections would strengthen a relation, and by what mechanism is each blocked?", "kind": "constraint", "answer_data": [ "Forbidden source-strength to target-construct pair", "Mechanism by which the strengthening would occur, such as transitivity or threshold collapse", "Blocking rule identifier and its enforcement point in the calculation" ] }, { "id": "als-proj-q-str-qualifiers", "text": "How are confidence, evidence and cluster membership represented in a target that offers no qualifier slot?", "kind": "relationship", "answer_data": [ "Qualifier name", "Available representation options: annotation, reification, sidecar record, or omission", "Chosen option and the corresponding loss entry" ] }, { "id": "als-proj-q-str-approve", "text": "Who may approve a change to the strength-mapping table, and on what evidence?", "kind": "decision", "answer_data": [ "Approving steward role", "Specification citation supporting the proposed construct", "Recorded conflict or dissent reference" ] }, { "id": "als-proj-q-str-check", "text": "What check demonstrates that no emitted triple, row or field exceeds the recorded strength?", "kind": "validation", "answer_data": [ "Invariant check identifier", "Inventory of emitted constructs actually inspected", "Pass or fail result with counts and offending items" ] } ], "data_elements": [ { "id": "als-proj-de-str-recorded", "name": "Recorded strength", "description": "The strength as asserted in the source, from strict identity to advisory preference.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-041", "SRC-003" ] }, { "id": "als-proj-de-str-ceiling", "name": "Maximum permissible construct", "description": "Strongest construct the target may use for that recorded strength.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-041", "SRC-003", "SRC-025" ] }, { "id": "als-proj-de-str-forbidden", "name": "Forbidden construct list", "description": "Constructs explicitly barred for the recorded strength, each with the reason.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-024" ] }, { "id": "als-proj-de-str-qualmode", "name": "Qualifier representation mode", "description": "How confidence, evidence and cluster membership are carried, or that they are omitted.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-080" ] }, { "id": "als-proj-de-str-transitivity", "name": "Transitivity note", "description": "Statement of whether the chosen construct is transitive and what unintended closure it could create.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "als-proj-de-str-nothreshold", "name": "Threshold non-upgrade flag", "description": "Assertion that no confidence threshold was used to raise a graded assertion to an identity construct.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-041", "SRC-003" ] } ], "artifacts": [ { "id": "als-proj-art-strength-map", "name": "Relation-strength projection mapping table", "description": "Governed, versioned table binding each recorded strength to the strongest permissible construct per target profile, with forbidden pairs, qualifier representation modes and specification citations.", "media_or_form": [ "governed mapping table in the adopting store", "machine-readable rule set consumed by the planning function", "published reference page for external consumers" ], "serial": true, "identity_strategy": "Authoritative master-system table identifier where the Dimension registers governed tables; otherwise a governed table IRI under the model namespace; otherwise a Dimension-minted UUID or ULID, with a monotonic version label that never encodes a date.", "source_refs": [ "SRC-041", "SRC-003", "SRC-025" ] } ], "inline_only_rationale": null } ] }, { "id": "als-proj-layer-loss", "name": "Projection-loss disclosure", "description": "The typed, machine-readable report that accompanies every projection and states exactly what the target could not carry.", "source_refs": [ "SRC-003", "SRC-080", "SRC-103", "SRC-105", "SRC-045" ], "findings": [ { "id": "als-proj-loss-report", "name": "Machine-readable projection-loss report", "description": "Every projection emits a loss report enumerating, as typed entries: omitted qualifiers, unsupported relation kinds together with the substitute construct used, cardinality changes such as multi-valued qualifiers flattened to one column, identifier conversions and their reversibility, hidden evidence present in the source but invisible in the target, ordering changes, and non-round-trippable fields. The report follows the SHACL validation-report shape: a top-level conformance or fidelity verdict plus a list of entries each carrying a focus reference, a path, a component identifier and a severity. An empty report is a positive claim of losslessness for the declared profile, not the absence of a report.", "source_refs": [ "SRC-003", "SRC-080", "SRC-103", "SRC-105", "SRC-045" ], "questions": [ { "id": "als-proj-q-loss-taxonomy", "text": "What is the complete entry taxonomy of a projection-loss report, and what does each entry type assert?", "kind": "definition", "answer_data": [ "Entry type codes covering omitted qualifier, unsupported relation kind, cardinality change, identifier conversion, hidden evidence, ordering change and non-round-trippable field", "Per-type definition and required fields", "Default severity per type" ] }, { "id": "als-proj-q-loss-address", "text": "How is a loss entry addressed so a consumer can point at exactly the assertion, field and target construct concerned?", "kind": "identity", "answer_data": [ "Entry identifier", "Source assertion reference and source path", "Target construct reference or a statement that no target construct exists" ] }, { "id": "als-proj-q-loss-summary", "text": "Which counts and severities summarise a report, and what makes a projection lossless for a given profile?", "kind": "measurement", "answer_data": [ "Per-type entry counts", "Maximum severity present", "Lossless verdict together with the definition of losslessness for that profile" ] }, { "id": "als-proj-q-loss-hidden", "text": "How does the report disclose evidence and confidence that exist in the source but are invisible in the target?", "kind": "evidence", "answer_data": [ "Hidden-evidence entry with the qualifier concerned", "Reference to the source evidence record", "Statement of what a target-only consumer can and cannot see" ] }, { "id": "als-proj-q-loss-publish", "text": "Which parts of a loss report may be published alongside the projection, and which must remain internal?", "kind": "access", "answer_data": [ "Publishability label per entry", "Redaction rule applied", "List of internal-only entries and the reason for withholding each" ] } ], "data_elements": [ { "id": "als-proj-de-loss-id", "name": "Loss report identifier", "description": "Identifier of the report, bound to one projection version.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-proj-de-loss-verdict", "name": "Fidelity verdict", "description": "Top-level statement of whether the projection is lossless for the declared profile.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-proj-de-loss-entry", "name": "Loss entry", "description": "One typed disclosure of something the target could not carry as recorded.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-proj-de-loss-type", "name": "Loss entry type", "description": "Entry type code from the governed taxonomy.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-103", "SRC-105" ] }, { "id": "als-proj-de-loss-path", "name": "Source path", "description": "Path within the source assertion identifying the affected element.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-proj-de-loss-severity", "name": "Entry severity", "description": "Severity of the entry, distinguishing benign weakening from a material fidelity warning.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-proj-de-loss-reversible", "name": "Reversibility flag", "description": "Whether the described change can be undone on import without external information.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-080" ] } ], "artifacts": [ { "id": "als-proj-art-loss-report", "name": "Projection-loss report", "description": "Typed, machine-readable disclosure of omitted qualifiers, substituted relation kinds, cardinality and ordering changes, identifier conversions, hidden evidence and non-round-trippable fields for one projection version.", "media_or_form": [ "structured report record in the adopting store", "report page rendered beside the projection", "report resource exposed over the serving interface" ], "serial": true, "identity_strategy": "Authoritative master-system report identifier where the store issues one; otherwise a governed report IRI derived from the projection's own IRI; otherwise a Dimension-minted UUID or ULID, with a monotonic serial label that is never a date.", "source_refs": [ "SRC-045", "SRC-103", "SRC-105" ] } ], "inline_only_rationale": null } ] }, { "id": "als-proj-layer-roundtrip", "name": "Round-trip verification and refusal", "description": "Verification that a projection can be re-imported without undeclared loss, and the calculated refusal or partial-projection recommendation when no safe weakening exists.", "source_refs": [ "SRC-041", "SRC-024", "SRC-102", "SRC-077", "SRC-045", "SRC-106" ], "findings": [ { "id": "als-proj-import-roundtrip", "name": "Import round-trip verification and fidelity classification", "description": "Re-importing a projection and comparing the reconstructed assertion set with the source through the same canonical form and digest. Results are classified as byte-identical, semantically equivalent, weakened as declared, or divergent. Declared loss already listed in the loss report is reconciled and discounted; anything else is undeclared loss and is a defect. Round-trip never repairs strength: a re-imported close match is not evidence that the source was strict identity, and compaction in linked-data or relaxed database modes may legitimately fail to reconstruct the original form.", "source_refs": [ "SRC-102", "SRC-077", "SRC-080", "SRC-105", "SRC-106" ], "questions": [ { "id": "als-proj-q-rt-procedure", "text": "What is the comparison procedure, and which canonical form is compared at each step?", "kind": "process", "answer_data": [ "Ordered procedure steps from stored bytes to reconstructed assertions", "Canonical form and algorithm used at each comparison step", "Comparison scope, including which fields are excluded and why" ] }, { "id": "als-proj-q-rt-states", "text": "Which fidelity states may a round-trip result take, and what distinguishes them?", "kind": "state", "answer_data": [ "Fidelity state codes", "Definition and discriminating test for each state", "Trigger that moves a result from one state to another" ] }, { "id": "als-proj-q-rt-undeclared", "text": "How is undeclared loss distinguished from declared loss, and what is the disposition of each?", "kind": "quality", "answer_data": [ "Reference to the declared loss report entries", "List of differences not covered by any declared entry", "Disposition code for each undeclared difference" ] }, { "id": "als-proj-q-rt-times", "text": "Which times are recorded for a round-trip, and how do they relate to export and assertion times?", "kind": "temporal", "answer_data": [ "Re-import observation time", "Export generation time of the projection examined", "Assertion event times of the reconstructed assertions and the resulting drift interval" ] } ], "data_elements": [ { "id": "als-proj-de-rt-id", "name": "Round-trip identifier", "description": "Identifier of one verification run against one projection version.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-106" ] }, { "id": "als-proj-de-rt-state", "name": "Fidelity state", "description": "Classification of the run: byte-identical, semantically equivalent, weakened as declared, or divergent.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-077", "SRC-080" ] }, { "id": "als-proj-de-rt-form", "name": "Compared canonical form", "description": "Canonical form and algorithm used for the comparison.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-102", "SRC-077" ] }, { "id": "als-proj-de-rt-undeclared", "name": "Undeclared differences", "description": "Differences observed that no declared loss entry accounts for.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-045" ] }, { "id": "als-proj-de-rt-observed", "name": "Observation time", "description": "RFC 3339 timestamp with seconds and explicit offset recording when the round-trip was performed.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "als-proj-de-rt-digests", "name": "Compared digest pair", "description": "Digest of the stored projection and digest of the re-serialized reconstruction.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-106" ] } ], "artifacts": [ { "id": "als-proj-art-roundtrip-report", "name": "Round-trip verification report", "description": "Record of one verification run: canonical forms compared, digest pair, fidelity state, reconciled declared losses and any undeclared differences with their disposition.", "media_or_form": [ "structured verification record", "reviewer-facing comparison summary" ], "serial": true, "identity_strategy": "Authoritative master-system verification identifier where the store issues one; otherwise a governed report IRI derived from the projection IRI plus a monotonic run sequence; otherwise a Dimension-minted UUID or ULID. The run sequence never encodes a date.", "source_refs": [ "SRC-102", "SRC-077", "SRC-106" ] } ], "inline_only_rationale": null }, { "id": "als-proj-refusal", "name": "Partial projection and refusal when safe weakening is impossible", "description": "When a target cannot express any construct at or below the recorded strength without misrepresenting it, the correct outcome is partial projection of the safely representable subset, or refusal. Typical triggers: a target whose only equivalence construct asserts individual equality while the assertion is a graded close match; a redirect surface that would imply permanent replacement for a merely preferred alias; a canonical link whose asymmetry contradicts a symmetric assertion; or an access label barring emission. The outcome is a calculated recommendation with reasons. It does not enforce anything: the adopting Dimension decides, executes and records any override.", "source_refs": [ "SRC-041", "SRC-003", "SRC-023", "SRC-024", "SRC-045" ], "questions": [ { "id": "als-proj-q-ref-condition", "text": "What conditions make safe weakening impossible for a given assertion and target, and what recommendation follows?", "kind": "exception", "answer_data": [ "Condition code from the governed list", "Affected assertion reference and target profile", "Recommendation of partial projection or refusal, with reason text and citation" ] }, { "id": "als-proj-q-ref-subset", "text": "When a projection is partial, which subset is emitted, and how is the omitted remainder declared?", "kind": "composition", "answer_data": [ "Selector describing the emitted subset", "List of omitted assertions with per-item reason", "Reference to the loss-report entries covering the omission" ] }, { "id": "als-proj-q-ref-override", "text": "Who may override a refusal recommendation, and what must the override record contain?", "kind": "authority", "answer_data": [ "Overriding authority role", "Justification and accepted-risk statement", "Reference to the override record held by the Dimension's platform services" ] }, { "id": "als-proj-q-ref-complete", "text": "What must a consumer be told so that a partial projection is not mistaken for a complete set of aliases?", "kind": "requirement", "answer_data": [ "Completeness flag carried in the projection self-description", "Coverage statement describing the selected scope", "Description of the excluded scope and where to obtain it" ] } ], "data_elements": [ { "id": "als-proj-de-ref-condition", "name": "Refusal condition", "description": "Governed code identifying why no safe weakening exists.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-041", "SRC-024" ] }, { "id": "als-proj-de-ref-recommendation", "name": "Recommendation", "description": "Calculated outcome: full projection, partial projection, or refusal.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-045" ] }, { "id": "als-proj-de-ref-subset", "name": "Emitted subset selector", "description": "Expression describing exactly which assertions were emitted in a partial projection.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-103" ] }, { "id": "als-proj-de-ref-complete", "name": "Completeness flag", "description": "Declaration of whether the projection covers the whole selected scope.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "als-proj-de-ref-override", "name": "Override reference", "description": "Reference to an override decision held by the adopting Dimension, where one exists.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "als-proj-de-ref-reason", "name": "Reason", "description": "Human-readable reason citing the blocking construct and its specification.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-041", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "A refusal is a decision record returned by the evaluation function and carried as fields on the projection attempt and, where a partial projection was released, in its loss report. There is no document to publish because nothing, or only a declared subset, was exported. Enforcing the refusal, storing the decision in an audit trail and applying any override are performed by the adopting Dimension's platform services, so materialising an artifact here would claim ownership of enforcement and audit-trail semantics this model does not hold." } ] } ] } ] }, "functions": [ { "id": "als-asrt-fn-compose-envelope", "name": "Compose alias assertion envelope", "description": "Assemble a new assertion envelope from two role-bearing endpoint references, an issuer, a declared purpose scope and a host record, minting an assertion identifier in a namespace disjoint from both endpoint namespaces.", "inputs": [ "Source-role endpoint reference", "Target-role endpoint reference", "Issuer agent reference", "Purpose, tenant, jurisdiction and scope declaration", "Host record reference" ], "outputs": [ "Identified alias assertion envelope record", "Assertion identifier and initial envelope version" ], "preconditions": [ "Both endpoint locators are absolute or expandable through a published namespace binding, or a presence state of absent or explicitly unknown is declared", "An issuer is named and an assertion time with an explicit offset is supplied", "The host record exists and its retention scope is known" ], "effects": [ "Creates a new envelope with its own identifier and version series", "Records role order, purpose scope and tenant on the envelope", "Creates, renames or modifies nothing at either endpoint and reserves no endpoint identifier" ], "source_refs": [ "SRC-007", "SRC-011", "SRC-013", "SRC-009", "SRC-008" ] }, { "id": "als-asrt-fn-bind-endpoint-locator", "name": "Bind and normalize an endpoint locator", "description": "Expand a compact or local endpoint reference into an absolute locator using a cited namespace binding, and record the normalization level applied so that comparison behaviour is reproducible.", "inputs": [ "Raw endpoint locator with its declared form", "Namespace or prefix binding map reference and edition", "Declared target normalization level" ], "outputs": [ "Absolute endpoint locator", "Recorded normalization level and locator form code", "Namespace binding reference used for expansion" ], "preconditions": [ "The cited prefix binding is published and resolvable", "A relative reference is accompanied by an explicit base reference, otherwise it is routed to the malformed-reference path", "Character data is in Normalization Form C before comparison" ], "effects": [ "Stores the expanded absolute locator alongside the retained original form", "Records the normalization level so a later consumer can reproduce or reject the comparison", "Mints, alters or reassigns no endpoint identifier and edits no binding map owned by another authority" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-002", "SRC-011", "SRC-017" ] }, { "id": "als-asrt-fn-pin-endpoint-version", "name": "Pin endpoint version or capture a reference snapshot", "description": "Fix an endpoint reference against a stated register version, or capture an immutable snapshot of the reference with a content digest, and set the reference mode accordingly.", "inputs": [ "Endpoint locator", "Version token supplied by the endpoint authority", "Optional immutable capture of the reference" ], "outputs": [ "Version pin value for that side", "Endpoint reference snapshot with content digest where captured", "Reference mode code (snapshot or live)" ], "preconditions": [ "The version token originates from the authority that governs the endpoint namespace", "A capture is immutable once written and is a capture of a reference, not a copy of endpoint record content", "Composite keys are recorded as named parts rather than concatenated strings" ], "effects": [ "Fixes the endpoint reference at a stated version or capture", "Makes a floating reference explicit where no pin is available", "Copies no endpoint attributes beyond the locator, key parts, version token and digest" ], "source_refs": [ "SRC-013", "SRC-011", "SRC-016", "SRC-017" ] }, { "id": "als-asrt-fn-record-resolution-observation", "name": "Record an endpoint resolution observation", "description": "Attach an externally produced resolution outcome for an endpoint locator to the envelope, with the time it was observed, so that dangling and retired endpoints become visible without this model performing any dereference.", "inputs": [ "Endpoint locator", "Resolution outcome produced by the external resolution service", "Observation timestamp with an explicit offset" ], "outputs": [ "Resolution status code for that side", "Resolution observation timestamp", "Reference to the observing resolution service" ], "preconditions": [ "The outcome was produced by the resolution service owned by the referenced reference and resolution model", "The observation time is distinct from the assertion time and is not substituted for it" ], "effects": [ "Annotates the envelope with the last known resolution state of each side", "Distinguishes a retired endpoint that resolves to a tombstone from one that never existed", "Performs no dereference, no redirect, no retry and no repair of any endpoint" ], "source_refs": [ "SRC-004", "SRC-017", "SRC-016", "SRC-008" ] }, { "id": "als-asrt-fn-declare-shape", "name": "Declare assertion cardinality, membership and conditions", "description": "Make the arity of the claim explicit, record the combination rule and member ranks for multi-member sides, and attach attribute-value guards that bound when the assertion applies.", "inputs": [ "Member set for each role", "Combination rule and member ranks", "Condition guards referencing externally defined attributes" ], "outputs": [ "Explicit cardinality declaration", "Ordered membership with per-member rank", "Condition guard set and any recorded produced attributes" ], "preconditions": [ "Every member locator has already been bound to absolute form", "Condition attributes reference definitions owned by external terminology or schema models", "Serialization order is not relied upon for ranking" ], "effects": [ "Replaces cardinality implied by repeated entries with an asserted declaration", "Records ordering and membership semantics explicitly", "Evaluates no guard and computes no mapping result" ], "source_refs": [ "SRC-011", "SRC-013", "SRC-010", "SRC-012" ] }, { "id": "als-asrt-fn-flag-envelope-anomaly", "name": "Flag a structural anomaly in an assertion envelope", "description": "Classify degenerate structure in and between envelopes: self links, malformed or unresolvable references, structurally identical duplicates, and pairs whose recorded claims or version pins conflict.", "inputs": [ "Envelope record under examination", "Comparison set of envelopes within the same declared scope", "Declared normalization level for locator comparison" ], "outputs": [ "Anomaly classification codes", "Duplicate-of and conflicts-with references between envelope identifiers", "Quarantine state for envelopes with malformed references" ], "preconditions": [ "Locators are normalized to the same declared level before any comparison", "Comparison uses only recorded envelope fields and never dereferences an endpoint", "Scope, tenant and purpose are part of the structural key so cross-scope envelopes are not compared as duplicates" ], "effects": [ "Records self-link, duplicate, malformed and conflicting-pin flags on the envelopes concerned", "Links conflicting envelopes to each other for downstream adjudication", "Merges no records, retracts no assertion, resolves no conflict, performs no entity matching and writes no audit entry" ], "source_refs": [ "SRC-004", "SRC-002", "SRC-001", "SRC-011", "SRC-014" ] }, { "id": "als-asrt-fn-supersede-envelope", "name": "Issue a superseding envelope version", "description": "Replace a claim-bearing value by minting a successor envelope that cites the version it supersedes, leaving the prior envelope intact and resolvable for consumers holding a cached copy.", "inputs": [ "Current envelope identifier and version", "Changed claim-bearing values", "Issuer reference and reason code" ], "outputs": [ "Successor envelope with a new version token", "Supersedes reference on the successor and a superseded marker on the prior envelope", "Retraction reason where the claim is withdrawn rather than revised" ], "preconditions": [ "The current envelope is identified and its claim-bearing fields are known", "The issuer is authorised under the adopting Dimension's governance for this tenant", "The prior envelope is retained rather than overwritten" ], "effects": [ "Creates a successor version and links the version chain", "Preserves the superseded envelope for provenance and cache invalidation", "Deletes nothing, reuses no retired assertion identifier and touches no endpoint record" ], "source_refs": [ "SRC-009", "SRC-013", "SRC-017", "SRC-008" ] }, { "id": "als-tax-fn-curate-kind", "name": "Curate a relation kind in the register", "description": "Add or amend a relation kind, its normative definition, discriminating tests and admissible planes, producing a new governed register release.", "inputs": [ "proposed relation kind code", "normative definition text", "discriminating tests against neighbouring kinds", "admissible plane and endpoint type list", "authorising decision record reference" ], "outputs": [ "register entry with status", "new register release identifier", "change note against the previous release" ], "preconditions": [ "The proposing role is authorised by the register owner", "No existing active kind already covers the proposed semantics", "At least one primary source clause supports the proposed definition" ], "effects": [ "A new register release is published with the added or amended entry", "Regeneration of the crosswalk and property matrix is requested", "The prior register release is retained unchanged for reconstruction" ], "source_refs": [ "SRC-020", "SRC-016", "SRC-026" ] }, { "id": "als-tax-fn-assign-kind", "name": "Assign exactly one relation kind and plane to an assertion", "description": "Classify a candidate assertion by selecting one relation kind and one equivalence plane from the register in force, recording the justification category and, where supplied, a confidence value.", "inputs": [ "subject and object endpoint references", "declared endpoint denotation types", "candidate relation kind", "justification category", "optional confidence value", "register release in force" ], "outputs": [ "classified assertion record", "assigned relation kind and plane", "recorded strength rank and inference-permission flag" ], "preconditions": [ "Both endpoint references are supplied by their owning systems", "The selected kind is active in the register release in force", "The endpoints satisfy the kind's admissible endpoint types" ], "effects": [ "The assertion carries exactly one relation kind and one plane", "Event time and observation time are recorded separately", "No matching, merging or resolution is performed by this function" ], "source_refs": [ "SRC-020", "SRC-021", "SRC-028" ] }, { "id": "als-tax-fn-declare-properties", "name": "Declare the formal property profile of a relation kind", "description": "Record directionality, symmetry, reflexivity, transitivity, invertibility, inverse kind, strength rank and inference permission for a relation kind, using four-valued property states so that source silence is not recorded as denial.", "inputs": [ "relation kind code", "source clause references for each property", "proposed four-valued property states", "strength rank proposal" ], "outputs": [ "property profile entry", "regenerated relation property matrix", "list of properties left as not-asserted-by-source" ], "preconditions": [ "The relation kind exists and is active in the register", "Each asserted property cites a resolvable source clause" ], "effects": [ "The property profile becomes the declared reading of the kind", "Absent source support is recorded as not-asserted rather than denied", "No closure, entailment or materialisation is computed" ], "source_refs": [ "SRC-019", "SRC-020", "SRC-006" ] }, { "id": "als-tax-fn-bind-external-term", "name": "Bind a relation kind to an external vocabulary term", "description": "Record an alignment binding from a local relation kind to an external term, with a comparability verdict, the dated external edition and the supporting clause, explicitly without claiming conformance.", "inputs": [ "relation kind code", "external term IRI or registered token", "external specification edition or registry snapshot", "comparability verdict", "supporting clause reference" ], "outputs": [ "crosswalk row", "recorded divergences between local and external semantics", "binding reconfirmation due date" ], "preconditions": [ "The external term is published in a citable, dated specification or registry", "The comparability verdict is supported by a cited clause" ], "effects": [ "The binding is published as an alignment only", "Conformance is not asserted and no target behaviour is imported", "Divergences are recorded for consumers to inspect" ], "source_refs": [ "SRC-020", "SRC-016", "SRC-025", "SRC-028" ] }, { "id": "als-tax-fn-record-strength-change", "name": "Record a downgrade or upgrade of an assertion's classification", "description": "Register a change of relation kind on an existing assertion, preserving the prior classification, the reason, the authorising role and both effective and observation timestamps.", "inputs": [ "assertion reference", "prior relation kind", "proposed relation kind", "change reason code", "authorising role identifier", "evidence reference where the change raises strength" ], "outputs": [ "new current classification", "retained superseded classification", "classification change record" ], "preconditions": [ "The proposed kind is active in the register release in force", "An upgrade to the top strength rank carries an authority declaration and an evidence reference", "The change is authorised by a role permitted to reclassify" ], "effects": [ "The superseded classification is retained rather than overwritten", "Effective interval and observation timestamp are recorded separately", "Adjudication of the underlying evidence remains with the owning model" ], "source_refs": [ "SRC-026", "SRC-027", "SRC-028" ] }, { "id": "als-tax-fn-declare-conflict", "name": "Declare a taxonomic conflict, contradiction or cycle", "description": "Record that a set of assertions matches a declared invalid combination, contradiction or cycle rule, and refer it to the owning adjudication service.", "inputs": [ "assertion references in the conflicting set", "matched invalid combination or cycle rule identifier", "observation timestamp", "referral target reference" ], "outputs": [ "conflict declaration record", "referral notice", "affected assertion list" ], "preconditions": [ "The matched rule exists in the published rule catalogue", "All referenced assertions are retrievable" ], "effects": [ "The conflict is declared and made visible on the affected assertions", "The declaration is referred for adjudication outside this model", "No assertion is deleted, suppressed or enforced against by this function" ], "source_refs": [ "SRC-018", "SRC-020", "SRC-028" ] }, { "id": "als-tax-fn-retire-kind", "name": "Retire a relation kind with successor mapping", "description": "Deprecate or withdraw a relation kind, name its successor where one exists, and state the obligations for assertions still carrying the retired kind.", "inputs": [ "relation kind code", "retirement reason", "successor kind code where applicable", "authorising decision record reference", "retirement effective timestamp" ], "outputs": [ "updated register entry with deprecated or withdrawn status", "successor mapping", "migration obligation statement for existing assertions" ], "preconditions": [ "The retirement is authorised by the register owner", "The impact on existing assertions carrying the kind has been recorded" ], "effects": [ "The kind may no longer be assigned to new assertions after the effective timestamp", "Existing assertions retain the retired kind until reclassified under change control", "Historic register releases remain retrievable for reconstruction" ], "source_refs": [ "SRC-016", "SRC-026", "SRC-027" ] }, { "id": "als-evid-fn-record-provenance", "name": "Record assertion provenance envelope", "description": "Capture the attributable envelope around one equivalence assertion: the distinct actor roles, the source-system and master-record bindings, the derivation lineage and the separately recorded time points.", "inputs": [ "Equivalence assertion reference", "Agent references with their roles", "Source-system and master-record references per side", "Decision, observation, ingestion and creation instants" ], "outputs": [ "Provenance envelope bound to the assertion", "Resolvable provenance container reference" ], "preconditions": [ "Both identifiers resolve within declared namespaces", "The asserter reference resolves in the external party registry", "All supplied instants conform to RFC 3339 with seconds and an explicit offset or Z" ], "effects": [ "Assertion becomes attributable and its lineage traversable", "Missing roles are recorded as explicitly absent rather than left ambiguous" ], "source_refs": [ "SRC-009", "SRC-032", "SRC-034", "SRC-008" ] }, { "id": "als-evid-fn-register-confidence", "name": "Register a confidence statement reported by a referenced method", "description": "Record a score, its scale, the thresholds in force, the resulting decision region and any explanation, as an outcome reported by an external method. This function stores and validates a reported measurement; it never computes, re-scores or optimises one.", "inputs": [ "Assertion reference", "Method reference with tool version and configuration digest", "Reported score with its scale", "Threshold values and decision region" ], "outputs": [ "Confidence statement attached to the assertion", "Scale-compatibility validation result" ], "preconditions": [ "The referenced method and its configuration digest are recorded", "The score scale is declared and its bounds known", "The reporting agent is identified" ], "effects": [ "Confidence becomes queryable independently of relation semantics and authority", "A score on an undeclared or incompatible scale is refused rather than coerced" ], "source_refs": [ "SRC-034", "SRC-036", "SRC-039" ] }, { "id": "als-evid-fn-attach-evidence", "name": "Attach, supersede or retract an evidence item", "description": "Register a discrete evidence item against an assertion with polarity, citation, digest, strength, sensitivity classification and jurisdiction of origin, or mark an existing item retracted or superseded without removing it.", "inputs": [ "Assertion reference", "Evidence item reference or retained exhibit", "Polarity, strength, sensitivity and jurisdiction values", "Retraction or supersession pointer where applicable" ], "outputs": [ "Evidence item registered against the assertion", "Updated evidence status without loss of the prior item" ], "preconditions": [ "The item has a resolvable citation or a content digest", "Sensitivity classification has been assigned", "Retraction supplies the retracting agent and instant" ], "effects": [ "Supporting and refuting evidence coexist under the same assertion", "Retracted items remain inspectable, marked rather than deleted" ], "source_refs": [ "SRC-032", "SRC-037", "SRC-038" ] }, { "id": "als-evid-fn-record-adjudication", "name": "Record a human review and adjudication outcome", "description": "Record why a pair reached review, who reviewed it, whether they were independent, the outcome reached and the reason, together with any amendment made to the predicate or confidence.", "inputs": [ "Assertion reference", "Reviewer agent reference and independence flag", "Review trigger", "Outcome code, reason and any amendment" ], "outputs": [ "Adjudication record bound to the assertion", "Amended predicate or confidence statement where the outcome changed the assertion" ], "preconditions": [ "The assertion exists and its current state is readable by the reviewer", "The reviewer agent resolves in the external party registry", "Review instant conforms to RFC 3339 with seconds and an explicit offset or Z" ], "effects": [ "The assertion is distinguishable as human-confirmed rather than tool-proposed", "A deferred outcome is preserved and does not become a rejection" ], "source_refs": [ "SRC-034", "SRC-035", "SRC-037" ] }, { "id": "als-evid-fn-raise-disagreement", "name": "Raise a disagreement and set the undetermined state", "description": "Record that two or more assertions about the same pair conflict, or that a method returned no warranted decision, and place the pair in a disputed or undetermined state without selecting a winner or mutating any member assertion.", "inputs": [ "References to the conflicting assertions or the undecided pair", "Reason for no decision or for the conflict", "Raising agent reference and instant" ], "outputs": [ "Disagreement state over the assertion set", "No-decision reason attached to the pair" ], "preconditions": [ "Each member assertion carries its own attribution and method reference", "No prior evidence or confidence statement is modified by this call" ], "effects": [ "Competing assertions coexist with independent provenance", "Selection of an operative assertion is deferred to the consuming system and attributed there" ], "source_refs": [ "SRC-032", "SRC-001", "SRC-036" ] }, { "id": "als-evid-fn-check-evidence-profile", "name": "Check an assertion against a declared evidence and provenance profile", "description": "Report whether an assertion satisfies a declared minimum profile: required actor roles present, method identity and configuration digest recorded, score scale declared, evidence polarity coverage met, and time points conforming. The function reports conformance only; consequences of non-conformance are decided by the adopting Dimension's policy model.", "inputs": [ "Assertion reference", "Profile reference naming required elements", "Evaluation instant" ], "outputs": [ "Conformance report listing satisfied and unsatisfied requirements", "Machine-readable non-conformance list" ], "preconditions": [ "A profile has been declared and versioned", "The assertion record is readable at the requested scope" ], "effects": [ "Gaps in evidence and provenance become visible and comparable across assertions", "No blocking, refusal or enforcement occurs within this model" ], "source_refs": [ "SRC-033", "SRC-034", "SRC-037" ] }, { "id": "als-evid-fn-project-interchange", "name": "Project the evidence and confidence record into an alignment target", "description": "Serialise the assertion's provenance, method, confidence and evidence into an external interchange form, applying the declared projection constraints so that a disputed, undetermined or low-strength assertion is not silently promoted into a transitive or substitution-licensing predicate.", "inputs": [ "Assertion reference or mapping-set reference", "Target alignment vocabulary", "Projection constraint set" ], "outputs": [ "Interchange representation in the target vocabulary", "Suppression and downgrade log listing what was withheld or weakened and why" ], "preconditions": [ "Relation predicate and semantic strength are recorded", "Disagreement state is resolved to agreed, or an explicit downgrade rule is supplied", "Namespace expansion map is available for both sides" ], "effects": [ "Exported statements carry method, confidence and review provenance rather than a bare link", "Assertions ineligible for transitive closure are withheld or downgraded, never exported as exact equivalence by default" ], "source_refs": [ "SRC-003", "SRC-001", "SRC-033", "SRC-034", "SRC-035" ] }, { "id": "als-prop-fn-declare-kind", "name": "Declare a relation kind and its formal properties", "description": "Register a relation predicate in the governed catalogue with the properties its owning specification actually asserts, the axiomatic force of each, and its position in the strength ordering.", "inputs": [ "Predicate IRI and owning specification reference with version or publication date", "Declared symmetry, reflexivity, inverse pairing, applicability and cardinality force values with clause citations", "Proposed strength class relative to existing catalogue entries" ], "outputs": [ "Relation-kind semantic profile record", "Catalogue change note stating whether the kind is new, revised or deprecates an existing kind" ], "preconditions": [ "The predicate IRI resolves and is not a redefinition of a standard predicate under altered semantics", "Every declared property is supported by a cited clause or is explicitly recorded as undeclared", "The owning specification version is recorded so later external changes are detectable" ], "effects": [ "The kind becomes available for binding to assertions", "Consumers can read licensed and explicitly disclaimed entailments before relying on the kind", "No existing assertion is reinterpreted; a semantics change requires a new kind identifier" ], "source_refs": [ "SRC-001", "SRC-041", "SRC-003", "SRC-025", "SRC-026" ] }, { "id": "als-prop-fn-bind-assertion", "name": "Bind an alias assertion to kind, context and warrant", "description": "Record one alias edge with exactly one catalogued kind, a context binding or explicit scope-unknown marker, and its warrant, preserving the strength the originating authority asserted.", "inputs": [ "Subject identifier and object identifier with their referent types", "Catalogued relation kind and the source-asserted predicate retained verbatim", "Context binding attributes or an explicit scope-unknown marker", "Warrant fields: justification type, optional confidence with declared semantics, asserting agent reference" ], "outputs": [ "Alias assertion record with references to its context binding and warrant record", "Lossy-encoding note where the incoming kind is not expressible in the local catalogue" ], "preconditions": [ "The named kind exists in the catalogue and is not deprecated", "Subject and object referent types satisfy the kind's declared applicability", "The local kind is not stronger than the kind the originating authority asserted", "Assertion time and observation time are both supplied" ], "effects": [ "The assertion becomes available for declared-semantics validation and reporting", "No entailment is materialised, no inverse edge is created unless symmetry is declared, and no host record is merged" ], "source_refs": [ "SRC-003", "SRC-025", "SRC-008", "SRC-034", "SRC-012" ] }, { "id": "als-prop-fn-validate-declared-semantics", "name": "Validate declared semantics and report results", "description": "Check a supplied assertion set against declared applicability, cardinality force, disjointness and non-equivalence constraints, and emit a report with severities and contagion exposure indicators.", "inputs": [ "Reference and digest of the assertion set to evaluate", "Constraint or shape version and the declared non-equivalence declarations in force", "Scope parameters for exposure indicator computation" ], "outputs": [ "Declared-semantics conformance report with overall conformance flag and individual results", "Contagion exposure indicators for strength-of-identity assertions", "Explicit undetermined outcomes where a comparison involves a scope-unknown assertion" ], "preconditions": [ "Every assertion in the set resolves to a catalogued kind", "Each assertion carries a context binding or an explicit scope-unknown marker", "The constraint version is recorded so the report can later be shown stale" ], "effects": [ "A report is produced and referenced from the assertion set", "No assertion is modified, no remediation is applied, no downstream operation is blocked", "Persistence, retention and audit of the report are handed to the referenced validation and audit models" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-045", "SRC-034" ] }, { "id": "als-prop-fn-evaluate-composition-rule", "name": "Evaluate a composition rule over a supplied edge sequence", "description": "For an ordered edge sequence supplied by the caller, report the strongest kind the declared composition rules license, or an explicit non-composable or inadmissible outcome with a reason.", "inputs": [ "Caller-supplied finite ordered sequence of edges, each naming a catalogued kind and a context key", "Declared composition rule set version" ], "outputs": [ "Composed result kind bounded by the weakest link, or an explicit none", "Non-composable or inadmissible outcome with reason code and the offending edge or adjacent pair" ], "preconditions": [ "The edge sequence is supplied by the caller; this function does not discover it", "Each edge names a catalogued kind and either a context binding or a scope-unknown marker", "Adjacent edges have been assessed for context compatibility" ], "effects": [ "A reported outcome is returned to the caller", "No graph is traversed, no path is discovered, no closure is materialised, and no new assertion is created" ], "source_refs": [ "SRC-001", "SRC-019", "SRC-003", "SRC-043" ] }, { "id": "als-prop-fn-assess-context-compatibility", "name": "Assess compatibility of two context bindings", "description": "Compare two declared context bindings attribute by attribute and report compatible, incompatible with codes, or undetermined.", "inputs": [ "Two context binding records or scope-unknown markers", "Comparison rules for jurisdiction, purpose, effective interval and source-version co-validity" ], "outputs": [ "Compatibility verdict of compatible, incompatible or undetermined", "Incompatibility code set naming each attribute that conflicts" ], "preconditions": [ "Both bindings declare comparable attributes or an explicit unknown for each attribute compared", "Interval comparison uses instants with seconds and explicit offsets" ], "effects": [ "The verdict is available to composition evaluation and to validation reporting", "A comparison involving a scope-unknown binding is reported as undetermined and never as compatible" ], "source_refs": [ "SRC-026", "SRC-008", "SRC-034", "SRC-030" ] }, { "id": "als-prop-fn-record-strength-change", "name": "Record an authorised strength or scope change", "description": "Create a superseding assertion and its supersession record when an existing edge is weakened, strengthened, rescoped or retracted, retaining the original.", "inputs": [ "Reference to the prior assertion", "New relation kind or new scope attributes and new effective interval", "Authority reference, change direction and reason", "Evidence reference where the change strengthens the edge" ], "outputs": [ "Supersession record linking prior and superseding assertions", "Updated state on the prior assertion marking it superseded or retracted" ], "preconditions": [ "The acting role holds the declared authority for the change direction", "A strengthening change meets the declared evidence bar", "The prior assertion is active or expired, not already retracted", "The new effective interval is expressed with seconds and an explicit offset" ], "effects": [ "The prior assertion is retained and readable, never mutated in place", "The strength and scope history of the edge remains reconstructible", "Downstream propagation and enforcement of the change are left to the consuming systems" ], "source_refs": [ "SRC-009", "SRC-026", "SRC-008", "SRC-034" ] }, { "id": "als-graph-fn-enumerate-candidate-paths", "name": "Enumerate candidate alias paths", "description": "Walk the alias graph between a subject and object endpoint under a named traversal policy version, returning the set of candidate paths with their ordered edge lists, hop counts and a termination reason. Produces evidence only.", "inputs": [ "Subject endpoint reference", "Object endpoint reference or an open target", "Traversal policy identifier and version", "Input graph snapshot reference or digest" ], "outputs": [ "Candidate path set with ordered edge identifiers and hop counts", "Termination reason and visited-node and examined-edge counts", "Non-exhaustive flag where a bound truncated the walk" ], "preconditions": [ "The named traversal policy version exists and is approved", "The requested predicate set is a subset of the policy allowed predicate set", "The caller is entitled to read the endpoints and edges in scope" ], "effects": [ "Creates a path evidence report bound to the policy version and input digest", "Records the traversal run instant and traversing agent for attribution", "Asserts no alias edge and modifies no endpoint, edge or snapshot" ], "source_refs": [ "SRC-048", "SRC-009", "SRC-051" ] }, { "id": "als-graph-fn-report-path-strength", "name": "Report path strength and weakest edge", "description": "Compute and report, for each candidate path, its weakest edge, the resulting path strength class and any per-edge confidence values, applying the registered predicate composition table and refusing any aggregation that would exceed the weakest link.", "inputs": [ "Candidate path set", "Registered predicate strength lattice and composition table", "Per-edge confidence and justification references" ], "outputs": [ "Weakest edge reference per path", "Path strength class per path, equal to the minimum edge strength", "Per-edge confidence listing with source attribution", "Flag where a path chains a non-transitive predicate and is therefore not composable" ], "preconditions": [ "Every edge on the path has a registered strength class or is flagged as unclassified", "The composition table version is recorded with the result" ], "effects": [ "Annotates the path evidence report with strength results", "Rejects any request for an aggregate score above the weakest edge strength", "Creates no new edge and changes no recorded confidence on any edge" ], "source_refs": [ "SRC-003", "SRC-034", "SRC-049", "SRC-030" ] }, { "id": "als-graph-fn-check-traversal-bounds", "name": "Check traversal bounds, cycles and repeats", "description": "Evaluate a completed or in-progress traversal against the declared bounds and repeated-node rule, detecting cycles, duplicate paths and safeguard breaches, and emitting them as diagnostics.", "inputs": [ "Traversal run record", "Traversal policy version with its bounds and repeated-node rule" ], "outputs": [ "Cycle diagnostics with the repeating node and edge references", "Duplicate-path suppression count", "Safeguard breach flags with the exceeded bound and observed value" ], "preconditions": [ "The run record references a resolvable policy version", "Duplicate suppression follows connectivity matching that does not count the number of ways a connection can be made" ], "effects": [ "Attaches diagnostics to the path evidence report", "Marks results non-exhaustive where a bound was reached", "Takes no enforcement action and alters no policy" ], "source_refs": [ "SRC-048", "SRC-051" ] }, { "id": "als-graph-fn-register-cluster-snapshot", "name": "Register an externally calculated cluster snapshot", "description": "Accept a cluster result computed by an external reasoning or master-data process and register it as an immutable snapshot with its rule identifier, rule version, parameters, input digest, snapshot instant and per-member evidence references, then compute the reproducibility digest.", "inputs": [ "Externally supplied member list", "Calculation rule reference, rule version and parameter set", "Input graph digest and snapshot instant", "Per-member evidence references" ], "outputs": [ "Registered cluster snapshot record", "Snapshot digest over the sorted member list", "Reproducibility status and any missing-evidence findings" ], "preconditions": [ "The calculation rule reference resolves to a named owning authority", "Every member carries at least one evidence reference or is flagged as rule-admitted", "The snapshot instant is expressed in RFC 3339 with seconds and an explicit offset" ], "effects": [ "Creates an immutable snapshot record; corrections create a new snapshot linked as a revision", "Records the registering agent and registration instant separately from the snapshot instant", "Executes no clustering, no closure computation, no matching and no merge" ], "source_refs": [ "SRC-009", "SRC-034", "SRC-008", "SRC-050" ] }, { "id": "als-graph-fn-validate-cluster-integrity", "name": "Validate cluster and graph integrity", "description": "Evaluate a registered snapshot or a bounded subgraph against the registered integrity conditions — contradictory not-same edges inside a cluster, disjoint predicates on the same pair, single-edge dependencies, stale members, orphaned representatives, oversize clusters — and emit results with focus references and severities.", "inputs": [ "Registered cluster snapshot or bounded subgraph reference", "Registered integrity condition set and severity mapping", "Upstream endpoint withdrawal records where available" ], "outputs": [ "Integrity result set with focus reference, condition code and severity", "Contradiction markers raised on affected paths and snapshots", "Notification list of the owners accountable for each result" ], "preconditions": [ "The evaluated snapshot or subgraph is resolvable and its digest verifiable", "The condition set version is recorded with the results" ], "effects": [ "Creates an integrity check report and attaches markers to affected records", "Blocks a marked cluster from being cited as confirmed equivalence until the marker is resolved", "Repairs nothing, retracts no edge, changes no membership and enforces no outcome" ], "source_refs": [ "SRC-045", "SRC-018", "SRC-003", "SRC-050" ] }, { "id": "als-graph-fn-report-lineage-impact", "name": "Report cluster lineage and downstream impact", "description": "Given a recorded split, merge or membership change, produce the lineage record linking predecessor and successor snapshots and enumerate the downstream assertions and references that cited the affected snapshot, classified by impact.", "inputs": [ "Lineage event record with event instant and triggering cause", "Predecessor and successor snapshot references", "Register of downstream citations of the affected snapshots" ], "outputs": [ "Lineage record with retained aliases and moved or withdrawn members", "Impact-classified list of affected downstream assertions and references with their owners", "Historical membership and prior representative references preserved for lookup" ], "preconditions": [ "Predecessor snapshots are retained and resolvable", "Event time and record time are both present and expressed with seconds and an explicit offset" ], "effects": [ "Issues a lineage and impact report in the cluster-line series", "Preserves prior membership and prior representative decisions unchanged", "Does not update, notify-and-remediate or reconcile any downstream system, and performs no merge" ], "source_refs": [ "SRC-009", "SRC-008", "SRC-050" ] }, { "id": "als-graph-fn-resolve-representative-reference", "name": "Resolve the recorded representative reference", "description": "Return the canonical-representative reference recorded for a cluster at a given instant and scope, together with the selecting authority, rule version and effective interval, so that a caller can cite the decision without re-deriving it.", "inputs": [ "Cluster snapshot reference", "Requested instant and scope descriptor" ], "outputs": [ "Representative member reference in force, or an explicit none-recorded result", "Selecting authority reference, rule reference and rule version", "Effective interval and the decision instant", "Conflict result where two decisions claim the same scope and interval" ], "preconditions": [ "A representative reference has been recorded for the cluster, scope and interval, or the absence is reportable", "The requested instant is expressed in RFC 3339 with seconds and an explicit offset" ], "effects": [ "Returns a read-only decision reference and records the read for citation reconstruction", "Selects no representative, applies no selection rule and ranks no member", "Rewrites no endpoint identity, creates no alias edge and performs no redirect or dereference" ], "source_refs": [ "SRC-018", "SRC-002", "SRC-009", "SRC-008" ] }, { "id": "als-state-fn-open-assertion-status", "name": "Open assertion status", "description": "Places a newly created alias/same-as assertion under lifecycle governance by recording its initial status and the first transition record.", "inputs": [ "Assertion record reference", "Proposing agent reference and role", "Initial evidence references with polarity", "Proposed effective interval" ], "outputs": [ "Initial status assignment (candidate or proposed)", "Transition record with ordinal one", "Entry-condition check result" ], "preconditions": [ "The assertion record exists and carries at least two endpoint references", "Mandatory attributes required by the entry conditions for the initial status are present", "A proposing agent with a recorded role is supplied" ], "effects": [ "The assertion becomes addressable with a governed status", "History begins and is thereafter append-only", "No endpoint, master-data or match record is created or altered" ], "source_refs": [ "SRC-053", "SRC-058", "SRC-009" ] }, { "id": "als-state-fn-validate-transition", "name": "Validate proposed transition", "description": "Checks a proposed from/to transition against the governed matrix, its entry conditions and any open exit obligations, and returns a conformance verdict with reasons. The verdict is advisory to the recording process; it is not an authorization decision and it does not enforce anything.", "inputs": [ "Current status", "Proposed target status", "Change-kind code", "Candidate evidence and attribute set", "Matrix version reference" ], "outputs": [ "Conformance verdict (conformant or non-conformant)", "Violated rule references", "Unmet entry conditions and outstanding exit obligations" ], "preconditions": [ "A published transition matrix version is resolvable", "The current status is readable from the latest transition record" ], "effects": [ "Produces a verdict consumed by the append function", "Non-conformant verdicts are retained for the rejected-transition record", "Never changes the assertion status by itself" ], "source_refs": [ "SRC-053", "SRC-052" ] }, { "id": "als-state-fn-append-transition", "name": "Append transition record", "description": "Seals and appends one immutable transition record for a validated status decision, including attribution, reason, both time axes and the chained integrity digest.", "inputs": [ "Validated transition proposal", "Deciding agent reference and role", "Reason text", "Decision, observation and ingestion timestamps" ], "outputs": [ "Sealed transition record with next ordinal", "Updated current-status projection", "Record digest and predecessor digest" ], "preconditions": [ "The transition validated as conformant, or the record is explicitly typed as a rejected transition", "All timestamps are RFC 3339 with seconds and an explicit offset or Z", "The predecessor record digest is retrievable" ], "effects": [ "History grows by exactly one entry; no earlier entry is modified", "Current status is derived, not independently edited", "Ordinals are never reused, including after rejection or rollback" ], "source_refs": [ "SRC-054", "SRC-055", "SRC-008" ] }, { "id": "als-state-fn-resolve-status-as-of", "name": "Resolve status as of a given time", "description": "Reconstructs the assertion's status on either time axis: the status believed to have applied at a past instant, or the status as it was knowable at a past ingestion instant.", "inputs": [ "Assertion reference", "As-of event-time coordinate", "As-known-at ingestion-time coordinate" ], "outputs": [ "Resolved status for the requested axis", "Contributing record set", "Flag when the two axes disagree" ], "preconditions": [ "At least one transition record exists", "Both time coordinates are RFC 3339 values with seconds and explicit offset or Z" ], "effects": [ "Read-only reconstruction; no record is written", "Late arrivals are included on the belief axis and excluded from the as-known-at axis" ], "source_refs": [ "SRC-057", "SRC-008", "SRC-055" ] }, { "id": "als-state-fn-link-supersession", "name": "Record supersession or replacement link", "description": "Records the directed supersedes / superseded-by or replaced-by relationship between a retiring assertion and its successor, together with the status transition of the retiring assertion.", "inputs": [ "Predecessor assertion reference", "Successor assertion reference", "Change-kind code", "Deciding agent and reason" ], "outputs": [ "Bidirectional link pair", "Transition record moving the predecessor to superseded", "Statement of how the successor differs in scope or strength" ], "preconditions": [ "The successor assertion exists and is at least in a recordable status", "The predecessor is not already in a terminal status that forbids supersession" ], "effects": [ "Both assertions remain readable and independently addressable", "No endpoint is deleted and no redirect is executed" ], "source_refs": [ "SRC-009", "SRC-053", "SRC-056" ] }, { "id": "als-state-fn-record-retraction-tombstone", "name": "Record retraction and raise tombstone", "description": "Withdraws an assertion as wrong or unsupportable and raises the tombstone that keeps its identifier resolvable with a stated reason, terminal status, former effective interval, links and a history pointer.", "inputs": [ "Assertion reference", "Retraction reason", "Refuting evidence references", "Deciding authority reference" ], "outputs": [ "Transition record moving the assertion to retracted", "Tombstone record", "Post-tombstone readable field set" ], "preconditions": [ "The retraction is conformant with the transition matrix", "A reason is supplied; an empty reason is not acceptable", "Refuting evidence references, where they exist, are attached" ], "effects": [ "The identifier keeps resolving and is never reassigned", "History, prior reasons and refuting evidence references remain readable", "Disposition of the underlying storage remains with the retention policy owner" ], "source_refs": [ "SRC-056", "SRC-055", "SRC-032" ] }, { "id": "als-state-fn-detect-status-conflict", "name": "Detect conflicting simultaneous statuses", "description": "Identifies mutually inconsistent statuses recorded for the same assertion over overlapping effective intervals and represents the situation as an explicit dispute naming the conflicting records.", "inputs": [ "Assertion reference", "Candidate transition records", "Overlap tolerance parameter" ], "outputs": [ "Conflict record with references to the conflicting decisions", "Proposed disputed status transition", "Consumption advisory while unresolved" ], "preconditions": [ "Two or more records assert statuses whose effective intervals overlap", "Each conflicting record names its deciding authority" ], "effects": [ "The conflict is made visible rather than silently reconciled", "No conflicting record is deleted, reordered or downgraded", "Resolution requires a recorded decision by a competent authority" ], "source_refs": [ "SRC-050", "SRC-053", "SRC-055" ] }, { "id": "als-state-fn-flag-evidence-expiry", "name": "Flag evidence expiry and review due", "description": "Marks assertions whose evidence validity horizon or mandated review interval has passed, so that expiry is an explicit recorded state rather than a silent staleness.", "inputs": [ "Assertion reference", "Evidence validity horizon", "Review interval policy reference", "Evaluation instant" ], "outputs": [ "Expiry-due or expired marker", "Proposed transition to expired", "Notification payload for affected consumers" ], "preconditions": [ "An evidence validity horizon or review interval is recorded", "The evaluation instant is an RFC 3339 value with seconds and explicit offset or Z" ], "effects": [ "Expiry becomes a recorded transition with its own reason and time coordinates", "The assertion remains readable with an altered consumption rule", "Evidence content itself is neither re-evaluated nor modified here" ], "source_refs": [ "SRC-008", "SRC-053", "SRC-055" ] }, { "id": "als-res-fn-resolve-as-of", "name": "Resolve alias set as of a stated frame", "description": "Return the admissible equivalence assertions for a given identifier at a stated event instant and observation cut-off, with a status drawn from the closed vocabulary and never a silently elected canonical endpoint.", "inputs": [ "subject identifier endpoint", "as-of event instant (RFC 3339, seconds, explicit offset)", "as-of observation/ingestion cut-off instant", "optional version pin or memento reference per endpoint" ], "outputs": [ "resolution answer record with status, candidate set or no-answer reason", "determinant input digest and pin manifest reference", "per-candidate asserting authority and confidence carried through unchanged" ], "preconditions": [ "both as-of instants are well formed and the observation cut-off is not earlier than the assertion population's earliest ingestion instant", "every candidate assertion has a recorded validity interval and asserting authority" ], "effects": [ "issues an immutable answer record", "records the answer's provenance activity and generation instant", "emits ambiguity or no-answer status rather than selecting a single endpoint" ], "source_refs": [ "SRC-059", "SRC-008", "SRC-015" ] }, { "id": "als-res-fn-evaluate-chain-evidence", "name": "Evaluate an observed chain within budget", "description": "Admit an externally observed hop sequence, order it, detect cycles, apply the hop budget and classify each hop as permanent relocation, temporary relocation or non-relocating hint. This function evaluates evidence; it never performs a dereference or follows a hop itself.", "inputs": [ "ordered hop observations with observer, signal type and observation instant", "declared hop budget", "as-of observation cut-off" ], "outputs": [ "chain observation trace with termination reason", "per-hop relocation class", "chain-derived status contribution (loop detected, budget exhausted, terminal reached)" ], "preconditions": [ "each hop carries an observation instant at or before the cut-off", "the observing agent is identified and attributable" ], "effects": [ "persists the trace as evidence, including partial and looping traces", "never promotes a hop to an assertion by itself" ], "source_refs": [ "SRC-023", "SRC-024", "SRC-006" ] }, { "id": "als-res-fn-capture-hint-evidence", "name": "Capture a published equivalence hint as evidence", "description": "Record a published canonical link, relocation response or alsoKnownAs-style statement as attributable evidence, run the reciprocity and authority checks, and set promotion eligibility without creating an assertion.", "inputs": [ "context endpoint and published relation type", "target endpoint and captured representation", "observing agent and capture instant" ], "outputs": [ "captured hint evidence item with payload digest", "promotion eligibility flag and the checks that produced it", "reciprocity finding where a return hint exists" ], "preconditions": [ "the relation type is recognised or explicitly recorded as unregistered", "the capture is attributable to a named observing agent" ], "effects": [ "stores evidence only; an assertion is created solely by a separate authority-backed proposal", "records that transport-level signals alone do not establish subject identity" ], "source_refs": [ "SRC-024", "SRC-006", "SRC-009", "SRC-060" ] }, { "id": "als-res-fn-register-endpoint-change", "name": "Register an external endpoint change and raise re-evaluation", "description": "Ingest an externally decided merge, split, withdrawal, deactivation or reinstatement of an endpoint, mark every assertion naming that endpoint for re-evaluation and set interim admissibility. The endpoint decision and any master-data merge remain external.", "inputs": [ "reference to the deciding authority's change record and its effective instant", "change class", "ingestion instant" ], "outputs": [ "re-evaluation request with state and impacted assertion set", "interim admissibility per impacted assertion", "continuity hints for predecessor and successor endpoints" ], "preconditions": [ "the change is evidenced by the endpoint's own authority", "the effective instant and ingestion instant are recorded separately" ], "effects": [ "opens a re-evaluation request without altering any endpoint or master record", "retains all affected assertions rather than deleting them" ], "source_refs": [ "SRC-056", "SRC-063" ] }, { "id": "als-res-fn-emit-impact-report", "name": "Emit change impact and readiness content", "description": "Produce the impact and migration readiness report and the change notice content for a registered endpoint change over a stated interval, enumerating created, updated and deleted alias entries. Delivery, subscription and receipting are external.", "inputs": [ "registered endpoint change reference", "interval start and optional end instants", "consumer set definition" ], "outputs": [ "change impact and migration readiness report", "alias change notice content with per-entry change type", "readiness signal" ], "preconditions": [ "the re-evaluation request has reached a reportable state", "interval boundaries are expressed with seconds and explicit offset" ], "effects": [ "publishes report and notice content for consumers to collect", "does not transmit, retry or acknowledge notifications" ], "source_refs": [ "SRC-008", "SRC-061" ] }, { "id": "als-res-fn-admit-proposal", "name": "Admit a contended proposal", "description": "Accept or reject a proposed assertion change under an expected-version precondition, an idempotency key and a request fingerprint, replaying the original outcome for a recognised retry and recording duplicates and in-flight collisions explicitly.", "inputs": [ "proposed assertion change", "expected-version token", "idempotency key and request fingerprint" ], "outputs": [ "concurrency outcome code", "replayed original outcome for a recognised retry", "duplicate-of reference where the proposal restates an existing assertion" ], "preconditions": [ "the normalised endpoint pair key can be computed", "the key retention window is declared and current" ], "effects": [ "applies at most one state transition per idempotency key and fingerprint pair", "rejects a mismatched precondition instead of overwriting", "rejects reuse of a key with a different fingerprint" ], "source_refs": [ "SRC-023", "SRC-062" ] }, { "id": "als-res-fn-contain-assertion", "name": "Contain a disputed or harmful assertion", "description": "Place an assertion into a contested, suppressed or quarantined state with a stated reason, expiry and tombstone statement, link any compensating action, and keep every prior decision and evidence item intact.", "inputs": [ "assertion or conflict set reference", "containment action code and stated reason", "raising agent, instant and evidence threshold met" ], "outputs": [ "containment and compensation record with tombstone statement", "updated per-member containment state", "expiry instant and review obligation" ], "preconditions": [ "the raising agent holds the declared entitlement for the action", "the assertion and its evidence are already durably retained" ], "effects": [ "suppresses the assertion from candidate sets while leaving it discoverable in diagnostics", "never deletes an assertion, its evidence or an answer that cited it", "enforcement of consumer visibility tiers is delegated to the adopting Dimension's access-control model" ], "source_refs": [ "SRC-009", "SRC-056", "SRC-063" ] }, { "id": "als-res-fn-replay-answer", "name": "Replay a previously issued answer", "description": "Recompute a prior answer from this model's own retained inputs and compare the result with the stored answer record, to demonstrate that historical answering is deterministic.", "inputs": [ "prior answer record reference", "its recorded as-of frame, pin manifest and determinant digest" ], "outputs": [ "replay verdict (reproduced, diverged, inputs unavailable)", "divergence report naming the changed inputs" ], "preconditions": [ "the determinant input set and the pin manifest are still retained", "the observation cut-off can be reapplied to the retained assertion population" ], "effects": [ "produces a verdict about this model's own records only", "does not constitute or replace the consuming systems' audit trail, which is owned elsewhere" ], "source_refs": [ "SRC-059", "SRC-009", "SRC-015" ] }, { "id": "als-grole-fn-assign-authority-role", "name": "Assign and attest a control role", "description": "Record that a named agent holds a control role for a defined scope, on whose behalf it acts, under which delegation instrument, and until when.", "inputs": [ "Agent identifier", "Control role code", "Authority scope expression", "Delegation instrument reference", "Effective time and expiry or re-attestation time" ], "outputs": [ "Role assignment record with qualified delegation", "Separation-of-duties check result for the affected assertions" ], "preconditions": [ "The delegating agent is itself recorded with authority covering the delegated scope", "The delegation instrument reference resolves", "The assignment does not create a forbidden role combination for an existing assertion" ], "effects": [ "Role assignment becomes citable by assertions created within its scope and validity window", "Assignment is queued for re-attestation at its expiry time" ], "source_refs": [ "SRC-009", "SRC-069", "SRC-034" ] }, { "id": "als-grole-fn-determine-approval-tier", "name": "Determine the required approval tier for a proposed assertion", "description": "Given the declared relation strength, the evidence class present and any confidence value, look up the approval threshold schedule and return the required approval tier and reviewer independence requirement. This determines what approval is required; it never grants approval and never authorises access.", "inputs": [ "Declared relation strength tier", "Evidence class and coded justification", "Confidence value and its scale", "Reference to the current approval threshold schedule" ], "outputs": [ "Required approval tier", "Reviewer independence requirement", "Shortfall statement naming any missing evidence" ], "preconditions": [ "A current version of the approval threshold schedule is resolvable", "The declared relation strength is a value in the governed tier list" ], "effects": [ "Proposed assertion is placed in a pending state until the required approval or a valid exception exists" ], "source_refs": [ "SRC-003", "SRC-075", "SRC-064", "SRC-034" ] }, { "id": "als-grole-fn-record-review-outcome", "name": "Record a review or adjudication outcome", "description": "Capture the reviewer's decision on a pending assertion or on a contest, including the independence check, the evidence considered, the decision and the resulting relation strength and assurance level.", "inputs": [ "Assertion identifier and version", "Reviewer identifier and independence check result", "Evidence references considered", "Decision code and reason" ], "outputs": [ "Review decision record", "Updated relation strength and assurance level on the assertion", "Audit event reference returned by the external audit store" ], "preconditions": [ "The reviewer holds the reviewer role within a valid authority window", "The reviewer is not the matching operator or the publisher when independence is required", "The required evidence class for the target relation strength is present, or the decision is a downgrade or refusal" ], "effects": [ "Assertion moves from pending to approved, refused or downgraded", "Any prior approval superseded by this decision is marked as superseded rather than deleted" ], "source_refs": [ "SRC-034", "SRC-012", "SRC-069", "SRC-009" ] }, { "id": "als-grole-fn-grant-scoped-exception", "name": "Grant a scoped, time-boxed exception", "description": "Record an exception that relaxes an approval requirement for a named scope until a mandatory expiry, with compensating conditions and a post-hoc review date, without altering the relation strength or assurance level of any covered assertion.", "inputs": [ "Requesting agent and exception reason code", "Granting policy authority and mandate reference", "Scope expression and covered assertion set", "Expiry time, compensating conditions and review due date" ], "outputs": [ "Exception record", "Exception reference attached to each covered assertion" ], "preconditions": [ "The granting agent holds the policy authority role for the stated scope", "An expiry time is supplied and is within the maximum duration for the exception class", "The exception does not raise the relation strength, assurance level or evidence class of any covered assertion" ], "effects": [ "Covered assertions may be published while carrying a visible exception reference", "At expiry the covered assertions return to the pending or suspended state defined for the exception class" ], "source_refs": [ "SRC-069", "SRC-073", "SRC-066" ] }, { "id": "als-grole-fn-classify-sensitivity", "name": "Classify privacy sensitivity of an assertion and its evidence", "description": "Apply personal data, special category, confidentiality, sensitivity, compartment, pseudonymisation and protected-location values to the assertion and to each evidence element, including any label that arises only from the act of linking.", "inputs": [ "Endpoint identifiers, labels and their existing classifications", "Matching evidence and feature inventory", "Applicable special category and confidentiality code lists" ], "outputs": [ "Classification label set on the assertion", "Per-element classification on evidence, features and reviewer notes", "Re-identification effect statement for the link" ], "preconditions": [ "The tenant scope of the assertion is known", "The governing code lists for confidentiality, sensitivity and special categories are resolvable" ], "effects": [ "Labels become attributes available to the external decision point", "Default disclosure class of each element is set from its classification" ], "source_refs": [ "SRC-066", "SRC-070", "SRC-071", "SRC-074" ] }, { "id": "als-grole-fn-project-disclosure-view", "name": "Project a disclosure-scoped view of an assertion", "description": "Materialise the subset of an assertion permitted for a stated audience and scope level according to the current disclosure profile, applying the declared masking or redaction obligations. The function applies a declared profile to produce a projection; it does not evaluate an access request, does not return permit or deny, and does not enforce the result.", "inputs": [ "Assertion identifier and version", "Audience code and requested scope level", "Declared purpose of use", "Current disclosure profile version" ], "outputs": [ "Projected assertion view limited to the permitted disclosure classes", "Handling obligations attached to the projection", "Statement of the classes withheld from the projection" ], "preconditions": [ "A current disclosure profile version is resolvable", "The declared purpose of use is present in the assertion's declared purpose list, or a valid exception reference is supplied", "The request has already been authorised by the external decision point" ], "effects": [ "A projection is produced together with its obligations for the enforcement point to discharge", "An audit event reference for the disclosure is recorded against the assertion" ], "source_refs": [ "SRC-072", "SRC-066", "SRC-067", "SRC-064" ] }, { "id": "als-grole-fn-bind-retention-and-hold", "name": "Bind retention class and record hold state", "description": "Attach a retention class and disposition authority citation to a record owned by this model and record the application or lifting of a legal hold as notified by the records authority. The function records bindings and states; it never destroys, transfers or sanitises anything.", "inputs": [ "Record identifier and record kind", "Retention class code and disposition authority citation", "Hold notice reference, applying authority and hold event time" ], "outputs": [ "Retention binding on the record", "Updated hold state with applying authority and effective time" ], "preconditions": [ "The retention class resolves in the schedule published by the records authority", "A hold state change is accompanied by a resolvable notice reference from an authority entitled to issue it" ], "effects": [ "Disposition of the record is suspended while the hold state is applied", "Eligibility for disposition is computed by the records system from the bound class, not by this model" ], "source_refs": [ "SRC-055", "SRC-069", "SRC-070" ] }, { "id": "als-grole-fn-retract-assertion", "name": "Retract an assertion and publish a tombstone", "description": "Withdraw a previously published assertion by recording the invalidating event, publishing a retraction notice and leaving a tombstone that preserves the identifier, the reason, the responsible authority and the references needed to trace what happened.", "inputs": [ "Assertion identifier and version", "Retraction reason code and retracting authority", "Retraction event time", "Superseding assertion reference, if any" ], "outputs": [ "Retraction notice and tombstone record", "Preserved provenance references", "Notification payload for prior recipients" ], "preconditions": [ "The retracting agent holds an authority covering the assertion's scope, or is the endpoint authority whose contest was upheld", "Any legal hold on the record permits the retraction to be recorded without disposing of the underlying evidence" ], "effects": [ "The assertion ceases to be current and is excluded from disclosure projections other than the tombstone", "Provenance, approval and exception references survive the withdrawal under their own retention classes" ], "source_refs": [ "SRC-009", "SRC-065", "SRC-055", "SRC-072" ] }, { "id": "als-gplat-fn-project-alias-set", "name": "Project alias set into a declared binding", "description": "Renders the format-neutral alias set into one declared storage or interface projection, applying the projection capability matrix, the pinned prefix map and the predicate binding profile, and returning every downgrade and omission applied.", "inputs": [ "Format-neutral alias set edition and its digest", "Projection descriptor and capability flags", "Prefix map edition pin", "Predicate binding profile edition" ], "outputs": [ "Projection artifact for the target binding", "Applied-loss report referencing loss register entries", "Companion metadata document where the projection cannot embed set metadata" ], "preconditions": [ "The projection is declared conformant for the alias set's schema version", "Every compact identifier expands unambiguously against the pinned prefix map", "All losses the projection will cause are already declared in the loss register" ], "effects": [ "Emits a distribution of the alias set without altering the format-neutral record", "Records each applied downgrade and each discarded non-standard slot against its loss-register entry" ], "source_refs": [ "SRC-082", "SRC-034", "SRC-087", "SRC-083", "SRC-080" ] }, { "id": "als-gplat-fn-verify-roundtrip", "name": "Verify projection round-trip fidelity", "description": "Writes a corpus alias set through a projection, reads it back, canonicalizes both sides and reports which declared features survived, which were lost and which losses are undeclared.", "inputs": [ "Source alias set or conformance corpus edition", "Projection descriptor and implementation under test", "Canonicalization profile" ], "outputs": [ "Per-feature fidelity verdict", "Delta against the current loss register", "Blocking defect list for undeclared losses" ], "preconditions": [ "Canonical form is computable for both source and re-read forms under a single regime", "The corpus edition covers every feature the projection claims to carry" ], "effects": [ "Updates the round-trip loss register with new or resolved entries", "Blocks publication of the projection while any undeclared loss remains open" ], "source_refs": [ "SRC-077", "SRC-088", "SRC-087", "SRC-083" ] }, { "id": "als-gplat-fn-bind-external-predicate", "name": "Resolve an internal alias strength to a target predicate", "description": "Selects the target-vocabulary predicate and modifier for a given internal alias strength, checks the target vocabulary's disjointness and closure constraints, and returns either a binding with its recorded downgrade or a refusal.", "inputs": [ "Internal alias strength, kind and confidence", "Target vocabulary identifier and version", "Predicate binding profile and export guard parameters" ], "outputs": [ "Bound predicate IRI with optional modifier", "Semantic downgrade note, or a refusal reason code", "List of features that cannot be carried and their carriage decision" ], "preconditions": [ "A binding entry exists for the strength and target vocabulary version", "No prohibited predicate pair is created by the binding", "Any strengthening binding carries a valid approval reference" ], "effects": [ "Records the binding decision, downgrade and guard outcome against the alias", "Withholds the alias from export when no sufficiently weak predicate exists" ], "source_refs": [ "SRC-003", "SRC-076", "SRC-081", "SRC-034", "SRC-030" ] }, { "id": "als-gplat-fn-expand-compact-identifier", "name": "Expand and compact identifiers deterministically", "description": "Expands a compact identifier to a full IRI, or compacts a full IRI, using only the pinned prefix map edition, and raises an error rather than guessing when a prefix is undeclared or ambiguous.", "inputs": [ "Compact identifier or full IRI", "Prefix map edition pin and its digest" ], "outputs": [ "Full IRI or compact identifier", "Ambiguity or undeclared-prefix error with the offending prefix" ], "preconditions": [ "The prefix map edition is pinned and its digest verified", "No prefix in the map binds to more than one stem" ], "effects": [ "Rejects any record containing an identifier that cannot be resolved without external lookup", "Leaves the underlying record unchanged" ], "source_refs": [ "SRC-034", "SRC-080", "SRC-084" ] }, { "id": "als-gplat-fn-compute-canonical-digest", "name": "Compute canonical form and edition digest", "description": "Applies the canonicalization regime appropriate to the projection, produces the canonical byte sequence and computes the edition digest with a named algorithm and encoding.", "inputs": [ "Alias record or alias-set edition", "Canonicalization profile and regime selector", "Digest algorithm and encoding identifiers" ], "outputs": [ "Canonical byte sequence", "Edition digest with algorithm and encoding identifiers", "List of fields excluded from the canonical form" ], "preconditions": [ "Set-level slots have been propagated to each record before hashing", "Identity and computed-cardinality fields are declared excluded" ], "effects": [ "Writes the digest to the integrity manifest for the edition", "Never assigns or derives a record identifier from the digest" ], "source_refs": [ "SRC-077", "SRC-088", "SRC-034" ] }, { "id": "als-gplat-fn-emit-redirect-projection", "name": "Emit a redirect projection rule set", "description": "Derives a server-agnostic redirect rule set from an alias-set edition, binding alias status to a permanent, temporary or see-other status class and setting cache directives, for execution by an external HTTP service.", "inputs": [ "Alias-set edition and canonical-identifier selection", "Status-class binding table and exclusion list", "Namespace write-authority declarations" ], "outputs": [ "Redirect rule set with status classes and Location targets", "Cache validity directives per status class", "Derivation record naming the source edition and its digest" ], "preconditions": [ "The owner package holds or is delegated write authority over every namespace stem targeted", "No alias strength on the exclusion list, including graded matches, is bound to a permanent redirect" ], "effects": [ "Produces an artifact for an external service to execute; this model performs no request handling, negotiation or logging", "Marks previously emitted rule sets for regeneration when the source edition is superseded" ], "source_refs": [ "SRC-023", "SRC-084", "SRC-003" ] }, { "id": "als-gplat-fn-apply-edition-patch", "name": "Apply a versioned patch to an alias-set edition", "description": "Applies an ordered, atomic patch document to a base edition, guarded by a leading test operation on the base digest, and returns a new immutable edition with a compatibility verdict.", "inputs": [ "Base edition and its recorded digest", "Ordered patch document beginning with a base-digest test operation", "Target schema version" ], "outputs": [ "New edition with its own opaque serial and digest", "Compatibility verdict and required version increment", "Change-log entry linking base and result" ], "preconditions": [ "The base-digest test operation succeeds", "The patch does not attempt to modify an already released edition" ], "effects": [ "Creates a new edition and leaves the base edition byte-identical", "Applies all operations or none, and appends the outcome to the change log" ], "source_refs": [ "SRC-079", "SRC-085", "SRC-077", "SRC-082" ] }, { "id": "als-gplat-fn-assign-record-identity", "name": "Assign an alias record identifier by priority", "description": "Assigns the identifier for a new alias record or set by walking the identity priority in order and recording which tier was used and why any higher tier was unavailable.", "inputs": [ "Candidate master-system identifier from the system of record, if any", "Governed namespace stem available to the owner package", "Minting context indicating whether time-ordered or unpredictable identifiers are required" ], "outputs": [ "Assigned identifier and the tier it came from", "Justification when a lower tier was used", "Rejection when a date, digest, version string or file path was proposed as identity" ], "preconditions": [ "The system of record has been checked for an existing identifier before minting", "The governed namespace is owned or delegated to the owner package" ], "effects": [ "Binds the identifier immutably to the record for its lifetime", "Mints a time-ordered UUID only where sortable keys are needed and an unpredictable UUID where they are not" ], "source_refs": [ "SRC-078", "SRC-034", "SRC-084", "SRC-008" ] }, { "id": "als-gplat-fn-emit-agents-bootstrap", "name": "Generate the AGENTS.md orientation record", "description": "Produces or refreshes the root orientation file that tells an agent what this model is, where its records actually live, how to read and change them, and which processes govern that, including when the records are held by an MCP server or a document store rather than local files.", "inputs": [ "Registry entry for the model", "Storage binding descriptor, including MCP server or collection descriptors", "Interface binding descriptor and process catalogue" ], "outputs": [ "AGENTS.md file carrying the six required orientation fields", "Resolution report confirming each declared link dereferences" ], "preconditions": [ "All six required links resolve at generation time", "The storage binding names the server or collection descriptor rather than a filesystem path when records are not file-held" ], "effects": [ "Places the file at the alias-set root, with nested files overriding for sub-trees", "Allows an agent to locate non-file-held records without assuming a local directory" ], "source_refs": [ "SRC-086", "SRC-082", "SRC-034" ] }, { "id": "als-cmd-fn-canonicalize-command", "name": "Canonicalise command and compute fingerprint", "description": "Produce the canonical serialisation of a mutation command's semantically significant content under the declared canonicalisation profile and compute its digest, so that a replayed idempotency key can be compared against the original payload.", "inputs": [ "Mutation command payload", "Canonicalisation profile identifier", "Digest algorithm identifier" ], "outputs": [ "Canonical serialisation", "Canonical request fingerprint digest" ], "preconditions": [ "The declared canonicalisation profile is registered and its version is resolvable", "All time values in the payload carry seconds and an explicit offset" ], "effects": [ "Calculation only; no record is appended and no external system is contacted", "The fingerprint is a comparison value and is never used as an identifier" ], "source_refs": [ "SRC-062", "SRC-008" ] }, { "id": "als-cmd-fn-classify-command-replay", "name": "Classify command against the receipt series", "description": "Look up the composite (submitting client reference, idempotency key) in the receipt series and classify the incoming command as first occurrence, in-flight duplicate, completed replay or key reuse with a differing payload.", "inputs": [ "Submitting client reference", "Idempotency key", "Canonical request fingerprint digest", "Current time for expiry evaluation" ], "outputs": [ "Replay classification code", "Reference to the previously recorded outcome when the classification is a completed replay", "Outcome code when the classification is a conflict" ], "preconditions": [ "The command carries a well-formed idempotency key", "The receipt series for the composite key is readable" ], "effects": [ "Calculation only; the command is not applied and no assertion record is appended", "Does not deliver any response and does not write an audit-log entry" ], "source_refs": [ "SRC-062", "SRC-023" ] }, { "id": "als-cmd-fn-evaluate-version-precondition", "name": "Evaluate optimistic-concurrency precondition", "description": "Compare the version validator supplied by the command with the register's current version token for the target assertion at the declared concurrency scope, and report whether the precondition holds.", "inputs": [ "Target assertion reference", "Observed version token", "Precondition mode", "Declared concurrency scope" ], "outputs": [ "Precondition result (holds or fails)", "Current version token at evaluation time", "Conflict outcome code on failure" ], "preconditions": [ "The target assertion exists, or the precondition mode expects absence", "Replay classification has already been determined so a replay is not misreported as a stale version" ], "effects": [ "Validation only; no state is changed", "Failure prevents any subsequent record from being appended by the same command" ], "source_refs": [ "SRC-023", "SRC-062" ] }, { "id": "als-cmd-fn-run-validation-check-set", "name": "Run the declared validation check set", "description": "Evaluate every applicable check from the in-force catalogue version against the command payload and the current register state, covering endpoint reference and version, relation-property contract, type/scheme/context compatibility, required evidence and review, contradictions, not-same constraints, effective interval and declared access scope.", "inputs": [ "Command payload", "Check catalogue version identifier", "Current state of the target assertion and of active assertions over the same endpoint pair", "Recorded not-same constraints and declared access scopes" ], "outputs": [ "Conformance flag", "Ordered validation result entries with element pointers, offending values, source check identifiers and severities" ], "preconditions": [ "The check catalogue version is resolvable and in force", "Endpoint references are syntactically well formed and carry version tokens where required" ], "effects": [ "Validation only; produces results without appending any assertion record", "Does not dereference or resolve endpoints, does not compute entailments, and does not decide whether the actor is authorised" ], "source_refs": [ "SRC-045", "SRC-003", "SRC-031", "SRC-060", "SRC-072" ] }, { "id": "als-cmd-fn-compose-problem-report", "name": "Compose machine-readable failure report", "description": "Project a failed validation run, a precondition failure or a replay conflict into a machine-readable failure document with a stable problem type, a summary title, an occurrence-specific detail and an extension array carrying one entry per failed check with its element pointer.", "inputs": [ "Validation result entries or conflict outcome code", "Problem type registry", "Occurrence reference" ], "outputs": [ "Failure report document", "Primary reported problem type", "Retryability classification" ], "preconditions": [ "Every reported problem type is registered and stable", "The occurrence reference identifies the specific command attempt" ], "effects": [ "Calculation only; the document is returned to the caller and, where the failure is durable, recorded in the validation report series", "Unrecognised extension members are ignored by consumers rather than treated as errors" ], "source_refs": [ "SRC-089", "SRC-045", "SRC-023" ] }, { "id": "als-cmd-fn-record-proposal-version", "name": "Record a proposal version", "description": "Append a new immutable proposal version to an assertion's version chain, carrying the endpoint references, relation-property binding, direction and canonical designation, proposed effective interval, declared confidence, asserting authority reference, declared access scope and revision link to any predecessor.", "inputs": [ "Validated propose command payload", "Assertion identifier or a request to mint one", "Proposing agent reference", "Command event time and register observation time" ], "outputs": [ "Proposal version identifier and sequence position", "Updated current version token", "Command receipt entry" ], "preconditions": [ "Replay classification is first occurrence", "The concurrency precondition holds", "The validation run reported no blocking violation" ], "effects": [ "Appends one immutable record; no earlier record is modified", "Does not resolve endpoints, does not merge records and does not notify any downstream system" ], "source_refs": [ "SRC-009", "SRC-052", "SRC-090" ] }, { "id": "als-cmd-fn-record-evidence-attachment", "name": "Record an evidence attachment", "description": "Append an immutable evidence item bound to a named proposal version, with its role, payload digest or external reference, provenance attributes, declared classification and both generation and observation times.", "inputs": [ "Validated submit-evidence command payload", "Target proposal version identifier", "Submitting agent reference" ], "outputs": [ "Evidence item identifier and sequence position", "Updated required-evidence sufficiency indicator for the target version" ], "preconditions": [ "The target proposal version exists and is not in a terminal state", "The concurrency precondition holds for the target version", "The evidence payload digest is present" ], "effects": [ "Appends one immutable record; withdrawal is a separate appended record and never an edit", "Does not evaluate the truth of the evidence and does not store or transmit any withheld payload" ], "source_refs": [ "SRC-072", "SRC-009" ] }, { "id": "als-cmd-fn-record-decision-assertion", "name": "Record an approve or reject decision assertion", "description": "Append an immutable decision assertion binding the decision outcome and reason to the decided proposal version, the relied-upon validation report and their digests, the deciding authority reference, the decision basis and both decision event time and register observation time.", "inputs": [ "Validated approve or reject command payload", "Decided proposal version identifier and digest", "Relied-upon validation report identifier and digest", "Deciding authority reference and decision basis" ], "outputs": [ "Decision assertion identifier and sequence position", "Updated lifecycle state of the decided version", "Command receipt entry" ], "preconditions": [ "The cited validation report exists and was computed over the cited proposal version", "No prior decision assertion for the same proposal version exists, unless the command is an explicit later decision", "The concurrency precondition holds" ], "effects": [ "Appends one immutable record; a reversal is a later appended record, never an edit", "Records that a named authority decided; performs no authorization evaluation, no enforcement and no audit-log write" ], "source_refs": [ "SRC-009", "SRC-072", "SRC-052" ] }, { "id": "als-cmd-fn-record-state-transition", "name": "Record a lifecycle state transition", "description": "Append an immutable transition record for activation, supersession, retraction or quarantine marking, naming prior and resulting states, the authorising decision assertion, the effective interval applied, any superseded version and conflict type, and the acting agent.", "inputs": [ "Validated transition command payload", "Authorising decision assertion reference where the transition requires one", "Effective interval values", "Acting agent reference" ], "outputs": [ "Transition record identifier and sequence position", "Updated lifecycle state and current version token", "Transition correlation identifier" ], "preconditions": [ "The requested transition is legal from the assertion's current state", "The concurrency precondition holds", "Effective start precedes any effective end and overlap rules are satisfied or an accompanying supersession is present" ], "effects": [ "Appends one immutable record and updates only the derived current-state pointer", "Emits a correlation identifier for other models to consume; performs no notification delivery, no redirect execution, no endpoint merge and no physical deletion" ], "source_refs": [ "SRC-052", "SRC-009", "SRC-072" ] }, { "id": "als-cmd-fn-derive-compensation-plan", "name": "Derive a compensating record plan", "description": "For a command that applied only partially, enumerate the records it already appended and compute the counter-record set that would restore a consistent state, together with the concurrency validators each counter-record requires.", "inputs": [ "Originating command identifier and its receipt", "Records appended by that command", "Current state and version tokens of the affected assertions" ], "outputs": [ "Compensating record plan with one proposed counter-record per appended record", "Residual inconsistency report where no automatic compensation exists" ], "preconditions": [ "The originating command receipt exists and is in a failed or partially applied state", "The affected assertions are readable at their current versions" ], "effects": [ "Calculation and recording only; the plan is appended as a record and is not executed by this function", "Applying any counter-record requires a separate command with its own idempotency key and concurrency precondition" ], "source_refs": [ "SRC-023", "SRC-089", "SRC-009" ] }, { "id": "als-query-fn-read-current", "name": "Read Current Alias Assertions", "description": "Return the alias assertions currently held for a subject identifier within an explicit scope, with per-assertion provenance references, a parameter echo and a completeness statement.", "inputs": [ "Subject identifier", "Relation kind filter", "Declared context filter", "Dataset or authority scope", "Access scope reference", "Result limit" ], "outputs": [ "Candidate result set with per-assertion relation kind and provenance references", "Answer state code", "Parameter echo including applied defaults and effective scope", "Disclosure statement reference" ], "preconditions": [ "The request has passed validation against the published capability profile", "The access scope reference resolves and an external decision is available or the call is denied", "The relation kinds requested are all declared in the relation-property profile" ], "effects": [ "Read-only: no alias assertion, endpoint record or host entity is created, modified or deleted", "Emits a result record and a bound disclosure statement; the audit trail of the call belongs to the adopting Dimension's logging service", "Never selects a preferred identifier and never rewrites an endpoint identifier into a local form" ], "source_refs": [ "SRC-048", "SRC-094", "SRC-023", "SRC-009" ] }, { "id": "als-query-fn-read-as-of", "name": "Read Alias Assertions As At an Instant", "description": "Return the alias assertion state for a subject as at a supplied validity instant, record instant, or both, disclosing whether the served state is an exact or nearest-preceding match and which lifecycle states were admitted.", "inputs": [ "Subject identifier", "As-of validity instant in RFC 3339 with seconds and explicit offset or Z", "As-of record or observation instant in the same form", "Admitted lifecycle state set", "Relation kind filter", "Access scope reference" ], "outputs": [ "As-of result set with served-state intervals", "Temporal match mode code", "Staleness flags for endpoints and evidence references", "Disclosure statement reference and content digest for replay" ], "preconditions": [ "The capability profile declares as-of support and which timelines are supported", "The requested instants fall within the declared temporal coverage window", "Each supplied instant carries an explicit offset; an unknown offset is preserved and not rewritten" ], "effects": [ "Read-only over stored states; performs no datetime negotiation and follows no redirect against an external resolver", "Reports a TimeGate or TimeMap reference where one is known, without invoking it", "Records both instants and the profile versions so the same query is replayable" ], "source_refs": [ "SRC-008", "SRC-059", "SRC-095", "SRC-009" ] }, { "id": "als-query-fn-resolve-candidates", "name": "Resolve Identifier to Candidate Equivalents", "description": "Resolve a supplied identifier to the complete admitted set of candidate equivalent identifiers under explicit relation kinds, direction, hop limit, strength-loss budget, context and as-of instants, returning every candidate with its supporting evidence.", "inputs": [ "Subject identifier", "Relation kind filter and direction", "Hop limit and maximum allowed strength loss", "Declared context", "As-of instants", "Access scope reference" ], "outputs": [ "Complete candidate set with supporting paths and per-edge provenance", "Answer state covering single, ambiguous, none-asserted, not-answerable and truncated outcomes", "Attributed authority canonical claims where published", "Ordering key declaration or an explicit unordered marker" ], "preconditions": [ "The relation-property profile is resolvable and versioned", "The requested hop limit does not exceed the service maximum", "An entailment stance is either requested or supplied as a declared service default" ], "effects": [ "Never selects, mints, caches or persists a canonical identifier; canonical claims are attributed to the authority that published them", "Produces no new alias candidates: nothing is matched, scored for similarity or inferred from attributes", "Read-only with respect to all assertions, endpoints and host entities" ], "source_refs": [ "SRC-023", "SRC-014", "SRC-030", "SRC-048", "SRC-006" ] }, { "id": "als-query-fn-traverse-paths", "name": "Enumerate Alias Paths", "description": "Enumerate every candidate path between a start identifier and either a target identifier or any reachable endpoint, under explicit relation kinds, direction, hop limit, strength budget, context, as-of instants and access scope, in a cycle-safe way.", "inputs": [ "Start identifier and optional target identifier", "Relation kind filter and direction", "Hop limit and maximum allowed strength loss", "Declared context and as-of instants", "Access scope reference", "Continuation token for a resumed traversal" ], "outputs": [ "Every candidate path with ordered edges, per-edge provenance and derivation labels", "Cycle notices and contradiction notices", "Truncation reason and continuation token", "Completeness state and parameter echo" ], "preconditions": [ "Cycle-safe connectivity matching is available so that traversal terminates", "Every requested relation kind has declared symmetry, transitivity and disjointness properties", "Result and hop limits from the capability profile are in force" ], "effects": [ "Read-only: derived edges exist only within the returned report and are never written back to any store", "Reports rather than resolves contradictions and never removes a contradicted path silently", "Truncation is always disclosed; a truncated traversal is never presented as a complete answer" ], "source_refs": [ "SRC-048", "SRC-003", "SRC-006", "SRC-091" ] }, { "id": "als-query-fn-calculate-path-strength", "name": "Calculate Composed Path Strength", "description": "Compute the composed strength and cumulative loss for a path from its per-edge confidence values and relation-kind properties under a declared, versioned composition method, and mark the path admitted or excluded against the caller's budget.", "inputs": [ "Path edge sequence with per-edge relation kinds and confidence values", "Composition method reference and version", "Maximum allowed strength loss", "Per-relation-kind default confidence values" ], "outputs": [ "Composed path strength and cumulative loss", "Admitted or excluded flag with an exclusion reason code", "Echo of the composition method reference and any defaults applied", "Warning marker where a non-transitive relation kind was chained" ], "preconditions": [ "The composition method is declared and versioned before use", "Every edge carries a confidence value or a declared default for its relation kind", "Relation-kind transitivity flags are available for every edge" ], "effects": [ "Calculation only: produces an annotation on the path report and no standing quality or conflict record", "The value is reported as a declared measurement, never as an assertion that the endpoints are the same", "Leaves all assertions and confidence values unchanged" ], "source_refs": [ "SRC-033", "SRC-003", "SRC-030" ] }, { "id": "als-query-fn-compare-assertions", "name": "Compare Competing Alias Assertions", "description": "Compare two or more assertions about the same endpoint pair or candidate across authority, relation semantics, confidence, declared context, temporal validity, evidence and lifecycle state, and report the differences with an outcome code.", "inputs": [ "Two or more assertion references", "Comparison dimension set", "As-of instants", "Access scope reference" ], "outputs": [ "Per-dimension difference summaries", "Evidence reference and verification state per assertion", "Comparison outcome code", "List of dimensions unavailable for at least one assertion" ], "preconditions": [ "All referenced assertions are readable within the access scope, or the unreadable ones are reported as unavailable", "The relation-property profile is available so that semantic differences can be stated factually", "Verification state, where reported, comes from the mechanism that produced it" ], "effects": [ "Reports differences only: does not rank authorities, retract, supersede, merge or accept any assertion", "Verification is kept separate from any decision to rely on a claim, which remains with the caller", "Emits a comparison report bound to the request record and changes nothing in the compared assertions" ], "source_refs": [ "SRC-072", "SRC-045", "SRC-009", "SRC-033" ] }, { "id": "als-query-fn-validate-request", "name": "Validate a Query Request Against the Capability Profile", "description": "Validate a submitted request against the published capability profile and relation-property profile, returning a conformance flag and per-result severities with the focus parameter, and a normalised request with defaults made explicit.", "inputs": [ "Request record", "Capability profile reference and version", "Relation-property profile reference and version" ], "outputs": [ "Conformance flag", "Validation results with severity, focus parameter and the constraint or limit breached", "Normalised request with every applied default echoed", "Refusal reason code where the request cannot be executed" ], "preconditions": [ "Both profiles are resolvable and versioned", "The request record has been assigned an identifier before validation" ], "effects": [ "Validation is idempotent and leaves the request, the profiles and all alias assertions unchanged", "A malformed or refused request is rejected as a whole and never partially executed", "Distinguishes a refused request from a valid request that returns no candidates" ], "source_refs": [ "SRC-045", "SRC-094", "SRC-093" ] }, { "id": "als-query-fn-report-integrity", "name": "Report Result Completeness and Disclosure", "description": "Produce the disclosure statement that must accompany any result set or path report, recording sources consulted and their outcomes, limits reached, suppression signalled by the access scope, and unresolvable endpoints.", "inputs": [ "Result set or path report reference", "Sources consulted with per-source outcome", "Limits reached during execution", "Suppression flag and band derived from the external access decision", "Endpoint resolvability check outcomes" ], "outputs": [ "Completeness state code", "Per-source failure mode including whether a failure was silenced", "Suppression signal without disclosure of withheld content", "Caveat text stating that absence is not evidence of non-equivalence" ], "preconditions": [ "The result being qualified exists and carries an identifier", "The suppression signal derives from an external decision reference and not from a local judgement", "Silenced source failures are known to the executor and are recoverable for reporting" ], "effects": [ "Report only: the model does not evaluate, enforce, override or log the access decision and does not create the audit trail", "Binds the statement one-to-one to the result it qualifies; a result without one is invalid and must not be cached or forwarded", "Never converts a silenced failure into an ordinary empty answer" ], "source_refs": [ "SRC-092", "SRC-023", "SRC-067", "SRC-094" ] }, { "id": "als-report-conflicts", "name": "Report conflicts over an alias assertion set", "description": "Produces a released conflict report instance stating every incompatibility detected within a frozen assertion scope, classified against the governed conflict taxonomy, graded for significance and cited to its evidence and source constraint - without resolving, ranking away or suppressing any participating claim.", "inputs": [ "Frozen scope binding and input snapshot reference", "Conflict class vocabulary identifier and version", "Equivalence strength vocabulary bindings for each participating authority", "Observation cut-off time in RFC 3339 with explicit seconds and offset", "Requester context used only to select the audience redaction profile" ], "outputs": [ "Conflict report instance with a conformance-style summary", "Ordered set of conflict result records with participants, class, severity, source constraint and evidence", "Coverage and completeness statement including unreachable authorities", "Claim inclusion register showing every in-scope claim and any disclosed scope-based exclusion", "Failure outcome record where production aborted or degraded" ], "preconditions": [ "The scope selector resolves to at least one alias assertion in the bound snapshot", "The conflict class vocabulary version is resolvable and not withdrawn", "Every participating assertion declares the strength vocabulary it used, or is reported as unclassifiable rather than silently normalised", "Release is permitted by an external authorization decision; this function performs no authorization" ], "effects": [ "Emits an immutable conflict report instance with attached provenance", "Records the observation cut-off and the covered event-time range as separate values", "Leaves every alias assertion, its lifecycle state and its confidence entirely unmodified", "Failure modes: unresolvable scope aborts with a failure outcome record; snapshot unavailable aborts; vocabulary version mismatch aborts; an unreachable authority degrades the report and is declared in the coverage statement so that absence of a conflict is never reported as confirmation of sameness" ], "source_refs": [ "SRC-045", "SRC-003", "SRC-001", "SRC-039", "SRC-097", "SRC-008" ] }, { "id": "als-report-impact", "name": "Report impact of a change to an alias assertion set", "description": "Produces a released impact report instance projecting the effects of one classified triggering change across the assertion, cluster-view and downstream-reference surfaces, with per-item lineage back to the trigger and prior state and an explicit residual-uncertainty statement.", "inputs": [ "Trigger source reference, trigger class code and trigger event time", "Prior and posterior state references or snapshots", "Requested impact surfaces", "Downstream reference index reference together with the completeness declaration supplied by that index's owner", "Retrospective window where the trigger is a retraction or a false strong-identity discovery" ], "outputs": [ "Impact report instance partitioned by impact surface", "Impacted item entries with lineage chains and prior state references", "Per-member fate assignments for cluster merges and splits", "Reach completeness qualifier and residual uncertainty statement", "Surfaces explicitly not assessed, with reasons" ], "preconditions": [ "The trigger is resolvable and classified against the governed trigger vocabulary", "Prior state is retrievable, or is declared irrecoverable so that lineage gaps are visible rather than implied", "The downstream reference index is declared with its own completeness, or downstream reach is reported as unenumerated", "The retrospective window is bounded and stated for retraction and false strong-identity triggers" ], "effects": [ "Emits an immutable impact report instance with attached provenance", "Performs no merge, split, supersession, retraction or state change on any assertion or derived cluster", "Sends nothing: any resulting communication requires a separate notice-composition step and an external delivery service", "Failure modes: unclassifiable trigger aborts; missing prior state degrades the report with a declared lineage gap; an unavailable downstream index degrades the report to unenumerated reach, which must never be rendered as no impact" ], "source_refs": [ "SRC-009", "SRC-027", "SRC-100", "SRC-101", "SRC-033" ] }, { "id": "als-report-fn-disposition-readiness", "name": "Report disposition readiness for alias mapping records", "description": "Produces a released readiness report classifying each in-scope alias mapping record as eligible, blocked, retained, externally governed or not assessed, citing the governing retention rule, any blocking hold or freeze and the governing jurisdiction, and emitting a self-contained handoff payload for the authority that will actually execute disposition.", "inputs": [ "Record scope binding for alias mapping records", "Retention rule and schedule references with versions, owned by the records retention model", "Legal hold, litigation hold and freeze register references, owned by the issuing authorities", "Jurisdiction and governing-authority context", "Observation cut-off time in RFC 3339 with explicit seconds and offset" ], "outputs": [ "Disposition-readiness report instance with exactly one status per record", "Cited retention rule, hold reference and issuing authority per record", "Earliest eligibility time where a rule was resolvable", "Required residue element list per record with justifications", "Handoff payload addressed to the executing authority, with the frozen scope and the assessment's validity limit" ], "preconditions": [ "Each record in scope resolves to an authoritative identifier held by its owning system", "Retention rule references resolve, or the record is reported as not assessed rather than assumed eligible", "The hold and freeze register is reachable, or blocked-unknown is reported and the record is never classified eligible", "The governing jurisdiction is stated where disposition authority sits outside the adopting Dimension" ], "effects": [ "Emits an immutable readiness report instance with attached provenance", "Deletes, destroys, transfers or anonymises nothing; places, extends or releases no hold or freeze; constructs no audit record; makes no authorization decision", "Transfers a self-contained handoff to the executing records authority, whose confirmation of execution is received as an external input", "Failure modes: unreachable hold register forces blocked-unknown for affected records; unresolvable retention rule forces not assessed; a record whose owning authority cannot be identified is reported as externally governed with an unknown authority rather than being classified eligible" ], "source_refs": [ "SRC-055", "SRC-098", "SRC-100", "SRC-101", "SRC-008" ] }, { "id": "als-report-compose-change-notice", "name": "Compose change notice content for a released report", "description": "Builds delivery-neutral notification content describing a reported change and pointing at the released report instance, redacted for a stated audience scope. It produces content and hands it to a notification service.", "inputs": [ "Released report instance reference", "Audience scope and its redaction profile", "Notice vocabulary binding for change type and tombstone representation", "Recipient category list supplied by the referencing systems, not derived here" ], "outputs": [ "Change notice content payload with change type, affected items and effective time", "Dereferenceable reference to the released report instance", "Statement of the audience scope the content was redacted for", "List of report sections withheld from this audience" ], "preconditions": [ "The report instance is released and immutable", "Redaction for the stated audience scope has been applied and recorded", "The notice vocabulary binding is resolvable" ], "effects": [ "Produces notification content only", "Does not discover an inbox, open a connection, transmit, retry, confirm receipt or escalate; subscription management, delivery and escalation remain with the external notification service", "Does not determine whether a controller's obligation to communicate a change to recipients has been discharged; it supplies the content that obligation may be discharged with", "Failure modes: unreleased or superseded report instance aborts composition; missing redaction profile aborts rather than releasing unredacted content" ], "source_refs": [ "SRC-099", "SRC-100", "SRC-101" ] }, { "id": "als-report-reissue", "name": "Reissue or supersede a report instance", "description": "Issues a corrected or refreshed report instance in an existing series, linked to its predecessor by a revision relation and marking that predecessor superseded, so that a released report is never edited in place and its history stays reconstructable.", "inputs": [ "Predecessor report instance reference", "Reissue reason code and narrative", "New frozen scope binding and input snapshot", "Vocabulary and rule versions in force at reissue" ], "outputs": [ "New report instance in the same series", "Revision link from the new instance to its predecessor", "Superseded marker recorded against the predecessor as a separate annotation", "Supersession notice content where downstream consumers were notified of the predecessor" ], "preconditions": [ "The predecessor instance exists and is retrievable", "The reissue reason is stated; a reissue with no stated reason is refused", "The new snapshot is frozen and digest-bound before generation" ], "effects": [ "Creates a new immutable instance and annotates, but never rewrites, the predecessor", "Retains the predecessor's content under the retention rule owned by the records retention model, which alone may authorise its disposition", "Failure modes: an unretrievable predecessor aborts the reissue rather than starting a detached series; a digest mismatch on the predecessor is reported as a reproducibility failure and does not permit repair in place" ], "source_refs": [ "SRC-009", "SRC-055", "SRC-100" ] }, { "id": "als-report-bind-scope-snapshot", "name": "Bind report scope and input snapshot", "description": "Resolves a scope selector against the declared sources at a stated observation cut-off, freezes the resulting population as an immutable scope binding with a digest-bound input snapshot, and declares any source that could not be reached. This is the reproducibility basis every report function depends on.", "inputs": [ "Scope selector expression", "Source and authority references to resolve against", "Observation cut-off time in RFC 3339 with explicit seconds and offset" ], "outputs": [ "Immutable scope binding with the resolved population", "Input snapshot reference with content digest", "Unreachable source declaration with reason per source", "Ingestion time recorded separately from the observation cut-off" ], "preconditions": [ "At least one declared source reference resolves", "The observation cut-off is a valid RFC 3339 value with explicit seconds and an offset or Z", "The selector is deterministic over the bound snapshot" ], "effects": [ "Fixes a reproducible basis that later report instances cite rather than re-resolve", "Holds references and digests rather than copying source payloads, except where the adopting Dimension's retention policy explicitly permits caching", "Failure modes: no source resolves aborts binding; a non-deterministic selector is refused; partial resolution produces a binding that carries an explicit unreachable-source declaration and cannot be presented as complete" ], "source_refs": [ "SRC-009", "SRC-033", "SRC-008" ] }, { "id": "als-proj-fn-resolve-target-profile", "name": "Resolve projection target profile", "description": "Return the versioned capability profile for a named projection target, including supported relation strengths, qualifier slots, required identifier form, cardinality and ordering guarantees, and the specification it binds to. Read-only.", "inputs": [ "Target profile identifier or target name", "Requested profile version, or a request for the current version" ], "outputs": [ "Resolved capability profile with version and content digest", "Capability class verdict for the target", "Unresolved-profile signal where no profile is registered" ], "preconditions": [ "The caller is authorised to read the model's projection definitions" ], "effects": [ "No state change; the resolved profile identifier and version are recorded on any downstream projection plan" ], "source_refs": [ "SRC-103", "SRC-104", "SRC-108" ] }, { "id": "als-proj-fn-plan-projection", "name": "Calculate projection plan", "description": "Compute per-assertion mapping decisions against a resolved profile and the strength-mapping table: target construct, qualifier disposition, identifier conversion and cardinality handling. Produces no bytes and performs no matching or inference.", "inputs": [ "Source alias assertion set with recorded strengths, authorities and qualifiers", "Resolved target capability profile", "Strength-mapping table version" ], "outputs": [ "Projection plan with target construct and qualifier disposition per assertion", "Provisional loss entries", "Non-upgrade invariant check result" ], "preconditions": [ "Every source assertion carries an explicit recorded strength", "The requested strength-mapping table version resolves" ], "effects": [ "Deterministic calculation only; source assertions are never modified, and no candidate equivalence is generated or scored" ], "source_refs": [ "SRC-041", "SRC-003", "SRC-025" ] }, { "id": "als-proj-fn-serialize-canonical", "name": "Serialize projection in canonical form", "description": "Produce byte-stable output for the target format using the algorithm named in the profile, and compute a content digest as an integrity qualifier over the canonical bytes.", "inputs": [ "Approved projection plan", "Target format and canonicalization algorithm selection", "Encoding and newline profile" ], "outputs": [ "Canonical byte sequence in the target format", "Content digest naming algorithm and covered scope", "Canonicalization warnings for features that cannot be stabilised" ], "preconditions": [ "The plan passed the non-upgrade invariant check", "A canonicalization algorithm is defined for the selected target format" ], "effects": [ "Produces bytes and a digest; writes to no endpoint, repository, collection, MCP server or serving configuration" ], "source_refs": [ "SRC-102", "SRC-077", "SRC-106" ] }, { "id": "als-proj-fn-compute-loss-report", "name": "Compute projection-loss report", "description": "Emit the typed, machine-readable report of omitted qualifiers, substituted relation kinds, cardinality and ordering changes, identifier conversions, hidden evidence and non-round-trippable fields for one projection version.", "inputs": [ "Projection plan with provisional loss entries", "Canonical serialization result and its warnings", "Target capability profile" ], "outputs": [ "Loss report with typed entries, paths and severities", "Fidelity verdict for the declared profile", "Publishability label per entry" ], "preconditions": [ "A projection plan exists for the assertion set and target profile" ], "effects": [ "Emits a derived record; alters neither the projection nor the source assertions, and makes no publication decision" ], "source_refs": [ "SRC-080", "SRC-103", "SRC-045" ] }, { "id": "als-proj-fn-validate-projection", "name": "Validate projection against profile and invariants", "description": "Check a candidate or stored projection for profile conformance, completeness of self-description, and the non-upgrade invariant, returning a conformance result in report form.", "inputs": [ "Candidate projection as bytes or parsed form", "Target capability profile", "Strength-mapping table" ], "outputs": [ "Conformance result with per-check findings and severities", "List of emitted constructs that exceed the recorded strength", "Missing self-description findings" ], "preconditions": [ "The candidate declares its dialect or context and its profile version" ], "effects": [ "Reporting only; validation never rewrites the projection and never enforces publication, withdrawal or access decisions" ], "source_refs": [ "SRC-006", "SRC-045", "SRC-108" ] }, { "id": "als-proj-fn-verify-roundtrip", "name": "Verify import round-trip fidelity", "description": "Compare a re-imported assertion set with its source through a shared canonical form and digest, classify the fidelity state and separate declared from undeclared loss.", "inputs": [ "Stored projection and its recorded digest", "Re-imported assertion set", "Original source assertion set with version", "Declared loss report for the projection" ], "outputs": [ "Fidelity state classification", "Undeclared-difference list with dispositions", "Observation timestamp and digest comparison result" ], "preconditions": [ "Both sides reduce to the same canonical form", "The declared loss report for the projection version is available" ], "effects": [ "Comparison and classification only; performs no repair, merge, re-publication or strengthening of any relation" ], "source_refs": [ "SRC-102", "SRC-077", "SRC-106" ] }, { "id": "als-proj-fn-evaluate-refusal", "name": "Evaluate safe-weakening feasibility and refusal", "description": "Determine whether every assertion in scope has a permissible construct at or below its recorded strength in the target, and recommend full projection, partial projection or refusal with reasons.", "inputs": [ "Projection plan including unresolved mappings", "Target profile capability class", "Publishability and access labels on the source assertions" ], "outputs": [ "Recommendation of full, partial or refused projection", "Emitted-subset selector for a partial projection", "Reason set citing the blocking constructs and their specifications" ], "preconditions": [ "At least one assertion lacks a permissible construct at or below its recorded strength, or an access label blocks emission" ], "effects": [ "Returns a recommendation and reasons; the adopting Dimension decides and executes, and any override record is stored by its platform services" ], "source_refs": [ "SRC-041", "SRC-023", "SRC-024" ] } ], "composition": [ { "target": "WM-XCT-011 Identifier / Reference (registered parent)", "relation": "EXTEND", "purpose": "Specializes the parent reference model for the single case of an asserted equivalence between two references. Identifier syntax, scheme and namespace registration, allocation, non-reuse guarantees, generic authority machinery and resolution execution remain wholly with the parent and are used by reference here.", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-002" ] }, { "target": "Host record adopting the alias mixin", "relation": "MIX-IN", "purpose": "The envelope attaches to a host record that supplies its weak identity context, tenancy and retention scope. The host owns its own lifecycle and disposition; the mixin contributes only the assertion fields.", "required": true, "source_refs": [ "SRC-007", "SRC-002" ] }, { "target": "Endpoint entity and record models at each side", "relation": "REFERENCE", "purpose": "Carries role-bearing locators, version pins, composite key parts, snapshot digests and recorded resolution observations for records owned elsewhere. Endpoint attributes, descriptions, classifications and lifecycles are never imported or mutated here.", "required": true, "source_refs": [ "SRC-007", "SRC-006", "SRC-010" ] }, { "target": "Identifier issuing and registration authority model", "relation": "REFERENCE", "purpose": "Cites the authority governing each endpoint namespace, its version tokens, deprecation notices and non-reuse guarantees. Allocation, minting, retirement and tombstoning of endpoint identifiers are executed entirely by that authority.", "required": false, "source_refs": [ "SRC-017", "SRC-015" ] }, { "target": "Relation classification and semantic predicate vocabularies", "relation": "ALIGN", "purpose": "Binds the envelope's predicate slot to externally defined terms (owl:sameAs, owl:differentFrom, the SKOS mapping properties, ConceptMap relationship codes). Term definitions, sub-property hierarchies and entailment consequences stay in those vocabularies; only the term reference and an optional negation modifier are carried here.", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-013" ] }, { "target": "Formal equivalence closure and reasoning model", "relation": "REFERENCE", "purpose": "Supplies asserted pairs as input to entailment and transitive-closure computation. This model neither computes, materialises nor stores closure results, and forbids local chaining of assertions because the mapping predicates differ in transitivity.", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-012" ] }, { "target": "Record-linkage and matching engine model", "relation": "REFERENCE", "purpose": "Consumes candidate evidence produced by matching engines and records only the justification locator, tool reference and creator-supplied confidence. Blocking, similarity computation, thresholding and engine execution remain outside.", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "target": "Master data merge and survivorship model", "relation": "REFERENCE", "purpose": "Provides asserted pairs that a merge process may consume. Golden-record construction, survivorship rules, redirect execution and any physical consolidation of endpoint records are owned entirely by that model.", "required": false, "source_refs": [ "SRC-017", "SRC-015" ] }, { "target": "SSSOM mapping set exchange profile", "relation": "ALIGN", "purpose": "Maps envelope fields onto SSSOM mapping and mapping-set slots for interchange, noting that SSSOM requires only predicate_id and mapping_justification while this model additionally requires bound endpoint references or an explicit presence state. Alignment is declared; conformance is not claimed without a published validation report.", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "target": "HL7 FHIR R5 ConceptMap exchange profile", "relation": "ALIGN", "purpose": "Aligns endpoint scoping, source and target version pinning, no-map and unmapped handling, and dependsOn condition guards with ConceptMap structures for healthcare interchange, without adopting FHIR's terminology-service behaviour.", "required": false, "source_refs": [ "SRC-013" ] }, { "target": "Link set and dataset description profiles", "relation": "ALIGN", "purpose": "Aligns the assertion set descriptor with third-party link set documents and dataset link descriptions, including explicit subject-side and object-side targets and absolute anchors, so that assertion sets are publishable without a bespoke format.", "required": false, "source_refs": [ "SRC-007", "SRC-010", "SRC-006", "SRC-016" ] }, { "target": "Provenance model aligned to PROV", "relation": "ALIGN", "purpose": "Expresses issuance, attribution, derivation and primary-source citation of the assertion using PROV terms, and uses named provenance bundles for set-level attribution. Provenance record storage and provenance-of-provenance remain external.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "Authorization and access decision model", "relation": "REFERENCE", "purpose": "Supplies tenant, jurisdiction, purpose and licence attributes as decision inputs. Policy evaluation, decision records and enforcement are owned there; this model makes and stores no access decision.", "required": false, "source_refs": [ "SRC-014", "SRC-013" ] }, { "target": "Audit and event-log model", "relation": "REFERENCE", "purpose": "Receives creation, supersession, retraction and tombstoning events carrying the assertion identifier, issuer, event time and observation time. Audit-record structure, retention, integrity and tamper evidence are owned there; this model stores no audit trail.", "required": false, "source_refs": [ "SRC-009", "SRC-008" ] }, { "target": "WM-XCT-011 parent identity and identifier model", "relation": "CHILD", "purpose": "WM-XCT-036 consumes identifiers and identifier-scheme declarations from the parent model as endpoint references. Allocation, formatting, validation and retirement of identifiers stay with the parent; this model only asserts relations between identifiers already issued there.", "required": true, "source_refs": [ "SRC-021", "SRC-022" ] }, { "target": "Adopting-Dimension host entity, record and concept models", "relation": "MIX-IN", "purpose": "The alias assertion set is applied as a mixin to host models whose subjects need federated equivalence, without those models absorbing the relation taxonomy or the strength and negation machinery.", "required": true, "source_refs": [ "SRC-021", "SRC-028" ] }, { "target": "OWL 2 Web Ontology Language identity axioms (owl:sameAs, SameIndividual, owl:differentFrom, DifferentIndividuals)", "relation": "ALIGN", "purpose": "Binds the strict-identity and explicit not-same kinds to OWL 2 axioms and carries the satisfaction conditions as the definition of the maximal strength rank. Entailment, closure and any reasoner behaviour remain owned by OWL 2 semantics and the executing reasoner.", "required": false, "source_refs": [ "SRC-018", "SRC-019", "SRC-031" ] }, { "target": "SKOS mapping and labelling properties (exactMatch, closeMatch, mappingRelation, altLabel)", "relation": "ALIGN", "purpose": "Binds exact-semantic-match, close-match and the name or label alias plane to SKOS terms, importing the symmetry, transitivity and disjointness declarations as documented properties. Concept schemes and thesaurus editing remain with SKOS-based models.", "required": false, "source_refs": [ "SRC-020" ] }, { "target": "schema.org sameAs and alternateName", "relation": "ALIGN", "purpose": "Records schema.org sameAs as a reference-page projection whose expected type is a URL, deliberately kept below the strict-identity rank so that it is not read as an OWL identity axiom.", "required": false, "source_refs": [ "SRC-025" ] }, { "target": "IETF HTTP semantics and web-linking relations (301, 308, rel=canonical, alternate, duplicate)", "relation": "REFERENCE", "purpose": "Carries redirect and link-relation references as projections of referent replacement and representation equivalence. Redirect execution, link header emission and origin-server behaviour are not owned here.", "required": false, "source_refs": [ "SRC-023", "SRC-024", "SRC-006", "SRC-016" ] }, { "target": "DCMI Metadata Terms (replaces, isReplacedBy, identifier)", "relation": "ALIGN", "purpose": "Binds the referent-replacement kind and its inverse to DCMI supersession terms, keeping replacement distinct from equivalence.", "required": false, "source_refs": [ "SRC-026" ] }, { "target": "SSSOM mapping metadata model", "relation": "ALIGN", "purpose": "Aligns justification category, confidence, subject and object type, cardinality and predicate negation with an established mapping-metadata vocabulary so that exchanged assertions remain interpretable. Mapping production and curation pipelines are not owned here.", "required": false, "source_refs": [ "SRC-028" ] }, { "target": "HL7 FHIR Patient.link record-level equivalence types", "relation": "REFERENCE", "purpose": "Carries a deployed record-equivalence projection showing replaced-by, replaces, refer and seealso as distinct kinds. Record content, status semantics and clinical processing remain with the FHIR resource model.", "required": false, "source_refs": [ "SRC-027" ] }, { "target": "Wikidata identity properties P460, P1889 and P2888", "relation": "REFERENCE", "purpose": "Provides deployed projections for probable-entity-match, explicit difference and exact match, including sourcing-circumstance and determination-method qualifiers. Wikidata editorial governance is not owned here.", "required": false, "source_refs": [ "SRC-029" ] }, { "target": "Adopting-Dimension entity resolution and matching model", "relation": "REFERENCE", "purpose": "Supplies the candidate pairs, similarity scores and adjudication decisions that this model records as confidence and justification. Blocking, scoring, thresholding and match adjudication are not owned here.", "required": false, "source_refs": [ "SRC-028", "SRC-030" ] }, { "target": "Adopting-Dimension validation, enforcement and audit services", "relation": "REFERENCE", "purpose": "Executes the published applicability tests and conflict rules and holds the resulting verdicts and audit trail. This model declares the rules and receives conflict declarations; it does not evaluate, enforce or hold audit-trail semantics.", "required": false, "source_refs": [ "SRC-022", "SRC-028" ] }, { "target": "Domain-specific alias profiles such as clinical, bibliographic or geospatial equivalence profiles", "relation": "EXTEND", "purpose": "Downstream profiles may constrain admissible relation kinds, planes, endpoint types and evidence thresholds for their subject area. They must not redefine the generic relation-kind semantics, strength scale, negation states or change-control machinery held here.", "required": false, "source_refs": [ "SRC-027", "SRC-028" ] }, { "target": "WM-XCT-011 (parent identifier and identity model)", "relation": "CHILD", "purpose": "Inherit what an identifier is, who issues it, its namespace and its validity rules. This model adds only the assertion that two such identifiers denote the same subject, plus the evidence, provenance and confidence qualifying that assertion; it does not mint, format or re-validate identifiers.", "required": true, "source_refs": [ "SRC-001", "SRC-039" ] }, { "target": "Agent and party registry of the adopting Dimension", "relation": "REFERENCE", "purpose": "Resolve asserter, authority, publisher, reviewer and approver references to typed agents. This model carries the role binding and the mandate citation for each assertion; agent identity, agent lifecycle and organisational hierarchy remain owned by the registry.", "required": true, "source_refs": [ "SRC-009", "SRC-034" ] }, { "target": "Entity-resolution and matching engine (external runtime component)", "relation": "REFERENCE", "purpose": "Carry the method reference, tool version, configuration digest, feature inventory, thresholds and reported score as recorded parameters and outcomes. Execution, scheduling, blocking, scoring and threshold optimisation stay with the engine; holding a score confers no ownership of the scoring process.", "required": false, "source_refs": [ "SRC-036", "SRC-037" ] }, { "target": "W3C PROV-O and PROV-DM provenance vocabularies", "relation": "ALIGN", "purpose": "Bind local roles and lineage to prov:wasAttributedTo, qualified association and role, prov:wasDerivedFrom, prov:hadPrimarySource, prov:wasRevisionOf and prov:Bundle. Alignment is claimed at the binding level only; no conformance claim is made without a validated profile.", "required": false, "source_refs": [ "SRC-009", "SRC-032" ] }, { "target": "SSSOM Mapping and MappingSet metadata model", "relation": "ALIGN", "purpose": "Map local method, justification, author, creator, reviewer, tool version, source version, confidence and predicate-modifier fields onto their SSSOM counterparts for interchange of mapping sets, without adopting SSSOM's file-format or propagation rules as internal semantics.", "required": false, "source_refs": [ "SRC-034", "SRC-035" ] }, { "target": "SKOS mapping properties and OWL 2 individual (in)equality axioms", "relation": "ALIGN", "purpose": "Reference exactMatch, closeMatch, SameIndividual and DifferentIndividuals as the governed predicates whose transitivity, symmetry, disjointness and substitution licensing are defined externally. This model records which predicate is asserted and constrains export onto it; it never restates or varies their entailment rules.", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "target": "W3C Data Quality Vocabulary measurement model", "relation": "ALIGN", "purpose": "Express calibration and evaluation results as quality measurements against named metrics and dimensions, with PROV supplying the provenance of the assessment. Metric catalogues and the running of assessments remain outside this model.", "required": false, "source_refs": [ "SRC-033" ] }, { "target": "Evaluation dataset and gold-standard corpus registry", "relation": "REFERENCE", "purpose": "Point at the reference data against which linkage quality was measured, with its representativeness caveat. Curation, governance and access control of that corpus, including any restriction on its reuse, are owned by the registry.", "required": false, "source_refs": [ "SRC-040" ] }, { "target": "Access-control, consent and retention policy model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Supply the sensitivity classification, jurisdiction of origin and access classification that a policy model needs as inputs. Evaluation of those policies, enforcement of access decisions and execution of disposition and deletion occur entirely in that model.", "required": true, "source_refs": [ "SRC-037", "SRC-038" ] }, { "target": "Audit and event-log model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Cite audit records that evidence who read, asserted or adjudicated an equivalence. Audit-trail semantics, immutability guarantees and log retention are owned by that model; this model stores only the reference.", "required": false, "source_refs": [ "SRC-037", "SRC-038" ] }, { "target": "Subject models requiring federated identity equivalence", "relation": "MIX-IN", "purpose": "Attach the alias assertion surface, with its evidence, provenance and confidence qualifiers, to any subject model whose instances are known under identifiers in more than one system, without that model redefining equivalence semantics locally.", "required": false, "source_refs": [ "SRC-034", "SRC-039" ] }, { "target": "NIST SP 800-63A-4 identity assurance guidance", "relation": "ALIGN", "purpose": "Take the graded-evidence and identity-resolution concepts as an external reference frame for authority-derived assurance. Identity proofing processes, credential service provider obligations and assurance-level determination are performed under that guidance, not by this model.", "required": false, "source_refs": [ "SRC-038" ] }, { "target": "WM-XCT-011 parent cross-cutting identifier and identity model", "relation": "CHILD", "purpose": "Inherit subject identity scope from the parent and contribute only the declared formal and contextual properties of assertions made between identifiers. Identifier minting, namespace governance, resolution and the identifier's own lifecycle remain with the parent and are not reproduced here.", "required": true, "source_refs": [ "SRC-044", "SRC-023" ] }, { "target": "Host entity, concept or record models adopting federated identity equivalence", "relation": "MIX-IN", "purpose": "Attach declared alias edges, context bindings and warrant to a host subject without altering the host's own identity scheme, attributes or lifecycle. The host remains the system of record for its subject; this mixin adds only equivalence assertions about it.", "required": true, "source_refs": [ "SRC-003", "SRC-025" ] }, { "target": "External OWL 2 and RDF entailment, reasoning and closure service", "relation": "REFERENCE", "purpose": "Carry the service reference and the binding parameters it needs, such as the entailment regime or profile, so that declared kinds can be evaluated externally. Reasoning, substitution of identicals, closure computation and materialisation of inferred edges are executed by the target and are never performed or stored here.", "required": false, "source_refs": [ "SRC-019", "SRC-044", "SRC-045" ] }, { "target": "Entity resolution and probabilistic record-linkage model", "relation": "REFERENCE", "purpose": "Carry the candidate-link identifier, justification type, score and estimation-method reference produced by the target. Blocking, comparison-vector construction, weight estimation, threshold selection and clerical review remain with the target and are not re-derived here.", "required": false, "source_refs": [ "SRC-012", "SRC-047" ] }, { "target": "Provenance and attribution model aligned to PROV-O", "relation": "REFERENCE", "purpose": "Reference agents, activities, derivations and generation times as the warrant for an assertion. The provenance model owns its own record lifecycle, graph semantics and bundle handling; only assertion-specific pointers are held locally.", "required": true, "source_refs": [ "SRC-009" ] }, { "target": "Constraint validation and reporting model aligned to SHACL", "relation": "REFERENCE", "purpose": "Bind shape and severity vocabulary and receive the report structure for declared-semantics results. Execution of validation, enforcement of outcomes, report persistence, retention and audit-trail semantics are owned by the target.", "required": false, "source_refs": [ "SRC-045" ] }, { "target": "Identifier redirect, succession and replacement handling model", "relation": "REFERENCE", "purpose": "Carry the declared relocation or succession kind and its explicit non-identity semantics so consumers do not over-read a permanent redirect or a replacement statement as entity identity. Resolution, redirect following and reference rewriting are executed by the target.", "required": false, "source_refs": [ "SRC-026", "SRC-023" ] }, { "target": "W3C OWL 2 identity vocabulary: owl:sameAs, owl:differentFrom, owl:equivalentClass", "relation": "ALIGN", "purpose": "Map catalogued kinds and non-equivalence declarations onto OWL 2 axioms, recording the licensed entailments and the applicability restriction to individuals, without claiming conformance to any OWL 2 profile absent published validation evidence.", "required": false, "source_refs": [ "SRC-001", "SRC-019", "SRC-042" ] }, { "target": "W3C SKOS mapping vocabulary: exactMatch, closeMatch, broadMatch, narrowMatch, relatedMatch", "relation": "ALIGN", "purpose": "Map catalogued kinds onto SKOS mapping properties, preserving the declared symmetry set, the inverse pairing of broad and narrow match, the transitivity of exact match only, and the disjointness of exact match with broad and related match.", "required": false, "source_refs": [ "SRC-003", "SRC-043" ] }, { "target": "schema.org sameAs property, vocabulary release v30.0", "relation": "ALIGN", "purpose": "Map the reference-page identity indication onto a catalogued kind with URL-valued objects and no declared algebraic properties, so publication-oriented sameAs values are never promoted to logical identity.", "required": false, "source_refs": [ "SRC-025", "SRC-046" ] }, { "target": "SSSOM Simple Standard for Sharing Ontological Mappings", "relation": "ALIGN", "purpose": "Field-level alignment for justification, confidence, mapping cardinality, subject and object source versions, negated-predicate modifier, author and tool, so mapping sets can be exchanged without reinterpreting predicate semantics.", "required": false, "source_refs": [ "SRC-034", "SRC-012" ] }, { "target": "WM-XCT-011 (registered parent model of WM-XCT-036)", "relation": "CHILD", "purpose": "WM-XCT-036 is registered as a child of WM-XCT-011 and inherits generic identifier and reference-binding semantics for its endpoints from it. What an endpoint identifier is, how it is minted and how a reference resolves stay in the parent; this model adds only the equivalence relation between two such references and the graph, traversal and cluster-view semantics over it.", "required": true, "source_refs": [ "SRC-002" ] }, { "target": "Adopting-Dimension entity-resolution and master-data policy model", "relation": "REFERENCE", "purpose": "Carry the reference, binding and subject-specific parameters for cluster calculation rules and canonical-representative selection: rule identifier, rule version, parameters, owning authority, scope and effective interval. That model owns matching, clustering, merge, representative selection, and its own lifecycle and operational functions; none of those are reproduced here.", "required": true, "source_refs": [ "SRC-050", "SRC-034" ] }, { "target": "External reasoning or entailment service (OWL 2 entailment regime)", "relation": "REFERENCE", "purpose": "Carry the reference to the service that would compute identity closure over these edges, along with the edge set, predicate profiles and policy bindings handed to it. Holding this reference grants no evaluation or execution semantics here: traversal returns candidate paths and never materialises an entailed identity assertion.", "required": false, "source_refs": [ "SRC-018", "SRC-045" ] }, { "target": "W3C OWL 2 individual equality and inequality vocabulary (owl:sameAs, owl:differentFrom, owl:AllDifferent)", "relation": "ALIGN", "purpose": "Classify alias and not-same edges against OWL 2 assertion semantics, including the absence of a unique name assumption, so that strength classes and contradiction conditions are anchored to a normative vocabulary. Recorded as an alignment only; no OWL conformance is claimed and no entailment is performed.", "required": false, "source_refs": [ "SRC-018" ] }, { "target": "W3C SKOS mapping property vocabulary (skos:exactMatch, skos:closeMatch, skos:broadMatch, skos:narrowMatch, skos:relatedMatch)", "relation": "ALIGN", "purpose": "Bind the per-predicate symmetry and transitivity profile and the traversal composition table to SKOS mapping properties and their integrity conditions, including the deliberate non-transitivity of closeMatch and the disjointness of exactMatch with broadMatch and relatedMatch.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "SSSOM mapping and mapping-set metadata", "relation": "ALIGN", "purpose": "Align edge-level justification, confidence, predicate modifier, tool and source fields, and mapping-set versioning, so that externally published mapping sets can be ingested as membership evidence without restating their model. SSSOM owns the mapping record vocabulary and its own versioning.", "required": false, "source_refs": [ "SRC-034" ] }, { "target": "W3C PROV-O provenance vocabulary", "relation": "ALIGN", "purpose": "Express path records, cluster snapshots and lineage events as derived entities with generating activities, attributed agents and generation instants, and express snapshot supersession as revision. PROV-O owns the general provenance model; only the bindings and subject-specific qualifiers are held here.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "ISO 25964-2 vocabulary interoperability mapping types", "relation": "ALIGN", "purpose": "Align the graded strength lattice with the exact, inexact and partial equivalence distinctions used for mappings between controlled vocabularies, so that thesaurus-derived edges keep their original precision when they enter the alias graph. Alignment is partial because only the freely published data model was consulted.", "required": false, "source_refs": [ "SRC-049" ] }, { "target": "Adopting-Dimension audit-trail and access-log model", "relation": "REFERENCE", "purpose": "Carry audit record references for traversal runs, snapshot registrations, lineage events and restricted-finding disclosures. That model owns audit capture, tamper-evidence, trail integrity, retention and replay; carrying the reference transfers none of those semantics here.", "required": true, "source_refs": [ "SRC-009" ] }, { "target": "Adopting-Dimension retention, disposition and privacy policy model", "relation": "REFERENCE", "purpose": "Carry retention class references and disposition outcome references for edges, path evidence reports, cluster snapshots and lineage records. That model owns the schedule, the legal basis and the execution of destruction or erasure; this model records the class, reports impact and writes the tombstone.", "required": true, "source_refs": [ "SRC-009" ] }, { "target": "Adopting-Dimension validation service (SHACL processor or equivalent runtime evaluator)", "relation": "REFERENCE", "purpose": "Reference the shapes, condition set version and severity vocabulary used to express integrity results, so that results here are interpretable against a shared validation model. The runtime evaluator and any enforcement action on a violation belong to that service; referencing it confers no evaluation or enforcement ownership here.", "required": false, "source_refs": [ "SRC-045" ] }, { "target": "WM-XCT-011 (registered parent model of the alias/same-as family)", "relation": "CHILD", "purpose": "Inherit the parent's subject framing and registry placement. The parent, not this model, defines the shared identifier-reference substrate; this model contributes the assertion-level status vocabulary, transition control and immutable history. The parent boundary is registry-declared and has no external primary description, so this link is recorded as a gap pending boundary review.", "required": true, "source_refs": [ "SRC-053" ] }, { "target": "Host entity, master-data or catalogue models carrying identifiers from multiple authorities", "relation": "MIX-IN", "purpose": "Attach assertion status and transition history to host subjects without importing host identity semantics. The host owns creation, merge, split and any other mutation of its records; this mixin only records what was asserted, by whom, on what basis and in which status.", "required": true, "source_refs": [ "SRC-053", "SRC-050" ] }, { "target": "Identifier and endpoint registration model (endpoint lifecycle, deprecation, redirect execution)", "relation": "REFERENCE", "purpose": "Carry endpoint references and the binding between an assertion and its endpoints, plus the assertion-side consequence of an upstream deprecation or replacement notice. Endpoint status, permanence rules and any resolution or redirect execution remain owned by the endpoint registry.", "required": true, "source_refs": [ "SRC-052", "SRC-056" ] }, { "target": "Entity-resolution and match-scoring model", "relation": "REFERENCE", "purpose": "Reference a match score or reconciliation result as evidence for a status decision, with the scoring method identifier. Similarity computation, thresholds, blocking and clustering remain owned by the resolution model.", "required": false, "source_refs": [ "SRC-050", "SRC-003" ] }, { "target": "Agent, role and authority registry", "relation": "REFERENCE", "purpose": "Resolve the deciding agent, its role at decision time and its mandate or delegation instrument. Agent lifecycle, credentialing and organisational structure remain with the registry.", "required": true, "source_refs": [ "SRC-009", "SRC-054" ] }, { "target": "Access-policy and authorization model", "relation": "REFERENCE", "purpose": "Cite the governing decision or access policy in the transition record so a reader can see under which rule the decision was framed. Evaluation of whether a principal may read or write, and any enforcement or access-audit record, remain wholly with that model.", "required": false, "source_refs": [ "SRC-055", "SRC-052" ] }, { "target": "Retention, disposition and privacy model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Carry the retention class and disposition authority references applicable to assertion records and tombstones. Scheduling, approval and physical execution of disposal or erasure are owned by that model; this model states only what must survive while a record is retained.", "required": true, "source_refs": [ "SRC-055", "SRC-056" ] }, { "target": "W3C PROV-O / PROV-DM provenance vocabulary", "relation": "ALIGN", "purpose": "Declared, non-conformant alignment: transition records map to activities with qualified attribution, reasons and event times; supersession maps to revision. Invalidation is deliberately not used for retraction, because PROV invalidation means the entity is no longer available for use while a retracted assertion must stay readable as a tombstone.", "required": false, "source_refs": [ "SRC-009", "SRC-032" ] }, { "target": "ISO/IEC 11179-6:2023 registration status framework", "relation": "ALIGN", "purpose": "Map local statuses onto registration-status categories - progression statuses versus terminal documentation statuses - and adopt the registration-authority view of who determines status. The mapping is partial: contested and withdrawn-authority states have no direct counterpart.", "required": false, "source_refs": [ "SRC-053" ] }, { "target": "SKOS mapping property vocabulary (exactMatch, closeMatch, related matches)", "relation": "ALIGN", "purpose": "Bind the asserted predicate strength to a standard mapping property so consumers can interpret how strong the claimed equivalence is. The status qualifies the assertion about the predicate; it does not redefine SKOS semantics or entail owl:sameAs.", "required": false, "source_refs": [ "SRC-003", "SRC-050" ] }, { "target": "Preservation description information practice (OAIS Provenance and Fixity)", "relation": "ALIGN", "purpose": "Align the transition history and integrity digests with preservation description information so that provenance, fixity and access-rights context travel with an exported assertion. Archival ingest, storage and preservation planning remain with the archive.", "required": false, "source_refs": [ "SRC-054", "SRC-055" ] }, { "target": "WM-XCT-011 (parent identifier and identity model)", "relation": "CHILD", "purpose": "Identifier syntax, namespace governance, authority delegation and persistence guarantees are defined by the parent; this mixin consumes governed identifiers as endpoints and adds equivalence assertion and resolution semantics only.", "required": true, "source_refs": [ "SRC-060", "SRC-063" ] }, { "target": "Host entity, agent, place or product models needing federated identity equivalence", "relation": "MIX-IN", "purpose": "Attach alias endpoints, assertion sets and as-of resolution behaviour to any host subject without duplicating its own identity or lifecycle model.", "required": false, "source_refs": [ "SRC-060", "SRC-001" ] }, { "target": "Relation reasoning and equivalence inference model", "relation": "REFERENCE", "purpose": "Carry the assertion, its authority and its confidence; delegate transitive, symmetric and reflexive closure, cluster formation and any entailment over equivalence to the reasoning model. OWL 2 places the formal consequences of SameIndividual in separate semantics documents, confirming the split.", "required": true, "source_refs": [ "SRC-001" ] }, { "target": "HTTP transport and dereference execution component", "relation": "REFERENCE", "purpose": "Reference observed relocation and hint responses as evidence while leaving request execution, redirect following, connection handling and endpoint availability entirely to the transport component.", "required": true, "source_refs": [ "SRC-023" ] }, { "target": "Adopting-Dimension access-control and authorization model", "relation": "REFERENCE", "purpose": "Declare visibility tiers and suppression fields on answers and containment records; evaluation and enforcement of any access decision remain with the authorization model.", "required": true, "source_refs": [ "SRC-056" ] }, { "target": "Master-data merge, survivorship and reconciliation model", "relation": "REFERENCE", "purpose": "Consume an externally decided merge or split as a change event that triggers re-evaluation of local assertions; record merging, survivorship rules and golden-record construction stay external.", "required": true, "source_refs": [ "SRC-063" ] }, { "target": "Notification delivery and subscription model", "relation": "REFERENCE", "purpose": "Hand prepared change notice and readiness content to the delivery model, which owns transport, subscription management, retry and receipting.", "required": false, "source_refs": [ "SRC-061" ] }, { "target": "Consumer audit trail and event log model", "relation": "REFERENCE", "purpose": "Point answers and containment records at downstream audit systems for evidentiary use; this model retains its own decision records but owns no audit-trail semantics for how answers were consumed.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "Memento time-based access framework (RFC 7089)", "relation": "ALIGN", "purpose": "Align as-of resolution and version pinning with datetime negotiation, TimeGate and TimeMap where an endpoint authority offers them; alignment only, no conformance claimed.", "required": false, "source_refs": [ "SRC-059" ] }, { "target": "IANA Link Relation Types registry (RFC 8288)", "relation": "ALIGN", "purpose": "Draw recognised hint relation types from the registry rather than minting local vocabulary, and record unregistered types explicitly as such.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "W3C PROV-O provenance vocabulary", "relation": "ALIGN", "purpose": "Express assertion, observation, answer and containment provenance using Entity, Activity, Agent, wasGeneratedBy, wasAttributedTo, wasRevisionOf and generatedAtTime; alignment only.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "ResourceSync Framework (ANSI/NISO Z39.99-2017) change documents", "relation": "ALIGN", "purpose": "Shape impact enumeration and change notice content as change lists with created, updated and deleted entries bounded by from and until instants.", "required": false, "source_refs": [ "SRC-061" ] }, { "target": "W3C DID Resolution v1 resolution metadata", "relation": "ALIGN", "purpose": "Align the closed resolution status vocabulary, versionTime and versionId options, and deactivated/canonicalId/equivalentId metadata with an existing resolver contract; the target specification is a Candidate Recommendation Draft, so alignment is provisional.", "required": false, "source_refs": [ "SRC-015" ] }, { "target": "WM-XCT-011 (parent identifier and reference model)", "relation": "CHILD", "purpose": "The endpoints of an equivalence are identifiers governed elsewhere; the parent model owns identifier structure, resolution and reference semantics, while this model adds only the equivalence assertion and its governance.", "required": true, "source_refs": [ "SRC-034", "SRC-003" ] }, { "target": "Authorization policy, decision and enforcement model (XACML / ABAC architecture)", "relation": "REFERENCE", "purpose": "This model supplies classification, purpose, tenant and disclosure-class attributes plus obligation references and names the decision point it relies on; evaluating a request, returning permit or deny, and enforcing the result remain entirely with that model.", "required": true, "source_refs": [ "SRC-067", "SRC-068" ] }, { "target": "Audit and event record model", "relation": "REFERENCE", "purpose": "Restricted disclosures, exception invocations, approvals and retractions carry an audit event reference; capture, protection, retention and interrogation of audit records are owned by the audit store.", "required": true, "source_refs": [ "SRC-069", "SRC-066" ] }, { "target": "Records retention and disposition model", "relation": "REFERENCE", "purpose": "Retention class, disposition authority citation and hold state are bound to this model's records; schedule approval, freeze administration, destruction, transfer and sanitisation are executed by the records authority.", "required": true, "source_refs": [ "SRC-055", "SRC-069" ] }, { "target": "Privacy, lawful basis and consent model", "relation": "REFERENCE", "purpose": "Purpose codes, special-category flags and lawful-basis references are carried locally so assertions can be scoped and suppressed; consent capture, impact assessment, records of processing and data subject request handling stay with the privacy model.", "required": true, "source_refs": [ "SRC-070", "SRC-071", "SRC-074" ] }, { "target": "Provenance model aligned to W3C PROV", "relation": "ALIGN", "purpose": "Attribution, delegation, role, revision and invalidation of assertions are expressed using PROV terms so that governance history is portable; this is an alignment and no conformance to PROV constraints is claimed without evidence.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "SSSOM mapping-set publication profile", "relation": "ALIGN", "purpose": "Role attributes map to author, creator, curator and reviewer slots and evidence maps to justification, curation rule and confidence so governed assertions can be exchanged as mapping sets; serialisation, propagation and chaining rules remain owned by that profile.", "required": false, "source_refs": [ "SRC-034", "SRC-012" ] }, { "target": "HL7 FHIR Person.link and Linkage assurance profile", "relation": "ALIGN", "purpose": "Relation strength tiers and assurance levels align to a published four-level assurance scale and to source, alternate and historical endpoint designation for healthcare interchange; no FHIR conformance is claimed.", "required": false, "source_refs": [ "SRC-064", "SRC-065", "SRC-075" ] }, { "target": "Subject entity, registry or catalogue model adopting cross-authority equivalence", "relation": "MIX-IN", "purpose": "The mixin attaches authority, approval, privacy and records controls to a host model's records without owning their identifiers, lifecycle or business semantics.", "required": true, "source_refs": [ "SRC-065", "SRC-034" ] }, { "target": "Selective disclosure and credential presentation model", "relation": "REFERENCE", "purpose": "Where a governed mapping is disclosed as a credential, this model states the disclosure class and handling obligations while presentation construction, proof formats and unlinkability guarantees belong to the credential model.", "required": false, "source_refs": [ "SRC-072" ] }, { "target": "WM-XCT-011 (parent cross-cutting model in the same registry cluster)", "relation": "CHILD", "purpose": "WM-XCT-036 specializes the parent's generic identifier-reference machinery for the single case of asserted equivalence between identifiers. Generic identity, authority and conflict machinery remains in the parent and is not restated here.", "required": true, "source_refs": [ "SRC-081", "SRC-034" ] }, { "target": "Host entity, registry or catalogue model in the adopting Dimension", "relation": "MIX-IN", "purpose": "As a mixin, the alias mapping attaches to any host subject that bears identifiers, supplying equivalence assertions without adding attributes to, or taking any position on, the host's own lifecycle.", "required": true, "source_refs": [ "SRC-081", "SRC-082" ] }, { "target": "SKOS Simple Knowledge Organization System mapping vocabulary", "relation": "ALIGN", "purpose": "Provides bound predicates for graded matches on export, together with the disjointness integrity conditions that constrain which bindings are legal. SKOS retains ownership of concept-scheme semantics; a SKOS match is never treated as individual identity.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "OWL 2 SameIndividual axiom and the owl:sameAs property", "relation": "ALIGN", "purpose": "Provides the strict-identity export binding and defines the entailment consequences that the export guards exist to control. Reasoning and closure are performed by the consuming system, not here.", "required": false, "source_refs": [ "SRC-076", "SRC-030" ] }, { "target": "SSSOM (Simple Standard for Sharing Ontological Mappings)", "relation": "ALIGN", "purpose": "Interchange profile for mapping sets: the irreducible record fields, set-level metadata, prefix map requirement, propagatable slots and record hashing procedure. Bound as an alignment for exchange; SSSOM's own tooling and governance remain external.", "required": false, "source_refs": [ "SRC-034", "SRC-087", "SRC-088" ] }, { "target": "W3C Controlled Identifiers alsoKnownAs property", "relation": "ALIGN", "purpose": "Binding for unverified, subject-level equivalence claims, carrying the standard's requirement that reciprocity be present before equivalence is assumed and that the assertion is not self-proving.", "required": false, "source_refs": [ "SRC-081" ] }, { "target": "PROV-O: The PROV Ontology", "relation": "ALIGN", "purpose": "Term binding for attributing an equivalence assertion to an agent and an activity and for recording generation time. Activity, agent and qualified-influence semantics stay with PROV-O; prov:alternateOf is explicitly not an alias predicate.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "Identifier scheme and resolution-service model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Supplies the identifier schemes and resolution endpoints this model references. WM-XCT-036 carries the scheme reference and redirect binding parameters only; endpoint identifier scheme design, minting and resolution execution stay with that model.", "required": true, "source_refs": [ "SRC-084", "SRC-023" ] }, { "target": "Access-control and policy-evaluation model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Supplies the access decision for alias records and artifacts. This model carries the policy reference and alias-specific binding parameters, such as the re-identification sensitivity rule; evaluation, decision and enforcement are performed entirely by the referenced model.", "required": true, "source_refs": [ "SRC-081", "SRC-082" ] }, { "target": "Audit and event-log model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Receives change and export events and returns an audit reference that this model stores. Audit-record lifecycle, immutability and retention execution belong to that model and are not reproduced here.", "required": true, "source_refs": [ "SRC-009", "SRC-082" ] }, { "target": "WM-XCT-011 (registered parent model of WM-XCT-036)", "relation": "CHILD", "purpose": "WM-XCT-036 is registered as a child of WM-XCT-011 and inherits the subject and identifier definitions it governs. This model contributes only equivalence assertions over those identifiers and the mutation-command surface that changes them; identifier minting, subject typing and register-wide governance remain with the parent.", "required": true, "source_refs": [ "SRC-090", "SRC-052" ] }, { "target": "Host entity, catalogue or registry model that carries the aliased endpoints", "relation": "MIX-IN", "purpose": "Attach the alias assertion and its command surface to a host subject record without altering the host's own identity or lifecycle, in the same way an also-known-as set attaches to a subject document and a mapping property attaches to a concept.", "required": true, "source_refs": [ "SRC-060", "SRC-003" ] }, { "target": "Adopting-Dimension authorization and policy-decision model", "relation": "REFERENCE", "purpose": "Carry the declared access scope, the actor reference and the deciding authority reference on the command envelope and the decision record. Evaluating whether an actor may issue a command, and enforcing that evaluation, belong entirely to the target.", "required": true, "source_refs": [ "SRC-072", "SRC-052" ] }, { "target": "Adopting-Dimension audit-trail model", "relation": "REFERENCE", "purpose": "Emit the correlation identifier, command identifier, idempotency key, fingerprint digest, actor reference and outcome code for every accepted, rejected and replayed command. Audit-record construction, tamper-evidence, retention and query are owned by the target; this model neither writes nor reads audit records.", "required": true, "source_refs": [ "SRC-009", "SRC-052" ] }, { "target": "W3C SKOS mapping properties (skos:exactMatch, skos:closeMatch, skos:relatedMatch, skos:broadMatch, skos:narrowMatch)", "relation": "ALIGN", "purpose": "Bind the declared relation property of an alias assertion to a governed external vocabulary term, and take the vocabulary's disjointness statements as the basis for the contradiction check. SKOS defines no mutation commands, so nothing of this model's command lifecycle is derived from it and no conformance is claimed.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "OWL 2 individual equality and difference (owl:sameAs, owl:differentFrom)", "relation": "ALIGN", "purpose": "Bind strong equivalence and explicit distinctness assertions to a governed logical vocabulary and take the absence of a unique name assumption as the reason distinctness must be asserted rather than inferred. Entailment and consistency checking are performed by an external reasoner, not here.", "required": false, "source_refs": [ "SRC-031" ] }, { "target": "Interface projection model for the alias register (HTTP or MCP binding)", "relation": "REFERENCE", "purpose": "Bind the model-level idempotency key and concurrency validator to concrete transport constructs and map outcome codes to transport status codes and failure documents. Transport execution, connection handling and retry scheduling are owned by the target.", "required": false, "source_refs": [ "SRC-023", "SRC-062", "SRC-089" ] }, { "target": "Adopting-Dimension retention, disposition and privacy model", "relation": "REFERENCE", "purpose": "Carry the retention-class reference, legal-hold reference and disposition-decision reference on terminal-state and evidence records. Retention scheduling, erasure execution and personal-data rectification duties are owned by the target; this model only appends tombstones and disposition references.", "required": true, "source_refs": [ "SRC-052", "SRC-009" ] }, { "target": "Status, revocation or resolution service for aliased endpoints", "relation": "REFERENCE", "purpose": "Expose the assertion's current lifecycle state and effective interval for consumption by resolvers and status checkers. Status checking, resolution, canonical redirect execution and endpoint merge are defined and performed by the target, consistent with credential status semantics being defined outside the data model that carries the status reference.", "required": false, "source_refs": [ "SRC-072", "SRC-060" ] }, { "target": "WM-XCT-011", "relation": "CHILD", "purpose": "WM-XCT-036 is registered beneath WM-XCT-011 and specialises it for asserted identifier equivalence and its query surface. Generic identity, authority and conflict machinery that the parent already carries is not restated here; only equivalence-specific relation semantics, traversal and comparison are modelled locally.", "required": true, "source_refs": [ "SRC-001", "SRC-030" ] }, { "target": "Identifier scheme and registry model for alias endpoints, designated by the adopting Dimension", "relation": "REFERENCE", "purpose": "Endpoints are carried by reference in the canonical form of their issuing authority. Minting, syntax, check characters, registry lifecycle and endpoint deletion belong to the identifier-scheme model; this model carries the reference, a resolvability flag and a staleness flag only.", "required": true, "source_refs": [ "SRC-014", "SRC-096" ] }, { "target": "Access-decision and enforcement service aligned to OASIS XACML 3.0", "relation": "REFERENCE", "purpose": "The query surface accepts an access scope and an external decision reference and reports suppression. Evaluation producing Permit, Deny, Indeterminate or NotApplicable, the discharge of obligations and all enforcement remain with the decision and enforcement points.", "required": true, "source_refs": [ "SRC-067", "SRC-023" ] }, { "target": "Provenance record service aligned to W3C PROV-O", "relation": "REFERENCE", "purpose": "Every returned edge carries references to attribution, generation and derivation records. Creating, storing, securing and retaining provenance records and the audit trail of queries belongs to that service; this model neither writes nor retains them.", "required": true, "source_refs": [ "SRC-009" ] }, { "target": "Versioned-state retrieval service aligned to RFC 7089 Memento", "relation": "REFERENCE", "purpose": "An as-of read may report a TimeGate or TimeMap reference for an endpoint's prior states and the interval a served state covers. Datetime negotiation, memento selection and redirect execution are performed by that service and never by this model.", "required": false, "source_refs": [ "SRC-059", "SRC-023" ] }, { "target": "Host entity models that adopt the alias mixin", "relation": "MIX-IN", "purpose": "The alias assertion structure and its query surface attach to host entity models. Host lifecycle, attributes, merge, survivorship and golden-record processing remain owned by the host model; adoption grants no right to rewrite host identifiers under equivalence.", "required": true, "source_refs": [ "SRC-030", "SRC-001" ] }, { "target": "W3C SKOS mapping relations (exactMatch, closeMatch, broadMatch, narrowMatch, relatedMatch)", "relation": "ALIGN", "purpose": "Supported relation kinds are aligned to SKOS mapping properties together with their declared transitivity, symmetry and disjointness, so that traversal rules are inherited per kind rather than assumed uniformly. This is an alignment for interoperability and not a conformance claim.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "W3C OWL 2 SameIndividual and DifferentIndividuals axioms", "relation": "ALIGN", "purpose": "Strict equivalence and explicit not-same relation kinds are aligned to OWL 2 assertions and to the absence of a unique name assumption. Entailment computation, closure and the regime-specific handling of inconsistency stay with the reasoning service.", "required": false, "source_refs": [ "SRC-001", "SRC-019", "SRC-091" ] }, { "target": "SPARQL 1.1 Service Description and Federated Query capability and failure semantics", "relation": "ALIGN", "purpose": "Capability declaration, dataset and graph scoping, scope precedence and remote-source failure semantics are aligned to SPARQL 1.1 so that an RDF projection is interoperable. The model does not require SPARQL as its interface and does not inherit its execution engine.", "required": false, "source_refs": [ "SRC-093", "SRC-092", "SRC-048", "SRC-094" ] }, { "target": "Assertion authoring and stewardship surface of WM-XCT-036", "relation": "COMPOSE", "purpose": "The query surface reads assertions that the authoring surface creates, retracts and supersedes, and refers contradicted paths and unresolved comparisons to stewardship. Authoring, retraction and stewardship decisions are never performed by a query function.", "required": true, "source_refs": [ "SRC-009", "SRC-072" ] }, { "target": "WM-XCT-011 (parent identification / identifier model)", "relation": "CHILD", "purpose": "WM-XCT-036 is registered as a child of the identification model. Reports cite identifier endpoints and asserting authorities as references only; identifier minting, scheme registration, syntax and resolution stay in the parent. Because OWL 2 makes no unique name assumption, the parent's distinct identifiers are neither same nor different by default, which is precisely why the equivalence and reporting surface is added here rather than there.", "required": true, "source_refs": [ "SRC-001", "SRC-027" ] }, { "target": "W3C PROV-O provenance and lineage model", "relation": "ALIGN", "purpose": "Report-instance provenance and impact lineage are expressed with derivation, revision, attribution and invalidation relations, and generation and invalidation times. The alignment is a vocabulary binding: PROV owns activity, agent and bundle record semantics, and a report instance is never presented as a provenance store or as an audit trail.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "Records retention, disposition authority and legal hold register model", "relation": "REFERENCE", "purpose": "Readiness reports carry retention rule references, hold and freeze citations and issuing-authority references. That model owns schedules, disposition authority, hold placement and release, and the execution of destruction, transfer and erasure; NARA practice shows holds are issued and released by an external authority and merely suspend the disposition cycle. This model reports readiness and hands off; it never executes.", "required": true, "source_refs": [ "SRC-055", "SRC-098", "SRC-101" ] }, { "target": "Notification delivery and subscription service", "relation": "REFERENCE", "purpose": "Change notice content produced here is handed to a service that owns inbox discovery, delivery, storage, receipt and escalation. Linked Data Notifications deliberately leaves the payload vocabulary open while fixing the sender, receiver and consumer roles, so carrying the payload confers no delivery semantics.", "required": false, "source_refs": [ "SRC-099", "SRC-100" ] }, { "target": "Shape and constraint validation service (validation-report producer)", "relation": "ALIGN", "purpose": "The conflict report borrows the validation-report shape - focus item, source constraint component, severity, message, detail nesting, and a conformance flag that separates no results from validated as correct - so consumers can read it with existing tooling. Referencing that shape grants no ownership of evaluation, execution or enforcement; the engine and its runtime remain external.", "required": false, "source_refs": [ "SRC-045", "SRC-097" ] }, { "target": "Data quality, confidence and assurance measurement model", "relation": "REFERENCE", "purpose": "Confidence-divergence conflicts and completeness qualifiers cite externally computed quality measurements and externally assigned identity assurance levels by reference. Metric definition and computation stay in the quality model; this model records the citation and never normalises differing scales into one number.", "required": false, "source_refs": [ "SRC-033", "SRC-039" ] }, { "target": "Audit and event-log model", "relation": "REFERENCE", "purpose": "Report issuance, reissue and release events are emitted for recording by the adopting Dimension's audit model. This model neither constructs, seals, stores nor attests an audit trail, and a report instance carries no tamper-evidence guarantee.", "required": false, "source_refs": [ "SRC-009", "SRC-055" ] }, { "target": "Subject entity models that adopt the alias mixin", "relation": "MIX-IN", "purpose": "The reporting surface attaches to any subject model whose records carry alias assertions across authorities, in the way that a patient record carries links to duplicate records of the same individual and a concept carries graded mapping relations to concepts in other schemes. The adopting model keeps its own identity, lifecycle and access rules unchanged.", "required": false, "source_refs": [ "SRC-027", "SRC-003" ] }, { "target": "WM-XCT-011 parent cross-cutting identity entry", "relation": "EXTEND", "purpose": "Specialise the parent identity surface with cross-authority equivalence assertions and their projection contract. Identifier minting, scheme syntax, authority registration and generic identity lifecycle machinery remain in the parent and are not restated here.", "required": true, "source_refs": [ "SRC-041", "SRC-003" ] }, { "target": "Host entity, event, resource or agent models that carry identifiers", "relation": "MIX-IN", "purpose": "Attach alias assertions and projection bindings to any identified subject without altering the host's own identity, attributes or lifecycle.", "required": false, "source_refs": [ "SRC-080", "SRC-025" ] }, { "target": "OWL 2 SameIndividual / owl:sameAs", "relation": "ALIGN", "purpose": "Strict-identity projection target, permitted only where the recorded strength is strict identity from a competent authority. Entailment, closure and consistency checking remain with the reasoner.", "required": false, "source_refs": [ "SRC-041" ] }, { "target": "SKOS mapping properties: exactMatch, closeMatch, broadMatch, relatedMatch", "relation": "ALIGN", "purpose": "Graded mapping targets for non-strict strengths, carrying the declared transitivity of exactMatch and the deliberate non-transitivity of closeMatch as constraints on projection.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "schema.org sameAs", "relation": "ALIGN", "purpose": "Weak reference-page projection target; emitted only with an explicit non-identity note because the property denotes a reference page indicating identity rather than an identity axiom.", "required": false, "source_refs": [ "SRC-025" ] }, { "target": "IANA canonical link relation (RFC 6596), Web Linking (RFC 8288) and HTTP redirection semantics (RFC 9110)", "relation": "ALIGN", "purpose": "Web-preference projection targets. This model calculates advisory redirect and canonical maps and carries their non-identity semantics; emitting responses, mutating endpoints and serving configuration remain with the infrastructure owner.", "required": false, "source_refs": [ "SRC-023", "SRC-024", "SRC-006" ] }, { "target": "RDF Dataset Canonicalization (RDFC-1.0) and JSON Canonicalization Scheme (RFC 8785)", "relation": "ALIGN", "purpose": "Deterministic serialization algorithms bound per target format so that projections are comparable, digestible and round-trip verifiable.", "required": true, "source_refs": [ "SRC-102", "SRC-077" ] }, { "target": "JSON-LD 1.1, W3C Model for Tabular Data, and JSON Schema draft 2020-12", "relation": "ALIGN", "purpose": "Linked-data, tabular and JSON-family projection targets, supplying identifier compaction, metadata description and dialect declaration mechanisms; their lossy-compaction and syntactic-indistinguishability limits are carried as declared loss.", "required": false, "source_refs": [ "SRC-080", "SRC-103", "SRC-108" ] }, { "target": "MCP resource interface (Model Context Protocol, resources)", "relation": "REFERENCE", "purpose": "Carries resource URI or template, name and mimeType binding parameters only. Server capability negotiation, subscriptions, list-changed notifications and resource lifecycle remain with the MCP server.", "required": false, "source_refs": [ "SRC-104" ] }, { "target": "MongoDB Extended JSON (v2) type system", "relation": "REFERENCE", "purpose": "Carries the canonical or relaxed mode selection and the resulting type-fidelity expectation for database projections. Collection layout, indexing, storage administration and deployment operation are not owned here.", "required": false, "source_refs": [ "SRC-105" ] }, { "target": "SHACL validation report vocabulary", "relation": "ALIGN", "purpose": "Supplies the report shape reused for projection conformance and loss reporting: a conformance verdict plus typed results with focus, path, source component and severity. Execution of a SHACL processor is not owned here.", "required": false, "source_refs": [ "SRC-045" ] }, { "target": "HTTP Digest Fields (RFC 9530) and PROV-O", "relation": "REFERENCE", "purpose": "Supplies the registered digest algorithms used as integrity qualifiers and the agent, activity and derivation terms stamped on each projection. Verification, signature policy and management of the wider provenance graph belong to their owning services.", "required": false, "source_refs": [ "SRC-106", "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension MUST name one accountable owner package for WM-XCT-036 and record it in the registry entry before any alias set is published; an alias set without a named owner package is a draft and MUST NOT be projected.", "The owner package MUST hold, or hold documented delegated write authority over, every namespace stem for which it publishes canonical-identifier or redirect claims. Stems under another authority are referenced only and MUST NOT be redefined, extended or redirected by this model.", "The owner package MUST publish and keep dereferenceable, for the declared support window, the canonical schema, the prefix map edition, the projection capability matrix, the predicate binding profile and the round-trip loss register that its alias sets pin.", "The owner package MUST NOT assume ownership of the referenced access-evaluation, enforcement or audit models. It records their references and the alias-specific binding parameters and nothing more.", "The owner package MUST designate the normative projection for each alias set and resolve divergence between projections as a defect rather than as a permitted variant." ], "namespace_guidance": "Use one stable namespace stem per owner package, chosen as a web address the package can write to. Prefer a slash namespace where individual alias records must be dereferenced separately and a hash namespace where the whole set is served as one document. Version identifiers, dates and edition serials belong in the document location and in metadata, never inside a term identifier: a term identifier that encodes its own version cannot survive the next version. Every compact identifier used in an alias set MUST expand unambiguously to a full IRI using only the prefix map bundled with or pinned by that set, with no external lookup. Prefixes bound to third-party stems are recorded with their controlling authority and are never re-pointed locally; a deprecated stem remains resolvable and is marked deprecated rather than removed.", "registry_links": [ "Registry entry vr.wm-xct-036 for model WM-XCT-036, navigation path NAV.XCT.ALS, domain tag XCT.ALS, parent WM-XCT-011.", "Owner-package namespace document served from the owned stem, carrying the prefix map and canonical schema references.", "External prefix and vocabulary registries referenced for third-party stems, recorded with their controlling authority and the retrieval time of the declaration used." ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonical form is computed on the format-neutral alias record, never on a projection. Set-level slots are propagated to each record first, slots are ordered by the canonical schema's declared slot order, multi-valued slots are sorted lexicographically, floating-point confidence values are truncated to at most three fractional digits with ties rounded away from zero, and the result is encoded as UTF-8.", "Graph projections are canonicalized to canonical N-Quads with deterministically assigned labels for unlabelled nodes before any digest, diff or signature is computed; two datasets yield the same canonical form if and only if they are isomorphic.", "The two canonicalization regimes are declared explicitly and are not interchangeable. Digests produced under the slot-record regime and under the graph regime are never compared with each other, and each published digest names the regime that produced it.", "The record identity field and any computed cardinality field are excluded from the canonical form, so that assigning or re-deriving an identifier never changes a digest and a digest can never be self-referential.", "Canonicalization MUST be independent of incidental serialization detail: key order in object serializations, anchors and aliases in indented serializations, column padding and quoting in tabular serializations, and line-ending convention." ], "patch_rules": [ "Every change between editions is expressed as an ordered patch document applied atomically: operations are applied in sequence and, if any operation fails, no operation is applied and the base edition is left untouched.", "Every patch MUST begin with a test operation asserting the base edition's recorded digest, so a patch cannot be silently applied to an unexpected base.", "A patch never rewrites a released edition. It produces a new edition with its own opaque serial, its own digest and a supersession pointer to the base.", "A patch that removes or renames a slot, re-binds a predicate to a different strength, narrows a prefix map, or changes a canonicalization step is a breaking change and MUST carry a major version increment and a migration note.", "A patch that changes the subject identifier, predicate, object identifier or asserting authority of an existing assertion is not permitted: the prior assertion is retracted and a new record is created with a supersession link." ], "compatibility_rules": [ "Alias-set schemas and profiles are versioned MAJOR.MINOR.PATCH: MAJOR for consumer-breaking changes, MINOR for backward-compatible additions, PATCH for backward-compatible corrections.", "Within a major line a consumer MUST ignore slots it does not recognise rather than fail, and MUST report the slots it discarded so that the round-trip loss register stays accurate; an unrecognised major version is the only version condition that justifies rejection.", "Once released, an edition's contents MUST NOT be modified. Corrections are issued as a new edition with a supersession pointer; the superseded edition and its digest remain retrievable for the declared support window.", "Deprecated prefixes, predicates, projections and identifiers remain resolvable for the declared support window and are marked deprecated rather than deleted, so that consumers holding earlier editions can still interpret them.", "A compatibility promise applies only to the format-neutral record and the normative projection; non-normative projections may change binding detail within a minor version provided every change is reflected in the loss register." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier: where the system of record for the alias record, alias set or artifact already assigns an identifier, that identifier is the artifact's identity and MUST be reused verbatim rather than re-minted.", "Governed global identifier or IRI: where no master-system identifier exists, assign a dereferenceable IRI from a namespace stem the owner package owns or is delegated, optionally expressed as a compact identifier that expands unambiguously against the pinned prefix map.", "Dimension-assigned UUID or ULID: only where neither of the above exists, mint a UUID or ULID assigned by the adopting Dimension, preferring a time-ordered UUID version where sortable keys are needed and an unpredictable version where the identifier must not be guessable, in the canonical hyphenated hexadecimal form.", "Never identity: dates, timestamps, version strings, edition serials, content digests, hash values, file names, directory paths, row numbers, document-store surrogate keys and projection-local primary keys are never artifact identity, in any projection. A projection that proposes one as a key is rejected as a defect." ], "timestamp_rule": "All date-times MUST be recorded as RFC 3339 date-times that include seconds and an explicit time-offset, either a numeric offset such as +02:00 or Z; fractional seconds are optional but the seconds field is never omitted, and a bare date is never a date-time. Event time — when the asserting authority made, amended or retracted the equivalence — MUST be recorded separately from observation time, when this model first saw the assertion, and from ingestion time, when the record was written into a projection; where the three differ, all three are stored, and no consumer may infer one from another. The -00:00 offset is used only to state that the instant is known in UTC while the local offset is unknown, and is never written as a synonym for Z. A date is never an identifier.", "serial_naming_rule": "Serially published artifacts — the loss register, prefix map, binding profile, change log, redirect rule set, conformance corpus, canonicalization profile and integrity manifest — carry an opaque, monotonically increasing edition sequence assigned by the owner package, for example edition-000417. The sequence is independent of event time, observation time, ingestion time and content digest. Sequence values MUST NOT encode a date or period, MUST NOT be reused after a retraction, MUST NOT be parsed for meaning by a consumer, and MUST NOT be treated as the artifact's identity: the artifact's governed IRI carries identity, the sequence carries order only, and the RFC 3339 timestamps carry time.", "integrity_rule": "Every published edition carries a digest computed over its canonical form, accompanied by the canonicalization regime, algorithm and encoding identifiers, and recorded in the integrity manifest for that edition. Digests verify integrity, detect drift and support signing; equal digests establish only that two records are highly likely to be identical in content, not that they are the same record. A digest MUST NOT be used as, promoted to, or derived into an artifact identifier, MUST NOT be compared across canonicalization regimes, and MUST NOT be treated as evidence of provenance on its own." }, "policies": [ "Format neutrality: no alias semantics may exist only inside a projection. Any feature discovered in one serialization but absent from the format-neutral record is either promoted into the record or removed; projections are distributions, never sources of truth.", "Declared loss before publication: a projection may be published only when every information loss, semantic weakening, unsupported relation kind and round-trip limitation it causes is already declared in the loss register, with detectability and compensating carrier stated. Undeclared loss blocks publication.", "No strengthening on export: an export MUST NOT make an assertion stronger than the record supports. A graded, low-confidence, unreciprocated or under-review alias is never emitted under a strict identity predicate; where the target vocabulary offers no sufficiently weak predicate, the alias is withheld and the withholding is recorded with its reason.", "Namespace authority: canonical-identifier and redirect claims are published only for namespace stems the owner package owns or is delegated. Claims touching third-party stems are recorded as references and never served as redirects.", "Reference-only boundary: where this model references an access-evaluation, enforcement, matching or audit model, it stores the reference and alias-specific binding parameters only. It MUST NOT implement policy evaluation, enforcement, matching execution or audit-trail retention, and MUST NOT be cited as the audit trail.", "Edition immutability: released editions, their digests and their manifests are immutable. Corrections are new editions with supersession pointers, and the superseded edition remains retrievable for the declared support window." ], "crud": { "read": [ "A read resolves the format-neutral alias record first and the requested projection second. A consumer reading only a projection MUST also read the prefix map edition and schema version that projection pins, otherwise identifiers cannot be expanded deterministically.", "Every read returns the edition serial, the canonicalization regime, the canonical digest and the declared schema version, so that a consumer can detect drift without re-fetching the whole set.", "Reads served through an MCP server, a document store, an HTTP API or a file tree MUST yield the same canonical form. A divergence is a defect raised against the loss register, never a permitted variant of the alias set.", "A read of a superseded, retracted or tombstoned record returns its status and its supersession or retraction pointer for the declared support window, rather than a bare not-found response, so that downstream caches and redirect projections can invalidate correctly.", "Reads of licence-restricted third-party mapping content are subject to the licence recorded on the alias set; the licence reference travels with every projection and every excerpt." ], "create": [ "Creation requires the irreducible fields of an equivalence record — subject identifier, predicate or strength, object identifier and a justification — together with the asserting authority. A record missing any of them MUST be rejected rather than stored as incomplete.", "Identity is assigned by walking the identity priority in order before any digest is computed, and the tier actually used is recorded with the reason any higher tier was unavailable.", "Every compact identifier in the new record MUST expand unambiguously against the pinned prefix map edition at creation time; an unresolvable or ambiguous prefix rejects the record.", "Assertion event time, observation time and ingestion time are set at creation as RFC 3339 date-times with seconds and an explicit offset, and are stored separately whenever they differ.", "A new record inherits the alias set's canonical schema version, prefix map pin and licence; it MUST NOT be created against a schema version the owner package has not published." ], "update": [ "Updates are applied as ordered, atomic patch documents whose first operation tests the base edition digest; a failed operation leaves the base edition untouched.", "A change to subject, predicate, object or asserting authority is not an update. The prior assertion is retracted with its retraction event time and reason, and a new record is created carrying a supersession link.", "Updates never mutate a released edition. They produce a new edition with its own opaque serial, its own digest and an appended change-log entry recording the compatibility verdict.", "Any update that changes a bound predicate, a prefix binding or a canonicalization step triggers regeneration of the affected projections, including redirect rule sets, and re-runs the round-trip verification for those projections.", "Every update emits a change event to the referenced audit model and stores the audit reference returned; the audit entry itself is owned, retained and protected by that model, not by this one." ], "delete": [ "Retention default: alias records are retired by tombstone, not erased. The record is marked retracted or withdrawn with its retraction event time, reason and superseding pointer, and its identifier is permanently retired and never reused for another record.", "A tombstone MUST remain readable for the declared support window so that downstream projections, caches and previously emitted redirect rule sets can be invalidated and regenerated; retirement is not complete until the affected redirect and export projections have been regenerated.", "Hard erasure is permitted only where an external obligation requires it, for example a lawful erasure demand or a withdrawal of licence to hold third-party mapping content. This model does not own or execute that decision: the adopting Dimension's retention-and-disposition policy, acting with the referenced access-control and records-management model, determines whether erasure is required and performs it. This model records only the disposition outcome, the authority reference that compelled it, and the resulting tombstone.", "Deleting a projection artifact never deletes the alias record it was derived from, and deleting an alias-set edition is prohibited while any published edition or manifest references it; such an edition is superseded and marked deprecated instead.", "Audit entries describing a deletion, and their own retention periods, are held by the referenced audit and event-log model and lie outside this model's retention control; this model retains only the audit reference." ] }, "roles": [ { "name": "Alias Model Owner (owner package)", "responsibilities": [ "Hold accountability for WM-XCT-036 in the adopting Dimension and keep the registry entry current.", "Publish and maintain the canonical schema, capability matrix, binding profile, prefix map and loss register for the declared support window.", "Approve or refuse bindings and projections that would export an assertion more strongly than the record supports." ] }, { "name": "Namespace and Prefix Steward", "responsibilities": [ "Maintain the namespace ownership declarations and evidence of write authority or delegation for every published stem.", "Publish prefix map editions, detect and resolve prefix collisions, and mark deprecated stems rather than removing them.", "Refuse any claim, redirect or canonical-identifier assertion targeting a stem the owner package does not control." ] }, { "name": "Projection and Interoperability Engineer", "responsibilities": [ "Implement and certify each declared projection against the capability matrix and keep the normative projection designation accurate.", "Run round-trip verification, maintain the conformance corpus and keep every loss, weakening and unsupported relation kind declared before publication.", "Emit redirect rule sets and companion metadata documents for execution by external services, without taking on request handling." ] }, { "name": "Schema and Release Manager", "responsibilities": [ "Version the canonical schema and profiles, classify each change as breaking or non-breaking, and enforce edition immutability.", "Compose patch documents with base-digest test operations and maintain the change log and integrity manifests.", "Manage deprecation and support windows so that consumers holding earlier editions can still interpret them." ] }, { "name": "Alias Curator and Authority Liaison", "responsibilities": [ "Record each equivalence assertion with its asserting authority, justification, confidence and validity, and keep reciprocity status current for third-party claims.", "Raise, triage and resolve conflicting or contested assertions and record retractions with reason and event time.", "Maintain the canonical-identifier selection for each equivalence cluster and trigger downstream regeneration when it changes." ] }, { "name": "Conformance Verifier", "responsibilities": [ "Verify canonical forms, digests and integrity manifests independently of the publishing pipeline and report drift as a defect.", "Audit that no artifact identity has been derived from a date, digest, filename or edition serial, and that all timestamps carry seconds and an explicit offset.", "Confirm that referenced evaluation, enforcement and audit models have not been reimplemented inside this model." ] } ], "access": { "default_rule": "Structure is readable, evidence is guarded. Bundle, layer and finding metadata for a published alias set default to the access class of the less restrictive of the two identifier namespaces involved, while artifacts and record-level evidence default to the access class of the more restrictive. Where the adopting Dimension has bound an access-evaluation model, that model's decision governs absolutely and this default applies only in its absence; this model carries the policy reference and the alias-specific binding parameters and never performs, caches or overrides an access decision.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "An alias linking a pseudonymous or indirect identifier to a directly identifying one is re-identifying by construction and MUST be classed at the higher sensitivity of the two, regardless of how open either identifier is on its own.", "Licence-restricted third-party mapping content may be exposed as aggregate counts while individual records remain restricted; the licence recorded on the alias set governs and its restriction travels with every projection and excerpt.", "Retracted, contested and withheld assertions remain visible to the conformance verifier and to the asserting authority even when withdrawn from general read, so that a retraction can be verified rather than merely trusted.", "An alias whose very existence is sensitive MUST NOT be bound to a redirect projection or any other publicly resolvable form, because a redirect discloses the association to anyone who can issue a request.", "Draft and unapproved bindings are readable only by the owner package and the projection engineer until approved, so that an unreviewed strengthening cannot be exported." ], "audit_requirements": [ "Every create, patch, retraction, binding approval, withholding decision and projection publication emits an event carrying the actor reference, the RFC 3339 event time with seconds and explicit offset, the edition serial, and the canonical digest before and after the change.", "Events are handed to the referenced audit and event-log model, which owns audit-record storage, immutability and retention. This model stores only the audit reference returned to it and MUST NOT be represented as the audit trail.", "Export decisions that applied a semantic downgrade, withheld an alias, or discarded unsupported or non-standard slots MUST be recorded against the loss-register entry they correspond to, so that the register remains an accurate account of what consumers actually received.", "Access decisions themselves are logged by the referenced access-evaluation model; this model records only that a decision reference was obtained, never the evaluation or its internal reasoning." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Registry ID vr.wm-xct-036 and Model ID WM-XCT-036", "Owner package and accountable contact", "Pinned canonical schema version, prefix map edition and normative projection" ], "read_order": [ "Read the AGENTS.md at the alias-set root first; in a nested tree the nearest AGENTS.md applies and takes precedence over ancestors.", "Confirm Name and Type identify this model as the Alias / Same-as Mapping mixin before interpreting any record as an equivalence assertion.", "Follow the Specification URL to the canonical model specification and pin the declared schema version; do not interpret records against an unpinned or unpublished version.", "Follow the Storage type URL to learn where records actually live and never assume local files: it names a Git-tracked file tree, an MCP server and its resource template, a document-store connection and collection descriptor, or an HTTP API base, together with the identifier used to address a record in that store.", "Follow the Interface URL for the read and patch operations, authentication binding, pagination and error contract of that storage type, including how to request the canonical form rather than a convenience projection.", "Follow the Processes URL for the create, update, retire and publish procedures, including the atomic patch rule with its base-digest test operation and the edition-immutability rule, before writing anything.", "Resolve the pinned prefix map edition, the projection capability matrix and the round-trip loss register before expanding any compact identifier or emitting any export, so that losses are known in advance rather than discovered afterwards." ] } }, "coverage": { "claim": "This audit examined WM-XCT-036's aggregate-root scope, entry-kind framing against both registry axes, ownership-boundary discipline, the empty relationship contract, retention and access design, and artifact-identity rules, and spot-checked bundle-count consistency (27/27 against provider_counts); it does not re-verify any live URL, does not independently recompute the full finding/question/function counts, and does not substitute for the still-pending formal boundary review.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "The assertion carries its own identifier in a namespace disjoint from both endpoints, with an explicit structural key for duplicate detection, and weak host-dependent addressability. Backed by RDF 1.2 triple-term and reification semantics, ConceptMap url plus identifier plus version, and the identifier-authority rule that identifiers are never reassigned." }, { "dimension": "lifecycle", "status": "covered", "notes": "All nine required statuses are defined with categories, consumption rules, entry and exit conditions, terminality and a governed transition matrix, plus explicit handling of forbidden attempts." }, { "dimension": "relationships", "status": "covered", "notes": "Per-kind directionality, symmetry, reflexivity, transitivity and invertibility are declared with four-valued states, and inverse kinds are named. Closure is never computed." }, { "dimension": "temporal", "status": "covered", "notes": "Event/validity time and observation/ingestion time are separate mandatory fields; as-of requests carry both; RFC 3339 with seconds and explicit offset is enforced, and -00:00 is preserved as unknown local offset. Memento supplies the as-of access pattern." }, { "dimension": "provenance", "status": "covered", "notes": "Five actor roles are kept distinct, bound to PROV agent types and qualified attribution, with source-system binding, derivation lineage, primary source and a provenance container for provenance-of-provenance." }, { "dimension": "ownership", "status": "covered", "notes": "Owner or steward, endpoint authorities, policy authority, privacy officer and records authority are separated with explicit scope expressions and exclusions." }, { "dimension": "validation", "status": "covered", "notes": "A versioned check catalogue with declared severity and applicability, and a per-run outcome report with focus element, path, value, source check and severity, plus a machine-readable failure projection with one entry per failed check." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default for evidence and reviewer material, grants expressed at bundle, layer, finding and artifact scope, least-privilege minimum grants, and named exceptions including emergency release; the decision itself is external by design." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Tombstone residue limited to non-identifying control metadata; retention rules, holds and execution owned by the referenced records model or adopting-Dimension policy; drafts discardable without tombstone; readiness statuses blocked, retained, externally governed and not assessed all bar disposition. Readiness is reported, never executed." }, { "dimension": "interoperability", "status": "covered", "notes": "Bindings to OWL 2, SKOS, schema.org, JSON-LD, CSVW, JSON Schema, YAML, MCP, MongoDB Extended JSON, RFC 6596 and RFC 9110 are recorded as versioned alignments, with each specification's own stated limits carried as declared loss." }, { "dimension": "cardinality and membership", "status": "covered", "notes": "One-to-one, one-to-many, many-to-one and many-to-many are declared explicitly with a combination rule and per-member ranks, following SSSOM mapping cardinality and ConceptMap group and element structure, so arity is never inferred from repeated rows." }, { "dimension": "conditional applicability", "status": "covered", "notes": "Attribute-value guards and produced attributes follow ConceptMap dependsOn and product, with attribute definitions referenced externally and evaluation delegated to a runtime evaluator." }, { "dimension": "negative and unknown assertions", "status": "covered", "notes": "Explicit not-same, unknown, unassessed and absent are four distinct recorded states, grounded in the absence of a unique-name assumption in OWL and in deployed negation mechanisms." }, { "dimension": "semantic strength and inference control", "status": "covered", "notes": "Ordinal strength rank plus an inference-permission flag, with a rule that a confidence value never upgrades a rank and that any permitted inference is executed by an externally owned regime." }, { "dimension": "confidence and calibration", "status": "covered", "notes": "Score, scale, thresholds and decision region are separated; calibration is asserted or explicitly denied; error rates carry uncertainty intervals; no cross-scale coercion is permitted." }, { "dimension": "evidence quality and contradiction", "status": "covered", "notes": "Positive, refuting and ambiguous items coexist with citation, digest, graded strength, freshness, retraction and declared absence; contradiction is retained rather than resolved by discarding." }, { "dimension": "fairness and subgroup bias", "status": "gap", "notes": "Disaggregated subgroup performance and the linked-versus-unlinked comparison method are grounded in Harron et al., but no primary source supplies normative disparity thresholds, protected-attribute governance or a required remediation path; this node is a supported gap rather than a canonical requirement." }, { "dimension": "contradiction and contagion", "status": "covered", "notes": "Difference axioms, negated predicates and standard disjointness are first-class declarations, and exposure indicators quantify how many sources and classes a strength-of-identity edge would draw together before a consumer accepts it." }, { "dimension": "normative conformance evidence", "status": "gap", "notes": "The model aligns to OWL 2, SKOS, SSSOM and schema.org but claims conformance to none of them. No published validation evidence for an OWL 2 profile or a SHACL shapes package was located during this research, so conformance would have to be demonstrated by the adopting Dimension before it is asserted." }, { "dimension": "traversal bounds and termination", "status": "covered", "notes": "Named policy versions fix allowed predicates, direction, maximum depth, maximum paths and time budget; repeated-node and duplicate-path handling follows SPARQL 1.1 connectivity matching; every run reports a termination reason and a non-exhaustive flag." }, { "dimension": "reproducibility of derived views", "status": "covered", "notes": "Snapshots require rule identifier, rule version, parameter set, input digest and snapshot instant, plus a reproducibility status flag; unreproducible snapshots are non-citable. The regeneration check itself is run by the calculation owner, which is a dependency this model reports on rather than controls." }, { "dimension": "canonical representative selection", "status": "gap", "notes": "No consulted standard defines how a representative is chosen within a set of co-denoting identifiers; OWL 2 and RDF 1.2 leave co-denoting IRIs equal in standing. The model therefore records only the reference to an external decision (authority, rule, version, scope, interval). The selection rule vocabulary itself is unsupported by primary sources and is deliberately not modelled here." }, { "dimension": "immutability and integrity", "status": "covered", "notes": "Append-only patch rules, canonical serialisation, chained digests, non-reused ordinals and appended annotation for every later intervention including redaction." }, { "dimension": "determinism and replay", "status": "covered", "notes": "Canonical candidate ordering, determinant input digest, rule-set version on every answer and an explicit replay function with a divergence verdict." }, { "dimension": "concurrency and idempotency", "status": "gap", "notes": "Optimistic preconditions and precondition-failure rejection rest on a full IETF standard, but the idempotency key plus fingerprint pattern rests on an expired Internet-Draft rather than a published standard. The structure is retained because the failure mode is real, and the node is marked as lacking settled normative support." }, { "dimension": "authority and delegation", "status": "covered", "notes": "Nine control roles with delegation instruments, scope expressions, expiry, re-attestation and forbidden role combinations, plus precedence and contest rules for competing authorities." }, { "dimension": "approval and exception", "status": "covered", "notes": "Approval tiers keyed to relation strength and evidence class with an explicit invariant that an exception can never strengthen relation semantics, assurance level or evidence class." }, { "dimension": "privacy and sensitivity", "status": "covered", "notes": "Personal data and special-category flags, confidentiality and sensitivity labels, pseudonymisation state, the emergent re-identification effect of linking, purpose limitation and tenant compartments." }, { "dimension": "semantic fidelity on export", "status": "covered", "notes": "No-strengthening policy, disjointness prohibitions from SKOS integrity conditions, closure licence declarations for each bound predicate, and reciprocity requirements before an incoming claim is treated as equivalence." }, { "dimension": "canonicalization and integrity", "status": "covered", "notes": "Two explicitly separate regimes — canonical N-Quads for graph projections and an ordered slot-record form for tabular and document projections — with digests never compared across regimes and never promoted to identity." }, { "dimension": "failure handling and compensation", "status": "covered", "notes": "Failure classification, retryability signalling, partial-failure detection and a derived compensating-record plan are defined; compensation is appended and applied by separate keyed commands, never executed as a rewrite." }, { "dimension": "entailment stance", "status": "covered", "notes": "Every answer echoes the regime applied and whether it was requested or default, labels each edge asserted or derived, forbids write-back of derived edges, and reports regime-specific inconsistency handling." }, { "dimension": "canonical selection", "status": "covered", "notes": "No function selects a canonical identifier. Authority-published canonical claims, including method-guaranteed ones, are carried as attributed claims with their declared guarantee level and an explicit not-applied marker." }, { "dimension": "conflict neutrality", "status": "covered", "notes": "Non-adjudication and minority-claim preservation are model policies, function effects, a dedicated finding, and canonicalization rules that keep any authority-weighted ordering as a labelled presentational view separate from the canonical order." }, { "dimension": "uncertainty and completeness", "status": "covered", "notes": "Coverage completeness, downstream reach completeness and residual uncertainty are required outputs. The rules that no conflict found is not confirmation of sameness, and that unenumerated reach is not absence of impact, are stated in policy and in function failure modes." }, { "dimension": "notification boundary", "status": "covered", "notes": "Notice content is produced and redacted here; inbox discovery, delivery, receipt, retry and escalation are external, following the sender/receiver/consumer separation and the deliberately open payload vocabulary of Linked Data Notifications." }, { "dimension": "round-trip fidelity", "status": "covered", "notes": "Four fidelity states, declared-versus-undeclared loss reconciliation against the loss report, and an explicit rule that round-trip never repairs or raises a relation's strength." }, { "dimension": "authenticity and signature", "status": "gap", "notes": "Content digests detect corruption but not authorship, and the specification cited says so explicitly. No signature suite, key management or trust-anchor profile has been selected for published projections, so authenticity is currently an unmet requirement rather than a solved one." }, { "dimension": "enforcement and audit trail", "status": "not-applicable", "notes": "Redirect execution, endpoint mutation, store administration and audit-record storage belong to the adopting Dimension and the owning infrastructure; this model supplies fields, recommendations and reasons only." } ], "known_omissions": [ "No definition of predicate vocabulary terms or their entailments; owl:sameAs, owl:differentFrom, the SKOS mapping properties and ConceptMap relationship codes are cited as external vocabularies and are not redefined, extended or reinterpreted here.", "No algorithm for selecting a preferred or canonical endpoint from an equivalence group; canonical selection is left to the endpoint authority, following the DID Resolution pattern in which the method specification, not a third-party claim, guarantees a canonical identifier.", "No modelling of link discovery, blocking keys, similarity functions or scoring thresholds; the model records the resulting justification locator and confidence but not the computation that produced them.", "No single mandated encoding for the assertion; reification with triple terms, named graphs, tabular mapping rows and link set documents are all treated as projections of the same semantics, and their trade-offs are not adjudicated.", "No treatment of commercial or contractual settlement for redistributing third-party mapping sets beyond a licence reference on the envelope and set descriptor.", "No cross-tenant reconciliation procedure for the case where two tenants hold contradictory assertions about the same pair under different purpose scopes; the conflict is representable but adjudication is delegated.", "No jurisdiction-specific legal constraints on linking natural-person records are modelled; the adopting Dimension must supply them through its data-protection policy.", "Bitemporal reconstruction beyond effective interval plus observation time is not modelled; a full valid-time and transaction-time bitemporal model is left to a sibling model.", "Confidence calibration is not defined: the model carries a value in the interval 0 to 1 and its justification category but does not standardise how scores from different matching engines compare.", "Multilingual and script-variant label equivalence is only recognised as a plane; the naming model owns transliteration, language tagging and preferred-label selection.", "Relation kinds for part-whole, version succession and broader or narrower mapping are deliberately excluded, since they are not sameness claims; consumers needing them should use the aligned SKOS hierarchical mappings or a version model.", "Group-level or bulk equivalence between whole datasets or schemes is not modelled; only pairwise assertions between two endpoints are in scope.", "No validated crosswalk exists between the score scales in play, and none is proposed here; a bounded confidence value, an unbounded likelihood weight and a four-point ordinal assurance level are stored side by side without conversion.", "Cluster-level and transitive-closure confidence is not modelled: how confidence propagates when three pairwise assertions imply a three-member equivalence class is left to the consuming system, and this is the most likely material omission.", "Incremental and streaming re-linkage, including how an assertion is revisited when a source record changes after the decision instant, is represented only as a revalidation point rather than as a process.", "Cost-sensitive threshold optimisation is recorded as declared parameters and an accepted residual error, not as an optimisation procedure or an objective function.", "The cryptanalytic risk model for privacy-preserving encodings such as Bloom-filter identifiers is out of scope; only the representation choice and its interpretability cost are recorded.", "Machine-learning training data governance, drift monitoring and model documentation for a referenced matcher are out of scope and are assumed to be owned by the engine's own model.", "Reciprocal and asymmetric assertions, where one authority asserts equivalence and the other has not been asked, are representable through the disagreement state but no dedicated non-response element is defined.", "The clause-level mapping typology of ISO 25964-2, covering exact, inexact, partial and compound equivalence, could not be verified from the standard text because the standard is paywalled; the catalogue therefore records no ISO 25964-2 alignment and a Dimension needing one must obtain the text and add it.", "Behaviour of owl:sameAs applied to classes or properties under the RDF-based (OWL Full) semantics is flagged as a regime change but is not modelled in detail; only the OWL 2 DL applicability restriction is declared.", "The choice between named-graph scoping and statement-level reifier annotation for context binding is deliberately left to the storage projection; RDF 1.2 is a Candidate Recommendation and its annotation mechanism may still change before Recommendation.", "Label-based, multilingual and transliteration-sensitive matching heuristics are excluded, as matching is owned by the entity resolution model.", "Bidirectional alignment to MADS and to ISO-style thesaurus data models is not covered, so vocabularies published only in those forms need an additional crosswalk.", "No fixed numeric thresholds, score scales or default confidence values are supplied, because every cited source treats these as method- and domain-specific.", "Cryptographic signing of assertions and of supersession records is not specified beyond the digest-based integrity rule.", "Signature and trust-anchor semantics for federated alias assertions: how a receiving Dimension verifies that an edge really was asserted by the named authority is not modelled, and no primary source was consulted for it.", "The vocabulary of representative-selection rules (source-priority, recency, completeness, jurisdiction) is deliberately absent because no consulted standard defines it; only the reference to an external decision is carried.", "Context-dependent or scoped identity — the position that two identifiers may be interchangeable for one purpose and not another — is acknowledged through the substitution-license element and referentially opaque contexts, but a full contextual-identity mechanism is not modelled and rests on secondary sources only.", "The schema.org sameAs property is widely used with a much weaker, page-reference meaning that conflicts with owl:sameAs; this was not verified against a primary source in this work and is recorded as a likely additional conflict rather than an established one.", "Concrete numeric defaults for maximum hop depth, path count and cluster review thresholds are left to the adopting Dimension; the consulted sources support the need for bounds but supply no normative values.", "Probabilistic or fuzzy equivalence models, and any calculus for combining confidence values along a chain, are excluded by the weakest-edge policy; alternatives exist in the literature and are not evaluated here.", "Streaming or incremental cluster maintenance is not modelled; only whole-snapshot registration and revision are covered, which may not suit very high-churn graphs.", "Cross-Dimension federation of the graph itself — how two adopting Dimensions exchange and reconcile their edge registers and policy profiles — is not modelled.", "The boundary of the registered parent model WM-XCT-011 could not be verified from any public source, so the CHILD link is declared as a gap pending boundary review; some identity-substrate concepts may belong there rather than here.", "No consulted primary standard defines a disputed status for identity assertions. The disputed state is supported by analogy from registration-status practice and by empirical evidence of contested sameAs links, and is marked as a structural gap rather than canonical.", "Quorum sizes, reviewer independence rules and escalation thresholds are left to the adopting Dimension; the consulted sources describe designated-expert review but do not fix quorum mechanics.", "Cryptographic notarisation, external timestamping authorities and countersignature of transition records are deliberately excluded; only a digest chain is required.", "No confidence or strength scale is prescribed for evidence or predicate strength, so cross-Dimension comparability of confidence values is not guaranteed.", "Machine-readable serialisations of the status vocabulary and transition matrix are required to exist but their concrete syntax is a projection decision, not fixed here.", "Bulk or federated propagation of a retraction to downstream caches is described only as a notification obligation; no delivery guarantee is defined.", "No cost or performance model for re-observation, so the staleness budget is declared without guidance on how to size it.", "Bulk or set-wise as-of resolution over large identifier populations is not modelled; only single-subject resolution semantics are specified.", "Cryptographic countersignature of assertions by both endpoint authorities is not modelled, although reciprocity is recorded; verifiable attestation would strengthen promotion but no settled cross-authority mechanism was identified.", "Partial or scoped equivalence (same subject in one context, distinct in another) is acknowledged only through direction and asserting authority; contextual scoping of equivalence is not developed here.", "No guidance is given on reconciling an endpoint authority whose own as-of answers change retroactively without notice.", "No normative numeric mapping from confidence score to approval tier; thresholds are declared locally and marked as a gap rather than presented as canonical.", "No treatment of bias, fairness or disparate error rates in probabilistic matching across population subgroups, which sits with the matching operator's model governance.", "No modelling of cross-border transfer mechanisms, adequacy decisions or standard contractual clauses that may constrain publishing an assertion outside a jurisdiction.", "No clause-level alignment to ISO 15489, ISO/IEC 27701 or ISO/IEC 24760, whose texts are paywalled and were not verified; the records and privacy grounding uses openly verifiable legislation and public-authority guidance instead.", "No sector-specific regulator or supervisory authority register, and no enumeration of jurisdictional protected-address or shielded-identity programmes.", "No specification of notification mechanics to prior recipients of a retracted assertion beyond the notice payload; the delivery channel is a projection concern.", "No probabilistic or fuzzy equivalence model: confidence is carried as an attributed value, and no aggregation, propagation or decay function over confidences is defined, because no primary source supports one.", "No cluster-closure algorithm: the model declares what closure each bound predicate licenses in a consuming system but does not specify how equivalence clusters are computed, split or merged, since that is matching-engine work held outside the boundary.", "No canonical-identifier selection policy beyond the requirement that a selection exist and be pinned; ranking sources to pick a preferred identifier is Dimension policy and varies by domain.", "No treatment of identifier equivalence for versions, editions or manifestations of a work, where alternation and specialization are distinct from identity; PROV-O's alternateOf and specializationOf are cited as the boundary marker rather than modelled.", "No signature or trust-chain model for signed alias sets; canonical form and digests are specified as prerequisites for signing, but key management and verification are external.", "No specification of endpoint identifier schemes, resolver query syntax or content-negotiation implementation, which belong to the referenced identifier-scheme and resolution model.", "No fixed support-window durations, deprecation periods or confidence thresholds; these are Dimension policy parameters and any number given here would be unsupported.", "No cross-register distributed transaction protocol. Compensation is defined within a single alias register; a command spanning two registers is out of scope and no two-phase commit or saga coordination is specified.", "No canonical confidence scale, no rule for comparing confidence values expressed on different scales, and no arithmetic for combining evidence into a confidence value.", "No bulk or batch command semantics beyond per-command idempotency: batch atomicity, partial batch acceptance and batch-level validators are not specified.", "The securing mechanism for decision assertions is referenced as an option but no signature suite, key management or proof format is selected.", "Machine-readable shapes for the check catalogue are referenced by identifier; the concrete shapes graph and its authoring rules belong to the adopting Dimension.", "Reciprocity handling is only partially specified: the practice of not treating an alias as equivalence unless the reverse assertion exists is recorded as a check, but no procedure is defined for soliciting or verifying the reciprocal assertion from the other endpoint's owner.", "No normative status enumeration is adopted from ISO/IEC 11179-6, since only its catalogue record was accessible; the lifecycle state codes here are model-specific and are not claimed to align with that standard's registration statuses.", "No normative standard defines a maximum-strength-loss budget for chained identity links. The parameter is grounded in the SKOS rationale for refusing transitivity to closeMatch and in the linked-data identity literature, not in a normative rule, and the composition arithmetic itself is left to a declared local method. This is the largest evidence gap in the structure.", "No widely adopted normative vocabulary exists for negative mapping assertions outside OWL 2 DifferentIndividuals; SKOS has no negative mapping relation. Contradiction reporting therefore rests on OWL 2 alignment plus local codes.", "Truncation, hop limits and continuation semantics for graph traversal are not normatively specified by SPARQL, which defines cycle-safe connectivity but not result-bounding. The continuation-token design borrows a registered link-relation pattern and is common practice rather than a requirement.", "Bitemporal as-of reads over assertion graphs have no single normative standard; the structure combines HTTP-level datetime negotiation, provenance generation and invalidation instants, and interval modelling from a specification that is still a Candidate Recommendation Draft.", "Confidence scales are not standardised and the vocabulary treating quality as an annotation is a non-normative Note, so confidence values from different authorities are explicitly not comparable without a declared method.", "Cost, latency, index design and caching of large traversals are excluded as projection concerns, even though they materially determine whether a hop limit is reachable in practice.", "Human stewardship of contradicted paths and unresolved comparison outcomes is referenced through a composition link but not modelled; it belongs to the adopting Dimension's process layer.", "Multilingual and transliterated label evidence often used to justify alias assertions is not modelled; only the evidence reference is carried, so label-level comparison is out of reach of this surface.", "No verified primary standard defines endpoint or cluster split. FHIR Patient.link covers directed supersession (replaced-by, replaces) and non-replacing reference (refer, seealso), but unmerge and split are under-specified in every source consulted; the split representation here, including per-member fate and undetermined assignments, is structurally reasoned rather than standards-derived and is marked a gap.", "Quantitative estimation of downstream reference reach for unenumerable consumers - cached copies, offline replicas, unindexed integrations - has no verified standard. The reach completeness qualifier records that the question was asked and answered honestly; it does not make the answer measurable.", "What constitutes disproportionate effort under the Article 19 notification obligation is not modelled. No threshold, cost basis or test is supplied, because none is defined in the verified source.", "Cryptographic signing, timestamping authority and non-repudiation of report instances are deferred entirely to an external attestation service. The integrity rule uses content digests, which detect corruption but do not establish authorship.", "Localisation and translation of conflict messages, status basis notes and notice content are out of scope; only the audience-scope redaction dimension is modelled.", "Cost, latency and scale characteristics of producing reports over very large federated assertion sets are not modelled; the frozen-snapshot requirement has real operational cost that this model states as a constraint without sizing.", "Human workflow for acting on a report - triage queues, assignment, escalation timers - is deliberately absent, because it belongs to whatever process model consumes the report.", "No profile is defined for RDF-star or RDF 1.2 triple terms, so qualifier attachment in RDF currently relies on named graphs or sidecar records, both of which are declared as cardinality or hidden-evidence loss.", "Signature and key-management profiles for published projections are unselected; only content digests are specified.", "Format coverage stops at the listed targets. Spreadsheet binary formats, Parquet and Arrow, GraphQL schema projections and SQL DDL views are not profiled and must not be projected until a profile exists.", "Streaming, incremental and delta projections are not modelled; every projection is treated as a complete snapshot of its declared scope, which makes large federated exports expensive.", "Internationalisation of literal qualifiers, specifically language tags and base direction, is only partially addressed through the tabular and linked-data alignments and has no dedicated loss-entry type.", "The registry records a parent entry but no relation rationales, so the composition targets listed here are proposed alignments awaiting registration rather than ratified contracts; the parent EXTEND link in particular should be treated as a gap until its rationale is recorded." ], "conflicts": [ "skos:exactMatch is symmetric and transitive but is explicitly a mapping property between concepts, not owl:sameAs, whose consequences propagate to every property of the individuals. Any single 'same-as' field that does not record which vocabulary is meant changes entailments when the data is consumed by a reasoner.", "skos:closeMatch is deliberately non-transitive to avoid compound error across chained mappings while skos:exactMatch is transitive. A model that stores one flat equivalence flag cannot preserve this distinction, which is why chaining is prohibited locally and the predicate term is always named.", "RDF 1.2 requires exact code-point comparison of IRIs with no normalization performed before comparison, whereas RFC 3986 and RFC 3987 define a graduated normalization ladder. Storing a normalized locator without recording the level applied makes it impossible to reproduce either behaviour, so the normalization level is a required part of the record rather than an implementation detail.", "The IANA Link Relation Types registry contains no 'same-as' relation. 'canonical' designates a preferred version of a resource, 'duplicate' designates byte-for-byte identical representations and 'alternate' designates a substitute; none of these is identity equivalence, so link-shaped projections must use extension relation URIs and must not borrow these tokens.", "SSSOM requires only predicate_id and mapping_justification, leaving subject_id and object_id optional, which permits records this model treats as incomplete envelopes. The divergence is recorded as an alignment note rather than reconciled, and importing such records produces envelopes in a quarantine or explicit-unknown state.", "DID Core states that the presence of an alsoKnownAs assertion does not prove it true and advises against treating identifiers as equivalent without a reciprocated inverse relationship, whereas DID Resolution requires a conforming method to guarantee that equivalentId and canonicalId are logically equivalent to the id. Structurally similar fields therefore span very different assurance levels, so assurance level is recorded explicitly on every assertion.", "The SSSOM authors acknowledge that mappings as standardised carry no context and are designed to be universally applicable, while ConceptMap scopes a mapping by purpose, jurisdiction and value set. This model follows the scoped reading and treats context-free mappings as under-specified, which is a deliberate divergence from the simpler profile.", "The token sameAs denotes materially different claims across sources: OWL 2 interprets it as identity of domain elements, while schema.org sameAs expects the URL of a reference web page that indicates the item's identity. Binding both to the same local kind would be an overclaim, so they are bound to different strength ranks.", "SKOS makes exactMatch transitive and symmetric yet explicitly separates it from owl:sameAs; consumers that chain exactMatch and then read the chain as identity produce unsound conclusions, so the model records exactMatch transitivity as scheme-scoped and prohibits promotion to strict identity without a separate assertion.", "RFC 6596 is Informational rather than standards-track and defines canonical as a preferred IRI for duplicative or superset content, whereas widespread practice reads rel=canonical as sameness of the referent. The model records the specification reading and flags the practice reading as a counterexample.", "HTTP permanent redirection tells clients which URI to use for future requests; it does not assert that two resources denote the same entity, yet redirect chains are commonly harvested as identity links.", "Web architecture advises against associating arbitrarily different URIs with the same resource, while Linked Data practice depends on cross-dataset aliasing; the model treats identifier alias as legitimate but scoped, rather than resolving the disagreement.", "The published SSSOM article documents match_type while the maintained specification uses mapping_justification and adds a predicate modifier for negation; version drift between the peer-reviewed article and the living specification means every binding must pin an edition.", "Wikidata's deployed said-to-be-the-same-as property is symmetric and hedged, which conflicts with the common assumption that any recorded sameness property licenses substitution.", "SKOS makes exactMatch transitive and closeMatch deliberately non-transitive to prevent compound errors across schemes, while OWL 2 SameIndividual licenses full substitution. Published linked datasets nonetheless routinely project probabilistic matches onto these predicates. This model records the conflict and constrains export rather than claiming the practice is safe.", "HL7 FHIR states that its four-level IdentityAssuranceLevel is based on NIST authentication levels, but NIST SP 800-63 revision 4 replaced a single level-of-assurance scale with separate identity, authenticator and federation assurance components. The FHIR note is stale relative to the current NIST model, so the two must not be treated as a crosswalk.", "DQV models quality as measurements over datasets, distributions, linksets and graphs. Attaching quality measurements to an individual mapping assertion is an extension of that pattern, not conformance to it, and is labelled as such.", "PROV provides no confidence construct at all. Confidence must be carried by a separate vocabulary and merely attributed through PROV, so any claim that a PROV graph alone conveys match certainty is unsupported.", "Statistics Canada requires secure storage with data destruction timetables for linkage-ready identifying files, which can conflict directly with retaining evidence exhibits long enough to reproduce a decision. The model records the conflict and escalates it rather than resolving it locally.", "SSSOM confidence is defined as a single value without a mandated semantics for what the number measures, so two producers can populate the same field with a calibrated posterior and an uncalibrated similarity score. This model requires an explicit scale and calibration statement, which is stricter than the source.", "SKOS deliberately avoids owl:sameAs between concepts, because merging concepts would conflict with SKOS constraints on preferred labels, yet linked-data practice frequently asserts owl:sameAs between concept IRIs. The model records the asserted kind and reports the practice conflict rather than normalising either side.", "schema.org documents sameAs as the URL of a reference web page that unambiguously indicates the item's identity, with expected type URL and no declared entailment, whereas it is widely consumed as if it were owl:sameAs. Treating it as logical identity is a common but unsupported promotion.", "SSSOM mapping cardinality values such as one-to-one are descriptive metadata about an observed mapping set, whereas FunctionalProperty, InverseFunctionalProperty and HasKey are axioms with real inferential force. Conflating the two is a recurring error, and HasKey additionally applies only to explicitly named individuals.", "HTTP 301 and 308 permanently relocate a resource and permit clients to rewrite references, which concerns resolution of a locator and is not an assertion that two described things are identical. dcterms:isReplacedBy is likewise directional succession, not identity.", "skos:exactMatch is declared transitive while skos:closeMatch is deliberately not, precisely so that similarity does not compound across schemes. Tools that chain match properties uniformly generate equivalences that no cited specification licenses.", "OWL 2 DL restricts SameIndividual to individuals; asserting owl:sameAs between classes moves an ontology into OWL 2 Full and changes the available reasoning guarantees, so the same surface syntax carries different force depending on regime.", "Probabilistic record linkage yields error-bounded statistical links whose quality depends on model assumptions and, in classical practice, on clerical review; a linkage posterior is a different quantity from a logical identity axiom and the two must not be stored under one predicate.", "SKOS makes skos:exactMatch transitive (S45) while explicitly refusing transitivity to skos:closeMatch to avoid compound errors across schemes; a single traversal cannot treat these predicates alike, so the composition table must be predicate-specific and closeMatch chains must be blocked rather than merely flagged.", "OWL 2 SameIndividual asserts full interchangeability, which is stronger than most published alias data actually warrants; Halpin and colleagues argue it is often too strong and that referentially opaque contexts exist. The model resolves this by graded strength classes and explicit substitution licensing, at the cost of not being directly OWL-conformant.", "SSSOM carries a numeric confidence per mapping, while OWL 2 identity is boolean and admits no degrees. Registering an SSSOM mapping as an alias edge therefore preserves confidence as reported evidence and never lets it be read as a partial owl:sameAs.", "The absence of an alias edge means nothing under OWL 2's lack of a unique name assumption, whereas practical systems often read absence as difference. The model forbids reporting absence of a path as a difference claim, which will disappoint consumers expecting a closed-world answer.", "RDF 1.2 Concepts is a Candidate Recommendation, not a Recommendation, at the time of writing; the triple-term and rdf:reifies mechanism used to justify edge-level annotation may still change, so the alignment is provisional.", "ISO 25964-2's exact/inexact/partial equivalence distinctions and SKOS's closeMatch/exactMatch pair are related but not formally reconciled by either source; the mapping between the two lattices is an assumption of this model, and incomparable pairs must be declared rather than silently ordered.", "PROV-DM states that after invalidation an entity is no longer available for use, whereas this model requires a retracted assertion to remain readable as a tombstone. Retraction is therefore aligned to a terminal status plus tombstone rather than to prov invalidation; the divergence is declared, not resolved.", "ISO/IEC 11179-6 registration statuses cover progression and terminal documentation states such as Candidate, Recorded, Retired and Superseded but provide no counterpart for disputed, retracted or authority-withdrawn assertions, so the alignment is explicitly partial.", "SKOS deliberately avoids owl:sameAs because it is too strict, while many federated deployments publish owl:sameAs for the same intent. A status vocabulary cannot repair that semantic difference, so predicate strength must be recorded independently of status.", "Registry practice discourages reclaiming registered values, while DataCite permits deleting a draft DOI before registration. This model resolves the tension narrowly: only a never-published, never-referenced candidate may be discarded, and the discard is itself recorded.", "Records-management disposal duties can require eventual destruction of records that this model would otherwise keep readable indefinitely; the retention and disposition owner prevails, and the tombstone minimum is asserted only for the retention period in force.", "Statutory erasure rights can conflict with the non-erasure of reviewer identities and reason texts; the model resolves this by redaction markers that preserve structure, which some regulators may still consider insufficient.", "RFC 6596 defines canonical as a preference over duplicative or superset content and RFC 8288 warns against inferring extra semantics from relation types, yet common practice treats a canonical link as an identity statement. This model follows the specifications and treats it as evidence only, which will disagree with tools that equate the two.", "DID Core advises against treating an alsoKnownAs relation as equivalence unless it is reciprocated, while much published linked data asserts one-directional same-as without reciprocity. This model records the asymmetry rather than resolving it.", "Memento leaves best-match selection to server discretion, so two authorities can return different states for the same requested datetime; this model pins and records what it received rather than asserting a single correct historical state.", "ROR does not require predecessor and successor relationships to be bidirectional, so a merge or split may be discoverable from only one side; enumeration of impacted references can therefore be incomplete through no fault of this model.", "The DID Resolution alignment is to a Candidate Recommendation Draft whose dereferencing section is marked at risk, so status-vocabulary alignment may need revision.", "RFC 3339 permits leap seconds while several storage and query stacks reject or smear them; the canonicalisation rule preserves what was received and the divergence is recorded rather than hidden.", "Graduated mapping properties are inconsistent on transitivity: exact match is transitive while close match is deliberately not, precisely to avoid compound errors when chaining across schemes. Approval rules that treat the two alike would propagate error, so chained assertions are capped rather than inheriting strength.", "Strict identity constructs are widely misused in practice according to survey literature, yet no standard defines the evidence required before asserting one. Tiering approval by relation strength is therefore a defensible governance decision, not a claim of conformance to any published rule.", "Four-level identity assurance codes describe confidence in an asserted identity and derive from authentication assurance work; using them as approval thresholds for equivalence assertions is an alignment, not an equivalence of semantics, and the mismatch is recorded rather than hidden.", "The mapping interchange standard makes author, reviewer, licence and confidence optional and requires only predicate and justification, so data can be fully conformant to it while lacking the authority evidence required here. This model applies a stricter local rule and does not describe such data as non-conformant to that standard.", "Storage limitation under data protection law can require earlier deletion than a records schedule's minimum retention permits; the adopting Dimension must record which instrument prevails, because neither cited source resolves the conflict.", "Records disposition authority as cited is a national federal construct; other Dimensions have differently named instruments and approval routes, so the citation is a reference pattern rather than a universal requirement.", "SKOS declares skos:exactMatch symmetric and transitive within its mapping vocabulary but does not entail OWL individual identity, while owl:sameAs licenses full substitution. Systems that treat exactMatch as sameAs create closure this model does not sanction; the binding is recorded as a downgrade, never as conformance.", "W3C Controlled Identifiers advises against treating alsoKnownAs as equivalence unless the relationship is reciprocated in the counterpart document, whereas an owl:sameAs assertion is unilateral and immediately entailment-bearing. One alias record cannot satisfy both readings, so reciprocity status is carried and the binding profile chooses per target vocabulary.", "SSSOM mandates support for only its tabular serialization and permits implementations that do not support non-standard slots to discard unknown keys and columns on read. That directly conflicts with any lossless round-trip expectation and is the reason the loss register is a publication gate rather than documentation.", "RDF Dataset Canonicalization is defined over RDF datasets and produces canonical N-Quads, while the SSSOM record hash is defined over a canonical S-expression of slots with a non-cryptographic 64-bit function. Two incompatible canonical and digest regimes therefore coexist, and their outputs are not comparable; the model declares both rather than over-claiming a single canonical form.", "Permanent redirects under HTTP semantics assert that a target resource has been assigned a new permanent URI, which is a stronger claim than a graded or provisional alias supports. Projecting a close match as a permanent redirect would publish an identity claim the record does not carry, so graded strengths are excluded from permanent redirects.", "The W3C vocabulary-publishing recipes advise placing version identifiers in vocabulary document filenames, while this model forbids filenames and version strings from acting as identity. The recipe is followed for document locations only; term and record identity is never derived from either.", "Published Linked Data shows systematic over-application of owl:sameAs where a weaker similarity was intended. This is a practice conflict rather than a specification conflict, and it is the empirical basis for the no-strengthening policy and the export guard.", "AGENTS.md has no versioned normative specification and defines no required fields of its own. The six mandatory orientation fields are a Vercy contract layered on a de facto community convention, and are presented as such rather than as conformance to an external standard.", "RFC 9457 recommends representing the single most relevant problem and discourages generic batch problem types, while the validation contract must report every failed check at once. This model resolves the tension by emitting one stable validation-failure problem type with an errors extension array carrying per-check pointers, following the specification's own validation-error example pattern. This is a documented accommodation, not a conformance claim.", "The Idempotency-Key HTTP Header Field specification is an expired IETF Internet-Draft (draft-07, 2025-10-15), not a standard. Its status choices for an in-flight duplicate and for key reuse with a differing payload are widely implemented but not normative, whereas RFC 9110 normatively assigns 412 to a failed precondition. Implementations therefore differ on whether a reused key with a changed payload is a 409 or a 422, and this model keeps its own outcome codes primary with transport mapping declared by the interface projection.", "SKOS makes exactMatch symmetric and transitive and asserts disjointness with broadMatch and relatedMatch, while OWL sameAs carries full substitution semantics under no unique name assumption. The two are not interchangeable: recording an assertion bound to a SKOS mapping property does not license OWL-strength substitution, and this model computes neither closure. A consumer that treats them as equivalent will over-infer.", "DID Core advises that alias assertions should not be treated as equivalence unless reciprocated, whereas a great deal of federated practice treats a single-direction same-as assertion as sufficient. This model records direction and reciprocity explicitly and makes reciprocity a declared check rather than an assumption, which is stricter than common practice.", "Registry practice retains entries permanently for historic purposes, while privacy regimes may compel erasure of records containing personal data. The model resolves this by separating the tombstone, which is always retained here, from the payload, whose erasure is executed by the referenced retention and privacy models — but the two obligations remain in genuine tension and the adopting Dimension must decide the boundary.", "OWL 2 equality licenses substitution and full transitive closure, while SKOS deliberately makes closeMatch non-transitive to prevent compound errors across chained schemes. A path mixing these kinds cannot inherit one closure rule, so the model requires per-kind declaration and forbids uniform closure.", "Decentralized identifier methods supply a method-guaranteed canonical identifier and recommend its use, whereas this model forbids canonical selection. The conflict is resolved by carrying such a value as an attributed claim of the publishing authority with its guarantee level, never as the query surface's choice.", "An also-known-as style claim and an OWL 2 equality assertion look interchangeable but differ sharply in strength: the former is explicitly not to be treated as equivalence absent a reciprocated inverse and out-of-method verification. Collapsing both onto one relation kind would be a semantic error and is prohibited.", "The federated-query SILENT modifier turns a source failure into a single empty solution that is indistinguishable from nothing asserted at the solution level. The model therefore requires the failure mode to be recorded in the disclosure statement and treats any silenced result as incomplete.", "Entailment regimes disagree on inconsistency: an inconsistent OWL 2 DL ontology must raise an error, while under RDF-based semantics a system may merely warn. Identical alias data can therefore yield an error or an answer, so the regime must be echoed with every result.", "HTTP permits a server to return not-found in order to conceal a forbidden resource, which conflicts with the requirement to distinguish nothing asserted from withheld. The model resolves this by carrying the suppression signal inside an authorised channel while permitting existence-concealing behaviour at the transport projection.", "Authority-published mapping files are refreshed on cadences ranging from daily to monthly, so a current read and an as-of read can disagree purely because of ingestion lag; the model therefore requires observation time and refresh cadence rather than treating a current read as authoritative.", "SKOS declares exactMatch transitive but deliberately declines to declare closeMatch transitive, precisely to avoid compound errors when chaining mappings across more than two schemes, while OWL 2 SameIndividual is strict identity and PROV-O alternateOf is weaker still. Treating these as one same-as strength produces chains that no source endorses; reports must therefore cite the strength vocabulary and version each participant used, and the model refuses to normalise across them.", "FHIR Person.link.assurance is an ordinal four-level scale (level1 probabilistic through level4 highest) with no defined probability semantics, whereas DQV measurements are numeric values of a declared metric. The two cannot be arithmetically combined or ranked against each other, so a confidence-divergence conflict reports both by reference and computes no unified score.", "SHACL severity has three levels (Violation, Warning, Info) while FHIR OperationOutcome has five (fatal, error, warning, information, success). There is no lossless mapping in either direction, so severity vocabularies are declared per report rather than assumed, and any consumer-side mapping must be recorded.", "Records-management practice suspends disposition indefinitely under a hold until the issuing authority formally releases it, whereas the Article 19 obligation pushes toward prompt communication of erasure or restriction to recipients. These can pull in opposite directions for the same record: this model reports both the block and the notification-content obligation and adjudicates neither, leaving the tension visible to the accountable authorities.", "OWL 2 has no unique name assumption, so the absence of a not-same constraint carries no information about difference and the absence of a conflict carries no information about sameness. Any consumer treating a clean conflict report as confirmation of identity is misreading it; this is stated in policy and in the conflict function's failure modes rather than left implicit.", "DQV is a W3C Working Group Note whose publication explicitly does not imply W3C endorsement, so alignment to it is non-normative and is recorded as an alignment only, never as conformance.", "Patient.link is a modifier element in FHIR, meaning the link type changes how the whole record is interpreted, whereas SKOS mapping properties are additive annotations that change nothing about the concept. A report that mixes both kinds of link must not present them as the same sort of statement.", "skos:exactMatch is declared transitive while skos:closeMatch is deliberately non-transitive to stop errors compounding. Projecting a chain of close matches into exactMatch would silently manufacture transitivity the source never asserted, so this pairing is a forbidden mapping.", "schema.org defines sameAs as the URL of a reference web page that unambiguously indicates the item's identity, not as an identity axiom, yet consumers routinely treat it as owl:sameAs. Projections to it must therefore carry an explicit non-identity note.", "RFC 9110 treats 301 and 308 as assigning a new permanent URI while 303 explicitly redirects to a different resource. Tools that harvest redirects as equivalence conflate these, so redirect observation is never accepted as evidence of identity here.", "RFC 6596 permits the canonical target to be a superset of the context IRI's content, making the relation asymmetric. It therefore cannot be projected back as a bidirectional alias, which conflicts with common site-migration practice.", "MongoDB relaxed Extended JSON collapses Int32, Int64 and Double distinctions that canonical mode preserves. A relaxed export cannot be round-trip verified at type level and must declare that loss explicitly.", "YAML anchors and aliases denote node identity within one serialization and are discarded on composition, yet naive exporters emit them as if they expressed sameness; the canonicalization rules suppress them for this reason.", "JSON-LD compaction is acknowledged as lossy by its own specification, so a compacted linked-data projection cannot be claimed round-trippable without also publishing the context that governed it." ], "regional_assumptions": [ "Jurisdiction is modelled as a declared code list on the envelope and no specific legal regime is assumed. Where endpoints identify natural persons, a GDPR-style purpose-limitation reading is taken as the stricter default for the access exception, and adopting Dimensions under other regimes may relax it by explicit declaration.", "Erasure and legal-hold semantics vary by regime; the model records a retention class and disposition decision reference and leaves execution to the adopting Dimension, so a jurisdiction requiring full erasure rather than tombstoning must be handled by that policy, not by this model.", "Healthcare-facing alignment assumes HL7 FHIR R5 terminology practice, which is normative in that sector but is not a general-purpose assumption outside it.", "Language, script and bidirectional handling of display labels follows IRI internationalization guidance; locale-specific collation, transliteration equivalence and script-variant matching are not assumed and are not treated as evidence of sameness.", "Identifier-authority guidance drawn from life-science practice generalises well on non-reuse and tombstoning, but its prefix-registry assumptions may not hold in sectors without a shared prefix registry, in which case the Dimension's own binding map is the sole authority.", "Endpoint references are assumed to be resolvable within the adopting Dimension's federation; no assumption is made that they resolve on the public web.", "No assumption is made that a national or sectoral identifier authority exists for any given subject; where none exists, the governed-IRI and UUID or ULID fallbacks in the identity priority apply.", "Legal restrictions on cross-register linking of person records vary by jurisdiction and are treated as an adopting-Dimension input rather than as a modelled constraint.", "Language and script handling for the name or label alias plane assumes the adopting Dimension's naming model supplies language tags; no default language is assumed.", "Normalization, comparison and blocking practice in the cited public-authority and epidemiological literature is validated predominantly on Latin-script, Western naming conventions. Transliteration, diacritics, patronymics, name order and multi-part family names change error rates materially, and evaluation results are not assumed transferable across scripts.", "The legal basis for holding identifying evidence, the permitted retention period and the requirement for human intervention in automated decisions differ by jurisdiction. Those are referenced as policy inputs through sensitivity classification and jurisdiction of origin; no jurisdiction's rules are embedded as defaults.", "NIST SP 800-63A-4 is United States federal guidance and Statistics Canada's process model is Canadian public-sector practice. Both are used as evidence of defensible practice, not as globally binding requirements.", "The FHIR assurance scale reflects healthcare identity-matching practice and is not assumed appropriate for non-healthcare subject domains without local validation.", "Subgroup performance disaggregation presumes that subgroup attributes are lawfully available for evaluation, which is not the case in every jurisdiction; where they are unavailable, the model requires the limitation to be declared rather than the evaluation to be silently skipped.", "Jurisdiction codes and territorial scope values are supplied by the adopting Dimension; no particular national, supranational or industry code list is assumed or mandated.", "Data-protection constraints on linking a pseudonymous identifier to a directly identifying identifier are assumed to exist in most jurisdictions, but their content varies and is referenced through a purpose grant rather than encoded in the model.", "Language, script and transliteration of any labels used as matching evidence are recorded but no locale-specific normalisation is mandated, since normalisation rules differ by script and by domain.", "Legal effect of a supersession or retraction, including whether a superseded equivalence must be actively unwound in downstream systems, is jurisdiction- and contract-specific and is left to the adopting Dimension.", "Calendar and offset handling assumes RFC 3339 semantics only; no assumption is made about local civil-time rules, and -00:00 is preserved to signal an unknown local offset.", "Retention periods, lawful-basis requirements and erasure obligations for records that link personal identifiers vary by jurisdiction; the model carries a retention class reference and an impact report but assumes the adopting Dimension's retention and privacy models supply the jurisdiction-specific schedule and execute it.", "The scope descriptor on a representative decision is expected to carry jurisdictional scope where a regulator mandates a particular identifier for a particular territory; the model permits concurrent scope-specific representatives rather than assuming one global canonical identifier.", "Sources consulted are English-language W3C, IETF, ISO/NISO and open scientific material; sector- or nation-specific identity-equivalence rules (for example national registry crosswalk mandates) were not surveyed and may impose stricter constraints.", "The assumption that endpoint identifiers are IRIs or otherwise globally scoped holds for linked-data and registry federations; deployments federating opaque local keys must first bind them to a governed namespace via the parent model before this mixin applies.", "The NARA universal electronic records management requirements are United States federal guidance; other jurisdictions impose different schedules, approval authorities and transfer duties, and the retention statements here must be re-derived locally.", "European data-protection erasure and objection rights are assumed to be capable of forcing redaction of person-identifying fields inside otherwise immutable records; the redaction-marker mechanism is the assumed accommodation and has not been tested against a specific supervisory decision.", "Persistent-identifier practice is drawn from the scholarly DOI ecosystem; sectors using other identifier schemes may permit deletion or reassignment, which would break the tombstone guarantee and must be declared by the adopting Dimension.", "Offsets are assumed to be recordable at source; where a legacy system supplies local time without an offset, the adopting Dimension must supply and record the offset determination rule rather than assuming UTC.", "Timestamps are assumed to be recorded with an explicit UTC offset regardless of jurisdiction; deployments relying on local civil time without an offset must convert before ingestion and record -00:00 where the original offset is genuinely unknown.", "Legal erasure obligations differ by jurisdiction; the model assumes the adopting Dimension holds a policy that names which obligation applies and executes it, and it makes no assumption that erasure is or is not required.", "Identifier authorities cited here are internationally scoped research and web registries; national identifier registers may forbid retaining a withdrawn identifier at all, which would conflict with the retain-and-tombstone default and requires a Dimension-level exception.", "Evidence capture of published representations may be constrained by copyright or database rights that vary by jurisdiction; the model assumes digests and provenance may always be retained even where the payload cannot.", "Data protection framing follows the EU and UK General Data Protection Regulation articles cited; other regimes differ materially on special-category definitions, erasure rights and lawful bases, and an adopting Dimension must substitute its own.", "Records retention framing follows US federal electronic records management practice as the reference regime; the disposition authority, freeze and transfer constructs must be re-bound to the local records authority elsewhere.", "Confidentiality, sensitivity, compartment, purpose-of-use and assurance code systems originate in healthcare interoperability; their use outside healthcare is an alignment that requires a locally governed value set.", "Protected-address, shielded-identity and comparable programmes vary by jurisdiction and are referenced abstractly through a protected-location flag and disclosable granularity rather than enumerated.", "Tenant isolation assumes a single adopting Dimension can name its tenants authoritatively; federated deployments spanning several Dimensions need an agreed tenant register that this model does not define.", "Erasure and disposition obligations vary by jurisdiction. This model encodes no jurisdiction's rule and assumes the adopting Dimension supplies the applicable retention-and-disposition policy and executes it through the referenced access and records-management model.", "Licence terms attached to third-party mapping sets are publisher- and jurisdiction-specific. The licence reference is carried with every projection and excerpt but is never interpreted, enforced or summarised by this model.", "Timestamps assume the proleptic Gregorian calendar and UTC-relative offsets as used by RFC 3339. Where a source authority records assertion times in another civil calendar, the value is converted before storage and the original calendar designation, if needed, is carried as a separate annotation rather than encoded in the timestamp.", "Character encoding is assumed to be UTF-8 throughout, which the canonicalization rules require. Identifier schemes using non-Unicode-normalizable forms are outside the tested surface.", "Language, script and transliteration variants of a label are not aliases in this model. Where a Dimension treats a transliterated identifier as the same identifier, that equivalence must be asserted explicitly as a record, not inferred from string similarity.", "Time values follow RFC 3339 with explicit offsets; no jurisdiction-specific business calendar, working-day arithmetic or local civil-time interpretation is assumed for effective intervals, and any such interpretation must be declared by the adopting Dimension.", "Where alias assertions link identifiers of natural persons, jurisdictions with rectification and erasure duties (for example EU or UK data-protection regimes) may require the referenced privacy model to erase evidence payloads while this model retains only the tombstone; jurisdictions without such duties may retain complete history including payloads.", "Legal hold, records-retention schedules and the admissibility requirements for decision records are jurisdiction-specific and are owned by the adopting Dimension; this model carries only the references.", "Authority precedence between competing asserting authorities is assumed to be declared locally; no cross-border or cross-sector precedence order is asserted here.", "No assumption is made that the register and its referenced authorization, audit and retention models are operated in the same jurisdiction or under the same data-residency constraints.", "Instants are assumed to be RFC 3339 with explicit offsets and a stated temporal reference system; non-Gregorian and ordinal reference systems are supported only by declaring the system explicitly.", "Erasure obligations such as statutory rights of deletion are assumed to be executed by the adopting Dimension's retention policy and by the authority holding the assertion; this model carries only a disposition reference and encodes no jurisdiction-specific rule.", "Cross-border restrictions on evidence disclosure are assumed to be expressed as access-scope attributes evaluated by an external decision point, so no regional policy is embedded in the query surface.", "Named registries and identifier systems are illustrative of authority-published mappings and are not assumed to exist or be reachable in every adopting Dimension.", "Language, script and transliteration conventions of endpoint identifiers are assumed to be governed by the issuing authority; the model compares identifiers as opaque strings and applies no locale-sensitive normalisation.", "Article 19 of Regulation (EU) 2016/679 was verified through the legislation.gov.uk rendering of the assimilated text; the EU-official text at EUR-Lex was not reachable during this research, so the source is recorded at authority tier 2 and the quoted obligation should be re-verified against the Official Journal text before any conformance claim.", "Disposition and hold practice is verified only for United States federal records through NARA's Universal ERM Requirements and the Federal Records Centers freeze process, which distinguish an agency-issued litigation hold from a NARA freeze over records in Federal Records Center custody. Other jurisdictions place, scope and release holds differently, and the readiness status set is parameterised by jurisdiction for that reason.", "FHIR identity assurance levels reflect healthcare identity practice, where level3 is exemplified by government-issued photo identification. They are not a general-purpose confidence scale and should not be reused outside that framing without local calibration.", "No single jurisdiction is assumed to govern all endpoints in a federated alias set. Each participating authority may sit under a different regime, which is why externally governed is a first-class readiness status rather than an error condition.", "Only English-language primary sources were consulted; national records or identity-matching standards published in other languages may define conflict or disposition classes not represented here.", "No jurisdiction-specific rules are assumed. Where an identifier is personal data, the adopting Dimension's applicable data-protection regime governs whether it may appear in any public projection at all, and that decision precedes every rule stated here.", "Public web projections assume the adopting Dimension controls the origin serving the context IRI. Where it does not, redirect and canonical output is a recommendation to a third party with no expectation of adoption.", "UTF-8 is assumed throughout. Legacy regional encodings in CSV or Git-tracked files require an explicit transcoding step that must be declared as an identifier conversion and a fidelity loss.", "Calendar and numeric formatting in human-readable projections follows the target profile, not a locale default; no regional formatting is inferred from the consumer's location." ], "adversarial_checks": [ "Tested whether this model should own an endpoint resolution or dereference function. Rejected: RFC 3986 states that a URI provides identification only and that access is neither guaranteed nor implied, and resolution execution belongs to the referenced reference and resolution model. The model therefore records externally produced resolution observations with their observation times and performs no dereference, redirect or repair.", "Tested whether a transitive-closure or 'merge equivalent identifiers' function could be justified locally. Rejected on two independent grounds: closure is an entailment consequence owned by the reasoning model and the available predicates differ in transitivity, and merge with survivorship is owned by the master-data model. Both were moved to composition links and out_of_scope.", "Tested whether 'same-as' could be projected onto a registered IANA link relation type. The registry has no such relation, and 'canonical', 'duplicate' and 'alternate' address representation preference, byte-identity and substitution respectively. The attractive shortcut was rejected and extension relation URIs are required instead.", "Tested whether the envelope could key itself on one of the endpoint identifiers, which would simplify lookup. Rejected because it makes the assertion indistinguishable from the endpoint, silently asserts precedence for one side, and would collide with the endpoint authority's non-reuse guarantees. Namespace disjointness became an explicit governance requirement.", "Tested whether cardinality could be left implicit in repeated rows, as in common two-column mapping files. Rejected because a genuine one-to-many claim then becomes indistinguishable from several independent one-to-one claims, and because the ranked-preference case cannot be recovered from serialization order.", "Tested whether an exception or conflict register should be a local artifact. Rejected because a durable register of what went wrong, who saw it and when drifts into audit-record and enforcement semantics owned elsewhere; anomalies are held as inline state codes and cross-references between envelope identifiers instead.", "Searched for a primary standard defining a comparable, calibrated confidence scale for equivalence assertions and found none. Rather than inventing a scale, confidence is carried as an issuer-scoped opaque value and the absence of a comparable scale is recorded as a checklist gap.", "Tested whether the model could declare conformance to SSSOM or ConceptMap on the strength of field-level correspondence. Rejected: the required-field sets differ and no validation report exists, so both are recorded as declared alignments with named profile versions rather than conformance claims.", "Boundary sweep against every relation rationale: each bundle, layer, finding and function was re-read for target-owned concepts. Matching, adjudication, merge, redirect execution, entailment and closure, identifier minting, label governance, access decision-making, retention execution and audit-trail semantics were all moved to out_of_scope, boundary_notes or composition references. The conflict function declares and refers; it does not detect or enforce. The applicability test set is a catalogue, not an evaluator.", "Collapse test: an adversary asked whether the nine kinds could be reduced to a single sameAs plus a confidence number. They cannot, because closeMatch is non-transitive while exactMatch is transitive, strict identity licenses substitution while a probable match does not, replacement is directional while equivalence is not, and explicit negation is a positive claim with its own evidence. Collapsing them loses information that the cited primary sources declare.", "Overclaim test: each proposed binding was checked for a citable clause. schema.org sameAs was deliberately not bound to the strict-identity rank because its expected type is the URL of a reference page; rel=canonical was not bound to identity because it is defined as a preferred IRI for duplicated content; HTTP 301 and 308 were bound only to referent replacement because the specification frames permanence as future request targeting.", "Silence test: every formal property was checked for whether the source asserts it, denies it, or is silent. SKOS asserts symmetry for closeMatch and exactMatch and transitivity only for exactMatch, and is silent on reflexivity; the model therefore records reflexivity as not-asserted-by-source rather than inventing a value. Recording silence as denial was rejected as unsupported.", "Negation test: the assumption that a missing alias implies non-identity was tested against OWL's explicit absence of a unique-name assumption and rejected; four distinct states were introduced so that unknown and unassessed cannot be read as negative, and a not-same claim must carry its own evidence.", "Artifact discipline test: each finding was checked against the exclusive representation rule. Findings whose content is a scalar attribute of an assertion or register row, namely strength and inference, plane discrimination, endpoint scope and negation states, were given a substantive inline rationale and no artifact, to avoid materialising duplicate registers or shadowing endpoint records owned elsewhere.", "Cycle and contradiction test: replacement chains, historical-identifier chains and combinations such as strict identity co-occurring with explicit not-same were examined. Rules were declared for each, with referral to an external adjudication service, and the model was checked to ensure it does not attempt to break cycles or resolve contradictions itself.", "Does any finding or function own matching execution? Checked each function: register-confidence stores a reported measurement and refuses incompatible scales but never computes or re-scores; feature and blocking configuration is recorded as parameters. Blocking, comparison and scoring remain with the referenced engine, and the boundary note states that holding a score confers no ownership of the scoring process.", "Does any element grant ownership of enforcement or audit-trail semantics? Checked: check-evidence-profile reports conformance and explicitly performs no blocking; the access layer classifies and refers; audit requirements state that events are emitted and cited while retention, immutability and audit-trail semantics belong to the referenced audit model. Deletion execution is assigned to the adopting Dimension's retention policy model in both the boundary notes and the delete rules.", "Can a high score be silently promoted to identity? Attempted the path: score lives in a separate element from semantic strength and assurance; a standing policy forbids deriving one axis from another; the export function withholds or downgrades disputed and undetermined assertions rather than emitting a transitive predicate. The path is closed by construction, though nothing prevents a non-conforming downstream consumer from ignoring the constraint, which is stated as a residual risk.", "Can an authoritative assertion masquerade as statistically certain? Checked: an authority-only assertion records an assurance level and a mandate with no score, and the strength-separation finding requires an explicit statement that no error estimate exists in that case.", "Can prior evidence be silently mutated or a winner silently selected? Checked patch rules, update operations and the disagreement finding: statements are append-and-supersede with immutable predecessors, retraction marks rather than removes, and the raise-disagreement function forbids modifying any member assertion. Selection of an operative assertion is explicitly deferred to the consuming system and attributed there.", "Is any structural node presented as canonical without primary support? Reviewed each: fairness and subgroup bias has method-level support from Harron et al. but no normative threshold or governance requirement in any primary source, so it is marked a gap in the checklist rather than asserted as canonical. Cluster-level confidence propagation was considered and deliberately omitted rather than invented.", "Does the model duplicate the parent identifier model or a sibling? Checked in-scope against out-of-scope: identifier minting, syntax, namespace validity and subject definition are excluded and delegated to the parent; master-data merge and survivorship are excluded so no golden-record semantics leak in.", "The relation ledger supplied for this model is empty, so every boundary was derived from the registry parent, the declared out-of-scope list and the external alignments rather than from stated relation rationales. Each bundle, layer, finding and function was re-read against the composition links: all references to a matching engine, policy model, audit model, evaluation corpus and agent registry carry only the target reference, binding and subject-specific parameters, and no target-owned lifecycle or operational function is reproduced locally.", "Tested whether a single symmetric and transitive alias predicate would suffice. Rejected: SKOS declares closeMatch symmetric but explicitly not transitive, and declares broadMatch and narrowMatch as an inverse pair, so a uniform algebra would over-generate equivalences that no source licenses.", "Tested whether this model should own transitive closure so that consumers get a complete alias set. Rejected: closure and entailment are reasoner concerns referenced through a composition link. The model evaluates a declared composition rule over a caller-supplied edge sequence and never discovers paths or materialises inferences.", "Tested whether a sufficiently high confidence value could promote closeMatch to exactMatch, or a linkage posterior to owl:sameAs. Rejected: no cited specification licenses strength promotion from a numeric score, and probabilistic linkage explicitly carries error rates and assumption dependence.", "Tested whether dcterms:isReplacedBy or an HTTP 308 permanent redirect entails identity of the described thing. Rejected: both are directional relations about succession of a record or relocation of a resource, and RFC 9110 frames permanence as licence to rewrite references, not as an identity claim.", "Tested whether the conformance report implies ownership of validation execution, enforcement or audit retention. Rejected: the report is a derived, non-authoritative structure aligned to an external validation model; execution, enforcement, persistence, retention and audit trail all sit with referenced models, and the delete rules name who owns erasure.", "Tested whether schema.org sameAs could serve as the canonical predicate for the whole model, given its adoption. Rejected: its documented meaning is a reference web page indicating identity, its expected type is URL, and it declares no symmetry, transitivity, inverse or domain restriction beyond Thing.", "Searched for a counterexample to uniform inverse pairing. Found one: broadMatch and narrowMatch are an OWL inverse axiom under SKOS S43, whereas dcterms:replaces and isReplacedBy are a documentary inverse pair without such an axiom. The model therefore records axiomatic force alongside every declared property instead of a bare boolean.", "Tested whether an assertion with no declared context could be treated as globally valid to simplify consumption. Rejected: RDF's open-world reading means silence asserts nothing, and the identity literature documents referentially opaque contexts where substitution must not be applied, so scope-unknown is reported as undetermined rather than compatible.", "Attempted to justify owning cluster calculation locally, since the model already holds the edges and could compute connected components cheaply. Rejected: transitive closure over identity edges is an entailment computation whose correctness depends on predicate semantics owned elsewhere, and owning it would import reasoning lifecycle into a mixin. Reduced to registration, digesting and reproducibility checking of an externally supplied result.", "Attempted to add a representative-selection rule set (source priority, recency, completeness). Rejected: no consulted standard supports any selection criterion, and modelling one would convert a preference decision into apparent equivalence semantics. Retained only the reference to the deciding authority, its rule version, scope and interval, and recorded the absence as a checklist gap.", "Attempted to let the traversal function write a derived alias edge when a path of exactMatch edges is found, since exactMatch is transitive under SKOS S45. Rejected: transitivity licenses an inference, not a write, and materialising it would make this model the source of assertions it cannot justify. The non-materialisation rule and the assertion-status field were made mandatory on every derived record instead.", "Tested whether an integrity check report constitutes enforcement or audit ownership. Concluded it does not: results carry focus, condition and severity and trigger nothing, the evaluator is referenced rather than owned, and audit capture is delegated. Wording in the finding, the function effects and the composition link was tightened so that no repair, retraction or notification-and-remediation is implied.", "Tested whether a confidence value could safely be aggregated along a path to give a single score, which consumers repeatedly request. Rejected on the evidence that compound error across chained mappings is exactly what SKOS's non-transitive closeMatch guards against; weakest-edge reporting was made mandatory and aggregation above the weakest link prohibited.", "Checked whether 'stale member' and 'orphaned representative' handling smuggles in endpoint lifecycle ownership. It does not: the model detects and annotates, referencing the upstream withdrawal record, and explicitly states that endpoint removal is executed by the master-data model and that immutable snapshots are annotated rather than edited.", "Checked every artefact against the exclusive-representation rule and every finding for double representation. Five findings carry artefacts with a null rationale; four are inline-only with substantive rationales explaining why a published document would create a competing statement of edge existence, predicate profile, blocking marker or representative decision.", "Re-read every bundle, layer, finding and function against each composition rationale looking for target-owned concepts. Moved reasoning closure, matching, merge, representative selection, authorisation decisions, audit capture and disposition execution out of the structural nodes and into composition links, out_of_scope entries and boundary notes.", "Checked every finding and function against the composition ledger for target-owned concepts: none defines endpoint lifecycle, deprecation of an endpoint itself, redirect execution, similarity or match computation, authorization evaluation, enforcement or master-data mutation. Endpoint deprecation and replacement appear only as referenced upstream triggers with assertion-side consequences.", "Checked that citing an access policy or an audit service grants no ownership: the authority finding records attribution and cites policy only, the validate-transition function returns an advisory conformance verdict rather than a permission decision, and the access layer states explicitly that the platform audit service owns audit-trail semantics.", "Attempted to break the append-only claim with rollback, correction and lawful erasure. Rollback is a forward restoring transition, correction is an appended restatement, erasure is a redaction marker preserving structure and digests; none removes or reorders a record, so the claim survives.", "Tested whether a retraction could be used to hide an inconvenient assertion: the tombstone must remain resolvable with a stated reason, refuting evidence references survive, and a formerly public identifier may not become silently unresolvable.", "Tested whether any identifier or serial token is date-derived: ordinals are monotonic integers scoped to an assertion with an explicit prohibition on temporal components, and the identifier priority states that a date, version label or status term is never an identifier.", "Tested conformance overreach: PROV, SKOS, ISO/IEC 11179-6 and OAIS appear only as ALIGN links with named partiality, and the recorded conflicts show where alignment fails rather than asserting compliance.", "Tested for duplication of the parent model: because the WM-XCT-011 boundary is unverifiable from public sources, identity-substrate concepts were deliberately left out and the link is declared a gap rather than modelled locally.", "Does any bundle, layer, finding or function claim ownership of redirect execution, endpoint availability, authorization evaluation, data merge or equivalence inference? Checked: chain handling ingests observed hops and never dereferences; endpoint condition is an observation pointing at the endpoint authority; access declares fields and delegates enforcement; endpoint change is registered, not decided; inference is delegated with an explicit composition link.", "Could an answer be produced that silently picks one endpoint or follows an unbounded chain? Checked: ambiguity returns the full candidate set with an ambiguity status, an exhausted budget and a detected loop each produce their own status with the partial trace retained, and non-determinism conditions forbid emitting an answer at all.", "Could a past answer change without trace? Checked: append-only assertions and immutable answers, dual timelines with an observation cut-off, rule-set version and determinant digest on every answer, and a replay function that reports divergence rather than overwriting.", "Does any structural node rest only on secondary sources or on assumption? Checked: every node cites at least one primary source; the two nodes whose normative support is weak (hop budget, idempotency keys) are marked as gaps rather than presented as canonical, and confidence quantification is left undefined rather than fabricated.", "Does the model duplicate the parent identifier model or a sibling? Checked: no identifier minting, syntax, persistence guarantee or authority-delegation content is modelled here; each is bounded out with a cited neighbour note and a composition link.", "Does containment or quarantine amount to an audit-trail or enforcement claim? Checked: containment sets state and publishes a tombstone on this model's own records; enforcement of visibility and the audit trail of consumption are both delegated outward with explicit composition links.", "Checked every bundle, layer, finding and function against the authorization boundary: no node evaluates an access request or returns permit or deny. The disclosure projection function consumes a declared profile and has an explicit precondition that the request was already authorised externally, matching the standard separation of administration, decision, information and enforcement points.", "Checked that no node claims ownership of audit capture, storage, protection or retention; only audit event references are held, and the access layer states explicitly that the external store is the audit source of truth.", "Checked that no node executes destruction, transfer or media sanitisation. Retention class and hold state are bindings; the delete rules name the records authority and the privacy model as the owners of execution and of erasure decisions respectively.", "Rejected an attractive but unsupported authority-weighted trust score node: no cited standard defines how to compute a numeric trust value across federated authorities, so the concept was reduced to declared confidence plus a policy-set threshold, and the calibration gap was recorded in the checklist.", "Rejected local modelling of consent records, impact assessments and records of processing: those sit with the controller under the cited legislation and vocabulary, so only references, purpose codes and lawful-basis pointers are carried.", "Tested the counterexample of a weak hint being laundered into a strict identity claim by chaining through a third party's transitive exact match, or by an exception. Chain depth and strength ceilings, plus the exception invariant that forbids raising relation strength, assurance level or evidence class, close both routes and are recorded as constraints rather than assumed behaviour.", "Verified identity and time discipline: identity priority names the authoritative master-system identifier first, no artifact uses a date or file name as an identifier, sequence labels are explicitly not identifiers, and every timestamp rule separates event time from observation or ingestion time.", "Tested whether this model should own an evaluation or enforcement engine for access decisions, since it defines an access default. Rejected: no primary source grants it enforcement semantics, and the default rule was rewritten to defer absolutely to the referenced access-evaluation model, with the model carrying only the reference and alias-specific binding parameters.", "Tested whether the change events it emits make it the audit trail. Rejected: audit-record storage, immutability and retention are held by the referenced audit model, and this model retains only the audit reference; the CRUD delete rules state explicitly that audit retention lies outside its control.", "Tested whether a content digest could serve as a stable record identifier, which would be convenient for deduplication. Rejected: the SSSOM hashing procedure states that equal hashes make records only highly likely to be identical, and identity fields are excluded from the canonical form, so a digest is structurally incapable of being identity.", "Tested whether skos:exactMatch could be presented as a conformant projection of owl:sameAs. Rejected: SKOS does not entail individual identity and declares exactMatch disjoint with broadMatch and relatedMatch, so the binding is recorded as a documented downgrade with an explicit closure licence, not as conformance.", "Tested whether one canonical serialization could be declared for all projections, which would simplify the integrity rule. Rejected: RDF Dataset Canonicalization applies only to RDF datasets and the SSSOM record hash applies to slot records, so two regimes are declared explicitly and cross-regime digest comparison is prohibited.", "Searched for a normative standard for calibrating or comparing equivalence confidence across publishers. None found; SSSOM's confidence slot is uncalibrated. Recorded as a checklist gap rather than asserted as a capability.", "Tested whether defining endpoint identifier schemes or resolver behaviour was necessary to make the redirect projection useful. Rejected: the model emits a server-agnostic rule set and a derivation record, and the referenced identifier-scheme and resolution model retains scheme design and request handling.", "Tested whether the mixin should carry the host subject's merge or survivorship rules, since equivalence and record merging often ship together. Rejected: attribute survivorship is master-data work belonging to the host or golden-record model, and importing it would let an equivalence assertion silently rewrite subject attributes.", "Does any function perform matching, inference, resolution, merge, authorization, audit-log writing, notification delivery or physical deletion? Checked against all ten functions: each is confined to canonicalisation and digesting, receipt classification, validator comparison, check evaluation, failure-document composition, record appending or compensation-plan derivation. Every function that touches an external concern emits a reference or correlation identifier and explicitly disclaims the target's behaviour.", "Could the idempotency key or the request fingerprint be mistaken for an identifier? Explicitly forbidden in the identity priority rule: the key is a scoped uniqueness constraint within its retention window and the fingerprint is a comparison value. Record identity always comes from the master-system identifier, the governed IRI or a minted UUID or ULID.", "Does replay resolution mask a genuine lost update? Ordering is specified: replay classification runs before precondition evaluation, and the two produce distinct outcome codes, so a stale validator can never be silently absorbed as a duplicate. Receipt expiry is published and post-expiry retries fall back to the concurrency validator as the remaining safeguard.", "Does the model quietly own audit semantics by keeping receipts and transition records? Receipts, reports, decisions and transitions are domain state of the register with internal digest chaining for tamper-detection; the audit-trail model owns audit-record storage, tamper-evidence, retention and query. The internal integrity guarantee is stated as independent of, and not a substitute for, that model.", "Does declaring an access scope amount to making an access decision? No. Validation confirms only that the declared scope is present, registered and not broader than the scope recorded on the target. Whether the actor may act is decided by the referenced authorization model, whose decision reference is recorded rather than re-derived.", "Does the model claim conformance to any cited standard? No. SKOS and OWL bindings are declared as alignments; the ISO registration standard is used only as evidence that a governed registration procedure exists, because only its catalogue record was accessible; the idempotency-key draft is cited as expired work in progress; and the accommodation of the problem-details single-problem guidance is recorded as a conflict rather than presented as conformance.", "Is any structural node unsupported by a primary source? Every bundle, layer, finding, function and composition link cites at least one primary source from IETF, W3C or ISO/IEC. The one node without primary support — a normative confidence scale — is recorded as a gap in the checklist and as a known omission rather than being modelled as canonical structure.", "Tried to justify a preferred-identifier output using method-guaranteed canonical identifiers and the registered canonical link relation. Rejected: both are claims a publisher makes about its own resources, not a licence for a third-party query surface to collapse a candidate set. Retained as attributed claims with a not-applied marker.", "Tried to make transitive closure the default traversal semantics on the strength of equality transitivity. Rejected: SKOS explicitly refuses transitivity for closeMatch to avoid compound errors and the empirical literature documents systematic over-assertion of identity links. Closure is now declared per relation kind and chaining a non-transitive kind is flagged.", "Tried to add a matching or similarity finding that would generate candidates where no assertion exists. Rejected as outside the boundary: it would convert the model into an entity-resolution engine and would allow a no-answer state to be filled with inference.", "Tried to model an audit trail and a policy-evaluation record inside the access layer. Rejected: decision and enforcement are separated by the access-control standard and attribution records are owned by the provenance service. Both were moved to composition links, boundary notes and reference-only data elements, and the audit requirements were rewritten as reference obligations.", "Tried to treat a silenced federated-source failure as an ordinary empty result. Rejected after reading the normative service-invocation definition, which makes the two indistinguishable at the solution level. A mandatory disclosure statement bound one-to-one to every result was added instead.", "Tried to name serial records by their as-of date for operator convenience. Rejected under the identity rule that a date is not an identifier; serial ULIDs bound to the request record are used, with instants retained as attributes.", "Tried to implement as-of reads by following a TimeGate and negotiating a datetime. Rejected as execution of a resolution protocol owned by another service; the model reports the TimeGate or TimeMap reference and serves its own stored state with an explicit match mode.", "Tried to let comparison emit a recommended assertion when one authority's evidence was verified and the other's was not. Rejected: verification does not establish the truth of a claim and the decision to rely on it belongs to the caller, so the outcome vocabulary records divergence and non-comparability instead.", "Does any bundle, layer, finding or function let this model resolve a conflict, rank a claim out of existence, delete a record, place or release a hold, decide access or write an audit trail? Every function's effects were re-read against every composition rationale. Result: none does. Severity and ordering are explicitly non-resolutive; deletion, hold placement, authorization and audit construction appear only as REFERENCE links, out_of_scope entries and boundary notes, and each function states them as prohibited effects.", "Could a conflict or readiness report be mistaken for an audit record and relied on evidentially? Rejected. Report instances carry provenance and content digests, which support reproducibility but not tamper-evidence. The audit link is a REFERENCE, the model makes no non-repudiation claim, and the security checklist row states this rather than hiding it.", "Does impact reporting duplicate the entity-resolution engine's matching semantics? Checked and rejected. The impact function consumes a classified trigger plus prior and posterior state references and never recomputes a match, a score or a blocking key; match computation is an out_of_scope entry and a REFERENCE to the quality and measurement model.", "Is a clean conflict report presented anywhere as proof of sameness? Rejected on OWL 2 grounds: no unique name assumption means silence entails nothing. The conformance-style summary is paired with a mandatory coverage statement, unreachable authorities degrade rather than clear a report, and the prohibition is repeated in policy, in the function failure modes and in the recorded conflicts.", "Does disposition readiness quietly assume US federal records law? Partly, and it is disclosed. The status set is jurisdiction-parameterised, externally governed is first-class, and the regional assumption records that only NARA practice and one EU-derived notification obligation were verified. Jurisdiction is marked a gap in the checklist rather than presented as covered.", "Which attractive structure was proposed and rejected for lack of primary support? A conflict-resolution workflow layer (target-owned: adjudication belongs to a named accountable party, not to a reporting mixin); a notification delivery and subscription layer (target-owned per the sender/receiver/consumer separation in Linked Data Notifications); a tombstone-production finding (would have implied this model performs deletion, so residue is declared as a rule set and the tombstone is created by the executing records authority); and a unified numeric confidence score reconciling assurance levels with quality metrics (no source supports the arithmetic).", "Does the reporting surface silently reproduce the parent identification model's identity machinery? Checked against the CHILD relation rationale. This model mints identifiers only for its own report instances and results; every referenced endpoint, hold, retention rule and measurement is carried in its owning authority's namespace, and the canonicalization rules explicitly forbid local identifier rewriting on the grounds that rewriting would itself be an unasserted equivalence claim.", "Attempted to justify emitting owl:sameAs for a high-confidence probabilistic match once a threshold was crossed. Rejected: SameIndividual asserts individual equality, and no confidence value converts a graded assertion into an equality axiom. The threshold non-upgrade flag exists to make this refusal auditable.", "Tested whether a chain of 301 responses could be projected as transitive identity. Rejected: RFC 8288 forbids inferring extra semantics from a relation type's presence or cardinality, and RFC 9110's 303 demonstrates that redirection can target a genuinely different resource.", "Tested whether a content digest could serve as the projection's identifier, which would be convenient and stable. Rejected: digests detect corruption rather than establish authenticity or identity, and two unrelated exports of the same empty scope produce the same digest.", "Checked whether the loss report should own storage of the audit trail or enforcement of refusals, since it already knows the facts. Rejected: the report is a derived record, and audit-trail and enforcement semantics belong to the adopting Dimension's platform services.", "Considered importing entity-resolution scoring so projection could select targets automatically. Rejected: matching produces the assertions this model consumes, and modelling it here would duplicate a sibling model's function and blur the asserted-versus-computed boundary.", "Checked whether a CSV projection could ever be declared lossless. Rejected: the tabular data model itself cannot distinguish an empty unquoted field from an empty quoted field, so every CSV projection must carry at least a syntactic-fidelity loss entry.", "Tested whether a database view, secondary key or YAML anchor could stand in for an alias record and save a projection step. Rejected: each is a storage or serialization convenience with no asserting authority, no strength and no confidence, and reading one back as an assertion would fabricate provenance.", "Reviewed whether the advisory redirect map amounts to owning redirect execution. Rejected: the map is a calculated, non-executing recommendation carrying an explicit advisory-only flag, and every function's effects statement excludes writing to endpoints, repositories, collections or serving configuration." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "mixin", "status": "deferred", "rationale": "Two distinct axes are in play: record_plane='world-model' classifies where this registry entry sits (a plane label, not a subject-model kind), while entry_kind must be chosen from the schema enum to describe what the model itself is. 'Mixin' is defensible: it matches the registry's own recorded value and the model's explicit self-description as a weakly identified, host-dependent attachment, consistent with sibling mixins like currency, geometry, localization, and digital-signature models. However, the assertion envelope's independent proposal, decision, transition, query, and reporting machinery is unusually rich for a mixin and would equally support 'relationship' as the entry kind, since the core content is an evidenced, versioned connector between two independently owned endpoints that never takes ownership of either side. Status is recorded as deferred rather than accepted because the registry's own review_state is explicitly boundary-review-required and the WM-XCT-011 parent boundary is self-admitted as unverifiable from any public source, so final certification should wait for that review rather than being closed unilaterally here." }, "decisions": [ { "concept": "Entry-kind classification: mixin vs relationship", "disposition": "Deferred within boundary_decision; provisionally keep 'mixin' pending formal review", "rationale": "The registry already records entry_kind='mixin' and the model's scope statement calls itself a 'weakly identified mixin attached to a host record,' matching the sibling cohort (currency, geometry, localization, signature). But the envelope's independent proposal/decision/transition/query/report machinery is far richer than typical mixin scope and would equally support 'relationship' as the entry kind." }, { "concept": "Aggregate root scope", "disposition": "Accept the assertion envelope as the sole internal aggregate root", "rationale": "Command envelopes, concurrency tokens, and append-only transition history are consistently scoped to the individual assertion envelope, while endpoints, equivalence clusters, and reports are explicitly treated as externally computed or externally owned artifacts this model only registers or references, never mutates." }, { "concept": "Ownership boundary over matching, merge, redirect, authorization and audit", "disposition": "Accept as well-evidenced", "rationale": "Over one hundred entries in the model's own adversarial_checks section specifically test and reject attempts to let this model perform matching execution, transitive closure, master-data merge, redirect execution, access decisions, or audit-trail storage, consistently redirecting each to a named external model via composition references." }, { "concept": "Empty relationship contract versus asserted boundary_notes neighbors", "disposition": "Accept the content but flag as a formal registration gap", "rationale": "The frozen relationship-contract array is literally empty while the model's own boundary_notes and adversarial_checks describe eight distinct neighbor relations (parent, endpoint models, identifier authority, predicate vocabularies, reasoning/closure model, matching engine, authorization model, audit model); none of these is yet a ratified registry relation, a gap the model itself acknowledges deriving around." }, { "concept": "Parent link to WM-XCT-011", "disposition": "Accept as declared in the registry but treat as unverified", "rationale": "Registry parent_ids names WM-XCT-011, but the model's own known_omissions state that WM-XCT-011's boundary 'could not be verified from any public source,' and review_state is explicitly boundary-review-required, so the CHILD relationship should not be treated as confirmed." }, { "concept": "Access and authorization reference-only boundary", "disposition": "Accept the deny-by-default, reference-only access design", "rationale": "The access section consistently stores only a policy reference and a coarse suppression signal rather than performing or caching an access decision, matching the standard separation of decision, enforcement, and information points, reinforced by dedicated adversarial_checks confirming no permit/deny result is produced locally." }, { "concept": "Artifact identity-priority rule", "disposition": "Accept as consistently applied", "rationale": "All roughly eighty declared artifacts follow the same three-tier identity priority (authoritative master-system identifier, then governed IRI, then Dimension-assigned UUID/ULID) and explicitly forbid dates, digests, filenames, or version strings from serving as identity, with dedicated adversarial_checks rejecting digest-as-identifier shortcuts." }, { "concept": "Command-envelope idempotency design resting on an expired IETF draft", "disposition": "Accept the design pattern but keep its normative weight downgraded", "rationale": "Source SRC-062, the Idempotency-Key HTTP Header Field draft, expired 2026-04-18 and is not a standard; the model already labels concurrency-and-idempotency as a checklist 'gap' rather than 'covered,' so the self-rating already matches the evidentiary weakness and needs no further downgrade." }, { "concept": "Citation of non-final W3C Candidate Recommendation specs", "disposition": "Accept with the hedges already present", "rationale": "RDF 1.2 Concepts and DID Resolution are both cited at Candidate Recommendation stage rather than full Recommendation, and the model's own conflicts list already flags both as provisional and subject to change before final publication, so no additional hold beyond live re-verification is required." }, { "concept": "Retention versus jurisdictional erasure duties", "disposition": "Accept as a deliberately unresolved, clearly disclosed tension", "rationale": "The tombstone-first retention design can conflict with statutory erasure obligations in some jurisdictions; rather than silently resolving this, the model assigns the decision to the adopting Dimension's retention and privacy models and states the tension explicitly in its conflicts list, which is the correct posture for a format-neutral mixin." }, { "concept": "Redundant near-duplicate entries in the conflicts and omissions lists", "disposition": "Accept content, recommend an editorial deduplication pass", "rationale": "Several conflict entries restate the same skos:exactMatch-transitive versus skos:closeMatch-non-transitive point in only slightly different framings; this does not affect correctness but inflates review burden and risks masking genuinely distinct issues among repeated ones." }, { "concept": "Duplicate citation of the same W3C Recommendation at two URIs", "disposition": "Accept as valid per W3C publishing convention", "rationale": "SRC-001/SRC-018 (OWL 2 Structural Specification) and SRC-003/SRC-020 (SKOS Reference) each cite both the floating latest-version URI and the immutable dated permalink for the same Recommendation, which is standard W3C practice and not a citation error, merely non-minimal." }, { "concept": "Enterprise identity profile 0.1.0", "disposition": "Additive bounded reference profile attached to unchanged parent synthesis", "rationale": "The new Claude and Grok studies/reviews concern only the enterprise increment. Historical single-provider policy, reviewable-draft status and all parent holds remain. Profile evidence: https://ver.cy/enterprise/research/em-xct-01/" } ], "publicationHolds": [ "Live re-verification is required for all 108 cited source URLs and version/edition pins before this leaves reviewable-draft status, especially the two Candidate-Recommendation-stage W3C drafts (RDF 1.2 Concepts, DID Resolution) and the expired idempotency-key Internet-Draft, none of which this no-tools audit could re-check.", "This entire result was produced under an owner-authorized single-provider waiver: the repository owner instructed the queue to continue Claude-only from WM-XCT-013 onward after repeated Grok structured-output failures (authorized 2026-08-29), so no independent second-provider cross-check exists for WM-XCT-036, and that absence must stay visibly disclosed on this artifact.", "The relationship contract for vr.wm-xct-036 is currently an empty array despite the model's boundary_notes and adversarial_checks describing eight distinct neighbor relations (parent WM-XCT-011, endpoint models, identifier authority, predicate vocabularies, reasoning/closure model, matching engine, authorization model, audit model); none is yet a ratified registry relation.", "The registry review_state is explicitly 'boundary-review-required' with priority_confidence 'low'; this draft should not advance past reviewable-draft status until that formal boundary review resolves the entry-kind tension and the unverified WM-XCT-011 parent link noted in this audit.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft.", "Enterprise identity 0.1.0 is a bounded companion-validated reference profile, not full parent conformance, native enforcement, authenticated identity or completed EM-XCT-01. See the separate profile/review limits." ], "deferredResearch": [ "Confirm whether 'mixin' remains correct for WM-XCT-036 once WM-XCT-011's own boundary is formally reviewed, given the unusually rich independent command, lifecycle, and query surface compared to a typical attachable mixin.", "Compare WM-XCT-036 against already-published sibling mixins (digital signature proof, geometry coordinate reference, currency monetary value, localization language) to confirm this registry's specific, broader usage of 'mixin' as a host-attached but internally structured component.", "Run an editorial deduplication pass over the conflicts and known_omissions lists, which contain several near-identical restatements of the same skos:exactMatch/closeMatch transitivity point, to reduce review burden without losing distinct content.", "Re-verify all cited source URLs at the next research refresh, particularly the two W3C Candidate Recommendation drafts and the expired idempotency-key Internet-Draft, to confirm whether any has since reached final or Recommendation status.", "Once a second provider is available again, run a full adversarial cross-check against this Claude-only structure, focused on the entry-kind classification and the empty relationship contract, the two weakest-evidenced axes in single-provider mode." ] }, "statistics": { "sources": 108, "bundles": 27, "layers": 65, "findings": 120, "questions": 537, "artifacts": 81, "functions": 98 }, "enterpriseProfiles": [ { "format": "vercy-enterprise-profile-publication", "profileId": "urn:vercy:profile:enterprise-identity", "profileVersion": "0.1.0", "parentModelId": "WM-XCT-036", "parentPublicationVersion": "0.3.1-enterprise.1", "semanticBasis": [ { "modelId": "WM-XCT-011", "version": "0.3.0-research.1", "specSha256": "aad32a06d60f58191cba4c6675a8d93a49985c91ec5480ca5c05c132725d0834" }, { "modelId": "WM-XCT-036", "version": "0.3.0-research.1", "specSha256": "21fe1b8e3663c00c92ca433f5045581589f7e5b433775b3060d30ecc08c48b17" } ], "canonicalUrl": "https://ver.cy/models/wm-xct-036-alias-same-as-mapping/profiles/enterprise-identity/0.1.0/", "researchUrl": "https://ver.cy/enterprise/research/em-xct-01/", "status": "published", "researchAssurance": "reviewable-draft", "nativeReadiness": "Tested outer V3 snapshot binding with explicitly invoked companion; native V3 does not enforce nested semantics. New synthetic Dimensions only.", "contourStatus": "partial", "language": "en", "providers": { "studies": [ "Claude", "Grok" ], "audits": [ "Claude", "Grok" ], "scope": "See review.md for exact first/follow-up scopes; no full parent or 108-source review claimed." }, "validation": { "tests": 87, "passed": true, "newDimensionScenarios": 3 }, "license": "Apache-2.0", "createdAt": "2026-09-21T17:23:35.504538+00:00" } ], "runtimeDiscoveryNote": "Restores unchanged legacy semantic-package discovery: 0.3.1 accidentally projected natural-language research composition targets as executable dependency IDs. This metadata patch does not ratify or resolve the broad conceptual dependency graph. The optional 0.1.0 reference profile has a separately explicit, tested two-model closure over archived 0.3.0 semantic packages." }